diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-07 22:12:54 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-07 22:20:45 +0200 |
| commit | 462d76898a306981fbeac859cd54da1468e80639 (patch) | |
| tree | 9a49723da751b4a7225e3dd37181ecceed192f3a /packages/meshbay-node/src/meshbay_node/roster.py | |
| parent | 92e6b9823119b5461efc304a81e79e186a928e6d (diff) | |
| download | meshbay-462d76898a306981fbeac859cd54da1468e80639.tar.gz | |
fix(node): name members admitted without an invitation name
A member who joined by link, by a new device or into an open group was
pinned in the roster with no name, so the audit log showed only the
first characters of their id. The hub's MNP token now carries the
account's username, and after the handshake the node writes it into the
roster for an account whose name is empty. An invitation's name is never
overwritten; the name is a label, authority stays on `sub`.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-node/src/meshbay_node/roster.py')
| -rw-r--r-- | packages/meshbay-node/src/meshbay_node/roster.py | 18 |
1 files changed, 18 insertions, 0 deletions
diff --git a/packages/meshbay-node/src/meshbay_node/roster.py b/packages/meshbay-node/src/meshbay_node/roster.py index eb8c031..07b9ea6 100644 --- a/packages/meshbay-node/src/meshbay_node/roster.py +++ b/packages/meshbay-node/src/meshbay_node/roster.py @@ -398,6 +398,24 @@ class Roster: (user_id,)) as cur: return [dict(r) for r in await cur.fetchall()] + async def name_identity(self, user_id: str, username: str) -> bool: + """ + Give a nameless account the name its hub token carries. + + Only an empty name is filled: an invitation names the person the + operator meant, and that stays. Links, devices and open groups pin an + account with no name, which left the audit log showing a bare id. + """ + assert self._db + if not username: + return False + cur = await self._db.execute( + "UPDATE identities SET username = ? " + "WHERE user_id = ? AND username = ''", + (username, user_id)) + await self._db.commit() + return cur.rowcount > 0 + async def revoke_device(self, user_id: str, pk_ed25519: str) -> bool: """ Retire one device, leaving the account's others alone. |