aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-node
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 11:49:56 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 11:49:56 +0200
commitd3ad243c4ae3a273f623bd5fc631e3266aa4d0e4 (patch)
tree95ff1252c80a71e93c5098822d31b835572d8b52 /packages/meshbay-node
parent69554fac7eba6eef7eb8a1c0111c5b92e7f21256 (diff)
downloadmeshbay-d3ad243c4ae3a273f623bd5fc631e3266aa4d0e4.tar.gz
fix: only the owner decides who hosts a group, and nobody is made a member unasked
- hub: a node may host a group only if its account owns it or the owner approved that node (new `group_hosts`). Membership was the ceiling, and every member holds the group key, so any member's node could register as a host and be the one clients kept. A node claiming a group it may not host is recorded as a request; the owner is notified once and approves or refuses it (GET/POST/DELETE /v1/groups/{id}/hosts[/{node_id}]), which takes effect on a connected node at once. - hub: an owner adding a username creates an invitation (new `group_invitations`), accepted or declined by the invitee (/v1/groups/invitations, /{id}/invitation/accept|decline). Until then the group is not listed, not dialled, not searched and not in any token. Invitation links, open joins and group creation still make members directly: they are the account's own act. - hub: the MNP token names only the group it is minted for (group_id is now required), so a node operator no longer learns a member's other groups. - SPA: invitations on the home page; invited people and host requests in the group's settings; the transport sends group_id. Ten catalogues. - Browser probes for both screens, run in Chrome and Firefox. - Design §5.2, §7.2, §7.3, AV32, AV33; protocol §6.3; user guide. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-node')
-rw-r--r--packages/meshbay-node/src/meshbay_node/cli/members.py4
-rw-r--r--packages/meshbay-node/tests/golden/cli.json2
2 files changed, 3 insertions, 3 deletions
diff --git a/packages/meshbay-node/src/meshbay_node/cli/members.py b/packages/meshbay-node/src/meshbay_node/cli/members.py
index 5d26bd0..08cff39 100644
--- a/packages/meshbay-node/src/meshbay_node/cli/members.py
+++ b/packages/meshbay-node/src/meshbay_node/cli/members.py
@@ -100,8 +100,8 @@ def member(args) -> None:
print()
print(f"Send it to {args.target} however you normally talk. It works")
print("once, for that account only, and never passes through the hub.")
- print("They enter it the first time they open the group — you do not")
- print("need to be online then.")
+ print("They accept the invitation in MeshBay, then enter the code the")
+ print("first time they open the group — you do not need to be online then.")
print()
print(f"also written to {path}")
return
diff --git a/packages/meshbay-node/tests/golden/cli.json b/packages/meshbay-node/tests/golden/cli.json
index 71fa336..b397eeb 100644
--- a/packages/meshbay-node/tests/golden/cli.json
+++ b/packages/meshbay-node/tests/golden/cli.json
@@ -334,7 +334,7 @@
"asked": [],
"exit": 0,
"stderr": "",
- "stdout": "INVITATION CODE TEST-CODE\nvalid until \n\nSend it to bob however you normally talk. It works\nonce, for that account only, and never passes through the hub.\nThey enter it the first time they open the group — you do not\nneed to be online then.\n\nalso written to <tmp>/home/.local/share/meshbay/invite-code\n",
+ "stdout": "INVITATION CODE TEST-CODE\nvalid until \n\nSend it to bob however you normally talk. It works\nonce, for that account only, and never passes through the hub.\nThey accept the invitation in MeshBay, then enter the code the\nfirst time they open the group — you do not need to be online then.\n\nalso written to <tmp>/home/.local/share/meshbay/invite-code\n",
"systemctl": []
},
"member invite bob@example.test --link": {