diff options
Diffstat (limited to 'CLAUDE.md')
| -rw-r--r-- | CLAUDE.md | 16 |
1 files changed, 10 insertions, 6 deletions
@@ -262,10 +262,12 @@ These are about working on the tree rather than about the design: `docs/MESHBAY_DESIGN.md` §13.5b is the register; `test_availability_between_ members.py` is where a new case goes, and every test in it is two accounts, because a one-member test proves a one-member property -- **Never change the KDF parameters in one place.** `keyderive.js`, - `keyderive.py`, the QE harness and `test_bundle_kdf_parity.py` are held - byte-identical by that test, and a mismatch does not look like an error — it - looks like an account nobody can open +- **Never change the KDF parameters in one place.** `keyderive.js` (the page), + `meshbay-client/src/keyring.js` (the desktop main process) and a Python + reference written from `MESHBAY_DESIGN.md` §3.7 are held byte-identical, down + to opening a bundle, by `test_bundle_kdf_parity.py` and + `test_desktop_keyring.py`; a mismatch does not look like an error — it looks + like an account nobody can open - **Raw answer SDP is saved before `setRemoteDescription`** — Chrome strips sha-256 from a multi-hash SDP, and the fingerprint is the channel binding - **Upload chunk size is 48 KB**, which is what fits the aiortc SCTP limit after @@ -921,7 +923,7 @@ here are kept only where they are a rule about *editing* the code. | Handshake, version range | `meshbay_common/handshake.py` — `MNP_MIN_SUPPORTED`, `check_version` | read by both servers and both clients | | Wire messages, `req_id`, `IndexEntry` | `meshbay_common/protocol.py` | §5.3 | | Signed admin transcripts | `meshbay_common/adminop.py`, `join.py`, `device.py` | §5.4 | -| Key derivation from a passphrase | `meshbay_common/keyderive.py` + `static/keyderive.js` | §3.1. **Parity-tested — never change the parameters in one place** | +| Key derivation from a passphrase, bundle format | `static/keyderive.js` (page) + `meshbay-client/src/keyring.js` (desktop main process) | §3.1, §3.7. **Parity-tested — never change the parameters in one place.** `meshbay_common/keyderive.py` is an older, unused derivation, not this one | | Path folding, NFC, long paths, reserved names | `meshbay_common/paths.py` | §10 | | ~~Double Ratchet / Sender Keys~~ | — | **Deleted.** Both were written and never called. Kept code that nothing calls reads as an alternative somebody may reach for, and its green tests read as evidence of a protection that is not in the product. The reasoning that ruled them out is at the top of `chatbox.py` | @@ -961,7 +963,7 @@ here are kept only where they are a rule about *editing* the code. | Signaling relay | `meshbay_hub/api/signaling.py` | §7.2 | | Groups, membership, presence, public-group quota | `meshbay_hub/api/groups.py` | §7.3 | | Admin API, instance policy, moderation | `meshbay_hub/api/admin.py`, `hub.py` | §7.4, §7.5 | -| Notifications, federation, relays, reports | `meshbay_hub/api/notifications.py`, `federation.py`, `relay.py`, `moderation.py` | §7.6. **Federation is off**: `federation.FEDERATION_ENABLED` is False and every MHP route answers 503, because no two hubs have ever completed a request between them. Its tests open the gate for themselves. **Relays are closed the same way** (`relay.RELAYS_ENABLED`): nothing in the tree calls them | +| Notifications, federation, reports | `meshbay_hub/api/notifications.py`, `federation.py`, `moderation.py` | §7.6. **Federation is off**: `federation.FEDERATION_ENABLED` is False and every MHP route answers 503, because no two hubs have ever completed a request between them. Its tests open the gate for themselves | | Sign-in lockout | `meshbay_hub/login_throttle.py`, settings in `hub_settings.py` (`login.*`) | §7.7. **Every path that checks a passphrase calls `_take_login_attempt` first** — login, passphrase change, account deletion | | What answers without an account | `tests/test_unauthenticated_surface.py` — `PUBLIC` | §7.4. A new open route fails the suite until it is listed there with its reason | | Asset versioning | `meshbay_hub/api/webapp.py` — `_asset_version()` | the whole module graph is served under `/a/<hash>/`, and the hash covers **every file under `static/`**, subdirectories included — nothing to register | @@ -999,6 +1001,8 @@ here are kept only where they are a rule about *editing* the code. | Flow-control worst case | `packages/meshbay-hub/tests/harness/window_leak.mjs` | | Session renewal against a hub that enforces rotation | `packages/meshbay-hub/tests/harness/session_harness.mjs` | | An invitation link opened in the real app, signed out and in | `packages/meshbay-hub/tests/harness/invite_link_probe.py` | +| An invitation answered on the home page (accept, decline), in both engines | `packages/meshbay-hub/tests/harness/invitation_probe.py` | +| A group owner's invited list and host approvals, in both engines | `packages/meshbay-hub/tests/harness/group_hosts_probe.py` | | A show's modal and the player, walked episode to episode | `packages/meshbay-hub/tests/harness/video_series_probe.py` | | A lazily loaded view whose module answers 404 (a tab older than the deploy) | `packages/meshbay-hub/tests/harness/lazy_failure_probe.py` | |