aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md8
1 files changed, 8 insertions, 0 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 78a3261..d2bec10 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -1046,6 +1046,14 @@ requester and it therefore grants nothing across accounts.
- The denylist is consulted for user, `jti` **and** group.
- The node **refuses connections when it holds no group key** — there is no
`gek_required: false` bypass (**NS8**).
+- **The roster must admit the account for the group** before a session opens,
+ after the proof and whatever the token says (`not_authorized_for_group`). The
+ key proves possession, the token proves the hub's view of membership, and
+ neither is the node's own answer: without this, a member revoked or unpinned
+ here but still on the hub kept a full session with the key they held, and was
+ handed the chat epoch their removal had just opened. A removal, from any door
+ (MNP, the node page, the CLI), also opens a new chat epoch in each group the
+ person could read and closes every connection they hold.
**Refusals carry a code**, not only a sentence, because a client can act on a code.
`not_a_member` means the hub did not count the account a member when it minted the