diff options
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 78a3261..d2bec10 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -1046,6 +1046,14 @@ requester and it therefore grants nothing across accounts. - The denylist is consulted for user, `jti` **and** group. - The node **refuses connections when it holds no group key** — there is no `gek_required: false` bypass (**NS8**). +- **The roster must admit the account for the group** before a session opens, + after the proof and whatever the token says (`not_authorized_for_group`). The + key proves possession, the token proves the hub's view of membership, and + neither is the node's own answer: without this, a member revoked or unpinned + here but still on the hub kept a full session with the key they held, and was + handed the chat epoch their removal had just opened. A removal, from any door + (MNP, the node page, the CLI), also opens a new chat epoch in each group the + person could read and closes every connection they hold. **Refusals carry a code**, not only a sentence, because a client can act on a code. `not_a_member` means the hub did not count the account a member when it minted the |