diff options
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 14 |
1 files changed, 7 insertions, 7 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 07aef05..85e436b 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -128,8 +128,9 @@ else about content. This is decision **E9**, and it is the rule any new feature is measured against. A feature that wants a row on the hub about a group's content is a feature that has misunderstood the model. It has been re-verified at each content-model change: -`SwarmSource` carries a content hash, a node id and an endpoint — **no paths, no -filenames** — and private groups register nothing at all (**H7**). +**no node registers a content hash with the hub**, for any group (**H7**); the only +hashes the hub holds are those of public content somebody reported (§7.5) — **no +paths, no filenames**. --- @@ -520,8 +521,7 @@ group key.** That is a property of open joining, not a defect of this design. Content in such a group is protected from the network and from non-members, and from nobody else. -Note the axis. **`visibility`** (public/private) controls discoverability and swarm -hash registration (**H7**). **`join_policy`** (open/request/invite) controls +Note the axis. **`visibility`** (public/private) controls discoverability. **`join_policy`** (open/request/invite) controls admission. Only the second decides whether a code is required: a public group with `join_policy = "invite"` keeps the code, because being findable is not being open. @@ -2027,7 +2027,7 @@ radius is proof of the passphrase. An admin can delete one too. The row is **tombstoned rather than dropped**: username released, email and password hash cleared, node linking key dropped, memberships, notifications, refresh tokens, -node registrations, device keys and public-swarm sources removed, active tokens +node registrations and device keys removed, active tokens refused at once by a status check rather than left to expire. Device keys go because the desktop client keeps its half: left on the tombstone, the key would refuse that installation to the next account created from it. @@ -3143,7 +3143,7 @@ be understood, not so the incident can be retold. | **H4** | Revocation reaches nodes, drops live sessions, and **persists across a restart** (§7.5) | | **H5** | An admin challenge is a **structured, domain-separated transcript naming the operation and subject**, and the client refuses to sign anything that is not what the user asked for (§5.4) | | **H6** | Unauthenticated work a node will do is bounded: a small pre-handshake buffer, a transcode semaphore, per-user pending-offer caps, and a membership check on signaling (§7.2) | -| **H7** | **Only public groups register content hashes with the hub.** Private groups register nothing, and the swarm route requires authentication | +| **H7** | **No node registers a content hash with the hub**, for any group. The only content hashes it holds are of public content somebody reported (§7.5) | **Medium** @@ -3252,7 +3252,7 @@ had already been asked. | **AV1** | **An empty claim is a claim on nothing.** A node's group set is `authorized ∩ claimed`, and an absent or empty `group_ids` registers it for no group rather than all of its owner's — on registration and on `update_groups` alike (§7.2) | | **AV2** | **A client treats the hub's node list as candidates, not a ranking**, and tries the next one on a `not_hosted` refusal (`MESHBAY_NODE_PROTOCOL.md` §6.3) | | **AV3** | **A node speaks only for the groups it is registered for.** `chat_notify` names a group and is checked against that node's set before a notification is written for anyone, and it is rate-limited per node — the fan-out is one write per member | -| **AV4** | **Nobody names a third party's address.** A swarm source publishes a transport and a port, never a host; where a peer is comes from its node record, stamped with the address its announce arrived from. The number of hashes one account may claim is bounded | +| **AV4** | **Nobody names a third party's address.** Where a peer is comes from its node record, stamped with the address its announce arrived from | | **AV5** | **An answer is accepted only from the node the offer was sent to.** A `peer_id` is bound to its node, so no connected node can resolve another's pending offer | | **AV6** | **A relay proves possession of its approved key.** A public key is not a password, and the register call is unauthenticated by design — it is not a user — so the proof is the only thing standing between a stranger and where nodes send relayed traffic | | **AV7** | **A node bounds how many peers it holds and how long an unproven one lasts.** The hub's cap is per calling account, which is a limit on each member and not on the machine, so without this an operator's exposure grew with the size of their groups | |