aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_NODE_PROTOCOL.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/MESHBAY_NODE_PROTOCOL.md')
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md7
1 files changed, 5 insertions, 2 deletions
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 0b5213c..0045f78 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -489,8 +489,11 @@ absent. `verify_proof` compares with `hmac.compare_digest`.
| *(after the proof)* the roster admits `sub` for `group_id` — an active member row, or the node-wide operator row | `This node has not admitted you to this group`, code `not_authorized_for_group` | the key proves possession and the token the hub's view; the node's own answer is the roster. Someone revoked here but still a hub member, holding the key, is refused a session |
`AuthorizedPeer` carries `user_id`, `group_id`, `username`, `jti` — and deliberately
-**no user public key**. `username` is read from a `username` claim that neither the MNP
-token nor the hub session token carries, so it is empty in practice. A key arriving in a token would be a key the hub chose, and the
+**no user public key**. `username` is the MNP token's `username` claim, the account's
+hub name (cut to 64 characters). It is a label, never authority: after the handshake the
+node writes it into the roster for an account whose pinned name is empty — admission
+by link, by device or into an open group carries no name — and an invitation's name is
+never overwritten. A key arriving in a token would be a key the hub chose, and the
node records the uploader's key in order to decide who may later delete a file: that
would let whoever issues tokens decide it instead. Identity keys are pinned by the
node's roster. The hub certifies accounts, not keys.