aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_NODE_PROTOCOL.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/MESHBAY_NODE_PROTOCOL.md')
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md6
1 files changed, 4 insertions, 2 deletions
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 2e5aca3..70047b2 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -489,8 +489,10 @@ would let whoever issues tokens decide it instead. Identity keys are pinned by t
node's roster. The hub certifies accounts, not keys.
`not_a_member` means the hub did not count this account a member of the group when it
-minted the token. The MNP token is minted for each connection, from the membership the
-hub holds at that moment, so a stale `groups` claim is no longer the usual cause; the
+minted the token. The MNP token is minted for each connection and names **only** that
+connection's group (`POST /v1/nodes/mnp-token {node_pk, group_id}`; `groups` is empty
+for a non-member), so the operator it is handed to learns nothing of the member's
+other groups. A stale `groups` claim is therefore no longer the usual cause; the
client still refreshes its session once and retries on that code before telling someone
who was just invited that they are not a member.