diff options
Diffstat (limited to 'docs/MESHBAY_NODE_PROTOCOL.md')
| -rw-r--r-- | docs/MESHBAY_NODE_PROTOCOL.md | 12 |
1 files changed, 7 insertions, 5 deletions
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md index 676b96f..e7fce90 100644 --- a/docs/MESHBAY_NODE_PROTOCOL.md +++ b/docs/MESHBAY_NODE_PROTOCOL.md @@ -685,11 +685,13 @@ the node that proved it, for the account that stored it. (`keyderive.js` in a browser, `keyring.js` in the desktop application's main process), and optionally a second copy under the account recovery key. The node stores bytes and serves them back to the same `user_id`. -* **A client reads `MBK3` and nothing else.** A bundle in an earlier format was - sealed under the passphrase alone; the client refuses it by name - (`bundle_format_retired`) and does not mint a replacement identity, which would - leave the node pinning a key nobody holds. `member unpin` drops the bundle, and - the next join is a first contact. +* **A client writes `MBK3` and nothing else.** It reads one earlier format once, + to replace it (*transitional*): `MBK2`, `"MBK2" ‖ nonce (12) ‖ AES-GCM` under the + passphrase's Argon2 key, no associated data. The identity in it is stored again + as `MBK3` with `keypair_bundle_store` once the session is up. Anything older is + refused by name (`bundle_format_retired`), and the client does not mint a + replacement identity, which would leave the node pinning a key nobody holds; + `member unpin` drops the bundle, and the next join is a first contact. * `keypair_bundle_store` is accepted **after** authentication (it is not in the pre-proof list); the fetch is what happens before. * A `store` omitting `bundle_enc_recovery` leaves any existing recovery copy in place. |