summaryrefslogtreecommitdiffstats
path: root/docs/invite-pairing-v1.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/invite-pairing-v1.md')
-rw-r--r--docs/invite-pairing-v1.md11
1 files changed, 7 insertions, 4 deletions
diff --git a/docs/invite-pairing-v1.md b/docs/invite-pairing-v1.md
index 290c756..ad36a1a 100644
--- a/docs/invite-pairing-v1.md
+++ b/docs/invite-pairing-v1.md
@@ -96,8 +96,11 @@ node writes the pin to its roster DB, prints it in `status`
The operator types 8 characters into their own browser. Nothing is pasted, nothing
is copied out of a terminal, no browser is needed on the node host, and the hub is
-not involved at any point. `admin_pk_ed25519` in `node.toml` becomes a legacy
-fallback, still read, no longer required.
+not involved at any point. `admin_pk_ed25519` in `node.toml` became a legacy
+fallback, and was removed on 2026-08-15: the roster is the only source of operator
+authority. A config that still names the key is warned about at startup, so a
+deployment relying on it learns why its invites stopped rather than discovering a
+signature error.
### 3.2 Invite (one click, operator or delegate)
@@ -357,7 +360,7 @@ is a roster row and a CLI command — no protocol change, no migration.
| Two people race one code | Single-use row, `used_at` set under a transaction; the loser gets a plain refusal |
| Invite created while the node is offline | Not possible — invites are created on the node. The SPA must say "node offline, cannot invite" instead of failing obscurely |
| Member connects while the group has no active GEK | `join_result {ok: false, reason: "no_gek"}`; the operator runs `gek-init` |
-| Legacy deployment with `admin_pk_ed25519` set | Read at startup and inserted as an `identities` row with `pinned_via = 'legacy-config'`; no migration needed for the current demo |
+| Legacy deployment with `admin_pk_ed25519` set | Ignored since 2026-08-15, with a warning at startup naming the config file. The operator pairs a browser; there is no second path |
---
@@ -393,7 +396,7 @@ coherent with each other rather than individually demo-able.
| `identities` / `members` / `invites`, codes, single-use redemption | `meshbay_node/roster.py` |
| `join_transcript` — both public keys signed together | `meshbay_common/join.py` |
| `join_request` / `join_result` handler, valid pre-proof and post-handshake | `transport/webrtc_server.py` |
-| Admin authority read from the roster on every check, `admin_pk_ed25519` kept as legacy | `webrtc_server._verify_admin_sig` |
+| Admin authority read from the roster on every check, and from nowhere else | `webrtc_server._verify_admin_sig` |
| **Auto-pin of the keystore key deleted** (M3) | `daemon._legacy_admin_pk` |
| `meshbay-node operator pair`, roster in `status` | `daemon.main`, `ui/app.py` |
| Pairing form in the group's Members tab | `app.js`, `transport.js` |