diff options
Diffstat (limited to 'docs/meshbay-draft-v6.md')
| -rw-r--r-- | docs/meshbay-draft-v6.md | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/docs/meshbay-draft-v6.md b/docs/meshbay-draft-v6.md index 6a161cd..2ea73c4 100644 --- a/docs/meshbay-draft-v6.md +++ b/docs/meshbay-draft-v6.md @@ -42,6 +42,7 @@ | 6 | Portability | exFAT/NTFS and Windows are the **common** case. Case folding and Unicode normalization become correctness requirements, not compatibility notes | E8 / decision 12 | | 7 | Accounts | Native registration is **hybrid**: passphrase-derived `auth_key` (the recovery path) plus a device Ed25519 key for day-to-day authentication | E3 / decision 4 | | 8 | Authorship | Chat senders are **cryptographically authenticated to each other**; an upload has a **provable owner** who may delete it, as the operator may. v5's node-asserted attribution is replaced | operator decision, §2.4b | +| 9 | Node authority | The operator may **close uploading to everyone but themselves**, per group. Signed MNP op, stored on the node, enforced by the node — the hidden button is a courtesy, the refusal is the control | §2.1b | --- @@ -67,6 +68,39 @@ v5's rule that nothing derived is written beside the originals is **unchanged**, decides the video-thumbnail question: a frame grab is produced on demand and cached on the device that asked, so the node keeps no thumbnail store. +### 2.1b §5.2 Uploads — the operator may close them + +New. A group where every member may add files is the default and stays the default; +some groups want a library the operator curates, and until now the only way to get one +was to designate no upload root at all, which refuses the operator too. + +`member_upload` is a per-group setting, and three things about it are load-bearing: + +- **It lives on the node**, in `roster.db`, not in `node.toml` and not on the hub. Not + the hub because a hub that decides who may write to someone else's disk has authority + over that node, which is the arrangement this design exists to avoid (change 5). Not + `node.toml` because that file is hand-written, full of comments recording decisions, + and `ops.py` deliberately appends to it rather than round-tripping it through a + writer — a setting changed from a panel must not rewrite the operator's file, and must + not need a restart. +- **Changing it is a signed operator instruction** (`OP_MEMBER_UPLOAD`, MNP + `member_upload`), on the same path as removing a member. An unsigned one would let any + member turn it back on, which makes the control a suggestion. The transcript's subject + is `on` or `off` — what the operator is shown before signing has to name the outcome, + not the operation. +- **The node enforces it**; the interface merely stops offering it. `handshake_ack` + carries `member_upload` so a client knows whether to draw the Upload button and the + chat paperclip, and the node broadcasts `member_upload_ack` to everyone connected when + it changes. None of that is the control: a member on an old tab, or one speaking MNP + directly, is refused by the node with `member_upload_off`. + +**Absent means allowed**, at every layer — no row in `group_settings`, no key in the +group context, no field in the ack. A node or client that predates the setting behaves +exactly as it did, and an upgrade never silently closes a group. + +The operator is always exempt. Turning it off otherwise locks them out of their own +node, with a config file and a restart as the only way back. + ### 2.2 §5.5 Admission — devices, not one key per person v5 and `invite-pairing-v1.md` bind **one** key pair to an account per node: `identities` |