aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-android/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-android/README.md')
-rw-r--r--packages/meshbay-android/README.md10
1 files changed, 7 insertions, 3 deletions
diff --git a/packages/meshbay-android/README.md b/packages/meshbay-android/README.md
index 8c357fe..b5ee534 100644
--- a/packages/meshbay-android/README.md
+++ b/packages/meshbay-android/README.md
@@ -7,7 +7,11 @@ The shell is a system WebView showing the interface **from the package** —
`build/generated/`, never committed (§8.3) — with a bridge
(`app/src/main/assets/bridge/meshbay-bridge.js`) that offers the page the same
`window.meshbay` as the desktop preload, wherever it offers anything at all.
-Hub calls leave from native code, to the signed-in hub only.
+Hub calls leave from native code, to the signed-in hub only. The device key,
+the bundle key and every node identity are held natively under an Android
+Keystore key; the page is told public keys and handed signatures, asked for by
+kind — never bytes. `meshbay-hub/tests/vectors/keyring.json` holds that keyring
+to the desktop's and to the specification.
```bash
# needs JDK 17+ and an Android SDK (ANDROID_HOME, or sdk.dir in local.properties)
@@ -18,5 +22,5 @@ Hub calls leave from native code, to the signed-in hub only.
The security contract is also pinned from the Python suite by reading this
source: `packages/meshbay-hub/tests/test_android_shell.py`.
-Not built yet: native keys, downloads to disk, casting, phone-specific
-behaviour (back button, network handover), signed releases.
+Not built yet: downloads to disk, casting, phone-specific behaviour (back
+button, network handover), signed releases.