diff options
Diffstat (limited to 'packages/meshbay-common/src/meshbay_common/adminop.py')
| -rw-r--r-- | packages/meshbay-common/src/meshbay_common/adminop.py | 24 |
1 files changed, 7 insertions, 17 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/adminop.py b/packages/meshbay-common/src/meshbay_common/adminop.py index b8915a9..bd7a439 100644 --- a/packages/meshbay-common/src/meshbay_common/adminop.py +++ b/packages/meshbay-common/src/meshbay_common/adminop.py @@ -47,14 +47,6 @@ OP_INVITE_LINK_CREATE = "invite_link_create" # Taking back an unredeemed link, by the handle it was issued with. OP_INVITE_CANCEL = "invite_cancel" OP_MEMBER_REVOKE = "member_revoke" -# Rotating the group key is what actually takes it away from a revoked member: -# revocation stops the node serving the *next* key, and they still hold the -# current one. The node generates the new key itself with its own CSPRNG, so -# nothing arriving over MNP contributes key material — the C5b rule is about -# key material from outside, not about the instruction. -OP_GEK_ROTATE = "gek_rotate" -# Forgetting a pinned identity, so someone can pair again after losing a device. -OP_MEMBER_UNPIN = "member_unpin" # Which group "applications" (Chat, Files, and whatever registers later) are # shown to members. Signed like the rest: it decides what a member sees, not # anything about key material, but an unsigned toggle would let any member @@ -67,11 +59,6 @@ OP_APPS_ENABLED = "apps_enabled" # security property in itself, but the pattern (every operator setting is # signed) is what keeps the authorization model simple to reason about. OP_SET_SCAN_SETTINGS = "set_scan_settings" -# How many transfers one member may run at once in this group. Signed like the -# rest: an unsigned cap is one any member can raise for themselves, which makes -# the control a suggestion. The subject is "d=2,u=2" so what the operator is -# shown before signing names the outcome and not the operation. -OP_TRANSFER_LIMITS = "transfer_limits" # Whether the node uses the operator's own API token/language instead of the # shipped default — node-wide (docs/MESHBAY_DESIGN.md §9.7), one credential # shared by every group. Signed like the rest: it turns on outbound @@ -114,16 +101,19 @@ OP_CHAT_LINK_PREVIEW = "chat_link_preview" # operator's, signed like the other per-group switches. OP_SEARCH_LISTED = "search_listed" # Open a new chat epoch for a group, by hand. The removals that matter open one -# by themselves (member revoke/unpin, device revoke, gek_rotate); this is the -# operator saying "do it anyway", which is the same shape as `gek_rotate` and -# signed for the same reason. +# by themselves (member revoke/unpin, device revoke, group key rotation); this is the +# operator saying "do it anyway", and is signed like the rest. # # There is no op for *enabling* chat encryption. It is not a setting — MNP 2.0 # has no plaintext chat to fall back to. OP_CHAT_EPOCH = "chat_epoch" OP_ROOT_EJECT = "root_eject" OP_ROOT_PLUG = "root_plug" -OP_GROUP_DETACH = "group_detach" +# Also gone with 6.0, because no client ever sent them: `gek_rotate`, +# `member_unpin`, `transfer_limits` and `group_detach`. Rotating the group key, +# forgetting an identity, the per-member transfer caps and no longer hosting a +# group are done on the node's machine — the desktop application's Node page +# or the CLI. A door nobody uses is an untested way in. # OP_ROOT_ADD, OP_ROOT_UPDATE and OP_GROUP_ATTACH are gone (MNP 6.0). Each one # chose what of the operator's disk is shared and who may write there, and a # signature proves only that the operator's key signed — in a browser, through |