diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/auth.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/auth.py | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/auth.py b/packages/meshbay-hub/src/meshbay_hub/auth.py index 1d09581..41fb159 100644 --- a/packages/meshbay-hub/src/meshbay_hub/auth.py +++ b/packages/meshbay-hub/src/meshbay_hub/auth.py @@ -241,7 +241,8 @@ def issue_access_token( def issue_mnp_token(user_id: str, groups: list[str] | None = None, - node_pk: str | None = None, ttl: int = 900) -> str: + node_pk: str | None = None, ttl: int = 900, + username: str = "") -> str: """Issue the short-lived token a member presents to a node in the handshake. `aud=MNP_AUD`, so it is accepted by `authorize_token` and refused by the hub @@ -254,6 +255,11 @@ def issue_mnp_token(user_id: str, groups: list[str] | None = None, cannot be replayed to another node the member also belongs to — the node checks it in `authorize_token` (E10). The client knows the target node's key before it connects and asks for a token bound to it. + + `username` is the account's name, so the node can show a person by name in + its audit log and roster. Admission by link, by device or into an open group + carries no name of its own; without this the node knew those members only + by id. It is a label, never authority: the node decides on `sub`. """ if _hub_sk_pem is None: raise RuntimeError("Hub keypair not loaded") @@ -261,6 +267,7 @@ def issue_mnp_token(user_id: str, groups: list[str] | None = None, payload = { "iss": _hub_id, "sub": user_id, + "username": username, "jti": str(uuid.uuid4()), "iat": now, "exp": now + ttl, |