diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/db/models.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/db/models.py | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/models.py b/packages/meshbay-hub/src/meshbay_hub/db/models.py index 293b940..1e652a6 100644 --- a/packages/meshbay-hub/src/meshbay_hub/db/models.py +++ b/packages/meshbay-hub/src/meshbay_hub/db/models.py @@ -60,6 +60,14 @@ class User(Base): # active|suspended|revoked status: Mapped[str] = mapped_column(String(16), default="active") created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) + # The second half of what opens this account's keypair bundles on nodes + # (`auth.seal_pepper`, sealed at rest). A bundle is sealed under a key derived + # from the passphrase *and* this, so an operator holding one cannot test + # passphrase guesses offline: the pepper is handed only to a session that + # proved the passphrase or a device key, never to a node. Created the first + # time it is asked for; the version names which pepper sealed a bundle. + bundle_pepper: Mapped[str | None] = mapped_column(String(128), nullable=True) + bundle_pepper_version: Mapped[int] = mapped_column(Integer, default=1, server_default="1") nodes: Mapped[list["Node"]] = relationship(back_populates="user") group_memberships: Mapped[list["GroupMember"]] = relationship(back_populates="user") |