diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/db')
6 files changed, 273 insertions, 16 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py new file mode 100644 index 0000000..b47fca0 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py @@ -0,0 +1,49 @@ +"""an owner's addition is an invitation; hosts are designated by the owner + +Adding somebody to a group no longer makes them a member until they accept, and +a node may host a group only if its account owns it or the owner approved it. + +Revision ID: a1b2c3d4e5f7 +Revises: f7a8b9c0d1e2 +""" + +from collections.abc import Sequence + +import sqlalchemy as sa +from alembic import op + +revision: str = "a1b2c3d4e5f7" +down_revision: str | Sequence[str] | None = "f7a8b9c0d1e2" +branch_labels: str | Sequence[str] | None = None +depends_on: str | Sequence[str] | None = None + + +def upgrade() -> None: + op.create_table( + "group_invitations", + sa.Column("group_id", sa.String(36), sa.ForeignKey("groups.id"), nullable=False), + sa.Column("user_id", sa.String(36), sa.ForeignKey("users.id"), nullable=False), + sa.Column("invited_by", sa.String(36), sa.ForeignKey("users.id"), nullable=True), + sa.Column("created_at", sa.DateTime(timezone=True), nullable=False, + server_default=sa.func.now()), + sa.PrimaryKeyConstraint("group_id", "user_id"), + ) + op.create_index("ix_group_invitations_user", "group_invitations", ["user_id"]) + op.create_table( + "group_hosts", + sa.Column("group_id", sa.String(36), sa.ForeignKey("groups.id"), nullable=False), + sa.Column("node_id", sa.String(36), sa.ForeignKey("nodes.id"), nullable=False), + sa.Column("status", sa.String(16), nullable=False, server_default="pending"), + sa.Column("requested_at", sa.DateTime(timezone=True), nullable=False, + server_default=sa.func.now()), + sa.Column("decided_at", sa.DateTime(timezone=True), nullable=True), + sa.PrimaryKeyConstraint("group_id", "node_id"), + ) + op.create_index("ix_group_hosts_node", "group_hosts", ["node_id"]) + + +def downgrade() -> None: + op.drop_index("ix_group_hosts_node", table_name="group_hosts") + op.drop_table("group_hosts") + op.drop_index("ix_group_invitations_user", table_name="group_invitations") + op.drop_table("group_invitations") diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py new file mode 100644 index 0000000..57de9b2 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py @@ -0,0 +1,29 @@ +"""the admin allow-list grants an account, not whoever holds the name + +Revision ID: b2c3d4e5f6a8 +Revises: a1b2c3d4e5f7 +""" + +from collections.abc import Sequence + +import sqlalchemy as sa +from alembic import op + +revision: str = "b2c3d4e5f6a8" +down_revision: str | Sequence[str] | None = "a1b2c3d4e5f7" +branch_labels: str | Sequence[str] | None = None +depends_on: str | Sequence[str] | None = None + + +def upgrade() -> None: + op.create_table( + "admin_pins", + sa.Column("username", sa.String(64), primary_key=True), + sa.Column("user_id", sa.String(36), nullable=False), + sa.Column("pinned_at", sa.DateTime(timezone=True), nullable=False, + server_default=sa.func.now()), + ) + + +def downgrade() -> None: + op.drop_table("admin_pins") diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py new file mode 100644 index 0000000..dbf1718 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py @@ -0,0 +1,28 @@ +"""a bundle pepper per account, so a node cannot test passphrase guesses + +Revision ID: c3d4e5f6a7b9 +Revises: b2c3d4e5f6a8 +""" + +from collections.abc import Sequence + +import sqlalchemy as sa +from alembic import op + +revision: str = "c3d4e5f6a7b9" +down_revision: str | Sequence[str] | None = "b2c3d4e5f6a8" +branch_labels: str | Sequence[str] | None = None +depends_on: str | Sequence[str] | None = None + + +def upgrade() -> None: + with op.batch_alter_table("users") as batch: + batch.add_column(sa.Column("bundle_pepper", sa.String(128), nullable=True)) + batch.add_column(sa.Column("bundle_pepper_version", sa.Integer(), nullable=False, + server_default="1")) + + +def downgrade() -> None: + with op.batch_alter_table("users") as batch: + batch.drop_column("bundle_pepper_version") + batch.drop_column("bundle_pepper") diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py new file mode 100644 index 0000000..0e61390 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py @@ -0,0 +1,38 @@ +"""drop the public-content swarm table + +Nodes registered the hashes of their public groups here and nothing ever read +them back: the swarm was written and never used. + +Revision ID: e6f7a8b9c0d1 +Revises: c4d5e6f7a8b9 +""" + +from collections.abc import Sequence + +import sqlalchemy as sa +from alembic import op + +revision: str = "e6f7a8b9c0d1" +down_revision: str | Sequence[str] | None = "c4d5e6f7a8b9" +branch_labels: str | Sequence[str] | None = None +depends_on: str | Sequence[str] | None = None + + +def upgrade() -> None: + op.drop_index("ix_swarm_hash", table_name="swarm_sources") + op.drop_table("swarm_sources") + + +def downgrade() -> None: + op.create_table( + "swarm_sources", + sa.Column("content_hash", sa.String(64), nullable=False), + sa.Column("node_id", sa.String(36), nullable=False), + sa.Column("endpoint", sa.String(128), nullable=False), + sa.Column("registered_at", sa.DateTime(timezone=True), nullable=False, + server_default=sa.func.now()), + sa.Column("last_seen", sa.DateTime(timezone=True), nullable=False, + server_default=sa.func.now()), + sa.PrimaryKeyConstraint("content_hash", "node_id"), + ) + op.create_index("ix_swarm_hash", "swarm_sources", ["content_hash"]) diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py new file mode 100644 index 0000000..18466b8 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py @@ -0,0 +1,35 @@ +"""content reports wait for an administrator + +A hash reported by enough distinct accounts is queued for review instead of +being blocked on the spot, unless the instance chose automatic blocking. + +Revision ID: f7a8b9c0d1e2 +Revises: e6f7a8b9c0d1 +""" + +from collections.abc import Sequence + +import sqlalchemy as sa +from alembic import op + +revision: str = "f7a8b9c0d1e2" +down_revision: str | Sequence[str] | None = "e6f7a8b9c0d1" +branch_labels: str | Sequence[str] | None = None +depends_on: str | Sequence[str] | None = None + + +def upgrade() -> None: + op.create_table( + "content_reviews", + sa.Column("content_hash", sa.String(64), nullable=False), + sa.Column("status", sa.String(16), nullable=False), + sa.Column("opened_at", sa.DateTime(timezone=True), nullable=False, + server_default=sa.func.now()), + sa.Column("decided_at", sa.DateTime(timezone=True), nullable=True), + sa.Column("decided_by", sa.String(64), nullable=True), + sa.PrimaryKeyConstraint("content_hash"), + ) + + +def downgrade() -> None: + op.drop_table("content_reviews") diff --git a/packages/meshbay-hub/src/meshbay_hub/db/models.py b/packages/meshbay-hub/src/meshbay_hub/db/models.py index 09eb437..1e652a6 100644 --- a/packages/meshbay-hub/src/meshbay_hub/db/models.py +++ b/packages/meshbay-hub/src/meshbay_hub/db/models.py @@ -60,6 +60,14 @@ class User(Base): # active|suspended|revoked status: Mapped[str] = mapped_column(String(16), default="active") created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) + # The second half of what opens this account's keypair bundles on nodes + # (`auth.seal_pepper`, sealed at rest). A bundle is sealed under a key derived + # from the passphrase *and* this, so an operator holding one cannot test + # passphrase guesses offline: the pepper is handed only to a session that + # proved the passphrase or a device key, never to a node. Created the first + # time it is asked for; the version names which pepper sealed a bundle. + bundle_pepper: Mapped[str | None] = mapped_column(String(128), nullable=True) + bundle_pepper_version: Mapped[int] = mapped_column(Integer, default=1, server_default="1") nodes: Mapped[list["Node"]] = relationship(back_populates="user") group_memberships: Mapped[list["GroupMember"]] = relationship(back_populates="user") @@ -145,6 +153,53 @@ class GroupMember(Base): user: Mapped["User"] = relationship(back_populates="group_memberships") +class GroupInvitation(Base): + """ + Somebody asked to add this account to a group, and it has not said yes. + + Separate from `GroupMember` on purpose. A membership row is what the hub + acts on — it lets an account's client dial the group's nodes, names the + group in the account's MNP tokens and lists the group in its sidebar and in + Search — and an owner could create one for any username, unasked. That made + any account able to have any other account's client connect to a node of + its choosing. So an owner's addition is an invitation until the invitee + accepts it; redeeming an invitation link, joining an open group and creating + a group are the account's own acts and still write the membership directly. + """ + __tablename__ = "group_invitations" + + group_id: Mapped[str] = mapped_column(ForeignKey("groups.id"), primary_key=True) + user_id: Mapped[str] = mapped_column(ForeignKey("users.id"), primary_key=True) + invited_by: Mapped[str | None] = mapped_column(ForeignKey("users.id")) + created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) + + __table_args__ = (Index("ix_group_invitations_user", "user_id"),) + + +class GroupHost(Base): + """ + A node the group's owner has approved as a host, refused, or not yet + answered (`approved` / `refused` / `pending`). + + A node registers for the groups it claims, and clients connect to whichever + registered node answers first. Every member holds the group key, so a + member's node passes the handshake like the real host would: the ceiling on + what a node may claim cannot be "groups its account belongs to". It is + "groups its account owns", plus the nodes listed here as `approved`. A node + that claims a group it may not host is recorded `pending`, and the owner is + told, so a legitimate second host is one click away rather than refused. + """ + __tablename__ = "group_hosts" + + group_id: Mapped[str] = mapped_column(ForeignKey("groups.id"), primary_key=True) + node_id: Mapped[str] = mapped_column(ForeignKey("nodes.id"), primary_key=True) + status: Mapped[str] = mapped_column(String(16), default="pending", nullable=False) + requested_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) + decided_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True)) + + __table_args__ = (Index("ix_group_hosts_node", "node_id"),) + + class GroupInviteLink(Base): """ The hub's half of an invitation link (docs/MESHBAY_DESIGN.md §7.3). @@ -266,22 +321,6 @@ class UserDevice(Base): __table_args__ = (Index("ix_user_devices_user", "user_id"),) -class SwarmSource(Base): - """ - Tracks which nodes can serve a given content hash (public swarm). - Hub maintains this for load-balanced public content delivery. - """ - __tablename__ = "swarm_sources" - - content_hash: Mapped[str] = mapped_column(String(64), primary_key=True) - node_id: Mapped[str] = mapped_column(String(36), primary_key=True) - endpoint: Mapped[str] = mapped_column(String(128), nullable=False) - registered_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) - last_seen: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) - - __table_args__ = (Index("ix_swarm_hash", "content_hash"),) - - class Notification(Base): __tablename__ = "notifications" @@ -341,6 +380,24 @@ class ContentBlocklist(Base): added_by: Mapped[str | None] = mapped_column(String(64)) # "auto" or admin username +class ContentReview(Base): + """ + A reported hash waiting for — or given — an administrator's decision. + + Opened when enough distinct accounts have reported it; `status` is + `pending`, then `blocked` or `dismissed`. A dismissed hash stays dismissed: + more reports of it do not reopen it, and an administrator can still block + it from the blocklist. The reports themselves stay in `content_reports`. + """ + __tablename__ = "content_reviews" + + content_hash: Mapped[str] = mapped_column(String(64), primary_key=True) + status: Mapped[str] = mapped_column(String(16), default="pending") + opened_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) + decided_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True)) + decided_by: Mapped[str | None] = mapped_column(String(64)) + + class UserPreference(Base): __tablename__ = "user_preferences" @@ -388,6 +445,27 @@ class LoginThrottle(Base): last_failure_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), nullable=False) +class AdminPin(Base): + """ + Which account an allow-listed admin name (`hub.toml` `admin_usernames`) + belongs to, recorded the first time an active account holds it. + + The allow-list names people by username, and a username is not an identity: + deleting an account releases its name, and whoever registered it next + inherited the admin role. The allow-list now grants the pinned + account, so a name that changes hands grants nothing. No foreign key, on + purpose: the pin has to outlive the account it points at, or the name would + be free to pin again. A name removed from the allow-list loses its pin at + the next start, which is how an operator hands a listed name to a new + account. + """ + __tablename__ = "admin_pins" + + username: Mapped[str] = mapped_column(String(64), primary_key=True) + user_id: Mapped[str] = mapped_column(String(36), nullable=False) + pinned_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now) + + class HubSetting(Base): """ Instance-wide settings an admin changes at runtime from the panel. |