aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/db
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/db')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py49
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py29
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py28
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py38
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py35
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/models.py110
6 files changed, 273 insertions, 16 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py
new file mode 100644
index 0000000..b47fca0
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/a1b2c3d4e5f7_invitations_and_group_hosts.py
@@ -0,0 +1,49 @@
+"""an owner's addition is an invitation; hosts are designated by the owner
+
+Adding somebody to a group no longer makes them a member until they accept, and
+a node may host a group only if its account owns it or the owner approved it.
+
+Revision ID: a1b2c3d4e5f7
+Revises: f7a8b9c0d1e2
+"""
+
+from collections.abc import Sequence
+
+import sqlalchemy as sa
+from alembic import op
+
+revision: str = "a1b2c3d4e5f7"
+down_revision: str | Sequence[str] | None = "f7a8b9c0d1e2"
+branch_labels: str | Sequence[str] | None = None
+depends_on: str | Sequence[str] | None = None
+
+
+def upgrade() -> None:
+ op.create_table(
+ "group_invitations",
+ sa.Column("group_id", sa.String(36), sa.ForeignKey("groups.id"), nullable=False),
+ sa.Column("user_id", sa.String(36), sa.ForeignKey("users.id"), nullable=False),
+ sa.Column("invited_by", sa.String(36), sa.ForeignKey("users.id"), nullable=True),
+ sa.Column("created_at", sa.DateTime(timezone=True), nullable=False,
+ server_default=sa.func.now()),
+ sa.PrimaryKeyConstraint("group_id", "user_id"),
+ )
+ op.create_index("ix_group_invitations_user", "group_invitations", ["user_id"])
+ op.create_table(
+ "group_hosts",
+ sa.Column("group_id", sa.String(36), sa.ForeignKey("groups.id"), nullable=False),
+ sa.Column("node_id", sa.String(36), sa.ForeignKey("nodes.id"), nullable=False),
+ sa.Column("status", sa.String(16), nullable=False, server_default="pending"),
+ sa.Column("requested_at", sa.DateTime(timezone=True), nullable=False,
+ server_default=sa.func.now()),
+ sa.Column("decided_at", sa.DateTime(timezone=True), nullable=True),
+ sa.PrimaryKeyConstraint("group_id", "node_id"),
+ )
+ op.create_index("ix_group_hosts_node", "group_hosts", ["node_id"])
+
+
+def downgrade() -> None:
+ op.drop_index("ix_group_hosts_node", table_name="group_hosts")
+ op.drop_table("group_hosts")
+ op.drop_index("ix_group_invitations_user", table_name="group_invitations")
+ op.drop_table("group_invitations")
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py
new file mode 100644
index 0000000..57de9b2
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/b2c3d4e5f6a8_admin_pins.py
@@ -0,0 +1,29 @@
+"""the admin allow-list grants an account, not whoever holds the name
+
+Revision ID: b2c3d4e5f6a8
+Revises: a1b2c3d4e5f7
+"""
+
+from collections.abc import Sequence
+
+import sqlalchemy as sa
+from alembic import op
+
+revision: str = "b2c3d4e5f6a8"
+down_revision: str | Sequence[str] | None = "a1b2c3d4e5f7"
+branch_labels: str | Sequence[str] | None = None
+depends_on: str | Sequence[str] | None = None
+
+
+def upgrade() -> None:
+ op.create_table(
+ "admin_pins",
+ sa.Column("username", sa.String(64), primary_key=True),
+ sa.Column("user_id", sa.String(36), nullable=False),
+ sa.Column("pinned_at", sa.DateTime(timezone=True), nullable=False,
+ server_default=sa.func.now()),
+ )
+
+
+def downgrade() -> None:
+ op.drop_table("admin_pins")
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py
new file mode 100644
index 0000000..dbf1718
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/c3d4e5f6a7b9_bundle_pepper.py
@@ -0,0 +1,28 @@
+"""a bundle pepper per account, so a node cannot test passphrase guesses
+
+Revision ID: c3d4e5f6a7b9
+Revises: b2c3d4e5f6a8
+"""
+
+from collections.abc import Sequence
+
+import sqlalchemy as sa
+from alembic import op
+
+revision: str = "c3d4e5f6a7b9"
+down_revision: str | Sequence[str] | None = "b2c3d4e5f6a8"
+branch_labels: str | Sequence[str] | None = None
+depends_on: str | Sequence[str] | None = None
+
+
+def upgrade() -> None:
+ with op.batch_alter_table("users") as batch:
+ batch.add_column(sa.Column("bundle_pepper", sa.String(128), nullable=True))
+ batch.add_column(sa.Column("bundle_pepper_version", sa.Integer(), nullable=False,
+ server_default="1"))
+
+
+def downgrade() -> None:
+ with op.batch_alter_table("users") as batch:
+ batch.drop_column("bundle_pepper_version")
+ batch.drop_column("bundle_pepper")
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py
new file mode 100644
index 0000000..0e61390
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e6f7a8b9c0d1_drop_swarm_sources.py
@@ -0,0 +1,38 @@
+"""drop the public-content swarm table
+
+Nodes registered the hashes of their public groups here and nothing ever read
+them back: the swarm was written and never used.
+
+Revision ID: e6f7a8b9c0d1
+Revises: c4d5e6f7a8b9
+"""
+
+from collections.abc import Sequence
+
+import sqlalchemy as sa
+from alembic import op
+
+revision: str = "e6f7a8b9c0d1"
+down_revision: str | Sequence[str] | None = "c4d5e6f7a8b9"
+branch_labels: str | Sequence[str] | None = None
+depends_on: str | Sequence[str] | None = None
+
+
+def upgrade() -> None:
+ op.drop_index("ix_swarm_hash", table_name="swarm_sources")
+ op.drop_table("swarm_sources")
+
+
+def downgrade() -> None:
+ op.create_table(
+ "swarm_sources",
+ sa.Column("content_hash", sa.String(64), nullable=False),
+ sa.Column("node_id", sa.String(36), nullable=False),
+ sa.Column("endpoint", sa.String(128), nullable=False),
+ sa.Column("registered_at", sa.DateTime(timezone=True), nullable=False,
+ server_default=sa.func.now()),
+ sa.Column("last_seen", sa.DateTime(timezone=True), nullable=False,
+ server_default=sa.func.now()),
+ sa.PrimaryKeyConstraint("content_hash", "node_id"),
+ )
+ op.create_index("ix_swarm_hash", "swarm_sources", ["content_hash"])
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py
new file mode 100644
index 0000000..18466b8
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/f7a8b9c0d1e2_add_content_reviews.py
@@ -0,0 +1,35 @@
+"""content reports wait for an administrator
+
+A hash reported by enough distinct accounts is queued for review instead of
+being blocked on the spot, unless the instance chose automatic blocking.
+
+Revision ID: f7a8b9c0d1e2
+Revises: e6f7a8b9c0d1
+"""
+
+from collections.abc import Sequence
+
+import sqlalchemy as sa
+from alembic import op
+
+revision: str = "f7a8b9c0d1e2"
+down_revision: str | Sequence[str] | None = "e6f7a8b9c0d1"
+branch_labels: str | Sequence[str] | None = None
+depends_on: str | Sequence[str] | None = None
+
+
+def upgrade() -> None:
+ op.create_table(
+ "content_reviews",
+ sa.Column("content_hash", sa.String(64), nullable=False),
+ sa.Column("status", sa.String(16), nullable=False),
+ sa.Column("opened_at", sa.DateTime(timezone=True), nullable=False,
+ server_default=sa.func.now()),
+ sa.Column("decided_at", sa.DateTime(timezone=True), nullable=True),
+ sa.Column("decided_by", sa.String(64), nullable=True),
+ sa.PrimaryKeyConstraint("content_hash"),
+ )
+
+
+def downgrade() -> None:
+ op.drop_table("content_reviews")
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/models.py b/packages/meshbay-hub/src/meshbay_hub/db/models.py
index 09eb437..1e652a6 100644
--- a/packages/meshbay-hub/src/meshbay_hub/db/models.py
+++ b/packages/meshbay-hub/src/meshbay_hub/db/models.py
@@ -60,6 +60,14 @@ class User(Base):
# active|suspended|revoked
status: Mapped[str] = mapped_column(String(16), default="active")
created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
+ # The second half of what opens this account's keypair bundles on nodes
+ # (`auth.seal_pepper`, sealed at rest). A bundle is sealed under a key derived
+ # from the passphrase *and* this, so an operator holding one cannot test
+ # passphrase guesses offline: the pepper is handed only to a session that
+ # proved the passphrase or a device key, never to a node. Created the first
+ # time it is asked for; the version names which pepper sealed a bundle.
+ bundle_pepper: Mapped[str | None] = mapped_column(String(128), nullable=True)
+ bundle_pepper_version: Mapped[int] = mapped_column(Integer, default=1, server_default="1")
nodes: Mapped[list["Node"]] = relationship(back_populates="user")
group_memberships: Mapped[list["GroupMember"]] = relationship(back_populates="user")
@@ -145,6 +153,53 @@ class GroupMember(Base):
user: Mapped["User"] = relationship(back_populates="group_memberships")
+class GroupInvitation(Base):
+ """
+ Somebody asked to add this account to a group, and it has not said yes.
+
+ Separate from `GroupMember` on purpose. A membership row is what the hub
+ acts on — it lets an account's client dial the group's nodes, names the
+ group in the account's MNP tokens and lists the group in its sidebar and in
+ Search — and an owner could create one for any username, unasked. That made
+ any account able to have any other account's client connect to a node of
+ its choosing. So an owner's addition is an invitation until the invitee
+ accepts it; redeeming an invitation link, joining an open group and creating
+ a group are the account's own acts and still write the membership directly.
+ """
+ __tablename__ = "group_invitations"
+
+ group_id: Mapped[str] = mapped_column(ForeignKey("groups.id"), primary_key=True)
+ user_id: Mapped[str] = mapped_column(ForeignKey("users.id"), primary_key=True)
+ invited_by: Mapped[str | None] = mapped_column(ForeignKey("users.id"))
+ created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
+
+ __table_args__ = (Index("ix_group_invitations_user", "user_id"),)
+
+
+class GroupHost(Base):
+ """
+ A node the group's owner has approved as a host, refused, or not yet
+ answered (`approved` / `refused` / `pending`).
+
+ A node registers for the groups it claims, and clients connect to whichever
+ registered node answers first. Every member holds the group key, so a
+ member's node passes the handshake like the real host would: the ceiling on
+ what a node may claim cannot be "groups its account belongs to". It is
+ "groups its account owns", plus the nodes listed here as `approved`. A node
+ that claims a group it may not host is recorded `pending`, and the owner is
+ told, so a legitimate second host is one click away rather than refused.
+ """
+ __tablename__ = "group_hosts"
+
+ group_id: Mapped[str] = mapped_column(ForeignKey("groups.id"), primary_key=True)
+ node_id: Mapped[str] = mapped_column(ForeignKey("nodes.id"), primary_key=True)
+ status: Mapped[str] = mapped_column(String(16), default="pending", nullable=False)
+ requested_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
+ decided_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True))
+
+ __table_args__ = (Index("ix_group_hosts_node", "node_id"),)
+
+
class GroupInviteLink(Base):
"""
The hub's half of an invitation link (docs/MESHBAY_DESIGN.md §7.3).
@@ -266,22 +321,6 @@ class UserDevice(Base):
__table_args__ = (Index("ix_user_devices_user", "user_id"),)
-class SwarmSource(Base):
- """
- Tracks which nodes can serve a given content hash (public swarm).
- Hub maintains this for load-balanced public content delivery.
- """
- __tablename__ = "swarm_sources"
-
- content_hash: Mapped[str] = mapped_column(String(64), primary_key=True)
- node_id: Mapped[str] = mapped_column(String(36), primary_key=True)
- endpoint: Mapped[str] = mapped_column(String(128), nullable=False)
- registered_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
- last_seen: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
-
- __table_args__ = (Index("ix_swarm_hash", "content_hash"),)
-
-
class Notification(Base):
__tablename__ = "notifications"
@@ -341,6 +380,24 @@ class ContentBlocklist(Base):
added_by: Mapped[str | None] = mapped_column(String(64)) # "auto" or admin username
+class ContentReview(Base):
+ """
+ A reported hash waiting for — or given — an administrator's decision.
+
+ Opened when enough distinct accounts have reported it; `status` is
+ `pending`, then `blocked` or `dismissed`. A dismissed hash stays dismissed:
+ more reports of it do not reopen it, and an administrator can still block
+ it from the blocklist. The reports themselves stay in `content_reports`.
+ """
+ __tablename__ = "content_reviews"
+
+ content_hash: Mapped[str] = mapped_column(String(64), primary_key=True)
+ status: Mapped[str] = mapped_column(String(16), default="pending")
+ opened_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
+ decided_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True))
+ decided_by: Mapped[str | None] = mapped_column(String(64))
+
+
class UserPreference(Base):
__tablename__ = "user_preferences"
@@ -388,6 +445,27 @@ class LoginThrottle(Base):
last_failure_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), nullable=False)
+class AdminPin(Base):
+ """
+ Which account an allow-listed admin name (`hub.toml` `admin_usernames`)
+ belongs to, recorded the first time an active account holds it.
+
+ The allow-list names people by username, and a username is not an identity:
+ deleting an account releases its name, and whoever registered it next
+ inherited the admin role. The allow-list now grants the pinned
+ account, so a name that changes hands grants nothing. No foreign key, on
+ purpose: the pin has to outlive the account it points at, or the name would
+ be free to pin again. A name removed from the allow-list loses its pin at
+ the next start, which is how an operator hands a listed name to a new
+ account.
+ """
+ __tablename__ = "admin_pins"
+
+ username: Mapped[str] = mapped_column(String(64), primary_key=True)
+ user_id: Mapped[str] = mapped_column(String(36), nullable=False)
+ pinned_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
+
+
class HubSetting(Base):
"""
Instance-wide settings an admin changes at runtime from the panel.