summaryrefslogtreecommitdiffstats
path: root/tmp-decisions.md
diff options
context:
space:
mode:
Diffstat (limited to 'tmp-decisions.md')
-rw-r--r--tmp-decisions.md48
1 files changed, 33 insertions, 15 deletions
diff --git a/tmp-decisions.md b/tmp-decisions.md
index 97a27ea..347d771 100644
--- a/tmp-decisions.md
+++ b/tmp-decisions.md
@@ -1,7 +1,8 @@
-# Open decisions — client architecture
+# Client architecture — decisions
-> Working note, not a spec. Created 2026-08-13 after the second security review.
-> Delete or fold into `docs/meshbay-draft-v5.md` once decided.
+> Created 2026-08-13 after the second security review. D1/D2/D3 decided the same day;
+> D4 (hub minimization) deferred. Fold into `docs/meshbay-draft-v5.md`.
+> The analysis below is kept as the rationale behind the decisions, not as open questions.
---
@@ -9,18 +10,35 @@
| # | Decision | State |
|---|---|---|
-| D1 | Does the hub keep serving the web UI? | **Open** — leaning yes |
-| D2 | Browser extension, native desktop client, or both? | **Open** — needs time |
+| D1 | Does the hub keep serving the web UI? | ✅ **DECIDED 2026-08-13 — yes** |
+| D2 | Browser extension, native desktop client, or both? | ✅ **DECIDED 2026-08-13 — native client, offered alongside the hub-served SPA** |
| D3 | Transport: aiortc primary, QUIC at parity, TCP+HTTP removed | ✅ Decided 2026-08-13 |
+| D4 | Hub minimization (old Phase 12) | ⏸️ **Deferred, may be dropped** |
-**Neither D1 nor D2 blocks anything right now.** Phase 11.5 (security remediation),
-Phase 12 (hub minimization), Phase 14 (node CLI) and Phase 15 (Sender Keys) are entirely
-client-agnostic — every finding they close is node-side or hub-side. Phase 11.5 is in
-progress on that basis.
+**What was decided.** The hub keeps serving the web UI — that is the zero-install path
+and it stays. A native desktop client is offered *in addition*, not as a replacement.
+Hub minimization is off the critical path and may be dropped entirely.
----
+**What that means, stated once and then respected.** Keeping the hub in the trusted path
+is a legitimate product call, and this project is not obliged to defend against its own
+operator. But two consequences should be carried deliberately rather than by accident:
+
+1. **T3 is accepted permanently for browser users.** A hub that serves the code can
+ exfiltrate keys from the page regardless of what the protocol does. The native client
+ gives users who care an alternative; browser users are trusting meshbay.org, and the
+ docs should say so plainly rather than claiming end-to-end integrity.
+2. **H3 was the last open High finding and its only fix lived in the dropped phase.**
+ The hub is the public key directory: substituting a key during an invite hands it the
+ group key, silently, with no forgery and no code injection. So key transparency and
+ safety numbers were kept and are now Phase 12.1 — everything else from hub
+ minimization is dropped. If Phase 12 is later dropped too, H3 stays open by choice,
+ and "unreadable by other parties, even the hub" stops being a claim the project can
+ make about an adversarial hub.
+
+The honest framing that survives all of this: **the hub cannot read your content unless
+it actively attacks you.** That is still a strong property, and it is defensible.
-## Why these are open
+## Rationale — why the native client is not a T3 fix
The second review recommended a native client and claimed *"T3 disappears — code integrity
stops depending on the hub."* **That claim was wrong and has been corrected** in
@@ -52,12 +70,12 @@ It should not be justified as the fix for T3 unless 18.7 ships with it.
---
-## D1 — Should the hub keep serving the UI?
+## D1 rationale — hub keeps serving the UI ✅
Keeping it is defensible. It is how anyone tries the platform without installing anything,
and it stays the fallback when a device has no client installed.
-What must be true if it stays (all already scheduled in Phase 12.6):
+What must be true now that it stays (Phase 12.2/12.3):
- strict CSP and Subresource Integrity on the bundle
- the hub publishes a **signed digest** of the served bundle, so any third party — an
@@ -69,7 +87,7 @@ The honest framing: hub-served SPA is a **convenience tier**, not the secure tie
---
-## D2 — Extension vs native: what each actually covers
+## D2 rationale — native chosen; extension not taken up
Three shapes, cheapest first:
@@ -85,7 +103,7 @@ hub operator does not control**. Manifest V3 forbids remote code, which works in
the structure enforces exactly what we want. Keys live in extension storage, isolated from
page JS. Moderate effort.
-**Option C — Native desktop client (pywebview + aiortc)**
+**Option C — Native desktop client (pywebview + aiortc)** ← **CHOSEN**
Phase 13. Full control, durable keys in an OS keystore, QUIC, hub-less access, best UX.
Highest effort, and the security argument depends on 18.7.