diff options
Diffstat (limited to 'tmp-decisions.md')
| -rw-r--r-- | tmp-decisions.md | 48 |
1 files changed, 33 insertions, 15 deletions
diff --git a/tmp-decisions.md b/tmp-decisions.md index 97a27ea..347d771 100644 --- a/tmp-decisions.md +++ b/tmp-decisions.md @@ -1,7 +1,8 @@ -# Open decisions — client architecture +# Client architecture — decisions -> Working note, not a spec. Created 2026-08-13 after the second security review. -> Delete or fold into `docs/meshbay-draft-v5.md` once decided. +> Created 2026-08-13 after the second security review. D1/D2/D3 decided the same day; +> D4 (hub minimization) deferred. Fold into `docs/meshbay-draft-v5.md`. +> The analysis below is kept as the rationale behind the decisions, not as open questions. --- @@ -9,18 +10,35 @@ | # | Decision | State | |---|---|---| -| D1 | Does the hub keep serving the web UI? | **Open** — leaning yes | -| D2 | Browser extension, native desktop client, or both? | **Open** — needs time | +| D1 | Does the hub keep serving the web UI? | ✅ **DECIDED 2026-08-13 — yes** | +| D2 | Browser extension, native desktop client, or both? | ✅ **DECIDED 2026-08-13 — native client, offered alongside the hub-served SPA** | | D3 | Transport: aiortc primary, QUIC at parity, TCP+HTTP removed | ✅ Decided 2026-08-13 | +| D4 | Hub minimization (old Phase 12) | ⏸️ **Deferred, may be dropped** | -**Neither D1 nor D2 blocks anything right now.** Phase 11.5 (security remediation), -Phase 12 (hub minimization), Phase 14 (node CLI) and Phase 15 (Sender Keys) are entirely -client-agnostic — every finding they close is node-side or hub-side. Phase 11.5 is in -progress on that basis. +**What was decided.** The hub keeps serving the web UI — that is the zero-install path +and it stays. A native desktop client is offered *in addition*, not as a replacement. +Hub minimization is off the critical path and may be dropped entirely. ---- +**What that means, stated once and then respected.** Keeping the hub in the trusted path +is a legitimate product call, and this project is not obliged to defend against its own +operator. But two consequences should be carried deliberately rather than by accident: + +1. **T3 is accepted permanently for browser users.** A hub that serves the code can + exfiltrate keys from the page regardless of what the protocol does. The native client + gives users who care an alternative; browser users are trusting meshbay.org, and the + docs should say so plainly rather than claiming end-to-end integrity. +2. **H3 was the last open High finding and its only fix lived in the dropped phase.** + The hub is the public key directory: substituting a key during an invite hands it the + group key, silently, with no forgery and no code injection. So key transparency and + safety numbers were kept and are now Phase 12.1 — everything else from hub + minimization is dropped. If Phase 12 is later dropped too, H3 stays open by choice, + and "unreadable by other parties, even the hub" stops being a claim the project can + make about an adversarial hub. + +The honest framing that survives all of this: **the hub cannot read your content unless +it actively attacks you.** That is still a strong property, and it is defensible. -## Why these are open +## Rationale — why the native client is not a T3 fix The second review recommended a native client and claimed *"T3 disappears — code integrity stops depending on the hub."* **That claim was wrong and has been corrected** in @@ -52,12 +70,12 @@ It should not be justified as the fix for T3 unless 18.7 ships with it. --- -## D1 — Should the hub keep serving the UI? +## D1 rationale — hub keeps serving the UI ✅ Keeping it is defensible. It is how anyone tries the platform without installing anything, and it stays the fallback when a device has no client installed. -What must be true if it stays (all already scheduled in Phase 12.6): +What must be true now that it stays (Phase 12.2/12.3): - strict CSP and Subresource Integrity on the bundle - the hub publishes a **signed digest** of the served bundle, so any third party — an @@ -69,7 +87,7 @@ The honest framing: hub-served SPA is a **convenience tier**, not the secure tie --- -## D2 — Extension vs native: what each actually covers +## D2 rationale — native chosen; extension not taken up Three shapes, cheapest first: @@ -85,7 +103,7 @@ hub operator does not control**. Manifest V3 forbids remote code, which works in the structure enforces exactly what we want. Keys live in extension storage, isolated from page JS. Moderate effort. -**Option C — Native desktop client (pywebview + aiortc)** +**Option C — Native desktop client (pywebview + aiortc)** ← **CHOSEN** Phase 13. Full control, durable keys in an OS keystore, QUIC, hub-less access, best UX. Highest effort, and the security argument depends on 18.7. |