aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-client/src/transcripts.js
Commit message (Collapse)AuthorAgeFilesLines
* fix: an identity signs a named kind, and a device approval answers a requestChristophe Besson20 hours1-0/+159
The desktop main process builds every transcript itself from fields (transcripts.js) and signs no raw bytes; the page's identity has the same contract (crypto.js transcriptFor). The keyring seals no bundle while browser access is off. On the node, device_add must redeem a pending request filed by the same keys, and device_revoke is signed under its own prefix (meshbay:device_revoke:v1), so a retirement signature admits nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>