From 215864bf655f7dcb793e80c836598655d6d945a9 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 28 Sep 2026 22:39:05 +0200 Subject: docs: keypair_bundle_delete is reserved for device_policy (O3) The node honours it and no interface sends it; offered alone it would strand the next browser that signs in. Stated in both documents. Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_DESIGN.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'docs/MESHBAY_DESIGN.md') diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index f152883..c37e43b 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -618,7 +618,8 @@ control. It closes for a native device unconditionally, because that device's ke is in no bundle anywhere. It closes for an *account* only when no browser needs a bundle on that node — which needs `device_policy {allow_bundle: false}`, **signed by a pinned key** so the decision is the user's and never the hub's (open item -O3). +O3). Withdrawing a bundle already exists on the wire (`keypair_bundle_delete`) and +is not offered in the interface: it belongs with that decision, not before it. --- -- cgit v1.2.3