From 2f2a9a6542d2194e50ffba6f382e4fdffd481838 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Sat, 10 Oct 2026 14:21:46 +0200 Subject: feat(android): one backup destination, a group the account owns alone Chosen once at the top of Android Sync for every kind; photos and contacts go into /-photos and -contacts. Owner and sole member are checked at set-up and before every run. Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_DESIGN.md | 46 +++++++++++++++++++++++++--------------------- 1 file changed, 25 insertions(+), 21 deletions(-) (limited to 'docs/MESHBAY_DESIGN.md') diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 052570a..8293493 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -3326,7 +3326,7 @@ are two albums. ### 9.12 Photo backup (Android) The Android application sends the photos taken on the phone to **one folder of -one group**, chosen by the member, once a day. It is a client feature over the +a group the member owns and is the only member of**, once a day. It is a client feature over the upload path that exists: a backed-up photo is a `file_upload` into a writable root under a slot the node granted, with every rule of §6.4, and its owner is recorded as for any upload. **No message, no node state and no hub state was @@ -3345,9 +3345,24 @@ object — absent, not refusing (§11.3). **Where it lives.** Its controls are on a page of their own, **Android Sync**, under a **Phone** heading of the side menu (`android-sync-page.js`), shown only -where `platform.photoSync` exists. Settings holds what the account prefers on -every client; this page holds what one phone sends, and is where whatever else -the phone sends will go. +where `platform.phoneSync` exists. Settings holds what the account prefers on +every client; this page holds what one phone sends: photos, contacts (§9.13), +and the kinds to come (messages, calendar, files). + +**One destination for every kind.** The top of the page chooses it once: a +group and one of its writable folders (`Destination.kt`, `sync-destination.js`). +Each kind goes into its own folder under it, `/-photos`, +`/-contacts`, made if missing. Only a group **the account owns +and is the only member of, with nobody invited**, is offered, because what a +group's folder holds every member can read, and none of this is the group's. +The hub's member list is asked again **at every run, before anything is +read**: a group that has gained a member, an invitation or another owner stops +every backup (`not_private`, a lasting refusal said once) rather than being +read from then on. Moving the destination is a fresh start for every kind: +each is told, forgets what it sent (its ledger belongs to the old place) and +runs at once; what was sent stays where it is. The page says so before it +happens, and says too when the group's Photos tab does not show +`/-photos`, since photos there are kept but shown nowhere. **When.** A run is due 24 hours after the last run that *finished*; an interrupted one is retried at the next chance, at most every fifteen minutes. @@ -3364,19 +3379,15 @@ node's partial upload resumes it (§8.5). like a member sending by hand and gives it back, so a family's daily backups never occupy the node's upload pool ahead of a person. -**Where.** The member chooses the group (one per phone) and a folder among -those that are writable, available and shown by the group's Photos tab — a -folder outside those would take the photos and show them nowhere. Inside it, -each photo goes under `YYYY/YYYY-MM` from when it was taken, because an album is a +**Where.** Under `/-photos` of the destination, each photo +goes under `YYYY/YYYY-MM` from when it was taken, because an album is a directory (§9.9) and one folder of twenty thousand is a slow album. Albums on the phone are chosen too; the camera alone is the default, because screenshots and saved images are where photos nobody meant to share live. **By default the photos already on the phone are sent, newest first**, then each new one; "from -now on" is an option. A confirmation is drawn **when the destination or the +now on" is an option. A confirmation is drawn **when the backup starts or its starting point changes, never per run and never for a change of albums alone**: -it names the group, its owner, its member count, the folder, the count and size -about to go, and says that members can download them and that what they -downloaded cannot be taken back. +it names the folder and the count and size about to go. **Additive by construction.** The backup never deletes, renames or replaces anything on the node: `photo-sync.js` reaches no such operation @@ -3419,15 +3430,8 @@ path, additive, once a day, the page doing the sending and the phone handing bytes over by token (`/phonesync/`, `phonesync/` in the Android package, `phone-sync.js` on the page). Messages follow the same design. -**Only a group the person is alone in.** What a group's folder holds every -member can read, and an address book is not the group's. The set-up offers -only groups whose member list is this account and nobody invited, and every -run asks the hub again before reading anything: somebody who joins later stops -the backup (`not_private`, a lasting refusal said once) rather than reading -every copy from then on. Any writable folder of that group is offered, not -only the ones the Photos tab shows. - -**Where.** `/-contacts/`, made if missing. Each copy is a new +**Where.** `/-contacts/` of the destination every kind shares +(§9.12), checked at every run the same way. Each copy is a new file named for when it was taken (`contacts-2026-10-10-0900.vcf`), never a replacement: restoring is importing the newest one, and an older one is there if a phone sync went wrong. -- cgit v1.2.3