From 462d76898a306981fbeac859cd54da1468e80639 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 7 Oct 2026 22:12:54 +0200 Subject: fix(node): name members admitted without an invitation name A member who joined by link, by a new device or into an open group was pinned in the roster with no name, so the audit log showed only the first characters of their id. The hub's MNP token now carries the account's username, and after the handshake the node writes it into the roster for an account whose name is empty. An invitation's name is never overwritten; the name is a label, authority stays on `sub`. Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_DESIGN.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'docs/MESHBAY_DESIGN.md') diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index baf8e1e..0284dbe 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -1131,7 +1131,7 @@ token (E10).** A member hands whatever it presents here to the node operator, who is in the threat model, so the credential must open nothing at the hub. The hub signs two audiences with its one key: a session token (`aud` = the hub API) for `hubFetch` and signaling, and a short-lived **MNP token** (`aud = MNP_AUD`, -from `POST /v1/nodes/mnp-token`) that carries the member's `sub`, `jti` and **the +from `POST /v1/nodes/mnp-token`) that carries the member's `sub`, `username`, `jti` and **the one group the connection is for** — never the member's other groups, which the operator it is handed to has no business learning — and is the only thing presented in the handshake. The node binds `MNP_AUD` -- cgit v1.2.3