From 6832df6177ad973ad0e1b4f0a49d7a6da06c6e04 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Fri, 9 Oct 2026 12:08:31 +0200 Subject: feat: notifications on Android while closed, with nothing to install The phone fetches what is new every fifteen minutes with a poll secret (POST /v1/push/poll) that reads notification lines and nothing else. When a UnifiedPush distributor is already installed, the hub also pushes at once, encrypted to the phone (RFC 8291); losing the distributor falls back to fetching. The hub now honours "disable all notifications" itself: create_notification creates nothing for that account, as it already did for a muted group, so neither switch lets anything reach a phone. The interface used to be the only reader of the account-wide switch. Push endpoints are member-supplied URLs: a send refuses non-public addresses, connects to the address it checked, and follows no redirect. Android build untested here (no SDK on this machine). Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_HTTP_API.md | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'docs/MESHBAY_HTTP_API.md') diff --git a/docs/MESHBAY_HTTP_API.md b/docs/MESHBAY_HTTP_API.md index 74b9d77..1bcb55d 100644 --- a/docs/MESHBAY_HTTP_API.md +++ b/docs/MESHBAY_HTTP_API.md @@ -180,6 +180,14 @@ hub also serves the web application at `/` and `/app/`, which are not listed. | DELETE | `/v1/notifications` | user or node | Throw them all away. | | POST | `/v1/notifications/read-all` | user or node | Dismiss every one — the same thing as `DELETE ""`, under the name an older client knows it by. | +### Push + +| Method | Path | Auth | What | +|---|---|---|---| +| POST | `/v1/push/subscriptions` | user | Register this phone, or update its row: with an endpoint and keys when it has a push distributor, without them when it will fetch instead. | +| POST | `/v1/push/poll` | none | What is new for this phone since `since`: the same payloads a push carries, oldest first, at most twenty. | +| DELETE | `/v1/push/subscriptions/{subscription_id}` | user | Stop telling one phone anything: turned off there, or signed out of. | + ## Node control API `http://127.0.0.1:`, port 18000 unless `ui_port` in `node.toml` says -- cgit v1.2.3