From 6bb2fa48ef13e0630e155565c4c0e046de03a1a1 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 28 Sep 2026 22:47:23 +0200 Subject: refactor(node): remove five loopback routes nothing called The group-setting routes for app directories, chat directory, link previews, Search listing and scan settings had no caller and no test; those settings are signed MNP operations only. Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_NODE_PROTOCOL.md | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'docs/MESHBAY_NODE_PROTOCOL.md') diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md index c3254da..ce99a40 100644 --- a/docs/MESHBAY_NODE_PROTOCOL.md +++ b/docs/MESHBAY_NODE_PROTOCOL.md @@ -1207,6 +1207,11 @@ one is the one that decides. A front door is allowed to differ in how it *authen — a signature here, a run token on loopback, an operator's shell for the CLI — and never in what it *does*. +An operation has the doors something uses, and no more: a door nobody calls is an +untested way in. The per-group settings the group's Settings tab changes — +application folders, the chat folder, link previews, the Search listing, the scan +settings — are signed MNP operations only. + --- ## 11. Content plane -- cgit v1.2.3