From 0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 1 Oct 2026 09:46:39 +0200 Subject: fix(node): how a hosted group admits people is the operator's, not the hub's attach_group no longer copies join_policy and visibility from the hub's answer: they come with the operator's request (the desktop creation form, `group add --open`) and default to invite/private; the CLI says when the hub lists the group otherwise. Every string written into node.toml is escaped (toml_string) and read back through tomllib, so a group or folder name cannot write lines of its own (F-17). Co-Authored-By: Claude Opus 5.5 --- docs/MESHBAY_DESIGN.md | 6 ++++++ docs/QUICKSTART.md | 2 +- 2 files changed, 7 insertions(+), 1 deletion(-) (limited to 'docs') diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 2966e5e..38977af 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -544,6 +544,12 @@ admission. Only the second decides whether a code is required: a public group wi **`join_policy` is read from `node.toml`, never from the hub.** A hub able to declare a group open would be handed its key. An unknown group reads as `invite`. +It is written there when the node starts hosting the group, from the operator's +own request — the creation form in the desktop application, `group add --open` on +the command line — and is `invite` unless that request says `open`; the hub's +record of the group is looked up for its id and name only. Every string written +into `node.toml` is escaped as a TOML string (`ops.node_toml.toml_string`): a group +or folder name is someone else's text. ### 3.6 Passphrase change and recovery diff --git a/docs/QUICKSTART.md b/docs/QUICKSTART.md index a11bb00..ce1eec1 100644 --- a/docs/QUICKSTART.md +++ b/docs/QUICKSTART.md @@ -235,7 +235,7 @@ What those three did: | | | |---|---| -| `group add` | told the node to host that group, and made the directory its first shared folder. It is **read-write** by default, so members can upload into it. Add `--no-writable` if you want a published, read-only library. | +| `group add` | told the node to host that group, and made the directory its first shared folder. It is **read-write** by default, so members can upload into it. Add `--no-writable` if you want a published, read-only library. It admits members **by invitation**; add `--open` to let anyone the hub lists the group to join. | | `reload` | made the running daemon re-read its config without dropping anyone. | | `gek init` | generated the group's encryption key. **Nothing works before this** — the key never leaves your node, and every member receives it wrapped for their own key, on every connection. | -- cgit v1.2.3