From 0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 1 Oct 2026 09:46:39 +0200 Subject: fix(node): how a hosted group admits people is the operator's, not the hub's attach_group no longer copies join_policy and visibility from the hub's answer: they come with the operator's request (the desktop creation form, `group add --open`) and default to invite/private; the CLI says when the hub lists the group otherwise. Every string written into node.toml is escaped (toml_string) and read back through tomllib, so a group or folder name cannot write lines of its own (F-17). Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-client/src/main.js | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-client') diff --git a/packages/meshbay-client/src/main.js b/packages/meshbay-client/src/main.js index 309d5f6..236a285 100644 --- a/packages/meshbay-client/src/main.js +++ b/packages/meshbay-client/src/main.js @@ -2184,7 +2184,10 @@ function registerBridge() { attachGroup: async (a) => { const body = { name: aText(a.name, 'the group name'), shared_dir: aText(a.path, 'the folder', 4096), - writable: a.writable !== false }; + writable: a.writable !== false, + // The person's choice on the creation form; the node never + // takes it from the hub. + join_policy: a.joinPolicy === 'open' ? 'open' : 'invite' }; await confirmOrRefuse('native.attach_confirm', { name: body.name, path: body.shared_dir }); return ['POST', '/api/groups/attach', body]; -- cgit v1.2.3