From 462d76898a306981fbeac859cd54da1468e80639 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 7 Oct 2026 22:12:54 +0200 Subject: fix(node): name members admitted without an invitation name A member who joined by link, by a new device or into an open group was pinned in the roster with no name, so the audit log showed only the first characters of their id. The hub's MNP token now carries the account's username, and after the handshake the node writes it into the roster for an account whose name is empty. An invitation's name is never overwritten; the name is a label, authority stays on `sub`. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-common/src/meshbay_common/handshake.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'packages/meshbay-common') diff --git a/packages/meshbay-common/src/meshbay_common/handshake.py b/packages/meshbay-common/src/meshbay_common/handshake.py index c3d5b94..dad8cdc 100644 --- a/packages/meshbay-common/src/meshbay_common/handshake.py +++ b/packages/meshbay-common/src/meshbay_common/handshake.py @@ -343,7 +343,7 @@ def authorize_token( return AuthorizedPeer( user_id=user_id, group_id=group_id, - username=decoded.get("username", ""), + username=str(decoded.get("username") or "")[:64], jti=jti, ) -- cgit v1.2.3