From b1ebcdeb9082457972c41a47e77494902335d262 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 17:13:40 +0200 Subject: feat: browser access, decided in the desktop application Off for an account made there: its identities stay on the device and nothing is left on nodes. Turned on from the Profile page behind a native confirmation; each node is settled when its group next opens. The hub keeps a mirror a browser reads to say why a group will not open; it grants nothing. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/api/users.py | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'packages/meshbay-hub/src/meshbay_hub/api/users.py') diff --git a/packages/meshbay-hub/src/meshbay_hub/api/users.py b/packages/meshbay-hub/src/meshbay_hub/api/users.py index 88e6d9e..92b3d3d 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/users.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/users.py @@ -1277,6 +1277,11 @@ ALLOWED_PREF_KEYS = frozenset([ # Whether the Members tab asks the hub to mail an invitation. Remembered # because unticking it on every invitation is what nobody would keep doing. "invite_email", + # "on" / "off": a mirror of what the desktop application holds for the + # account, written by it so a browser can say why it cannot open a group. + # It grants nothing — nodes never read it, and a browser session writing + # "on" leaves the application's own setting as it was. + "browser_access", ]) # `default_tab:`, which is what the SPA writes (group-page.js). The -- cgit v1.2.3