From 998f9c69308ee88fac36cfb77dfb6d07c6fa926a Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 23 Sep 2026 17:46:48 +0200 Subject: feat(hub): invitation-link tickets bound to a verified address MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit group_invite_links holds sha256(ticket) and the invitee's address blind index; redeeming grants membership to that account only. Owner-only create/list/cancel (a node token may create, never mail), 20 outstanding per group, optional mail written by the hub itself and capped at 10 per sender per day (mail.invite_link_daily_cap). MESHBAY_DESIGN.md ยง3.4 now carries the whole link design. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/config.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/config.py') diff --git a/packages/meshbay-hub/src/meshbay_hub/config.py b/packages/meshbay-hub/src/meshbay_hub/config.py index f2212de..e618510 100644 --- a/packages/meshbay-hub/src/meshbay_hub/config.py +++ b/packages/meshbay-hub/src/meshbay_hub/config.py @@ -130,6 +130,11 @@ class MailConfig: # recipient, and without the exemption a typo locks the account out for the # whole window. email_change_cooldown: int = 172800 # 48 hours + # Invitation-link mails one account may have the hub send per day. The only + # per-account bound here, because a link reaches addresses with no account, + # and the per-recipient cap alone would let one account mail ten strangers + # each, without end. + invite_link_daily_cap: int = 10 @dataclass @@ -174,7 +179,7 @@ def load_config(path: Path | None = None) -> HubConfig: "destination_cooldown_seconds", "destination_daily_cap", "hourly_budget", "hourly_reserved_for_recovery", "verification_resend_cooldown", "reset_cooldown", - "email_change_cooldown", + "email_change_cooldown", "invite_link_daily_cap", ): setattr(cfg.mail, name, ml.get(name, getattr(cfg.mail, name))) if cap := raw.get("captcha", {}): -- cgit v1.2.3