From b1ebcdeb9082457972c41a47e77494902335d262 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 17:13:40 +0200 Subject: feat: browser access, decided in the desktop application Off for an account made there: its identities stay on the device and nothing is left on nodes. Turned on from the Profile page behind a native confirmation; each node is settled when its group next opens. The hub keeps a mirror a browser reads to say why a group will not open; it grants nothing. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/static/auth-page.js | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/auth-page.js') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/auth-page.js b/packages/meshbay-hub/src/meshbay_hub/static/auth-page.js index 8e67e20..d3d3bd7 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/auth-page.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/auth-page.js @@ -409,9 +409,15 @@ export function RegisterPage() { // username and every key derivation must fold in the same string. // `captcha.token` rides along — the submit button is already disabled // until it is set when a captcha is configured (see the form below). - await window.MeshBayKeys.registerUser( + const reg = await window.MeshBayKeys.registerUser( name, email, password, emailRecovery ? rk.mnemonic : null, captcha.token); + // An account made in the desktop application starts without browser + // access: its identities stay on this device and nothing of them is + // left on nodes until the person turns it on, here, natively. + if (reg.userId && await platform.nativeKeys()) { + try { await platform.keys.createdHere(reg.userId); } catch { /* kept on */ } + } setRecoveryMnemonic(rk.mnemonic); session.recoveryKey = await window.MeshBayKeys.deriveRecoveryKey(rk.mnemonic, name); -- cgit v1.2.3