From 0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 1 Oct 2026 09:46:39 +0200 Subject: fix(node): how a hosted group admits people is the operator's, not the hub's attach_group no longer copies join_policy and visibility from the hub's answer: they come with the operator's request (the desktop creation form, `group add --open`) and default to invite/private; the CLI says when the hub lists the group otherwise. Every string written into node.toml is escaped (toml_string) and read back through tomllib, so a group or folder name cannot write lines of its own (F-17). Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js | 3 +++ 1 file changed, 3 insertions(+) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js index d4c2ab8..bdb3dbc 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js @@ -255,6 +255,9 @@ function CreateGroupWizard({ token, username, onCreated, onNodeLinked, allowPubl name: name.trim(), path: mainRoot.path, writable: mainRoot.writable !== false, + // How people join is set on the node, from this form — the node does + // not take it from the hub. + joinPolicy, }; await platform.node.op('attachGroup', attachBody); await platform.node.op('reload'); -- cgit v1.2.3