From 6d167392f6f8ede37e2794a68a3738f8ba03131d Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 16:58:31 +0200 Subject: feat(client): the desktop application keeps M and every node identity in its main process keyring.js derives, opens, mints, seals, signs and agrees there; the page gets public keys and a handle. Argon2 comes from the page's own WebAssembly build (Electron's crypto has none). Without OS key storage the page keeps its keys as a browser does. A node's bundle is settled after connecting, re-sealed when the key changed. Co-Authored-By: Claude Opus 5.5 --- .../meshbay-hub/src/meshbay_hub/static/platform.js | 32 ++++++++++++++++++++-- 1 file changed, 30 insertions(+), 2 deletions(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/platform.js') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/platform.js b/packages/meshbay-hub/src/meshbay_hub/static/platform.js index 8bf09b4..19f12a6 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/platform.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/platform.js @@ -508,9 +508,36 @@ export async function setUiLocale(code) { return bridge.setLocale(code); } +/** + * The account's keys, held by the desktop application's main process + * (`meshbay-client/src/keyring.js`): the bundle master key and the identity on + * every node. The page asks for public keys, signatures and agreements. + * + * Null in a browser. `available()` is false in the application too where the + * OS has no key storage — identities kept there and lost at the next start + * would strand the account on every node — and the page then keeps its keys as + * a browser does. + */ +let _keysAvailable = null; +export const keys = (bridge && bridge.keys) ? { + ...bridge.keys, + async available() { + if (_keysAvailable === null) { + try { _keysAvailable = Boolean(await bridge.keys.available()); } + catch { _keysAvailable = false; } + } + return _keysAvailable; + }, +} : null; + +/** Whether this page's keys are held by the application rather than here. */ +export async function nativeKeys() { + return Boolean(keys && await keys.available()); +} + export default { isNative, hubBase, capabilities, secrets, nativeSave, apiFetch, device, bridgeMessage, folder, rootPicker, node, - cast, minimizeToTray, setTrayLabels, setUiLocale }; + cast, minimizeToTray, setTrayLabels, setUiLocale, keys, nativeKeys }; // Also a global, because `transport.js` is loaded as a classic script — it // predates the module graph and exposes `MeshBayTransport` the same way. The @@ -520,5 +547,6 @@ if (typeof window !== 'undefined') { window.MeshBayPlatform = { isNative, hubBase, capabilities, secrets, nativeSave, apiFetch, device, bridgeMessage, folder, rootPicker, node, - cast, minimizeToTray, setTrayLabels, setUiLocale }; + cast, minimizeToTray, setTrayLabels, setUiLocale, + keys, nativeKeys }; } -- cgit v1.2.3