From 8926f163dad9d32dc06c3a142658a4e11d9c12c1 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 15:48:51 +0200 Subject: refactor(hub): the transport holds an identity, never a private key Two public keys, sign() and shared(); the apps take transport.signFn. What holds the keys (this page, or the desktop main process) is the identity's business alone. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js b/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js index 270c76e..f0604ce 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js @@ -157,7 +157,7 @@ extendTransport(class { const epoch = this.chatEpoch || keys.current; const epochKey = keys.byEpoch.get(epoch); if (!epochKey) throw new Error('No chat key for this group — reconnect'); - if (!this.devicePk || !this._sessionKeys || !this._sessionKeys.skEdB64) { + if (!this.devicePk || !this._identity) { throw new Error('This device is not identified to the node — reconnect'); } @@ -172,8 +172,7 @@ extendTransport(class { const { nonce, ct } = await C.sealChat( epochKey, gid, epoch, this.devicePk, plaintext); const device = C.b64decode(this.devicePk); - const sig = C.b64decode(await window.MeshBayKeys.signBytes( - this._sessionKeys.skEdB64, + const sig = C.b64decode(await this._identity.sign( C.chatSigningTranscript(gid, epoch, device, nonce, ct))); const msg = await this._sendAndWait({ -- cgit v1.2.3