From 0378e8e0912a1a7e6cea4424e69d524e7afecbf8 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 21:04:39 +0200 Subject: fix: an identity signs a named kind, and a device approval answers a request The desktop main process builds every transcript itself from fields (transcripts.js) and signs no raw bytes; the page's identity has the same contract (crypto.js transcriptFor). The keyring seals no bundle while browser access is off. On the node, device_add must redeem a pending request filed by the same keys, and device_revoke is signed under its own prefix (meshbay:device_revoke:v1), so a retirement signature admits nothing. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/tests/harness/chat_send_probe.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/tests/harness') diff --git a/packages/meshbay-hub/tests/harness/chat_send_probe.py b/packages/meshbay-hub/tests/harness/chat_send_probe.py index e5cfc8b..e7f1dae 100644 --- a/packages/meshbay-hub/tests/harness/chat_send_probe.py +++ b/packages/meshbay-hub/tests/harness/chat_send_probe.py @@ -172,7 +172,9 @@ function makeTransport(name, chatReply) { tp._gekRaw = hex('__GEK_HEX__'); tp.chatEpoch = 1; tp._identity = { pkEdB64: DEVICE_PK_B64, - sign: (bytes) => window.MeshBayKeys.signBytes(SK_ED_B64, bytes) }; + signAs: (kind, fields) => window.MeshBayKeys.signBytes(SK_ED_B64, + window.MeshBayCrypto.transcriptFor(kind, fields, + { pkEdB64: DEVICE_PK_B64 })) }; tp.devicePk = DEVICE_PK_B64; tp._send = (obj) => { log.push('sent ' + obj.type); -- cgit v1.2.3