From 462d76898a306981fbeac859cd54da1468e80639 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 7 Oct 2026 22:12:54 +0200 Subject: fix(node): name members admitted without an invitation name A member who joined by link, by a new device or into an open group was pinned in the roster with no name, so the audit log showed only the first characters of their id. The hub's MNP token now carries the account's username, and after the handshake the node writes it into the roster for an account whose name is empty. An invitation's name is never overwritten; the name is a label, authority stays on `sub`. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-node/src/meshbay_node/transport/webrtc/admission.py | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) (limited to 'packages/meshbay-node/src/meshbay_node/transport/webrtc/admission.py') diff --git a/packages/meshbay-node/src/meshbay_node/transport/webrtc/admission.py b/packages/meshbay-node/src/meshbay_node/transport/webrtc/admission.py index 20ebc79..fd9c756 100644 --- a/packages/meshbay-node/src/meshbay_node/transport/webrtc/admission.py +++ b/packages/meshbay-node/src/meshbay_node/transport/webrtc/admission.py @@ -380,9 +380,8 @@ class AdmissionMixin: return await self._pin_and_admit( - # The name comes from the invitation, not from the token: the hub does - # not put a username claim in a JWT, so pinning from the session alone - # left the roster nameless and `member revoke ` unable to match. + # The invitation's name first: it is the person the operator meant. + # The token's name covers an invitation that carries none. roster, user_id, invite["username"] or username, pk_ed_b64, pk_x_b64, group_id=invite["group_id"], role=invite["role"], approved_by=invite["created_by"], -- cgit v1.2.3