Watch
0
0
Fork
You've already forked hyperhive
0

docs: drop statements about absent things, state current behaviour

This commit is contained in:
atlas 2026-10-02 09:26:41 +02:00
commit b83fdc60f3
4 changed files with 22 additions and 30 deletions

View file

@ -207,17 +207,14 @@ tuwunel has none.
Promoting a user to homeserver admin and resetting a password both need an
admin **sender**: `!admin …` messages into `#admins:<server_name>`, and
tuwunel only treats a message as a command when its sender is already an
admin. `@hive-<hive>:` has no admin sender to make that call with. Both are
swarm-level operations.
admin. Only `@swarm` is a homeserver admin, so both are swarm-level
operations.
<details><summary>Store precedence for a hive's sender account</summary>
`swarm/services/matrix/sender-token` is a shared path `hive-c0re` and
`swarm-controller` both build from the same function; nothing reads it.
`ensure_hive_user` reads the per-hive path
`swarm/hives/<hive>/matrix/sender-token` **first, on every sweep**, not
just when that file is missing (`sender_source`'s decision), so a value
at the shared path never takes effect once the per-hive path has one.
just when that file is missing (`sender_source`'s decision).
`swarm-controller` mints a per-hive token within five minutes of a hive
appearing; the sweep then overwrites the per-hive file, no boot
required.
@ -246,9 +243,7 @@ halves. `registrationTokenFile` is a removed option: a config that
still sets it fails to evaluate with a message naming the appservice.
<!-- vale write-good.Passive = NO -->
- **Access tokens are independent of the registration token.** An
access token lives on the device that minted it, so accounts and
sessions are unaffected by the registration token's presence.
- **Access tokens live on the device that minted them.**
`login_with_password` stays on, so the password fallback works
too.
- **The homeserver's `admin_execute` promotes only `@swarm` at boot**
@ -271,9 +266,9 @@ Initial rollout settings:
until you list peers.
- `allow_registration = false`. tuwunel checks this flag only for
requests that arrive **without** an appservice token, so the appservices
still create accounts and tuwunel refuses everyone else. It's not a
hardening afterthought: with no registration token configured,
`allow_registration = true` makes tuwunel refuse to start unless
still create accounts and tuwunel refuses everyone else. With no
registration token configured, `allow_registration = true` makes
tuwunel refuse to start unless
`yes_i_am_very_very_sure_…_open_registration_…` is also set.
- `allow_encryption` — server-side E2EE switch, sourced from
`services.hyperhive.swarm.matrix.allowEncryption` (**default `false`**, opt-in).