Trust and standing¶
Kunuleco keeps apart two questions that most services blur. One is who you are, which your identity answers. The other is what you may do in a given place, which grants and standing answer. Being present somewhere answers neither.
Grants, not lists¶
Access to a capsule comes from a grant, a record signed by the person who made it. The
node checks that signature before it honours the grant. You give someone specific
capabilities (read, write, and so on) on a capsule you own, and take them back later.
grant and revoke act on your own capsule of that name. Only a capsule's owner can share
it or revoke access to it, and a capsule someone shared with you cannot be shared on.
Because the grant names the thing it opens, taking it back is clean. And because presence
is not permission, someone can stand in your Hall without being able to open anything in
it.
The node user and the owner¶
Every node has its own account, the node user, created the first time the node starts.
It is the root that other rights come from, and nobody can sign in as it. The first person
to create an account on a node becomes its owner. The node user gives that person four
grants once, create_user and node_admin and the right to pass each of them on.
Owner and Steward are different things. The owner runs the node, and node_admin is what
makes someone an owner, so a person who can create accounts is not thereby an owner. A
Steward runs a Hall.
The owner's four grants from the node user do not expire. Every create_user, node_admin
and delegate: grant that a person gives expires 90 days after it is given, and nothing
renews it unless the person who gave it does.
| Command | What it does |
|---|---|
delegations |
List the grants you gave that are still live, with their expiry |
renew <name> |
Renew every expiring grant you gave that person |
renew all |
List what would be renewed, and sign nothing |
yes |
Renew exactly the list renew all showed, within ten minutes |
undelegate <id> |
Revoke a grant, and what was passed on from it |
When you sign in, the node tells you which of your grants lapse within 30 days.
Standing¶
Standing is your trust level inside one Hall. It rises from visitor to steward, and each tier adds to the one below it.
| Tier | Can |
|---|---|
| Visitor | Read the public zone. Not a member |
| Newcomer | Read and write in the public zone. The first member tier |
| Familiar | Use the common zone |
| Trusted | Moderate the common zone, and vouch in a members-only Hall |
| Steward | Use the private zone, govern the Hall, and set other people's standing |
standing shows yours in the Hall you are in. standing <user> <tier> is the Steward's command for
setting someone's tier, and in this build it grants nothing (see
Known issues). So a member reaches Newcomer
through accept or an open Hall, and no one can yet be raised to Familiar, Trusted or Steward.
Getting into a Hall¶
A Hall's threshold decides how much ceremony entry takes. A Steward changes it with
set hall threshold <open|knock|invite_only|members_only>.
| Threshold | What happens on first entry |
|---|---|
open |
You walk in as a Newcomer |
knock |
Your knock waits for a Steward. This is the default for a new Hall |
invite_only |
Reserved. For now your request waits for a Steward, as with knock |
members_only |
Your knock waits, and two vouches from Trusted members admit you without a Steward |
A Steward reviews the queue with knocks and answers with accept <user> or
reject <user>. In a members-only Hall a Trusted member or the Hall's owner can
vouch <user>. When two vouches from people who are still Trusted are in, the person is
admitted as a Newcomer. See Your first Hall.
Petnames¶
A petname is your own private alias for someone (petname mira#7K2QX9 mira). It is
bound to their full handle, and to their identifier when your peer registry has one, not to
a display name. An alias you have set cannot be quietly pointed at someone else. To reassign
it, you clear it first with petname <name> --clear. Your petnames and contacts live in
your private peer registry and survive restarts.
Blocking¶
block <name> blocks the person by the AID their connection proved, wherever that person
appears on your node, and drops any session you have open with them. If your node has never
verified who a name belongs to, or the name belongs to more than one identity, block says
so and blocks nothing. unblock <name> lifts it, and someone who was a contact comes back
as a contact. blocked lists who you have blocked.
A block is a decision your node makes about what it accepts. It does not reach into anyone else's node or erase what they already have.
Membership is intentional¶
Sponsorship. Once a node has an account, creating another one needs a sponsor who holds
create_user. The owner holds it, and other people hold it only if the owner passes it on.
Nodes grow on purpose rather than by drift.
Meeting in person. meet shows a kunul1… seed and a QR code. The other person runs
join with it, and their node dials yours over the local network and checks that the
identity your node proves matches the AID inside the seed. If it does not match, the
connection is dropped and nothing is recorded, so what you scanned is who you get.