Skip to content

Latest commit

 

History

History
60 lines (49 loc) · 3.13 KB

File metadata and controls

60 lines (49 loc) · 3.13 KB

Remembered web-device login

The Telex web client can remember a human login on one browser profile without storing the human's account password. This is optional. Leave remember this device unchecked to retain the original password-in-memory behavior.

When selected, the client first signs in with the ordinary account name and password, creates or resumes its dr1... delivery installation, and asks the control API for one random rd1... remembered-device credential bound to that same installation UUID. The server returns the credential once and stores only its SHA-256 digest. The browser stores the credential in the account/server scope in IndexedDB, never LocalStorage or the service-worker cache.

The three secrets deliberately have different authority:

  • the account password authenticates the human everywhere and can create a remembered-device credential;
  • rd1... authenticates only the named human installation and can reconnect the web client; and
  • dr1... identifies only the installation's delivery checkpoint and cannot authenticate anything.

On a later launch, the web client uses the authentication ID account/<installation-uuid> with the saved rd1... bearer, then proves the matching dr1... installation during device binding. A mismatched pair is rejected. Ordinary IRC clients remain unchanged and continue to use the bare account name and password.

Revocation

The integrated account screen lists active remembered devices with their browser-generated label and creation date. Revoking one credential closes live IRC, native, and Stage sessions bound to that installation but preserves its delivery checkpoint. The next password login can therefore resume without replaying the installation from zero.

Explicit disconnect in the web client requests revocation of that browser's saved credential and always clears the local copy. If the revocation request cannot reach the server, the account screen on another signed-in device can revoke the orphaned entry, or a password change can revoke every remembered device. An ordinary transport loss, background suspension, tab close, or application close does not request revocation; those are the events the remembered credential exists to survive.

Changing the account password atomically revokes every remembered-device credential and disconnects every active session for the account. It preserves account history, read state, installation tokens, and delivery checkpoints. Creating another remembered credential or changing the password always requires authentication with the actual account password; an rd1... credential cannot mint another bearer or rotate the account password.

Remembered credentials have no independent expiry in v1. They remain active until explicit revocation, password change, or eviction of their underlying installation. The existing limit of 16 active installations per human account therefore also bounds remembered credentials.

Clearing browser site data removes the local credential without notifying the server. Use the account screen from another signed-in device to revoke the orphaned entry, or change the account password to revoke all remembered devices.