Bind capability state to Noise generations

This commit is contained in:
jack
2026-07-25 16:58:57 +02:00
committed by jack
parent 0e29885d43
commit 7bf19a6ee5
8 changed files with 556 additions and 123 deletions
+4 -4
View File
@@ -70,10 +70,10 @@ The fallback is signed and its signature is required on receive, so relays
cannot forge its sender or contents. It is not confidential: relays can see
the raw file TLV. The UI says this explicitly and asks on every send. A peer
without a stable Noise key from a verified registry entry cannot use the
fallback. Keep
the fallback only for the mixed-version migration and remove it after
supported Android and iOS releases advertise `privateMedia`. Never replace it
with an unsigned fallback, persist blanket consent, or send both forms.
fallback. Keep it only for the mixed-version migration, and remove it only
after minimum-supported Android and iOS releases emit authenticated bit-8
`0x21` state and the legacy population has aged out. Never replace it with an
unsigned fallback, persist blanket consent, or send both forms.
Incoming clients accept all three migration-era shapes: