Let a vault be shared from the phone, not only read there
ci / build and test (push) Canceled after 0s
ci / android head (push) Canceled after 0s
ci / api image (push) Canceled after 0s

This screen's own comment argued ADD out: an address typed into a box, a
directory lookup, a role picker and a paragraph saying what adding somebody did
not do, for an act a colleague at a desktop is already performing.

That was a cost argument and it was wrong about who is holding what. The person
who needs to let somebody into a vault is often the one away from their desk, and
answering them with "go and find a desktop" is the thing this head exists to stop
doing. Making a vault was already here on exactly that reasoning.

Nothing shared changed — AddMemberCommand, the role and the chips are the same
members the desktop binds — so what this is, is markup and the argument it
reverses. Four rows under the members list: the box, three role chips rather than
a picker because the answer is one of three short words, ADD, and the paragraph.
Gated on being able to administer the vault, so a plain member sees nothing
rather than a button whose only outcome is a 403.

The paragraph is not the optional part. Adding somebody changes what the server
will serve and nothing else; the key is still wrapped by a machine that holds one
— which on an unlocked phone is this one, in the same press. A screen that
offered the first and stayed quiet about the second would imply the server can
hand out access, which is the single claim this product is built to refuse.

What the phone still does not draw is anything that takes access away. REMOVE and
WITHDRAW KEY act on the first press, and an irreversible revocation under a thumb
with its explanation in a tooltip no touch screen can show is the wrong trade —
which is the line this file already drew and this does not move.

Check 12.4 walks it, including the locked-keychain case: the membership is made
and the line says the key could not be wrapped, which is a state somebody can act
on rather than silence.
This commit is contained in:
2026-08-05 19:10:25 +02:00
parent dc1ebf6afa
commit 0c61ea3a97
4 changed files with 106 additions and 7 deletions
+6 -1
View File
@@ -546,7 +546,12 @@ desktop job. Pins and import have no phone screen either, and importing an `~/.s
on a phone at all. **VAULTS does have one**, behind MORE, and it is there for a reason the design could not
have anticipated: a vault arrives without being asked for — somebody wraps its key to you — so the person
it arrives for is at least as likely to be holding a phone as sitting at a desktop, and a membership
visible only on a head they have not installed is a membership they cannot see.
visible only on a head they have not installed is a membership they cannot see. **Somebody can be added to
a vault from the phone too**, with the same box, the same role and the same sentence about what adding does
not do — and if that phone can open the vault, it wraps the key in the same press. What the phone still
does not draw is anything that takes access away: REMOVE and WITHDRAW KEY act on the first press, and an
irreversible revocation under a thumb with its explanation in a tooltip nothing can show is the wrong
trade.
**Port forwarding is not built anywhere**, and the phone's More screen says so in a paragraph rather than
leaving a gap. The v2 design draws a whole screen for it; nothing in the SSH layer forwards anything, so