Site
The definition of a site in Stem, a peer that publishes a space on the web under a relationship signed by both the space owner and the site, replacing the siteUrl string and the HTTPS lookup that HM24 trusts.

Part of Stem. This page defines site and the signed relationship that makes a peer one.

A site of a space is a peer that the space root names in its site attribute by URL and peer id, and that has authenticated as an account holding a live sync grant on the space root signed by the owner; both halves must hold for the peer to be treated as the site.

A site does two jobs. On the web it serves the space's public content at https://<url>/hm/<space>/… and, to readers who authenticate, the private content they may read. On the network it is the always-on authority peer that the owner's devices offer to and that readers sync from.

The two halves

The owner's half is the site attribute of the space root: {url, peer}. It is part of the root's signed state, so it is as trustworthy as anything else the owner publishes, and it tells readers where to look.

The grant is a Grant signed by the owner with subject the space root (a node subject with node omitted), audience {kind: key, key: <site account>} and access sync. The site account is a key the site operator controls; its peer authenticates as that account. The grant is what allows the site to hold and relay the space's private blobs, and what the owner revokes to fire a site. Until encryption exists sync behaves as read for delivery, so the grant also makes the site a reader of everything in the space.

A URL without a grant is a dangling pointer: peers will not treat the named peer as an authority peer and will not serve it private blobs. A grant without the URL makes the site peer an authority peer that readers cannot find by name. Registration, as a flow, publishes both.

Trust

HM24 trusts whoever answers an HTTPS request to /hm/api/config at the siteUrl. If the owner points siteUrl at a hostile host, that host receives the space's private blobs. In Stem the owner still chooses the site, but the choice is a grant to a key, and the peer must prove it holds that key. DNS and TLS are left to do what they are good at, which is getting a browser to the right web server. The disclosure ledger records every blob the owner's peers served to the site under basis site, so a mistaken grant is auditable.

Where it is used

Today (HM24)

A site is a space whose home document names a siteUrl; the daemon fetches https://<siteUrl>/hm/api/config, trusts the peer id it finds there as the space's authority, authenticates to it when it holds a writer key, and serves it private blobs. The Sites page records the direction: "a site's authority over a space becomes an explicit, signed relationship instead of a siteUrl string plus an HTTPS lookup." This page is that relationship.

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime