- Connections ▸ Share Library with a Friend… makes a one-time invite code
(device id, display name, token) and the inviter's send-only folder.
- Connections ▸ Add Friend Library… takes the pasted code: adds the
inviter, shares our folder, and accepts theirs receive-only when it's
offered back.
- Syncthing hides an unknown device's folders (verified on 1.30), so the
inviter probes a new knock only while an invite is open: added with
nothing shared, completed on the right token, otherwise removed and
never probed again. Used and cancelled codes go nowhere.
- Sync Settings lists open invites (Cancel Invite) and gives each friend a
page: avatar, plain-language status with a next step, last seen, last
synced, Remove Friend. Removals are staged until OK.
- scripts/cassette_pair.py runs throwaway Syncthings on loopback;
pytest --syncthing drives a real three-machine handshake.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>