Skip to content

feat: link Signet contacts, with word checks and local blocks - #202

Draft
TheCryptoDonkey wants to merge 4 commits into
mainfrom
feat/signet-contacts
Draft

TheCryptoDonkey wants to merge 4 commits into
mainfrom
feat/signet-contacts

Conversation

@TheCryptoDonkey

Copy link
Copy Markdown
Member

Draft. Three decisions below are the owner's, and this should not merge before them. It is not part of desktop 0.1.26.

What this is

The contacts half of feat/signet-ownership-attestations, put on today's main. That branch was 240 commits behind and mixed two things. Only the first is here.

Taken Left out
Link Signet contacts from the room sheet Agent ownership on Signet's bot-ownership events
A word check both people take part in The ownership registry and revocation store
Blocks made in Signet, applied on this device signet-protocol as a dependency
A check chip that says where a check came from

Ownership is left out because main bounded ownership proofs to thirty days on 22 September (#140) and the branch took a different answer. Which one holds is a decision of its own.

What changed from the branch

  • An approval is not a pairing until the code is confirmed. The pairing link can be photographed, and the first approval to arrive does not say whose Signet sent it. The panel now shows a six digit code, the person types it into Signet, and nothing is saved or fetched until they say Signet matched. The contacts SDK has required this of consumers since 26 September.
  • The wait for an approval is the SDK's own, not two minutes.
  • A projection carrying a field beyond its scopes is refused whole, as the SDK now does. One test expected the covered fields to survive; it is rewritten and a second test states the refusal.
  • The package is pinned to a commit of its public repository, not a path on one machine. It is not on npm yet.
  • The browser test opens the new room form first, as main's start page now needs.

docs/decisions.md has the reasoning, in the entry of 28 September.

Decisions for the owner

  1. The fixed words go. The word check now needs both people on an app that speaks it. Android, agents and desktop apps before the next release do not, so a person on the web cannot check somebody on one of those until they update. The dialog says "Older apps cannot complete this check". The alternative is to keep the fixed words as a labelled second path.
  2. Checks made before this change stop showing. Checks are now stored under the identity that made them. Older records stay on disk and are not attributed to anybody, so a chip that said "checked" will say "not checked".
  3. No Web Locks, no check. A browser without them cannot start a check or link contacts. That is a refusal on purpose, so two tabs cannot undo each other.

What it does not do

A block is local. It filters this device's roster, chat and invitations and closes its media peers. Nobody is removed from the room, no key is revoked, and no other member's view changes. Tier gated admission and returning a check to Signet are separate work, set out in docs/signet-contact-admission.md.

Tested

  • npm run typecheck: clean.
  • Unit suite: 2,713 of 2,715 pass on a busy machine. The two that fail time out at five seconds and are not touched here: src/chat.test.ts "opening an old room" and src/voice-effects.test.ts "keeps the level". The first fails the same way on main's checkout under the same load, and is the test that failed on release: publish Android 0.6.22 #187.
  • Browser tests, Chromium only, run locally: test/verification.spec.ts and test/nostr-rooms.spec.ts, 15 of 15, including the pairing with a confirmed code, a block, and a revocation.
  • Not run locally: Firefox, WebKit and the rest of the browser suite. CI on this pull request is the check for those.
  • Not tested: a real pairing against Signet on a phone.

🤖 Generated with Claude Code

https://claude.ai/code/session_01H76NN8NDdN4TGw32qi7E18

Takes the contacts half of feat/signet-ownership-attestations and puts it
on today's main. The ownership half is left out: main bounded ownership
proofs to thirty days on 22 September, and the branch took a different
answer.

What a person gets:

- Link Signet contacts from the room sheet. Names, keys and blocks are
  asked for; tiers and check records are optional and chosen in Signet.
- A word check that both people take part in, over the contacts SDK's
  commit and reveal profile, in place of the fixed words.
- A block made in Signet filters this device's roster, chat and
  invitations and closes its media peers. It is local: nobody is removed
  from the room and no key is revoked.
- A check chip that says where a check came from.

Changed from the branch:

- An approval is not a pairing until the person confirms the pairing code
  in Signet. A QR can be photographed, and the first approval to arrive
  does not say who sent it. Nothing is saved or fetched before that.
- The wait for an approval is the SDK's own, not two minutes.
- A projection carrying a field beyond its scopes is refused whole, as the
  SDK now does. The test that expected the covered fields to survive is
  rewritten to say so.
- @forgesworn/signet-contacts is pinned to a commit of its public
  repository in place of a path on one machine.

docs/decisions.md has the reasoning.

Claude-Session: https://claude.ai/code/session_01H76NN8NDdN4TGw32qi7E18
Checks are kept under the identity that made them, and the chip asked for
that store with whatever identity the room on screen had. A docked call's
tiles outlive their room, so the chip could be painted with none. The
store refused, inside a paint that swallows what its callers throw, and
the rest of the paint went with it: the room title stayed "Room" after a
switch to another room.

test/call-dock.spec.ts:23 failed on CI and three times in three here. It
passes three in three with this.

Claude-Session: https://claude.ai/code/session_01H76NN8NDdN4TGw32qi7E18
…cked

A pairing named the first read and write relay in settings whether or not
it was up. With that relay returning 502, Signet could not answer and the
panel said nothing. The panel now asks every read and write relay at once
and names the first that answers, or says that none did.

Signet's approval screen ticks names and keys alone. An approval without
blocks linked nothing and the message did not say what to do. The panel now
says before the pairing which boxes to tick and afterwards which was left.

Found by pairing this branch with the Signet web app over public relays.

Claude-Session: https://claude.ai/code/session_01H76NN8NDdN4TGw32qi7E18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant