Skip to content

feat(profiles): show verified agent owner and archive state - #232

Merged
wesbillman merged 5 commits into
mainfrom
peon/profile-agent-identity
Sep 24, 2026
Merged

wesbillman merged 5 commits into
mainfrom
peon/profile-agent-identity

Conversation

@kalvinnchau

@kalvinnchau kalvinnchau commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a Managed by row to the profile Info tab for identities with an agent hint. It matches the base Buzz desktop copy and is shown only when the owner is backed by verifiable relay evidence:

  • Owner: read from the NIP-OA auth tag on the agent's winning signature-verified kind 0. Requires exactly one tag, owner ≠ agent, conditions that hold for the event, and a valid BIP-340 signature over nostr:agent-auth:<agent>:<conditions>. The row shows the owner's name, with " (you)" when the viewer is the owner, and opens the owner's profile.
  • No verified owner (missing/invalid tag, failed read, or no available view): the row is hidden, as in base Buzz. Reopening the profile retries.

Agent type, instructions and archive state are not shown. buzz-app has no reader for type, instructions are out of scope, and archive is an action in base Buzz, not an Info row.

Stale-owner protection

  • The owner comes from a session-owned session.observe view. Verification is bound to the exact winning event id, so an auth-only update or a late older read never keeps or restores a previous owner.
  • While the view is live, the profile directory's retained signed head seeds the choice. Reopening after cache eviction never accepts an older response than the one the session already shows.
  • With no view available (observed-view capacity exhausted), no row is shown instead of an owner the pane cannot keep current.
  • profile-directory now notifies subscribers when the winning signed kind 0 changes even if display fields do not. Before this, a newer auth-free profile restored from disk at startup left an open pane showing the old owner. The snapshot object stays the same when nothing visible changed, so snapshot consumers do not re-render.

Tests

  • owner-attestation.test.ts: tag, condition and signature validation.
  • ProfileAgentIdentity.test.tsx: verified owner row, "(you)", hidden when unverified or unreadable, owner routing, auth-only remove/replace/equal-time updates, eviction and stale reopen reads, purge and account replacement, disk-restore of a newer auth-free profile, and the real observed-view cap (no row while full, row after one slot frees and the profile is reopened, then live updates).
  • Negative controls: reverting the directory notification fails the disk-restore test; removing the no-view gate, the "(you)" suffix, or the verification requirement each fails its tests.

Not covered

Real IndexedDB/browser startup, native packaging and live socket reconnect.

@kalvinnchau
kalvinnchau requested review from a team, comp615 and wesbillman as code owners September 24, 2026 18:54
@kalvinnchau
kalvinnchau force-pushed the peon/profile-agent-identity branch from 74ce296 to f28f486 Compare September 24, 2026 19:24
peon and others added 5 commits September 24, 2026 13:11
Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
…licKey fallback

Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
…view

Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
…changes

The directory suppressed notifications when a newer signed kind 0 kept the
same display fields, so a head restored from disk (store.ts accept) never
re-rendered a mounted agent pane and it kept showing a removed owner.
Notify on winning-event changes and read the head in the pane through
useSyncExternalStore. Adds real view-cap auth-only regressions.

Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Rename the owner row to "Managed by" with "(you)" for the viewer, hide it
unless a verified owner is bound to the latest profile event, and drop the
archive row, matching base Buzz desktop. Verification binding, the live-view
gate, and directory head notification are unchanged.

Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
@kalvinnchau
kalvinnchau force-pushed the peon/profile-agent-identity branch from f28f486 to 89bbe76 Compare September 24, 2026 20:12

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

No blocking defects found. Reviewed head 89bbe768dfbc689cbac85067613a1c020cd72ea6 against base d57f8bf4147b9374a0cff1298ca3e8339a6a52d6, including independent protocol and UI/lifecycle review. This is a comment review, not an approval.

The owner verifier matches the current NIP-OA producer/validator contract. I traced winning-event selection through live/read updates, retained directory evidence, disk restore, asynchronous verification, view capacity and session retirement. Agent hints remain presentation-only; archive/type/instructions are correctly outside this change.

Hosted CI passed 3,019 Vitest tests, 584 Chromium/WebKit journey cases and seven browser measurements, plus Rust/tool integration. Its synthetic merge 288c9d2da3ae2b30768a6bd6150015f207f1dd75 has the same tracked tree as the reviewed head. The new mounted session/crypto tests are appropriate lower-layer coverage; no broad suites were repeated locally.

One non-blocking documentation/test follow-up is inline. The PR body also overstates dedicated owner-specific purge/account-replacement coverage in the new test file. Real IndexedDB startup, live socket reconnect, attended visual acceptance and native packaging remain unverified; Windows native CI was skipped. No code change is required by this review.

Comment thread docs/profiles.md
- The row shows the owner's name (`formatPublicKey` without a profile name),
with "(you)" when the viewer is the owner. It opens the owner's profile in
the same slot when the host can open it.
- A missing or invalid tag, a failed read, or no available view shows no row.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking: qualify “a failed read” as “a failed read with no retained signed profile.” session.observe().refresh() preserves its remote evidence on error, and ProfileAgentIdentity selects from that evidence plus the retained directory head without checking read status. An already-verified owner therefore remains visible after a failed refresh, consistent with the retained name/avatar; this is not an ownership-verification bypass. Please align this sentence and the PR description with that behavior, and add error-with-retained-head / error-without-head cases to make the intended policy explicit.

@wesbillman
wesbillman merged commit 254baae into main Sep 24, 2026
12 checks passed
@wesbillman
wesbillman deleted the peon/profile-agent-identity branch September 24, 2026 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants