feat(profiles): show verified agent owner and archive state - #232
Conversation
74ce296 to
f28f486
Compare
Co-authored-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
…licKey fallback Co-authored-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
…view Co-authored-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
…changes The directory suppressed notifications when a newer signed kind 0 kept the same display fields, so a head restored from disk (store.ts accept) never re-rendered a mounted agent pane and it kept showing a removed owner. Notify on winning-event changes and read the head in the pane through useSyncExternalStore. Adds real view-cap auth-only regressions. Co-authored-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Rename the owner row to "Managed by" with "(you)" for the viewer, hide it unless a verified owner is bound to the latest profile event, and drop the archive row, matching base Buzz desktop. Verification binding, the live-view gate, and directory head notification are unchanged. Co-authored-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
f28f486 to
89bbe76
Compare
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
No blocking defects found. Reviewed head 89bbe768dfbc689cbac85067613a1c020cd72ea6 against base d57f8bf4147b9374a0cff1298ca3e8339a6a52d6, including independent protocol and UI/lifecycle review. This is a comment review, not an approval.
The owner verifier matches the current NIP-OA producer/validator contract. I traced winning-event selection through live/read updates, retained directory evidence, disk restore, asynchronous verification, view capacity and session retirement. Agent hints remain presentation-only; archive/type/instructions are correctly outside this change.
Hosted CI passed 3,019 Vitest tests, 584 Chromium/WebKit journey cases and seven browser measurements, plus Rust/tool integration. Its synthetic merge 288c9d2da3ae2b30768a6bd6150015f207f1dd75 has the same tracked tree as the reviewed head. The new mounted session/crypto tests are appropriate lower-layer coverage; no broad suites were repeated locally.
One non-blocking documentation/test follow-up is inline. The PR body also overstates dedicated owner-specific purge/account-replacement coverage in the new test file. Real IndexedDB startup, live socket reconnect, attended visual acceptance and native packaging remain unverified; Windows native CI was skipped. No code change is required by this review.
| - The row shows the owner's name (`formatPublicKey` without a profile name), | ||
| with "(you)" when the viewer is the owner. It opens the owner's profile in | ||
| the same slot when the host can open it. | ||
| - A missing or invalid tag, a failed read, or no available view shows no row. |
There was a problem hiding this comment.
Non-blocking: qualify “a failed read” as “a failed read with no retained signed profile.” session.observe().refresh() preserves its remote evidence on error, and ProfileAgentIdentity selects from that evidence plus the retained directory head without checking read status. An already-verified owner therefore remains visible after a failed refresh, consistent with the retained name/avatar; this is not an ownership-verification bypass. Please align this sentence and the PR description with that behavior, and add error-with-retained-head / error-without-head cases to make the intended policy explicit.
Summary
Adds a Managed by row to the profile Info tab for identities with an agent hint. It matches the base Buzz desktop copy and is shown only when the owner is backed by verifiable relay evidence:
authtag on the agent's winning signature-verified kind 0. Requires exactly one tag, owner ≠ agent, conditions that hold for the event, and a valid BIP-340 signature overnostr:agent-auth:<agent>:<conditions>. The row shows the owner's name, with " (you)" when the viewer is the owner, and opens the owner's profile.Agent type, instructions and archive state are not shown. buzz-app has no reader for type, instructions are out of scope, and archive is an action in base Buzz, not an Info row.
Stale-owner protection
session.observeview. Verification is bound to the exact winning event id, so an auth-only update or a late older read never keeps or restores a previous owner.profile-directorynow notifies subscribers when the winning signed kind 0 changes even if display fields do not. Before this, a newer auth-free profile restored from disk at startup left an open pane showing the old owner. The snapshot object stays the same when nothing visible changed, so snapshot consumers do not re-render.Tests
owner-attestation.test.ts: tag, condition and signature validation.ProfileAgentIdentity.test.tsx: verified owner row, "(you)", hidden when unverified or unreadable, owner routing, auth-only remove/replace/equal-time updates, eviction and stale reopen reads, purge and account replacement, disk-restore of a newer auth-free profile, and the real observed-view cap (no row while full, row after one slot frees and the profile is reopened, then live updates).Not covered
Real IndexedDB/browser startup, native packaging and live socket reconnect.