Skip to content

feat: attach sanitized image and opt-in diagnostics to feedback - #245

Merged
kalvinnchau merged 10 commits into
mainfrom
am/feedback-media
Sep 25, 2026
Merged

kalvinnchau merged 10 commits into
mainfrom
am/feedback-media

Conversation

@kalvinnchau

@kalvinnchau kalvinnchau commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Stack 2 on #242. Attaches sanitized images and opt-in diagnostics to private kind 42000 feedback using the session-bound ordinary media uploader, matching Buzz Desktop. Text enters the deployment feedback inbox; uploaded media remains subject to ordinary deployment media-read policy, not inbox-only access. Images upload when selected, diagnostics only when explicitly opted in at send, and closing/removing/discarding does not remotely delete uploads.

Upload policy alignment

Kalvin explicitly accepted using the ordinary Blossom media upload path for feedback images and opt-in diagnostics to match block/buzz Desktop, rather than requiring new operator-only attachment storage for this parity change. Feedback text remains in the private kind 42000 inbox; attachments follow the deployment’s ordinary media-read policy and are not operator-only. The UI discloses this before image selection and warns that removing or discarding feedback does not delete uploaded blobs. Desktop source trace: block/buzz at 20131488528e35e6c50f4ccdb0490a9135c28edf, desktop/src/features/settings/hooks/useSendFeedback.ts → desktop/src-tauri/src/commands/media.rs (PUT /upload). This records the accepted access tradeoff, not proof of deployed media policy or native execution.

Implementation

  • Keep feedback preparation outside relay protocol; preserve broker validation of tenant-local imeta, signed event, and session/destination/cancellation fences.
  • Gate upload on a scoped writable feedback session. Default diagnostics off; no channel membership gate for this channel-less operation.
  • Disclose media visibility and non-deletion before selection and at local discard confirmation.

Evidence and deferred

  • Rebased on feat: add private text feedback plugin #242 head 8d1fd8c and main 6fa0e9a. At head 725fdae: typecheck, full Vitest package suite (326 files, 3,554 tests, two workers), and pre-push selected checks passed. The unbounded Vitest run timed out in an unrelated Vite-config subprocess; its isolated rerun and bounded full run passed. Node integration test run was blocked by offline Cargo cache missing bech32; do not count it as pass.
  • Synthetic broker and component/session fixtures exercise bounded tags, upload affordances, diagnostics opt-in, retry and disclosure. No faithful isolated relay/media workflow, packaged-native run, Desktop native workflow, or tenant cross-read probe has run at this head. Keep draft pending these and hosted CI; prior CI results were on old heads.

No browser cases added or removed. Do not interpret green source-level tests as remote media confidentiality.

@kalvinnchau
kalvinnchau added this pull request to stack #246 September 24, 2026 22:13
@kalvinnchau
kalvinnchau force-pushed the am/feedback-media branch 2 times, most recently from 725fdae to c5c6beb Compare September 25, 2026 01:42
@kalvinnchau
kalvinnchau force-pushed the am/feedback-media branch 3 times, most recently from 6e11970 to 3ba0f12 Compare September 25, 2026 04:32
@kalvinnchau
kalvinnchau marked this pull request as ready for review September 25, 2026 05:19
@kalvinnchau
kalvinnchau requested review from a team, comp615 and wesbillman as code owners September 25, 2026 05:19

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord automated source review, published via Wes’s account.

One actionable P2 finding is attached inline: edits made while diagnostics upload is pending are silently omitted from the sent feedback.

Reviewed head: 31006baf5e28c49b39d20e5db02ce084cd812afc
Base / merge-base: af82c6c9949a7a9c6effc1a5b64229789312db92 (#242).

Reviewed the incremental diff and traced the account-dialog owner, image sanitization, session-bound upload, feedback serialization, broker validation, outbox retry/dismissal, and added tests. Preserved the documented ordinary-media-access/non-deletion product decision. Pinned Git objects only; no dirty source inputs.

Source-only: no tests, PR-code execution, app launch, uploads, or CI verification. Real relay/media delivery, packaged-native behavior, and Desktop parity remain unverified. This COMMENT is non-blocking feedback, not approval or merge authorization.

Comment thread src/bundled/feedback/FeedbackDialog.tsx
Base automatically changed from am/feedback-text to main September 25, 2026 18:45

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord’s automated source review, published via Wes’s account.

No new actionable findings in this follow-up. The prior P2 (draft edits lost during diagnostics upload) is addressed in source: FeedbackDialog.tsx:358,371 disables both category selection and the textarea throughout busy. The existing submission/close/unmount paths retain their attempt and cancellation fences, and the outbox captures pending intent synchronously before the editing state is released.

The deferred-upload regression at FeedbackDialog.test.tsx:552–597 waits for upload entry, asserts the text/category controls are disabled and no send has occurred, releases the upload in finally, then checks one send with the original text/category and diagnostics descriptor. Reviewed the real shared-control prop forwarding, account-dialog caller, error/retry/close lifecycle, and relevant incoming-base interactions. This is a follow-up to review 5320509145, not a reopening of the accepted ordinary-media visibility/non-deletion policy.

Reviewed head: 695340480dc10e9f183883f50a3f9a70d97e4b34
Base / merge-base: f761867ed81f25604933620f9b4747a871a69c04

Source-only, using pinned Git objects with no dirty source inputs. No tests, PR-code execution, installs, app launch, or media uploads performed. One read-only CI snapshot reported JavaScript/browser measurements successful, but Rust/tool integration and browser journey shards still in progress; Windows validation was skipped. No CI waiting or runtime/native acceptance is implied. Real relay/media delivery, packaged-native behavior and Desktop parity remain unverified. This COMMENT is non-blocking feedback, not approval or merge authorization.

am and others added 6 commits September 25, 2026 12:26
Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
am and others added 4 commits September 25, 2026 12:26
Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Keep one attempt fence for dismissal, preparation, and uploads; assert serialized diagnostics preflight at the admitted boundary.

Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Retain caller/session cancellation and verify that channel loss and cache clearing do not abort a channel-less feedback upload.

Co-authored-by: Kalvin Chau <kalvin@block.xyz>

Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Co-authored-by: Kalvin Chau <kalvin@block.xyz>
Signed-off-by: Kalvin Chau <kalvin@block.xyz>
@kalvinnchau
kalvinnchau merged commit e52ec14 into main Sep 25, 2026
14 checks passed
@kalvinnchau
kalvinnchau deleted the am/feedback-media branch September 25, 2026 19:49
johnmatthewtennant pushed a commit that referenced this pull request Sep 28, 2026
* origin/main:
  feat: attach sanitized image and opt-in diagnostics to feedback (#245)
  test: repair three baseline Vitest failures (#276)
  fix(agents): recover status polling and scope failure diagnostics (#283)
  Share avatar editing across community profiles and managed agents (#271)
  feat(profiles): archive, unarchive and delete agents from the profile pane (#256)
  ci: run browser journeys on three shards per engine (#280)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/agents/AgentEditor.tsx
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants