Refactor local signing into async delegates - #295
Draft
bradseiler wants to merge 1 commit into
Draft
bradseiler wants to merge 1 commit into
bradseiler wants to merge 1 commit into
Conversation
Signed-off-by: Brainy Bumble <seiler@block.xyz>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Buzz's host broker signs relay events directly with a local nsec. That synchronous boundary cannot support a future NIP-46 signing server.
What
Move local signing into an asynchronous delegate selected by the captured relay and viewer identity. Update broker callers to await signing, authorization, and publication while preserving current local-key behavior.
How
The local delegate uses the existing key and bound HTTP or socket transport. Validation, admission, receipts, retries, key lifetime, and encryption stay with their existing owners. Callers recheck cancellation, authentication freshness, and session lifetime after signing where required. Regression tests hold signing and publication to verify ordering and failure paths.
Risk
This touches broker signing for messages, profiles, presence, uploads, Git authentication, account binding, read state, sidebar preferences, and member commands. Async boundaries can expose cancellation and session races. The patch is intended to preserve behavior; it adds no NIP-46 client or remote identity support.
Testing
No manual testing against a production relay or real Keychain. Human acceptance and hosted checks are pending; keep this PR in draft.
Known gaps from the local full browser run: 710 passed and 2 failed. Chromium diff-preview focus timed out in
tests/browser/diffs.spec.mjs:102; an unchanged complete-file rerun passed. WebKit image scrolling timed out waiting for wheel/scrollend intests/browser/timeline.mjs:65; its complete-file rerun also failed the static helper control. Root causes remain unproven. Those fixtures and checked UI paths are unchanged from the tested base, and their traces do not load the modified signing broker. No browser cases were added or removed.The reviewed snapshot is based on
80511fa86c2543e10447779c451ecfaf4652bff6. Current main was checked for overlap and a clean merge; hosted checks will validate the merged tree.Bigger picture
This establishes the asynchronous signing boundary for a later NIP-46 delegate. Remote signing, identity loading, and encryption remain separate work.
Generated with Codex