Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 3 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,8 +145,9 @@ request-owned, cancelled on disconnect and cleaned before admission is released.
Picker/paste/drop share the same tab-local draft. Files must finish uploading
before Send; navigation pauses unfinished uploads for explicit Retry. Reload loses
unsent files. Background Send, attachment-first new sessions and UX polish are
separate work. Live uploads currently use the development broker, not a packaged
native upload implementation.
separate work. Live uploads use the development broker in dev runs and the
native `relay_upload` path in packaged desktop builds. Packaged HEIC and non-MP4
video files are not converted by the broker and may be rejected by the relay.

The broker supports reads, live traffic and basic message sending **as your real
account**. Profile changes and invite admission can also write to real communities.
Expand Down
19 changes: 15 additions & 4 deletions docs/identity.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,10 +94,21 @@ authentication. Events older than 15 minutes get a strong ID readback instead of
being republished or silently re-dated. Missing/failed readback retains uncertainty;
the user must inspect the conversation before explicitly sending a new message.

Optional capabilities are absent until implemented: protected media/upload,
repository HTTP and other broker-only
helpers are not claimed by this adapter. Public HTTPS avatars/icons can display;
protected media does not gain access from the image CSP allowance. NIP-FI assertion
Protected media and uploads are native, because the webview cannot attach Blossom
(kind 24242) authentication itself: `<img>`, `<video>` and `<audio>` send no custom
headers, and the CSP keeps `connect-src` closed to general HTTPS. Relay `/media/`
URLs selected by shared TypeScript render through the `buzz-media` URI scheme,
which validates HTTPS and the `/media/<hash>` URL shape but does not enforce
saved-community membership; the selected server receives a short-lived token
scoped to its origin. The scheme signs a fresh 60-second `get` token per request
and forwards only a bounded single `Range`; non-image/video/audio types (and SVG)
are served with download disposition and `nosniff`. The main webview does not navigate to protected media for downloads: a narrowly scoped native command authenticates the bounded media GET, saves to the OS Downloads directory without replacing existing files, and rejects unsafe filenames. `relay_upload`
hashes, signs (`upload` + `x`) and sends the exact bytes JavaScript passes it;
shared TypeScript (`hostUpload`) owns limits, error mapping and descriptor
validation. JavaScript never signs kind 24242. HEIC and non-MP4 video conversion
remain dev-broker-only (ffmpeg), so those files upload unconverted and the relay
may reject them. Repository HTTP and other
broker-only helpers are not claimed by this adapter. NIP-FI assertion
acquisition is not implemented, so deployments enforcing it are outside acceptance.
Windows/Linux custody, credential migration and release-signing acceptance remain
separate limitations.
Expand Down
1 change: 1 addition & 0 deletions src-tauri/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ hmac = "0.12"
base64 = "0.22"
reqwest = { version = "0.13", default-features = false, features = ["rustls"] }
url = "2"
percent-encoding = "2"
tauri-plugin-dialog = "2"
tauri-plugin-opener = "2"
tauri-plugin-updater = "2"
Expand Down
3 changes: 3 additions & 0 deletions src-tauri/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,9 @@ fn main() {
"relay_agent_observer",
"relay_agent_memories_read",
"relay_agent_library",
"relay_upload",
"relay_upload_cancel",
"media_download",
"get_os_idle_seconds",
"plugin_import_folder",
"plugin_import_git",
Expand Down
3 changes: 3 additions & 0 deletions src-tauri/capabilities/default.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,9 @@
"allow-relay-agent-observer",
"allow-relay-agent-memories-read",
"allow-relay-agent-library",
"allow-relay-upload",
"allow-relay-upload-cancel",
"allow-media-download",
"allow-get-os-idle-seconds",
"allow-plugin-import-folder",
"allow-plugin-import-git",
Expand Down
3 changes: 3 additions & 0 deletions src-tauri/src/browser_permissions_tests.rs
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,9 @@ fn native_command_permissions_allow_only_main_webview() {
"relay_agent_observer",
"relay_agent_memories_read",
"relay_agent_library",
"relay_upload",
"relay_upload_cancel",
"media_download",
"get_os_idle_seconds",
"plugin_import_folder",
"plugin_import_git",
Expand Down
14 changes: 10 additions & 4 deletions src-tauri/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -18,10 +18,11 @@ use os_idle::get_os_idle_seconds;
mod relay;
use identity::{identity_create, identity_export, identity_import, identity_restore, IdentityHost};
use relay::{
relay_agent_library, relay_agent_log_proof, relay_agent_memories_read, relay_agent_observer,
relay_agent_resolve, relay_channel_publish, relay_channel_sign, relay_decode_sidebar,
relay_direct_message, relay_http, relay_kit_decode, relay_kit_prepare, relay_kit_sign,
relay_sign, relay_sign_sidebar, relay_workflow_runs,
media_download, relay_agent_library, relay_agent_log_proof, relay_agent_memories_read,
relay_agent_observer, relay_agent_resolve, relay_channel_publish, relay_channel_sign,
relay_decode_sidebar, relay_direct_message, relay_http, relay_kit_decode, relay_kit_prepare,
relay_kit_sign, relay_sign, relay_sign_sidebar, relay_upload, relay_upload_cancel,
relay_workflow_runs,
};
mod terminal;
use agent_models::{agent_models_begin, agent_models_cancel, agent_models_run, ModelHost};
Expand Down Expand Up @@ -393,6 +394,9 @@ fn commands<R: tauri::Runtime>() -> impl Fn(tauri::ipc::Invoke<R>) -> bool + Sen
relay_agent_observer,
relay_agent_memories_read,
relay_agent_library,
relay_upload,
relay_upload_cancel,
media_download,
get_os_idle_seconds,
plugin_import_folder,
plugin_import_git,
Expand Down Expand Up @@ -508,6 +512,8 @@ pub fn run() {
};
builder
.manage(IdentityHost::default())
.manage(relay::Uploads::default())
.register_asynchronous_uri_scheme_protocol("buzz-media", relay::media_protocol)
.manage(Imports::default())
.manage(HarnessSetup::default())
.manage(Terminals::default())
Expand Down
Loading
Loading