Skip to content

🤖 docs(nip-fi): remove implementation references from the spec - #7912

Merged
wpfleger96 merged 3 commits into
mainfrom
hayt/nip-fi-spec-s4-deny
Sep 28, 2026
Merged

wpfleger96 merged 3 commits into
mainfrom
hayt/nip-fi-spec-s4-deny

Conversation

@wpfleger96

@wpfleger96 wpfleger96 commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

This removes implementation references and implementation status from docs/nips/NIP-FI.md so the spec holds normative text only. It drops the Blossom compliance note, the known-gap notes, crate/file paths and PR numbers, roadmap "supersedes" sentences, doc-history lines, and the design-rationale note on session-only vs deny-until-TTL (its restart re-push SHOULD remains stated normatively elsewhere).

Two wording changes carry normative weight: PUT /media/upload is listed as a plain kind-24242 upload route instead of a temporary alias, and the JWKS fetcher's SSRF controls become a MUST instead of a description.

It doesn't depend on any enforcement PR and can merge at any time.

Related: #7265

…nown-gap note

The deny_protected row documents repair-mode behaviour main's code already
has. The known-gap paragraph is stale once #7265 wires the real deny map.

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
@wpfleger96
wpfleger96 requested a review from a team as a code owner September 26, 2026 15:40
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Sep 26, 2026
@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is ebe99a46e8802b9ff20fdf6a1028ce93bdefaa43...10abcb4feb135367d64824d5824ba8a4a0475dee.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review 10abcb4feb135367d64824d5824ba8a4a0475dee to authorize a new review.
Any previous review applies only to its recorded range.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

No blocking findings in this documentation-only patch. Reviewed head a481ea8bfee64468e5b1bbc7a56b43b946d6f27c against base 781d39510cf23cfe224e8f521ae06a23377e06de.

The new denial row preserves the existing fixed HTTP 503 contract. The Blossom note removal is correct under the stated merge order: merge #7265 first, then this PR. That prerequisite is still open; its inspected head ad4174b03247ee7cf9290d7cdb18615144ed90b5 replaces the shared admission stub with the issuer-scoped deny map. The separate Blossom verifier gaps remain documented.

Source-only validation: complete diff and PR-text/privacy scan, HTTP denial mapping, Blossom upload/GET/HEAD pairing, and prerequisite wiring. No PR code, builds, or tests executed. One optional wording correction is inline; no runtime/client behavior changes here.

Comment thread docs/nips/NIP-FI.md Outdated
The spec holds normative text only; compliance notes, crate paths, and PR
numbers belong in code and PR history.

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
@wpfleger96 wpfleger96 changed the title 🤖 docs(nip-fi): document deny_protected denial and drop stale Blossom known-gap note 🤖 docs(nip-fi): remove implementation references from the spec Sep 28, 2026
@github-actions github-actions Bot removed the codex-security-review-current The posted Codex security review matches its recorded range. label Sep 28, 2026
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Sep 28, 2026
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
@github-actions github-actions Bot removed the codex-security-review-current The posted Codex security review matches its recorded range. label Sep 28, 2026
@wpfleger96
wpfleger96 enabled auto-merge (squash) September 28, 2026 16:54
@wpfleger96
wpfleger96 merged commit 447951a into main Sep 28, 2026
36 checks passed
@wpfleger96
wpfleger96 deleted the hayt/nip-fi-spec-s4-deny branch September 28, 2026 16:56
wpfleger96 pushed a commit that referenced this pull request Sep 28, 2026
* origin/main:
  🤖 docs(nip-fi): remove implementation references from the spec (#7912)
  fix(relay): fail startup on invalid operator listener config (#7933)
  fix(db): limit event transactions to listener mention kinds (#7932)
  feat(relay): deliver pubkey mentions to relay companions (#7793)
  docs(protocol): propose simplified channel artifacts (#7791)
  feat(push): support configurable HTTP(S) delivery URLs (#7877)
  fix(ci): select runtime suites from PR changes only (#7843)
  test(desktop): synchronize upload edit smoke test (#7903)

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
johnmatthewtennant pushed a commit that referenced this pull request Sep 28, 2026
…in-ui

* origin/main:
  test(desktop): wait for channel head refresh before paging thread summary test (#7955)
  🤖 perf: bound long-thread aux reads and make query deadlines terminal (#7854)
  Add native HPKE encryption for nsec backups (#7849)
  test(desktop): scope video menu e2e probes to emitted messages (#7953)
  Add owner deletion admission control plane (#7818)
  fix(sidebar): converge stale-at-open state across devices (sections/sort/stars/mutes) (#7805)
  feat(nip-fi): harden Blossom kind-24242 verifier to NIP-FI spec (#7288)
  Make relay readiness process-local (#7341)
  🤖 docs(nip-fi): remove implementation references from the spec (#7912)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

This branch was successfully deployed

1 active deployment
codex-review — 10abcb4f Deployed Sep 28, 2026 by wpfleger96 via Run Codex Security Review #5954
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants