Commit Graph
2326 Commits
Author SHA1 Message Date
Taylor Ho 321047feb9 fix(desktop): align workflows sidebar styling
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 10:30:55 -07:00
Taylor Ho 4212f22c23 Improve workflow DM channel labels
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 10:30:28 -07:00
Taylor Ho fa962ed48e Show message content in workflow filters
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 10:03:26 -07:00
Taylor Ho bbd0df4a69 Refine workflow condition spacing
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 09:58:37 -07:00
Taylor Ho 705a0b566d Refine workflow filter editing
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 09:51:14 -07:00
Taylor Ho 4c2a83e90a Polish workflow author picker
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 09:39:51 -07:00
Taylor Ho 934e2b7eb3 Refine workflow filter controls
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 09:32:46 -07:00
Taylor Ho 2dcb090b61 Polish workflow trigger filters
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 09:22:22 -07:00
Taylor Ho dfdde30d87 Align workflows layout with agents page
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 00:55:15 -07:00
Taylor Ho b2761d893d Refine workflow card hover state
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 00:30:10 -07:00
Taylor Ho 2af66ff0ad Simplify workflow card footer
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 00:23:01 -07:00
Taylor Ho 0d92496f69 Add workflow enable toggle to card menu
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 00:21:19 -07:00
Taylor Ho 37f288942b Polish workflow index labels
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-14 00:17:35 -07:00
Taylor Ho d52292870e Polish workflow trigger labels
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:46:52 -07:00
Taylor Ho b6df66007a Hide unsupported workflow actions
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:46:35 -07:00
Taylor Ho a9229f370a Test simplified workflow equality labels
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:45:55 -07:00
Taylor Ho 5d6ac15476 Simplify workflow equality labels
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:45:01 -07:00
Taylor Ho 8be1947168 Remove workflow step conditions from form
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:39:44 -07:00
Taylor Ho c92338cde0 Clarify workflow author ID pagination
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:28:17 -07:00
Taylor Ho 7075eba33e Show workflow step details
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:27:19 -07:00
Taylor Ho 4a5bff2614 Clarify workflow text conditions
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:18:36 -07:00
Taylor Ho 4f6ccb2890 Polish workflow trigger presentation
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:15:00 -07:00
Taylor Ho 5c4a43ec22 Improve workflow trigger details
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 23:09:03 -07:00
Taylor Ho b09299e0ae Add workflow message picker
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 22:49:22 -07:00
Taylor Ho 5cdbf19fd1 Clarify workflow step conditions
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 22:41:31 -07:00
Taylor Ho 314cfd0b7b Polish workflow trigger conditions and sequence editor
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 22:35:03 -07:00
Taylor Ho 2d51c6beef Limit workflow ID conditions to equality
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 22:07:35 -07:00
Taylor Ho 21268599d6 Clarify workflow condition defaults
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 21:50:32 -07:00
Taylor Ho 13c9c73ffa Polish workflow condition selectors
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 21:45:13 -07:00
Taylor Ho c463f043e4 Polish workflow message inputs
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:12:38 -07:00
Taylor Ho ac175010fa Polish workflow landing cards
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:12:37 -07:00
Taylor Ho 0e6a04fafd Mark unsupported workflow actions
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:12:37 -07:00
Taylor Ho a97b0aa0d0 Label unsupported workflow reaction action
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:12:36 -07:00
Taylor Ho 3cf827b844 Use emoji picker across workflow fields
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:12:35 -07:00
Taylor Ho 20073b3a9d feat(workflows): polish conditions and fix listing
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:12:34 -07:00
Taylor Ho 75c6336818 fix(desktop): simplify monthly schedule warning
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:55 -07:00
Taylor Ho 604b9b7390 feat(desktop): improve workflow schedule picker
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:54 -07:00
Taylor Ho a6e7e05b6e Guard unsaved workflow changes
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:53 -07:00
Taylor Ho 03e8542648 Fix workflow node selection styling
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:53 -07:00
Taylor Ho a6ad61851d Simplify workflow inspector copy
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:52 -07:00
Taylor Ho 487745a667 Refine workflow inspector hierarchy
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:52 -07:00
Taylor Ho 1eb1921b07 Polish workflow builder interactions
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:51 -07:00
Taylor Ho b883ac557b Redesign workflow editor
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:51 -07:00
Taylor Ho 75019b0906 Polish workflow creation form
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
2026-08-13 14:11:50 -07:00
b269e8df7e fix(desktop): route compact preview geometry fixture through media proxy (#5799)
**Category:** fix (CI)
**User Impact:** None — test-only change that unblocks `main` and every
open PR.

**Problem:** `main` has been red since #5629 landed on `45f4b91a3`:
`Desktop Smoke E2E (3)` fails `compact link preview image geometry
truncates long titles to one line` on every build (main run 31727837133,
and e.g. #5792, #5790). Two independently-green PRs raced: #5629 added
the test stubbing its preview image at the raw relay origin
(`http://localhost:3000/media/*.png`), while #5627 rewrites sent
snapshot media through the authenticated local media proxy
(`http://127.0.0.1:54321` in the E2E mock bridge). Merged together, the
image request goes to the proxy origin, the stub never matches, and
`naturalWidth` stays `0`.

**Solution:** Point the route stub at the mock proxy origin, matching
the existing `sent link preview media uses the authenticated proxy in
compact and rich cards` test in the same spec.

**Testing:** Reproduced the failure locally on `45f4b91a3`, then with
this fix: targeted test passes, and the full `messaging.spec.ts` smoke
suite passes 58/58.

Signed-off-by: Thomas Petersen <thomasp@squareup.com>
Co-authored-by: Wintermute <3f1797424fd9ad6653a83665c660517777cd7f8c228c0d5907f49e01537f3ca5@buzz.block.builderlab.xyz>
2026-08-13 13:42:16 -07:00
2693e0db1f Make workflow run history authoritative in Desktop (#5780)
## Summary

- persist stable workflow run `error_code` values separately from human
diagnostics
- expose NIP-98 authenticated, channel-authorized run history and
approval reads with stable keyset pagination
- connect Desktop to those authoritative reads and return the
relay-created run ID on trigger
- show truthful loading, failure, and pending-trace states, and do not
render approval actions from non-actionable stored hashes

## Validation

- pre-push `branch-skew`, `desktop-typecheck`, `desktop-test`,
`rust-tests`, `desktop-tauri-checks`, and `desktop-check` all passed on
`a097dbe5f`
- Desktop tests: 4,761 passed, 0 failed
- `cargo check -p buzz-relay`
- `git diff --check`

## Remaining gate

This does not claim a relay-backed Playwright workflow journey. The
browser relay bridge still routes workflow invokes through in-memory
handlers; that production-shaped acceptance gate remains follow-up work
before Workflows can leave preview.

---------

Signed-off-by: Wes <wesbillman@users.noreply.github.com>
Co-authored-by: Carl <c7ebe626f000404285d3686e1dc74cc07cc60a9754a150041ba132e14bd3e2ec@buzz.block.builderlab.xyz>
Co-authored-by: Mongo <5c25403eab7271f9f94ddd4f2b270e8cac2c92e2c830c51877cca6ec974ffb3f@buzz.block.builderlab.xyz>
Co-authored-by: Princess Donut <68157ebd23b3897c1991015c3038658ea916200c67d3a54620b0754d1b92f6e0@buzz.block.builderlab.xyz>
mobile-v0.11.0-rc.1
2026-08-13 12:56:37 -07:00
45f4b91a36 fix(desktop): more compact "compact" link previews (#5629)
**Category:** improvement
**User Impact:** Compact link previews now use a single-line title and
smaller thumbnail, making conversations easier to scan.

**Problem:** Compact previews gave long titles and oversized thumbnails
too much visual weight in the message timeline.

**Solution:** Keep titles to one ellipsized line and reduce image
thumbnails to a 104×64 treatment while preserving the existing wide
aspect ratio; Rich previews remain unchanged.

<details>
<summary>File changes</summary>

**desktop/src/shared/ui/compact-link-preview-attachment.tsx**
Tightens the Compact presentation with a single-line title and smaller
wide thumbnail, leaving Rich previews untouched.

**desktop/tests/e2e/messaging.spec.ts**
Adds focused coverage for title overflow, exact 64px card and 104×64
thumbnail geometry, and successful decoded-image rendering using a
realistic fixture, plus an optional visual capture.

**desktop/tests/fixtures/github-pr-5629-og.png**
Provides realistic visible image bytes for the compact-preview
image-rendering E2E path.

</details>

## Reproduction steps

1. Launch the desktop app with link preview style set to Compact.
2. Send a link whose preview has an image and a long title.
3. Confirm the thumbnail renders at the smaller wide size and the title
truncates to one line with an ellipsis.
4. Switch link preview style to Rich and confirm its presentation is
unchanged.

## Screenshot

![Compact link preview at 64px tall with a decoded real-image thumbnail
and one-line truncated
title](https://d24qwcpro867f5.cloudfront.net/repos/buzz/prs/5629/compact-link-preview-real-image-64px.png)

---------

Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
Co-authored-by: Carl <acda9e433d19dcd0e6b6840f7f4b98f3a56f1fab98049d444c087019e6d36560@buzz.block.builderlab.xyz>
2026-08-13 10:51:49 -07:00
98d3d77b42 Fix mobile composer input regressions (#5594)
## Summary

- reuse the channel member snapshot so first-use `@` suggestions appear
immediately
- reduce selection-only composer rebuilds so iOS selection handles stay
responsive
- make Return insert a newline, send only from the composer button, and
animate multiline growth with reduced-motion support

## Validation

- `just mobile-check`
- `just mobile-test` — 1,271 tests passed
- signed iPhone Release and Pixel 10 debug builds installed and launched
- `just ci` passed mobile, Rust, desktop, and web checks until the
unrelated `buzz-terminal` lifecycle test timed out waiting for `$0`;
reproduced unchanged in isolation

---------

Signed-off-by: kenny lopez <klopez4212@gmail.com>
Signed-off-by: Fast Fizz <2df81cb51f05a9d5387ef24d7b9ecb8fcdfcd1c70ffabc67061c9596e1b5b1c4@buzz.block.builderlab.xyz
Signed-off-by: Fast Fizz <2df81cb51f05a9d5387ef24d7b9ecb8fcdfcd1c70ffabc67061c9596e1b5b1c4@buzz.block.builderlab.xyz>
Co-authored-by: Fast Fizz <2df81cb51f05a9d5387ef24d7b9ecb8fcdfcd1c70ffabc67061c9596e1b5b1c4@buzz.block.builderlab.xyz>
2026-08-13 17:58:29 +01:00
8abc2baf0b Add mobile community invites (#5641)
## Summary
- add a permission-gated mobile community invite page
- create, copy, and natively share configurable invite links
- invite a validated npub directly with member/admin role selection
- reuse Buzz profile actions, search styling, settings rows, and modal
sheets

## Validation
- `just mobile-check`
- `flutter test` (1,275 tests)
- Pixel and iPhone review builds installed and launched

---------

Signed-off-by: kenny lopez <klopez4212@gmail.com>
Signed-off-by: Kenny Lopez <klopez4212@gmail.com>
Signed-off-by: Fast Fizz <2df81cb51f05a9d5387ef24d7b9ecb8fcdfcd1c70ffabc67061c9596e1b5b1c4@buzz.block.builderlab.xyz>
Co-authored-by: Carl <3c4caeafb646d23867f1c4832e68211d77e2561946171625f75c3ce1a3f2670f@buzz.block.builderlab.xyz>
Co-authored-by: Fast Fizz <2df81cb51f05a9d5387ef24d7b9ecb8fcdfcd1c70ffabc67061c9596e1b5b1c4@buzz.block.builderlab.xyz>
2026-08-13 17:47:44 +01:00
Alex RosenzweigandGitHub a96af89526 Harden shared agent instruction review (#4220)
## Summary

- render shared-agent instructions as literal text so Markdown cannot
conceal spoiler contents, link destinations, or image sources
- reject non-reviewable Unicode controls at every agent-definition
boundary while preserving legitimate rendered emoji sequences
- verify shared catalog event IDs and signatures before trusting
authorship, coordinates, pagination, or executable content
- preserve the exact system-prompt bytes between review and execution
instead of silently stripping or normalizing content

## Security rationale

Shared system prompts are executable configuration. Previously, catalog
prompts were projected through the chat Markdown renderer, which could
hide text, replace link destinations with benign labels, and turn image
syntax into remote loads. Zero-width and bidirectional controls could
also make reviewed text differ from what the agent executes.

This change establishes a review invariant: the prompt a user sees is
the prompt the agent executes. Definitions that cannot be reviewed
faithfully are rejected rather than rewritten. Catalog events must also
pass Nostr ID/signature verification before they can claim a publisher,
coordinate, or cursor.

## What changed

- catalog instructions render as exact literal text rather than rich
Markdown
- catalog relay events are verified on a fresh wire-shaped object before
paging, coordinate selection, attribution, or projection
- forged content, pubkeys, signatures, and invalid newer heads are
ignored and cannot shadow a valid signed definition
- TypeScript catalog parsing rejects unsafe remote definitions before
they reach the UI
- shared Rust validation covers persona create/update/import, inbound
relay sync, definition-less managed-agent sync, and catalog publication
paths
- definition-less managed agents now fail closed on local create, local
update, and publication before persistence or relay retention
- linked managed agents validate their local name while treating the
persona definition as authoritative; their inert record-level prompt is
not executed or published
- names reject layout controls; prompts retain ordinary newlines and
tabs
- legitimate emoji composition is supported, including contextual VS16,
ZWJ, skin-tone, family, flag, and keycap sequences
- detached selectors/joiners, bidirectional controls, tag characters,
zero-width concealment, and other default-ignorables remain rejected
- names are bounded to 128 characters and prompts to 64 KiB
- contributor guidance documents the byte-for-byte review requirement
for future sharing paths

Validation reports the offending code point and never silently removes
it.

## E2E recording


[buzz-shared-agent-security-e2e.webm](https://github.com/user-attachments/assets/44d6b75f-0877-490f-bda4-a716fae3f700)

The recording demonstrates:

- a safe definition remains visible
- a prompt containing zero-width `U+200B` is rejected
- a name containing bidi override `U+202E` is rejected
- the prompt is preserved exactly
- spoiler, link, and image syntax remains literal and does not render or
load

## Verification

Passed locally:

- `just test`: all 10 unit and Docker-backed integration stages
- desktop frontend unit suite: 4,295 tests
- persona catalog relay unit suite: 32 tests, including forged-event and
cursor-shadowing cases
- focused Rust definition-validation coverage: 3 local create/update
tests and 6 publication-filtered tests
- complete desktop Tauri library suite after rebase: 2,263 passed, 14
ignored, 0 failed
- desktop Tauri clippy with warnings denied and Rust formatting
- complete agent Playwright spec: 34 tests
- the exact formerly failing `inbox-edit` immediate-attachment smoke
test after rebase: 1 test
- focused shared-agent publish, literal-review, hidden-control,
signature, and cross-member import Playwright coverage
- desktop E2E production build and TypeScript typecheck
- changed-file formatting/lint and file-size ratchet
- pre-commit secret scan and DCO signoff

The branch was rebased onto current `main`, which includes the upstream
attachment-button label fix. Fresh post-rebase GitHub CI is green for
every required and selected check: Desktop Core, all four Desktop Smoke
E2E shards, both Desktop E2E Integration shards and their aggregate,
Desktop E2E Relay, Desktop Build (macOS), Windows Rust, Rust Lint, DCO,
security scanners, and Desktop Release Candidate. The previously failing
`Desktop Smoke E2E (3)` shard now passes.

The repository-wide desktop check also reports existing CSS
formatting/`!important` findings in `components.css` and `terminal.css`;
neither file is changed by this PR. GitHub's Desktop Core lint and
format stage passes on the rebased branch.

---------

Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
2026-08-13 13:11:45 +10:00