mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Desktop: mint a server-scoped kind-24242 t=get Authorization header (BUD-01: server tag, no x tag; 600s expiration) from the app's signing keys and attach it in the localhost media proxy, the buzz-media:// scheme handler, and the media download/import fetch path. Fail-open to an unsigned request when signing keys are unavailable (recovery mode), so media keeps rendering while the relay's read-auth flag is off. Dev MCP: view_image detects relay-hosted /media/ URLs (host + effective port must match BUZZ_RELAY_URL; ws/wss default ports compare equal to http/https) and attaches the same t=get header signed from BUZZ_PRIVATE_KEY. Never signs for non-relay origins, so the bearer token cannot leak to third parties. An unauthenticated 401/403 names the missing key in the error. Client lanes for the authenticated-media-GET rollout; the relay-side verifier (BUZZ_REQUIRE_MEDIA_READ_AUTH) lands separately. Co-authored-by: Tyler Longwell <tlongwell@block.xyz> Signed-off-by: Tyler Longwell <tlongwell@block.xyz>