mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
The bridge top_level channel-window filter (handle_channel_window_filter) passed all window rows to the response without an author-only guard. Since next_cursor and has_more are computed at the DB layer before any in-memory filtering, a bridge-level skip would still expose draft ids via the 39006 bounds overlay and leave has_more counts inflated by draft rows. Fix: add an author_pubkey param to get_channel_window. When Some, the query appends AND (e.kind NOT IN (30300, 31234) OR e.pubkey = $N), excluding author-only kinds (KIND_DRAFT=31234, KIND_EVENT_REMINDER=30300) for rows whose pubkey does not match the requester. This keeps the cursor, has_more, and all overlay values computed against the already-restricted row set. Pass Some(&pubkey_bytes) from handle_channel_window_filter via the new pubkey_bytes parameter; internal / test callers pass None. Tests: two new e2e tests in e2e_nip37_draft.rs: - test_channel_window_draft_excluded_for_non_author: mixed kinds:[9,31234] query by a channel member who is not the author must return zero draft rows and zero draft ids anywhere in the response (rows, aux, overlays). kind:9 positive control row must still be present. - test_channel_window_draft_visible_to_author: the author sees their own kind:31234 draft in the window, consistent with all other author-only read paths. Closes the last unguarded author-only read surface identified in code review of PR #1757. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>