feat(channels): add channel creation - #138
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2e33dc625f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d50ace6462
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
Changes requested
Reviewed head d50ace64625147ec0dafdf85297696375ade4f5c against stacked base 7c36465d7ebf3295ef20f6698ce90e3e075fb27c. Contract: create ordinary public/private, ongoing/temporary channels through the existing durable outbox and relay authority, then navigate to the joined channel; use private-channel icons consistently. No new relay protocol, ACL model, or metadata-round-trip requirement is needed.
P1: Preserve the pending create identity across dialog and session lifecycles
src/features/relay/session.ts:715–757
The kind-9007 command is durable, but its channel UUID, operation ID and input signature live only in pendingChannelCreation. If publication commits but acknowledgement is lost, reconnecting/reloading replaces this closure while the outbox restores the original operation as unknown. Submitting the same details then calls crypto.randomUUID() and sends a second create instead of confirming/retrying the saved event. Both channels can exist, with the original operation still unresolved. service.ts:50–98 replaces the session; outbox.ts:201–252,501–514 preserves and can retry the original event.
The same missing recovery owner also strands the form without reconnecting: after an uncertain error, close/reopen resets every field (CreateChannelDialog.tsx:48–55), while the retained coordinator rejects any signature different from the now-hidden old values. Preserve a scope-bound pending intent and restore its form values/UUID/operation, using the existing exact-event outbox recovery rather than a new retry subsystem. Regression coverage should include uncertain publication followed by reconnect/reload and dialog close/reopen, asserting no second create identity.
P2: Reject truncated mandatory tag prefixes before indexing them
dev/session-commands.mjs:40–51
For kind 9007 with empty content, a valid timestamp and only [["h", "11111111-1111-1111-1111-111111111111"]], optional-tag validation succeeds and .slice(0, 4).every(...) validates only the present prefix. The following tags[1][1] throws; valid h/name and h/name/visibility prefixes fail similarly at the next missing tag. Both broker sign/publish endpoints call this predicate, so malformed input now reaches the outer 500 Local relay broker failed path instead of the intended 400 rejection. The base's exact-length check prevented this. This is a validation regression, not a signing/ACL bypass. Check mandatory arity before dereferencing and cover all truncated prefixes at the predicate and broker boundary.
Evidence and limits
Source-only review on pinned bare objects with independent authority and UI lanes plus targeted adjudication; no repository code, tests, builds, or live writes were executed by this review. Existing CI run 35763069455 succeeded: its browser jobs checked out synthetic merge bd8479038ae91f58ee5dbaf286e9ef7cb56b09c6, merging this exact head into the pinned base, rather than checking out the head directly. JavaScript reported 201 files / 2,110 tests, and Chromium/WebKit both passed the sidebar dialog journey. That journey opens/closes the dialog; it does not submit through the new recovery coordinator. These green checks do not cover the failure paths above. Native packaging, real-relay TTL behavior, and live create/reconnect acceptance remain unverified here. All three outgoing commits have DCO trailers, and the hosted DCO check passed.
Exit criteria are the two bounded repairs above with regression coverage. Do not expand completion to require matching name/description/TTL readback: the existing contract intentionally applies authoritative membership before optional metadata. The open reserved-description hypothesis is not an open-Session/ACL defect: Session classification also requires relay-authored private metadata.
|
🤖 Addressed both requested changes and pushed d2af0dc.\n\n- Pending channel creation now survives reconnect/reload through the durable outbox, restores the modal after close/reopen, and retries the exact saved event identity.\n- Truncated kind-9007 mandatory tag prefixes now return 400 instead of reaching an internal error, with predicate and sign/publish boundary coverage.\n- Merged current main and retained its current session-search coverage.\n\nValidated with pnpm check, 53 focused unit/integration tests, two affected Chromium sidebar journeys, and the pre-push gate (89 files / 1,288 tests plus design-system guards). |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d2af0dc587
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 029b62b963
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c16e60c41d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0a988333b4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39a8159484
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f4ab023824
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3f0289925d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
Follow-up at 23d0b913f9af5e5effad0884ee690380c2fd75b1 against base 877ae2a6749221dd6850d5695b5c8de023a239e3: changes requested for three recovery defects detailed inline. Merge criteria: preserve unfinished private-creation identity through access-cache purges; make an explicit membership retry consume its new roster result; restore dismissed entries to their original container when persistence fails. These are local fixes within the existing outbox/session owners, not a request for a new protocol or access grants.
The broker-prefix and dialog form-retention fixes remain present. Source-only follow-up with an independent persistence review: existing exact-head CI passed, Windows native validation was skipped, and this review executed no tests, builds, or real-relay acceptance.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2c612a1670
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cfaefce691
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
Follow-up: recovery blockers resolved in source
Reviewed cfaefce69173c26f7f22a97437323df031dbacf7 against base 877ae2a6749221dd6850d5695b5c8de023a239e3, focusing on the five-file delta since 23d0b913f9af5e5effad0884ee690380c2fd75b1 and its agreed recovery exit criteria.
- Ordinary private-channel creation receipts now survive access purge/hydration without granting membership or content access. Retry preserves the original operation; creator membership still gates completion, not optional metadata.
- Initial membership inspection no longer rejects a fresh retry on the previous roster error. Failed dismissal restores retained receipts to confirmed storage rather than promoting them into pending writes. Regression tests cover these repairs in source; they were not executed here.
- Validation remains open: source-only review on pinned Blox objects, with no repository-code execution or CI reruns. GitHub reports merge conflicts and no main CI evidence for this exact head; DCO/security checks passed. Older green CI does not validate this delta, and runtime/native acceptance is unverified.
No actionable code blocker found in this follow-up. Nonblocking documentation follow-up: describe the narrow unfinished ordinary-creation receipt exception in docs/relay-queries.md, retaining its read-visibility boundary.
Resolve conflicts while preserving these repairs and satisfy exact-head CI/reviewer gates before merging. This is a source-review comment, not approval or a merge-readiness claim.
cfaefce to
d820533
Compare
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
d820533 to
39cc184
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39cc1849d2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
wesbillman
left a comment
There was a problem hiding this comment.
Carl, an automated reviewer, commenting via Wes’s GitHub account.
No remaining source-review blockers at 39cc1849d2ac8c57a2177c3ced75de1b2e731cea against ba41020800b32737d8804ce9a9f98a4e9a5ef25e. The rebase preserves the previously verified recovery repairs: unfinished ordinary creation identity survives access purge/hydration, membership retry ignores only the prior read error, and failed dismissal restores the original receipt container. Broker-prefix validation and dialog draft/navigation behavior remain intact. All three independent review lanes returned; no new material defect found.
Source and regression-test inspection only; no local suites or live writes executed. At the CI snapshot for this head, JavaScript, browser measurements, DCO and security checks passed; Rust/tool integration and Chromium/WebKit journeys were still running, and Windows native validation was skipped. This is not an all-green CI claim. Live relay creation/reconnect/TTL behavior and packaged-native acceptance remain unverified. The prior nonblocking receipt-exception documentation note remains a follow-up.
Finish the outstanding CI/reviewer gates before merging. This is a comment, not formal approval or a merge-readiness claim.
…search-send * origin/main: Connect attachments to existing message delivery (#176) perf: preserve unchanged thread row identities (#171) perf: cache markdown preparation by content (#172) Add safe attachment upload groundwork (#150) feat: add sampling profiler launch modes (#148) feat(channels): remove DMs from the sidebar (#157) Distinguish namesake agents and selected recipients (#142) feat(channels): move diagnostics into Channel Settings (#163) Replace warning banners with shared Base UI toasts (#164) feat(shortcuts): add keyboard shortcut settings (#155) fix(channels): give floating unread cue an opaque panel surface (#153) feat(communities): add BUZZ_DEV_OPEN_RELAY to open the default relay on fresh dev ports (#151) Restore recipient avatars beside the composer mention tool (#162) Fix startup inventory duplication and late panel scroll shifts (#160) feat(channels): add channel creation (#138) Standardize Button and IconButton with Buzz design tokens (#145) Signed-off-by: Zach Marley <zmarley@squareup.com>
Summary
Snapshots
Private channel and sidebar actions
Create channel
Testing
Dependency