mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
S2 — a `private: true` channel was keyed from community_root at the root epoch, so posts under the Lock icon landed on a plane every member decrypts. Now (CORD-03 §1): - ConcordActions.currentChannelPlane / historicalChannelPlanes derive a private channel only from the held key in the Community List entry's `privateChannels`, bound to the channel epoch; with no key there is no plane at all — never the root-derived one. - The session, subscription planner, plane registry, the app's verbs (send, image, reply, react, edit, typing) and amy all resolve planes through it. A key delivered later is adopted in place (ConcordCommunitySession.adoptPrivateChannels), and keys an invite carries are stored on join. - A keyless private channel is locked: ConcordChannel.keyHeld / canPost() false, the composer is replaced by a notice, and `amy concord send` fails with `no_channel_key` (`channels` reports `readable`). Creating private channels (key delivery) stays open (F7). S3 — deleting your own Concord message went out as a NIP-17 kind 5 to the p-tagged users, leaking the rumor id outside the community, and never reached the channel. Account.delete / deletePrivately now route Concord notes (messages, replies, reactions) to AccountConcordActions.deleteConcordRumors: the in-stream kind 5, sealed 20013 on the plane of each target's bound epoch. Tapping your own Concord reaction again retracts it the same way. S9 — chat ingest (session, typing, ConcordActions.channelRumors) goes through ChannelChat.acceptOpened, and EventCache.consumeConcordRumor refuses non-chat kinds as defense in depth. channelMessages orders by created_at*1000+ms. CORD-03 §3 — your own kind-1111 thread replies can be edited like kind-9 messages. Review statuses updated for S2, S3, S9 (chat half), S10, I13-I16. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PmuzkD5qdqgv6dMeRMoC5N