Files
amethyst/commons
Claude 90043b1e87 fix(relay-auth): four defects the venue-coverage change introduced
Audit of the previous commit. Each of these is the same shape: an id that
looks like something it isn't.

- A Concord community id is a bare 64-hex string, so `rememberVenueLabel`'s
  public-chat branch took it — and on a POST_VENUE, which is exactly what a
  pending plane wrap now derives, that branch *get-or-creates*. So naming a
  Concord room minted the phantom public chat (plus its metadata subscription)
  this function exists to avoid, then named the room after the phantom's own
  nevent, making the Concord lookup below it unreachable. Both joined-room
  shapes now resolve first, and the community name is read off the folded
  ConcordChannels in LocalCache before the active account's joined list —
  LocalCache is shared by every logged-in account, so a prompt raised for one
  account no longer degrades to a hex prefix while another is on screen.

- `venueHostRelays()` folded the process-wide BuzzWorkspaces singleton into a
  per-account venue set, so every logged-in account auto-authenticated on a
  workspace only one of them joined — silently revealing a bystander account's
  npub where the user used to be asked. `isFirstParty` cannot catch that: the
  Buzz set carries no account. Only per-account list events belong here; the
  workspace's own first-party reason in AuthCoordinator is unchanged.

- A NIP-29 group id is scoped to its host relay and is routinely generic (`_`
  is the spec's relay-wide group), so matching on the id alone let a group we
  merely browsed elsewhere pass for one we joined. The trusted-venue check now
  takes the (relay, venue) pair. A Concord community id is a 64-hex derived
  value that names one community wherever it is served, so it still matches on
  its own.

- Marmot (MLS) carries its group id in an `h` tag exactly like NIP-29, so the
  new rule read a kind-445 send as a post into a room — an opaque MLS id with
  no metadata behind it, 64-hex, and therefore another phantom-channel mint at
  label time. MLS kinds keep their prior reading.

Two allocations out of the auth path while here: only a stream-wrap kind pays
for the plane lookup (it ran per pending event), and the lookup itself is a
membership test on the session rather than a union of its channel and
prior-epoch address sets.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PHCHwnWjVt83Ne3qGBeGq6
2026-08-12 22:28:47 +00:00
..