feat(desktop): add team sharing to community catalog - #3995
Conversation
5c11456 to
8bd3c8e
Compare
28c614f to
a4c603a
Compare
8ed79f3 to
f573bdc
Compare
wesbillman
left a comment
There was a problem hiding this comment.
Reviewing on Wes's behalf. Requesting changes for two security blockers in the catalog review surface:
-
Verify relay events before they can affect paging, coordinate selection, attribution, or displayed content.
fetchCatalogEventscurrently inserts every rawRelayEventreturned by the socket intobyIdand derivesoldestCreatedAtfrom it;sharedCatalogHeadsthen trusts the rawid,pubkey,created_at, tags, and content.RelayClient.fetchEventsis only a transport fetch and does not verify signatures. A forged/unsigned 30178 event can therefore appear under another publisher, claim or retract their coordinate ahead of a valid signed head, and control the pagination cursor. The backend re-fetch and verification correctly prevents adoption, but it does not protect browsing, publisher attribution, remote image loads, or denial/shadowing of legitimate entries. Please verify ID + signature on a fresh wire-shaped object before adding an event to the paging map or deriving a cursor/head from it, and add regressions for a forged newer head, forged author/content, malformed signature, and an invalid event attempting to controluntil. The equivalent hardening and tests already exist in PR #4220 for kind 30175; this shared helper should preserve that invariant for both 30175 and 30178 rather than regress it. -
Render executable team/member instructions byte-for-byte, not as Markdown, and reject non-reviewable controls at the adoption boundary.
TeamCatalogDialog.tsxpasses bothteam.instructionsandmember.systemPromptthrough the chat Markdown renderer. Markdown can conceal spoiler bodies, link destinations, and image sources, so the instructions reviewed in the dialog can differ materially from the plaintext later executed by the adopted agents. The current team catalog validators only enforce schema/size bounds, so bidi/default-ignorable controls can also make reviewed text differ from execution. Please use the literal instruction-review component/invariant from PR #4220 and apply its executable-text validation to team instructions and every member prompt before publication/adoption. Add coverage proving Markdown syntax stays literal, hidden controls fail closed, and accepted bytes are preserved exactly through adoption.
The feature has unusually substantial coverage otherwise: this head adds/changes 62 test/spec/fixture files, including the Rust adoption/pending/sharing/reconcile suites, TS relay/parser tests, and Playwright catalog/screenshot specs. CI is green at e64aa20ff81e236ca068aab3b9ad93142fb839e3, but the existing fixtures use placeholder sig: "sig" values and therefore do not exercise the first trust boundary.
e64aa20 to
131a906
Compare
3bcca7e to
f869c80
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - Rust tests: team_catalog/tests.rs (999 lines), adopt/tests.rs (999), pending/tests.rs (679), event_sync_team_catalog_tests.rs (436) - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
0acacf4 to
16a1ff3
Compare
f869c80 to
72c1491
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - Rust tests: team_catalog/tests.rs (999 lines), adopt/tests.rs (999), pending/tests.rs (679), event_sync_team_catalog_tests.rs (436) - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
16a1ff3 to
e5e5c2a
Compare
72c1491 to
dc6f777
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - Rust tests: team_catalog/tests.rs (999 lines), adopt/tests.rs (999), pending/tests.rs (679), event_sync_team_catalog_tests.rs (436) - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
e5e5c2a to
5cce7c6
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - Rust tests: team_catalog/tests.rs (999 lines), adopt/tests.rs (999), pending/tests.rs (679), event_sync_team_catalog_tests.rs (436) - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
5cce7c6 to
728ae20
Compare
5362227 to
96335ec
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - Rust tests: team_catalog/tests.rs (999 lines), adopt/tests.rs (999), pending/tests.rs (679), event_sync_team_catalog_tests.rs (436) - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
728ae20 to
9a086df
Compare
96335ec to
7629469
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - persona_events.rs: domination-aware flush for kind:5 tombstones. A tombstone is signed strictly past the future-dated head it retracts, so its retained created_at is the domination floor. The relay ingest gate rejects events beyond ±900s of server time, so a byte-frozen future-dated replay can age out of the acceptance window and strand the head live forever. Flush now re-dates to now when the floor has passed, publishes at the floor when it is within the window, and leaves the tombstone pending to converge when the floor is further ahead than the window — never emitting an event the relay rejects. - Rust tests: team_catalog/tests.rs, adopt/tests.rs, pending/tests.rs (incl. gate tests driving both the 30176 and 30178 tombstones through a stub relay that enforces the real ±900s ingest gate, covering the delayed/offline-retry case), event_sync_team_catalog_tests.rs - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
9a086df to
a66f7fa
Compare
7629469 to
58d52a5
Compare
Implements the backend for 30178 team catalog sharing on the community catalog. No UI callers yet — this PR is the backend half of a two-PR split; desktop PR #3995 (stacked here) adds the TS parse layer, hooks, CommunityCatalogDialog, and e2e. Changes: - team_catalog.rs: 30178 projection builder + size contracts (32 KiB ceiling, per-field bounds, avatar downscaling for raster data URLs); build_team_catalog_event/content, team_catalog_content_from_event, tombstone_team_catalog_coordinate - commands/teams/pending.rs: publish/unshare/tombstone commands with relay-scoped share state; refresh_or_retract_shared_head_at for immediate retraction on member edits that exceed the size contract; persona-edit refresh guard so unrelated personas are never embedded - commands/teams/adopt/: add_team_from_catalog with backend head verification + byte-level rollback across both stores; plan_add with full member provenance (owner, d-tag, member-key, projection-hash); builtin reuse via hint matching; commit_stores atomic writer - event_sync.rs: reconcile_team_catalog_heads_at startup reconcile; republish changed heads, tombstone unrebuildable ones, skip unshared; multi-head continuation so a single pass handles all shared teams - persona_events.rs: domination-aware flush for kind:5 tombstones. A tombstone is signed strictly past the future-dated head it retracts, so its retained created_at is the domination floor. The relay ingest gate rejects events beyond ±900s of server time, so a byte-frozen future-dated replay can age out of the acceptance window and strand the head live forever. Flush now re-dates to now when the floor has passed, publishes at the floor when it is within the window, and leaves the tombstone pending to converge when the floor is further ahead than the window — never emitting an event the relay rejects. - Rust tests: team_catalog/tests.rs, adopt/tests.rs, pending/tests.rs (incl. gate tests driving both the 30176 and 30178 tombstones through a stub relay that enforces the real ±900s ingest gate, covering the delayed/offline-retry case), event_sync_team_catalog_tests.rs - 27 shared JSON parity fixtures (team_catalog_content/) - Existing TeamRecord + AgentDefinition types extended with sharing fields (team_catalog_source, catalog_source, shared flag, etc.) - All commands registered in lib.rs; dormant until UI PR merges Stack: this PR -> #3995 Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
a66f7fa to
6a57da7
Compare
Extend the unified add-agent dialog (#5015) into a single Community Catalog surface that browses both shared agents and shared teams. The dialog keeps sections for personas and teams with type-tagged selection and a teams-preferred launch. TeamsSection's discover entry and the new-agent card both open this one dialog. Teams are decoded from kind 30178 projection events by teamCatalogRelay.ts. Signature verification, shared-tag gating, and coordinate collapse live in the shared catalogRelay.ts seam, so both the persona and team paths reject unsigned or forged heads before projecting. Instruction review renders verbatim in a <pre> on all three surfaces (persona, team, and member instructions) so the text a user reviews is the text sent to the agent. TeamShareDialog publishes and unshares team catalog entries. Playwright e2e covers the unified create/catalog/import navigation, the teams catalog flow, and the screenshot regression set. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
58d52a5 to
76da912
Compare








Stack: #5112 → this PR
Stacks on the team catalog backend PR (#5112). Contains all
desktop/src/**,desktop/tests/**, anddesktop/playwright.config.tschanges — 30 files, +4,276/−985 lines.TS parse layer
teamCatalogRelay.tsdecodes kind 30178 projection events intoTeamCatalogEntryrecords.catalogRelay.tsgeneralizes the persona catalog relay into a shared base that both persona and team catalog hooks extend, eliminating the per-kind duplication in the previous persona-only implementation.Hooks
useTeamCatalogRelay.tssubscribes to the team catalog kind, applies freshness ordering, and exposes the decoded entries.useAgentsDataRefresh.tsgains team catalog invalidation alongside the existing persona refresh path.CommunityCatalogDialog
Single unified surface replacing the two former separate dialogs. Agents and Teams appear as labeled sections; the selection helper (
communityCatalogSelection.ts) handles preferred-loading, vanished-item repair (explicit selection cleared when the encoded key leaves live data), and cross-section auto-init. All selection transitions are covered by 15 deterministic unit tests incommunityCatalogSelection.test.mjs.TeamShareDialog
Publishes and unshares catalog entries via the backend
set_team_sharedTauri command (both share and unshare transitions callset_team_shared).e2e + screenshots
team-catalog.spec.tscovers the full browse + adopt flow.team-catalog-screenshots.spec.tsproduces the 8-image pixel-regression set (comment 5208042093).Deletion
PersonaCatalogDialog.tsxis removed; persona browsing now lives inside the unifiedCommunityCatalogDialog.Follow-ups
A post-merge PR will extend the shared agent-definition text-safety policy (
isSafeAgentDefinitionText— Unicode-control/bidi/zero-width rejection, length bounds) to the team surface: team create/update/adopt/projection parse and memberdisplay_name/system_promptfields, backend plus the frontendmemberPassesV1path. Persona definitions already carry this via #4220; teams currently validate only byte bounds, so this closes the parity gap.