Skip to content

feat(messages): delete messages authored by owned agents - #680

Merged
johnmatthewtennant merged 12 commits into
mainfrom
glm/agent-owner-message-delete
Oct 8, 2026
Merged

johnmatthewtennant merged 12 commits into
mainfrom
glm/agent-owner-message-delete

Conversation

@johnmatthewtennant

@johnmatthewtennant johnmatthewtennant commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Why

People can remove their own messages, but cannot remove a message authored by an agent they own. This adds the same deliberate removal control for verified agent owners.

What

  • Show Delete message only when the viewer's ownership of the message's agent is verified from the agent's signed NIP-OA profile.
  • Keep the explicit confirmation and warn that copies may remain elsewhere. After confirmation, publish the existing NIP-09 deletion request as the owner.
  • Fold owner-authorized deletions for agent messages out of the timeline. Reaction deletion remains author-only, and the relay remains the authorization authority.

Reviewer-reproducible examples

The browser journey creates ephemeral viewer and agent identities and a signed NIP-OA ownership profile, then exercises the built app against an isolated broker fixture:

source bin/activate-hermit
pnpm test:browser tests/browser/owned-agent-message-deletion.spec.mjs --project chromium --project webkit --no-deps

The test opens the owned agent's message actions, checks the confirmation and its copy warning, confirms deletion, and asserts that the message disappears and the viewer publishes a kind-5 event targeting that message. It also captures the menu and confirmation shown below.

Real-staging acceptance at 52ea99da (deletion product code unchanged at the current head) verified owner-confirmed deletion, non-owner UI denial and relay rejection, removal from independently read channel history, and an off-channel observer's owned-agent unread count 0 → 1 → 0. The owner could not remove the agent's reaction.

Screenshots

Owner deletion against staging

Recorded at 52ea99da with disposable identities and messages.

OWNED_AGENT_DELETION.mp4

Owned agent message actions

Owner agent message actions

Confirming deletion

Confirming owner agent message deletion

Luna and others added 12 commits October 6, 2026 17:41
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>
…ge-delete

* origin/main:
  feat: add mobile pairing Settings plugin (#595)
  Cache the floating action bar's MediaQueryList (#652)
  feat(messages): copy and paste mentions, channel refs and links (#579)
  Remember desktop window size and position across launches (#655)
  fix(messages): show verified workflow ownership separately from signer (#663)
  fix(activity): collapse duplicate channel-wide agent indicators (#664)
  docs: make native development the acceptance path (#666)
  Sign plugin releases with NIP-PS (#465)

Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>

# Conflicts:
#	src/features/relay/session.ts
#	src/features/relay/unread.test.ts
#	src/features/relay/unread.ts
…ge-delete

* origin/main: (23 commits)
  feat(agents): default conversation context to each thread (#646)
  Name browser host and separate development tooling (#699)
  test(archive): stamp expiry fixtures with one fixed time (#697)
  feat(messages): list Mark unread above Copy message (#638)
  fix(messages): link credential-free http:// URLs like https:// (#691)
  refactor(hooks): replace custom wiring with standard Lefthook hooks (#641)
  fix: deduplicate working agent indicators in composers (#687)
  feat(messages): click images to zoom in the gallery viewer (#688)
  fix(media): serve ranged buzz-media reads from shared signed blocks (#690)
  fix(messages): exclude row chrome from cross-message copies (#645)
  docs: Add kind 30177 publishing guidance for plugin authors (#558)
  feat(agents): allow creating agents with Claude Code
  feat: Enroll Builderlab remote agents (30177) to community (#647)
  Enroll Builderlab agents with the selected community during attestation (#642)
  fix(messages): restore main typecheck for pasted mentions (#684)
  Install the bundled Buzz CLI skill on desktop startup (#667)
  refactor: share status, DM and sidebar intent policy across hosts (#683)
  fix(sessions): show enabled page in navigation (#648)
  fix(composer): replace exact emoji shortcodes on closing colon (#584)
  refactor(mentions): let the Mentions plugin own what the chooser offers (#669)
  ...

Signed-off-by: Opus <f425b86c3b780d43f8d9cf1802429d04dd985bf92eac44fca9468b5ad3887c5e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/features/messages/MessageManagement.tsx
Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>
@johnmatthewtennant

Copy link
Copy Markdown
Contributor Author

Validation update for pushed head 1341d72:

  • Normal pre-push hooks passed (types, related unit tests: 186 files / 3,874 tests, design guards); DCO check passed. Fresh CI is running.
  • Full mentions file: Chromium 5/5 passed. Initial Blox WebKit run: 5/5 failed in newPage before application assertions; this is not a passing both-engine result.
  • Isolated blank-page WebKit probe reproduced “Could not create EGL display: no supported platform available.” Pointing EGL vendor discovery and DRI driver discovery at the task-local extracted Mesa files fixes the blank-page probe. Full Chromium + WebKit mentions validation is now rerunning with those runtime paths; no repository changes or assertion skips.
  • Prior real-staging owned-agent deletion and natural unread reconciliation acceptance was at 52ea99d; product code is unchanged by 1341d72 (only the approved keyboard interaction in mentions.spec.mjs changed).

PR remains draft and unmerged. Saved-team mouse/layout defect remains separately deferred.

@johnmatthewtennant

Copy link
Copy Markdown
Contributor Author

Follow-up at pushed head 1341d72: the full mentions run now executes both browsers after the task-local EGL runtime correction. Result: 9/10 passed (Chromium 5/5, WebKit 4/5). Saved-team keyboard case passes in both engines. Remaining WebKit failure is the existing recipient/tool geometry assertion at mentions.spec.mjs:363: received 3px vertical difference, expected <=2px. This is now an application assertion, not the earlier newPage runtime blocker. Comparing base 656fa91 under the same runtime to establish attribution; no assertions relaxed and no product changes. Fresh CI monitoring remains active. PR remains draft/unmerged; prior real-staging owner-delete/unread acceptance remains valid at product-identical 52ea99d.

@johnmatthewtennant
johnmatthewtennant marked this pull request as ready for review October 8, 2026 18:16
@johnmatthewtennant
johnmatthewtennant requested a review from a team as a code owner October 8, 2026 18:16

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes needed: [P2] Remove internal links from the public PR description. The staging-recording link under “Reviewer-reproducible examples” exposes an internal deployment address and returns HTTP 401; “Related issue” links to private coordination. Replace these with a sanitized, publicly accessible recording and self-contained issue context (or a public issue). The two attached fixture screenshots do not need this change.

No additional actionable production-code findings from this source pass.

— Star Lord automated source review via Wes’s account (wesbillman). Head 1341d72efd22913e48369a1647e6e761b46347bf; base 656fa91a0348b43a8fbbfd51eedfeddc1e1ca2d3. No tests/app execution; CI not checked. Video and linked issue content were inaccessible; staging acceptance and runtime/focus behavior remain independently unverified.

@johnmatthewtennant

Copy link
Copy Markdown
Contributor Author

Addressed the public-description finding: removed the authenticated internal recording URL and private issue link. The description now provides self-contained context and a privacy-checked recording hosted as a GitHub attachment (anonymous HTTP 200), while retaining the existing public fixture screenshots. Acceptance remains explicitly scoped to the tested product-code head; no source changes or new test runs were needed. The updated PR-template review passed.

AI-generated by Sol.

@johnmatthewtennant
johnmatthewtennant merged commit 2630e04 into main Oct 8, 2026
22 checks passed
@johnmatthewtennant
johnmatthewtennant deleted the glm/agent-owner-message-delete branch October 8, 2026 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants