Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
186 commits
Select commit Hold shift + click to select a range
0720f53
Downgrade desktop Huddles to audio protocol v2 (#6610)
klopez4212 Aug 23, 2026
2d28037
perf(desktop): persist channel heads, collapse thread reads and reply…
tlongwell-block Aug 24, 2026
17af15e
fix(desktop): keep member runtime status off the UI thread (#6445)
matt2e Aug 24, 2026
72ba987
fix(desktop): stabilize members dialog scrolling (#6670)
matt2e Aug 24, 2026
2f13e30
fix(desktop): hide selection formatting tray on composer right-click …
matt2e Aug 24, 2026
0e69b3f
show mention counts in channel notifications (#6696)
tulsi-builder Aug 24, 2026
26f4c3e
feat(mobile): browse and join open channels (#6243)
brow Aug 24, 2026
01091c1
fix(mobile): recover stale and shuffled messages (#6691)
wesbillman Aug 24, 2026
db5617d
fix(desktop): emit singular `mention` feed category so alerts route c…
morgmart Aug 24, 2026
9f55bf6
fix(desktop): align jump-to-latest pill with composer height (#6606)
tellaho Aug 24, 2026
a029853
Add mobile profile editing (#6583)
klopez4212 Aug 24, 2026
6eff84d
fix(mobile): join starter channels after accepting invite (#5915)
brow Aug 24, 2026
4bf8097
fix(messages): route edits to the owning composer (#6575)
tellaho Aug 24, 2026
f6e6617
fix(desktop): bound thread /query and surface load errors, not false-…
wpfleger96 Aug 24, 2026
f79d346
fix(composer): wrap Buzz chip labels without orphaning icons (#6581)
tellaho Aug 24, 2026
02dc49f
docs(security): route reports through private advisories (#6728)
jmecom Aug 24, 2026
69b1225
fix(ci): prevent poisoned Rust caches (#6618)
wesbillman Aug 24, 2026
30d2fc5
fix(desktop): restore icon-only remote marker (#6491)
wesbillman Aug 24, 2026
c5166f2
feat(desktop): simplify the message action rail (#6529)
morgmart Aug 24, 2026
e760c51
feat(workflows): discover trigger filter values (#6712)
tellaho Aug 25, 2026
8d2d0ff
Centralize replaceable event persistence (#6660)
TheSentinel454 Aug 25, 2026
a8e1c66
fix(desktop): polish inline chip states (#6718)
tellaho Aug 25, 2026
822c5ab
Hide Huddles in mobile agent DMs (#6676)
klopez4212 Aug 25, 2026
9aa332a
Add inline profile camera capture (#6680)
klopez4212 Aug 25, 2026
8b81201
Fix mobile Huddle agent voice turn states (#6611)
klopez4212 Aug 25, 2026
9d1e4b2
Extract community persistence (#6668)
TheSentinel454 Aug 25, 2026
931747c
Add staging dev relay image workflow (#6709)
bradseiler Aug 25, 2026
a121907
feat(buzz-agent): gate LLM tool calls on session/request_permission (…
wpfleger96 Aug 25, 2026
bb5b935
Fix TipTap editor mount race (#6779)
klopez4212 Aug 25, 2026
d12dea4
Support community deletion in versioned media buckets (#6738)
bradseiler Aug 25, 2026
9b6a637
fix(desktop): make lightbox zoom controls interactive (#6710)
kalvinnchau Aug 25, 2026
29f2054
highlight search terms in results and messages (#6702)
tulsi-builder Aug 25, 2026
12f3fea
revert fixed mention highlight (#6716)
tulsi-builder Aug 25, 2026
113a33b
Add database pressure observability (#6700)
TheSentinel454 Aug 25, 2026
a526dca
feat: navigate images across message threads (#6705)
kalvinnchau Aug 25, 2026
7ba1197
feat(desktop): persist agent addressing across composer messages (#6714)
tellaho Aug 25, 2026
f249710
Qualify canonical relay images for staged delivery (#6781)
TheSentinel454 Aug 25, 2026
b58de7c
fix(desktop-messages): preserve inline agent mentions with persistent…
tellaho Aug 25, 2026
22f32c9
docs(nest): make commit attribution policy-neutral (#6707)
wesbillman Aug 25, 2026
ee6ca5f
Remove public relay signing key fallback (#6729)
jmecom Aug 25, 2026
7a1b7d8
chore(release): release Buzz Desktop version 0.5.19 (#6828)
wpfleger96 Aug 25, 2026
cae7f82
fix(ci): check out source in docker.yml merge job (#6833)
wpfleger96 Aug 25, 2026
820a858
fix(release): attribute desktop candidates to the operator (#6831)
wpfleger96 Aug 25, 2026
e8cd751
fix(desktop): respect automatic mention preference after send (#6837)
tellaho Aug 25, 2026
8471049
feat(desktop): add KLIPY GIF search to composers (#5554)
klopez4212 Aug 25, 2026
52621c0
chore(release): release Buzz Desktop version 0.5.20 (#6839)
wpfleger96 Aug 25, 2026
e8172b5
feat(desktop): hyperlink selected composer text on link paste (#6684)
matt2e Aug 26, 2026
4f529a4
fix(desktop): prioritize sidebar channel status (#6861)
matt2e Aug 26, 2026
db514b1
fix(desktop): stop pulsing addressed agents on send (#6873)
matt2e Aug 26, 2026
dcee330
Fix Admin feedback filter overflow (#6825)
TheSentinel454 Aug 26, 2026
ef0d202
refactor(db): finish replaceable event store extraction (#6777)
TheSentinel454 Aug 26, 2026
583af02
fix(cli): preserve signatures in event reads (#6884)
wesbillman Aug 26, 2026
f177f49
Use paired tags for standing & per-turn context (#6701)
salman1993 Aug 26, 2026
22cdda4
feat(desktop): restore message quick reactions (#6892)
morgmart Aug 26, 2026
de188eb
feat(projects): add agent and CLI project-home support (#6590)
thomaspblock Aug 26, 2026
4f554b6
feat(sidebar): prioritize unread DMs in overflow navigation (#6842)
tellaho Aug 26, 2026
01c87a3
Apply access policy when reusing channel agents (#6838)
jmecom Aug 26, 2026
8f3566a
Deduplicate ACP thread prompt context (#6706)
salman1993 Aug 26, 2026
03bfc83
fix(desktop-tooltip): increase surface contrast (#6897)
tellaho Aug 26, 2026
eb8e97c
fix(desktop): show edited head content in thread panel (#6887)
salman1993 Aug 26, 2026
79df468
Add Buzz benchmark evaluation layers (#6823)
salman1993 Aug 26, 2026
ceb8ba6
fix(desktop): accent-colored mention badges that count thread mention…
tulsi-builder Aug 26, 2026
cdab765
Add gated security reviews (#6816)
jmecom Aug 26, 2026
cada302
fix(desktop): keep project sheets independent from threads (#6901)
thomaspblock Aug 27, 2026
b622003
broker: define the agent-to-broker action contract (#6742)
baxen Aug 27, 2026
c856be0
fix(desktop): keep the draft space when typing right after a mention …
matt2e Aug 27, 2026
4d77175
fix(client): resurface hidden DMs from live activity (#6885)
klopez4212 Aug 27, 2026
b3baa56
fix(db): exclude kind:30179 ciphertext from brownfield FTS (#6822)
tlongwell-block Aug 27, 2026
27c1a7c
Fade expanded video controls on hover (#6926)
klopez4212 Aug 27, 2026
9176e34
fix(projects): allow owners to delete agent projects (#6533)
wesbillman Aug 27, 2026
82e7480
chore(deps): update ubuntu:24.04 docker digest to 33ceb71 (#6664)
renovate[bot] Aug 27, 2026
30596d3
chore(deps): update dependency @tanstack/react-virtual to v3.14.10 (#…
renovate[bot] Aug 27, 2026
525007a
chore(deps): update dependency vitest to v4.1.11 (#6667)
renovate[bot] Aug 27, 2026
c363ce1
chore(deps): update rui314/setup-mold digest to 7e4f20a (#6663)
renovate[bot] Aug 27, 2026
0ccf934
fix(db): disable heartbeat vacuum truncation (#6898)
TheSentinel454 Aug 27, 2026
745ff60
Fix Codex security review authorization (#6913)
jmecom Aug 27, 2026
0808ab4
fix(cli): enrich template cardinality error with per-candidate presen…
wpfleger96 Aug 27, 2026
69096c9
preserve channel description paragraph breaks (#6946)
tulsi-builder Aug 27, 2026
57216c9
test(db): use canonical channel roster fixtures (#6819)
TheSentinel454 Aug 27, 2026
be8d775
feat(agent): discover Databricks Unity Catalog models (#6918)
kalvinnchau Aug 27, 2026
ae0ecd9
feat(model-capabilities): humanize Databricks UC model families (#6955)
wpfleger96 Aug 27, 2026
a7c7414
feat(desktop): implement 30178 team catalog backend (#5112)
wpfleger96 Aug 27, 2026
80177e4
fix(ci): bump Codex CLI to 0.150.1 to unhang security review jobs (#6…
wpfleger96 Aug 27, 2026
350caf1
fix(desktop): lift right auxiliary pane above shared header backdrop …
wpfleger96 Aug 28, 2026
9733863
perf(desktop): restore project context during startup (#6939)
thomaspblock Aug 28, 2026
b496758
fix(desktop): resolve exact typed mentions on space (#6862)
matt2e Aug 28, 2026
953a179
feat(auth): add NIP-FI canonical assertion verifier and contracts (#6…
wpfleger96 Aug 28, 2026
e76c819
refactor(db): split channel membership store (#6782)
TheSentinel454 Aug 28, 2026
86b9142
refactor(relay): NIP-98 admin auth with Operator/Moderator roles and …
wpfleger96 Aug 28, 2026
58cc4b7
Fix mobile jump-to-latest flicker (#6807)
klopez4212 Aug 28, 2026
a89f5df
fix(desktop): complete project empty and context states (#6980)
thomaspblock Aug 28, 2026
ed11c8d
Refresh mobile utility surfaces and theme picker (#6944)
klopez4212 Aug 28, 2026
2f66ee2
feat(desktop): add team sharing to community catalog (#3995)
wpfleger96 Aug 28, 2026
a373078
refactor(db): extract domain stores from database runtime (#6987)
TheSentinel454 Aug 28, 2026
c432a11
feat(mobile): push notifications MVP (#6269)
brow Aug 28, 2026
b593c7d
perf(mobile): reduce cold startup and channel rendering delays (#6996)
wesbillman Aug 28, 2026
2c99ee7
fix(desktop): resolve bundled sidecar on cheap path and bound login-s…
wpfleger96 Aug 28, 2026
8dbc65d
fix(composer): polish automatic mentions (#6956)
tellaho Aug 29, 2026
00e61ea
fix(desktop): surface channel history load failures (#7013)
thomaspblock Aug 29, 2026
eed74bd
feat(buzz-agent): surface stop reason and silent-turn WARN in telemet…
wpfleger96 Aug 29, 2026
c3132c3
feat(desktop): use segmented controls for channel creation (#6845)
matt2e Aug 31, 2026
3ed623b
feat(db): configurable writer session timeouts (lock, idle-txn, state…
TheSentinel454 Aug 31, 2026
e47690c
Enforce NIP-OA authorization time bounds (#7004)
jmecom Aug 31, 2026
f463e72
fix: retrieving cold memories; add regression task (#6950)
philazar Aug 31, 2026
17ecf0b
fix(ci): salvage Codex review output on PTY-shutdown hang (#7042)
wpfleger96 Aug 31, 2026
bc006f6
feat: render agent avatars as squircles (#7106)
mahanti Aug 31, 2026
93237b4
fix(acp): wake agents from workflow messages (#6953)
wesbillman Aug 31, 2026
2f3dd85
fix(relay): reject a frame on its own acknowledgement channel (#6961)
wesbillman Aug 31, 2026
5673c33
feat(desktop): add protected-build Bestie experiment (#6902)
mahanti Aug 31, 2026
cb31449
add public descriptions to agent personas (#7126)
tulsi-builder Aug 31, 2026
b47b5a5
fix(desktop): back split thread headers (#7137)
thomaspblock Aug 31, 2026
4952f58
docs: add review-proven failure-path & async-state rules to AGENTS.md…
jedwards27 Aug 31, 2026
674c173
feat(buzz-acp): give each channel thread its own agent session (#6732)
salman1993 Aug 31, 2026
9ab1631
feat(db): add NIP-FI identity and final-admission schema foundation (…
wpfleger96 Aug 31, 2026
0affe52
fix(model-capabilities): humanize databricks goose model names (#7135)
kalvinnchau Sep 1, 2026
4a9de1a
feat(desktop): add isolated named demo builds (#6407)
loganj Sep 1, 2026
571c190
fix(desktop): scope composer autocomplete to focus (#6860)
matt2e Sep 1, 2026
59328d5
feat(desktop): add thread-scoped ACP session experiment (#6909)
salman1993 Sep 1, 2026
114dbf7
Add voice notes to desktop messages (#6978)
klopez4212 Sep 1, 2026
bd73490
ci: run PostgreSQL tests in isolated lane (#6730)
TheSentinel454 Sep 1, 2026
ac4aa94
Hide download action on voice notes (#7182)
klopez4212 Sep 1, 2026
70895b3
feat(buzz-auth): add production NIP-FI federated assertion runtime (#…
wpfleger96 Sep 1, 2026
e17a0d4
fix(dev): keep the canonical profile when launching from desktop/ (#7…
wesbillman Sep 1, 2026
cae158c
fix(dev-mcp): extend shell timeout cap to 20 minutes and align outer …
wpfleger96 Sep 1, 2026
4365883
chore(ci): lower Codex security review effort (#7179)
wpfleger96 Sep 1, 2026
b270437
fix(mobile): isolate extension linker flags; complete iOS build in CI…
brow Sep 1, 2026
4794a5c
ci: relax file-size ceilings by surface (#6485)
wesbillman Sep 1, 2026
42b4244
feat(mobile): prepare `buzz-push-gateway` for deployment (#7158)
brow Sep 1, 2026
e5a7e26
fix(desktop): preserve keyring identity during recovery (#7203)
wesbillman Sep 1, 2026
5aed49b
feat(buzz-agent): add DatabricksAuthCoordinator single-flight OAuth (…
wpfleger96 Sep 1, 2026
42aeb15
feat(desktop): add Pi agent preset (#7208)
salman1993 Sep 1, 2026
beb7640
feat(relay): add detailed readiness metrics (#7149)
ravarora2 Sep 1, 2026
d4420eb
docs(nip-fi): rewrite NIP-FI as stateless OSS Buzz spec v2 (#7214)
wpfleger96 Sep 1, 2026
560fea7
feat: add databricks fable 5.1 model capabilities (#7213)
kalvinnchau Sep 1, 2026
1c8321c
fix(desktop): retain automatic mentions only in threads (#7144)
tellaho Sep 1, 2026
0e87866
ci: split CI into reusable workflows (#7168)
TheSentinel454 Sep 2, 2026
2af9773
fix(acp): replace real user name in base prompt mention example (#7250)
wpfleger96 Sep 2, 2026
04babf0
chore(db): drop Phase-A NIP-FI relay-side authority ledger (#7221)
wpfleger96 Sep 2, 2026
0dbd036
feat(agents): harness-agnostic effort write path and spawn bridge (#4…
wpfleger96 Sep 2, 2026
434dafe
fix(desktop): discover authenticated owned relay agents (#7122)
loganj Sep 2, 2026
83e5962
fix(desktop): keep explicit agent profiles bound to their exact key (…
loganj Sep 2, 2026
91ab9d3
Add operation-aware database pool acquisition metrics (#7195)
ravarora2 Sep 2, 2026
b6dc533
fix(composer): align wrapped inline chip fragments (#7242)
tellaho Sep 2, 2026
187df22
docs(nip-fi): adopt deny-until-TTL and extend enforcement to HTTP ing…
wpfleger96 Sep 2, 2026
6f60932
fix(desktop): harden profile batch and thread-reply fetches against r…
wpfleger96 Sep 2, 2026
ac5a186
feat(desktop): add persistent Bestie experience (#7223)
mahanti Sep 2, 2026
47d068e
feat(cli): add buzz gifs command group and NIP-30 emoji tags on messa…
wpfleger96 Sep 3, 2026
c328202
docs(nip-fi): document Git smart-HTTP credential exemption (#7268)
wpfleger96 Sep 3, 2026
44d19f5
fix(desktop): preserve spacing after multi-word mentions (#7128)
loganj Sep 3, 2026
d5a73b9
fix(desktop): derive agent availability from relay presence (#7127)
loganj Sep 3, 2026
5073e07
fix(desktop): unify owned-agent cloud provenance markers (#7129)
loganj Sep 3, 2026
40220d5
perf(desktop): publish mention sends before waking agents (#7154)
matt2e Sep 3, 2026
6f5ec4a
Add mobile voice notes (#7121)
klopez4212 Sep 3, 2026
c6ca9d9
Show status and huddle indicators beside names (#7112)
klopez4212 Sep 3, 2026
7a9a523
🤖 fix(desktop): harden smoke E2E tests against Bestie overlay and toa…
wpfleger96 Sep 3, 2026
6cf514e
fix(desktop): wrap message tables within the available pane (#7279)
loganj Sep 3, 2026
752cbfc
docs(nip-fi): add Blossom kind-24242 media possession-proof exception…
wpfleger96 Sep 3, 2026
8868787
feat(relay): add early startup lifecycle logs (#7258)
ravarora2 Sep 3, 2026
8e7b275
fix(scripts): copy global-agent-config.json in buzz-adopt-prod-agents…
wpfleger96 Sep 3, 2026
75f101d
chore(release): release Buzz Desktop version 0.5.21 (#7301)
wpfleger96 Sep 3, 2026
2ac0aa1
Collapse contiguous join messages (#7262)
TheSentinel454 Sep 3, 2026
4b0744d
test(desktop): await Bestie drag and profile hover endpoints (#7294)
loganj Sep 4, 2026
b1f6b7e
feat(desktop): preserve mentions across copy and paste (#7228)
matt2e Sep 4, 2026
01bacb8
chore(release): release Buzz Desktop version 0.5.22 (#7308)
wpfleger96 Sep 4, 2026
cd02b69
refactor(relay): extract NIP-29 membership authorization (#7285)
TheSentinel454 Sep 4, 2026
ee883d7
fix(desktop): bind duplicate mention selections to exact recipients (…
loganj Sep 4, 2026
ce9decb
fix(acp): rename system tag to agent-instructions (#7332)
salman1993 Sep 4, 2026
d595806
fix(desktop): authorize remote mentions at publication (#7124)
loganj Sep 4, 2026
e7e2993
feat(desktop): invite owned agents from standalone forums (#7125)
loganj Sep 4, 2026
b17c077
fix(buzz-acp): bound busy-owner hold to prevent cross-channel starvat…
wpfleger96 Sep 4, 2026
e09f715
Verify ACP relay events before prompt routing (#7010)
jmecom Sep 4, 2026
5d10783
Persist video playback speed preference (#7336)
morgmart Sep 4, 2026
4afef86
fix(desktop): restore mention chip identity icons (#7338)
loganj Sep 4, 2026
4beffef
feat(buzz-acp): update base prompt; add buzz context and skills to Pi…
salman1993 Sep 4, 2026
4d447b9
Add generic information-flow control core (#7293)
jmecom Sep 4, 2026
f038cbb
fix(sidebar): simplify unread indicators and emphasize priority activ…
tellaho Sep 4, 2026
dad5a33
fix(desktop): keep packaged frontendDist relative so Windows embeds a…
jhedlund Sep 5, 2026
3c7f288
chore(release): release Buzz Desktop version 0.5.23 (#7381)
wesbillman Sep 5, 2026
7417dd8
Merge block/buzz upstream through v0.5.23
branarakic Sep 7, 2026
78da9de
Disable upstream-only privileged review triggers
branarakic Sep 7, 2026
434ccd5
Harden fork CI after upstream sync
branarakic Sep 7, 2026
1ef9c84
Format merged desktop discovery tests
branarakic Sep 7, 2026
56103de
Harden upstream HTML handling
branarakic Sep 7, 2026
3038fe0
Validate agent avatar preview URLs
branarakic Sep 7, 2026
0b37bbd
Use OriginTrail GHCR paths in fork builds
branarakic Sep 7, 2026
d7eb34a
Stabilize workflow step smoke test
branarakic Sep 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
41 changes: 41 additions & 0 deletions .config/nextest.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
nextest-version = "0.9.136"
# The PostgreSQL lane uses a run-scoped desired-state template database and a
# per-test wrapper, both of which require nextest's script support.
experimental = ["setup-scripts", "wrapper-scripts"]

[scripts.setup.postgres-template]
# Bootstrap the desired-state source database once per nextest invocation.
command = { command-line = "scripts/postgres-test-setup.sh", relative-to = "workspace-root" }
slow-timeout = "60s"

[scripts.wrapper.postgres-isolation]
# Clone or create a unique database for each test process, then drop it on exit.
command = { command-line = "scripts/postgres-test-wrapper.sh", relative-to = "workspace-root" }

[profile.postgres-ci]
# This structural convention keeps new PostgreSQL-backed tests discoverable
# without maintaining an exact list of test names.
default-filter = """
(test(/postgres_tests::/) or binary(/^postgres_/))
and not test(/(^|::)external_infra[^:]*::/)
"""
fail-fast = false
# Eight workers was the fastest stable setting in the Blox benchmark while the
# wrapper retained one database per concurrently running test process.
test-threads = 8

[test-groups.postgres-cluster-global]
# These tests inspect cluster-wide activity or create least-privilege sessions,
# so database-per-test isolation alone cannot make them independent.
max-threads = 1

[[profile.postgres-ci.overrides]]
filter = "test(/cluster_global_/)"
test-group = "postgres-cluster-global"

[[profile.postgres-ci.scripts]]
# Script filters are separate from default-filter: they attach the setup and
# isolation wrapper to the same automatically discovered test set.
filter = "(test(/postgres_tests::/) or binary(/^postgres_/)) and not test(/(^|::)external_infra[^:]*::/)"
setup = "postgres-template"
run-wrapper = "postgres-isolation"
90 changes: 88 additions & 2 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,21 @@ REDIS_URL=redis://localhost:6379
# READ_DATABASE_URL is set, reader (default 50).
# BUZZ_DB_POOL_SIZE=50

# Writer-session Postgres timeouts for buzz-db-backed pools and the relay audit
# pool, all in milliseconds; 0 disables. The separately deployed push gateway
# owns its own database and session policy and does not consume these knobs.
# lock_timeout: fail a statement that waits this long on any lock instead of
# parking behind a wedged holder (default 5000).
# BUZZ_DB_LOCK_TIMEOUT_MS=5000
# idle_in_transaction_session_timeout: reap sessions idle inside an open
# transaction — bounds how long a wedged client can hold locks (default 60000).
# BUZZ_DB_IDLE_TXN_TIMEOUT_MS=60000
# statement_timeout: cap any single statement's runtime. Off by default —
# startup migrations/backfills legitimately run long statements. Warning: a
# pathologically low value (e.g. 1) also times out connection setup and can
# prevent any DB connection from establishing.
# BUZZ_DB_STATEMENT_TIMEOUT_MS=0

# -----------------------------------------------------------------------------
# Typesense (search)
# -----------------------------------------------------------------------------
Expand All @@ -51,17 +66,70 @@ TYPESENSE_URL=http://localhost:8108
BUZZ_BIND_ADDR=0.0.0.0:3000
# Public WebSocket URL — used in NIP-42 auth challenges
RELAY_URL=ws://localhost:3000
# Stable relay signing key. Set this in dev if you want REST-created forum posts
# to keep resolving to the original author across relay restarts.
# Stable relay signing key (required). `just bootstrap` generates a random key in
# the gitignored .env file. Preserve that value across restarts and backups.
# BUZZ_RELAY_PRIVATE_KEY=<32-byte hex private key>
# Optional: path to the web UI dist directory. When set, the relay serves
# the web frontend at / for browser requests. Leave unset for local dev
# (use `just web` for Vite HMR instead).
# BUZZ_WEB_DIR=./web/dist

# NIP-PL mobile push is an explicit deployment opt-in. A gateway URL alone
# never enables it. When enabled and the URL is absent, the canonical
# https://push.buzz.xyz/v1/deliveries/apns endpoint is used.
BUZZ_PUSH_ENABLED=false
# BUZZ_PUSH_GATEWAY_DELIVERY_URL=https://push.buzz.xyz/v1/deliveries/apns

# -----------------------------------------------------------------------------
# Admin Dashboard (private moderation surface)
# -----------------------------------------------------------------------------
# Host name that serves the moderation dashboard and its /api/admin/v1
# endpoints. Leave unset to keep the admin surface absent.
# BUZZ_ADMIN_HOST=admin.localhost:3000
#
# Authentication mode. Accepted values: nip98 (default), disabled.
# Any other value is a startup error. Token authentication was removed:
# BUZZ_ADMIN_TOKEN is ignored with a startup warning — remove it from the environment.
# BUZZ_ADMIN_AUTH=nip98
#
# Option A — BUZZ_ADMIN_AUTH=nip98 (Nostr pubkey-based auth, default):
# NIP-98 HTTP Auth. Each request must carry an Authorization: Nostr header
# with a signed kind-27235 event. Authorized principals are resolved from:
# 1. RELAY_OPERATOR_PUBKEYS — comma-separated 64-char hex pubkeys (config Operators).
# 2. RELAY_OWNER_PUBKEY — implicit Operator fallback when RELAY_OPERATOR_PUBKEYS is unset.
# 3. relay_operators table — DB-managed Operator/Moderator roster.
# The dashboard requires a NIP-07 browser extension.
# Setting RELAY_OPERATOR_PUBKEYS for the admin console does NOT require
# RELAY_OPERATOR_API_ORIGIN; that origin is only for community provisioning
# (see below). When BUZZ_ADMIN_HOST is set, the relay advertises the admin
# origin in its NIP-11 document (`admin_api` field) so clients can auto-discover
# the console without manual URL entry.
# RELAY_OPERATOR_PUBKEYS=<64-char hex pubkey>[,<64-char hex pubkey>...]
#
# Option B — BUZZ_ADMIN_AUTH=disabled (network-layer auth only):
# Set only when the admin API is already protected at the network layer
# (VPN, private ingress). The relay logs a WARN on every startup.
# `just admin` defaults to this mode for local review.
#
# Directory holding the built dashboard assets (`pnpm -C admin-web build`).
# BUZZ_ADMIN_WEB_DIR=./admin-web/dist
#
# Canonical origin (http(s)://host[:port], no path) that community-provisioning
# NIP-98 requests are verified against. Required only to USE the provisioning
# endpoints (POST /operator/communities) — not for the admin console. When
# RELAY_OPERATOR_PUBKEYS is set but this is unset, the relay boots with a WARN
# and provisioning requests fail closed until it is set.
# RELAY_OPERATOR_API_ORIGIN=http://127.0.0.1:3000

# Optional relay-owned KLIPY key. When set, NIP-11 advertises GIF search and
# authenticated desktop clients use this relay as the metadata/search proxy.
# Keep the real value in your deployment's secret manager; never commit it.
# BUZZ_KLIPY_API_KEY=

# Shared Redis-backed admission limits. Defaults shown below; each value must
# be a positive integer.
# BUZZ_RATE_LIMIT_HUMAN_MESSAGES_PER_MIN=60
# BUZZ_RATE_LIMIT_GIF_SEARCHES_PER_MIN=30
# BUZZ_RATE_LIMIT_HUMAN_API_CALLS_PER_MIN=300
# BUZZ_RATE_LIMIT_HUMAN_WS_EVENTS_PER_SEC=10
# BUZZ_RATE_LIMIT_AGENT_STANDARD_MESSAGES_PER_MIN=120
Expand Down Expand Up @@ -180,6 +248,12 @@ RUST_LOG=buzz_relay=debug,buzz_datastore=info,buzz_db=debug,buzz_auth=debug,buzz
# Use `buzz-acp models` to discover available model IDs.
# BUZZ_ACP_MODEL=

# Optional Databricks model-picker visibility filter. Discovery-only; this does
# not grant inference access. Comma-separated full-string * / ? patterns are
# OR-matched against raw workspace endpoint and Unity Catalog model-service IDs.
# Unset or blank shows every catalog entry. A nonblank value with no usable patterns is invalid.
# DATABRICKS_MODEL_FILTER=databricks-*,data_tools.goose.*

# ── Timeouts & sessions ──────────────────────────────────────────────────────
# Max seconds per agent turn before timeout (default 320 = ~5 min).
# BUZZ_ACP_TURN_TIMEOUT=320
Expand Down Expand Up @@ -219,6 +293,10 @@ RUST_LOG=buzz_relay=debug,buzz_datastore=info,buzz_db=debug,buzz_auth=debug,buzz
# dkg-trust@1 profile and trust_network query operation.
# VITE_BUZZ_DKG_WEB_OF_TRUST=true

# Protected internal builds only: selects the module graph that contains the
# default-off Bestie experiment. Official OSS builds must leave this unset.
# VITE_BUZZ_BESTIE=1

# ── Subscription & filtering ─────────────────────────────────────────────────
# Subscribe mode: "mentions" (default), "all", or "config" (rule-based).
# BUZZ_ACP_SUBSCRIBE=mentions
Expand All @@ -242,6 +320,14 @@ RUST_LOG=buzz_relay=debug,buzz_datastore=info,buzz_db=debug,buzz_auth=debug,buzz
# Set to true to process the agent's own messages (default: ignore self).
# BUZZ_ACP_NO_IGNORE_SELF=false

# ── Session scoping ──────────────────────────────────────────────────────────
# How ACP provider sessions are scoped in channels: "channel" (default) or
# "thread". "channel" keeps one provider session per channel (legacy). "thread"
# gives each canonical channel thread its own isolated provider session; direct
# messages stay conversation-scoped either way. Ships as "channel" so thread
# scoping can be canaried and rolled back without code changes.
# BUZZ_ACP_SESSION_POLICY=channel

# ── Context ──────────────────────────────────────────────────────────────────
# Max context messages fetched for thread replies and DMs (0–100). 0 = disabled.
# BUZZ_ACP_CONTEXT_MESSAGE_LIMIT=12
Expand Down
4 changes: 4 additions & 0 deletions .github/ISSUE_TEMPLATE/bug-report.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ about: Report a reproducible bug in Buzz
labels: bug
---

> [!IMPORTANT]
> Do not include security vulnerabilities in a public issue. [Report them
> privately through a GitHub security advisory](https://github.com/block/buzz/security/advisories/new).
**Describe the bug**
A clear and concise description of what the bug is.

Expand Down
4 changes: 4 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Report a security vulnerability
url: https://github.com/block/buzz/security/advisories/new
about: Report security vulnerabilities privately to the Buzz maintainers.
Loading
Loading