Skip to content

feat: add mobile pairing Settings plugin - #595

Merged
kalvinnchau merged 10 commits into
mainfrom
kennylopez-mobile-pairing-plugin
Oct 6, 2026
Merged

kalvinnchau merged 10 commits into
mainfrom
kennylopez-mobile-pairing-plugin

Conversation

@klopez4212

@klopez4212 klopez4212 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Adds Settings → Pair mobile as a bundled plugin, porting the encrypted pairing protocol and QR design from block/buzz#8085. The QR starts and refreshes automatically; supported phones enter the desktop’s six-digit code, while older phones retain code comparison. Identity export stays native, and leaving Settings cancels pairing. Desktop verifies a separate random code with a five-attempt limit before export; an unacknowledged transfer stays visible until the user deliberately retries.

Validated: independent agent review, 81 protocol tests/doctests, 17 native pairing tests, 11 component/client tests, composition checks, and 16 Chromium/WebKit pairing and Settings checks. Seven browser scenarios cover Settings integration, cleanup, responsive layout stability, and reduced motion with fixture IPC; no existing cases removed. Native staging connected to the production relay and was tried with an older phone. Still to verify: complete code-entry pairing with the updated mobile app.

Snapshots use disposable fixture data and the reserved example relay wss://relay.example/pairing; the QR screenshot was decoded to verify its destination.

Scan QR Enter desktop code on phone
Pair mobile QR Desktop verification code

@klopez4212
klopez4212 marked this pull request as ready for review October 5, 2026 17:19
@klopez4212
klopez4212 requested review from a team, comp615 and wesbillman as code owners October 5, 2026 17:19
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T19:52:54.967429Z 7cc0037 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f775fb3a1d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Cargo.toml
Comment thread src/bundled/pairing/PairingSettings.tsx Outdated
Comment thread src/bundled/pairing/PairingSettings.tsx Outdated

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes needed: update the imported code-entry authorization, preserve an uncertain transfer outcome, and replace the public QR screenshot; details inline and below.

  • [P2] Replace the QR image with portable fixture data. docs/images/pairing/qr.png, also embedded in this public PR description, decodes to an internal deployment address. Disposable identity data does not sanitize the encoded destination. Regenerate it with a generic example relay and update the attachment; do not merely remove visible labels. Both attached images were inspected, and their bytes match the pinned files. No claim is made that the pictured session remains live.
  • The existing hidden-window auto-restart finding also remains valid at this head: native cancellation is immediately eligible for renderer renewal. Keep close-triggered cancellation terminal until the pairing view is deliberately reopened.

Star Lord automated source review via Wes’s account. Head 99c0323b02c04d05716e99b22592f6ba78d5191b; base 365061c45b726502a6bdc835a24827c6002a83f0. Source and publication-material inspection only; no tests, app launches, pairing sessions, or security probes. Updated-mobile/native end-to-end behavior remains unverified. This is a non-blocking COMMENT review, not approval.

Comment thread src-tauri/src/pairing/mod.rs Outdated
Comment thread src-tauri/src/pairing/mod.rs Outdated
Comment thread src-tauri/src/pairing/mod.rs
Comment thread src-tauri/src/pairing/mod.rs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 72ec901c16

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src-tauri/src/pairing/mod.rs Outdated

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes still needed at this head; I revalidated these existing findings rather than opening duplicate inline threads:

  • P2 — Preserve uncertainty after post-send transport failure. The new payload_sent flag only affects expire; Ok(Err(message)) still becomes an ordinary error. Route ambiguous post-publication I/O failures to Check your phone, retaining explicit phone import rejection as an error, and cover both outcomes. Existing discussion.
  • P2 — Keep window-close cancellation terminal. The macOS hide path still leaves the component mounted, and cancelled still triggers automatic renewal. Existing discussion and repair.
  • P2 — Replace the public QR fixture. Both PR attachments match the pinned files; the QR image is byte-identical to the previously reviewed image, so the encoded internal deployment destination remains. Regenerate it with a portable fixture relay. Prior finding.

The independent desktop-code/five-attempt guard and timeout-specific uncertainty path address the corresponding earlier defects in source.

Star Lord’s automated source review via Wes’s account (wesbillman). Head: 72ec901c162dbebff3027ec6d1e130772cf3e18c; base: c8e7abb0eeeb7c5231a2c767edc28bef86c2a4ef. No code, tests or app executed. Native/updated-mobile interoperability and success/error/retry focus remain unverified; the one CI snapshot still had browser jobs running.

@klopez4212

Copy link
Copy Markdown
Contributor Author

🤖 Addressed the three findings in Wes’s latest review in 7cc0037: post-publication transport failures retain “Check your phone”; native window-close cancellation stays terminal; and both snapshots were regenerated using disposable data, with the QR encoding only wss://relay.example/pairing. Decoded the published QR image locally and verified an exact fixture match. Updated the PR attachments and validation summary.

Also corrected the Settings keyboard-navigation test to include Pair mobile. Validation: 17 native tests, 11 component/client tests, 14 pairing browser checks and 2 Settings keyboard checks passed; all push hooks passed. Independent review found no blockers in these fixes. Updated-mobile/native end-to-end pairing remains unverified; this does not claim all CI or all other review findings are clear.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7cc00375e2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src-tauri/src/pairing/mod.rs Outdated

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes still needed in the existing follow-ups; no duplicate inline threads:

  • P2 — Legacy denial: provide a mismatch action that sends user_denied before disposing the session; “Codes match” remains the only action.
  • P2 — Import acknowledgement: coordinate the mobile fix so success follows durable import and the generation check. Rechecked block/buzz@1e67395fd19a8b4de0cecca97cd1b36842fe8b77: pairing_provider.dart:750 still sends success before persistence at :763–764, allowing false desktop success.
  • P3 — Connection timeout: bound connection establishment and surface Try again; a stalled connection still becomes expiry and automatically renews.

The post-publication uncertainty and terminal-cancellation fixes address my previous findings in source. Both inspected attachments match the pinned files, and the QR now encodes the portable example relay.

Star Lord’s automated source review via Wes’s account (wesbillman). Head 7cc00375e2bb3fc4bdc15b654bde496c067f2253; base c8e7abb0eeeb7c5231a2c767edc28bef86c2a4ef. No tests or app executed; live pairing, macOS hide/reopen and keyboard-focus transitions remain unverified. The single CI snapshot was pending. Non-blocking COMMENT, not approval.

@kalvinnchau kalvinnchau changed the title Add mobile pairing Settings plugin feat: add mobile pairing Settings plugin Oct 6, 2026
@kalvinnchau
kalvinnchau force-pushed the kennylopez-mobile-pairing-plugin branch from 7cc0037 to 8a583c5 Compare October 6, 2026 18:02
@kalvinnchau

kalvinnchau commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Follow-up to Wes’s final review (review) at pushed head 8a583c54:

  • Legacy denial: fixed in d4dcfa69 and subsequent cancellation refinements. Legacy Cancel sends bounded best-effort user_denied before payload publication, then terminates the attempt; owner/UI regression tests cover the path. Replied in the original thread.
  • Connection timeout: fixed in d4dcfa69. Connection establishment has a 10-second bound, and setup has a separate 35-second bound; failure surfaces Try again instead of auto-renewing an expired QR. Replied in the original thread.
  • Mobile import acknowledgement: the import-ack repair is separate block/buzz work, not part of desktop PR feat: add mobile pairing Settings plugin #595. Replied in the original thread.

The separate Clippy-only context grouping in 8a583c54 passed the required push checks and full native package (303 passed, 7 ignored). Kalvin reports live testing of the new code-entry flow succeeded: typing the desktop code on the phone automatically paired it, with no desktop “Codes match” click. This is human acceptance evidence for that flow.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One existing change remains; no duplicate inline thread:

  • P2 — Import acknowledgement: the mobile repair is explicitly deferred, but desktop still says “Phone paired” / “Your account is ready,” and docs/pairing.md:34–36 implies updating the phone supplies the guarantee. Current mobile source still acknowledges before persistence; an import failure can therefore follow desktop success. Keeping the mobile repair separate is fine: until it ships, make desktop success/docs describe the transfer and ask users to verify the account on their phone, rather than guarantee durable import.

Legacy denial and bounded connection/setup timeouts now address the other two follow-ups in source.

Star Lord’s automated source review via Wes’s account (wesbillman). Head 8a583c54f607d0154357ee35e81c5aa88eb335c1; base 97155e7cbd1f97ecedfab5ec8f36310f6caf2e89. Source-only; no tests/app execution. Live updated-mobile pairing and native/keyboard acceptance remain unverified. One CI snapshot: JS/DCO passed; Rust/browser journeys running; Windows skipped. Non-blocking COMMENT, not approval.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

One remaining P2; changes recommended before merge. Submitted as COMMENT under this repository’s agent-review policy, not approval. Native integration, protocol/security, and renderer review lanes are complete; the actionable finding is inline.

Reviewed head 8a583c54f607d0154357ee35e81c5aa88eb335c1 against target 97155e7cbd1f97ecedfab5ec8f36310f6caf2e89 (merge base d27bed1cb354af03ddb796e17de6c0a8053b9d07).

  • Validation: independently reproduced the cancellation ordering using the pinned production client with inert import stubs/fake native state; native outcome loss is source-derived. Verified hosted logs at merge 9391f58118f1ed838349c8759b778de60eabddc5: 7,984 JS tests, 80 protocol tests + 2 doctests, and the native package’s 295 tests passed (7 ignored). All seven Chromium pairing journeys passed. Browser coverage uses fixture IPC, not real handoff.
  • Earlier fixes: independent desktop-code authorization/guess budget, legacy denial, bounded connection/setup, shared visible-QR deadline, terminal cancellation, and post-send transport/timeout uncertainty are present. Both PR images match pinned blobs; locally decoded QR destination is the reserved example relay.
  • Remaining gates/limits: repair the inline cancellation defect with native-owner and client/UI regressions, and clear remaining CI. No live phone/Keychain or macOS hide/reopen run by this review. Author-reported successful live code-entry testing is useful acceptance evidence, but the separately scoped mobile import-ack repair remains unshipped per the existing discussion; desktop success therefore does not establish durable import on affected phones. The optional security-documentation note is not a request to redesign the agreed phone-entry UX.

Comment thread src-tauri/src/pairing/mod.rs Outdated
Comment thread docs/pairing.md
@kalvinnchau

kalvinnchau commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Follow-up to the latest reviews, pushed at 0b1f159d:

  • Import acknowledgement wording (review): the desktop no longer guarantees durable import. The finish step now reads "Your account was sent. Check that it's signed in on your phone." docs/pairing.md item 5 now says Phone paired means the phone acknowledged the transfer. It notes that current phones can acknowledge before saving, asks the user to verify on the phone, and says the mobile fix is separate block/buzz work, outside this PR.
  • Cancellation outcome (P2, review): fixed in the native owner, client, and UI, with regressions. Details are in the inline thread.
  • Screen-observer note: documented. Details are in the inline thread.

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No further changes requested on this follow-up. Native cancellation now preserves and returns the possible-transfer outcome, and the desktop copy/docs ask users to verify sign-in on the phone rather than guarantee durable import; the screen-observer limitation is also documented.

Star Lord’s automated source review via Wes’s account (wesbillman): head 0b1f159dbb24adfd12d3f9ca5f7e5a8dd85f6b19, base 97155e7cbd1f97ecedfab5ec8f36310f6caf2e89. Source-only—no tests or app execution; hosted CI required passed in one snapshot, Windows was skipped, and live phone/native-window/keyboard-focus behavior remains unverified by this review. This COMMENT is not approval.

@kalvinnchau
kalvinnchau force-pushed the kennylopez-mobile-pairing-plugin branch from 0b1f159 to 156d5d8 Compare October 6, 2026 21:22

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carl, an automated reviewer, commenting via Wes’s GitHub account.

One P2 remains; hold approval until the inline relay-lifetime defect is addressed. All three delegated lanes are complete and reconciled with native lifecycle/integration review. The previous cancellation finding is repaired. The other two inline notes are optional.

Reviewed head 156d5d87d9decd9e0544b4495c582c67cf10251b against base/merge-base 484a793261a070ff27e4683969a40fb6ccf2dbe5. Pairing source/tests are byte-identical to reviewed 0b1f159d; incoming integration changes were separately inspected.

Current-head CI is green (21 successful checks, Windows native validation skipped). Eight inert production-client ordering probes passed at 0b1f159d. The new finding is independently source-verified, not an executed sidecar reproduction; existing browser journeys substitute IPC.

Merge criteria: reconcile the supported relay’s lifetime with QR renewal and cover that boundary, retaining terminal cancellation and post-publication uncertainty. No independent live phone, native hide/reopen, or assistive-technology acceptance was performed. Earlier live code-entry success is author-reported; the separately scoped mobile durable-import fix remains unshipped, so desktop acknowledgement still does not certify durable phone login.

Comment thread src-tauri/src/pairing/mod.rs Outdated
Comment thread tests/browser/pairing-fixture.tsx
Comment thread docs/pairing.md Outdated
@kalvinnchau
kalvinnchau force-pushed the kennylopez-mobile-pairing-plugin branch from 156d5d8 to e73ea91 Compare October 6, 2026 22:15

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes needed: refresh the integration lockfile; the current-base merged build fails before compiling the native browser fixture (P2 inline). The pre-connect deadline addresses the prior relay-lifetime finding while preserving uncertain-transfer outcomes; both screenshots match the previously inspected portable fixtures.

Star Lord’s automated source review via Wes’s account. Head e73ea9148f7ae978c54bd8d3ef48b0f97eb56322; base 936279f300d97ba2fb7860cb0eaab7bbd2ac91d0. Source-only: no tests or app execution. Browser journeys were skipped after the fixture failure; Rust was pending and Windows skipped. Live-phone, native-window and keyboard-focus acceptance remain unverified. Non-blocking COMMENT, not approval.

Comment thread Cargo.lock
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
Signed-off-by: klopez4212 <klopez4212@gmail.com>
am and others added 6 commits October 6, 2026 15:28
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
Signed-off-by: am <6e30cd56c30e030cd31bb0939b94a7c257c9a09d5ba2d92cf2735da45629f248@buzz.block.builderlab.xyz>
Native cancellation now serializes with payload publication and keeps the
attempt registered as Uncertain (or its known terminal result) once the
payload may have been sent. pairing_cancel returns that outcome and the
client displays it instead of assuming an unsent cancellation.

Desktop success copy and docs now ask the user to verify the account on the
phone, and docs note that code entry does not resist a live screen observer.

Co-authored-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Budget 115 seconds from before connecting, including setup, as approved for capped sidecars. Keep generic transport errors and uncertain publication outcomes distinct. Correct browser cancellation fixture results and qualify captured-QR protection.

Co-authored-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Co-authored-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
@kalvinnchau
kalvinnchau force-pushed the kennylopez-mobile-pairing-plugin branch from e73ea91 to 01d9320 Compare October 6, 2026 22:30

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No further actionable changes requested on this follow-up: the lockfile now disambiguates the plugin manager’s nostr 0.45.5 dependency, and the merged-tree locked fixture build succeeds.

Star Lord automated source review via Wes’s account; head 01d9320e3f409dff8a27b4d009df1b2d5388c835, base 5feaddbfcbc41f93c259610492978eb886c9055c; COMMENT only, not approval.

No local tests or app execution; other CI lanes were pending in the inspected snapshot, Windows was skipped, and native/phone pairing and keyboard-focus acceptance remain unverified.

@kalvinnchau
kalvinnchau merged commit b48921f into main Oct 6, 2026
22 checks passed
@kalvinnchau
kalvinnchau deleted the kennylopez-mobile-pairing-plugin branch October 6, 2026 22:55
johnmatthewtennant pushed a commit that referenced this pull request Oct 6, 2026
…ge-delete

* origin/main:
  feat: add mobile pairing Settings plugin (#595)
  Cache the floating action bar's MediaQueryList (#652)
  feat(messages): copy and paste mentions, channel refs and links (#579)
  Remember desktop window size and position across launches (#655)
  fix(messages): show verified workflow ownership separately from signer (#663)
  fix(activity): collapse duplicate channel-wide agent indicators (#664)
  docs: make native development the acceptance path (#666)
  Sign plugin releases with NIP-PS (#465)

Signed-off-by: Luna <0828be588d5c9c4d092c5b1cf01761d5aef63d6b104807fd8e8284d517dd1a99@buzz.block.builderlab.xyz>

# Conflicts:
#	src/features/relay/session.ts
#	src/features/relay/unread.test.ts
#	src/features/relay/unread.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants