Compare commits

...
Author SHA1 Message Date
reya 9230628441 update concord backend 2026-09-15 08:26:07 +07:00
reya 871efa6b6f add concord backend 2026-09-15 07:56:09 +07:00
reya 8b0cbd294e add concord plan 2026-09-15 07:35:49 +07:00
reya e221eda546 add concord crypto 2026-09-15 07:19:58 +07:00
reya e49168851e add plan 2026-09-14 20:33:27 +07:00
reya b6f4a97778 feat: add support for reaction (#52)
Reviewed-on: https://git.reya.su/reya/coop-mobile/pulls/52
2026-09-07 13:30:42 +00:00
16 changed files with 3706 additions and 91 deletions
+1129
View File
File diff suppressed because it is too large Load Diff
@@ -63,7 +63,7 @@ class NostrForegroundService : Service() {
// Initialize Nostr client
try {
nostr.init(dbDir.absolutePath)
nostr.init(dbDir.absolutePath, AppStore(this@NostrForegroundService))
} catch (e: Exception) {
throw IllegalStateException("Failed to initialize Nostr Client", e)
}
@@ -5,9 +5,13 @@ import androidx.compose.foundation.interaction.MutableInteractionSource
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.offset
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
@@ -34,6 +38,7 @@ import androidx.compose.ui.text.buildAnnotatedString
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextDecoration
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import coil3.compose.AsyncImage
import rust.nostr.sdk.EventId
import rust.nostr.sdk.PublicKey
@@ -46,6 +51,13 @@ import su.reya.coop.formatAsTime
import su.reya.coop.isImageUrl
import su.reya.coop.removeImageUrls
@Immutable
data class ReactionGroup(
val emoji: String,
val authors: List<PublicKey>,
val containsMe: Boolean
)
@Immutable
data class MessageModel(
val id: EventId,
@@ -54,15 +66,20 @@ data class MessageModel(
val images: List<String>,
val timestamp: String,
val isMine: Boolean,
val replyEventIds: List<EventId>
val replyEventIds: List<EventId>,
val reactions: List<ReactionGroup> = emptyList()
)
@Composable
fun rememberMessageModel(event: UnsignedEvent, currentUser: PublicKey? = null): MessageModel {
fun rememberMessageModel(
event: UnsignedEvent,
reactions: List<UnsignedEvent> = emptyList(),
currentUser: PublicKey? = null
): MessageModel {
val settings = LocalSettings.current
val isMobileData = LocalConnectivity.current
return remember(event, currentUser, settings, isMobileData) {
return remember(event, reactions, currentUser, settings, isMobileData) {
val id = event.ensureId().id()!!
val isMine = currentUser == event.author()
val content = event.content()
@@ -104,6 +121,16 @@ fun rememberMessageModel(event: UnsignedEvent, currentUser: PublicKey? = null):
append(cleanedContent.substring(lastIndex))
}
val groupedReactions = reactions.groupBy { it.content() }
.map { (emoji, events) ->
val authors = events.map { it.author() }
ReactionGroup(
emoji = emoji,
authors = authors,
containsMe = authors.any { it == currentUser }
)
}
MessageModel(
id = id,
author = event.author(),
@@ -111,7 +138,8 @@ fun rememberMessageModel(event: UnsignedEvent, currentUser: PublicKey? = null):
images = images,
timestamp = event.createdAt().formatAsTime(),
isMine = isMine,
replyEventIds = replyEventIds
replyEventIds = replyEventIds,
reactions = groupedReactions
)
}
}
@@ -158,46 +186,108 @@ fun ChatMessage(
horizontalAlignment = if (model.isMine) Alignment.End else Alignment.Start,
verticalArrangement = Arrangement.spacedBy(4.dp)
) {
if (model.annotatedContent.isNotBlank()) {
Surface(
modifier = Modifier.widthIn(max = 280.dp),
color = containerColor,
contentColor = contentColor,
shape = bubbleShape,
Box(contentAlignment = Alignment.BottomEnd) {
Column(
modifier = Modifier.padding(
bottom = if (model.reactions.isNotEmpty()) 4.dp else 0.dp,
end = if (model.reactions.isNotEmpty() && !model.isMine) 8.dp else 0.dp
),
horizontalAlignment = if (model.isMine) Alignment.End else Alignment.Start,
verticalArrangement = Arrangement.spacedBy(4.dp)
) {
Text(
text = model.annotatedContent,
modifier = Modifier.padding(horizontal = 16.dp, vertical = 8.dp),
style = MaterialTheme.typography.bodyLarge
)
if (model.annotatedContent.isNotBlank()) {
Surface(
modifier = Modifier.widthIn(max = 280.dp),
color = containerColor,
contentColor = contentColor,
shape = bubbleShape,
) {
Text(
text = model.annotatedContent,
modifier = Modifier.padding(horizontal = 16.dp, vertical = 8.dp),
style = MaterialTheme.typography.bodyLarge
)
}
}
model.images.forEach { imageUrl ->
Surface(
shape = RoundedCornerShape(16.dp),
color = MaterialTheme.colorScheme.surfaceVariant,
modifier = Modifier.widthIn(max = 280.dp)
) {
AsyncImage(
model = imageUrl,
contentDescription = "Image from chat",
modifier = Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(16.dp)),
contentScale = ContentScale.FillWidth
)
}
}
}
}
model.images.forEach { imageUrl ->
Surface(
shape = RoundedCornerShape(16.dp),
color = MaterialTheme.colorScheme.surfaceVariant,
modifier = Modifier.widthIn(max = 280.dp)
) {
AsyncImage(
model = imageUrl,
contentDescription = "Image from chat",
modifier = Modifier
.fillMaxWidth()
.clip(RoundedCornerShape(16.dp)),
contentScale = ContentScale.FillWidth
if (model.reactions.isNotEmpty()) {
MessageReactions(
reactions = model.reactions,
modifier = Modifier.offset(y = 12.dp)
)
}
}
if (isMessageClicked) {
Text(
text = model.timestamp,
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.outline,
modifier = Modifier.align(
if (model.isMine) Alignment.End else Alignment.Start
)
modifier = Modifier.padding(top = if (model.reactions.isNotEmpty()) 8.dp else 0.dp)
)
}
}
}
}
@Composable
private fun MessageReactions(
reactions: List<ReactionGroup>,
modifier: Modifier = Modifier
) {
val totalCount = reactions.sumOf { it.authors.size }
val displayEmojis = reactions.take(3).map { it.emoji }
Row(
modifier = modifier,
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp)
) {
displayEmojis.forEach { emoji ->
Surface(
modifier = Modifier.size(24.dp),
color = MaterialTheme.colorScheme.surface,
shape = CircleShape,
) {
Box(contentAlignment = Alignment.Center) {
Text(
text = emoji,
fontSize = 12.sp,
)
}
}
}
if (totalCount > 2) {
Surface(
modifier = Modifier.size(24.dp),
color = MaterialTheme.colorScheme.surface,
shape = CircleShape,
) {
Box(contentAlignment = Alignment.Center) {
Text(
text = totalCount.toString(),
style = MaterialTheme.typography.labelSmall,
fontSize = 10.sp,
)
}
}
}
}
}
@@ -80,6 +80,7 @@ import androidx.compose.ui.platform.LocalWindowInfo
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.unit.IntOffset
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.sp
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import coop.composeapp.generated.resources.Res
import coop.composeapp.generated.resources.ic_arrow_back
@@ -91,6 +92,7 @@ import kotlinx.coroutines.launch
import kotlinx.coroutines.withContext
import org.jetbrains.compose.resources.painterResource
import rust.nostr.sdk.EventId
import rust.nostr.sdk.KindStandard
import rust.nostr.sdk.UnsignedEvent
import su.reya.coop.LocalNavigator
import su.reya.coop.LocalProfileCache
@@ -144,10 +146,21 @@ fun ChatScreen(
val loading = viewModel.loading
val newOtherMessages = viewModel.newOtherMessages
val requireScreening = viewModel.requireScreening
val messages = viewModel.messages
val allEvents = viewModel.messages
val displayMessages by remember {
derivedStateOf { allEvents.filter { it.kind().asStd() != KindStandard.REACTION } }
}
val reactionsByMessage by remember {
derivedStateOf {
allEvents.filter { it.kind().asStd() == KindStandard.REACTION }
.groupBy { it.tags().eventIds().firstOrNull() }
}
}
val groupedMessages =
remember { derivedStateOf { messages.groupBy { it.createdAt().formatAsGroup() } } }
remember { derivedStateOf { displayMessages.groupBy { it.createdAt().formatAsGroup() } } }
val roomState by remember(id, currentUser?.publicKey) {
(room as Room).uiStateFlow(profileCache, currentUser?.publicKey)
@@ -170,7 +183,7 @@ fun ChatScreen(
for (group in groupedMessages.value) {
val msgInGroup = group.value
val idx = msgInGroup.indexOfFirst { it.id() == eventId }
val idx = msgInGroup.indexOfFirst { it.ensureId().id() == eventId }
if (idx != -1) {
targetIndex = currentIndex + idx
break
@@ -214,8 +227,8 @@ fun ChatScreen(
}
}
LaunchedEffect(messages.size) {
if (messages.isNotEmpty()) {
LaunchedEffect(allEvents.size) {
if (displayMessages.isNotEmpty()) {
listState.animateScrollToItem(0)
}
}
@@ -293,7 +306,7 @@ fun ChatScreen(
room?.let { ScreenerCard(accountViewModel, it) }
}
when (messages.isNotEmpty()) {
when (displayMessages.isNotEmpty()) {
true -> {
LazyColumn(
modifier = Modifier
@@ -308,14 +321,15 @@ fun ChatScreen(
items = messagesInGroup,
key = { it.ensureId().id()?.toHex()!! }
) { event ->
val msgReactions = reactionsByMessage[event.id()] ?: emptyList()
val model =
rememberMessageModel(event, currentUser?.publicKey)
rememberMessageModel(event, msgReactions, currentUser?.publicKey)
val replyPreview =
remember(model.replyEventIds, messages.size) {
remember(model.replyEventIds, displayMessages.size) {
model.replyEventIds.firstOrNull()
?.let { replyId ->
messages.find { it.id() == replyId }
displayMessages.find { it.ensureId().id() == replyId }
}
}
@@ -464,14 +478,11 @@ fun ChatScreen(
val (model, bounds) = selectedMessage ?: return@AnimatedVisibility
val density = LocalDensity.current
val windowInfo = LocalWindowInfo.current
val windowHeight = windowInfo.containerSize.height
val scrollState = rememberScrollState()
var menuHeight by remember { mutableFloatStateOf(0f) }
val spacing = with(density) { 12.dp.toPx() }
val showAbove =
(windowHeight - bounds.bottom) < (menuHeight + spacing) && bounds.top > (menuHeight + spacing)
var toolbarHeight by remember { mutableFloatStateOf(0f) }
val spacing = with(density) { 6.dp.toPx() }
Box(
modifier = Modifier
@@ -480,11 +491,30 @@ fun ChatScreen(
.clickable { selectedMessage = null }
.verticalScroll(scrollState),
) {
val totalExtraHeight = if (menuHeight > 0) menuHeight + spacing else 300f
val totalExtraHeight = (if (menuHeight > 0) menuHeight + spacing else 300f) +
(if (toolbarHeight > 0) toolbarHeight + spacing else 100f)
val contentBottom = with(density) { (bounds.bottom + totalExtraHeight).toDp() }
Spacer(modifier = Modifier.height(contentBottom + 200.dp))
// Reaction Toolbar (Above)
Box(
modifier = Modifier
.offset { IntOffset(0, (bounds.top - toolbarHeight - spacing).toInt().coerceAtLeast(0)) }
.onGloballyPositioned { toolbarHeight = it.size.height.toFloat() }
.fillMaxWidth()
.padding(horizontal = 16.dp),
contentAlignment = if (model.isMine) Alignment.CenterEnd else Alignment.CenterStart
) {
ReactionToolbar(
onReaction = { reaction ->
viewModel.sendReaction(model.id, reaction)
selectedMessage = null
}
)
}
// Message Preview
ChatMessage(
model = model,
modifier = Modifier
@@ -492,38 +522,35 @@ fun ChatScreen(
.padding(horizontal = 16.dp)
)
val menuOffset = if (showAbove) {
bounds.top - menuHeight - spacing
} else {
bounds.bottom + spacing
}
// Action Menu (Below)
Box(
modifier = Modifier
.offset { IntOffset(0, menuOffset.toInt().coerceAtLeast(0)) }
.offset { IntOffset(0, (bounds.bottom + spacing).toInt()) }
.onGloballyPositioned { menuHeight = it.size.height.toFloat() }
.fillMaxWidth()
.padding(horizontal = 16.dp),
contentAlignment = if (model.isMine) Alignment.CenterEnd else Alignment.CenterStart
) {
ContextMenu { action ->
when (action) {
"Copy" -> {
scope.launch {
val content = model.annotatedContent
val data = ClipData.newPlainText(content, content)
clipboardManager.setClipEntry(ClipEntry(data))
ContextMenu(
onAction = { action ->
when (action) {
"Copy" -> {
scope.launch {
val content = model.annotatedContent
val data = ClipData.newPlainText(content, content)
clipboardManager.setClipEntry(ClipEntry(data))
}
}
}
"Reply" -> {
replyingTo = model
}
"Reply" -> {
replyingTo = model
}
else -> {}
else -> {}
}
selectedMessage = null
}
selectedMessage = null
}
)
}
}
}
@@ -622,9 +649,41 @@ private fun ReplyPreview(
}
}
@Composable
private fun ReactionToolbar(
onReaction: (String) -> Unit
) {
val reactionEmojis = listOf("👍", "❤️", "😂", "😮", "😢", "😡", "🎉")
Surface(
color = MaterialTheme.colorScheme.surfaceContainerHigh,
shape = RoundedCornerShape(24.dp),
shadowElevation = 1.dp
) {
Row(
modifier = Modifier
.padding(horizontal = 12.dp, vertical = 8.dp),
horizontalArrangement = Arrangement.spacedBy(8.dp),
verticalAlignment = Alignment.CenterVertically
) {
reactionEmojis.forEach { emoji ->
Text(
text = emoji,
modifier = Modifier
.clickable { onReaction(emoji) }
.padding(4.dp),
fontSize = 24.sp
)
}
}
}
}
@OptIn(ExperimentalMaterial3ExpressiveApi::class)
@Composable
private fun ContextMenu(onAction: (String) -> Unit) {
private fun ContextMenu(
onAction: (String) -> Unit
) {
val menuItems = listOf(
"Copy" to Res.drawable.ic_copy,
"Reply" to Res.drawable.ic_reply
@@ -633,6 +692,8 @@ private fun ContextMenu(onAction: (String) -> Unit) {
DropdownMenuGroup(
shapes = MenuDefaults.groupShape(1, 1),
containerColor = MenuDefaults.groupVibrantContainerColor,
tonalElevation = 1.dp,
shadowElevation = 1.dp,
modifier = Modifier.width(220.dp)
) {
val itemCount = menuItems.size
@@ -0,0 +1,138 @@
package su.reya.coop.concord
import kotlinx.serialization.decodeFromString
import rust.nostr.sdk.UnsignedEvent
import kotlin.time.Instant
/**
* Folding the Control Plane (CORD-04 §1).
*
* The Control Plane carries the Community's authoritative state as **editions**: each is a
* `kind 3308` rumor naming its entity (`vsk`), that entity's stable coordinate (`eid`), this
* edition's version (`ev`) and the hash of the previous one (`ep`). Every member folds the whole
* chain and reaches the same verdict, so authority is arithmetic rather than a server's say-so.
*
* v1 folds only two entity types: Community metadata (`vsk 0`) and Channel metadata (`vsk 2`).
*
* ## What v1 does not do
*
* **The fold is not gated on authority.** CORD-04 judges every edition by its actor's rank in the
* owner-rooted Roster, via the `vac` citation. v1 has no Roster, so a `control_root` holder could
* publish a forged metadata or Channel edition and v1 would display it.
*
* That gap is bounded rather than open only the owner and staff hold `control_root` (CORD-02 §2),
* and the spec itself calls that secret "a spam gate, never authority" but it is real. It is the
* reason the feature ships labelled beta. Closing it is CORD-04's job: fold `vsk 1` (Roles) and
* `vsk 3` (Grants), then require every edition's `vac` to cite a Grant whose actor strictly
* outranks the entity it edits.
*/
object ConcordControl {
/**
* Parses one Control rumor into an edition, or null when it is not a foldable edition.
*
* A `vsk 10` Dissolution tombstone is refused here: it is chainless (no `ev`, no `ep`) and v1
* does not implement dissolution, so treating it as an ordinary edition would misread it.
*/
fun editionOf(rumor: UnsignedEvent): ControlEdition? {
if (rumor.kind().asU16() != ConcordKind.CONTROL_EDITION.toUShort()) return null
val tags = rumor.tags().toVec()
val vsk = tags.firstOrNull { it.kind() == ConcordTag.VSK }?.content()?.toIntOrNull() ?: return null
if (vsk == ConcordVsk.DISSOLVED) return null
val eidHex = tags.firstOrNull { it.kind() == ConcordTag.EID }?.content() ?: return null
if (eidHex.hex32() == null) return null
val version = tags.firstOrNull { it.kind() == ConcordTag.EV }?.content()?.toULongOrNull() ?: return null
// CORD-04: versions climb from 1. A zero version has no place in the chain.
if (version == 0uL) return null
val prev = tags.firstOrNull { it.kind() == ConcordTag.EP }?.content()
if (prev != null && prev.hex32() == null) return null
return ControlEdition(
vsk = vsk,
eidHex = eidHex.lowercase(),
version = version,
prevHashHex = prev?.lowercase(),
content = rumor.content(),
actorHex = rumor.author().toHex(),
rumorIdHex = rumor.id()?.toHex() ?: return null,
createdAt = Instant.fromEpochSeconds(rumor.createdAt().asSecs().toLong()),
)
}
/**
* Projects the editions into the metadata and Channel list v1 renders.
*
* Entities are folded independently: each `(vsk, eid)` group resolves to its own winner, so a
* broken chain on one Channel never takes the Community's metadata down with it.
*/
fun fold(editions: List<ControlEdition>, communityIdHex: String): ControlFold {
var meta: CommunityMeta? = null
val channels = mutableMapOf<String, ChannelMeta>()
editions.groupBy { it.vsk to it.eidHex }.forEach { (entity, group) ->
val (vsk, eidHex) = entity
if (vsk != ConcordVsk.METADATA && vsk != ConcordVsk.CHANNEL) return@forEach
// The metadata entity *is* the Community, so its coordinate must be the community_id;
// an edition naming anything else is not this Community's metadata.
if (vsk == ConcordVsk.METADATA && eidHex != communityIdHex) return@forEach
val winner = winner(group) ?: return@forEach
when (vsk) {
ConcordVsk.METADATA -> meta = decode(winner.content)
else -> decode<ChannelMeta>(winner.content)?.let { channels[eidHex] = it }
}
}
return ControlFold(meta = meta, channels = channels)
}
/**
* Picks the highest version whose `ep` chain reaches all the way back to version 1.
*
* "Highest" is not simply `max(ev)`: CORD-04 lets a client refuse to downgrade, so we walk down
* from the top and take the first version we can actually verify. A missing predecessor or a
* broken link disqualifies that version, not the entity.
*
* Ties on the same version break on the **lower rumor id**, never on `created_at`, so two
* clients folding the same two candidates always agree.
*/
private fun winner(group: List<ControlEdition>): ControlEdition? {
val byVersion = group
.groupBy { it.version }
.mapValues { (_, candidates) -> candidates.minByOrNull { it.rumorIdHex } ?: return null }
val eid = byVersion.values.firstOrNull()?.eidHex?.hex32() ?: return null
for (top in byVersion.keys.sortedDescending()) {
var prev: ByteArray? = null
var candidate: ControlEdition? = null
var intact = true
for (version in 1uL..top) {
val edition = byVersion[version]
if (edition == null) {
intact = false
break
}
// The first edition has no predecessor; every later one must chain to the last.
val expected = if (version == 1uL) null else prev?.toHex()
if (edition.prevHashHex != expected) {
intact = false
break
}
prev = editionHash(eid, version, prev, edition.content.encodeToByteArray())
candidate = edition
}
if (intact) return candidate
}
return null
}
private inline fun <reified T> decode(content: String): T? =
runCatching { concordJson.decodeFromString<T>(content) }.getOrNull()
}
@@ -0,0 +1,250 @@
package su.reya.coop.concord
import okio.Buffer
import okio.ByteString
import okio.ByteString.Companion.decodeHex
import okio.ByteString.Companion.toByteString
import rust.nostr.sdk.Keys
import rust.nostr.sdk.PublicKey
import rust.nostr.sdk.SecretKey
/**
* Byte-exact cryptographic primitives from Concord (CORD-02 Appendix A).
*
* Everything here is frozen by the spec, and a single wrong byte breaks interop silently
* rather than loudly so each function quotes the CORD section that governs it, and each was
* checked against RFC 5869 vectors and independently computed digests before it was written.
* Concord ships no test vectors of its own ("Examples are illustrative, not verifiable test
* vectors"), and no test file is kept — see PLAN.md §14.
*
* Only HMAC-SHA256 and SHA-256 come from outside: both are Okio `ByteString` members that
* are available on every target this module builds for, so no new crypto dependency is
* needed. Everything else is composition of the existing nostr SDK.
*/
/**
* HKDF-SHA256 (RFC 5869), Extract then Expand.
*
* Concord always calls this with no salt (CORD-02 A.1 specifies a zero-length salt, not 32
* zero bytes), so [salt] defaults to empty. It is exposed only so the RFC's known-answer
* vectors which do use a salt can be re-checked by hand; Concord publishes none.
*
* @param length output length in octets, `1..255 * 32` per RFC 5869.
*/
fun hkdfSha256(
ikm: ByteArray,
info: ByteArray,
salt: ByteArray = ByteArray(0),
length: Int = 32,
): ByteArray {
require(length in 1..255 * 32) { "HKDF output length must be 1..8160, was $length" }
// Extract: PRK = HMAC-SHA256(salt, IKM). Note IKM is the HMAC *message*, not the key.
// Okio refuses a zero-length HMAC key, while RFC 5869 treats an absent salt as HashLen
// (32) zero octets — and HMAC zero-pads any key shorter than its 64-octet block, so the
// two are literally the same key. Substituting is exact, not a workaround; the RFC's own
// zero-length-salt vector was checked against it.
val saltKey = if (salt.isEmpty()) ByteArray(32).toByteString() else salt.toByteString()
val prk = ikm.toByteString().hmacSha256(saltKey)
// Expand: T(n) = HMAC-SHA256(PRK, T(n-1) | info | n), counter being one octet.
val out = Buffer()
var t = ByteString.EMPTY
var counter = 1
while (out.size < length) {
t = Buffer()
.write(t)
.write(info)
.writeByte(counter)
.readByteString()
.hmacSha256(prk)
out.write(t)
counter++
}
return out.readByteArray(length.toLong())
}
/**
* Builds the HKDF `info` for a Concord label (CORD-02 A.1):
*
* ```
* info = utf8(label) | 0x00 | id[32] | epoch_be[8] // epoch omitted for labels marked "—"
* ```
*
* [id] is always present and always 32 bytes, all-zeroes where a label has no meaningful
* id. The epoch is the only omittable field.
*/
fun hkdfInfo(label: String, id: ByteArray, epoch: ULong? = null): ByteArray {
require(id.size == 32) { "Concord HKDF id must be 32 bytes, was ${id.size}" }
return Buffer().apply {
writeUtf8(label)
writeByte(0)
write(id)
if (epoch != null) writeLong(epoch.toLong())
}.readByteArray()
}
/** A plane's derived keypair: `(sk, xonly(sk))` from CORD-02 A.2 `group_key`. */
data class GroupKey(val secretKey: SecretKey, val publicKey: PublicKey)
/**
* The secret-key material of a plane's group key: CORD-02 A.2's `group_key` up to and
* including A.3's `scalar_normalize`.
*
* ```
* info = hkdfInfo(label, id, epoch)
* seed = hkdf(secret, info)
* while (!isValidScalar(seed)) { info = info | counter++; seed = hkdf(secret, info) }
* ```
*
* A.3 only bites when the HKDF output is not a secp256k1 scalar, which is ~2¹² rare, so
* [isValid] exists as a seam for tests; production callers pass the default.
*
* This is deliberately split from [groupKey]: it is pure byte manipulation and so is
* unit-testable, whereas the secp256k1 half needs the nostr SDK, whose native library
* cannot be loaded by a host JVM unit test (see PLAN.md §13.2).
*/
fun groupSeed(
label: String,
secret: ByteArray,
id: ByteArray,
epoch: ULong? = null,
isValid: (ByteArray) -> Boolean = ::isValidScalar,
): ByteArray {
val base = hkdfInfo(label, id, epoch)
var counter = -1 // -1 means "no counter byte", i.e. the first attempt
while (counter <= 255) {
val info = if (counter < 0) base else base + byteArrayOf(counter.toByte())
val seed = hkdfSha256(secret, info)
if (isValid(seed)) return seed
counter++ // A.3: the counter starts at 0 on the first retry
}
error("Concord group_key: scalar_normalize exhausted for label $label")
}
/**
* A secp256k1 secret key is any integer in `[1, n-1]`, so CORD-02 A.3's validity test rejects
* exactly the all-zeroes seed and any seed not below the group order.
*/
fun isValidScalar(seed: ByteArray): Boolean {
if (seed.size != 32) return false
var anyNonZero = false
for (byte in seed) {
if (byte != 0.toByte()) {
anyNonZero = true
break
}
}
if (!anyNonZero) return false
for (i in 0 until 32) {
val candidate = seed[i].toInt() and 0xff
val order = SECP256K1_ORDER[i].toInt() and 0xff
if (candidate != order) return candidate < order
}
return false // exactly n, also out of range
}
private val SECP256K1_ORDER =
"fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141".hexToBytes()
/**
* `group_key` (CORD-02 A.2): a plane's keypair, `(scalar_normalize(seed), xonly_pubkey(sk))`.
*
* The `conv_key` of A.2 needs no implementation of its own it *is* the NIP-44 conversation
* key, which the SDK derives from the pair returned here, so nothing here hand-rolls ECDH.
*/
fun groupKey(label: String, secret: ByteArray, id: ByteArray, epoch: ULong? = null): GroupKey {
val secretKey = SecretKey.fromBytes(groupSeed(label, secret, id, epoch))
return GroupKey(secretKey, Keys(secretKey).publicKey())
}
/**
* `community_id` (CORD-02 A.4), which is also the community's self-certification:
*
* ```
* community_id = sha256( utf8("concord/community") | owner_xonly[32] | owner_salt[32] )
* ```
*
* Note this is a plain SHA-256 commitment with **no** `0x00` separator and no length
* prefix it is deliberately *not* the HKDF construction of A.1, despite looking like it.
*/
fun communityId(ownerXonly: ByteArray, ownerSalt: ByteArray): ByteArray {
require(ownerXonly.size == 32) { "owner_xonly must be 32 bytes, was ${ownerXonly.size}" }
require(ownerSalt.size == 32) { "owner_salt must be 32 bytes, was ${ownerSalt.size}" }
return Buffer().apply {
writeUtf8(ConcordLabel.COMMUNITY)
write(ownerXonly)
write(ownerSalt)
}.readByteString().sha256().toByteArray()
}
/**
* `prevcommit` (CORD-02 A.8) the commitment to the previous epoch's key, published when
* an epoch rolls so that members can verify the rotation chained from what they held:
*
* ```
* prevcommit = sha256( utf8("concord/epoch-key-commitment") | prev_epoch_be[8] | prev_key[32] )
* ```
*/
fun prevCommit(prevEpoch: ULong, prevKey: ByteArray): ByteArray {
require(prevKey.size == 32) { "prev_key must be 32 bytes, was ${prevKey.size}" }
return Buffer().apply {
writeUtf8(ConcordLabel.EPOCH_KEY_COMMITMENT)
writeLong(prevEpoch.toLong())
write(prevKey)
}.readByteString().sha256().toByteArray()
}
/**
* `edition_hash` (CORD-02 A.8) links a Control edition to its predecessor, so a client
* folding the Control plane can detect a rewritten chain:
*
* ```
* edition_hash = sha256(
* len64(label) | label // label = ConcordLabel.EDITION_HASH
* | entity_id[32]
* | version_be[8]
* | (prev ? 0x01 | prev[32] : 0x00 | zero[32])
* | len64(content) | content ) // content bytes verbatim, never re-serialized
* ```
*
* [content] must be the exact bytes that were signed re-serializing the JSON would change
* the hash.
*/
fun editionHash(entityId: ByteArray, version: ULong, prev: ByteArray?, content: ByteArray): ByteArray {
require(entityId.size == 32) { "entity_id must be 32 bytes, was ${entityId.size}" }
require(prev == null || prev.size == 32) { "prev must be 32 bytes" }
val label = ConcordLabel.EDITION_HASH.encodeToByteArray()
return Buffer().apply {
writeLong(label.size.toLong())
write(label)
write(entityId)
writeLong(version.toLong())
if (prev != null) {
writeByte(1)
write(prev)
} else {
writeByte(0)
write(ByteArray(32))
}
writeLong(content.size.toLong())
write(content)
}.readByteString().sha256().toByteArray()
}
/** 64 lowercase hex chars, the encoding CORD-01 mandates for every 32-byte value on the wire. */
internal fun ByteArray.toHex(): String = toByteString().hex()
/** Inverse of [toHex]. Throws on odd length or a non-hex character. */
internal fun String.hexToBytes(): ByteArray = decodeHex().toByteArray()
/** Inverse of [toHex], returning null instead of throwing — for reading untrusted input. */
internal fun String.hexToBytesOrNull(): ByteArray? = runCatching { hexToBytes() }.getOrNull()
/**
* A 32-byte value read from hex, or null when it is not exactly 32 bytes.
*
* The length check is the point: most of Concord's ids and keys are 32 bytes, and a short or long
* value must be rejected before it reaches a derivation that assumes a fixed width.
*/
internal fun String.hex32(): ByteArray? = if (length == 64) hexToBytesOrNull() else null
@@ -0,0 +1,253 @@
package su.reya.coop.concord
import kotlin.io.encoding.Base64
import rust.nostr.sdk.Nip19Coordinate
import rust.nostr.sdk.RelayUrl
import rust.nostr.sdk.nip44Decrypt
/**
* CORD-05: redeeming an invite.
*
* Two ways to be handed the keys, one bundle:
*
* - **Public link** `$BASE/invite/<naddr>#<fragment>`. The naddr names where the encrypted
* bundle sits on relays; the fragment carries an off-network unlock token and never reaches a
* server. The bundle is fetched, then decrypted with a key derived from the token.
* - **Direct Invite** the same bundle, giftwrapped straight to an npub. Nothing to fetch. That
* path needs only [decryptInviteBundle]; the arrival is handled in `ConcordManager.onInboxRumor`.
*
* Minting is out of v1's scope, so this file only decodes.
*
* A bundle is attacker-crafted input reached by following a link, so nothing here allocates on the
* strength of what the bundle claims (CORD-05 §1).
*/
/** The stock relay dictionary (CORD-05 §3). Referenced by one byte so links stay short. */
internal object ConcordRelayDictionary {
val STOCK = listOf(
"wss://jskitty.com/nostr",
"wss://asia.vectorapp.io/nostr",
"wss://relay.ditto.pub",
"wss://relay.dreamith.to",
)
}
/** The link's secret half: `[version][flags][relays?][token:16]`, base64url without padding. */
data class InviteFragment(
val version: Int,
val relays: List<String>,
/** The 16-byte unlock token, hex. Derives exactly one thing: the bundle key. */
val tokenHex: String,
)
/** A parsed invite link: the public locator plus the secret fragment. */
data class ParsedInvite(
val signerHex: String,
val identifier: String,
/** Relays the naddr itself names. Usually empty; the compact form travels in the fragment. */
val naddrRelays: List<RelayUrl>,
val fragment: InviteFragment,
)
private const val FRAGMENT_VERSION = 4
/** The one flag v1 knows: the stock set is in use, so zero relay bytes follow. */
private const val FLAG_STOCK_RELAYS = 1
private const val TOKEN_BYTES = 16
/** CORD-05 §3: the fragment only needs to *find* the bundle; the bundle carries the real set. */
private const val MAX_BOOTSTRAP_RELAYS = 3
/** CORD-05 §1: the spec's reference ceiling on a bundle's Channel list. */
private const val MAX_INVITE_CHANNELS = 256
/** CORD-02 §6: five stable relays is the recommendation, not a rule; a client may truncate. */
private const val MAX_COMMUNITY_RELAYS = 5
/** The fragment is unpadded base64url; ABSENT_OPTIONAL also tolerates a padded paste. */
private val fragmentBase64 = Base64.UrlSafe.withPadding(Base64.PaddingOption.ABSENT_OPTIONAL)
/**
* Decodes a link into its locator and fragment, or null when it is not a Concord invite.
*
* The base domain is deliberately ignored CORD-05 §2 makes the base interchangeable and says any
* client recognizing an invite must respect the naddr and fragment verbatim so only the last path
* segment and the `#` fragment are read.
*/
fun parseInviteLink(text: String): ParsedInvite? {
val trimmed = text.trim()
val hash = trimmed.indexOf('#')
if (hash <= 0 || hash == trimmed.lastIndex) return null
val naddr = trimmed.substring(0, hash).substringAfterLast('/')
val fragment = decodeInviteFragment(trimmed.substring(hash + 1)) ?: return null
val coordinate = runCatching { Nip19Coordinate.fromBech32(naddr) }.getOrNull() ?: return null
if (coordinate.coordinate().kind().asU16() != ConcordKind.INVITE_BUNDLE.toUShort()) return null
return ParsedInvite(
signerHex = coordinate.coordinate().publicKey().toHex(),
identifier = coordinate.coordinate().identifier(),
naddrRelays = coordinate.relays(),
fragment = fragment,
)
}
/**
* CORD-05 §3's fragment layout:
*
* ```
* [version=4][flags][relays?][token:16]
* ```
*
* With the stock flag set no relay bytes follow. Otherwise a count byte precedes that many entries,
* each a leading byte selecting a dictionary id, a host with `wss://` implied, or a verbatim URL.
*/
fun decodeInviteFragment(fragment: String): InviteFragment? {
val bytes = runCatching { fragmentBase64.decode(fragment) }.getOrNull() ?: return null
// Two header bytes plus the token at minimum.
if (bytes.size < 2 + TOKEN_BYTES) return null
val reader = FragmentReader(bytes)
if (reader.byte() != FRAGMENT_VERSION) return null
val flags = reader.byte() ?: return null
// The stock flag selects the whole dictionary, so nothing extra is carried and the cap on
// explicit entries does not apply to it.
val relays = if (flags and FLAG_STOCK_RELAYS != 0) {
ConcordRelayDictionary.STOCK
} else {
val count = reader.byte() ?: return null
buildList {
repeat(count) {
val lead = reader.byte() ?: return null
val relay = when (lead) {
0 -> reader.slice(reader.byte() ?: return null)?.let { "wss://$it" }
255 -> reader.slice(reader.byte() ?: return null)
else -> ConcordRelayDictionary.STOCK.getOrNull(lead - 1)
} ?: return null
add(relay)
}
}.take(MAX_BOOTSTRAP_RELAYS)
}
// Whatever is left must be exactly the token: a short one silently weakens the link.
val token = bytes.copyOfRange(reader.index, bytes.size)
if (token.size != TOKEN_BYTES) return null
return InviteFragment(
version = FRAGMENT_VERSION,
relays = relays,
tokenHex = token.toHex(),
)
}
/**
* `bundle_key = hkdf(token, "concord/invite-key")` (CORD-05 §2). The token derives exactly this one
* thing decrypting the bundle and nothing else.
*
* Modelled as a `group_key` with an all-zero `id` and no epoch, per CORD-02 A.6, because the spec's
* `nip44_encrypt(bundle_key, )` is the same self-ECDH conversation key every other Concord
* `nip44_encrypt` call uses (CORD-01). Encoding it as a keypair rather than a raw conversation key
* is what lets the existing SDK do the encryption instead of hand-rolling NIP-44.
*/
fun inviteBundleKey(tokenHex: String): GroupKey? =
tokenHex.hexToBytesOrNull()?.let { groupKey(ConcordLabel.INVITE_KEY, it, ByteArray(32)) }
/** Decrypts a `kind 33301` bundle's content into [CommunityInvite], or null on any failure. */
fun decryptInviteBundle(content: String, key: GroupKey): CommunityInvite? {
val plaintext = runCatching { nip44Decrypt(key.secretKey, key.publicKey, content) }.getOrNull()
?: return null
return runCatching { concordJson.decodeFromString<CommunityInvite>(plaintext) }.getOrNull()
}
/** CORD-05 §2: a link is retired by re-posting its coordinate as a `vsk 9` tombstone. */
fun isInviteTombstone(vsk: String?): Boolean = vsk == ConcordVsk.INVITE_TOMBSTONE.toString()
/**
* CORD-05 §1's required checks, in the order the spec gives them. Returns every problem found so
* the preview can explain itself rather than silently refusing.
*
* The first one is the load-bearing one: `community_id == sha256("concord/community" owner
* owner_salt)` is what stops a bundle smuggling a false owner or a fake key for a real Community.
*/
fun CommunityInvite.problems(): List<String> {
val problems = mutableListOf<String>()
val ownerBytes = owner.hex32()
val saltBytes = ownerSalt.hex32()
val rootBytes = communityRoot.hex32()
if (ownerBytes == null) problems += "The invite's owner key is malformed"
if (saltBytes == null) problems += "The invite's owner salt is malformed"
if (rootBytes == null) problems += "The invite's community key is malformed"
if (ownerBytes != null && saltBytes != null) {
if (communityId(ownerBytes, saltBytes).toHex() != communityId.lowercase()) {
problems += "The invite does not prove its community id"
}
}
if (communityId.hex32() == null) problems += "The invite's community id is malformed"
if (controlPk != null && controlPk.hex32() == null) problems += "The invite's control key is malformed"
if (channels.size > MAX_INVITE_CHANNELS) {
problems += "The invite carries ${channels.size} channels (max $MAX_INVITE_CHANNELS)"
}
channels.forEachIndexed { index, channel ->
if (channel.id.hex32() == null) problems += "Channel $index has a malformed id"
if (channel.key.hex32() == null) problems += "Channel $index has a malformed key"
}
return problems
}
/** CORD-05 §1: an expired bundle still previews, but joining refuses. */
fun CommunityInvite.isExpired(nowMs: Long): Boolean = expiresAt != null && expiresAt <= nowMs
/**
* The Community's relay set as the invite names it. [fallback] is the link's bootstrap relays,
* used only when the bundle lists none: the bootstrap set exists to *find* the bundle, and the
* bundle's copy is the join-time snapshot of the real set (CORD-02 §6).
*/
fun CommunityInvite.relaySet(fallback: List<String> = emptyList()): List<String> {
val source = relays.ifEmpty { fallback }
return source.map { it.trim() }.filter { it.isNotEmpty() }.distinct().take(MAX_COMMUNITY_RELAYS)
}
/** Turns a validated bundle into the membership we persist. */
fun CommunityInvite.toMembership(relays: List<String>): Membership = Membership(
communityId = communityId.lowercase(),
owner = owner.lowercase(),
ownerSalt = ownerSalt.lowercase(),
communityRoot = communityRoot.lowercase(),
rootEpoch = rootEpoch,
controlPk = controlPk?.lowercase(),
controlRoot = null,
relays = relays,
name = name,
channels = channels.map { channel ->
StoredChannelKey(
id = channel.id.lowercase(),
key = channel.key.lowercase(),
epoch = channel.epoch,
name = channel.name,
// A Public Channel is one whose key *is* the community_root (CORD-03 §1), which is the
// only reading the bundle supports. The Control fold overrides this for display.
private = !channel.key.equals(communityRoot, ignoreCase = true),
)
},
)
/** Reads the fragment's length-prefixed fields, refusing to run past the end. */
private class FragmentReader(private val bytes: ByteArray) {
var index = 0
private set
fun byte(): Int? = if (index < bytes.size) bytes[index++].toInt() and 0xff else null
fun slice(length: Int): String? {
if (length < 0 || index + length > bytes.size) return null
val value = bytes.decodeToString(index, index + length)
index += length
return value
}
}
@@ -0,0 +1,282 @@
package su.reya.coop.concord
/**
* Frozen constants from the Concord specification.
*
* Concord is defined by the CORD documents (github.com/concord-protocol/concord); the
* numbers, labels and permission bits below are normative and must match byte for byte
* or nothing interoperates. They are collected in this one file so that a spec revision
* is a one-file change and so that no literal kind number ever appears at a call site.
*
* References are to the CORD section that defines each value. See `PLAN.md` Appendix A
* for the same tables with prose.
*/
/**
* Event kinds, either the outer wrap or the inner rumor it carries (CORD-01, CORD-02 §5,
* CORD-02 Appendix B).
*/
object ConcordKind {
/** NIP-59 gift wrap. Concord reuses it but reverses the roles: fixed author, ephemeral `p`. */
const val WRAP = 1059
/** Ephemeral wrap for kinds that must never be stored (typing, voice presence). */
const val EPHEMERAL_WRAP = 21059
/**
* Sealed content for everything that must stay secret: Chat, Guestbook, rekey blobs
* and Direct Invites. CORD-02 §5 makes this choice normative, never stylistic.
*/
const val SEAL = 20013
/**
* Plaintext seal. **Control plane only** (CORD-02 §5) the roster is public by design
* so that membership, and therefore authority, is verifiable by anyone.
*/
const val PLAINTEXT_SEAL = 20014
/** Channel message (NIP-C7 shape). Chat plane. */
const val MESSAGE = 9
/** Threaded reply (NIP-22 shape). Chat plane. */
const val REPLY = 1111
/** Reaction (NIP-25 shape). Chat plane. */
const val REACTION = 7
/** Delete (NIP-09 shape). Chat plane. */
const val DELETE = 5
/** Disappearing-message timer notice (CORD-08 §4). Chat plane. */
const val TIMER_NOTICE = 1740
/** Edit. Chat plane. */
const val EDIT = 3302
/** Rekey blobs (CORD-06). Rekey addresses. */
const val REKEY = 3303
/** Join / Leave. Guestbook plane. */
const val JOIN_LEAVE = 3306
/** Control edition — sub-kinded by [ConcordVsk]. Control plane. */
const val CONTROL_EDITION = 3308
/** Kick. Guestbook plane. */
const val KICK = 3309
/** WebXDC peer signal. Chat plane. */
const val WEBXDC_SIGNAL = 3310
/** Guestbook snapshot, chunked, refounder-signed. Guestbook plane. */
const val GUESTBOOK_SNAPSHOT = 3312
/** Typing indicator. Chat plane, ephemeral. */
const val TYPING = 23311
/** Voice presence (CORD-07). Chat plane, ephemeral. */
const val VOICE_PRESENCE = 23313
/** Direct Invite — giftwrapped straight to an npub. Rides a standard wrap, not a stream. */
const val DIRECT_INVITE = 3313
/** Public invite bundle. Addressable, signed by its per-link keypair at an empty `d`. */
const val INVITE_BUNDLE = 33301
/** Community List — one addressable event per fragment, NIP-44 to self. */
const val COMMUNITY_LIST = 33302
/** Invite List — replaceable, NIP-44 to self. */
const val INVITE_LIST = 13303
}
/** Control edition sub-kinds, the `vsk` tag on [ConcordKind.CONTROL_EDITION] (CORD-02 Appendix A). */
object ConcordVsk {
/** Community metadata. */
const val METADATA = 0
/** Role. */
const val ROLE = 1
/** Channel metadata — the only other edition v1 folds. */
const val CHANNEL = 2
/** Grant. */
const val GRANT = 3
/** Banlist. */
const val BANLIST = 4
/** Reserved for role ordering. */
const val RESERVED_ROLE_ORDER = 5
/** Claimed by the invite bundle's live marker. */
const val INVITE_LIVE = 6
/** Retired (was the v1 owner attestation). */
const val RETIRED_OWNER_ATTESTATION = 7
/** Invite-link registry. */
const val INVITE_REGISTRY = 8
/** Claimed by the invite bundle's revocation tombstone. */
const val INVITE_TOMBSTONE = 9
/** Dissolved tombstone — chainless, exempt from version discipline. */
const val DISSOLVED = 10
/** Pin List. */
const val PIN_LIST = 11
}
/**
* Permission bits (CORD-04 §3). Rank ordering is separate: `position` orders authority and
* **lower is higher**, with the owner at position 0.
*/
object ConcordPermission {
const val MANAGE_ROLES = 1 shl 0
const val MANAGE_CHANNELS = 1 shl 1
const val MANAGE_METADATA = 1 shl 2
const val KICK = 1 shl 3
const val BAN = 1 shl 4
const val MANAGE_MESSAGES = 1 shl 5
const val CREATE_INVITE = 1 shl 6
/** Retired (was `MANAGE_INVITES`). Never grant it. */
const val RETIRED_MANAGE_INVITES = 1 shl 7
const val VIEW_AUDIT_LOG = 1 shl 8
const val MENTION_EVERYONE = 1 shl 9
// 1 shl 10 is reserved.
const val PIN_MESSAGES = 1 shl 11
// 1 shl 12 is reserved.
/**
* Staff = anyone holding a staff bit, plus the owner. Staff are the ones who hold
* `control_root` and can therefore write to the Control plane.
*/
const val STAFF = MANAGE_ROLES or MANAGE_CHANNELS or MANAGE_METADATA or
BAN or CREATE_INVITE or PIN_MESSAGES
}
/**
* HKDF label registry (CORD-02 Appendix A.6). The label is the *first* field of the HKDF
* `info` (see `hkdfInfo`), so these strings are on the wire and must not be edited.
*/
object ConcordLabel {
/** A Channel's group key. `secret` = channel key, or `community_root` for a public channel. */
const val CHANNEL = "concord/channel"
/** Control Plane **read** key. `secret` = `community_root`. */
const val CONTROL = "concord/control"
/** Control Plane signer, held by staff only. `secret` = `control_root`. */
const val CONTROL_SIGNER = "concord/control-signer"
/** Guestbook Plane group key. `secret` = `community_root`. */
const val GUESTBOOK = "concord/guestbook"
/** Dissolution tombstone address. `secret` = `community_id`, id = 32 zero bytes, no epoch. */
const val DISSOLVED = "concord/dissolved"
/** A channel rekey address. `secret` = the prior `community_root`. */
const val REKEY_PSEUDONYM = "concord/rekey-pseudonym"
/** A base (community-wide) rekey address. `secret` = the prior `community_root`. */
const val BASE_REKEY_PSEUDONYM = "concord/base-rekey-pseudonym"
/** A rekey blob locator. `secret` = `rotator_xonly ‖ recipient_xonly`. */
const val RECIPIENT_PSEUDONYM = "concord/recipient-pseudonym"
/** SFU room keypair (CORD-07). */
const val VOICE_SIGNER = "concord/voice-signer"
/** 32-byte call media key (CORD-07). */
const val VOICE_MEDIA = "concord/voice-media"
/** Per-sender frame key (CORD-07). id = `sha256(identity)`, no epoch. */
const val VOICE_SENDER = "concord/voice-sender"
/** A member's Grant coordinate. no epoch. */
const val GRANT = "concord/grant"
/** Banlist coordinate. no epoch. */
const val BANLIST = "concord/banlist"
/** A Channel's Pin List coordinate. no epoch. */
const val PINS = "concord/pins"
/** A creator's invite-link registry coordinate. no epoch. */
const val INVITE_LINKS = "concord/invite-links"
/** Public-invite decrypt key. `secret` = the link's unlock token, no epoch. */
const val INVITE_KEY = "concord/invite-key"
/**
* Prefix for the `community_id` commitment (CORD-02 A.4). Not an HKDF label it is
* hashed directly, with no `0x00` separator and no length prefix.
*/
const val COMMUNITY = "concord/community"
/** Prefix for `prevcommit` (CORD-02 A.8). Also hashed directly, not through HKDF. */
const val EPOCH_KEY_COMMITMENT = "concord/epoch-key-commitment"
/**
* Label for `edition_hash` (CORD-02 A.8).
*
* Deliberately **not** under the `concord/` prefix: the spec pins the reference
* implementation's own `vector` label here. Reproduce it exactly.
*/
const val EDITION_HASH = "vector-community/v1/edition"
}
/** Tag names (CORD-01, CORD-02 §5 and the per-kind sections). */
object ConcordTag {
/** `["ms", "<0..999>"]` — sub-second ordering. True time = `created_at * 1000 + ms`. */
const val MS = "ms"
/** `["p", "<ephemeral pubkey>"]` — the one tag a stream wrap carries (NIP-59 reversed). */
const val P = "p"
/** `["channel", "<channel_id>"]` — MUST also be committed inside the author-signed rumor. */
const val CHANNEL = "channel"
/** `["epoch", "<n>"]` — MUST also be committed inside the author-signed rumor. */
const val EPOCH = "epoch"
/** `["q", "<rumor id>", "", "<author>"]` — NIP-C7 inline quote. */
const val QUOTE = "q"
/** `["vsk", "<n>"]` — Control edition entity type. */
const val VSK = "vsk"
/** `["eid", "<hex32>"]` — stable coordinate of a Control edition's entity. */
const val EID = "eid"
/** `["ev", "<n>"]` — this edition's version, climbing from 1. */
const val EV = "ev"
/** `["ep", "<hash hex>"]` — previous edition hash. Absent on the first edition. */
const val EP = "ep"
/** `["vac", "<grant eid>", "<version>", "<hash>"]` — authority citation. Absent when the owner acts. */
const val VAC = "vac"
/** `["expiration", "<secs>"]` — NIP-40. MUST be on both wrap and rumor, same value. */
const val EXPIRATION = "expiration"
/** `["d", ""]` / `["d", "<index>"]` — addressable coordinate. */
const val D = "d"
/** `["snap", "<id>", "<i>", "<n>"]` — Guestbook snapshot chunk. */
const val SNAP = "snap"
/** `["invite", "<creator hex>", "<label>"]` — optional invite attribution on a join. */
const val INVITE = "invite"
/** `["k", "3313"]` — the one deliberate outer-tag exception on a Direct Invite wrap. */
const val K = "k"
}
@@ -0,0 +1,584 @@
package su.reya.coop.concord
import kotlinx.coroutines.CancellationException
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.flow.update
import kotlinx.serialization.decodeFromString
import rust.nostr.sdk.AckPolicy
import rust.nostr.sdk.Event
import rust.nostr.sdk.Filter
import rust.nostr.sdk.Kind
import rust.nostr.sdk.PublicKey
import rust.nostr.sdk.RelayUrl
import rust.nostr.sdk.ReqTarget
import rust.nostr.sdk.SendEventTarget
import rust.nostr.sdk.Tag
import rust.nostr.sdk.UnsignedEvent
import su.reya.coop.AppStorage
import su.reya.coop.nostr.Nostr
import kotlin.concurrent.Volatile
import kotlin.time.Clock
import kotlin.time.Duration.Companion.seconds
/**
* Concord's read path: which planes we hold keys for, what we fold out of them, and how an invite
* turns into membership.
*
* ## Why this lives on [Nostr]
*
* The client has exactly **one** notification pump. `client.notifications()` is called once, inside
* [Nostr.handleNotifications], and a second consumer would silently split the stream so Concord
* routes through that pump rather than subscribing to its own (see [isPlaneAddress] and [onInboxRumor]).
*
* ## The two phases
*
* [restore] is local and fast: it reads memberships from storage and folds whatever the Control
* plane has already cached, so routing is meaningful before anything hits the network. [sync] is
* the network half: connect the Community's relays and subscribe to its plane addresses. The pump
* calls them in that order, so the first event that arrives already knows where it belongs.
*/
class ConcordManager(private val nostr: Nostr) {
/**
* Concord's plane pubkeys, keyed by hex. Every incoming `kind 1059` is routed by author: a
* Concord wrap is signed by a plane's *derived* stream key and can never be read by the NIP-17
* path, which assumes an ephemeral author and a `p`-tagged recipient.
*
* Replaced wholesale rather than mutated, and read from the notification pump's thread while a
* worker coroutine rewrites it, so the reference is volatile.
*/
@Volatile
private var planes: Map<String, Plane> = emptyMap()
/** Latest Control fold per community id. Replaced wholesale; see [planes]. */
@Volatile
private var folds: Map<String, ControlFold> = emptyMap()
/**
* Unread badges by Channel id. Replaced wholesale; see [planes]. In memory only, mirroring
* `Room.unreadCount` in the chat layer, so a restart begins with every badge cleared.
*/
@Volatile
private var unread: Map<String, Int> = emptyMap()
/**
* Bumped whenever a plane rumor is cached or a message is sent, so a screen showing a Channel
* has something to re-query on. A counter rather than a set of changed scopes, because two
* messages to the same Channel must both be observable.
*/
private val _revision = MutableStateFlow(0L)
val revision: StateFlow<Long> = _revision.asStateFlow()
private val _memberships = MutableStateFlow<List<Membership>>(emptyList())
val memberships: StateFlow<List<Membership>> = _memberships.asStateFlow()
private val _communities = MutableStateFlow<List<CommunityState>>(emptyList())
val communities: StateFlow<List<CommunityState>> = _communities.asStateFlow()
/** Direct Invites that arrived giftwrapped to us and have not been accepted or dismissed. */
private val _directInvites = MutableStateFlow<List<CommunityInvite>>(emptyList())
val directInvites: StateFlow<List<CommunityInvite>> = _directInvites.asStateFlow()
private var store: ConcordStore? = null
/**
* Hands over the encrypted storage [Nostr] cannot reach on its own.
*
* [Nostr] is a Context-free singleton, so the Android layer passes [AppStorage] in through
* [Nostr.init]. Until this is called nothing can be persisted or restored, and the manager
* simply routes nothing.
*/
internal fun attach(storage: AppStorage) {
store = ConcordStore(storage, nostr)
}
// -----------------------------------------------------------------------------------------
// Routing
// -----------------------------------------------------------------------------------------
/** True when a wrap's author is one of our planes' stream keys. */
fun isPlaneAddress(authorHex: String): Boolean = planes.containsKey(authorHex)
/**
* Handles one stream wrap from a plane we hold a key for.
*
* [PlaneKey.unwrap] runs every check a reader must make and returns null on any failure, so a
* forged, unverifiable, mis-bound or undecryptable wrap is dropped here without ever being
* rendered. What survives is stored under its logical scope and, for Control, re-folded.
*/
suspend fun handlePlaneEvent(event: Event) {
val plane = planes[event.author().toHex()] ?: return
val rumor = plane.key.unwrap(event) ?: return
val store = store ?: return
store.cacheRumor(plane.scopeIdHex, event.id().toHex(), rumor)
_revision.update { it + 1 }
// A message from someone else is the only thing a badge counts. Our own wraps come back
// through the same subscription and so does a re-fetch, so the check is on the rumor's
// author rather than on the arrival.
if (plane.role == PlaneRole.Channel) countUnread(plane.scopeIdHex, rumor)
// Control carries consensus state, so every edition changes what we can read: a new
// Channel means a new plane address, and therefore a new subscription.
if (plane.role == PlaneRole.Control) refreshControl(plane.communityIdHex)
}
/**
* Intercepts rumors that arrive through the ordinary NIP-17 giftwrap pipeline and belong to
* Concord instead.
*
* Returns true when Concord consumed the rumor. A Direct Invite (kind `3313`) rides a *standard*
* NIP-59 wrap, so it unwraps fine but it is a key handoff, not a message, and letting it
* through would have the chat layer build a room out of it. Returning true here keeps all
* Concord kind knowledge inside this package and leaves the chat code untouched.
*/
fun onInboxRumor(rumor: UnsignedEvent): Boolean {
if (rumor.kind().asU16() != ConcordKind.DIRECT_INVITE.toUShort()) return false
val invite = runCatching { concordJson.decodeFromString<CommunityInvite>(rumor.content()) }.getOrNull()
if (invite == null) {
println("Concord: a direct invite arrived but its bundle could not be read")
return true
}
if (invite.problems().isNotEmpty()) {
println("Concord: refusing a direct invite that does not prove its community id")
return true
}
_directInvites.update { current ->
if (current.any { it.communityId.equals(invite.communityId, ignoreCase = true) }) current
else current + invite
}
return true
}
// -----------------------------------------------------------------------------------------
// Lifecycle
// -----------------------------------------------------------------------------------------
/** Local half of startup: load memberships, fold the cached Control plane, index the planes. */
suspend fun restore() {
val store = store ?: return
val memberships = store.loadMemberships()
_memberships.value = memberships
// Fold what is already on disk so Channels and metadata render immediately. Live editions
// arrive later through handlePlaneEvent and re-fold.
folds = memberships.associate { membership ->
membership.communityId to ConcordControl.fold(
editions = store.cachedRumors(membership.communityId)
.mapNotNull { ConcordControl.editionOf(it) },
communityIdHex = membership.communityId,
)
}
refreshPlanes()
}
/** Network half of startup: connect every Community's relays and subscribe to its planes. */
suspend fun sync() {
for (membership in _memberships.value) {
try {
subscribeCommunity(membership)
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
println("Concord: could not subscribe to ${membership.communityId}: ${e.message}")
}
}
}
// -----------------------------------------------------------------------------------------
// Invites
// -----------------------------------------------------------------------------------------
/**
* Fetches and decrypts the bundle behind a public invite link, so the UI can show what joining
* would mean. Nothing is joined, nothing is subscribed and no presence is announced here
* (CORD-05 §1: a bundle is passive until the user accepts).
*/
suspend fun previewInvite(link: String): InvitePreview {
val parsed = parseInviteLink(link) ?: throw IllegalArgumentException("That is not a Concord invite link")
val bundleKey = inviteBundleKey(parsed.fragment.tokenHex)
?: throw IllegalArgumentException("The invite link's token is malformed")
val client = nostr.client ?: throw IllegalStateException("Nostr client is not ready")
// The fragment's bootstrap relays only have to *find* the bundle; the bundle then carries
// the Community's real relay set (CORD-05 §3).
val relays = (parsed.naddrRelays.map { it.toString() } + parsed.fragment.relays)
.mapNotNull { runCatching { RelayUrl.parse(it) }.getOrNull() }
.distinct()
if (relays.isEmpty()) throw IllegalStateException("The invite link names no relay to fetch from")
relays.forEach { relay ->
client.addRelay(relay)
client.connectRelay(relay)
}
val filter = Filter()
.kind(Kind(ConcordKind.INVITE_BUNDLE.toUShort()))
.author(PublicKey.fromBytes(parsed.signerHex.hexToBytes()))
.identifier(parsed.identifier)
val bundle = client
.fetchEvents(ReqTarget.manual(relays.associateWith { listOf(filter) }), timeout = 8.seconds)
.toVec()
.firstOrNull()
?: throw IllegalStateException("No invite bundle was found at that link")
if (isInviteTombstone(bundle.tagValue(ConcordTag.VSK))) {
throw IllegalStateException("This invite link has been revoked")
}
val invite = decryptInviteBundle(bundle.content(), bundleKey)
?: throw IllegalStateException("The invite bundle could not be opened")
return preview(invite, link, parsed.fragment.relays)
}
/** The same preview for a Direct Invite, which arrived with no link to fetch. */
fun previewDirectInvite(invite: CommunityInvite): InvitePreview = preview(invite, link = null, fallbackRelays = emptyList())
/** Accepts an invite: persist the keys, connect, subscribe, and announce the join. */
suspend fun join(preview: InvitePreview): CommunityState {
preview.problems.firstOrNull()?.let { throw IllegalArgumentException(it) }
if (preview.expired) throw IllegalArgumentException("That invite has expired")
val store = store ?: throw IllegalStateException("Concord storage is not ready")
val membership = preview.invite.toMembership(preview.relays)
val updated = _memberships.value.filterNot { it.communityId == membership.communityId } + membership
store.saveMemberships(updated)
_memberships.value = updated
refreshPlanes()
subscribeCommunity(membership)
// CORD-02 §5: a Join is each member's own word, published to the Guestbook. There is no
// Guestbook fold in v1 — the Control plane is what drives the UI.
if (!preview.alreadyJoined) publishJoin(membership, preview.invite)
_directInvites.update { invites ->
invites.filterNot { it.communityId.equals(membership.communityId, ignoreCase = true) }
}
return _communities.value.firstOrNull { it.membership.communityId == membership.communityId }
?: CommunityState(membership, null, emptyList())
}
// -----------------------------------------------------------------------------------------
// Reading
// -----------------------------------------------------------------------------------------
/**
* A Channel's messages, oldest first. Reads the local cache; the live subscription is what
* keeps it current.
*/
suspend fun channelMessages(channelIdHex: String): List<ConcordMessage> =
store?.cachedRumors(channelIdHex).orEmpty()
.mapNotNull { it.toConcordMessage() }
.sortedBy { it.timestampMs }
/** A Channel's unread badge. See [ConcordChannel.unreadCount] for what it does and does not survive. */
fun unreadCount(channelIdHex: String): Int = unread[channelIdHex] ?: 0
/** Clears a Channel's badge — the Channel screen calls this once its messages are on display. */
fun markChannelRead(channelIdHex: String) {
if ((unread[channelIdHex] ?: 0) == 0) return
unread = unread - channelIdHex
publishUnread(channelIdHex, 0)
}
// -----------------------------------------------------------------------------------------
// Writing
// -----------------------------------------------------------------------------------------
/**
* Sends a message to a Channel (CORD-03 §3).
*
* The send *is* [PlaneKey.rumor] plus [PlaneKey.wrap], with nothing in between: the rumor carries
* the `channel`/`epoch` binding stamped from the Channel's own key, and the wrap is signed by that
* key's stream half, so a message cannot be built for a coordinate it will not verify at.
*
* The message is cached locally *before* it is published, so it is visible even if every relay is
* unreachable and so the subscription's echo of the wrap lands on the same `d` slot instead of
* duplicating it.
*
* Returns the message as a reader will see it. Throws when the Channel is hidden behind a key we
* were never granted a Private Channel is listable without being writable.
*/
suspend fun sendChannelMessage(channelIdHex: String, content: String): ConcordMessage {
val client = nostr.client ?: throw IllegalStateException("Nostr client is not ready")
val plane = planes.values.firstOrNull {
it.role == PlaneRole.Channel && it.scopeIdHex.equals(channelIdHex, ignoreCase = true)
} ?: throw IllegalArgumentException("That Channel is not one we hold a key for")
val author = nostr.signer.getPublicKeyAsync() ?: throw IllegalStateException("User not signed in")
val rumor = plane.key.rumor(
author = author,
kind = ConcordKind.MESSAGE.toUShort(),
content = content,
createdAt = Clock.System.now(),
)
val wrap = plane.key.wrap(rumor, nostr.signer)
store?.cacheRumor(plane.scopeIdHex, wrap.id().toHex(), rumor)
_revision.update { it + 1 }
// Always the Community's own relays, never the app's defaults (see [subscribeCommunity]).
val relays = _memberships.value
.firstOrNull { it.communityId == plane.communityIdHex }
?.relays
.orEmpty()
.mapNotNull { runCatching { RelayUrl.parse(it) }.getOrNull() }
if (relays.isEmpty()) throw IllegalStateException("That Community names no relay to publish to")
client.sendEvent(event = wrap, target = SendEventTarget.to(relays), ackPolicy = AckPolicy.none())
.failed.forEach { (relay, reason) -> println("Concord: $relay refused a message: $reason") }
return rumor.toConcordMessage()
?: throw IllegalStateException("Concord: could not read back the message just sent")
}
/** Records a badge change and re-publishes [communities] so a badge drawn from it moves. */
private fun publishUnread(channelIdHex: String, count: Int) {
_communities.update { states ->
if (states.none { state -> state.channels.any { it.idHex == channelIdHex } }) return@update states
states.map { state ->
state.copy(
channels = state.channels.map {
if (it.idHex == channelIdHex) it.copy(unreadCount = count) else it
}
)
}
}
}
/** Counts one incoming message against its Channel, ignoring our own and anything but a message. */
private fun countUnread(channelIdHex: String, rumor: UnsignedEvent) {
if (rumor.kind().asU16() != ConcordKind.MESSAGE.toUShort()) return
if (rumor.author() == nostr.signer.publicKeyFlow.value) return
val count = (unread[channelIdHex] ?: 0) + 1
unread = unread + (channelIdHex to count)
publishUnread(channelIdHex, count)
}
// -----------------------------------------------------------------------------------------
// Planes
// -----------------------------------------------------------------------------------------
/**
* Rebuilds the plane index and the Community read model from the memberships and folds we hold.
*
* Returns the communities whose set of plane addresses changed, because those are exactly the
* ones whose subscription is now stale a Control edition that adds a Channel adds an address.
*/
private fun refreshPlanes(): Set<String> {
val previous = planes
val next = mutableMapOf<String, Plane>()
val states = mutableListOf<CommunityState>()
for (membership in _memberships.value) {
val communityId = membership.communityId.hex32()
val root = membership.communityRoot.hex32()
val fold = folds[membership.communityId]
val granted = membership.channels.associateBy { it.id }
if (communityId != null && root != null) {
// Control is write-restricted: we hold the read key plus the writers' pubkey, which
// is all reading takes (CORD-01, CORD-02 §5). A bundle with no `control_pk` is a
// legacy, pre-split Community, whose plane was addressed by the `concord/control`
// derivation itself; v1 does not read those, so such a Community shows no metadata.
// CORD-02 §5 requires that legacy reading and the first base rotation upgrades it.
membership.controlPk?.let { controlPkHex ->
if (controlPkHex.hex32() != null) {
val key = controlPlaneKey(root, communityId, membership.rootEpoch, controlPkHex)
next[key.streamPublicKeyHex] = Plane(
communityIdHex = membership.communityId,
role = PlaneRole.Control,
key = key,
scopeIdHex = membership.communityId,
)
}
}
val guestbook = guestbookPlaneKey(root, communityId, membership.rootEpoch)
next[guestbook.streamPublicKeyHex] = Plane(
communityIdHex = membership.communityId,
role = PlaneRole.Guestbook,
key = guestbook,
scopeIdHex = membership.communityId,
)
}
val channelIds = (granted.keys + fold?.channels?.keys.orEmpty()).distinct()
val channels = channelIds.mapNotNull { channelIdHex ->
val meta = fold?.channels?.get(channelIdHex)
if (meta?.deleted == true) return@mapNotNull null
val stored = granted[channelIdHex]
val channelId = channelIdHex.hex32()
// A Public Channel's key *is* the community_root, so one we were never granted is
// still derivable; a Private one is not (CORD-03 §1).
val secret = stored?.key?.hex32()
?: if (meta?.isPrivate != true) root else null
val epoch = stored?.epoch ?: membership.rootEpoch
var plane: PlaneKey? = null
if (channelId != null && secret != null) {
plane = channelPlaneKey(secret, channelId, epoch)
next[plane.streamPublicKeyHex] = Plane(
communityIdHex = membership.communityId,
role = PlaneRole.Channel,
key = plane,
scopeIdHex = channelIdHex,
)
}
ConcordChannel(
idHex = channelIdHex,
name = meta?.name ?: stored?.name ?: channelIdHex.take(8),
private = meta?.isPrivate ?: stored?.private ?: false,
epoch = epoch,
hasKey = plane != null,
// Carried across the re-index rather than recomputed: a Control edition must not
// silently clear every badge, the same way ChatRepository preserves its counters.
unreadCount = unread[channelIdHex] ?: 0,
)
}
states += CommunityState(
membership = membership,
meta = fold?.meta,
channels = channels.sortedBy { it.name.lowercase() },
)
}
planes = next
_communities.value = states
return _memberships.value
.filter { membership ->
previous.planeKeys(membership.communityId) != next.planeKeys(membership.communityId)
}
.map { it.communityId }
.toSet()
}
/** Re-folds one Community's Control plane from the cache, then re-indexes if planes shifted. */
private suspend fun refreshControl(communityIdHex: String) {
val store = store ?: return
val editions = store.cachedRumors(communityIdHex).mapNotNull { ConcordControl.editionOf(it) }
folds = folds + (communityIdHex to ConcordControl.fold(editions, communityIdHex))
if (communityIdHex in refreshPlanes()) {
_memberships.value.firstOrNull { it.communityId == communityIdHex }?.let { subscribeCommunity(it) }
}
}
/**
* Subscribes to one Community: connect its relays, then ask for every plane's address.
*
* `channel` and `epoch` are multi-letter tags, and Nostr filters only accept single-letter ones,
* so plane addresses are the finest granularity available. That is the right level anyway one
* key per plane and the `channel`/`epoch` binding is a strict check after decryption.
*/
private suspend fun subscribeCommunity(membership: Membership) {
val client = nostr.client ?: return
val id = subscriptionId(membership.communityId)
client.unsubscribe(id)
val relays = membership.relays.mapNotNull { runCatching { RelayUrl.parse(it) }.getOrNull() }.distinct()
if (relays.isEmpty()) return
// Always the Community's own relays, never the app's defaults: Concord reverses NIP-59
// (fixed author, ephemeral `p`), so a relay enforcing the optional `p`-tag guard drops
// these wraps, and the bootstrap set is tuned for NIP-17.
relays.forEach { relay ->
client.addRelay(relay)
client.connectRelay(relay)
}
val filters = planes.values
.filter { it.communityIdHex == membership.communityId }
.mapNotNull { plane -> plane.key.streamPublicKeyHex.hex32() }
.distinct()
.map { Filter().kind(Kind(ConcordKind.WRAP.toUShort())).author(PublicKey.fromBytes(it)) }
if (filters.isEmpty()) return
client.subscribe(target = ReqTarget.manual(relays.associateWith { filters }), id = id)
}
/** Publishes a still-fetchable Guestbook Join (CORD-02 §5) — each member's own word. */
private suspend fun publishJoin(membership: Membership, invite: CommunityInvite?) {
val client = nostr.client ?: return
val communityId = membership.communityId.hex32() ?: return
val root = membership.communityRoot.hex32() ?: return
val author = nostr.signer.getPublicKeyAsync() ?: throw IllegalStateException("User not signed in")
val plane = guestbookPlaneKey(root, communityId, membership.rootEpoch)
// CORD-05 §1: an accepting joiner echoes the invite's creator and label, which is what
// makes per-link usage counters possible at all.
val extraTags = invite?.creatorNpub?.let { creator ->
listOf(Tag.custom(ConcordTag.INVITE, listOf(creator, invite.label.orEmpty())))
}.orEmpty()
val rumor = plane.rumor(
author = author,
kind = ConcordKind.JOIN_LEAVE.toUShort(),
content = "join",
createdAt = Clock.System.now(),
extraTags = extraTags,
)
val wrap = plane.wrap(rumor, nostr.signer)
val targets = membership.relays.mapNotNull { runCatching { RelayUrl.parse(it) }.getOrNull() }
client.sendEvent(event = wrap, target = SendEventTarget.to(targets), ackPolicy = AckPolicy.none())
}
private fun subscriptionId(communityIdHex: String): String = "$SUBSCRIPTION_PREFIX$communityIdHex"
private fun preview(
invite: CommunityInvite,
link: String?,
fallbackRelays: List<String>,
): InvitePreview {
val relays = invite.relaySet(fallbackRelays)
val problems = invite.problems() + if (relays.isEmpty()) listOf("The invite names no relays") else emptyList()
return InvitePreview(
link = link,
invite = invite,
relays = relays,
problems = problems,
expired = invite.isExpired(Clock.System.now().toEpochMilliseconds()),
alreadyJoined = _memberships.value.any { it.communityId.equals(invite.communityId, ignoreCase = true) },
)
}
private companion object {
const val SUBSCRIPTION_PREFIX = "concord:"
}
}
/** What a plane is for — the Community-wide Control and Guestbook planes, or one Channel. */
private enum class PlaneRole { Control, Guestbook, Channel }
/**
* One plane address we hold: the key to decrypt it, the role that says how to fold it, and the
* [scopeIdHex] it caches under.
*/
private class Plane(
val communityIdHex: String,
val role: PlaneRole,
val key: PlaneKey,
val scopeIdHex: String,
)
private fun Map<String, Plane>.planeKeys(communityIdHex: String): Set<String> =
filterValues { it.communityIdHex == communityIdHex }.keys
/** The first content value of a tag, or null. Used for tags read without their companion fields. */
private fun Event.tagValue(kind: String): String? =
tags().toVec().firstOrNull { it.kind() == kind }?.content()
@@ -0,0 +1,259 @@
package su.reya.coop.concord
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.Json
import rust.nostr.sdk.UnsignedEvent
import kotlin.time.Instant
/**
* Concord's data model: what we persist about a Community, what an invite carries, and what the
* Control fold projects.
*
* Types that travel on the wire ([CommunityInvite], [CommunityMeta], [ChannelMeta], [ConcordIcon])
* keep the spec's snake_case field names because those keys are normative. Types that are ours
* alone ([Membership], [StoredChannelKey]) keep Kotlin naming.
*
* Concord reserves every top-level field it does not define, and CORD-02 §6 requires editors to
* round-trip fields they do not understand. v1 only ever *reads* these documents, so the models
* below carry just the fields v1 uses and rely on `ignoreUnknownKeys`; anything aimed at writing
* them back must preserve what it did not parse.
*/
internal val concordJson = Json {
ignoreUnknownKeys = true
encodeDefaults = true
}
// ---------------------------------------------------------------------------------------------
// Persisted
// ---------------------------------------------------------------------------------------------
/**
* A Community this device has joined, as stored locally. Holding these keys *is* membership
* (CORD-02 §2), so the whole blob lives in [su.reya.coop.AppStorage]'s encrypted store.
*
* There is no owner recovery by design: [communityId] commits to [owner], so losing the owner key
* cannot be repaired by anyone, including us. Nothing in the UI should suggest otherwise.
*/
@Serializable
data class Membership(
/** Hex `community_id`. Never appears on the wire; every coordinate derives from it one-way. */
val communityId: String,
/** Owner x-only pubkey hex, the other half of the `community_id` commitment. */
val owner: String,
/** 32-byte hex salt; not secret, travels in invites so anyone can recompute the commitment. */
val ownerSalt: String,
/** 32-byte hex `community_root`. The base access key — never leaves the encrypted store. */
val communityRoot: String,
/** Epoch the root was issued at (CORD-02 §3). */
val rootEpoch: ULong,
/** Control Plane signer pubkey (CORD-02 §5), used to *address* the plane. Trusted on trust. */
val controlPk: String? = null,
/** Staff-only write key. v1 never writes to the Control Plane, so this stays null. */
val controlRoot: String? = null,
/** The Community's relays — always from the invite, never the app's defaults (see PLAN.md 13.2). */
val relays: List<String> = emptyList(),
/** Last known name, cached so a community renders before its Control fold lands. */
val name: String? = null,
/** Channels this invite actually granted a key for. */
val channels: List<StoredChannelKey> = emptyList(),
)
/**
* A Channel key handed out by an invite. Public Channels derive from `community_root` and so carry
* it here, which is why [private] can only be a hint the Control fold is the authority.
*/
@Serializable
data class StoredChannelKey(
val id: String,
val key: String,
val epoch: ULong,
val name: String? = null,
val private: Boolean = false,
)
// ---------------------------------------------------------------------------------------------
// Invite bundle (CORD-05 §1)
// ---------------------------------------------------------------------------------------------
/**
* The `CommunityInvite` bundle: the same document whether it arrives inside a public link's
* encrypted relay-side event or giftwrapped straight to an npub as a Direct Invite (CORD-05 §6).
*
* The `community_id` self-certifies the owner, so a bundle cannot smuggle a false owner onto a real
* Community. [controlPk] is the one field taken on trust: it derives from a secret the joiner will
* never hold, so nothing in the bundle can prove it. Build nothing security-relevant on it.
*/
@Serializable
data class CommunityInvite(
@SerialName("community_id") val communityId: String = "",
val owner: String = "",
@SerialName("owner_salt") val ownerSalt: String = "",
@SerialName("community_root") val communityRoot: String = "",
@SerialName("root_epoch") val rootEpoch: ULong = 0u,
@SerialName("control_pk") val controlPk: String? = null,
val channels: List<InviteChannel> = emptyList(),
val relays: List<String> = emptyList(),
val name: String? = null,
val icon: ConcordIcon? = null,
/** Unix **milliseconds** — see [expiryToEpochSeconds]. Optional. */
@SerialName("expires_at") val expiresAt: Long? = null,
@SerialName("creator_npub") val creatorNpub: String? = null,
val label: String? = null,
)
/** One granted Channel inside a bundle. `key` is `community_root` for a Public one (CORD-03 §1). */
@Serializable
data class InviteChannel(
val id: String = "",
val key: String = "",
val epoch: ULong = 0u,
val name: String? = null,
)
/**
* A pointer to an encrypted blob icon, banner (CORD-02 §6). The media server holds ciphertext
* only; a member fetches, decrypts and verifies [hash]. v1 never fetches these.
*/
@Serializable
data class ConcordIcon(
val url: String? = null,
val key: String? = null,
val nonce: String? = null,
val hash: String? = null,
)
// ---------------------------------------------------------------------------------------------
// Control fold
// ---------------------------------------------------------------------------------------------
/** Community metadata — the `vsk 0` entity's content (CORD-02 §6). */
@Serializable
data class CommunityMeta(
val name: String? = null,
val description: String? = null,
/** The Community's own relay set. This is the authority; the invite's copy is a snapshot. */
val relays: List<String> = emptyList(),
val icon: ConcordIcon? = null,
val banner: ConcordIcon? = null,
/** Disappearing-messages timer in seconds (CORD-08). Read only; v1 does not enforce it. */
@SerialName("message_expiration") val messageExpiration: Long? = null,
)
/** Channel metadata — the `vsk 2` entity's content (CORD-03 §2). */
@Serializable
data class ChannelMeta(
val name: String? = null,
@SerialName("private") val isPrivate: Boolean = false,
/** Terminal: the id is never reused and clients drop the Channel (CORD-03 §2). */
val deleted: Boolean = false,
)
/**
* One `kind 3308` Control edition, parsed from its rumor (CORD-04 §1, CORD-02 Appendix B).
*
* The tags are the edition machinery `vsk` names the entity type, `eid` its stable coordinate,
* `ev` this version, `ep` the hash of the previous edition. [content] is the entity's new state as
* a JSON string, held verbatim because [editionHash] hashes those bytes and never a re-serialization.
*/
data class ControlEdition(
val vsk: Int,
val eidHex: String,
val version: ULong,
val prevHashHex: String?,
val content: String,
val actorHex: String,
val rumorIdHex: String,
val createdAt: Instant,
)
/** The projected Control state v1 uses: the Community's metadata and its Channel list. */
data class ControlFold(
val meta: CommunityMeta?,
val channels: Map<String, ChannelMeta>,
)
// ---------------------------------------------------------------------------------------------
// Read surface
// ---------------------------------------------------------------------------------------------
/** A Channel as the UI sees it: its identity, and whether we actually hold a key to read it. */
data class ConcordChannel(
val idHex: String,
val name: String,
val private: Boolean,
val epoch: ULong,
/** False for a Private Channel we were never granted — listable, but not readable. */
val hasKey: Boolean,
/**
* Messages from others since this Channel was last opened. In memory only, exactly like
* `Room.unreadCount`: it survives a Control re-fold, but not a restart.
*/
val unreadCount: Int = 0,
)
/** A Community with its Control fold applied. */
data class CommunityState(
val membership: Membership,
/** Null until a `vsk 0` edition has been folded; the invite's name fills in before that. */
val meta: CommunityMeta?,
val channels: List<ConcordChannel>,
)
/** A Chat-plane message, already unwrapped and signature-checked. */
data class ConcordMessage(
val idHex: String,
val author: String,
val content: String,
val createdAt: Instant,
/** CORD-02 §4: `created_at * 1000 + ms`. The only ordering basis the protocol uses. */
val timestampMs: Long,
)
/** A redeemed-in-part invite, ready for the UI to preview before anything joins (CORD-05 §1). */
data class InvitePreview(
/** Null for a Direct Invite, which arrives with no link. */
val link: String?,
val invite: CommunityInvite,
/** Resolved relay set: the bundle's, falling back to the link's bootstrap relays. */
val relays: List<String>,
/** Non-empty means the bundle is refused — these are the reasons, in plain English. */
val problems: List<String>,
val expired: Boolean,
val alreadyJoined: Boolean,
) {
val joinable: Boolean get() = problems.isEmpty() && !expired
}
// ---------------------------------------------------------------------------------------------
// Helpers
// ---------------------------------------------------------------------------------------------
/**
* CORD-05 §1: the bundle's `expires_at` is unix **milliseconds**, the Invite List's is unix
* **seconds**, and a NIP-40 `expiration` tag is **seconds**. Three spellings of one instant, so
* every conversion lives here. Returns null when the bundle carries no expiry at all.
*/
fun CommunityInvite.expiryToEpochSeconds(): Long? = expiresAt?.let { it / 1000 }
/** CORD-02 §4: true time is `created_at * 1000 + ms`; an absent or out-of-range `ms` reads as 0. */
internal fun UnsignedEvent.concordTimestampMs(): Long {
val ms = tags().toVec()
.firstOrNull { it.kind() == ConcordTag.MS }
?.content()
?.toIntOrNull()
?.takeIf { it in 0..999 }
return createdAt().asSecs().toLong() * 1000 + (ms ?: 0)
}
/** Projects a Chat-plane rumor into a [ConcordMessage], or null when it is not a message. */
internal fun UnsignedEvent.toConcordMessage(): ConcordMessage? {
if (kind().asU16() != ConcordKind.MESSAGE.toUShort()) return null
return ConcordMessage(
idHex = id()?.toHex().orEmpty(),
author = author().toHex(),
content = content(),
createdAt = Instant.fromEpochSeconds(createdAt().asSecs().toLong()),
timestampMs = concordTimestampMs(),
)
}
@@ -0,0 +1,308 @@
package su.reya.coop.concord
import kotlinx.coroutines.CancellationException
import rust.nostr.sdk.AsyncNostrSigner
import rust.nostr.sdk.Event
import rust.nostr.sdk.EventBuilder
import rust.nostr.sdk.Keys
import rust.nostr.sdk.Kind
import rust.nostr.sdk.Nip44Version
import rust.nostr.sdk.PublicKey
import rust.nostr.sdk.Tag
import rust.nostr.sdk.Timestamp
import rust.nostr.sdk.UnsignedEvent
import rust.nostr.sdk.nip44Decrypt
import rust.nostr.sdk.nip44Encrypt
import kotlin.time.Instant
/**
* The CORD-01 wire stack: `wrap seal rumor`.
*
* A stream is a shared key and a stream of gift wraps signed with it. Everything a plane sends
* is three nested layers:
*
* ```
* wrap kind 1059, signed by the stream key, one ephemeral `p` tag
* nip44(conv_key) of
* seal kind 20013 (encrypted) or 20014 (plaintext), signed by the real author
* nip44(conv_key) of | byte-verbatim
* rumor unsigned, its authority is the seal's signature around it
* ```
*
* Both encrypted layers use the *same* conversation key that is double encryption under one
* key, not two, and it is what makes the wrap readable by anyone holding the plane key.
*
* Concord reverses NIP-59: the author is fixed (the stream key) and the `p` tag is ephemeral,
* which is why the app's normal NIP-59 path in `MessageManager.extractRumor` cannot read these
* and why routing happens by author before that code is reached.
*/
/**
* Which of CORD-01's two seal forms a plane uses; CORD-02 §5 makes this a fixed property of the
* plane, "never a per-message choice". Because the plane owns it, [wrap] cannot pick the wrong
* one and [unwrap] can reject a seal of the other form instead of quietly accommodating it.
*/
enum class SealForm(private val kindValue: Int) {
/**
* Chat, Guestbook, rekey. The rumor is NIP-44-encrypted inside the already-encrypted wrap,
* so no relay honest or malicious can retain and display the rumor as a public event.
*/
Encrypted(ConcordKind.SEAL),
/**
* Control plane only. The seal's content is the rumor's serialized JSON **byte-verbatim**,
* because a signature over ciphertext is bound to the key that encrypted it and would break
* if re-wrapped under another key across an epoch change.
*/
Plaintext(ConcordKind.PLAINTEXT_SEAL);
val kind: UShort get() = kindValue.toUShort()
}
/**
* CORD-03 §3: what a Chat-plane rumor must commit so a member cannot re-wrap another's message
* into a different Channel or replay it across an epoch.
*
* The tags live *inside* the author-signed rumor, so the author's signature covers them; the
* reader checks them strict-equal against the coordinate whose key opened the wrap.
*/
data class ChatBinding(val channelIdHex: String, val epoch: ULong)
/**
* One plane's keys and, for a Chat plane, the coordinate its rumors are bound to.
*
* [read] decrypts: it is the conversation key for the wrap and for an encrypted seal. [stream]
* is the address that signs wraps. They are the same key on a normal stream, and differ only on
* a write-restricted one (CORD-01, used by the Control Plane in CORD-02 §5) where a reader
* holds the read key plus the writers' *pubkey*, enough to verify a wrap but not to mint one.
*
* Deliberately not a `data class`: there is no value equality worth having, and the default
* `toString` keeps key material out of logs.
*/
class PlaneKey(
val read: GroupKey,
val stream: GroupKey?,
/** The x-only hex of the key every wrap on this plane must be signed by. */
val streamPublicKeyHex: String,
/** CORD-02 §5: the one seal form this plane may use, on both the write and the read side. */
val form: SealForm,
val chat: ChatBinding?,
)
/**
* A Channel's Chat plane (CORD-03 §1). Public channels pass `community_root` as the secret,
* Private ones their own independent `channel_key`; the `channel_id` in the derivation is what
* gives each Channel a distinct address either way.
*/
fun channelPlaneKey(channelSecret: ByteArray, channelId: ByteArray, epoch: ULong): PlaneKey {
val key = groupKey(ConcordLabel.CHANNEL, channelSecret, channelId, epoch)
return PlaneKey(
read = key,
stream = key,
streamPublicKeyHex = key.publicKey.toHex(),
form = SealForm.Encrypted,
chat = ChatBinding(channelId.toHex(), epoch),
)
}
/** The community-wide Guestbook plane (CORD-02 §5), where joins, leaves and kicks are recorded. */
fun guestbookPlaneKey(communityRoot: ByteArray, communityId: ByteArray, epoch: ULong): PlaneKey {
val key = groupKey(ConcordLabel.GUESTBOOK, communityRoot, communityId, epoch)
return PlaneKey(
read = key,
stream = key,
streamPublicKeyHex = key.publicKey.toHex(),
form = SealForm.Encrypted,
chat = null,
)
}
/**
* The Control plane's **read** key (CORD-02 §5). Its wraps are signed by the staff-held
* `control-signer` key instead, so this plane is read-only and [streamPublicKeyHex] is
* whatever the invite claimed nothing in an invite can prove it, so build nothing
* security-relevant on it beyond the subscription address.
*/
fun controlPlaneKey(
communityRoot: ByteArray,
communityId: ByteArray,
epoch: ULong,
streamPublicKeyHex: String,
): PlaneKey {
val key = groupKey(ConcordLabel.CONTROL, communityRoot, communityId, epoch)
return PlaneKey(
read = key,
stream = null,
streamPublicKeyHex = streamPublicKeyHex,
form = SealForm.Plaintext,
chat = null,
)
}
/**
* Builds an unsigned rumor for this plane (CORD-01).
*
* The `channel`/`epoch` binding tags are stamped from the plane itself, and therefore from the
* very key that will encrypt the wrap, so a rumor can never be built whose coordinate does not
* match the key it travels under. `ms` rides every rumor (CORD-02 A.5) because `created_at` is
* never tweaked true time is `created_at * 1000 + ms`.
*
* A rumor is never signed and never a standalone artifact: its authority is the seal's
* signature around it.
*/
fun PlaneKey.rumor(
author: PublicKey,
kind: UShort,
content: String,
createdAt: Instant,
extraTags: List<Tag> = emptyList(),
): UnsignedEvent {
val tags = buildList {
chat?.let {
add(Tag.custom(ConcordTag.CHANNEL, listOf(it.channelIdHex)))
add(Tag.custom(ConcordTag.EPOCH, listOf(it.epoch.toString())))
}
add(Tag.custom(ConcordTag.MS, listOf(msOf(createdAt).toString())))
addAll(extraTags)
}
return EventBuilder(Kind(kind), content)
.tags(tags)
.customCreatedAt(Timestamp.fromSecs(createdAt.epochSeconds.toULong()))
.finalizeUnsigned(author)
.ensureId()
}
/**
* Wraps [rumor] into a publishable stream event.
*
* [signer] signs the *seal*, so it must be the real author's signer the user's own key, which
* also means a NIP-46 bunker works here. The wrap is signed by the plane's stream key instead,
* and the seal form comes from the plane itself (CORD-02 §5).
*
* Both the seal and the wrap take the rumor's `created_at`, never a fresh one, so the three
* layers agree and pagination by wrap timestamp lines up with message ordering.
*/
suspend fun PlaneKey.wrap(rumor: UnsignedEvent, signer: AsyncNostrSigner): Event {
val stream = stream ?: error("Concord: this plane is read-only and cannot wrap")
val createdAt = rumor.createdAt()
val rumorJson = rumor.asJson()
val seal = try {
EventBuilder(
Kind(form.kind),
// CORD-01: byte-verbatim for a plaintext seal, so a re-wrap can carry the exact
// signed bytes forward instead of re-serializing them.
if (form == SealForm.Encrypted) nip44Seal(read, rumorJson) else rumorJson,
)
.customCreatedAt(createdAt)
.finalizeAsync(signer)
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
throw IllegalStateException("Concord: failed to seal rumor: ${e.message}", e)
}
// The receiver drops a rumor whose author differs from its seal's, so publishing a mismatch
// would produce a message nobody can read. Fail here instead, where the cause is visible.
check(seal.author() == rumor.author()) {
"Concord: seal author ${seal.author().toHex()} does not match rumor author ${rumor.author().toHex()}"
}
return try {
// The ephemeral `p` is discarded: it only breaks linkage between a plane's wraps. Only
// its pubkey is kept, and `Tag.publicKey` has already serialized it, so destroying the
// keypair right away is safe. v1 has no giftwrap deletion, which is the one thing
// CORD-01 §Deletions would want the secret for.
val ephemeral = Keys.generate().use { Tag.publicKey(it.publicKey()) }
Keys(stream.secretKey).use { keys ->
EventBuilder(Kind(concordKind(ConcordKind.WRAP)), nip44Seal(read, seal.asJson()))
.tags(listOf(ephemeral))
.customCreatedAt(createdAt)
.finalize(keys)
}
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
throw IllegalStateException("Concord: failed to wrap seal: ${e.message}", e)
}
}
/**
* Unwraps a stream event and enforces every check a reader must make, returning null when any
* of them fails.
*
* Null means **drop**, never retry: a wrong key, a forged or unverifiable signature, an
* impersonation attempt, a decompression/serialization failure, or a `channel`/`epoch`
* mismatch (CORD-03 §3). The checks are all here so a caller cannot skip one, and nothing is
* rendered before they pass.
*/
fun PlaneKey.unwrap(event: Event): UnsignedEvent? {
if (event.kind().asU16() != ConcordKind.WRAP.toUShort()) return null
// The wrap is signed by the stream key. Verifying this is what makes CORD-01's
// write-restricted split real: a read-key holder can verify a wrap but cannot mint one.
if (event.author().toHex() != streamPublicKeyHex) return null
if (!event.verify()) return null
val seal = runCatching {
Event.fromJson(nip44Decrypt(read.secretKey, read.publicKey, event.content()))
}.getOrNull() ?: return null
if (!seal.verify()) return null
// CORD-02 §5 makes the seal form a fixed property of the plane, so a seal of the other form
// is a discipline violation, not a variant to accommodate: only the matching pair is accepted.
val sealKind = seal.kind().asU16()
val rumorJson = when {
sealKind == SealForm.Encrypted.kind && form == SealForm.Encrypted -> runCatching {
nip44Decrypt(read.secretKey, read.publicKey, seal.content())
}.getOrNull() ?: return null
// Plaintext seal: the rumor's bytes are already the content, never re-parsed as an event.
sealKind == SealForm.Plaintext.kind && form == SealForm.Plaintext -> seal.content()
else -> return null
}
val rumor = runCatching { UnsignedEvent.fromJson(rumorJson).ensureId() }.getOrNull() ?: return null
// NIP-59's impersonation check: the seal proves who wrote the rumor inside it.
if (rumor.author() != seal.author()) return null
if (!bindsToThisPlane(rumor)) return null
return rumor
}
/**
* CORD-03 §3, strict-equal and fail-closed: on a Chat plane both tags must be present and match
* this plane's coordinate, so neither a re-wrap into another Channel nor a cross-epoch replay
* survives. The community-wide Guestbook and Control planes split no sub-context, so the spec
* binds nothing there and this is a no-op.
*/
private fun PlaneKey.bindsToThisPlane(rumor: UnsignedEvent): Boolean {
val expected = chat ?: return true
val tags = rumor.tags().toVec()
val channel = tags.firstOrNull { it.kind() == ConcordTag.CHANNEL }?.content()
val epoch = tags.firstOrNull { it.kind() == ConcordTag.EPOCH }?.content()
return channel == expected.channelIdHex && epoch == expected.epoch.toString()
}
/**
* CORD-02 A.5: true time is `created_at * 1000 + ms`, and a reader drops a rumor whose `ms`
* falls outside `0..999`. `mod` rather than `%` so a pre-epoch timestamp cannot produce a
* negative value.
*/
private fun msOf(createdAt: Instant): Int = createdAt.toEpochMilliseconds().mod(1000L).toInt()
/**
* NIP-44's plaintext cap, enforced by the publisher (CORD-01 §Encoding).
*
* Libraries are lenient and a lenient publisher mints events a strict reader cannot decrypt, so
* this fails loudly at build time instead of producing an undecryptable message.
*/
private const val MAX_PLAINTEXT_BYTES = 65_535
private fun nip44Seal(key: GroupKey, plaintext: String): String {
val size = plaintext.encodeToByteArray().size
require(size <= MAX_PLAINTEXT_BYTES) {
"Concord: NIP-44 plaintext is $size bytes, over the $MAX_PLAINTEXT_BYTES cap"
}
return nip44Encrypt(key.secretKey, key.publicKey, plaintext, Nip44Version.V2)
}
/** `Kind` for a frozen [ConcordKind] number; the SDK's constructor wants a `UShort`. */
private fun concordKind(kind: Int): UShort = kind.toUShort()
@@ -0,0 +1,113 @@
package su.reya.coop.concord
import kotlinx.coroutines.CancellationException
import kotlinx.serialization.decodeFromString
import kotlinx.serialization.encodeToString
import rust.nostr.sdk.EventBuilder
import rust.nostr.sdk.Filter
import rust.nostr.sdk.Keys
import rust.nostr.sdk.Kind
import rust.nostr.sdk.KindStandard
import rust.nostr.sdk.Tag
import rust.nostr.sdk.UnsignedEvent
import su.reya.coop.AppStorage
import su.reya.coop.nostr.Nostr
/**
* Concord's local persistence, in the two places the rest of the app already keeps things.
*
* **Secrets [AppStorage]'s encrypted store.** A Community's keys *are* membership (CORD-02 §2),
* so they go through `setSecret`, which is backed by Android Keystore AES-GCM. They must never go
* through plaintext storage, and they never touch LMDB.
*
* **Community state LMDB, as index events.** Decrypted plane rumors are cached the same way
* [su.reya.coop.nostr.MessageManager] caches DM rumors, so history survives a restart and the
* Control fold has something to fold before the network answers.
*/
class ConcordStore(private val storage: AppStorage, private val nostr: Nostr) {
suspend fun loadMemberships(): List<Membership> {
val raw = try {
storage.getSecret(MEMBERSHIPS_KEY)
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
println("Concord: could not read memberships: ${e.message}")
return emptyList()
} ?: return emptyList()
return try {
concordJson.decodeFromString<List<Membership>>(raw)
} catch (e: Exception) {
println("Concord: stored memberships are unreadable: ${e.message}")
emptyList()
}
}
suspend fun saveMemberships(memberships: List<Membership>) {
try {
storage.setSecret(MEMBERSHIPS_KEY, concordJson.encodeToString(memberships))
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
throw IllegalStateException("Concord: could not store memberships: ${e.message}", e)
}
}
/**
* Caches one decrypted plane rumor under its logical scope a Channel id for Chat, the
* community id for Control and Guestbook.
*
* The `d` tag is not optional. [KindStandard.APPLICATION_SPECIFIC_DATA] is an *addressable*
* kind, so LMDB keeps one event per `(kind, pubkey, d)` coordinate: without a unique `d` every
* message would replace the one before it and history would vanish silently. The wrap id is
* that unique value, exactly as [su.reya.coop.nostr.MessageManager.setCachedRumor] uses it
* and it doubles as the dedupe key when a wrap arrives from several relays.
*/
suspend fun cacheRumor(scopeIdHex: String, wrapIdHex: String, rumor: UnsignedEvent) {
try {
val event = EventBuilder(Kind.fromStd(KindStandard.APPLICATION_SPECIFIC_DATA), rumor.asJson())
.tags(
listOf(
Tag.identifier(wrapIdHex),
Tag.custom(INDEX_SCOPE_TAG, listOf(scopeIdHex)),
Tag.custom(INDEX_KIND_TAG, listOf(rumor.kind().asU16().toString())),
)
)
.finalizeAsync(Keys.generate())
nostr.client?.database()?.saveEvent(event)
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
println("Concord: failed to cache rumor: ${e.message}")
}
}
/** Every cached rumor for one scope, oldest first. */
suspend fun cachedRumors(scopeIdHex: String): List<UnsignedEvent> {
val events = try {
val filter = Filter()
.kind(Kind.fromStd(KindStandard.APPLICATION_SPECIFIC_DATA))
.reference(scopeIdHex)
nostr.client?.database()?.query(filter)?.toVec() ?: return emptyList()
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
println("Concord: failed to read cached rumors: ${e.message}")
return emptyList()
}
return events
.mapNotNull { runCatching { UnsignedEvent.fromJson(it.content()).ensureId() }.getOrNull() }
.sortedBy { it.createdAt().asSecs() }
}
private companion object {
const val MEMBERSHIPS_KEY = "concord_memberships"
/** Single-letter index tags; `r` is what `Filter.reference` queries. */
const val INDEX_SCOPE_TAG = "r"
const val INDEX_KIND_TAG = "k"
}
}
@@ -144,12 +144,15 @@ class MessageManager(private val nostr: Nostr) {
private suspend fun setCachedRumor(giftId: EventId, rumor: UnsignedEvent) {
try {
val isReaction = rumor.kind().asStd() == KindStandard.REACTION
val kValue = if (isReaction) "reaction" else "dm"
// Construct reference tags
val tags = listOf(
Tag.identifier(giftId.toHex()),
Tag.publicKey(rumor.author()),
Tag.custom("r", listOf(rumor.roomId().toString())),
Tag.custom("k", listOf("14"))
Tag.custom("k", listOf("14", kValue))
)
// Set event kind
@@ -176,12 +179,13 @@ class MessageManager(private val nostr: Nostr) {
val kind = Kind.fromStd(KindStandard.APPLICATION_SPECIFIC_DATA)
val kTag = SingleLetterTag.lowercase(Alphabet.K)
// Get all DM events
val filter = Filter().kind(kind).customTags(kTag, listOf("14", "dm"))
// Get all rumors (DMs and Reactions)
val filter = Filter().kind(kind).customTags(kTag, listOf("14", "dm", "reaction"))
val events = client?.database()?.query(filter)?.toVec() ?: return null
// Collect rooms
val roomsMap: MutableMap<Long, Room> = mutableMapOf()
val lastDmTimestampMap: MutableMap<Long, ULong> = mutableMapOf()
events
.map { UnsignedEvent.fromJson(it.content()) }
@@ -189,18 +193,41 @@ class MessageManager(private val nostr: Nostr) {
.forEach { rumor ->
val id = rumor.roomId()
val isFromMe = rumor.author() == userPubkey
val isReaction = rumor.kind().asStd() == KindStandard.REACTION
val existing = roomsMap[id]
val createdAt = rumor.createdAt()
// If the room is new or the current rumor is newer than the existing one
if (existing == null || createdAt.asSecs() > existing.createdAt.asSecs()) {
// A room is "Ongoing" if it was already marked as such or if the current rumor is from the user
val isOngoing = (existing?.kind == RoomKind.Ongoing) || isFromMe
if (existing == null) {
val room = Room.new(rumor = rumor, userPubkey = userPubkey, id = id)
roomsMap[id] = if (isOngoing) room.copy(kind = RoomKind.Ongoing) else room
} else if (isFromMe && existing.kind != RoomKind.Ongoing) {
// If it's an older rumor but sent by the user, mark the room as Ongoing
roomsMap[id] = existing.copy(kind = RoomKind.Ongoing)
// If the first event we see is a reaction, don't use it as lastMessage
roomsMap[id] = if (isReaction) {
room.copy(lastMessage = null)
} else {
lastDmTimestampMap[id] = createdAt.asSecs()
room
}
if (isFromMe) {
roomsMap[id] = roomsMap[id]!!.copy(kind = RoomKind.Ongoing)
}
} else {
// Update the overall room timestamp (for sorting) if this event is newer
if (createdAt.asSecs() > existing.createdAt.asSecs()) {
roomsMap[id] = roomsMap[id]!!.copy(createdAt = createdAt)
}
// Update the last message content if this is a DM and it's newer than the last DM we've seen
if (!isReaction) {
val lastDmTs = lastDmTimestampMap[id] ?: 0uL
if (createdAt.asSecs() >= lastDmTs) {
lastDmTimestampMap[id] = createdAt.asSecs()
roomsMap[id] = roomsMap[id]!!.copy(lastMessage = rumor.content())
}
}
// If any event is from the user, mark the room as Ongoing
if (isFromMe && roomsMap[id]?.kind != RoomKind.Ongoing) {
roomsMap[id] = roomsMap[id]!!.copy(kind = RoomKind.Ongoing)
}
}
}
@@ -348,4 +375,64 @@ class MessageManager(private val nostr: Nostr) {
throw IllegalStateException("Failed to send message: ${e.message}", e)
}
}
suspend fun sendReaction(
to: Set<PublicKey>,
targetEventId: EventId,
reaction: String,
onRumorCreated: ((UnsignedEvent) -> Unit)? = null,
) {
try {
val currentUser =
signer.getPublicKeyAsync() ?: throw IllegalStateException("User not signed in")
val tags = mutableListOf<Tag>()
tags.add(Tag.event(targetEventId))
// Add public key tags for each recipient (including me) to ensure roomId consistency
to.forEach { pubkey ->
tags.add(Tag.publicKey(pubkey))
}
for (receiver in setOf(currentUser) + to) {
// Construct the rumor event
val rumor = EventBuilder(Kind.fromStd(KindStandard.REACTION), reaction)
.tags(tags)
.finalizeUnsigned(currentUser)
.ensureId()
// Emit the rumor to the chat screen
if (receiver == currentUser) {
onRumorCreated?.invoke(rumor)
}
// Construct the gift wrap event
val gift = nip59MakeGiftWrapAsync(
signer = signer,
receiverPubkey = receiver,
rumor = rumor,
extraTags = listOf(
Tag.custom("k", listOf("14"))
)
)
// Send the event to receiver's NIP-17 relays
val output = client?.sendEvent(
event = gift,
target = SendEventTarget.toNip17(),
ackPolicy = AckPolicy.none(),
authenticationTimeout = Duration.parse("2s")
)
if (output != null) {
// Keep track of rumor IDs
val id = rumor.id() ?: throw IllegalStateException("Rumor ID is null")
rumorMap[id] = output.id
}
}
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
throw IllegalStateException("Failed to send reaction: ${e.message}", e)
}
}
}
@@ -32,6 +32,8 @@ import rust.nostr.sdk.SleepWhenIdle
import rust.nostr.sdk.Timestamp
import rust.nostr.sdk.UnsignedEvent
import rust.nostr.sdk.initLogger
import su.reya.coop.AppStorage
import su.reya.coop.concord.ConcordManager
import kotlin.time.Duration
import kotlin.time.Duration.Companion.seconds
@@ -50,6 +52,7 @@ class Nostr(
val messages = MessageManager(this)
val profiles = ProfileManager(this)
val relays = RelayManager(this)
val concord = ConcordManager(this)
private val isInitialized = MutableStateFlow(false)
@@ -64,10 +67,18 @@ class Nostr(
_newEvents.tryEmit(event)
}
suspend fun init(dbPath: String, logLevel: LogLevel = LogLevel.WARN) {
suspend fun init(
dbPath: String,
storage: AppStorage,
logLevel: LogLevel = LogLevel.WARN,
) {
try {
if (isInitialized.value) return
// Concord's keys live in the encrypted store, which only the Android layer can build.
// Handing it over here keeps it out of the Context-free singleton's constructor.
concord.attach(storage)
// Initialize the logger for nostr client
initLogger(logLevel)
@@ -144,16 +155,35 @@ class Nostr(
val notifications = client?.notifications() ?: return@supervisorScope
val giftWrapQueue = Channel<Event>(1024)
val concordQueue = Channel<Event>(1024)
var processedCount = 0
var eoseReceived = false
try {
concord.restore()
} catch (e: Exception) {
println("Failed to restore Concord state: ${e.message}")
}
launch(defaultDispatcher) { concord.sync() }
launch(defaultDispatcher) {
for (event in concordQueue) {
try {
concord.handlePlaneEvent(event)
} catch (e: Exception) {
println("Failed to handle Concord plane event: ${e.message}")
}
}
}
launch(defaultDispatcher) {
for (event in giftWrapQueue) {
val rumor = messages.extractRumor(event)
processedCount++
// Trigger new message notification
if (rumor != null) {
if (rumor != null && !concord.onInboxRumor(rumor)) {
val isSelfMessage = rumor.author() == signer.publicKeyFlow.value
val isNew = rumor.createdAt().asSecs() >= now.asSecs()
@@ -214,7 +244,11 @@ class Nostr(
}
KindStandard.GIFT_WRAP -> {
giftWrapQueue.send(event)
if (concord.isPlaneAddress(event.author().toHex())) {
concordQueue.send(event)
} else {
giftWrapQueue.send(event)
}
}
else -> {}
@@ -241,8 +241,29 @@ class ChatRepository(
}
}
fun sendReaction(roomId: Long, targetEventId: EventId, reaction: String) {
scope.launch(defaultDispatcher) {
try {
val room = getChatRoom(roomId) ?: throw IllegalArgumentException("Room not found")
nostr.messages.sendReaction(
to = room.members,
targetEventId = targetEventId,
reaction = reaction,
onRumorCreated = {
scope.launch(defaultDispatcher) {
updateRoomState(it, roomId)
}
},
)
} catch (e: Exception) {
showError("Error: ${e.message}")
}
}
}
private suspend fun updateRoomState(event: UnsignedEvent, roomId: Long = event.roomId()) {
val currentUser = nostr.signer.getPublicKeyAsync() ?: return
val isReaction = event.kind().asStd() == KindStandard.REACTION
_state.update { currentState ->
val rooms = currentState.rooms.toMutableMap()
@@ -256,22 +277,24 @@ class ChatRepository(
// New room discovery
val newRoom = Room.new(event, currentUser, roomId).copy(
kind = newKind,
unreadCount = if (isFromMe) 0 else 1
unreadCount = if (isFromMe || isReaction) 0 else 1,
lastMessage = if (isReaction) null else event.content()
)
rooms[newRoom.id] = newRoom
} else if (event.createdAt().asSecs() >= existingRoom.createdAt.asSecs()) {
// Only update preview if message is newer (handles sync/late arrivals)
// Update timestamp for any newer event (DM or Reaction)
// But only update preview if it's a DM
rooms[roomId] = existingRoom.copy(
lastMessage = event.content(),
lastMessage = if (isReaction) existingRoom.lastMessage else event.content(),
createdAt = event.createdAt(),
kind = newKind,
unreadCount = if (isFromMe) existingRoom.unreadCount else existingRoom.unreadCount + 1
unreadCount = if (isFromMe || isReaction) existingRoom.unreadCount else existingRoom.unreadCount + 1
)
} else if (isFromMe && existingRoom.kind != RoomKind.Ongoing) {
// Even if it's an older message, if it's from me, the room is ongoing
// Even if it's an older message or reaction, if it's from me, the room is ongoing
rooms[roomId] = existingRoom.copy(kind = RoomKind.Ongoing)
} else {
// Don't update the room list state for older messages
// Don't update the room list state for older messages or reactions that don't change preview
return@update currentState
}
currentState.copy(rooms = rooms)
@@ -74,4 +74,8 @@ class ChatScreenViewModel(
fun sendFileMessage(file: ByteArray?, type: String?) {
chatRepository.sendFileMessage(id, file, type)
}
fun sendReaction(targetEventId: EventId, reaction: String) {
chatRepository.sendReaction(id, targetEventId, reaction)
}
}