Repository navigation
Block and report, enforced by the server - #1
Merged
Merged
Conversation
A block is one row per direction in `blocks` (0053). It leaves the friendship alone, so the conversation stays in both lists and both people keep the history, and it closes every write into the conversation: messages, edits (a tombstone is still allowed), reactions, sealed answers, new or accepted requests, pins and the timer. `call-ring` refuses a ring across a block, and the client drops blocked peers from the set presence and the call hub listen to. The blocker gets "You blocked X" with Unblock in place of the composer, and the blocked side is told. If both have blocked, one unblocking leaves the other row, so the conversation stays shut. smoke.sql walks that case through RLS as `authenticated`. Report sends the complaint, and the last 30 messages if the reporter ticks the box, to `report-user`, which emails a ticket to the inbox through Resend. Each quoted message is matched by id against `messages`, so the sender and time come from the server. `reports` keeps who reported whom and when, and no text. Fixes found on the way: - a failed 1:1 timer change was an unhandled rejection with no message - set_conversation_timer() had no contact check, so a removed contact could keep changing the timer on the old conversation - accepting or declining a request ignored errors, and a failed decline still announced the person as hidden - removing a reaction was optimistic with no rollback - "Replying to yourself" was hard-coded English - delete-account left the sticker library and anything past the first 1000 objects in a folder - call-ring put an unvalidated peer_id into a PostgREST filter string
PanzerPeter
force-pushed
the
claude/bold-wozniak-1jha9k
branch
from
September 25, 2026 17:35
23fc62a to
4edba45
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Block
A block is one row per direction in a new
blockstable (migration0053). It leaves the friendship in place, so the conversation stays in both lists and both people keep the history. What it closes is every write into the conversation, in either direction:call-ringrefuses them, and the app stops listening for calls and presence from a blocked peerThe blocker sees "You blocked X" with an Unblock button where the message box was, and a "Blocked" badge on the chat row. The blocked person sees "X has blocked you" and can still read the history. If both have blocked, one unblocking leaves the other row, so the chat stays closed.
smoke.sqltests that case through RLS as a signed-in user. People you've blocked are listed under Settings → Privacy → Hidden and blocked, so a block can still be lifted after the chat is deleted.Report
Report in the chat menu sends the complaint to a new
report-userfunction. If the reporter ticks the box, the last 30 messages go with it. The function emails a ticket to hi.nearside@gmail.com through Resend. It looks up each quoted message by id, so the sender and time come from the server; only the wording comes from the reporter's device.reportsstores who reported whom and when, and no text. Limit: 5 reports per person per day.Bugs fixed along the way
set_conversation_timer()had no contact check, so a removed contact could keep changing the timer on the old conversation.delete-accountleft the sticker library behind, plus anything past the first 1,000 files in a folder.call-ringput an unvalidatedpeer_idinto a PostgREST filter string.Deploy steps
supabase/migrations/0053_blocks_and_reports.sqlin the SQL editor.supabase secrets set RESEND_API_KEY=..., thensupabase functions deploy report-user. The default senderonboarding@resend.devonly delivers to the address the Resend account is registered with.call-ringanddelete-account.Testing
npm run typecheck,npm run lintandnpm run testpass: 1,449 tests.schema.sqlon a local Postgres 16, with a matching catalog and passing smoke tests.