Repository navigation
feat(channels): opt-in auto-approval for new shared channels - #196
Conversation
Review — CS-lead review PR#196 auto-approve — head 218c8fbVerdict: APPROVE with nits. Nothing blocks the merge once CI is green on this head. Recommendation: merge the code, but keep Evidence tags: [T] test run, [A] analysis. Verified
Nits (non-blocking)
Not verified
|
Brings in #182 (9d29dae), #191, #194 and #196, so that the observer anchor and the backfill are tested against the current base. Master's server now indexes live observations from the persisted resolved_path (#182). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QbNdgonR8kq7SPEU7LcmXD
Summary
Add an opt-in
channelProposals.autoApprovesetting (defaultfalse). When public channel suggestions are enabled, the ingestor approves a brand-new valid hashtag channel in the same database transaction as its insert and activates its decryption key through the existing queue flow. The read-only server remains read-only.Existing pending, rejected and revoked proposals are not auto-approved by resubmission or restart. Duplicate requests and crash replays remain idempotent. The configured
maxApprovedcap is enforced before insertion; at capacity the request fails without creating or activating a channel. The existing public-submission gate (strongapiKey), name validation, queue cap and global submission rate limit remain unchanged.Verification
cmd/ingestor: fullgo test ./...passed; focused auto-approval tests also passed under-race;go vet ./...passed.cmd/serverandinternal/channelregistry:go test ./...passed.test-channel-proposals-e2e.jspassed 23/23 checks, including the new auto-approval flow in a real browser, visibility in an independent session, and preservation of an older pending suggestion.test-channel-proposals.jspassed 32/32;git diff --check, Go formatting, JavaScript syntax and example JSON validation passed.Operations and limitations
This changes no deployed configuration. To enable it, set both
channelProposals.enabled: trueandchannelProposals.autoApprove: truein the shared config, retain a strong adminapiKey, and restart the ingestor. Disabling auto-approval later does not revoke already approved channels.On a public instance, visitors can consume the finite approved-channel allowance, subject to the existing global submission rate limit. Rejected/revoked names are protected while their rows remain; after retention removes a row, the same name is indistinguishable from a new name and may be auto-approved again. This PR does not add a permanent denylist.
No merge, deploy, or production configuration change is included.