Skip to content

feat(bot-mode): share files through Group Chats - #96761

Closed
dokterdok wants to merge 14 commits into
NousResearch:mainfrom
dokterdok:feat/group-chat-attachment-surfaces-20260828
Closed

dokterdok wants to merge 14 commits into
NousResearch:mainfrom
dokterdok:feat/group-chat-attachment-surfaces-20260828

Conversation

@dokterdok

Copy link
Copy Markdown

The user problem

Sharing a file with a Bot Group Chat should feel like sharing one in any normal
chat. It should not matter whether the chat is hosted by a gateway, still run by
Desktop, or reached from Signal, Telegram, WhatsApp, Slack, or another Hermes
messaging adapter.

Today those paths do not share one complete lifecycle. This draft connects the
existing Desktop attachment UX to the durable gateway layer from the parent PR.

Important

This draft is stacked on the attachment runtime PR. Review
57962642d7..a7eddf11a3.

What users can do

From Desktop

Use the existing picker, paste, or drag and drop in a Group Chat. Images, PDFs,
Office files, archives, and other files are uploaded before the durable room
command is accepted.

From a messaging app

Attach a file to the normal Group Chat command:

/group list
/group 2
/group 2 send

The attachment may be sent with text or by itself. Hermes localizes it through
the adapter's authenticated media cache, stores it once, and reports the same
Group Chat status and recent activity as a text message.

In history

History keeps the file name, type, size, opaque ID, and source gateway, never
the raw bytes or a machine path. Images can load a preview on demand; files can
be downloaded on demand. The local cache is bounded.

What users can rely on

  • The draft stays in the composer until every upload and the durable command
    enqueue succeed.
  • Typing during an upload preserves the newer text and newly added files while
    removing only the files that were actually sent.
  • Transport redelivery reuses the same upload and room entry, even after the
    adapter's temporary file has disappeared.
  • A Desktop command reads files only while it holds the live room claim.
  • The Bot roster is frozen at send time. A Bot added later cannot receive an
    older file, and an unavailable original Bot keeps the command safely pending.
  • A Stop request can overtake a long upload/read and no partial file reaches a
    Bot turn.
  • One bad or expired file produces an actionable error without exposing paths,
    URLs, bytes, or provider details.

Compatibility

This reuses the attachment controls and per-session image/PDF/file RPCs merged
in #89486 and #89540. It preserves opaque IDs so the open chip interaction in
#89758 can compose with gateway-backed history; if #89758 lands first, this
draft should rebase onto its final chip implementation rather than duplicate it.

Boundaries

  • This stack completes same-gateway, Desktop-driven, and messaging-client file
    flows.
  • Cross-gateway RoomLink byte transfer remains the next stacked increment.
  • Messaging adapters must provide authenticated, already-localized cache paths,
    which is the existing MessageEvent.media_urls contract. Remote URLs and
    symlinks fail closed.
  • Unsolicited notifications and public file URLs are not added.

Validation at a7eddf11a3

Check Result
Focused Python suite 242 passed
Focused Desktop/hosted-client suite 165 passed
Desktop TypeScript check passed
Ruff passed
git diff --check passed

Coverage includes image-only and attachment-only sends, PDF and generic files,
adapter redelivery, upload interruption, lease loss, priority Stop, send-time
recipient freeze, restart/replay, lazy history reads, tampering, MIME mismatch,
path traversal, symlinks, quotas, abandoned-upload cleanup, and composer edits
during upload.

Exact-head live UAT and screenshots will be added before this stack leaves
draft.

Related work

Type of change

  • Bug fix
  • New feature
  • Security fix
  • Tests
  • Refactor

@alt-glitch alt-glitch added type/feature New feature or request P3 Low — cosmetic, nice to have comp/desktop Electron desktop app (apps/desktop/*) comp/gateway Gateway runner, session dispatch, delivery comp/cli CLI entry point, hermes_cli/, setup wizard comp/tui Terminal UI (ui-tui/ + tui_gateway/) comp/plugins Plugin system and bundled plugins platform/slack Slack app adapter needs-decision Awaiting maintainer decision before any implementation sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages sweeper:risk-security-boundary Sweeper risk: may affect sandboxing, auth, credentials, or sensitive data labels Aug 28, 2026
@dokterdok

Copy link
Copy Markdown
Author

Closing this cumulative prototype now that #97681 captures the user contract, safety boundaries, and phased landing plan against the rebuilt Bot Mode tree. Its useful layer can be re-cut as a narrow current-main contribution after the foundation direction is agreed.

@dokterdok dokterdok closed this Aug 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/cli CLI entry point, hermes_cli/, setup wizard comp/desktop Electron desktop app (apps/desktop/*) comp/gateway Gateway runner, session dispatch, delivery comp/plugins Plugin system and bundled plugins comp/tui Terminal UI (ui-tui/ + tui_gateway/) needs-decision Awaiting maintainer decision before any implementation P3 Low — cosmetic, nice to have platform/slack Slack app adapter sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages sweeper:risk-security-boundary Sweeper risk: may affect sandboxing, auth, credentials, or sensitive data sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state type/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants