Repository navigation
feat(bridge): sign chat lookup via X-Genie-Signature when keys are present - #1566
Conversation
…esent Closes the second unsigned callsite in genie→omni HTTP. The bridge calls GET /api/v2/chats?externalId=<jid> while spawning a claude pane to use the contact's display name as the tmux window title. Today this call goes bearer-only. After P0a (#568) added per-instance lockdown and P0b (#569) gave the omni CLI signing capability, the remaining gap is genie callsites OTHER than registerAgentInOmni (which group 3 already wraps). If an operator locks down a real instance, the bridge would have failed to look up the chat name and silently fallen back to using the raw JID. Fix: thread `signOmniRequest('GET', path, '')` through the same path used by registerAgentInOmni. When no host keypair exists locally, signOmniRequest returns null and we go bearer-only — matching today's behavior, fully backward-compatible. Refs: omni-host-fingerprint-trust wish; P1 (\"extend signing coverage to other genie callsites\") from PR #569's followup list
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Replaces pgserve v2's filesystem-bound fingerprint (sha256(realpath ‖ name ‖ uid)) with an opt-in host-signed identity that derives the per-package DB fingerprint from genie's existing per-host ed25519 keypair (~/.genie/keys/genie-host.ed25519). Same package on same host → same database, regardless of cwd or path. Closes the multi-checkout-orphan defect (two app__automagik_genie_* DBs visible on the demo host today) and reuses the signing primitive genie already ships for omni handshake (#1537) + chat-lookup signing (#1566). 8 execution groups across pgserve + genie. Wish is structurally clean (genie wish lint pgserve-host-signed-identity reports no violations). Ready for /review handoff.
Summary
Closes the second unsigned callsite in genie→omni HTTP. The bridge calls `GET /api/v2/chats?externalId=` while spawning a claude pane to use the contact's display name as the tmux window title — today bearer-only.
After omni#568 (P0a kill-switch) + omni#569 (P0b operator-host signing), the remaining gap is genie callsites other than `registerAgentInOmni` (which Group 3 already wraps). If an operator locks down a real instance, this lookup would silently fall back to using the raw JID as the window name.
Fix
Thread `signOmniRequest('GET', path, '')` through the same path used by `registerAgentInOmni`. When no host keypair exists locally, `signOmniRequest` returns null and we go bearer-only — matching today's behavior, fully backward-compatible.
Verification
Test plan
Surface coverage after this PR
That's all genie→omni HTTP callsites. NATS-side bridge dispatch doesn't go through HTTP auth.
Refs: omni-host-fingerprint-trust wish; P1 follow-up to omni#569