Skip to content

feat(bridge): sign chat lookup via X-Genie-Signature when keys are present - #1566

Merged
namastex888 merged 1 commit into
devfrom
feat/sign-chat-lookup
Apr 30, 2026
Merged

namastex888 merged 1 commit into
devfrom
feat/sign-chat-lookup

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Summary

Closes the second unsigned callsite in genie→omni HTTP. The bridge calls `GET /api/v2/chats?externalId=` while spawning a claude pane to use the contact's display name as the tmux window title — today bearer-only.

After omni#568 (P0a kill-switch) + omni#569 (P0b operator-host signing), the remaining gap is genie callsites other than `registerAgentInOmni` (which Group 3 already wraps). If an operator locks down a real instance, this lookup would silently fall back to using the raw JID as the window name.

Fix

Thread `signOmniRequest('GET', path, '')` through the same path used by `registerAgentInOmni`. When no host keypair exists locally, `signOmniRequest` returns null and we go bearer-only — matching today's behavior, fully backward-compatible.

Verification

bun run typecheck                       # clean
bunx biome check src/services/executors/claude-code.ts   # clean
bun test src/services/executors/        # 113 pass / 0 fail

Test plan

  • CI green
  • After merge: lock down an instance with `omni instances update --require-genie-signature`, send a WhatsApp message, confirm the bridge spawns a tmux pane with the contact's display name (not the raw JID)
  • Hosts that haven't run `genie omni handshake` still work unchanged

Surface coverage after this PR

Genie callsite Signs?
`registerAgentInOmni` (POST /api/v2/agents) ✅ since #1539 (group 3)
`findOmniAgent` (GET /api/v2/agents?name=...) ✅ since #1539 (group 3)
`lookupChatName` (GET /api/v2/chats) ✅ this PR
`genie omni handshake` (POST /api/v2/trust/handshake) n/a — bootstrap, auth-exempt by design

That's all genie→omni HTTP callsites. NATS-side bridge dispatch doesn't go through HTTP auth.

Refs: omni-host-fingerprint-trust wish; P1 follow-up to omni#569

…esent

Closes the second unsigned callsite in genie→omni HTTP. The bridge
calls GET /api/v2/chats?externalId=<jid> while spawning a claude pane
to use the contact's display name as the tmux window title.

Today this call goes bearer-only. After P0a (#568) added per-instance
lockdown and P0b (#569) gave the omni CLI signing capability, the
remaining gap is genie callsites OTHER than registerAgentInOmni (which
group 3 already wraps). If an operator locks down a real instance, the
bridge would have failed to look up the chat name and silently fallen
back to using the raw JID.

Fix: thread `signOmniRequest('GET', path, '')` through the same path
used by registerAgentInOmni. When no host keypair exists locally,
signOmniRequest returns null and we go bearer-only — matching today's
behavior, fully backward-compatible.

Refs: omni-host-fingerprint-trust wish; P1 (\"extend signing coverage to
other genie callsites\") from PR #569's followup list
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@coderabbitai

coderabbitai Bot commented Apr 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: d917a721-336a-4ea3-a901-b5cc51d77af3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/sign-chat-lookup

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@namastex888
namastex888 merged commit c4c9de8 into dev Apr 30, 2026
16 checks passed
namastex888 pushed a commit that referenced this pull request Apr 30, 2026
Replaces pgserve v2's filesystem-bound fingerprint
(sha256(realpath ‖ name ‖ uid)) with an opt-in host-signed identity that
derives the per-package DB fingerprint from genie's existing per-host
ed25519 keypair (~/.genie/keys/genie-host.ed25519). Same package on
same host → same database, regardless of cwd or path. Closes the
multi-checkout-orphan defect (two app__automagik_genie_* DBs visible
on the demo host today) and reuses the signing primitive genie
already ships for omni handshake (#1537) + chat-lookup signing (#1566).

8 execution groups across pgserve + genie. Wish is structurally clean
(genie wish lint pgserve-host-signed-identity reports no violations).
Ready for /review handoff.
@automagik-genie
automagik-genie deleted the feat/sign-chat-lookup branch September 25, 2026 04:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants