From 0420c59c5afe42b3e02508d9ea64776bfcd8494a Mon Sep 17 00:00:00 2001 From: Coracle-Bot Date: Sat, 12 Sep 2026 08:31:37 +0000 Subject: [PATCH] Read supportedmethods for the logged in pubkey rather than for the relay --- src/app/access.ts | 4 ++-- src/app/management.ts | 21 ++++++++++++++++----- 2 files changed, 18 insertions(+), 7 deletions(-) diff --git a/src/app/access.ts b/src/app/access.ts index 8b5988b9..70029585 100644 --- a/src/app/access.ts +++ b/src/app/access.ts @@ -383,8 +383,8 @@ export class Access { sleep(300), ]) - // The relay reports methods relay-wide rather than per-user, so a listed method can - // still come back "blocked" for this particular user — treat that as having no claim. + // A relay that reports methods relay-wide rather than per-user can still come back + // "blocked" for this particular user — treat that as having no claim. if (methods?.includes("createclaim")) { const {result: claims} = await management.listClaims() diff --git a/src/app/management.ts b/src/app/management.ts index aa35c387..126d7994 100644 --- a/src/app/management.ts +++ b/src/app/management.ts @@ -1,7 +1,7 @@ import {derived, readable, writable} from "svelte/store" import {ago, MINUTE, now, simpleCache} from "@welshman/lib" import {ROOM_CREATE_PERMISSION, hexTags, tagValues} from "@welshman/util" -import {relayManagement, user} from "@app/core" +import {fromApp, relayManagement, user} from "@app/core" import {deriveEventsForUrl} from "@app/repository" export type BannedPubkeyItem = { @@ -21,11 +21,11 @@ export const deriveSpaceBannedPubkeyItems = (url: string) => { return store } -export const deriveSpaceSupportedMethods = simpleCache(([url]: [string | undefined]) => { +const deriveSupportedMethodsForPubkey = simpleCache(([, url]: [pubkey: string, url: string]) => { let checkedAt = 0 return readable([], set => { - if (url && checkedAt < ago(5, MINUTE)) { + if (checkedAt < ago(5, MINUTE)) { checkedAt = now() relayManagement @@ -41,10 +41,21 @@ export const deriveSpaceSupportedMethods = simpleCache(([url]: [string | undefin }) }) +// The request is signed as the logged in user and answered for that pubkey, so the methods +// belong to a user as much as to a url and logging in has to swap them out. +export const deriveSpaceSupportedMethods = (url?: string) => + fromApp($app => { + if (url && $app.user) { + return deriveSupportedMethodsForPubkey($app.user.pubkey, url) + } + + return readable([]) + }) + // User -// A relay answers supportedmethods with everything it implements rather than with what the -// caller may use, so all this can tell us is that the call wasn't refused outright. +// Holding any management method at all is what makes someone staff here. A relay that still +// answers relay-wide tells us only that the call wasn't refused outright. export const deriveUserIsSpaceAdmin = (url?: string) => derived(deriveSpaceSupportedMethods(url), $methods => $methods.length > 0)