NEC-130: Editors cannot see collaborators' key fingerprints #194

Merged
nectenda-agent merged 3 commits from worktree-nec-130-editors-cannot-see-collaborators-key-fin into main 2026-09-27 13:47:59 +01:00
Collaborator

Task: NEC-130 — https://projectron.nerchure.com/tasks/130

The People dialog was offered only for folders this vault owns, so an editor could never see or compare a collaborator's key fingerprint. Comparing fingerprints is the defence against a server that substitutes keys (docs/security-model.md, CRYPTO-104), and it takes both people. Every member now reaches the dialog from the palette, the folder menu, the folder's settings page and the organisation's folder list. Editors see names, roles, fingerprints and Mark as compared; invite, role, remove, invitations and add-from-roster stay owner-only. The server already let any member list a folder's people, so only the plugin changes. Row logic moves to member-rows.ts with unit tests (mutation-checked both ways), and identity.test.ts gains an e2e step that opens the dialog as the editor vault and records a comparison.

Spec: docs/changes/NEC-130-editor-people-view/spec.md

Changelog

Editors can now open a shared folder's People list to see and compare everyone's key fingerprints and mark them as compared.

Task: NEC-130 — https://projectron.nerchure.com/tasks/130 The People dialog was offered only for folders this vault owns, so an editor could never see or compare a collaborator's key fingerprint. Comparing fingerprints is the defence against a server that substitutes keys (docs/security-model.md, CRYPTO-104), and it takes both people. Every member now reaches the dialog from the palette, the folder menu, the folder's settings page and the organisation's folder list. Editors see names, roles, fingerprints and Mark as compared; invite, role, remove, invitations and add-from-roster stay owner-only. The server already let any member list a folder's people, so only the plugin changes. Row logic moves to member-rows.ts with unit tests (mutation-checked both ways), and identity.test.ts gains an e2e step that opens the dialog as the editor vault and records a comparison. Spec: `docs/changes/NEC-130-editor-people-view/spec.md` ## Changelog Editors can now open a shared folder's People list to see and compare everyone's key fingerprints and mark them as compared.
The People dialog and every way into it were offered only for folders
this vault owns, so an editor could never see or compare a collaborator's
key fingerprint. Comparing is the defence against a server that swaps
keys, and it takes both people.

Every member now reaches the dialog from the palette, the folder menu,
the folder's settings page and the organisation's folder list. An editor
sees names, roles, fingerprints and "Mark as compared"; the invite row,
role dropdown, Remove, invitations and add-from-roster stay owner-only.
The row rule moves to member-rows.ts so it is tested without Obsidian.

Task: NEC-130

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P25qBQE9kWrX9Eg5VALBMC
The seeded owner never enrols a key, so its row had no fingerprint and
no "Mark as compared". The step now gives the folder's owner a key on
the shard for its duration and restores the row afterwards. It waits for
the owner's row rather than the first description, which is the People
heading's and empty. It checks the comparison under the owner's address
and the fingerprint that was shown, and closes the dialog in a finally.

Task: NEC-130

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P25qBQE9kWrX9Eg5VALBMC
Expect People… on an editor's folder row
All checks were successful
Release note / release-note (pull_request) Successful in 13s
CI / build (pull_request) Successful in 4m39s
CI / e2e (pull_request) Successful in 5m25s
CI / promote (pull_request) Has been skipped
bc14585aa1
The unshare step asserted an editor's synced-folder row carries only
"Stop syncing here". It now also offers the read-only people list, so
the step expects it on this build and the old row on the last published
plugin. What it guards is unchanged: no way to end a folder that is not
the editor's to end.

Task: NEC-130

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P25qBQE9kWrX9Eg5VALBMC
cruelacid force-pushed worktree-nec-130-editors-cannot-see-collaborators-key-fin from bc14585aa1
All checks were successful
Release note / release-note (pull_request) Successful in 13s
CI / build (pull_request) Successful in 4m39s
CI / e2e (pull_request) Successful in 5m25s
CI / promote (pull_request) Has been skipped
to 411ffd68ad
All checks were successful
Release note / release-note (pull_request) Successful in 13s
CI / build (pull_request) Successful in 4m42s
CI / e2e (pull_request) Successful in 5m20s
CI / promote (pull_request) Has been skipped
Deploy site / deploy (push) Successful in 50s
CI / build (push) Successful in 5m6s
CI / e2e (push) Successful in 5m23s
CI / promote (push) Successful in 32s
2026-09-27 11:08:22 +01:00
Compare
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda!194
No description provided.