M21: push relay #33

Open
opened 2026-10-02 01:51:18 +00:00 by jhgaylor · 0 comments
Owner

Depends on: #29

From PLAN.md, "Control track → M21: push relay".


  • Today: each home daemon holds VAPID keys, and each phone subscribes to each daemon.
  • With control:
    • control holds one VAPID key pair;
    • devices subscribe once;
    • daemons send notifications through control, addressed to the user's devices.
  • Payloads are encrypted for each device's push subscription (RFC 8291), so control and the browser's push service see neither the title nor the body. Control sees only "daemon X notified user Y".
  • Per-user rules come from M12: needs-input goes to editors who opted in, and approvals go to whoever is asked.
  • Done when:
    • a phone that never connected to a Mac gets "needs input" from an agent there, through control;
    • tapping it opens that pane over the relay;
    • control's logs show no notification text.
**Depends on:** #29 _From PLAN.md, "Control track → M21: push relay"._ --- - **Today:** each home daemon holds VAPID keys, and each phone subscribes to each daemon. - **With control:** - control holds one VAPID key pair; - devices subscribe once; - daemons send notifications through control, addressed to the user's devices. - **Payloads are encrypted** for each device's push subscription (RFC 8291), so control and the browser's push service see neither the title nor the body. Control sees only "daemon X notified user Y". - **Per-user rules** come from M12: `needs-input` goes to editors who opted in, and approvals go to whoever is asked. - **Done when:** - a phone that never connected to a Mac gets "needs input" from an agent there, through control; - tapping it opens that pane over the relay; - control's logs show no notification text.
Sign in to join this conversation.
No description provided.