Repository navigation
Profiles: emoji, pronouns and website, served as OpenProfile.md (0.6.0, qc 0.5.0) - #293
Conversation
…0, qc 0.5.0) OpenProfile 0.4 default fields on qrypt.chat profiles: - users.emoji / users.pronouns (migration 20261006230000, applied on dev2). - Settings > Profile edits emoji (OpenEmoji picker), pronouns, website, bio. - /u/<username> shows them and links rel=openprofile to /u/<username>/openprofile.md (same public columns, via @profullstack/openprofile). - Chat shows a sender's emoji (OpenEmoji art) and pronouns. - qc: qc profile [--emoji --pronouns --website --bio] [--openprofile]; the TUI shows senders' emoji (HD where supported) and pronouns. - /api/profile/update used setSession with an empty refresh token, so updates ran anonymously and matched no row: now a token-scoped client. Fields are validated (one emoji grapheme, 40-char pronouns, http(s) only). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| {!isOwn && ( | ||
| <div className="message-sender"> | ||
| {/* The server only stores a single emoji grapheme here, so this is our artwork, not markup. */} | ||
| {sender?.emoji && <span aria-hidden="true" className="message-sender-emoji" dangerouslySetInnerHTML={{ __html: `${renderOpenEmoji(String(sender.emoji).replace(/[&<>"']/g, (c) => `&#${c.charCodeAt(0)};`))} ` }} />} |
ThreatCrush Security Scan13 finding(s) MEDIUM: 9 | LOW: 4
Snippets are redacted; ThreatCrush never prints matched credential material. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Anthony: OpenProfile should support emoji, website and pronouns by default, "qc too".
Profile fields (OpenProfile 0.4 defaults)
20261006230000_user_emoji_pronouns.sqladdsusers.emoji(≤32 chars) andusers.pronouns(≤40 chars). It is already applied on dev2, with PostgREST reloaded.websitealready existed.rel="me"website link. It also linksrel="openprofile"to…@profullstack/openprofile0.2.0. It covers name, Kind, Handle, Emoji, Pronouns, Web, Avatar, the first bio line as the headline, and Accounts → the qrypt.chat page. It uses onlyPUBLIC_PROFILE_COLUMNS, the same boundary asby-username, which still never includes phone_number or salt.qc 0.5.0
qc profileshows your profile.qc profile --emoji 🔭 --pronouns she/her --website https://… --bio …sets fields (an empty value clears one), and--openprofileprints the OpenProfile.md.Bug fixed on the way:
/api/profile/updatecalledsetSession({ refresh_token: '' }), which auth-js refuses. Updates ran anonymously and RLS matched no row. It now uses a token-scoped client. Inputs are validated: emoji must be exactly one emoji grapheme, pronouns are bounded with no markup, and websites must be http(s), with https:// added to a bare domain.Tests: 700/700, including field validation, an OpenProfile round trip through the package, the update route, and qc argument parsing.
next buildpasses.Note: messaging is Preshy's area; Anthony asked for this directly.
🤖 Generated with Claude Code