Skip to content

Profiles: emoji, pronouns and website, served as OpenProfile.md (0.6.0, qc 0.5.0) - #293

Merged
ralyodio merged 1 commit into
masterfrom
feat/profile-emoji-pronouns
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
feat/profile-emoji-pronouns

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Anthony: OpenProfile should support emoji, website and pronouns by default, "qc too".

Profile fields (OpenProfile 0.4 defaults)

  • Migration 20261006230000_user_emoji_pronouns.sql adds users.emoji (≤32 chars) and users.pronouns (≤40 chars). It is already applied on dev2, with PostgREST reloaded. website already existed.
  • Settings → Profile (new section) edits emoji (with the OpenEmoji picker), pronouns, website and bio. An empty field hides it.
  • /u/<username> shows the emoji next to the name, pronouns after the handle, the bio and a rel="me" website link. It also links rel="openprofile" to…
  • /u/<username>/openprofile.md (new): the same public profile as OpenProfile.md, built with @profullstack/openprofile 0.2.0. It covers name, Kind, Handle, Emoji, Pronouns, Web, Avatar, the first bio line as the headline, and Accounts → the qrypt.chat page. It uses only PUBLIC_PROFILE_COLUMNS, the same boundary as by-username, which still never includes phone_number or salt.
  • Chat shows each sender's emoji (as OpenEmoji art) and pronouns.

qc 0.5.0

  • qc profile shows your profile. qc profile --emoji 🔭 --pronouns she/her --website https://… --bio … sets fields (an empty value clears one), and --openprofile prints the OpenProfile.md.
  • The TUI shows each sender's emoji (drawn in HD where supported) and pronouns.

Bug fixed on the way: /api/profile/update called setSession({ refresh_token: '' }), which auth-js refuses. Updates ran anonymously and RLS matched no row. It now uses a token-scoped client. Inputs are validated: emoji must be exactly one emoji grapheme, pronouns are bounded with no markup, and websites must be http(s), with https:// added to a bare domain.

Tests: 700/700, including field validation, an OpenProfile round trip through the package, the update route, and qc argument parsing. next build passes.

Note: messaging is Preshy's area; Anthony asked for this directly.

🤖 Generated with Claude Code

…0, qc 0.5.0)

OpenProfile 0.4 default fields on qrypt.chat profiles:
- users.emoji / users.pronouns (migration 20261006230000, applied on dev2).
- Settings > Profile edits emoji (OpenEmoji picker), pronouns, website, bio.
- /u/<username> shows them and links rel=openprofile to
  /u/<username>/openprofile.md (same public columns, via
  @profullstack/openprofile).
- Chat shows a sender's emoji (OpenEmoji art) and pronouns.
- qc: qc profile [--emoji --pronouns --website --bio] [--openprofile]; the
  TUI shows senders' emoji (HD where supported) and pronouns.
- /api/profile/update used setSession with an empty refresh token, so
  updates ran anonymously and matched no row: now a token-scoped client.
  Fields are validated (one emoji grapheme, 40-char pronouns, http(s) only).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
{!isOwn && (
<div className="message-sender">
{/* The server only stores a single emoji grapheme here, so this is our artwork, not markup. */}
{sender?.emoji && <span aria-hidden="true" className="message-sender-emoji" dangerouslySetInnerHTML={{ __html: `${renderOpenEmoji(String(sender.emoji).replace(/[&<>"']/g, (c) => `&#${c.charCodeAt(0)};`))} ` }} />}
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

13 finding(s)

MEDIUM: 9 | LOW: 4

Severity Rule Location
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:38
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:66
MEDIUM js-unescaped-html-sink src/app/faq/page.jsx:57
MEDIUM js-unescaped-html-sink src/app/layout.jsx:137
MEDIUM js-unescaped-html-sink src/app/layout.jsx:141
MEDIUM js-unescaped-html-sink src/app/page.jsx:47
MEDIUM redos-nested-quantifier src/lib/auth/dns-name.js:88
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:84
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:128
LOW secret-generic-credential src/app/api/auth/register-anon/route.test.js:32
LOW secret-jwt tests/debug-sms.js:10
LOW secret-generic-credential tests/private-key-import-export.test.js:252
LOW secret-generic-credential tests/private-key-import-export.test.js:264

Snippets are redacted; ThreatCrush never prints matched credential material.

@socket-security

Copy link
Copy Markdown
Contributor

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​profullstack/​openprofile@​0.2.0781009992100

View full report

@socket-security

Copy link
Copy Markdown
Contributor

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Low adoption: npm @profullstack/openprofile

Location: Package overview

From: package.json → npm/@profullstack/openprofile@0.2.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@profullstack/openprofile@0.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@ralyodio
ralyodio merged commit 2a4332a into master Oct 6, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants