Skip to content

feat: revoke (unlink) device via DELETE /devices/:id - #210

Closed
Andreschuks101 wants to merge 136 commits into
codebestia:mainfrom
Andreschuks101:feature/157-revoke-device
Closed

feat: revoke (unlink) device via DELETE /devices/:id#210
Andreschuks101 wants to merge 136 commits into
codebestia:mainfrom
Andreschuks101:feature/157-revoke-device

Conversation

@Andreschuks101

Copy link
Copy Markdown

Revoke (unlink) a device — DELETE /devices/:id

closes #157

Soft-revokes a device and tears down all of its access across the cluster.

Changes

  • Schema/migration: new devices (revokedAt, publicKey, lastSeenAt) and
    device_prekeys tables, relations, types, and migration 0007_device_revocation.
  • DELETE /devices/:id: stamps revokedAt, deletes the device's prekeys,
    disconnects its live sockets, publishes device_revoked on the Redis bus, and
    emits a key_change notice to peers in shared conversations.
  • GET /devices: lists the caller's devices.
  • Revocation service: persistence runs in a transaction; the "last active
    device" rule is enforced atomically inside the UPDATE so concurrent revokes
    cannot remove a user's final device.
  • Socket layer: sockets bind to a per-device room on connect; a revoked or
    foreign device is refused at connection time, excluding it from future fan-out.
    A Redis bus subscriber tears down device sockets on every instance.

Behaviour / acceptance criteria

  • revokedAt set; prekeys removed; live sockets disconnected.
  • Revoked device excluded from future fan-out (leaves its room, rejected on reconnect).
  • Revoking the only active device returns 409.
  • Peers in shared conversations receive a key_change event.

Testing

  • New unit tests for the route and the revocation service (ownership, already-revoked,
    last-device 409, success path, concurrent-revoke race, socket disconnect, peer
    notification, bus publish).
  • Full backend suite passes (109 tests); lint and prettier clean.

Notes

  • Clients pass deviceId in the Socket.IO handshake auth to bind a socket to a device.
  • Device/prekey registration endpoints are out of scope for this issue (revocation only).

codebestia and others added 30 commits May 12, 2026 14:16
feat(backend): PostgreSQL connection with Drizzle ORM + base schema
feat(backend): SIWS wallet auth with JWT + Socket.IO middleware
feat(backend): real-time messaging via Socket.IO with persistent storage
feat(contracts): TokenTransfer Soroban contract with testnet deploy script
feat(web): landing page for Clicked
ci(backend): format check, lint, and test pipeline
Adds GET /users/:id — requires a valid JWT, returns id/username/avatarUrl
plus wallet address/isPrimary pairs; explicit serialization prevents
leaking internal fields. Returns 404 for unknown or malformed IDs.

Fixes codebestia#10
Adds proposals Soroban contract with cast_vote/execute_proposal:
double-vote prevention, expiry enforcement, yes>no pass threshold,
and cross-contract treasury withdraw on passed proposals. Also adds
group_treasury contract gating withdraw behind the proposals contract.
20 tests cover all acceptance criteria.

Fixes codebestia#39
Adds contracts/scripts/deploy_group_treasury.sh mirroring deploy_token_transfer.sh.
Validates DEPLOYER_SECRET, ADMIN_ADDRESS, TOKEN_CONTRACT_ID, and INITIAL_MEMBERS
(comma-separated) before building, uploading WASM, deploying, and calling initialize.
Outputs contract ID and .env setup instructions. Adds GROUP_TREASURY_CONTRACT_ID
to .env.example.

Fixes codebestia#42
- Add useSocket hook connecting to backend via socket.io-client
- Add /app/conversations/[id]/page.tsx with scrollable message thread
- Messages grouped by date with day separators
- Self messages right-aligned (accent), others left-aligned
- Auto-scroll to bottom only when user is already at the bottom
- Shows avatar, sender name, content, and timestamp per message
- Add reusable validate(schema) Express middleware returning structured 400s
- Add ChallengeSchema and VerifySchema for auth routes
- Replace manual if(!field) guards in auth.ts with validate middleware
- Structured error format: { error, issues: [{ field, message }] }
- Add supertest + 6 tests covering valid input, missing fields, wrong types
feat: group treasury contract, Makefile, and AI agent chat/fraud endpoints
…oint-10

feat(api): implement GET user profile endpoint
- Add last_read_message_id nullable FK column to conversation_members schema
- Generate migration 0002_greedy_hellion.sql (ALTER TABLE + FK constraint)
- Add message_read Socket.IO event handler with membership + message validation
- Persist lastReadMessageId per userId/conversationId in conversation_members
- Broadcast read_receipt { userId, lastReadMessageId } to conversation room
- Prevent spoofed reads: validates message exists in target conversation
- Add 4 tests covering success, non-member error, invalid message, DB persistence
- Extract Express app into src/app.ts for testability (server start stays in index.ts)
- Add supertest dev dependency for HTTP assertion
- Add 10 integration test cases for POST /auth/challenge and POST /auth/verify:
  challenge: valid walletAddress, missing walletAddress, empty body
  verify: new user JWT, existing user JWT, expired nonce, invalid sig,
          missing fields, empty body, malformed wallet address (Keypair throws)
- All mocks (DB, nonce, Stellar SDK) are offline — no real network or DB required
- 21 tests pass across 3 test files
- Add ioredis dependency and src/lib/redis.ts with graceful null fallback
- Cache GET /conversations per userId with 30-second TTL (CONV_CACHE_TTL)
- Cache key format: conversations:<userId>
- Invalidate cache for all conversation members after send_message
- Invalidate cache for all new members after create_conversation
- Redis errors silently degrade: requests fall through to DB
- Add 5 tests: cache hit skips DB, cache miss writes to Redis, null Redis fallback,
  Redis error fallback, per-user key format verified
codebestia and others added 23 commits June 23, 2026 12:13
[CONTRACT] Add member management to Group Treasury
created apps/web/src/components/ui/Modal.tsx:1
…mponent

add WalletAddress component with copy and explorer link
…ndicator

feat: add online presence indicator to DM avatars and member count to…
feat(ui): implement CopyButton with clipboard API and framer-motion t…
Centralize admin check and update backend configuration
@drips-wave

drips-wave Bot commented Jun 25, 2026

Copy link
Copy Markdown

@Andreschuks101 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No need to define the devices anymore.
Work with the already defined one.
Merge main into your branch to get it.

@codebestia

Copy link
Copy Markdown
Owner

Hello @Andreschuks101
Please resolve the conflicts.

@codebestia

Copy link
Copy Markdown
Owner

Hello @Andreschuks101
Unfortunately I will be closing this PR.
There was an issue with the main branch which lead to a fix that affected this PR.
Please raise another PR.
I apologize for the inconvenience this will be causing you.

@codebestia codebestia closed this Jun 26, 2026
@codebestia

Copy link
Copy Markdown
Owner

Please update your main branch before raising another PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DELETE /devices/:id — revoke (unlink) a device