* badges: webapp (#7433)
* badges: service migrations, store and catalog
* badges: BTCPay provider and settlement poller
* badges: web listener and /api endpoints
* web: checkout single-page app
* badges: tests and BTCPay fixtures
* badges: README and ini reference
* badges: fix hex16 build on GHC 8.10.7
* badges: Stripe card lane
* badges: fix Stripe card checkout, add theming
* badges: add a discount row to the order summary
* badges: site navbar, embedding, theme, Forget move
* badges: use SB code prefix in web checkout
* badges: rename sxb app namespace to sb
* badges: embed checkout nav via site; keep original app navbar
* badges: post iframe height, apply site background when embedded
* badges: embed dark surfaces, steadier iframe height
* badges: hide app footer when embedded
* badges: size embedded body to content, not viewport
* badges: declare color-scheme to stop reload flash
* badges: fade shell in on load, no reload blank
* badges: prerender app shell into index.html
* badges: pre-paint theme, hide shell on deep reload
* badges: logo returns to landing client-side
* badges: embedded wizard back, buy-a-code, resume
* badges: signal app-managed screens, resume across reload
* badges: rebuild wizard history on deep load so Back walks it
* badges: carry welcome-page height as the iframe floor
* badges: keep selection on Buy a code; rename to Your codes
* badges: read web shell as UTF-8, not locale
* badges: resume the exact paid order after Stripe card redirect
* badges: move docker deploy under scripts
* badges: add serve_webapp toggle and webapp export
* badges: wire split webapp deploy in docker config
* badges: quiet agent logs by default
* badges: resume card redirect in the embedded frame
* badges: migrate Stripe adapter to PaymentIntents
* badges: correct Stripe restricted key scopes in ini example
* badges: card via Payment Element and PaymentIntents
* badges: fix stale Checkout Session wording in Stripe adapter
* badges: fix stale CheckoutActions reference in card comment
* badges: order shell stylesheet before bootstrap script
* badges: remove development card stand-in
* badges: theme the Stripe card form with the site palette
* badges: exclude web from the Haskell build stage
* badges: unify invoice cancel and mark canceled
* badges: default log level to info
* badges: unify closed-invoice buy-again button
* badges: mute agent connection logs at info level
* badges: show purchase time in local timezone in Your codes
* badges: log service events on own channel, quiet agent
* badges: fold service migrations into one baseline
* badges: run compose on postgres over host network
* badges: use high-res hero art
* badges: add web CI to catch stale builds
* badges: rebuild web shell from committed source
* badges: normalize invoice-code link and columns
* badges: drop unused columns, rename index
* badges: note deferred receipt_hash in migrations
* badges: apply code-review fixes
* badges: reduce comments across service and web
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
* badges: improve web page (#7546)
* badges: improve web page
* improve layout
* improve layout
* fix
* small changes
---------
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
* badges: read one issuer key from the ini
* badges: move and group the service tests
* badges: service fixes (#7567)
* badges: match the redeem error wording in tests
* badges: drop unused imports in the bot tests
* badges: cancel Stripe orders when they expire
* badges: correct the Stripe config and docs
* badges: refuse to revoke a redeemed code
* badges: make the fake Stripe cancel like Stripe
* badges: limit replayed webhook deliveries
---------
Co-authored-by: sh <37271604+shumvgolove@users.noreply.github.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
Co-authored-by: shum <github.shum@liber.li>
Co-authored-by: spaced4ndy <8711996+spaced4ndy@users.noreply.github.com>
- redeem errors are typed (CEBadgeRedeemError) instead of matched by text in the apps
- service timeout (A_SERVICE) decodes in the apps and offers Retry via the existing retry alert
- unexpected redeem errors show the error itself instead of a generic message
- service error codes are a typed enum in the apps (BadgeServiceErrorCode)
- CRBadgeRedeemed returns badge state, so the apps skip a second round-trip after redeem
- setBadgeAlertAcked is scoped to user_id
- badgeChanged updates non-active profiles, so other profiles' badges don't go stale
- pitch banner is not shown to a profile that already has a badge
- one badgeTypeName per platform, used by the badge screen and the badge info alert
- BadgeAlertKind and BadgeAlertPrice decode via standard JSON, no custom decoders
- dead "Support ended" title branch removed from Your Badge view
- kotlin: users from badge responses carry remoteHostId
- kotlin: redeem code field keeps the IME's cursor and composition state
- kotlin: "Get your code" shown in all flavours
- kotlin: "Don't show again" -> "Dismiss", matching iOS
- kotlin: parseBadgeCode moved next to its FFI in platform/Core.kt
- kotlin: BadgesView no longer cross-fades on badge state updates
- kotlin: section title not uppercased
- ios: redeem code field parses once per change
- ios: A_SERVICE rejected reason is not decoded
- CLI: "cannot redeem badge code: ..." with the source of the error
- comments clarified
* core: support message signing in p2p groups
* improve
* add member key
* distribute keys and sign
* refactor
* better query
* map
* sign in relay groups too
* clean up
* list
* fix test
* update bot types
* some refactor
* remove unnecessary condition
* simplify
* refactor
* simplify
* move
* clean up
* diff
* diff
* limit attempts for key sending
* optimize
* fix test
* split
* fuse
* null
* only mark as "key sent" when forwarder supports binary encoding
* fix bot apis
* fix some tests
* add key distribution steps, and fix some tests
* fix test
* increase timeout
* fix tests
* fix more tests
* simplify
* disable test output
* mark keys sent with invitations
* fix test
* fix test, query plans
* unify signing of connection info packets
* revert change to createNewGroup
* create key at group/member creation
* rename, remove liftIO
* clean up
* fix type
* remove ad hoc key sending
* update bot api
* diff
* reduce diff
* failing test
* fix sending messages in groups with members before version 18
* remove test delays
* update query plans
* update test
* add tests
* fix tests
---------
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
* core, ui: auto-accept group invitations per user profile
Add a per-profile toggle for auto-accepting group invitations, and regroup it
with the existing contact-requests setting under a single Auto-accept section
in Privacy & Security, relabelled "Contact requests in groups".
The join is fully async. processGroupInvitation already had an async accept
path, used when the invitation matches a group link the user opened:
prepareAgentJoin + createMemberConnectionAsync + joinAgentConnectionAsync,
with the outcome reported later against the CFJoinConn command id. Auto-accept
takes that same path instead of going through APIJoinGroup, so it works while
the app is closed and never blocks message processing.
An auto-accepted invitation still records a CIRcvGroupInvitation item in the
chat with the inviting contact, so there is a record of who added the user to
which group.
Two details worth noting for review:
hostContact is reported to clients only for group links. Clients respond to it
by replacing the transient host connection view with the group and removing
that chat - correct for a group link, where the contact is a placeholder, but
wrong for a plain invitation, where it is a real contact.
A resent invitation returns the existing group, because createGroupInvitation
is idempotent on inv_queue_info. The join therefore only runs while the
membership is still GSMemInvited, so a resend cannot open a second connection.
* booldef
* order
* refactor
* update translation key
* query plans
* ios: export translations
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
Co-authored-by: Evgeny Poberezkin <2769109+epoberezkin@users.noreply.github.com>
* directory: identify registration owner by member id to fix incorrect de-listing
The leave/removed/role-changed handlers identified the registration owner by
contact id. A non-owner member can be associated with the owner's contact (via
the contact/member merge), so its departure incorrectly de-listed the group.
Compare by group member id (owner_member_id) instead, falling back to contact
id for registrations recorded before owner_member_id existed.
* fix test, always compare contact ID in owner check
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
* directory: only create group links after approval
* update test
* update messages
* diff
* get group and link in one query
* reduce database reads
* better errors
* typos
* query plans
---------
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
Messages of blocked members are hidden, but they still marked chat item
as user mention, showing mention badge and counting group as unread in
"mentions only" notification mode:
- createNonLive passed mentions unfiltered, allowing members blocked by
admin to mention user - it is the default path, as it is only used
when full delete is not allowed;
- userReply was set for replies to user messages from blocked members.
* core: remove SimpleX Status preset contact
Preset contact cards are only created at user record creation
(createPresetContactCards), so this affects new profiles only;
existing profiles keep their stored SimpleX Status contact.
Removing the card shifts contact ids allocated after /create user
down by one, hence the test id updates.
* plans: justify SimpleX Status preset contact removal
* core: don't mark member support chat items read when reading group without scope
Reading a group without a scope marked support-scope items read without
decrementing the per-member support_chat_items_* counters, so members stayed
unread in the support list even after their chat was fully read. Restrict the
no-scope group read and its timed-items query to main-scope items.
* plans: support chat unread on no-scope group read
* core: update query plans for group scope read
The main-scope read and timed-items queries now filter on group_scope_tag
and group_scope_group_member_id, so they seek via idx_chat_items_group_scope_stats_all
(5-column) instead of idx_chat_items_groups_user_mention (3-column).
* plans: document query-plan and benchmark performance results
* tests: fix unreliable support item id capture in no-scope group read test
lastItemId returns the latest item by item_ts, which right after createGroup2
can be the group "connected" event rather than the just-sent support message.
The per-item read then targeted the wrong (already-read, main-scope) item and
never decremented the support counters, so the test failed regardless of the
fix (consistently in CI, flakily locally depending on item ordering).
Capture the support item id directly from the member-support scope instead,
keeping the change contained to this test. Verified: the test passes with the
fix and fails when the fix is reverted.
* tests: fix name-shadowing build error in no-scope group read test
The local pattern binding `itemId` shadowed the `itemId` helper imported
from ChatTests.Utils, which -Wname-shadowing (Werror) rejects. Rename the
local binding to `iId`.
* core, ui: plan per-server roles for self-hosted servers
* core: add per-server roles field to UserServer
* core: add nullable role columns to protocol_servers
* core: persist per-server roles
* core: validate server coverage using per-server roles
* test: cover per-server roles resolution and coverage
* multiplatform: per-server role toggles for self-hosted servers
* ios: per-server role toggles for self-hosted servers
* core: per-server role overrides with per-role defaults
* test: cover three-state per-server role resolution
* fix: derive Eq for ServerRolesOverride
* multiplatform: three-state role dropdowns on saved servers
* ios: three-state role pickers on saved servers
* test: per-server roles independent across two servers
* test: enable names role in name-resolution tests
* style: trim comments in per-server roles code
* chore: rename server_roles migration to 20260716 (last)
* core: per-server roles override operator roles, inherit when unset
* multiplatform: per-server role default inherits from operator
* ios: per-server role default inherits from operator
* refactor(servers): tidy per-server roles per review
- dedup no-operator default into ServerRoles.noOperatorDefault (Kotlin/Swift)
- iOS: move roles-section control flow to the call site via a named gate,
and parse the server address once instead of up to three times
- Kotlin: collapse redundant derivedState; revert defaultOn->default rename
for cross-platform parity
- drop unused Hashable conformance on Swift ServerRoles
- add agentServerCfgs test for names inheritance from an operator
- remove no-op enableNamesRole calls from dormant DirectoryTests
- fix ChatClient import ordering
* chore(migration): date server_roles migration 20260720
* only show roles when server is enabled, move section above QR code
---------
Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>