Skip to content

refactor(sends): the shared send guard, journal and recipient list - #257

Merged
leemour merged 1 commit into
mainfrom
refactor/shared-send-guard
Sep 30, 2026
Merged

leemour merged 1 commit into
mainfrom
refactor/shared-send-guard

Conversation

@leemour

@leemour leemour commented Sep 30, 2026

Copy link
Copy Markdown
Owner

T6 item 3b (plan docs_ai/plans/2026-09-30-max-onto-services.md, corrected 2026-09-30).

What changes

  • src/sends/ (guard, journal, permissions, recipients) is deleted; max uses cli-messaging 0.62.0's sendGuard, SendJournal, RecipientList, permissions.
  • src/sends.ts builds the guard for a profile — command: "max", max's allow hint via allowFix — and wraps it (operating) so every journal line of one write carries the same operationId, minted at the check; a send's is its sendId.
  • MaxClient journals sendId (string) instead of cid; the cid is made before the check so the reservation names it. Old cid lines are still read as sendId by the shared journal, so the hourly limit and the unknown-outcome retry keep counting them.
  • src/app.ts: max's AppIdentity, needed by the shared modules (and by the MAX Messenger, item 5).
  • src/bot/permissions.ts, src/bot-mcp/*: import path only.

User-visible (changelog)

  • max sends list --json: cid → sendId (string); every line gains operationId.

Risk

This is the guard in front of the owner's real account (RISK-73). Covered: the full suite (1196 tests, incl. server/retry/limit/permissions), plus a new src/sends.test.ts for the operation id. The live test-live run on test chats happens before the next release, with the owner's yes.

Checked: pnpm lint && pnpm typecheck && pnpm test && pnpm test:matrix && pnpm docs:check.

🤖 Generated with Claude Code

T6 item 3b. max-cli's src/sends/ twins are gone; src/sends.ts builds
cli-messaging's sendGuard for a profile (with max's allow hint through
allowFix) and wraps it so every journal line of one write carries the same
operationId: minted at the check, a send's being its sendId.

MaxClient journals the send identity as sendId (a string) instead of cid;
the shared journal still reads old cid lines as sendId. The cid is now
made before the guard's check, so the reservation names it too.

src/bot/permissions.ts and src/bot-mcp/ change their imports only.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@leemour
leemour merged commit 56328f1 into main Sep 30, 2026
4 checks passed
@leemour
leemour deleted the refactor/shared-send-guard branch October 1, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant