Compare commits

..
Author SHA1 Message Date
Bailey Dixon d4832a6a38 fix(android): coalesce replayed chat message ids 2026-07-27 09:30:39 -04:00
6 changed files with 210 additions and 237 deletions
+12
View File
@@ -1,5 +1,17 @@
# Hermes-Relay — Dev Log
## 2026-07-27 — Android replayed-message identity reconciliation
Android history reconciliation now collapses reconnect/rejoin replays of the
same persisted message ID before publishing the transcript to Compose. The
latest repeated snapshot replaces the value at the message's first transcript
position, preserving stable ordering, distinct messages, and the LazyColumn
identity contract without index- or random-key fallbacks.
Focused coverage reproduces the duplicate UUID condition and verifies that the
authoritative final content wins while every rendered message keeps a unique
stable UI key.
## 2026-07-26 — Android 1.5.1 patch reconciliation
Android 1.5.1 reconciles the post-1.5.0 voice and chat fixes into versionCode
@@ -1223,6 +1223,14 @@ class ChatHandler {
// so we can attach results back to the originating assistant message's ToolCall
val toolResults = items.filter { it.role == "tool" }
.associateBy { it.toolCallId }
// A reconnect/rejoin history response can repeat a persisted message row.
// Chat's LazyColumn renders domain ids as stable keys (via ChatMessage.uiKey),
// so allowing both copies through would crash Compose before either copy
// could be reconciled. A domain id identifies one persisted message: retain
// its first transcript position while adopting the latest repeated snapshot.
// Rows without ids remain independent, and tool/hidden rows keep their
// separate handling above/below.
val renderedItems = coalesceRenderedHistoryItems(items)
// Accumulator for media markers we find in loaded content — fired AFTER
// the wholesale `_messages.value = ...` assignment so the ViewModel's
@@ -1240,8 +1248,8 @@ class ChatHandler {
// silently misses those rows, so a gateway turn's tokens/badges survived
// only if a content match happened to cover them. See
// [reconcileLiveIdsToServer].
val serverItemIds = items.mapNotNullTo(HashSet()) { it.id }
val idRemap = reconcileLiveIdsToServer(items, serverItemIds)
val serverItemIds = renderedItems.mapNotNullTo(HashSet()) { it.id }
val idRemap = reconcileLiveIdsToServer(renderedItems, serverItemIds)
// Carry CLIENT-ONLY enrichment forward across the reload, keyed by the
// RECONCILED message id. The server transcript (MessageItem) rebuilds
@@ -1278,7 +1286,7 @@ class ChatHandler {
// clientOnly bubbles (same exchange, pre-sync copy).
val syncedRealtimeTurnContents = mutableSetOf<String>()
val loaded = items.mapNotNull { item ->
val loaded = renderedItems.mapNotNull { item ->
val displayKind = item.displayKind?.trim()?.lowercase()
if (displayKind == "hidden") return@mapNotNull null
val role = when {
@@ -1540,6 +1548,34 @@ class ChatHandler {
}
}
/**
* Collapse replayed visible history rows by their authoritative message id.
*
* Replacing the value at its first-seen slot preserves transcript ordering;
* the last repeated value wins so a later, more complete snapshot is not lost.
* Null ids cannot be proven identical and therefore remain separate rows.
*/
private fun coalesceRenderedHistoryItems(items: List<MessageItem>): List<MessageItem> {
val firstSlotById = HashMap<String, Int>()
val coalesced = ArrayList<MessageItem>(items.size)
for (item in items) {
if (renderedRoleOf(item) == null) continue
val id = item.id
if (id == null) {
coalesced += item
continue
}
val existingSlot = firstSlotById[id]
if (existingSlot == null) {
firstSlotById[id] = coalesced.size
coalesced += item
} else {
coalesced[existingSlot] = item
}
}
return coalesced
}
/** One adoptable server row during id reconciliation. `taken` enforces consume-once. */
private class ReconcileSlot(
val serverId: String,
@@ -27,6 +27,7 @@ import androidx.compose.material3.Scaffold
import androidx.compose.material3.Text
import androidx.compose.material3.TopAppBar
import androidx.compose.runtime.Composable
import androidx.compose.runtime.DisposableEffect
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
@@ -51,10 +52,17 @@ import com.hermesandroid.relay.network.upstream.DashboardAuthProvider
import com.hermesandroid.relay.network.upstream.DashboardAuthSession
import com.hermesandroid.relay.network.upstream.DashboardCookieStore
import com.hermesandroid.relay.network.upstream.EncryptedDashboardCookieStore
import com.hermesandroid.relay.network.upstream.DashboardRedirectAuthMode
import com.hermesandroid.relay.network.upstream.NativeDashboardSignInCoordinator
import com.hermesandroid.relay.network.upstream.dashboardRedirectAuthMode
import com.hermesandroid.relay.network.upstream.importDashboardCookieHeader
import com.hermesandroid.relay.network.upstream.isNativeDashboardTransportEligible
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import kotlinx.coroutines.CancellationException
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.Job
import kotlinx.coroutines.launch
import okhttp3.HttpUrl.Companion.toHttpUrlOrNull
import kotlinx.coroutines.withContext
/**
* Connection-level Dashboard authentication flow. It is deliberately outside
@@ -84,6 +92,10 @@ fun DashboardSignInScreen(
var actionMessage by remember { mutableStateOf<String?>(null) }
var actionIsError by remember { mutableStateOf(false) }
var oauthProvider by remember { mutableStateOf<DashboardAuthProvider?>(null) }
var redirectAuthMode by remember(dashboardUrl, connectionId) {
mutableStateOf(DashboardRedirectAuthMode.WebView)
}
var nativeSignInJob by remember(dashboardUrl, connectionId) { mutableStateOf<Job?>(null) }
var authenticationComplete by remember { mutableStateOf(false) }
val cookieStoreFactory = remember(appContext, connectionId) {
@@ -138,6 +150,7 @@ fun DashboardSignInScreen(
providers = client.getAuthProviders().getOrNull()
?.takeIf { it.isNotEmpty() }
?: status.authProviderDetails
redirectAuthMode = dashboardRedirectAuthMode(status.authFlows)
val session = if (status.authRequired) client.currentSession().getOrNull() else null
connectionViewModel.recordDashboardStatus(
status = status,
@@ -183,13 +196,68 @@ fun DashboardSignInScreen(
fun startRedirectSignIn(provider: DashboardAuthProvider) {
if (actionInFlight || dashboardUrl.isBlank()) return
// `native_pkce` is an upstream desktop capability. Android owns the
// dashboard cookie flow so the provider returns to the public
// /auth/callback, whose cookies are then verified via /api/auth/me.
oauthProvider = provider
if (redirectAuthMode == DashboardRedirectAuthMode.WebView) {
oauthProvider = provider
return
}
if (!isNativeDashboardTransportEligible(dashboardUrl)) {
actionMessage = resources.getString(R.string.dashboard_native_signin_requires_https)
actionIsError = true
return
}
val authClient = connectionViewModel.nativeDashboardAuthClientForActive(dashboardUrl)
if (authClient == null) {
actionMessage = resources.getString(R.string.dashboard_native_signin_unavailable)
actionIsError = true
return
}
actionInFlight = true
actionIsError = false
actionMessage = resources.getString(R.string.dashboard_native_signin_opening)
nativeSignInJob = scope.launch {
try {
NativeDashboardSignInCoordinator(authClient).signIn(provider.name) { authorizationUrl ->
withContext(Dispatchers.Main.immediate) {
launchNativeDashboardAuthorization(context, authorizationUrl)
}
}
val client = clientFactory()
val session = try {
verifyAndRecord(client)
} finally {
client.shutdown()
}
if (session?.authenticated == true) {
actionMessage = session.provider?.let {
resources.getString(R.string.dashboard_signed_in_with, it)
} ?: resources.getString(R.string.dashboard_signed_in)
actionIsError = false
finishAuthentication()
} else {
actionMessage = resources.getString(R.string.dashboard_signin_no_session)
actionIsError = true
}
} catch (cancelled: CancellationException) {
throw cancelled
} catch (error: Exception) {
actionMessage = error.message
?: resources.getString(R.string.dashboard_signin_failed)
actionIsError = true
} finally {
actionInFlight = false
nativeSignInJob = null
}
}
}
oauthProvider?.let { provider ->
DisposableEffect(dashboardUrl, connectionId) {
onDispose { nativeSignInJob?.cancel() }
}
oauthProvider
?.takeIf { redirectAuthMode == DashboardRedirectAuthMode.WebView }
?.let { provider ->
DashboardOAuthDialog(
dashboardUrl = dashboardUrl,
provider = provider,
@@ -223,7 +291,10 @@ fun DashboardSignInScreen(
TopAppBar(
title = { Text(stringResource(R.string.dashboard_sign_in)) },
navigationIcon = {
IconButton(onClick = onBack) {
IconButton(onClick = {
nativeSignInJob?.cancel()
onBack()
}) {
Icon(
Icons.AutoMirrored.Filled.ArrowBack,
contentDescription = stringResource(R.string.dashboard_back),
@@ -252,8 +323,16 @@ fun DashboardSignInScreen(
actionInFlight = actionInFlight,
actionMessage = actionMessage,
actionIsError = actionIsError,
nativePkce = redirectAuthMode == DashboardRedirectAuthMode.NativePkce,
nativeSignInInFlight = nativeSignInJob != null,
nativeTransportEligible = isNativeDashboardTransportEligible(dashboardUrl),
onSignIn = ::submitPassword,
onOAuthSignIn = ::startRedirectSignIn,
onCancelNativeSignIn = {
actionMessage = resources.getString(R.string.dashboard_native_signin_cancelled)
actionIsError = false
nativeSignInJob?.cancel()
},
)
}
}
@@ -319,8 +398,12 @@ private fun DashboardSignInForm(
actionInFlight: Boolean,
actionMessage: String?,
actionIsError: Boolean,
nativePkce: Boolean,
nativeSignInInFlight: Boolean,
nativeTransportEligible: Boolean,
onSignIn: (String, String, String) -> Unit,
onOAuthSignIn: (DashboardAuthProvider) -> Unit,
onCancelNativeSignIn: () -> Unit,
) {
var username by remember { mutableStateOf("") }
var password by remember { mutableStateOf("") }
@@ -346,12 +429,19 @@ private fun DashboardSignInForm(
redirectProviders.forEach { provider ->
Button(
onClick = { onOAuthSignIn(provider) },
enabled = !actionInFlight,
enabled = !actionInFlight && (!nativePkce || nativeTransportEligible),
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.dashboard_signin_with_provider, provider.displayName ?: provider.name))
}
}
if (nativePkce && !nativeTransportEligible && redirectProviders.isNotEmpty()) {
Text(
text = stringResource(R.string.dashboard_native_signin_requires_https),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.error,
)
}
if (passwordProvider != null || providers.isEmpty()) {
if (redirectProviders.isNotEmpty()) HorizontalDivider()
OutlinedTextField(
@@ -388,6 +478,14 @@ private fun DashboardSignInForm(
},
)
}
if (nativeSignInInFlight) {
Button(
onClick = onCancelNativeSignIn,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.dashboard_cancel))
}
}
}
@Composable
@@ -416,17 +514,14 @@ private fun DashboardOAuthDialog(
)
}
fun handleNavigation(url: String?) {
fun maybeVerify(url: String?) {
val loadedUrl = url?.takeIf { it.isNotBlank() } ?: return
when (dashboardWebViewAuthNavigation(dashboardUrl, loadedUrl)) {
DashboardWebViewAuthNavigation.Continue -> return
DashboardWebViewAuthNavigation.RejectLoopbackCallback -> {
statusText = notAcceptedStatus
onError(notAcceptedStatus)
return
}
DashboardWebViewAuthNavigation.ImportAndVerify -> Unit
}
val root = dashboardUrl.trim().trimEnd('/')
val relative = loadedUrl.trim().removePrefix(root)
val stillAuthenticating = relative.startsWith("/login", true) ||
relative.startsWith("/auth/login", true) ||
relative.startsWith("/auth/callback", true)
if (!loadedUrl.startsWith(root, true) || stillAuthenticating) return
val manager = CookieManager.getInstance()
manager.flush()
val imported = importDashboardCookieHeader(
@@ -477,21 +572,11 @@ private fun DashboardOAuthDialog(
override fun shouldOverrideUrlLoading(
view: WebView,
request: WebResourceRequest,
): Boolean {
val target = request.url.toString()
if (
dashboardWebViewAuthNavigation(dashboardUrl, target) ==
DashboardWebViewAuthNavigation.RejectLoopbackCallback
) {
handleNavigation(target)
return true
}
return false
}
): Boolean = false
override fun onPageFinished(view: WebView, url: String?) {
super.onPageFinished(view, url)
handleNavigation(url)
maybeVerify(url)
}
}
loadUrl(loginUrl)
@@ -502,52 +587,3 @@ private fun DashboardOAuthDialog(
}
}
}
internal enum class DashboardWebViewAuthNavigation {
Continue,
ImportAndVerify,
RejectLoopbackCallback,
}
/**
* Android redirect providers use the dashboard's cookie/OIDC flow. A foreign
* loopback callback belongs to the desktop native-PKCE contract and must never
* be followed, imported, or treated as an authenticated Android return.
*/
internal fun dashboardWebViewAuthNavigation(
dashboardUrl: String,
loadedUrl: String,
): DashboardWebViewAuthNavigation {
val dashboard = dashboardUrl.trim().trimEnd('/').toHttpUrlOrNull()
?: return DashboardWebViewAuthNavigation.Continue
val loaded = loadedUrl.trim().toHttpUrlOrNull()
?: return DashboardWebViewAuthNavigation.Continue
val sameOrigin = dashboard.scheme == loaded.scheme &&
dashboard.host.equals(loaded.host, ignoreCase = true) &&
dashboard.port == loaded.port
if (!sameOrigin) {
val foreignLoopback = loaded.scheme == "http" &&
loaded.host in setOf("127.0.0.1", "localhost", "::1") &&
loaded.encodedPath == "/callback"
return if (foreignLoopback) {
DashboardWebViewAuthNavigation.RejectLoopbackCallback
} else {
DashboardWebViewAuthNavigation.Continue
}
}
val basePath = dashboard.encodedPath.trimEnd('/')
val relativePath = loaded.encodedPath
.removePrefix(basePath)
.ifBlank { "/" }
return if (
relativePath.equals("/login", ignoreCase = true) ||
relativePath.equals("/auth/login", ignoreCase = true)
) {
DashboardWebViewAuthNavigation.Continue
} else {
// Includes the public /auth/callback response: import its cookies at
// root scope, then verify the resulting session through /api/auth/me.
DashboardWebViewAuthNavigation.ImportAndVerify
}
}
@@ -1517,6 +1517,49 @@ class ChatHandlerTest {
assertEquals(messages.size, messages.map { it.uiKey }.distinct().size)
}
@Test
fun loadMessageHistory_coalescesReplayedDomainIdWithoutLosingOrderOrContent() {
val replayedId = "2c93af28-0b0b-436b-a112-7f164cac931d"
handler.loadMessageHistory(
listOf(
MessageItem(
id = "user-1",
role = "user",
content = JsonPrimitive("question"),
timestamp = 1.0,
),
MessageItem(
id = replayedId,
role = "assistant",
content = JsonPrimitive("partial answer"),
timestamp = 2.0,
),
MessageItem(
id = "system-1",
role = "system",
content = JsonPrimitive("distinct visible content"),
timestamp = 3.0,
),
// Rejoin replay of the same persisted message. The latest
// snapshot is authoritative, but its first transcript position
// and Compose identity must remain stable.
MessageItem(
id = replayedId,
role = "assistant",
content = JsonPrimitive("final answer"),
timestamp = 4.0,
),
)
)
val messages = handler.messages.value
assertEquals(listOf("user-1", replayedId, "system-1"), messages.map { it.id })
assertEquals("final answer", messages[1].content)
assertEquals("distinct visible content", messages[2].content)
assertEquals(messages.size, messages.map { it.uiKey }.distinct().size)
}
@Test
fun loadMessageHistory_secondReloadMatchesByIdAfterReconciliation() {
// Once the first reload adopts the server id, subsequent reloads match by
@@ -1,114 +0,0 @@
package com.hermesandroid.relay.ui.screens
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.DashboardCookieJar
import com.hermesandroid.relay.network.upstream.InMemoryDashboardCookieStore
import com.hermesandroid.relay.network.upstream.importDashboardCookieHeader
import kotlinx.coroutines.test.runTest
import okhttp3.OkHttpClient
import okhttp3.mockwebserver.MockResponse
import okhttp3.mockwebserver.MockWebServer
import org.junit.After
import org.junit.Assert.assertEquals
import org.junit.Assert.assertFalse
import org.junit.Assert.assertTrue
import org.junit.Before
import org.junit.Test
class DashboardWebViewAuthPolicyTest {
private lateinit var server: MockWebServer
@Before
fun setUp() {
server = MockWebServer()
server.start()
}
@After
fun tearDown() {
server.shutdown()
}
@Test
fun selfHostedOidc_usesDashboardLoginWithoutNativeOrLoopbackParameters() {
val url = DashboardApiClient.authLoginUrl(
baseUrl = "https://hermes.example.test",
provider = "self-hosted",
next = "/",
)
assertEquals(
"https://hermes.example.test/auth/login?provider=self-hosted&next=%2F",
url,
)
assertFalse(url.contains("/auth/native/authorize"))
assertFalse(url.contains("redirect_uri"))
assertFalse(url.contains("127.0.0.1"))
}
@Test
fun publicDashboardCallback_importsCookieAndVerifiesAuthenticatedSession() = runTest {
assertEquals(
DashboardWebViewAuthNavigation.ImportAndVerify,
dashboardWebViewAuthNavigation(
"https://hermes.example.test",
"https://hermes.example.test/auth/callback?code=public-code&state=public-state",
),
)
server.enqueue(
MockResponse()
.setHeader("Content-Type", "application/json")
.setBody(
"""{"authenticated":true,"username":"operator","provider":"self-hosted"}""",
),
)
val store = InMemoryDashboardCookieStore()
val callbackUrl = server.url("/auth/callback?code=public-code").toString()
assertEquals(
1,
importDashboardCookieHeader(
store = store,
url = callbackUrl,
cookieHeader = "hermes_session=authenticated",
),
)
val client = DashboardApiClient(
baseUrl = server.url("/").toString(),
okHttpClient = OkHttpClient.Builder()
.cookieJar(DashboardCookieJar(store))
.build(),
)
val session = client.currentSession().getOrThrow()
assertTrue(session.authenticated)
val request = server.takeRequest()
assertEquals("/api/auth/me", request.path)
assertEquals("hermes_session=authenticated", request.getHeader("Cookie"))
client.shutdown()
}
@Test
fun foreignLoopbackCallbacksAreRejectedWhileProviderPagesContinue() {
val dashboard = "https://hermes.example.test"
listOf(
"http://127.0.0.1:40179/callback?code=code",
"http://localhost:40179/callback?code=code",
"http://[::1]:40179/callback?code=code",
).forEach { callback ->
assertEquals(
callback,
DashboardWebViewAuthNavigation.RejectLoopbackCallback,
dashboardWebViewAuthNavigation(dashboard, callback),
)
}
assertEquals(
DashboardWebViewAuthNavigation.Continue,
dashboardWebViewAuthNavigation(
dashboard,
"https://auth.example.test/application/o/authorize/",
),
)
}
}
+1 -41
View File
@@ -2169,7 +2169,7 @@ An API endpoint or Relay can be added later without recreating the connection.
## ADR 39 — Android dashboard redirect auth uses native PKCE
**Status:** Superseded by ADR 40 (2026-07-27).
**Status:** Accepted (2026-07-25).
**Context.** Android originally completed redirect-provider dashboard sign-in
inside a WebView and imported cookies. Current upstream Gateway can advertise a
@@ -2202,43 +2202,3 @@ socket.
is offered.
- Older upstream versions remain usable through the explicitly identified
WebView compatibility path.
---
## ADR 40 — Android dashboard redirect auth remains cookie/OIDC
**Status:** Accepted (2026-07-27).
**Context.** Upstream advertises `native_pkce` in `/api/status.auth_flows` for
its desktop client. The corresponding `/auth/native/*` broker is explicitly a
desktop system-browser flow: it redirects to a loopback listener owned by the
desktop process and returns bearer tokens rather than dashboard cookies.
Android incorrectly treated that server-wide capability as a platform-neutral
mode selector, so redirect providers such as self-hosted OIDC were sent through
the desktop loopback contract.
**Decision.** Android redirect-provider sign-in always uses the upstream
dashboard cookie flow:
- open `/auth/login?provider=...&next=...` in the embedded sign-in WebView;
- allow the provider to return through the dashboard's public
`/auth/callback`;
- import only cookies observed on the configured dashboard origin;
- verify the imported session through `/api/auth/me`;
- reject a foreign `http://127.0.0.1`, `localhost`, or `[::1]` `/callback`
navigation instead of following or importing it.
Android does not select `/auth/native/authorize` from `auth_flows`. Desktop
native PKCE remains an upstream desktop capability and is unchanged. Existing
encrypted native-token support is retained only so already-issued Android
sessions can be cleared or age out safely; it is not a sign-in entry point.
**Consequences.**
- Self-hosted OIDC uses the same public callback registered for the dashboard.
- Android Manage, Chat, Voice, and onboarding continue to share one verified
dashboard cookie session.
- A server-wide desktop capability can no longer switch Android into a
loopback callback flow.
- Android retains an embedded WebView for dashboard authentication; provider
compatibility and WebView security updates remain part of Android upkeep.