Private
Public Access
Add direct messages (#52)
A DM is a Room with a new is_dm flag, not a separate model -- reuses all the membership/message/WS plumbing Room already has instead of duplicating it. The room's `name` (still required + globally unique) is an internal, never-displayed token derived deterministically from the two participants' sorted user IDs (dm_room_name), which makes find-or-create a single indexed lookup and gets free race-condition safety from the existing unique constraint -- a concurrent double- start from both people just hits the same IntegrityError->retry-as- lookup path create_room already established. Both participants get the plain 'member' role (no owner/admin distinction makes sense for a 1:1 DM), which incidentally reuses every existing role gate to block add-member, room-settings edits, and join-via-browse on a DM for free. update_room also gets an explicit is_dm guard independent of that, since renaming a DM isn't just a privacy concern -- it would silently corrupt the find-or-create invariant. DMs are excluded from both Browse Rooms and the admin portal's room listing (fully private, per scope). GET /api/rooms/mine precomputes each DM's other participant (name, avatar, presence) as dm_partner in one batched query, so the sidebar can render a DM row without a fetch per row. Frontend: a new "Direct Messages" sidebar section (searchable by partner name, not the internal room name), clicking someone in the People list starts or resumes a DM, and the chat header/composer/RoomInfoPanel all render the partner's identity instead of a room name where it's a DM. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -93,9 +93,14 @@ async def set_user_site_admin(
|
||||
|
||||
|
||||
async def list_rooms_admin(db: AsyncSession) -> list[tuple[Room, int]]:
|
||||
# #52: DMs are fully private, not just unlisted -- excluded here rather
|
||||
# than merely omitted from the response, so there's no admin-portal
|
||||
# surface (this list, or the audit log via anything that touches this
|
||||
# query) that reveals a DM even exists between two users.
|
||||
result = await db.execute(
|
||||
select(Room, func.count(RoomMembership.user_id))
|
||||
.outerjoin(RoomMembership, RoomMembership.room_id == Room.id)
|
||||
.where(Room.is_dm.is_(False))
|
||||
.group_by(Room.id)
|
||||
.order_by(Room.created_at)
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user