Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 35d562bb09 | |||
| 0a3f10cbc0 | |||
|
|
0e585e492a |
@@ -1,268 +0,0 @@
|
||||
# Nostr Event Stream Visualization
|
||||
|
||||
**Issue:** #874 - [NEXUS] Implement Nostr Event Stream Visualization
|
||||
|
||||
## Overview
|
||||
|
||||
Visualize incoming Nostr events as data streams or particles flowing through the Nexus, representing the agent's connection to the wider mesh.
|
||||
|
||||
## Architecture
|
||||
|
||||
```
|
||||
+---------------------------------------------------+
|
||||
| Nostr Event Visualizer |
|
||||
+---------------------------------------------------|
|
||||
| Nostr Relay Connection |
|
||||
| +-------------+ +-------------+ +-------------+
|
||||
| | WebSocket | | Event | | Subscription|
|
||||
| | Client | | Handler | | Manager |
|
||||
| +-------------+ +-------------+ +-------------+
|
||||
| +-------------+ +-------------+ +-------------+
|
||||
| | Particle | | Color | | Animation |
|
||||
| | System | | Manager | | Engine |
|
||||
| +-------------+ +-------------+ +-------------+
|
||||
+---------------------------------------------------+
|
||||
```
|
||||
|
||||
## Components
|
||||
|
||||
### 1. Nostr Event Visualizer (`js/nostr-event-visualizer.js`)
|
||||
Main visualization class for Nostr events.
|
||||
|
||||
**Features:**
|
||||
- Connect to Nostr relay via WebSocket
|
||||
- Subscribe to event stream
|
||||
- Visualize events as particles
|
||||
- Color-coded by event type
|
||||
- Animated particle system
|
||||
|
||||
**Usage:**
|
||||
```javascript
|
||||
// Create visualizer
|
||||
const visualizer = new NostrEventVisualizer({
|
||||
relayUrl: 'wss://relay.nostr.info',
|
||||
maxEvents: 100,
|
||||
particleCount: 50,
|
||||
streamSpeed: 1.0
|
||||
});
|
||||
|
||||
// Initialize with Three.js scene
|
||||
visualizer.init(scene, camera, renderer);
|
||||
|
||||
// Connect to Nostr relay
|
||||
visualizer.connect();
|
||||
|
||||
// Update visualization
|
||||
visualizer.update(deltaTime);
|
||||
```
|
||||
|
||||
### 2. Event Types Visualized
|
||||
|
||||
| Event Type | Color | Description |
|
||||
|------------|-------|-------------|
|
||||
| text_note | Blue | Text notes/posts |
|
||||
| recommend_server | Gold | Server recommendations |
|
||||
| contact_list | Cyan | Contact lists |
|
||||
| encrypted_direct_message | Pink | Encrypted messages |
|
||||
|
||||
### 3. Particle System
|
||||
|
||||
**Features:**
|
||||
- Particles flow through the Nexus world
|
||||
- Color-coded by event type
|
||||
- Size pulses for active events
|
||||
- Turbulence for natural movement
|
||||
- Bounded within world space
|
||||
|
||||
**Configuration:**
|
||||
```javascript
|
||||
const visualizer = new NostrEventVisualizer({
|
||||
particleCount: 50, // Number of particles
|
||||
streamSpeed: 1.0, // Flow speed
|
||||
particleSize: 0.5, // Particle size
|
||||
maxEvents: 100, // Max events to track
|
||||
eventTypes: [ // Event types to visualize
|
||||
'text_note',
|
||||
'recommend_server',
|
||||
'contact_list',
|
||||
'encrypted_direct_message'
|
||||
]
|
||||
});
|
||||
```
|
||||
|
||||
## Usage Examples
|
||||
|
||||
### Basic Usage
|
||||
```javascript
|
||||
// Create visualizer
|
||||
const visualizer = new NostrEventVisualizer({
|
||||
relayUrl: 'wss://relay.nostr.info'
|
||||
});
|
||||
|
||||
// Initialize with Three.js
|
||||
visualizer.init(scene, camera, renderer);
|
||||
|
||||
// Connect to relay
|
||||
visualizer.connect();
|
||||
|
||||
// Update in animation loop
|
||||
function animate() {
|
||||
requestAnimationFrame(animate);
|
||||
visualizer.update(1/60); // 60 FPS
|
||||
renderer.render(scene, camera);
|
||||
}
|
||||
animate();
|
||||
```
|
||||
|
||||
### With Event Callbacks
|
||||
```javascript
|
||||
const visualizer = new NostrEventVisualizer({
|
||||
onEvent: (event) => {
|
||||
console.log('New event:', event.kind, event.content);
|
||||
},
|
||||
onConnect: () => {
|
||||
console.log('Connected to Nostr relay');
|
||||
},
|
||||
onDisconnect: () => {
|
||||
console.log('Disconnected from Nostr relay');
|
||||
}
|
||||
});
|
||||
```
|
||||
|
||||
### Get Status
|
||||
```javascript
|
||||
const status = visualizer.getStatus();
|
||||
console.log('Connected:', status.connected);
|
||||
console.log('Events:', status.eventCount);
|
||||
console.log('Particles:', status.activeParticles);
|
||||
```
|
||||
|
||||
## Integration with Nexus
|
||||
|
||||
### Auto-Initialize
|
||||
```javascript
|
||||
// In app.js or initialization code
|
||||
document.addEventListener('DOMContentLoaded', () => {
|
||||
// Wait for Three.js scene to be ready
|
||||
if (window.scene && window.camera && window.renderer) {
|
||||
const visualizer = new NostrEventVisualizer();
|
||||
visualizer.init(window.scene, window.camera, window.renderer);
|
||||
visualizer.connect();
|
||||
|
||||
// Store globally
|
||||
window.nostrVisualizer = visualizer;
|
||||
}
|
||||
});
|
||||
```
|
||||
|
||||
### With Animation Loop
|
||||
```javascript
|
||||
// In animation loop
|
||||
function animate() {
|
||||
requestAnimationFrame(animate);
|
||||
|
||||
// Update Nostr visualizer
|
||||
if (window.nostrVisualizer) {
|
||||
window.nostrVisualizer.update(1/60);
|
||||
}
|
||||
|
||||
// Render scene
|
||||
renderer.render(scene, camera);
|
||||
}
|
||||
```
|
||||
|
||||
## Event Handling
|
||||
|
||||
### Event Types
|
||||
```javascript
|
||||
// text_note (kind 1)
|
||||
{
|
||||
"id": "...",
|
||||
"pubkey": "...",
|
||||
"created_at": 1234567890,
|
||||
"kind": 1,
|
||||
"tags": [],
|
||||
"content": "Hello Nostr!",
|
||||
"sig": "..."
|
||||
}
|
||||
|
||||
// recommend_server (kind 2)
|
||||
{
|
||||
"id": "...",
|
||||
"pubkey": "...",
|
||||
"created_at": 1234567890,
|
||||
"kind": 2,
|
||||
"tags": [],
|
||||
"content": "wss://relay.example.com",
|
||||
"sig": "..."
|
||||
}
|
||||
|
||||
// contact_list (kind 3)
|
||||
{
|
||||
"id": "...",
|
||||
"pubkey": "...",
|
||||
"created_at": 1234567890,
|
||||
"kind": 3,
|
||||
"tags": [["p", "pubkey1"], ["p", "pubkey2"]],
|
||||
"content": "",
|
||||
"sig": "..."
|
||||
}
|
||||
|
||||
// encrypted_direct_message (kind 4)
|
||||
{
|
||||
"id": "...",
|
||||
"pubkey": "...",
|
||||
"created_at": 1234567890,
|
||||
"kind": 4,
|
||||
"tags": [["p", "recipient_pubkey"]],
|
||||
"content": "encrypted_content",
|
||||
"sig": "..."
|
||||
}
|
||||
```
|
||||
|
||||
## Testing
|
||||
|
||||
### Unit Tests
|
||||
```bash
|
||||
node --test tests/test_nostr_visualizer.js
|
||||
```
|
||||
|
||||
### Integration Tests
|
||||
```javascript
|
||||
// Create visualizer
|
||||
const visualizer = new NostrEventVisualizer();
|
||||
|
||||
// Connect to relay
|
||||
visualizer.connect();
|
||||
|
||||
// Check status
|
||||
const status = visualizer.getStatus();
|
||||
assert(status.connected === true);
|
||||
|
||||
// Update visualization
|
||||
visualizer.update(1/60);
|
||||
|
||||
// Disconnect
|
||||
visualizer.disconnect();
|
||||
```
|
||||
|
||||
## Related Issues
|
||||
|
||||
- **Issue #874:** This implementation
|
||||
- **Issue #1124:** MemPalace integration (related visualization)
|
||||
|
||||
## Files
|
||||
|
||||
- `js/nostr-event-visualizer.js` - Main visualization module
|
||||
- `docs/nostr-event-visualizer.md` - This documentation
|
||||
- `tests/test_nostr_visualizer.js` - Test suite (to be added)
|
||||
|
||||
## Conclusion
|
||||
|
||||
This system provides real-time visualization of Nostr events in the Nexus world:
|
||||
1. **Connection** to Nostr relays via WebSocket
|
||||
2. **Visualization** of events as colored particles
|
||||
3. **Animation** with turbulence and pulsing
|
||||
4. **Integration** with Three.js scene
|
||||
|
||||
**Ready for production use.**
|
||||
54
electron-main-secure.js
Normal file
54
electron-main-secure.js
Normal file
@@ -0,0 +1,54 @@
|
||||
const { app, BrowserWindow } = require('electron');
|
||||
const path = require('path');
|
||||
|
||||
// Import the secure MemPalace bridge
|
||||
const { setupSecureMemPalaceIPC } = require('./electron-mempalace-bridge');
|
||||
|
||||
let mainWindow;
|
||||
|
||||
function createWindow() {
|
||||
mainWindow = new BrowserWindow({
|
||||
width: 1200,
|
||||
height: 800,
|
||||
webPreferences: {
|
||||
nodeIntegration: false,
|
||||
contextIsolation: true,
|
||||
preload: path.join(__dirname, 'preload.js')
|
||||
}
|
||||
});
|
||||
|
||||
mainWindow.loadFile('index.html');
|
||||
|
||||
// Open DevTools in development
|
||||
if (process.env.NODE_ENV === 'development') {
|
||||
mainWindow.webContents.openDevTools();
|
||||
}
|
||||
}
|
||||
|
||||
app.whenReady().then(() => {
|
||||
// Set up secure MemPalace IPC
|
||||
setupSecureMemPalaceIPC();
|
||||
|
||||
createWindow();
|
||||
|
||||
app.on('activate', () => {
|
||||
if (BrowserWindow.getAllWindows().length === 0) {
|
||||
createWindow();
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
app.on('window-all-closed', () => {
|
||||
if (process.platform !== 'darwin') {
|
||||
app.quit();
|
||||
}
|
||||
});
|
||||
|
||||
// Handle any uncaught exceptions
|
||||
process.on('uncaughtException', (error) => {
|
||||
console.error('Uncaught exception:', error);
|
||||
});
|
||||
|
||||
process.on('unhandledRejection', (reason, promise) => {
|
||||
console.error('Unhandled rejection at:', promise, 'reason:', reason);
|
||||
});
|
||||
290
electron-mempalace-bridge.js
Normal file
290
electron-mempalace-bridge.js
Normal file
@@ -0,0 +1,290 @@
|
||||
/**
|
||||
* Secure MemPalace IPC Bridge
|
||||
* Issue #1423: [SECURITY] Electron MemPalace bridge allows arbitrary command execution
|
||||
*
|
||||
* Replaces raw command execution with typed, validated IPC actions.
|
||||
*/
|
||||
|
||||
const { app, BrowserWindow, ipcMain } = require('electron');
|
||||
const { spawn } = require('child_process');
|
||||
const path = require('path');
|
||||
|
||||
// Whitelist of allowed MemPalace actions
|
||||
const ALLOWED_ACTIONS = {
|
||||
'init': {
|
||||
command: 'mempalace',
|
||||
args: ['init'],
|
||||
requiredArgs: ['palacePath'],
|
||||
validate: (args) => {
|
||||
// Validate palacePath is safe (no shell metacharacters)
|
||||
const palacePath = args.palacePath;
|
||||
if (!palacePath || typeof palacePath !== 'string') {
|
||||
throw new Error('palacePath must be a string');
|
||||
}
|
||||
// Reject paths with shell metacharacters
|
||||
if (/[;&|`$(){}[\]<>]/.test(palacePath)) {
|
||||
throw new Error('palacePath contains unsafe characters');
|
||||
}
|
||||
return [palacePath];
|
||||
}
|
||||
},
|
||||
'mine': {
|
||||
command: 'mempalace',
|
||||
args: ['mine'],
|
||||
requiredArgs: ['path', 'mode', 'wing'],
|
||||
validate: (args) => {
|
||||
const { path: minePath, mode, wing } = args;
|
||||
|
||||
// Validate each argument
|
||||
if (!minePath || typeof minePath !== 'string') {
|
||||
throw new Error('path must be a string');
|
||||
}
|
||||
if (!mode || typeof mode !== 'string') {
|
||||
throw new Error('mode must be a string');
|
||||
}
|
||||
if (!wing || typeof wing !== 'string') {
|
||||
throw new Error('wing must be a string');
|
||||
}
|
||||
|
||||
// Reject unsafe characters
|
||||
const unsafePattern = /[;&|`$(){}[\]<>]/;
|
||||
if (unsafePattern.test(minePath) || unsafePattern.test(mode) || unsafePattern.test(wing)) {
|
||||
throw new Error('Arguments contain unsafe characters');
|
||||
}
|
||||
|
||||
// Validate mode is one of allowed values
|
||||
const allowedModes = ['convos', 'files', 'web'];
|
||||
if (!allowedModes.includes(mode)) {
|
||||
throw new Error(`Mode must be one of: ${allowedModes.join(', ')}`);
|
||||
}
|
||||
|
||||
return [minePath, '--mode', mode, '--wing', wing];
|
||||
}
|
||||
},
|
||||
'search': {
|
||||
command: 'mempalace',
|
||||
args: ['search'],
|
||||
requiredArgs: ['query', 'wing'],
|
||||
optionalArgs: ['room', 'n'],
|
||||
validate: (args) => {
|
||||
const { query, wing, room, n } = args;
|
||||
|
||||
// Validate required arguments
|
||||
if (!query || typeof query !== 'string') {
|
||||
throw new Error('query must be a string');
|
||||
}
|
||||
if (!wing || typeof wing !== 'string') {
|
||||
throw new Error('wing must be a string');
|
||||
}
|
||||
|
||||
// Reject unsafe characters in query and wing
|
||||
const unsafePattern = /[;&|`$(){}[\]<>]/;
|
||||
if (unsafePattern.test(query) || unsafePattern.test(wing)) {
|
||||
throw new Error('Arguments contain unsafe characters');
|
||||
}
|
||||
|
||||
// Build command args
|
||||
const cmdArgs = [query, '--wing', wing];
|
||||
|
||||
// Add optional arguments
|
||||
if (room && typeof room === 'string' && !unsafePattern.test(room)) {
|
||||
cmdArgs.push('--room', room);
|
||||
}
|
||||
if (n && typeof n === 'number' && n > 0 && n <= 100) {
|
||||
cmdArgs.push('--n', String(n));
|
||||
}
|
||||
|
||||
return cmdArgs;
|
||||
}
|
||||
},
|
||||
'status': {
|
||||
command: 'mempalace',
|
||||
args: ['status'],
|
||||
requiredArgs: ['wing'],
|
||||
validate: (args) => {
|
||||
const { wing } = args;
|
||||
|
||||
if (!wing || typeof wing !== 'string') {
|
||||
throw new Error('wing must be a string');
|
||||
}
|
||||
|
||||
// Reject unsafe characters
|
||||
if (/[;&|`$(){}[\]<>]/.test(wing)) {
|
||||
throw new Error('wing contains unsafe characters');
|
||||
}
|
||||
|
||||
return ['--wing', wing];
|
||||
}
|
||||
},
|
||||
'add_drawer': {
|
||||
command: 'mempalace',
|
||||
args: ['add_drawer'],
|
||||
requiredArgs: ['wing', 'room', 'text'],
|
||||
validate: (args) => {
|
||||
const { wing, room, text } = args;
|
||||
|
||||
// Validate all arguments
|
||||
if (!wing || typeof wing !== 'string') {
|
||||
throw new Error('wing must be a string');
|
||||
}
|
||||
if (!room || typeof room !== 'string') {
|
||||
throw new Error('room must be a string');
|
||||
}
|
||||
if (!text || typeof text !== 'string') {
|
||||
throw new Error('text must be a string');
|
||||
}
|
||||
|
||||
// Reject unsafe characters
|
||||
const unsafePattern = /[;&|`$(){}[\]<>]/;
|
||||
if (unsafePattern.test(wing) || unsafePattern.test(room)) {
|
||||
throw new Error('wing or room contains unsafe characters');
|
||||
}
|
||||
|
||||
// Text can contain more characters, but still reject dangerous ones
|
||||
if (/[;&|`$]/.test(text)) {
|
||||
throw new Error('text contains unsafe characters');
|
||||
}
|
||||
|
||||
return [wing, room, text];
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
/**
|
||||
* Validate and execute a MemPalace action
|
||||
*/
|
||||
async function executeMemPalaceAction(action, args = {}) {
|
||||
// Check if action is allowed
|
||||
if (!ALLOWED_ACTIONS[action]) {
|
||||
throw new Error(`Unknown action: ${action}. Allowed actions: ${Object.keys(ALLOWED_ACTIONS).join(', ')}`);
|
||||
}
|
||||
|
||||
const actionConfig = ALLOWED_ACTIONS[action];
|
||||
|
||||
try {
|
||||
// Validate arguments and build command args
|
||||
const commandArgs = actionConfig.validate(args);
|
||||
|
||||
// Build full command
|
||||
const command = actionConfig.command;
|
||||
const fullArgs = [...actionConfig.args, ...commandArgs];
|
||||
|
||||
console.log(`[MemPalace] Executing: ${command} ${fullArgs.join(' ')}`);
|
||||
|
||||
// Execute with spawn (safer than exec)
|
||||
return new Promise((resolve, reject) => {
|
||||
const child = spawn(command, fullArgs, {
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
shell: false // Don't use shell
|
||||
});
|
||||
|
||||
let stdout = '';
|
||||
let stderr = '';
|
||||
|
||||
child.stdout.on('data', (data) => {
|
||||
stdout += data.toString();
|
||||
});
|
||||
|
||||
child.stderr.on('data', (data) => {
|
||||
stderr += data.toString();
|
||||
});
|
||||
|
||||
child.on('close', (code) => {
|
||||
if (code === 0) {
|
||||
resolve({ stdout, stderr, code });
|
||||
} else {
|
||||
reject(new Error(`Command failed with code ${code}: ${stderr}`));
|
||||
}
|
||||
});
|
||||
|
||||
child.on('error', (error) => {
|
||||
reject(error);
|
||||
});
|
||||
});
|
||||
|
||||
} catch (error) {
|
||||
console.error(`[MemPalace] Validation error for ${action}:`, error.message);
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Set up secure IPC handlers
|
||||
*/
|
||||
function setupSecureMemPalaceIPC() {
|
||||
// Remove any existing handlers
|
||||
ipcMain.removeHandler('exec-python');
|
||||
|
||||
// Set up typed action handlers
|
||||
ipcMain.handle('mempalace-action', async (event, { action, args }) => {
|
||||
try {
|
||||
const result = await executeMemPalaceAction(action, args);
|
||||
return { success: true, ...result };
|
||||
} catch (error) {
|
||||
console.error(`[MemPalace] Action ${action} failed:`, error.message);
|
||||
return { success: false, error: error.message };
|
||||
}
|
||||
});
|
||||
|
||||
// Keep legacy exec-python handler but with validation (for backward compatibility)
|
||||
// This should be deprecated and removed in future versions
|
||||
ipcMain.handle('exec-python', async (event, command) => {
|
||||
console.warn('[MemPalace] DEPRECATED: exec-python called. Use mempalace-action instead.');
|
||||
|
||||
// Parse the command to extract action and args
|
||||
const parts = command.trim().split(/\s+/);
|
||||
if (parts.length < 2 || parts[0] !== 'mempalace') {
|
||||
return {
|
||||
success: false,
|
||||
error: 'Only mempalace commands are allowed',
|
||||
deprecated: true
|
||||
};
|
||||
}
|
||||
|
||||
const action = parts[1];
|
||||
const args = {};
|
||||
|
||||
// Parse arguments from command string
|
||||
// This is a simplified parser - in production, use proper argument parsing
|
||||
for (let i = 2; i < parts.length; i++) {
|
||||
const part = parts[i];
|
||||
if (part.startsWith('--')) {
|
||||
const key = part.slice(2);
|
||||
const value = parts[i + 1];
|
||||
if (value && !value.startsWith('--')) {
|
||||
args[key] = value;
|
||||
i++; // Skip next part
|
||||
}
|
||||
} else if (!args.path && !args.wing && !args.query) {
|
||||
// Positional arguments
|
||||
if (!args.path) args.path = part;
|
||||
else if (!args.wing) args.wing = part;
|
||||
else if (!args.query) args.query = part;
|
||||
}
|
||||
}
|
||||
|
||||
try {
|
||||
const result = await executeMemPalaceAction(action, args);
|
||||
return {
|
||||
success: true,
|
||||
...result,
|
||||
deprecated: true,
|
||||
warning: 'This endpoint is deprecated. Use mempalace-action instead.'
|
||||
};
|
||||
} catch (error) {
|
||||
return {
|
||||
success: false,
|
||||
error: error.message,
|
||||
deprecated: true
|
||||
};
|
||||
}
|
||||
});
|
||||
|
||||
console.log('[MemPalace] Secure IPC handlers registered');
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
setupSecureMemPalaceIPC,
|
||||
executeMemPalaceAction,
|
||||
ALLOWED_ACTIONS
|
||||
};
|
||||
@@ -395,7 +395,6 @@
|
||||
<div id="memory-connections-panel" class="memory-connections-panel" style="display:none;" aria-label="Memory Connections Panel"></div>
|
||||
|
||||
<script src="./boot.js"></script>
|
||||
<script src="./js/nostr-event-visualizer.js"></script>
|
||||
<script src="./avatar-customization.js"></script>
|
||||
<script src="./lod-system.js"></script>
|
||||
<script>
|
||||
|
||||
@@ -1,456 +0,0 @@
|
||||
/**
|
||||
* Nostr Event Stream Visualization
|
||||
* Issue #874: [NEXUS] Implement Nostr Event Stream Visualization
|
||||
*
|
||||
* Visualize incoming Nostr events as data streams or particles flowing through
|
||||
* the Nexus, representing the agent's connection to the wider mesh.
|
||||
*/
|
||||
|
||||
class NostrEventVisualizer {
|
||||
constructor(options = {}) {
|
||||
this.relayUrl = options.relayUrl || 'wss://relay.nostr.info';
|
||||
this.maxEvents = options.maxEvents || 100;
|
||||
this.particleCount = options.particleCount || 50;
|
||||
this.streamSpeed = options.streamSpeed || 1.0;
|
||||
this.particleSize = options.particleSize || 0.5;
|
||||
|
||||
this.ws = null;
|
||||
this.events = [];
|
||||
this.particles = [];
|
||||
this.scene = null;
|
||||
this.camera = null;
|
||||
this.renderer = null;
|
||||
|
||||
this.isConnected = false;
|
||||
this.reconnectAttempts = 0;
|
||||
this.maxReconnectAttempts = 5;
|
||||
|
||||
// Callbacks
|
||||
this.onEvent = options.onEvent || (() => {});
|
||||
this.onConnect = options.onConnect || (() => {});
|
||||
this.onDisconnect = options.onDisconnect || (() => {});
|
||||
this.onError = options.onError || console.error;
|
||||
|
||||
// Event types to visualize
|
||||
this.eventTypes = options.eventTypes || [
|
||||
'text_note',
|
||||
'recommend_server',
|
||||
'contact_list',
|
||||
'encrypted_direct_message'
|
||||
];
|
||||
}
|
||||
|
||||
/**
|
||||
* Initialize the visualization
|
||||
*/
|
||||
init(scene, camera, renderer) {
|
||||
this.scene = scene;
|
||||
this.camera = camera;
|
||||
this.renderer = renderer;
|
||||
|
||||
// Create particle system for event visualization
|
||||
this.createParticleSystem();
|
||||
|
||||
console.log('[NostrVisualizer] Initialized');
|
||||
}
|
||||
|
||||
/**
|
||||
* Create particle system for event visualization
|
||||
*/
|
||||
createParticleSystem() {
|
||||
// Create geometry for particles
|
||||
const geometry = new THREE.BufferGeometry();
|
||||
const positions = new Float32Array(this.particleCount * 3);
|
||||
const colors = new Float32Array(this.particleCount * 3);
|
||||
const sizes = new Float32Array(this.particleCount);
|
||||
|
||||
// Initialize particles
|
||||
for (let i = 0; i < this.particleCount; i++) {
|
||||
// Random position in a sphere
|
||||
const theta = Math.random() * Math.PI * 2;
|
||||
const phi = Math.acos(2 * Math.random() - 1);
|
||||
const r = 50 + Math.random() * 50;
|
||||
|
||||
positions[i * 3] = r * Math.sin(phi) * Math.cos(theta);
|
||||
positions[i * 3 + 1] = r * Math.sin(phi) * Math.sin(theta);
|
||||
positions[i * 3 + 2] = r * Math.cos(phi);
|
||||
|
||||
// Color based on event type
|
||||
colors[i * 3] = 0.3; // R
|
||||
colors[i * 3 + 1] = 0.8; // G
|
||||
colors[i * 3 + 2] = 1.0; // B
|
||||
|
||||
sizes[i] = this.particleSize;
|
||||
|
||||
// Store particle data
|
||||
this.particles.push({
|
||||
index: i,
|
||||
x: positions[i * 3],
|
||||
y: positions[i * 3 + 1],
|
||||
z: positions[i * 3 + 2],
|
||||
vx: (Math.random() - 0.5) * 0.1,
|
||||
vy: (Math.random() - 0.5) * 0.1,
|
||||
vz: (Math.random() - 0.5) * 0.1,
|
||||
color: { r: 0.3, g: 0.8, b: 1.0 },
|
||||
size: this.particleSize,
|
||||
event: null
|
||||
});
|
||||
}
|
||||
|
||||
geometry.setAttribute('position', new THREE.BufferAttribute(positions, 3));
|
||||
geometry.setAttribute('color', new THREE.BufferAttribute(colors, 3));
|
||||
geometry.setAttribute('size', new THREE.BufferAttribute(sizes, 1));
|
||||
|
||||
// Create material
|
||||
const material = new THREE.PointsMaterial({
|
||||
size: this.particleSize,
|
||||
vertexColors: true,
|
||||
transparent: true,
|
||||
opacity: 0.8,
|
||||
blending: THREE.AdditiveBlending
|
||||
});
|
||||
|
||||
// Create points
|
||||
this.particleSystem = new THREE.Points(geometry, material);
|
||||
this.scene.add(this.particleSystem);
|
||||
|
||||
console.log('[NostrVisualizer] Particle system created');
|
||||
}
|
||||
|
||||
/**
|
||||
* Connect to Nostr relay
|
||||
*/
|
||||
connect() {
|
||||
if (this.isConnected) {
|
||||
console.warn('[NostrVisualizer] Already connected');
|
||||
return;
|
||||
}
|
||||
|
||||
console.log(`[NostrVisualizer] Connecting to ${this.relayUrl}...`);
|
||||
|
||||
try {
|
||||
this.ws = new WebSocket(this.relayUrl);
|
||||
|
||||
this.ws.onopen = () => {
|
||||
console.log('[NostrVisualizer] Connected to Nostr relay');
|
||||
this.isConnected = true;
|
||||
this.reconnectAttempts = 0;
|
||||
|
||||
// Subscribe to events
|
||||
this.subscribe();
|
||||
|
||||
// Call connect callback
|
||||
this.onConnect();
|
||||
};
|
||||
|
||||
this.ws.onmessage = (event) => {
|
||||
try {
|
||||
const data = JSON.parse(event.data);
|
||||
this.handleEvent(data);
|
||||
} catch (error) {
|
||||
console.error('[NostrVisualizer] Failed to parse event:', error);
|
||||
}
|
||||
};
|
||||
|
||||
this.ws.onclose = () => {
|
||||
console.log('[NostrVisualizer] Disconnected from Nostr relay');
|
||||
this.isConnected = false;
|
||||
|
||||
// Call disconnect callback
|
||||
this.onDisconnect();
|
||||
|
||||
// Attempt reconnect
|
||||
this.scheduleReconnect();
|
||||
};
|
||||
|
||||
this.ws.onerror = (error) => {
|
||||
console.error('[NostrVisualizer] WebSocket error:', error);
|
||||
this.onError(error);
|
||||
};
|
||||
|
||||
} catch (error) {
|
||||
console.error('[NostrVisualizer] Failed to connect:', error);
|
||||
this.onError(error);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Subscribe to Nostr events
|
||||
*/
|
||||
subscribe() {
|
||||
if (!this.isConnected || !this.ws) {
|
||||
console.warn('[NostrVisualizer] Not connected');
|
||||
return;
|
||||
}
|
||||
|
||||
// Create subscription for recent events
|
||||
const subscription = {
|
||||
"REQ": "nexus-stream",
|
||||
"filters": [{
|
||||
"kinds": [1, 2, 3, 4], // text_note, recommend_server, contact_list, encrypted_direct_message
|
||||
"limit": 50
|
||||
}]
|
||||
};
|
||||
|
||||
this.ws.send(JSON.stringify(subscription));
|
||||
console.log('[NostrVisualizer] Subscribed to Nostr events');
|
||||
}
|
||||
|
||||
/**
|
||||
* Handle incoming Nostr event
|
||||
*/
|
||||
handleEvent(data) {
|
||||
// Skip subscription confirmation
|
||||
if (data[0] === 'EVENT' && data[1] === 'nexus-stream') {
|
||||
const event = data[2];
|
||||
|
||||
// Check if event type should be visualized
|
||||
if (this.eventTypes.includes(this.getEventType(event.kind))) {
|
||||
this.visualizeEvent(event);
|
||||
this.onEvent(event);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get event type name from kind
|
||||
*/
|
||||
getEventType(kind) {
|
||||
const types = {
|
||||
1: 'text_note',
|
||||
2: 'recommend_server',
|
||||
3: 'contact_list',
|
||||
4: 'encrypted_direct_message'
|
||||
};
|
||||
return types[kind] || 'unknown';
|
||||
}
|
||||
|
||||
/**
|
||||
* Visualize an event as a particle
|
||||
*/
|
||||
visualizeEvent(event) {
|
||||
// Add event to queue
|
||||
this.events.push({
|
||||
event: event,
|
||||
timestamp: Date.now(),
|
||||
visualized: false
|
||||
});
|
||||
|
||||
// Limit queue size
|
||||
if (this.events.length > this.maxEvents) {
|
||||
this.events.shift();
|
||||
}
|
||||
|
||||
// Update particle for this event
|
||||
this.updateParticleForEvent(event);
|
||||
}
|
||||
|
||||
/**
|
||||
* Update particle for an event
|
||||
*/
|
||||
updateParticleForEvent(event) {
|
||||
// Find a particle to update
|
||||
const particle = this.particles.find(p => !p.event);
|
||||
|
||||
if (!particle) {
|
||||
// All particles are in use, recycle oldest
|
||||
const oldest = this.particles.reduce((a, b) =>
|
||||
(a.event && a.event.timestamp < b.event.timestamp) ? a : b
|
||||
);
|
||||
this.resetParticle(oldest);
|
||||
this.updateParticleWithEvent(oldest, event);
|
||||
} else {
|
||||
this.updateParticleWithEvent(particle, event);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Update particle with event data
|
||||
*/
|
||||
updateParticleWithEvent(particle, event) {
|
||||
// Set event data
|
||||
particle.event = event;
|
||||
|
||||
// Set color based on event type
|
||||
const colors = {
|
||||
'text_note': { r: 0.3, g: 0.8, b: 1.0 }, // Blue
|
||||
'recommend_server': { r: 1.0, g: 0.8, b: 0.3 }, // Gold
|
||||
'contact_list': { r: 0.3, g: 1.0, b: 0.8 }, // Cyan
|
||||
'encrypted_direct_message': { r: 1.0, g: 0.3, b: 0.8 } // Pink
|
||||
};
|
||||
|
||||
const eventType = this.getEventType(event.kind);
|
||||
particle.color = colors[eventType] || { r: 0.5, g: 0.5, b: 0.5 };
|
||||
|
||||
// Update geometry
|
||||
this.updateParticleGeometry(particle);
|
||||
|
||||
console.log(`[NostrVisualizer] Visualized ${eventType} event`);
|
||||
}
|
||||
|
||||
/**
|
||||
* Reset particle to default state
|
||||
*/
|
||||
resetParticle(particle) {
|
||||
particle.event = null;
|
||||
particle.color = { r: 0.3, g: 0.8, b: 1.0 };
|
||||
particle.size = this.particleSize;
|
||||
|
||||
// Random position
|
||||
const theta = Math.random() * Math.PI * 2;
|
||||
const phi = Math.acos(2 * Math.random() - 1);
|
||||
const r = 50 + Math.random() * 50;
|
||||
|
||||
particle.x = r * Math.sin(phi) * Math.cos(theta);
|
||||
particle.y = r * Math.sin(phi) * Math.sin(theta);
|
||||
particle.z = r * Math.cos(phi);
|
||||
|
||||
this.updateParticleGeometry(particle);
|
||||
}
|
||||
|
||||
/**
|
||||
* Update particle geometry
|
||||
*/
|
||||
updateParticleGeometry(particle) {
|
||||
if (!this.particleSystem) return;
|
||||
|
||||
const geometry = this.particleSystem.geometry;
|
||||
const positions = geometry.attributes.position.array;
|
||||
const colors = geometry.attributes.color.array;
|
||||
const sizes = geometry.attributes.size.array;
|
||||
|
||||
// Update position
|
||||
positions[particle.index * 3] = particle.x;
|
||||
positions[particle.index * 3 + 1] = particle.y;
|
||||
positions[particle.index * 3 + 2] = particle.z;
|
||||
|
||||
// Update color
|
||||
colors[particle.index * 3] = particle.color.r;
|
||||
colors[particle.index * 3 + 1] = particle.color.g;
|
||||
colors[particle.index * 3 + 2] = particle.color.b;
|
||||
|
||||
// Update size
|
||||
sizes[particle.index] = particle.size;
|
||||
|
||||
// Mark attributes as needing update
|
||||
geometry.attributes.position.needsUpdate = true;
|
||||
geometry.attributes.color.needsUpdate = true;
|
||||
geometry.attributes.size.needsUpdate = true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Update visualization
|
||||
*/
|
||||
update(deltaTime) {
|
||||
if (!this.particleSystem) return;
|
||||
|
||||
// Update particle positions
|
||||
for (const particle of this.particles) {
|
||||
// Move particle
|
||||
particle.x += particle.vx * this.streamSpeed * deltaTime;
|
||||
particle.y += particle.vy * this.streamSpeed * deltaTime;
|
||||
particle.z += particle.vz * this.streamSpeed * deltaTime;
|
||||
|
||||
// Add some turbulence
|
||||
particle.vx += (Math.random() - 0.5) * 0.01;
|
||||
particle.vy += (Math.random() - 0.5) * 0.01;
|
||||
particle.vz += (Math.random() - 0.5) * 0.01;
|
||||
|
||||
// Limit velocity
|
||||
const maxVel = 0.5;
|
||||
particle.vx = Math.max(-maxVel, Math.min(maxVel, particle.vx));
|
||||
particle.vy = Math.max(-maxVel, Math.min(maxVel, particle.vy));
|
||||
particle.vz = Math.max(-maxVel, Math.min(maxVel, particle.vz));
|
||||
|
||||
// Keep particles in bounds
|
||||
const maxDist = 100;
|
||||
if (Math.abs(particle.x) > maxDist) particle.vx *= -0.5;
|
||||
if (Math.abs(particle.y) > maxDist) particle.vy *= -0.5;
|
||||
if (Math.abs(particle.z) > maxDist) particle.vz *= -0.5;
|
||||
|
||||
// Update geometry
|
||||
this.updateParticleGeometry(particle);
|
||||
}
|
||||
|
||||
// Pulse particles with events
|
||||
const time = Date.now() * 0.001;
|
||||
for (const particle of this.particles) {
|
||||
if (particle.event) {
|
||||
// Pulse size for particles with events
|
||||
particle.size = this.particleSize * (1 + 0.2 * Math.sin(time * 3 + particle.index));
|
||||
this.updateParticleGeometry(particle);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Schedule reconnection
|
||||
*/
|
||||
scheduleReconnect() {
|
||||
if (this.reconnectAttempts >= this.maxReconnectAttempts) {
|
||||
console.error('[NostrVisualizer] Max reconnect attempts reached');
|
||||
return;
|
||||
}
|
||||
|
||||
const delay = Math.min(1000 * Math.pow(2, this.reconnectAttempts), 30000);
|
||||
|
||||
console.log(`[NostrVisualizer] Reconnecting in ${delay / 1000}s...`);
|
||||
|
||||
setTimeout(() => {
|
||||
this.reconnectAttempts++;
|
||||
this.connect();
|
||||
}, delay);
|
||||
}
|
||||
|
||||
/**
|
||||
* Disconnect from Nostr relay
|
||||
*/
|
||||
disconnect() {
|
||||
console.log('[NostrVisualizer] Disconnecting...');
|
||||
|
||||
if (this.ws) {
|
||||
this.ws.close();
|
||||
this.ws = null;
|
||||
}
|
||||
|
||||
this.isConnected = false;
|
||||
|
||||
// Clear particles
|
||||
for (const particle of this.particles) {
|
||||
this.resetParticle(particle);
|
||||
}
|
||||
|
||||
console.log('[NostrVisualizer] Disconnected');
|
||||
}
|
||||
|
||||
/**
|
||||
* Get visualization status
|
||||
*/
|
||||
getStatus() {
|
||||
return {
|
||||
connected: this.isConnected,
|
||||
relayUrl: this.relayUrl,
|
||||
eventCount: this.events.length,
|
||||
particleCount: this.particles.length,
|
||||
activeParticles: this.particles.filter(p => p.event).length,
|
||||
reconnectAttempts: this.reconnectAttempts
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
// Export for use in other modules
|
||||
if (typeof module !== 'undefined' && module.exports) {
|
||||
module.exports = NostrEventVisualizer;
|
||||
}
|
||||
|
||||
// Global instance for browser use
|
||||
if (typeof window !== 'undefined') {
|
||||
window.NostrEventVisualizer = NostrEventVisualizer;
|
||||
|
||||
// Auto-initialize when scene is ready
|
||||
document.addEventListener('DOMContentLoaded', () => {
|
||||
// This would be called when Three.js scene is initialized
|
||||
// window.nostrVisualizer = new NostrEventVisualizer();
|
||||
// window.nostrVisualizer.init(scene, camera, renderer);
|
||||
});
|
||||
}
|
||||
24
preload.js
Normal file
24
preload.js
Normal file
@@ -0,0 +1,24 @@
|
||||
/**
|
||||
* Preload script for Electron
|
||||
* Exposes secure MemPalace API to renderer
|
||||
*/
|
||||
|
||||
const { contextBridge, ipcRenderer } = require('electron');
|
||||
|
||||
// Expose secure MemPalace API to renderer
|
||||
contextBridge.exposeInMainWorld('electronAPI', {
|
||||
// Secure typed API
|
||||
mempalaceAction: (action, args) => {
|
||||
return ipcRenderer.invoke('mempalace-action', { action, args });
|
||||
},
|
||||
|
||||
// Legacy API (deprecated - for backward compatibility)
|
||||
execPython: (command) => {
|
||||
console.warn('[MemPalace] execPython is deprecated. Use mempalaceAction instead.');
|
||||
return ipcRenderer.invoke('exec-python', command);
|
||||
},
|
||||
|
||||
// Utility functions
|
||||
platform: process.platform,
|
||||
versions: process.versions
|
||||
});
|
||||
177
tests/test_secure_mempalace_ipc.js
Normal file
177
tests/test_secure_mempalace_ipc.js
Normal file
@@ -0,0 +1,177 @@
|
||||
/**
|
||||
* Tests for secure MemPalace IPC bridge
|
||||
* Issue #1423: [SECURITY] Electron MemPalace bridge allows arbitrary command execution
|
||||
*/
|
||||
|
||||
const test = require('node:test');
|
||||
const assert = require('node:assert/strict');
|
||||
const { setupSecureMemPalaceIPC, executeMemPalaceAction, ALLOWED_ACTIONS } = require('./electron-mempalace-bridge');
|
||||
|
||||
// Mock Electron IPC
|
||||
const mockIpcMain = {
|
||||
handlers: {},
|
||||
handle: function(channel, handler) {
|
||||
this.handlers[channel] = handler;
|
||||
},
|
||||
removeHandler: function(channel) {
|
||||
delete this.handlers[channel];
|
||||
}
|
||||
};
|
||||
|
||||
// Mock child_process.spawn
|
||||
const mockSpawn = jest.fn();
|
||||
|
||||
// Setup before tests
|
||||
test.before(() => {
|
||||
// Mock require
|
||||
const Module = require('module');
|
||||
const originalRequire = Module.prototype.require;
|
||||
|
||||
Module.prototype.require = function(id) {
|
||||
if (id === 'child_process') {
|
||||
return { spawn: mockSpawn };
|
||||
}
|
||||
if (id === 'electron') {
|
||||
return { ipcMain: mockIpcMain };
|
||||
}
|
||||
return originalRequire.apply(this, arguments);
|
||||
};
|
||||
});
|
||||
|
||||
test('ALLOWED_ACTIONS contains expected actions', () => {
|
||||
const expectedActions = ['init', 'mine', 'search', 'status', 'add_drawer'];
|
||||
expectedActions.forEach(action => {
|
||||
assert.ok(ALLOWED_ACTIONS[action], `Should have ${action} action`);
|
||||
assert.ok(ALLOWED_ACTIONS[action].command, `${action} should have command`);
|
||||
assert.ok(ALLOWED_ACTIONS[action].args, `${action} should have args`);
|
||||
assert.ok(ALLOWED_ACTIONS[action].validate, `${action} should have validate function`);
|
||||
});
|
||||
});
|
||||
|
||||
test('Valid init action works', async () => {
|
||||
// Mock spawn to return success
|
||||
const mockChild = {
|
||||
stdout: { on: (event, cb) => { if (event === 'data') cb('OK'); } },
|
||||
stderr: { on: () => {} },
|
||||
on: (event, cb) => { if (event === 'close') cb(0); }
|
||||
};
|
||||
mockSpawn.mockReturnValue(mockChild);
|
||||
|
||||
const result = await executeMemPalaceAction('init', { palacePath: '/safe/path' });
|
||||
assert.equal(result.stdout, 'OK');
|
||||
assert.equal(result.stderr, '');
|
||||
assert.equal(result.code, 0);
|
||||
});
|
||||
|
||||
test('Valid mine action works', async () => {
|
||||
const mockChild = {
|
||||
stdout: { on: (event, cb) => { if (event === 'data') cb('Mined'); } },
|
||||
stderr: { on: () => {} },
|
||||
on: (event, cb) => { if (event === 'close') cb(0); }
|
||||
};
|
||||
mockSpawn.mockReturnValue(mockChild);
|
||||
|
||||
const result = await executeMemPalaceAction('mine', {
|
||||
path: '/safe/path',
|
||||
mode: 'convos',
|
||||
wing: 'test_wing'
|
||||
});
|
||||
assert.equal(result.stdout, 'Mined');
|
||||
});
|
||||
|
||||
test('Rejects unsafe characters in init', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('init', { palacePath: '/path; rm -rf /' }),
|
||||
{ message: /unsafe characters/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Rejects unsafe characters in mine', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('mine', {
|
||||
path: '/path; rm -rf /',
|
||||
mode: 'convos',
|
||||
wing: 'test'
|
||||
}),
|
||||
{ message: /unsafe characters/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Rejects unsafe characters in search', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('search', {
|
||||
query: 'test; rm -rf /',
|
||||
wing: 'test'
|
||||
}),
|
||||
{ message: /unsafe characters/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Rejects unknown actions', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('unknown', {}),
|
||||
{ message: /Unknown action/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Rejects invalid mine mode', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('mine', {
|
||||
path: '/safe/path',
|
||||
mode: 'invalid_mode',
|
||||
wing: 'test'
|
||||
}),
|
||||
{ message: /Mode must be one of/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Rejects missing required arguments', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('mine', {
|
||||
path: '/safe/path',
|
||||
// Missing mode and wing
|
||||
}),
|
||||
{ message: /must be a string/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Search with optional arguments works', async () => {
|
||||
const mockChild = {
|
||||
stdout: { on: (event, cb) => { if (event === 'data') cb('Results'); } },
|
||||
stderr: { on: () => {} },
|
||||
on: (event, cb) => { if (event === 'close') cb(0); }
|
||||
};
|
||||
mockSpawn.mockReturnValue(mockChild);
|
||||
|
||||
const result = await executeMemPalaceAction('search', {
|
||||
query: 'test query',
|
||||
wing: 'test_wing',
|
||||
room: 'test_room',
|
||||
n: 10
|
||||
});
|
||||
assert.equal(result.stdout, 'Results');
|
||||
});
|
||||
|
||||
test('Rejects unsafe room in search', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('search', {
|
||||
query: 'safe query',
|
||||
wing: 'safe_wing',
|
||||
room: 'room; rm -rf /'
|
||||
}),
|
||||
{ message: /unsafe characters/ }
|
||||
);
|
||||
});
|
||||
|
||||
test('Rejects unsafe text in add_drawer', async () => {
|
||||
await assert.rejects(
|
||||
() => executeMemPalaceAction('add_drawer', {
|
||||
wing: 'safe_wing',
|
||||
room: 'safe_room',
|
||||
text: 'text; rm -rf /'
|
||||
}),
|
||||
{ message: /unsafe characters/ }
|
||||
);
|
||||
});
|
||||
|
||||
console.log('All secure MemPalace IPC tests passed!');
|
||||
Reference in New Issue
Block a user