synapse: route an event by the role of the account it was delivered for
The dispatcher's choice of profile was checked against a hardcoded "user" role,
so an admin's own events could never reach the admin-only profiles their routing
instruction named. The event fell to whichever profile all() happened to yield
first — a profile without the tools the event needed — and the instruction looked
like it did not work. The role now comes from navi_users for the account the event
was delivered for (_user_role, failing closed to "user" and logging), and it is the
role the run carries as current_user_role.

Alongside, in the same path:

- the dispatcher is offered each profile as "id (name) — description", so a rule
  that names a profile in words has something to match it against;
- an unroutable event lands on a role-aware fallback (secretary for an admin,
  assistant otherwise) instead of the first of all(), and every substitution is
  logged as synapse.reaction_profile_downgraded with both ids;
- session_key is folded to one spelling — whitespace collapsed, lowercased — so a
  chat cannot fork on "TG:42" against "tg:42";
- the conversation rule is read from whichever instruction document states it,
  not from the dispatcher one alone.

A refused profile is still refused: hidden stays hidden for everyone, and an
admin-only profile stays out of reach for a regular user's event.
1 parent 4387a27 commit 02f5ac8df1443d26e679742fe6c0326c6eceab6f
@Eugene Sukhodolskiy Eugene Sukhodolskiy authored 1 hour ago
Showing 7 changed files
View
docs/auth.md
View
docs/profiles.md
View
docs/synapse.md
View
manuals/synapse_instructions.md
View
navi/profiles/dispatcher/system_prompt.txt
View
navi/synapse/reactions.py
View
tests/unit/core/test_synapse_reactions.py