Two unblocking changes for first-contact flows.
Sender attribution: relay captures shortHash(senderSigningKey) at
PUT time (after signature verification, no new trust surface) and
surfaces it on bridge push (IncomingMessage.from) + inbox-fetch
(FetchedBlob.from) + DecryptHandler raw arg. Apps receiving a prekey
envelope from a never-before-seen peer can now bootstrap X3DH via
shade.receive('fp:<hex>', env) — pre-4.8 the wire envelope didn't
authenticate the sender and there was no out-of-band hint to use.
Idempotent ALTER TABLE migrations for SQLite + Postgres add a
sender_fp TEXT column; legacy rows surface as from=undefined
(inter-version compat).
Inbox.start() race: pre-4.8 start() called register() fire-and-forget
AND schedulePoll(0) synchronously, so the first poll on a fresh
address often beat the register HTTP RTT and got SHADE_NOT_FOUND.
start() now defers; register() success kicks schedulePoll(0). Manual
tick() is unaffected (deliberate user action, no gating).
Both reported by Prism. Tests cover all five acceptance criteria
from the sender-attribution request (PUT capture, bridge surface,
fetch surface, inter-version compat, end-to-end pair smoke) plus
the three from the race-fix request.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@shade/widgets
Embeddable React widgets for live Shade observability. Drop them into any React dashboard (Nova, Orchestrator, your own apps) to show what's happening in your Shade deployment.
Install
bun add @shade/widgets react react-dom
Quick start
import { ShadeProvider, IdentityCard, SessionList, RecentActivity } from '@shade/widgets';
function MyDashboard() {
return (
<ShadeProvider
observerUrl="https://shade.example.com/shade-observer"
token={process.env.SHADE_TOKEN!}
>
<IdentityCard />
<SessionList />
<RecentActivity />
</ShadeProvider>
);
}
You need a running @shade/observer endpoint for the widgets to talk to.
Components
| Component | Description |
|---|---|
<IdentityCard /> |
Your fingerprint, registration ID, init/rotation timestamps |
<SessionList /> |
Active Shade sessions with per-session message counts and DH ratchet steps |
<PrekeyStock lowThreshold={5} /> |
Gauge of remaining one-time prekeys with low-stock warning |
<RecentActivity limit={50} /> |
Live SSE feed of events flowing through the system |
<ServerStatus /> |
Prekey server stats (registered identities, fetches, replenishes, rate limits) |
<FingerprintCompare /> |
Paste a safety number to verify it matches your identity |
<WidgetCatalog /> |
Meta-widget letting users pick which widgets to display |
Letting users pick widgets
<ShadeProvider observerUrl="..." token="...">
<WidgetCatalog
available={['identity', 'sessions', 'prekeys', 'activity', 'server']}
defaultLayout={['identity', 'sessions', 'activity']}
/>
</ShadeProvider>
User selections persist to localStorage. Pass onLayoutChange to override with your own persistence.
Theming
<ShadeProvider observerUrl="..." token="..." themeMode="auto">
Modes: dark (default), light, auto (matches prefers-color-scheme).
Each widget renders self-contained CSS via inline styles — no Tailwind, no external CSS file, no conflicts with your host app.
Hooks
For custom layouts, use the underlying hooks directly:
import { useShadeState, useShadeEvents } from '@shade/widgets';
function CustomWidget() {
const { state, loading } = useShadeState();
const { events, connected } = useShadeEvents();
// ... render whatever you want
}
Polling interval
Default poll for /api/state is 5 seconds. Override:
<ShadeProvider observerUrl="..." token="..." pollIntervalMs={2000}>
The SSE event stream updates instantly regardless of poll interval.