* chat: de-dup private chats across ephemeral/stable IDs; prefer most advanced delivery status\n\n- Fixes LazyVStack duplicate ID warnings and blank row in PM\n- Merges messages by id from ephemeral and Noise-key stores\n- Chooses read > delivered > partiallyDelivered > sent > sending > failed (newer wins on tie)\n- Ensures status icon updates immediately without waiting for another send\n- Adds exhaustive handling for DeliveryStatus in ranking
* logging: reduce noisy info logs to debug; keep errors/warnings\n\n- Downgrade routing/ACK/subscription/connect logs to debug\n- Retain security/fingerprint/keychain info logs\n- Keep errors and warnings intact\n\ndocs: add docs/privacy-assessment.md covering BLE privacy, routing TTL/jitter, Nostr E2E gift wraps, ACK throttling, and logging posture
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
* Refactor: move Nostr embedding and TLVs out of BLE; add NostrEmbeddedBitChat, Packets, PeerIDUtils; centralize MessageDeduplicator; update ChatViewModel to use new helpers; remove AI_CONTEXT.md and CLAUDE.md
* Rename class to BLEService with compatibility alias; move mention parsing out of BLE; emit low-level BLE events to delegate; unify hex helpers; accept 64-hex in isPeerConnected; add PeerIDResolver
* Project: rename file to BLEService.swift and update Xcode project; keep typealias SimplifiedBluetoothService = BLEService for compatibility
* Remove SimplifiedBluetoothService alias; update app code to use BLEService explicitly
* Tests: rename MockSimplifiedBluetoothService to MockBLEService; update typealiases and Xcode project
* Docs: update comments to refer to BLEService (tests, protocol, noise service)
* Tests: rename SimplifiedBluetoothServiceTests to BLEServiceTests; update project references and class names
* Introduce Transport protocol; BLEService conforms; document delegate-only event pattern in BLEService; keep publishers internal for UnifiedPeerService
* Adopt Transport end-to-end: add TransportPeerSnapshot + publishers; BLEService maps to Transport snapshots; UnifiedPeerService consumes Transport; ChatViewModel holds Transport
* Fix Transport integration: replace getPeerFingerprint with getFingerprint(for:); update PrivateChatManager and CommandProcessor to use Transport; add BLEService.getFingerprint(for:); update PeerManager to use Transport
* Refactor transport and BLE/Nostr layers; unify UI events; fix MainActor isolation
- Rename SimplifiedBluetoothService to BLEService and slim responsibilities
- Introduce Transport protocol and peerEventsDelegate for UI updates
- Add NostrTransport and MessageRouter to route PM/read/favorite via BLE or Nostr
- Centralize TLVs, PeerID utils, and MessageDeduplicator outside BLE
- Update UnifiedPeerService and ChatViewModel to use Transport and delegate events
- Fix MainActor isolation: route delegate calls via Task on MainActor; update notifyUI helper
- Adjust related files and tests accordingly
* BLEService: remove internal publishers; switch to delegate-only events
- Drop legacy messages/peers/fullPeers publishers
- Provide lightweight peerSnapshotSubject only to satisfy Transport
- Rework publishFullPeerData to build snapshots from internal state and notify delegate + subject
- Remove all peersPublisher.send call sites
- Keep UnifiedPeerService on delegate updates exclusively
* Remove inlined Nostr send helpers from ChatViewModel; route via MessageRouter
- Replace direct Nostr sends (PM, ACKs, favorites) with MessageRouter
- Add router method for delivery ACKs and implement NostrTransport.sendDeliveryAck
- Simplify ChatViewModel favorite notification path to use router
- Keep Nostr receive handling intact; reduce duplication
* Fix ReadReceipt initializer usage in ChatViewModel (readerID + readerNickname)
* Fix unused variable warning: replace shadowed 'nostrPubkey' bind with boolean check in ChatViewModel
* Fix queued PM format: use TLV for pending messages after Noise handshake
- Pending messages (including first-time favorite notifications) now use the same TLV encoding as normal sends
- Ensures ChatViewModel can decode on first send, even if handshake completes after queuing
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
* UI: prefer mesh radio icon when connected; map short peer ID to full Noise key; rename ephemeral mapping to shortIDToNoiseKey; ensure header flips to purple globe on disconnect and keeps name.
* chore: stop tracking build artifacts; ignore .DerivedData and .Result*
* logging: add global threshold via BITCHAT_LOG_LEVEL and demote chatty logs to debug; keep critical errors/warnings and key state transitions
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Remove completely unused message aggregation system (100% dead code)
- Remove broken store-and-forward implementation that only worked for relayed messages to offline favorites
- Update documentation to reflect actual functionality
- Net reduction of 312 lines of unmaintained code
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
* refactor: remove dead code and consolidate system messages
- Delete 3 unused functions in ShareViewController (36 lines)
- Extract addSystemMessage() helper to eliminate duplication (120+ lines)
- Remove 22 'let _ =' wasteful computations across multiple files
- Net reduction of 215 lines of dead/duplicate code
- Improves maintainability and reduces technical debt
* fix: remove remaining unused variables to eliminate compiler warnings
- Remove unused senderNoiseKey in ChatViewModel
- Remove unused lastSuccess variable in BluetoothMeshService
- Eliminates all compiler warnings related to unused values
* refactor: remove all dead legacy and migration code
- Remove unused migrateSession() functions (never called in production)
- NoiseSession.migrateSession() - 13 lines
- NoiseEncryptionService.migratePeerSession() - 18 lines
- Test for migration functionality - 17 lines
- Remove unnecessary keychain cleanup code (no legacy data existed)
- cleanupLegacyKeychainItems() - 62 lines
- aggressiveCleanupLegacyItems() - 72 lines
- resetCleanupFlag() - 4 lines
- Simplified panic mode to just use deleteAllKeychainData()
Total removed: 194 lines of dead/unnecessary code
Analysis revealed:
- KeychainManager introduced July 5, 2025
- Cleanup code added July 15, 2025 (10 days later)
- Legacy service names were never used in production
- Migration functions were incomplete implementation never called
- Peer ID rotation remains active (not legacy)
* Remove dead code and simplify codebase
- Remove unused BinaryEncodable protocol and BinaryMessageType enum
- Delete MockNoiseSession.swift (never used in tests)
- Remove all relay detection code (hardcoded to false)
- Removed isRelayConnected property from BitchatPeer
- Removed relayConnected case from ConnectionState enum
- Cleaned up relay-related UI indicators in ContentView
- Removed relay status checks from ChatViewModel
- Simplified peer connection logic by removing relay layer
Total: 169 lines removed across 5 files
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Remove unused BinaryEncodable protocol and BinaryMessageType enum
- Delete MockNoiseSession.swift (never used in tests)
- Remove all relay detection code (hardcoded to false)
- Removed isRelayConnected property from BitchatPeer
- Removed relayConnected case from ConnectionState enum
- Cleaned up relay-related UI indicators in ContentView
- Removed relay status checks from ChatViewModel
- Simplified peer connection logic by removing relay layer
Total: 169 lines removed across 5 files
- Remove unused migrateSession() functions (never called in production)
- NoiseSession.migrateSession() - 13 lines
- NoiseEncryptionService.migratePeerSession() - 18 lines
- Test for migration functionality - 17 lines
- Remove unnecessary keychain cleanup code (no legacy data existed)
- cleanupLegacyKeychainItems() - 62 lines
- aggressiveCleanupLegacyItems() - 72 lines
- resetCleanupFlag() - 4 lines
- Simplified panic mode to just use deleteAllKeychainData()
Total removed: 194 lines of dead/unnecessary code
Analysis revealed:
- KeychainManager introduced July 5, 2025
- Cleanup code added July 15, 2025 (10 days later)
- Legacy service names were never used in production
- Migration functions were incomplete implementation never called
- Peer ID rotation remains active (not legacy)
- Remove unused senderNoiseKey in ChatViewModel
- Remove unused lastSuccess variable in BluetoothMeshService
- Eliminates all compiler warnings related to unused values
Simplified the protocol by removing version negotiation and handshake sequences.
All devices now use protocol version 1 without negotiation. This eliminates
unnecessary connection overhead and complexity while maintaining full
compatibility across the network.
Changes:
- Removed versionHello and versionAck message types
- Simplified connection flow to use announce packets only
- Removed version negotiation state tracking
- Cleaned up handshake timeout logic
- Reduced connection establishment overhead
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Increase tap target size for back button in private message view
- Limit @mentions autocomplete to top 4 matches for better usability
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Remove system messages for peer connections to reduce chat noise
- Keep essential state management (ephemeral sessions, read receipts)
- Users can still see who's online via /w command
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Add alert UI to notify users when Bluetooth is off/unauthorized
- Monitor Bluetooth state changes in BluetoothMeshService
- Show appropriate messages for different Bluetooth states
- Add Settings button to open system settings on iOS
- Check initial Bluetooth state on app startup
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Added deduplication logic in ChatViewModel to handle duplicate peer IDs gracefully
- Enhanced PeerManager to prevent duplicate peers by tracking both nicknames and IDs
- Added final safety check to ensure no duplicates in peers array
- This fixes crash when Dictionary(uniqueKeysWithValues:) encounters duplicate keys
- Added getBestAvailableNickname() method to resolve nicknames from multiple sources
- Updated all PeerSession creations to use better nickname resolution
- Changed fallback from 'Unknown' to 'anon[peerID]' format for distinguishability
- Modified getPeerNicknames() to proactively update Unknown entries
- This ensures autocomplete shows meaningful nicknames instead of @Unknown
- Add comprehensive bounds checking before all data access operations
- Validate payload lengths don't exceed available data
- Protect against integer overflow in size calculations
- Handle malformed compressed packets gracefully
- Add extensive test coverage for edge cases
This fixes crashes when receiving malformed Bluetooth packets that claim
payload sizes larger than the actual data available.
- Implement Core Bluetooth state restoration with restoration identifiers
- Add background task management to protect critical BLE operations
- Fix aggressive battery optimization that killed background connectivity
- Disable scan duty cycling in background (was causing 89-97% downtime)
- Add missing didEnterBackground/willEnterForeground notifications
- Fix advertising cutoff in low battery conditions (now only <10%)
- Add background-processing entitlement to Info.plist
- Optimize scan parameters for background vs foreground modes
These changes address the issue where devices lose mesh connectivity when
the app is backgrounded, ensuring continuous Bluetooth operation within
iOS background execution limits.
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Replace VStack with LazyVStack for message list to enable on-demand rendering
- Batch UI updates in ChatViewModel to reduce main thread operations
- Consolidate 12 timers into 3 (high/medium/low frequency) in BluetoothMeshService
- Fix thread safety in scheduleUIUpdate with main thread check
These changes significantly improve app responsiveness and reduce CPU usage.
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Fix force unwrapping in NostrIdentity bech32 functions that could crash on non-ASCII input
- Add comprehensive input validation for all protocol messages (peer IDs, nicknames, timestamps)
- Strengthen keychain security with better sandbox detection and consistent app group usage
- Implement secure memory clearing for cryptographic keys and shared secrets
- Fix panic mode not reconnecting to mesh by restarting services after emergency disconnect
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
* Implement dynamic connection limits based on network size
Fixes connection thrashing in group scenarios by dynamically adjusting the connection limit based on the number of nearby peers.
Changes:
- Replace fixed maxConnectedPeripherals with dynamic calculation
- Maintain full mesh connectivity for small groups (<10 peers)
- Scale connection limit up to 2x for larger groups
- Override battery-based limits when needed to prevent thrashing
- Add logging to track dynamic limit changes
This solves the "perfect storm" issue where 6-8 people would constantly disconnect/reconnect when the power saver mode limited connections to 5.
* Implement optimistic version negotiation with caching
Skip version negotiation for known peers by caching negotiated versions for 24 hours.
Changes:
- Add version cache that persists beyond session lifetime
- Check cache before sending version hello
- Skip negotiation entirely for cached peers (instant connection)
- Cache cleanup runs every 60 seconds
- Invalidate cache on protocol errors for automatic fallback
- Log when using cached versions
This reduces protocol messages by ~40% for reconnecting peers and enables instant connections for known devices.
* Fix unused variable warning
* Implement protocol message deduplication
Suppress duplicate protocol messages within configurable time windows to reduce overhead.
Changes:
- Add deduplication tracker with per-message-type time windows
- Suppress duplicate announces within 5 seconds
- Suppress duplicate version negotiations within 10 seconds
- Track messages by peer ID and optional content hash
- Automatic cleanup of expired entries every 60 seconds
- Log when duplicates are suppressed
This reduces protocol message overhead by 20-30% in group scenarios where multiple connection attempts trigger redundant announcements and version negotiations.
* Fix MessageType enum case name
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>