Skip to main content

abstract_chatshare

Login-gated chat + file-share + video backend for abstractendeavors.com (route /chat). It is the server half of the contract in PROTOCOL.md; the React frontend (@putkoff/abstract-chatshare) is the other half.

The service is a single asyncio process: websockets for the WS/HTTP surface and psycopg (3, async) over the shared auth_v2 Postgres database. Presence, typing, call state and fan-out live in memory; Postgres is the durable store. There is no web framework, no Redis, no connection pooler — just a tiny internal asyncio.Queue pool of a few connections. The only third-party dependencies are websockets>=17, psycopg[binary]>=3.1 and cryptography (for Web Push), plus self-hosted coturn for TURN.

What it does

  • Discord-like rooms: invite-only, owner/mod/member roles, bans, invite links (with optional guest registration through abstract_logins' invites table), DMs, reactions, edits, read markers, typing, soft-deletes, attachments backed by the existing Secure Files system.
  • Calls: the server only relays WebRTC signaling (rtc.signal) between members of the same room call and issues ephemeral coturn REST credentials; media is a P2P mesh.
  • Bots: a generic, Discord-style bot API (see below). The first bot, hugpy-ai, is built separately as a hugpy-side adapter against this API; this service knows nothing about it.
  • Web Push ("pings"): closed-app notifications via the browser vendors' push services (FCM / Mozilla autopush / APNs). Those services are unavoidable for delivering to a closed app, but every payload is encrypted end-to-end (RFC 8291 aes128gcm under RFC 8292 VAPID, both implemented here on cryptography), so they only ever see ciphertext. Generate the VAPID key with abstract-chatshare vapid generate --out /etc/abstractendeavors/chat-vapid.pem; push is disabled cleanly when no key file is present. Per-room level (all/mentions/none), burst coalescing and foreground suppression are described in the "Web Push" section of PROTOCOL.md.

All of the wire protocol (auth handshake, objects, events, requests, rate limits) lives in PROTOCOL.md and is implemented exactly.

Install / run

pip install abstract_chatshare           # websockets + psycopg[binary]
abstract-chatshare migrate               # create/upgrade the chat_* tables (advisory-locked)
abstract-chatshare serve                 # listen on CHAT_HOST:CHAT_PORT (default 127.0.0.1:6016)

serve runs migrations on startup as well. Configuration is entirely environment-driven; see the Config table in PROTOCOL.md and deploy/chat.env.example. The default DSN is postgresql:///auth_v2 (unix socket, peer auth as the abstractendeavors service user).

nginx proxies location ^~ /chat/ to 127.0.0.1:6016 with the path preserved, so the service sees /chat/ws, /chat/bot, /chat/health, /chat/invite/... and /chat/files/.... See deploy/ for the systemd unit, nginx snippet, env example and a hardened turnserver.conf.

Module map (src/abstract_chatshare/)

module responsibility
config.py env → immutable Config; wire limits + reaction set
db.py tiny async pool, migrations (advisory-locked), every query (parameterized)
auth.py handshake Origin/cookie/session/access checks; periodic re-check
ice.py STUN list + coturn REST ephemeral TURN creds
ratelimit.py per-user and per-IP sliding windows
serialize.py rows → wire objects (User/Room/Member/Invite/Ban/Message/Bot), attachment re-resolution
hub.py connection registry, membership cache, presence, raw fan-out, typing throttle
calls.py in-memory call state + mesh signaling bookkeeping
app.py shared state + high-level fan-out + the single post_message path
handlers.py user request dispatch + validation
bots.py bot invocations, bot request surface, mentions, command validation
http.py public invite endpoints + bot-file serving (CORS, per-IP limits)
server.py websockets.serve + process_request routing + the connection loops
cli.py serve, migrate, bot …

Bot API (surface for the hugpy-ai adapter)

A bot is a global actor (available in every room and in DMs; never a chat_members row). It is created by the operator and connects over a dedicated websocket. Build a hugpy-side adapter against this surface; the service stays generic.

Admin (operator CLI, token shown once, only its sha256 is stored):

abstract-chatshare bot create <name> --display-name "hugpy-ai" [--description "..."]
    # prints  csb_<id>_<token>   (store it; it is never shown again)
abstract-chatshare bot list
abstract-chatshare bot rotate-token <name>      # prints a new token
abstract-chatshare bot enable|disable <name>

name matches ^[a-z0-9_-]{2,32}$ and is the @name used to mention the bot.

Connection: ws://127.0.0.1:6016/chat/bot with header Authorization: Bot <token>.

  • A request carrying an Origin header is refused 403 (bot tokens must never be used from a browser). A bad/disabled token is 401. One live connection per bot; a new one replaces the old (old closed 4409). Max inbound frame 24 MiB (for file.put). Framing is identical to the user side ({t, rid, ...} requests → {t:"res", ...}; {t:"ev", ...} events).

Privacy: a bot receives only (a) messages that @mention it, (b) every message in its DM room, and (c) slash commands addressed to it (cmd.invoke). It never sees other room traffic. A bot may post in a room only in reply to an invocation from that room at most 30 min old, and may edit/delete only its own messages, within 30 min of posting.

Events to the bot: bot.ready, invoke (kind ∈ mention|dm|command), autocomplete. Requests from the bot: commands.set, invocation.defer (→ bot.thinking), msg.send (normal or ephemeral), msg.edit (fan-out coalesced to ≤4/s), msg.delete, typing, file.put (≤16 MiB, served from GET /chat/files/{token}), autocomplete.result. See the Bots section of PROTOCOL.md for exact payloads and CommandSpec/OptionSpec.

Note (clarification over PROTOCOL.md): every non-ephemeral bot reply tied to an invocation stores an interaction object (not only command invocations), so the frontend can clear the bot.thinking placeholder for mention/dm replies too. For mention/dm, interaction.command is null. This is a superset of the spec's requirement and was recorded in PROTOCOL.md.

Metadata

Release files for abstract-chatshare 0.0.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for abstract-chatshare 0.0.7
File Size Uploaded
abstract_chatshare-0.0.7.tar.gz 74.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for abstract-chatshare 0.0.7
File Interpreter ABI Platform
abstract_chatshare-0.0.7-py3-none-any.whl Python 3 none any Details

Total release size: 136.4 kB

Release files / abstract_chatshare-0.0.7.tar.gz

Download URL abstract_chatshare-0.0.7.tar.gz
Size 74.1 kB
Tags Source
SHA-256 checksum
How to use checksums
bef08dfb9cfd62047753c7b688401c81c0054975def003c931fa2425edb5c8d3
BLAKE2b-256 checksum
How to use checksums
08ec5c5b54b6f48560ed9b8b8a088c7fb9f3b75ba32c15bd50658390d9066e51
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release files / abstract_chatshare-0.0.7-py3-none-any.whl

Download URL abstract_chatshare-0.0.7-py3-none-any.whl
Size 62.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
848fee2d9e8394248f90d22946fec3028f638a4bc24eae3f7d1764bfdc6663ae
BLAKE2b-256 checksum
How to use checksums
6fd52bd91e02b1d8ba0fea811654c88860ba84abba636ff07bdb4860cc209f47
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

0.0.7 This release

2 release files

0.0.6

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page