refactor(trust): ego-centric trust replaces the global Duniter membership

The global membership rule (curated bootstrap referents + sigQty/stepMax
parameters) solved sybil-proof identity for a UBI — a problem this app
doesn't have — and its screen leaked graph jargon (npub roots, parameter
steppers). Trust is now computed from the user's own position only:
you vouch / vouched by people you know (distance <=2) / vouched by N.

- TrustCubit: drop networkMember tier, referents and params; keep the
  circle rule and the 365-day vouch expiry (renewable, self-pruning).
- Delete TrustReferents, WotSettings, TrustNetworkScreen and the bundled
  referents asset; unwire injector/bootstrap/app/chat.
- New 'Your people' screen (/your-people, from the profile): who you
  vouch for (revocable) and who vouches for you, names via ProfileCache.
- i18n: wot.* removed, yourPeople.* added (en/es/pt/ast); trust.member
  removed. Kind 30777 events on relays stay fully compatible — only the
  interpretation changes.
This commit is contained in:
vjrj 2026-07-11 13:03:20 +02:00
parent 4af90876f4
commit dc7b2eee27
25 changed files with 595 additions and 863 deletions

View file

@ -2,32 +2,28 @@ import 'package:commons_core/commons_core.dart';
import 'package:equatable/equatable.dart';
import 'package:flutter_bloc/flutter_bloc.dart';
/// Where a peer stands, from strongest to weakest signal.
/// Where a peer stands, from strongest to weakest signal. Trust is
/// ego-centric: computed from YOUR position in the public vouch graph,
/// never from a global membership verdict.
enum TrustTier {
/// Passes the full Duniter membership rule (sigQty certifications from members,
/// within stepMax of a bootstrap referent).
networkMember,
/// In your personal circle (you vouch, or a friend-of-a-friend does).
inYourCircle,
/// Vouched for by someone, but not (yet) a member nor in your circle.
/// Vouched for by someone, but not (yet) in your circle.
vouched,
/// No certifications seen.
unknown,
}
/// Trust standing of one peer: the full Duniter membership verdict, your own
/// circle, and the raw certifier count computed from the public certification
/// graph with the active [WotParams] and bootstrap referents.
/// Trust standing of one peer, seen from this user's position: your own
/// vouch, your circle (friend-of-a-friend), and the raw certifier count
/// computed from the public certification graph.
class TrustState extends Equatable {
const TrustState({
this.certifierCount = 0,
this.iVouch = false,
this.knownToYou = false,
this.isNetworkMember = false,
this.networkBootstrapped = false,
this.loading = true,
this.busy = false,
});
@ -42,21 +38,11 @@ class TrustState extends Equatable {
/// friend-of-a-friend, vouch). Spam-resistant and works from day one.
final bool knownToYou;
/// Whether the peer is a full member per the Duniter rule (sigQty + stepMax
/// from the bootstrap referents).
final bool isNetworkMember;
/// Whether any bootstrap referents exist at all. When false, network
/// membership can't be determined yet (the trust net isn't seeded) and the UI
/// should say so instead of implying the peer failed the rule.
final bool networkBootstrapped;
final bool loading;
final bool busy;
/// The strongest applicable signal, for the badge.
TrustTier get tier {
if (isNetworkMember) return TrustTier.networkMember;
if (knownToYou) return TrustTier.inYourCircle;
if (certifierCount > 0) return TrustTier.vouched;
return TrustTier.unknown;
@ -66,8 +52,6 @@ class TrustState extends Equatable {
int? certifierCount,
bool? iVouch,
bool? knownToYou,
bool? isNetworkMember,
bool? networkBootstrapped,
bool? loading,
bool? busy,
}) =>
@ -75,8 +59,6 @@ class TrustState extends Equatable {
certifierCount: certifierCount ?? this.certifierCount,
iVouch: iVouch ?? this.iVouch,
knownToYou: knownToYou ?? this.knownToYou,
isNetworkMember: isNetworkMember ?? this.isNetworkMember,
networkBootstrapped: networkBootstrapped ?? this.networkBootstrapped,
loading: loading ?? this.loading,
busy: busy ?? this.busy,
);
@ -86,23 +68,19 @@ class TrustState extends Equatable {
certifierCount,
iVouch,
knownToYou,
isNetworkMember,
networkBootstrapped,
loading,
busy,
];
}
/// Reads and toggles this user's vouch for [peerPubkey] over a [TrustTransport],
/// and computes the full Duniter membership verdict against the bootstrap
/// [referents] and active [params].
/// Reads and toggles this user's vouch for [peerPubkey] over a
/// [TrustTransport], and computes the peer's standing from this user's own
/// position in the vouch graph (ego-centric no referents, no parameters).
class TrustCubit extends Cubit<TrustState> {
TrustCubit(
this._transport, {
required this.peerPubkey,
required this.selfPubkey,
this.referents = const {},
this.params = WotParams.duniter,
Future<void> Function()? onDispose,
}) : _onDispose = onDispose,
super(const TrustState());
@ -110,26 +88,20 @@ class TrustCubit extends Cubit<TrustState> {
final TrustTransport? _transport;
final String peerPubkey;
final String selfPubkey;
/// Bootstrap referents (Duniter seeds) the membership rule trusts by
/// construction. Empty = the network isn't seeded yet.
final Set<String> referents;
/// Active web-of-trust parameters (sigQty / stepMax / validity).
final WotParams params;
final Future<void> Function()? _onDispose;
bool get isOnline => _transport != null;
/// Personal "circle" rule: one vouch from your side, out to a friend-of-a-
/// friend. Loose by design "people near you", separate from formal
/// membership.
/// friend. Loose by design "people near you".
static const _circleThreshold = 1;
static const _circleDistance = 2;
/// Vouches expire and must be renewed, so stale trust prunes itself.
static const _vouchValidity = Duration(days: 365);
/// Loads the certification graph and computes: the peer's certifier count,
/// whether you vouch, whether they're in your circle, and whether they pass
/// the full Duniter membership rule against the bootstrap referents.
/// whether you vouch, and whether they're in your circle.
Future<void> load() async {
final transport = _transport;
if (transport == null) {
@ -147,23 +119,17 @@ class TrustCubit extends Cubit<TrustState> {
threshold: _circleThreshold,
maxDistance: _circleDistance,
);
// Full membership: only meaningful once the trust net has referents.
final members = referents.isEmpty
? const <String>{}
: wot.membersWith(seeds: referents, params: params);
emit(state.copyWith(
certifierCount: certifiers.length,
iVouch: certifiers.contains(selfPubkey),
knownToYou: circle.contains(peerPubkey),
isNetworkMember: members.contains(peerPubkey),
networkBootstrapped: referents.isNotEmpty,
loading: false,
));
}
/// Adds or removes this user's vouch, then reloads. Never vouches for self.
/// The certification is issued with the active validity so it expires and
/// must be renewed (Duniter rule).
/// The certification is issued with a validity so it expires and must be
/// renewed.
Future<void> toggleVouch() async {
final transport = _transport;
if (transport == null || peerPubkey == selfPubkey) return;
@ -173,7 +139,7 @@ class TrustCubit extends Cubit<TrustState> {
} else {
await transport.certify(
subjectPubkey: peerPubkey,
validity: params.sigValidity,
validity: _vouchValidity,
);
}
await load();