The post, word for word, and who it came from
She repeats a broadcast post into a group and labels it. She does not summarise it, and no model sees it.
What the group sees
The post text arrives verbatim, and under it the application writes the attribution. She does not summarise, introduce or comment on a post, and there is no model anywhere on the path, so the only transformation is a trailing blank line trimmed.
An edit at the source updates her message in place; a deletion at the source removes her copy for everyone. Members have no commands here at all, because the bridge is not something a member asks for.
📣 From the channel {channel}, {when}
📣 Also new in {channel}: {n} earlier posts.
nothing for a hostile channel post to instruct
A bridge is only as private as the far side
The sentence that belongs next to this feature rather than under it, and what the product actually does today.
The hop where it is lost
A bridge to a network without end-to-end encryption loses confidentiality at that hop. Whatever crosses is readable by that network's servers the moment it arrives, and no amount of care on this side changes it. That sentence belongs next to the feature rather than in a footnote, because somebody deciding whether to bridge needs it before they decide, not after.
What exists today crosses no such boundary: it is a broadcast channel to a chat group on the same network, one deployment, no model on the path. There is no bridge to another network in the product, and this page is not announcing one. Every way in, and what state it is in
Channel content is not end-to-end encrypted.
Extensible by shape, which is not the same claim
The planning half of the bridge, the cadence, the digest, the budgets and the suppression records, holds nothing network-specific and would carry over unchanged. The origin it records is versioned and carries a source field, which today holds one value. That makes it extensible by shape. It does not make this an extensible product, and the page will not imply one until something has actually been built on that seam.
Whichever comes first, and what a digest is for
A tick that books its successor before doing the work, so a failure cannot end the rhythm.
| Question | Answer |
|---|---|
| What triggers a post | Per mapping, every N minutes or every N member messages, whichever comes first, measured from the last send. How far back keeps stale posts from ever announcing, repeats per post limits how often one is said, and Dismiss stops a post at the next tick. A post retired with zero announcements always writes a suppression record |
| When a digest happens | Whenever more than one post is pending on a due tick: one message with the newest in full and up to 4 older as excerpts, oldest first so nothing starves, and everything beyond counted in the remainder line. Remainder posts spend no repeat and stay pending |
| The rhythm | A self-chaining queue job every 60 seconds with a minute-bucket key, so boot seeds collapse into the live chain; the successor is booked before the work, so a failing tick cannot kill the cadence |
| Publishable to the web, exactly | A row publishes on the per-channel switch alone, default OFF, derived on every read, so switching off unpublishes on the next request. Publishing unnamed strips the name from the column, the text, the search index and the attribution. Whether announcements also stand in the activity stream is a separate switch, and all of it is keyed on the link-derived channel key, so a rejoin cannot silently unpublish |
| Media | Re-hosted at intake because relays expire files after about 48 hours and a repeat can outlive that; plaintext, since it is the operator own public broadcast and encryption would buy nothing. Oversize forwards as text with the omission stated on the console |
| Reaches outside, and the model | The SimpleX network only. No model anywhere on the path: posts forward verbatim, and the only transformation is a trailing blank line trim |
Per channel, off by default, and named or not
Putting announcements on the public website is a separate decision, taken per channel and reversible on the next request.
Derived, so switching off is enough
Publishing an announcement to the public website is a separate switch per channel, off by default, and it is derived on every read rather than stamped onto a row. So switching it off unpublishes on the next request, with nothing to re-run.
Publishing a channel unnamed strips the name from the column, the text, the search index and the attribution, and the whole arrangement is keyed on a value derived from the channel link, so leaving and rejoining cannot silently unpublish.
(not named)
Everything succeeded, and an hour was lost
No exception, no failed job, no member affected. A list that was merely out of date, and somebody acting on it.
The channel list went on offering a channel whose group had just been cleared elsewhere in the console, so the operator picked a dead source for a mapping and waited an hour for posts that could never arrive. Nothing failed, which is what made it expensive.
The tick ran 1516 times and succeeded every time.
The standing rule it produced
This is the incident behind a standing rule: an action taken in one surface must reach every surface that shows it. A list that is merely out of date is not a cosmetic fault, because somebody will act on it.