fix(simplex): document contactId-only allowlist and warn on name entries

After #44729 SIMPLEX_ALLOWED_USERS matches only the numeric contactId, but
the docs still told operators display names work, and existing name
entries would silently stop matching. Update the docs and log a one-time
warning at first connect listing non-numeric entries that are now ignored.
This commit is contained in:
kshitijk4poor
2026-09-27 12:12:25 +05:30
committed by kshitij
parent 07c5310295
commit 1ec84a2dae
2 changed files with 8 additions and 4 deletions

View File

@@ -146,6 +146,10 @@ class SimplexAdapter(BasePlatformAdapter):
self._health_task = asyncio.create_task(self._health_monitor())
self._mark_connected()
logger.info("SimpleX: connected to %s", self.ws_url)
names = [u for u in os.getenv("SIMPLEX_ALLOWED_USERS", "").split(",") if u.strip() not in ("", "*") and not u.strip().isdigit()]
if names and not is_reconnect:
logger.warning("SimpleX: SIMPLEX_ALLOWED_USERS entries %s are not numeric contactIds and are ignored "
"(display names are not trusted; see /contacts for IDs)", names)
self._wire_plugin_handlers(None)
return True

View File

@@ -52,7 +52,7 @@ SIMPLEX_HOME_CHANNEL=<contact-id>
| Variable | Required | Description |
|---|---|---|
| `SIMPLEX_WS_URL` | Yes | WebSocket URL of the simplex-chat daemon |
| `SIMPLEX_ALLOWED_USERS` | Recommended | Comma-separated allowlist. Each entry can be a numeric `contactId` **or** a display name — both forms work. |
| `SIMPLEX_ALLOWED_USERS` | Recommended | Comma-separated allowlist of numeric `contactId`s. Display names are **not** accepted — any contact can change theirs. |
| `SIMPLEX_ALLOW_ALL_USERS` | Optional | Set `true` to allow every contact (use carefully) |
| `SIMPLEX_AUTO_ACCEPT` | Optional | Auto-accept incoming contact requests (default: `true`) |
| `SIMPLEX_GROUP_ALLOWED` | Optional | Comma-separated group IDs the bot participates in, or `*` for any group. Omit to ignore group messages entirely |
@@ -60,15 +60,15 @@ SIMPLEX_HOME_CHANNEL=<contact-id>
| `SIMPLEX_HOME_CHANNEL_NAME` | Optional | Human label for the home channel |
| `HERMES_SIMPLEX_TEXT_BATCH_DELAY` | Optional | Quiet-period seconds (default: `0.8`) used to concatenate rapid-fire inbound text messages into one event |
## Find your contact ID or display name
## Find your contact ID
After starting the daemon, open a conversation with your agent contact. The numeric `contactId` appears in session logs. If you'd rather use the display name shown in the SimpleX UI, that works too — `SIMPLEX_ALLOWED_USERS` accepts either form.
After starting the daemon, open a conversation with your agent contact. The numeric `contactId` appears in session logs (or run `/contacts` in the daemon). `SIMPLEX_ALLOWED_USERS` matches only this ID: display names are chosen by the contact and can collide, so they are ignored.
## Authorization
By default **all contacts are denied**. You must either:
1. Set `SIMPLEX_ALLOWED_USERS` to a comma-separated list of `contactId`s and/or display names (e.g. `SIMPLEX_ALLOWED_USERS=4,alice` matches either contactId 4 or the contact whose display name is "alice"), or
1. Set `SIMPLEX_ALLOWED_USERS` to a comma-separated list of numeric `contactId`s (e.g. `SIMPLEX_ALLOWED_USERS=4,9`), or
2. Use **DM pairing** — send any message to the bot and it will reply with a pairing code. Enter that code via `hermes pairing approve simplex <CODE>`.
## Group chats