block / block/buzz

Community permissions UI shows contradictory 'Send instructions' settings

Open
#4,156 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
32.7k
Forks
4.3k
Avg merge
1d 13h
Merged PRs (30d)
253

Description

**Describe the bug**

The community/channel permissions settings in Buzz Desktop present two controls governing who can send instructions to agents, and they can display contradictory values simultaneously. One control indicates *everyone* can send instructions, while another indicates *only the owner* can. This makes it impossible to know what the actual enforced policy is, which is a security-visibility issue: an owner cannot tell from the UI whether their agents are protected against arbitrary members issuing instructions.

**Steps to reproduce**

1. Open Buzz Desktop as a community owner.
2. Open the community/channel settings that govern permissions for sending instructions to agents.
3. Observe both settings shown in the attached screenshots — one is scoped to everyone, the other to owner-only.

**Expected behavior**

A single source of truth for who can send instructions. Either the two controls should be reconciled (one derives from the other, or they are merged), or the UI should surface the effective policy that will actually be enforced, so the owner is never left guessing.

**Version and platform**

- Buzz version: unknown (current Desktop as of 2026-08-01)
- OS: macOS

**Logs / additional context**

Screenshots from the reporting owner showing the conflicting settings side by side:

![settings-1](https://matrikel.communities.buzz.xyz/media/bdd8edf9f44a3c291e244ccc540385ad245d759d8cf529cb47d7cdbab1b3e1a7.png)

![settings-2](https://matrikel.communities.buzz.xyz/media/afae7907bd523165c03946d6bf8bf1198fadbf8b773fb15e0cc14455f1927ff1.png)

Also emailed to buzz@block.xyz on 2026-08-01 for tracking; filing here per your issue-report flow.

Contributor guide

Open the contributing guide

Research direction

Start from the community/channel permissions settings in Buzz Desktop and trace both controls for sending instructions to agents to the effective policy they display and enforce. Reproduce the contradictory owner/everyone state from the screenshots, then verify that the UI presents one consistent source of truth and clearly reflects the enforced policy.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, desktop
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.