Carry the sender's compose time as an optional "ts" (Unix seconds) in the plaintext header JSON that rides outside the AEAD, and prefer it as the displayed message time so both ends show the same send time regardless of when the tx confirms. Parse "ts" leniently. On ingest, clamp: reject a "ts" implausibly in the future vs the receive/block time (1h skew tolerated) so a wrong/ahead peer clock can't pin messages to the bottom of a thread; a past compose time is fine (the note buffer may broadcast a queued message later, and a confirmed tx's block time is always >= compose time). Tests cover the round-trip and the future-clock clamp. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
282 KiB
282 KiB