Move the runtime knobs that previously only lived in the dsh profile patch
(listen host/port, workspace, requireToken, timeouts, answer cap, roster
refresh, allow-execution, provider/model overrides) into the plugin settings
file, editable from the Ask Peer settings page. The profile keeps only the
bootstrap (callerName, keyDir, listen) and the settings file wins for
everything else; most knobs hot-apply, host/port after restart.
Add signed friend cards: one dsh-ask-peer-card: blob carrying name, host,
port, public sign, description and tags, signed by the issuing identity.
The settings page shows your card and 'Add friend from a card' verifies a
pasted card against the key embedded in it, then pre-fills the friend form
so adding a friend is a single copy-paste instead of copying four fields.
Signed, not encrypted: the embedded key is public, and a signature is what
proves the contact info came from the matching private key holder. New
endpoints GET /sign/card and POST /sign/verify; smoke test covers the local
settings round-trip, valid-card verify, and tampered-card rejection.
Session titles are fixed at creation and never track context growth.
Derive the advertisement from the conversation itself:
- topic: latest genuine user message (skips dsh-system-prompt snapshots),
shown as "working on: ..." in the roster and peers_list
- topics: recency-weighted keywords from the last few messages
peers_list output and schema gain per-session topic/topics, and the real
three-agent choice test now asserts on live topics and a docker-flavored
answer from ada.