From 0b146737764d14064f3eadc18c2f22b7b08cd0f9 Mon Sep 17 00:00:00 2001 From: greenart7c3 Date: Thu, 18 Dec 2025 08:14:07 -0300 Subject: [PATCH] Only accept bunker requests inside the content provider --- app/src/main/java/com/greenart7c3/nostrsigner/SignerProvider.kt | 1 + .../nostrsigner/service/EventNotificationConsumer.kt | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/app/src/main/java/com/greenart7c3/nostrsigner/SignerProvider.kt b/app/src/main/java/com/greenart7c3/nostrsigner/SignerProvider.kt index 910371f3..36e9648a 100644 --- a/app/src/main/java/com/greenart7c3/nostrsigner/SignerProvider.kt +++ b/app/src/main/java/com/greenart7c3/nostrsigner/SignerProvider.kt @@ -378,6 +378,7 @@ class SignerProvider : ContentProvider() { } "content://$appId.GET_PUBLIC_KEY" -> { + if (selection != "Amber") return null // only accept content provider when it's a bunker request val npub = if (projection != null && projection.isNotEmpty()) IntentUtils.parsePubKey(projection[0]) else null val account = if (npub != null) { LocalPreferences.loadFromEncryptedStorageSync(context!!, npub) diff --git a/app/src/main/java/com/greenart7c3/nostrsigner/service/EventNotificationConsumer.kt b/app/src/main/java/com/greenart7c3/nostrsigner/service/EventNotificationConsumer.kt index 3de5ead8..fd634c4c 100644 --- a/app/src/main/java/com/greenart7c3/nostrsigner/service/EventNotificationConsumer.kt +++ b/app/src/main/java/com/greenart7c3/nostrsigner/service/EventNotificationConsumer.kt @@ -302,7 +302,7 @@ class EventNotificationConsumer(private val applicationContext: Context) { applicationContext.contentResolver.query( "content://${BuildConfig.APPLICATION_ID}.$type".toUri(), projection, - null, + "Amber", null, event.pubKey, )