Handle relay URLs safely in SignerProvider for NIP-42 permissions

- Sanitize `relayUrl` by attempting to extract the host using `java.net.URI` before querying the database for NIP-42 (kind 22242) permissions.
- Fall back to the original URL string if URI parsing fails or if the host is null.
This commit is contained in:
greenart7c3
2026-03-09 15:32:24 -03:00
parent e0d175cb80
commit 3c53ed3808
@@ -178,7 +178,13 @@ class SignerProvider : ContentProvider() {
val historyDatabase = Amber.instance.getHistoryDatabase(account.npub)
var permission = if (event.kind == 22242) {
// Kind 22242 = relay client auth (NIP-42): check relay-specific permission first
val relayUrl = AmberEvent.relay(event) ?: ""
val relayUrl = AmberEvent.relay(event)?.let { url ->
try {
java.net.URI(url).host ?: url
} catch (e: Exception) {
url
}
} ?: ""
database.dao().getPermissionForRelay(packageName, "SIGN_EVENT", 22242, relayUrl)
?: database.dao().getWildcardRelayPermission(packageName, "SIGN_EVENT", 22242)
} else {