mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-06 11:28:22 +00:00
Handle relay URLs safely in SignerProvider for NIP-42 permissions
- Sanitize `relayUrl` by attempting to extract the host using `java.net.URI` before querying the database for NIP-42 (kind 22242) permissions. - Fall back to the original URL string if URI parsing fails or if the host is null.
This commit is contained in:
@@ -178,7 +178,13 @@ class SignerProvider : ContentProvider() {
|
||||
val historyDatabase = Amber.instance.getHistoryDatabase(account.npub)
|
||||
var permission = if (event.kind == 22242) {
|
||||
// Kind 22242 = relay client auth (NIP-42): check relay-specific permission first
|
||||
val relayUrl = AmberEvent.relay(event) ?: ""
|
||||
val relayUrl = AmberEvent.relay(event)?.let { url ->
|
||||
try {
|
||||
java.net.URI(url).host ?: url
|
||||
} catch (e: Exception) {
|
||||
url
|
||||
}
|
||||
} ?: ""
|
||||
database.dao().getPermissionForRelay(packageName, "SIGN_EVENT", 22242, relayUrl)
|
||||
?: database.dao().getWildcardRelayPermission(packageName, "SIGN_EVENT", 22242)
|
||||
} else {
|
||||
|
||||
Reference in New Issue
Block a user