mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-06 03:18:23 +00:00
Force always-ask for null-package (browser) callers
Browser deep-links (nostrsigner://) arrive with no calling package, so every web caller collapses into the single shared "null" key. Honoring a remembered grant stored under that key meant a grant given to one website would auto-approve requests from any other website. Never load (and thus never honor) the shared "null" application entity in IntentSingleEventHomeScreen: with no applicationEntity, every isRemembered check returns null (always-ask) and the signPolicy==2 auto-accept shortcut no longer fires for null-package callers. Persistence was already guarded (sendResult only persists when packageName != null; sendRejection short-circuits on key == "null"; the multi-event screen returns early on a null package), so no remembered grant is created for null callers either. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gac3VnX6fhYhSjQD6XiHdu
This commit is contained in:
+6
@@ -63,6 +63,12 @@ fun IntentSingleEventHomeScreen(
|
||||
val key = "$packageName"
|
||||
|
||||
LaunchedEffect(Unit) {
|
||||
// Browser deep-links (nostrsigner://) arrive with no calling package, so
|
||||
// every web caller would otherwise share the single "null" key. Honoring a
|
||||
// remembered grant for that shared identity would let a grant given to one
|
||||
// website auto-approve any other website. Never load (and thus never honor)
|
||||
// the shared "null" application: force always-ask for null-package callers.
|
||||
if (packageName == null) return@LaunchedEffect
|
||||
launch(Dispatchers.IO) {
|
||||
applicationEntity = Amber.instance.getDatabase(account.npub).dao().getByKey(key)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user