From b43cbfe57edd28b97c17b3087899fafcf0a96697 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 19 Jun 2026 09:41:21 +0000 Subject: [PATCH] Force always-ask for null-package (browser) callers Browser deep-links (nostrsigner://) arrive with no calling package, so every web caller collapses into the single shared "null" key. Honoring a remembered grant stored under that key meant a grant given to one website would auto-approve requests from any other website. Never load (and thus never honor) the shared "null" application entity in IntentSingleEventHomeScreen: with no applicationEntity, every isRemembered check returns null (always-ask) and the signPolicy==2 auto-accept shortcut no longer fires for null-package callers. Persistence was already guarded (sendResult only persists when packageName != null; sendRejection short-circuits on key == "null"; the multi-event screen returns early on a null package), so no remembered grant is created for null callers either. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01Gac3VnX6fhYhSjQD6XiHdu --- .../ui/components/IntentSingleEventHomeScreen.kt | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/app/src/main/java/com/greenart7c3/nostrsigner/ui/components/IntentSingleEventHomeScreen.kt b/app/src/main/java/com/greenart7c3/nostrsigner/ui/components/IntentSingleEventHomeScreen.kt index 53a214db..49a991f2 100644 --- a/app/src/main/java/com/greenart7c3/nostrsigner/ui/components/IntentSingleEventHomeScreen.kt +++ b/app/src/main/java/com/greenart7c3/nostrsigner/ui/components/IntentSingleEventHomeScreen.kt @@ -63,6 +63,12 @@ fun IntentSingleEventHomeScreen( val key = "$packageName" LaunchedEffect(Unit) { + // Browser deep-links (nostrsigner://) arrive with no calling package, so + // every web caller would otherwise share the single "null" key. Honoring a + // remembered grant for that shared identity would let a grant given to one + // website auto-approve any other website. Never load (and thus never honor) + // the shared "null" application: force always-ask for null-package callers. + if (packageName == null) return@LaunchedEffect launch(Dispatchers.IO) { applicationEntity = Amber.instance.getDatabase(account.npub).dao().getByKey(key) }