Files
Claude c37f5291e8 Store encrypt/decrypt payloads as ciphertext, decrypt on demand
History/activity rows previously persisted the plaintext of every
NIP-04/NIP-44(/v3) encrypt and decrypt operation (encrypt = plaintext
input, decrypt = plaintext output) and the decrypted private zap. That
left sensitive cleartext at rest in history_db_$npub.

Now the encrypted form is stored instead and the plaintext is recovered
on demand only when the activity/history screen renders a row:

- Encrypt requests store their ciphertext output; decrypt requests store
  the ciphertext input that arrived in the request. Rejected encrypts
  store nothing (no ciphertext exists, so no plaintext is leaked).
- HistoryEntity gains encryptionPubKey + encryptionScope; the existing
  kind column carries the NIP-44 v3 kind. ActivityRow decrypts via
  account.decrypt / nip44v3Decrypt / decryptZapEvent, falling back to the
  stored value for pre-migration rows or missing context.
- Ciphertext rows are exempted from content truncation so they remain
  decryptable.

Covers all three ingestion paths (ContentProvider/relay via
SignerProviderQuery, nostrsigner:// intents, NIP-46 bunker approvals) and
both accept and reject flows. Adds HistoryDatabase migration 3->4.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WABMihCLr9XN51uLWj93oX
2026-06-19 10:21:23 +00:00
..
2025-12-10 09:37:25 -03:00
2025-12-10 09:37:25 -03:00