mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-06 11:28:22 +00:00
The SignerProvider's authorities are enumerated explicitly in the manifest, and the new NIP44_V3_ENCRYPT / NIP44_V3_DECRYPT authorities were missing. As a result contentResolver.query() for a v3 URI resolved to no provider and returned null, which the bunker path treats as "needs approval" — so invalid v3 requests (e.g. a decrypt whose kind does not match the ciphertext) were surfaced to the user instead of being rejected, and valid v3 requests could never auto-accept from a remembered permission. Also validate v3 bunker requests at the relay entry point and reject malformed ones (missing kind, context mismatch, bad MAC/padding, non-base64 payload) with a generic error response before any approval screen is shown.