Files
Amber/app
greenart7c3 24a5e2071c Fix relay-auth whitelist authorizing any requester (GHSA-vx4h-56qj-wcp7)
The auth whitelist auto-accepted kind-22242 (NIP-42) signing for any
caller: whitelistAutoAccept bypassed the per-requester permission check
in the SignerProvider/NIP-46 query path, letting any installed app or
bunker client silently obtain relay-auth signatures for whitelisted
relays (confused deputy, CWE-863).

The whitelist is now only a relay constraint: non-whitelisted relays
still auto-reject, but membership no longer grants signing. Kind-22242
requests always require a requester-scoped SIGN_EVENT permission
(relay-specific or wildcard grant) or fall through to the user prompt,
matching the whitelist's documented behavior and the approval UIs.

Adds SignerProviderQueryTest covering: no silent signing without a
grant, silent signing with relay-scoped/wildcard grants, auto-reject of
non-whitelisted relays before any permission lookup, and unchanged
empty-whitelist behavior.
2026-08-10 08:48:50 -03:00
..
2024-03-01 06:56:32 -03:00
2023-07-26 16:44:33 -03:00
2026-08-07 07:02:35 -03:00