mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-05 19:08:23 +00:00
BunkerSigningEngine decrypts an incoming kind-24133 event, checks a BunkerPermissionStore for an auto-accept/reject rule (falling back to a BunkerApprovalPort prompt), performs the requested sign/nip04/nip44 operation, and returns the signed response event ready to publish. It's new code focused on the desktop bunker use case rather than a port of :app's BunkerRequestUtils/EventNotificationConsumer pipeline, which stays untouched and keeps using its existing Room/Context-coupled implementation directly — rewiring the shipping Android signing path onto shared code carries far more regression risk than the desktop use case needs. SecureCryptoHelper is expect/actual: the Android actual mirrors :app's existing Keystore-backed helper (unused by :app for now, kept in sync so :shared's Android target builds and is available for future adoption); the desktop actual stores an AES-256 master key in the OS keychain via java-keyring (Windows Credential Manager / macOS Keychain / Linux Secret Service) and uses it for AES-GCM at-rest encryption, mirroring the same key-wrapping shape Android uses.