From 08bd5d9b4a33b43037703fb90a90a521f78d5ff6 Mon Sep 17 00:00:00 2001 From: Vitor Pamplona Date: Mon, 20 Jul 2026 09:28:34 -0400 Subject: [PATCH] fix(napplet): tightening an app's trust level drops its live grants MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Changing an app to PARANOID did not stop it signing. `sessionAllows` is consulted BEFORE `signerLedger.decide()`, so a live "allow for this session" grant short-circuits exactly the check the stricter policy would have failed. The user picks "I'm a bit paranoid", the UI updates, and the app carries on signing on the strength of a grant made under the old policy — until every applet surface closes. The trust level is a decision about how an app is treated from now on, so the policy change now drops what that app is currently holding, the same way revoking and forgetting already do. It fires on any change rather than only on tightening: loosening is the user's call too, and a stale grant surviving a deliberate re-decision is surprising in either direction. Completes the revocation work — the three paths that change what an app may do (forget, per-op revoke, trust level) now all clear its live session grants. Not automatically tested: this is a Compose click handler and `amethyst` has no Robolectric. The underlying `revokeSessionGrants` is covered by `revokingAnAppDropsItsLiveSessionSignerGrants`, which was verified to fail before its namespacing fix. Co-Authored-By: Claude Opus 4.8 --- .../loggedIn/napplets/ConnectedAppDetailScreen.kt | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/napplets/ConnectedAppDetailScreen.kt b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/napplets/ConnectedAppDetailScreen.kt index b60173b5f5..fcc64c3386 100644 --- a/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/napplets/ConnectedAppDetailScreen.kt +++ b/amethyst/src/main/java/com/vitorpamplona/amethyst/ui/screen/loggedIn/napplets/ConnectedAppDetailScreen.kt @@ -221,7 +221,15 @@ fun ConnectedAppDetailScreen( PolicyPicker( selected = current.signerPolicy, onSelect = { newPolicy -> - mutate { signerLedger.setPolicy(coordinate, newPolicy) } + mutate { + signerLedger.setPolicy(coordinate, newPolicy) + // Live session grants are consulted BEFORE the policy, so tightening an app + // to PARANOID would not have stopped it signing — the grant it already holds + // short-circuits the check the new policy would fail. Changing the trust + // level is a decision about how this app is treated from now on, so drop + // what it is holding and let the new policy actually apply. + NappletBrokerService.revokeSessionGrants(coordinate) + } }, ) }