mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
docs(changelog): correct claims the code does not support
An audit of the v1.13.0 notes against the implementation found several claims that are wrong or overstated. These are user-facing release notes, so a false claim changes what people believe about their own security. Corrected: - **Privacy Lock.** The notes said it gates Messages "behind a password or biometric" on "Android and Desktop", with inactivity auto-lock and optional preview redaction. It does not exist on Android at all — no code, no settings entry — and there is no biometric implementation on any platform (`CredentialPrompter` has no implementations). Preview redaction persists a setting nothing reads, and the auto-lock is a fixed timer, since the idle-reset modifier is never applied. It is also a screen gate rather than encryption at rest: the account stays live and messages keep syncing while locked. Now described as what ships — a password gate on the Desktop Messages and Wallet columns. - **"Every signature, payment, or data read needs your explicit approval."** Only payments require per-use consent; everything else can be granted once and reused, and the default trust level auto-signs notes, reactions and encryption after a single tap. - **Web of Trust (GrapeRank)** was listed under app features, but crawling and scoring exist only in the `amy` CLI — no app module references it. The app consumes NIP-85 cards published by an operator, which is what the entry now says. - **"One-tap trust for your follows' relays"** described bulk-granting relays used by people you follow. What exists is category rules evaluated per challenge. - **Pinned web apps "show the app's own icon"** — they render a generic placeholder. - **PoW** contradicted itself: "all cores" in one entry, "half the device's cores" in another. The latter matches `PoWPolicy.minerWorkers`. - **Onion-Location "through every HTTP client"** — the Android app's clients only; the desktop, CLI, geode and sandbox blob clients don't install it. - **Relay hardening** claimed REQ refusals stop immediately and failures evict "on the first strike"; both take repeated failures, and the first-strike eviction applies only to crawls. - **`bunker://` links cannot be pasted in** — Amethyst only emits them. - **Git code browser** needs a repository with an http(s) clone URL. - **Geohash anonymous identity** — the per-area identity is unlinkable, but the optional nickname is one global handle, so setting it links your posts across areas. - **Concord ban** is read-time enforcement for everyone else; the banned member keeps the keys until a Refounding. Adds an Upgrading section for the user-visible effects of the per-account isolation work: sites signed out once, permissions re-asked per account, and relay logins now prompting under the default remote-signer policy. Contributor and translator credits are left as they are — several entries are unresolved npubs and Crowdin-generated usernames, but correcting attribution is not a call to make from the code. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
2ccd837f30
commit
996b800da5
+50
-33
@@ -4,9 +4,10 @@ Highlights:
|
||||
|
||||
- Adds an **in-app Browser for Nostr web clients**, with support for **Nostr Web
|
||||
Apps (NIP-5D napplets)** and **static websites (NIP-5A nSites)**. They run in a
|
||||
keyless sandbox that can never touch your private key — every signature,
|
||||
payment, or data read needs your explicit approval. "Log in with Amethyst"
|
||||
lets Nostr web apps sign in as you.
|
||||
keyless sandbox that can never touch your private key. Payments always prompt
|
||||
with the amount shown; signing and data access are permission-gated, with the
|
||||
scope you choose when you connect. "Log in with Amethyst" lets Nostr web apps
|
||||
sign in as you.
|
||||
- Adds **Communities (Concord)**: a new end-to-end-encrypted communities
|
||||
protocol with channels, invites, roles, moderation, and full history —
|
||||
browsable and chattable from Messages.
|
||||
@@ -16,10 +17,11 @@ Highlights:
|
||||
- Adds a **Remote Signer (NIP-46)**: for the first time, other apps and websites
|
||||
can sign through Amethyst — with informed, per-account consent — whether your
|
||||
key lives in Amethyst or on an external signer like Amber. Also adds a
|
||||
**Privacy Lock** that gates your Messages behind a password or biometric.
|
||||
**Privacy Lock** on Desktop that gates the Messages and Wallet columns behind
|
||||
a password.
|
||||
- Adds **relay login permissions (NIP-42)**: when a relay asks you to
|
||||
authenticate, choose Once / Always / Never per relay, with one-tap trust for
|
||||
your follows' relays.
|
||||
authenticate, choose Once / Always / Never per relay, with one-tap rules to
|
||||
trust relays used by people you follow.
|
||||
- Adds **NIP-29 Groups**: relay-hosted group chat with subgroups, custom roles,
|
||||
invite links, threads, and pinned messages.
|
||||
- Redesigns the **Messages inbox**: groups community and group channels with
|
||||
@@ -34,6 +36,20 @@ Highlights:
|
||||
options that flow through buttons, badges, and highlights.
|
||||
- Adds **proof-of-work (NIP-13)** publishing and **negentropy (NIP-77)** sync.
|
||||
|
||||
## Upgrading
|
||||
|
||||
- Web apps, napplets and nSites now get **separate storage per account** —
|
||||
cookies, logins and site data no longer leak between the accounts on your
|
||||
device. Existing sites are signed out once as a result; signing back in stores
|
||||
the session under the account you are using, and switching away and back keeps
|
||||
it.
|
||||
- Permissions you granted to web apps are likewise **per account** now, so each
|
||||
app asks once more under each account you use it with. A permission granted by
|
||||
one account no longer applies to the others.
|
||||
- Apps connected through the remote signer (NIP-46) now **ask before signing a
|
||||
relay login** (NIP-42) instead of approving it automatically under the
|
||||
"Let's be reasonable" trust level.
|
||||
|
||||
## New Features
|
||||
|
||||
### Web Apps, Sites & the Browser
|
||||
@@ -43,8 +59,8 @@ Highlights:
|
||||
cannot reach your private key, storage, or data.
|
||||
- Adds an in-app Browser — a drawer entry and pinnable bottom-bar tab — with an
|
||||
omnibox address bar, autocomplete, history, favorites, recents, and captured
|
||||
favicons. The trusted app draws the address bar so a page can never spoof its
|
||||
URL.
|
||||
favicons. The address bar is drawn by Amethyst, never by the page, so its URL
|
||||
cannot be spoofed.
|
||||
- Adds "Log in with Amethyst": nSites open with a NIP-07 `window.nostr`
|
||||
provider, so standard Nostr web apps can sign in and request signatures as your
|
||||
active account — consent-gated, sign-only, and scoped per site.
|
||||
@@ -53,7 +69,7 @@ Highlights:
|
||||
badges) — every capability brokered and permission-gated (once / this session /
|
||||
always).
|
||||
- Pins favorite web apps to the bottom bar as embedded, swap-in-place tabs that
|
||||
stay warm and show the app's own icon.
|
||||
stay warm between visits.
|
||||
- Discovers web apps: the empty browser suggests a curated list plus nSites and
|
||||
napplets published by people you follow, and profiles gain an "Apps & Sites"
|
||||
tab.
|
||||
@@ -79,7 +95,9 @@ Highlights:
|
||||
- Groups channels by community in Messages with last-message, unread counts,
|
||||
facepiles, and live typing.
|
||||
- Adds moderation: ban/unban with read-time enforcement, role grants, a "Make
|
||||
admin" toggle, and a full member roster.
|
||||
admin" toggle, and a full member roster. A ban hides a member's posts for
|
||||
everyone else; removing their access to the community's keys takes a
|
||||
Refounding.
|
||||
- Backfills channel history across epochs, paging back to the true start of a
|
||||
channel.
|
||||
- Surfaces Concord replies and reactions on the Notifications tab with a
|
||||
@@ -92,7 +110,8 @@ Highlights:
|
||||
- Reads code with branch/tag switching, file search, image preview, commit
|
||||
history, syntax highlighting, and word-level diff highlighting.
|
||||
- Reviews patches and pull requests with computed diffs and status actions; PR
|
||||
updates surface on the repo screen.
|
||||
updates surface on the repo screen. The code browser needs a repository with an
|
||||
http(s) clone URL.
|
||||
- Manages issues: Issues and Patches & PRs tabs split by open/closed, issue
|
||||
labels with filtering, and a full-screen New Issue composer.
|
||||
- Edits a repository announcement from the repo screen, bookmarks repositories,
|
||||
@@ -104,8 +123,9 @@ Highlights:
|
||||
|
||||
- Adds Location Channels: geohash-based public rooms that interoperate with
|
||||
BitChat, browsable from a dedicated drawer list and pinnable to the bottom nav.
|
||||
- Posts under an unlinkable per-area anonymous identity (with an optional
|
||||
nickname that survives restarts), or opt in to post as your real account.
|
||||
- Posts under an unlinkable per-area anonymous identity, or opt in to post as
|
||||
your real account. An optional nickname survives restarts, but it is a single
|
||||
handle reused in every area — setting one links your posts across areas.
|
||||
- Teleports to any place from a map picker or the feed-filter dialog to read and
|
||||
post to distant rooms, and follows a teleported place to keep its feed.
|
||||
- Reacts, zaps, and replies on location messages, with a "live near you" bubble
|
||||
@@ -126,37 +146,34 @@ Highlights:
|
||||
### Remote Signer & Security
|
||||
|
||||
- Lets other apps and websites sign through Amethyst for the first time
|
||||
(NIP-46): connect by scanning or pasting a `nostrconnect://` code or a
|
||||
`bunker://` link, and keep signing in the background — whether your key is
|
||||
stored directly in Amethyst or delegated to an external signer like Amber
|
||||
(NIP-55).
|
||||
(NIP-46): connect by scanning or pasting a `nostrconnect://` code, and keep
|
||||
signing in the background — whether your key is stored directly in Amethyst or
|
||||
delegated to an external signer like Amber (NIP-55).
|
||||
- Asks for informed consent before authorizing an app — showing its name and
|
||||
icon, which account will sign, the exact permissions, and an event preview —
|
||||
with per-account sheets and one-tap batched approval.
|
||||
- Manages connected apps from a dedicated screen with per-app relay list, live
|
||||
health, time-bound grants, and instant "forget this app".
|
||||
- Adds a Privacy Lock for Messages (Android and Desktop): gate your DMs behind a
|
||||
password or biometric, with an inactivity auto-lock and optional preview
|
||||
redaction.
|
||||
- Adds a Privacy Lock on Desktop: gate the Messages and Wallet columns behind a
|
||||
password, with an auto-lock timeout. It is a screen gate, not encryption at
|
||||
rest — messages continue to sync while it is locked.
|
||||
- Adds interactive relay login prompts (NIP-42): choose Once / Always / Never
|
||||
per relay, with venue-aware prompts for public chats, communities, and live
|
||||
streams, and one-tap trust for your follows' relays.
|
||||
streams, and one-tap rules to trust relays used by people you follow.
|
||||
|
||||
### Web of Trust (GrapeRank)
|
||||
|
||||
- Computes GrapeRank Web-of-Trust scores by crawling the social graph and scoring
|
||||
every user — now even without a personal account (operator-less mode).
|
||||
- Crawls followers in reverse (who follows a user) alongside follows-of-follows,
|
||||
and tracks hop distance and follower count on trust cards.
|
||||
- Discovers score providers via NIP-85 and fetches follow/profile data through
|
||||
each author's own outbox relays for fuller coverage.
|
||||
- Discovers Web-of-Trust score providers via NIP-85 and shows hop distance and
|
||||
follower count on trust cards. Computing the scores — crawling the social graph,
|
||||
reverse-follower crawling, and publishing NIP-85 cards — is done by the `amy`
|
||||
command-line tool, not the app; see the Cli section.
|
||||
|
||||
### Publishing & Sync
|
||||
|
||||
- Adds proof-of-work (NIP-13) publishing: a fire-and-forget mining queue with
|
||||
per-account difficulty and per-category settings, scheduled-post mining, and
|
||||
per-post overrides, shielded by a foreground service and mined across all
|
||||
cores.
|
||||
per-post overrides, shielded by a foreground service and mined across half the
|
||||
device's cores.
|
||||
- Adds NIP-77 negentropy sync as a first-class capability, with deletion
|
||||
(NIP-09/62) propagation so scoped syncs no longer strand deletions.
|
||||
- Shows PoW mining progress, and surfaces PoW, OpenTimestamps, and location
|
||||
@@ -232,8 +249,8 @@ Highlights:
|
||||
- Adds an HTTP/2 keepalive ping to stop stale-connection image stalls, and trims
|
||||
the image cache and player warm pool under memory pressure.
|
||||
- Hardens the relay client: enforces blocked relays on every REQ/COUNT/publish,
|
||||
stops re-sending REQs relays refuse, evicts failures on the first strike, and
|
||||
fixes reconnect backoff on network/transport changes.
|
||||
backs off from REQs relays repeatedly refuse, drops relays that fail hard
|
||||
during crawls, and fixes reconnect backoff on network/transport changes.
|
||||
- Fixes nutzap relay routing to receive/advertise on inbox/DM (kind 10019)
|
||||
relays instead of outbox.
|
||||
- Fixes Concord invite handling (revocation, keyless CORD-05, clearer failure
|
||||
@@ -248,8 +265,8 @@ Highlights:
|
||||
main thread.
|
||||
- Serializes account construction so concurrent loaders can't build duplicate
|
||||
accounts.
|
||||
- Routes Onion-Location through every HTTP client and maps Tor/Arti errors to
|
||||
accurate SOCKS reply codes.
|
||||
- Routes Onion-Location through the Android app's HTTP clients and maps Tor/Arti
|
||||
errors to accurate SOCKS reply codes.
|
||||
- Extracts the rich-text renderer and many event cards (calendar/RSVP, podcast
|
||||
atoms/splits, relay discovery, code snippet, ecash mint, activity, Git
|
||||
diff/status, and more) into shared commons so Desktop and Android render
|
||||
|
||||
Reference in New Issue
Block a user