docs(changelog): correct claims the code does not support

An audit of the v1.13.0 notes against the implementation found several
claims that are wrong or overstated. These are user-facing release notes,
so a false claim changes what people believe about their own security.

Corrected:

- **Privacy Lock.** The notes said it gates Messages "behind a password or
  biometric" on "Android and Desktop", with inactivity auto-lock and
  optional preview redaction. It does not exist on Android at all — no
  code, no settings entry — and there is no biometric implementation on
  any platform (`CredentialPrompter` has no implementations). Preview
  redaction persists a setting nothing reads, and the auto-lock is a fixed
  timer, since the idle-reset modifier is never applied. It is also a
  screen gate rather than encryption at rest: the account stays live and
  messages keep syncing while locked. Now described as what ships — a
  password gate on the Desktop Messages and Wallet columns.
- **"Every signature, payment, or data read needs your explicit
  approval."** Only payments require per-use consent; everything else can
  be granted once and reused, and the default trust level auto-signs notes,
  reactions and encryption after a single tap.
- **Web of Trust (GrapeRank)** was listed under app features, but crawling
  and scoring exist only in the `amy` CLI — no app module references it.
  The app consumes NIP-85 cards published by an operator, which is what the
  entry now says.
- **"One-tap trust for your follows' relays"** described bulk-granting
  relays used by people you follow. What exists is category rules evaluated
  per challenge.
- **Pinned web apps "show the app's own icon"** — they render a generic
  placeholder.
- **PoW** contradicted itself: "all cores" in one entry, "half the device's
  cores" in another. The latter matches `PoWPolicy.minerWorkers`.
- **Onion-Location "through every HTTP client"** — the Android app's
  clients only; the desktop, CLI, geode and sandbox blob clients don't
  install it.
- **Relay hardening** claimed REQ refusals stop immediately and failures
  evict "on the first strike"; both take repeated failures, and the
  first-strike eviction applies only to crawls.
- **`bunker://` links cannot be pasted in** — Amethyst only emits them.
- **Git code browser** needs a repository with an http(s) clone URL.
- **Geohash anonymous identity** — the per-area identity is unlinkable, but
  the optional nickname is one global handle, so setting it links your
  posts across areas.
- **Concord ban** is read-time enforcement for everyone else; the banned
  member keeps the keys until a Refounding.

Adds an Upgrading section for the user-visible effects of the per-account
isolation work: sites signed out once, permissions re-asked per account,
and relay logins now prompting under the default remote-signer policy.

Contributor and translator credits are left as they are — several entries
are unresolved npubs and Crowdin-generated usernames, but correcting
attribution is not a call to make from the code.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Vitor Pamplona
2026-07-19 19:52:52 -04:00
co-authored by Claude Opus 4.8
parent 2ccd837f30
commit 996b800da5
+50 -33
View File
@@ -4,9 +4,10 @@ Highlights:
- Adds an **in-app Browser for Nostr web clients**, with support for **Nostr Web
Apps (NIP-5D napplets)** and **static websites (NIP-5A nSites)**. They run in a
keyless sandbox that can never touch your private key — every signature,
payment, or data read needs your explicit approval. "Log in with Amethyst"
lets Nostr web apps sign in as you.
keyless sandbox that can never touch your private key. Payments always prompt
with the amount shown; signing and data access are permission-gated, with the
scope you choose when you connect. "Log in with Amethyst" lets Nostr web apps
sign in as you.
- Adds **Communities (Concord)**: a new end-to-end-encrypted communities
protocol with channels, invites, roles, moderation, and full history —
browsable and chattable from Messages.
@@ -16,10 +17,11 @@ Highlights:
- Adds a **Remote Signer (NIP-46)**: for the first time, other apps and websites
can sign through Amethyst — with informed, per-account consent — whether your
key lives in Amethyst or on an external signer like Amber. Also adds a
**Privacy Lock** that gates your Messages behind a password or biometric.
**Privacy Lock** on Desktop that gates the Messages and Wallet columns behind
a password.
- Adds **relay login permissions (NIP-42)**: when a relay asks you to
authenticate, choose Once / Always / Never per relay, with one-tap trust for
your follows' relays.
authenticate, choose Once / Always / Never per relay, with one-tap rules to
trust relays used by people you follow.
- Adds **NIP-29 Groups**: relay-hosted group chat with subgroups, custom roles,
invite links, threads, and pinned messages.
- Redesigns the **Messages inbox**: groups community and group channels with
@@ -34,6 +36,20 @@ Highlights:
options that flow through buttons, badges, and highlights.
- Adds **proof-of-work (NIP-13)** publishing and **negentropy (NIP-77)** sync.
## Upgrading
- Web apps, napplets and nSites now get **separate storage per account** —
cookies, logins and site data no longer leak between the accounts on your
device. Existing sites are signed out once as a result; signing back in stores
the session under the account you are using, and switching away and back keeps
it.
- Permissions you granted to web apps are likewise **per account** now, so each
app asks once more under each account you use it with. A permission granted by
one account no longer applies to the others.
- Apps connected through the remote signer (NIP-46) now **ask before signing a
relay login** (NIP-42) instead of approving it automatically under the
"Let's be reasonable" trust level.
## New Features
### Web Apps, Sites & the Browser
@@ -43,8 +59,8 @@ Highlights:
cannot reach your private key, storage, or data.
- Adds an in-app Browser — a drawer entry and pinnable bottom-bar tab — with an
omnibox address bar, autocomplete, history, favorites, recents, and captured
favicons. The trusted app draws the address bar so a page can never spoof its
URL.
favicons. The address bar is drawn by Amethyst, never by the page, so its URL
cannot be spoofed.
- Adds "Log in with Amethyst": nSites open with a NIP-07 `window.nostr`
provider, so standard Nostr web apps can sign in and request signatures as your
active account — consent-gated, sign-only, and scoped per site.
@@ -53,7 +69,7 @@ Highlights:
badges) — every capability brokered and permission-gated (once / this session /
always).
- Pins favorite web apps to the bottom bar as embedded, swap-in-place tabs that
stay warm and show the app's own icon.
stay warm between visits.
- Discovers web apps: the empty browser suggests a curated list plus nSites and
napplets published by people you follow, and profiles gain an "Apps & Sites"
tab.
@@ -79,7 +95,9 @@ Highlights:
- Groups channels by community in Messages with last-message, unread counts,
facepiles, and live typing.
- Adds moderation: ban/unban with read-time enforcement, role grants, a "Make
admin" toggle, and a full member roster.
admin" toggle, and a full member roster. A ban hides a member's posts for
everyone else; removing their access to the community's keys takes a
Refounding.
- Backfills channel history across epochs, paging back to the true start of a
channel.
- Surfaces Concord replies and reactions on the Notifications tab with a
@@ -92,7 +110,8 @@ Highlights:
- Reads code with branch/tag switching, file search, image preview, commit
history, syntax highlighting, and word-level diff highlighting.
- Reviews patches and pull requests with computed diffs and status actions; PR
updates surface on the repo screen.
updates surface on the repo screen. The code browser needs a repository with an
http(s) clone URL.
- Manages issues: Issues and Patches & PRs tabs split by open/closed, issue
labels with filtering, and a full-screen New Issue composer.
- Edits a repository announcement from the repo screen, bookmarks repositories,
@@ -104,8 +123,9 @@ Highlights:
- Adds Location Channels: geohash-based public rooms that interoperate with
BitChat, browsable from a dedicated drawer list and pinnable to the bottom nav.
- Posts under an unlinkable per-area anonymous identity (with an optional
nickname that survives restarts), or opt in to post as your real account.
- Posts under an unlinkable per-area anonymous identity, or opt in to post as
your real account. An optional nickname survives restarts, but it is a single
handle reused in every area — setting one links your posts across areas.
- Teleports to any place from a map picker or the feed-filter dialog to read and
post to distant rooms, and follows a teleported place to keep its feed.
- Reacts, zaps, and replies on location messages, with a "live near you" bubble
@@ -126,37 +146,34 @@ Highlights:
### Remote Signer & Security
- Lets other apps and websites sign through Amethyst for the first time
(NIP-46): connect by scanning or pasting a `nostrconnect://` code or a
`bunker://` link, and keep signing in the background — whether your key is
stored directly in Amethyst or delegated to an external signer like Amber
(NIP-55).
(NIP-46): connect by scanning or pasting a `nostrconnect://` code, and keep
signing in the background — whether your key is stored directly in Amethyst or
delegated to an external signer like Amber (NIP-55).
- Asks for informed consent before authorizing an app — showing its name and
icon, which account will sign, the exact permissions, and an event preview —
with per-account sheets and one-tap batched approval.
- Manages connected apps from a dedicated screen with per-app relay list, live
health, time-bound grants, and instant "forget this app".
- Adds a Privacy Lock for Messages (Android and Desktop): gate your DMs behind a
password or biometric, with an inactivity auto-lock and optional preview
redaction.
- Adds a Privacy Lock on Desktop: gate the Messages and Wallet columns behind a
password, with an auto-lock timeout. It is a screen gate, not encryption at
rest — messages continue to sync while it is locked.
- Adds interactive relay login prompts (NIP-42): choose Once / Always / Never
per relay, with venue-aware prompts for public chats, communities, and live
streams, and one-tap trust for your follows' relays.
streams, and one-tap rules to trust relays used by people you follow.
### Web of Trust (GrapeRank)
- Computes GrapeRank Web-of-Trust scores by crawling the social graph and scoring
every user — now even without a personal account (operator-less mode).
- Crawls followers in reverse (who follows a user) alongside follows-of-follows,
and tracks hop distance and follower count on trust cards.
- Discovers score providers via NIP-85 and fetches follow/profile data through
each author's own outbox relays for fuller coverage.
- Discovers Web-of-Trust score providers via NIP-85 and shows hop distance and
follower count on trust cards. Computing the scores — crawling the social graph,
reverse-follower crawling, and publishing NIP-85 cards — is done by the `amy`
command-line tool, not the app; see the Cli section.
### Publishing & Sync
- Adds proof-of-work (NIP-13) publishing: a fire-and-forget mining queue with
per-account difficulty and per-category settings, scheduled-post mining, and
per-post overrides, shielded by a foreground service and mined across all
cores.
per-post overrides, shielded by a foreground service and mined across half the
device's cores.
- Adds NIP-77 negentropy sync as a first-class capability, with deletion
(NIP-09/62) propagation so scoped syncs no longer strand deletions.
- Shows PoW mining progress, and surfaces PoW, OpenTimestamps, and location
@@ -232,8 +249,8 @@ Highlights:
- Adds an HTTP/2 keepalive ping to stop stale-connection image stalls, and trims
the image cache and player warm pool under memory pressure.
- Hardens the relay client: enforces blocked relays on every REQ/COUNT/publish,
stops re-sending REQs relays refuse, evicts failures on the first strike, and
fixes reconnect backoff on network/transport changes.
backs off from REQs relays repeatedly refuse, drops relays that fail hard
during crawls, and fixes reconnect backoff on network/transport changes.
- Fixes nutzap relay routing to receive/advertise on inbox/DM (kind 10019)
relays instead of outbox.
- Fixes Concord invite handling (revocation, keyless CORD-05, clearer failure
@@ -248,8 +265,8 @@ Highlights:
main thread.
- Serializes account construction so concurrent loaders can't build duplicate
accounts.
- Routes Onion-Location through every HTTP client and maps Tor/Arti errors to
accurate SOCKS reply codes.
- Routes Onion-Location through the Android app's HTTP clients and maps Tor/Arti
errors to accurate SOCKS reply codes.
- Extracts the rich-text renderer and many event cards (calendar/RSVP, podcast
atoms/splits, relay discovery, code snippet, ecash mint, activity, Git
diff/status, and more) into shared commons so Desktop and Android render