Files
Claude ad67564bbf fix: make the consent preview read-only, not just reaction-free
Audit follow-up. Dropping NoteCompose's reaction row left the content
renderers' own actions live inside the signer consent preview: poll votes,
calendar RSVPs, badge accepts, follow-set toggles, channel/community joins,
plus profile/link taps and the relay card's info link. A tap there would
sign a second event against one that may never exist.

- New commonsUI Modifier.blockInteractions(): consumes presses/releases in
  the Initial pointer pass (so no child click/long-click starts) and the
  activation keys (Enter/Space/D-pad center; Tab still leaves), while
  leaving movement alone so a drag on the preview still scrolls the dialog.
  Covered by a desktop Compose UI test with no-modifier controls.
- With taps blocked, "Show more" could no longer be reached, so the
  preview seeds ShowFullTextCache: everything being signed is shown in
  full without a tap.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GSwjzewTFcwzqAKVJ1WJ9B
2026-10-02 20:29:35 +00:00
..