mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 19:53:08 +00:00
A self-contained napplet (tools/napplet-test/index.html) that calls every window.napplet.* API and renders each result on screen, for verifying the NIP-5D host end to end on a real device — including the new identity.getList/getZaps/getBadges, identity.onChanged, keys.onAction, and resource.bytes nostr: paths. publish.sh uploads it to a Blossom server (BUD-02) and publishes the NIP-5D named-napplet event (kind 35129) via nak; README documents the flow and a per-feature verification checklist. Tooling only — no app code or deps. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016ncMHuBBVHEf7spAoSssde
Napplet test harness
A self-contained napplet for on-device verification of Amethyst's NIP-5D host — it calls every
window.napplet.* API and shows each result on screen, so you can confirm the whole
shim → shell → broker → consent round-trip (and the newer identity.getList/getZaps/getBadges,
identity.onChanged, keys.onAction, and resource.bytes nostr: paths) works on a real device.
Files
index.html— the napplet. Read-only checks run on load; publish/upload/pay are behind buttons; live pushes (identity.changed,keys.action) land in the top banner.publish.sh— uploadsindex.htmlto a Blossom server and publishes the napplet event.
Prerequisites
nak(signs + publishes the events),curl, andsha256sum(orshasum/openssl).- A Blossom server that accepts BUD-02 uploads (e.g.
https://blossom.primal.net,https://cdn.satellite.earth, or your own). - Your nsec — use the same key you're logged in as in Amethyst, so the napplet appears under
your account and the identity reads (
getProfile,getFollows, …) have data.
Publish
cd tools/napplet-test
./publish.sh --sec nsec1yourkey... --server https://blossom.primal.net \
--relay wss://relay.damus.io --relay wss://nos.lol
Then verify it resolves (optional):
amy napplet fetch <your-pubkey-hex> --d napplet-test
Open it in Amethyst
Build & install the debug app and watch the logs:
./gradlew :amethyst:installPlayDebug
adb logcat -s NappletHostActivity NappletBrokerService NappletContentServer
Logged in as the publishing key, find "Napplet Test Harness" in your Apps / Napplets list (or its
feed card) and tap Open. It launches in the sandboxed :napplet process.
What to verify
- On load: each read row turns green.
shell.supports(identity)= true,(bogus)= false. Every capability prompts for consent the first time. - identity.getList/getZaps/getBadges: open your own profile first so the cache has your lists / zaps / badges, then relaunch — the rows show your data (empty arrays are valid if you have none).
- identity.onChanged: with the napplet open, switch accounts (or log out) → the banner shows
identity.changed → <pubkey>. It must NOT fire on the initial load. - keys.onAction: with a hardware keyboard (or
adb shell input keyevent 47for "S" while holding Ctrl), press Ctrl+S → banner showskeys.action → save fired, and the keystroke is consumed. - resource.bytes
nostr:: paste anostr:nevent1…/note1…/naddr1…/npub1…and run → it returns the event JSON as a blob. Also try anhttps://…image URL. - Side effects (deliberate):
relay.publishsigns+broadcasts a note as you;upload.blobuploads a tiny blob;value.payInvoicepays a BOLT-11 invoice (needs a connected wallet). Each prompts. - Security: the applet has no direct network (a plain
fetch()inside it fails — CSPconnect-src 'none'); an undeclared capability is denied even if you'd allow it.
Notes
publish.shusesnak's-t key=val1;val2multi-element tag syntax (e.g.path=/index.html;<hash>). If yournakversion differs, adjust accordingly.- Re-running
publish.shreplaces the same addressable event (d=napplet-test).