mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
NIP-29 metadata/roster events (39000-39003) "are addressable events signed by the relay keypair directly ... as stated by the NIP-11 `self` pubkey", and "relays shouldn't accept these events if they're signed by anyone else". So the authoritative test for a genuine group is `39000.author == relay.self` — which also rejects a stray user-published 39000 even on a real NIP-29 relay, something the earlier supported_nips heuristic could not. Add `isRelaySignedRelayGroup(channel)`: strict `author == self` when the relay publishes `self`, falling back to `supported_nips ∋ 29` when it omits `self`, and false when it has neither. Apply it at the surfaces that show unsolicited groups: - Discovery feed: replace the relay-level supported_nips filter with the per-channel self-key check in matches(); the screen now warms each candidate relay's NIP-11 and re-invalidates the feed as each doc resolves. - On-relay group list: filter to relay-signed groups, warming that relay's NIP-11 so genuine groups fill in and fakes stay hidden. - CLI `relaygroup browse`/`info`: fetch the relay's NIP-11 (new Context.relayInfo) and drop 39xxx not signed by `self`; browse reports the dropped count. Explicit user actions (a received invite link, opening an naddr) are left untouched — hiding those would be user-hostile. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01B5MLY4hq5LXJ2D5WeLRyXj