mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
A user must be able to connect to any relay they choose, including a plain ws:// one. Narrowing network_security_config.xml to loopback and .onion would let the Data safety form answer "Yes" to encrypted-in-transit, but cutting off cleartext relays is not an acceptable price for a nicer label. Considered and rejected, written down so it reads as a decision rather than an oversight. So the answer is No, and that is fine. The "No" was never what made the old form incoherent - pairing it with "App doesn't collect or share data" was, since with nothing collected there is no encryption question to answer. With collection declared truthfully, "No" is simply accurate, and the one-sentence defence is recorded with it: Amethyst connects over TLS by default, and cleartext happens only for a relay address the user typed in themselves. Also records the consequence rather than leaving it implicit: a user on a ws:// relay who publishes a workout sends that kind 1301 in cleartext. The options that preserve ws:// - warning when a cleartext relay is added, or before publishing a health-derived event to one - are noted as not implemented, so that too is a choice on the record. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TPShPiTfg16yesupcLgyqf