mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
Adds the platform-agnostic core for hosting untrusted napplet (NIP-5D) / nsite (NIP-5A) web content behind a hard trust boundary, so applet HTML/JS can never reach the nsec, app storage, or LocalCache. The Android host runs the WebView in a separate OS process (:napplet) that holds no secrets and brokers every dangerous operation over IPC to the main process. This commit lands the verifiable heart of that boundary in commons commonMain (KMP-pure, fully unit-tested): - NappletCapability + NAP-domain mapping (default-deny on unknown domains) - NappletIdentity keyed by addressable coordinate (grants survive updates) - NappletPermissionLedger / GrantState / store (persistent vs session vs once; standing DENY is authoritative) - NappletRequest/NappletResponse wire protocol (no response carries key bytes) - NappletBroker: the only holder of the signer; enforces consent, signs as the user only, refuses to publish foreign or unsigned events Architecture, process model, IPC schema, WebView hardening, and consent UX are documented in amethyst/plans/2026-06-19-napplet-sandbox-host.md. The Android :napplet process, WebView host, AIDL broker, and consent UI are the next phase. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016ncMHuBBVHEf7spAoSssde