Files
amethyst/nappletHost/src/main/res
Claude 3a78cd21c4 fix(browser): Tor always wins and fails closed; per-document subscriptions; bounded held requests
Tor / proxy
- NappletProxyClaims: no host exemptions — any surface that wants Tor puts
  all of :napplet on Tor. Pages set to the open web show why they're on
  Tor anyway (BrowserChrome.State.torForced, fed by MSG_ROUTE/observeRoute).
- WebViewProxyPolicy fails closed: a load waits for the route to apply, and
  gets onFailed (never a direct load) when applying fails or the WebView
  can't proxy while Tor is wanted. Callbacks run on the main executor.
- Launchers pass useTor = "Tor is on", not "port known": a Tor surface with
  no port yet blocks (embedded: Retry re-reads the port; full screen:
  refuses with a toast) instead of going out on the open web.

Sessions
- Provider closes a live tab before accepting a duplicate create; closeTab
  removes by identity. Session ids carry a per-process nonce. rearmSession
  clears createOnShow. Late onUiError while a create is pending is ignored;
  Retry re-creates a surface that never opened.
- Sessions start unattended; controllers always send their state.

NIP-07 / relay reads
- Relay subIds are stamped per document; pushes for a replaced document
  are dropped. A main-frame onPageStarted ends the document.
- Held requests are capped (32) and expire (2 min) with failure replies.
- Browser token mints carry the surface's storage profile; the broker
  refuses one that isn't the signed-in account's. Browser tokens get their
  own LRU so subdomain cycling can't evict napplet tokens.
- Broker tracks attendance per client: encrypted subscription events are
  held undecrypted until the page is attended; relay.query waits for it.

Also: releaseWhenGone tracks every parked back-stack entry; the console
error count is read in its own composable scope.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G3bteStHvaf18TdABSkb8h
2026-09-30 20:38:30 +00:00
..