Files
amethyst/commons
Claude cb7ba7dbf7 feat: remember relay auth "log in" for the rest of the session
A NIP-42 challenge is not a one-off: relays re-challenge on every reconnect,
and the client reconnects constantly (network changes, doze, app switches).
Answering the prompt without the "remember" switch authorized only the single
in-flight challenge, so the same relay asked the same question again minutes
later — the prompt fatigue that pushes users into "always allow" on a relay
they only wanted to try once.

Adds RelayAuthSessionGrants: a per-account, in-memory set of relays approved
during this run of the app. It lives on Account, so it dies with the process
and at logout — that is what keeps it distinct from the stored ALLOW the
"remember" switch writes to disk.

Wiring:
- RelayAuthInputs/RelayAuthResolver gain hasSessionGrant, ranked below the
  stored override so a later "never allow" takes effect immediately, and
  below the block list which still wins outright. Not gated on isFirstParty:
  an explicit answer for this relay outranks any inference about it.
- AuthCoordinator records the grant on ALLOW_ONCE.
- setDecision/clearDecision drop the grant, so "follows your rules again"
  after removing an exception is true rather than silently still allowed.
- Relay auth settings lists the grants under "Just for now", each row
  promotable to a real exception or forgettable with an undo.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rado2dnqpbCuCUyCd3trQz
2026-08-17 14:21:40 +00:00
..