mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
Third refinement from the Primal comparison — and the one that needed an architecture change, not just UI. Quartz: NostrConnectSignerService now fans each request into a child coroutine under a Semaphore(maxConcurrentHandles=16) instead of handling them inline, so a request awaiting a consent prompt no longer blocks other clients' auto-allowed traffic and several prompts can be pending at once. Intake (dedup, staleness, rate-limit, seen-id persistence) stays on the single consumer. Two guards keep it safe: BunkerRequestProcessor serializes the actual crypto with a Mutex (authorization — the prompt — runs unlocked, only sign/encrypt/decrypt holds the lock) so an external NIP-55 signer never sees concurrent IPC ops; and Nip46PermissionAuthorizer serializes first-connect consent so two connects can't stack dialogs. Covered by BunkerRequestProcessorConcurrencyTest (crypto never overlaps; a blocked prompt doesn't stall another client's signing). Amethyst: SignerConsentCoordinator is now a shared pending StateFlow; one SignerConsentActivity observes it and shows the rich single-request dialog (1 pending) or a batched checkbox list with select-all + a Remember toggle + Allow/Deny selected (>1). Dismissing the sheet denies every still-open request (fail closed). Needs on-device validation (burst batching, no concurrent external-signer IPC, fail-closed on dismiss) — see the device checklist. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015FHr2mu5SiHwYNR7evYUuF