mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 08:04:45 +00:00
The "locked nApplet vs open nSite" distinction was a `websiteMode: Boolean` threaded through an Intent extra and re-branched at eight independent sites across the launcher, the content server, both host surfaces, and the chrome. That is one coupled security posture (capabilities, CSP, NIP-07 injection, off-origin policy, network UI) expressed as scattered, drift-prone flags — and boolean-blind, since the "website" is actually the *more* capable mode. Introduce `HostProfile` (NAPPLET | WEBSITE), resolved once in the trusted main process and carried over the Intent/Messenger boundary as its name. Every coupled consequence now reads from one place: - `declaredCapabilities(requires)` — THE broker grant, minted into the token - `appCsp` / `injectsNip07` / `allowsOffOrigin` / `exposesNetwork` Pure mechanical mapping (every branch 1:1, no behavior change). The wire extra `EXTRA_WEBSITE_MODE` boolean becomes `EXTRA_HOST_PROFILE` string — safe, as it is in-app process-to-process IPC, never persisted. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HrxLCMcQADUPnm8Sj9ZJ63