mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 03:38:23 +00:00
Completes Phase 4 end-to-end. DesktopIAccount.resolveDmInboxRelaysStrict now uses the resolver injected from Main.kt instead of the LocalCache-only fast path. Three-layer lookup at every call: 1. LocalCache hit (kind:10050 already observed via feed pipeline) 2. Resolver's 1h LRU cache 3. Indexer fan-out via the dedicated unauthenticated NostrClient The unauthenticated NostrClient is constructed in App() alongside relayManager and connects on creation; DisposableEffect disconnects on the App-level dispose. Critically NO RelayAuthenticator is attached to this client — only the primary relayManager.client has one (via DesktopAuthCoordinator). This closes security review F-01: indexer queries no longer extract identity-key signatures during kind:10050 probes against curated indexers. resolveDmInboxRelaysStrict is converted from sync to suspend; the three send paths (sendNip17PrivateMessage, sendNip17EncryptedFile, sendGiftWraps) already run in suspend context inside DmSendTracker batches, so the conversion is local. Resolver is plumbed through MainContent as a new parameter rather than a CompositionLocal — explicit threading matches the existing pattern for accountRelays and relayManager. The legacy LocalCache-only fallback inside resolveDmInboxRelaysStrict is preserved for the constructor-default case (tests, CLI). When dmInboxResolver is null, behaviour matches the pre-this-commit strict-fix from 5293dae65.