Files
amethyst/tools
Claude 0a48ddab5d fix(quartz): real NFKC on Linux, private zaps and deriveKey over NIP-46
Linux native's UnicodeNormalizer returned its input unchanged, so NIP-49
keys encrypted under a non-ASCII password (normalized by every other
client) could not be decrypted there. Add a pure-Kotlin UAX #15 NFKC
normalizer with tables generated from the Unicode 17.0 UCD by
tools/unicode-nfkc/generate.py, and use it on Linux. It passes all 20,034
lines of Unicode's NormalizationTest.txt and matches java.text.Normalizer
for every code point the JDK defines (NfkcNormalizerJdkParityTest).

NostrSignerRemote.decryptZapEvent and deriveKey were TODO(), whose
NotImplementedError is an Error that escapes DecryptCache's handlers.
A private zap's anon payload is AES-CBC under the NIP-04 shared secret,
so the recipient now decrypts it through the bunker's nip04_decrypt.
The sender's copy and deriveKey need the raw private key, which a bunker
never exposes, so they now throw CouldNotPerformException and
UnsupportedMethodException. An end-to-end test runs the remote signer
against Quartz's own bunker over an in-process relay.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QytMdt3MPxvmmWrAX3bJYS
2026-09-28 17:35:15 +00:00
..