mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-10 08:27:04 +00:00
Remove the signer self-gating bypass that allowed external (Amber/NIP-55) and remote (NIP-46) signers to skip Amethyst's per-napplet consent UI. All signer types now go through Amethyst's consent dialogs first; the external signer then adds its own approval on top (double-prompting). This lets users differentiate signing requests by app inside the external signer, since Amethyst itself is the requesting app. Also expand the REASONABLE policy to auto-approve Encrypt and Decrypt operations, matching the intent that common/private-key operations that apps routinely need are pre-approved at the "reasonable" trust level. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013hTFpoExYYLYEGGtXBx6ZT