Files
amethyst/nappletHost/src/main/res/values/strings.xml
T
Claude 3a78cd21c4 fix(browser): Tor always wins and fails closed; per-document subscriptions; bounded held requests
Tor / proxy
- NappletProxyClaims: no host exemptions — any surface that wants Tor puts
  all of :napplet on Tor. Pages set to the open web show why they're on
  Tor anyway (BrowserChrome.State.torForced, fed by MSG_ROUTE/observeRoute).
- WebViewProxyPolicy fails closed: a load waits for the route to apply, and
  gets onFailed (never a direct load) when applying fails or the WebView
  can't proxy while Tor is wanted. Callbacks run on the main executor.
- Launchers pass useTor = "Tor is on", not "port known": a Tor surface with
  no port yet blocks (embedded: Retry re-reads the port; full screen:
  refuses with a toast) instead of going out on the open web.

Sessions
- Provider closes a live tab before accepting a duplicate create; closeTab
  removes by identity. Session ids carry a per-process nonce. rearmSession
  clears createOnShow. Late onUiError while a create is pending is ignored;
  Retry re-creates a surface that never opened.
- Sessions start unattended; controllers always send their state.

NIP-07 / relay reads
- Relay subIds are stamped per document; pushes for a replaced document
  are dropped. A main-frame onPageStarted ends the document.
- Held requests are capped (32) and expire (2 min) with failure replies.
- Browser token mints carry the surface's storage profile; the broker
  refuses one that isn't the signed-in account's. Browser tokens get their
  own LRU so subdomain cycling can't evict napplet tokens.
- Broker tracks attendance per client: encrypted subscription events are
  held undecrypted until the page is attended; relay.query waits for it.

Also: releaseWhenGone tracks every parked back-stack entry; the console
error count is read in its own composable scope.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G3bteStHvaf18TdABSkb8h
2026-09-30 20:38:30 +00:00

25 lines
1.5 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<resources>
<!-- Sandbox host (`:napplet` process) UI. Kept here so the sandbox module needs no app resources. -->
<string name="napplet_invalid">Invalid nApplet.</string>
<string name="napplet_webview_too_old">This device\'s WebView is too old to run nApplets safely.</string>
<!-- Live "allow always" action notices -->
<string name="napplet_action_published">“%1$s” published a note as you</string>
<string name="napplet_action_uploaded">“%1$s” uploaded a file</string>
<string name="napplet_action_paid">“%1$s” made a payment</string>
<!-- Loading / unavailable screens -->
<string name="napplet_unavailable_title">Couldn\'t load “%1$s”</string>
<string name="napplet_unavailable_subtitle">The publisher\'s servers may be offline, or you\'re not connected. You can try again.</string>
<string name="napplet_unavailable_retry">Try again</string>
<!-- Developer console: page-load failures surfaced as console errors -->
<string name="napplet_console_load_error">Failed to load (%1$d): %2$s</string>
<string name="napplet_console_http_error">HTTP %1$d %2$s</string>
<!-- Shown by the full-screen browser / napplet (in the sandbox process, where compose resources can't be
read outside composition) when a page is not loaded because its Tor route can't be honored. -->
<string name="napplet_route_blocked">Not loaded: Tor isn\'t available for this page yet. Try again in a moment.</string>
</resources>