mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 03:38:23 +00:00
The injected NIP-07 provider offered only getPublicKey/getRelays/signEvent, so a page hosted in the nSite viewer or the in-app browser could sign but never seal: a NIP-59 kind:13 seal is NIP-44 ciphertext authored by the real key, and signEvent alone cannot produce one. That put NIP-17 DMs and every gift-wrapped app protocol out of reach of any web app logging in with Amethyst. Adds nostr.nip44Encrypt/nip44Decrypt to the broker, behind a new SIGNER capability. SIGNER is website-only by construction: no NIP-5D domain maps to it, so resolveRequiredCapabilities can never hand it to a locked napplet however its manifest is written. Individual calls still pass the per-operation signer ledger, reusing the vocabulary NIP-46 already uses for the same ops -- encrypt auto-allows under REASONABLE, decrypt always asks. nip04 stays deliberately absent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Hge2jR1BPnyZse75VQ4kg