mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 11:18:24 +00:00
Two defects found auditing the NIP-44 change. The in-app browser mints its own per-origin launch token and never consulted HostProfile, so it still granted IDENTITY+RELAY. Those are exactly the surfaces that set __nappletNip07, so the shim advertised window.nostr.nip44 and the broker then denied every call -- worse than not advertising it, since apps stop falling back. The website set now lives once, in NappletCapability, and both mints read it. Second, the broker recorded a consent grant under the REQUESTED op rather than the op the grant itself carried. Nip44Decrypt is the first napplet-side request with a narrower alternative (DecryptFrom(peer)), so a user tapping "always allow for Alice" would have been stored as a broad "allow decrypt" -- every conversation, forever, from one tap. Recording now goes through NostrSignerPermissionLedger.record, which uses the grant's own op, and a standing narrow grant is honoured on later requests instead of re-prompting. This mirrors the NIP-46 authorizer, which already got both right. With the recording fixed, the consent dialog can safely name the counterparty: Nip44Decrypt now supplies it, so the prompt reads "read your private messages with Alice" and offers the scoped grant beside the broad one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Hge2jR1BPnyZse75VQ4kg