mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
Backup screen (Android): - The key-access gate lost its queued action on Android 8-10. There the device-credential activity always runs, stops the screen, and ON_STOP cleared the action. It was also lost when a wrong fingerprint (a soft failure) preceded the lockout PIN fallback. Now only a new request or the keyguard result replaces it. - The nsec clipboard auto-clear ran in a composition scope, so leaving the screen within 60 s cancelled it and left the nsec on the clipboard. It now runs in the AccountViewModel scope. - The copied nsec is flagged IS_SENSITIVE, so Android 13+ hides it in the system copy overlay, which is outside FLAG_SECURE. - Password fields are disabled while scrypt runs, so the result always matches what is shown. Encrypt uses the ByteArray overload (no hex copy of the key). NIP-49 (quartz): - decrypt() rejects ciphertexts that are not 48 bytes. A shorter one with a valid tag decoded as a zero-padded key (test reproduces it). - An OutOfMemoryError from scrypt, e.g. an ncryptsec made elsewhere at LOG_N 20 (1 GiB), becomes an IllegalStateException, so login reports it instead of crashing. - The decrypted plaintext buffer inside LibSodiumInstance is wiped after copying out. CLI: `amy login` and `amy key decrypt` accept hand-copied keys (UPPERCASE, grouped), like the apps. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012hhtLQhig6Wmt5U4C3owaP