Files
amethyst/cli/src
Claude 83ccbbd2a3 fix: audit fixes for the key backup and NIP-49 changes
Backup screen (Android):
- The key-access gate lost its queued action on Android 8-10. There the
  device-credential activity always runs, stops the screen, and ON_STOP
  cleared the action. It was also lost when a wrong fingerprint (a soft
  failure) preceded the lockout PIN fallback. Now only a new request or the
  keyguard result replaces it.
- The nsec clipboard auto-clear ran in a composition scope, so leaving the
  screen within 60 s cancelled it and left the nsec on the clipboard. It now
  runs in the AccountViewModel scope.
- The copied nsec is flagged IS_SENSITIVE, so Android 13+ hides it in the
  system copy overlay, which is outside FLAG_SECURE.
- Password fields are disabled while scrypt runs, so the result always matches
  what is shown. Encrypt uses the ByteArray overload (no hex copy of the key).

NIP-49 (quartz):
- decrypt() rejects ciphertexts that are not 48 bytes. A shorter one with a
  valid tag decoded as a zero-padded key (test reproduces it).
- An OutOfMemoryError from scrypt, e.g. an ncryptsec made elsewhere at
  LOG_N 20 (1 GiB), becomes an IllegalStateException, so login reports it
  instead of crashing.
- The decrypted plaintext buffer inside LibSodiumInstance is wiped after
  copying out.

CLI: `amy login` and `amy key decrypt` accept hand-copied keys (UPPERCASE,
grouped), like the apps.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012hhtLQhig6Wmt5U4C3owaP
2026-09-26 22:29:47 +00:00
..