mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-11 08:47:33 +00:00
Self-review of this session's changes surfaced four issues: - Perms re-seeded on every re-pair. connectViaNostrConnect pre-granted the offer's declared ops outside the first-contact guard, so re-pairing an app overwrote per-op decisions the user had since changed (e.g. an op set to DENY came back as ALLOW). Now only on first contact. - Perms could silently grant sensitive ops. The nostrconnect flow shows no dialog (scan = consent), so the declared perms are never surfaced — yet seeding pre-granted everything except decrypt/deletion, which would silently allow config-overwrite (kinds 0/3) and other sensitive kinds. Tightened to only the ops REASONABLE already auto-allows, so pairing never exceeds the default policy; sensitive kinds still prompt on first use. - Batched-consent deny-all race. SignerConsentActivity.onDestroy denied every pending request when finishing; a request arriving as the sheet closed is owned by a freshly-launched instance, so it was wrongly denied. Removed — each dialog's onDismissRequest already fails closed, and the 120s bridge timeout backs it up. - Redundant work: batched-selection state keyed on list size (a new request in a same-size swap was unselectable) → key on the token set; connected-apps loader re-read loadPolicy per app when allPolicies() already carried it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015FHr2mu5SiHwYNR7evYUuF