mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-10 16:33:27 +00:00
Follow-ups to the audit: - Abuse protection: the signer service now bounds its event queue (DROP_LATEST) and rate-limits per author BEFORE decrypting — decryption can be an external-signer (NIP-55) IPC round-trip, so a looping or hostile client can no longer force one per event or grow the queue without limit. Fixed window (default 40 requests / 10s per author, oldest authors evicted). The limiter is touched only by the single consumer coroutine, so it needs no locking. Covered by a headless test. - logout now clears the client's persisted metadata/relays too (not just the ledger grant), so a disconnected app stops being listened for after restart. Not changed: get_public_key/ping stay ungated — gating them behind a prior connect risks breaking clients that discover the pubkey at connect time, and the pubkey is already public, so the enumeration leak is negligible. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015FHr2mu5SiHwYNR7evYUuF