mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-08 23:54:39 +00:00
Adds a "Browser" navigation destination (drawer + pinnable bottom-nav item, API 30+) that opens any URL. The page renders in the sandboxed, keyless `:napplet` process and is streamed into the main activity as a cross-process surface via androidx.privacysandbox.ui (SurfaceControlViewHost) — only pixels and input cross the boundary, never the WebView's JS context or the NIP-07 bridge. The trusted address bar is drawn by the main process around the embedded surface, so the sandbox can never spoof the URL. NIP-07 `window.nostr` is injected the same way nSite website mode does it, but scoped per visited origin: each origin gets its own broker-minted launch token (keyed by the trusted source origin), so a grant to one site never leaks to another. - NappletBrowserService (`:napplet`): hosts the live-URL WebView, exposes it as a SandboxedUiAdapter, and relays the per-origin NIP-07 bridge to the broker. - NappletBrowserUiAdapter: wraps the WebView session for privacysandbox.ui. - NappletBrokerService: mints a per-origin synthetic identity so NIP-07 consent is scoped per host. - EmbeddedBrowserController + BrowserScreen: bind the service, render the SandboxedSdkView, and drive the trusted address bar (navigate/reload/back/Tor). - shim.js: a direct-bridge transport so the injected shim works in a top-level page that has no trusted shell parent. - Browser nav item hidden below API 30 (SurfaceControlViewHost requirement). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MgMpRcWj6y82LxLiwcuzmN