mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-09 16:14:40 +00:00
Adds a platform-agnostic resolver for NIP-5A static-website / napplet (NIP-5D) manifests in quartz commonMain, under nip5aStaticWebsites/resolver/: - StaticSitePathLookup: request-path normalization (query/fragment stripping, leading-slash insensitivity, root/dir -> index.html), slash-insensitive path lookup over a manifest's path tags, and a web-asset Content-Type guess. - StaticSiteResolver: hash verification, Blossom candidate-URL assembly, and a suspend resolve() that downloads each listed server in order and accepts the first blob whose recomputed sha256 matches the manifest pin. HTTP is injected via a BlobFetcher typealias so quartz keeps no HTTP dependency. The trust model is the point: the signed manifest is the authority, the Blossom server is untrusted. A server that substitutes/corrupts a blob fails verification and is skipped -- it can withhold content but never forge it. Tests cover normalization, lookup, MIME guessing, and the security cases (tampered server skipped -> falls through to honest server; all-tampered -> Unresolvable; undeclared path -> PathNotInManifest without fetching). Also adds quartz/plans/2026-06-19-napplet-nip5a-resolver.md documenting the design and the open event-shape alignment questions (35128 vs 35129 manifest kind, capability declaration vs NIP-89, aggregate build hash, server ordering) to raise with the napplet author before the nsite/napplet event shape forks. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CdAJMbnHJfiMY7UcS99T6C