mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 11:48:24 +00:00
The Android half of the handoff: a screen that publishes on the old phone and reads on the new one, and AndroidCordnBlobStore behind it. That store does NOT reuse account.createBlossomUploadAuth the way CordnMediaService does. §12 requires the BUD-01 authorization to be signed by an ephemeral key and never the owner npub — signing as the owner would tell the storage server, under the account's own name, that this person is uploading right now, which is the linkage the opaque tip exists to prevent and would arrive by a side door. Message attachments are already attributable; a migration blob is meant to link to nobody. Two things are said where they are decided rather than in a help page, because neither is discoverable afterwards and both are irreversible in the ways that matter: before exporting, that the encrypted documents leave the device for a storage server; before importing, that this replaces whatever cordn groups are already here, because MLS state cannot be merged. The handed-off state is deliberately not phrased as an error — nothing broke and nothing was deleted, the device stood down on purpose, and taking it back is one button. The settings entry answers the earlier question: cordn had four flat rows (link, coordinators, key packages, backup) and migration would have made five, which made it the largest feature in the account settings list by count and among the least used. They are now one "cordn" entry into a hub holding all five, still searchable under one name a user would look for. ./gradlew test green; all three Marmot/cordn isolation guards pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n