Files
amethyst/commonsUI
Claude ecb9513b4d feat(cordn): the migrate screens, and one settings entry instead of five
The Android half of the handoff: a screen that publishes on the old phone
and reads on the new one, and AndroidCordnBlobStore behind it.

That store does NOT reuse account.createBlossomUploadAuth the way
CordnMediaService does. §12 requires the BUD-01 authorization to be signed
by an ephemeral key and never the owner npub — signing as the owner would
tell the storage server, under the account's own name, that this person is
uploading right now, which is the linkage the opaque tip exists to prevent
and would arrive by a side door. Message attachments are already
attributable; a migration blob is meant to link to nobody.

Two things are said where they are decided rather than in a help page,
because neither is discoverable afterwards and both are irreversible in
the ways that matter: before exporting, that the encrypted documents leave
the device for a storage server; before importing, that this replaces
whatever cordn groups are already here, because MLS state cannot be
merged. The handed-off state is deliberately not phrased as an error —
nothing broke and nothing was deleted, the device stood down on purpose,
and taking it back is one button.

The settings entry answers the earlier question: cordn had four flat rows
(link, coordinators, key packages, backup) and migration would have made
five, which made it the largest feature in the account settings list by
count and among the least used. They are now one "cordn" entry into a hub
holding all five, still searchable under one name a user would look for.

./gradlew test green; all three Marmot/cordn isolation guards pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n
2026-09-23 02:45:47 +00:00
..