- Add shared NIP-44 v2 crypto helpers (src/nip44.py, src/nip44.js) producing
ephemeral_xonly_pubkey[32] || native_nip44_payload framing, interoperable
with base64-decoded nak encrypt output in both directions
- Upgrade existing senders/receivers in place (no duplicate apps): plaintext
remains the default; --relay-pubkey / --relay-secret (or env vars) select
encrypted mode on the same programs and ports
- Receiver detects plaintext first, then falls back to encrypted framing via
the 32-byte pubkey boundary and NIP-44 0x02 version byte, handling the
leading-brace ephemeral pubkey collision
- Add src/udp_encrypt_send.sh nak+nc wrapper and src/test_udp_nostr.py suite
(46 tests: plaintext, encrypted, mixed traffic, nak interop, collision,
malformed/tampered packets, wrong keys, size budget, env secrets)
- Update README and encryption implementation plan