From 09ed5e95deb94fea224d88e4a1ffebee2c4af42f Mon Sep 17 00:00:00 2001 From: Padreug Date: Fri, 19 Jun 2026 23:19:58 +0200 Subject: [PATCH] docs(nostr-client): TTL expiry is now a post-bind deauth cause MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit nsecbunkerd#27 enforces token lifecycle at sign time (Option D): an expired token (`expiresAt`) now stops signing post-bind, not just at connect — reversing the earlier #24 "TTL is connect-window-only" note. A lapsed TTL now surfaces as the same BunkerRejectedError as a revoke, so the Phase D re-pair handling covers both. Docstring corrected to say so. refs nsecbunkerd#27/#24/#25, aiolabs/bitspire#52 Co-Authored-By: Claude Opus 4.8 (1M context) --- packages/nostr-client/src/bunker-signer.ts | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/packages/nostr-client/src/bunker-signer.ts b/packages/nostr-client/src/bunker-signer.ts index ed80f02..642b570 100644 --- a/packages/nostr-client/src/bunker-signer.ts +++ b/packages/nostr-client/src/bunker-signer.ts @@ -29,9 +29,11 @@ import type { Signer } from './signer.js' const DEFAULT_BUNKER_TIMEOUT_MS = 10_000 /** - * Raised when the bunker actively rejects a request (e.g. the operator - * revoked the spire's binding, or a kind/method is outside the policy). - * Callers should treat this as "unpaired" and surface a re-pair prompt. + * Raised when the bunker actively rejects a request. Post-bind causes + * (nsecbunkerd#27, sign-time lifecycle enforcement): the operator revoked the + * binding (`KeyUser`/`Token.revokedAt`), the token's TTL (`expiresAt`) lapsed, + * or the requested kind/method is outside the policy. Callers should treat + * this as "unpaired" and surface a re-pair prompt. */ export class BunkerRejectedError extends Error { constructor(message: string) {