docs(nostr-client): TTL expiry is now a post-bind deauth cause

nsecbunkerd#27 enforces token lifecycle at sign time (Option D): an expired
token (`expiresAt`) now stops signing post-bind, not just at connect —
reversing the earlier #24 "TTL is connect-window-only" note. A lapsed TTL
now surfaces as the same BunkerRejectedError as a revoke, so the Phase D
re-pair handling covers both. Docstring corrected to say so.

refs nsecbunkerd#27/#24/#25, aiolabs/bitspire#52

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-06-19 23:19:58 +02:00
commit 09ed5e95de

View file

@ -29,9 +29,11 @@ import type { Signer } from './signer.js'
const DEFAULT_BUNKER_TIMEOUT_MS = 10_000 const DEFAULT_BUNKER_TIMEOUT_MS = 10_000
/** /**
* Raised when the bunker actively rejects a request (e.g. the operator * Raised when the bunker actively rejects a request. Post-bind causes
* revoked the spire's binding, or a kind/method is outside the policy). * (nsecbunkerd#27, sign-time lifecycle enforcement): the operator revoked the
* Callers should treat this as "unpaired" and surface a re-pair prompt. * binding (`KeyUser`/`Token.revokedAt`), the token's TTL (`expiresAt`) lapsed,
* or the requested kind/method is outside the policy. Callers should treat
* this as "unpaired" and surface a re-pair prompt.
*/ */
export class BunkerRejectedError extends Error { export class BunkerRejectedError extends Error {
constructor(message: string) { constructor(message: string) {