docs(backend): pin get_public_key as an intentional, load-bearing ACL exception (#26) #53
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/26-document-get-public-key-ungated"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Re: #26 — resolves the open question with option A (accept + document). Issue to be closed manually after merge, per repo convention (no auto-close keyword).
What
get_public_keyreturns the signer pubkey without routing throughpubkeyAllowed(), unlike every other NIP-46 method (connect,ping,sign_event,nip04/44_*). #26 flagged this as an unaudited/ungated disclosure through the ACL seam and asked us to decide deliberately between two options: (A) accept + document, or (B) override the strategy to gate it.The decision: option A — because option B breaks production
I verified against the live clients before touching the gate. Gating
get_public_keywould reintroduce the exact "signer unavailable" outage class we just spent the #41 saga eliminating:nip46_bunker_client.py::connect()flips_connected = Trueand immediately callsget_public_keyto verify the target pubkey — NIP-46 spec46.mdoverview step 5. It runs before any policy-bearing method, as part of session establishment._ensure_policy(remote_bunker.pyDEFAULT_POLICY_RULES+DEFAULT_POLICY_METHODS_NO_KIND) plants rules forsign_event(whitelisted kinds) + the fournip04/44crypto methods only. There is noget_public_keyrule (and none forconnect/pingeither —connectis granted structurally by any live token, not by a policy rule).undefinedfromcheckIfPubkeyAllowed, dropping the client's post-connect call onto the admin-approval path where it stalls until timeout → session establishment fails → "signer unavailable".The pubkey isn't secret — it's the identity the bunker openly signs as; a relay observer derives it from published events anyway. So option A is correct on the merits and mandatory for compatibility.
The change
Pure documentation — a load-bearing comment at the
get_public_keycase explaining why it must stay ungated, so a future refactor doesn't "helpfully" gate it and cause the outage. No behavior change.tsc: clean (the 3 pre-existing errors inauthorize.ts/web/authorize.tsare unchanged and unrelated).npm run test:nip46: green (serves NIP-46 + survives a flap).If we ever want per-app gating/audit of identity disclosure, it must be co-designed with a policy rule the clients actually plant — tracked in the #26 discussion (NDK vs rust-nostr prior-art survey).
🤖 Generated with Claude Code