diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 9f3d5d9..97f173b 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,67 @@ +# Checkpoint — permissions UI + updater PATH fix (2026-09-27 night) + +## Where things are +- Project: `/home/avi/Projects/Keynctr`, branch `master` @ **`fa59b63`** + ("fix(updates): augment spawned PATH so npm/cargo resolve from Electron"). + Previous: `adbc7c2` (permissions UI), `98593cb` (checkpoint), `c89b31a`. +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/`. +- Release binary rebuilt at fa59b63 (22:43, verified mtime — not a cache hit). +- NOTE: a running Electron app still serves the OLD backend + stale `dist/` + until relaunch; the running serve predates both commits. + +## What was completed +1. **Permissions are visible (Step 4, first slice).** `Nip46Status` now + carries the connection's declared `perms=` grant list and expiry. The + Signer Mode screen shows a **Permissions** panel on a live session: one + row per granted method ("Sign events — kinds 1, 30023"), or a plain + statement that the signer app (Amber) approves every request when no + grant list was declared. `frontend/src/lib/permissions.ts` holds the + shared label formatters. +2. **"Always allow" is now kind-scoped (was: method-wide, too broad).** + A `sign_event` grant records the kind of the request the user actually + approved; a kind-1 grant never covers a kind-3 request — uncovered kinds + fall back to the approval prompt. Legacy kind-less grants keep their + all-kinds meaning (stored vaults keep working; new grants are never + created kind-less). Enforced in BOTH `bunker.rs` (bunker mode) and + `nip46_client.rs` (client mode) via `Vault::has_signer_grant(peer, + method, event_kind)`. The Signer screen's grants list renders the human + label with kind scope. +3. **Check-for-updates fixed.** The Electron-spawned backend inherited the + desktop launcher's PATH (no `~/.cargo/bin`, no mise/asdf shims), so + `npm`/`cargo` "didn't exist". `updates.rs::run()` now appends the + well-known per-user tool dirs to the inherited PATH (inherited wins on + conflicts; missing dirs ignored). Verified live under + `env -i PATH=/usr/bin:/bin`: `update_check` returns a full report. + +## Commits added +- `adbc7c2` feat(signer): permissions UI — declared grants surfaced, always-allow kind-scoped +- `fa59b63` fix(updates): augment spawned PATH so npm/cargo resolve from Electron + +## Verification (all green at fa59b63) +- Rust: `cargo test` 219 unit + 6 e2e (NEW: `signer_grants_are_kind_scoped`, + two `augmented_path` tests); `cargo clippy --all-targets` 0; `cargo fmt + --check` clean; `cargo build --release` rebuilt 22:43. +- Frontend: `npm test` 135 (10 new: `permissions.test.ts` unit + 2 + SignerModeScreen permission-panel tests), `typecheck`, `lint`, + `format:check`, `build`, `electron:build` all green. + +## Deferred / next steps +- Live eyeball: relaunch the app, pair with a `perms=`-carrying client (or + Amber) and check the Permissions panel; approve kind-1 "Always allow", + then send a kind-3 request and confirm it PROMPTS (kind scope). +- Two-account live pass from the previous checkpoint still open (pair + account B in Amber, switch back and forth). +- Publish kind-0 to primal/damus (one Amber approval). +- Step 4 remainder (if wanted): interactive grant editing in the approval + modal (approve-with-narrowing UI); today the modal is Approve / Always + allow (kind-scoped) / Reject. +- Step 5 (KDF upgrade m=64MiB/t=3 + vault header versioning), Step 6 (undo + history), Step 7 (rename/hygiene incl. `homepage` URL). + +--- + # Checkpoint — multi-account signer switching (Option A) (2026-09-27 eve) ## Where things are