diff --git a/src/signer/nip46_client.rs b/src/signer/nip46_client.rs index e9b84f9..5999af5 100644 --- a/src/signer/nip46_client.rs +++ b/src/signer/nip46_client.rs @@ -586,6 +586,24 @@ impl Nip46ClientSigner { &event.pubkey.to_hex()[..16], event.content.len() ); + // Local-only debug capture (never leaves this machine): keep the + // full event so a failed handshake can be dissected offline. + { + let path = std::path::Path::new( + "/home/avi/Tools/keynctr-debug/pairing-capture.jsonl", + ); + if let Some(dir) = path.parent() { + let _ = std::fs::create_dir_all(dir); + } + if let Ok(mut f) = std::fs::OpenOptions::new() + .create(true) + .append(true) + .open(path) + { + use std::io::Write; + let _ = writeln!(f, "{}", event.as_json()); + } + } // Never answer ourselves. if event.pubkey == our_pk { continue; @@ -601,10 +619,15 @@ impl Nip46ClientSigner { continue; }; let Ok(request) = serde_json::from_str::(&plain) else { + eprintln!( + "[nip46 pairing] decrypted payload is not a NIP-46 request (len {})", + plain.len() + ); continue; }; if request.method != "connect" { // Anything before the handshake is premature — ignore. + eprintln!("[nip46 pairing] pre-handshake '{}' ignored", request.method); continue; } // NIP-46: the client answers the signer's `connect` with the @@ -621,6 +644,7 @@ impl Nip46ClientSigner { { return Err(format!("Could not answer the connect request: {e}")); } + eprintln!("[nip46 pairing] connect answered; awaiting identity handshake"); // Optional requested_perms ride in params[1]; parse leniently — // a malformed grant list degrades to "no local enforcement", // which defers to the signer's own approval prompts.