diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 40fe156..fefc63d 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,61 @@ +# Checkpoint — NIP-46 e2e test + bunker:// frontend support (2026-09-11) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`85756df`** ("feat(signer): accept bunker:// URIs, async + signer permissions, NIP-46 e2e test"). Previous: `c096705`, `f917e5e`. +- Working tree: clean for tracked files. Untracked junk intentionally NOT + committed: `.opencode/`, `.impeccable/`, `.directory`, `COSMIC_THEME.md`, + `KeynectrAppIconPossibility02.jpeg`, `deferred/`, and the dead stub + `src/signer/nip46_external.rs`. +- Verification (all green this session): `cargo test` **200 + 1 e2e passed / 0 + failed**, `cargo clippy --all-targets` 0 warnings, `cargo fmt --check` clean, + `cargo build --release` green. Frontend: `npm test` **116 passed (16 files)**, + `npm run typecheck` clean, `npm run lint` clean, `npm run format:check` clean + (Prettier applied to the 4 previously-warning files), `npm run electron:build` + and `npm run build` green. + +## What was completed (this session) +- `tests/nip46_e2e.rs` (new, 450 lines): full in-process NIP-46 client test — + minimal local relay + fake Amber speaking the bunker flow, NIP-44 round-trip, + `connect` handshake, identity asserted to come from `get_public_key` (URI key + must never become identity), `sign_event` result verified against the signer + pubkey, vault persistence asserting `profile.secret_key` stays empty for + remote profiles. +- Frontend bunker:// support landed: `SignerManager.parseExternalSignerURI` + accepts `bunker://` (pubkey = authority before `@`) as well as + `nostrconnect://`; `SignerModeScreen` validates both, placeholder/hint explain + Amber vs Nostr Connect sources. +- Signer trait permission surface made async (`permissions`, `can_*`, + `is_connection_valid` now `async`, `blocking_lock` -> `lock().await`). +- Dev-loop gremlins fixed along the way: zombie vite on :5173 killed, stray + Electron (launched against dead vite, SIGTRAP core dump) cleaned up, app + relaunched and confirmed on screen. + +## Commits added (newest first) +- `85756df` feat(signer): accept bunker:// URIs, async signer permissions, + NIP-46 e2e test + +## How to reproduce / exercise +- Dev loop: `npm run dev` in `frontend/` (vite on :5173), THEN second terminal + `npm run start:dev` (or `NOSTR_GUI_DEV_URL=http://localhost:5173 + KEYNCTR_ENABLE_GPU=1 npx electron .`). Vite must be up FIRST or Electron + crashes on load. Rust edits need `cargo build --release` + backend restart. +- E2E test: `cargo test --test nip46_e2e` (~0.6s, no network). +- GUI: Signer mode screen -> paste Amber `bunker://...` link -> approve in + Amber -> app resolves identity via `get_public_key`. + +## Deferred / next steps +1. **Verify Amber end-to-end on device** (pair via Amber, sign a note, publish) + — unchanged, still the top item. +2. Delete dead stub `src/signer/nip46_external.rs`; `deferred/` stays deferred. +3. `publish_profile_metadata` (kind 0) still signs locally — reroute through + `Signing` for external profiles. +4. Step 4 (permissions UI), Step 5 (KDF upgrade), Step 6 (undo history), + Step 7 (rename/hygiene incl. `homepage` URL) — unchanged. + +--- + # Checkpoint — Vault-load rewrite fix + Amber handshake lands (2026-09-11) ## Where things are