checkpoint: vault-load rewrite fix (c096705) + Amber verify as next step

This commit is contained in:
Avi 2026-09-11 15:13:16 -05:00
commit 84f11e615d

View file

@ -1,3 +1,59 @@
# Checkpoint — Vault-load rewrite fix + Amber handshake lands (2026-09-11)
## Where things are
- Project: `/home/avi/Projects/Keynctr`
- Branch: `master` @ **`c096705`** ("fix(vault): stop rewriting the vault on every
load; clippy cleanup"). Previous: `f917e5e` (Amber-compatible handshake).
- Working tree: clean for tracked files (untracked leftovers unchanged — see older
"Still untracked" sections).
- Verification: `cargo test` **200 passed / 0 failed**, `cargo clippy --all-targets`
0 warnings, `cargo fmt --check` clean, `cargo build --release` green.
(Frontend untouched this session; vite dev server still running on :5173.)
## What was completed (this session)
**Carried-forward open question — CLOSED, landed as `c096705`.**
`migrate_vault_signer_modes` used to return `changed = true` unconditionally, so
`App::load` re-encrypted and re-saved the vault on every single start. Now a change
is reported only when `vault.version` actually moves: per-profile `signer_mode`
normalisation was always a no-op (the serde default fills missing fields at parse
time and the current version serialises it explicitly). The idempotency test was
tightened to assert `changed == false` for a current-version vault. Also dropped a
clone-on-Copy in `nip46_client.rs::get_public_key` (clippy warning from `f917e5e`).
**`f917e5e` (committed earlier today, before this session):** Amber-compatible
NIP-46 handshake — `bunker://` URIs accepted, URI authority key no longer treated
as identity (Amber mints a per-connection comms key; real identity learned via
`get_public_key` after the connect ack), 120 s human-approval window with the
session held in Connecting (fail closed), absent `perms=` delegates enforcement to
the signer, `send_rpc` honours its timeout. **On-device Amber round-trip has not
been re-verified since this commit — that is the next task.**
## Commits added (newest first)
- `c096705` fix(vault): stop rewriting the vault on every load; clippy cleanup
- `f917e5e` fix(signer): Amber-compatible handshake — bunker:// URIs, deferred
identity, ack wait (landed earlier today)
## How to reproduce / exercise
- Dev loop (from memory, unchanged): `npx vite --port 5173`, then
`NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` in
`frontend/` (backend from `target/release/keynectr serve`). Rust edits need
rebuild + backend restart.
- Exercise vault fix: start the app twice; the vault file's mtime should NOT change
on the second start when nothing was modified.
## Deferred / next steps
1. **Verify Amber end-to-end on device** (pair via Amber, sign a note, publish).
2. Dead stub `src/signer/nip46_external.rs` (untracked, superseded by
`nip46_client.rs`) — delete or fold its docs; `deferred/SignerConnectionPanel.tsx.wip/`
stays deferred.
3. `publish_profile_metadata` (kind 0) still signs locally — reroute through
`Signing` for external profiles.
4. Step 4 (permissions UI), Step 5 (KDF upgrade), Step 6 (undo history),
Step 7 (rename/hygiene incl. `homepage` URL + 5 Prettier files) — unchanged.
---
# Checkpoint — External NIP-46 signing works end-to-end (2026-09-10)
## Where things are