From 84f11e615dd618162d81e2914f192fb7791291f0 Mon Sep 17 00:00:00 2001 From: Avi Date: Fri, 11 Sep 2026 15:13:16 -0500 Subject: [PATCH] checkpoint: vault-load rewrite fix (c096705) + Amber verify as next step --- CHECKPOINT-encryption.md | 56 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+) diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 2050b56..40fe156 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,59 @@ +# Checkpoint — Vault-load rewrite fix + Amber handshake lands (2026-09-11) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`c096705`** ("fix(vault): stop rewriting the vault on every + load; clippy cleanup"). Previous: `f917e5e` (Amber-compatible handshake). +- Working tree: clean for tracked files (untracked leftovers unchanged — see older + "Still untracked" sections). +- Verification: `cargo test` **200 passed / 0 failed**, `cargo clippy --all-targets` + 0 warnings, `cargo fmt --check` clean, `cargo build --release` green. + (Frontend untouched this session; vite dev server still running on :5173.) + +## What was completed (this session) + +**Carried-forward open question — CLOSED, landed as `c096705`.** +`migrate_vault_signer_modes` used to return `changed = true` unconditionally, so +`App::load` re-encrypted and re-saved the vault on every single start. Now a change +is reported only when `vault.version` actually moves: per-profile `signer_mode` +normalisation was always a no-op (the serde default fills missing fields at parse +time and the current version serialises it explicitly). The idempotency test was +tightened to assert `changed == false` for a current-version vault. Also dropped a +clone-on-Copy in `nip46_client.rs::get_public_key` (clippy warning from `f917e5e`). + +**`f917e5e` (committed earlier today, before this session):** Amber-compatible +NIP-46 handshake — `bunker://` URIs accepted, URI authority key no longer treated +as identity (Amber mints a per-connection comms key; real identity learned via +`get_public_key` after the connect ack), 120 s human-approval window with the +session held in Connecting (fail closed), absent `perms=` delegates enforcement to +the signer, `send_rpc` honours its timeout. **On-device Amber round-trip has not +been re-verified since this commit — that is the next task.** + +## Commits added (newest first) +- `c096705` fix(vault): stop rewriting the vault on every load; clippy cleanup +- `f917e5e` fix(signer): Amber-compatible handshake — bunker:// URIs, deferred + identity, ack wait (landed earlier today) + +## How to reproduce / exercise +- Dev loop (from memory, unchanged): `npx vite --port 5173`, then + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` in + `frontend/` (backend from `target/release/keynectr serve`). Rust edits need + rebuild + backend restart. +- Exercise vault fix: start the app twice; the vault file's mtime should NOT change + on the second start when nothing was modified. + +## Deferred / next steps +1. **Verify Amber end-to-end on device** (pair via Amber, sign a note, publish). +2. Dead stub `src/signer/nip46_external.rs` (untracked, superseded by + `nip46_client.rs`) — delete or fold its docs; `deferred/SignerConnectionPanel.tsx.wip/` + stays deferred. +3. `publish_profile_metadata` (kind 0) still signs locally — reroute through + `Signing` for external profiles. +4. Step 4 (permissions UI), Step 5 (KDF upgrade), Step 6 (undo history), + Step 7 (rename/hygiene incl. `homepage` URL + 5 Prettier files) — unchanged. + +--- + # Checkpoint — External NIP-46 signing works end-to-end (2026-09-10) ## Where things are