From 98593cb1704651858a5eae685a64f29141a7f501 Mon Sep 17 00:00:00 2001 From: Avi Date: Sun, 27 Sep 2026 21:02:21 -0500 Subject: [PATCH] docs(checkpoint): multi-account signer switching (park/switch/cancel) at c89b31a (2026-09-27) --- CHECKPOINT-encryption.md | 59 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index e88cb10..9f3d5d9 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,62 @@ +# Checkpoint — multi-account signer switching (Option A) (2026-09-27 eve) + +## Where things are +- Project: `/home/avi/Projects/Keynctr`, branch `master` @ **`c89b31a`** + ("feat(nip46): pair a second signer account — park the live session, + switch re-dials it"). Previous: `1b4655c` (checkpoint), `332ab64`. +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/`. + +## What was completed (user-facing) +1. **You can now add a second Amber account.** Pairing a new signer while + one is connected no longer says "Already connected — disconnect + first": the current session is PARKED (kept restorable, never revoked) + and the new account pairs. +2. **Switching profiles switches signer accounts.** Click a profile in + Profiles: if it has a saved signer session, the live one is parked and + that profile's session is re-dialed automatically (no scan, identity + guard still enforced). Local-key profiles leave the signer alone. +3. **Cancel on the QR is safe.** Leaving the QR view cancels only the + pairing attempt and brings the parked session back (new + `nip46_cancel_pairing` IPC; the old path revoked). +- One session is live at a time (Amber signs one active account anyway); + all others stay saved and switchable. + +## Commits added +- `c89b31a` feat(nip46): pair a second signer account — park the live session, switch re-dials it + +## Verification (all green at c89b31a) +- Rust: `cargo test` 216 unit + 6 e2e (NEW: two fake Ambers on one relay — + B's pairing parks A unrevoked with client key intact; switch back + re-dials A and signs; no-op switch; local profile untouched; B + restorable). `cargo clippy --all-targets` 0 warnings; `cargo fmt --check` + clean; `cargo build --release` rebuilt (binary mtime Sep 27 21:00). +- Frontend: `npm test` 125 passed; `typecheck`, `lint`, `format:check` + clean; `npm run build` + `electron:build` green. + +## Resume / reproduce +- GUI: relaunch the app (or restart the backend) to pick up the new + release binary. Profiles -> click another paired profile -> log shows + `restoring session` + `identity check on restored session: PASS`. +- Add account B: Create Profile -> Sign in with Amber -> switch to + account B IN AMBER -> scan. Account A stays restorable. +- e2e: `cargo test --test nip46_e2e` (6 tests, loopback relay only). + +## Outstanding +- LIVE two-account eyeball by the user (pair account B from a second + Amber profile, switch back and forth) — e2e proves the mechanics, a + real-device pass confirms it end-to-end. +- Live "Check for updates" failure is an ENVIRONMENT issue, not a bug: + the updater shells out to `npm outdated`/`cargo update` in the source + tree; the spawned backend's PATH lacks npm/cargo (Electron-launched + process), so it errors. Fix options: bake a login-shell PATH into the + updater or surface a clearer message. Not started. +- Publish kind-0 to primal/damus (one Amber approval); Step 4 + permissions UI; KDF upgrade (Step 5); rename pass (Step 7). + +--- + # Checkpoint — forensics log cleaned + live publish confirmed (2026-09-26) ## Where things are