Skip to content

Signer hardening & UX follow-ups: NIP-42 AUTH, multi-relay bunker URI, retry backoff, outbox model #87

Description

@DocNR

Backlog cleanup, batch 2 — items that survived the 2026-08-10 BACKLOG.md trim but weren't in #81-86. Re-verified each against current main (b693e2f, 2026-08-10) before filing rather than trusting old BACKLOG prose — about half the original candidates (proxy per-client relay subscriptions, secondary-pool eviction, the nostrconnect URL scheme, the old ConnectSheet bunker-URI-discoverability complaint, the "@unknown" account fallback, the AddAccount hex placeholder, diagnostic print() cleanup) turned out to already be shipped and are excluded here.

  • nostrconnect Activity-log errors don't distinguish failure modes. Shared/RelayUtils.swift is explicitly commented "best-effort: failures are silently dropped... callers that need per-relay status reporting should extend this namespace" — publishEventToRelays still returns only a success count. Clave/AppState+NostrConnect.swift:122,181,248 collapse everything into generic strings like "All relays rejected connect response." Extend to per-relay URL+status and thread through to the activity log.
  • No NIP-42 AUTH support in LightRelay. Zero AUTH handling in Shared/LightRelay.swift. Auth-gated relays (nostr.wine paid tier, garden.zap.cooking, relay.nsec.app in some modes) still reject Clave's publishes. Fix: on ["AUTH", challenge], build+sign a kind:22242 event, send ["AUTH", signed], wait for OK, then publish.
  • Bunker URIs are pinned to a single relay. Clave/AppState+AccountManager.swift:40 builds bunker://<pubkey>?relay=<one-url>&secret=... — no fallback set. Directly relevant to relay.powr.build is down - Clave unusable #79 (relay.powr.build 502s through Cloudflare): a multi-relay bunker URI would let paired clients retry a fallback relay during exactly that kind of outage.
  • Bunker URI leaks the real signer pubkey to anyone who receives it. No ephemeral-per-connection-keypair scheme exists (checked for pubkey-translation/mapping code, found none). Amber shipped this pattern in PR #365 — generate an ephemeral keypair per pairing, translate incoming/outgoing p-tags in LightSigner.handleRequest. Prerequisite for future per-pairing-secret work too.
  • No time-bound permission grants. No grantedUntil/expiresAt field anywhere in the model — grants are binary (always-allow or always-prompt). Amber offers 1min/5min/10min/always. Would need a field on the permissions model + expiry check in LightSigner.handleRequest + a duration picker in the approval UI.
  • sign_event publish retry is fixed 3×2s, not exponential with fresh timestamps. Clave/Views/Home/ApprovalSheet.swift:416 comment confirms "3×2s publish retry per signer" is still the model; no fresh-timestamp-per-attempt or exponential backoff. A single stale-timestamp retry can get silently deduped by the relay. Amber's pattern: 5 attempts, 200ms→3.2s, regenerate event id + re-encrypt each attempt.
  • Bunker secrets have no TTL. Secrets are single-use and rotate on next connection, but a leaked-and-unused secret has no time-based expiry. Add a 24h default TTL as defense-in-depth.
  • No certificate pinning on proxy registration requests. No URLSessionDelegate/pinning code found in the iOS client's proxy-registration path.
  • [Large, deferred to v0.3.0+] No NIP-65 outbox model for kind:0 propagation. Editing a profile (via clave.casa or, later, in-app) only publishes to Clave's own relay set — not to where the user's actual followers read from. Distinct from the fresh-npub onboarding gap already in Proxy & signing reliability: event cache, request dedup, fresh-npub onboarding #82 (that's clients failing to read without NIP-65; this is Clave not using NIP-65 to publish broadly).
  • No SSH commit signing configured for the repo. Straightforward hygiene: ed25519 signing key, add to GitHub, git config --global gpg.format ssh + commit.gpgsign true.
  • [Needs a fresh look — from 2026-05-07, unverified since] ForegroundRelaySubscription was flapping against relay.damus.io. 7 WS-handshake failures over a 5-minute window in the original capture (~/Downloads/clave-wisp-devmenu.log). Not re-confirmed against current build — worth a quick recheck before investing, might already be resolved incidentally by other relay-pool work.

Source: internal backlog triage, 2026-08-10.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions