Commit Graph
16 Commits
Author SHA1 Message Date
archipelago eef17eb79b fix(nostr): bind cached app sessions to selected identity
Reuse only unexpired JWTs for the verified selected native public key. Invalidate stale session credentials and in-flight responses on account switching or logout, notify app state before authentication, and accept identity bootstrap only from the expected signer origin.

Preserve saved profiles and private keys. Validation: 23 focused provider tests passed, including cached-key mismatch, expiry, late response, logout and repeated-selection regressions.
2026-10-08 13:07:56 -04:00
archipelago 88d473f6e1 Normalize only loopback authorities in embedded app runtime URLs 2026-10-06 15:05:17 -04:00
archipelago a49d4d7128 Keep slow app sessions alive and defer automatic companion prompts 2026-10-06 12:55:47 -04:00
archipelago cc9f02dfd2 Keep embedded app URL stable as initial runtime state arrives 2026-10-06 10:56:42 -04:00
archipelago 715e86c901 Queue native signer requests without losing pending app consent 2026-10-06 10:41:58 -04:00
archipelago e97f958f45 fix: bound monitoring subprocesses and collect fresh system readings 2026-10-05 21:31:32 -04:00
archipelago 3d0c67eb9b fix: retain native signer session through repeated public-key lookups 2026-10-05 21:18:27 -04:00
archipelago 6f098cd9c2 fix: clone public identity fields before cross-frame signer handoff 2026-10-05 21:11:03 -04:00
archipelago 6ac26f637c fix(apps): preserve lifecycle state and wait for usable launch endpoints 2026-09-30 09:10:30 -04:00
archipelago 00682e6420 test: expect Cuprate launches through companion UI 2026-09-12 16:17:47 -04:00
archipelago 4f0d123f27 feat: open GitWorkshop at Archipelago repository
Demo images / Build & push demo images (push) Successful in 3m33s
2026-09-12 15:57:57 -04:00
archipelago f5c0ba85cd feat(release): stage GitWorkshop and next node updates 2026-09-09 18:15:21 -04:00
archipelago 62731cc729 test(ui): use shipped app for generated launch port check 2026-09-07 03:30:29 -04:00
archipelago 46cb0bfd37 fix(ui): gate-fronted https launches + signed-catalog App Store
Demo images / Build & push demo images (push) Failing after 36s
directAppUrl(), the legacy open() path, and resolveRuntimeLaunchUrl()
now upgrade to https only for ports the app gate fronts — decided from
the signed catalog's embedded manifest ports (auth gated/open), so
plain-HTTP publishes (legacy installs, auth:none API ports like
Cuprate's RPC) keep http instead of failing outright. fetchAppCatalog()
merges the daemon-verified signed catalog into the App Store listing
(signed entries appear immediately; community copy supplies featured
and curated metadata), and Marketplace.vue uses the same dynamic fetcher
as Discover so the grid sees signed-new apps too.
2026-08-31 18:41:00 -04:00
archipelago 7c0a492c43 fix(ui): launch apps on the page's scheme over HTTPS
New-tab apps and the companion WebView got hardcoded http:// URLs, so a
node reached over HTTPS opened Vaultwarden, BTCPay, Grafana et al in
cleartext. Every app port is gate-owned and serves TLS on the same port
(appgate/tls.rs), so directAppUrl(), the legacy open() path, and
resolveRuntimeLaunchUrl() now follow the page's scheme. HTTP pages (the
kiosk, LAN) are unchanged; netbird keeps its unconditional https.
2026-08-31 17:08:26 -04:00
Archipelago b67e1527a2 Archipelago — open-source initial import 2026-08-12 10:55:50 +00:00