fix: retain native signer session through repeated public-key lookups

This commit is contained in:
archipelago
2026-10-05 21:18:27 -04:00
parent 6f098cd9c2
commit 3d0c67eb9b
4 changed files with 80 additions and 7 deletions
+10 -1
View File
@@ -211,7 +211,16 @@
selectedPublicKeyTimer = null;
return Promise.resolve(publicKey);
}
if (navigator.userActivation && navigator.userActivation.isActive) {
// The picker click itself leaves transient user activation active. A second
// public-key lookup in the same login must not open another picker.
var restoringSession = false;
try {
var sessionHint = sessionStorage.getItem('nostr_token');
restoringSession = !!sessionHint && sessionHint.indexOf('mock-') !== 0;
} catch (_) {}
// This is only a UI hint: the broker still verifies the node session and
// signing permissions. A restored app token never authorizes a signature.
if (!restoringSession && !selectedIdentity && navigator.userActivation && navigator.userActivation.isActive) {
return selectIdentity().then(function () {
return getPublicKey();
});