If you don't believe it or don't get it, I don't have the time to try to convince you, sorry.
Public Key
npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Profile Code
nprofile1qqsd4fqmakmgtyfk806yqlmg0juh38x9g0ksyjah0s3d9jzd3r65z5cpp4mhxue69uhkummn9ekx7mqpzemhxue69uhkummnw3ezuum5v94k27fwdejhgn3kfze
Show more details
Published at
2026-07-14T20:55:47Z Event JSON
{
"id": "250fd5aab96784f8f39dcc10740e73c29115298482bfc6d841e4a6a855512b24" ,
"pubkey": "daa41bedb68591363bf4407f687cb9789cc543ed024bb77c22d2c84d88f54153" ,
"created_at": 1784062547 ,
"kind": 0 ,
"tags": [],
"content": "{\"name\":\"Geek\",\"about\":\"If you don't believe it or don't get it, I don't have the time to try to convince you, sorry.\",\"lud16\":\"[email protected] \",\"nip05\":\"[email protected] \",\"picture\":\"https://i.nostr.build/9hBT56LGKiVNsw0H.webp\",\"display_name\":\"Geek\",\"website\":\"https://hello.geektoshi.tech/\",\"banner\":\"https://r2.primal.net/cache/0/57/40/05740b59efcc0f0a5ebff107fdc7393ec470ee82021309307f801b2117e70c34.jpg\",\"displayName\":\"Geektoshi\"}" ,
"sig": "bbbd27109fea4a5e73c7ae557cd9233507d0ae9faf72636772e2e41f10768fa49e639e9b400d171114c69f898655ba1d90a51f44f68afece4c222515cb6b1873"
}
Last Notes npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek primal currently sets a 4 digit pin so i kept their design choice but improved the encryption. if they want to do 6 digit pins, its just a single change in a few lines. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek you should know better lol
https://i.nostr.build/GUtwQdWJgudDovko.png npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek works npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i'm not here to argue, otherwise i'd still be on twitter 😃 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek fml lol npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek that's a fair clarification. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek again, just curious. it is up to projects, but i'm sure few if any thought about audits when they requested funding. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek https://i.nostr.build/Pm6j8Z53tfpUJBiq.gif npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek it's hard out here for a pimp 🤣 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek taking a week or two of not working on nostr projects to work on a thing for nostr projects 😂 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek nostr-station is awesome, and you're welcome npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek that thing is dead. feel free to use relay.nip46.com. i forked it from bunklay (which nsec.app used) with some improvements. source is open on my github if you want to run an instance yourself. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek honestly probably a relay issue not an amber issue npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek thank you, now following both. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek it's not and it does generate random IDs, but it's just unnecessary. the ID generated is a Uint8Array and breaks the 64 character limit of subscription IDs so it works, but it's not spec compliant. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek lol damn the clankers also make juice? to answer your questions, the old code used generatePrivateKey() to generate random IDs for things like images, highlights, relay subscriptions, which is just not a good practice to have a bunch of random private-key-like objects everywhere. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek 10000% npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek it is mitigation for both storage-at-rest and host leakage scenarios. it would not prevent an xss attack. the solution here is user-facing: use a trusted browser extension or bunker. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek I haven't used seedsigner, but seems like a good project so I donated some sats.
#nevent1q…skmq npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i'm not on the dirty bird, are they on nostr? npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek @npub1utx…50e8 if you decide this is worth merging (i submitted another this morning as well), let me know if you would like this ported over to Wisp. I haven't checked yet, but I would assume these would apply there as well. They're all pretty small fixes so no work at all. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek @npub1l5s…gx9z since we were discussing earlier npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Just opened a PR hardening how Primal's web app encrypts keys at rest which is a bit meatier than the one I submitted this morning.
Previously the PIN encrypted an nsec with a single unsalted SHA-256 hash of the PIN and unauthenticated AES-CBC. The PR upgrades this to PBKDF2 (600k iterations, random salt) and AES-256-GCM, which makes brute-forcing a stored blob drastically more expensive and makes wrong PINs fail cleanly. Existing users are migrated automatically on their next unlock, so nobody has to re-enter anything.
It also encrypts the NIP-46 client transport key, which was previously plaintext in localStorage, using a non-extractable WebCrypto key.
https://github.com/PrimalHQ/primal-web-app/pull/211 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i'm just a rando, but i think that just makes sense. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek curious...do you plan on performing security audits on all supported projects? npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Couple more Dark Wisp PRs...no issues found with key generation or storage, both properly encrypted 🎉
https://github.com/barrydeen/dark-wisp-android/pull/63
https://github.com/barrydeen/dark-wisp-android/pull/64 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Bruh, gross npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek I cosign this note npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek I am happy to be able to finally replace last cycle's "1. what" wiith this cycle's " runs" npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Lol you're asking for lot npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek This is why I only use email aliases npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek This is the way npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek @nprofile…9mdk and i chatted a bit about it. Biggest issue seems to be plaintext nsecs npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek So can we start taking security seriously or are we going to forget this as usual? npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Seems like ignorance and hubris to me npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek We should probably be defaulting to ncryptsec as well tbh npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek This is the exact PR I'm working on for primal now npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Went through about 8 Nostr projects in the past few days and at least for key generation, everything seems good. I know there's others doing similar work right now so if there are issues, i'm sure they'll pop up.
There are some issues with key handling afterwards, but at least generation is solid. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Totally agree npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek 1. What #nevent1q…d90n npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek key generation and storage looks good on Dark Wisp, so just a small security patch. Will send a bunker sign-in PR later this week.
https://github.com/barrydeen/dark-wisp-android/pull/62 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Yeah I did some reviews of primal's code the past couple days and finding the same. Sent them a PR and will probably do another. Gonna hit a few other apps as well this week. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Lol dude, this made me laugh so hard npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Its like that though unfortunatrly #nevent1q…ycq2 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Not from you. There's just a lot of things people hold to be truth because its been repeated enough that folks think that's how it is without ever verifying the claim or doing the work themselves. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Yeah this is an issue and apps are still doing nsec login npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Same, I hold no fiat. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek And bitcoin has no coins, wallets don't store anything, mining isn't extracting anything....it's an analogy to ecplainna concept npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek needed a break from working on my own stuff so pr'd primal
https://github.com/PrimalHQ/primal-web-app/pull/210 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek always has been npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Seed generation with dice. Not an endorsement of Bitbox, just a good guide.
https://bitbox.swiss/bitbox02/BitBox_Diceware_HowTo.pdf
https://bitbox.swiss/bitbox02/BitBox_Diceware_LookupTable.pdf npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek or apparently not even reading their own code for years... npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek totally fair npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek yeah i thought the question had shifted to this as well, but his main concern is still key generation. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek nothing can fix a key with insufficient entropy but a new key. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek hence "at best"...something like 1234 is 0 bits, and most would fall in the 6-8 bit range. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Will nostr freak out when they learn their debit card pin is only 13 bits of entropy at best? npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i mean if you never sign in via nsec you're mostly fine. browser and bunker signers essentially solve this as long as the app properly handles both nip specs. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek essentially yes. for nostr keys, the main point of attack is likely plaintext key storage and not entropy issues. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek you wouldn't be able to backtrace the key to determine if you had enough RNG.
if you used a webapp, it depends on if they're using something simple like Math.random or actually pulling entropy from the kernel (hopefully the latter). you don't need to say how you generated the key, but i plan on auditing a few just to verify (almost done with primal).
a lot of the ecosystem uses nostr-tools so the libraries used (@noble/curves for example) are sound and should at least in theory be 256-bit keys. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek that is the point though npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek the amount of misinformation disseminated by lack of understand is outstanding, but not the fault of users. cryptography is hard (on purpose). npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek depends on how you generated it npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek I wrote a NIP draft for "service announcements" which not just lets you check service status via Nostr events but opens up new usecases for devs and self-hosters.
1. Patch status across services
2. Autoconfiguration of clients
3. Services can easily find each other and communicate if needed
4. Simple deployment history
https://nips.pollerama.fun/nip/naddr1qvzqqqrcvypzpk4yr0kmdpv3xcalgsrldp7tj7yuc4p76qjtka7z95kgfky02s2nqy28wumn8ghj7un9d3shjtnyv9kh2uewd9hszrthwden5te0dehhxtnvdakqq9tnv4e8v6trv5kkzmnwda6kucm9d4jkuarn423sar npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek yikes, that's a bad look npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i get you 100%...i build all my own tools for this exact reason npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Every app needs FIPS...just got a dumb idea, let's see if it works... npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Satori 0.7.0 is out with some NIP compliance and performance improvements as well as an implementation of NIP-09 (event deletion requests)
https://github.com/Letdown2491/satori
https://github.com/Letdown2491/satori-startos
Also published Hanami 0.14.0 with a built-in audio player, and tons of performance and security improvements (Start9 packages coming next release).
https://github.com/Letdown2491/hanami npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek This is quite good
#naddr1qv…55nt npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Hanami 0.13.1 is out and is a mandatory security upgrade that adds key verification for users logging in via bunker URI.
This fixes an issue where Hanami trusted a signer held a key which could have led to user impersonation in multi-user instances (single-user mitigated by pubkey gating). Drives and private files are encrypted so their contents would never have been visible in the rare chance anyone was affected. Regardless, there's a security advisory in the repo with further details.
https://github.com/Letdown2491/hanami/releases/tag/v0.13.1 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Building Hanami 0.13.1...this will be a required upgrade. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Updating the Start9 box then taking a few days off...you guys are off the chain today. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek this is the kind of shitposting that makes nostr just the best
#nevent1q…cs46 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek If coldcard played dice maybe it wouldnt have happened. Sorry couldn't help myself 😎 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Spent some time looking at Nostr key generation last night...seems to be a non-issue if you're using something like nostr-tools with @noble/curves at least. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Nope...I'm a psycho multisig enjoyer npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek call the manager, maybe he can help npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek The Coldcard discussions sure have been entertaining...I bet the people complaining also think that "cold storage" means the bitcoin are only stored on your "wallet"...
Security and convenience are not mutually inclusive. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Good service provider getting better
#nevent1q…cxtc npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek congrats! love what you're doing with lnvps. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek just remember, StartOS 0.4.0+...it will not work on the 0.3 series and I have no plans to support it. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek I'd eat the hell out of that not gonna lie npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Sounds good I'll look in a bit npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Well I did a PR on the blossom test suite and released a new version of my blossom server so I failed already lol npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek gives me winamp meets cyberpunk vibes and i mean that in the most positive way possible. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek dude, this looks so good! npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i believe they do mayo on the corn pizza and it's apparently delicious npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Just released Hanami 0.13.0 with full blossom BUD compliance, tested using hzrd149/blossom-compliance (though we do skip a few optional items).
clients that probe before authenticating used to get a csrf 403 and give up. now they get the 401 they expect. /media and /list pagination work properly. BUD-08 NIP-94 metadata in descriptors. and BUD-11 tokens are bound to the server they were signed for, so a hostile server in your list cant replay them at you. Docker images are currently being built and will be available in the packages section shortly.
https://github.com/Letdown2491/hanami/releases/tag/v0.13.0 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek minds are clouded thinking their way fixes everything npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek I don't feel like doing anything today, GM. https://blossom.geektoshi.tech/6c94c5fe6faf8dd85d6dcac8f4076bf5b6717ecf0209bd9a0ea4e4fdc38edb82.jpg npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i was going to do a movie rewatch before Dune 3 came out, but your posts have inspired me to do a reread of the books before then. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek Part of it is that the blossom-compliance tool creates a temp key and if a server requires a whitelisted npub, some of the tests will fail. I submitted a PR to @npub1v0l…qj49 repo to allow an env to set an npub for testing. Other than that, just putting in the work to be spec compliant lol.
As for the peering, it's just a list of servers that don't get posted to the kind 10063 list. Each hanami instance gets assigned a random npub on first run (which makes FIPS peers possible for example), and you can set them up as backup-only (no public blob links, etc). Peers get added on each end so they communicate with each other.
Still plenty to do and document but most of it is in the readme and deployment docs already https://github.com/Letdown2491/hanami npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek It's at relay.nip46.com and is a fork of bunklay with some performance and security hardening fixes. Source below if you want to run your own and I have a Start9 package as well. I like the attribute fields idea, I'll chime in on the PR page.
https://github.com/Letdown2491/nip46-relay
https://github.com/Letdown2491/nip46-relay-startos npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek opened a PR to the blossom-compliance test suite so that tests can be run on blossom servers that whitelist npubs for access (like hanami or nostr.build for example)
https://github.com/v0l/blossom-compliance/pull/1 npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek basically yes.
what actually broke this before wasnt a missing endpoint. clients send an unauthenticated request first and use the 401 to know they should sign, and hanami was answering with a csrf 403 instead, so they just gave up. thats fixed. /media was broken every single time too, it redirected to /upload and the upload check threw out the clients media token. and /list ignored cursor and limit, so paging clients kept refetching the whole list.
worth knowing either way, hanami doesnt wait for a client to mirror. set redundancy_target and it keeps every blob on that many of your servers itself, verifies placement on a background scrub and refills whats missing.
fair warning, i tested against hzrd149s compliance suite, not against every client out there. so its spec correct, not a promise about any specific app. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek unfortunately won't help much as their gated to my npub. i have instructions on the hanami repo, and maybe i'll create a docker image with the built in sidecar sometime soon. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek yeah i would tend to agree, but everyone is free to do what they wish with their projects. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek that's the dev's call not mine lol. i'd happily take it over if asked, but went my own direction. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i have blossom servers running over fips...haven't seen tons of fips stuff yet though sadly. npub1m2jphmdkskgnvwl5gplksl9e0zwv2sldqf9mwlpz6tyymz84g9fsqr3wgu Geek i like it!