Files
n_os_tr/plans/upstream_nsigner_tickets.md

102 lines
3.9 KiB
Markdown

# Upstream Tickets for n_signer Integration
> Current snapshot for n-OS-tr integration status.
## T1: deny-by-default policy behavior
**Status:** CLOSED — implemented in `n_signer` v0.0.16
**Priority:** High (historical; now resolved)
**Description:**
`n_signer` now enforces deny-by-default behavior with explicit approval / preapproval rules, satisfying n-OS-tr's required safety model.
**Acceptance Criteria:**
- Requests without an allow decision are denied or require attended approval.
- No implicit auto-allow behavior remains for sensitive methods.
- Behavior is available in release v0.0.16.
**Where to File:**
Closed. No new ticket needed.
---
## T2: `--preapprove` CLI flag
**Status:** CLOSED — implemented in `n_signer` v0.0.16
**Priority:** High (historical; now resolved)
**Description:**
Boot-time preapproval rules are now supported via repeatable `--preapprove` CLI flags, removing the need for build-time patching for this function.
**Acceptance Criteria:**
- `--preapprove` is accepted at process startup.
- Multiple preapproval rules can be supplied.
- Rules apply to matching caller / method / nostr_index combinations.
- Feature is available in release v0.0.16.
**Where to File:**
Closed. No new ticket needed.
---
## T3: `get_secret_key` / `get_private_key` export method
**Status:** OPEN — critical-path blocker
**Priority:** Critical
**Description:**
Service daemons need raw 64-hex secret keys for signing and startup provisioning. The real key export JSON-RPC method is still missing upstream. Right now, `n-os-tr-get-key` usage has been relying on placeholder assumptions (including temporary `get_public_key`-based workflows in some integration paths), but this is not sufficient for real daemon key provisioning.
**Acceptance Criteria:**
- Add a JSON-RPC method named `get_secret_key` (or equivalent upstream-approved private-key export name).
- Method returns a 64-character lowercase hex secret key for an authorized nostr index / role.
- Method is policy-gated (no unconditional export).
- Method supports service-daemon provisioning use cases for non-user roles.
- Unauthorized callers and disallowed indices return explicit structured errors.
**Where to File:**
- Repository: `git.laantungir.net/laantungir/n_signer`
- Ticket title: **Add get_secret_key JSON-RPC method for service daemon key provisioning**
---
## T9: `--banner-prefix STRING`
**Status:** OPEN — UX nice-to-have
**Priority:** Medium
**Description:**
Add a banner prefix option so n-OS-tr can render explicit visual identification on tty1 (for example, `n-OS-tr SIGNER`) to reduce operator confusion between virtual terminals.
**Acceptance Criteria:**
- Add CLI option `--banner-prefix STRING`.
- Prefix appears consistently in the signer TUI/banner header.
- Option is optional and backward-compatible.
- Rendering remains stable across redraws.
**Where to File:**
- Repository: `git.laantungir.net/laantungir/n_signer`
- Ticket title: **Add --banner-prefix STRING for tty-specific signer identification**
---
## T11: `nostr_terminal` and `otp` signer socket support
**Status:** OPEN
**Priority:** High
**Description:**
CLI tools should sign through `n_signer` instead of managing their own key material. Both `nostr_terminal` and `otp` need first-class support for talking to the signer over its framed JSON-RPC socket.
**Acceptance Criteria:**
- `nostr_terminal` accepts `NOSTR_SIGNER_SOCKET` environment variable.
- `otp` accepts `NOSTR_SIGNER_SOCKET` environment variable.
- Both clients can speak n_signer's framed JSON-RPC protocol for `sign_event`.
- If signer is absent/unreachable, both clients fail or fall back gracefully (no crash, no hang loop).
- Existing non-signer workflows remain backward-compatible.
**Where to File:**
- `nostr_terminal` repository: `git.laantungir.net/laantungir/nostr_terminal`
- `otp` repository: `git.laantungir.net/laantungir/otp`
- Suggested ticket title (both repos): **Add NOSTR_SIGNER_SOCKET support and n_signer sign_event JSON-RPC integration**