-
Notifications
You must be signed in to change notification settings - Fork 17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Allow probing for permissions #26
Comments
I just tested it and if I authorize the site in nos2x-fox for like 5 minutes, I can decrypt messages for 5 minutes without the popup being brought up. Just as intended. |
This is a feature request. noStrudel dev had it such that you had to click on each message to decrypt it and only recently added support to decrypt all messages at once and his reason was that he wants control over what his extension decrypts but that comes at the cost of a horrible UI for users that want messages to decrypt always. Currently the nip07 api does not allow the client dev to figure out if decrypt would open a popup or not but if there was, the client dev could decrypt by default if no popup was involved and show the "decrypt" button else. I |
Let me see if I understand it correctly: I'm guessing you're talking about the first scenario. |
The first, yes. I want NoStrudel to not show decrypt buttons if decrypt works non-interactively. |
I wonder if revealing this information to a site could have negative consequences. I mean, letting the site find out if I have authorized some action automatically. The site could take advantage of this. |
Yeah, I thought of that, too. The plugin could still track or even show what's going on so it could at least prevent it from happening secretly. Some toast "decrypted 12 messages" ... |
noStrudel does not decrypt messages automatically because its author prefers to not give the extension permanent decrypt permission. As most users probably give this permission it would be nice if the nostr client could detect this.
I thought there was maybe a hack one could do - cancel request if it doesn't resolve in 100ms - but I could not find a way to do that.
I think a boolean parameter could be used.
If
interactive
is set tofalse
, immediately throw an exception if the action is not permitted already.The text was updated successfully, but these errors were encountered: