npub1z0โฆ08ldk on Nostr: 2026 Summer Stage 4 โ Amber Signer Login, Relay Cleanup & Login Hardening ๐ ...
2026 Summer Stage 4 โ Amber Signer Login, Relay Cleanup & Login Hardening
๐ Signer Login (Amber / NIP-46)
A new Signer tab in the Nostr login dialog supports cross-device pairing via NIP-46 (nostrconnect://). The NIP-46 flow is signer-agnostic, so it works with any remote NIP-46 signer โ Amber, Primal, nsec.app, Keys.band, etc. A QR code is shown for easy mobile scanning.
๐ Unified Signer Plumbing
Amber and nostrconnect logins are now wired into the shared signer utilities (useLoginActions, useCurrentUser, and signerUtils.getUserSigner()). Every existing code path that already used the unified signer for nsec, extension, or bunker logins now also works for signer-based logins. Several spots that still called window.nostr directly were updated to use the shared signer, including list utilities, dashboard Nostr utilities, post writing, and NIP-42 auth.
๐ Relay Cleanup
Stale relays were removed from all relay lists and fallbacks across the dashboard, including relay.damus.io and wss://relay.nostr.net. Default search and publish relays now consistently use wss://nos.lol and wss://relay.primal.net. The shared NPool is cached at module level so bunker and nostrconnect logins reuse a single connection pool instead of opening fresh WebSocket connections on every signer call.
๐ ๏ธ Android & Older WebView Compatibility
Added an AbortSignal.any() polyfill for older Android WebViews that don't support it, which previously broke every nostrconnect login with AbortSignal.any is not a function. The Signer tab also reorders the login options to promote the reliable NIP-46 flow first, while the NIP-55 on-device flow is clearly marked experimental because Chrome's IntentDispatcher doesn't always return the redirect after Amber approval.
๐ My Rooms Reliability
Fixed the My Rooms page rendering an empty list even when the signed-in user owned rooms. It now fetches kind 30312 events directly from the relay's /api/events endpoint and parses room fields from tags, avoiding the broken /api/rooms-by-pubkey route. Diagnostics were also added for unexpected response shapes so relay compatibility issues are visible instead of silently failing.
๐งช Testing & Infrastructure
Added a gsd-browser end-to-end test script that exercises Amber, nsec, and extension login plus signing round-trips against a local dev server. A scripts/BROWSER_TESTING.md guide documents what each test covers, how the transports are mocked, and the gotchas discovered while building the suite. A reverse proxy server was also added for public Amber testing routes.
๐งน Bug Fixes & Polish
- Fixed nostrconnect session race conditions and stale state when the login dialog is closed and reopened.
- Guarded all async login handlers against setState calls on unmounted components.
- Replaced the shared loading boolean with per-method loadingMethod state so a long Amber wait no longer disables the other login tabs.
- Deduplicated relay list constants and moved search relays to a single PUBLIC_SEARCH_RELAYS env variable.
- Added an accessible aria-label to the nostrconnect QR code.
- Restored the production start script and added start:proxy for the dev proxy server.
Special thanks to Contributors @Yeghro, @bitkarrot, Testers: @buttercuproberts, @DrShift, @Reed
#updates
Published at
2026-08-13 12:44:00 UTCEvent JSON
{
"id": "0d5f2ead50ebc6100b7c6ed3777f492092e819d0b2bf9d46732d4a71a6a0550b",
"pubkey": "13ff84142a6526245124c180fb5342cea130d558fec7d488019d1dae7aaca18a",
"created_at": 1786625040,
"kind": 1,
"tags": [],
"content": "2026 Summer Stage 4 โ Amber Signer Login, Relay Cleanup \u0026 Login Hardening\n\n๐ Signer Login (Amber / NIP-46)\n\nA new Signer tab in the Nostr login dialog supports cross-device pairing via NIP-46 (nostrconnect://). The NIP-46 flow is signer-agnostic, so it works with any remote NIP-46 signer โ Amber, Primal, nsec.app, Keys.band, etc. A QR code is shown for easy mobile scanning.\n\n๐ Unified Signer Plumbing\n\nAmber and nostrconnect logins are now wired into the shared signer utilities (useLoginActions, useCurrentUser, and signerUtils.getUserSigner()). Every existing code path that already used the unified signer for nsec, extension, or bunker logins now also works for signer-based logins. Several spots that still called window.nostr directly were updated to use the shared signer, including list utilities, dashboard Nostr utilities, post writing, and NIP-42 auth.\n\n๐ Relay Cleanup\n\nStale relays were removed from all relay lists and fallbacks across the dashboard, including relay.damus.io and wss://relay.nostr.net. Default search and publish relays now consistently use wss://nos.lol and wss://relay.primal.net. The shared NPool is cached at module level so bunker and nostrconnect logins reuse a single connection pool instead of opening fresh WebSocket connections on every signer call.\n\n๐ ๏ธ Android \u0026 Older WebView Compatibility\n\nAdded an AbortSignal.any() polyfill for older Android WebViews that don't support it, which previously broke every nostrconnect login with AbortSignal.any is not a function. The Signer tab also reorders the login options to promote the reliable NIP-46 flow first, while the NIP-55 on-device flow is clearly marked experimental because Chrome's IntentDispatcher doesn't always return the redirect after Amber approval.\n\n๐ My Rooms Reliability\n\nFixed the My Rooms page rendering an empty list even when the signed-in user owned rooms. It now fetches kind 30312 events directly from the relay's /api/events endpoint and parses room fields from tags, avoiding the broken /api/rooms-by-pubkey route. Diagnostics were also added for unexpected response shapes so relay compatibility issues are visible instead of silently failing.\n\n๐งช Testing \u0026 Infrastructure\n\nAdded a gsd-browser end-to-end test script that exercises Amber, nsec, and extension login plus signing round-trips against a local dev server. A scripts/BROWSER_TESTING.md guide documents what each test covers, how the transports are mocked, and the gotchas discovered while building the suite. A reverse proxy server was also added for public Amber testing routes.\n\n๐งน Bug Fixes \u0026 Polish\n\n- Fixed nostrconnect session race conditions and stale state when the login dialog is closed and reopened.\n- Guarded all async login handlers against setState calls on unmounted components.\n- Replaced the shared loading boolean with per-method loadingMethod state so a long Amber wait no longer disables the other login tabs.\n- Deduplicated relay list constants and moved search relays to a single PUBLIC_SEARCH_RELAYS env variable.\n- Added an accessible aria-label to the nostrconnect QR code.\n- Restored the production start script and added start:proxy for the dev proxy server.\n\nSpecial thanks to Contributors @Yeghro, @bitkarrot, Testers: @buttercuproberts, @DrShift, @Reed\n\n#updates",
"sig": "c9f4533b31ae86ad56f60f864530b5138ff62f9cbfa7ea2da0fd202021a4d800dc6532026c986a23e814d2b860831587d750b952790fb33cd8b8c403ccce6957"
}