Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CONCEPT.md
Original file line number Diff line number Diff line change
Expand Up @@ -319,6 +319,9 @@ WebAuthn Passkey (PRF extension)
1. Platform Passkey sync — iCloud Keychain, Google Password Manager, 1Password,
Bitwarden, hardware authenticator with sync
2. Optional explicit 12-word backup, shown once on sign-up, never sent to the server
3. Optional social recovery — guardians hold SLIP-39 shares of the same 128-bit
entropy. They do not hold the passkey. Specified in
[`docs/social-recovery.md`](./docs/social-recovery.md). Not implemented.

**The server never holds the nsec.** All NOSTR signing happens in the browser.

Expand Down Expand Up @@ -979,6 +982,7 @@ repository — they're intentionally not part of this project's scope.
| 2026-09-22 | Payments store USD/CHF/EUR/PHP at payment time. A USD stipend keeps the USD amount that was sent. |
| 2026-09-22 | A top-level forum note may store an optional place pin (latitude, longitude, label at most 80 characters). Replies cannot. Public JSON includes `place` only when set. `GET /messages/places` lists live top-level pins for a map. The label is not a kind:1 hashtag and is not the profile location. |
| 2026-09-24 | Initiator shares the moderator rank; permissions still name the minimum rank only. **Supersedes** the 2026-09-20 strict total order founder > moderator > verified > basis. |
| 2026-09-29 | Social recovery of the user-held seed is specified in docs/social-recovery.md and is not implemented. Guardians hold SLIP-39 shares of the frozen mnemonic-v1 entropy. They do not hold the passkey. The api must not be the source of the public keys those shares are encrypted to. Custodial nsecs are out of scope. |

## Next Steps

Expand Down
17 changes: 9 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -104,14 +104,15 @@ bun run e2e # Playwright against bun src/index.ts

## Documentation

| Doc | Purpose |
| -------------------------------------- | ------------------------------------------------------------------- |
| [`CONCEPT.md`](./CONCEPT.md) | Project vision, architecture, principles, decisions |
| [`SPEC.md`](./SPEC.md) | Implemented HTTP surface (request/response contracts) |
| [`FLOWS.md`](./FLOWS.md) | Core UI journeys (sign-in → profile → donate → recurring → message) |
| [`docs/handbook/`](./docs/handbook/) | Mandatory: every function and HTTP endpoint |
| [`CONTRIBUTING.md`](./CONTRIBUTING.md) | Dev setup, conventions, workflow |
| [`SECURITY.md`](./SECURITY.md) | Reporting vulnerabilities |
| Doc | Purpose |
| ------------------------------------------------------ | --------------------------------------------------------------------- |
| [`CONCEPT.md`](./CONCEPT.md) | Project vision, architecture, principles, decisions |
| [`SPEC.md`](./SPEC.md) | Implemented HTTP surface (request/response contracts) |
| [`FLOWS.md`](./FLOWS.md) | Core UI journeys (sign-in → profile → donate → recurring → message) |
| [`docs/social-recovery.md`](./docs/social-recovery.md) | Social recovery of the user-held seed (concept only, not implemented) |
| [`docs/handbook/`](./docs/handbook/) | Mandatory: every function and HTTP endpoint |
| [`CONTRIBUTING.md`](./CONTRIBUTING.md) | Dev setup, conventions, workflow |
| [`SECURITY.md`](./SECURITY.md) | Reporting vulnerabilities |

## License

Expand Down
1 change: 1 addition & 0 deletions SPEC.md
Original file line number Diff line number Diff line change
Expand Up @@ -5082,6 +5082,7 @@ exist on the account model; `GET /debug/accounts` and
## Out of scope for v1

- Passkey + PRF + NIP-06 user-owned keys (non-custodial phase)
- Social recovery of the user-held seed ([docs/social-recovery.md](docs/social-recovery.md)). Not a v1 route. Does not apply to the custodial nsec. No path in that document is reserved.
- Email/password login (or any second login method)
- Internationalization of api response text and push payloads (they stay English). A signed-in account may store `locale` and `fiat`; that is not translated copy.
- Platform custody of **receiver** funds (receiving stays LUD-16 only)
Expand Down
Loading
Loading