mailship/test
Agent 40ac047629 Implement NIP-98 HTTP auth for GET/PUT/DELETE /subscription/email
Three browser-facing endpoints now require a kind-27235 HTTP auth event
(NIP-98) proving the caller controls the pubkey:

- GET  /subscription/email — pubkey extracted from auth header instead
       of query param; returns subscription for the authed pubkey.
- PUT  /subscription/email — pubkey extracted from auth header instead
       of trusting a client-supplied body field.
- DELETE /subscription/:key — verifies auth pubkey matches subscription
       owner (returns 403 if mismatch).

Server-side: decode base64 'Nostr <b64>' Authorization header, JSON.parse,
check kind === 27235, verifyEvent (nostr-tools/pure), then check u /
method / payload tags against the request URL / method / body.

README updated to reflect 'implemented' auth (not 'planned').
Integration test updated to generate NIP-98 auth headers via a new helper
script (script/nip98-auth-header.mjs).
2026-09-14 13:04:26 -04:00
..
cors.test.sh fix: scope CORS to browser routes only, require CORS_ORIGIN (fail closed) 2026-09-10 11:29:18 -04:00
digest-template.test.js fix(digest): replace hardcoded #7161FF with {{brandAccent}} 2026-09-10 11:23:31 -04:00
integration.sh Implement NIP-98 HTTP auth for GET/PUT/DELETE /subscription/email 2026-09-14 13:04:26 -04:00
normalize-relay-url.test.js test: add failing test for normalizeRelayUrl(undefined) crash 2026-08-25 09:29:29 -04:00
reschedule-on-frequency-change.test.js fix: reschedule cron job when confirmed subscriber changes frequency 2026-09-10 11:30:56 -04:00
web-ui.test.js fix: guard normalizeRelayUrl against undefined env var 2026-08-24 18:21:00 -04:00