From c049ecb6a87913e28415d321713db3f607b445ae Mon Sep 17 00:00:00 2001 From: Jon Staab Date: Wed, 13 Nov 2024 09:51:55 -0800 Subject: [PATCH] Accept ack responses in nip46 initiate --- packages/signer/src/signers/nip46.ts | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/packages/signer/src/signers/nip46.ts b/packages/signer/src/signers/nip46.ts index 1b01159..81ea960 100644 --- a/packages/signer/src/signers/nip46.ts +++ b/packages/signer/src/signers/nip46.ts @@ -99,6 +99,11 @@ export class Nip46Broker extends Emitter { if (response?.result === secret) { complete(pubkey) } + + if (response?.result === 'ack') { + console.warn("Bunker responded to nostrconnect with 'ack', which can lead to session hijacking") + complete(pubkey) + } }, })