If you make a site with nostr login, just a friendly reminder that nip07 doesn't validate nsecs and a malicious extension can easily spoof the public key.

Reply to this note

Please Login to reply.

Discussion

Sooo.. private key login? 😱👀

No there is an http auth nip, 96 I think or 98

Perfect.. will look after it. Its important