working on getting nsecbunker to create one-time-use tokens

you'll enter the generated token on a client and have a policy automatically apply to it the permissions the administrator has granted

here, a policy that just allows using DMs, but can't do anything else:

https://nostr.build/av/1acd661c0a267f3c859ce2cf1e9deadc1a4f5c2479f362d44a315df01d688dea.mov

Reply to this note

Please Login to reply.

Discussion

What do you use for front end stuff, react?

no, I hate react

I reluctantly use svelte because I haven't found anything less bad πŸ˜…

forever grateful to nostr:npub1chakany8dcz93clv4xgcudcvhnfhdyqutprq2yh72daydevv8zasmuhf02 for the tip

Yeah, that’s what I’ve heard too. Gonna try that next

Have you tried htmx?

never heard of it before but looks like it's not designed to build complex apps but rather to replace hotwire/stimulus, which doesn't really work for nostr

You should really name this app nsequestr.

πŸ€”

I will probably change the name but not sure what to yet

Zapped you, hopefully it went to the right address πŸ˜… I love love love what I’m seeing here btw πŸ”₯

Could this eventually allow for adding a nostr client to something like Hootsuite or Loomly for crossposting socials?

How does this work? Calls back to your server to sign?

Not to my server; to any server, like your umbrel or start9

πŸ‘€ Awesome! I can't wait, this is looking really good.

#[4]​ πŸ‘€

Exactly, but this model permits a level of granularity (and full-guarantee revocation!) that NIP-26 could never ever dream of allowing.

I am now doing single use tokens; copy a single code (or scan a QR code) and an entire preset policy is set for that application! πŸ™Œ

Do clients have to specifically add support for this though, just like NIP-26? That seemed to be a pain point for that NIP, getting support for it. If that's needed for nsecbunker, hopefully since it's much more powerful, we'll see wider support across the ecosystem.

No; that’s the beauty of it. No one has to support it (other than the application users want to use) no relay needs to change, no client needs to change.

I’ve been using it for over a month and no one had to do anything.

No one can even tell that I’m using it to write this very note! πŸ˜‚

Oh. Well, my Umbrel is ready. Hook a dude up.

#[4]​ β€˜s full guide coming out tomorrow (I took a long time to review it so my bad that it’s delayed!)

So am I good to go?