Skip to content

CON-13: say once what an npub costs, before the first revision - #84

Open
molgerz wants to merge 2 commits into
mainfrom
feat/con-13-npub-onboarding-notice
Open

molgerz wants to merge 2 commits into
mainfrom
feat/con-13-npub-onboarding-notice

Conversation

@molgerz

@molgerz molgerz commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Closes CON-13.

What an npub costs, said once, before the first revision is written under it.

What is in it

  • PseudonymNotice is a dialog on the first sign-in with a given npub: everything signed stays linked to it forever, publishing cannot reliably be undone, and a private space restricts access rather than encrypting.
  • Acknowledgement is stored per npub, not per browser — a second person on the same machine, or a deliberately unlinked second pseudonym, has been told nothing.
  • It appears on a resumed session too, not only on a fresh login(): the question the storage answers is "has this npub been told".
  • Escape defers, it does not acknowledge. The app has one warning per npub to spend and Escape is the reflex for making dialogs disappear, so it only postpones the notice until the next load; only "I understand" records it. For the same reason the button no longer takes focus — one Enter is as reflexive as one Escape.
  • While the dialog is up, the rest of the shell is inert: aria-modal without that is a claim the page does not honour, and Ctrl/Cmd+K would otherwise put the caret in a search field hidden under the backdrop.

How to test

  1. Clear site data, sign in: the dialog appears before anything can be written.
  2. Press Ctrl/Cmd+K and Tab a few times while it is up — focus stays in the dialog, the search field behind it is unreachable.
  3. Press Escape, then reload: the dialog is back. Nothing was spent.
  4. Click "I understand", reload: it stays away.
  5. Sign in with a second npub in the same browser: it appears again for that npub.
  6. With a screen reader (or the accessibility inspector): the dialog itself takes focus and is described by its body text.

Automated: typecheck, lint, tests and build are green.

M and others added 2 commits September 14, 2026 14:08
docs/09 has always stated it and always ended with "there is no onboarding
page yet": an npub is a permanent pseudonym, everything written under it is
linkable across relays, and for a team where npubs map to real names that is
a public activity history.

`PseudonymNotice` says it as a dialog on the first sign-in with a given npub —
three sentences: what is signed stays linked to the npub forever, publishing
cannot reliably be undone, and a private space restricts access rather than
encrypting. A dismissible banner under the top bar was the cheaper option and
is exactly what that paragraph rules out; a strip that can be scrolled past is
the fine print.

Acknowledgement is stored per npub, not per browser. A browser is not an
identity: a second person on the same machine, or the same person starting a
deliberately unlinked second pseudonym, has been told nothing. It also shows
on a resumed session, not only on a fresh login() click — the question the
storage answers is "has this npub been told", and anyone already signed in
when this ships has not been.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…l goes inert

The app has exactly one warning per npub to spend, and Escape was spending it.
Escape is the trained reflex for making a dialog go away, so it now only defers
the notice until the next load; only "I understand" records the npub as told.
For the same reason the button no longer takes focus on open — one Enter on a
focused button is as reflexive as one Escape. The dialog itself takes focus and
is described by its body, so a screen reader reads the three sentences.

While the dialog is up, everything behind it is `inert`. `aria-modal` without
that is a claim the page does not honour, and concretely the top bar's
Ctrl/Cmd+K would put the caret in a search field hidden under the backdrop.
The state moved into `usePseudonymNotice` beside the storage, because both the
dialog and the shell need it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant