docs: plan several profiles on a device, starting from what a profile is

The switch already exists as a state transition -- switchToWallet,
resetToSelector, a null identity sent to startup with popUpTo(0), every
collector a child of collectLatest -- and is reachable from nowhere: Landing
shows only when the device holds no identity, so a second can never be
added, and the profile tab's "change account" is a pending route. This plan
builds the two entrances and fixes what the transition gets wrong.

Before either, it changes one rule the two sign-in plans share. A seed's
nostr key is not written to the credentials file; it is derived from the
words at listing and from the running node at activation, and the writers
keep one key out of two files. That puts the wallet where the profile should
be: the list is a merge of two files with opposite ideas of what a row is,
and the node has to run for a profile to know its own key. Phase 1 makes a
profile a credential and a seed a wallet attached to one -- the credential
written when the seed is, repaired into the file for every seed already on
the device, merge inverted to list credentials and attach seeds by pubkey,
the identity's key read from the credential with the node's as a
cross-check, and a second refusal on forget for a key a seed derives. The
node still starts for a profile with a wallet attached, for the channel
watcher rather than for the key; making it lazy is now one branch and is
named as its own decision.

The other decision is that a switch is a restart of the signed-in graph,
not a swap under it: every route carries the key it was pushed for. That
settles the switcher as a pushed screen behind one tap, the previous node
stopped, the last-used profile as the one that opens on launch, and a
profile added from inside switched to.

Nine phases: the credential; the switch, with the relay observer that never
cancelled its predecessor and the node that kept running; the startup
precedence, which put "show me the list" above "open this one" and never
saved a default; the switcher, showing the nostr profile rather than
"Default name" and labelling a row with a wallet attached; the add rows,
where a profile created from inside is a bare key and not a second wallet,
and "end this" -- which wipes every profile's database -- goes; an owner on
the two fetch queues and an inbox sweep on activation, because a gift wrap
fetched under the other profile's key is stored and never opened again; the
exits; a round trip; rollout, with the one downgrade that lists a seed's
profile twice.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Pulled-From: curated/curated@a5ff264164
This commit is contained in:
Kgothatso Ngako
2026-09-13 00:09:02 +02:00
parent 5f2414dcb5
commit 44324c902b
2 changed files with 1192 additions and 0 deletions

View File

@@ -18,6 +18,7 @@ silent, or a decision that looked arbitrary and was not.
| [dead-code.md](./dead-code.md) | code in the sync and relay stack that nothing calls, why each piece is still there, and which of it is a bug rather than a leftover |
| [nsec-sign-in.md](./nsec-sign-in.md) | signing in with an existing nostr key — why an nsec can never have a wallet behind it, the ten call sites that make it small, and the sign-in machine that was already built and unreachable |
| [npub-sign-in.md](./npub-sign-in.md) | signing in with only a public key — what a key that cannot sign can still see here, why that is a preview rather than a browser, and the four decisions the word settles |
| [multiple-profiles.md](./multiple-profiles.md) | several profiles on one device — why a profile is a credential and a seed is a wallet attached to one, why a switch is a restart rather than a swap, the two entrances the app lacks, and the inbox a switch would silently lose |
| [jvm-target.md](./jvm-target.md) | what desktop support cost, phased — why the native chain was already done, why an empty source set in our phoenix fork was the real blocker, and why DAO tests need none of it |
| [material-design-conformance.md](./material-design-conformance.md) | what the M3 foundations actually require, measured against all 43 screens — the colour pairing that renders the app's own proposals invisible, and eight phases that put the decisions back in the theme |
| [curated-to-mantra.md](./curated-to-mantra.md) | pulling the Curated fork's thirty-nine commits back under Mantra's names — which lines of work to take, the three decisions, and a measured way to replay a twice-rebranded history without touching seven hundred files by hand |
@@ -57,3 +58,8 @@ The npub sign-in note is a phased plan that has been built, and reads as that
plan's out-of-scope note answered: it takes the `Identity` type and the sign-in
machine as given and asks what an identity with no secret is for, before it asks
how to build one; read its table of where the build chose differently first.
The multiple-profiles note is a phased plan that has not been built, and reads as
the third of the sign-in notes: it asks what happens when the device holds two
identities, and its first phase changes one rule the other two share — a seed's
key becomes a credential like any other — so read it with `StoredIdentity.merge`,
`SovereignWalletViewModel.switchToWallet` and the startup screen open.

1186
docs/multiple-profiles.md Normal file

File diff suppressed because it is too large Load Diff