Phase 7 of docs/npub-sign-in.md.
NpubPreviewRoundTripJvmTest is the nsec round trip with the repository
made real: an in-memory database under the app's own DAOs, because the
assertion this exists for is about what is not in it. An npub is signed in
the way the sign-in screen does it, listed the way startup does, activated
as a read-only identity, and handed to NavigationViewModel: it lands on
UnqueuedProfileSynchronization. The kind 0 the relays would answer with is
indexed through the read-only key pair: ProfileLoaded. And with the real
NotaryViewModel watching the same rows for longer than its key package
delay, nothing was signed -- the only unsigned row for the pubkey is the
placeholder, still at genesis; nothing is queued for a signature; no key
package bundle; no broadcast request; no node.
The contrast that makes those assertions worth having: the same harness
as a signing identity does sign -- the notary makes a key package bundle
within its delay. Without it, "nothing was signed" could be true of a
harness in which nothing can be signed.
Then the upgrade: the nsec of the key held read-only signs in over it
through the same view model, under the same id, leaving one credential
that is now a secret, one listed identity, and one account -- the second
sign-in planted nothing.
The full jvm suites pass: 988 in the app, 159 in the library.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Pulled-From: curated/curated@315e93315a