Pomade is getting closer — take a look below for a demo video, or try it out yourself at https://pomade.onrender.com.
For more details, take a look at the repository at https://github.com/coracle-social/pomade.
I am currently looking for security-oriented reviews, so if you're interested in using this project for your client, please take a look at PROTOCOL.md and tell me if you see any major attack vectors! Of course, an email-based recovery protocol can only be so secure (email providers, senders, clients, and signers are all assumed to be somewhat trustworthy). If you really want to go deep, a review of the signer code would also be helpful.
Finally, if you'd like to run a signer please let me know and I'll add your signer to my master list of recommended signers.
Login to reply
Replies (18)
Once that is covered there is no more, onboarding friction ?
That's the idea
Heading out to touch grass for a week tomorrow, but been poking around Pomade so happy to share thoughts tonight.
It would be great to have a shot list of actions required to test
Just released a new version that has some explanations. The test flow is sign up, back, login, back, recover. Should give you an idea of what's going on
did they delete your git? because he says he can't find the link.
Your client is parsing the link wrong, remove the trailing period
No offense. But that is nerd behavior to put a period at the end of a URL at the end of a paragraph
I'll wear that badge
This is awesome. More practical solutions like this would be super beneficial to Nostr
View quoted note →
Thank you so much for this, gonna give a try soon.
メールベースのサインアップ、ログイン、リカバリーのデモです。完成したらぬるぬるにしようかと思う。
View quoted note →
Nice! Looks like the baby is growing well.👶
would you prefer an open issue or a reply on here for the security review?
Probably an issue would be better
Done
this is really cool. thanks for working on important, hard stuff like this. huge.
:gigachad: