Remove noise service exposure; single-owner selection state

Transport callers no longer reach the raw NoiseEncryptionService:
getNoiseService() is deleted in favor of narrow purpose-named Transport
methods (session public key, identity fingerprint, static/signing keys,
sign/verify, callback installation). VerificationService now reaches
crypto through the transport, so it can no longer pin a stale service
across a panic reset. myPeerID/myNickname become private(set); the
existing setNickname mutator is the sole nickname path.

ConversationStore is now the sole owner of private-chat selection:
PrivateChatManager.selectedPeer is a published read-only mirror, and
startChat/endChat mutate through the store intent. The bridge method
and its five call sites are deleted, removing a latent bug where a
stale manager selection pushed back into the store could resurrect a
just-removed conversation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
jack
2026-06-11 15:29:07 +02:00
co-authored by Claude Fable 5
parent ed86ed1065
commit 8a867a17a1
16 changed files with 205 additions and 99 deletions
@@ -98,10 +98,13 @@ final class VerificationServiceTests: XCTestCase {
}
private func makeService() -> (VerificationService, NoiseEncryptionService) {
let noise = NoiseEncryptionService(keychain: MockKeychain())
// The service consumes Noise identity operations through the
// Transport's narrow noise* wrappers; the mock transport's backing
// encryption service is returned for direct assertions.
let transport = MockTransport()
let service = VerificationService()
service.configure(with: noise)
return (service, noise)
service.configure(with: transport)
return (service, transport.mockNoiseService)
}
private func makeSignedQR(