2e2d96016e
The active identity drives the single live gift-wrap subscription and every send/display, and every identity redeems into the ONE shared grin balance. Switching reuses the rotate/import stop-wait-start machinery: it verifies the wallet password by unlocking the target BEFORE any teardown (a wrong password never strands the wallet with no running identity), gates on no in-flight send, tears down the service and stands a fresh one on the target key against the SAME shared store (so processed-dedup carries across and nothing double redeems), and moves only the active pointer (identity.json is never overwritten). The catch-up now looks back from when THIS identity last listened, so a payment that arrived while it was dormant is fetched and redeemed on switch-in; the service surfaces a syncing state and a count of payments redeemed during that catch-up for a "you were paid while away" cue. TxNostrMeta gains recipient_pubkey (serde-default empty = primary) to tag which front door a payment used, for per-identity activity and a later accounting split. Wallet gains nostr_identities / add_nostr_identity / switch_nostr_identity, init_nostr adopts the held-identity index with legacy migration, and a wallet-password change now re-encrypts every held identity through the same NIP-49 path. Only the active nsec is ever decrypted in memory; the rest stay encrypted at rest.