No it is not safe to let a browser touch your private keys! Ever!
The good news is that they don't need to. They can simply send a message to be signed.
For Nostr this is defined in NIP-46 and a number of signing apps are in development. Your Nostr PWA just needs a 'sign in' button, you can then choose (using a trusted app) which acount to log in with, and what permissions to grant.
No it is not safe to let a browser touch your private keys! Ever!
The good news is that they don't need to. They can simply send a message to be signed.
For Nostr this is defined in NIP-46 and a number of signing apps are in development. Your Nostr PWA just needs a 'sign in' button, you can then choose (using a trusted app) which acount to log in with, and what permissions to grant.