Skip to content

fix: unlock no seed reveal#282

Open
ahmed-tarek-salem wants to merge 2 commits into
mainfrom
fix/unlock-no-seed-reveal
Open

fix: unlock no seed reveal#282
ahmed-tarek-salem wants to merge 2 commits into
mainfrom
fix/unlock-no-seed-reveal

Conversation

@ahmed-tarek-salem

Copy link
Copy Markdown
Contributor

No description provided.

sallymoc added 2 commits July 14, 2026 10:23
The 'Install commitlint' step ran 'yarn add conventional-changelog-conventionalcommits',
which now resolves to a version depending on @conventional-changelog/template@1.2.1
(requires Node >=22) and fails on the Node 20 runner. commitlint, config-conventional,
and conventional-changelog-conventionalcommits@^7 are already pinned in package.json/
yarn.lock, so 'yarn install --frozen-lockfile' covers them.
Unlock previously called revealSeed() (decrypting a seed to plaintext) just
to run a private/public key-match check and detect watch-only wallets. That
decrypted the user's first seed on every unlock, needlessly widening the
attack surface.

Replace it with WalletService.hasValidKeyPair(), which validates the key pair
internally and returns a boolean without ever returning or storing the
plaintext seed. Watch-only wallets are detected from metadata (isOnlyWatch)
with no decryption at all. Behavior is otherwise unchanged.

revealSeed() is now only called when a seed is genuinely needed (send, backup,
signing).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants