From 447d714313e456e538c967aa1d2f6203c767d20c Mon Sep 17 00:00:00 2001
From: clawbot <35+clawbot@noreply.example.org>
Date: Wed, 7 Oct 2026 10:59:16 +0200
Subject: [PATCH] fix: show every password error in its own fixed-height line
(closes #493)
The add wallet screen reported a missing, short or mismatched password in
the flash line at the top of the popup, and the private key export,
recovery phrase and delete wallet screens each wrote to a line of their own
above the password field. All four now use showError() and hideError() with
a fixed-height error line below the field, as the send confirmation and
approval screens do. On the add wallet screen the line sits beside the
Import button, which keeps its place at 360x600. The line clears when the
screen is shown again and when the password is tried again. Other add
wallet messages stay in the flash line.
Model: opus-5-5
---
README.md | 19 +--
TODO.md | 13 ++
src/popup/index.html | 50 ++++----
src/popup/views/addWallet.js | 16 ++-
src/popup/views/deleteWallet.js | 27 +++--
src/popup/views/exportPrivkey.js | 25 ++--
src/popup/views/showPhrase.js | 27 +++--
tests/addressScanCancelled.test.js | 2 +
tests/deleteWalletLostPassword.test.js | 2 +-
tests/e2e/run.js | 115 +++++++++++++++++-
tests/exportPrivkey.test.js | 10 +-
tests/passwordErrorLines.test.js | 159 +++++++++++++++++++++++++
12 files changed, 386 insertions(+), 79 deletions(-)
create mode 100644 tests/passwordErrorLines.test.js
diff --git a/README.md b/README.md
index 317d142..bd10903 100644
--- a/README.md
+++ b/README.md
@@ -1444,14 +1444,17 @@ view would leave a wallet one click from deletion.
without it, the lost-password route on DeleteWallet is the first they
would hear of it. The hint line reserves its height, so switching tabs
cannot move the password fields under the pointer.
- - "Import" button
+ - "Import" button, with the error line beside it so that it adds no height
+ to a screen whose button already starts near the bottom of the popup
- **Transitions**:
- "Import" with a valid entry and a matching password of at least 12
characters → creates the wallet, clears the navigation stack, and →
**Home**. The phrase and xprv modes then scan for further used addresses
and report the count as a flash message.
- - "Import" with an invalid entry, a duplicate wallet or address, or a short
- or mismatched password → flash message, no screen change
+ - "Import" with a missing, short or mismatched password → full-sentence
+ error on the error line, no screen change
+ - "Import" with an invalid entry or a duplicate wallet or address → flash
+ message, no screen change
- "Back" → previous screen (Welcome, Home, or Settings)
#### AddressDetail (`address`)
@@ -1490,8 +1493,8 @@ view would leave a wallet one click from deletion.
copy)
- Warning that anyone holding the private key can transfer all funds from
the address
- - Error line
- - Password input and "Reveal" button, shown until the key is revealed
+ - Password input, error line and "Reveal" button, shown until the key is
+ revealed
- The private key on a highlighted background, tap to copy, shown only after
the password has been accepted
- **Transitions**:
@@ -1829,8 +1832,8 @@ view would leave a wallet one click from deletion.
- Wallet name
- Warning box stating that anyone holding these words can take everything in
the wallet, from any device, without the password
- - Error line
- - Password input + "Reveal" button, shown until the password is accepted
+ - Password input, error line and "Reveal" button, shown until the password
+ is accepted
- The recovery phrase itself, in full and click-to-copy, shown only after a
correct password and in place of the password prompt
- **Transitions**:
@@ -1859,8 +1862,8 @@ view would leave a wallet one click from deletion.
- "Back" button, "Delete Wallet" heading
- Warning naming the wallet and stating that deletion is permanent and any
funds are unrecoverable without the recovery phrase
- - Error line
- Password input
+ - Error line
- "Confirm Delete" button
- An underlined "I have lost my password" control
- **Transitions**:
diff --git a/TODO.md b/TODO.md
index 8924db6..1612ee4 100644
--- a/TODO.md
+++ b/TODO.md
@@ -44,6 +44,19 @@ then continue tagging as milestones land.
# Completed Steps
+- 2026-10-07: Every password error in the popup is shown the same way
+ ([#493](https://git.eeqj.de/sneak/AutistMask/issues/493)): with `showError()`
+ and `hideError()` in a fixed-height error line below the password field, as
+ the send confirmation and approval screens already did. The add wallet screen
+ showed a missing, short or mismatched password in the flash line, and the
+ private key export, recovery phrase and delete wallet screens each had a line
+ of their own above the field. On the add wallet screen the line sits beside
+ the Import button, so the button stays where it was at 360x600. Each line
+ clears when the screen is shown again and when the password is tried again.
+ The add wallet screen's other messages, such as an invalid recovery phrase, a
+ duplicate wallet and the address scan, stay in the flash line.
+ `tests/passwordErrorLines.test.js` drives all four screens in the popup.
+
- 2026-10-07: Pre-1.0 security review of the extension
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
`99292b9` for key handling, the DEBUG mode policy, and what the background
diff --git a/src/popup/index.html b/src/popup/index.html
index f92c9c5..3b853cc 100644
--- a/src/popup/index.html
+++ b/src/popup/index.html
@@ -207,12 +207,22 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
/>
-
+
+
+
+
+
@@ -396,10 +406,6 @@
Warning: anyone with this private key can access and
transfer all funds from this address. Never share it.
-
+
@@ -1116,10 +1126,6 @@
is permanent. Any
funds will be unrecoverable without your recovery phrase.
-