diff --git a/README.md b/README.md index 3d666e7..317d142 100644 --- a/README.md +++ b/README.md @@ -1510,6 +1510,14 @@ view would leave a wallet one click from deletion. route, including the Settings gear. A decrypt still running when the screen is left is discarded rather than written. The screen is not restorable, so reopening the popup lands on Home rather than back on the key. +- **Clipboard**: tapping the key copies it to the clipboard, and the wallet + never clears the clipboard afterwards; leaving the screen wipes the key from + the page only. The clipboard is the user's, not the wallet's. Clearing it + would go against what the user expects, and by then they may have copied + something else vital that the clear would destroy. The user knows the key is + secret from the warning above the password input, which says that anyone with + it can access and transfer all funds from the address, and knows it is on the + clipboard because they copied it. From then on it is theirs to manage. #### AddressToken (`address-token`) @@ -1840,6 +1848,9 @@ view would leave a wallet one click from deletion. gear. A decrypt still running when the screen is left is discarded rather than written. The screen is not restorable, so reopening the popup lands on Home rather than back on the phrase. +- **Clipboard**: tapping the phrase copies it, and the wallet never clears the + clipboard afterwards, for the reasons given under ExportPrivKey; here the + warning box above the password input is what tells the user it is secret. #### DeleteWallet (`delete-wallet-confirm`) diff --git a/TODO.md b/TODO.md index 255c855..d33ad3b 100644 --- a/TODO.md +++ b/TODO.md @@ -45,6 +45,14 @@ but the review is broader than any of them. # Completed Steps +- 2026-10-07: The README says that the wallet never clears the clipboard after + the private key or the recovery phrase is copied, and why + ([#492](https://git.eeqj.de/sneak/AutistMask/issues/492)): the clipboard is + the user's, clearing it would go against what they expect, and it could + destroy something else they copied since. It is under ExportPrivKey, with a + line under ShowRecoveryPhrase, and names the warning each password screen + actually shows, which says nothing about the clipboard. + - 2026-10-07: The Firefox end-to-end suite no longer tolerates any uncaught extension error ([#487](https://git.eeqj.de/sneak/AutistMask/issues/487)). Its one entry, Firefox reporting a popup promise that settled after the page