2 Commits
Author SHA1 Message Date
sneak a099221911 chore: prune landed remote branches (closes #167)
check / check (push) Canceled after 0s
e2e / e2e-chrome (push) Canceled after 0s
e2e / e2e-firefox (push) Canceled after 0s
Seventeen branches on origin that the issue classifies as landed, or
superseded by a merged pull request, were deleted; the evidence for each
is on the issue. Five whose work is not in next are kept: the three
issue 87 error-display branches and feature/show-private-key, reference
for issues 493 and 492, and chore/token-list-enrichment, re-created at
f7a2437, pending issue 495. TODO.md records this.

The branch-pruning Future Step had already left TODO.md in the issue 191
rewrite, so only the Completed Steps entry is added.

Model: opus-5-5
2026-10-07 06:14:42 +00:00
clawbot 860db6034c docs: README says why the wallet never clears the clipboard (closes #492)
check / check (push) Canceled after 0s
e2e / e2e-chrome (push) Canceled after 0s
e2e / e2e-firefox (push) Canceled after 0s
The owner's ruling on #19 is
now in the README, under ExportPrivKey: copying the key leaves it on the
clipboard, because the clipboard is the user's, clearing it would go
against what they expect, and it could destroy something else they
copied since. ShowRecoveryPhrase copies the phrase the same way and
points back to it. Both describe the warning each password screen
shows on next, which does not mention the clipboard.

Model: opus-5-5
2026-10-07 08:09:06 +02:00
2 changed files with 39 additions and 0 deletions
+11
View File
@@ -1510,6 +1510,14 @@ view would leave a wallet one click from deletion.
route, including the Settings gear. A decrypt still running when the screen is
left is discarded rather than written. The screen is not restorable, so
reopening the popup lands on Home rather than back on the key.
- **Clipboard**: tapping the key copies it to the clipboard, and the wallet
never clears the clipboard afterwards; leaving the screen wipes the key from
the page only. The clipboard is the user's, not the wallet's. Clearing it
would go against what the user expects, and by then they may have copied
something else vital that the clear would destroy. The user knows the key is
secret from the warning above the password input, which says that anyone with
it can access and transfer all funds from the address, and knows it is on the
clipboard because they copied it. From then on it is theirs to manage.
#### AddressToken (`address-token`)
@@ -1840,6 +1848,9 @@ view would leave a wallet one click from deletion.
gear. A decrypt still running when the screen is left is discarded rather than
written. The screen is not restorable, so reopening the popup lands on Home
rather than back on the phrase.
- **Clipboard**: tapping the phrase copies it, and the wallet never clears the
clipboard afterwards, for the reasons given under ExportPrivKey; here the
warning box above the password input is what tells the user it is secret.
#### DeleteWallet (`delete-wallet-confirm`)
+28
View File
@@ -45,6 +45,34 @@ but the review is broader than any of them.
# Completed Steps
- 2026-10-07: Stale branches pruned from `origin`
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
classifies each branch it lists, with the evidence. The seventeen still on
`origin` that it classifies as landed, or superseded by a merged pull request,
were deleted. `feat/message-signing` and `fix/59-transaction-view-ui-policies`
had been deleted on 2026-09-09; both landed and stay deleted. Five are kept
because their work is not in `next`: `fix/consistent-error-display`,
`fix/87-consistent-error-display` and `fix/87-consistent-error-display-v2`,
the change for [#87](https://git.eeqj.de/sneak/AutistMask/issues/87) that
never landed, as reference for
[#493](https://git.eeqj.de/sneak/AutistMask/issues/493);
`feature/show-private-key`, whose README clipboard policy section was the
reference for [#492](https://git.eeqj.de/sneak/AutistMask/issues/492); and
`chore/token-list-enrichment`, deleted on 2026-09-09 and re-created at
`f7a2437`, whose `scripts/` tooling waits on
[#495](https://git.eeqj.de/sneak/AutistMask/issues/495). Afterwards
`git ls-remote --heads origin` showed `main`, `next`, these five, and
`issue-167-prune-branches`, the head of
[#491](https://git.eeqj.de/sneak/AutistMask/pulls/491).
- 2026-10-07: The README says that the wallet never clears the clipboard after
the private key or the recovery phrase is copied, and why
([#492](https://git.eeqj.de/sneak/AutistMask/issues/492)): the clipboard is
the user's, clearing it would go against what they expect, and it could
destroy something else they copied since. It is under ExportPrivKey, with a
line under ShowRecoveryPhrase, and names the warning each password screen
actually shows, which says nothing about the clipboard.
- 2026-10-07: The Firefox end-to-end suite no longer tolerates any uncaught
extension error ([#487](https://git.eeqj.de/sneak/AutistMask/issues/487)). Its
one entry, Firefox reporting a popup promise that settled after the page