Author SHA1 Message Date
clawbot 860db6034c docs: README says why the wallet never clears the clipboard (closes #492)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
The owner's ruling on #19 is
now in the README, under ExportPrivKey: copying the key leaves it on the
clipboard, because the clipboard is the user's, clearing it would go
against what they expect, and it could destroy something else they
copied since. ShowRecoveryPhrase copies the phrase the same way and
points back to it. Both describe the warning each password screen
shows on next, which does not mention the clipboard.

Model: opus-5-5
2026-10-07 08:09:06 +02:00
2 changed files with 19 additions and 0 deletions
+11
View File
@@ -1510,6 +1510,14 @@ view would leave a wallet one click from deletion.
route, including the Settings gear. A decrypt still running when the screen is
left is discarded rather than written. The screen is not restorable, so
reopening the popup lands on Home rather than back on the key.
- **Clipboard**: tapping the key copies it to the clipboard, and the wallet
never clears the clipboard afterwards; leaving the screen wipes the key from
the page only. The clipboard is the user's, not the wallet's. Clearing it
would go against what the user expects, and by then they may have copied
something else vital that the clear would destroy. The user knows the key is
secret from the warning above the password input, which says that anyone with
it can access and transfer all funds from the address, and knows it is on the
clipboard because they copied it. From then on it is theirs to manage.
#### AddressToken (`address-token`)
@@ -1840,6 +1848,9 @@ view would leave a wallet one click from deletion.
gear. A decrypt still running when the screen is left is discarded rather than
written. The screen is not restorable, so reopening the popup lands on Home
rather than back on the phrase.
- **Clipboard**: tapping the phrase copies it, and the wallet never clears the
clipboard afterwards, for the reasons given under ExportPrivKey; here the
warning box above the password input is what tells the user it is secret.
#### DeleteWallet (`delete-wallet-confirm`)
+8
View File
@@ -45,6 +45,14 @@ but the review is broader than any of them.
# Completed Steps
- 2026-10-07: The README says that the wallet never clears the clipboard after
the private key or the recovery phrase is copied, and why
([#492](https://git.eeqj.de/sneak/AutistMask/issues/492)): the clipboard is
the user's, clearing it would go against what they expect, and it could
destroy something else they copied since. It is under ExportPrivKey, with a
line under ShowRecoveryPhrase, and names the warning each password screen
actually shows, which says nothing about the clipboard.
- 2026-10-07: The Firefox end-to-end suite no longer tolerates any uncaught
extension error ([#487](https://git.eeqj.de/sneak/AutistMask/issues/487)). Its
one entry, Firefox reporting a popup promise that settled after the page