The export private key (#btn-export-privkey-confirm) and delete wallet (#btn-delete-wallet-confirm) buttons are not disabled while the password is being verified asynchronously. This means a user could double-click and trigger multiple decrypt/delete operations.
By contrast, confirm-tx, approve-tx, and approve-sign all disable their buttons during processing.
Expected behavior
All buttons that trigger async password verification should be disabled (with text-muted class) during processing and re-enabled afterward.
## Problem
The export private key (`#btn-export-privkey-confirm`) and delete wallet (`#btn-delete-wallet-confirm`) buttons are not disabled while the password is being verified asynchronously. This means a user could double-click and trigger multiple decrypt/delete operations.
By contrast, `confirm-tx`, `approve-tx`, and `approve-sign` all disable their buttons during processing.
## Expected behavior
All buttons that trigger async password verification should be disabled (with `text-muted` class) during processing and re-enabled afterward.
## Files affected
- `src/popup/views/addressDetail.js` (export private key button handler)
- `src/popup/views/deleteWallet.js` (delete wallet button handler)
## Suggested fix
Add `button.disabled = true; button.classList.add("text-muted");` before the async operation and re-enable in a `finally` block.
Found during consistency audit for #78.
This is already fixed on main in commit 886cd38 ("fix: disable export-privkey and delete-wallet buttons during async processing"). Both btn-export-privkey-confirm and btn-delete-wallet-confirm now have button.disabled = true; button.classList.add("text-muted") before async operations with re-enable in finally/error paths.
Closing as resolved.
This is already fixed on `main` in commit 886cd38 ("fix: disable export-privkey and delete-wallet buttons during async processing"). Both `btn-export-privkey-confirm` and `btn-delete-wallet-confirm` now have `button.disabled = true; button.classList.add("text-muted")` before async operations with re-enable in `finally`/error paths.
Closing as resolved.
clawbot
removed their assignment 2026-02-28 22:28:20 +01:00
sneak
was assigned by clawbot2026-02-28 22:28:20 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
The export private key (
#btn-export-privkey-confirm) and delete wallet (#btn-delete-wallet-confirm) buttons are not disabled while the password is being verified asynchronously. This means a user could double-click and trigger multiple decrypt/delete operations.By contrast,
confirm-tx,approve-tx, andapprove-signall disable their buttons during processing.Expected behavior
All buttons that trigger async password verification should be disabled (with
text-mutedclass) during processing and re-enabled afterward.Files affected
src/popup/views/addressDetail.js(export private key button handler)src/popup/views/deleteWallet.js(delete wallet button handler)Suggested fix
Add
button.disabled = true; button.classList.add("text-muted");before the async operation and re-enable in afinallyblock.Found during consistency audit for #78.
This is already fixed on
mainin commit886cd38("fix: disable export-privkey and delete-wallet buttons during async processing"). Bothbtn-export-privkey-confirmandbtn-delete-wallet-confirmnow havebutton.disabled = true; button.classList.add("text-muted")before async operations with re-enable infinally/error paths.Closing as resolved.