The lost-password delete screen asks the user to type the wallet's name back. Two gaps in that check:
A wallet named only with spaces compared equal to an empty field, so typing nothing would have deleted it. An empty field (or one holding only spaces or invisible characters) is now refused, whatever the wallet is called.
A zero-width space in a name was not removed before comparing, so the name could not be typed back. confirmKey() now first removes the characters src/shared/symbolSpoof.js already defines as painting nothing (INVISIBLE_CHARACTERS: \p{Cf}, \p{Default_Ignorable_Code_Point}, U+007F), on both sides.
What the diff does not make obvious: refusing an empty field would have made a name that shows nothing (only spaces, or only a zero-width space, which the rename field accepts today because trim() leaves U+200B alone) impossible to confirm. So displayName() now shows such a name as "Wallet N" on both delete screens, and that is what the user types back. The settings list and other screens still show the stored name as before.
README.md (DeleteWalletLostPassword) now describes the matching as the code does, including the inner-space collapsing it already did.
The five new tests fail against current next.
Judgement call: the "Wallet N" fallback for a name that shows nothing goes beyond the two listed fixes; without it, the empty-field refusal would leave such a wallet undeletable on this screen.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/AutistMask/issues/336.
The lost-password delete screen asks the user to type the wallet's name back. Two gaps in that check:
- A wallet named only with spaces compared equal to an empty field, so typing nothing would have deleted it. An empty field (or one holding only spaces or invisible characters) is now refused, whatever the wallet is called.
- A zero-width space in a name was not removed before comparing, so the name could not be typed back. `confirmKey()` now first removes the characters `src/shared/symbolSpoof.js` already defines as painting nothing (`INVISIBLE_CHARACTERS`: `\p{Cf}`, `\p{Default_Ignorable_Code_Point}`, U+007F), on both sides.
What the diff does not make obvious: refusing an empty field would have made a name that shows nothing (only spaces, or only a zero-width space, which the rename field accepts today because `trim()` leaves U+200B alone) impossible to confirm. So `displayName()` now shows such a name as "Wallet N" on both delete screens, and that is what the user types back. The settings list and other screens still show the stored name as before.
`README.md` (DeleteWalletLostPassword) now describes the matching as the code does, including the inner-space collapsing it already did.
The five new tests fail against current `next`.
Judgement call: the "Wallet N" fallback for a name that shows nothing goes beyond the two listed fixes; without it, the empty-field refusal would leave such a wallet undeletable on this screen.
Model: opus-5-5
A wallet named only with spaces compared equal to an empty field, so
typing nothing would have deleted it, and a zero-width space in a name
made the name impossible to type back.
An empty typed confirmation is now refused whatever the name is. The
characters src/shared/symbolSpoof.js already defines as painting nothing
are removed from both sides before comparing. A name that shows nothing
at all is shown on the delete screens as "Wallet N", so it can still be
typed back.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #336.
The lost-password delete screen asks the user to type the wallet's name back. Two gaps in that check:
confirmKey()now first removes the characterssrc/shared/symbolSpoof.jsalready defines as painting nothing (INVISIBLE_CHARACTERS:\p{Cf},\p{Default_Ignorable_Code_Point}, U+007F), on both sides.What the diff does not make obvious: refusing an empty field would have made a name that shows nothing (only spaces, or only a zero-width space, which the rename field accepts today because
trim()leaves U+200B alone) impossible to confirm. SodisplayName()now shows such a name as "Wallet N" on both delete screens, and that is what the user types back. The settings list and other screens still show the stored name as before.README.md(DeleteWalletLostPassword) now describes the matching as the code does, including the inner-space collapsing it already did.The five new tests fail against current
next.Judgement call: the "Wallet N" fallback for a name that shows nothing goes beyond the two listed fixes; without it, the empty-field refusal would leave such a wallet undeletable on this screen.
Model: opus-5-5
PASS
Model: opus-5-5