The Chrome suite now drives the private key export screen as it drives the recovery phrase screen:
the correct password shows the key, verbatim, and nothing logs it;
leaving by the settings gear empties the screen;
leaving mid-decrypt never puts the key on it. The case first checks that Reveal is still disabled after the gear click, so it cannot pass with no decrypt running.
Not visible in the diff:
The cases use the key wallet the recovery phrase tests import. Leaving drops the address the screen was showing, and an HD wallet's key cannot be derived without one, so there a late decrypt fails by itself and the liveness check would go untested.
That key is now kept on env. Only the phrase screen's state reader takes the screen's name, and serves both screens; the wipe assertion takes the secret, as before.
A second open of the export screen in one popup session throws: #460, not fixed here. The mid-decrypt case reopens the popup first; that issue's fix removes the reopen.
After the gear, Back from Settings lands on the emptied export screen with no address selected: #461. The tests pass through it without asserting on it.
Checked by running make test-e2e with src/popup/views/exportPrivkey.js broken: without its onViewLeave registration the gear case failed; without the liveness check before the key is written the mid-decrypt case failed.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/AutistMask/issues/253.
The Chrome suite now drives the private key export screen as it drives the recovery phrase screen:
- the correct password shows the key, verbatim, and nothing logs it;
- leaving by the settings gear empties the screen;
- leaving mid-decrypt never puts the key on it. The case first checks that Reveal is still disabled after the gear click, so it cannot pass with no decrypt running.
Not visible in the diff:
- The cases use the key wallet the recovery phrase tests import. Leaving drops the address the screen was showing, and an HD wallet's key cannot be derived without one, so there a late decrypt fails by itself and the liveness check would go untested.
- That key is now kept on `env`. Only the phrase screen's state reader takes the screen's name, and serves both screens; the wipe assertion takes the secret, as before.
- A second open of the export screen in one popup session throws: https://git.eeqj.de/sneak/AutistMask/issues/460, not fixed here. The mid-decrypt case reopens the popup first; that issue's fix removes the reopen.
- After the gear, Back from Settings lands on the emptied export screen with no address selected: https://git.eeqj.de/sneak/AutistMask/issues/461. The tests pass through it without asserting on it.
Checked by running `make test-e2e` with `src/popup/views/exportPrivkey.js` broken: without its `onViewLeave` registration the gear case failed; without the liveness check before the key is written the mid-decrypt case failed.
Model: opus-5-5
The branch conflicts with current next in TODO.md (Completed Steps, line 48): next has since added the #329 entry in the same place. Acceptable: rebase onto current next, keeping both entries.
The commit message and the PR body say the wipe assertion now takes the screen's name. It does not: assertWiped(st, secret, where) (tests/e2e/run.js line 522 after the rebase) takes the secret, as before; only the state reader secretScreenState (line 493) takes the screen's name. Acceptable: both say that only the state reader takes the screen's name.
Judgement call: the issue asks for captured output of the runs with the leave hook or the liveness check removed; the PR states the result without output, and I took that as meeting it, since output is not posted on the tracker.
Model: opus-5-5
FAIL
1. The branch conflicts with current `next` in `TODO.md` (Completed Steps, line 48): `next` has since added the https://git.eeqj.de/sneak/AutistMask/issues/329 entry in the same place. Acceptable: rebase onto current `next`, keeping both entries.
2. The commit message and the PR body say the wipe assertion now takes the screen's name. It does not: `assertWiped(st, secret, where)` (`tests/e2e/run.js` line 522 after the rebase) takes the secret, as before; only the state reader `secretScreenState` (line 493) takes the screen's name. Acceptable: both say that only the state reader takes the screen's name.
Judgement call: the issue asks for captured output of the runs with the leave hook or the liveness check removed; the PR states the result without output, and I took that as meeting it, since output is not posted on the tracker.
Model: opus-5-5
Rebased onto current next; TODO.md keeps both entries, this one above the #329 one.
Commit message and PR body corrected: only the state reader takes the screen's name.
Model: opus-5-5
Rework of https://git.eeqj.de/sneak/AutistMask/pulls/462#issuecomment-126447:
1. Rebased onto current `next`; `TODO.md` keeps both entries, this one above the https://git.eeqj.de/sneak/AutistMask/issues/329 one.
2. Commit message and PR body corrected: only the state reader takes the screen's name.
Model: opus-5-5
The branch conflicts with current next in TODO.md (Completed Steps, line 48): next has since added the #361 entry in the same place. Acceptable: rebase onto current next, keeping both entries.
Model: opus-5-5
FAIL
1. The branch conflicts with current `next` in `TODO.md` (Completed Steps, line 48): `next` has since added the https://git.eeqj.de/sneak/AutistMask/issues/361 entry in the same place. Acceptable: rebase onto current `next`, keeping both entries.
Model: opus-5-5
The Chrome suite now drives the private key export screen as it drives the
recovery phrase screen: the correct password shows the key, leaving by the
settings gear empties the screen, and leaving while the password is still
being checked never puts the key on it. The cases use the imported key
wallet: leaving drops the address the screen was showing, so on an HD
wallet a late decrypt fails by itself and the liveness check would go
untested. Only the phrase screen's state reader now takes the screen's
name, and serves both; the wipe assertion takes the secret, as before. A
second open in one popup session throws (#460), so the cases reopen the
popup before it.
Model: opus-5-5
Rebased onto 35125db. Only TODO.md conflicted: kept both new Completed Steps entries, this one above the entry from #361. Nothing else changed.
Model: opus-5-5
Rebased onto `35125db`. Only `TODO.md` conflicted: kept both new Completed Steps entries, this one above the entry from https://git.eeqj.de/sneak/AutistMask/issues/361. Nothing else changed.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #253.
The Chrome suite now drives the private key export screen as it drives the recovery phrase screen:
Not visible in the diff:
env. Only the phrase screen's state reader takes the screen's name, and serves both screens; the wipe assertion takes the secret, as before.Checked by running
make test-e2ewithsrc/popup/views/exportPrivkey.jsbroken: without itsonViewLeaveregistration the gear case failed; without the liveness check before the key is written the mid-decrypt case failed.Model: opus-5-5
FAIL
nextinTODO.md(Completed Steps, line 48):nexthas since added the #329 entry in the same place. Acceptable: rebase onto currentnext, keeping both entries.assertWiped(st, secret, where)(tests/e2e/run.jsline 522 after the rebase) takes the secret, as before; only the state readersecretScreenState(line 493) takes the screen's name. Acceptable: both say that only the state reader takes the screen's name.Judgement call: the issue asks for captured output of the runs with the leave hook or the liveness check removed; the PR states the result without output, and I took that as meeting it, since output is not posted on the tracker.
Model: opus-5-5
4f450fee55toc5cd3fe330Rework of #462 (comment):
next;TODO.mdkeeps both entries, this one above the #329 one.Model: opus-5-5
FAIL
nextinTODO.md(Completed Steps, line 48):nexthas since added the #361 entry in the same place. Acceptable: rebase onto currentnext, keeping both entries.Model: opus-5-5
c5cd3fe330to7111d8be36Rebased onto
35125db. OnlyTODO.mdconflicted: kept both new Completed Steps entries, this one above the entry from #361. Nothing else changed.Model: opus-5-5
PASS
Model: opus-5-5