docs: README says why the wallet never clears the clipboard #494

Merged
clawbot merged 1 commits from issue-492-readme-clipboard into next 2026-10-07 08:09:07 +02:00
Collaborator

Puts the owner's ruling from #19 (comment) in the README, for #492.

  • ExportPrivKey gets a Clipboard item next to its secret handling. Tapping the key copies it, and the wallet never clears the clipboard. The clipboard is the user's: clearing it would go against what they expect, and it could destroy something vital they copied since. The warning above the password input is what tells the user the key is secret.
  • ShowRecoveryPhrase copies the phrase the same way (src/popup/views/showPhrase.js). It gets one line that points back to the ExportPrivKey item and names its own warning box.
  • TODO.md gets a Completed Steps entry.

Not visible in the diff: the old draft on feature/show-private-key said the warning tells the user that managing the clipboard is their job. Neither warning on next mentions the clipboard (src/popup/index.html). They say only that anyone with the key or the words can take the funds. The README describes them as they are.

Judgement call: the text is a labelled item inside the two screen entries rather than a new heading. That puts it where a reader of the private key export already is, and a heading there would look like another screen.

Model: opus-5-5

Puts the owner's ruling from https://git.eeqj.de/sneak/AutistMask/issues/19#issuecomment-5998 in the README, for https://git.eeqj.de/sneak/AutistMask/issues/492. - ExportPrivKey gets a **Clipboard** item next to its secret handling. Tapping the key copies it, and the wallet never clears the clipboard. The clipboard is the user's: clearing it would go against what they expect, and it could destroy something vital they copied since. The warning above the password input is what tells the user the key is secret. - ShowRecoveryPhrase copies the phrase the same way (`src/popup/views/showPhrase.js`). It gets one line that points back to the ExportPrivKey item and names its own warning box. - `TODO.md` gets a Completed Steps entry. Not visible in the diff: the old draft on `feature/show-private-key` said the warning tells the user that managing the clipboard is their job. Neither warning on `next` mentions the clipboard (`src/popup/index.html`). They say only that anyone with the key or the words can take the funds. The README describes them as they are. Judgement call: the text is a labelled item inside the two screen entries rather than a new heading. That puts it where a reader of the private key export already is, and a heading there would look like another screen. Model: opus-5-5
clawbot self-assigned this 2026-10-07 07:45:39 +02:00
clawbot added 1 commit 2026-10-07 07:45:39 +02:00
docs: README says why the wallet never clears the clipboard (closes #492)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
9477db3e91
The owner's ruling on #19 is
now in the README, under ExportPrivKey: copying the key leaves it on the
clipboard, because the clipboard is the user's, clearing it would go
against what they expect, and it could destroy something else they
copied since. ShowRecoveryPhrase copies the phrase the same way and
points back to it. Both describe the warning each password screen
shows on next, which does not mention the clipboard.

Model: opus-5-5
clawbot added the needs-review label 2026-10-07 07:45:48 +02:00
Author
Collaborator

PASS

Model: opus-5-5

PASS Model: opus-5-5
clawbot merged commit 860db6034c into next 2026-10-07 08:09:07 +02:00
clawbot deleted branch issue-492-readme-clipboard 2026-10-07 08:09:07 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/AutistMask#494