Skip to content

feat: block seed words extraction from view only wallets#7022

Merged
SWvheerden merged 1 commit intotari-project:developmentfrom
SWvheerden:sw_block_seed_words_extraction
May 5, 2025
Merged

feat: block seed words extraction from view only wallets#7022
SWvheerden merged 1 commit intotari-project:developmentfrom
SWvheerden:sw_block_seed_words_extraction

Conversation

@SWvheerden
Copy link
Copy Markdown
Collaborator

@SWvheerden SWvheerden commented May 5, 2025

Description

Block the extraction of seed words from wallets that don't have access to the correct seed words, which is view only wallets and hardware enabled wallets.

Summary by CodeRabbit

  • Bug Fixes
    • Exporting seed words is now restricted to supported wallet types only. Users with Hardware or View-only wallets will no longer be able to export seed words, and will receive an appropriate error message if they attempt to do so.

@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai bot commented May 5, 2025

Walkthrough

A validation step was introduced in the init_wallet function to restrict the export of seed words exclusively to wallets of type DerivedKeys. The function now checks the wallet type before attempting to export the seed words. If the wallet is not of type DerivedKeys (e.g., Hardware or View_only), it returns an error and halts the export process. No changes were made to the function's signature or to any public interfaces.

Changes

File(s) Change Summary
applications/minotari_console_wallet/src/init/mod.rs Added a check in init_wallet to prevent seed word export for non-DerivedKeys wallet types.

Sequence Diagram(s)

sequenceDiagram
    participant User
    participant init_wallet
    participant WalletDB

    User->>init_wallet: Request to export seed words
    init_wallet->>WalletDB: Query wallet type
    WalletDB-->>init_wallet: Return wallet type
    alt Wallet type is DerivedKeys
        init_wallet->>WalletDB: Retrieve seed words
        init_wallet->>User: Write seed words to file
    else Wallet type is not DerivedKeys
        init_wallet->>User: Return error "Cannot export seed words from a Hardware/View_only wallet"
    end
Loading

Poem

In the warren where secrets are kept,
Only DerivedKeys may their seed words accept.
Hardware and View_only, though clever and sly,
Must keep their seeds hidden, no export shall try.
With a hop and a check, the wallet stays neat—
Security first, for a rabbit’s retreat! 🐇✨


📜 Recent review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between a6c0199 and 18dd28b.

📒 Files selected for processing (1)
  • applications/minotari_console_wallet/src/init/mod.rs (1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms (7)
  • GitHub Check: test (mainnet, stagenet)
  • GitHub Check: test (nextnet, nextnet)
  • GitHub Check: ci
  • GitHub Check: test (testnet, esmeralda)
  • GitHub Check: cargo check with stable
  • GitHub Check: Cucumber tests / Base Layer
  • GitHub Check: Cucumber tests / FFI
🔇 Additional comments (1)
applications/minotari_console_wallet/src/init/mod.rs (1)

487-493: Excellent security enhancement to prevent unauthorized access to seed words.

The added validation check ensures that seed words can only be exported from wallets of type DerivedKeys. This effectively blocks the extraction of seed words from view-only wallets and hardware wallets, which should not have access to the seed words in the first place.

The implementation is clean and follows good practices:

  • It checks the wallet type before attempting to access seed words
  • It provides a clear error message to the user
  • It uses the existing error handling mechanism consistently

This change properly addresses the security concern mentioned in the PR objective.

✨ Finishing Touches
  • 📝 Generate Docstrings

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@github-actions
Copy link
Copy Markdown

github-actions bot commented May 5, 2025

Test Results (CI)

1 073 tests   1 068 ✅  12m 10s ⏱️
   30 suites      0 💤
    1 files        5 ❌

For more details on these failures, see this check.

Results for commit 18dd28b.

@github-actions
Copy link
Copy Markdown

github-actions bot commented May 5, 2025

Test Results (Integration tests)

 2 files   1 errors  9 suites   42m 6s ⏱️
18 tests 15 ✅ 0 💤 3 ❌
24 runs  15 ✅ 0 💤 9 ❌

For more details on these parsing errors and failures, see this check.

Results for commit 18dd28b.

@SWvheerden SWvheerden merged commit 510f6be into tari-project:development May 5, 2025
11 of 17 checks passed
@SWvheerden SWvheerden deleted the sw_block_seed_words_extraction branch May 6, 2025 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant