Skip to content

Security: Enforce idle-lock tracking during vault withdrawal - #32

Open
magqqgq wants to merge 1 commit into
p-11:mainfrom
magqqgq:magqqgq-patch-1
Open

magqqgq wants to merge 1 commit into
p-11:mainfrom
magqqgq:magqqgq-patch-1

Conversation

@magqqgq

@magqqgq magqqgq commented Aug 16, 2026

Copy link
Copy Markdown

This PR patches a HIGH severity session security vulnerability in the wallet frontend.

Key Changes:

Idle Lock Enforced: Changed the tracking policy for the signing-sensitive vault-withdraw screen from never to when-unlocked. This ensures that the wallet will correctly lock if the user is inactive during the withdrawal review and submission process.

Regression Testing: Added a test in use-session-timeout.test.ts to prove that withdrawal inactivity is explicitly tracked while the vault is unlocked, and untracked once locked.

This PR patches a HIGH severity session security vulnerability in the wallet frontend.

Key Changes:

Idle Lock Enforced: Changed the tracking policy for the signing-sensitive vault-withdraw screen from never to when-unlocked. This ensures that the wallet will correctly lock if the user is inactive during the withdrawal review and submission process.

Regression Testing: Added a test in use-session-timeout.test.ts to prove that withdrawal inactivity is explicitly tracked while the vault is unlocked, and untracked once locked.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant