Skip to content

feat(pairing): enter desktop codes on mobile - #8085

Open
klopez4212 wants to merge 2 commits into
mainfrom
kennylopez-pairing-code-container
Open

klopez4212 wants to merge 2 commits into
mainfrom
kennylopez-pairing-code-container

Conversation

@klopez4212

Copy link
Copy Markdown
Contributor

Summary

Enter the desktop’s six-digit code on mobile to complete pairing. Adds digit-only error shakes and native error haptics, a separate biometrics choice, and a direct community-icon loading/arrival animation.

Updates desktop instructions and removes confirmation clicks for compatible phones while preserving older clients. Fixes early pairing offers being lost during relay subscription startup.

Related issue

Related: #8060 (pairing connection failures); no duplicate code-entry PR found.

Testing

  • Full mobile and desktop checks/tests passed after merging main. Focused coverage: 78 core pairing, 5 desktop pairing, and 4 subscription helper tests.
  • Android build installed on Pixel; desktop QR/code handoff and mobile flow manually verified.
  • Full just ci blocked unpacking the speech dependency under local disk pressure; Rust pre-push lanes excluded. Hosted CI remains required.

…ntry

Signed-off-by: kenny lopez <klopez4212@gmail.com>
…de-container

Signed-off-by: kenny lopez <klopez4212@gmail.com>
@klopez4212
klopez4212 requested a review from a team as a code owner October 4, 2026 16:45
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T16:51:06.239800Z 530c3a4 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@klopez4212
klopez4212 deployed to codex-review October 4, 2026 16:45 — with GitHub Actions Active
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🔐 Codex Security Review

Note: This is an automated, security-focused review generated by Codex.
Use it as a supplement to human review; false positives are possible.

Scope

  • Exact PR diff: f0eb5575ffc9d5f57af4ed3f574529d997c83a0d...530c3a454ecf4808237ca566c515d3d5a10d59a9
  • Model: gpt-5.6-sol

💡 Click "edited" above to see earlier reviews for this PR.


Review Summary

Overall Risk: HIGH

The new code-entry pairing flow can release the desktop identity without proving that the user entered the displayed code.

Findings

[HIGH] Target-generated proof bypasses human SAS confirmation

  • Category: Auth
  • Location: desktop/src-tauri/src/commands/pairing.rs:425 (source)
  • Description: The accepted transcript hash is derived entirely from the QR session secret, public keys, and ECDH material already known to any scanning target. A malicious target can advertise code-entry and generate this proof immediately without seeing or entering the desktop's six-digit code. The desktop then automatically sends the identity payload without source-side approval.
  • Impact: Anyone who captures or photographs a pairing QR code can obtain the user's nsec and permanently control their identity, defeating the SAS confirmation that previously prevented unintended pairing.
  • Recommendation: Retain explicit desktop confirmation, or redesign code entry around a source-generated secret that the target cannot derive from the QR data, with a single-attempt authenticated response before releasing the payload.

Notes

  • No additional limitations were reported.

Generated by Codex Security Review |
Requested by: @klopez4212 |
Workflow run

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 530c3a454e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +425 to +429
match s.handle_target_sas_confirm(&event) {
Ok(proof) => {
let identity = payload.take().ok_or("Pairing payload missing")?;
let transfer = s.send_payload(PayloadType::Custom, identity)
.map_err(|e| e.to_string())?;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Retain source-side SAS confirmation before releasing identity

A target that captures the QR can advertise code-entry and compute this transcript proof itself: every hash input is either in the QR or derived from the target's own key, so the proof does not demonstrate that a person entered the desktop code. This branch then sends the desktop nsec without any desktop-side approval, allowing an attacker who photographs or copies the QR and wins the offer race to receive the identity. This removes the MITM gate explicitly described in crates/buzz-core/src/pairing/NIP-AB.md:316 and :545-551; retain explicit source confirmation or use a proof based on information the target cannot derive without the user's input.

Useful? React with 👍 / 👎.

Comment on lines +60 to +63
final route = ModalRoute.of(context);
if (route != null && route.isActive) {
Navigator.of(context).removeRoute(route);
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reset successful pairing state when dismissing the route

After an add-community or identity-recovery flow succeeds, this removes the route without resetting the non-auto-disposed pairingProvider, leaving it in PairingStatus.success. Reopening “Send to Desktop” then immediately removes the new route again, and removing the last community later returns to a root PairingPage whose new showLoading predicate renders only an endless loading surface, so the user cannot reach pairing controls until restarting the app. Reset the pairing state after the success handoff is consumed.

AGENTS.md reference: AGENTS.md:L257-L262

Useful? React with 👍 / 👎.

This branch was successfully deployed

1 active deployment
codex-review — 530c3a45 Deployed Oct 4, 2026 by klopez4212 via Run Codex Security Review #6780
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex-security-review-current The posted Codex security review matches its recorded range.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant