feat(pairing): enter desktop codes on mobile - #8085
klopez4212 wants to merge 2 commits into
Conversation
…ntry Signed-off-by: kenny lopez <klopez4212@gmail.com>
…de-container Signed-off-by: kenny lopez <klopez4212@gmail.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
🔐 Codex Security Review
Review SummaryOverall Risk: HIGH
Findings[HIGH]
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 530c3a454e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| match s.handle_target_sas_confirm(&event) { | ||
| Ok(proof) => { | ||
| let identity = payload.take().ok_or("Pairing payload missing")?; | ||
| let transfer = s.send_payload(PayloadType::Custom, identity) | ||
| .map_err(|e| e.to_string())?; |
There was a problem hiding this comment.
Retain source-side SAS confirmation before releasing identity
A target that captures the QR can advertise code-entry and compute this transcript proof itself: every hash input is either in the QR or derived from the target's own key, so the proof does not demonstrate that a person entered the desktop code. This branch then sends the desktop nsec without any desktop-side approval, allowing an attacker who photographs or copies the QR and wins the offer race to receive the identity. This removes the MITM gate explicitly described in crates/buzz-core/src/pairing/NIP-AB.md:316 and :545-551; retain explicit source confirmation or use a proof based on information the target cannot derive without the user's input.
Useful? React with 👍 / 👎.
| final route = ModalRoute.of(context); | ||
| if (route != null && route.isActive) { | ||
| Navigator.of(context).removeRoute(route); | ||
| } |
There was a problem hiding this comment.
Reset successful pairing state when dismissing the route
After an add-community or identity-recovery flow succeeds, this removes the route without resetting the non-auto-disposed pairingProvider, leaving it in PairingStatus.success. Reopening “Send to Desktop” then immediately removes the new route again, and removing the last community later returns to a root PairingPage whose new showLoading predicate renders only an endless loading surface, so the user cannot reach pairing controls until restarting the app. Reset the pairing state after the success handoff is consumed.
AGENTS.md reference: AGENTS.md:L257-L262
Useful? React with 👍 / 👎.
Summary
Enter the desktop’s six-digit code on mobile to complete pairing. Adds digit-only error shakes and native error haptics, a separate biometrics choice, and a direct community-icon loading/arrival animation.
Updates desktop instructions and removes confirmation clicks for compatible phones while preserving older clients. Fixes early pairing offers being lost during relay subscription startup.
Related issue
Related: #8060 (pairing connection failures); no duplicate code-entry PR found.
Testing
just ciblocked unpacking the speech dependency under local disk pressure; Rust pre-push lanes excluded. Hosted CI remains required.