Repository navigation
fix: Report access-key permissions accurately - #154
Conversation
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
mattsse
left a comment
There was a problem hiding this comment.
Please address the inline finding.
| }); | ||
| return scopes; | ||
| function permissionMode(values: readonly unknown[] | undefined, semantics: 1 | undefined) { | ||
| if (semantics !== 1) return "unknown" as const; |
There was a problem hiding this comment.
With accounts@0.17.3 still pinned, the accounts/cli access-key creation and authorization update paths never persist permissionSemantics. A key created by tempo wallet login therefore reaches this branch with undefined, so keys and whoami report its permission modes as unknown rather than the permissions just recorded. Please bump accounts and the lockfile to a release containing tempoxyz/accounts#846 before merging.
0.19.0 includes tempoxyz/accounts#846, which records permissionSemantics on keys created or re-authorized through accounts/cli. It is younger than the 7-day minimumReleaseAge, so it gets a version-pinned exclusion like mppx@0.12.0 and viem@2.57.1.
Throwing from loadWalletState made one malformed limit or scope fail every command, including login and logout, with no recovery short of editing store.json. Drop the malformed entries as before and clear permissionSemantics for that key so its modes are reported as unknown.
updateSpendingLimit enables limit enforcement on the key and leaves other tokens and call scopes untouched, so the locally updated limits are still the complete spending set. Clearing permissionSemantics made keys and whoami report unknown modes after every keys update, even once accounts records the marker.
An omitted and an empty recipient list both allow any recipient on chain, and ox drops empty lists when decoding authorizations, so nearly every scope would have switched from [] to null. Report both as [] to keep the JSON output compatible.
This reverts commit 2bcbe6f.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Preserve omitted and empty limits/scopes through storage and display, and show unknown for ambiguous legacy records. Malformed stored permission entries are dropped and that key's permission modes are reported as unknown, so a bad entry cannot block wallet state from loading.
Bumps
accountsto 0.19.0, which includes tempoxyz/accounts#846 and recordspermissionSemanticson keys created or re-authorized throughaccounts/cli. 0.19.0 is younger than the 7-dayminimumReleaseAge, so it gets a version-pinned exclusion likemppx@0.12.0.keys updatekeeps the recorded semantics, sinceupdateSpendingLimitenables limit enforcement and leaves other tokens and scopes untouched. Scoperecipientsstays an array in JSON output; omitted and empty lists both mean any recipient on chain.Prompted by: @grandizzy