Skip to content

fix: Report access-key permissions accurately - #154

Merged
mattsse merged 9 commits into
mainfrom
centaur/report-access-key-permissions-20260928
Oct 1, 2026
Merged

mattsse merged 9 commits into
mainfrom
centaur/report-access-key-permissions-20260928

Conversation

@decofe

@decofe decofe commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Preserve omitted and empty limits/scopes through storage and display, and show unknown for ambiguous legacy records. Malformed stored permission entries are dropped and that key's permission modes are reported as unknown, so a bad entry cannot block wallet state from loading.

Bumps accounts to 0.19.0, which includes tempoxyz/accounts#846 and records permissionSemantics on keys created or re-authorized through accounts/cli. 0.19.0 is younger than the 7-day minimumReleaseAge, so it gets a version-pinned exclusion like mppx@0.12.0.

keys update keeps the recorded semantics, since updateSpendingLimit enables limit enforcement and leaves other tokens and scopes untouched. Scope recipients stays an array in JSON output; omitted and empty lists both mean any recipient on chain.

Prompted by: @grandizzy

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@grandizzy
grandizzy marked this pull request as ready for review September 28, 2026 17:21
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>

@mattsse mattsse left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please address the inline finding.

Comment thread src/commands/identity.ts
});
return scopes;
function permissionMode(values: readonly unknown[] | undefined, semantics: 1 | undefined) {
if (semantics !== 1) return "unknown" as const;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

With accounts@0.17.3 still pinned, the accounts/cli access-key creation and authorization update paths never persist permissionSemantics. A key created by tempo wallet login therefore reaches this branch with undefined, so keys and whoami report its permission modes as unknown rather than the permissions just recorded. Please bump accounts and the lockfile to a release containing tempoxyz/accounts#846 before merging.

0.19.0 includes tempoxyz/accounts#846, which records permissionSemantics
on keys created or re-authorized through accounts/cli. It is younger than
the 7-day minimumReleaseAge, so it gets a version-pinned exclusion like
mppx@0.12.0 and viem@2.57.1.
Throwing from loadWalletState made one malformed limit or scope fail every
command, including login and logout, with no recovery short of editing
store.json. Drop the malformed entries as before and clear
permissionSemantics for that key so its modes are reported as unknown.
updateSpendingLimit enables limit enforcement on the key and leaves other
tokens and call scopes untouched, so the locally updated limits are still
the complete spending set. Clearing permissionSemantics made keys and
whoami report unknown modes after every keys update, even once accounts
records the marker.
An omitted and an empty recipient list both allow any recipient on chain,
and ox drops empty lists when decoding authorizations, so nearly every
scope would have switched from [] to null. Report both as [] to keep the
JSON output compatible.
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedaccounts@​0.17.3 ⏵ 0.19.097 +1100100100 +2100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Recently published: npm accounts published 2 days ago

Location: Package overview

From: package.json → npm/accounts@0.19.0

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/accounts@0.19.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@mattsse mattsse left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@mattsse
mattsse merged commit fdd5e61 into main Oct 1, 2026
10 checks passed
@mattsse
mattsse deleted the centaur/report-access-key-permissions-20260928 branch October 1, 2026 00:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants