core: wallet review fixes, and show the derived addresses

Concurrency: the account index is incremented in SQL and read back in the
same transaction, so two profiles cannot be handed the same key. Importing
a phrase is one transaction and single_seed is UNIQUE, so a phrase cannot
be discarded in favour of a key created meanwhile, and a device cannot end
up with two keys.

Wallet commands are no longer forwarded to a remote host: the recovery
phrase must not leave the device, and the raw command is logged there.

/wallet delete removes the key, confirmed by the last word of the phrase,
so creating a key before importing your own is no longer a dead end.

/wallet now shows every profile on the key with the first two name
addresses each, to check derivation against other wallets. Hidden profiles
are left out, as they are by /users. A bad phrase no longer says which word
was wrong. /wallet export uses the profile's own key.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
This commit is contained in:
Alain Brenzikofer
2026-09-09 09:05:47 +00:00
co-authored by Claude Opus 5
parent 257cdc02c8
commit ee11b368b6
13 changed files with 232 additions and 152 deletions
@@ -1538,7 +1538,8 @@ ALTER TABLE test_chat_schema.users ALTER COLUMN user_id ADD GENERATED ALWAYS AS
CREATE TABLE test_chat_schema.wallet_seeds (
wallet_seed_id bigint NOT NULL,
seed bytea NOT NULL,
next_account_index bigint DEFAULT 0 NOT NULL
next_account_index bigint DEFAULT 0 NOT NULL,
single_seed smallint DEFAULT 1 NOT NULL
);
@@ -1917,6 +1918,11 @@ ALTER TABLE ONLY test_chat_schema.wallet_seeds
ALTER TABLE ONLY test_chat_schema.wallet_seeds
ADD CONSTRAINT wallet_seeds_single_seed_key UNIQUE (single_seed);
ALTER TABLE ONLY test_chat_schema.xftp_file_descriptions
ADD CONSTRAINT xftp_file_descriptions_pkey PRIMARY KEY (file_descr_id);