Commit Graph
13 Commits
Author SHA1 Message Date
Alain Brenzikofer 610610a73c scan for names owned by wallet 2026-09-22 15:58:26 +02:00
Alain Brenzikofer faa96e3da7 cut comments 2026-09-21 17:39:38 +02:00
Alain Brenzikofer 1c5ed7275d rename to adapt 2026-09-21 17:25:35 +02:00
Alain Brenzikofer 768a230f21 /goal iteration 5 - unconfirmed 2026-09-21 17:03:54 +02:00
Alain Brenzikofer bfc4e1fbaa /goal iteration 4 - unconfirmed 2026-09-21 14:42:34 +02:00
Alain BrenzikoferandClaude Opus 5 309358a162 core: names are the device's, so drop the per-profile account
A name's profile is the record it resolves to, not the key that owns it, so
the account level was carrying a mapping nothing needs. It was also the only
source of the profile to account ambiguity after a restore, of /_wallet
bind, and of the index gap and the refusal that told a visible profile an
account was held by one it cannot see. All of it goes.

Names sit in account 0 from index 1. Index 0 is left unused so neither the
names nor the profile accounts, which start at 1, claim the origin of both
dimensions. users gains no columns at all now, so the migration is one
CREATE TABLE.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-11 12:12:41 +00:00
Alain BrenzikoferandClaude Opus 5 3ad17ca477 core: pin simplexmq for the BIP-44 path, and use it
ethereumPath now takes the address index, so the path a name key sits at is
built once in the library rather than again here.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-10 16:29:06 +00:00
Alain BrenzikoferandClaude Opus 5 03b6ed9a53 core: drop the types nothing reads, and say account where it means account
AccountRef and WalletAccount were built and never read: deriveNameKey now
returns the key, and the address comes from addressFromPrivateKey, which
already exists. SeedId is a plain Int64 like every other row id here.

The master key is derived once per command rather than once per name key,
which is where PBKDF2 runs.

A device has a key and a profile has an account, so /_wallet says "no
account for this profile" rather than repeating "no wallet key", which is
what it says when the device has none.

Also: no "wallet: " in front of "bad chat command: ", strEncode for the
address, the repeated seed lookup in one place, comments cut to what the
code does not say, and the export test pins its addresses and secrets,
including one whose first byte is zero.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-10 13:45:48 +00:00
Alain BrenzikoferandClaude Opus 5 db1b6413e0 core: export the secret of a single name key
/_wallet export gives the seed mnemonic, /_wallet export <account> <name>
gives the secret of one derived key, so a single name can be handed over
without the seed. Both are what a wallet takes on import: the mnemonic as a
recovery phrase, the secret as hex.

The commands are named for what they return, APIWalletExportSeedMnemonic
and APIWalletExportDerivedSecret, as the difference is which secret leaves
the device.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-10 10:11:29 +00:00
Alain BrenzikoferandClaude Opus 5 e7f5908d01 core: name the unique index on wallet_seeds
The one key per device rule is meant to be lifted later. SQLite cannot drop
a column with an inline UNIQUE, or its automatic index, so lifting it would
have meant rebuilding the table. As a named index it is a DROP INDEX and a
DROP COLUMN.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-10 09:53:26 +00:00
Alain BrenzikoferandClaude Opus 5 70d4c128bd core: make the wallet an API, not a user-facing feature
Names commands will use the wallet; users do not. The commands move to
/_wallet, and the help section, its topic and the changelog entry are
removed. The tests drive the API end to end.

Comments cut to what the code does not say, dead exports removed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-09 14:00:25 +00:00
Alain BrenzikoferandClaude Opus 5 ee11b368b6 core: wallet review fixes, and show the derived addresses
Concurrency: the account index is incremented in SQL and read back in the
same transaction, so two profiles cannot be handed the same key. Importing
a phrase is one transaction and single_seed is UNIQUE, so a phrase cannot
be discarded in favour of a key created meanwhile, and a device cannot end
up with two keys.

Wallet commands are no longer forwarded to a remote host: the recovery
phrase must not leave the device, and the raw command is logged there.

/wallet delete removes the key, confirmed by the last word of the phrase,
so creating a key before importing your own is no longer a dead end.

/wallet now shows every profile on the key with the first two name
addresses each, to check derivation against other wallets. Hidden profiles
are left out, as they are by /users. A bad phrase no longer says which word
was wrong. /wallet export uses the profile's own key.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-09 09:05:47 +00:00
Alain BrenzikoferandClaude Opus 5 c11d0318c4 core: wallet key for name ownership (CLI only)
A name has to be owned by an address the client can still derive after a
restart or on a new device. This adds that key and nothing else.

/wallet create makes one BIP-39 key per device and one BIP-44 account per
chat profile under it, /wallet shows the address that would own the next
name that profile buys, /wallet import and /wallet export move the key with
its recovery phrase.

A name key sits at m/44'/60'/<profile>'/0/<name>, which is ordinary BIP-44,
so the phrase reaches the same addresses in other wallets. No signing, so
nothing can be bought or edited yet.

Split out of #7390 / #7425.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Rvc3HbiWBTqbAvRT45G5oX
2026-09-08 15:30:13 +00:00