secureStorage.ts's saveSecretKey always calls SecureStore.setItemAsync against the same fixed key with no existing-value check. Combined with the create/import screens both calling it, a user who navigates back to /auth/create after already onboarding (e.g. via a deep link, or a stale navigation stack after the missing-persistence bug in a related issue) can silently destroy access to their original address by generating a new one over it, with zero confirmation step.
Definition of done:
saveSecretKey (or its callers) refuses to overwrite an existing secret without an explicit, scary, confirmed "replace wallet" step
- Covers both the create and import entry points
- Test asserting an existing secret survives an accidental re-entry into either screen
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.
secureStorage.ts'ssaveSecretKeyalways callsSecureStore.setItemAsyncagainst the same fixed key with no existing-value check. Combined with the create/import screens both calling it, a user who navigates back to/auth/createafter already onboarding (e.g. via a deep link, or a stale navigation stack after the missing-persistence bug in a related issue) can silently destroy access to their original address by generating a new one over it, with zero confirmation step.Definition of done:
saveSecretKey(or its callers) refuses to overwrite an existing secret without an explicit, scary, confirmed "replace wallet" stepBefore opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.