reset() in src/store/walletStore.ts sets isOnboarded, publicKey, and balances back to defaults but never calls deleteSecretKey() from src/services/secureStorage.ts. Any future "log out"/"remove wallet" UI built naively on top of reset() will leave the actual secret key sitting in SecureStore indefinitely — a stale credential surviving a user's explicit "delete my wallet" action is both a privacy and security expectation violation.
Definition of done:
reset() (or a dedicated logoutAndWipe()) also deletes the SecureStore entry
- Explicit distinction made (and enforced in code, not just comments) between "switch account / lock session" (keep secret) and "remove wallet" (wipe secret) — they must not share the same reset path
- Test verifying
getSecretKey() returns null after the wipe path
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.
reset()insrc/store/walletStore.tssetsisOnboarded,publicKey, andbalancesback to defaults but never callsdeleteSecretKey()fromsrc/services/secureStorage.ts. Any future "log out"/"remove wallet" UI built naively on top ofreset()will leave the actual secret key sitting in SecureStore indefinitely — a stale credential surviving a user's explicit "delete my wallet" action is both a privacy and security expectation violation.Definition of done:
reset()(or a dedicatedlogoutAndWipe()) also deletes the SecureStore entrygetSecretKey()returns null after the wipe pathBefore opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.