Skip to content

walletStore.reset() clears in-memory state but never deletes the SecureStore secret #33

Description

@ndii-dev

reset() in src/store/walletStore.ts sets isOnboarded, publicKey, and balances back to defaults but never calls deleteSecretKey() from src/services/secureStorage.ts. Any future "log out"/"remove wallet" UI built naively on top of reset() will leave the actual secret key sitting in SecureStore indefinitely — a stale credential surviving a user's explicit "delete my wallet" action is both a privacy and security expectation violation.

Definition of done:

  • reset() (or a dedicated logoutAndWipe()) also deletes the SecureStore entry
  • Explicit distinction made (and enforced in code, not just comments) between "switch account / lock session" (keep secret) and "remove wallet" (wipe secret) — they must not share the same reset path
  • Test verifying getSecretKey() returns null after the wipe path

Before opening a PR for this issue, read CONTRIBUTING.md.

This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:

  • Root cause / design-decision rationale in your own words — not a restatement of this issue
  • Every Definition of done bullet above addressed explicitly, with a one-line note on how
  • Evidence the code actually runs: pasted test/build output, a screen recording or before/after screenshots for UI changes, or real (non-mocked) logs for network/contract-facing work
  • New or updated tests included and shown passing (paste the output)
  • Any adjacent/related behavior this issue calls out re-verified, not assumed unaffected

PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions