What changed, and why it matters
This commit adds fallback logic so that if a backup password is missing from secure storage, a new one is automatically generated. It also bumps app version numbers. The change looks like a defensive hardening fix: previously, code assumed the backup password was always present (using a force-unwrap `!`), which could crash or behave unpredictably if the value was absent. The patch replaces that assumption with a safe default and automatic regeneration.
Review the `generateBackupPassword` implementation to confirm it creates a sufficiently strong, unique password and writes it atomically to secure storage. Verify that downstream backup encryption uses the regenerated password correctly and does not leave stale or unencrypted backup files behind.
Security signals we found
Removal of null-force-unwrap on sensitive storage read
Automatic regeneration of missing backup password
Defensive null/empty sanity check on backup password
Version bump suggesting release packaging
Evidence from the diff
In backup_view_model.dart the commit removes the force-unwrap (await secureStorage.read(key: key))! and instead defaults to an empty string, then calls generateBackupPassword(secureStorage) if the password is empty. A similar check is added in edit_backup_password_view_model.dart. Unused imports are cleaned up. scripts/macos/app_env.sh is updated to versions 5.6.5 and build numbers 73/140. There is no explicit security disclosure or attribution in the commit materials.
Changed components
lib/view_model/backup_view_model.dartlib/view_model/edit_backup_password_view_model.dartscripts/macos/app_env.shInspect captured patch +13 / −8
diff --git a/lib/view_model/backup_view_model.dart b/lib/view_model/backup_view_model.dart
index d9adb1b6..ad066d37 100644
--- a/lib/view_model/backup_view_model.dart
+++ b/lib/view_model/backup_view_model.dart
@@ -1,17 +1,15 @@
import 'dart:io';
-import 'package:cake_wallet/core/backup_service.dart';
import 'package:cake_wallet/core/backup_service_v3.dart';
import 'package:cake_wallet/core/execution_state.dart';
import 'package:cake_wallet/core/secure_storage.dart';
+import 'package:cake_wallet/entities/default_settings_migration.dart' show generateBackupPassword;
import 'package:cake_wallet/entities/secret_store_key.dart';
import 'package:cake_wallet/view_model/edit_backup_password_view_model.dart';
import 'package:cw_core/root_dir.dart';
import 'package:cw_core/utils/print_verbose.dart';
-import 'package:flutter/foundation.dart';
import 'package:mobx/mobx.dart';
import 'package:intl/intl.dart';
import 'package:cake_wallet/wallet_type_utils.dart';
-import 'package:path_provider/path_provider.dart';
part 'backup_view_model.g.dart';
@@ -60,7 +58,10 @@ abstract class BackupViewModelBase with Store {
@action
Future<void> init() async {
final key = generateStoreKeyFor(key: SecretStoreKey.backupPassword);
- backupPassword = (await secureStorage.read(key: key))!;
+ backupPassword = (await secureStorage.read(key: key)) ?? '';
+ if (backupPassword.isEmpty) {
+ generateBackupPassword(secureStorage);
+ }
}
@action
diff --git a/lib/view_model/edit_backup_password_view_model.dart b/lib/view_model/edit_backup_password_view_model.dart
index 69a3988f..9c672c61 100644
--- a/lib/view_model/edit_backup_password_view_model.dart
+++ b/lib/view_model/edit_backup_password_view_model.dart
@@ -1,4 +1,5 @@
import 'package:cake_wallet/core/secure_storage.dart';
+import 'package:cake_wallet/entities/default_settings_migration.dart' show generateBackupPassword;
import 'package:mobx/mobx.dart';
import 'package:cake_wallet/entities/secret_store_key.dart';
@@ -28,6 +29,9 @@ abstract class EditBackupPasswordViewModelBase with Store {
Future<void> init() async {
final key = generateStoreKeyFor(key: SecretStoreKey.backupPassword);
final password = (await secureStorage.read(key: key)) ?? '';
+ if (backupPassword.isEmpty) {
+ generateBackupPassword(secureStorage);
+ }
_originalPassword = password;
backupPassword = password;
}
diff --git a/scripts/macos/app_env.sh b/scripts/macos/app_env.sh
index e0b43efc..5916e060 100755
--- a/scripts/macos/app_env.sh
+++ b/scripts/macos/app_env.sh
@@ -16,13 +16,13 @@ if [ -n "$1" ]; then
fi
MONERO_COM_NAME="Monero.com"
-MONERO_COM_VERSION="5.6.1"
-MONERO_COM_BUILD_NUMBER=72
+MONERO_COM_VERSION="5.6.5"
+MONERO_COM_BUILD_NUMBER=73
MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="5.6.1"
-CAKEWALLET_BUILD_NUMBER=139
+CAKEWALLET_VERSION="5.6.5"
+CAKEWALLET_BUILD_NUMBER=140
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
if ! [[ " ${TYPES[*]} " =~ " ${APP_MACOS_TYPE} " ]]; then
Why this scored 42/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.