Don't force max brightness when showing seed QR (#3682)
What changed, and why it matters
This commit removes a feature that automatically cranked screen brightness to maximum when showing a wallet's seed/keys as a QR code. In some cases the brightness stayed stuck at max after closing the QR screen, which could let someone nearby more easily see or photograph the sensitive QR code. The fix simply shows the QR at whatever brightness the user already had set.
No immediate action required; the change is a defensive hardening fix. Users should ensure they are on a version containing this commit and avoid displaying seed QR codes in public or untrusted environments regardless of brightness.
Security signals we found
Removal of forced-max-brightness wrapper around sensitive QR display
Potential shoulder-surf / camera-surveillance risk from bright screen showing seed/keys
State-cleanup bug in brightness restoration on non-normal route returns
Evidence from the diff
The patch removes the use of BrightnessUtil.changeBrightnessForFunction around the fullscreen QR navigation in wallet_keys_page.dart. That utility forced full brightness and only restored the previous level if the route returned normally; certain dismiss paths left brightness at maximum. The new code navigates directly, leaving brightness under the user’s control.
Changed components
lib/src/screens/wallet_keys/wallet_keys_page.dartBrightnessUtil.changeBrightnessForFunctionInspect captured patch +5 / −8
### lib/src/screens/wallet_keys/wallet_keys_page.dart
@@ -7,7 +7,6 @@ import 'package:cake_wallet/src/widgets/primary_button.dart';
import 'package:cake_wallet/src/widgets/seedphrase_grid_widget.dart';
import 'package:cake_wallet/src/widgets/text_info_box.dart';
import 'package:cake_wallet/src/widgets/warning_box_widget.dart';
-import 'package:cake_wallet/utils/brightness_util.dart';
import 'package:cake_wallet/utils/clipboard_util.dart';
import 'package:cake_wallet/utils/show_bar.dart';
import 'package:cake_wallet/view_model/wallet_keys_view_model.dart';
@@ -406,12 +405,10 @@ class _WalletKeysPageBodyState extends State<WalletKeysPageBody>
Future<void> _showQR(BuildContext context) async {
final url = await widget.walletKeysViewModel.getUrl(false);
- BrightnessUtil.changeBrightnessForFunction(() async {
- await Navigator.pushNamed(
- context,
- Routes.fullscreenQR,
- arguments: QrViewData(data: url.toString(), version: QrVersions.auto),
- );
- });
+ await Navigator.pushNamed(
+ context,
+ Routes.fullscreenQR,
+ arguments: QrViewData(data: url.toString(), version: QrVersions.auto),
+ );
}
}Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.