What changed, and why it matters
This small patch fixes a state-cleanup bug in Monero's wallet API. Previously, when a wallet connected to a new daemon without providing a username, it could accidentally reuse login credentials from an earlier connection. The patch now explicitly clears those old credentials when no username is supplied, preventing the wallet from sending stale authentication to the wrong daemon.
Apply the patch. For defense in depth, review other optional state fields in WalletImpl::init() and similar re-initialization paths to ensure they are reset when inputs are omitted or changed.
Security signals we found
stale credential reuse
authentication state not reset across re-initialization
missing else branch in conditional credential assignment
Evidence from the diff
In WalletImpl::init(), the code sets m_daemon_login only when daemon_username is non-empty. If a subsequent init() call omits credentials while m_daemon_login still holds a value from a prior call, the stale boost::optional
Changed components
src/wallet/api/wallet.cppWalletImpl::init()daemon login state (m_daemon_login)Inspect captured patch +2 / −0
diff --git a/src/wallet/api/wallet.cpp b/src/wallet/api/wallet.cpp
index d0ed2f2..e299d8a 100644
--- a/src/wallet/api/wallet.cpp
+++ b/src/wallet/api/wallet.cpp
@@ -974,6 +974,8 @@ bool WalletImpl::init(const std::string &daemon_address, uint64_t upper_transact
clearStatus();
if(daemon_username != "")
m_daemon_login.emplace(daemon_username, daemon_password);
+ else
+ m_daemon_login = boost::none;
return doInit(daemon_address, proxy_address, upper_transaction_size_limit, use_ssl);
}
Why this scored 37/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.