What changed, and why it matters
This change adjusts how the Monero GUI wallet stores and passes login credentials for remote daemon connections. Previously, daemon username/password and 'trusted daemon' status were kept as persistent properties on the wallet object and reused across connections. The patch scopes those credentials to each individual connection instead, passing them as parameters when initializing a connection rather than storing them on the wallet. This reduces the risk that credentials or trust settings from one remote node could accidentally be reused for a different node later.
Treat as a hardening improvement. Review whether any remaining code paths still set or read m_daemonUsername/m_daemonPassword after this change, and ensure all daemon connection entry points pass credentials explicitly. No immediate incident response is indicated.
Security signals we found
Credential scoping/lifetime reduction
Removal of persistent daemon login state from wallet object
Defense against cross-connection credential reuse
Trusted-daemon flag no longer set globally before connect
Evidence from the diff
The commit refactors Wallet::init() and Wallet::initAsync() to accept daemonUsername and daemonPassword as call-site parameters rather than reading from the wallet object’s m_daemonUsername/m_daemonPassword members. main.qml’s applyRemoteNode() no longer calls setDaemonLogin() or setTrustedDaemon() before connectRemoteNode(); the credentials are now supplied during the actual init/initAsync call. This is a defensive hardening change that prevents daemon authentication state from leaking across connection changes or persisting longer than necessary.
Changed components
src/libwalletqt/Wallet.cppsrc/libwalletqt/Wallet.hmain.qmlInspect captured patch +7 / −6
### main.qml
@@ -1630,11 +1630,8 @@ ApplicationWindow {
function applyRemoteNode(index) {
selected = index;
- const remoteNode = currentRemoteNode();
persistentSettings.useRemoteNode = true;
if (currentWallet) {
- currentWallet.setDaemonLogin(remoteNode.username, remoteNode.password);
- currentWallet.setTrustedDaemon(remoteNode.trusted);
appWindow.connectRemoteNode();
}
}
### src/libwalletqt/Wallet.cpp
@@ -239,7 +239,7 @@ void Wallet::storeAsync(const QJSValue &callback, const QString &path /* = "" */
}
}
-bool Wallet::init(const QString &daemonAddress, bool trustedDaemon, quint64 upperTransactionLimit, bool isRecovering, bool isRecoveringFromDevice, quint64 restoreHeight, const QString& proxyAddress)
+bool Wallet::init(const QString &daemonAddress, const QString &daemonUsername, const QString &daemonPassword, bool trustedDaemon, quint64 upperTransactionLimit, bool isRecovering, bool isRecoveringFromDevice, quint64 restoreHeight, const QString& proxyAddress)
{
qDebug() << "init non async";
if (isRecovering){
@@ -257,7 +257,7 @@ bool Wallet::init(const QString &daemonAddress, bool trustedDaemon, quint64 uppe
{
QMutexLocker locker(&m_proxyMutex);
- if (!m_walletImpl->init(daemonAddress.toStdString(), upperTransactionLimit, m_daemonUsername.toStdString(), m_daemonPassword.toStdString(), false, false, proxyAddress.toStdString()))
+ if (!m_walletImpl->init(daemonAddress.toStdString(), upperTransactionLimit, daemonUsername.toStdString(), daemonPassword.toStdString(), false, false, proxyAddress.toStdString()))
{
return false;
}
@@ -290,9 +290,11 @@ void Wallet::initAsync(
qDebug() << "initAsync: " + daemonAddress;
m_initializing = true;
pauseRefresh();
- const auto future = m_scheduler.run([this, daemonAddress, trustedDaemon, upperTransactionLimit, isRecovering, isRecoveringFromDevice, restoreHeight, proxyAddress] {
+ const auto future = m_scheduler.run([this, daemonAddress, daemonUsername = m_daemonUsername, daemonPassword = m_daemonPassword, trustedDaemon, upperTransactionLimit, isRecovering, isRecoveringFromDevice, restoreHeight, proxyAddress] {
m_initialized = init(
daemonAddress,
+ daemonUsername,
+ daemonPassword,
trustedDaemon,
upperTransactionLimit,
isRecovering,
### src/libwalletqt/Wallet.h
@@ -435,6 +435,8 @@ class Wallet : public QObject, public PassprasePrompter
//! initializes wallet
bool init(
const QString &daemonAddress,
+ const QString &daemonUsername,
+ const QString &daemonPassword,
bool trustedDaemon,
quint64 upperTransactionLimit,
bool isRecovering,Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.