Trim seed input in restore wallet screen
What changed, and why it matters
This commit fixes a minor user-experience bug in the wallet restore screen. Previously, if a user accidentally typed or pasted their secret recovery phrase with leading or trailing spaces, the app would treat it as invalid and fail to restore the wallet. The change simply removes those extra spaces before checking the phrase. It is not a security vulnerability and does not expose funds or data.
No security action required. Treat as a routine UX fix. Optionally verify that other seed-input screens (create, import, settings) already trim consistently.
Security signals we found
Input normalization (trimming whitespace) on a mnemonic seed phrase
No changes to validation rules, cryptography, storage, or network handling
No memory-safety, injection, or privilege-escalation indicators
Evidence from the diff
The patch calls String.trim() on the mnemonic text from the restore screen’s controller before validating and decoding it. Two locations in lib/screens/restore_wallet.dart are updated: the restore-wallet flow and the polyseed height calculation. No cryptographic, authentication, or network code is changed. The effect is purely input normalization.
Changed components
lib/screens/restore_wallet.dartInspect captured patch +6 / −4
diff --git a/lib/screens/restore_wallet.dart b/lib/screens/restore_wallet.dart
index ba202bd..1ee981e 100644
--- a/lib/screens/restore_wallet.dart
+++ b/lib/screens/restore_wallet.dart
@@ -50,7 +50,7 @@ class _RestoreWalletScreenState extends State<RestoreWalletScreen> {
final wallet = Provider.of<WalletModel>(context, listen: false);
- final mnemonic = _mnemonicController.text;
+ final mnemonic = _mnemonicController.text.trim();
final restoreHeight = int.tryParse(_restoreHeightController.text) ?? 0;
setState(() {
@@ -109,7 +109,9 @@ class _RestoreWalletScreenState extends State<RestoreWalletScreen> {
}
Future<void> _calculatePolyseedHeight() async {
- if (!Polyseed.isValidSeed(_mnemonicController.text)) {
+ final mnemonic = _mnemonicController.text.trim();
+
+ if (!Polyseed.isValidSeed(mnemonic)) {
if (_isPolyseed) {
setState(() {
_isPolyseed = false;
@@ -120,8 +122,8 @@ class _RestoreWalletScreenState extends State<RestoreWalletScreen> {
}
final polyseed = Polyseed.decode(
- _mnemonicController.text,
- PolyseedLang.getByPhrase(_mnemonicController.text),
+ mnemonic,
+ PolyseedLang.getByPhrase(mnemonic),
PolyseedCoin.POLYSEED_MONERO,
);
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.