determine whether the wallet lock screen requires a password from the storage encryption key on each lock and unlock
What changed, and why it matters
This commit changes how Sparrow Wallet decides whether to show a password-protected lock screen. Previously, the app checked once when wallet settings changed and cached that result. Now it re-checks every time the wallet is locked or unlocked by looking directly at the storage encryption key. This is a defensive fix: it reduces the chance that the lock screen might be skipped or incorrectly shown if the wallet's encryption state changes without the app noticing.
Review whether any other code paths still rely on stale walletEncryptedProperty values, and verify that Storage.getEncryptionPubKey() and Storage.NO_PASSWORD_KEY correctly distinguish password-protected wallets from unencrypted or no-password wallets in all storage formats.
Security signals we found
Changed encryption-status check from cached/event-driven to per-lock/unlock evaluation
Removed reliance on walletSettingsChanged event to keep encryption status current
Switched from isEncrypted() (IO-dependent) to direct encryption public key comparison
Defensive hardening of lock screen behavior
Evidence from the diff
WalletController.updateWalletEncryptedStatus() was rewritten to determine encryption status from the storage encryption public key (ECKey) rather than calling Storage.isEncrypted(), which could throw IOException. The method is now invoked at the start of unlockWallet(CustomPasswordField) and walletLock(WalletLockEvent), instead of only on walletSettingsChanged and inside walletLock when lockPane was null. The walletSettingsChanged event handler was removed entirely. This makes the password prompt decision dynamic and tied to the actual storage key state on each lock/unlock transition.
Changed components
src/main/java/com/sparrowwallet/sparrow/wallet/WalletController.javaWallet lock/unlock UI flowStorage encryption status detectionInspect captured patch +5 / −13
### src/main/java/com/sparrowwallet/sparrow/wallet/WalletController.java
@@ -2,6 +2,7 @@
import com.google.common.eventbus.Subscribe;
import com.sparrowwallet.drongo.SecureString;
+import com.sparrowwallet.drongo.crypto.ECKey;
import com.sparrowwallet.drongo.crypto.InvalidPasswordException;
import com.sparrowwallet.drongo.wallet.Wallet;
import com.sparrowwallet.sparrow.AppServices;
@@ -190,6 +191,7 @@ private void initializeLockScreen() {
}
private void unlockWallet(CustomPasswordField passwordField) {
+ updateWalletEncryptedStatus();
if(walletEncryptedProperty.get()) {
String walletId = walletForm.getWalletId();
SecureString password = new SecureString(passwordField.getText());
@@ -221,11 +223,8 @@ private void unlockWallet() {
}
private void updateWalletEncryptedStatus() {
- try {
- walletEncryptedProperty.set(getWalletForm().getStorage().isEncrypted());
- } catch(IOException e) {
- log.warn("Error determining if wallet is locked", e);
- }
+ ECKey encryptionPubKey = getWalletForm().getStorage().getEncryptionPubKey();
+ walletEncryptedProperty.set(encryptionPubKey != null && !Storage.NO_PASSWORD_KEY.equals(encryptionPubKey));
}
@Subscribe
@@ -235,13 +234,6 @@ public void walletAddressesChanged(WalletAddressesChangedEvent event) {
}
}
- @Subscribe
- public void walletSettingsChanged(WalletSettingsChangedEvent event) {
- if(event.getWalletId().equals(walletForm.getWalletId())) {
- Platform.runLater(this::updateWalletEncryptedStatus);
- }
- }
-
@Subscribe
public void functionAction(FunctionActionEvent event) {
if(event.selectFunction() && event.getWallet().equals(walletForm.getWallet())) {
@@ -252,8 +244,8 @@ public void functionAction(FunctionActionEvent event) {
@Subscribe
public void walletLock(WalletLockEvent event) {
if(event.getWallet().equals(walletForm.getMasterWallet())) {
+ updateWalletEncryptedStatus();
if(lockPane == null) {
- updateWalletEncryptedStatus();
initializeLockScreen();
}
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.