Merge staging and keep the upstream CI workflow
What changed, and why it matters
This commit is a routine merge from a staging branch that mostly tidies up build scripts and CI. The only user-visible change is that the Firo wallet now groups 'revoked' and 'banned' masternodes together under a single red 'banned' label, instead of showing them as two separate statuses. It also updates a privacy-related internal dependency and makes sure empty API key templates are created automatically during builds and tests. There is no obvious security vulnerability in the diff itself.
Review the new mobile_app_privacy commit (0f07a82569854c1830a66ae86daa9308b382617a) for any privacy or security changes. Verify that relaxing .gitignore rules for cs_monero build outputs and diff files does not accidentally allow committed build artifacts or patch files. Confirm the generated API key template is only used for tests/development and never contains real keys.
Security signals we found
Dependency version bump for mobile_app_privacy (git ref changed)
.gitignore relaxation for cs_monero build artifacts and diff files
CI/build scripts now auto-generate API key template with additional Trocador placeholders
Evidence from the diff
The commit merges staging into the main branch while preserving the upstream GitHub Actions test workflow. Key changes: (1) Firo masternode status enum drops the revoked value; both revocation and PoSe ban now map to MasternodeStatus.banned with a red UI color. (2) Build/test scripts and CI now generate a fuller external_api_keys.dart template, adding Trocador key placeholders and explicit String types. (3) The mobile_app_privacy git dependency is bumped from c393e8d1... to 0f07a825.... (4) .gitignore no longer ignores crypto_plugins/cs_monero/built_outputs, build, and *.diff. (5) A Trocador error message is reformatted. No direct security flaw is visible in the diff, but the dependency bump and .gitignore change could affect the supply-chain/reproducibility surface; the actual content of the new dependency commit is not supplied, so security relevance cannot be fully assessed from this commit alone.
Changed components
Firo wallet masternode status displayBuild scripts (scripts/prebuild.sh, scripts/prebuild.ps1)CI workflow (.github/workflows/test.yaml)mobile_app_privacy git dependencyTrocador exchange API error string formattingInspect captured patch +63 / −16
### .github/workflows/test.yaml
@@ -49,6 +49,24 @@ jobs:
run: |
if [ -n "$CHANGE_NOW" ]; then
echo "$CHANGE_NOW" | base64 --decode > lib/external_api_keys.dart
+ else
+ cat > lib/external_api_keys.dart << 'EOF'
+ const String kChangeNowApiKey = "";
+ const String kSimpleSwapApiKey = "";
+ const String kNanswapApiKey = "";
+ const String kNanoSwapRpcApiKey = "";
+ const String kWizSwapApiKey = "";
+ const kShopInBitAccessKey = "";
+ const kShopInBitPartnerSecret = "";
+ const kCakePayApiToken = "";
+ const kExolixApiKey = "";
+ const kLetsExchangeId = "";
+ const kLetsExchangeToken = "";
+ const kCypherGoatApiKey = "";
+ const kCypherGoatAffiliate = "";
+ const kTrocadorApiKey = "";
+ const kTrocadorRefCode = "";
+ EOF
fi
- name: Ensure app config for tests
### .gitignore
@@ -106,9 +106,6 @@ pubspec.yaml
scripts/linux/build/libsecret/subprojects/gi-docgen/.meson-subproject-wrap-hash.txt
-crypto_plugins/cs_monero/built_outputs
-crypto_plugins/cs_monero/build
-crypto_plugins/*.diff
/devtools_options.yaml
# generated interfaces
### .gitmodules
[binary or diff unavailable]
### lib/pages/masternodes/sub_widgets/masternodes_list.dart
@@ -108,8 +108,7 @@ class _MasternodeCard extends StatelessWidget {
decoration: BoxDecoration(
color: switch (status) {
MasternodeStatus.active => stack.accentColorGreen,
- MasternodeStatus.banned => stack.accentColorOrange,
- MasternodeStatus.revoked => stack.accentColorRed,
+ MasternodeStatus.banned => stack.accentColorRed,
},
borderRadius: BorderRadius.circular(8),
),
### lib/services/exchange/trocador/trocador_api.dart
@@ -318,8 +318,7 @@ abstract class TrocadorAPI {
String error = map["error"] as String? ?? json.toString();
if (error ==
"trade could not be generated, some unknown error happened") {
- error =
- "This trade couldn't be completed. Please select another provider.";
+ error = "This trade couldn't be completed. Please select another provider.";
}
Logging.instance.e(
### lib/wallets/wallet/impl/firo_wallet.dart
@@ -34,8 +34,7 @@ import 'firo_transaction_type.dart';
enum MasternodeStatus {
active("ACTIVE"),
- banned("BANNED"),
- revoked("REVOKED");
+ banned("BANNED");
const MasternodeStatus(this.label);
@@ -82,8 +81,9 @@ class MasternodeInfo {
});
MasternodeStatus get status {
- if (revocationReason != 0) return MasternodeStatus.revoked;
- if (poseBanHeight != -1) return MasternodeStatus.banned;
+ if (revocationReason != 0 || poseBanHeight != -1) {
+ return MasternodeStatus.banned;
+ }
return MasternodeStatus.active;
}
### pubspec.lock
@@ -1631,8 +1631,8 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: c393e8d1be93cce013f53fe16ec44080b2fdefdd
- resolved-ref: c393e8d1be93cce013f53fe16ec44080b2fdefdd
+ ref: "0f07a82569854c1830a66ae86daa9308b382617a"
+ resolved-ref: "0f07a82569854c1830a66ae86daa9308b382617a"
url: "https://github.com/cypherstack/mobile_app_privacy"
source: git
version: "0.0.4"
### scripts/app_config/templates/pubspec.template.yaml
@@ -272,7 +272,7 @@ dependencies:
mobile_app_privacy:
git:
url: https://github.com/cypherstack/mobile_app_privacy
- ref: c393e8d1be93cce013f53fe16ec44080b2fdefdd
+ ref: 0f07a82569854c1830a66ae86daa9308b382617a
# required for web3dart to use EthereumAddress class...
wallet: 0.0.18
### scripts/prebuild.ps1
@@ -2,9 +2,27 @@
$KEYS = "..\lib\external_api_keys.dart"
if (-not (Test-Path $KEYS)) {
Write-Host "prebuild.ps1: creating template lib/external_api_keys.dart file"
- "const kChangeNowApiKey = '';" + "`nconst kSimpleSwapApiKey = '';" + "`nconst kNanswapApiKey = '';" + "`nconst kNanoSwapRpcApiKey = '';" + "`nconst kWizSwapApiKey = '';" + "`nconst kShopInBitAccessKey = '';" + "`nconst kShopInBitPartnerSecret = '';" + "`nconst kCakePayApiToken = '';" + "`nconst kExolixApiKey = '';" + "`nconst kLetsExchangeId = '';" + "`nconst kLetsExchangeToken = '';" + "`nconst kCypherGoatApiKey = '';" + "`nconst kCypherGoatAffiliate = '';" | Out-File $KEYS -Encoding UTF8
+
+ @'
+const String kChangeNowApiKey = "";
+const String kSimpleSwapApiKey = "";
+const String kNanswapApiKey = "";
+const String kNanoSwapRpcApiKey = "";
+const String kWizSwapApiKey = "";
+const kShopInBitAccessKey = "";
+const kShopInBitPartnerSecret = "";
+const kCakePayApiToken = "";
+const kExolixApiKey = "";
+const kLetsExchangeId = "";
+const kLetsExchangeToken = "";
+const kCypherGoatApiKey = "";
+const kCypherGoatAffiliate = "";
+const kTrocadorApiKey = "";
+const kTrocadorRefCode = "";
+'@ | Out-File $KEYS -Encoding UTF8
}
+
# Create template wallet test parameter files if they don't already exist
$coins = @("bitcoin", "bitcoincash", "dogecoin", "namecoin", "firo", "particl") # TODO add monero and wownero when those tests are updated to use the .gitignored test wallet setup: when doing that, make sure to update the test vectors for a new, private development seed
### scripts/prebuild.sh
@@ -4,7 +4,23 @@
KEYS=../lib/external_api_keys.dart
if ! test -f "$KEYS"; then
echo 'prebuild.sh: creating template lib/external_api_keys.dart file'
- printf 'const kChangeNowApiKey = "";\nconst kSimpleSwapApiKey = "";\nconst kNanswapApiKey = "";\nconst kNanoSwapRpcApiKey = "";\nconst kWizSwapApiKey = "";\nconst kShopInBitAccessKey = "";\nconst kShopInBitPartnerSecret = "";\nconst kCakePayApiToken = "";\nconst kExolixApiKey = "";\nconst kLetsExchangeId = "";\nconst kLetsExchangeToken = "";\nconst kCypherGoatApiKey = "";\nconst kCypherGoatAffiliate = "";\n' > $KEYS
+ cat << 'EOF' > "$KEYS"
+const kChangeNowApiKey = "";
+const kSimpleSwapApiKey = "";
+const kNanswapApiKey = "";
+const kNanoSwapRpcApiKey = "";
+const kWizSwapApiKey = "";
+const kShopInBitAccessKey = "";
+const kShopInBitPartnerSecret = "";
+const kCakePayApiToken = "";
+const kExolixApiKey = "";
+const kLetsExchangeId = "";
+const kLetsExchangeToken = "";
+const kCypherGoatApiKey = "";
+const kCypherGoatAffiliate = "";
+const kTrocadorApiKey = "";
+const kTrocadorRefCode = "";
+EOF
fi
# Create template wallet test parameter files if they don't already existWhy this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.