do not show anonymize all button in view only wallets
What changed, and why it matters
This commit hides an 'anonymize all' button in cryptocurrency wallets that are in view-only mode. View-only wallets cannot spend or move funds, so the button was likely non-functional or confusing. The change is a UI cleanup rather than a fix for a vulnerability that could be directly exploited.
No immediate security action required. Treat as a minor UX/defensive-hardening change. If the button was previously triggering any on-chain action or error state in view-only mode, review the handler for safe failure modes.
Security signals we found
UI element hidden in restricted wallet mode
View-only wallet boundary enforcement
Privacy feature (anonymize all) scoped to wallets with signing capability
Evidence from the diff
The patch adds a !viewOnly guard to the conditions that render the ‘anonymize all’ button and its spacing in wallet_view.dart. Previously, the button was shown whenever the wallet was a Spark wallet or had MWEB enabled, regardless of whether the wallet was view-only. The change prevents the button from appearing in view-only wallets, where the underlying anonymization operation presumably requires private keys that are not present.
Changed components
lib/pages/wallet_view/wallet_view.dartInspect captured patch +10 / −4
diff --git a/lib/pages/wallet_view/wallet_view.dart b/lib/pages/wallet_view/wallet_view.dart
index 209df99..417ad22 100644
--- a/lib/pages/wallet_view/wallet_view.dart
+++ b/lib/pages/wallet_view/wallet_view.dart
@@ -816,11 +816,17 @@ class _WalletViewState extends ConsumerState<WalletView> {
),
),
),
- if (isSparkWallet ||
- ref.watch(pWalletInfo(walletId)).isMwebEnabled)
+ if ((isSparkWallet ||
+ ref
+ .watch(pWalletInfo(walletId))
+ .isMwebEnabled) &&
+ !viewOnly)
const SizedBox(height: 10),
- if (isSparkWallet ||
- ref.watch(pWalletInfo(walletId)).isMwebEnabled)
+ if ((isSparkWallet ||
+ ref
+ .watch(pWalletInfo(walletId))
+ .isMwebEnabled) &&
+ !viewOnly)
Padding(
padding: const EdgeInsets.symmetric(horizontal: 16),
child: Row(
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.