What changed, and why it matters
This commit changes how the Epic Cash wallet is initialized and opened. It removes a dedicated wallet-open method, moves the open-wallet call into the general init flow, and switches the wallet-recovery call to be awaited properly. The changes look like bug fixes to wallet lifecycle handling rather than an obvious security patch, but the commit message gives no details and there are no external references.
Treat as a routine bug-fix commit unless additional context emerges. Reviewers should verify that removing the standalone open() method does not introduce race conditions during wallet initialization and that using secure-storage config directly is safe. No immediate security response is indicated by the diff alone.
Security signals we found
Wallet initialization logic changed
Secure storage read used for wallet config
Async wallet recovery call now awaited
Commit message is non-descriptive
Evidence from the diff
The patch comments out the entire EpiccashWallet.open() method and folds wallet opening into init(). It changes init() to read an existing wallet config from secure storage (${walletId}_config) and uses that config directly when opening an existing wallet, instead of calling _getRealConfig(). It also adds an await to EpicWallet.recover() in the template interface implementation. The diff is small and the commit message is vague (‘fix a couple issues’), so the exact issues being fixed are not stated.
Changed components
lib/wallets/wallet/impl/epiccash_wallet.darttool/wl_templates/EPIC_libepiccash_interface_impl.template.dartInspect captured patch +44 / −46
diff --git a/lib/wallets/wallet/impl/epiccash_wallet.dart b/lib/wallets/wallet/impl/epiccash_wallet.dart
index c7571f5..1915256 100644
--- a/lib/wallets/wallet/impl/epiccash_wallet.dart
+++ b/lib/wallets/wallet/impl/epiccash_wallet.dart
@@ -74,43 +74,43 @@ class EpiccashWallet extends Bip39Wallet {
/// Opens and initializes the Epic wallet instance.
/// Should only be called once during wallet initialization.
- Future<void> open() async {
- if (_wallet != null) {
- Logging.instance.d("Wallet already open, ensuring listener");
- if (!await libEpic.isEpicboxListenerRunning(wallet: _wallet!)) {
- await _listenToEpicbox();
- }
- return;
- }
-
- try {
- final config = await _getRealConfig();
- final password = await secureStorageInterface.read(
- key: '${walletId}_password',
- );
- if (password == null) {
- throw Exception('Wallet password not found');
- }
-
- final epicboxConfig = await getEpicBoxConfig();
-
- _wallet = await libEpic.openWallet(
- config: config,
- password: password,
- epicboxConfig: epicboxConfig.toString(),
- );
-
- await _listenToEpicbox();
-
- Logging.instance.d(
- "Epic wallet opened successfully with persistent isolate",
- );
- } catch (e, s) {
- Logging.instance.e("Failed to open Epic wallet", error: e, stackTrace: s);
- _wallet = null;
- rethrow;
- }
- }
+ // Future<void> open() async {
+ // if (_wallet != null) {
+ // Logging.instance.d("Wallet already open, ensuring listener");
+ // if (!await libEpic.isEpicboxListenerRunning(wallet: _wallet!)) {
+ // await _listenToEpicbox();
+ // }
+ // return;
+ // }
+ //
+ // try {
+ // final config = await _getRealConfig();
+ // final password = await secureStorageInterface.read(
+ // key: '${walletId}_password',
+ // );
+ // if (password == null) {
+ // throw Exception('Wallet password not found');
+ // }
+ //
+ // final epicboxConfig = await getEpicBoxConfig();
+ //
+ // _wallet = await libEpic.openWallet(
+ // config: config,
+ // password: password,
+ // epicboxConfig: epicboxConfig.toString(),
+ // );
+ //
+ // await _listenToEpicbox();
+ //
+ // Logging.instance.d(
+ // "Epic wallet opened successfully with persistent isolate",
+ // );
+ // } catch (e, s) {
+ // Logging.instance.e("Failed to open Epic wallet", error: e, stackTrace: s);
+ // _wallet = null;
+ // rethrow;
+ // }
+ // }
Future<void> updateEpicboxConfig(String host, int port) async {
final String stringConfig = jsonEncode({
@@ -834,14 +834,13 @@ class EpiccashWallet extends Bip39Wallet {
@override
Future<void> init({bool? isRestore}) async {
- if (_wallet != null) {
- Logging.instance.d("Wallet already initialized, skipping init");
- return await super.init();
- }
-
if (isRestore != true) {
+ final existingWalletConfig = await secureStorageInterface.read(
+ key: '${walletId}_config',
+ );
+
// check if should create a new wallet
- if (_wallet == null) {
+ if (existingWalletConfig == null) {
await updateNode();
final mnemonicString = await getMnemonic();
@@ -902,14 +901,13 @@ class EpiccashWallet extends Bip39Wallet {
"initializeExisting() ${cryptoCurrency.prettyName} wallet",
);
- final config = await _getRealConfig();
final password = await secureStorageInterface.read(
key: '${walletId}_password',
);
final epicboxConfig = await getEpicBoxConfig();
_wallet = await libEpic.openWallet(
- config: config,
+ config: existingWalletConfig,
password: password!,
epicboxConfig: epicboxConfig.toString(),
); // Spawns worker isolate
diff --git a/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart b/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart
index d40208c..b27429e 100644
--- a/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart
+++ b/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart
@@ -215,7 +215,7 @@ final class _LibEpicCashInterfaceImpl extends LibEpicCashInterface {
required String name,
required String epicBoxConfig,
}) async {
- final wallet = EpicWallet.recover(
+ final wallet = await EpicWallet.recover(
config: config,
password: password,
mnemonic: mnemonic,
Why this scored 34/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.