feat(paynym): add isTaproot param to getPaymentCode and enable on claim
What changed, and why it matters
This commit updates the Paynym (BIP47 reusable payment code) claim flow in Stack Wallet so that newly claimed payment codes advertise both SegWit and Taproot support. Previously the claim screen requested a non-SegWit payment code; now it requests a code with both feature bits set. The wallet's payment-code generator also gains a new optional `isTaproot` flag. This is a feature/correctness change rather than a clear security fix, but enabling the right address-type flags can affect which addresses are derived when other wallets pay you, so it has mild security/reliability relevance.
Review whether the new feature-bit combination is compatible with counterparties' BIP47/Paynym implementations and whether any fallback behavior for wallets that do not understand the Taproot bit is handled safely. Treat as a feature change with low security relevance unless additional context shows it fixes a known address-derivation issue.
Security signals we found
BIP47 payment-code feature-bit change (SegWit + Taproot)
Address-type signaling change during Paynym claim
No explicit vulnerability, CVE, or security advisory referenced in commit
No bounds-checking, cryptographic, or input-validation changes visible
Evidence from the diff
The diff touches two files. paynym_claim_view.dart changes the claim-time call from wallet.getPaymentCode(isSegwit: false) to wallet.getPaymentCode(isSegwit: true, isTaproot: true). paynym_interface.dart adds an isTaproot parameter (default false) to getPaymentCode and passes shouldSetSegwitBit: isSegwit || isTaproot and shouldSetTaprootBit: isTaproot into PaymentCode.fromBip32Node. This makes the generated BIP47 payment code signal P2TR capability in addition to SegWit. There is no explicit bug fix or vulnerability description in the commit; the change appears to be enabling Taproot support for Paynym claims.
Changed components
lib/pages/paynym/paynym_claim_view.dartlib/wallets/wallet/wallet_mixin_interfaces/paynym_interface.dartPaynym/BIP47 payment-code generationTaproot address support in Paynym claimsInspect captured patch +11 / −4
diff --git a/lib/pages/paynym/paynym_claim_view.dart b/lib/pages/paynym/paynym_claim_view.dart
index cb04fda..2f1bda1 100644
--- a/lib/pages/paynym/paynym_claim_view.dart
+++ b/lib/pages/paynym/paynym_claim_view.dart
@@ -192,8 +192,11 @@ class _PaynymClaimViewState extends ConsumerState<PaynymClaimView> {
if (shouldCancel) return;
- // get payment code
- final pCode = await wallet.getPaymentCode(isSegwit: false);
+ // get payment code with taproot + segwit feature bits
+ final pCode = await wallet.getPaymentCode(
+ isSegwit: true,
+ isTaproot: true,
+ );
if (shouldCancel) return;
diff --git a/lib/wallets/wallet/wallet_mixin_interfaces/paynym_interface.dart b/lib/wallets/wallet/wallet_mixin_interfaces/paynym_interface.dart
index 5319edf..aae2119 100644
--- a/lib/wallets/wallet/wallet_mixin_interfaces/paynym_interface.dart
+++ b/lib/wallets/wallet/wallet_mixin_interfaces/paynym_interface.dart
@@ -374,7 +374,10 @@ mixin PaynymInterface<T extends PaynymCurrencyInterface>
}
/// fetch or generate this wallet's bip47 payment code
- Future<PaymentCode> getPaymentCode({required bool isSegwit}) async {
+ Future<PaymentCode> getPaymentCode({
+ required bool isSegwit,
+ bool isTaproot = false,
+ }) async {
final node = await _getRootNode();
final paymentCode = PaymentCode.fromBip32Node(
@@ -382,7 +385,8 @@ mixin PaynymInterface<T extends PaynymCurrencyInterface>
_basePaynymDerivePath(testnet: info.coin.network.isTestNet),
),
networkType: networkType,
- shouldSetSegwitBit: isSegwit,
+ shouldSetSegwitBit: isSegwit || isTaproot,
+ shouldSetTaprootBit: isTaproot,
);
return paymentCode;
Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.