refactor(mwc): write .api_secret in updateNode(), not _getConfig()
What changed, and why it matters
This commit moves where a secret API file is created for the Mimblewimblecoin wallet. Previously, the file was created while reading the wallet configuration. Now, it is created when the wallet node is updated. The change appears to be a code cleanup (refactor) to ensure the secret is written at a more appropriate time, but the commit message and diff do not clearly explain any security problem being fixed.
Review the Mimblewimblecoin wallet flow to confirm that `_ensureApiSecret` is called before any operation that requires the API secret, and that removing it from `_getConfig()` does not leave any code path without a valid secret. Consider whether the change warrants a security note if it fixes a real bug.
Security signals we found
API secret file creation logic moved between wallet lifecycle methods
Refactor of secret material handling in Mimblewimblecoin wallet integration
No explicit security bug, CVE, or advisory referenced in commit
Evidence from the diff
The patch removes an _ensureApiSecret(walletDir) call from _getConfig() and adds it to updateNode(). _getConfig() now only builds and returns the configuration map, while updateNode() ensures the .api_secret file exists before fetching and persisting the config to secure storage. The change is small and labeled as a refactor. There is no direct evidence in the commit of a vulnerability, exploit, or security disclosure.
Changed components
lib/wallets/wallet/impl/mimblewimblecoin_wallet.dartMimblewimblecoinWallet._getConfig()MimblewimblecoinWallet.updateNode().api_secret file handlingInspect captured patch +3 / −2
diff --git a/lib/wallets/wallet/impl/mimblewimblecoin_wallet.dart b/lib/wallets/wallet/impl/mimblewimblecoin_wallet.dart
index db8f2c8..d31be37 100644
--- a/lib/wallets/wallet/impl/mimblewimblecoin_wallet.dart
+++ b/lib/wallets/wallet/impl/mimblewimblecoin_wallet.dart
@@ -589,8 +589,6 @@ class MimblewimblecoinWallet extends Bip39Wallet {
final String nodeApiAddress = uri.toString();
final walletDir = await _currentWalletDirPath();
- await _ensureApiSecret(walletDir);
-
final Map<String, dynamic> config = {};
config["wallet_dir"] = walletDir;
config["check_node_api_http_addr"] = nodeApiAddress;
@@ -1463,6 +1461,9 @@ class MimblewimblecoinWallet extends Bip39Wallet {
Future<void> updateNode() async {
_mimblewimblecoinNode = getCurrentNode();
+ final walletDir = await _currentWalletDirPath();
+ await _ensureApiSecret(walletDir);
+
// TODO: [prio=low] move this out of secure storage if secure storage not needed
final String stringConfig = await _getConfig();
await secureStorageInterface.write(
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.