Repository navigation
qc login: never hand a terminal keys that can't read the account (0.5.4, qc 0.4.3) - #287
Merged
Merged
Conversation
…5.4, qc 0.4.3) /cli/authorize called postQuantumEncryption.initialize(), which silently generates a fresh keypair in a browser that has none. qc then held keys no message was encrypted to, including its own sends, so everything showed '[Encrypted message - decryption failed]'. - The page only loads stored keys; with none it says to restore first. - /api/cli/authorize compares the handed-over public key with the account's key in user_public_keys and refuses a mismatch (409 key_mismatch). - qc checks its key against the account after login and in the TUI, and says so plainly instead of failing every message. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ThreatCrush Security Scan13 finding(s) MEDIUM: 9 | LOW: 4
Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Anthony: in the qc TUI every message, including his own just-sent ones, showed
[Encrypted message - decryption failed].Cause:
/cli/authorizecalledpostQuantumEncryption.initialize(), which silently generates a fresh keypair when the browser has none stored. qc received that throwaway keypair, but everything addressed to Anthony (including qc's own copy of what it sends) is encrypted to the account key inuser_public_keys. So nothing decrypted.Fixes
/api/cli/authorizetakes the handed-overpublic_keyand refuses one that differs from the account's key (409 key_mismatch). An account with no key on file passes.keyCheck()afterqc loginand when the TUI starts, and shows a plain warning instead of a wall of decrypt failures.Tests: 675/675, including new assertAccountKey and keyCheck tests.
next buildpasses.🤖 Generated with Claude Code