Skip to content

qc login: never hand a terminal keys that can't read the account (0.5.4, qc 0.4.3) - #287

Merged
ralyodio merged 1 commit into
masterfrom
fix/cli-key-mismatch
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/cli-key-mismatch

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Anthony: in the qc TUI every message, including his own just-sent ones, showed [Encrypted message - decryption failed].

Cause: /cli/authorize called postQuantumEncryption.initialize(), which silently generates a fresh keypair when the browser has none stored. qc received that throwaway keypair, but everything addressed to Anthony (including qc's own copy of what it sends) is encrypted to the account key in user_public_keys. So nothing decrypted.

Fixes

  • The authorize page only loads stored keys. If the browser has none, it says to restore from backup first.
  • /api/cli/authorize takes the handed-over public_key and refuses one that differs from the account's key (409 key_mismatch). An account with no key on file passes.
  • qc 0.4.3 runs keyCheck() after qc login and when the TUI starts, and shows a plain warning instead of a wall of decrypt failures.

Tests: 675/675, including new assertAccountKey and keyCheck tests. next build passes.

🤖 Generated with Claude Code

…5.4, qc 0.4.3)

/cli/authorize called postQuantumEncryption.initialize(), which silently
generates a fresh keypair in a browser that has none. qc then held keys no
message was encrypted to, including its own sends, so everything showed
'[Encrypted message - decryption failed]'.

- The page only loads stored keys; with none it says to restore first.
- /api/cli/authorize compares the handed-over public key with the account's
  key in user_public_keys and refuses a mismatch (409 key_mismatch).
- qc checks its key against the account after login and in the TUI, and
  says so plainly instead of failing every message.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

13 finding(s)

MEDIUM: 9 | LOW: 4

Severity Rule Location
MEDIUM redos-nested-quantifier src/app/api/profile/update/route.js:73
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:38
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:66
MEDIUM js-unescaped-html-sink src/app/faq/page.jsx:57
MEDIUM js-unescaped-html-sink src/app/layout.jsx:137
MEDIUM js-unescaped-html-sink src/app/layout.jsx:141
MEDIUM js-unescaped-html-sink src/app/page.jsx:47
MEDIUM redos-nested-quantifier src/lib/auth/dns-name.js:88
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:121
LOW secret-generic-credential src/app/api/auth/register-anon/route.test.js:32
LOW secret-jwt tests/debug-sms.js:10
LOW secret-generic-credential tests/private-key-import-export.test.js:252
LOW secret-generic-credential tests/private-key-import-export.test.js:264

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 214204d into master Oct 6, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant