Skip to content

Add explicit, secret-free Display messages for WalletError variants - #401

Merged
Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
k2ghostyou:drips/364
Sep 29, 2026
Merged

Emmyt24 merged 2 commits into
Octo-Protocol-org:dev-branchfrom
k2ghostyou:drips/364

Conversation

@k2ghostyou

Copy link
Copy Markdown

Summary

Add explicit, secret-free Display messages for WalletError variants

What was solved

#364 — Add a Display impl for WalletError guaranteed to never include secret material, with a compile-time-checked test

Add explicit, audited thiserror #[error("...")] Display messages for every WalletError variant in crates/wallet-core/src/error.rs, ensuring no variant's user/log-facing text leaks secret material, and add a parametrized test asserting each variant has an explicit, secret-free Display message.

Addressed:

  • Changed: crates/wallet-core/src/error.rs
  • Confirm whether WalletError currently derives Debug only or also has an explicit Display/std::error::Error impl (likely via thiserror; check Cargo.toml).
  • If Display isn't hand-controlled per variant, add explicit per-variant #[error("...")] messages so user-facing text is deliberate rather than derived Debug output.
  • Add/tighten thiserror::Error #[error("...")] messages for every WalletError variant in crates/wallet-core/src/error.rs.

Changes

  • crates/wallet-core/src/error.rs (modify)

Approach

  1. Read crates/wallet-core/src/error.rs and crates/wallet-core/Cargo.toml to confirm whether WalletError uses thiserror and how Display is currently derived.
  2. Add explicit #[error("...")] messages to every WalletError variant, ensuring no variant's text includes secret material (keys, seeds, mnemonics, raw bytes).
  3. Verify call sites in crates/api/src/error.rs and crates/wallet-core/src/lib.rs still compile against the new Display text; adjust only if a message change breaks an intentional mapping.
  4. Add a parametrized test every_walleterror_variant_has_an_explicit_display_message_containing_no_secret_material in error.rs enumerating all variants and asserting each Display output is non-empty and free of secret-like content.
  5. Run a final scope check to confirm only WalletError Display/messages and the new test changed.

Issues

Closes #364

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@k2ghostyou Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	crates/wallet-core/src/error.rs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a Display impl for WalletError guaranteed to never include secret material, with a compile-time-checked test

2 participants