Repository navigation
Conversation
🦋 Changeset detectedLatest commit: dcaac2e The changes in this PR will be included in the next version bump. This PR includes changesets to release 6 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
✅ Deploy Preview for appccc ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for apiccc ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for liveccc ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for docsccc ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
3e9345b to
dcaac2e
Compare
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (17)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe PR replaces bitcoinjs-lib PSBT handling with ChangesBitcoin PSBT handling
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant BitcoinSigner
participant JoyID
participant parseSignedPsbt
participant finalizeSignedInputs
BitcoinSigner->>JoyID: Request PSBT with autoFinalized false
JoyID-->>BitcoinSigner: Return signed PSBT
BitcoinSigner->>parseSignedPsbt: Validate response against original PSBT
parseSignedPsbt-->>BitcoinSigner: Return parsed transactions
opt Local finalization requested
BitcoinSigner->>finalizeSignedInputs: Finalize requested inputs with new signatures
finalizeSignedInputs-->>BitcoinSigner: Return finalized PSBT hex
end
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The PSBT signer migration looks consistent, and no concrete merge-blocking issue was found. Live JoyID wallet behavior was not exercised against the tests' mocked responses, which is normal pre-release validation. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The new signing flow checks that JoyID returns the same unsigned transaction, but it does not establish that all other PSBT data is unchanged. The signer migration may also remove extension fields when a PSBT is finalized locally. These are transaction-scoped risks; the available evidence does not establish an exploit or a broader service impact. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 29.17% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 24 functions across 10 files. (6 skipped: 6 unsupported.)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/canary |
|
🚀 Canary version published successfully! View workflow run The following packages have been published to npm:
|

Refs #517. Supersedes #556.
signPsbtalways returns a PSBT. JoyID is asked not to finalize, and CCC finalizes the inputs JoyID signed.initEccLib.Breaking (playground):
bitcoinfrom@ckb-ccc/playgroundis gone. Useimport * as btc from "@scure/btc-signer".Tested on testnet with JoyID and Xverse.