Skip to content

[Bug]: --json swallows the shared-dev-account warning, and a typo'd env var silently signs with the public account #292

Description

@filip-parity

Component

Other

Priority

P1

What happened?

Two related footguns around the implicit shared dev account:

  1. With no auth configured the CLI signs with the public dev mnemonic and warns on stderr — but with --json the warning is swallowed entirely (withCapturedConsole no-ops console.warn and both stream writes). Verified: pop status --json on a clean HOME emits clean JSON and 0 bytes of stderr.
  2. A typo'd env var name (DOTNS_MNEMONIC_TYPO=...) is silently ignored and the run falls back to the shared account. Verified by warning-count diff between correct and typo'd var names.

So exactly the audience that most needs the warning — scripts and CI running --json — never sees it, and a one-character env typo means transacting from a keypair everyone controls. This is also the top finding of the security review (auth ladder falls back to the public dev mnemonic).

Expected behavior

Either fail closed when nothing but the default resolves (require an explicit --allow-dev-account style opt-in), or at minimum keep the dev-account warning visible in --json mode (stderr is fair game for warnings even with machine-readable stdout).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

P1Secondary Prioritydotns-sdkRelated to the DotNS SDKtype: bugBug report

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions