You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
wdk-react-native-core PR #77 (tetherto/wdk-react-native-core#77) hardens the wallet lifecycle — lock() now returns a Promise and shares a mutex with other lifecycle calls, createWallet/restoreWallet now throw if a wallet is already active instead of silently overwriting the session, and a new switchWallet() convenience replaces the old manual lock+unlock pattern. This PR updates the showcase app to match.
What changed
src/app/index.tsx
Home screen's wallet-switch handler did lock() (unawaited) followed by await unlock(id). Replaced with await switchWallet(id) — the atomic convenience the upstream PR added specifically for this case, guaranteeing the previous wallet is fully locked before the next one loads.
src/app/features/wallet/manage-account.tsx
The "Lock Wallet" action called lock() without await. Since lock() now returns Promise, added await so the operation actually completes before the UI reports success.
src/app/features/cloud/cloud-backup.tsx
The restore flow called restoreWallet(mnemonic, targetId) directly with no guard for an already-active wallet. Under the new SDK behavior this would throw if a different wallet was unlocked at the time of restore. Added lock to the useWalletManager() destructure and guard the restore call: if (activeWalletId) { await lock(); } before restoreWallet(...).
Not changed (verified unaffected)
enableAutoInitialization, currentUserId, clearSensitiveDataOnBackground — never passed to WdkAppProvider in this app.
retry() — never called from useWdkApp.
setActiveWalletId — never called.
state.walletId optionality under LOCKED — never read in this codebase.
Dependency note
For testing, @tetherto/wdk-react-native-core is temporarily pointed at the PR branch:
This needs to be swapped back to the published version once #77 merges upstream.
Testing
Verified switchWallet cleanly transitions between two wallets from the Home screen, including rapid repeated switching.
Verified lock() completes before the UI reports "Wallet locked."
Verified createWallet/restoreWallet correctly throw (and display a clean error) on the raw testing screen when a wallet is already active — expected new behavior, not a regression.
Verified the specific regression scenario: Wallet A active → restore Wallet B from cloud backup → succeeds, and A is auto-locked first instead of throwing.
Verified restore-with-nothing-active still works unchanged.
Ran a full fresh-install happy path (create wallet → transfer screen → backup/restore) to confirm no other regressions.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@tetherto/wdk-worklet-bundler@1.0.0-beta.9. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
wdk-react-native-core PR #77 (tetherto/wdk-react-native-core#77) hardens the wallet lifecycle — lock() now returns a Promise and shares a mutex with other lifecycle calls, createWallet/restoreWallet now throw if a wallet is already active instead of silently overwriting the session, and a new switchWallet() convenience replaces the old manual lock+unlock pattern. This PR updates the showcase app to match.
What changed
src/app/index.tsx
Home screen's wallet-switch handler did lock() (unawaited) followed by await unlock(id). Replaced with await switchWallet(id) — the atomic convenience the upstream PR added specifically for this case, guaranteeing the previous wallet is fully locked before the next one loads.
src/app/features/wallet/manage-account.tsx
The "Lock Wallet" action called lock() without await. Since lock() now returns Promise, added await so the operation actually completes before the UI reports success.
src/app/features/cloud/cloud-backup.tsx
The restore flow called restoreWallet(mnemonic, targetId) directly with no guard for an already-active wallet. Under the new SDK behavior this would throw if a different wallet was unlocked at the time of restore. Added lock to the useWalletManager() destructure and guard the restore call: if (activeWalletId) { await lock(); } before restoreWallet(...).
Not changed (verified unaffected)
enableAutoInitialization, currentUserId, clearSensitiveDataOnBackground — never passed to WdkAppProvider in this app.
retry() — never called from useWdkApp.
setActiveWalletId — never called.
state.walletId optionality under LOCKED — never read in this codebase.
Dependency note
For testing, @tetherto/wdk-react-native-core is temporarily pointed at the PR branch:
github:nulllpc/wdk-react-native-core-fork#72b3793b706158163aaf6e7b6d2ee451e22aaea4
This needs to be swapped back to the published version once #77 merges upstream.
Testing
Verified switchWallet cleanly transitions between two wallets from the Home screen, including rapid repeated switching.
Verified lock() completes before the UI reports "Wallet locked."
Verified createWallet/restoreWallet correctly throw (and display a clean error) on the raw testing screen when a wallet is already active — expected new behavior, not a regression.
Verified the specific regression scenario: Wallet A active → restore Wallet B from cloud backup → succeeds, and A is auto-locked first instead of throwing.
Verified restore-with-nothing-active still works unchanged.
Ran a full fresh-install happy path (create wallet → transfer screen → backup/restore) to confirm no other regressions.