fix: copy the master at each layer so zeroization stays local
This commit is contained in:
parent
d7179694a6
commit
f7452832ea
3 changed files with 19 additions and 5 deletions
|
|
@ -67,7 +67,12 @@ class FumiNative {
|
|||
/// operation, so it never needs an isolate — and widget tests can settle
|
||||
/// it inside their fake-async zones.
|
||||
void setMaster(Uint8List master, {int? rotations}) {
|
||||
_master = master;
|
||||
// Own copy: the caller keeps its buffer (the onboarding screen zeroes
|
||||
// its reference on dispose, and wipe zeroes Hive's), and the account
|
||||
// rebuilds after register/restore/rotate must derive from untouched
|
||||
// bytes — a shared buffer zeroized elsewhere would rebuild an account
|
||||
// that matches none of our keys.
|
||||
_master = Uint8List.fromList(master);
|
||||
_rebuildAccount(rotations: rotations);
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue