fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: misreported hw key bug - #936

Merged
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug
Mar 30, 2026
Merged

fix: misreported hw key bug#936
coodos merged 6 commits into
mainfrom
fix/eid-wallet-misreported-software-key-bug

Conversation

@coodos

@coodoscoodos commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Description of change

  • getManager() now checks persisted context (+ cross-context by keyId) and queries eVault before falling back to factory
  • signPayload() runs #ensureKeySyncedToEvault() before every sign (cached per session per keyId)
  • On sign failure: tries eVault key resolution first, then hardware→software fallback
  • New methods: #resolveManagerByEvaultKey(), #ensureKeySyncedToEvault(), #findPersistedByKeyId(), setEvaultKeyResolver(), setEvaultSyncHandler()

Issue Number

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added eVault integration for public key registration and automatic synchronization during signing operations.
  • Improvements

    • Enhanced error handling and user-facing messages when processing social binding QR codes, with fallback identity display on request failures.
    • Refined key resolution logic across signing workflows for improved reliability.
  • Refactor

    • Code formatting and structure improvements throughout the codebase.

@coderabbitai

coderabbitaiBot commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 15 minutes and 19 seconds before requesting another review.

Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 15 minutes and 19 seconds.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 650f3af1-ca28-4d56-8ae9-2ccdc9d7fdff

📥 Commits

Reviewing files that changed from the base of the PR and between ccb48cc and 44ed4ee.

📒 Files selected for processing (6)
  • infrastructure/eid-wallet/package.json
  • infrastructure/eid-wallet/src-tauri/tauri.conf.json
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/settings/+page.svelte
📝 Walkthrough

Walkthrough

This PR integrates eVault-based key resolution and synchronization into the wallet. It adds a method to VaultController to fetch registered public keys from eVault's /whois endpoint, extends KeyService to resolve keys via eVault as a fallback mechanism and ensure keys are synced before signing, and wires these new handlers into GlobalState. Multiple UI components are updated to use a new signing context parameter.

Changes

Cohort / File(s)Summary
eVault Key Resolution & Sync
infrastructure/eid-wallet/src/lib/global/controllers/evault.ts, infrastructure/eid-wallet/src/lib/global/controllers/key.ts, infrastructure/eid-wallet/src/lib/global/state.ts
Added fetchRegisteredPublicKeys() to retrieve keys from eVault /whois endpoint; extended KeyService with resolver/sync callbacks and eVault-based key resolution fallback in getManager(); integrated handlers into GlobalState constructor.
UI Signing Context Updates
infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte, infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts, infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
Updated wallet signing calls to use "signing" context instead of "default"; enhanced error handling in social binding QR scan logic with explicit catch and user-facing messages.
Formatting & Refactoring
platforms/blabsy/client/src/components/chat/chat-window.tsx, platforms/blabsy/client/src/lib/context/chat-context.tsx, platforms/esigner/client/src/lib/stores/files.ts, platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte
Reformatted type annotations, state initializations, and conditional expressions without functional changes.

Sequence Diagram

sequenceDiagram
actor User
participant UI as UI Component
participant KeyService
participant VaultController
participant eVault as eVault API
participant Storage as Local Storage
User->>UI: Request signing
UI->>KeyService: getManager() / signPayload()
KeyService->>Storage: Restore persisted context
alt Persisted context found
KeyService->>Storage: Verify key exists
KeyService-->>UI: Use restored manager
else Persisted context missing/invalid
KeyService->>KeyService: setEvaultKeyResolver()
KeyService->>VaultController: Call resolver
VaultController->>eVault: GET /whois (with ename)
eVault-->>VaultController: Return keyBindingCertificates
VaultController->>VaultController: Decode & filter certs
VaultController-->>KeyService: Return public keys[]
KeyService->>Storage: Compare with local keys
KeyService-->>UI: Resolved manager
end
UI->>KeyService: signPayload() pre-sign
KeyService->>KeyService: setEvaultSyncHandler()
KeyService->>VaultController: Call sync handler
VaultController->>eVault: Sync public key
eVault-->>VaultController: Sync complete
KeyService->>Storage: Sign with resolved key
Storage-->>KeyService: Signature
KeyService-->>UI: Return signature
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested labels

evault-refactor

Suggested reviewers

  • xPathin
  • sosweetham

Poem

🐰 Keys dancing in the eVault store,
Syncing secrets we adore,
Resolving paths where none exist,
With JWT payloads gently kissed,
A rabbit's blessing on your quest! 🔐✨

🚥 Pre-merge checks | ❌ 3

❌ Failed checks (3 warnings)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title refers to fixing a hardware key bug, but the changeset shows substantial eVault integration, key resolution logic, and signing context changes across multiple files.Revise the title to better reflect the primary changes, such as 'feat: add eVault-based key resolution and sync integration' or clarify what 'misreported hw key bug' specifically addresses.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check⚠️ WarningPR description is incomplete and missing required information. Type of change is identified but testing details and reasoning are absent.Add 'How the change has been tested' section with specific test cases and steps. Provide issue number or link context. Explain the bug being fixed in 'Description of change' and detail testing methodology.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/eid-wallet-misreported-software-key-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos marked this pull request as ready for review March 30, 2026 10:51

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@infrastructure/eid-wallet/src/lib/global/controllers/evault.ts`:
- Around line 721-723: The JWT payload decoding omits base64url padding before
calling atob, causing InvalidCharacterError for unpadded segments; update the
decoding in the evault controller (the code that builds b64 from parts[1] and
parses payload) to add '=' padding until b64.length % 4 === 0 before calling
atob, then JSON.parse the result into the existing payload variable so valid
certificates aren't skipped.
In `@infrastructure/eid-wallet/src/lib/global/controllers/key.ts`:
- Around line 25-26: The pre-sign sync hook currently lacks a signing context
and a success result which lets the wrong keyId be cached as "synced"; update
the hook signature(s) and callers so the handler receives the exact keyId and
signing context and returns a boolean success. Concretely: change
EvaultKeyResolver/EvaultSyncHandler types and any GlobalState hook/method
signatures to accept (keyId: string, context: string) and return
Promise<boolean>, update VaultController.syncPublicKey to accept the same
(keyId, context) and return true only when the upload actually succeeds
(propagate errors instead of swallowing), and modify the code that caches synced
keys (the lines that currently store raw keyId after handler return) to cache
only when the handler returned true. Ensure all call sites (including where
VaultController.syncPublicKey is invoked) pass the validated keyId and context
through.
- Around line 99-119: The current logic deletes this.#contexts entry using
cacheKey when a restored manager is missing, but if persisted came from
`#findPersistedByKeyId`(keyId) you must delete the actual persisted map entry
instead of cacheKey; change the cleanup to remove the map key that corresponds
to the persisted entry (e.g., capture the mapKey returned/identified by
`#findPersistedByKeyId` or locate the matching entry in this.#contexts and call
this.#contexts.delete(matchingMapKey)), then call this.#store.set(CONTEXTS_KEY,
Object.fromEntries(this.#contexts)); apply the same fix for the other occurrence
at the 481-487 region.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9dbcefad-352b-45cb-9819-a4130689444b

📥 Commits

Reviewing files that changed from the base of the PR and between 718f013 and ccb48cc.

📒 Files selected for processing (10)
  • infrastructure/eid-wallet/src/lib/global/controllers/evault.ts
  • infrastructure/eid-wallet/src/lib/global/controllers/key.ts
  • infrastructure/eid-wallet/src/lib/global/state.ts
  • infrastructure/eid-wallet/src/routes/(app)/ePassport/+page.svelte
  • infrastructure/eid-wallet/src/routes/(app)/scan-qr/scanLogic.ts
  • infrastructure/eid-wallet/src/routes/(auth)/onboarding/+page.svelte
  • platforms/blabsy/client/src/components/chat/chat-window.tsx
  • platforms/blabsy/client/src/lib/context/chat-context.tsx
  • platforms/esigner/client/src/lib/stores/files.ts
  • platforms/pictique/client/src/routes/(protected)/messages/[id]/+page.svelte

Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/evault.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts Outdated
Comment threadinfrastructure/eid-wallet/src/lib/global/controllers/key.ts
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@coodos
coodos merged commit 9512a3d into mainMar 30, 2026
4 checks passed
@coodos
coodos deleted the fix/eid-wallet-misreported-software-key-bug branch March 30, 2026 14:50
@coderabbitaicoderabbitaiBot mentioned this pull request Jun 1, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@coodos