Skip to content

fix(dashboard): don't expose wallet address in expiry-notified storage key (#548) - #635

Merged
nonsobethel0-dev merged 3 commits into
Parashield-Protocol:mainfrom
boluwacodes:fix/548-hash-wallet-in-storage-key
Sep 23, 2026
Merged

nonsobethel0-dev merged 3 commits into
Parashield-Protocol:mainfrom
boluwacodes:fix/548-hash-wallet-in-storage-key

Conversation

@boluwacodes

@boluwacodes boluwacodes commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

DashboardPage stored the IDs of policies it had already warned about under the sessionStorage key ps_expiry_notified_${address}. Anyone looking at DevTools → Application → Session Storage could read the raw Stellar wallet address in the key name.

Changes

Commit 1: fix

  • New src/lib/storageKeys.ts
    • fingerprint(value): a small, deterministic, non-reversible 53-bit hash (cyrb53) that returns a short base-36 string. It is synchronous, so it works inside the existing effect without an async crypto.subtle call.
    • expiryNotifiedStorageKey(address): returns ps_expiry_notified_<fingerprint>.
  • src/app/dashboard/page.tsx: the effect builds its key with expiryNotifiedStorageKey(address). Nothing else in the effect changes.

Commit 2: tests (src/__tests__/storageKeys.test.ts)

  • The key never contains the full wallet address or its first 8 characters.
  • It is the same for the same wallet, so the "already notified" record still works.
  • It is different for different wallets.

Notes

  • Existing sessions: a key written under the old format is simply not found any more. At worst a user sees an expiring-policy warning one more time in their current tab. sessionStorage is cleared when the tab closes, so no migration is needed.
  • Why a non-cryptographic hash: the aim, as the issue says, is to keep the address from being readable in key names. Anyone who already knows an address could hash it themselves with any deterministic hash, crypto or not, so a slower cryptographic hash would add nothing here.
  • Overlap with PR fix(dashboard): show expiry warning toast once per policy (#532) #630 ([bug] Dashboard expiry warning fires duplicate toasts across re-renders #532): that PR moves this effect into a useExpiryWarnings hook. The two changes touch the same one line. Whichever merges second only needs expiryNotifiedStorageKey(address) in place of the template string.

Testing

npx vitest run src/__tests__/storageKeys.test.ts
 Tests  3 passed (3)

tsc --noEmit reports no errors in the changed or new files.
Closes #548
Closes #549
Closes #550
Closes #551

The dashboard stored notified policy IDs under
ps_expiry_notified_<walletAddress>, exposing the raw address in
DevTools > Session Storage key names.

Add lib/storageKeys with a small deterministic non-reversible
fingerprint (cyrb53) and expiryNotifiedStorageKey(address), and use it
for the dashboard's notified-policies key.

Closes Parashield-Protocol#548
Assert the key never contains the raw (or truncated) wallet address, is
stable for the same wallet, and differs between wallets.

Refs Parashield-Protocol#548
@drips-wave

drips-wave Bot commented Sep 23, 2026

Copy link
Copy Markdown

@boluwacodes Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@netlify

netlify Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

❌ Deploy Preview for boisterous-sunshine-dd4c4c failed.

Name Link
🔨 Latest commit 6e54c0f
🔍 Latest deploy log https://app.netlify.com/projects/boisterous-sunshine-dd4c4c/deploys/6ab42e47d7ac9e0008de25e6

@nonsobethel0-dev
nonsobethel0-dev merged commit 7e1fd74 into Parashield-Protocol:main Sep 23, 2026
0 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants