feat: add bluewallet#4679
Conversation
|
Thanks much for the submission! We don't use superlatives (such as "most trusted" in the screenshot) in listings. Also, the screenshots could be more consistent with other listings showing the full screen with no titles. Yeh, I just looked at pictures! Will check out the rest soon. |
|
roger roger! @ncoelho is working on replacement images |
65f93bf to
0228933
Compare
|
images replaced |
|
I have reviewed BlueWallet based on the current wallet requirements criteria and my evaluation is below. The summary is that the wallet passes on security, architecture, and overall design, however because the website does not yet support HSTS, I cannot at this time recommend it for listing. I will be glad to recommend BlueWallet for listing once this website issue is resolved. A few additional notes:
BlueWalletVersion v7.2.6 (latest tagged release; master at v8.0.0)Review Version 2026051501The wallet list is based on the personal evaluation of the maintainer(s) and These requirements are meant to be updated and strengthened over time. Basic requirements:
Optional criteria (some could become requirements):
|
|
@devdavidejesus Review LGTM. |
|
I looked into HSTS issue, and its not something we can fix easily, without introducing more intermediaries (like Cloudflare or Netlify). Currently the website sources are static and live on Github, and are directly published to Github Pages, which is quite elegant if you ask me. Is it something we can disregard? |
The history here is that this has been a listing criterion for over a decade and every wallet listed during that time period has complied. After a decade, HSTS still remains a "good idea" protecting sites against practical MITM attacks such as sslstrip. To be direct here, a wavier based on choice of hosting platforms would seem to allow just about any excuse (it's a pretty low bar) and would be paramount to removing the criterion. That said, a potential path forward would be a proposal issue or PR for removing the criterion. As much I would like to see BlueWallet listed, I'm not sure that's a good step forward. |
|
i was thinking for a few workarounds:
worst case scenario, i will set up deployment on Netlify |
|
Since the backup-domain option came up above, I verified the three BlueWallet domains against the official HSTS preload list (hstspreload.org) and checked what each one currently serves. HSTS preload status:
None of the three sends an HSTS header at the server level (verified today). What the domains serve: Posting this just so the verified facts are on the record. |
|
The requirement is that any sites serving executable code pointed to in the listing be HSTS enabled. Switching the link to one of the "backup" sites would certainly satisfy this requirement. |
Nicknic1
left a comment
There was a problem hiding this comment.
I will consult with s professional first then I'll get back to it thanks
|
pull request updated to use dot-app domain |
|
LGTM. I recommend BlueWallet for listing. Thanks everyone. |
|
LGTM. Will merge once the iOS and Android screenshots are resized to 250x350. Thank you for adding this wallet! |
|
Just checking if there’s any feedback on this. @Overtorment |
|
PR updated |
|
@Overtorment thanks for updating the images —> the iOS and Android screenshots look good now (both 250×350, filling the frame). Two things before this is ready to go in: 1. Desktop screenshot ( 2. Taproot tag —> now that the Could you add the
→
(both lines, so mobile and desktop stay consistent, same codebase backs both.) Once those two are in, this should be good for merge. |
a51a38f to
38b30b7
Compare
38b30b7 to
6ee8e40
Compare
|
PR updated |
LGTM. Both items resolved, verified on @Overtorment , thanks for the quick turnaround on the images and the Taproot verification. |
|
LGTM. |
Building on top of #3000
Submitting BlueWallet for review and addition to onchain wallets.
Full disclosure, this PR was created with help of cursor and opus 4.7