Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Wallet config file is saved with default permissions

クローズ
#331 コメント 0 件 リアクション 0 件 担当者 1 名 GitHub で見る

メンテナーはふだん 3 日以内に返信

@tvpeter がすでに取り組んでいます。

2026年9月21日 から。

評価

この issue はまだ評価されていません。

説明

bug

Describe the bug
The app wallet config command saves wallet configuration into config.toml using default directory permissions. As a result, the plaintext keys are readable, allowing any other local user or process on the host to be able to read the content of the file. A user reading it would reasonably expect the file to be user-only similar to bitcoind's cookie and LND macaroons.

To Reproduce

On a system with the common default :

  • Generate a key and build a secret descriptor via the documented flow (key generate to xprv/tprv, then descriptor).
  • Save a wallet config containing that secret descriptor:
  • bdk-cli wallet -w test config -e "wpkh(…/84'/1'/0'/0/)" -i "wpkh(…/84'/1'/0'/1/)"
  • Inspect the resulting permissions

Expected behavior

The application should enforce strict, user-only permissions for sensitive key-bearing files, matching standard security practices.

Build environment

  • BDK-CLI tag/commit: v4.0.0 5b3cb00
  • OS+version: macOS 26.6.2
  • Rust/Cargo version: 1.98.1
  • Rust/Cargo target:
主要言語
Rust
スター
143
フォーク
98
平均マージ
6日 8時間
マージ済み PR(30日)
6

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

bitcoindevkit/bdk-cli のほかの issue

bitcoindevkit/bdk-cli の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。