Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Wallet config file is saved with default permissions

Đã đóng
#331 0 bình luận 0 reaction 1 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 3 ngày

@tvpeter đang làm issue này rồi.

Từ ngày 21/9/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

bug

Describe the bug
The app wallet config command saves wallet configuration into config.toml using default directory permissions. As a result, the plaintext keys are readable, allowing any other local user or process on the host to be able to read the content of the file. A user reading it would reasonably expect the file to be user-only similar to bitcoind's cookie and LND macaroons.

To Reproduce

On a system with the common default :

  • Generate a key and build a secret descriptor via the documented flow (key generate to xprv/tprv, then descriptor).
  • Save a wallet config containing that secret descriptor:
  • bdk-cli wallet -w test config -e "wpkh(…/84'/1'/0'/0/)" -i "wpkh(…/84'/1'/0'/1/)"
  • Inspect the resulting permissions

Expected behavior

The application should enforce strict, user-only permissions for sensitive key-bearing files, matching standard security practices.

Build environment

  • BDK-CLI tag/commit: v4.0.0 5b3cb00
  • OS+version: macOS 26.6.2
  • Rust/Cargo version: 1.98.1
  • Rust/Cargo target:
Ngôn ngữ chính
Rust
Star
143
Fork
98
Merge trung bình
5 ngày 21 giờ
Pull request đã merge (30 ngày)
4

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của bitcoindevkit/bdk-cli

Tất cả issue của bitcoindevkit/bdk-cli

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.