Skip to content

bitbox02: allow passphrase entry in app - #4445

Open
benma-agent wants to merge 1 commit into
BitBoxSwiss:masterfrom
benma-agent:benma-agent/host-passphrase
Open

benma-agent wants to merge 1 commit into
BitBoxSwiss:masterfrom
benma-agent:benma-agent/host-passphrase

Conversation

@benma-agent

@benma-agent benma-agent commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Add an "Enter passphrase in app" link beneath "Enter BitBox passphrase" on the unlock screen. Show overlays for device consent, host input and passphrase confirmation while keeping the unlock screen visible underneath.

Withdraw the link when consent or confirmation starts. Rejection and cancellation resume device entry with a fresh prompt; guard against stale requests and delayed UI updates. The feature requires firmware 9.28.0 or later with optional passphrases enabled, and also works when attestation fails.

Validate against the firmware keyboard character set and 149-byte limit before sending input. Show validation errors in the dialog and keep input editable for correction or cancellation, preserving spaces and allowing an empty passphrase.

The go.mod replacement remains until the api-go PR is merged. make servewallet still works because it uses the vendored api-go dependency (-mod=vendor).

Related PRs:

Screenshots captured with Playwright against the app and firmware simulator:

Unsupported characters — desktop

Unsupported passphrase characters on desktop

Unsupported characters — mobile

Unsupported passphrase characters on mobile

Passphrase length limit

Passphrase exceeds the 149-character limit

@benma-agent
benma-agent force-pushed the benma-agent/host-passphrase branch 3 times, most recently from 4449d5b to 7051fd6 Compare September 25, 2026 15:48
@benma
benma requested a review from Beerosagos September 25, 2026 15:48
@benma
benma marked this pull request as ready for review September 25, 2026 15:49
@benma
benma requested a review from a team as a code owner September 25, 2026 15:49
Comment thread go.mod
Comment on lines +78 to +79

replace github.com/BitBoxSwiss/bitbox02-api-go => ../bitbox02-api-go

@benma benma Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will be removed once BitBoxSwiss/bitbox02-api-go#188 is merged and included here. make servewallet works regardless as it uses the vendored copy.

Offer "Enter passphrase in app" during optional BIP39 passphrase entry.
Ask for consent on the BitBox before accepting host input, then have the
BitBox confirm the submitted passphrase. Keep the unlock screen visible
under the consent, input and confirmation dialogs.

Withdraw host entry when consent or confirmation starts. Rejection and
cancellation resume device entry with a fresh prompt; guard against stale
requests and delayed UI updates. Keep protocol handling in the API library.

Validate against the firmware keyboard character set and 149-byte limit
before sending input, preventing oversized submissions from breaking the
connection. Show validation errors in the dialog and keep input editable.
Preserve spaces and distinguish an empty passphrase from cancellation.

Require firmware 9.28.0 or later with optional passphrases enabled, and
support the flow even when attestation fails. Vendor the API integration,
including the session-reset fix for reconnecting during unlock.

Keep the go.mod replacement until the api-go PR is merged. make servewallet
continues to work because it uses the vendored dependency.
@benma-agent
benma-agent force-pushed the benma-agent/host-passphrase branch from 7051fd6 to e374939 Compare September 25, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants