bitbox02: allow passphrase entry in app - #4445
Open
benma-agent wants to merge 1 commit into
Open
benma-agent wants to merge 1 commit into
benma-agent wants to merge 1 commit into
Conversation
This was referenced Sep 20, 2026
benma-agent
force-pushed
the
benma-agent/host-passphrase
branch
3 times, most recently
from
September 25, 2026 15:48
4449d5b to
7051fd6
Compare
benma
marked this pull request as ready for review
September 25, 2026 15:49
benma
reviewed
Sep 25, 2026
Comment on lines
+78
to
+79
|
|
||
| replace github.com/BitBoxSwiss/bitbox02-api-go => ../bitbox02-api-go |
Contributor
There was a problem hiding this comment.
Will be removed once BitBoxSwiss/bitbox02-api-go#188 is merged and included here. make servewallet works regardless as it uses the vendored copy.
Offer "Enter passphrase in app" during optional BIP39 passphrase entry. Ask for consent on the BitBox before accepting host input, then have the BitBox confirm the submitted passphrase. Keep the unlock screen visible under the consent, input and confirmation dialogs. Withdraw host entry when consent or confirmation starts. Rejection and cancellation resume device entry with a fresh prompt; guard against stale requests and delayed UI updates. Keep protocol handling in the API library. Validate against the firmware keyboard character set and 149-byte limit before sending input, preventing oversized submissions from breaking the connection. Show validation errors in the dialog and keep input editable. Preserve spaces and distinguish an empty passphrase from cancellation. Require firmware 9.28.0 or later with optional passphrases enabled, and support the flow even when attestation fails. Vendor the API integration, including the session-reset fix for reconnecting during unlock. Keep the go.mod replacement until the api-go PR is merged. make servewallet continues to work because it uses the vendored dependency.
benma-agent
force-pushed
the
benma-agent/host-passphrase
branch
from
September 25, 2026 18:00
7051fd6 to
e374939
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add an "Enter passphrase in app" link beneath "Enter BitBox passphrase" on the unlock screen. Show overlays for device consent, host input and passphrase confirmation while keeping the unlock screen visible underneath.
Withdraw the link when consent or confirmation starts. Rejection and cancellation resume device entry with a fresh prompt; guard against stale requests and delayed UI updates. The feature requires firmware 9.28.0 or later with optional passphrases enabled, and also works when attestation fails.
Validate against the firmware keyboard character set and 149-byte limit before sending input. Show validation errors in the dialog and keep input editable for correction or cancellation, preserving spaces and allowing an empty passphrase.
The
go.modreplacement remains until the api-go PR is merged.make servewalletstill works because it uses the vendored api-go dependency (-mod=vendor).Related PRs:
Screenshots captured with Playwright against the app and firmware simulator:
Unsupported characters — desktop
Unsupported characters — mobile
Passphrase length limit