Skip to content

Releases: LedgerHQ/ledger-live

live-mobile@4.23.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 20:46
abed962

4.23.0

Minor Changes

  • #22217 63960b1 Thanks @vpenskyi-ledger! - Fix the Swap receive field staying empty when reaching Swap from the Earn no-funds screen. Desktop now always identifies a token by toTokenId (plus its toToken alias), which toCurrencyId alone could not do; mobile passed no parameters at all and now forwards the asset. On both, an account the Earn live app synthesised for a token the user does not hold is no longer sent as an unresolvable id

  • #22404 b42673e Thanks @philipptpunkt! - Read the card cashback banner from GET /v1/card/cashback

    • Add getCardCashback endpoint, resolving the asset's currency/network pair (both nullable) to its ledgerId
    • Remove getRewardWallet (GET /v1/wallet/reward), its schema, types, mock and handlers
    • useCardCashback replaces useCardRewardWallet in the reward banner
    • Banner subtitle now shows the rate and ticker: "Total cashback · 1% in BTC"
    • cardRewardsAvailable / cardRewardCurrency analytics now read the cashback (amount > 0)
  • #22450 2d869a5 Thanks @LucasWerey! - fix(i18n): keep Thai selected across app restarts

    Removes the llmThai / lldThai feature flags. Flags resolve on their enabled: false default
    until the first remote fetch settles, so on every cold start the locale guard saw Thai as
    unsupported and persisted English over the user's choice.

  • #22667 d90780a Thanks @LucasWerey! - Fix the receive screen "Need a Tag/Memo?" link hit area overlapping the Copy address button (LIVE-38004).

  • #22840 e4c24f3 Thanks @LucasWerey! - Name the default Me contact "Me" in the Pay tab contacts list instead of "My addresses (Me)"

  • #22401 b239a21 Thanks @dilaouid! - fix(lwm): object in operation extra malformatted

  • #22381 c5964f8 Thanks @ysitbon! - Rename @domain/api-market-sentiment to @domain/api-market-index-fear-and-greed, and its exported api from marketSentimentApi to fearAndGreedApi, so the name states which CoinMarketCap index the package serves

  • #22453 370f955 Thanks @LucasWerey! - Track the add-password flow through @shared/analytics, per the Password tracking plan.

    The protection drawer reports its enable button as button_clicked with the variant it offers, and a stored password reports encryption_activated with type: "password" and the entry point it came from. That source is passed by each caller — settings from the Settings row, card from the Pay tab — and carried through the flow's route params instead of being guessed from where the user happens to be. password_enabled and biometrics_enabled join every event and the user's traits, read from whichever scheme protects the app, and the traits are refreshed as soon as a password is stored. No payload carries the password or anything derived from it.

    The Settings password and biometrics toggles report toggle_clicked with enabled set to the state the toggle had when it was tapped, on both the revamped and the legacy rows, and the revamped rows now track through @shared/analytics too.

  • #22629 5f20e00 Thanks @LucasWerey! - Lock the app only after it has been away for 15 seconds.

    The gate used to lock the moment the app left. It now notes when the app leaves and decides when it comes back: away for 15 seconds or more, the app locks; back sooner, it opens where the user left it. The lock on launch is unchanged, so an app the system ended while away still asks on the way back.

    While the app is away, protected content is covered, so the app switcher and the moment of return show a cover rather than the wallet. Under Detox the grace is one second, so e2e specs do not wait out the real one. On Android the return comes from the process lifecycle, like the departure, through a new appDidEnterForeground event on AppVisibilityModule; on iOS it is AppState turning active.

  • #22287 5f34cb6 Thanks @LucasWerey! - Stop a card holder from leaving the app with nothing protecting it.

    Both protection rows in Settings let anyone turn protection off, so someone holding a card could strip the app of its last lock. Without a card that stays allowed — the app lock is opt-in — but a card turns "at least one protection" into a rule.

    Removing the last one is now refused, and a sheet says why at the moment the user asks, rather than a disabled row that explains nothing. Removing one of two is still allowed: at least one protection is the invariant, and which one is the user's choice — so a password can still be swapped for biometrics, or the reverse.

    What counts as holding a card is the card session stored on the device, which @features/platform-card owns — not Pay's feature flag, and not whether the Pay tab has been opened. A holder who has not been near Pay on this launch is still a holder, and turning Pay's flag off does not turn the rule off. The session is read when the user asks to remove a protection, not when Settings opens, so a tap can never land before the answer, and a session that started or ended with Settings open is seen. A session that cannot be read counts as a card: a refusal can be retried, while a removal cannot be taken back.

    The rule applies to the revamped rows. The legacy rows shown while lwmPasswordRevamp is off are left as they are.

  • #22347 e012138 Thanks @LucasWerey! - Require a password of at least six characters from users who set a shorter one, the next time they get in.

    Any length was accepted before this epic — "1" among them — so the minimum the new screens enforce would otherwise apply to new passwords only. The prompt cannot be dismissed: there is no close button, the backdrop does not take a press, and the Android back button is swallowed while it holds the screen. A prompt that can be put off is one that short passwords outlive.

    It runs after a successful unlock, not at boot, because that is when the password has been proven and its length is known. Four steps: a sheet that says why, the new password, its confirmation, and a sheet that says it worked. The old password is never asked for again — they just typed it to get in.

    The requirement is stored, beside the verifier it describes. The protection state is deliberately not persisted, since a second source of truth about whether a password exists is a lockout risk, and this mark cannot be recomputed from a digest: a verifier says nothing about the length of the password behind it. So it rides in the same keychain record, written and cleared by the single write that sets the password it describes, and the two cannot disagree.

    It is also re-derived at every password unlock, which is what heals a record written before the mark existed, and what corrects one whose password was changed elsewhere. The stored mark still earns its place: a biometric unlock never sees a password, and the prompt is owed on that boot too.

    A write the keychain declines is reported as a failure rather than as a password change, so the confirmation holds instead of sending the user off with a verifier that is still the old one. The mark's own repair at unlock is best-effort by contrast: metadata must never cost somebody an unlock they have just earned.

    An overlay rather than a route: a route is presented over the app in its own window, and the sheets — which present into the app's window — would be visible through it while taking none of the taps aimed at them.

  • #22556 2074967 Thanks @LucasWerey! - Stop locking the app on Android for flows the app itself starts.

    Clearing the cache reboots the React tree without restarting the process, and the gate took its remount for a launch and locked again. Whether the launch lock was decided now lives in the app-lock state, which a reboot leaves in place, so it is decided once per process.

    Sharing an address or logs, or saving a file from the sh...

Read more

@ledgerhq/live-desktop@4.23.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 20:46
abed962

4.23.0

Minor Changes

  • #22217 63960b1 Thanks @vpenskyi-ledger! - Fix the Swap receive field staying empty when reaching Swap from the Earn no-funds screen. Desktop now always identifies a token by toTokenId (plus its toToken alias), which toCurrencyId alone could not do; mobile passed no parameters at all and now forwards the asset. On both, an account the Earn live app synthesised for a token the user does not hold is no longer sent as an unresolvable id

  • #22404 b42673e Thanks @philipptpunkt! - Read the card cashback banner from GET /v1/card/cashback

    • Add getCardCashback endpoint, resolving the asset's currency/network pair (both nullable) to its ledgerId
    • Remove getRewardWallet (GET /v1/wallet/reward), its schema, types, mock and handlers
    • useCardCashback replaces useCardRewardWallet in the reward banner
    • Banner subtitle now shows the rate and ticker: "Total cashback · 1% in BTC"
    • cardRewardsAvailable / cardRewardCurrency analytics now read the cashback (amount > 0)
  • #22450 2d869a5 Thanks @LucasWerey! - fix(i18n): keep Thai selected across app restarts

    Removes the llmThai / lldThai feature flags. Flags resolve on their enabled: false default
    until the first remote fetch settles, so on every cold start the locale guard saw Thai as
    unsupported and persisted English over the user's choice.

  • #22840 e4c24f3 Thanks @LucasWerey! - Name the default Me contact "Me" in the Pay tab contacts list instead of "My addresses (Me)"

  • #22634 e3b6f7a Thanks @mateuszpalosz-ext! - fix(aleo): keep the newer public and private sync fields when both syncs overlap

  • #22381 c5964f8 Thanks @ysitbon! - Rename @domain/api-market-sentiment to @domain/api-market-index-fear-and-greed, and its exported api from marketSentimentApi to fearAndGreedApi, so the name states which CoinMarketCap index the package serves

  • #22653 e8d5e1b Thanks @OlivierFreyssinet! - Bump DMK dependencies: device-management-kit 1.10.0, device-signer-kit-solana 1.13.3, device-signer-kit-ethereum 1.18.1, context-module 2.6.0, dmk-ledger-wallet 0.6.0, device-contacts-kit 0.5.0, signer-utils 1.3.0, device-transport-kit-mockserver 1.1.2

  • #22567 3ee4143 Thanks @tonykhaov! - List the Me contact in the desktop Send recipient contacts, like mobile, with only its addresses on the selected network.

  • #22615 7bc8d65 Thanks @mcayuelas-ledger! - Open the Pay request flow from the Add stablecoin "Crypto address" option instead of the standard Receive flow

  • #22318 83b8a5c Thanks @tonykhaov! - Use dnd-kit to reorder card assets in the desktop manage-assets dialog

  • #22379 ad2f1de Thanks @philipptpunkt! - Let the card transaction history read past its first page.

    • Both platforms read on by scrolling: native through the list's onEndReached, web through an observer on a sentinel at the end of the table.
    • A spinner marks the page in flight; no new copy, so nothing to translate.
    • Both take loadMore/isLoadingMore from the shared view model, so the three-row previews on the Pay surfaces are unaffected.
  • #22432 cfb7566 Thanks @tonykhaov! - Show the cashback a card transaction earned in its detail view

  • #22665 46cfd43 Thanks @lysyi3m! - fix(celo): label pending withdrawal rows with their unlock date

  • #22474 1a26e59 Thanks @live-github-bot! - Update coin module dependencies (coin-evm, coin-module-framework, coin-stellar, coin-tezos) and rebuild the lockfile

  • #22572 6e76dda Thanks @tonykhaov! - ContactAvatar takes isMe and is the only avatar that formats the Me label, so a Me avatar is announced once as " (Me)". MeAvatar takes a display-ready label and is no longer exported; ME_AVATAR_URL stays exported. PaySuccessRecipient.isMe is now required.

  • #22656 486a1a4 Thanks @LucasWerey! - Only mention ENS in the contact address input placeholder for networks that support domain resolution (LIVE-38284).

  • #22348 f7cd861 Thanks @ysitbon! - Let asset-aggregation and wallet-analytics declare the countervalues interface they need

    Both packages only ever needed one countervalues operation, calculate, over a state they
    receive as a parameter and never inspect. They now declare that operation themselves as a
    RateLookup interface, treat the state as an opaque RateSnapshot, and drop
    @ledgerhq/live-countervalues from their dependencies entirely. The apps fill the interface
    at startup, beside the crypto-assets store and the currencies resolver.

    No caller changes: the exported signatures keep their arity and the state argument is
    assignable as before, so the 41 files consuming these two packages are untouched.

    Tests get simpler as a side effect. Mocking countervalues was a module mock reaching across a
    package boundary; it is now an injected fake passed to setRateLookup.

  • #22534 c5a6a7e Thanks @ysitbon! - fix(feature-flags): report a re-resolution that throws

    A feature-flags re-resolution that throws at boot is now reported through logger.critical,
    whatever the state of the remote-flag cache.

  • #22503 33b4952 Thanks @daniel-choinski-ledger! - Inject the Tron address book into the DMK Tron signer so Tron transactions can clear-sign saved contact names.

    Adds a generic AddressBookProvider<T> in live-dmk-shared (the EVM provider is refactored onto it), a tronAddressBookProvider instance, a pure toTronAddressBook mapper (Contact[] -> TronAddressBook, Tron-family only, no chain id, ledgerAccounts always empty), and registers the source at each app's composition root. An absent or empty book leaves signing behavior unchanged.

  • #22481 d6866e7 Thanks @mcayuelas-ledger! - adapt crypto card title to be consistent

  • #22058 f8c92f9 Thanks @alexstapenka-ledger! - Instrument the shared sign/broadcast bridge defensively and dispatch consent-independent Earn
    transaction lifecycle events for native staking and allow-listed dApps on Desktop and Mobile.

  • #22558 e046686 Thanks @dilaouid! - feat(cosmos): s...

Read more

live-mobile@4.22.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 10:15
af8c537

4.22.0

Minor Changes

  • #22003 40d296b Thanks @liviuciulinaru! - Record the provider app the Card login redirect names, and send x-us-env on every Card request of a US holder

  • #22149 4d1d640 Thanks @mcayuelas-ledger! - Add card reward wallet endpoint and mobile reward balance view

  • #21741 250c1c0 Thanks @tonykhaov! - Add a mobile card-numbers View/Hide control that flips to the provider numbers image

  • #22258 e82ab0c Thanks @mcayuelas-ledger! - Wire the card's Manage PIN and Access Baanx rows to open the Baanx hosted pages in the secure
    browser, and the Help row to open the support article externally.

  • #21520 0d90780 Thanks @pawell24! - Announce the receive QR code to screen readers

    The QR container on the shared receive confirmation screen carried a testID but no
    accessible prop, so it never joined the accessibility tree. It is now a focusable
    element with a role and a localized label, instead of being skipped or announced as
    an unlabeled node.

  • #21747 871e485 Thanks @claudiiafg! - Fix keyboard handling in the mobile Contacts add, edit, and send flows. Input sheets now open at full height with the keyboard, primary actions remain visible in a keyboard-aware QueuedBottomSheet footer, and name fields focus immediately and capitalize each word.

  • #22077 72367fc Thanks @mcayuelas-ledger! - Wire the card onboarding widget to real, derived onboarding data and remove the unused stub endpoint and legacy devtool mock path it replaces

  • #22093 2e94d90 Thanks @LucasWerey! - Fix available balance showing inflated value for DADA cross-network assets (e.g. Tezos + Etherlink)

  • #22192 c22ee67 Thanks @mcayuelas-ledger! - Add reusable Apple/Google Pay add-to-wallet CTA, instructions, and wallet-app opening.

  • #22218 285b50d Thanks @mcayuelas-ledger! - Open Google Wallet through its launch intent, and show iOS and Android error scenes when the wallet app is unavailable, with a Play Store fallback on Android.

  • #21999 724f029 Thanks @mdomanski-ext-ledger! - feat(aleo): share the bond pieces between Desktop and Mobile

    Replaces the ad-hoc messages getTransactionStatus returned for a rejected bond with typed
    error classes, translated on both clients and now distinguishing a closed validator from an
    unbonding one. Adds the isValidatorBondable / getMinBondAmount helpers to the coin
    module, moves the per-network default validator into the Aleo currency config so every
    client reads the same address, and adds a reusable Aleo bridge mock for Mobile.

  • #22336 b5d2be9 Thanks @mateuszpalosz-ext! - feat(aleo): add the claim unbonded staking flow on Mobile

  • #22137 353ed46 Thanks @mdomanski-ext-ledger! - feat(aleo): show the staking position and its status on the Mobile account page

  • #22123 b5338ec Thanks @mateuszpalosz-ext! - feat(aleo): add the shared staking hooks the delegation views read

  • #22212 49b535f Thanks @mdomanski-ext-ledger! - refactor(aleo): serve the validator committee from RTK Query

  • #22211 d137f01 Thanks @LucasWerey! - Offer biometrics on the unlock screen with the symbol the device actually uses.

    The field asked for biometrics with a generic touch symbol, because Lumen had no biometric one when the screen was built. It has since gained FaceId and Fingerprint, so a face device now shows a face and a fingerprint device a fingerprint.

    The device reports six kinds and there are two symbols: a touch is a fingertip on either platform, and everything the device reads from the face — iris and Optic ID included — takes the face symbol, since there is no iris symbol and an eye read is nearer a face than a fingertip. The capability is read asynchronously while the affordance comes from stored state, so the generic touch symbol still stands in for the moment before the device has answered, and for a read that fails.

  • #22275 35a5198 Thanks @LucasWerey! - Give a user protected by biometrics alone a way back when their face goes unread.

    The unlock screen already retried the prompt when tapped, but nothing said so: with no password set, a face the camera never saw left the Ledger mark on black and no visible way forward. The whole screen being the button is no help to someone who cannot tell there is a button.

    A real call to action now sits under the mark — "Unlock Ledger Wallet" — and it appears only once the prompt has gone. While the prompt is up the system dialog owns the screen, and at boot the bare mark is what keeps the handover from the launch screen invisible.

    The other half is the OS's and already works: while its dialog is up, the device credential the app asks for makes iOS draw "Try Face ID Again" and "Enter Passcode" itself. It is only after that dialog is cancelled, when nothing will reopen it, that the app has to offer the way back.

  • #22125 795e693 Thanks @LucasWerey! - Make biometrics a protection in its own right: password and biometrics become independent, and either one alone is enough to lock the app.

    Biometrics used to require a password. Its Settings row was disabled until one existed and reset itself whenever the password went away, and the legacy lock returned early without a password, so a biometrics-only user was never locked at all. The revamped path now derives the lock from both protections, so enabling biometrics alone locks the app — and Settings offers it with no password set.

    The row is hidden where the device has no biometrics, or has the hardware with nothing enrolled, rather than shown disabled: there is nothing the user could do about it from that screen.

    Biometrics is asked for before the unlock screen draws a field, so it is the first thing the user meets and the password is the fallback. While the prompt is up the screen stands in for the splash, with the mark at the splash's own size so the handover moves nothing. Only a refusal reveals the password field — and a user protected by biometrics alone never sees it: pressing the screen asks again, which is their only way in.

    The prompt is an explicit owner check through BiometricPrompt / LAContext, not a side effect of reading a protected keychain item. A biometry-gated read can resolve without the OS ever showing anything, and Android reports a correct device PIN as a success the keystore item cannot consume — either way the caller is told the user proved something they were never asked for. On Android 11 and above the OS draws its own "use PIN" button in place of the negative one, and every label it shows comes from the app rather than the library's English defaults.

    The keychain item is therefore a plain marker, not an authentication step: it records that biometrics is on, which the pro...

Read more

@ledgerhq/live-desktop@4.22.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 10:15
af8c537

4.22.0

Minor Changes

  • #22004 c60196a Thanks @liviuciulinaru! - Carry the provider app id of the Card login redirect through the desktop deep link

  • #22003 40d296b Thanks @liviuciulinaru! - Record the provider app the Card login redirect names, and send x-us-env on every Card request of a US holder

  • #22150 731ebd2 Thanks @mcayuelas-ledger! - Display card reward balance in the desktop card details view

  • #21700 3702460 Thanks @tonykhaov! - Unlock card numbers with the Ledger Wallet password.

  • #22259 e4ac322 Thanks @mcayuelas-ledger! - Wire the card's Manage PIN and Access Baanx rows to open the Baanx hosted pages in the Discover
    webview, and the Help row to open the support article externally.

  • #22077 72367fc Thanks @mcayuelas-ledger! - Wire the card onboarding widget to real, derived onboarding data and remove the unused stub endpoint and legacy devtool mock path it replaces

  • #22093 2e94d90 Thanks @LucasWerey! - Fix available balance showing inflated value for DADA cross-network assets (e.g. Tezos + Etherlink)

  • #21999 724f029 Thanks @mdomanski-ext-ledger! - feat(aleo): share the bond pieces between Desktop and Mobile

    Replaces the ad-hoc messages getTransactionStatus returned for a rejected bond with typed
    error classes, translated on both clients and now distinguishing a closed validator from an
    unbonding one. Adds the isValidatorBondable / getMinBondAmount helpers to the coin
    module, moves the per-network default validator into the Aleo currency config so every
    client reads the same address, and adds a reusable Aleo bridge mock for Mobile.

  • #22053 cf09fa6 Thanks @mateuszpalosz-ext! - feat(aleo): add the claim unbonded staking flow

  • #21975 0a5c2a0 Thanks @mateuszpalosz-ext! - added Aleo staking operations, gated on the enableStaking flag

  • #22123 b5338ec Thanks @mateuszpalosz-ext! - feat(aleo): add the shared staking hooks the delegation views read

  • #22212 49b535f Thanks @mdomanski-ext-ledger! - refactor(aleo): serve the validator committee from RTK Query

  • #22228 1ec8d15 Thanks @tonykhaov! - Refine the Pay card assets list with loading skeletons, translated states, funding information, and asset values in the details dialog.

  • #22276 eca09da Thanks @sarneijim! - Add Braze Tools inspect for local eligibility and requiredStates fetch-cache inject

  • #22164 386710a Thanks @sarneijim! - Share Nano S Touchscreen Upgrade Program banner copy keys so Desktop and Mobile can reuse the same model-specific lookup

  • #22231 c682542 Thanks @tonykhaov! - Open card transaction history from an asset, scope it to that asset, and show cashback values.

  • #22312 319fbe4 Thanks @sarneijim! - Show the signed-off Touchscreen Upgrade Program copy only to Nano S users

  • #22278 95a1007 Thanks @tonykhaov! - Reveal card numbers as soon as the image loads and shorten the flip to 300ms

  • #22182 1557452 Thanks @tonykhaov! - Reveal card numbers without a password unlock gate

  • #22229 905d26b Thanks @tonykhaov! - Add a manage dialog for reordering Pay card funding assets and starting the add-asset flow.

  • #22129 ea94dd0 Thanks @lysyi3m! - fix(concordium): drop the PLT error surface nothing can reach

    mapPltRejectReason turned a chain reject reason into a typed Error and had no
    caller. It could not gain one: an Error is what the pre-send checks return and
    what the signer throws, and neither ever sees a reject reason. A reject reason
    exists only on the wallet-proxy history response, and history renders an
    Operation, which carries failed: true and no cause. Surfacing the cause means
    a code in Operation.extra and a renderer for it, not this function.

    Removed with it: ConcordiumNonExistentTokenId and ConcordiumPltTransferRejected,
    whose only producer it was, and ConcordiumAccountNotAllowed and
    ConcordiumAccountDenied, which never had one — getAccountListStatus folds both
    list verdicts into one, so reporting the cause means widening the stored
    transferStatus first.

    A test in each app now pins that every PLT error a producer can raise has copy of
    its own, so the next one added without it fails rather than reaching a user as a
    class name.

  • #22139 7848066 Thanks @lysyi3m! - feat(concordium): show why the chain rejected a PLT transfer

    A rejected PLT transfer read as a failed row with no explanation. Operation
    details now name the cause, on desktop and mobile.

  • #22147 1648042 Thanks @lysyi3m! - fix(concordium): say which list refused a PLT sender

    A blocked sender was told to contact the issuer for access, which is wrong for a
    deny list. The send flow now reports the two causes separately.

    Removes the unused PltListStatus type.

  • #22186 eb2a2a5 Thanks @lysyi3m! - feat(concordium): surface PLT pause and sender restrictions

  • #22187 31ec33f Thanks @mateuszpalosz-ext! - aleo part 2 staking ui

  • #22141 35105ea Thanks @sarneijim! - Filter desktop Braze Content Cards with local eligibility before publishing to Redux

  • #22281 1a1766d Thanks @mdomanski-ext-ledger! - fix(desktop): keep the amount field ...

Read more

@ledgerhq/live-desktop@4.21.1

Choose a tag to compare

@github-actions github-actions released this 22 Sep 11:20
2ab0010

4.21.1

Patch Changes

live-mobile@4.20.1

Choose a tag to compare

@github-actions github-actions released this 18 Sep 16:02
6baeea1

4.20.1

Patch Changes

  • #22189 153959b Thanks @hedi-edelbloute! - Support Cardano firmware app v8.0.8 by bumping @cardano-foundation/ledgerjs-hw-app-cardano from 7.x to 8.0.0. The v7 host binding used an older APDU protocol incompatible with the rewritten v8 device app, breaking account scan, receive and signing flows on firmware 8.0.x. Also raise the Cardano nano app minVersion to 8.0.8 so users on an incompatible older app are prompted to update instead of hitting broken flows.

  • #22198 b9c7dea Thanks @gre-ledger! - Enforce the QR code pairing sequence on both sides of the handshake

    The host and the candidate now run the pairing messages through an explicit single-use state
    machine: each message is only accepted at the one point of the sequence where it is expected,
    and the peer that initiated the handshake is bound for the whole session. Envelopes, keys and
    decrypted bodies are validated before being acted upon, so a duplicate, out-of-order, foreign or
    malformed message ends the session with a QRCodeProtocolError: Desktop then asks for a fresh
    QR code, Mobile goes to its existing retry screen.

  • Updated dependencies [b9c7dea]:

    • @ledgerhq/ledger-key-ring-protocol@0.21.3

@ledgerhq/live-desktop@4.20.1

Choose a tag to compare

@github-actions github-actions released this 18 Sep 16:02
6baeea1

4.20.1

Patch Changes

  • #22198 b9c7dea Thanks @gre-ledger! - Enforce the QR code pairing sequence on both sides of the handshake

    The host and the candidate now run the pairing messages through an explicit single-use state
    machine: each message is only accepted at the one point of the sequence where it is expected,
    and the peer that initiated the handshake is bound for the whole session. Envelopes, keys and
    decrypted bodies are validated before being acted upon, so a duplicate, out-of-order, foreign or
    malformed message ends the session with a QRCodeProtocolError: Desktop then asks for a fresh
    QR code, Mobile goes to its existing retry screen.

  • Updated dependencies [153959b, b9c7dea]:

    • @ledgerhq/live-common@37.6.1
    • @ledgerhq/ledger-key-ring-protocol@0.21.3
    • @ledgerhq/asset-detail@0.11.5
    • @ledgerhq/live-dmk-desktop@0.21.1

live-mobile@4.20.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 15:32
657069a

4.20.0

Minor Changes

  • #21206 750bdd4 Thanks @RobinVncnt! - Add mobile E2E for the post-onboarding hub mock flow (LIVE-31323).

  • #21042 d5e1c7d Thanks @ooke-ledger! - Tell the two Hyperliquid account-picker states apart.

    The perps receiving step used one description for both states, so users who already had a Hyperliquid account were told to add one. It now reads "Select an account you want to deposit funds into to place your trades" when accounts exist, and keeps "To fund your perps, you need a Hyperliquid account.

  • #21515 7f4723c Thanks @sarneijim! - Bump Segment analytics SDKs for retry, rate-limit and security fixes (LIVE-35839)

  • #21237 db835f9 Thanks @vpenskyi-ledger! - Remove native navbar title on Select Quote page in Swap wallet40 header

  • #21355 fc74af8 Thanks @semeano! - Offer the Zcash memo only to shielded recipients. A memo travels in a shielded output, so a transparent recipient could never receive one, yet the send flow showed the input for every Zcash address and made the user fill or skip it. Send descriptors can now distinguish static memo support from recipient-specific visibility, and a memo left over from an earlier shielded recipient is dropped when the recipient turns transparent, so it can no longer reach the transaction builder.

  • #21421 3d23fd4 Thanks @tonykhaov! - Add a first-time verify hint on mobile Pay Request, persisted once dismissed.

  • #21434 b7f83a1 Thanks @tonykhaov! - Add persisted Pay Request verify-hint state in @features/flow-pay-request.

  • #21367 d182d46 Thanks @claudiiafg! - Fix the Ledger Sync entry point from Contacts: align the introduction copy and artwork with the production design, only show it when the user actually tries to add a contact or an address, start the flow on "Choose your sync method", and return to Contacts instead of the Portfolio once the flow is done on Mobile.

  • #21470 5b79eb3 Thanks @claudiiafg! - Fix the Contacts add address flow stalling on Continue by only offering networks the device can register an address on: EVM networks running their own coin app, such as Ethereum Classic, Sonic and Sei, are no longer selectable

  • #21431 c06bd2e Thanks @claudiiafg! - Fix the extra left padding on the address field of the Mobile add address and edit address drawers. Both screens render the address without the "To:" prefix, but Lumen's AddressInput mounts its prefix even when empty, so the prefix still took a slot in the field's inner gap and pushed the address 8px to the right. Add address now drops that gap and keeps the spacing only between the address and the trailing QR code icon, and edit address, which has no trailing icon, uses a plain TextInput instead.

  • #21543 eea933c Thanks @claudiiafg! - Fix the trash icon of the contact "Delete contact" action rendering white instead of red.

  • #21587 46b51dd Thanks @claudiiafg! - Fix the Contacts feature introduction so closing it counts as seen and keeps you on the Contacts list, instead of navigating back and reopening the introduction on the next visit.

  • #21592 9e0d7eb Thanks @koda-apps! - Fix misaligned "Maybe later" link on the notifications opt-in prompt drawer

  • #21393 406f56f Thanks @RobinVncnt! - Align the content card tag and dismiss cross with their desktop counterparts by using the Lumen UI Tag and InteractiveIcon components.

  • #21026 4f514c9 Thanks @LucasWerey! - Store a scrypt verifier instead of the password itself. Confirming a password now derives a digest and persists {version, scrypt, salt, digest} in the keychain, so nothing that can be replayed as a password is kept anywhere.

    The protection state lands with it: two independent flags plus a session lock, keyed off "any protection is enabled" rather than on having a password, which is the coupling that makes biometrics-only impossible today.

    Ordering is the safety argument throughout — the whole verifier is one keychain item, so an interrupted write leaves the previous verifier or none, never a half-written pairing, and the state flips only once the write has landed. Derivations are serialised: two concurrent setups would otherwise interleave and store a verifier whose salt belongs to the other run.

    The password field also gains a length cap. It sits far above anything anyone types, and exists because deriving a digest is deliberately slow.

  • #21746 c2e2276 Thanks @amaslakov! - Add the error message shown when the protocol refuses a Tezos stake amount as too small

  • #21401 8c40cc1 Thanks @claudiiafg! - Skip the extra confirmation modal when editing a contact or address name. Apply changes now starts the device action directly when needed, and the Apply CTA shows the Ledger logo in that case.

  • #21440 0089a4b Thanks @claudiiafg! - Drive Contacts add-address confirmation through the Device Intent Executor instead of mocked Continue screens, including prefill and Send entry points.

  • #21599 e601584 Thanks @LucasWerey! - Pin the Contacts feature introduction CTA to the bottom of the mobile sheet

  • #21277 37dde9f Thanks @sarneijim! - Log Segment identify calls (enqueued or failed) in the mobile analytics debug overlay

  • #21606 000eac0 Thanks @LucasWerey! - Fix missing 8px spacing between items in the mobile contacts list

  • #21526 4494817 Thanks @tonykhaov! - Open the contact address sheet from the Pay strip and continue to MAD with the chosen recipient.

  • #21418 60ee73c Thanks @liviuciulinaru! - Rename CARD_API_URL to CARD_BAANX_API_URL, keep the production defaults, and drop the Env vars section from the Card / Pay DevTool.

  • #21551 727b9e5 Thanks @mcayuelas-ledger! - Register and persist the card onboarding widget state in Ledger Wallet M...

Read more

@ledgerhq/live-desktop@4.20.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 15:32
657069a

4.20.0

Minor Changes

  • #21371 56bf73c Thanks @vpenskyi-ledger! - Fix NoFundsStake modal passing raw currency object to Swap live-app instead of expected { toCurrencyId } format, causing the Receive field to not be pre-filled when navigating from Earn zero-balance account flow

  • #21042 d5e1c7d Thanks @ooke-ledger! - Tell the two Hyperliquid account-picker states apart.

    The perps receiving step used one description for both states, so users who already had a Hyperliquid account were told to add one. It now reads "Select an account you want to deposit funds into to place your trades" when accounts exist, and keeps "To fund your perps, you need a Hyperliquid account.

  • #21515 7f4723c Thanks @sarneijim! - Bump Segment analytics SDKs for retry, rate-limit and security fixes (LIVE-35839)

  • #21433 8f8f1a4 Thanks @mcayuelas-ledger! - Add a web ContactAddressPicker dialog skeleton to the Pay contact flow and open it from the desktop Pay tab when a contact is pressed. The address list UI and the account/send handoff on address selection land in follow-ups.

  • #21355 fc74af8 Thanks @semeano! - Offer the Zcash memo only to shielded recipients. A memo travels in a shielded output, so a transparent recipient could never receive one, yet the send flow showed the input for every Zcash address and made the user fill or skip it. Send descriptors can now distinguish static memo support from recipient-specific visibility, and a memo left over from an earlier shielded recipient is dropped when the recipient turns transparent, so it can no longer reach the transaction builder.

  • #21434 b7f83a1 Thanks @tonykhaov! - Add persisted Pay Request verify-hint state in @features/flow-pay-request.

  • #21408 c270975 Thanks @tonykhaov! - Add a first-time Popover on desktop Pay Request Verify.

  • #21367 d182d46 Thanks @claudiiafg! - Fix the Ledger Sync entry point from Contacts: align the introduction copy and artwork with the production design, only show it when the user actually tries to add a contact or an address, start the flow on "Choose your sync method", and return to Contacts instead of the Portfolio once the flow is done on Mobile.

  • #21470 5b79eb3 Thanks @claudiiafg! - Fix the Contacts add address flow stalling on Continue by only offering networks the device can register an address on: EVM networks running their own coin app, such as Ethereum Classic, Sonic and Sei, are no longer selectable

  • #21453 3b0dbae Thanks @mcayuelas-ledger! - Add the web ContactAddressPicker dialog to the Pay contact flow and open it from the desktop Pay tab when a contact is pressed. The picker lists the contact's addresses segmented by network with asset-aware icons, resolved through the view model, and exposes an optional add-address action that routes to the contact's add-address flow. Address grouping, icon resolution and truncation are shared from @features/flow-contacts. The account/send handoff on address selection lands in a follow-up.

  • #21587 46b51dd Thanks @claudiiafg! - Fix the Contacts feature introduction so closing it counts as seen and keeps you on the Contacts list, instead of navigating back and reopening the introduction on the next visit.

  • #21601 96661b4 Thanks @mateuszpalosz-ext! - part 1 for Aleo bond flow

  • #21746 c2e2276 Thanks @amaslakov! - Add the error message shown when the protocol refuses a Tezos stake amount as too small

  • #21401 8c40cc1 Thanks @claudiiafg! - Skip the extra confirmation modal when editing a contact or address name. Apply changes now starts the device action directly when needed, and the Apply CTA shows the Ledger logo in that case.

  • #21440 0089a4b Thanks @claudiiafg! - Drive Contacts add-address confirmation through the Device Intent Executor instead of mocked Continue screens, including prefill and Send entry points.

  • #21374 d6e689f Thanks @tonykhaov! - Update the desktop Pay feature tour layout and copy to match mockups (LIVE-36499).

  • #21418 60ee73c Thanks @liviuciulinaru! - Rename CARD_API_URL to CARD_BAANX_API_URL, keep the production defaults, and drop the Env vars section from the Card / Pay DevTool.

  • #21548 55bd216 Thanks @mcayuelas-ledger! - Add a getCardOnboardingStatus RTK Query endpoint and a schema-validated mock fixture.

  • #21550 6ed1820 Thanks @mcayuelas-ledger! - Mount and persist the card onboarding widget in Ledger Wallet Desktop.

  • #21546 85474db Thanks @semeano! - Change show private balance label.

  • #21248 9672658 Thanks @OlivierFreyssinet! - Edit an external address on the device from Contacts. The device intent now calls @ledgerhq/device-contacts-kit's ContactsManager.editExternalAddressIdentifier() and ContactsManager.editExternalAddressScope(), each returning the rotated address proof to persist while the group's name proof passes through untouched, and both apps render the confirmation step and one InfoState per failure.

    The device serves address and label edits as two separate commands, so an edit changing both asks the user to confirm twice, showing the same waiting screen for each step rather than numbering them. Nothing partial is ever stored: an abandoned or rejected edit leaves the record untouched, and a retry restarts the whole chain.

  • #21247 a55d4ca Thanks @OlivierFreyssinet! - Rename a contact on the device from Contacts. The device intent now calls @ledgerhq/device-contacts-kit's ContactsManager.renameContact(), which returns the rotated name proof to persist, and both apps render the confirmation step and one InfoState per failure. A rejection keeps the job open so the user can retry on the same device.

    Rename is a blockchain-agnostic dashboard operation, so it initializes on the dashboard (BOLOS) rather than a coin app: a contact with no address is renameable, and an outdated device surfaces as an OS-update screen instead of an app-update one.

  • #21269 [8c83fe6](8c83fe6b...

Read more

@ledgerhq/live-desktop@4.19.1

Choose a tag to compare

@github-actions github-actions released this 11 Sep 13:48
7c9ab74

4.19.1

Patch Changes

  • #21863 a312094 Thanks @francois-guerin-ledger! - chore(llc): update Arc mainnet native contract address

  • Updated dependencies [a312094]:

    • @ledgerhq/live-common@37.5.1
    • @ledgerhq/asset-detail@0.11.4
    • @ledgerhq/live-dmk-desktop@0.20.10