Releases: LedgerHQ/ledger-live
Release list
live-mobile@4.23.0
4.23.0
Minor Changes
-
#22217
63960b1Thanks @vpenskyi-ledger! - Fix the Swap receive field staying empty when reaching Swap from the Earn no-funds screen. Desktop now always identifies a token bytoTokenId(plus itstoTokenalias), whichtoCurrencyIdalone could not do; mobile passed no parameters at all and now forwards the asset. On both, an account the Earn live app synthesised for a token the user does not hold is no longer sent as an unresolvable id -
#22404
b42673eThanks @philipptpunkt! - Read the card cashback banner fromGET /v1/card/cashback- Add
getCardCashbackendpoint, resolving the asset'scurrency/networkpair (both nullable) to itsledgerId - Remove
getRewardWallet(GET /v1/wallet/reward), its schema, types, mock and handlers useCardCashbackreplacesuseCardRewardWalletin the reward banner- Banner subtitle now shows the rate and ticker: "Total cashback · 1% in BTC"
cardRewardsAvailable/cardRewardCurrencyanalytics now read the cashback (amount > 0)
- Add
-
#22450
2d869a5Thanks @LucasWerey! - fix(i18n): keep Thai selected across app restartsRemoves the
llmThai/lldThaifeature flags. Flags resolve on theirenabled: falsedefault
until the first remote fetch settles, so on every cold start the locale guard saw Thai as
unsupported and persisted English over the user's choice. -
#22667
d90780aThanks @LucasWerey! - Fix the receive screen "Need a Tag/Memo?" link hit area overlapping the Copy address button (LIVE-38004). -
#22840
e4c24f3Thanks @LucasWerey! - Name the default Me contact "Me" in the Pay tab contacts list instead of "My addresses (Me)" -
#22401
b239a21Thanks @dilaouid! - fix(lwm): object in operation extra malformatted -
#22381
c5964f8Thanks @ysitbon! - Rename@domain/api-market-sentimentto@domain/api-market-index-fear-and-greed, and its exported api frommarketSentimentApitofearAndGreedApi, so the name states which CoinMarketCap index the package serves -
#22453
370f955Thanks @LucasWerey! - Track the add-password flow through@shared/analytics, per the Password tracking plan.The protection drawer reports its enable button as
button_clickedwith the variant it offers, and a stored password reportsencryption_activatedwithtype: "password"and the entry point it came from. Thatsourceis passed by each caller —settingsfrom the Settings row,cardfrom the Pay tab — and carried through the flow's route params instead of being guessed from where the user happens to be.password_enabledandbiometrics_enabledjoin every event and the user's traits, read from whichever scheme protects the app, and the traits are refreshed as soon as a password is stored. No payload carries the password or anything derived from it.The Settings password and biometrics toggles report
toggle_clickedwithenabledset to the state the toggle had when it was tapped, on both the revamped and the legacy rows, and the revamped rows now track through@shared/analyticstoo. -
#22629
5f20e00Thanks @LucasWerey! - Lock the app only after it has been away for 15 seconds.The gate used to lock the moment the app left. It now notes when the app leaves and decides when it comes back: away for 15 seconds or more, the app locks; back sooner, it opens where the user left it. The lock on launch is unchanged, so an app the system ended while away still asks on the way back.
While the app is away, protected content is covered, so the app switcher and the moment of return show a cover rather than the wallet. Under Detox the grace is one second, so e2e specs do not wait out the real one. On Android the return comes from the process lifecycle, like the departure, through a new
appDidEnterForegroundevent onAppVisibilityModule; on iOS it isAppStateturning active. -
#22287
5f34cb6Thanks @LucasWerey! - Stop a card holder from leaving the app with nothing protecting it.Both protection rows in Settings let anyone turn protection off, so someone holding a card could strip the app of its last lock. Without a card that stays allowed — the app lock is opt-in — but a card turns "at least one protection" into a rule.
Removing the last one is now refused, and a sheet says why at the moment the user asks, rather than a disabled row that explains nothing. Removing one of two is still allowed: at least one protection is the invariant, and which one is the user's choice — so a password can still be swapped for biometrics, or the reverse.
What counts as holding a card is the card session stored on the device, which
@features/platform-cardowns — not Pay's feature flag, and not whether the Pay tab has been opened. A holder who has not been near Pay on this launch is still a holder, and turning Pay's flag off does not turn the rule off. The session is read when the user asks to remove a protection, not when Settings opens, so a tap can never land before the answer, and a session that started or ended with Settings open is seen. A session that cannot be read counts as a card: a refusal can be retried, while a removal cannot be taken back.The rule applies to the revamped rows. The legacy rows shown while
lwmPasswordRevampis off are left as they are. -
#22347
e012138Thanks @LucasWerey! - Require a password of at least six characters from users who set a shorter one, the next time they get in.Any length was accepted before this epic —
"1"among them — so the minimum the new screens enforce would otherwise apply to new passwords only. The prompt cannot be dismissed: there is no close button, the backdrop does not take a press, and the Android back button is swallowed while it holds the screen. A prompt that can be put off is one that short passwords outlive.It runs after a successful unlock, not at boot, because that is when the password has been proven and its length is known. Four steps: a sheet that says why, the new password, its confirmation, and a sheet that says it worked. The old password is never asked for again — they just typed it to get in.
The requirement is stored, beside the verifier it describes. The protection state is deliberately not persisted, since a second source of truth about whether a password exists is a lockout risk, and this mark cannot be recomputed from a digest: a verifier says nothing about the length of the password behind it. So it rides in the same keychain record, written and cleared by the single write that sets the password it describes, and the two cannot disagree.
It is also re-derived at every password unlock, which is what heals a record written before the mark existed, and what corrects one whose password was changed elsewhere. The stored mark still earns its place: a biometric unlock never sees a password, and the prompt is owed on that boot too.
A write the keychain declines is reported as a failure rather than as a password change, so the confirmation holds instead of sending the user off with a verifier that is still the old one. The mark's own repair at unlock is best-effort by contrast: metadata must never cost somebody an unlock they have just earned.
An overlay rather than a route: a route is presented over the app in its own window, and the sheets — which present into the app's window — would be visible through it while taking none of the taps aimed at them.
-
#22556
2074967Thanks @LucasWerey! - Stop locking the app on Android for flows the app itself starts.Clearing the cache reboots the React tree without restarting the process, and the gate took its remount for a launch and locked again. Whether the launch lock was decided now lives in the app-lock state, which a reboot leaves in place, so it is decided once per process.
Sharing an address or logs, or saving a file from the sh...
@ledgerhq/live-desktop@4.23.0
4.23.0
Minor Changes
-
#22217
63960b1Thanks @vpenskyi-ledger! - Fix the Swap receive field staying empty when reaching Swap from the Earn no-funds screen. Desktop now always identifies a token bytoTokenId(plus itstoTokenalias), whichtoCurrencyIdalone could not do; mobile passed no parameters at all and now forwards the asset. On both, an account the Earn live app synthesised for a token the user does not hold is no longer sent as an unresolvable id -
#22404
b42673eThanks @philipptpunkt! - Read the card cashback banner fromGET /v1/card/cashback- Add
getCardCashbackendpoint, resolving the asset'scurrency/networkpair (both nullable) to itsledgerId - Remove
getRewardWallet(GET /v1/wallet/reward), its schema, types, mock and handlers useCardCashbackreplacesuseCardRewardWalletin the reward banner- Banner subtitle now shows the rate and ticker: "Total cashback · 1% in BTC"
cardRewardsAvailable/cardRewardCurrencyanalytics now read the cashback (amount > 0)
- Add
-
#22450
2d869a5Thanks @LucasWerey! - fix(i18n): keep Thai selected across app restartsRemoves the
llmThai/lldThaifeature flags. Flags resolve on theirenabled: falsedefault
until the first remote fetch settles, so on every cold start the locale guard saw Thai as
unsupported and persisted English over the user's choice. -
#22840
e4c24f3Thanks @LucasWerey! - Name the default Me contact "Me" in the Pay tab contacts list instead of "My addresses (Me)" -
#22634
e3b6f7aThanks @mateuszpalosz-ext! - fix(aleo): keep the newer public and private sync fields when both syncs overlap -
#22381
c5964f8Thanks @ysitbon! - Rename@domain/api-market-sentimentto@domain/api-market-index-fear-and-greed, and its exported api frommarketSentimentApitofearAndGreedApi, so the name states which CoinMarketCap index the package serves -
#22653
e8d5e1bThanks @OlivierFreyssinet! - Bump DMK dependencies: device-management-kit 1.10.0, device-signer-kit-solana 1.13.3, device-signer-kit-ethereum 1.18.1, context-module 2.6.0, dmk-ledger-wallet 0.6.0, device-contacts-kit 0.5.0, signer-utils 1.3.0, device-transport-kit-mockserver 1.1.2 -
#22567
3ee4143Thanks @tonykhaov! - List the Me contact in the desktop Send recipient contacts, like mobile, with only its addresses on the selected network. -
#22615
7bc8d65Thanks @mcayuelas-ledger! - Open the Pay request flow from the Add stablecoin "Crypto address" option instead of the standard Receive flow -
#22318
83b8a5cThanks @tonykhaov! - Use dnd-kit to reorder card assets in the desktop manage-assets dialog -
#22379
ad2f1deThanks @philipptpunkt! - Let the card transaction history read past its first page.- Both platforms read on by scrolling: native through the list's
onEndReached, web through an observer on a sentinel at the end of the table. - A spinner marks the page in flight; no new copy, so nothing to translate.
- Both take
loadMore/isLoadingMorefrom the shared view model, so the three-row previews on the Pay surfaces are unaffected.
- Both platforms read on by scrolling: native through the list's
-
#22432
cfb7566Thanks @tonykhaov! - Show the cashback a card transaction earned in its detail view -
#22665
46cfd43Thanks @lysyi3m! - fix(celo): label pending withdrawal rows with their unlock date -
#22474
1a26e59Thanks @live-github-bot! - Update coin module dependencies (coin-evm, coin-module-framework, coin-stellar, coin-tezos) and rebuild the lockfile -
#22572
6e76ddaThanks @tonykhaov! -ContactAvatartakesisMeand is the only avatar that formats the Me label, so a Me avatar is announced once as " (Me)".MeAvatartakes a display-readylabeland is no longer exported;ME_AVATAR_URLstays exported.PaySuccessRecipient.isMeis now required. -
#22656
486a1a4Thanks @LucasWerey! - Only mention ENS in the contact address input placeholder for networks that support domain resolution (LIVE-38284). -
#22348
f7cd861Thanks @ysitbon! - Let asset-aggregation and wallet-analytics declare the countervalues interface they needBoth packages only ever needed one countervalues operation,
calculate, over a state they
receive as a parameter and never inspect. They now declare that operation themselves as a
RateLookupinterface, treat the state as an opaqueRateSnapshot, and drop
@ledgerhq/live-countervaluesfrom their dependencies entirely. The apps fill the interface
at startup, beside the crypto-assets store and the currencies resolver.No caller changes: the exported signatures keep their arity and the state argument is
assignable as before, so the 41 files consuming these two packages are untouched.Tests get simpler as a side effect. Mocking countervalues was a module mock reaching across a
package boundary; it is now an injected fake passed tosetRateLookup. -
#22534
c5a6a7eThanks @ysitbon! - fix(feature-flags): report a re-resolution that throwsA feature-flags re-resolution that throws at boot is now reported through
logger.critical,
whatever the state of the remote-flag cache. -
#22503
33b4952Thanks @daniel-choinski-ledger! - Inject the Tron address book into the DMK Tron signer so Tron transactions can clear-sign saved contact names.Adds a generic
AddressBookProvider<T>inlive-dmk-shared(the EVM provider is refactored onto it), atronAddressBookProviderinstance, a puretoTronAddressBookmapper (Contact[] -> TronAddressBook, Tron-family only, no chain id,ledgerAccountsalways empty), and registers the source at each app's composition root. An absent or empty book leaves signing behavior unchanged. -
#22481
d6866e7Thanks @mcayuelas-ledger! - adapt crypto card title to be consistent -
#22058
f8c92f9Thanks @alexstapenka-ledger! - Instrument the shared sign/broadcast bridge defensively and dispatch consent-independent Earn
transaction lifecycle events for native staking and allow-listed dApps on Desktop and Mobile.
live-mobile@4.22.0
4.22.0
Minor Changes
-
#22003
40d296bThanks @liviuciulinaru! - Record the provider app the Card login redirect names, and send x-us-env on every Card request of a US holder -
#22149
4d1d640Thanks @mcayuelas-ledger! - Add card reward wallet endpoint and mobile reward balance view -
#21741
250c1c0Thanks @tonykhaov! - Add a mobile card-numbers View/Hide control that flips to the provider numbers image -
#22258
e82ab0cThanks @mcayuelas-ledger! - Wire the card's Manage PIN and Access Baanx rows to open the Baanx hosted pages in the secure
browser, and the Help row to open the support article externally. -
#21520
0d90780Thanks @pawell24! - Announce the receive QR code to screen readersThe QR container on the shared receive confirmation screen carried a
testIDbut no
accessibleprop, so it never joined the accessibility tree. It is now a focusable
element with a role and a localized label, instead of being skipped or announced as
an unlabeled node. -
#21747
871e485Thanks @claudiiafg! - Fix keyboard handling in the mobile Contacts add, edit, and send flows. Input sheets now open at full height with the keyboard, primary actions remain visible in a keyboard-awareQueuedBottomSheetfooter, and name fields focus immediately and capitalize each word. -
#22077
72367fcThanks @mcayuelas-ledger! - Wire the card onboarding widget to real, derived onboarding data and remove the unused stub endpoint and legacy devtool mock path it replaces -
#22093
2e94d90Thanks @LucasWerey! - Fix available balance showing inflated value for DADA cross-network assets (e.g. Tezos + Etherlink) -
#22192
c22ee67Thanks @mcayuelas-ledger! - Add reusable Apple/Google Pay add-to-wallet CTA, instructions, and wallet-app opening. -
#22218
285b50dThanks @mcayuelas-ledger! - Open Google Wallet through its launch intent, and show iOS and Android error scenes when the wallet app is unavailable, with a Play Store fallback on Android. -
#21999
724f029Thanks @mdomanski-ext-ledger! - feat(aleo): share the bond pieces between Desktop and MobileReplaces the ad-hoc messages
getTransactionStatusreturned for a rejected bond with typed
error classes, translated on both clients and now distinguishing a closed validator from an
unbonding one. Adds theisValidatorBondable/getMinBondAmounthelpers to the coin
module, moves the per-network default validator into the Aleo currency config so every
client reads the same address, and adds a reusable Aleo bridge mock for Mobile. -
#22336
b5d2be9Thanks @mateuszpalosz-ext! - feat(aleo): add the claim unbonded staking flow on Mobile -
#22137
353ed46Thanks @mdomanski-ext-ledger! - feat(aleo): show the staking position and its status on the Mobile account page -
#22123
b5338ecThanks @mateuszpalosz-ext! - feat(aleo): add the shared staking hooks the delegation views read -
#22212
49b535fThanks @mdomanski-ext-ledger! - refactor(aleo): serve the validator committee from RTK Query -
#22211
d137f01Thanks @LucasWerey! - Offer biometrics on the unlock screen with the symbol the device actually uses.The field asked for biometrics with a generic touch symbol, because Lumen had no biometric one when the screen was built. It has since gained
FaceIdandFingerprint, so a face device now shows a face and a fingerprint device a fingerprint.The device reports six kinds and there are two symbols: a touch is a fingertip on either platform, and everything the device reads from the face — iris and Optic ID included — takes the face symbol, since there is no iris symbol and an eye read is nearer a face than a fingertip. The capability is read asynchronously while the affordance comes from stored state, so the generic touch symbol still stands in for the moment before the device has answered, and for a read that fails.
-
#22275
35a5198Thanks @LucasWerey! - Give a user protected by biometrics alone a way back when their face goes unread.The unlock screen already retried the prompt when tapped, but nothing said so: with no password set, a face the camera never saw left the Ledger mark on black and no visible way forward. The whole screen being the button is no help to someone who cannot tell there is a button.
A real call to action now sits under the mark — "Unlock Ledger Wallet" — and it appears only once the prompt has gone. While the prompt is up the system dialog owns the screen, and at boot the bare mark is what keeps the handover from the launch screen invisible.
The other half is the OS's and already works: while its dialog is up, the device credential the app asks for makes iOS draw "Try Face ID Again" and "Enter Passcode" itself. It is only after that dialog is cancelled, when nothing will reopen it, that the app has to offer the way back.
-
#22125
795e693Thanks @LucasWerey! - Make biometrics a protection in its own right: password and biometrics become independent, and either one alone is enough to lock the app.Biometrics used to require a password. Its Settings row was disabled until one existed and reset itself whenever the password went away, and the legacy lock returned early without a password, so a biometrics-only user was never locked at all. The revamped path now derives the lock from both protections, so enabling biometrics alone locks the app — and Settings offers it with no password set.
The row is hidden where the device has no biometrics, or has the hardware with nothing enrolled, rather than shown disabled: there is nothing the user could do about it from that screen.
Biometrics is asked for before the unlock screen draws a field, so it is the first thing the user meets and the password is the fallback. While the prompt is up the screen stands in for the splash, with the mark at the splash's own size so the handover moves nothing. Only a refusal reveals the password field — and a user protected by biometrics alone never sees it: pressing the screen asks again, which is their only way in.
The prompt is an explicit owner check through
BiometricPrompt/LAContext, not a side effect of reading a protected keychain item. A biometry-gated read can resolve without the OS ever showing anything, and Android reports a correct device PIN as a success the keystore item cannot consume — either way the caller is told the user proved something they were never asked for. On Android 11 and above the OS draws its own "use PIN" button in place of the negative one, and every label it shows comes from the app rather than the library's English defaults.The keychain item is therefore a plain marker, not an authentication step: it records that biometrics is on, which the pro...
@ledgerhq/live-desktop@4.22.0
4.22.0
Minor Changes
-
#22004
c60196aThanks @liviuciulinaru! - Carry the provider app id of the Card login redirect through the desktop deep link -
#22003
40d296bThanks @liviuciulinaru! - Record the provider app the Card login redirect names, and send x-us-env on every Card request of a US holder -
#22150
731ebd2Thanks @mcayuelas-ledger! - Display card reward balance in the desktop card details view -
#21700
3702460Thanks @tonykhaov! - Unlock card numbers with the Ledger Wallet password. -
#22259
e4ac322Thanks @mcayuelas-ledger! - Wire the card's Manage PIN and Access Baanx rows to open the Baanx hosted pages in the Discover
webview, and the Help row to open the support article externally. -
#22077
72367fcThanks @mcayuelas-ledger! - Wire the card onboarding widget to real, derived onboarding data and remove the unused stub endpoint and legacy devtool mock path it replaces -
#22093
2e94d90Thanks @LucasWerey! - Fix available balance showing inflated value for DADA cross-network assets (e.g. Tezos + Etherlink) -
#21999
724f029Thanks @mdomanski-ext-ledger! - feat(aleo): share the bond pieces between Desktop and MobileReplaces the ad-hoc messages
getTransactionStatusreturned for a rejected bond with typed
error classes, translated on both clients and now distinguishing a closed validator from an
unbonding one. Adds theisValidatorBondable/getMinBondAmounthelpers to the coin
module, moves the per-network default validator into the Aleo currency config so every
client reads the same address, and adds a reusable Aleo bridge mock for Mobile. -
#22053
cf09fa6Thanks @mateuszpalosz-ext! - feat(aleo): add the claim unbonded staking flow -
#21975
0a5c2a0Thanks @mateuszpalosz-ext! - added Aleo staking operations, gated on theenableStakingflag -
#22123
b5338ecThanks @mateuszpalosz-ext! - feat(aleo): add the shared staking hooks the delegation views read -
#22212
49b535fThanks @mdomanski-ext-ledger! - refactor(aleo): serve the validator committee from RTK Query -
#22228
1ec8d15Thanks @tonykhaov! - Refine the Pay card assets list with loading skeletons, translated states, funding information, and asset values in the details dialog. -
#22276
eca09daThanks @sarneijim! - Add Braze Tools inspect for local eligibility and requiredStates fetch-cache inject -
#22164
386710aThanks @sarneijim! - Share Nano S Touchscreen Upgrade Program banner copy keys so Desktop and Mobile can reuse the same model-specific lookup -
#22231
c682542Thanks @tonykhaov! - Open card transaction history from an asset, scope it to that asset, and show cashback values. -
#22312
319fbe4Thanks @sarneijim! - Show the signed-off Touchscreen Upgrade Program copy only to Nano S users -
#22278
95a1007Thanks @tonykhaov! - Reveal card numbers as soon as the image loads and shorten the flip to 300ms -
#22182
1557452Thanks @tonykhaov! - Reveal card numbers without a password unlock gate -
#22229
905d26bThanks @tonykhaov! - Add a manage dialog for reordering Pay card funding assets and starting the add-asset flow. -
#22129
ea94dd0Thanks @lysyi3m! - fix(concordium): drop the PLT error surface nothing can reachmapPltRejectReasonturned a chain reject reason into a typedErrorand had no
caller. It could not gain one: anErroris what the pre-send checks return and
what the signer throws, and neither ever sees a reject reason. A reject reason
exists only on the wallet-proxy history response, and history renders an
Operation, which carriesfailed: trueand no cause. Surfacing the cause means
a code inOperation.extraand a renderer for it, not this function.Removed with it:
ConcordiumNonExistentTokenIdandConcordiumPltTransferRejected,
whose only producer it was, andConcordiumAccountNotAllowedand
ConcordiumAccountDenied, which never had one —getAccountListStatusfolds both
list verdicts into one, so reporting the cause means widening the stored
transferStatusfirst.A test in each app now pins that every PLT error a producer can raise has copy of
its own, so the next one added without it fails rather than reaching a user as a
class name. -
#22139
7848066Thanks @lysyi3m! - feat(concordium): show why the chain rejected a PLT transferA rejected PLT transfer read as a failed row with no explanation. Operation
details now name the cause, on desktop and mobile. -
#22147
1648042Thanks @lysyi3m! - fix(concordium): say which list refused a PLT senderA blocked sender was told to contact the issuer for access, which is wrong for a
deny list. The send flow now reports the two causes separately.Removes the unused
PltListStatustype. -
#22186
eb2a2a5Thanks @lysyi3m! - feat(concordium): surface PLT pause and sender restrictions -
#22187
31ec33fThanks @mateuszpalosz-ext! - aleo part 2 staking ui -
#22141
35105eaThanks @sarneijim! - Filter desktop Braze Content Cards with local eligibility before publishing to Redux -
#22281
1a1766dThanks @mdomanski-ext-ledger! - fix(desktop): keep the amount field ...
@ledgerhq/live-desktop@4.21.1
live-mobile@4.20.1
4.20.1
Patch Changes
-
#22189
153959bThanks @hedi-edelbloute! - Support Cardano firmware app v8.0.8 by bumping @cardano-foundation/ledgerjs-hw-app-cardano from 7.x to 8.0.0. The v7 host binding used an older APDU protocol incompatible with the rewritten v8 device app, breaking account scan, receive and signing flows on firmware 8.0.x. Also raise the Cardano nano app minVersion to 8.0.8 so users on an incompatible older app are prompted to update instead of hitting broken flows. -
#22198
b9c7deaThanks @gre-ledger! - Enforce the QR code pairing sequence on both sides of the handshakeThe host and the candidate now run the pairing messages through an explicit single-use state
machine: each message is only accepted at the one point of the sequence where it is expected,
and the peer that initiated the handshake is bound for the whole session. Envelopes, keys and
decrypted bodies are validated before being acted upon, so a duplicate, out-of-order, foreign or
malformed message ends the session with aQRCodeProtocolError: Desktop then asks for a fresh
QR code, Mobile goes to its existing retry screen. -
Updated dependencies [
b9c7dea]:- @ledgerhq/ledger-key-ring-protocol@0.21.3
@ledgerhq/live-desktop@4.20.1
4.20.1
Patch Changes
-
#22198
b9c7deaThanks @gre-ledger! - Enforce the QR code pairing sequence on both sides of the handshakeThe host and the candidate now run the pairing messages through an explicit single-use state
machine: each message is only accepted at the one point of the sequence where it is expected,
and the peer that initiated the handshake is bound for the whole session. Envelopes, keys and
decrypted bodies are validated before being acted upon, so a duplicate, out-of-order, foreign or
malformed message ends the session with aQRCodeProtocolError: Desktop then asks for a fresh
QR code, Mobile goes to its existing retry screen. -
Updated dependencies [
153959b,b9c7dea]:- @ledgerhq/live-common@37.6.1
- @ledgerhq/ledger-key-ring-protocol@0.21.3
- @ledgerhq/asset-detail@0.11.5
- @ledgerhq/live-dmk-desktop@0.21.1
live-mobile@4.20.0
4.20.0
Minor Changes
-
#21206
750bdd4Thanks @RobinVncnt! - Add mobile E2E for the post-onboarding hub mock flow (LIVE-31323). -
#21042
d5e1c7dThanks @ooke-ledger! - Tell the two Hyperliquid account-picker states apart.The perps receiving step used one description for both states, so users who already had a Hyperliquid account were told to add one. It now reads "Select an account you want to deposit funds into to place your trades" when accounts exist, and keeps "To fund your perps, you need a Hyperliquid account.
-
#21515
7f4723cThanks @sarneijim! - Bump Segment analytics SDKs for retry, rate-limit and security fixes (LIVE-35839) -
#21237
db835f9Thanks @vpenskyi-ledger! - Remove native navbar title on Select Quote page in Swap wallet40 header -
#21355
fc74af8Thanks @semeano! - Offer the Zcash memo only to shielded recipients. A memo travels in a shielded output, so a transparent recipient could never receive one, yet the send flow showed the input for every Zcash address and made the user fill or skip it. Send descriptors can now distinguish static memo support from recipient-specific visibility, and a memo left over from an earlier shielded recipient is dropped when the recipient turns transparent, so it can no longer reach the transaction builder. -
#21421
3d23fd4Thanks @tonykhaov! - Add a first-time verify hint on mobile Pay Request, persisted once dismissed. -
#21434
b7f83a1Thanks @tonykhaov! - Add persisted Pay Request verify-hint state in@features/flow-pay-request. -
#21367
d182d46Thanks @claudiiafg! - Fix the Ledger Sync entry point from Contacts: align the introduction copy and artwork with the production design, only show it when the user actually tries to add a contact or an address, start the flow on "Choose your sync method", and return to Contacts instead of the Portfolio once the flow is done on Mobile. -
#21470
5b79eb3Thanks @claudiiafg! - Fix the Contacts add address flow stalling on Continue by only offering networks the device can register an address on: EVM networks running their own coin app, such as Ethereum Classic, Sonic and Sei, are no longer selectable -
#21431
c06bd2eThanks @claudiiafg! - Fix the extra left padding on the address field of the Mobile add address and edit address drawers. Both screens render the address without the "To:" prefix, but Lumen's AddressInput mounts its prefix even when empty, so the prefix still took a slot in the field's inner gap and pushed the address 8px to the right. Add address now drops that gap and keeps the spacing only between the address and the trailing QR code icon, and edit address, which has no trailing icon, uses a plain TextInput instead. -
#21543
eea933cThanks @claudiiafg! - Fix the trash icon of the contact "Delete contact" action rendering white instead of red. -
#21587
46b51ddThanks @claudiiafg! - Fix the Contacts feature introduction so closing it counts as seen and keeps you on the Contacts list, instead of navigating back and reopening the introduction on the next visit. -
#21592
9e0d7ebThanks @koda-apps! - Fix misaligned "Maybe later" link on the notifications opt-in prompt drawer -
#21393
406f56fThanks @RobinVncnt! - Align the content card tag and dismiss cross with their desktop counterparts by using the Lumen UI Tag and InteractiveIcon components. -
#21026
4f514c9Thanks @LucasWerey! - Store a scrypt verifier instead of the password itself. Confirming a password now derives a digest and persists{version, scrypt, salt, digest}in the keychain, so nothing that can be replayed as a password is kept anywhere.The protection state lands with it: two independent flags plus a session lock, keyed off "any protection is enabled" rather than on having a password, which is the coupling that makes biometrics-only impossible today.
Ordering is the safety argument throughout — the whole verifier is one keychain item, so an interrupted write leaves the previous verifier or none, never a half-written pairing, and the state flips only once the write has landed. Derivations are serialised: two concurrent setups would otherwise interleave and store a verifier whose salt belongs to the other run.
The password field also gains a length cap. It sits far above anything anyone types, and exists because deriving a digest is deliberately slow.
-
#21746
c2e2276Thanks @amaslakov! - Add the error message shown when the protocol refuses a Tezos stake amount as too small -
#21401
8c40cc1Thanks @claudiiafg! - Skip the extra confirmation modal when editing a contact or address name. Apply changes now starts the device action directly when needed, and the Apply CTA shows the Ledger logo in that case. -
#21440
0089a4bThanks @claudiiafg! - Drive Contacts add-address confirmation through the Device Intent Executor instead of mocked Continue screens, including prefill and Send entry points. -
#21599
e601584Thanks @LucasWerey! - Pin the Contacts feature introduction CTA to the bottom of the mobile sheet -
#21277
37dde9fThanks @sarneijim! - Log Segment identify calls (enqueued or failed) in the mobile analytics debug overlay -
#21606
000eac0Thanks @LucasWerey! - Fix missing 8px spacing between items in the mobile contacts list -
#21526
4494817Thanks @tonykhaov! - Open the contact address sheet from the Pay strip and continue to MAD with the chosen recipient. -
#21418
60ee73cThanks @liviuciulinaru! - RenameCARD_API_URLtoCARD_BAANX_API_URL, keep the production defaults, and drop the Env vars section from the Card / Pay DevTool. -
#21551
727b9e5Thanks @mcayuelas-ledger! - Register and persist the card onboarding widget state in Ledger Wallet M...
@ledgerhq/live-desktop@4.20.0
4.20.0
Minor Changes
-
#21371
56bf73cThanks @vpenskyi-ledger! - Fix NoFundsStake modal passing raw currency object to Swap live-app instead of expected{ toCurrencyId }format, causing the Receive field to not be pre-filled when navigating from Earn zero-balance account flow -
#21042
d5e1c7dThanks @ooke-ledger! - Tell the two Hyperliquid account-picker states apart.The perps receiving step used one description for both states, so users who already had a Hyperliquid account were told to add one. It now reads "Select an account you want to deposit funds into to place your trades" when accounts exist, and keeps "To fund your perps, you need a Hyperliquid account.
-
#21515
7f4723cThanks @sarneijim! - Bump Segment analytics SDKs for retry, rate-limit and security fixes (LIVE-35839) -
#21433
8f8f1a4Thanks @mcayuelas-ledger! - Add a webContactAddressPickerdialog skeleton to the Pay contact flow and open it from the desktop Pay tab when a contact is pressed. The address list UI and the account/send handoff on address selection land in follow-ups. -
#21355
fc74af8Thanks @semeano! - Offer the Zcash memo only to shielded recipients. A memo travels in a shielded output, so a transparent recipient could never receive one, yet the send flow showed the input for every Zcash address and made the user fill or skip it. Send descriptors can now distinguish static memo support from recipient-specific visibility, and a memo left over from an earlier shielded recipient is dropped when the recipient turns transparent, so it can no longer reach the transaction builder. -
#21434
b7f83a1Thanks @tonykhaov! - Add persisted Pay Request verify-hint state in@features/flow-pay-request. -
#21408
c270975Thanks @tonykhaov! - Add a first-time Popover on desktop Pay Request Verify. -
#21367
d182d46Thanks @claudiiafg! - Fix the Ledger Sync entry point from Contacts: align the introduction copy and artwork with the production design, only show it when the user actually tries to add a contact or an address, start the flow on "Choose your sync method", and return to Contacts instead of the Portfolio once the flow is done on Mobile. -
#21470
5b79eb3Thanks @claudiiafg! - Fix the Contacts add address flow stalling on Continue by only offering networks the device can register an address on: EVM networks running their own coin app, such as Ethereum Classic, Sonic and Sei, are no longer selectable -
#21453
3b0dbaeThanks @mcayuelas-ledger! - Add the webContactAddressPickerdialog to the Pay contact flow and open it from the desktop Pay tab when a contact is pressed. The picker lists the contact's addresses segmented by network with asset-aware icons, resolved through the view model, and exposes an optional add-address action that routes to the contact's add-address flow. Address grouping, icon resolution and truncation are shared from@features/flow-contacts. The account/send handoff on address selection lands in a follow-up. -
#21587
46b51ddThanks @claudiiafg! - Fix the Contacts feature introduction so closing it counts as seen and keeps you on the Contacts list, instead of navigating back and reopening the introduction on the next visit. -
#21601
96661b4Thanks @mateuszpalosz-ext! - part 1 for Aleo bond flow -
#21746
c2e2276Thanks @amaslakov! - Add the error message shown when the protocol refuses a Tezos stake amount as too small -
#21401
8c40cc1Thanks @claudiiafg! - Skip the extra confirmation modal when editing a contact or address name. Apply changes now starts the device action directly when needed, and the Apply CTA shows the Ledger logo in that case. -
#21440
0089a4bThanks @claudiiafg! - Drive Contacts add-address confirmation through the Device Intent Executor instead of mocked Continue screens, including prefill and Send entry points. -
#21374
d6e689fThanks @tonykhaov! - Update the desktop Pay feature tour layout and copy to match mockups (LIVE-36499). -
#21418
60ee73cThanks @liviuciulinaru! - RenameCARD_API_URLtoCARD_BAANX_API_URL, keep the production defaults, and drop the Env vars section from the Card / Pay DevTool. -
#21548
55bd216Thanks @mcayuelas-ledger! - Add a getCardOnboardingStatus RTK Query endpoint and a schema-validated mock fixture. -
#21550
6ed1820Thanks @mcayuelas-ledger! - Mount and persist the card onboarding widget in Ledger Wallet Desktop. -
#21546
85474dbThanks @semeano! - Change show private balance label. -
#21248
9672658Thanks @OlivierFreyssinet! - Edit an external address on the device from Contacts. The device intent now calls@ledgerhq/device-contacts-kit'sContactsManager.editExternalAddressIdentifier()andContactsManager.editExternalAddressScope(), each returning the rotated address proof to persist while the group's name proof passes through untouched, and both apps render the confirmation step and oneInfoStateper failure.The device serves address and label edits as two separate commands, so an edit changing both asks the user to confirm twice, showing the same waiting screen for each step rather than numbering them. Nothing partial is ever stored: an abandoned or rejected edit leaves the record untouched, and a retry restarts the whole chain.
-
#21247
a55d4caThanks @OlivierFreyssinet! - Rename a contact on the device from Contacts. The device intent now calls@ledgerhq/device-contacts-kit'sContactsManager.renameContact(), which returns the rotated name proof to persist, and both apps render the confirmation step and oneInfoStateper failure. A rejection keeps the job open so the user can retry on the same device.Rename is a blockchain-agnostic dashboard operation, so it initializes on the dashboard (
BOLOS) rather than a coin app: a contact with no address is renameable, and an outdated device surfaces as an OS-update screen instead of an app-update one.
@ledgerhq/live-desktop@4.19.1
4.19.1
Patch Changes
-
#21863
a312094Thanks @francois-guerin-ledger! - chore(llc): update Arc mainnet native contract address -
Updated dependencies [
a312094]:- @ledgerhq/live-common@37.5.1
- @ledgerhq/asset-detail@0.11.4
- @ledgerhq/live-dmk-desktop@0.20.10