app/auth/import.tsx's TextInput sets both secureTextEntry and multiline. React Native's Android implementation has a long-standing platform limitation where secureTextEntry is silently ignored when multiline is also set, meaning the Stellar secret key the user is typing may render in plaintext on-screen on Android despite the code's explicit intent to mask it — the opposite of import.tsx's stated design goal. This needs to be verified on a real Android device/emulator, not assumed from the source alone.
Definition of done:
- Confirmed on-device (not just from documentation) whether masking actually fails on Android in the current Expo/RN version pinned in
package.json
- If confirmed, redesign the input (e.g. single-line with a paste-focused UX, given secret keys have no natural line breaks) rather than relying on a combination known to be unreliable
- Regression test or at minimum a documented manual QA step added to the release checklist
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.
app/auth/import.tsx'sTextInputsets bothsecureTextEntryandmultiline. React Native's Android implementation has a long-standing platform limitation wheresecureTextEntryis silently ignored whenmultilineis also set, meaning the Stellar secret key the user is typing may render in plaintext on-screen on Android despite the code's explicit intent to mask it — the opposite ofimport.tsx's stated design goal. This needs to be verified on a real Android device/emulator, not assumed from the source alone.Definition of done:
package.jsonBefore opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.