Repository navigation
Secret field keeps the keyboard out; status announced; nothing secret prints; reduced motion - #51
Merged
Conversation
…ng secret prints; reduced motion honoured - The secret-text field had spellcheck=false but not autocomplete, autocapitalize and autocorrect off, which the sister projects set on every secret-bearing field: on iOS, predictive text LEARNS what is typed into a plain textarea, so a seed phrase entered here could surface as a keyboard suggestion later. Both pages' text fields now carry all four. The password field moves from autocomplete=off (ignored for password inputs by every browser) to new-password, which does suppress autofill. - The status line is a live region (role=status, aria-live=polite): a screen reader now hears 'Weak password', 'Decrypted successfully' and 'Decryption failed' instead of silence. Same for the recovery hint. - @media print blanks every field that can hold a secret, the QR and the fingerprints: Print and Save as PDF write the screen to a file. - prefers-reduced-motion: reduce stops the spinner and transitions. Verified in Chrome with print media emulated: #t, #out, #p hidden, status visible; attributes present. test:crypto 91/91.
This was referenced Oct 8, 2026
Contributor
Author
|
Also available merged with every other review PR, in dependency order and verified together, as #57 — merge that or the individual PRs, not both. |
seQRets
pushed a commit
that referenced
this pull request
Oct 9, 2026
From the QR of an encrypted text, 'Print card' prints one page: the QR at 8 cm, the Base64 in full, and three steps to decrypt it — open ittybitz.app or the recovery file kept beside the card, scan or type, enter the password (and the key file, named, if one was used). The password is never on it, so the card can sit in a safe or with a notary and be lost or copied without harm. For a safe, a notary or a drawer, a sheet that says how to open it is worth more than a QR alone. Only ENCRYPTED text gets the button: a ciphertext is made to be kept on paper, a decrypted text or a seed never is, and #51's print rule keeps hiding those. The card is a print-only section filled when the button is pressed and emptied on afterprint (with a fallback timer), so the ciphertext does not linger in the document for a later Save Page As. Verified in Chrome with print media emulated: the page is replaced by the card; after afterprint the card is empty and the body class gone; the button is absent for a decrypted seed's SeedQR. test:crypto 91/91.
seQRets
pushed a commit
that referenced
this pull request
Oct 9, 2026
…, safer key files Releases the merged review PRs (#45, #48, #50, #51, #54, #55, #59) so the download links serve what the site will be running. Without a release, the footer's "Download app" would keep handing out v3.0.11. Version bumped in package.json, the app footer (scripts/build/head.html, rebuilt), the Recovery tool's label (which tracks the app release since v3.0.10), and the pinned recovery links in both READMEs. Size claims corrected to 30 KB everywhere: the Recovery tool is 30,141 bytes after #50/#51/#55, while the READMEs said 28 KB and both pages said 27 KB. The edit is length-neutral, so the stated size is the shipped size. Cryptography untouched: crypto.ts, bip39.ts, crypto-core.js and the fixture corpus are byte-identical to v3.0.11, and the Recovery tool's decrypt core still hashes 055983a4. Regression suite 91/91; build reproducible. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Four gaps found by comparing the page against its sisters' field and a11y conventions. Markup/CSS only; no crypto touched (
test:crypto91/91). Both pages.1. The secret-text field learns nothing.
#thadspellcheck="false"but notautocomplete="off" autocapitalize="off" autocorrect="off", which My-Seed-Phrase and My-Passphrase set on every secret-bearing field. On iOS, predictive text learns what is typed into a plain textarea, so a seed phrase entered here could surface later as a keyboard suggestion. Both pages' text fields now carry all four. The password field moves fromautocomplete="off"— which browsers ignore on password inputs — tonew-password, which does suppress autofill suggestions.2. The status line is announced.
#status(and the recovery tool's#hint) now haverole="status" aria-live="polite", so a screen-reader user hears "Weak password…", "Decrypted successfully", "Decryption failed…" instead of silence.3. Nothing secret prints. There was no
@media printat all; Print / "Save as PDF" writes the screen to a file, revealed secret and all. The secret field, result, password (while shown), QR canvas and the three fingerprint codes are nowvisibility:hiddenin print; overlays aredisplay:none.4.
prefers-reduced-motion: reducestops the spinner and transitions.Verified
Served the rebuilt page and emulated print media over CDP:
#t,#out,#p→hidden, the status line stays visible. Attributes read back as set;role="status"/aria-live="polite"present.Touches both built files, so it conflicts on the artifacts with the other open PRs —
npm run buildafter whichever lands first.