2026-08-12 - 2026-08-15
Overview
22 Pull requests merged by 1 user
Merged
#272 fix: render the view "Back" lands on after the popup is reopened (closes #268)
Merged
#278 fix: carry EIP-1193 error codes through to the page (closes #274)
Merged
#277 fix: a shared ticker no longer hides one of its two real tokens (closes #276)
Merged
#273 test: drive the EIP-1193 dApp approval round trips in the browser (closes #183)
Merged
#270 fix: judge the symbol a user sees, not the bytes a contract returns (closes #260)
Merged
#256 test: containerized Firefox end-to-end harness (closes #184)
Merged
#269 harden: verify the signed transaction against what the popup displayed (closes #216)
Merged
#266 fix: filter the restored view stack against RESTORABLE_VIEWS (closes #224)
Merged
#264 fix: one wording for a rejected password on every screen (closes #172)
Merged
#267 test: close the empty-array hole in the e2e unstubbed-request guard (closes #187)
Merged
#258 test: drive ConfirmTx in the e2e suite, gate assertion included (closes #238)
Merged
#243 fix: explain a rejected dust threshold instead of snapping back silently (closes #233)
Merged
#205 harden: verify all approval fields and make failed signing retryable (closes #174)
Merged
#240 feat: remove an address from an HD wallet, behind a confirmation (closes #162)
Merged
#257 fix: filter a fake ETH token from the balance list too (closes #235)
Merged
#249 test: cover every verify-build failure mode from make check (closes #227)
Merged
#201 fix: WaitTx timeout no longer overwrites a rendered success screen (closes #155)
Merged
#248 fix: wipe the exported private key from the DOM on leaving the screen (closes #221)
Merged
#247 fix: explain a stored non-master xprv wallet instead of throwing at signing time (closes #234)
Merged
#244 fix: treat an unreported holders_count as unknown, not as zero holders (closes #230)
Merged
#206 fix: run libsodium on WebAssembly under the extension CSP (closes #182)
Merged
#241 docs: describe the bundled token list by selection criterion, not count (closes #239)
7 Pull requests proposed by 1 user
Proposed
#281 refactor: one shared extension-API module, and drive the dApp flows on Firefox (closes #153)
Proposed
#282 fix: answer the page when a background handler throws (closes #280)
Proposed
#284 fix: one transaction approval at a time, and honest copy for a nonce collision (closes #271)
Proposed
#286 build: add ESLint to script/lint and containerize linting (closes #152)
Proposed
#288 test: assert the #150 and #151 items the harness did not cover (closes #188)
Proposed
#289 fix: settle a site approval on the port that carries its teardown (closes #275)
Proposed
#291 build: run the browser e2e suites in CI (closes #259)
23 Issues closed from 1 user
Closed
#268 fix: Back after reopening the popup lands on a blank screen, because goBack() never re-renders
Closed
#274 fix: EIP-1193 error codes never reach the page — a dApp cannot detect a user rejection
Closed
#276 fix: seven bundled tokens are filtered as spoofs of their own duplicate symbol
Closed
#220 blocked: no Actions runner is picking up jobs — every CI run sits queued forever
Closed
#183 test: drive the EIP-1193 dApp approval round trips in the browser harness
Closed
#260 fix: a whitespace-padded symbol bypasses the spoof filter but still displays as the real one
Closed
#184 test: containerized Firefox end-to-end harness (geckodriver, MV2 temporary add-on)
Closed
#216 harden: approval verification compares against the dApp's request, not against what the popup displayed
Closed
#224 fix: the restored viewStack can contain views the popup may not reopen onto, giving a dead-end screen
Closed
#172 fix: "Wrong password." is a sentence fragment and diverges from the other password prompts
Closed
#187 test: an empty-array POST body escapes the e2e unstubbed-request guard
Closed
#238 test: ConfirmTx has no automated coverage at all — the screen that decides what gets signed
Closed
#233 fix: the dust threshold field rejects input silently, snapping back with no explanation
Closed
#174 harden: approvalVerify does not compare chainId, nonce or fee fields; failed signing leaves an unretryable button
Closed
#162 feat: delete an address from an HD wallet (with confirmation)
Closed
#235 fix: a fake token impersonating ETH is filtered from history and send, but still shows in the balance list
Closed
#227 test: verify-build's failure modes are only ever proven by hand — make the battery a committed target
Closed
#155 fix: WaitTx 60s timeout overwrites an already-rendered success screen
Closed
#221 fix: leaving the private-key export screen leaves the private key in the DOM for the life of the popup
Closed
#234 fix: an already-imported non-master xprv wallet will throw at signing time with no explanation
Closed
#230 fix: an omitted holders_count is coerced to 0, so a legitimate token gets filtered as spam
Closed
#182 fix: libsodium WASM is refused by the extension CSP on every popup load, silently falling back to asm.js
Closed
#239 docs: the bundled token list is described as "top 250" in four places and "roughly 500" in another; it is 512
26 Issues created by 1 user
Opened
#242 tokenList.js header comment says "511 tokens"; the array has 512
Opened
#245 harden: connectedSites is never cleared for a removed address or wallet
Opened
#246 harden: decimals || "18" collapses absent and zero if a backend ever sends numeric 0
Opened
#250 fix: a contract deployment shows a blank recipient on the wait and approval screens
Opened
#251 harden: parseHoldersCount partial-parses a malformed count into a reported low count, hiding the token
Opened
#252 fix: flash messages longer than one line wrap and shift the layout, defeating the reserved-space policy
Opened
#253 test: the private-key export screen has no e2e coverage, unlike the recovery-phrase screen
Opened
#254 test: the defective-wallet UI gates have no coverage — all six can be deleted with the suite still green
Opened
#255 decision: a defective xprv wallet is told to use other software, but we hold the only key and will not export it
Opened
#259 build: nothing automatic ever runs the e2e suites, so every browser-level guarantee is manual-only
Opened
#260 fix: a whitespace-padded symbol bypasses the spoof filter but still displays as the real one
Opened
#261 fix: an address holding only unpriced tokens reports its total as $0.00
Opened
#262 fix: an approval claimed when its window closes is orphaned, leaving the dApp promise unsettled forever
Opened
#263 chore: script/bootstrap can report success while leaving playwright-core unlinked
Opened
#265 fix: the empty-password message diverges on the private key export screen
Opened
#268 fix: Back after reopening the popup lands on a blank screen, because goBack() never re-renders
Opened
#271 fix: two concurrent dApp transactions are populated with the same nonce, and the second fails terminally
Opened
#274 fix: EIP-1193 error codes never reach the page — a dApp cannot detect a user rejection
Opened
#275 fix: approving a site connection races the popup teardown and can be recorded as a rejection
Opened
#276 fix: seven bundled tokens are filtered as spoofs of their own duplicate symbol
Opened
#279 fix: an unsupported method is reported to the page with no EIP-1193 code (4200)
Opened
#280 fix: a throw inside handleRpc hangs the dApp's promise forever with no error
Opened
#283 Uniswap V2_SWAP_EXACT_OUT (command 0x09) is decoded by a function nothing calls
Opened
#285 docs: README still documents the EIP-1193 code loss that #274 fixed
Opened
#287 flake: the Chrome e2e dApp signing prompt loses its page about one run in three under load
Opened
#290 test: make test-e2e is flaky under host load — "the extension opened no approval window within 30000ms"
9 Unresolved Conversations
Open
#218
test: popup reload mid-refresh can fail the e2e run with "loadHomeTxs failed: Failed to fetch"
Open
#152
build: add ESLint to script/lint — make check cannot currently catch undefined identifiers
Open
#188
test: assert the DoD items from #150 and #151 that the harness does not yet cover
Open
#190
milestone 1.0.0: approval-path security, build-integrity guard, e2e harness and filter coverage
Open
#153
fix: Firefox target is non-functional — Chrome callback APIs used against the promise-only browser namespace
Open
#229
test: the Settings view has no browser coverage, so a wrong element id takes the whole screen down undetected
Open
#219
decision: the phishing blocklist URL embeds a competitor's org name, and its documented upstream no longer exists
Open
#207
decision: a dApp-supplied gas limit is silently dropped, so the popup always re-estimates
Open
#222
decision: the per-unit TODO.md entry makes every merge invalidate every open PR