fix: show the true token amount on the approval screen, or none at all (closes #306)
decodeCalldata resolved an ERC-20 amount's scale from the 512-entry bundled token list alone and fell back to 18 decimals for everything else. Most tokens are outside that list, including anything the user added by contract address, so a transfer of 5000000000 units of a 6-decimal token - 5,000 tokens - was drawn as "Amount 0.0000". A user who reads zero confirms, and loses the balance or grants the allowance. The new src/shared/approvalAmount.js resolves decimals from the bundled list, then state.trackedTokens, then the decimals the block explorer already reported in addr.tokenBalances, accepting only a real uint8 from any of them and refusing a scale the explorer's own entries disagree about. Where no source knows the scale the amount is not formatted at all: the line reads "5000000000 base units (decimals unknown)". A formatted number computed from a guessed scale is the defect itself, and for a token with fewer decimals than the guess it is wrong in the direction that reads as zero. approve is covered alongside transfer; an unbounded allowance still reads "Unlimited", which needs no scale. The same string is carried to the status screens, so no formatted figure reappears downstream. Verified failing first: restoring only the old lookup fails 6 of the 15 new tests, with the unknown-decimals transfer case receiving exactly "0.0000".
This commit is contained in:
14
TODO.md
14
TODO.md
@@ -44,6 +44,20 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-20: The dApp approval screen no longer shows a token transfer it
|
||||
cannot scale as `0.0000`
|
||||
([#306](https://git.eeqj.de/sneak/AutistMask/issues/306)). `decodeCalldata`
|
||||
read decimals from the 512-entry bundled token list alone and fell back to 18,
|
||||
so every token outside it — most of them, including anything the user added by
|
||||
contract address — was displayed at the wrong scale: a `transfer` of 5,000
|
||||
units of a 6-decimal token read as `0.0000`, and a user who reads zero
|
||||
confirms the drain. The new `src/shared/approvalAmount.js` resolves the scale
|
||||
from the bundled list, then `state.trackedTokens`, then the decimals the block
|
||||
explorer already reported in `addr.tokenBalances`, and refuses one the
|
||||
explorer's own entries disagree about. Where no source knows it, the amount
|
||||
line is not formatted at all: it shows the base-unit integer and states that
|
||||
the scale is unknown, for `approve` as well as `transfer`. An unbounded
|
||||
allowance still reads `Unlimited`, which needs no scale.
|
||||
- 2026-08-20: A web page can no longer switch the wallet's chain, and switching
|
||||
no longer destroys the user's endpoints
|
||||
([#308](https://git.eeqj.de/sneak/AutistMask/issues/308)).
|
||||
|
||||
Reference in New Issue
Block a user