harden: ignore a nonce the page supplies with eth_sendTransaction (closes #404)
A site could fix the nonce of the transaction the user was asked to sign: the same nonce as a pending transaction, at a higher fee, replaces it, and a nonce above the account's next one leaves the new transaction stuck behind a gap. `nonce` is no longer one of the fields taken from the request, so the transaction always gets the account's next nonce from the network, and that is the nonce the approval screen shows and the popup signs. Model: opus-5-5
This commit is contained in:
@@ -121,7 +121,7 @@ describe("prepareApprovalTx", () => {
|
||||
);
|
||||
});
|
||||
|
||||
test("keeps a nonce, gas limit and fee the request did fix", async () => {
|
||||
test("keeps a gas limit and fee the request did fix, but not its nonce", async () => {
|
||||
const approved = await prepareApprovalTx(
|
||||
providerWith(),
|
||||
signer.address,
|
||||
@@ -133,7 +133,7 @@ describe("prepareApprovalTx", () => {
|
||||
maxPriorityFeePerGas: "0x3b9aca00",
|
||||
},
|
||||
);
|
||||
expect(approved.nonce).toBe("0x2");
|
||||
expect(approved.nonce).toBe("0x7");
|
||||
expect(approved.gasLimit).toBe("0x30d40");
|
||||
expect(approved.maxFeePerGas).toBe("0x12a05f200");
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user