harden: key remembered site permissions by full origin (closes #402)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 2s
e2e / e2e-firefox (push) Failing after 1s

allowedSites and deniedSites held the bare hostname, so a grant to
https://dapp.example also authorised http://dapp.example and every port
on that host, and the connection, transaction and signature prompts
named only the hostname. Both lists now store and match the full origin
(scheme://host[:port]), the key the connections approved without
Remember already used. The prompts, the Settings site lists and
AUTISTMASK_REMOVE_SITE use the origin too. Entries saved by hostname
are not migrated (pre-1.0): they match no site.

Model: opus-5-5
This commit was merged in pull request #431.
This commit is contained in:
2026-10-04 18:09:04 +02:00
parent f24b5bca19
commit 1144fdb71b
29 changed files with 470 additions and 231 deletions
+5 -3
View File
@@ -285,11 +285,13 @@ not appear and may be permanently lost.
AutistMask injects a standard `window.ethereum` provider (EIP-1193) into web
pages. When a site requests access to your wallet:
1. A popup appears showing the site's hostname and the address that will be
shared.
1. A popup appears showing the site's origin (its scheme, host and port, for
example `https://app.example`) and the address that will be shared.
2. Click "Allow" to connect or "Deny" to reject.
3. Optionally check "Remember my choice for this site" to skip the prompt next
time.
time. The choice applies to that exact origin only: a choice remembered for
`https://app.example` does not cover `http://app.example` or another port of
the same host, which ask again.
When a connected site requests a transaction, a separate approval popup appears
showing the transaction details (from, to, value, data, network fee, network and