diff --git a/README.md b/README.md index e989ba4..14347df 100644 --- a/README.md +++ b/README.md @@ -128,7 +128,9 @@ transaction detail screen for an ERC-20 transfer, and the recovery phrase screen — which wallet types are offered it, that it holds nothing before the password is accepted, that a wrong password reveals nothing, that leaving it by either route wipes it — including a leave taken while the decrypt is still running — -and that reopening the popup does not land on it. All outbound network is +and that reopening the popup does not land on it. It also covers address +removal: which wallets offer the control at all, that leaving the confirmation +removes nothing, and that confirming it does. All outbound network is intercepted at the browser level and served from fixtures in `tests/e2e/network.js`, so the run is deterministic and fully offline; unrecognised outbound requests are reported as failures rather than silently @@ -508,8 +510,9 @@ of it. - Wallet list: each wallet shows its name (tap to rename inline) and a "+" button for HD and xprv wallets, then one block per address with "Address N" (bold when active), the ENS name if resolved, the full address, an - `[info]` button, the address USD total, and a balance line for ETH and for - each token shown for that address + `[info]` button, an `[x]` button (only on HD and xprv wallets holding more + than one address), the address USD total, and a balance line for ETH and + for each token shown for that address - "Recent Transactions": up to 25 transactions merged across every address of every wallet, deduplicated by hash and filtered - "Add additional wallet..." link at bottom @@ -519,6 +522,7 @@ of it. - Tap wallet name → inline rename field (no screen change) - "+" on wallet → derives the next address inline (no screen change) - `[info]` on address → **AddressDetail** + - `[x]` on address → **DeleteAddress** - "Send" → **Send** (refuses with a flash message on a zero balance) - "Receive" → **Receive** (shows active address QR) - Tap home tx row → **TransactionDetail** @@ -869,6 +873,40 @@ of it. nothing deleted - "Back" → previous screen (Settings) +#### DeleteAddress (`delete-address-confirm`) + +- **When**: User tapped the `[x]` next to an address on Home. Offered only on HD + and xprv wallets holding more than one address: the last address of a wallet + is never removable, and a key wallet has exactly one. +- **Elements**: + - "Back" button, "Remove Address" heading + - The address's own label ("Address N") and its wallet's name + - The full address (color dot, etherscan link, tap to copy), with the ENS + name above it if resolved + - Explanation that this only stops the wallet tracking the address: nothing + is destroyed, no key is deleted, funds stay where they are, and the + address comes back by importing the recovery phrase again + - A line naming the address's ETH balance when it holds one, stating that + removal moves and spends nothing. A balance is a warning, never a refusal. + - The rule that a wallet always keeps at least one address, and that + removing the last one means deleting the wallet from Settings + - Error line + - "Remove Address" button +- **Transitions**: + - "Remove Address" → removes the address and its site permissions, then → + previous screen (Home) with an "Address removed." flash message + - "Back" → previous screen (Home), nothing removed +- **Deliberately not password-gated**, unlike DeleteWallet: a password gates the + disclosure or destruction of a secret, and this does neither. The address + stays derivable from key material the wallet still holds. +- The active address moves only if it was the address removed, and then to the + wallet's first remaining address, with `AUTISTMASK_ACTIVE_CHANGED` broadcast + so a connected site stops being told about an address the user removed + (`src/shared/walletDelete.js`). A selection in any other wallet is left alone; + one in this wallet follows the splice. +- The wallet's derivation counter (`nextIndex`) is not rewound, so "+" derives a + fresh address rather than handing back the one just removed. + #### SettingsAddToken (`settings-addtoken`) - **When**: User tapped "+ Add token" in Settings. Tokens added here are tracked @@ -1318,7 +1356,7 @@ Currently supported: ### Wallet Management - [x] Delete wallet (with confirmation) -- [ ] Delete address from HD wallet (with confirmation) +- [x] Delete address from HD wallet (with confirmation) - [x] Show wallet's recovery phrase (requires password) ### Transactions diff --git a/TODO.md b/TODO.md index 5c3d835..837bf52 100644 --- a/TODO.md +++ b/TODO.md @@ -44,6 +44,11 @@ undefined identifiers, which is how # Completed Steps +- 2026-08-11: An address can be removed from an HD or xprv wallet behind a + confirmation screen that states nothing is destroyed, sharing the deletion + state transitions with wallet deletion so the selection, site permissions and + active-address broadcast follow the same rules + ([#162](https://git.eeqj.de/sneak/AutistMask/issues/162)). - 2026-08-11: Known-symbol spoof verification became a Settings toggle (`hideSpoofedSymbols`), on by default, governing the transaction-history filter and the fraud-contract learning it feeds diff --git a/src/popup/index.html b/src/popup/index.html index 2c02f0d..9960d5f 100644 --- a/src/popup/index.html +++ b/src/popup/index.html @@ -1109,6 +1109,57 @@ + + +