harden: show a personal message's hex and mark control characters in its text (closes #403)
check / check (push) Failing after 3s
e2e / e2e-chrome (push) Failing after 3s
e2e / e2e-firefox (push) Failing after 2s

The signature screen showed only the text a personal message decodes
to, with bidirectional and zero-width characters acting on it, so a
site could make the message read differently from the bytes that are
signed, and a message that was not hex was decoded into NUL
characters. The screen now shows the hex as "Raw data" alongside the
decoded text, and each control or format character in the text as a
U+XXXX mark. Signing takes the bytes from the hex, so a message that
is not hex cannot be signed: it is shown as plain text, with the error
line saying so and "Sign" disabled.

Model: opus-5-5
This commit is contained in:
2026-10-04 16:52:46 +00:00
parent de3f7a9a11
commit 248057a25d
5 changed files with 229 additions and 13 deletions
+10
View File
@@ -45,6 +45,16 @@ but the review is broader than any of them.
# Completed Steps
- 2026-10-04: The signature screen shows a personal message as the bytes that
are signed ([#403](https://git.eeqj.de/sneak/AutistMask/issues/403)). It
showed only the decoded text, with bidirectional and zero-width characters
acting on it, so a site could make the message read differently from what is
signed, and a message that was not hex was shown as NUL characters. The hex is
now shown as "Raw data" alongside the decoded text, control and format
characters in the text are shown as `U+XXXX` marks, and a message that is not
hex is shown as plain text with "Sign" disabled, since signing takes the bytes
from the hex and such a message has none to sign.
- 2026-10-04: A nonce the site supplies with `eth_sendTransaction` is ignored
([#404](https://git.eeqj.de/sneak/AutistMask/issues/404)). It was passed on to
the transaction, so a site could replace one of the user's pending