From 2bec46fa5d981b1f6f4871ee38423f818384cc25 Mon Sep 17 00:00:00 2001 From: clawbot Date: Tue, 11 Aug 2026 12:39:44 +0000 Subject: [PATCH] docs: correct three README claims contradicted by the code (closes #213) - Blocklist attribution: the cited AugurProject/eth-phishing-detect repository no longer exists (GitHub returns 404), and the vendored list and the runtime refresh both come from the live upstream that BLOCKLIST_URL points at. The dead link is dropped, the project, copyright and license are kept, and a note records why no repository link is given. - Token display: balances.js shows any ERC-20 with a nonzero balance that is in the bundled top-250 list, tracked, or has 1,000+ holders, so tokens do appear without the user adding them. The Data Model section now states that rule, including that it is unconditional while the 1,000-holder setting applies only to transaction history and the send selector. The manual-only claims elsewhere are corrected to match. - Navigation: replaced the flat/no-tabs paragraph with the stack model the Screen Map documents, naming the AddWallet import tabs and the AddressDetail overflow menu. --- README.md | 55 ++++++++++++++++++++++++++++++++++++++----------------- TODO.md | 3 +++ 2 files changed, 41 insertions(+), 17 deletions(-) diff --git a/README.md b/README.md index 7a049bd..b8df696 100644 --- a/README.md +++ b/README.md @@ -346,17 +346,32 @@ The core hierarchy is **Wallets → Addresses**: address scan on import, but imported from an extended private key rather than a recovery phrase. It therefore has no recovery phrase to display or back up. -- An **address** holds ETH and any user-added ERC-20 tokens. +- An **address** holds ETH and ERC-20 tokens. - The user can have multiple wallets, each with multiple addresses (HD) or a single address (key). +Which tokens an address shows is decided by `fetchTokenBalances()` in +`src/shared/balances.js`, from the Blockscout `token-balances` response, so +tokens do appear without the user adding them. An ERC-20 is shown when its +balance is nonzero and it is in the bundled top-250 token list, is tracked by +the user, or has 1,000 or more holders; a token claiming a symbol from the +bundled list from any other contract address is always dropped. That filter is +unconditional — the "Hide tokens with fewer than 1,000 holders" setting governs +the transaction history and the send-screen token selector, not this list. +Tracked tokens with a zero balance are listed as well while "Show tracked tokens +with zero balance" is on. + #### Navigation The main view shows all addresses grouped by wallet, with ETH balances inline. The user taps an address to see its detail view (full address, balance, tokens, -send/receive). Navigation is flat — every view has a "Back" or "Cancel" button -that returns to the previous context. No deep nesting, no tabs, no hamburger -menus. +send/receive). Navigation is a stack: each forward action pushes the current +screen, and every view has a "Back" or "Cancel" button that pops back to it (see +the Screen Map below). There is no hamburger menu and no persistent tab bar; the +Settings gear in the title bar is the only global control. Two screens carry an +in-screen control beyond that: AddWallet uses three tabs to select the import +mode, and AddressDetail keeps its one rarely-used action ("Export Private Key") +behind a "···" menu. ### Screen Map @@ -393,7 +408,7 @@ screen, including ExportPrivKey, falls back to Home. - **When**: At least one wallet exists. This is the root screen. - **Elements**: - Active address ETH balance (large) + USD value in parentheses - - "Total:" USD value across ETH and all tracked tokens of the active address + - "Total:" USD value across ETH and every token shown for the active address - Active address (color dot, full address, etherscan link, tap to copy) - Send / Receive quick-action buttons, both acting on the active address - ETH/USD price display @@ -401,7 +416,7 @@ screen, including ExportPrivKey, falls back to Home. button for HD and xprv wallets, then one block per address with "Address N" (bold when active), the ENS name if resolved, the full address, an `[info]` button, the address USD total, and a balance line for ETH and for - each tracked token + each token shown for that address - "Recent Transactions": up to 25 transactions merged across every address of every wallet, deduplicated by hash and filtered - "Add additional wallet..." link at bottom @@ -454,8 +469,8 @@ screen, including ExportPrivKey, falls back to Home. - ENS name (if resolved, bold above the address) - Full address (color dot, etherscan link, tap to copy) - USD total for address - - Balance list: ETH + tracked ERC-20 tokens (4 decimal places, USD inline). - Each balance row is clickable → **AddressToken** + - Balance list: ETH + the ERC-20 tokens shown for this address (4 decimal + places, USD inline). Each balance row is clickable → **AddressToken** - Send / Receive / + Token buttons and a "···" menu button - "···" dropdown containing a single "Export Private Key" entry - Transaction list (with ENS resolution for counterparties) @@ -861,7 +876,7 @@ communicates with three external services to function as a wallet: What the extension does NOT do: - No analytics or telemetry services -- No token list APIs (user adds tokens manually by contract address) +- No token list APIs (the top-250 token list is bundled at build time) - No Infura/Alchemy dependency (any JSON-RPC endpoint works) - No backend servers operated by the developer @@ -984,7 +999,8 @@ hardcoded test phrase. - Add multiple addresses within an HD wallet - Manage multiple wallets simultaneously - View ETH balance per address -- View ERC-20 token balances (user adds token by contract address) +- View ERC-20 token balances (bundled top-250 tokens, tokens with 1,000 or more + holders, and tokens the user adds by contract address) - Send ETH to an address - Send ERC-20 tokens to an address - Receive ETH/tokens (display address, copy to clipboard, QR code) @@ -1130,7 +1146,8 @@ Currently supported: - Built in token swaps (use a DEX in the browser) - Analytics, telemetry, or tracking of any kind - Advertisements or promotions -- Obscure token list auto-discovery (user adds tokens manually) +- Obscure token list auto-discovery — nothing outside the bundled list, the + 1,000-holder floor, and the tokens the user added by contract address - We detect common/popular ERC20s in the basic case - Fiat on/off ramps - Extensive transaction decoding/parsing @@ -1187,14 +1204,18 @@ This repository includes data files from third-party projects that are not covered by the GPL-3.0 license above. These files, their copyright holders, and their licenses are: -| File | Source | Copyright | License | -| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | --------------------------------- | -------------------------------------------------------------- | -| `src/shared/phishingBlocklist.json` | [eth-phishing-detect](https://github.com/AugurProject/eth-phishing-detect) community-maintained phishing domain blocklist | Copyright (c) 2018 kumavis | [DBAD (Don't Be a Dick)](https://github.com/philsturgeon/dbad) | -| `src/shared/scamlist.js` (address data from MyEtherWallet) | [ethereum-lists](https://github.com/MyEtherWallet/ethereum-lists) `addresses-darklist.json` | Copyright (c) 2020 MyEtherWallet | MIT | -| `src/shared/scamlist.js` (address data from EtherScamDB) | [EtherScamDB](https://github.com/MrLuit/EtherScamDB) `scams.yaml` | Copyright (c) 2018 Luit Hollander | MIT | +| File | Source | Copyright | License | +| ---------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------- | -------------------------------------------------------------- | +| `src/shared/phishingBlocklist.json` | `eth-phishing-detect` community-maintained phishing domain blocklist, vendored from its `src/config.json` | Copyright (c) 2018 kumavis | [DBAD (Don't Be a Dick)](https://github.com/philsturgeon/dbad) | +| `src/shared/scamlist.js` (address data from MyEtherWallet) | [ethereum-lists](https://github.com/MyEtherWallet/ethereum-lists) `addresses-darklist.json` | Copyright (c) 2020 MyEtherWallet | MIT | +| `src/shared/scamlist.js` (address data from EtherScamDB) | [EtherScamDB](https://github.com/MrLuit/EtherScamDB) `scams.yaml` | Copyright (c) 2018 Luit Hollander | MIT | The full license texts for these third-party files are included in the -[LICENSE](LICENSE) file. +[LICENSE](LICENSE) file. The `eth-phishing-detect` row carries no repository +link because the upstream is hosted under a competitor's organization name, +which project policy keeps out of code and documentation; the vendored copy and +the runtime refresh both come from that upstream, whose URL is the +`BLOCKLIST_URL` constant in `src/shared/phishingDomains.js`. ## Author diff --git a/TODO.md b/TODO.md index 608523b..d202884 100644 --- a/TODO.md +++ b/TODO.md @@ -44,6 +44,9 @@ undefined identifiers, which is how # Completed Steps +- 2026-08-11: Three `README.md` claims corrected against the code — blocklist + attribution, token-display rule, navigation model + ([#213](https://git.eeqj.de/sneak/AutistMask/issues/213)). - 2026-08-11: README Screen Map rebuilt from the code — every screen, element and transition re-verified against `src/popup/` ([#164](https://git.eeqj.de/sneak/AutistMask/issues/164)).