harden: show a personal message's hex and its text in byte order, hidden characters marked (closes #403)
The signature screen showed only the text a personal message decodes to, with bidirectional, right-to-left and zero-width characters acting on it, so a site could make the message read differently from the bytes that are signed, and a message that was not hex was decoded into NUL characters. The screen now shows the hex as "Raw data" alongside the text, lays the text out left to right in byte order, and shows each control character, line and paragraph separator, and character that paints nothing (the set src/shared/symbolSpoof.js already strips) as a U+XXXX mark. A message is hex when getBytes, which signing uses, reads it; one that is not cannot be signed, so it is shown as plain text with "Sign" disabled. Model: opus-5-5
This commit was merged in pull request #435.
This commit is contained in:
@@ -1698,6 +1698,15 @@
|
||||
></div>
|
||||
</div>
|
||||
|
||||
<div id="approve-sign-hex-section" class="mb-3 hidden">
|
||||
<div class="text-xs text-muted mb-1">Raw data</div>
|
||||
<div
|
||||
id="approve-sign-hex"
|
||||
class="text-xs break-all"
|
||||
style="max-height: 6rem; overflow-y: auto"
|
||||
></div>
|
||||
</div>
|
||||
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1 text-xs">Password</label>
|
||||
<input
|
||||
|
||||
Reference in New Issue
Block a user