harden: warn for token-permission typed data and show the primary type ethers signs (closes #400)
check / check (push) Successful in 3m10s
e2e / e2e-chrome (push) Successful in 4m48s
e2e / e2e-firefox (push) Successful in 3m49s

The typed-data screen listed a Permit or Permit2 signature as plain
key/value lines, like a sign-in message. It now shows a red warning for
them naming the spender and each token and amount, read only from the
fields the signed type declares (a Permit's token is the domain's
verifyingContract); anything those fields do not give reads Unknown.

The screen printed the page's primaryType, but ethers signs the type it
derives from types. It now shows that type, and refuses typed data whose
stated type is missing or differs: error line, Sign disabled, checked
again where signing starts.

Deviation: the warning names no deadline or expiry; see the issue.
Judgement call: DAI's older permit and Permit2's batch and witness
transfer types are recognised too.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:37:52 +00:00
parent add11e57de
commit 457dd18642
4 changed files with 831 additions and 27 deletions
+19
View File
@@ -45,6 +45,25 @@ but the review is broader than any of them.
# Completed Steps
- 2026-10-03: The typed-data signing screen warns for a token permission, and
names the primary type ethers signs
([#400](https://git.eeqj.de/sneak/AutistMask/issues/400)). A Permit or Permit2
signature lets its spender take tokens from the signer's address, and the
screen listed it as plain key/value lines, exactly like a sign-in message. For
typed data signed as `Permit` (EIP-2612's, DAI's older one, or any other of
that name) or as one of Permit2's six signature types,
`src/popup/views/approval.js` now shows a red warning at the top of the
message naming the spender and each token and amount, read only from the
fields the signed type declares (a `Permit`'s token is the domain's
`verifyingContract`), with `Unlimited` for the largest amount the field holds,
the existing unknown-scale wording otherwise, and `Unknown` for whatever those
fields do not give. The screen printed the page's `primaryType`, but ethers
signs the type it derives from `types`; the screen now shows the derived type,
and typed data whose stated type is missing or differs, or that cannot be
read, is shown with an error line and Sign disabled, and is refused again
where signing starts. The warning names no deadline or expiry: those fields
mean different things across the shapes, and a date could read as the
permission ending when it does not.
- 2026-09-21: The network fee a transaction can commit is bounded by the product
of the gas limit and the fee per gas, not by each field alone, and the
wallet's own send is bounded the same way