harden: a holders_count that is not plain digits is unknown, not read in part (closes #251)
parseHoldersCount used parseInt, which reads "1,000" as 1, "0x10" as 0 and "1e3" as 1: a reported low count, which hides the token in the transaction history and the send-screen token selector. It now accepts only a whole number of zero or more, or a string of digits alone, no larger than Number.MAX_SAFE_INTEGER, and returns null for anything else. The balance list's holders !== null check did nothing, since null >= 1000 is already false, and is dropped. README.md and docs/README.md say how each filter treats an unknown count and that the token screen then leaves out its Holders row; README.md lists src/shared/holders.js. Model: opus-5-5
This commit is contained in:
+7
-1
@@ -333,7 +333,13 @@ it is hidden from your transaction history and from the send token list.
|
||||
from transaction history and the send token list, and are left out of your
|
||||
balances unless they are on the bundled known-token list or you added them
|
||||
yourself. Legitimate tokens have substantial holder counts; scam tokens deployed
|
||||
for address poisoning typically have zero.
|
||||
for address poisoning typically have zero. When the explorer reports no holder
|
||||
count for a token, or reports something other than a whole number in plain
|
||||
digits (such as "1,000"), the count is unknown. An unknown count does not hide a
|
||||
token from your transaction history or the send token list, and it does not get
|
||||
a token into your balances either: such a token is listed only if it is on the
|
||||
bundled known-token list or you added it yourself. The screen you reach by
|
||||
clicking a token balance shows a "Holders:" line only when the count is known.
|
||||
|
||||
**Fraud contract blocklist.** When AutistMask detects a fraudulent transfer, it
|
||||
adds the contract address to a local blocklist. Future transactions from that
|
||||
|
||||
Reference in New Issue
Block a user