harden: a holders_count that is not plain digits is unknown, not read in part (closes #251)
parseHoldersCount used parseInt, which reads "1,000" as 1, "0x10" as 0 and "1e3" as 1: a reported low count, which hides the token in the transaction history and the send-screen token selector. It now accepts only a whole number of zero or more, or a string of digits alone, no larger than Number.MAX_SAFE_INTEGER, and returns null for anything else. The balance list's holders !== null check did nothing, since null >= 1000 is already false, and is dropped. README.md and docs/README.md say how each filter treats an unknown count and that the token screen then leaves out its Holders row; README.md lists src/shared/holders.js. Model: opus-5-5
This commit is contained in:
@@ -147,20 +147,20 @@ async function fetchTokenBalances(address, blockscoutUrl, trackedTokens) {
|
||||
// null is a holding of an amount that cannot be stated, which is
|
||||
// not the same as a holding of zero, and must never render as one.
|
||||
const bal = scale === null ? null : formatTokenBalance(raw, scale);
|
||||
// null means the explorer reported no count, which is not the
|
||||
// same as a count of zero. This gate is not the low-holder
|
||||
// display filter: it has no user-facing off switch and governs
|
||||
// the whole balance list, so it stays strict and admits a token
|
||||
// only on a reported count — an unreported one is no evidence.
|
||||
// A legitimate token still reaches the list through the known
|
||||
// null means the explorer reported no readable count, which is
|
||||
// not the same as a count of zero. This gate is not the
|
||||
// low-holder display filter: it has no user-facing off switch and
|
||||
// governs the whole balance list, so it stays strict and admits a
|
||||
// token only on a reported count — an unreported one is no
|
||||
// evidence, and `null >= LOW_HOLDER_THRESHOLD` is false. A
|
||||
// legitimate token still reaches the list through the known
|
||||
// token list or by the user tracking it, and the null is carried
|
||||
// through to the views, where the two low-holder filters treat
|
||||
// an unknown count as "do not judge" rather than as zero.
|
||||
const holders = parseHoldersCount(item.token.holders_count);
|
||||
const isKnown = TOKEN_BY_ADDRESS.has(tokenAddr);
|
||||
const isTracked = trackedSet.has(tokenAddr);
|
||||
const hasEnoughHolders =
|
||||
holders !== null && holders >= LOW_HOLDER_THRESHOLD;
|
||||
const hasEnoughHolders = holders >= LOW_HOLDER_THRESHOLD;
|
||||
|
||||
// Skip spam tokens the user never asked to see
|
||||
if (!isKnown && !isTracked && !hasEnoughHolders) continue;
|
||||
|
||||
+15
-6
@@ -9,13 +9,22 @@
|
||||
|
||||
const LOW_HOLDER_THRESHOLD = 1000;
|
||||
|
||||
// Parse an explorer-supplied holders_count into a number, or null when the
|
||||
// explorer did not report one. Anything unparseable is unknown too: a count
|
||||
// we cannot read is not a count of zero.
|
||||
// Parse an explorer-supplied holders_count into a number, or null when it is
|
||||
// not one. Only a whole number of zero or more, or a string made of nothing
|
||||
// but the digits 0-9, is a count. Anything else is null, never read in part:
|
||||
// "1,000", "0x10" and "1e3" are unknown, not 1, 0 and 1, because a count we
|
||||
// cannot read is not a low count. A count above Number.MAX_SAFE_INTEGER is
|
||||
// null too: a number cannot hold it exactly, so it would come back rounded,
|
||||
// or as Infinity.
|
||||
function parseHoldersCount(raw) {
|
||||
if (raw === null || raw === undefined || raw === "") return null;
|
||||
const n = parseInt(raw, 10);
|
||||
return Number.isFinite(n) ? n : null;
|
||||
if (typeof raw === "number") {
|
||||
return Number.isSafeInteger(raw) && raw >= 0 ? raw : null;
|
||||
}
|
||||
if (typeof raw === "string" && /^[0-9]+$/.test(raw)) {
|
||||
const count = Number(raw);
|
||||
return Number.isSafeInteger(count) ? count : null;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
// True only for a token the explorer reported as having fewer holders than
|
||||
|
||||
@@ -137,9 +137,10 @@ function parseTokenTransfer(tt, addrLower, chainId) {
|
||||
contractAddress: normalizeAddress(
|
||||
tt.token?.address_hash || tt.token?.address || "",
|
||||
),
|
||||
// null when the explorer reported no count: unknown, not zero. The
|
||||
// low-holder filter declines to judge a null, so a legitimate token
|
||||
// is not hidden because a field went missing upstream.
|
||||
// null when the explorer reported no readable count: unknown, not
|
||||
// zero. The low-holder filter declines to judge a null, so a
|
||||
// legitimate token is not hidden because a field went missing
|
||||
// upstream.
|
||||
holders: parseHoldersCount(tt.token?.holders_count),
|
||||
chainId: chainId,
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user