harden: a holders_count that is not plain digits is unknown, not read in part (closes #251)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 2s
e2e / e2e-firefox (push) Failing after 3s

parseHoldersCount used parseInt, which reads "1,000" as 1, "0x10" as 0 and
"1e3" as 1: a reported low count, which hides the token in the transaction
history and the send-screen token selector. It now accepts only a whole
number of zero or more, or a string of digits alone, and returns null for
anything else. The balance list's holders !== null check did nothing, since
null >= 1000 is already false, and is dropped. README.md and docs/README.md
say how each filter treats an unknown count and that the token screen then
leaves out its Holders row; README.md lists src/shared/holders.js.

Model: opus-5-5
This commit is contained in:
2026-10-05 00:03:57 +00:00
parent f86740ce69
commit 657ba3b059
7 changed files with 78 additions and 30 deletions
+15
View File
@@ -57,6 +57,21 @@ describe("parseHoldersCount", () => {
expect(parseHoldersCount("many")).toBeNull();
expect(parseHoldersCount(NaN)).toBeNull();
});
// Each of these starts with a digit, so reading only the leading digits
// would turn it into a small reported count, and a small count is
// exactly what hides a token as spam (issue #251).
test.each(["1,000", "0x10", "1e3", "12 holders"])(
"%p is not read in part: it is unknown",
(raw) => {
expect(parseHoldersCount(raw)).toBeNull();
},
);
test("a negative count is unknown", () => {
expect(parseHoldersCount("-5")).toBeNull();
expect(parseHoldersCount(-5)).toBeNull();
});
});
describe("isLowHolderCount", () => {