harden: lost-password confirmation refuses empty input and ignores invisible characters (closes #336)
A wallet named only with spaces compared equal to an empty field, so typing nothing would have deleted it, and a zero-width space in a name made the name impossible to type back. An empty typed confirmation is now refused whatever the name is. The characters src/shared/symbolSpoof.js already defines as painting nothing are removed from both sides before comparing. A name that shows nothing at all is shown on the delete screens as "Wallet N", so it can still be typed back. Model: opus-5-5
This commit is contained in:
@@ -46,6 +46,9 @@ const A1 = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
||||
const B0 = "0x2260FAC5E5542a773Aa44fBCfeDf7C193bc2C599";
|
||||
const C0 = "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48";
|
||||
|
||||
// U+200B, built from its code point so that it can be seen in this file.
|
||||
const ZERO_WIDTH_SPACE = String.fromCodePoint(0x200b);
|
||||
|
||||
// ------------------------------------------------------------ DOM stub
|
||||
|
||||
function makeElement(id) {
|
||||
@@ -342,6 +345,72 @@ describe("the typed confirmation", () => {
|
||||
"secret-three",
|
||||
]);
|
||||
});
|
||||
|
||||
// A name of only spaces compares as nothing, and so does an empty
|
||||
// field. Typing nothing must still delete nothing.
|
||||
test.each(["", " "])(
|
||||
"typing %j deletes nothing when the name is only spaces",
|
||||
async (typedValue) => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets[1].name = " ";
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
|
||||
node("delete-wallet-lost-name-input").value = typedValue;
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
expect(node("delete-wallet-lost-flash").style.visibility).toBe(
|
||||
"visible",
|
||||
);
|
||||
expect(state.wallets).toHaveLength(3);
|
||||
expect(await persistedWallets(storage)).toHaveLength(3);
|
||||
},
|
||||
);
|
||||
|
||||
// A name that shows nothing would leave nothing on screen to type
|
||||
// back, so the screen names the wallet by its position instead, and
|
||||
// that is what the user types.
|
||||
test.each([
|
||||
["spaces", " "],
|
||||
["a zero-width space", ZERO_WIDTH_SPACE],
|
||||
])(
|
||||
"a name of only %s is shown and typed back as Wallet 2",
|
||||
async (_label, storedName) => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets[1].name = storedName;
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
|
||||
expect(node("delete-wallet-lost-name").textContent).toBe(
|
||||
"Wallet 2",
|
||||
);
|
||||
node("delete-wallet-lost-name-input").value = "Wallet 2";
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
const persisted = await persistedWallets(storage);
|
||||
expect(persisted.map((w) => w.encryptedSecret)).toEqual([
|
||||
"secret-one",
|
||||
"secret-three",
|
||||
]);
|
||||
},
|
||||
);
|
||||
|
||||
// A zero-width space paints nothing, so "My", a zero-width space and
|
||||
// "Wallet" reads as "MyWallet", and that is all the user can type. HTML
|
||||
// does not collapse it the way it collapses spaces, so it has to be
|
||||
// removed explicitly.
|
||||
test("a zero-width space inside the name is not part of it", async () => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets[1].name = "My" + ZERO_WIDTH_SPACE + "Wallet";
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
|
||||
node("delete-wallet-lost-name-input").value = "MyWallet";
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
const persisted = await persistedWallets(storage);
|
||||
expect(persisted.map((w) => w.encryptedSecret)).toEqual([
|
||||
"secret-one",
|
||||
"secret-three",
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("deleting without the password", () => {
|
||||
|
||||
Reference in New Issue
Block a user