harden: warn for token-permission typed data and show the primary type ethers signs (closes #400)
check / check (push) Successful in 1m19s
e2e / e2e-chrome (push) Failing after 1m36s
e2e / e2e-firefox (push) Successful in 34s

The typed-data screen listed a Permit or Permit2 signature as plain
key/value lines, exactly like a sign-in message. For EIP-2612's Permit and
Permit2's signature types it now shows a red warning naming the spender and
each token and amount, Unlimited for the field's largest value.

The screen printed the page's primaryType, but ethers signs the type it
derives from types. It now shows the derived type, and typed data whose
stated type is missing or differs is refused: error line, Sign disabled,
and checked again where signing starts.

Deviation: the warning names no deadline or expiry; see the issue.
Judgement call: DAI's older permit and Permit2's batch and witness transfer
types are recognised too.

Model: opus-5-5
This commit is contained in:
2026-10-03 12:50:26 +00:00
parent 598de3ff1a
commit 786613ce2d
4 changed files with 425 additions and 10 deletions
+16 -4
View File
@@ -911,9 +911,10 @@ approximation but a different number — 1,000 units of a 6-decimal token
formatted at 18 decimals reads `0.000000001` — on the screen whose only job is
to state what is being authorized. Both amount paths of that screen take this
rule: the ERC-20 `transfer`/`approve` line (`src/popup/views/approval.js`) and
the swap's `Amount` and `Min. received` lines (`src/shared/uniswap.js`). An
unbounded allowance or permit needs no scale to describe and is still shown as
`Unlimited`.
the swap's `Amount` and `Min. received` lines (`src/shared/uniswap.js`). The
token permission warning on the signature screen takes the same rule for its
amounts. An unbounded allowance or permit needs no scale to describe and is
still shown as `Unlimited`.
The rule holds only if nothing invents a scale UPSTREAM of it. Those three
sources are read as authoritative, so a value written into one of them cannot be
@@ -1801,10 +1802,21 @@ view would leave a wallet one click from deletion.
- Type: "Personal message" or "Typed data (EIP-712)"
- From: color dot + full address + etherscan link
- Message: decoded UTF-8 text (personal_sign) or formatted domain/type/
message fields (EIP-712 typed data)
message fields (EIP-712 typed data). The primary type shown is the one
ethers signs, derived from the typed data's `types`, not the type the site
states.
- Token permission warning, at the top of the message (typed data whose
primary type is EIP-2612's `Permit` or one of Permit2's signature types):
"⚠️ TOKEN PERMISSION: Signing this lets the spender below take the tokens
listed here from your address, without asking you again.", then the
spender's full address and, for each token, its symbol, full address and
amount (`Unlimited` for the largest amount the field holds)
- Password input and an error line
- "Sign" / "Reject" buttons
- **Transitions**:
- Typed data that states no primary type, or one other than the type it
would be signed as, or that cannot be read → shown with the error line
saying so and "Sign" disabled; only "Reject" remains
- "Sign" (correct password) → signs locally → closes popup (returns
signature)
- "Sign" (wrong password, or a signing failure) → error line, no screen