harden: warn for token-permission typed data and show the primary type ethers signs (closes #400)
check / check (push) Successful in 1m19s
e2e / e2e-chrome (push) Failing after 1m36s
e2e / e2e-firefox (push) Successful in 34s

The typed-data screen listed a Permit or Permit2 signature as plain
key/value lines, exactly like a sign-in message. For EIP-2612's Permit and
Permit2's signature types it now shows a red warning naming the spender and
each token and amount, Unlimited for the field's largest value.

The screen printed the page's primaryType, but ethers signs the type it
derives from types. It now shows the derived type, and typed data whose
stated type is missing or differs is refused: error line, Sign disabled,
and checked again where signing starts.

Deviation: the warning names no deadline or expiry; see the issue.
Judgement call: DAI's older permit and Permit2's batch and witness transfer
types are recognised too.

Model: opus-5-5
This commit is contained in:
2026-10-03 12:50:26 +00:00
parent 598de3ff1a
commit 786613ce2d
4 changed files with 425 additions and 10 deletions
+16
View File
@@ -45,6 +45,22 @@ but the review is broader than any of them.
# Completed Steps
- 2026-10-03: The typed-data signing screen warns for a token permission, and
names the primary type ethers signs
([#400](https://git.eeqj.de/sneak/AutistMask/issues/400)). A Permit or Permit2
signature lets its spender take tokens from the signer's address, and the
screen listed it as plain key/value lines, exactly like a sign-in message. For
EIP-2612's `Permit` (and DAI's older permit of the same name) and Permit2's
six signature types, `src/popup/views/approval.js` now shows a red warning at
the top of the message naming the spender and each token and amount, with
`Unlimited` for the largest amount the field holds and the existing
unknown-scale wording otherwise. The screen printed the page's `primaryType`,
but ethers signs the type it derives from `types`; the screen now shows the
derived type, and typed data whose stated type is missing or differs, or that
cannot be read, is shown with an error line and Sign disabled, and is refused
again where signing starts. The warning names no deadline or expiry: those
fields mean different things across the shapes, and a date could read as the
permission ending when it does not.
- 2026-09-21: The network fee a transaction can commit is bounded by the product
of the gas limit and the fee per gas, not by each field alone, and the
wallet's own send is bounded the same way