fix: floor malformed allowedSites, fraudContracts and selectedToken entries (closes #362)
check / check (push) Successful in 42s
e2e / e2e-chrome (push) Successful in 1m45s
e2e / e2e-firefox (push) Successful in 31s

A stored allowedSites whose value was not a list rendered a working popup and then made every subsequent save fail silently, so the user operated a wallet that persisted nothing -- worse than a blank popup, which is at least visibly broken. fraudContracts and selectedToken had the same shape: a container floored by truthiness or not at all, while its entries were dereferenced. Entries are now floored as well as containers, following the idiom #311 established, and a failed save raises a persistent banner instead of vanishing into a swallowed rejection.

The per-field justifications that used to live in a hand-written header are replaced by a contract test that drives each field's hostile and falsy values through a real popup boot, so a claim about a field answers to the code rather than to prose. Its guarantee is stated narrowly and deliberately: no structural dereference on the code paths a wholly-corrupted profile takes, which is not every path a stored record takes. The paths it does not drive are named where the claim is made, and are tracked in #379.
This commit was merged in pull request #366.
This commit is contained in:
2026-08-23 23:06:17 +02:00
parent 45500e66cf
commit a098bb0c32
14 changed files with 2100 additions and 354 deletions
+22 -2
View File
@@ -1,9 +1,14 @@
// AutistMask popup entry point.
// Loads state, initializes views, triggers first render.
const { state, saveState, loadState } = require("../shared/state");
const {
state,
saveState,
onSaveFailure,
loadState,
} = require("../shared/state");
const { StateUnusableError } = require("../shared/stateSchema");
const { setRuntimeDebug } = require("../shared/log");
const { log, setRuntimeDebug } = require("../shared/log");
const { refreshPrices } = require("../shared/prices");
const { refreshBalances } = require("../shared/balances");
const {
@@ -11,6 +16,7 @@ const {
showView,
updateDebugBanner,
setBackRenderer,
showSaveFailureBanner,
pushCurrentView,
goBack,
} = require("./views/helpers");
@@ -61,6 +67,14 @@ async function doRefreshAndRender() {
state.lastBalanceRefresh = Date.now();
await saveState();
renderWalletList();
} catch (e) {
// Every call site fires this and walks away — the boot below, the ten
// second interval, and eight views through ctx — so it must never
// reject: an unhandled rejection is not a report of anything. The save
// inside it reports its own failure through onSaveFailure() (see
// src/shared/state.js); what is left here is a failed network round
// trip, which the next tick retries.
log.errorf("popup: background refresh failed:", e);
} finally {
refreshInFlight = false;
}
@@ -136,6 +150,12 @@ function fallbackView() {
}
async function init() {
// First, before anything can save: showView() saves on every navigation
// without awaiting, so a save that fails from here on has somewhere to be
// reported rather than being swallowed by the save queue
// (https://git.eeqj.de/sneak/AutistMask/issues/362). Registered ahead of
// the approval-window branch below too, since that window saves as well.
onSaveFailure(showSaveFailureBanner);
try {
await loadState();
} catch (e) {
+78 -3
View File
@@ -53,12 +53,17 @@ function resetRenderedViews() {
const ALWAYS_RENDER_ON_BACK = new Set(["main"]);
// Views that render an address the user picked and cannot be rendered
// without one.
// without one. "confirm-tx" is here because its Sign button dereferences
// `state.wallets[state.selectedWallet].encryptedSecret`
// (src/popup/views/confirmTx.js) behind no guard of its own — a screen that
// can only throw when the user presses its one button must not be restored
// onto.
const ADDRESS_VIEWS = new Set([
"address",
"address-token",
"receive",
"transaction",
"confirm-tx",
]);
function needsAddress(view) {
@@ -74,6 +79,73 @@ function hasValidAddress(state) {
);
}
// The stored viewData ENTRIES each branch below dereferences, as opposed to
// the one field it gates on.
//
// A gate on a single truthy field checks the container, not the entries, and
// the dereference is one level below it: a stored `{"currentView":
// "success-tx","viewData":{"hash":"0x1"}}` passes `data.hash` and then throws
// on `address.toLowerCase()` inside addressTitle() (src/popup/views/
// helpers.js), out of restoreView(), which src/popup/index.js does not guard —
// so the rest of popup init never runs. txStatus.restoreWait() has checked its
// own branch's fields since it was written; these are the other four.
//
// Only what actually throws is required. Fields that are compared,
// concatenated or escaped coerce (escapeHtml() and displaySymbol() both
// String() their argument), so requiring them would refuse a restorable screen
// over a cosmetic value.
function isText(value) {
return typeof value === "string";
}
function isRecord(value) {
return typeof value === "object" && value !== null && !Array.isArray(value);
}
// An address handed to renderAddressHtml()/addressTitle(): both reach
// `address.slice()` and `address.toLowerCase()` with no guard.
function isAddressText(value) {
return isText(value);
}
// Decoded calldata, as decodedDetailsHtml() (src/popup/views/txStatus.js)
// walks it: `for (const d of decoded.details)` needs an iterable, and each
// entry's `address` reaches toAddressHtml(). Absent or falsy is the ordinary
// case and short-circuits before either.
function isRenderableDecoded(value) {
if (!value) return true;
if (!isRecord(value)) return false;
if (!value.details) return true;
if (!Array.isArray(value.details)) return false;
return value.details.every(
(entry) =>
isRecord(entry) && (!entry.address || isAddressText(entry.address)),
);
}
// The pending transaction confirmTx.show() renders: `token` reaches
// renderAddressHtml() when it is not "ETH", and `from`/`to` reach
// addressTitle(), makeBlockie() and getLocalWarnings().
function isRenderablePendingTx(value) {
return (
isRecord(value) &&
isText(value.token) &&
isAddressText(value.from) &&
isAddressText(value.to)
);
}
// The stored transaction transactionDetail.render() shows. contractAddress is
// optional on an ETH transfer, and reaches addressDotHtml() when it is there.
function isRenderableTx(value) {
return (
isRecord(value) &&
isAddressText(value.from) &&
isAddressText(value.to) &&
(!value.contractAddress || isAddressText(value.contractAddress))
);
}
// Render `view` from persisted state. Each view module shows itself, so a
// true return means the view is both rendered and on screen.
//
@@ -107,11 +179,11 @@ function renderView(view, state, views) {
views.settingsAddToken.show();
return true;
case "confirm-tx":
if (!data.pendingTx) return false;
if (!isRenderablePendingTx(data.pendingTx)) return false;
views.confirmTx.restore();
return true;
case "transaction":
if (!data.tx) return false;
if (!isRenderableTx(data.tx)) return false;
views.transactionDetail.render();
return true;
case "wait-tx":
@@ -120,10 +192,13 @@ function renderView(view, state, views) {
return Boolean(views.txStatus.restoreWait());
case "success-tx":
if (!data.hash) return false;
if (!isAddressText(data.to)) return false;
if (!isRenderableDecoded(data.decoded)) return false;
views.txStatus.renderSuccess();
return true;
case "error-tx":
if (!data.message) return false;
if (!isAddressText(data.to)) return false;
views.txStatus.renderError();
return true;
default:
+33
View File
@@ -132,6 +132,38 @@ function updateDebugBanner(viewName) {
}
}
// The banner shown when a save has failed, registered as the save-failure
// reporter by src/popup/index.js.
//
// Persistent and not dismissable, unlike showFlash(): what it says is true
// until the popup is closed, and a message that clears itself after two seconds
// is how the user goes on operating a wallet that is persisting nothing
// (https://git.eeqj.de/sneak/AutistMask/issues/362). It survives navigation
// because it hangs off document.body rather than off a view.
//
// Created on demand rather than authored in index.html, the same way
// updateDebugBanner() creates its own: it is absent from a popup where nothing
// has failed, which is the state that must not need markup to be in.
//
// textContent, never innerHTML: `detail` carries an error message, which may
// come from the browser's storage layer.
function showSaveFailureBanner(detail) {
let banner = document.getElementById("save-failure-banner");
if (!banner) {
banner = document.createElement("div");
banner.id = "save-failure-banner";
banner.style.cssText =
"background:#c00;color:#fff;text-align:center;font-size:10px;padding:2px 4px;font-family:monospace;position:sticky;top:0;z-index:10000;";
document.body.prepend(banner);
}
const message = (detail && (detail.message || detail.problem)) || detail;
banner.textContent =
"NOT SAVED — AutistMask could not write to storage, so recent" +
" changes are not stored. Close and reopen the popup; if this keeps" +
" happening, do not rely on anything you change now." +
(message ? " (" + String(message) + ")" : "");
}
// Callback that renders a view being navigated BACK onto. Set once by
// index.js via setBackRenderer(), which routes the view through the same
// per-view render and data guards restoreView() uses.
@@ -544,6 +576,7 @@ module.exports = {
showView,
onViewLeave,
updateDebugBanner,
showSaveFailureBanner,
setBackRenderer,
pushCurrentView,
goBack,