harden: a token scale above 80 decimal places is refused as unknown (closes #350)
toDecimals() accepted any uint8 scale, but formatUnits() and parseUnits() refuse more than 80 decimal places. A token reporting 81 to 255 made the formatter throw, and the catch in the swap decoder and in the ERC-20 decoder turned that into an undecoded approval screen with nothing saying why. MAX_DECIMALS is now 80, the formatter's own limit, so such a scale is treated exactly like an unknown one: both approval paths show the base-unit amount with the scale stated as unknown. The balance list, the history list and the Send screen use the same check. Model: opus-5-5
This commit is contained in:
@@ -45,6 +45,15 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: A token that reports more than 80 decimal places has no known
|
||||
scale ([#350](https://git.eeqj.de/sneak/AutistMask/issues/350)). The shared
|
||||
scale check `toDecimals()` accepted any `uint8`, but `formatUnits()` throws
|
||||
above 80, so such a token left a swap or an ERC-20 call on the approval screen
|
||||
undecoded, with nothing saying why. The check now stops at 80, and both
|
||||
approval paths show the base-unit amount with the scale stated as unknown. The
|
||||
balance list and the history list use the same check, so the same token no
|
||||
longer stops an address's token balances from refreshing or its history from
|
||||
loading.
|
||||
- 2026-10-04: Debug mode no longer writes RPC API keys to the console
|
||||
([#410](https://git.eeqj.de/sneak/AutistMask/issues/410)). `debugFetch` logged
|
||||
every request's full URL and body, so an RPC endpoint with a key in its path
|
||||
|
||||
Reference in New Issue
Block a user