harden: list and end site connections made without Remember in Settings (closes #406)
A site allowed without "Remember" lives only in the background's in-memory connectedSites map. Settings never listed it, and AUTISTMASK_REMOVE_SITE, sent on every remove, did nothing, so the user could not end such a connection. Settings now asks the background for those sites and lists them under Connected Sites. Removing a site from Allowed Sites or Connected Sites drops its remembered entry under every address and sends AUTISTMASK_REMOVE_SITE with the hostname; the background deletes every matching connectedSites entry and sends accountsChanged with an empty list to the site's tabs. Only the extension's own pages may send either message. Model: opus-5-5
This commit is contained in:
@@ -1582,8 +1582,14 @@ view would leave a wallet one click from deletion.
|
||||
a value carrying its unit, hex (`0x10`) or exponent (`1e3`) notation —
|
||||
is refused with a flash message and the field snaps back to the stored
|
||||
threshold, so a number the user did not type is never stored.
|
||||
- Allowed Sites: list with remove buttons
|
||||
- Denied Sites: list with remove buttons
|
||||
- Allowed Sites: the hostnames remembered as allowed, under any address,
|
||||
with remove buttons
|
||||
- Connected Sites: the hostnames of the sites allowed without "Remember my
|
||||
choice" that are still connected, with remove buttons. Only the background
|
||||
holds these, in memory, and Settings asks it for them with
|
||||
`AUTISTMASK_GET_CONNECTED_SITES`
|
||||
- Denied Sites: the hostnames remembered as denied, under any address, with
|
||||
remove buttons
|
||||
- About: project link, license, author, version, release date, and the
|
||||
commit, which links to the commit in the repository
|
||||
- Debug: hidden until revealed, then an "Enable debug mode" checkbox that
|
||||
@@ -1594,8 +1600,15 @@ view would leave a wallet one click from deletion.
|
||||
- `[recovery phrase]` on an HD wallet → **ShowRecoveryPhrase**
|
||||
- `[x]` on a wallet → **DeleteWallet**
|
||||
- Tap wallet name → inline rename field (no screen change)
|
||||
- `[x]` on a tracked token or a site → removes it in place (no screen
|
||||
change)
|
||||
- `[x]` on a tracked token → removes it in place (no screen change)
|
||||
- `[x]` on an allowed or connected site → disconnects that site, in place:
|
||||
its hostname is dropped from Allowed Sites under every address, and
|
||||
`AUTISTMASK_REMOVE_SITE` has the background end every connection approved
|
||||
without "Remember" from an origin with that hostname, under any address,
|
||||
and send `accountsChanged` with an empty list to the site's open tabs.
|
||||
Only the extension's own pages may send either message
|
||||
- `[x]` on a denied site → forgets the refusal, in place; it connects
|
||||
nothing and tells the background nothing
|
||||
- Ten clicks on the version → reveals the Debug well (no screen change)
|
||||
- "Back" (or Settings gear again) → previous screen (Home)
|
||||
|
||||
@@ -1790,7 +1803,8 @@ view would leave a wallet one click from deletion.
|
||||
- **Transitions**:
|
||||
- "Allow" / "Deny" → closes popup (returns result to background script; the
|
||||
choice is persisted to the allowed or denied list when "Remember" is
|
||||
checked)
|
||||
checked, and an "Allow" without it is listed under Connected Sites in
|
||||
**Settings**)
|
||||
- Popup closed without answering → treated as a denial
|
||||
|
||||
#### TxApproval (`approve-tx`)
|
||||
|
||||
Reference in New Issue
Block a user