fix: a shared ticker no longer hides one of its two real tokens (closes #276)
All checks were successful
check / check (push) Successful in 33s
All checks were successful
check / check (push) Successful in 33s
Seven bundled tokens were filtered as spoofs at their own address, so a user holding FRAX, TON, REUSD, EURE, MSUSD, MUSD or JPYC could not see or spend the one the wallet happened not to pick. The known-symbol table is derived from the bundled token list, first-wins in market-cap order, so a symbol that appears twice silently condemned its second contract. Both are real tokens from the same fetch and neither is stale -- three pairs are one issuer's old and new contract, four are unrelated issuers sharing a ticker. Picking a winner would have been guessing, and dropping the ambiguous symbols would have ended spoof filtering for those tickers entirely. The table now maps a symbol to the set of addresses that legitimately bear it. A contract outside the set is still a spoof, so the check is not weakened: a third contract bearing any of the seven shared tickers is refused, and that is tested. The filter decides what is fake, not what is worth holding, so a legacy contract stays in the set -- it still holds real balances. A test walks the whole bundled list asserting no token is filtered at its own address, which is the guard whose absence let this ship.
This commit was merged in pull request #277.
This commit is contained in:
14
TODO.md
14
TODO.md
@@ -45,6 +45,20 @@ undefined identifiers, which is how
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-12: `KNOWN_SYMBOLS` now maps a symbol to the set of contract addresses
|
||||
that bear it, not to one of them. A ticker is not unique: seven of the 512
|
||||
bundled tokens — `FRAX`, `REUSD`, `TON`, `EURE`, `MSUSD`, `MUSD` and `JPYC` —
|
||||
share a symbol with another bundled entry at a different real contract, and
|
||||
the table, built from the list first-wins, kept only the earlier one. The
|
||||
other seven were judged spoofs of their own symbol at their own address and
|
||||
hidden from the balance list, the history and the send selector, so a holder
|
||||
could not spend them. Both contracts of each pair come from the same CoinGecko
|
||||
fetch of 2026-02-27, so neither was stale and neither was dropped.
|
||||
`isSpoofedSymbol()` asks set membership instead of equality, which does not
|
||||
loosen the rule — a contract outside the set is still a spoof — and a test now
|
||||
walks `TOKENS` asserting no bundled token is filtered at its own address,
|
||||
which is the walk the suite lacked
|
||||
([#276](https://git.eeqj.de/sneak/AutistMask/issues/276)).
|
||||
- 2026-08-12: The dApp approval round trips are driven end to end in the
|
||||
browser. A test page served by the harness speaks EIP-1193 to the real inpage
|
||||
provider through the real content script, background worker and approval popup
|
||||
|
||||
Reference in New Issue
Block a user