harden: one connection and one signature prompt per site at a time (closes #405)
check / check (push) Failing after 1s
e2e / e2e-chrome (push) Failing after 2s
e2e / e2e-firefox (push) Failing after 2s

Each eth_requestAccounts or personal_sign call opened another approval
window, so a page calling in a loop could cover the screen with identical
prompts. While a site's connection or signature prompt is unanswered, a
further request of that kind from the same site is now refused with
EIP-1193 -32002 and opens no window; all signing methods count as one
kind. A connection prompt whose toolbar popup closed before it connected,
and which the toolbar popup no longer opens, is shown again by the site's
next request instead of refusing the site until the address changes.

Model: opus-5-5
This commit was merged in pull request #433.
This commit is contained in:
2026-10-04 19:43:11 +02:00
parent de3f7a9a11
commit d1751beb32
4 changed files with 379 additions and 20 deletions
+273 -3
View File
@@ -74,6 +74,22 @@ const NONCE = 7;
// "Hello AutistMask" as the hex string a dApp passes to personal_sign.
const MESSAGE = "0x48656c6c6f204175746973744d61736b";
// An EIP-712 document as a dApp passes it to eth_signTypedData_v4. The
// background only carries it to the approval screen, so a small one does.
const TYPED_DATA = JSON.stringify({
domain: { name: "AutistMask Test", version: "1", chainId: 1 },
primaryType: "Note",
types: {
EIP712Domain: [
{ name: "name", type: "string" },
{ name: "version", type: "string" },
{ name: "chainId", type: "uint256" },
],
Note: [{ name: "contents", type: "string" }],
},
message: { contents: "Hello AutistMask" },
});
// The transaction the background populates and the approval screen displays.
// The nonce is a parameter because the duplicate case turns on two artifacts
// differing in a field the dApp fixed nothing for.
@@ -229,6 +245,7 @@ function loadBackground(options) {
// raised through action.openPopup() opens no window at all, so this is
// the only place its id appears.
const actionPopups = [];
const openPopup = jest.fn(() => Promise.resolve());
global.chrome = {
storage,
@@ -283,7 +300,7 @@ function loadBackground(options) {
// popup: no window is created, so windows.onRemoved can never
// fire for it and the port disconnect is the only close signal
// that exists.
...(opts.actionPopup ? { openPopup: () => Promise.resolve() } : {}),
...(opts.actionPopup ? { openPopup } : {}),
},
};
@@ -330,7 +347,7 @@ function loadBackground(options) {
// The same for a message-signing approval, which pins the signing address
// at approval time in exactly the same way.
function requestSign(from) {
function requestSign(from, origin) {
let rpcResult = null;
messageListener(
{
@@ -338,7 +355,7 @@ function loadBackground(options) {
method: "personal_sign",
params: [MESSAGE, from || signer.address],
},
{ origin: ORIGIN },
{ origin: origin || ORIGIN },
(r) => {
rpcResult = r;
},
@@ -352,6 +369,24 @@ function loadBackground(options) {
};
}
// The same through eth_signTypedData_v4, whose params name the address
// first and the typed data second.
function requestTypedData() {
let rpcResult = null;
messageListener(
{
type: "AUTISTMASK_RPC",
method: "eth_signTypedData_v4",
params: [signer.address, TYPED_DATA],
},
{ origin: ORIGIN },
(r) => {
rpcResult = r;
},
);
return { result: () => rpcResult };
}
// A dApp asking to connect. The origin defaults to one the persisted
// state has never allowed, so the request really does raise a prompt
// instead of being answered from allowedSites.
@@ -426,12 +461,15 @@ function loadBackground(options) {
send,
requestTx,
requestSign,
requestTypedData,
requestSite,
connectApproval,
closeWindow,
broadcastTransaction,
created,
removed,
actionPopups,
openPopup,
storage,
// The user switching account in the toolbar popup, as the background
// sees it: the persisted active address changes underneath a pending
@@ -821,6 +859,238 @@ describe("one transaction approval at a time", () => {
});
});
// A page that asks again before the user has answered its last connection or
// signature request is refused, instead of opening one more window per call.
describe("one connection and one signature approval per site at a time", () => {
const PENDING_REFUSAL = {
error: {
code: -32002,
message: expect.stringMatching(/already waiting for your answer/),
},
};
test("a loop of eth_requestAccounts opens one approval and refuses the rest", async () => {
const bg = loadBackground();
const requests = [];
for (let i = 0; i < 5; i++) requests.push(bg.requestSite());
await settle();
expect(bg.created).toHaveLength(1);
expect(requests[0].result()).toBeNull();
for (const extra of requests.slice(1)) {
expect(extra.result()).toEqual(PENDING_REFUSAL);
}
// Once the user has answered, the site may ask again.
bg.closeWindow(1);
await settle();
expect(requests[0].result()).toEqual({
error: { code: 4001, message: "User rejected the request." },
});
const again = bg.requestSite();
await settle();
expect(again.result()).toBeNull();
expect(bg.created).toHaveLength(2);
});
test("a loop of personal_sign opens one approval and refuses the rest", async () => {
const bg = loadBackground();
const requests = [];
for (let i = 0; i < 5; i++) requests.push(bg.requestSign());
await settle();
expect(bg.created).toHaveLength(1);
expect(requests[0].result()).toBeNull();
for (const extra of requests.slice(1)) {
expect(extra.result()).toEqual(PENDING_REFUSAL);
}
});
test("a loop of eth_signTypedData_v4 opens one approval and refuses the rest", async () => {
const bg = loadBackground();
const requests = [];
for (let i = 0; i < 5; i++) requests.push(bg.requestTypedData());
await settle();
expect(bg.created).toHaveLength(1);
expect(requests[0].result()).toBeNull();
for (const extra of requests.slice(1)) {
expect(extra.result()).toEqual(PENDING_REFUSAL);
}
});
test("a pending personal_sign also refuses eth_signTypedData_v4", async () => {
const bg = loadBackground();
bg.requestSign();
const typed = bg.requestTypedData();
await settle();
expect(typed.result()).toEqual(PENDING_REFUSAL);
expect(bg.created).toHaveLength(1);
});
test("in the toolbar popup, a loop of eth_requestAccounts opens it once", async () => {
const bg = loadBackground({ actionPopup: true });
const requests = [];
for (let i = 0; i < 5; i++) requests.push(bg.requestSite());
await settle();
expect(bg.openPopup).toHaveBeenCalledTimes(1);
for (const extra of requests.slice(1)) {
expect(extra.result()).toEqual(PENDING_REFUSAL);
}
});
// A toolbar popup that closes before it connects tells the background
// nothing, so its prompt stays pending. Once the toolbar popup has been set
// to open something else, nothing shows that prompt, and the site asking
// again must show it again rather than be refused for good.
test("a toolbar prompt nothing shows any more is shown again when the site asks again", async () => {
const bg = loadBackground({ actionPopup: true });
const first = bg.requestSite();
await settle();
const id = first.id();
// Its popup closed without connecting. Another site's prompt takes the
// toolbar popup and is answered, which sets it back to the wallet.
const other = bg.requestSite(UNCONNECTED_ORIGIN);
await settle();
const otherPort = bg.connectApproval(other.id());
otherPort.decide(false, false);
otherPort.disconnect();
await settle();
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
"src/popup/index.html",
);
const repeat = bg.requestSite();
await settle();
expect(repeat.result()).toEqual(PENDING_REFUSAL);
expect(bg.openPopup).toHaveBeenCalledTimes(3);
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
"src/popup/index.html?approval=" + id,
);
// The user answers it, and the first request gets that answer.
bg.connectApproval(id).decide(true, false);
await settle();
expect(first.result()).toEqual({ result: [signer.address] });
});
// The user rejects a signature request from another site, which is
// connected already. Answering any approval sets the toolbar popup back to
// the wallet.
async function rejectSignatureFromAnotherSite(bg) {
const sign = bg.requestSign(undefined, ORIGIN);
await settle();
bg.send(
{
type: "AUTISTMASK_SIGN_RESPONSE",
id: sign.id(),
approved: false,
},
{ url: bg.fromPopup.url },
);
await settle();
expect(sign.result()).toEqual({
error: { code: 4001, message: "User rejected the request." },
});
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
"src/popup/index.html",
);
}
test("a toolbar prompt is shown again after another site's signature request is answered", async () => {
const bg = loadBackground({ actionPopup: true });
const first = bg.requestSite();
await settle();
const id = first.id();
// Its popup closed without connecting.
await rejectSignatureFromAnotherSite(bg);
const repeat = bg.requestSite();
await settle();
expect(repeat.result()).toEqual(PENDING_REFUSAL);
expect(bg.openPopup).toHaveBeenCalledTimes(2);
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
"src/popup/index.html?approval=" + id,
);
});
test("a prompt in a window is not opened again when the site asks again", async () => {
const bg = loadBackground({ actionPopup: true });
// The browser will not open the toolbar popup, so the prompt goes to a
// window of its own.
bg.openPopup.mockImplementation(() =>
Promise.reject(new Error("no toolbar popup")),
);
bg.requestSite();
await settle();
expect(bg.created).toHaveLength(1);
await rejectSignatureFromAnotherSite(bg);
expect(bg.created).toHaveLength(2);
const repeat = bg.requestSite();
await settle();
expect(repeat.result()).toEqual(PENDING_REFUSAL);
expect(bg.openPopup).toHaveBeenCalledTimes(1);
expect(bg.created).toHaveLength(2);
});
test("a prompt in a connected toolbar popup is not opened again when the site asks again", async () => {
const bg = loadBackground({ actionPopup: true });
const first = bg.requestSite();
await settle();
// The popup is open and showing the prompt.
bg.connectApproval(first.id());
await rejectSignatureFromAnotherSite(bg);
const repeat = bg.requestSite();
await settle();
expect(repeat.result()).toEqual(PENDING_REFUSAL);
expect(bg.openPopup).toHaveBeenCalledTimes(1);
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
"src/popup/index.html",
);
});
test("another site's connection request is not held up", async () => {
const bg = loadBackground();
bg.requestSite();
const repeat = bg.requestSite();
const other = bg.requestSite(UNCONNECTED_ORIGIN);
await settle();
expect(repeat.result()).toEqual(PENDING_REFUSAL);
expect(other.result()).toBeNull();
expect(bg.created).toHaveLength(2);
});
test("another site's signature request is not held up", async () => {
const bg = loadBackground();
// Connect a second site, so that it may ask for a signature at all.
const connecting = bg.requestSite();
await settle();
const port = bg.connectApproval(connecting.id());
port.decide(true, false);
port.disconnect();
await settle();
expect(connecting.result()).toEqual({ result: [signer.address] });
bg.requestSign();
const repeat = bg.requestSign();
const other = bg.requestSign(signer.address, FRESH_ORIGIN);
await settle();
expect(repeat.result()).toEqual(PENDING_REFUSAL);
expect(other.result()).toBeNull();
expect(bg.created).toHaveLength(3);
});
});
// A nonce collision found before the transaction reaches the network is the
// one send failure the wallet can speak about with certainty. The user is told
// it did not go out and to send it again, rather than being warned it might