harden: ignore a nonce the page supplies with eth_sendTransaction (closes #404)
A site could fix the nonce of the transaction the user was asked to sign: the same nonce as a pending transaction, at a higher fee, replaces it, and a nonce above the account's next one leaves the new transaction stuck behind a gap. `nonce` is no longer one of the fields taken from the request, so the transaction always gets the account's next nonce from the network, and that is the nonce the approval screen shows and the popup signs. Model: opus-5-5
This commit was merged in pull request #434.
This commit is contained in:
@@ -51,11 +51,15 @@ const POPULATE_TIMEOUT_MS = 20000;
|
||||
// passed to ethers: the object is page-controlled, and a future ethers that
|
||||
// learns to carry a new transaction field must not start picking one up out of
|
||||
// it without this module knowing.
|
||||
//
|
||||
// The nonce is not taken from the page; it is always the account's next nonce
|
||||
// from the network. A page that chose it could replace one of the user's
|
||||
// pending transactions (the same nonce at a higher fee) or leave this one stuck
|
||||
// behind a gap (a nonce above the next one).
|
||||
const REQUEST_FIELDS = [
|
||||
"to",
|
||||
"value",
|
||||
"data",
|
||||
"nonce",
|
||||
"gasLimit",
|
||||
"gasPrice",
|
||||
"maxFeePerGas",
|
||||
|
||||
Reference in New Issue
Block a user