harden: warn for token-permission typed data and show the primary type ethers signs (closes #400)
The typed-data screen listed a Permit or Permit2 signature as plain key/value lines, like a sign-in message. For typed data signed as Permit or as one of Permit2's types it now shows a red warning naming the spender and each token and amount, read only from the fields the signed type declares; whatever they do not give reads Unknown. The screen printed the page's primaryType, but ethers signs the type it derives from types. It now shows the derived type, and typed data whose stated type is missing or differs is refused: error line, Sign disabled, and checked again where signing starts. Deviation: the warning names no deadline or expiry; see the issue. Judgement call: DAI's older permit and Permit2's batch and witness transfer types are recognised too. Model: opus-5-5
This commit is contained in:
@@ -911,9 +911,10 @@ approximation but a different number — 1,000 units of a 6-decimal token
|
||||
formatted at 18 decimals reads `0.000000001` — on the screen whose only job is
|
||||
to state what is being authorized. Both amount paths of that screen take this
|
||||
rule: the ERC-20 `transfer`/`approve` line (`src/popup/views/approval.js`) and
|
||||
the swap's `Amount` and `Min. received` lines (`src/shared/uniswap.js`). An
|
||||
unbounded allowance or permit needs no scale to describe and is still shown as
|
||||
`Unlimited`.
|
||||
the swap's `Amount` and `Min. received` lines (`src/shared/uniswap.js`). The
|
||||
token permission warning on the signature screen takes the same rule for its
|
||||
amounts. An unbounded allowance or permit needs no scale to describe and is
|
||||
still shown as `Unlimited`.
|
||||
|
||||
The rule holds only if nothing invents a scale UPSTREAM of it. Those three
|
||||
sources are read as authoritative, so a value written into one of them cannot be
|
||||
@@ -1801,10 +1802,25 @@ view would leave a wallet one click from deletion.
|
||||
- Type: "Personal message" or "Typed data (EIP-712)"
|
||||
- From: color dot + full address + etherscan link
|
||||
- Message: decoded UTF-8 text (personal_sign) or formatted domain/type/
|
||||
message fields (EIP-712 typed data)
|
||||
message fields (EIP-712 typed data). The primary type shown is the one
|
||||
ethers signs, derived from the typed data's `types`, not the type the site
|
||||
states.
|
||||
- Token permission warning, at the top of the message (typed data whose
|
||||
primary type is `Permit`, as in EIP-2612, or one of Permit2's signature
|
||||
types): "⚠️ TOKEN PERMISSION: Signing this lets the spender below take the
|
||||
tokens listed here from your address, without asking you again.", then the
|
||||
spender's full address and, for each token, its symbol, full address and
|
||||
amount (`Unlimited` for the largest amount the field holds). These are
|
||||
read only from the fields the signed type declares, never from other keys
|
||||
the site puts in the message; any those fields do not give is shown as
|
||||
`Unknown`, and the domain, type and message lines still follow. Only typed
|
||||
data that cannot be read at all is shown as raw text.
|
||||
- Password input and an error line
|
||||
- "Sign" / "Reject" buttons
|
||||
- **Transitions**:
|
||||
- Typed data that states no primary type, or one other than the type it
|
||||
would be signed as, or that cannot be read → shown with the error line
|
||||
saying so and "Sign" disabled; only "Reject" remains
|
||||
- "Sign" (correct password) → signs locally → closes popup (returns
|
||||
signature)
|
||||
- "Sign" (wrong password, or a signing failure) → error line, no screen
|
||||
|
||||
Reference in New Issue
Block a user