harden: warn for token-permission typed data and show the primary type ethers signs (closes #400)
check / check (push) Successful in 49s
e2e / e2e-chrome (push) Successful in 1m44s
e2e / e2e-firefox (push) Successful in 31s

The typed-data screen listed a Permit or Permit2 signature as plain
key/value lines, like a sign-in message. For typed data signed as Permit
or as one of Permit2's types it now shows a red warning naming the
spender and each token and amount, read only from the fields the signed
type declares; whatever they do not give reads Unknown.

The screen printed the page's primaryType, but ethers signs the type it
derives from types. It now shows the derived type, and typed data whose
stated type is missing or differs is refused: error line, Sign disabled,
and checked again where signing starts.

Deviation: the warning names no deadline or expiry; see the issue.
Judgement call: DAI's older permit and Permit2's batch and witness
transfer types are recognised too.

Model: opus-5-5
This commit is contained in:
2026-10-03 14:38:06 +00:00
parent add11e57de
commit eaaf1593c0
4 changed files with 735 additions and 27 deletions
+18
View File
@@ -45,6 +45,24 @@ but the review is broader than any of them.
# Completed Steps
- 2026-10-03: The typed-data signing screen warns for a token permission, and
names the primary type ethers signs
([#400](https://git.eeqj.de/sneak/AutistMask/issues/400)). A Permit or Permit2
signature lets its spender take tokens from the signer's address, and the
screen listed it as plain key/value lines, exactly like a sign-in message. For
typed data signed as `Permit` (EIP-2612's, DAI's older one, or any other of
that name) or as one of Permit2's six signature types,
`src/popup/views/approval.js` now shows a red warning at the top of the
message naming the spender and each token and amount, read only from the
fields the signed type declares, with `Unlimited` for the largest amount the
field holds, the existing unknown-scale wording otherwise, and `Unknown` for
whatever those fields do not give. The screen printed the page's
`primaryType`, but ethers signs the type it derives from `types`; the screen
now shows the derived type, and typed data whose stated type is missing or
differs, or that cannot be read, is shown with an error line and Sign
disabled, and is refused again where signing starts. The warning names no
deadline or expiry: those fields mean different things across the shapes, and
a date could read as the permission ending when it does not.
- 2026-09-21: The network fee a transaction can commit is bounded by the product
of the gas limit and the fee per gas, not by each field alone, and the
wallet's own send is bounded the same way