harden: end a site's unremembered connection when its address or wallet is removed (closes #245)
A site connected without "Remember" lives only in the background's in-memory connectedSites map. Removing an address or deleting a wallet dropped the remembered permissions but never told the background; the entry went only as a side effect of the accountsChanged broadcast, which empties the whole map when the active address changes. dropSitePermissions(), shared by both removal paths, now sends AUTISTMASK_ADDRESSES_REMOVED with the removed addresses, and the background deletes their entries. Only the extension's own pages may send it. Model: opus-5-5
This commit is contained in:
@@ -407,7 +407,9 @@ describe("deleting without the password", () => {
|
||||
expect(saved.activeAddress).toBe(A0);
|
||||
expect(saved.selectedWallet).toBe(0);
|
||||
expect(saved.selectedAddress).toBe(0);
|
||||
expect(sent).toEqual([]);
|
||||
expect(sent).toEqual([
|
||||
{ type: "AUTISTMASK_ADDRESSES_REMOVED", addresses: [B0] },
|
||||
]);
|
||||
// Settings is stubbed, so this is where the route hands over, not
|
||||
// where it renders.
|
||||
expect(mockSettingsShow).toHaveBeenCalled();
|
||||
@@ -426,7 +428,10 @@ describe("deleting without the password", () => {
|
||||
"Wallet 3",
|
||||
]);
|
||||
expect(saved.activeAddress).toBe(B0);
|
||||
expect(sent).toEqual([{ type: "AUTISTMASK_ACTIVE_CHANGED" }]);
|
||||
expect(sent).toEqual([
|
||||
{ type: "AUTISTMASK_ADDRESSES_REMOVED", addresses: [A0, A1] },
|
||||
{ type: "AUTISTMASK_ACTIVE_CHANGED" },
|
||||
]);
|
||||
});
|
||||
|
||||
test("deleting the last wallet lands on Welcome with nothing left", async () => {
|
||||
|
||||
Reference in New Issue
Block a user