Commit Graph
8 Commits
Author SHA1 Message Date
clawbot f47d17a98f chore: the native token's label follows the active network (closes #372)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 2s
e2e / e2e-firefox (push) Failing after 2s
networks.js gives each network a nativeCurrency (ETH, SepoliaETH) and nothing
read it: every screen wrote a hardcoded ETH, so on Sepolia the balance, the
value and the fee all read ETH. A nativeCurrency() helper in the popup's
helpers.js returns the active network's, and every native balance, value, fee,
reserve, type line and history entry is labelled with it. The "ETH" that
selectedToken and txInfo.token hold is the native token's id and is unchanged.
The confirmation screen's not-enough-to-pay-the-fee sentence now names the
coin to add, so show() sets it.

Model: opus-5-5
2026-10-04 21:53:00 +00:00
clawbot bd0a626e7b harden: stop the background reading the shared state singleton, and enforce it at build time (closes #324)
check / check (push) Successful in 33s
e2e / e2e-chrome (push) Successful in 1m45s
e2e / e2e-firefox (push) Successful in 31s
Five defects, one of which destroyed every wallet, came from src/background reading and writing the module-level state singleton the MV3 worker never populates, which silently served DEFAULT_STATE. Each point fix created the next defect. The background now has its own per-call getState() and a queued read-modify-write updateState(); the singleton is unreachable from it, and an unpopulated read throws instead of serving defaults.

The prohibition is enforced by the build, not by review: build.js asserts over esbuild's own metafile that no forbidden module is an input of a background bundle, so every specifier syntax esbuild resolves is covered, and both halves of the table are checked for rot -- a stale key, a stale module, an empty list, or an unlisted entry point under src/background/ all fail the build. The ESLint rule remains as fast local feedback and reads the same shared table. Known bounds are documented where the table lives.

Also closes #320: getProvider() now requires a validated network id, so a cold worker no longer prepares a non-mainnet dApp transaction for mainnet and gets refused by the wallet's own verifier. backgroundRefresh() no longer mutates address objects across a network round trip, the broadcast path takes its endpoint and chain id from one snapshot, and eight test storage stubs now structured-clone on get as the real chrome.storage.local does.

closes #320
2026-08-23 17:57:30 +02:00
clawbot c755a5e944 fix: a shared ticker no longer hides one of its two real tokens (closes #276)
check / check (push) Successful in 33s
Seven bundled tokens were filtered as spoofs at their own address, so a user
holding FRAX, TON, REUSD, EURE, MSUSD, MUSD or JPYC could not see or spend the
one the wallet happened not to pick.

The known-symbol table is derived from the bundled token list, first-wins in
market-cap order, so a symbol that appears twice silently condemned its second
contract. Both are real tokens from the same fetch and neither is stale --
three pairs are one issuer's old and new contract, four are unrelated issuers
sharing a ticker. Picking a winner would have been guessing, and dropping the
ambiguous symbols would have ended spoof filtering for those tickers entirely.

The table now maps a symbol to the set of addresses that legitimately bear it.
A contract outside the set is still a spoof, so the check is not weakened: a
third contract bearing any of the seven shared tickers is refused, and that is
tested. The filter decides what is fake, not what is worth holding, so a legacy
contract stays in the set -- it still holds real balances.

A test walks the whole bundled list asserting no token is filtered at its own
address, which is the guard whose absence let this ship.
2026-08-12 13:31:55 +02:00
clawbot ce4a0d7b8d fix: distinguish an unknown holder count from zero so a legitimate token is not filtered (closes #230)
check / check (push) Successful in 39s
2026-08-12 10:34:45 +02:00
clawbot 74c137dadf fix: add a Settings toggle for known-symbol spoof verification (closes #176)
check / check (push) Has been cancelled
2026-08-11 15:38:05 +02:00
clawbot 12acf4dc8c fix: honour a dust threshold of 0 and compare addresses case-insensitively (closes #179)
check / check (push) Has been cancelled
2026-08-11 15:16:48 +02:00
clawbot f271bcd7b4 fix: one transaction history row per value movement (closes #177)
check / check (push) Has been cancelled
2026-08-11 14:56:30 +02:00
clawbot 188882d635 test: cover the address-poisoning filters in transactions.js (closes #160)
check / check (push) Has been cancelled
47 tests over src/shared/transactions.js: both real address-poisoning attacks
as fixtures, each of the four filters on and off, threshold boundaries, no
false positives, and the per-address merge/dedup path. No source file changed.
2026-08-10 15:53:15 +02:00