Compare commits
5 Commits
13d444c3aa
...
fix/issue-
| Author | SHA1 | Date | |
|---|---|---|---|
| 34c1b00710 | |||
| 9dcd875dd4 | |||
| c755a5e944 | |||
| d5595c0151 | |||
| e4c3708b84 |
106
README.md
106
README.md
@@ -169,6 +169,34 @@ reserve while sitting on the same side of the estimate, so swapping the two in
|
|||||||
what [#154](https://git.eeqj.de/sneak/AutistMask/issues/154) was, and it was
|
what [#154](https://git.eeqj.de/sneak/AutistMask/issues/154) was, and it was
|
||||||
previously correct by reading only.
|
previously correct by reading only.
|
||||||
|
|
||||||
|
It also covers the **dApp approval round trips** — the one place where the
|
||||||
|
content script, the inpage provider, the background worker and the approval
|
||||||
|
popup all have to work together. A local test page is served by the route
|
||||||
|
handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
|
||||||
|
`MAIN`-world content script like any other page, and drives
|
||||||
|
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
|
||||||
|
`eth_sendTransaction` through the real prompts. Every signature is recovered in
|
||||||
|
the runner and compared against the active address, the transaction assertions
|
||||||
|
run against the raw signed transaction captured at `eth_sendRawTransaction`
|
||||||
|
rather than against anything the extension reported, rejecting each prompt is
|
||||||
|
required to return a rejection to the page rather than hang or resolve, and the
|
||||||
|
password is required to be absent from every message the approval window sends
|
||||||
|
to the background — with the message that would carry it required to be present,
|
||||||
|
so that check cannot pass by observing nothing. That last one is the standing
|
||||||
|
floor under [#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
||||||
|
|
||||||
|
Three limits of that coverage, none of them papered over. The RPC is stubbed
|
||||||
|
throughout, so this is **not** a real dApp against a real network with real
|
||||||
|
funds; that remains a human pass before 1.0.0. The site-connection prompt is
|
||||||
|
raised through `chrome.action.openPopup()`, and headless Chromium's
|
||||||
|
browser-action popup is not a page Playwright can see or click, so that one
|
||||||
|
prompt is driven at the URL the extension itself puts on the action — the same
|
||||||
|
page and the same approval id, but whether a real toolbar click shows it is not
|
||||||
|
observable here. And the EIP-1193 error code does not survive the last hop: the
|
||||||
|
rejection that crosses the boundary carries code 4001 and is asserted to, but
|
||||||
|
`src/content/inpage.js` rebuilds it as `new Error(message)`, so the calling page
|
||||||
|
catches an error with no `code` property.
|
||||||
|
|
||||||
Any test that drives a failure path on purpose declares the `console.error` it
|
Any test that drives a failure path on purpose declares the `console.error` it
|
||||||
is about to provoke, via `errors.expect()`. That is not a mute: the declaration
|
is about to provoke, via `errors.expect()`. That is not a mute: the declaration
|
||||||
consumes exactly one matching record, and a declaration nothing matched fails
|
consumes exactly one matching record, and a declaration nothing matched fails
|
||||||
@@ -215,10 +243,18 @@ and this suite exists because exactly that class of bug shipped twice.
|
|||||||
|
|
||||||
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
|
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
|
||||||
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
|
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
|
||||||
It covers popup load, wallet creation through the UI, and the Add Token screen.
|
It covers popup load, wallet creation through the UI, the Add Token screen, and
|
||||||
The suite lives in `tests/e2e/firefox/` and has **no npm dependencies at all**:
|
the four dApp round trips — `eth_requestAccounts`, `personal_sign`,
|
||||||
it is a small WebDriver client built on global `fetch` and `child_process`
|
`eth_sendTransaction`, and a closed approval window rejecting with EIP-1193 4001
|
||||||
against geckodriver's HTTP API.
|
— driven through the real content script, background page and approval windows.
|
||||||
|
|
||||||
|
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
|
||||||
|
**no npm dependencies at all**: it is built on global `fetch` and
|
||||||
|
`child_process` against geckodriver's HTTP API. The dApp fixture (`dapp.js`) and
|
||||||
|
the assertions do use `ethers`, and have to — a signature is recovered in the
|
||||||
|
runner rather than believed from the extension, and the stub node has to answer
|
||||||
|
`eth_sendRawTransaction` with the hash `ethers` computes for the artifact it
|
||||||
|
sent, or `provider.broadcastTransaction()` refuses the answer.
|
||||||
|
|
||||||
Unlike the Chrome suite it builds its own container image rather than pulling a
|
Unlike the Chrome suite it builds its own container image rather than pulling a
|
||||||
published one, because no published image carries both a pinned Firefox and a
|
published one, because no published image carries both a pinned Firefox and a
|
||||||
@@ -240,20 +276,30 @@ because BiDi's `browsingContext.navigate` refuses `moz-extension://` outright.
|
|||||||
**Any uncaught error from a `moz-extension://` source fails the run**, including
|
**Any uncaught error from a `moz-extension://` source fails the run**, including
|
||||||
errors from the background page, which the suite never navigates to: a `throw`
|
errors from the background page, which the suite never navigates to: a `throw`
|
||||||
at the top of `src/background/index.js` kills the background page and fails
|
at the top of `src/background/index.js` kills the background page and fails
|
||||||
step 1. Content-script errors should arrive by the same route, but this suite
|
step 1. Content scripts **are** exercised now — the dApp steps drive a page
|
||||||
does not exercise it and does not claim it — with `--network none` there is no
|
served from loopback, which survives `--network none` — but the _capture_ of a
|
||||||
`http://` page for a content script to be injected into. Errors from add-on
|
content-script error by this route is still unproven: no probe has forced a
|
||||||
install and background startup are folded into step 1 rather than discarded.
|
throw inside one and watched it fail the run, so it remains an expectation
|
||||||
Errors are read from the privileged `nsIConsoleService` in Marionette's chrome
|
rather than a demonstrated fact. Errors from add-on install and background
|
||||||
context and filtered to non-warning entries whose `sourceName` is the extension
|
startup are folded into step 1 rather than discarded.
|
||||||
origin. That mechanism is not a stylistic choice. WebDriver BiDi's
|
|
||||||
`log.entryAdded` delivers **nothing** for extension pages: on a plain `http://`
|
One error is tolerated rather than fatal, listed in `ALLOWED_ERRORS` in
|
||||||
page it reports uncaught errors with stack traces, and on the `moz-extension://`
|
`tests/e2e/firefox/run.js` with the issue that will delete it, and printed on
|
||||||
popup it reports zero events, because Firefox's remote agent excludes extension
|
every occurrence so the concession stays visible in the run output. It is
|
||||||
browsing contexts from BiDi observation. Any harness built on Playwright-BiDi or
|
Firefox reporting the site-approval popup's unawaited `sendMessage` settling
|
||||||
Puppeteer-BiDi would therefore see nothing and report success, which is exactly
|
after `window.close()` unloaded the context — the same teardown ordering as
|
||||||
the vacuous check this repo has already shipped twice. Do not migrate this suite
|
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275), and unsuppressable from
|
||||||
to BiDi.
|
the calling code, because `BaseContext.wrapPromise` reports it whether or not a
|
||||||
|
handler is attached. Errors are read from the privileged `nsIConsoleService` in
|
||||||
|
Marionette's chrome context and filtered to non-warning entries whose
|
||||||
|
`sourceName` is the extension origin. That mechanism is not a stylistic choice.
|
||||||
|
WebDriver BiDi's `log.entryAdded` delivers **nothing** for extension pages: on a
|
||||||
|
plain `http://` page it reports uncaught errors with stack traces, and on the
|
||||||
|
`moz-extension://` popup it reports zero events, because Firefox's remote agent
|
||||||
|
excludes extension browsing contexts from BiDi observation. Any harness built on
|
||||||
|
Playwright-BiDi or Puppeteer-BiDi would therefore see nothing and report
|
||||||
|
success, which is exactly the vacuous check this repo has already shipped twice.
|
||||||
|
Do not migrate this suite to BiDi.
|
||||||
|
|
||||||
Two limits are worth knowing, both real differences from the Chrome suite:
|
Two limits are worth knowing, both real differences from the Chrome suite:
|
||||||
|
|
||||||
@@ -277,17 +323,19 @@ Two limits are worth knowing, both real differences from the Chrome suite:
|
|||||||
but a step that logs heavily could evict unread errors. What poll-based costs
|
but a step that logs heavily could evict unread errors. What poll-based costs
|
||||||
is location, not coverage: an error cannot be placed within a step the way the
|
is location, not coverage: an error cannot be placed within a step the way the
|
||||||
Chrome suite's `pageerror` events place it.
|
Chrome suite's `pageerror` events place it.
|
||||||
- **Nothing is stubbed, which inverts the coverage of network-dependent code.**
|
- **Almost nothing is stubbed, which inverts the coverage of network-dependent
|
||||||
There is no fixture layer; the container runs with `--network none` instead,
|
code.** The container still runs with `--network none`, so the run is offline
|
||||||
so the run is offline and deterministic and no request can escape. The
|
and no request can escape. The one thing it can reach is the loopback fixture
|
||||||
extension swallows its own fetch failures, so the flows are unaffected — but
|
in `tests/e2e/firefox/dapp.js`, which serves the dApp page and a JSON-RPC node
|
||||||
every network call fails, so only the _failure_ branches of code that depends
|
and which the extension's `rpcUrl` is pointed at for the dApp steps; a
|
||||||
on one are ever executed. A `ReferenceError` in the success path of
|
JSON-RPC method that fixture does not model fails the run rather than
|
||||||
`renderTransactions`, or of price or balance rendering, passes this suite
|
answering `null`. Everything else — Blockscout, the price feed, the phishing
|
||||||
green. The offline run is also weaker than the Chrome suite's interception: it
|
blocklist — has no fixture and simply fails, and the extension swallows its
|
||||||
proves nothing got out, but it cannot report which requests were attempted.
|
own fetch failures, so only the _failure_ branches of that code are ever
|
||||||
Closing that gap needs a fixture layer, deliberately out of scope for this
|
executed. A `ReferenceError` in the success path of `renderTransactions`, or
|
||||||
harness.
|
of price rendering, passes this suite green. The offline run is also weaker
|
||||||
|
than the Chrome suite's interception for those calls: it proves nothing got
|
||||||
|
out, but it cannot report which requests were attempted.
|
||||||
|
|
||||||
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
||||||
`make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser
|
`make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser
|
||||||
|
|||||||
66
TODO.md
66
TODO.md
@@ -45,6 +45,72 @@ undefined identifiers, which is how
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-08-12: One shared extension-API module,
|
||||||
|
[`src/shared/browserApi.js`](src/shared/browserApi.js), is the only place in
|
||||||
|
the tree that names `browser` or `chrome`. Every call site returns a promise;
|
||||||
|
`runtime.lastError` is gone. The same commit gives the Firefox suite the four
|
||||||
|
dApp round trips — `eth_requestAccounts`, `personal_sign`,
|
||||||
|
`eth_sendTransaction` and a closed approval window rejecting with EIP-1193
|
||||||
|
4001 — against a page and a JSON-RPC node served from loopback, which survives
|
||||||
|
`--network none`. **The premise of
|
||||||
|
[#153](https://git.eeqj.de/sneak/AutistMask/issues/153) does not survive that
|
||||||
|
harness**: Firefox's `browser.*` honours a trailing Chrome-style callback and
|
||||||
|
populates `runtime.lastError`, both measured directly on Firefox 153.0.3, and
|
||||||
|
all four flows pass against the unconverted code. What landed is a uniformity
|
||||||
|
and coverage change, not a repair of a broken target.
|
||||||
|
- 2026-08-12: EIP-1193 error codes now reach the page. `src/content/inpage.js`
|
||||||
|
rebuilt every failure as `new Error(error.message)`, so the code the
|
||||||
|
background produced and the content script relayed intact was dropped in the
|
||||||
|
last hop and a dApp checking `err.code === 4001` saw `undefined` — a wallet
|
||||||
|
the user deliberately declined was indistinguishable from one that broke. The
|
||||||
|
provider now rejects with a `ProviderRpcError` carrying `code` and, where the
|
||||||
|
boundary sent one, `data`, passed through verbatim rather than matched against
|
||||||
|
a list, so 4001, 4100 and 4902 all arrive and a future code needs no edit
|
||||||
|
here. An error the background sent with no code stays a plain `Error` with no
|
||||||
|
`code` property, and `message` is unchanged in every case. All four request
|
||||||
|
entry points (`request`, `enable`, `send`, `sendAsync`) are covered by
|
||||||
|
`tests/inpageErrors.test.js`, and the e2e probe that printed the missing code
|
||||||
|
now requires it on the page's Error as well as on the wire, for all four
|
||||||
|
rejected flows ([#274](https://git.eeqj.de/sneak/AutistMask/issues/274)).
|
||||||
|
- 2026-08-12: `KNOWN_SYMBOLS` now maps a symbol to the set of contract addresses
|
||||||
|
that bear it, not to one of them. A ticker is not unique: seven of the 512
|
||||||
|
bundled tokens — `FRAX`, `REUSD`, `TON`, `EURE`, `MSUSD`, `MUSD` and `JPYC` —
|
||||||
|
share a symbol with another bundled entry at a different real contract, and
|
||||||
|
the table, built from the list first-wins, kept only the earlier one. The
|
||||||
|
other seven were judged spoofs of their own symbol at their own address and
|
||||||
|
hidden from the balance list, the history and the send selector, so a holder
|
||||||
|
could not spend them. Both contracts of each pair come from the same CoinGecko
|
||||||
|
fetch of 2026-02-27, so neither was stale and neither was dropped.
|
||||||
|
`isSpoofedSymbol()` asks set membership instead of equality, which does not
|
||||||
|
loosen the rule — a contract outside the set is still a spoof — and a test now
|
||||||
|
walks `TOKENS` asserting no bundled token is filtered at its own address,
|
||||||
|
which is the walk the suite lacked
|
||||||
|
([#276](https://git.eeqj.de/sneak/AutistMask/issues/276)).
|
||||||
|
- 2026-08-12: The dApp approval round trips are driven end to end in the
|
||||||
|
browser. A test page served by the harness speaks EIP-1193 to the real inpage
|
||||||
|
provider through the real content script, background worker and approval popup
|
||||||
|
for `eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
|
||||||
|
`eth_sendTransaction`. Every signature is recovered and compared against the
|
||||||
|
active address, the transaction is checked against the bytes handed to the
|
||||||
|
stubbed RPC, each rejection must reach the page as a rejection, and the
|
||||||
|
password must appear in no message the approval window sends — the assertion
|
||||||
|
that gives [#157](https://git.eeqj.de/sneak/AutistMask/issues/157) a permanent
|
||||||
|
floor. This does not discharge a real dApp with real funds against mainnet
|
||||||
|
([#183](https://git.eeqj.de/sneak/AutistMask/issues/183)).
|
||||||
|
- 2026-08-12: The known-symbol spoof rule now judges the symbol a user actually
|
||||||
|
sees. `isSpoofedSymbol()` normalizes before the lookup — NFKC, then every
|
||||||
|
character that paints nothing removed (the format and default-ignorable
|
||||||
|
characters, plus U+007F), then trimmed — so `" ETH "`, a no-break space, a
|
||||||
|
zero-width space, a Hangul filler, a variation selector, a DELETE and a
|
||||||
|
fullwidth `ETH` are all caught on the balance list, the history and the
|
||||||
|
send selector at once. Confusables that are distinct letters (Cyrillic `Е`),
|
||||||
|
bidi reordering and the visible C0/C1 controls — which measure 48.00px, a box,
|
||||||
|
in the pinned e2e Chromium where an invisible prefix measures 32.00px — stay
|
||||||
|
knowingly open and are asserted as open in the suite. No bundled symbol
|
||||||
|
contains whitespace or a non-ASCII character, so nothing legitimate is newly
|
||||||
|
filtered; the balance list's token-type gate also became case-insensitive,
|
||||||
|
which no longer drops a real holding if an explorer writes `erc-20`
|
||||||
|
([#260](https://git.eeqj.de/sneak/AutistMask/issues/260)).
|
||||||
- 2026-08-12: A containerized Firefox end-to-end harness
|
- 2026-08-12: A containerized Firefox end-to-end harness
|
||||||
(`make test-e2e-firefox`) drives the real popup in a real Firefox with the MV2
|
(`make test-e2e-firefox`) drives the real popup in a real Firefox with the MV2
|
||||||
build installed as a temporary add-on. Zero npm dependencies — a WebDriver
|
build installed as a temporary add-on. Zero npm dependencies — a WebDriver
|
||||||
|
|||||||
@@ -39,17 +39,21 @@ const {
|
|||||||
registerAlarmHandlers,
|
registerAlarmHandlers,
|
||||||
} = require("../shared/alarms");
|
} = require("../shared/alarms");
|
||||||
|
|
||||||
const storageApi =
|
const {
|
||||||
typeof browser !== "undefined"
|
actionApi,
|
||||||
? browser.storage.local
|
runtimeApi,
|
||||||
: chrome.storage.local;
|
storageGet,
|
||||||
const runtime =
|
tabsQuery,
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
tabsSendMessage,
|
||||||
const windowsApi =
|
windowsApi,
|
||||||
typeof browser !== "undefined" ? browser.windows : chrome.windows;
|
windowsCreate,
|
||||||
const tabsApi = typeof browser !== "undefined" ? browser.tabs : chrome.tabs;
|
windowsGetLastFocused,
|
||||||
const actionApi =
|
windowsRemove,
|
||||||
typeof browser !== "undefined" ? browser.browserAction : chrome.action;
|
} = require("../shared/browserApi");
|
||||||
|
|
||||||
|
const runtime = runtimeApi();
|
||||||
|
const windowsNs = windowsApi();
|
||||||
|
const actionNs = actionApi();
|
||||||
|
|
||||||
// Connected sites (in-memory, non-persisted): { "origin:address": true }
|
// Connected sites (in-memory, non-persisted): { "origin:address": true }
|
||||||
const connectedSites = {};
|
const connectedSites = {};
|
||||||
@@ -58,7 +62,7 @@ const connectedSites = {};
|
|||||||
const pendingApprovals = {};
|
const pendingApprovals = {};
|
||||||
|
|
||||||
async function getState() {
|
async function getState() {
|
||||||
const result = await storageApi.get("autistmask");
|
const result = await storageGet("autistmask");
|
||||||
return (
|
return (
|
||||||
result.autistmask || {
|
result.autistmask || {
|
||||||
wallets: [],
|
wallets: [],
|
||||||
@@ -122,8 +126,8 @@ async function proxyRpc(method, params) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function resetPopupUrl() {
|
function resetPopupUrl() {
|
||||||
if (actionApi && typeof actionApi.setPopup === "function") {
|
if (actionNs && typeof actionNs.setPopup === "function") {
|
||||||
actionApi.setPopup({ popup: "src/popup/index.html" });
|
actionNs.setPopup({ popup: "src/popup/index.html" });
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -179,12 +183,21 @@ function releaseApproval(approval) {
|
|||||||
// Open approval in a separate popup window.
|
// Open approval in a separate popup window.
|
||||||
// This is the primary mechanism for tx/sign approvals (triggered programmatically,
|
// This is the primary mechanism for tx/sign approvals (triggered programmatically,
|
||||||
// not from a user gesture) and the fallback for site-connection approvals.
|
// not from a user gesture) and the fallback for site-connection approvals.
|
||||||
function openApprovalWindow(id) {
|
// Never rejects. Its callers raise it from inside a Promise executor and drop
|
||||||
|
// the result on the floor, so a rejection here would be unhandled.
|
||||||
|
async function openApprovalWindow(id) {
|
||||||
const popupUrl = runtime.getURL("src/popup/index.html?approval=" + id);
|
const popupUrl = runtime.getURL("src/popup/index.html?approval=" + id);
|
||||||
const popupWidth = 360;
|
const popupWidth = 360;
|
||||||
const popupHeight = 600;
|
const popupHeight = 600;
|
||||||
|
|
||||||
windowsApi.getLastFocused((currentWin) => {
|
let currentWin = null;
|
||||||
|
try {
|
||||||
|
currentWin = await windowsGetLastFocused();
|
||||||
|
} catch {
|
||||||
|
// Nothing focused to centre on. The window still opens, at whatever
|
||||||
|
// position the browser picks.
|
||||||
|
}
|
||||||
|
|
||||||
const opts = {
|
const opts = {
|
||||||
url: popupUrl,
|
url: popupUrl,
|
||||||
type: "popup",
|
type: "popup",
|
||||||
@@ -199,12 +212,26 @@ function openApprovalWindow(id) {
|
|||||||
currentWin.top + (currentWin.height - popupHeight) / 2,
|
currentWin.top + (currentWin.height - popupHeight) / 2,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
windowsApi.create(opts, (win) => {
|
|
||||||
if (win) {
|
let win = null;
|
||||||
|
try {
|
||||||
|
win = await windowsCreate(opts);
|
||||||
|
} catch (e) {
|
||||||
|
// No window means no approval screen and no way for the user to
|
||||||
|
// answer. The request stays pending rather than being settled behind
|
||||||
|
// their back; say so rather than failing silently.
|
||||||
|
log.errorf("could not open the approval window:", e);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The id the onRemoved listener matches on to turn a closed window into a
|
||||||
|
// rejection. Guarded because the create() above is a real await now: an
|
||||||
|
// address switch can settle and remove the approval while the window is
|
||||||
|
// opening, and writing the id back would resurrect a bare entry that
|
||||||
|
// nothing would ever resolve.
|
||||||
|
if (win && pendingApprovals[id]) {
|
||||||
pendingApprovals[id].windowId = win.id;
|
pendingApprovals[id].windowId = win.id;
|
||||||
}
|
}
|
||||||
});
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Open an approval popup and return a promise that resolves with the user decision.
|
// Open an approval popup and return a promise that resolves with the user decision.
|
||||||
@@ -214,12 +241,12 @@ function requestApproval(origin, hostname) {
|
|||||||
const id = crypto.randomUUID();
|
const id = crypto.randomUUID();
|
||||||
pendingApprovals[id] = { origin, hostname, resolve };
|
pendingApprovals[id] = { origin, hostname, resolve };
|
||||||
|
|
||||||
if (actionApi && typeof actionApi.openPopup === "function") {
|
if (actionNs && typeof actionNs.openPopup === "function") {
|
||||||
actionApi.setPopup({
|
actionNs.setPopup({
|
||||||
popup: "src/popup/index.html?approval=" + id,
|
popup: "src/popup/index.html?approval=" + id,
|
||||||
});
|
});
|
||||||
try {
|
try {
|
||||||
const result = actionApi.openPopup();
|
const result = actionNs.openPopup();
|
||||||
if (result && typeof result.catch === "function") {
|
if (result && typeof result.catch === "function") {
|
||||||
result.catch(() => openApprovalWindow(id));
|
result.catch(() => openApprovalWindow(id));
|
||||||
}
|
}
|
||||||
@@ -281,7 +308,7 @@ function requestSignApproval(origin, hostname, signParams, approvedFrom) {
|
|||||||
|
|
||||||
// Detect when an approval popup (browser-action) closes without a response.
|
// Detect when an approval popup (browser-action) closes without a response.
|
||||||
// TX and sign approvals now use windows.create() and are handled by the
|
// TX and sign approvals now use windows.create() and are handled by the
|
||||||
// windowsApi.onRemoved listener below, but we still handle site-connection
|
// windows.onRemoved listener below, but we still handle site-connection
|
||||||
// approval disconnects here.
|
// approval disconnects here.
|
||||||
runtime.onConnect.addListener((port) => {
|
runtime.onConnect.addListener((port) => {
|
||||||
if (port.name.startsWith("approval:")) {
|
if (port.name.startsWith("approval:")) {
|
||||||
@@ -663,24 +690,26 @@ async function handleRpc(method, params, origin) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Broadcast chainChanged to all tabs when the network is switched.
|
// Broadcast chainChanged to all tabs when the network is switched.
|
||||||
function broadcastChainChanged(chainId) {
|
//
|
||||||
tabsApi.query({}, (tabs) => {
|
// Never rejects: its caller is an RPC handler that must answer the page
|
||||||
|
// whatever the browser made of the broadcast.
|
||||||
|
async function broadcastChainChanged(chainId) {
|
||||||
|
let tabs;
|
||||||
|
try {
|
||||||
|
tabs = await tabsQuery({});
|
||||||
|
} catch {
|
||||||
|
return;
|
||||||
|
}
|
||||||
for (const tab of tabs) {
|
for (const tab of tabs) {
|
||||||
tabsApi.sendMessage(
|
// A tab with no content script has no receiver, and that is the
|
||||||
tab.id,
|
// ordinary case rather than a fault. The rejection it produces is the
|
||||||
{
|
// promise-shaped form of the runtime.lastError this used to read.
|
||||||
|
tabsSendMessage(tab.id, {
|
||||||
type: "AUTISTMASK_EVENT",
|
type: "AUTISTMASK_EVENT",
|
||||||
eventName: "chainChanged",
|
eventName: "chainChanged",
|
||||||
data: chainId,
|
data: chainId,
|
||||||
},
|
}).catch(() => {});
|
||||||
() => {
|
|
||||||
if (runtime.lastError) {
|
|
||||||
// expected for tabs without our content script
|
|
||||||
}
|
}
|
||||||
},
|
|
||||||
);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Broadcast accountsChanged to all tabs, respecting per-address permissions
|
// Broadcast accountsChanged to all tabs, respecting per-address permissions
|
||||||
@@ -705,18 +734,21 @@ async function broadcastAccountsChanged() {
|
|||||||
: { approved: false, remember: false };
|
: { approved: false, remember: false };
|
||||||
if (!settleApproval(id, rejection)) continue;
|
if (!settleApproval(id, rejection)) continue;
|
||||||
if (approval.windowId) {
|
if (approval.windowId) {
|
||||||
windowsApi.remove(approval.windowId, () => {
|
// Rejects when the window has already gone, which is a race the
|
||||||
if (runtime.lastError) {
|
// user wins routinely by closing it themselves.
|
||||||
// window already closed
|
windowsRemove(approval.windowId).catch(() => {});
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
resetPopupUrl();
|
resetPopupUrl();
|
||||||
const s = await getState();
|
const s = await getState();
|
||||||
const activeAddress = await getActiveAddress();
|
const activeAddress = await getActiveAddress();
|
||||||
const allowed = activeAddress ? s.allowedSites[activeAddress] || [] : [];
|
const allowed = activeAddress ? s.allowedSites[activeAddress] || [] : [];
|
||||||
tabsApi.query({}, (tabs) => {
|
let tabs;
|
||||||
|
try {
|
||||||
|
tabs = await tabsQuery({});
|
||||||
|
} catch {
|
||||||
|
return;
|
||||||
|
}
|
||||||
for (const tab of tabs) {
|
for (const tab of tabs) {
|
||||||
const origin = tab.url ? new URL(tab.url).origin : "";
|
const origin = tab.url ? new URL(tab.url).origin : "";
|
||||||
const hostname = extractHostname(origin);
|
const hostname = extractHostname(origin);
|
||||||
@@ -724,22 +756,14 @@ async function broadcastAccountsChanged() {
|
|||||||
activeAddress &&
|
activeAddress &&
|
||||||
(allowed.includes(hostname) ||
|
(allowed.includes(hostname) ||
|
||||||
connectedSites[origin + ":" + activeAddress]);
|
connectedSites[origin + ":" + activeAddress]);
|
||||||
tabsApi.sendMessage(
|
// Same as chainChanged above: a tab without our content script
|
||||||
tab.id,
|
// rejects, and that is expected rather than a fault.
|
||||||
{
|
tabsSendMessage(tab.id, {
|
||||||
type: "AUTISTMASK_EVENT",
|
type: "AUTISTMASK_EVENT",
|
||||||
eventName: "accountsChanged",
|
eventName: "accountsChanged",
|
||||||
data: hasPermission ? [activeAddress] : [],
|
data: hasPermission ? [activeAddress] : [],
|
||||||
},
|
}).catch(() => {});
|
||||||
() => {
|
|
||||||
// Ignore errors for tabs without content script
|
|
||||||
if (runtime.lastError) {
|
|
||||||
// expected for tabs without our content script
|
|
||||||
}
|
}
|
||||||
},
|
|
||||||
);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Background balance refresh: every 60 seconds when the popup isn't open.
|
// Background balance refresh: every 60 seconds when the popup isn't open.
|
||||||
@@ -832,8 +856,8 @@ startBackgroundJobs();
|
|||||||
// window is an ordinary event with an attempt already in flight behind it.
|
// window is an ordinary event with an attempt already in flight behind it.
|
||||||
// settleApproval() refuses those, which leaves the attempt to report its real
|
// settleApproval() refuses those, which leaves the attempt to report its real
|
||||||
// outcome to the page.
|
// outcome to the page.
|
||||||
if (windowsApi && windowsApi.onRemoved) {
|
if (windowsNs && windowsNs.onRemoved) {
|
||||||
windowsApi.onRemoved.addListener((windowId) => {
|
windowsNs.onRemoved.addListener((windowId) => {
|
||||||
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
||||||
if (approval.windowId !== windowId) continue;
|
if (approval.windowId !== windowId) continue;
|
||||||
const rejection =
|
const rejection =
|
||||||
|
|||||||
@@ -1,12 +1,20 @@
|
|||||||
// AutistMask content script — bridges between inpage (window.ethereum)
|
// AutistMask content script — bridges between inpage (window.ethereum)
|
||||||
// and the background service worker via extension messaging.
|
// and the background service worker via extension messaging.
|
||||||
|
|
||||||
|
const {
|
||||||
|
hasBrowserNamespace,
|
||||||
|
runtimeApi,
|
||||||
|
sendMessage,
|
||||||
|
storageGet,
|
||||||
|
storageSet,
|
||||||
|
} = require("../shared/browserApi");
|
||||||
|
|
||||||
// In Chrome (MV3), inpage.js runs as a MAIN-world content script declared
|
// In Chrome (MV3), inpage.js runs as a MAIN-world content script declared
|
||||||
// in the manifest, so no injection is needed here. In Firefox (MV2), the
|
// in the manifest, so no injection is needed here. In Firefox (MV2), the
|
||||||
// "world" key is not supported, so we inject via a <script> tag.
|
// "world" key is not supported, so we inject via a <script> tag.
|
||||||
if (typeof browser !== "undefined") {
|
if (hasBrowserNamespace()) {
|
||||||
const script = document.createElement("script");
|
const script = document.createElement("script");
|
||||||
script.src = browser.runtime.getURL("src/content/inpage.js");
|
script.src = runtimeApi().getURL("src/content/inpage.js");
|
||||||
script.onload = function () {
|
script.onload = function () {
|
||||||
this.remove();
|
this.remove();
|
||||||
};
|
};
|
||||||
@@ -14,23 +22,27 @@ if (typeof browser !== "undefined") {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Send the persisted EIP-6963 provider UUID to the inpage script.
|
// Send the persisted EIP-6963 provider UUID to the inpage script.
|
||||||
// Generated once at install time and stored in chrome.storage.local.
|
// Generated once at install time and stored in extension storage.
|
||||||
(function sendProviderUuid() {
|
(async function sendProviderUuid() {
|
||||||
const storage =
|
let uuid = null;
|
||||||
typeof browser !== "undefined"
|
try {
|
||||||
? browser.storage.local
|
const items = await storageGet("eip6963Uuid");
|
||||||
: chrome.storage.local;
|
uuid = items?.eip6963Uuid;
|
||||||
storage.get("eip6963Uuid", (items) => {
|
|
||||||
let uuid = items?.eip6963Uuid;
|
|
||||||
if (!uuid) {
|
if (!uuid) {
|
||||||
uuid = crypto.randomUUID();
|
uuid = crypto.randomUUID();
|
||||||
storage.set({ eip6963Uuid: uuid });
|
await storageSet({ eip6963Uuid: uuid });
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// Storage was unavailable or refused the write. The announcement
|
||||||
|
// still has to go out — a provider that never announces is invisible
|
||||||
|
// to every EIP-6963 dApp — so it goes under a fresh uuid that this
|
||||||
|
// page load will not outlive.
|
||||||
|
if (!uuid) uuid = crypto.randomUUID();
|
||||||
}
|
}
|
||||||
window.postMessage(
|
window.postMessage(
|
||||||
{ type: "AUTISTMASK_PROVIDER_UUID", uuid },
|
{ type: "AUTISTMASK_PROVIDER_UUID", uuid },
|
||||||
location.origin,
|
location.origin,
|
||||||
);
|
);
|
||||||
});
|
|
||||||
})();
|
})();
|
||||||
|
|
||||||
// Relay requests from the page to the background script
|
// Relay requests from the page to the background script
|
||||||
@@ -39,27 +51,31 @@ window.addEventListener("message", (event) => {
|
|||||||
if (event.data?.type !== "AUTISTMASK_REQUEST") return;
|
if (event.data?.type !== "AUTISTMASK_REQUEST") return;
|
||||||
const { id, method, params } = event.data;
|
const { id, method, params } = event.data;
|
||||||
|
|
||||||
const runtime =
|
sendMessage({
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
type: "AUTISTMASK_RPC",
|
||||||
|
id,
|
||||||
runtime.sendMessage(
|
method,
|
||||||
{ type: "AUTISTMASK_RPC", id, method, params, origin: location.origin },
|
params,
|
||||||
(response) => {
|
origin: location.origin,
|
||||||
|
})
|
||||||
|
.then((response) => {
|
||||||
if (response) {
|
if (response) {
|
||||||
window.postMessage(
|
window.postMessage(
|
||||||
{ type: "AUTISTMASK_RESPONSE", id, ...response },
|
{ type: "AUTISTMASK_RESPONSE", id, ...response },
|
||||||
"*",
|
"*",
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
},
|
})
|
||||||
);
|
.catch(() => {
|
||||||
|
// No receiver: the background context is gone. The page's promise
|
||||||
|
// stays pending, which is what it did before this was a promise
|
||||||
|
// at all; turning it into a rejection here is a change to what
|
||||||
|
// dApps see and belongs to its own issue.
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
// Listen for events pushed from the background (e.g. accountsChanged)
|
// Listen for events pushed from the background (e.g. accountsChanged)
|
||||||
const runtime =
|
runtimeApi().onMessage.addListener((msg) => {
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
|
||||||
|
|
||||||
runtime.onMessage.addListener((msg) => {
|
|
||||||
if (msg.type === "AUTISTMASK_EVENT") {
|
if (msg.type === "AUTISTMASK_EVENT") {
|
||||||
window.postMessage(
|
window.postMessage(
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -11,6 +11,39 @@
|
|||||||
let nextId = 1;
|
let nextId = 1;
|
||||||
const pending = {};
|
const pending = {};
|
||||||
|
|
||||||
|
// EIP-1193 ProviderRpcError: `code`, `message`, optional `data`. A class
|
||||||
|
// rather than properties bolted onto an Error because this object crosses
|
||||||
|
// no boundary after construction — it is built in the page's own realm and
|
||||||
|
// handed straight to the caller's catch — so the prototype survives and
|
||||||
|
// `error.name` is a stable thing for a dApp to see.
|
||||||
|
class ProviderRpcError extends Error {
|
||||||
|
constructor(code, message, data) {
|
||||||
|
super(message);
|
||||||
|
this.name = "ProviderRpcError";
|
||||||
|
this.code = code;
|
||||||
|
if (data !== undefined) this.data = data;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Rebuild a boundary error as the error the page catches, carrying the
|
||||||
|
// code (and data) the extension reported. Without this a dApp cannot tell
|
||||||
|
// a user's refusal (4001) from a wallet that broke, and retries or shows
|
||||||
|
// an error instead of accepting the refusal.
|
||||||
|
//
|
||||||
|
// Whatever code arrived is passed through verbatim rather than being
|
||||||
|
// matched against a list: the extension emits 4001, 4100 and 4902 today,
|
||||||
|
// and a code this file has never heard of is still the truth about what
|
||||||
|
// happened. An error reported with no code at all stays a plain Error —
|
||||||
|
// a ProviderRpcError whose `code` is undefined would advertise a
|
||||||
|
// conformance it does not have. `message` is untouched in every case.
|
||||||
|
function toPageError(error) {
|
||||||
|
const message = (error && error.message) || "Request failed";
|
||||||
|
if (error && error.code !== undefined && error.code !== null) {
|
||||||
|
return new ProviderRpcError(error.code, message, error.data);
|
||||||
|
}
|
||||||
|
return new Error(message);
|
||||||
|
}
|
||||||
|
|
||||||
// Listen for responses from the content script
|
// Listen for responses from the content script
|
||||||
window.addEventListener("message", function onUuid(event) {
|
window.addEventListener("message", function onUuid(event) {
|
||||||
if (event.source !== window) return;
|
if (event.source !== window) return;
|
||||||
@@ -20,7 +53,7 @@
|
|||||||
if (!p) return;
|
if (!p) return;
|
||||||
delete pending[id];
|
delete pending[id];
|
||||||
if (error) {
|
if (error) {
|
||||||
p.reject(new Error(error.message || "Request failed"));
|
p.reject(toPageError(error));
|
||||||
} else {
|
} else {
|
||||||
p.resolve(result);
|
p.resolve(result);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -27,8 +27,7 @@ const { walletDefect } = require("../../shared/walletDefects");
|
|||||||
const { describeSigningFailure } = require("../../shared/approvalVerify");
|
const { describeSigningFailure } = require("../../shared/approvalVerify");
|
||||||
const txStatus = require("./txStatus");
|
const txStatus = require("./txStatus");
|
||||||
const uniswap = require("../../shared/uniswap");
|
const uniswap = require("../../shared/uniswap");
|
||||||
const runtime =
|
const { notify, runtimeApi, sendMessage } = require("../../shared/browserApi");
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
|
||||||
|
|
||||||
const erc20Iface = new Interface(ERC20_ABI);
|
const erc20Iface = new Interface(ERC20_ABI);
|
||||||
|
|
||||||
@@ -439,10 +438,20 @@ function showSignApproval(details) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
function show(id) {
|
// Awaited by nobody: the popup entry point calls this and moves on. It
|
||||||
|
// therefore has to absorb its own failure, and a background that cannot
|
||||||
|
// describe the approval is the same outcome as an approval that is gone.
|
||||||
|
async function show(id) {
|
||||||
approvalId = id;
|
approvalId = id;
|
||||||
runtime.connect({ name: "approval:" + id });
|
runtimeApi().connect({ name: "approval:" + id });
|
||||||
runtime.sendMessage({ type: "AUTISTMASK_GET_APPROVAL", id }, (details) => {
|
|
||||||
|
let details = null;
|
||||||
|
try {
|
||||||
|
details = await sendMessage({ type: "AUTISTMASK_GET_APPROVAL", id });
|
||||||
|
} catch {
|
||||||
|
details = null;
|
||||||
|
}
|
||||||
|
|
||||||
if (!details) {
|
if (!details) {
|
||||||
window.close();
|
window.close();
|
||||||
return;
|
return;
|
||||||
@@ -461,12 +470,9 @@ function show(id) {
|
|||||||
details.isPhishingDomain,
|
details.isPhishingDomain,
|
||||||
);
|
);
|
||||||
$("approve-hostname").textContent = details.hostname;
|
$("approve-hostname").textContent = details.hostname;
|
||||||
$("approve-address").innerHTML = approvalAddressHtml(
|
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
||||||
state.activeAddress,
|
|
||||||
);
|
|
||||||
attachCopyHandlers("view-approve-site");
|
attachCopyHandlers("view-approve-site");
|
||||||
$("approve-remember").checked = state.rememberSiteChoice;
|
$("approve-remember").checked = state.rememberSiteChoice;
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
let approvalId = null;
|
let approvalId = null;
|
||||||
@@ -548,7 +554,7 @@ function init(ctx) {
|
|||||||
|
|
||||||
$("btn-approve").addEventListener("click", () => {
|
$("btn-approve").addEventListener("click", () => {
|
||||||
const remember = $("approve-remember").checked;
|
const remember = $("approve-remember").checked;
|
||||||
runtime.sendMessage({
|
notify({
|
||||||
type: "AUTISTMASK_APPROVAL_RESPONSE",
|
type: "AUTISTMASK_APPROVAL_RESPONSE",
|
||||||
id: approvalId,
|
id: approvalId,
|
||||||
approved: true,
|
approved: true,
|
||||||
@@ -559,7 +565,7 @@ function init(ctx) {
|
|||||||
|
|
||||||
$("btn-reject").addEventListener("click", () => {
|
$("btn-reject").addEventListener("click", () => {
|
||||||
const remember = $("approve-remember").checked;
|
const remember = $("approve-remember").checked;
|
||||||
runtime.sendMessage({
|
notify({
|
||||||
type: "AUTISTMASK_APPROVAL_RESPONSE",
|
type: "AUTISTMASK_APPROVAL_RESPONSE",
|
||||||
id: approvalId,
|
id: approvalId,
|
||||||
approved: false,
|
approved: false,
|
||||||
@@ -648,7 +654,16 @@ function init(ctx) {
|
|||||||
decryptedSecret = null;
|
decryptedSecret = null;
|
||||||
}
|
}
|
||||||
|
|
||||||
runtime.sendMessage(payload, (response) => {
|
// A send that never reaches the background is reported to the user
|
||||||
|
// the same way a background that refused it is: describeSigningFailure
|
||||||
|
// turns a null response into the generic message below.
|
||||||
|
let response = null;
|
||||||
|
try {
|
||||||
|
response = await sendMessage(payload);
|
||||||
|
} catch {
|
||||||
|
response = null;
|
||||||
|
}
|
||||||
|
|
||||||
if (response && response.txHash) {
|
if (response && response.txHash) {
|
||||||
txStatus.showWait(pendingTxDetails, response.txHash);
|
txStatus.showWait(pendingTxDetails, response.txHash);
|
||||||
return;
|
return;
|
||||||
@@ -667,10 +682,9 @@ function init(ctx) {
|
|||||||
txStatus.showError(pendingTxDetails, null, outcome.message);
|
txStatus.showError(pendingTxDetails, null, outcome.message);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-reject-tx").addEventListener("click", () => {
|
$("btn-reject-tx").addEventListener("click", () => {
|
||||||
runtime.sendMessage({
|
notify({
|
||||||
type: "AUTISTMASK_TX_RESPONSE",
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
id: approvalId,
|
id: approvalId,
|
||||||
approved: false,
|
approved: false,
|
||||||
@@ -764,7 +778,13 @@ function init(ctx) {
|
|||||||
decryptedSecret = null;
|
decryptedSecret = null;
|
||||||
}
|
}
|
||||||
|
|
||||||
runtime.sendMessage(payload, (response) => {
|
let response = null;
|
||||||
|
try {
|
||||||
|
response = await sendMessage(payload);
|
||||||
|
} catch {
|
||||||
|
response = null;
|
||||||
|
}
|
||||||
|
|
||||||
if (response && response.signature) {
|
if (response && response.signature) {
|
||||||
window.close();
|
window.close();
|
||||||
return;
|
return;
|
||||||
@@ -780,10 +800,9 @@ function init(ctx) {
|
|||||||
showError("approve-sign-error", outcome.message);
|
showError("approve-sign-error", outcome.message);
|
||||||
if (outcome.retryable) setSignButtonBusy(false);
|
if (outcome.retryable) setSignButtonBusy(false);
|
||||||
});
|
});
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-reject-sign").addEventListener("click", () => {
|
$("btn-reject-sign").addEventListener("click", () => {
|
||||||
runtime.sendMessage({
|
notify({
|
||||||
type: "AUTISTMASK_SIGN_RESPONSE",
|
type: "AUTISTMASK_SIGN_RESPONSE",
|
||||||
id: approvalId,
|
id: approvalId,
|
||||||
approved: false,
|
approved: false,
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ const {
|
|||||||
pushCurrentView,
|
pushCurrentView,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, saveState, currentAddress } = require("../../shared/state");
|
const { state, saveState, currentAddress } = require("../../shared/state");
|
||||||
|
const { notify } = require("../../shared/browserApi");
|
||||||
const {
|
const {
|
||||||
updateSendBalance,
|
updateSendBalance,
|
||||||
renderSendTokenSelect,
|
renderSendTokenSelect,
|
||||||
@@ -293,11 +294,7 @@ function render(ctx) {
|
|||||||
state.activeAddress = addr;
|
state.activeAddress = addr;
|
||||||
await saveState();
|
await saveState();
|
||||||
render(ctx);
|
render(ctx);
|
||||||
const runtime =
|
notify({ type: "AUTISTMASK_ACTIVE_CHANGED" });
|
||||||
typeof browser !== "undefined"
|
|
||||||
? browser.runtime
|
|
||||||
: chrome.runtime;
|
|
||||||
runtime.sendMessage({ type: "AUTISTMASK_ACTIVE_CHANGED" });
|
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -29,8 +29,7 @@ const {
|
|||||||
GITEA_COMMIT_URL,
|
GITEA_COMMIT_URL,
|
||||||
} = require("../../shared/buildInfo");
|
} = require("../../shared/buildInfo");
|
||||||
|
|
||||||
const runtime =
|
const { notify } = require("../../shared/browserApi");
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
|
||||||
|
|
||||||
let versionClickCount = 0;
|
let versionClickCount = 0;
|
||||||
let versionClickTimer = null;
|
let versionClickTimer = null;
|
||||||
@@ -61,7 +60,7 @@ function renderSiteList(containerId, siteMap, stateKey) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
await saveState();
|
await saveState();
|
||||||
runtime.sendMessage({ type: "AUTISTMASK_REMOVE_SITE" });
|
notify({ type: "AUTISTMASK_REMOVE_SITE" });
|
||||||
renderSiteList(containerId, state[key], key);
|
renderSiteList(containerId, state[key], key);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -19,6 +19,8 @@
|
|||||||
// be bypassed on the scheduled tick — see backgroundRefresh() in
|
// be bypassed on the scheduled tick — see backgroundRefresh() in
|
||||||
// src/background/index.js and updatePhishingList() in shared/phishingDomains.js.
|
// src/background/index.js and updatePhishingList() in shared/phishingDomains.js.
|
||||||
|
|
||||||
|
const { alarmsApi } = require("./browserApi");
|
||||||
|
|
||||||
const BALANCE_REFRESH_ALARM = "autistmask-balance-refresh";
|
const BALANCE_REFRESH_ALARM = "autistmask-balance-refresh";
|
||||||
const PHISHING_REFRESH_ALARM = "autistmask-phishing-refresh";
|
const PHISHING_REFRESH_ALARM = "autistmask-phishing-refresh";
|
||||||
|
|
||||||
@@ -26,14 +28,10 @@ const MIN_ALARM_PERIOD_MINUTES = 1;
|
|||||||
const BALANCE_REFRESH_PERIOD_MINUTES = 1;
|
const BALANCE_REFRESH_PERIOD_MINUTES = 1;
|
||||||
const PHISHING_REFRESH_PERIOD_MINUTES = 24 * 60;
|
const PHISHING_REFRESH_PERIOD_MINUTES = 24 * 60;
|
||||||
|
|
||||||
// Resolved on use rather than captured at module load: the worker is torn
|
// alarmsApi() resolves on use rather than at module load: the worker is torn
|
||||||
// down and re-evaluated repeatedly, and tests install a stub after requiring
|
// down and re-evaluated repeatedly, and tests install a stub after requiring
|
||||||
// the module.
|
// this module. It returns null where the API is absent, which is why every
|
||||||
function alarmsApi() {
|
// entry point below degrades instead of throwing.
|
||||||
if (typeof browser !== "undefined" && browser.alarms) return browser.alarms;
|
|
||||||
if (typeof chrome !== "undefined" && chrome.alarms) return chrome.alarms;
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create an alarm unless one with the requested period already exists.
|
* Create an alarm unless one with the requested period already exists.
|
||||||
|
|||||||
@@ -66,7 +66,12 @@ async function fetchTokenBalances(address, blockscoutUrl, trackedTokens) {
|
|||||||
|
|
||||||
const balances = [];
|
const balances = [];
|
||||||
for (const item of items) {
|
for (const item of items) {
|
||||||
if (item.token?.type !== "ERC-20") continue;
|
// Case-insensitive: the token type is an explorer's label, not a
|
||||||
|
// protocol value, and an exact comparison silently drops a real
|
||||||
|
// holding if one ever writes "erc-20". Which types are admitted
|
||||||
|
// is unchanged.
|
||||||
|
const type = String(item.token?.type || "").toUpperCase();
|
||||||
|
if (type !== "ERC-20") continue;
|
||||||
const decimals = parseInt(item.token.decimals || "18", 10);
|
const decimals = parseInt(item.token.decimals || "18", 10);
|
||||||
const bal = formatTokenBalance(item.value || "0", decimals);
|
const bal = formatTokenBalance(item.value || "0", decimals);
|
||||||
if (bal === "0.0") continue;
|
if (bal === "0.0") continue;
|
||||||
|
|||||||
245
src/shared/browserApi.js
Normal file
245
src/shared/browserApi.js
Normal file
@@ -0,0 +1,245 @@
|
|||||||
|
// The one place in this tree that names `browser` or `chrome`.
|
||||||
|
//
|
||||||
|
// The two targets do not agree on either the namespace or the call shape.
|
||||||
|
// Chrome MV3 exposes `chrome.*`, where tabs, windows and messaging take a
|
||||||
|
// trailing callback and report failure through the global
|
||||||
|
// `chrome.runtime.lastError`. Firefox MV2 exposes `browser.*`, where those
|
||||||
|
// same methods return promises and take no callback at all — a function
|
||||||
|
// passed where an options argument is expected is simply never invoked, so
|
||||||
|
// the call looks like it succeeded and silently never completes. Resolving
|
||||||
|
// the namespace with a ternary and then calling it Chrome-style, which is
|
||||||
|
// what this codebase used to do, is broken on Firefox in exactly that way:
|
||||||
|
// see https://git.eeqj.de/sneak/AutistMask/issues/153.
|
||||||
|
//
|
||||||
|
// The strategy is promises out, everywhere. Callers `await`; nothing outside
|
||||||
|
// this file has to know which browser it is running on.
|
||||||
|
//
|
||||||
|
// Two deliberate asymmetries, because they are what the browsers actually do
|
||||||
|
// rather than what a uniform-looking shim would pretend:
|
||||||
|
//
|
||||||
|
// - Storage is called in its PROMISE form on both namespaces.
|
||||||
|
// `chrome.storage.local.get()` returns a promise on MV3 and the popup
|
||||||
|
// already depends on that — src/shared/state.js has always awaited it, and
|
||||||
|
// that is precisely why the Firefox popup flows work today while
|
||||||
|
// everything in the issue above does not. Wrapping it in a callback here
|
||||||
|
// would be a change, not a fix.
|
||||||
|
// - notify() sends without a callback. It is for a message whose answer
|
||||||
|
// nobody reads; appending a callback would only manufacture a
|
||||||
|
// lastError/rejection for a receiver that was never expected to reply.
|
||||||
|
//
|
||||||
|
// Everything is resolved on use rather than captured at module load. The MV3
|
||||||
|
// service worker is torn down and re-evaluated repeatedly, and the unit
|
||||||
|
// suite installs its stubs on `global.chrome` around a require().
|
||||||
|
|
||||||
|
// The extension API namespace, preferring `browser.*` where it exists.
|
||||||
|
//
|
||||||
|
// Whole-namespace, never per-method: mixing `browser.tabs` with
|
||||||
|
// `chrome.windows` would also mix promise and callback semantics inside a
|
||||||
|
// single call path, which is the bug this module exists to remove.
|
||||||
|
function extensionApi() {
|
||||||
|
if (typeof browser !== "undefined" && browser) return browser;
|
||||||
|
if (typeof chrome !== "undefined" && chrome) return chrome;
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// True when the resolved namespace is the promise-flavoured one.
|
||||||
|
//
|
||||||
|
// It doubles as "this is the Gecko/MV2 build", which is a second question
|
||||||
|
// with the same answer and one real caller: src/content/index.js has to
|
||||||
|
// inject the inpage provider itself there, because MV2 has no
|
||||||
|
// `"world": "MAIN"` for a manifest-declared content script.
|
||||||
|
function hasBrowserNamespace() {
|
||||||
|
return typeof browser !== "undefined" && !!browser;
|
||||||
|
}
|
||||||
|
|
||||||
|
function namespaceMember(name) {
|
||||||
|
const api = extensionApi();
|
||||||
|
return (api && api[name]) || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
function runtimeApi() {
|
||||||
|
return namespaceMember("runtime");
|
||||||
|
}
|
||||||
|
|
||||||
|
function tabsApi() {
|
||||||
|
return namespaceMember("tabs");
|
||||||
|
}
|
||||||
|
|
||||||
|
function windowsApi() {
|
||||||
|
return namespaceMember("windows");
|
||||||
|
}
|
||||||
|
|
||||||
|
function alarmsApi() {
|
||||||
|
return namespaceMember("alarms");
|
||||||
|
}
|
||||||
|
|
||||||
|
// The toolbar button. MV3 calls it `action`, MV2 calls it `browserAction`.
|
||||||
|
function actionApi() {
|
||||||
|
const api = extensionApi();
|
||||||
|
if (!api) return null;
|
||||||
|
return api.action || api.browserAction || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// `storage.local`, or null in a context that has no storage permission. Null
|
||||||
|
// rather than a throw because two callers degrade rather than fail on it.
|
||||||
|
function storageLocal() {
|
||||||
|
const storage = namespaceMember("storage");
|
||||||
|
return (storage && storage.local) || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The Chrome-only error channel. Never populated for a `browser.*` call,
|
||||||
|
// which is why the checks that used to guard callbacks in the background are
|
||||||
|
// gone: on this side it becomes a rejection, and on the other side there was
|
||||||
|
// never anything to read.
|
||||||
|
function lastError() {
|
||||||
|
const runtime = runtimeApi();
|
||||||
|
return (runtime && runtime.lastError) || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Call `owner[method](...args)` and return a promise for its result.
|
||||||
|
//
|
||||||
|
// On the promise namespace the method already returns one. On the callback
|
||||||
|
// namespace the callback is appended here and lastError becomes a rejection,
|
||||||
|
// because a caller holding a promise has nowhere to check a global flag.
|
||||||
|
function invoke(owner, method, ...args) {
|
||||||
|
if (!owner || typeof owner[method] !== "function") {
|
||||||
|
return Promise.reject(
|
||||||
|
new Error(
|
||||||
|
"extension API " +
|
||||||
|
method +
|
||||||
|
"() is not available in this context",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (hasBrowserNamespace()) {
|
||||||
|
try {
|
||||||
|
return Promise.resolve(owner[method](...args));
|
||||||
|
} catch (e) {
|
||||||
|
return Promise.reject(e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return new Promise((resolve, reject) => {
|
||||||
|
owner[method](...args, (result) => {
|
||||||
|
const err = lastError();
|
||||||
|
if (err) reject(new Error(err.message || String(err)));
|
||||||
|
else resolve(result);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Send a message to the extension's own contexts and resolve with the reply.
|
||||||
|
*
|
||||||
|
* Rejects when nothing is listening, on both browsers. A caller that does not
|
||||||
|
* care must say so — see notify().
|
||||||
|
*
|
||||||
|
* @param {Object} message
|
||||||
|
* @returns {Promise<*>} the receiver's response.
|
||||||
|
*/
|
||||||
|
function sendMessage(message) {
|
||||||
|
return invoke(runtimeApi(), "sendMessage", message);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Send a message nobody is expected to answer, and swallow the fact that
|
||||||
|
* nobody did.
|
||||||
|
*
|
||||||
|
* @param {Object} message
|
||||||
|
* @returns {void}
|
||||||
|
*/
|
||||||
|
function notify(message) {
|
||||||
|
const runtime = runtimeApi();
|
||||||
|
if (!runtime || typeof runtime.sendMessage !== "function") return;
|
||||||
|
const result = runtime.sendMessage(message);
|
||||||
|
// MV3 hands back a promise for a one-argument send, and it rejects when
|
||||||
|
// the background is not listening. Unhandled, that surfaces as an error
|
||||||
|
// the e2e suites fail the run on.
|
||||||
|
if (result && typeof result.catch === "function") result.catch(() => {});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {string|string[]|Object} keys
|
||||||
|
* @returns {Promise<Object>} the stored items, or {} where storage is absent.
|
||||||
|
*/
|
||||||
|
function storageGet(keys) {
|
||||||
|
const storage = storageLocal();
|
||||||
|
if (!storage) return Promise.resolve({});
|
||||||
|
return Promise.resolve(storage.get(keys));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Object} items
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
function storageSet(items) {
|
||||||
|
const storage = storageLocal();
|
||||||
|
if (!storage) return Promise.resolve();
|
||||||
|
return Promise.resolve(storage.set(items));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Object} queryInfo
|
||||||
|
* @returns {Promise<Array>} the matching tabs.
|
||||||
|
*/
|
||||||
|
function tabsQuery(queryInfo) {
|
||||||
|
return invoke(tabsApi(), "query", queryInfo);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Send a message to one tab's content script.
|
||||||
|
*
|
||||||
|
* Rejects for a tab that has no receiver, which is most of them. That
|
||||||
|
* rejection is the promise-shaped replacement for the runtime.lastError
|
||||||
|
* checks the broadcast helpers used to make, and callers ignore it the same
|
||||||
|
* way.
|
||||||
|
*
|
||||||
|
* @param {number} tabId
|
||||||
|
* @param {Object} message
|
||||||
|
* @returns {Promise<*>}
|
||||||
|
*/
|
||||||
|
function tabsSendMessage(tabId, message) {
|
||||||
|
return invoke(tabsApi(), "sendMessage", tabId, message);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Object} createData
|
||||||
|
* @returns {Promise<Object>} the created window.
|
||||||
|
*/
|
||||||
|
function windowsCreate(createData) {
|
||||||
|
return invoke(windowsApi(), "create", createData);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @returns {Promise<Object>} the last focused window.
|
||||||
|
*/
|
||||||
|
function windowsGetLastFocused() {
|
||||||
|
return invoke(windowsApi(), "getLastFocused");
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {number} windowId
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
function windowsRemove(windowId) {
|
||||||
|
return invoke(windowsApi(), "remove", windowId);
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
actionApi,
|
||||||
|
alarmsApi,
|
||||||
|
extensionApi,
|
||||||
|
hasBrowserNamespace,
|
||||||
|
notify,
|
||||||
|
runtimeApi,
|
||||||
|
sendMessage,
|
||||||
|
storageGet,
|
||||||
|
storageLocal,
|
||||||
|
storageSet,
|
||||||
|
tabsApi,
|
||||||
|
tabsQuery,
|
||||||
|
tabsSendMessage,
|
||||||
|
windowsApi,
|
||||||
|
windowsCreate,
|
||||||
|
windowsGetLastFocused,
|
||||||
|
windowsRemove,
|
||||||
|
};
|
||||||
@@ -18,6 +18,7 @@
|
|||||||
// its own refresh — see updatePhishingList().
|
// its own refresh — see updatePhishingList().
|
||||||
|
|
||||||
const vendoredConfig = require("./phishingBlocklist.json");
|
const vendoredConfig = require("./phishingBlocklist.json");
|
||||||
|
const { storageLocal } = require("./browserApi");
|
||||||
|
|
||||||
const BLOCKLIST_URL =
|
const BLOCKLIST_URL =
|
||||||
"https://raw.githubusercontent.com/MetaMask/eth-phishing-detect/main/src/config.json";
|
"https://raw.githubusercontent.com/MetaMask/eth-phishing-detect/main/src/config.json";
|
||||||
@@ -46,18 +47,10 @@ let lastAttemptTime = 0;
|
|||||||
let fetchPromise = null;
|
let fetchPromise = null;
|
||||||
let loadPromise = null;
|
let loadPromise = null;
|
||||||
|
|
||||||
// Resolved on use rather than captured at module load, so a test can install
|
// storageLocal() resolves on use rather than at module load, so a test can
|
||||||
// a stub after requiring the module and so the popup — which has no reason to
|
// install a stub after requiring this module, and it returns null where the
|
||||||
// touch the delta — does not fail to load where the API is absent.
|
// API is absent — which is why the popup, with no reason to touch the delta,
|
||||||
function storageApi() {
|
// loads fine without it.
|
||||||
if (typeof browser !== "undefined" && browser.storage) {
|
|
||||||
return browser.storage.local;
|
|
||||||
}
|
|
||||||
if (typeof chrome !== "undefined" && chrome.storage) {
|
|
||||||
return chrome.storage.local;
|
|
||||||
}
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Sanitise a timestamp read back from storage.
|
* Sanitise a timestamp read back from storage.
|
||||||
@@ -86,7 +79,7 @@ function sanitizeTimestamp(value) {
|
|||||||
* @returns {Promise<void>}
|
* @returns {Promise<void>}
|
||||||
*/
|
*/
|
||||||
async function loadDeltaFromStorage() {
|
async function loadDeltaFromStorage() {
|
||||||
const storage = storageApi();
|
const storage = storageLocal();
|
||||||
if (!storage) return;
|
if (!storage) return;
|
||||||
try {
|
try {
|
||||||
const result = await storage.get(DELTA_STORAGE_KEY);
|
const result = await storage.get(DELTA_STORAGE_KEY);
|
||||||
@@ -122,7 +115,7 @@ function ensureDeltaLoaded() {
|
|||||||
* @returns {Promise<void>}
|
* @returns {Promise<void>}
|
||||||
*/
|
*/
|
||||||
async function saveDeltaToStorage() {
|
async function saveDeltaToStorage() {
|
||||||
const storage = storageApi();
|
const storage = storageLocal();
|
||||||
if (!storage) return;
|
if (!storage) return;
|
||||||
try {
|
try {
|
||||||
const data = {
|
const data = {
|
||||||
|
|||||||
@@ -5,10 +5,7 @@ const { networkById } = require("./networks");
|
|||||||
// Dependency-free constant module; safe to pull into a background bundle.
|
// Dependency-free constant module; safe to pull into a background bundle.
|
||||||
const { RESTORABLE_VIEWS } = require("../popup/restorableViews");
|
const { RESTORABLE_VIEWS } = require("../popup/restorableViews");
|
||||||
|
|
||||||
const storageApi =
|
const { storageGet, storageSet } = require("./browserApi");
|
||||||
typeof browser !== "undefined"
|
|
||||||
? browser.storage.local
|
|
||||||
: chrome.storage.local;
|
|
||||||
|
|
||||||
const DEFAULT_STATE = {
|
const DEFAULT_STATE = {
|
||||||
hasWallet: false,
|
hasWallet: false,
|
||||||
@@ -114,11 +111,11 @@ async function saveState() {
|
|||||||
viewData: state.viewData,
|
viewData: state.viewData,
|
||||||
viewStack: state.viewStack,
|
viewStack: state.viewStack,
|
||||||
};
|
};
|
||||||
await storageApi.set({ autistmask: persisted });
|
await storageSet({ autistmask: persisted });
|
||||||
}
|
}
|
||||||
|
|
||||||
async function loadState() {
|
async function loadState() {
|
||||||
const result = await storageApi.get("autistmask");
|
const result = await storageGet("autistmask");
|
||||||
if (result.autistmask) {
|
if (result.autistmask) {
|
||||||
const saved = result.autistmask;
|
const saved = result.autistmask;
|
||||||
state.wallets = saved.wallets || [];
|
state.wallets = saved.wallets || [];
|
||||||
|
|||||||
@@ -8,11 +8,23 @@
|
|||||||
// either verdict alone, because the balance list is where the user forms
|
// either verdict alone, because the balance list is where the user forms
|
||||||
// their belief about what they own (issue #235).
|
// their belief about what they own (issue #235).
|
||||||
//
|
//
|
||||||
// KNOWN_SYMBOLS maps a symbol to the lowercased contract address that may
|
// KNOWN_SYMBOLS maps a symbol to the set of lowercased contract addresses
|
||||||
// bear it, or to null. Null means the symbol belongs to the native asset,
|
// that may bear it, or to null. Null means the symbol belongs to the native
|
||||||
// which has no contract at all, so no contract may bear it and every one
|
// asset, which has no contract at all, so no contract may bear it and every
|
||||||
// that does is a spoof. "ETH" is the only such entry today; the rule is
|
// one that does is a spoof. "ETH" is the only such entry today; the rule is
|
||||||
// written so that a second one needs no change here or at any call site.
|
// written so that a second one needs no change here or at any call site.
|
||||||
|
//
|
||||||
|
// The value is a set because a ticker is not unique: seven symbols in the
|
||||||
|
// bundled list belong to two real contracts each, and answering with one of
|
||||||
|
// them hid the other one's holders' money (issue #276). Membership, not
|
||||||
|
// equality, is therefore the question — but it is the same question, asked of
|
||||||
|
// a table that can now state the truth. Every address in a set is one the
|
||||||
|
// wallet ships as a real token; a contract outside the set is still a spoof.
|
||||||
|
//
|
||||||
|
// The symbol is attacker-controlled — it is whatever the ERC-20 contract
|
||||||
|
// returns — so the lookup is done on a normalized form (issue #260): the
|
||||||
|
// question is whether the symbol reaches the user's eye as a known one,
|
||||||
|
// since that is what the user acts on.
|
||||||
|
|
||||||
const { KNOWN_SYMBOLS } = require("./tokenList");
|
const { KNOWN_SYMBOLS } = require("./tokenList");
|
||||||
|
|
||||||
@@ -22,6 +34,59 @@ function normalizeAddress(addr) {
|
|||||||
return (addr || "").toLowerCase();
|
return (addr || "").toLowerCase();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Fold a symbol onto what a user actually sees, and no further:
|
||||||
|
//
|
||||||
|
// NFKC collapses compatibility variants that render as the ASCII
|
||||||
|
// letters they imitate — fullwidth ETH, styled mathematical
|
||||||
|
// letters — and maps the non-ASCII spaces onto U+0020.
|
||||||
|
// strip drops what paints nothing: \p{Cf} plus
|
||||||
|
// \p{Default_Ignorable_Code_Point} plus U+007F. That covers
|
||||||
|
// the format characters (zero-width space, joiner and
|
||||||
|
// non-joiner, word joiner, soft hyphen, byte-order mark, bidi
|
||||||
|
// marks and overrides), the variation selectors, the Hangul
|
||||||
|
// fillers, and DELETE. Removed everywhere, not merely at the
|
||||||
|
// ends.
|
||||||
|
// trim removes surrounding whitespace, which HTML collapses:
|
||||||
|
// `" ETH "` is painted next to the user's real ETH as `ETH`.
|
||||||
|
// toUpperCase makes the comparison case-insensitive, as before.
|
||||||
|
//
|
||||||
|
// The rule is "strip what paints nothing". The Unicode classes are how
|
||||||
|
// that is spelled, not what it means, which is why U+007F is named on its
|
||||||
|
// own: it is a control rather than a default-ignorable character, so no
|
||||||
|
// class here reaches it, yet it paints nothing all the same. Measured in
|
||||||
|
// the repo's pinned e2e Chromium (16px sans-serif, plain `ETH` = 32.00px,
|
||||||
|
// so an invisible prefix leaves 32.00px):
|
||||||
|
//
|
||||||
|
// U+007F, U+3164, U+115F, U+FE0F, U+FE00 32.00px — invisible
|
||||||
|
// U+FFA0 40.00px — a box
|
||||||
|
// U+1160 48.00px — a box
|
||||||
|
// U+0001, U+0085, U+0090 48.00px — a box
|
||||||
|
//
|
||||||
|
// U+1160 and U+FFA0 are `Default_Ignorable_Code_Point` members that font
|
||||||
|
// fallback nonetheless draws, and they are stripped anyway: erring toward
|
||||||
|
// hiding a token that does not look like `ETH` is the harmless direction of
|
||||||
|
// the two. The other controls are left alone for the same reason read the
|
||||||
|
// other way — a symbol carrying a visible box does not reach the eye as
|
||||||
|
// `ETH`, so filtering it would hide a token the user could not have
|
||||||
|
// confused with the native asset.
|
||||||
|
//
|
||||||
|
// Deliberately not folded, and asserted as open in tests/symbolSpoof.test.js:
|
||||||
|
// interior whitespace (`E T H` renders as `E T H`, so folding it would filter
|
||||||
|
// a token nobody could confuse with the native asset), confusables that are
|
||||||
|
// distinct letters rather than compatibility variants (Cyrillic capital Ie,
|
||||||
|
// U+0415; Greek capital Epsilon, U+0395), bidi reordering, which needs the
|
||||||
|
// bidi algorithm rather than a character filter, and the visible controls.
|
||||||
|
//
|
||||||
|
// This decides only how the question is asked. Nothing here changes what a
|
||||||
|
// surface displays; a token still shows the symbol it reports.
|
||||||
|
function normalizeSymbol(symbol) {
|
||||||
|
return String(symbol || "")
|
||||||
|
.normalize("NFKC")
|
||||||
|
.replace(/[\p{Cf}\p{Default_Ignorable_Code_Point}\x7F]/gu, "")
|
||||||
|
.trim()
|
||||||
|
.toUpperCase();
|
||||||
|
}
|
||||||
|
|
||||||
// True when a token bearing `symbol` from contract `contractAddress` is
|
// True when a token bearing `symbol` from contract `contractAddress` is
|
||||||
// impersonating a known symbol.
|
// impersonating a known symbol.
|
||||||
//
|
//
|
||||||
@@ -31,11 +96,11 @@ function normalizeAddress(addr) {
|
|||||||
function isSpoofedSymbol(symbol, contractAddress) {
|
function isSpoofedSymbol(symbol, contractAddress) {
|
||||||
const contract = normalizeAddress(contractAddress);
|
const contract = normalizeAddress(contractAddress);
|
||||||
if (!contract) return false;
|
if (!contract) return false;
|
||||||
const sym = (symbol || "").toUpperCase();
|
const sym = normalizeSymbol(symbol);
|
||||||
if (!KNOWN_SYMBOLS.has(sym)) return false;
|
if (!KNOWN_SYMBOLS.has(sym)) return false;
|
||||||
const legit = KNOWN_SYMBOLS.get(sym);
|
const legit = KNOWN_SYMBOLS.get(sym);
|
||||||
if (legit === null) return true;
|
if (legit === null) return true;
|
||||||
return contract !== normalizeAddress(legit);
|
return !legit.has(contract);
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
|
|||||||
@@ -3607,14 +3607,33 @@ for (const t of TOKENS) {
|
|||||||
TOKEN_BY_ADDRESS.set(t.address.toLowerCase(), t);
|
TOKEN_BY_ADDRESS.set(t.address.toLowerCase(), t);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Build a map of symbol (uppercased) -> legitimate contract address (lowercased).
|
// Build a map of symbol (uppercased) -> the set of contract addresses
|
||||||
// Used for spoofed-symbol detection. "ETH" maps to null (native token).
|
// (lowercased) that legitimately bear it. Used for spoofed-symbol detection.
|
||||||
|
// "ETH" maps to null: the native asset has no contract, so no contract may
|
||||||
|
// bear its symbol.
|
||||||
|
//
|
||||||
|
// The value is a set and not a single address because tickers are not unique
|
||||||
|
// and the list above proves it: seven of these 512 tokens share a symbol with
|
||||||
|
// another entry — FRAX, REUSD, TON, EURE, MSUSD, MUSD and JPYC — at two
|
||||||
|
// different real contracts each, all of them from the same source fetch. A
|
||||||
|
// one-address-per-symbol table can only answer that by picking a winner, and
|
||||||
|
// the loser is then a token in our own bundled list that the spoof filter
|
||||||
|
// hides from the balance list, the history and the send selector at its own
|
||||||
|
// address, so the user cannot spend it (issue #276). Naming every address
|
||||||
|
// that bears the symbol is the only shape that says what is true; it does not
|
||||||
|
// loosen the rule, because a contract outside the set is still a spoof.
|
||||||
const KNOWN_SYMBOLS = new Map();
|
const KNOWN_SYMBOLS = new Map();
|
||||||
KNOWN_SYMBOLS.set("ETH", null);
|
KNOWN_SYMBOLS.set("ETH", null);
|
||||||
for (const t of TOKENS) {
|
for (const t of TOKENS) {
|
||||||
const upper = t.symbol.toUpperCase();
|
const upper = t.symbol.toUpperCase();
|
||||||
if (!KNOWN_SYMBOLS.has(upper)) {
|
if (!KNOWN_SYMBOLS.has(upper)) {
|
||||||
KNOWN_SYMBOLS.set(upper, t.address.toLowerCase());
|
KNOWN_SYMBOLS.set(upper, new Set());
|
||||||
|
}
|
||||||
|
const addresses = KNOWN_SYMBOLS.get(upper);
|
||||||
|
// A null entry is the native asset and stays null: an ERC-20 that reports
|
||||||
|
// the native symbol does not thereby become entitled to it.
|
||||||
|
if (addresses !== null) {
|
||||||
|
addresses.add(t.address.toLowerCase());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
// Wallet and address deletion state transitions, kept out of the views so the
|
// Wallet and address deletion state transitions, kept out of the views so the
|
||||||
// selection and broadcast rules are testable without a DOM.
|
// selection and broadcast rules are testable without a DOM.
|
||||||
|
|
||||||
|
const { notify } = require("./browserApi");
|
||||||
|
|
||||||
// Two records of the same address can be stored in different cases, so
|
// Two records of the same address can be stored in different cases, so
|
||||||
// address equality is never a literal string comparison.
|
// address equality is never a literal string comparison.
|
||||||
function sameAddress(a, b) {
|
function sameAddress(a, b) {
|
||||||
@@ -144,9 +146,7 @@ function removeAddressFromState(state, walletIdx, addrIdx) {
|
|||||||
// accountsChanged to connected sites. Same call shape as the address
|
// accountsChanged to connected sites. Same call shape as the address
|
||||||
// switch in the home view.
|
// switch in the home view.
|
||||||
function broadcastActiveChanged() {
|
function broadcastActiveChanged() {
|
||||||
const runtime =
|
notify({ type: "AUTISTMASK_ACTIVE_CHANGED" });
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
|
||||||
runtime.sendMessage({ type: "AUTISTMASK_ACTIVE_CHANGED" });
|
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
|
|||||||
238
tests/e2e/firefox/dapp.js
Normal file
238
tests/e2e/firefox/dapp.js
Normal file
@@ -0,0 +1,238 @@
|
|||||||
|
// A loopback dApp origin and stub Ethereum node for the Firefox suite.
|
||||||
|
//
|
||||||
|
// The Firefox container runs with --network none, and the harness note in
|
||||||
|
// driver.js records the consequence: with no http:// origin in reach, no
|
||||||
|
// content script was ever injected, so content-script behaviour was
|
||||||
|
// UNVERIFIED and the dApp flows could not be driven at all.
|
||||||
|
//
|
||||||
|
// --network none removes every interface except loopback, and loopback is
|
||||||
|
// enough. This serves the page and the JSON-RPC endpoint from 127.0.0.1
|
||||||
|
// inside the same container Firefox runs in, so the dApp round trips execute
|
||||||
|
// against a real http:// origin and the run stays as offline as it was: the
|
||||||
|
// only reachable peer is this process.
|
||||||
|
//
|
||||||
|
// The page itself is not written twice. DAPP_HTML comes from the Chrome
|
||||||
|
// suite's fixture, so both harnesses drive the same __dapp API and the same
|
||||||
|
// message log.
|
||||||
|
//
|
||||||
|
// Unlike driver.js this file does use ethers, and it has to: the node has to
|
||||||
|
// answer eth_sendRawTransaction with the hash ethers computes for the
|
||||||
|
// artifact it was handed, or provider.broadcastTransaction() refuses the
|
||||||
|
// answer, and the suite recovers signatures itself rather than believing the
|
||||||
|
// extension's own verdict.
|
||||||
|
|
||||||
|
"use strict";
|
||||||
|
|
||||||
|
const http = require("http");
|
||||||
|
|
||||||
|
const { Transaction } = require("ethers");
|
||||||
|
|
||||||
|
const { DAPP_HTML } = require("../network");
|
||||||
|
|
||||||
|
// The same fee shape the Chrome suite uses, for the same reason: it has to
|
||||||
|
// pass the ceilings in src/shared/approvalVerify.js and it has to leave the
|
||||||
|
// reserve and the estimate distinguishable.
|
||||||
|
const GAS_LIMIT = 21000n;
|
||||||
|
const BASE_FEE_WEI = 100000000000n; // 100 gwei
|
||||||
|
const PRIORITY_FEE_WEI = 1000000000n; // 1 gwei
|
||||||
|
const GAS_PRICE_WEI = BASE_FEE_WEI + PRIORITY_FEE_WEI;
|
||||||
|
|
||||||
|
const STUB_BLOCK_NUMBER = 21000000;
|
||||||
|
|
||||||
|
// A 32-byte zero word, returned for every eth_call. It is what makes ethers'
|
||||||
|
// ENS reverse lookup resolve to "no resolver set" instead of throwing, and a
|
||||||
|
// throw there reaches the console through src/shared/log.js, which fails the
|
||||||
|
// run on its own.
|
||||||
|
const ZERO_WORD = "0x" + "0".repeat(64);
|
||||||
|
|
||||||
|
// One ETH, so the popup's balance lines render something and the wallet does
|
||||||
|
// not look empty on the approval screen.
|
||||||
|
const STUB_BALANCE_WEI = 10n ** 18n;
|
||||||
|
|
||||||
|
function hex(value) {
|
||||||
|
return "0x" + BigInt(value).toString(16);
|
||||||
|
}
|
||||||
|
|
||||||
|
function latestBlock() {
|
||||||
|
return {
|
||||||
|
hash: "0x" + "11".repeat(32),
|
||||||
|
parentHash: "0x" + "22".repeat(32),
|
||||||
|
number: hex(STUB_BLOCK_NUMBER),
|
||||||
|
timestamp: hex(1767326645),
|
||||||
|
nonce: "0x0000000000000000",
|
||||||
|
difficulty: "0x0",
|
||||||
|
gasLimit: "0x1c9c380",
|
||||||
|
gasUsed: "0xf4240",
|
||||||
|
miner: "0xc0ffee0000000000000000000000000000c0ffee",
|
||||||
|
extraData: "0x",
|
||||||
|
baseFeePerGas: hex(BASE_FEE_WEI),
|
||||||
|
transactions: [],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
const RPC_RESULTS = {
|
||||||
|
eth_chainId: "0x1",
|
||||||
|
net_version: "1",
|
||||||
|
eth_blockNumber: hex(STUB_BLOCK_NUMBER),
|
||||||
|
eth_getBalance: hex(STUB_BALANCE_WEI),
|
||||||
|
eth_call: ZERO_WORD,
|
||||||
|
eth_getCode: "0x",
|
||||||
|
eth_gasPrice: hex(GAS_PRICE_WEI),
|
||||||
|
eth_estimateGas: hex(GAS_LIMIT),
|
||||||
|
eth_getTransactionCount: "0x0",
|
||||||
|
eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI),
|
||||||
|
// "accepted but not mined", which is what a node says about a transaction
|
||||||
|
// it has only just taken. The wait screen the approval hands off to polls
|
||||||
|
// this for the rest of the run.
|
||||||
|
eth_getTransactionReceipt: null,
|
||||||
|
web3_clientVersion: "autistmask-e2e-firefox/0",
|
||||||
|
};
|
||||||
|
|
||||||
|
// Answer one JSON-RPC call. `broadcast` collects every raw transaction that
|
||||||
|
// reached this node, which is what the transaction assertions are made
|
||||||
|
// against — the artifact as the node saw it, never as the extension described
|
||||||
|
// it.
|
||||||
|
function rpcResult(req, state) {
|
||||||
|
const method = req.method;
|
||||||
|
|
||||||
|
if (method === "eth_sendRawTransaction") {
|
||||||
|
const raw = req.params && req.params[0];
|
||||||
|
state.broadcast.push(raw);
|
||||||
|
// ethers checks the hash it is given against the hash it computes for
|
||||||
|
// the artifact it sent, so this cannot be a fixed string.
|
||||||
|
return Transaction.from(raw).hash;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (method === "eth_getBlockByNumber" || method === "eth_getBlockByHash") {
|
||||||
|
return latestBlock();
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Object.prototype.hasOwnProperty.call(RPC_RESULTS, method)) {
|
||||||
|
return RPC_RESULTS[method];
|
||||||
|
}
|
||||||
|
|
||||||
|
// Never a silent default. An unstubbed method answered with null looks
|
||||||
|
// like a working node returning nothing, and the assertion downstream
|
||||||
|
// fails somewhere unrelated.
|
||||||
|
state.unstubbed.push(method);
|
||||||
|
throw new Error("no fixture for JSON-RPC method " + method);
|
||||||
|
}
|
||||||
|
|
||||||
|
function readBody(req) {
|
||||||
|
return new Promise((resolve, reject) => {
|
||||||
|
let body = "";
|
||||||
|
req.on("data", (chunk) => {
|
||||||
|
body += chunk;
|
||||||
|
});
|
||||||
|
req.on("end", () => resolve(body));
|
||||||
|
req.on("error", reject);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
function handleRpcBody(body, state) {
|
||||||
|
const parsed = JSON.parse(body);
|
||||||
|
const answer = (req) => {
|
||||||
|
try {
|
||||||
|
return {
|
||||||
|
jsonrpc: "2.0",
|
||||||
|
id: req.id,
|
||||||
|
result: rpcResult(req, state),
|
||||||
|
};
|
||||||
|
} catch (e) {
|
||||||
|
return {
|
||||||
|
jsonrpc: "2.0",
|
||||||
|
id: req.id,
|
||||||
|
error: { code: -32601, message: e.message },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
};
|
||||||
|
return Array.isArray(parsed) ? parsed.map(answer) : answer(parsed);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Serve the dApp page and the stub node on loopback.
|
||||||
|
*
|
||||||
|
* @returns {Promise<Object>} the running fixture: `url` and `origin` of the
|
||||||
|
* page, `rpcUrl` for the extension's rpcUrl setting, `broadcast` (the raw
|
||||||
|
* transactions the node received, in order), `unstubbed` (JSON-RPC methods
|
||||||
|
* nothing answered) and `close()`.
|
||||||
|
*/
|
||||||
|
async function startDappServer() {
|
||||||
|
const state = { broadcast: [], unstubbed: [], requests: [] };
|
||||||
|
|
||||||
|
const server = http.createServer((req, res) => {
|
||||||
|
const url = new URL(req.url, "http://127.0.0.1");
|
||||||
|
state.requests.push(req.method + " " + url.pathname);
|
||||||
|
|
||||||
|
if (url.pathname === "/rpc" && req.method === "POST") {
|
||||||
|
readBody(req)
|
||||||
|
.then((body) => {
|
||||||
|
const payload = JSON.stringify(handleRpcBody(body, state));
|
||||||
|
res.writeHead(200, {
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
// The extension fetches this from its background
|
||||||
|
// page, whose origin is moz-extension://. Without CORS
|
||||||
|
// the fetch fails and every transaction assertion
|
||||||
|
// fails for a reason that has nothing to do with the
|
||||||
|
// wallet.
|
||||||
|
"Access-Control-Allow-Origin": "*",
|
||||||
|
});
|
||||||
|
res.end(payload);
|
||||||
|
})
|
||||||
|
.catch((e) => {
|
||||||
|
res.writeHead(500, { "Content-Type": "text/plain" });
|
||||||
|
res.end(String(e && e.message));
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (url.pathname === "/") {
|
||||||
|
res.writeHead(200, { "Content-Type": "text/html; charset=utf-8" });
|
||||||
|
res.end(DAPP_HTML);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// An empty favicon rather than a 404: a 404 is a page error in
|
||||||
|
// Firefox's console under some settings, and the suite fails the run
|
||||||
|
// on those.
|
||||||
|
if (url.pathname === "/favicon.ico") {
|
||||||
|
res.writeHead(200, { "Content-Type": "image/x-icon" });
|
||||||
|
res.end("");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
res.writeHead(404, { "Content-Type": "text/plain" });
|
||||||
|
res.end("not found");
|
||||||
|
});
|
||||||
|
|
||||||
|
await new Promise((resolve, reject) => {
|
||||||
|
server.on("error", reject);
|
||||||
|
// Port 0: this host runs many sessions at once, and a fixed port is a
|
||||||
|
// guaranteed collision rather than a possible one.
|
||||||
|
server.listen(0, "127.0.0.1", resolve);
|
||||||
|
});
|
||||||
|
|
||||||
|
const { port } = server.address();
|
||||||
|
const origin = "http://127.0.0.1:" + port;
|
||||||
|
|
||||||
|
return {
|
||||||
|
origin,
|
||||||
|
url: origin + "/",
|
||||||
|
rpcUrl: origin + "/rpc",
|
||||||
|
broadcast: state.broadcast,
|
||||||
|
unstubbed: state.unstubbed,
|
||||||
|
requests: state.requests,
|
||||||
|
close: () =>
|
||||||
|
new Promise((resolve) => {
|
||||||
|
server.closeAllConnections();
|
||||||
|
server.close(() => resolve());
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
GAS_LIMIT,
|
||||||
|
GAS_PRICE_WEI,
|
||||||
|
STUB_BALANCE_WEI,
|
||||||
|
startDappServer,
|
||||||
|
};
|
||||||
@@ -110,6 +110,26 @@ class Driver {
|
|||||||
"extensions.webextensions.uuids": JSON.stringify({
|
"extensions.webextensions.uuids": JSON.stringify({
|
||||||
[EXTENSION_ID]: EXTENSION_UUID,
|
[EXTENSION_ID]: EXTENSION_UUID,
|
||||||
}),
|
}),
|
||||||
|
// The container has loopback and nothing else. Firefox's own
|
||||||
|
// link-status detection can read that as "offline" and then
|
||||||
|
// refuse every request, including the ones to the loopback dApp
|
||||||
|
// origin the suite serves; this takes the decision away from it.
|
||||||
|
"network.manage-offline-status": false,
|
||||||
|
// Force the site-connection prompt down its windows.create()
|
||||||
|
// fallback.
|
||||||
|
//
|
||||||
|
// src/background/index.js prefers the toolbar-anchored popup for
|
||||||
|
// that one approval and opens a real window only when
|
||||||
|
// openPopup() refuses. A panel is not a top-level browsing
|
||||||
|
// context, so WebDriver cannot see it, list it or click in it —
|
||||||
|
// the same blind spot the Chrome harness documents. Leaving this
|
||||||
|
// at its default would make which path runs depend on whether a
|
||||||
|
// headless Firefox counts as having had a user gesture, which is
|
||||||
|
// not a thing to leave to chance in a suite that has to be able
|
||||||
|
// to fail. The window path is shipped code and the same approval
|
||||||
|
// id, so what is driven is real; what is NOT covered either way
|
||||||
|
// is the panel presentation itself.
|
||||||
|
"extensions.openPopupWithoutUserGesture.enabled": false,
|
||||||
};
|
};
|
||||||
|
|
||||||
const value = await this.send("POST", "/session", {
|
const value = await this.send("POST", "/session", {
|
||||||
@@ -179,6 +199,16 @@ class Driver {
|
|||||||
return this.session("POST", "/execute/sync", { script, args });
|
return this.session("POST", "/execute/sync", { script, args });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The asynchronous form: the script is handed a resolve callback as its
|
||||||
|
// last argument and the call settles when that is invoked. Everything
|
||||||
|
// interesting about an extension page is promise-shaped — storage reads,
|
||||||
|
// the provider's own request() — and /execute/sync cannot wait for any
|
||||||
|
// of it.
|
||||||
|
async executeAsync(script, args = []) {
|
||||||
|
await this.setContext("content");
|
||||||
|
return this.session("POST", "/execute/async", { script, args });
|
||||||
|
}
|
||||||
|
|
||||||
// Runs in the privileged chrome scope, where Services and Ci exist.
|
// Runs in the privileged chrome scope, where Services and Ci exist.
|
||||||
async executeChrome(script, args = []) {
|
async executeChrome(script, args = []) {
|
||||||
await this.setContext("chrome");
|
await this.setContext("chrome");
|
||||||
@@ -329,6 +359,63 @@ class Driver {
|
|||||||
[selector],
|
[selector],
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ------------------------------------------------------------ windows
|
||||||
|
//
|
||||||
|
// The approval prompts this suite drives are separate top-level windows
|
||||||
|
// the extension opens itself, so every one of them is a window handle
|
||||||
|
// here and the suite has to move between them explicitly.
|
||||||
|
|
||||||
|
async windowHandles() {
|
||||||
|
return this.session("GET", "/window/handles");
|
||||||
|
}
|
||||||
|
|
||||||
|
async currentWindow() {
|
||||||
|
return this.session("GET", "/window");
|
||||||
|
}
|
||||||
|
|
||||||
|
async switchToWindow(handle) {
|
||||||
|
await this.setContext("content");
|
||||||
|
await this.session("POST", "/window", { handle });
|
||||||
|
}
|
||||||
|
|
||||||
|
async newWindow(type = "window") {
|
||||||
|
await this.setContext("content");
|
||||||
|
const value = await this.session("POST", "/window/new", { type });
|
||||||
|
return value.handle;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Closes the current window and leaves the session on `fallback`, because
|
||||||
|
// a session whose current window is gone fails every subsequent command
|
||||||
|
// with "no such window" rather than with anything diagnosable.
|
||||||
|
async closeWindow(fallback) {
|
||||||
|
await this.setContext("content");
|
||||||
|
await this.session("DELETE", "/window");
|
||||||
|
if (fallback) await this.switchToWindow(fallback);
|
||||||
|
}
|
||||||
|
|
||||||
|
async url() {
|
||||||
|
return this.session("GET", "/url");
|
||||||
|
}
|
||||||
|
|
||||||
|
// The handle of the first window whose URL matches, or null. Restores the
|
||||||
|
// window that was current before the search either way: a probe that
|
||||||
|
// silently relocates the session is a trap for the step after it.
|
||||||
|
async findWindow(predicate) {
|
||||||
|
const origin = await this.currentWindow();
|
||||||
|
try {
|
||||||
|
for (const handle of await this.windowHandles()) {
|
||||||
|
await this.switchToWindow(handle);
|
||||||
|
if (predicate(await this.url())) return handle;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
} finally {
|
||||||
|
// Tolerated: the window the search started from may have been the
|
||||||
|
// one that just closed, and a throw in here would replace the
|
||||||
|
// real result with "no such window".
|
||||||
|
await this.switchToWindow(origin).catch(() => {});
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// ------------------------------------------------------- error capture
|
// ------------------------------------------------------- error capture
|
||||||
@@ -349,10 +436,15 @@ class Driver {
|
|||||||
// background page, which BiDi would not have covered even if it worked.
|
// background page, which BiDi would not have covered even if it worked.
|
||||||
// Background-page capture is verified by probe — a throw at the top of
|
// Background-page capture is verified by probe — a throw at the top of
|
||||||
// src/background/index.js, which kills the background page outright, fails
|
// src/background/index.js, which kills the background page outright, fails
|
||||||
// the run. Content-script errors should arrive by the same route, but that
|
// the run.
|
||||||
// is UNVERIFIED here and must not be claimed: the container runs with
|
//
|
||||||
// --network none, so there is no http:// page for a content script to be
|
// Content scripts ARE now exercised: tests/e2e/firefox/dapp.js serves a page
|
||||||
// injected into and this suite never exercises one.
|
// from loopback, which survives --network none, and the suite drives the
|
||||||
|
// EIP-1193 round trips through the content script injected into it. What is
|
||||||
|
// still unproven is the CAPTURE, not the execution — no probe has forced a
|
||||||
|
// throw from inside a content script and watched it fail the run, so an
|
||||||
|
// uncaught content-script error arriving by this route remains an
|
||||||
|
// expectation rather than a demonstrated fact. Do not claim otherwise.
|
||||||
//
|
//
|
||||||
// Warnings are excluded so the semantics match Playwright's pageerror:
|
// Warnings are excluded so the semantics match Playwright's pageerror:
|
||||||
// uncaught errors only.
|
// uncaught errors only.
|
||||||
|
|||||||
@@ -15,8 +15,15 @@
|
|||||||
// UI steps below are written twice on purpose. Chrome runs on Playwright,
|
// UI steps below are written twice on purpose. Chrome runs on Playwright,
|
||||||
// which cannot see extension-page errors in Firefox at all (see the BiDi
|
// which cannot see extension-page errors in Firefox at all (see the BiDi
|
||||||
// note in driver.js), so the two backends have no common substrate to
|
// note in driver.js), so the two backends have no common substrate to
|
||||||
// abstract over. Three duplicated steps do not pay for a shim; revisit if
|
// abstract over. Duplicated steps do not pay for a shim; revisit if this
|
||||||
// this suite grows to where they do.
|
// suite grows to where they do. What IS shared is the dApp page fixture
|
||||||
|
// itself — DAPP_HTML, served here from loopback by dapp.js — so an assertion
|
||||||
|
// about the __dapp API means the same thing on both browsers.
|
||||||
|
//
|
||||||
|
// The dApp steps need an http:// origin, which --network none was thought to
|
||||||
|
// rule out. It does not: loopback survives it, so the page and the stub node
|
||||||
|
// are served from 127.0.0.1 inside the container and the run reaches nothing
|
||||||
|
// but this process. See tests/e2e/firefox/dapp.js.
|
||||||
//
|
//
|
||||||
// LIMITATION, and the difference from the Chrome suite worth knowing: error
|
// LIMITATION, and the difference from the Chrome suite worth knowing: error
|
||||||
// capture here is POLL-BASED, not event-streamed. The console service is
|
// capture here is POLL-BASED, not event-streamed. The console service is
|
||||||
@@ -40,7 +47,21 @@
|
|||||||
const fs = require("fs");
|
const fs = require("fs");
|
||||||
const path = require("path");
|
const path = require("path");
|
||||||
|
|
||||||
|
const {
|
||||||
|
Transaction,
|
||||||
|
formatEther,
|
||||||
|
getAddress,
|
||||||
|
getBytes,
|
||||||
|
hexlify,
|
||||||
|
parseEther,
|
||||||
|
toQuantity,
|
||||||
|
toUtf8Bytes,
|
||||||
|
verifyMessage,
|
||||||
|
} = require("ethers");
|
||||||
|
|
||||||
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
|
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
|
||||||
|
const { startDappServer } = require("./dapp");
|
||||||
|
const { STUB_COUNTERPARTY } = require("../network");
|
||||||
|
|
||||||
const REPO_ROOT = path.resolve(__dirname, "..", "..", "..");
|
const REPO_ROOT = path.resolve(__dirname, "..", "..", "..");
|
||||||
const POPUP_URL = EXTENSION_ORIGIN + "/src/popup/index.html";
|
const POPUP_URL = EXTENSION_ORIGIN + "/src/popup/index.html";
|
||||||
@@ -137,8 +158,596 @@ step("add token screen opens from address detail", async (env) => {
|
|||||||
assert(picks > 0, "no common-token quick-pick buttons rendered");
|
assert(picks > 0, "no common-token quick-pick buttons rendered");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// ------------------------------------------------- the dApp round trips
|
||||||
|
//
|
||||||
|
// Everything above drives the popup on its own. From here the page, the
|
||||||
|
// content script, the inpage provider, the background page and the approval
|
||||||
|
// window all have to work together, which on Firefox is exactly the seam
|
||||||
|
// https://git.eeqj.de/sneak/AutistMask/issues/153 is about: every one of
|
||||||
|
// these paths used to hand a Chrome-style callback to the promise-only
|
||||||
|
// browser.* namespace and simply never complete.
|
||||||
|
//
|
||||||
|
// The shape is the Chrome suite's (tests/e2e/run.js, the #183 section) and
|
||||||
|
// the assertions mean the same things:
|
||||||
|
//
|
||||||
|
// - the signature is recovered here, in the runner, from the artifact the
|
||||||
|
// extension produced, and compared against the address read out of
|
||||||
|
// extension storage. The background verifies too; these assertions do not
|
||||||
|
// lean on that, because a test that trusted the wallet's own verdict would
|
||||||
|
// pass against a wallet that verified nothing.
|
||||||
|
// - the transaction is asserted against the raw signed transaction that
|
||||||
|
// reached the stub node, not against anything the extension reported.
|
||||||
|
//
|
||||||
|
// What this does NOT cover: a real dApp with real funds against a real
|
||||||
|
// network. The node is a fixture on loopback.
|
||||||
|
|
||||||
|
const SIGN_TEXT = "AutistMask e2e round trip: personal_sign";
|
||||||
|
const SIGN_HEX = hexlify(toUtf8Bytes(SIGN_TEXT));
|
||||||
|
|
||||||
|
const TX_VALUE_ETH = "0.0123";
|
||||||
|
const TX_VALUE_WEI = parseEther(TX_VALUE_ETH);
|
||||||
|
// Call data that decodes as nothing, so the screen assertion compares the
|
||||||
|
// calldata itself rather than a decoder's summary of it.
|
||||||
|
const TX_DATA = "0xdeadbeef" + "01".repeat(28);
|
||||||
|
|
||||||
|
const USER_REJECTION_MESSAGE = "User rejected the request.";
|
||||||
|
|
||||||
|
// Read the extension's persisted state, point its rpcUrl at the loopback stub
|
||||||
|
// node, and hand back the active address. Runs on the popup page, which is
|
||||||
|
// the one moz-extension:// document the suite has open and therefore the only
|
||||||
|
// place the storage API is reachable from.
|
||||||
|
async function pointAtStubNode(d, rpcUrl) {
|
||||||
|
const outcome = await d.executeAsync(
|
||||||
|
`const done = arguments[arguments.length - 1];
|
||||||
|
const rpcUrl = arguments[0];
|
||||||
|
const api = typeof browser !== "undefined" ? browser : chrome;
|
||||||
|
Promise.resolve(api.storage.local.get("autistmask"))
|
||||||
|
.then((r) => {
|
||||||
|
const s = r.autistmask;
|
||||||
|
if (!s) throw new Error("the extension has no persisted state");
|
||||||
|
s.rpcUrl = rpcUrl;
|
||||||
|
const w = s.wallets && s.wallets[0];
|
||||||
|
const first = w && w.addresses && w.addresses[0];
|
||||||
|
const address = s.activeAddress || (first && first.address);
|
||||||
|
if (!address) throw new Error("the extension holds no address");
|
||||||
|
return Promise.resolve(api.storage.local.set({ autistmask: s }))
|
||||||
|
.then(() => done({ address: address }));
|
||||||
|
})
|
||||||
|
.catch((e) => done({ error: String((e && e.message) || e) }));`,
|
||||||
|
[rpcUrl],
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome && !outcome.error,
|
||||||
|
"could not point the extension at the stub node: " +
|
||||||
|
(outcome && outcome.error),
|
||||||
|
);
|
||||||
|
return getAddress(outcome.address);
|
||||||
|
}
|
||||||
|
|
||||||
|
// The approval window the background opened. Approvals are raised from an RPC
|
||||||
|
// call rather than from a user gesture, so the extension opens a real window
|
||||||
|
// for them, which is an ordinary window handle here.
|
||||||
|
async function waitForApprovalWindow(d, timeout = 30000) {
|
||||||
|
const deadline = Date.now() + timeout;
|
||||||
|
for (;;) {
|
||||||
|
const handle = await d.findWindow((u) => u.includes("?approval="));
|
||||||
|
if (handle) return handle;
|
||||||
|
if (Date.now() > deadline) {
|
||||||
|
throw new Error(
|
||||||
|
"the extension opened no approval window within " +
|
||||||
|
timeout +
|
||||||
|
"ms",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
await sleep(100);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function startRequest(d, key, method, params) {
|
||||||
|
return d.execute(
|
||||||
|
"window.__dapp.start(arguments[0], arguments[1], arguments[2]);" +
|
||||||
|
" return true;",
|
||||||
|
[key, method, params],
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// The settled outcome of a parked request, or {settled:"pending"} if it is
|
||||||
|
// still outstanding. A bounded wait rather than a bare await: "returns a
|
||||||
|
// rejection rather than hanging" is one of the things under test, and an
|
||||||
|
// await would report a hang as a step timeout with no indication of which
|
||||||
|
// call never settled.
|
||||||
|
function settleRequest(d, key, timeout = 45000) {
|
||||||
|
return d.executeAsync(
|
||||||
|
`const done = arguments[arguments.length - 1];
|
||||||
|
const key = arguments[0];
|
||||||
|
const timeout = arguments[1];
|
||||||
|
Promise.race([
|
||||||
|
window.__dapp.settle(key),
|
||||||
|
new Promise((r) => setTimeout(() => r({ settled: "pending" }), timeout)),
|
||||||
|
]).then(done, (e) => done({ settled: "error", message: String(e) }));`,
|
||||||
|
[key, timeout],
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Every AUTISTMASK_* message that has crossed between the page and the
|
||||||
|
// content script. This is the boundary half of the rejection assertion: the
|
||||||
|
// code has to be on the wire as well as on the Error the page catches, so a
|
||||||
|
// pass cannot come from the provider inventing one.
|
||||||
|
function dappMessages(d, type) {
|
||||||
|
return d.execute(
|
||||||
|
// `want` is bound outside the callback deliberately: inside it,
|
||||||
|
// arguments[0] is the message being tested, not the script argument,
|
||||||
|
// and the filter silently matches nothing.
|
||||||
|
"var want = arguments[0];" +
|
||||||
|
" return window.__dapp.messages.filter(function (m) {" +
|
||||||
|
" return !want || m.type === want; });",
|
||||||
|
[type || null],
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function lastResponseError(d) {
|
||||||
|
const responses = await dappMessages(d, "AUTISTMASK_RESPONSE");
|
||||||
|
const last = responses[responses.length - 1];
|
||||||
|
assert(last, "the page received no AUTISTMASK_RESPONSE at all");
|
||||||
|
return last.error || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// A rejected prompt, asserted at both ends: the page's promise rejected
|
||||||
|
// rather than hanging or resolving, and the response that crossed the
|
||||||
|
// boundary carried EIP-1193 code 4001.
|
||||||
|
async function assertUserRejection(d, key, label) {
|
||||||
|
const outcome = await settleRequest(d, key);
|
||||||
|
assert(
|
||||||
|
outcome.settled !== "pending",
|
||||||
|
label + " never settled: the rejected prompt left the page hanging",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome.settled === "rejected",
|
||||||
|
label + " resolved instead of rejecting: " + JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome.message === USER_REJECTION_MESSAGE,
|
||||||
|
label + " rejected with the wrong message: " + outcome.message,
|
||||||
|
);
|
||||||
|
const error = await lastResponseError(d);
|
||||||
|
assert(
|
||||||
|
error && error.code === 4001,
|
||||||
|
label +
|
||||||
|
" did not carry EIP-1193 code 4001 across the boundary: " +
|
||||||
|
JSON.stringify(error),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome.hasCode,
|
||||||
|
label +
|
||||||
|
" reached the page as an error with no code property at all, so a " +
|
||||||
|
"dApp cannot tell the user's refusal from a failure: " +
|
||||||
|
JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome.code === 4001,
|
||||||
|
label +
|
||||||
|
" reached the page with code " +
|
||||||
|
JSON.stringify(outcome.code) +
|
||||||
|
" rather than EIP-1193 4001",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome.name === "ProviderRpcError",
|
||||||
|
label +
|
||||||
|
" reached the page as " +
|
||||||
|
JSON.stringify(outcome.name) +
|
||||||
|
" rather than an EIP-1193 ProviderRpcError",
|
||||||
|
);
|
||||||
|
console.log(
|
||||||
|
"# " +
|
||||||
|
label +
|
||||||
|
": code 4001 on the wire and on the page's " +
|
||||||
|
outcome.name,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
step("the loopback dApp page gets the real inpage provider", async (env) => {
|
||||||
|
const d = env.driver;
|
||||||
|
|
||||||
|
// The popup is still the current window; point the extension at the stub
|
||||||
|
// node from there, then reload it so its in-memory copy of the state
|
||||||
|
// carries the new rpcUrl and cannot save the old one back over it.
|
||||||
|
env.address = await pointAtStubNode(d, env.server.rpcUrl);
|
||||||
|
await d.navigate(POPUP_URL);
|
||||||
|
await d.waitVisible("#view-main", STEP_TIMEOUT_MS);
|
||||||
|
env.popupWindow = await d.currentWindow();
|
||||||
|
|
||||||
|
env.dappWindow = await d.newWindow("tab");
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await d.navigate(env.server.url);
|
||||||
|
|
||||||
|
// window.ethereum is not the fixture's doing — it is the shipped content
|
||||||
|
// script, injected into a real http:// origin. Waiting for it is waiting
|
||||||
|
// for the real provider to have installed itself.
|
||||||
|
await d.waitFor(
|
||||||
|
"the injected EIP-1193 provider and the test page API",
|
||||||
|
"return !!window.ethereum && !!window.__dapp;",
|
||||||
|
[],
|
||||||
|
STEP_TIMEOUT_MS,
|
||||||
|
);
|
||||||
|
|
||||||
|
// EIP-6963, asked of the provider itself. The announcement carries the
|
||||||
|
// uuid src/content/index.js reads out of extension storage — call site 1
|
||||||
|
// in the issue — and it has to name this extension and hand back the very
|
||||||
|
// object on window.ethereum.
|
||||||
|
const announced = await d.executeAsync(
|
||||||
|
`const done = arguments[arguments.length - 1];
|
||||||
|
const onAnnounce = (e) => {
|
||||||
|
window.removeEventListener("eip6963:announceProvider", onAnnounce);
|
||||||
|
done({
|
||||||
|
rdns: e.detail.info.rdns,
|
||||||
|
uuid: e.detail.info.uuid,
|
||||||
|
isWindowEthereum: e.detail.provider === window.ethereum,
|
||||||
|
});
|
||||||
|
};
|
||||||
|
window.addEventListener("eip6963:announceProvider", onAnnounce);
|
||||||
|
window.dispatchEvent(new Event("eip6963:requestProvider"));
|
||||||
|
setTimeout(() => done(null), 15000);`,
|
||||||
|
);
|
||||||
|
assert(announced, "the provider announced itself to no EIP-6963 request");
|
||||||
|
assert(
|
||||||
|
announced.rdns === "berlin.sneak.autistmask",
|
||||||
|
"the announced provider is not this extension: " +
|
||||||
|
JSON.stringify(announced),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
announced.isWindowEthereum,
|
||||||
|
"the announced provider is not the object on window.ethereum",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
typeof announced.uuid === "string" && announced.uuid.length === 36,
|
||||||
|
"the announcement carries no stored provider uuid: " +
|
||||||
|
JSON.stringify(announced.uuid),
|
||||||
|
);
|
||||||
|
|
||||||
|
// A full page -> content script -> background round trip that needs no
|
||||||
|
// approval, so the relay is proven before any prompt is driven. This is
|
||||||
|
// call site 2, the one that used to fail for every window.ethereum
|
||||||
|
// request a dApp made.
|
||||||
|
const chainId = await d.executeAsync(
|
||||||
|
`const done = arguments[arguments.length - 1];
|
||||||
|
window.ethereum.request({ method: "eth_chainId" }).then(
|
||||||
|
(r) => done({ ok: r }),
|
||||||
|
(e) => done({ err: String((e && e.message) || e) }),
|
||||||
|
);`,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
chainId && chainId.ok === "0x1",
|
||||||
|
"eth_chainId did not round trip through the extension: " +
|
||||||
|
JSON.stringify(chainId),
|
||||||
|
);
|
||||||
|
console.log(
|
||||||
|
"# dapp origin " + env.server.origin + " active address " + env.address,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
step(
|
||||||
|
"eth_requestAccounts approved returns the selected address",
|
||||||
|
async (env) => {
|
||||||
|
const d = env.driver;
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await startRequest(d, "accounts", "eth_requestAccounts", []);
|
||||||
|
|
||||||
|
const popup = await waitForApprovalWindow(d);
|
||||||
|
await d.switchToWindow(popup);
|
||||||
|
await d.waitVisible("#view-approve-site");
|
||||||
|
|
||||||
|
const hostname = await d.text("#approve-hostname");
|
||||||
|
assert(
|
||||||
|
hostname === "127.0.0.1",
|
||||||
|
"the site prompt names the wrong origin: " +
|
||||||
|
JSON.stringify(hostname),
|
||||||
|
);
|
||||||
|
const shown = await d.text("#approve-address");
|
||||||
|
assert(
|
||||||
|
shown.toLowerCase().includes(env.address.toLowerCase()),
|
||||||
|
"the site prompt shows the wrong address: " + JSON.stringify(shown),
|
||||||
|
);
|
||||||
|
|
||||||
|
// Remembered, so the origin stays authorized for the sign and transaction
|
||||||
|
// steps below.
|
||||||
|
const checked = await d.execute(
|
||||||
|
'return document.getElementById("approve-remember").checked;',
|
||||||
|
);
|
||||||
|
if (!checked) await d.click("#approve-remember");
|
||||||
|
await d.click("#btn-approve");
|
||||||
|
|
||||||
|
// The approve button closes its own window, so get off it before asking
|
||||||
|
// the page anything.
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
const outcome = await settleRequest(d, "accounts");
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved",
|
||||||
|
"eth_requestAccounts did not resolve: " + JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
Array.isArray(outcome.result) && outcome.result.length === 1,
|
||||||
|
"eth_requestAccounts returned no single account: " +
|
||||||
|
JSON.stringify(outcome.result),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
getAddress(outcome.result[0]) === env.address,
|
||||||
|
"eth_requestAccounts returned " +
|
||||||
|
outcome.result[0] +
|
||||||
|
", not the selected address " +
|
||||||
|
env.address,
|
||||||
|
);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
step(
|
||||||
|
"personal_sign returns a signature that recovers to the address",
|
||||||
|
async (env) => {
|
||||||
|
const d = env.driver;
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await startRequest(d, "sign", "personal_sign", [SIGN_HEX, env.address]);
|
||||||
|
|
||||||
|
const popup = await waitForApprovalWindow(d);
|
||||||
|
await d.switchToWindow(popup);
|
||||||
|
await d.waitVisible("#view-approve-sign");
|
||||||
|
|
||||||
|
const screen = await d.execute(
|
||||||
|
`return {
|
||||||
|
hostname: document.getElementById("approve-sign-hostname").textContent,
|
||||||
|
type: document.getElementById("approve-sign-type").textContent,
|
||||||
|
message: document.getElementById("approve-sign-message").textContent,
|
||||||
|
from: document.getElementById("approve-sign-from").textContent,
|
||||||
|
};`,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.hostname === "127.0.0.1",
|
||||||
|
"the sign prompt names the wrong origin: " +
|
||||||
|
JSON.stringify(screen.hostname),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.type === "Personal message",
|
||||||
|
"the sign prompt reports the wrong type: " +
|
||||||
|
JSON.stringify(screen.type),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.message === SIGN_TEXT,
|
||||||
|
"the sign prompt shows the wrong message: " +
|
||||||
|
JSON.stringify(screen.message),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.from.toLowerCase().includes(env.address.toLowerCase()),
|
||||||
|
"the sign prompt shows the wrong signing address: " +
|
||||||
|
JSON.stringify(screen.from),
|
||||||
|
);
|
||||||
|
|
||||||
|
await d.fill("#approve-sign-password", PASSWORD);
|
||||||
|
await d.click("#btn-approve-sign");
|
||||||
|
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
const outcome = await settleRequest(d, "sign");
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved",
|
||||||
|
"personal_sign did not resolve: " + JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
const recovered = getAddress(
|
||||||
|
verifyMessage(getBytes(SIGN_HEX), outcome.result),
|
||||||
|
);
|
||||||
|
console.log(
|
||||||
|
"# personal_sign: recovered=" +
|
||||||
|
recovered +
|
||||||
|
" expected=" +
|
||||||
|
env.address,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
recovered === env.address,
|
||||||
|
"the personal_sign signature recovers to " +
|
||||||
|
recovered +
|
||||||
|
", not to the approved address " +
|
||||||
|
env.address,
|
||||||
|
);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
step(
|
||||||
|
"eth_sendTransaction shows the transaction and returns its hash",
|
||||||
|
async (env) => {
|
||||||
|
const d = env.driver;
|
||||||
|
const before = env.server.broadcast.length;
|
||||||
|
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await startRequest(d, "tx", "eth_sendTransaction", [
|
||||||
|
{
|
||||||
|
from: env.address,
|
||||||
|
to: STUB_COUNTERPARTY,
|
||||||
|
value: toQuantity(TX_VALUE_WEI),
|
||||||
|
data: TX_DATA,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
|
||||||
|
const popup = await waitForApprovalWindow(d);
|
||||||
|
await d.switchToWindow(popup);
|
||||||
|
await d.waitVisible("#view-approve-tx");
|
||||||
|
|
||||||
|
const screen = await d.execute(
|
||||||
|
`return {
|
||||||
|
hostname: document.getElementById("approve-tx-hostname").textContent,
|
||||||
|
from: document.getElementById("approve-tx-from").textContent,
|
||||||
|
to: document.getElementById("approve-tx-to").textContent,
|
||||||
|
value: document.getElementById("approve-tx-value").textContent,
|
||||||
|
data: document.getElementById("approve-tx-data").textContent,
|
||||||
|
dataShown: !document
|
||||||
|
.getElementById("approve-tx-data-section")
|
||||||
|
.classList.contains("hidden"),
|
||||||
|
};`,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.hostname === "127.0.0.1",
|
||||||
|
"the transaction prompt names the wrong origin: " +
|
||||||
|
JSON.stringify(screen.hostname),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.from.toLowerCase().includes(env.address.toLowerCase()),
|
||||||
|
"the transaction prompt shows the wrong sender: " +
|
||||||
|
JSON.stringify(screen.from),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.to.toLowerCase().includes(STUB_COUNTERPARTY.toLowerCase()),
|
||||||
|
"the transaction prompt shows the wrong recipient: " +
|
||||||
|
JSON.stringify(screen.to),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.value.startsWith(TX_VALUE_ETH + " ETH"),
|
||||||
|
"the transaction prompt shows the wrong value: " +
|
||||||
|
JSON.stringify(screen.value),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
screen.dataShown && screen.data === TX_DATA,
|
||||||
|
"the transaction prompt does not show the approved call data: " +
|
||||||
|
JSON.stringify(screen.data),
|
||||||
|
);
|
||||||
|
|
||||||
|
await d.fill("#approve-tx-password", PASSWORD);
|
||||||
|
await d.click("#btn-approve-tx");
|
||||||
|
|
||||||
|
// The approval window hands off to the wait screen rather than closing,
|
||||||
|
// and the hash it shows is asserted before it is retired: left open it
|
||||||
|
// polls the stub node for a receipt for the rest of the run.
|
||||||
|
await d.waitVisible("#view-wait-tx", STEP_TIMEOUT_MS);
|
||||||
|
const waitHash = await d.text("#wait-tx-hash");
|
||||||
|
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
const outcome = await settleRequest(d, "tx");
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved",
|
||||||
|
"eth_sendTransaction did not resolve: " + JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
|
||||||
|
// The artifact as the node saw it, not as the extension described it.
|
||||||
|
assert(
|
||||||
|
env.server.broadcast.length === before + 1,
|
||||||
|
"expected exactly one raw transaction to reach the node, got " +
|
||||||
|
(env.server.broadcast.length - before),
|
||||||
|
);
|
||||||
|
const signed = Transaction.from(
|
||||||
|
env.server.broadcast[env.server.broadcast.length - 1],
|
||||||
|
);
|
||||||
|
console.log(
|
||||||
|
"# eth_sendTransaction: signer=" +
|
||||||
|
getAddress(signed.from) +
|
||||||
|
" to=" +
|
||||||
|
getAddress(signed.to) +
|
||||||
|
" value=" +
|
||||||
|
formatEther(signed.value) +
|
||||||
|
" chainId=" +
|
||||||
|
signed.chainId,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
getAddress(signed.from) === env.address,
|
||||||
|
"the broadcast transaction was signed by " +
|
||||||
|
getAddress(signed.from) +
|
||||||
|
", not by the approved address " +
|
||||||
|
env.address,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
getAddress(signed.to) === getAddress(STUB_COUNTERPARTY),
|
||||||
|
"the broadcast transaction goes to " + signed.to,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
signed.value === TX_VALUE_WEI,
|
||||||
|
"the broadcast transaction carries " +
|
||||||
|
formatEther(signed.value) +
|
||||||
|
" ETH, not the approved " +
|
||||||
|
TX_VALUE_ETH,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
signed.data === TX_DATA,
|
||||||
|
"the broadcast transaction carries different call data: " +
|
||||||
|
signed.data,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
signed.chainId === 1n,
|
||||||
|
"the broadcast transaction is for chain " + signed.chainId,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
outcome.result === signed.hash,
|
||||||
|
"the page received " +
|
||||||
|
outcome.result +
|
||||||
|
", not the hash of the broadcast transaction " +
|
||||||
|
signed.hash,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
waitHash.includes(signed.hash),
|
||||||
|
"the wait screen shows a different hash: " +
|
||||||
|
JSON.stringify(waitHash),
|
||||||
|
);
|
||||||
|
|
||||||
|
await d.switchToWindow(popup);
|
||||||
|
await d.closeWindow(env.dappWindow);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
step(
|
||||||
|
"closing an approval window rejects the request with 4001",
|
||||||
|
async (env) => {
|
||||||
|
const d = env.driver;
|
||||||
|
const before = env.server.broadcast.length;
|
||||||
|
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await startRequest(d, "sign-closed", "personal_sign", [
|
||||||
|
SIGN_HEX,
|
||||||
|
env.address,
|
||||||
|
]);
|
||||||
|
|
||||||
|
const popup = await waitForApprovalWindow(d);
|
||||||
|
await d.switchToWindow(popup);
|
||||||
|
await d.waitVisible("#view-approve-sign");
|
||||||
|
|
||||||
|
// Closed, not rejected: this is the windows.onRemoved path, which can
|
||||||
|
// only fire if windows.create() handed back a window id for the approval
|
||||||
|
// to be matched against — call site 4 in the issue, where the id used to
|
||||||
|
// be assigned from a callback the browser.* namespace never invoked.
|
||||||
|
await d.closeWindow(env.dappWindow);
|
||||||
|
|
||||||
|
await assertUserRejection(d, "sign-closed", "a closed approval window");
|
||||||
|
assert(
|
||||||
|
env.server.broadcast.length === before,
|
||||||
|
"a closed approval window still put a transaction on the node",
|
||||||
|
);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
// ------------------------------------------------------------- runner
|
// ------------------------------------------------------------- runner
|
||||||
|
|
||||||
|
// Uncaught extension errors that are known, tracked and deliberately
|
||||||
|
// tolerated, in the same spirit as ALLOWED_ERRORS in tests/e2e/harness.js:
|
||||||
|
// every entry names the issue that will delete it, and every occurrence is
|
||||||
|
// still printed, so tolerating one is visible in the log rather than silent.
|
||||||
|
// This is the only concession in an otherwise zero-tolerance policy.
|
||||||
|
const ALLOWED_ERRORS = [
|
||||||
|
{
|
||||||
|
// The site-connection buttons in src/popup/views/approval.js send
|
||||||
|
// their decision and call window.close() on the next line. Firefox's
|
||||||
|
// BaseContext.wrapPromise reports, through Cu.reportError, any
|
||||||
|
// extension-API promise that settles after its context unloaded —
|
||||||
|
// whether or not the caller attached a handler, so notify()'s catch
|
||||||
|
// cannot suppress it.
|
||||||
|
//
|
||||||
|
// Pre-existing, and not introduced by the promise shim: the send was
|
||||||
|
// already unawaited, and this suite is merely the first thing to
|
||||||
|
// drive that window on Firefox. It is the same teardown ordering as
|
||||||
|
// the issue below, whose fix — making the outcome independent of when
|
||||||
|
// the popup closes — removes this entry with it.
|
||||||
|
pattern: /Promise (?:resolved|rejected) after context unloaded/,
|
||||||
|
source: /\/src\/popup\/index\.js$/,
|
||||||
|
issue: "https://git.eeqj.de/sneak/AutistMask/issues/275",
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
function allowedFor(e) {
|
||||||
|
return ALLOWED_ERRORS.find(
|
||||||
|
(a) => a.pattern.test(e.msg) && a.source.test(e.src),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
function formatError(e) {
|
function formatError(e) {
|
||||||
return (
|
return (
|
||||||
e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")"
|
e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")"
|
||||||
@@ -165,6 +774,21 @@ async function main() {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Loopback survives --network none, so this is the http:// origin the
|
||||||
|
// dApp steps need and the node they talk to. Started before the browser
|
||||||
|
// so its url is available to the first step that asks for it.
|
||||||
|
let server;
|
||||||
|
try {
|
||||||
|
server = await startDappServer();
|
||||||
|
} catch (e) {
|
||||||
|
console.error(
|
||||||
|
"e2e-firefox: cannot serve the dApp fixture: " + e.message,
|
||||||
|
);
|
||||||
|
process.exitCode = 1;
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
console.log("# dapp fixture: " + server.url + " rpc " + server.rpcUrl);
|
||||||
|
|
||||||
let driver;
|
let driver;
|
||||||
try {
|
try {
|
||||||
driver = await start();
|
driver = await start();
|
||||||
@@ -175,12 +799,20 @@ async function main() {
|
|||||||
// absent suite. Never skip and report success.
|
// absent suite. Never skip and report success.
|
||||||
console.error("e2e-firefox: cannot run the suite: " + e.message);
|
console.error("e2e-firefox: cannot run the suite: " + e.message);
|
||||||
if (driver) await driver.quit().catch(() => {});
|
if (driver) await driver.quit().catch(() => {});
|
||||||
|
await server.close();
|
||||||
process.exitCode = 1;
|
process.exitCode = 1;
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
const errors = new ConsoleErrors(driver, EXTENSION_ORIGIN);
|
const errors = new ConsoleErrors(driver, EXTENSION_ORIGIN);
|
||||||
const env = { driver, phrase: null };
|
const env = {
|
||||||
|
driver,
|
||||||
|
server,
|
||||||
|
phrase: null,
|
||||||
|
address: null,
|
||||||
|
dappWindow: null,
|
||||||
|
popupWindow: null,
|
||||||
|
};
|
||||||
|
|
||||||
console.log("# extension origin: " + EXTENSION_ORIGIN);
|
console.log("# extension origin: " + EXTENSION_ORIGIN);
|
||||||
console.log("1.." + steps.length);
|
console.log("1.." + steps.length);
|
||||||
@@ -232,6 +864,20 @@ async function main() {
|
|||||||
installFailure = null;
|
installFailure = null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Tolerated errors are set aside, never dropped: each one is
|
||||||
|
// printed with the issue that keeps it on the list, so the
|
||||||
|
// concession stays in the run output.
|
||||||
|
const tolerated = found.filter((e) => allowedFor(e));
|
||||||
|
found = found.filter((e) => !allowedFor(e));
|
||||||
|
for (const e of tolerated) {
|
||||||
|
console.log(
|
||||||
|
"# tolerated (" +
|
||||||
|
allowedFor(e).issue +
|
||||||
|
"): " +
|
||||||
|
formatError(e),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Any uncaught error from an extension source fails the step
|
// Any uncaught error from an extension source fails the step
|
||||||
// that provoked it, whether or not its assertions passed.
|
// that provoked it, whether or not its assertions passed.
|
||||||
if (!failure && found.length > 0) {
|
if (!failure && found.length > 0) {
|
||||||
@@ -256,7 +902,13 @@ async function main() {
|
|||||||
// blamed on any one step, but they are still reported and they
|
// blamed on any one step, but they are still reported and they
|
||||||
// still fail the run.
|
// still fail the run.
|
||||||
await sleep(1000);
|
await sleep(1000);
|
||||||
const trailing = await errors.take();
|
const trailingAll = await errors.take();
|
||||||
|
for (const e of trailingAll.filter((x) => allowedFor(x))) {
|
||||||
|
console.log(
|
||||||
|
"# tolerated (" + allowedFor(e).issue + "): " + formatError(e),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
const trailing = trailingAll.filter((e) => !allowedFor(e));
|
||||||
console.log(
|
console.log(
|
||||||
"# " +
|
"# " +
|
||||||
(steps.length - failed) +
|
(steps.length - failed) +
|
||||||
@@ -273,12 +925,25 @@ async function main() {
|
|||||||
);
|
);
|
||||||
for (const e of trailing) console.log("# " + formatError(e));
|
for (const e of trailing) console.log("# " + formatError(e));
|
||||||
}
|
}
|
||||||
|
// A JSON-RPC method nothing answered means the extension asked the
|
||||||
|
// node something this fixture does not model, and whatever depended
|
||||||
|
// on the answer took the error branch instead. That is a hole in the
|
||||||
|
// fixture, not a pass.
|
||||||
|
if (server.unstubbed.length > 0) {
|
||||||
|
console.log(
|
||||||
|
"# FAILED: no fixture for JSON-RPC method(s) " +
|
||||||
|
[...new Set(server.unstubbed)].join(", "),
|
||||||
|
);
|
||||||
|
process.exitCode = 1;
|
||||||
|
}
|
||||||
|
|
||||||
if (failed > 0 || trailing.length > 0) {
|
if (failed > 0 || trailing.length > 0) {
|
||||||
console.log("# FAILED");
|
console.log("# FAILED");
|
||||||
process.exitCode = 1;
|
process.exitCode = 1;
|
||||||
}
|
}
|
||||||
} finally {
|
} finally {
|
||||||
await driver.quit().catch(() => {});
|
await driver.quit().catch(() => {});
|
||||||
|
await server.close();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -23,6 +23,8 @@
|
|||||||
|
|
||||||
"use strict";
|
"use strict";
|
||||||
|
|
||||||
|
const { Transaction } = require("ethers");
|
||||||
|
|
||||||
// Fictional ERC-20 used to seed the transaction-detail test. The symbol
|
// Fictional ERC-20 used to seed the transaction-detail test. The symbol
|
||||||
// must not collide with any entry in src/shared/tokenList.js, or
|
// must not collide with any entry in src/shared/tokenList.js, or
|
||||||
// isSpoofedSymbol() in src/shared/transactions.js drops the transfer as a
|
// isSpoofedSymbol() in src/shared/transactions.js drops the transfer as a
|
||||||
@@ -62,6 +64,94 @@ function word(value) {
|
|||||||
return "0x" + BigInt(value).toString(16).padStart(64, "0");
|
return "0x" + BigInt(value).toString(16).padStart(64, "0");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// -------------------------------------------------------- dApp fixture
|
||||||
|
//
|
||||||
|
// The origin the EIP-1193 test page is served from, and the page itself.
|
||||||
|
//
|
||||||
|
// It is a fixture like every other one in this file: the route handler
|
||||||
|
// fulfils the navigation from the string below, so the page never comes
|
||||||
|
// from a remote origin and nothing about the dApp round trips leaves the
|
||||||
|
// container. `.test` is reserved by RFC 6761 and has no owner to reach in
|
||||||
|
// the first place; the launch arguments map every host to NOTFOUND anyway.
|
||||||
|
//
|
||||||
|
// What the page deliberately does NOT do is load a provider. window.ethereum
|
||||||
|
// is put there by the shipped manifest's MAIN-world content script, exactly
|
||||||
|
// as it is on any http(s) page a user visits, so what these tests speak to
|
||||||
|
// is the real inpage provider and not a copy the harness wired up.
|
||||||
|
//
|
||||||
|
// DAPP_HTML below is exported and served verbatim by the Firefox suite too
|
||||||
|
// (tests/e2e/firefox/dapp.js), from a loopback origin rather than through a
|
||||||
|
// route handler. The two suites drive different browsers over different
|
||||||
|
// protocols, but the page they drive — the __dapp API, the message log — is
|
||||||
|
// one fixture, so an assertion written against it means the same thing on
|
||||||
|
// both.
|
||||||
|
const DAPP_ORIGIN = "https://dapp.e2e.test";
|
||||||
|
const DAPP_URL = DAPP_ORIGIN + "/";
|
||||||
|
|
||||||
|
// Requests are parked rather than awaited. An approval prompt only exists
|
||||||
|
// while its call is in flight, so a test that awaited the promise could
|
||||||
|
// never drive the popup that has to settle it; start() files the promise
|
||||||
|
// under a key and settle() collects it once the prompt has been dealt with.
|
||||||
|
//
|
||||||
|
// The rejection branch records the whole observable shape of the error as it
|
||||||
|
// arrives — name, message, and whether a `code` is present at all as distinct
|
||||||
|
// from its value. EIP-1193 says a user rejection is a ProviderRpcError
|
||||||
|
// carrying code 4001; what the page can actually see is recorded here rather
|
||||||
|
// than assumed, and asserted in run.js.
|
||||||
|
//
|
||||||
|
// The message log is the page's half of the boundary observation: every
|
||||||
|
// AUTISTMASK_* message that crosses between this page and the content
|
||||||
|
// script, in both directions, verbatim.
|
||||||
|
const DAPP_HTML = [
|
||||||
|
"<!doctype html>",
|
||||||
|
'<html lang="en">',
|
||||||
|
"<head>",
|
||||||
|
'<meta charset="utf-8">',
|
||||||
|
"<title>AutistMask e2e dApp</title>",
|
||||||
|
// Inline and empty: without it Chromium asks for /favicon.ico, which
|
||||||
|
// the unstubbed-request guard would report as escaping traffic.
|
||||||
|
'<link rel="icon" href="data:,">',
|
||||||
|
"</head>",
|
||||||
|
"<body>",
|
||||||
|
"<h1>AutistMask e2e dApp</h1>",
|
||||||
|
"<script>",
|
||||||
|
"window.__dapp = {",
|
||||||
|
" messages: [],",
|
||||||
|
" calls: {},",
|
||||||
|
" start: function (key, method, params) {",
|
||||||
|
" window.__dapp.calls[key] = window.ethereum",
|
||||||
|
" .request({ method: method, params: params })",
|
||||||
|
" .then(",
|
||||||
|
" function (result) {",
|
||||||
|
" return { settled: 'resolved', result: result };",
|
||||||
|
" },",
|
||||||
|
" function (error) {",
|
||||||
|
" return {",
|
||||||
|
" settled: 'rejected',",
|
||||||
|
" message: String((error && error.message) || error),",
|
||||||
|
" name: error ? error.name : undefined,",
|
||||||
|
" hasCode: !!error && 'code' in Object(error),",
|
||||||
|
" code: error ? error.code : undefined,",
|
||||||
|
" };",
|
||||||
|
" },",
|
||||||
|
" );",
|
||||||
|
" },",
|
||||||
|
" settle: function (key) {",
|
||||||
|
" return window.__dapp.calls[key];",
|
||||||
|
" },",
|
||||||
|
"};",
|
||||||
|
"window.addEventListener('message', function (event) {",
|
||||||
|
" if (event.source !== window) return;",
|
||||||
|
" var d = event.data;",
|
||||||
|
" if (!d || typeof d.type !== 'string') return;",
|
||||||
|
" if (d.type.indexOf('AUTISTMASK') !== 0) return;",
|
||||||
|
" window.__dapp.messages.push(d);",
|
||||||
|
"});",
|
||||||
|
"</script>",
|
||||||
|
"</body>",
|
||||||
|
"</html>",
|
||||||
|
].join("\n");
|
||||||
|
|
||||||
// ------------------------------------------------------------ fee fixture
|
// ------------------------------------------------------------ fee fixture
|
||||||
//
|
//
|
||||||
// The confirmation screen carries two different numbers for the same
|
// The confirmation screen carries two different numbers for the same
|
||||||
@@ -101,6 +191,11 @@ const RPC_RESULTS = {
|
|||||||
eth_estimateGas: hex(GAS_LIMIT),
|
eth_estimateGas: hex(GAS_LIMIT),
|
||||||
eth_getTransactionCount: "0x0",
|
eth_getTransactionCount: "0x0",
|
||||||
eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI),
|
eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI),
|
||||||
|
// "not mined yet", which is what a node answers for a transaction it has
|
||||||
|
// only just accepted. The wait screen the dApp transaction approval hands
|
||||||
|
// off to polls this every 10 seconds; leaving it unstubbed would report
|
||||||
|
// the poll as escaping traffic the moment a test outlived one tick.
|
||||||
|
eth_getTransactionReceipt: null,
|
||||||
};
|
};
|
||||||
|
|
||||||
// The "latest" block, which ethers' getFeeData() reads baseFeePerGas from
|
// The "latest" block, which ethers' getFeeData() reads baseFeePerGas from
|
||||||
@@ -264,6 +359,31 @@ function rpcReply(req, opts, report) {
|
|||||||
if (req.method === "eth_getBlockByNumber") {
|
if (req.method === "eth_getBlockByNumber") {
|
||||||
return Object.assign(envelope, { result: latestBlock() });
|
return Object.assign(envelope, { result: latestBlock() });
|
||||||
}
|
}
|
||||||
|
// The end of the dApp transaction round trip: the raw signed transaction
|
||||||
|
// the background hands to the node. It is recorded verbatim so a test can
|
||||||
|
// recover the signer from the exact bytes that were broadcast, rather than
|
||||||
|
// from anything the extension reported about them.
|
||||||
|
//
|
||||||
|
// The reply must be the transaction's real hash. ethers compares the hash
|
||||||
|
// the node returns against the one it computes itself and throws on a
|
||||||
|
// mismatch, so a constant here would fail the broadcast for a reason that
|
||||||
|
// has nothing to do with what is being tested.
|
||||||
|
if (req.method === "eth_sendRawTransaction") {
|
||||||
|
const raw = Array.isArray(req.params) ? req.params[0] : null;
|
||||||
|
let parsed;
|
||||||
|
try {
|
||||||
|
parsed = Transaction.from(raw);
|
||||||
|
} catch {
|
||||||
|
report("eth_sendRawTransaction with an undecodable transaction");
|
||||||
|
return Object.assign(envelope, {
|
||||||
|
error: { code: -32000, message: "undecodable transaction" },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
if (Array.isArray(opts.broadcastTransactions)) {
|
||||||
|
opts.broadcastTransactions.push(raw);
|
||||||
|
}
|
||||||
|
return Object.assign(envelope, { result: parsed.hash });
|
||||||
|
}
|
||||||
if (req.method === "eth_estimateGas" && opts.failGasEstimate) {
|
if (req.method === "eth_estimateGas" && opts.failGasEstimate) {
|
||||||
// A refusal the node itself would produce, not a transport error:
|
// A refusal the node itself would produce, not a transport error:
|
||||||
// this is the shape the confirmation screen has to turn into
|
// this is the shape the confirmation screen has to turn into
|
||||||
@@ -375,6 +495,8 @@ function traceEnabled(raw) {
|
|||||||
* node-side refusal.
|
* node-side refusal.
|
||||||
* @param {boolean} [opts.holdGasEstimate] hold every batch containing an
|
* @param {boolean} [opts.holdGasEstimate] hold every batch containing an
|
||||||
* eth_estimateGas until this is cleared again.
|
* eth_estimateGas until this is cleared again.
|
||||||
|
* @param {string[]} [opts.broadcastTransactions] every raw signed
|
||||||
|
* transaction handed to eth_sendRawTransaction, appended in order.
|
||||||
* @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) =>
|
* @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) =>
|
||||||
* Promise<string|null>}>}
|
* Promise<string|null>}>}
|
||||||
*/
|
*/
|
||||||
@@ -420,6 +542,18 @@ async function installNetworkStubs(ctx, opts) {
|
|||||||
return handleRpc(route, req.postData(), opts, report);
|
return handleRpc(route, req.postData(), opts, report);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The local EIP-1193 test page. Served from here so the dApp round
|
||||||
|
// trips run against a real http(s) origin — which is what makes the
|
||||||
|
// shipped content scripts inject at all — without any remote origin
|
||||||
|
// being involved.
|
||||||
|
if (url.origin === DAPP_ORIGIN && p === "/") {
|
||||||
|
return route.fulfill({
|
||||||
|
status: 200,
|
||||||
|
contentType: "text/html; charset=utf-8",
|
||||||
|
body: DAPP_HTML,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Blockscout v2
|
// Blockscout v2
|
||||||
if (p.includes("/api/v2/")) {
|
if (p.includes("/api/v2/")) {
|
||||||
if (/\/addresses\/0x[0-9a-fA-F]{40}\/transactions$/.test(p)) {
|
if (/\/addresses\/0x[0-9a-fA-F]{40}\/transactions$/.test(p)) {
|
||||||
@@ -508,6 +642,9 @@ async function installNetworkStubs(ctx, opts) {
|
|||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
installNetworkStubs,
|
installNetworkStubs,
|
||||||
|
DAPP_HTML,
|
||||||
|
DAPP_ORIGIN,
|
||||||
|
DAPP_URL,
|
||||||
FEE_ESTIMATE_WEI,
|
FEE_ESTIMATE_WEI,
|
||||||
FEE_RESERVE_WEI,
|
FEE_RESERVE_WEI,
|
||||||
STUB_COUNTERPARTY,
|
STUB_COUNTERPARTY,
|
||||||
|
|||||||
1002
tests/e2e/run.js
1002
tests/e2e/run.js
File diff suppressed because it is too large
Load Diff
310
tests/inpageErrors.test.js
Normal file
310
tests/inpageErrors.test.js
Normal file
@@ -0,0 +1,310 @@
|
|||||||
|
// The EIP-1193 error the page actually catches (src/content/inpage.js).
|
||||||
|
//
|
||||||
|
// The bug this pins down (issue #274): the provider rebuilt every failure as
|
||||||
|
// `new Error(error.message)`, so the `code` the background produced and the
|
||||||
|
// content script relayed intact was thrown away in the last hop. A dApp
|
||||||
|
// checking `err.code === 4001` — the standard way to tell "the user said no"
|
||||||
|
// from "the wallet broke" — saw undefined, and well-behaved sites showed an
|
||||||
|
// error or retried instead of accepting the refusal.
|
||||||
|
//
|
||||||
|
// inpage.js is a bare IIFE injected into the page's JS context, not a module:
|
||||||
|
// it takes no import and exports nothing, and reaches for `window` at load.
|
||||||
|
// So it is evaluated here the way the browser evaluates it, against a stub
|
||||||
|
// window, and the provider is collected from `window.ethereum`. The globals it
|
||||||
|
// touches are passed in as function parameters rather than assigned to
|
||||||
|
// globalThis: nothing leaks between tests, and the source is compiled in this
|
||||||
|
// realm, so the errors it constructs are comparable against this file's own
|
||||||
|
// `Error` — which a second realm's intrinsics would silently defeat.
|
||||||
|
//
|
||||||
|
// There is no jsdom in this repo; see tests/txStatus.test.js.
|
||||||
|
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
const { webcrypto } = require("crypto");
|
||||||
|
|
||||||
|
const SOURCE = fs.readFileSync(
|
||||||
|
path.join(__dirname, "..", "src", "content", "inpage.js"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
|
||||||
|
const loadInto = new Function(
|
||||||
|
"window",
|
||||||
|
"self",
|
||||||
|
"crypto",
|
||||||
|
"Event",
|
||||||
|
"CustomEvent",
|
||||||
|
SOURCE,
|
||||||
|
);
|
||||||
|
|
||||||
|
class StubEvent {
|
||||||
|
constructor(type) {
|
||||||
|
this.type = type;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
class StubCustomEvent extends StubEvent {
|
||||||
|
constructor(type, init) {
|
||||||
|
super(type);
|
||||||
|
this.detail = init && init.detail;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Every code the background emits on the RPC path today, read out of
|
||||||
|
// src/background/index.js. The provider must not know this list — it passes
|
||||||
|
// through whatever arrived — but the cases below are the real ones.
|
||||||
|
const REJECTED = 4001; // user rejected the request
|
||||||
|
const UNAUTHORIZED = 4100; // site not connected / wrong address
|
||||||
|
const UNRECOGNIZED_CHAIN = 4902; // switch/add to an unsupported chain
|
||||||
|
|
||||||
|
// A stub window with the four things inpage.js touches: message listeners,
|
||||||
|
// postMessage out to the content script, window.ethereum, and dispatchEvent
|
||||||
|
// for the EIP-6963 announcement.
|
||||||
|
function loadProvider() {
|
||||||
|
const messageListeners = [];
|
||||||
|
const posted = [];
|
||||||
|
|
||||||
|
const win = {
|
||||||
|
addEventListener(type, fn) {
|
||||||
|
if (type === "message") messageListeners.push(fn);
|
||||||
|
},
|
||||||
|
removeEventListener(type, fn) {
|
||||||
|
const i = messageListeners.indexOf(fn);
|
||||||
|
if (type === "message" && i !== -1) messageListeners.splice(i, 1);
|
||||||
|
},
|
||||||
|
postMessage(data) {
|
||||||
|
posted.push(data);
|
||||||
|
},
|
||||||
|
dispatchEvent() {
|
||||||
|
return true;
|
||||||
|
},
|
||||||
|
};
|
||||||
|
win.window = win;
|
||||||
|
|
||||||
|
loadInto(win, win, webcrypto, StubEvent, StubCustomEvent);
|
||||||
|
|
||||||
|
// Deliver the content script's answer to an outstanding request. The id is
|
||||||
|
// read back off the wire rather than assumed: inpage.js issues its own
|
||||||
|
// eth_chainId at load, so the first id a test sees is not 1.
|
||||||
|
function respond(response) {
|
||||||
|
const request = posted
|
||||||
|
.filter((m) => m.type === "AUTISTMASK_REQUEST")
|
||||||
|
.pop();
|
||||||
|
expect(request).toBeDefined();
|
||||||
|
const event = {
|
||||||
|
source: win,
|
||||||
|
data: { type: "AUTISTMASK_RESPONSE", id: request.id, ...response },
|
||||||
|
};
|
||||||
|
for (const fn of messageListeners.slice()) fn(event);
|
||||||
|
}
|
||||||
|
|
||||||
|
return { provider: win.ethereum, posted, respond };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Start a request, answer it with `response`, and hand back the rejection.
|
||||||
|
// Fails the test if the call resolves instead.
|
||||||
|
async function rejectionFrom(start, response) {
|
||||||
|
const { provider, respond } = loadProvider();
|
||||||
|
const settled = start(provider).then(
|
||||||
|
(result) => ({ resolved: result }),
|
||||||
|
(error) => ({ error }),
|
||||||
|
);
|
||||||
|
// The provider posts synchronously, so the request is already on the wire.
|
||||||
|
respond(response);
|
||||||
|
const outcome = await settled;
|
||||||
|
expect(outcome).not.toHaveProperty("resolved");
|
||||||
|
return outcome.error;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("an EIP-1193 code reaches the page", () => {
|
||||||
|
test("a user rejection arrives as code 4001", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_requestAccounts" }),
|
||||||
|
{
|
||||||
|
error: {
|
||||||
|
code: REJECTED,
|
||||||
|
message: "User rejected the request.",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
expect(err.message).toBe("User rejected the request.");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("it is a ProviderRpcError, and an Error", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_requestAccounts" }),
|
||||||
|
{
|
||||||
|
error: {
|
||||||
|
code: REJECTED,
|
||||||
|
message: "User rejected the request.",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
expect(err).toBeInstanceOf(Error);
|
||||||
|
expect(err.name).toBe("ProviderRpcError");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("4100 unauthorized arrives intact", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "personal_sign", params: ["0x00"] }),
|
||||||
|
{ error: { code: UNAUTHORIZED, message: "Unauthorized" } },
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(UNAUTHORIZED);
|
||||||
|
expect(err.message).toBe("Unauthorized");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("4902 unrecognized chain arrives intact", async () => {
|
||||||
|
const message =
|
||||||
|
"AutistMask supports Ethereum Mainnet and Sepolia Testnet only.";
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "wallet_switchEthereumChain" }),
|
||||||
|
{ error: { code: UNRECOGNIZED_CHAIN, message } },
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(UNRECOGNIZED_CHAIN);
|
||||||
|
expect(err.message).toBe(message);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The provider is not allowed to know the list above: a code added to the
|
||||||
|
// background later must reach the page without this file being edited.
|
||||||
|
test("a code the provider has never heard of is passed through", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_accounts" }),
|
||||||
|
{ error: { code: 4900, message: "Disconnected" } },
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(4900);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("data is carried when the boundary sent it", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_call" }),
|
||||||
|
{
|
||||||
|
error: {
|
||||||
|
code: -32000,
|
||||||
|
message: "execution reverted",
|
||||||
|
data: "0x08c379a0",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(-32000);
|
||||||
|
expect(err.data).toBe("0x08c379a0");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("no data property is invented when the boundary sent none", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_requestAccounts" }),
|
||||||
|
{
|
||||||
|
error: {
|
||||||
|
code: REJECTED,
|
||||||
|
message: "User rejected the request.",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
expect("data" in err).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the message is untouched", () => {
|
||||||
|
test("a coded error keeps the message byte for byte", async () => {
|
||||||
|
const message =
|
||||||
|
"This site asked to sign as an address that is not " +
|
||||||
|
"the active one.";
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "personal_sign" }),
|
||||||
|
{ error: { code: UNAUTHORIZED, message } },
|
||||||
|
);
|
||||||
|
expect(err.message).toBe(message);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an error the background sent with no code keeps its message", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_sendTransaction" }),
|
||||||
|
{ error: { message: "No accounts available" } },
|
||||||
|
);
|
||||||
|
expect(err.message).toBe("No accounts available");
|
||||||
|
});
|
||||||
|
|
||||||
|
// A ProviderRpcError whose code is undefined would claim a conformance it
|
||||||
|
// does not have, and `'code' in err` is exactly what a careful dApp asks.
|
||||||
|
test("an error with no code gets no code property at all", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_sendTransaction" }),
|
||||||
|
{ error: { message: "No accounts available" } },
|
||||||
|
);
|
||||||
|
expect(err).toBeInstanceOf(Error);
|
||||||
|
expect("code" in err).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an error with no message keeps the generic fallback", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_sendTransaction" }),
|
||||||
|
{ error: { code: REJECTED } },
|
||||||
|
);
|
||||||
|
expect(err.message).toBe("Request failed");
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// Every entry point the provider exposes, not just eth_requestAccounts. They
|
||||||
|
// all funnel through the same response listener, and this is what says so.
|
||||||
|
describe("every request path carries the code", () => {
|
||||||
|
const rejection = {
|
||||||
|
error: { code: REJECTED, message: "User rejected the request." },
|
||||||
|
};
|
||||||
|
|
||||||
|
test("request()", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method: "eth_requestAccounts" }),
|
||||||
|
rejection,
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("enable()", async () => {
|
||||||
|
const err = await rejectionFrom((p) => p.enable(), rejection);
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("send(method, params)", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.send("eth_requestAccounts", []),
|
||||||
|
rejection,
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("send({ method, params })", async () => {
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.send({ method: "personal_sign", params: ["0x00"] }),
|
||||||
|
rejection,
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("sendAsync() hands the code to its callback", async () => {
|
||||||
|
const { provider, respond } = loadProvider();
|
||||||
|
const called = new Promise((resolve) => {
|
||||||
|
provider.sendAsync({ id: 1, method: "eth_requestAccounts" }, (e) =>
|
||||||
|
resolve(e),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
respond(rejection);
|
||||||
|
const err = await called;
|
||||||
|
expect(err.name).toBe("ProviderRpcError");
|
||||||
|
expect(err.code).toBe(REJECTED);
|
||||||
|
expect(err.message).toBe("User rejected the request.");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the success path is unchanged", () => {
|
||||||
|
test("a result still resolves", async () => {
|
||||||
|
const { provider, respond } = loadProvider();
|
||||||
|
const settled = provider.request({ method: "eth_requestAccounts" });
|
||||||
|
respond({ result: ["0xb61264DEFB0c4B8afb3D73724be15310036743a5"] });
|
||||||
|
await expect(settled).resolves.toEqual([
|
||||||
|
"0xb61264DEFB0c4B8afb3D73724be15310036743a5",
|
||||||
|
]);
|
||||||
|
expect(provider.selectedAddress).toBe(
|
||||||
|
"0xb61264DEFB0c4B8afb3D73724be15310036743a5",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -56,7 +56,7 @@ global.chrome = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const { isSpoofedSymbol } = require("../src/shared/symbolSpoof");
|
const { isSpoofedSymbol } = require("../src/shared/symbolSpoof");
|
||||||
const { KNOWN_SYMBOLS } = require("../src/shared/tokenList");
|
const { TOKENS, KNOWN_SYMBOLS } = require("../src/shared/tokenList");
|
||||||
const { filterTransactions } = require("../src/shared/transactions");
|
const { filterTransactions } = require("../src/shared/transactions");
|
||||||
const {
|
const {
|
||||||
fetchTokenBalances,
|
fetchTokenBalances,
|
||||||
@@ -124,6 +124,301 @@ describe("the shared rule", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Issue #260: the symbol is whatever the ERC-20 contract returns, and HTML
|
||||||
|
// collapses leading and trailing whitespace, so a token calling itself
|
||||||
|
// `" ETH "` reaches the user's eye as `ETH` while missing a raw
|
||||||
|
// KNOWN_SYMBOLS lookup. Normalizing inside the shared rule fixes all three
|
||||||
|
// surfaces at once, which is what consolidating the rule bought.
|
||||||
|
//
|
||||||
|
// Every character under test here is built from its code point rather than
|
||||||
|
// pasted in: most of them are invisible, and an invisible character in a
|
||||||
|
// test file is unreviewable.
|
||||||
|
const cp = (...codes) => String.fromCodePoint(...codes);
|
||||||
|
const NBSP = cp(0x00a0); // no-break space
|
||||||
|
const FIGURE_SPACE = cp(0x2007);
|
||||||
|
const IDEOGRAPHIC_SPACE = cp(0x3000);
|
||||||
|
const ZWSP = cp(0x200b); // zero-width space
|
||||||
|
const BOM = cp(0xfeff); // zero-width no-break space
|
||||||
|
const WORD_JOINER = cp(0x2060);
|
||||||
|
const SOFT_HYPHEN = cp(0x00ad);
|
||||||
|
const LRM = cp(0x200e); // left-to-right mark
|
||||||
|
const RLO = cp(0x202e); // right-to-left override
|
||||||
|
const HANGUL_FILLER = cp(0x3164);
|
||||||
|
const CHOSEONG_FILLER = cp(0x115f);
|
||||||
|
const VS16 = cp(0xfe0f); // variation selector-16
|
||||||
|
const VS1 = cp(0xfe00); // variation selector-1
|
||||||
|
const NEL = cp(0x0085); // next line, a C1 control
|
||||||
|
const DEL = cp(0x007f);
|
||||||
|
const FULLWIDTH_ETH = cp(0xff25, 0xff34, 0xff28);
|
||||||
|
const FULLWIDTH_USDC = cp(0xff55, 0xff53, 0xff44, 0xff43); // lowercase
|
||||||
|
const CYRILLIC_CAPITAL_IE = cp(0x0415);
|
||||||
|
|
||||||
|
describe("the shared rule: symbols that render as a known symbol", () => {
|
||||||
|
test("ASCII padding does not buy a pass", () => {
|
||||||
|
expect(isSpoofedSymbol(" ETH ", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
expect(isSpoofedSymbol("\tETH\n", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
expect(isSpoofedSymbol(" usdc ", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("non-breaking and other Unicode spaces do not either", () => {
|
||||||
|
expect(isSpoofedSymbol(NBSP + "ETH" + NBSP, FAKE_ETH_CONTRACT)).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
expect(
|
||||||
|
isSpoofedSymbol(
|
||||||
|
FIGURE_SPACE + "ETH" + IDEOGRAPHIC_SPACE,
|
||||||
|
FAKE_ETH_CONTRACT,
|
||||||
|
),
|
||||||
|
).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// These render as nothing at all, in any position, so they are removed
|
||||||
|
// wherever they sit rather than only at the ends.
|
||||||
|
test("zero-width characters are stripped wherever they sit", () => {
|
||||||
|
expect(isSpoofedSymbol("E" + ZWSP + "TH", FAKE_ETH_CONTRACT)).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
expect(isSpoofedSymbol(BOM + "ETH", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
expect(
|
||||||
|
isSpoofedSymbol("ET" + WORD_JOINER + "H", FAKE_ETH_CONTRACT),
|
||||||
|
).toBe(true);
|
||||||
|
expect(
|
||||||
|
isSpoofedSymbol("E" + SOFT_HYPHEN + "TH", FAKE_ETH_CONTRACT),
|
||||||
|
).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// An LRM is invisible and, in all-Latin text, moves nothing: dropping it
|
||||||
|
// leaves exactly the string the user saw.
|
||||||
|
test("an invisible bidi mark does not hide a known symbol", () => {
|
||||||
|
expect(isSpoofedSymbol(LRM + "ETH", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Invisibility is not confined to \p{Cf}. A Hangul filler is Lo and a
|
||||||
|
// variation selector is Mn, yet each of these four measures 32.00px in
|
||||||
|
// the repo's pinned e2e Chromium at 16px sans-serif — exactly the width
|
||||||
|
// of a plain `ETH` — so each reaches the user's eye as `ETH`. They are
|
||||||
|
// caught by \p{Default_Ignorable_Code_Point}, not by \p{Cf}.
|
||||||
|
test("invisible non-format characters are stripped too", () => {
|
||||||
|
expect(isSpoofedSymbol(HANGUL_FILLER + "ETH", FAKE_ETH_CONTRACT)).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
expect(
|
||||||
|
isSpoofedSymbol(CHOSEONG_FILLER + "ETH", FAKE_ETH_CONTRACT),
|
||||||
|
).toBe(true);
|
||||||
|
expect(isSpoofedSymbol("ETH" + VS16, FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
expect(isSpoofedSymbol("E" + VS1 + "TH", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Nor is it confined to the Unicode classes. U+007F is a control (Cc)
|
||||||
|
// and is not default-ignorable, so neither class reaches it, but it
|
||||||
|
// measures 32.00px in the same browser — it paints nothing, so a
|
||||||
|
// symbol carrying it reaches the eye as `ETH`. It is named on its own
|
||||||
|
// in the strip for exactly that reason.
|
||||||
|
test("U+007F paints nothing and is stripped", () => {
|
||||||
|
expect(isSpoofedSymbol(DEL + "ETH", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The other side of the boundary, which is not the class boundary but
|
||||||
|
// the visibility one: the remaining C0 and C1 controls render as a
|
||||||
|
// visible 48.00px box in the same browser, so a symbol carrying one
|
||||||
|
// does not look like `ETH` and must not be judged a spoof. Widening
|
||||||
|
// the strip to \p{Cc} — the obvious over-correction once U+007F is in
|
||||||
|
// it — fails this test.
|
||||||
|
test("visible control characters do not make a symbol a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol(NEL + "ETH", FAKE_ETH_CONTRACT)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol(cp(0x0001) + "ETH", FAKE_ETH_CONTRACT)).toBe(
|
||||||
|
false,
|
||||||
|
);
|
||||||
|
expect(isSpoofedSymbol(cp(0x0090) + "ETH", FAKE_ETH_CONTRACT)).toBe(
|
||||||
|
false,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("compatibility forms fold onto the symbol they imitate", () => {
|
||||||
|
expect(isSpoofedSymbol(FULLWIDTH_ETH, FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
expect(isSpoofedSymbol(FULLWIDTH_USDC, FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The two knowingly open classes, asserted here so that the boundary is
|
||||||
|
// a fact in the suite and not a claim in a PR body. A Cyrillic capital
|
||||||
|
// Ie is a distinct letter rather than a compatibility variant, so NFKC
|
||||||
|
// leaves it alone; and a right-to-left override reverses the rendering
|
||||||
|
// of what follows it, which dropping the control character does not
|
||||||
|
// undo. Closing either needs a confusables table or a bidi resolver,
|
||||||
|
// and both are a separate change from this one.
|
||||||
|
test("a Cyrillic homoglyph is knowingly still not caught", () => {
|
||||||
|
expect(
|
||||||
|
isSpoofedSymbol(CYRILLIC_CAPITAL_IE + "TH", FAKE_ETH_CONTRACT),
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a bidi-reordered symbol is knowingly still not caught", () => {
|
||||||
|
expect(isSpoofedSymbol(RLO + "HTE", FAKE_ETH_CONTRACT)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Normalization does not reach the native-asset exemption, which turns
|
||||||
|
// on the absence of a contract address and never on the symbol.
|
||||||
|
test("a padded symbol with no contract is still not a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol(" ETH ", null)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol(NBSP + "ETH", "")).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a genuine contract still bears its own padded symbol", () => {
|
||||||
|
expect(isSpoofedSymbol(" USDC ", USDC_CONTRACT)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol(ZWSP + "WETH", WETH_CONTRACT)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Normalization must not invent a match. Interior ASCII whitespace is
|
||||||
|
// left alone: `E T H` renders as `E T H`, not as `ETH`, so folding it
|
||||||
|
// would filter a token no user could confuse with the native asset.
|
||||||
|
test("a symbol that renders differently is not judged a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol("E T H", FAKE_ETH_CONTRACT)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol("ETH2", FAKE_ETH_CONTRACT)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol("MY ETH", FAKE_ETH_CONTRACT)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The false-positive question, answered against the shipped data rather
|
||||||
|
// than by assertion: no bundled symbol carries whitespace or a
|
||||||
|
// non-ASCII character, so the normalization cannot newly filter one.
|
||||||
|
// The character class starts at `!` rather than at the space so that it
|
||||||
|
// asserts the claim it stands for — `[ -~]` would admit an interior
|
||||||
|
// space and let a whitespace-bearing entry through the guard.
|
||||||
|
test("no bundled symbol is touched by the normalization", () => {
|
||||||
|
for (const [symbol, addresses] of KNOWN_SYMBOLS) {
|
||||||
|
expect(symbol).toBe(symbol.trim());
|
||||||
|
expect(symbol).toMatch(/^[!-~]+$/);
|
||||||
|
if (addresses === null) continue;
|
||||||
|
for (const address of addresses) {
|
||||||
|
expect(isSpoofedSymbol(symbol, address)).toBe(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// Issue #276: the guard that was missing. The suite walked KNOWN_SYMBOLS,
|
||||||
|
// which is built from TOKENS, so it could only ever assert that the table
|
||||||
|
// agrees with itself. Seven symbols appear twice in the bundled list at two
|
||||||
|
// different real contracts, and the table kept whichever came first, so the
|
||||||
|
// other seven contracts — tokens in our own shipped list, at their own
|
||||||
|
// addresses — were judged spoofs and hidden from the balance list, the
|
||||||
|
// history and the send selector. That is the over-filtering direction: it
|
||||||
|
// hides a holding the user cannot then spend.
|
||||||
|
//
|
||||||
|
// This walk is over TOKENS, the data the wallet actually ships, so it fails
|
||||||
|
// whenever a bundled token would be filtered at its own address no matter
|
||||||
|
// which side of the table the mistake is on.
|
||||||
|
describe("the shipped token list", () => {
|
||||||
|
test("no bundled token is filtered at its own address", () => {
|
||||||
|
const filtered = TOKENS.filter((t) =>
|
||||||
|
isSpoofedSymbol(t.symbol, t.address),
|
||||||
|
).map((t) => t.symbol + " @ " + t.address);
|
||||||
|
expect(filtered).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The third failure mode the issue asks about: a symbol whose table entry
|
||||||
|
// names an address that is in neither the table nor the list would be a
|
||||||
|
// contract we vouch for and do not ship. There is none, and the table is
|
||||||
|
// built from the list, so this asserts the derivation has not acquired a
|
||||||
|
// hand-written entry.
|
||||||
|
test("every address the table vouches for is a bundled token", () => {
|
||||||
|
const bundled = new Set(TOKENS.map((t) => t.address.toLowerCase()));
|
||||||
|
for (const [symbol, addresses] of KNOWN_SYMBOLS) {
|
||||||
|
if (addresses === null) continue;
|
||||||
|
expect(addresses.size).toBeGreaterThan(0);
|
||||||
|
for (const address of addresses) {
|
||||||
|
expect(address).toBe(address.toLowerCase());
|
||||||
|
expect(bundled.has(address)).toBe(true);
|
||||||
|
// And it is the token that actually reports that symbol.
|
||||||
|
const token = TOKENS.find(
|
||||||
|
(t) => t.address.toLowerCase() === address,
|
||||||
|
);
|
||||||
|
expect(token.symbol.toUpperCase()).toBe(symbol);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// Both contracts behind a shared ticker must pass, from either side: a
|
||||||
|
// rule that admits only the one the table happens to visit first is the
|
||||||
|
// bug, not the fix.
|
||||||
|
test("both contracts behind a shared ticker are admitted", () => {
|
||||||
|
const bySymbol = new Map();
|
||||||
|
for (const t of TOKENS) {
|
||||||
|
const upper = t.symbol.toUpperCase();
|
||||||
|
if (!bySymbol.has(upper)) bySymbol.set(upper, []);
|
||||||
|
bySymbol.get(upper).push(t);
|
||||||
|
}
|
||||||
|
const shared = [...bySymbol].filter(([, list]) => list.length > 1);
|
||||||
|
// The shared tickers are a fact about the shipped data; if a future
|
||||||
|
// list has none, this test would silently assert nothing.
|
||||||
|
expect(shared.length).toBeGreaterThan(0);
|
||||||
|
for (const [, list] of shared) {
|
||||||
|
for (const t of list) {
|
||||||
|
expect(isSpoofedSymbol(t.symbol, t.address)).toBe(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// The seven from issue #276, named so that the reconciliation is a fact
|
||||||
|
// in the suite: each is two real contracts from the same source fetch,
|
||||||
|
// and the table now holds both rather than the one that came first.
|
||||||
|
test("the seven shared tickers each name both bundled contracts", () => {
|
||||||
|
const expected = {
|
||||||
|
TON: [
|
||||||
|
"0x582d872a1b094fc48f5de31d3b73f2d9be47def1", // Toncoin
|
||||||
|
"0x2be5e8c109e2197d077d13a82daead6a9b3433c5", // Tokamak Network
|
||||||
|
],
|
||||||
|
FRAX: [
|
||||||
|
"0x853d955acef822db058eb8505911ed77f175b99e", // Legacy Frax Dollar
|
||||||
|
"0x3432b6a60d23ca0dfca7761b7ab56459d9c964d0", // Frax (prev. FXS)
|
||||||
|
],
|
||||||
|
REUSD: [
|
||||||
|
"0x5086bf358635b81d8c47c66d1c8b9e567db70c72", // Re Protocol reUSD
|
||||||
|
"0x57ab1e0003f623289cd798b1824be09a793e4bec", // Resupply USD
|
||||||
|
],
|
||||||
|
EURE: [
|
||||||
|
"0x39b8b6385416f4ca36a20319f70d28621895279d", // Monerium EUR emoney
|
||||||
|
"0x3231cb76718cdef2155fc47b5286d82e6eda273f", // Monerium EUR emoney [OLD]
|
||||||
|
],
|
||||||
|
MSUSD: [
|
||||||
|
"0x4ba01f22827018b4772cd326c7627fb4956a7c00", // Main Street USD
|
||||||
|
"0xab5eb14c09d416f0ac63661e57edb7aecdb9befa", // Metronome Synth USD
|
||||||
|
],
|
||||||
|
MUSD: [
|
||||||
|
"0xaca92e438df0b2401ff60da7e4337b687a2435da", // MetaMask USD
|
||||||
|
"0xdd468a1ddc392dcdbef6db6e34e89aa338f9f186", // Mezo USD
|
||||||
|
],
|
||||||
|
JPYC: [
|
||||||
|
"0x431d5dff03120afa4bdf332c61a6e1766ef37bdb", // JPY Coin
|
||||||
|
"0x2370f9d504c7a6e775bf6e14b3f12846b594cd53", // JPY Coin v1
|
||||||
|
],
|
||||||
|
};
|
||||||
|
for (const [symbol, addresses] of Object.entries(expected)) {
|
||||||
|
expect([...KNOWN_SYMBOLS.get(symbol)].sort()).toEqual(
|
||||||
|
[...addresses].sort(),
|
||||||
|
);
|
||||||
|
for (const address of addresses) {
|
||||||
|
expect(isSpoofedSymbol(symbol, address)).toBe(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// The other direction, on the same symbols: widening the table to hold
|
||||||
|
// every bundled address for a ticker must not turn it into a pass for
|
||||||
|
// any other contract.
|
||||||
|
test("a shared ticker from a third contract is still a spoof", () => {
|
||||||
|
const bySymbol = new Map();
|
||||||
|
for (const t of TOKENS) {
|
||||||
|
const upper = t.symbol.toUpperCase();
|
||||||
|
if (!bySymbol.has(upper)) bySymbol.set(upper, []);
|
||||||
|
bySymbol.get(upper).push(t);
|
||||||
|
}
|
||||||
|
for (const [symbol, list] of bySymbol) {
|
||||||
|
if (list.length < 2) continue;
|
||||||
|
expect(isSpoofedSymbol(symbol, FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
describe("surface 1: the transaction history", () => {
|
describe("surface 1: the transaction history", () => {
|
||||||
function fakeEthTransfer() {
|
function fakeEthTransfer() {
|
||||||
return {
|
return {
|
||||||
@@ -147,6 +442,22 @@ describe("surface 1: the transaction history", () => {
|
|||||||
expect(result.transactions).toEqual([]);
|
expect(result.transactions).toEqual([]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Issue #260 on this surface: the same transfer with a padded symbol.
|
||||||
|
test("a padded fake ETH token transfer is filtered too", () => {
|
||||||
|
const padded = { ...fakeEthTransfer(), symbol: " ETH " };
|
||||||
|
const result = filterTransactions([padded], {
|
||||||
|
hideSpoofedSymbols: true,
|
||||||
|
hideFraudContracts: true,
|
||||||
|
hideLowHolderTokens: true,
|
||||||
|
hideDustTransactions: true,
|
||||||
|
dustThresholdGwei: 100000,
|
||||||
|
});
|
||||||
|
expect(result.transactions).toEqual([]);
|
||||||
|
// The contract is learned as fraudulent, exactly as for the
|
||||||
|
// unpadded symbol: the padding must not cost the blocklist entry.
|
||||||
|
expect(result.newFraudContracts).toEqual([FAKE_ETH_CONTRACT]);
|
||||||
|
});
|
||||||
|
|
||||||
test("a real native ETH transfer survives", () => {
|
test("a real native ETH transfer survives", () => {
|
||||||
const native = {
|
const native = {
|
||||||
hash: "0x" + "2".repeat(64),
|
hash: "0x" + "2".repeat(64),
|
||||||
@@ -201,6 +512,36 @@ describe("surface 2: the Send token selector", () => {
|
|||||||
expect(select.children).toEqual([]);
|
expect(select.children).toEqual([]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Issue #260 on this surface: the option text is rendered into HTML,
|
||||||
|
// which collapses the padding, so an unfiltered padded token would sit
|
||||||
|
// in the selector reading exactly `ETH`.
|
||||||
|
test("a padded fake ETH token is not selectable either", () => {
|
||||||
|
render([
|
||||||
|
{
|
||||||
|
address: FAKE_ETH_CONTRACT,
|
||||||
|
symbol: " ETH ",
|
||||||
|
decimals: 18,
|
||||||
|
balance: "0.005",
|
||||||
|
holders: 900000,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
expect(select.children).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a genuine token with a padded symbol stays selectable", () => {
|
||||||
|
render([
|
||||||
|
{
|
||||||
|
address: USDC_CONTRACT,
|
||||||
|
symbol: " USDC ",
|
||||||
|
decimals: 6,
|
||||||
|
balance: "12.5",
|
||||||
|
holders: 900000,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
expect(select.children).toHaveLength(1);
|
||||||
|
expect(select.children[0].value).toBe(USDC_CONTRACT);
|
||||||
|
});
|
||||||
|
|
||||||
test("native ETH remains the always-present option", () => {
|
test("native ETH remains the always-present option", () => {
|
||||||
render([]);
|
render([]);
|
||||||
expect(select.innerHTML).toBe('<option value="ETH">ETH</option>');
|
expect(select.innerHTML).toBe('<option value="ETH">ETH</option>');
|
||||||
@@ -251,6 +592,35 @@ describe("surface 3: the balance list", () => {
|
|||||||
expect(balances).toEqual([]);
|
expect(balances).toEqual([]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Issue #260 on this surface: the balance list is where the user forms
|
||||||
|
// their belief about what they own, and it renders the symbol into HTML.
|
||||||
|
test("a padded fake ETH token is filtered too", async () => {
|
||||||
|
respondWith([fakeEthItem({ symbol: " ETH " })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a fake ETH token padded with a no-break space is filtered", async () => {
|
||||||
|
respondWith([fakeEthItem({ symbol: NBSP + "ETH" + NBSP })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The false-positive direction on the surface that matters most: a real
|
||||||
|
// holding whose symbol happens to carry padding is still listed, and the
|
||||||
|
// list still shows the symbol the token actually reports.
|
||||||
|
test("a genuine token with a padded symbol is not newly filtered", async () => {
|
||||||
|
respondWith([
|
||||||
|
fakeEthItem({
|
||||||
|
address_hash: USDC_CONTRACT,
|
||||||
|
symbol: " USDC ",
|
||||||
|
name: "USD Coin",
|
||||||
|
decimals: "6",
|
||||||
|
}),
|
||||||
|
]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, []);
|
||||||
|
expect(balances).toHaveLength(1);
|
||||||
|
expect(balances[0].symbol).toBe(" USDC ");
|
||||||
|
});
|
||||||
|
|
||||||
test("a genuine token keeps its place in the list", async () => {
|
test("a genuine token keeps its place in the list", async () => {
|
||||||
respondWith([
|
respondWith([
|
||||||
fakeEthItem({
|
fakeEthItem({
|
||||||
@@ -274,6 +644,33 @@ describe("surface 3: the balance list", () => {
|
|||||||
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// The adjacent finding from the same review as issue #260: the type gate
|
||||||
|
// compared exactly, so an explorer that ever varied the casing would
|
||||||
|
// silently drop a real holding before any filter ran. The comparison is
|
||||||
|
// now case-insensitive, which changes nothing about which types are
|
||||||
|
// admitted.
|
||||||
|
test("a differently-cased ERC-20 type still lists a real holding", async () => {
|
||||||
|
respondWith([
|
||||||
|
fakeEthItem({
|
||||||
|
type: "erc-20",
|
||||||
|
address_hash: USDC_CONTRACT,
|
||||||
|
symbol: "USDC",
|
||||||
|
name: "USD Coin",
|
||||||
|
decimals: "6",
|
||||||
|
}),
|
||||||
|
]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, []);
|
||||||
|
expect(balances).toHaveLength(1);
|
||||||
|
expect(balances[0].symbol).toBe("USDC");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("case insensitivity does not admit another token type", async () => {
|
||||||
|
respondWith([fakeEthItem({ type: "erc-721" })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
respondWith([fakeEthItem({ type: "ERC-20-EXTRA" })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
// The money test: the user holds real ETH and has been airdropped a fake
|
// The money test: the user holds real ETH and has been airdropped a fake
|
||||||
// ETH ERC-20. The fake is gone from the list of tokens; the real balance
|
// ETH ERC-20. The fake is gone from the list of tokens; the real balance
|
||||||
// is exactly what the node reported.
|
// is exactly what the node reported.
|
||||||
|
|||||||
@@ -207,8 +207,8 @@ describe("token list assumptions the fixtures rely on", () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
test("USDC and WETH map to their genuine lowercased contracts", () => {
|
test("USDC and WETH map to their genuine lowercased contracts", () => {
|
||||||
expect(KNOWN_SYMBOLS.get("USDC")).toBe(USDC_CONTRACT);
|
expect([...KNOWN_SYMBOLS.get("USDC")]).toEqual([USDC_CONTRACT]);
|
||||||
expect(KNOWN_SYMBOLS.get("WETH")).toBe(WETH_CONTRACT);
|
expect([...KNOWN_SYMBOLS.get("WETH")]).toEqual([WETH_CONTRACT]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("the spam fixture symbol is not in the known token list", () => {
|
test("the spam fixture symbol is not in the known token list", () => {
|
||||||
|
|||||||
Reference in New Issue
Block a user