Compare commits
12
Commits
189bd3f4ba
..
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8e52528f8b | ||
|
|
b8b13ef5cd | ||
|
|
ff05bd50f7 | ||
|
|
ca18beb97f | ||
|
|
bb60b399ec | ||
|
|
447d714313 | ||
|
|
29ba54d5b6 | ||
|
|
e3dd0e44da | ||
|
|
860db6034c | ||
|
|
cd8e45ae0c | ||
|
|
eeb10c20ef | ||
|
|
0aaa94471f |
@@ -339,7 +339,9 @@ There are two suites, one per browser, and they share no code. Chrome runs on
|
|||||||
Playwright; Firefox has its own WebDriver client, because Playwright cannot
|
Playwright; Firefox has its own WebDriver client, because Playwright cannot
|
||||||
observe errors on a Firefox extension page at all — see
|
observe errors on a Firefox extension page at all — see
|
||||||
[Firefox](#firefox-make-test-e2e-firefox) below. Both require docker, and both
|
[Firefox](#firefox-make-test-e2e-firefox) below. Both require docker, and both
|
||||||
are outside `make check`.
|
are outside `make check`. Neither opens the popup from the toolbar button: both
|
||||||
|
load its page in an ordinary tab, so what the toolbar popup itself adds, its
|
||||||
|
size and its closing when it loses focus, is covered by neither.
|
||||||
|
|
||||||
### Chrome (`make test-e2e`)
|
### Chrome (`make test-e2e`)
|
||||||
|
|
||||||
@@ -412,27 +414,52 @@ content script, the inpage provider, the background worker and the approval
|
|||||||
popup all have to work together. A local test page is served by the route
|
popup all have to work together. A local test page is served by the route
|
||||||
handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
|
handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
|
||||||
`MAIN`-world content script like any other page, and drives
|
`MAIN`-world content script like any other page, and drives
|
||||||
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
|
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4`,
|
||||||
`eth_sendTransaction` through the real prompts. Every signature is recovered in
|
`eth_sendTransaction` and `wallet_switchEthereumChain` through the real prompts.
|
||||||
the runner and compared against the active address, the transaction assertions
|
Every signature is recovered in the runner and compared against the active
|
||||||
run against the raw signed transaction captured at `eth_sendRawTransaction`
|
address, the transaction assertions run against the raw signed transaction
|
||||||
rather than against anything the extension reported, rejecting each prompt is
|
captured at `eth_sendRawTransaction` rather than against anything the extension
|
||||||
required to return a rejection to the page rather than hang or resolve, a prompt
|
reported, rejecting each prompt is required to return a rejection to the page
|
||||||
raised while another approval window has focus is required to open a window of
|
rather than hang or resolve, a network switch request is required to leave the
|
||||||
its own, and the password is required to be absent from every message the
|
stored network unchanged and send no `chainChanged` until it is approved, a
|
||||||
approval window sends to the background — with the message that would carry it
|
network switch in Settings is required to send the page `chainChanged` with the
|
||||||
required to be present, so that check cannot pass by observing nothing. That
|
new chain id, a prompt raised while another approval window has focus is
|
||||||
last one is the standing floor under
|
required to open a window of its own, and the password is required to be absent
|
||||||
|
from every message the approval window sends to the background — with the
|
||||||
|
message that would carry it required to be present, so that check cannot pass by
|
||||||
|
observing nothing. That last one is the standing floor under
|
||||||
[#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
[#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
||||||
|
|
||||||
Two limits of that coverage, neither of them papered over. The RPC is stubbed
|
The limits of that coverage and of the rest of the Chrome suite, none of them
|
||||||
throughout, so this is **not** a real dApp against a real network with real
|
papered over:
|
||||||
funds; that remains a human pass before 1.0.0. The site-connection prompt is
|
|
||||||
raised through `chrome.action.openPopup()`, and headless Chromium's
|
- The RPC is stubbed throughout, so this is **not** a real dApp against a real
|
||||||
browser-action popup is not a page Playwright can see or click, so that one
|
network with real funds; that remains a human pass before 1.0.0.
|
||||||
prompt is driven at the URL the extension itself puts on the action — the same
|
- The site-connection prompt is raised through `chrome.action.openPopup()`, and
|
||||||
page and the same approval id, but whether a real toolbar click shows it is not
|
headless Chromium's browser-action popup is not a page Playwright can see or
|
||||||
observable here.
|
click, so that one prompt is driven at the URL the extension itself puts on
|
||||||
|
the action — the same page and the same approval id, but whether a real
|
||||||
|
toolbar click shows it is not observable here.
|
||||||
|
- Each site-connection request is made 1.5 seconds after the tab it will be
|
||||||
|
driven in is opened (`APPROVAL_TAB_SETTLE_MS` in `tests/e2e/run.js`), because
|
||||||
|
opening that tab closes the previous prompt's toolbar popup; a request made
|
||||||
|
just after that popup closes is not covered.
|
||||||
|
- In the tests that approve a signature or a transaction, the approval window
|
||||||
|
runs with `chrome.runtime.sendMessage` wrapped to record what it sends, and in
|
||||||
|
the tests that reject a site connection the prompt gets a click listener that
|
||||||
|
records that Reject was pressed; neither changes what the window does.
|
||||||
|
- The tap to copy test first grants clipboard permission to every page in the
|
||||||
|
browser, which the manifest does not ask for, so whether a real popup may
|
||||||
|
write to the clipboard on a click alone is not covered.
|
||||||
|
- The layout tests for an over-long flash message and for the password error
|
||||||
|
lines write the text straight into the page instead of letting the popup's
|
||||||
|
code put it there, and the second brings each screen up by toggling its
|
||||||
|
`hidden` class rather than navigating to it; they cover the layout, not the
|
||||||
|
code that fills it.
|
||||||
|
- Leaving the recovery phrase or private key screen while its decrypt runs is
|
||||||
|
forced by clicking Reveal and the settings gear in one page task, which a
|
||||||
|
person cannot do; the case a person can hit, the first decrypt after the popup
|
||||||
|
opens while libsodium is still loading, is not driven.
|
||||||
|
|
||||||
Any test that drives a failure path on purpose declares the `console.error` it
|
Any test that drives a failure path on purpose declares the `console.error` it
|
||||||
is about to provoke, via `errors.expect()`. That is not a mute: the declaration
|
is about to provoke, via `errors.expect()`. That is not a mute: the declaration
|
||||||
@@ -446,8 +473,8 @@ collecting for a fixed grace period after the last test returns
|
|||||||
the context. A request whose _first_ dispatch falls after that window is never
|
the context. A request whose _first_ dispatch falls after that window is never
|
||||||
seen at all and cannot fail the run. In practice a request a test fires without
|
seen at all and cannot fail the run. In practice a request a test fires without
|
||||||
awaiting reaches the route handler about 10ms later, and anything on a repeating
|
awaiting reaches the route handler about 10ms later, and anything on a repeating
|
||||||
timer gets observed on an earlier tick during the ~20s suite — but a one-shot
|
timer gets observed on an earlier tick during the suite — but a one-shot call
|
||||||
call deliberately deferred past the window will escape.
|
deliberately deferred past the window will escape.
|
||||||
|
|
||||||
That interception covers the MV3 background service worker as well as the popup
|
That interception covers the MV3 background service worker as well as the popup
|
||||||
page, which it does not by default — `script/test-e2e` sets
|
page, which it does not by default — `script/test-e2e` sets
|
||||||
@@ -501,10 +528,11 @@ Chrome that ever changes this fails the run instead of passing it.
|
|||||||
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
|
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
|
||||||
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
|
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
|
||||||
It covers popup load, the StateRecovery screen (the same cases as the Chrome
|
It covers popup load, the StateRecovery screen (the same cases as the Chrome
|
||||||
suite), wallet creation through the UI, the Add Token screen, and the four dApp
|
suite), wallet creation through the UI, the Add Token screen, and the dApp round
|
||||||
round trips — `eth_requestAccounts`, `personal_sign`, `eth_sendTransaction`, and
|
trips — `eth_requestAccounts`, `personal_sign`, `wallet_switchEthereumChain`
|
||||||
a closed approval window rejecting with EIP-1193 4001 — driven through the real
|
rejected and then approved, `eth_sendTransaction`, and a closed approval window
|
||||||
content script, background page and approval windows.
|
rejecting with EIP-1193 4001 — driven through the real content script,
|
||||||
|
background page and approval windows.
|
||||||
|
|
||||||
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
|
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
|
||||||
**no npm dependencies at all**: it is built on global `fetch` and
|
**no npm dependencies at all**: it is built on global `fetch` and
|
||||||
@@ -579,25 +607,18 @@ without an `await`. Demonstrated, not assumed: a `throw` placed past the first
|
|||||||
and on Chrome (`pageerror`), with the rest of the run unaffected because the
|
and on Chrome (`pageerror`), with the rest of the run unaffected because the
|
||||||
approval view had already rendered.
|
approval view had already rendered.
|
||||||
|
|
||||||
One error is tolerated rather than fatal, listed in `ALLOWED_ERRORS` in
|
Errors are read from the privileged `nsIConsoleService` in Marionette's chrome
|
||||||
`tests/e2e/firefox/run.js` with the issue that will delete it, and printed on
|
context and filtered to non-warning entries whose `sourceName` is the extension
|
||||||
every occurrence so the concession stays visible in the run output. It is
|
origin. That mechanism is not a stylistic choice. WebDriver BiDi's
|
||||||
Firefox reporting the site-approval popup's unawaited `sendMessage` settling
|
`log.entryAdded` delivers **nothing** for extension pages: on a plain `http://`
|
||||||
after `window.close()` unloaded the context — the same teardown ordering as
|
page it reports uncaught errors with stack traces, and on the `moz-extension://`
|
||||||
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275), and unsuppressable from
|
popup it reports zero events, because Firefox's remote agent excludes extension
|
||||||
the calling code, because `BaseContext.wrapPromise` reports it whether or not a
|
browsing contexts from BiDi observation. Any harness built on Playwright-BiDi or
|
||||||
handler is attached. Errors are read from the privileged `nsIConsoleService` in
|
Puppeteer-BiDi would therefore see nothing and report success, which is exactly
|
||||||
Marionette's chrome context and filtered to non-warning entries whose
|
the vacuous check this repo has already shipped twice. Do not migrate this suite
|
||||||
`sourceName` is the extension origin. That mechanism is not a stylistic choice.
|
to BiDi.
|
||||||
WebDriver BiDi's `log.entryAdded` delivers **nothing** for extension pages: on a
|
|
||||||
plain `http://` page it reports uncaught errors with stack traces, and on the
|
|
||||||
`moz-extension://` popup it reports zero events, because Firefox's remote agent
|
|
||||||
excludes extension browsing contexts from BiDi observation. Any harness built on
|
|
||||||
Playwright-BiDi or Puppeteer-BiDi would therefore see nothing and report
|
|
||||||
success, which is exactly the vacuous check this repo has already shipped twice.
|
|
||||||
Do not migrate this suite to BiDi.
|
|
||||||
|
|
||||||
Two limits are worth knowing, both real differences from the Chrome suite:
|
Three limits are worth knowing, all real differences from the Chrome suite:
|
||||||
|
|
||||||
- **Error capture is poll-based, not event-streamed.** The console is drained at
|
- **Error capture is poll-based, not event-streamed.** The console is drained at
|
||||||
each step boundary, so an error is attributed to the step it was drained
|
each step boundary, so an error is attributed to the step it was drained
|
||||||
@@ -614,24 +635,30 @@ Two limits are worth knowing, both real differences from the Chrome suite:
|
|||||||
and silently evicts the oldest, so more than 250 console messages between two
|
and silently evicts the oldest, so more than 250 console messages between two
|
||||||
drains destroys the excess unread. 400 throws inside one step are reported as
|
drains destroys the excess unread. 400 throws inside one step are reported as
|
||||||
exactly the newest 250, three runs running. That buffer is shared with
|
exactly the newest 250, three runs running. That buffer is shared with
|
||||||
Firefox's own console noise; a clean run peaks at 4 of 250 at the install
|
Firefox's own console noise; a clean run, measured when the suite had three
|
||||||
drain and 0 at every later drain, so the three steps here have wide headroom,
|
steps (popup load, wallet creation and Add Token), peaked at 4 of 250 at the
|
||||||
but a step that logs heavily could evict unread errors. What poll-based costs
|
install drain and 0 at every later drain, but a step that logs heavily could
|
||||||
is location, not coverage: an error cannot be placed within a step the way the
|
evict unread errors. What poll-based costs is location, not coverage: an error
|
||||||
Chrome suite's `pageerror` events place it.
|
cannot be placed within a step the way the Chrome suite's `pageerror` events
|
||||||
|
place it.
|
||||||
- **Almost nothing is stubbed, which inverts the coverage of network-dependent
|
- **Almost nothing is stubbed, which inverts the coverage of network-dependent
|
||||||
code.** The container still runs with `--network none`, so the run is offline
|
code.** The container still runs with `--network none`, so the run is offline
|
||||||
and no request can escape. The one thing it can reach is the loopback fixture
|
and no request can escape. The one thing it can reach is the loopback fixture
|
||||||
in `tests/e2e/firefox/dapp.js`, which serves the dApp page and a JSON-RPC node
|
in `tests/e2e/firefox/dapp.js`, which serves the dApp page and a JSON-RPC node
|
||||||
and which the extension's `rpcUrl` is pointed at for the dApp steps; a
|
and which the extension's `rpcUrl` is pointed at for the dApp steps; a
|
||||||
JSON-RPC method that fixture does not model fails the run rather than
|
JSON-RPC method that fixture does not model fails the run rather than
|
||||||
answering `null`. Everything else — Blockscout, the price feed, the phishing
|
answering `null`. Everything else, Blockscout and the price feed among it, has
|
||||||
blocklist — has no fixture and simply fails, and the extension swallows its
|
no fixture and simply fails, and the extension swallows its own fetch
|
||||||
own fetch failures, so only the _failure_ branches of that code are ever
|
failures, so only the _failure_ branches of that code are ever executed. A
|
||||||
executed. A `ReferenceError` in the success path of `renderTransactions`, or
|
`ReferenceError` in the success path of `renderTransactions`, or of price
|
||||||
of price rendering, passes this suite green. The offline run is also weaker
|
rendering, passes this suite green. The offline run is also weaker than the
|
||||||
than the Chrome suite's interception for those calls: it proves nothing got
|
Chrome suite's interception for those calls: it proves nothing got out, but it
|
||||||
out, but it cannot report which requests were attempted.
|
cannot report which requests were attempted.
|
||||||
|
- **The site-connection prompt always opens in a window of its own.** The
|
||||||
|
profile turns off `extensions.openPopupWithoutUserGesture.enabled`, so
|
||||||
|
`src/background/index.js` falls back from the toolbar popup, which WebDriver
|
||||||
|
cannot see, to `windows.create()`; the toolbar popup path is not covered on
|
||||||
|
Firefox.
|
||||||
|
|
||||||
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
||||||
`make test`. `REPO_POLICIES.md` caps `make test` at 60 seconds and a browser
|
`make test`. `REPO_POLICIES.md` caps `make test` at 60 seconds and a browser
|
||||||
@@ -1240,14 +1267,21 @@ path rather than on the home screen. Read the claim narrowly, as that file
|
|||||||
states it: what those boots prove is no structural dereference on the code paths
|
states it: what those boots prove is no structural dereference on the code paths
|
||||||
a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes.
|
a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes.
|
||||||
Not driven: any pairing of values the four slots do not produce, a view only
|
Not driven: any pairing of values the four slots do not produce, a view only
|
||||||
forward navigation opens, anything behind a click, and everything a healthy
|
forward navigation opens, anything behind a click or a timer, and, of what a
|
||||||
profile reaches. Within that boundary the verdict is unconditional — if one of
|
healthy profile reaches, anything beyond its boot onto each view the popup can
|
||||||
those boots leaves the popup unhealthy or off the view it stored, `make check`
|
reopen onto. The fields the router does not read share a slot on each boot, so
|
||||||
fails, including when it takes two corrupted fields at once, because the verdict
|
one of them truthy while another is falsy is reached only where the falsy slot
|
||||||
is the combined boot and the per-field re-boot that names a culprit can only
|
pairs a field that cannot be falsy with one that is. Within that boundary the
|
||||||
decorate the message. So does a field that gains a floor while its row still
|
verdict is unconditional — if one of those boots leaves the popup unhealthy,
|
||||||
claims it has none, and so does a field added to `PERSISTED_FIELDS` with no row
|
`make check` fails, including when it takes two corrupted fields at once,
|
||||||
at all. The per-field justification that used to live in the header of
|
because the verdict is the combined boot and the per-field re-boot that names a
|
||||||
|
culprit can only decorate the message. The combined boot must also land on the
|
||||||
|
view it stored, and each value driven only onto the restore path must land on
|
||||||
|
its view, or fall back to Home, as its row declares; a field the router reads
|
||||||
|
can legitimately change which view renders, so its own sweep is held to health
|
||||||
|
alone. `make check` also fails on a field that gains a floor while its row still
|
||||||
|
claims it has none, and on a field added to `PERSISTED_FIELDS` with no row at
|
||||||
|
all. The per-field justification that used to live in the header of
|
||||||
`src/shared/stateSchema.js` shipped a false claim in three consecutive changes,
|
`src/shared/stateSchema.js` shipped a false claim in three consecutive changes,
|
||||||
each caught only by a reviewer re-deriving thirty fields by hand.
|
each caught only by a reviewer re-deriving thirty fields by hand.
|
||||||
|
|
||||||
@@ -1421,14 +1455,17 @@ view would leave a wallet one click from deletion.
|
|||||||
without it, the lost-password route on DeleteWallet is the first they
|
without it, the lost-password route on DeleteWallet is the first they
|
||||||
would hear of it. The hint line reserves its height, so switching tabs
|
would hear of it. The hint line reserves its height, so switching tabs
|
||||||
cannot move the password fields under the pointer.
|
cannot move the password fields under the pointer.
|
||||||
- "Import" button
|
- "Import" button, with the error line beside it so that it adds no height
|
||||||
|
to a screen whose button already starts near the bottom of the popup
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
- "Import" with a valid entry and a matching password of at least 12
|
- "Import" with a valid entry and a matching password of at least 12
|
||||||
characters → creates the wallet, clears the navigation stack, and →
|
characters → creates the wallet, clears the navigation stack, and →
|
||||||
**Home**. The phrase and xprv modes then scan for further used addresses
|
**Home**. The phrase and xprv modes then scan for further used addresses
|
||||||
and report the count as a flash message.
|
and report the count as a flash message.
|
||||||
- "Import" with an invalid entry, a duplicate wallet or address, or a short
|
- "Import" with a missing, short or mismatched password → full-sentence
|
||||||
or mismatched password → flash message, no screen change
|
error on the error line, no screen change
|
||||||
|
- "Import" with an invalid entry or a duplicate wallet or address → flash
|
||||||
|
message, no screen change
|
||||||
- "Back" → previous screen (Welcome, Home, or Settings)
|
- "Back" → previous screen (Welcome, Home, or Settings)
|
||||||
|
|
||||||
#### AddressDetail (`address`)
|
#### AddressDetail (`address`)
|
||||||
@@ -1467,8 +1504,8 @@ view would leave a wallet one click from deletion.
|
|||||||
copy)
|
copy)
|
||||||
- Warning that anyone holding the private key can transfer all funds from
|
- Warning that anyone holding the private key can transfer all funds from
|
||||||
the address
|
the address
|
||||||
- Error line
|
- Password input, error line and "Reveal" button, shown until the key is
|
||||||
- Password input and "Reveal" button, shown until the key is revealed
|
revealed
|
||||||
- The private key on a highlighted background, tap to copy, shown only after
|
- The private key on a highlighted background, tap to copy, shown only after
|
||||||
the password has been accepted
|
the password has been accepted
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
@@ -1487,6 +1524,14 @@ view would leave a wallet one click from deletion.
|
|||||||
route, including the Settings gear. A decrypt still running when the screen is
|
route, including the Settings gear. A decrypt still running when the screen is
|
||||||
left is discarded rather than written. The screen is not restorable, so
|
left is discarded rather than written. The screen is not restorable, so
|
||||||
reopening the popup lands on Home rather than back on the key.
|
reopening the popup lands on Home rather than back on the key.
|
||||||
|
- **Clipboard**: tapping the key copies it to the clipboard, and the wallet
|
||||||
|
never clears the clipboard afterwards; leaving the screen wipes the key from
|
||||||
|
the page only. The clipboard is the user's, not the wallet's. Clearing it
|
||||||
|
would go against what the user expects, and by then they may have copied
|
||||||
|
something else vital that the clear would destroy. The user knows the key is
|
||||||
|
secret from the warning above the password input, which says that anyone with
|
||||||
|
it can access and transfer all funds from the address, and knows it is on the
|
||||||
|
clipboard because they copied it. From then on it is theirs to manage.
|
||||||
|
|
||||||
#### AddressToken (`address-token`)
|
#### AddressToken (`address-token`)
|
||||||
|
|
||||||
@@ -1741,8 +1786,12 @@ view would leave a wallet one click from deletion.
|
|||||||
plus a "+ Add token" button
|
plus a "+ Add token" button
|
||||||
- Display: "Show tracked tokens with zero balance" checkbox, "UTC
|
- Display: "Show tracked tokens with zero balance" checkbox, "UTC
|
||||||
Timestamps" checkbox, and a Theme selector (System / Light / Dark)
|
Timestamps" checkbox, and a Theme selector (System / Light / Dark)
|
||||||
- Network: network selector (Ethereum Mainnet / Sepolia Testnet); switching
|
- Network: network selector (Ethereum Mainnet / Sepolia Testnet). The
|
||||||
resets the RPC and Blockscout endpoints to that network's defaults
|
network changes only here, or when the user approves a site's request on
|
||||||
|
**NetworkApproval**; either way, switching restores the RPC and Blockscout
|
||||||
|
endpoints last used on that network, or that network's defaults if it has
|
||||||
|
none, and sends `chainChanged` with the new chain id to every open tab.
|
||||||
|
Choosing the network already active changes nothing and sends nothing
|
||||||
- Ethereum RPC: endpoint URL input + "Save" button (validated against
|
- Ethereum RPC: endpoint URL input + "Save" button (validated against
|
||||||
`eth_chainId` before being saved)
|
`eth_chainId` before being saved)
|
||||||
- Blockscout API: endpoint URL input + "Save" button (validated against
|
- Blockscout API: endpoint URL input + "Save" button (validated against
|
||||||
@@ -1798,8 +1847,8 @@ view would leave a wallet one click from deletion.
|
|||||||
- Wallet name
|
- Wallet name
|
||||||
- Warning box stating that anyone holding these words can take everything in
|
- Warning box stating that anyone holding these words can take everything in
|
||||||
the wallet, from any device, without the password
|
the wallet, from any device, without the password
|
||||||
- Error line
|
- Password input, error line and "Reveal" button, shown until the password
|
||||||
- Password input + "Reveal" button, shown until the password is accepted
|
is accepted
|
||||||
- The recovery phrase itself, in full and click-to-copy, shown only after a
|
- The recovery phrase itself, in full and click-to-copy, shown only after a
|
||||||
correct password and in place of the password prompt
|
correct password and in place of the password prompt
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
@@ -1817,6 +1866,9 @@ view would leave a wallet one click from deletion.
|
|||||||
gear. A decrypt still running when the screen is left is discarded rather than
|
gear. A decrypt still running when the screen is left is discarded rather than
|
||||||
written. The screen is not restorable, so reopening the popup lands on Home
|
written. The screen is not restorable, so reopening the popup lands on Home
|
||||||
rather than back on the phrase.
|
rather than back on the phrase.
|
||||||
|
- **Clipboard**: tapping the phrase copies it, and the wallet never clears the
|
||||||
|
clipboard afterwards, for the reasons given under ExportPrivKey; here the
|
||||||
|
warning box above the password input is what tells the user it is secret.
|
||||||
|
|
||||||
#### DeleteWallet (`delete-wallet-confirm`)
|
#### DeleteWallet (`delete-wallet-confirm`)
|
||||||
|
|
||||||
@@ -1825,8 +1877,8 @@ view would leave a wallet one click from deletion.
|
|||||||
- "Back" button, "Delete Wallet" heading
|
- "Back" button, "Delete Wallet" heading
|
||||||
- Warning naming the wallet and stating that deletion is permanent and any
|
- Warning naming the wallet and stating that deletion is permanent and any
|
||||||
funds are unrecoverable without the recovery phrase
|
funds are unrecoverable without the recovery phrase
|
||||||
- Error line
|
|
||||||
- Password input
|
- Password input
|
||||||
|
- Error line
|
||||||
- "Confirm Delete" button
|
- "Confirm Delete" button
|
||||||
- An underlined "I have lost my password" control
|
- An underlined "I have lost my password" control
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
@@ -2027,7 +2079,10 @@ view would leave a wallet one click from deletion.
|
|||||||
no window and takes no nonce, and the site can send it again once the pending
|
no window and takes no nonce, and the site can send it again once the pending
|
||||||
one is answered. The window is centred on the browser window the user was last
|
one is answered. The window is centred on the browser window the user was last
|
||||||
in; if that was another approval window, or the browser refuses the centred
|
in; if that was another approval window, or the browser refuses the centred
|
||||||
position, the browser picks the position.
|
position, the browser picks the position. The network shown is the one the
|
||||||
|
transaction was populated on, and a site cannot switch it without the user:
|
||||||
|
its `wallet_switchEthereumChain` request changes the network only when the
|
||||||
|
user approves it on **NetworkApproval**.
|
||||||
- **Elements**:
|
- **Elements**:
|
||||||
- "Transaction Request" heading
|
- "Transaction Request" heading
|
||||||
- Phishing warning banner (shown when the hostname is on the phishing
|
- Phishing warning banner (shown when the hostname is on the phishing
|
||||||
@@ -2118,6 +2173,40 @@ view would leave a wallet one click from deletion.
|
|||||||
- Popup window closed without answering → the request is rejected with
|
- Popup window closed without answering → the request is rejected with
|
||||||
EIP-1193 code 4001
|
EIP-1193 code 4001
|
||||||
|
|
||||||
|
#### NetworkApproval (`approve-network`)
|
||||||
|
|
||||||
|
- **When**: A connected website asks to switch the network with
|
||||||
|
`wallet_switchEthereumChain`, naming a supported network other than the active
|
||||||
|
one. Only the user switches the network: until the user approves the request
|
||||||
|
here, it changes nothing — not the network, the RPC and Blockscout endpoints,
|
||||||
|
the balances or the cached token data — and no page is sent `chainChanged`.
|
||||||
|
Opened the same way as TxApproval, in a separate popup window. Only one exists
|
||||||
|
per site at a time: a further switch request from a site whose switch request
|
||||||
|
is still unanswered is refused with EIP-1193 code `-32002` and opens no
|
||||||
|
window. A request naming the network already active is answered at once and
|
||||||
|
opens nothing; one naming an unsupported chain is refused with code `4902`,
|
||||||
|
and one from a site that is not connected with code `4100`.
|
||||||
|
`wallet_addEthereumChain` never switches the network.
|
||||||
|
- **Elements**:
|
||||||
|
- "Network Switch Request" heading
|
||||||
|
- Phishing warning banner (shown when the hostname is on the phishing
|
||||||
|
blocklist)
|
||||||
|
- Site origin (bold, scheme and port included) + "wants to switch the
|
||||||
|
wallet's network."
|
||||||
|
- Current network: its name
|
||||||
|
- Requested network: its name
|
||||||
|
- A line saying that switching changes the network for the whole wallet and
|
||||||
|
for every site
|
||||||
|
- "Switch" / "Reject" buttons
|
||||||
|
- **Transitions**:
|
||||||
|
- "Switch" → closes popup; the background switches the network as
|
||||||
|
**Settings** does, restoring the RPC and Blockscout endpoints last used on
|
||||||
|
that network (or that network's defaults if it has none), sends
|
||||||
|
`chainChanged` to every open tab, and answers the site with success
|
||||||
|
- "Reject" → closes popup; the site is answered with EIP-1193 code 4001 and
|
||||||
|
nothing changes
|
||||||
|
- Popup window closed without answering → the same as "Reject"
|
||||||
|
|
||||||
#### StateRecovery (`state-recovery`)
|
#### StateRecovery (`state-recovery`)
|
||||||
|
|
||||||
- **When**: the stored profile fails `assertStateUsable()`. At open, that is
|
- **When**: the stored profile fails `assertStateUsable()`. At open, that is
|
||||||
@@ -2412,6 +2501,8 @@ logged.
|
|||||||
- Sign transactions requested by connected sites (`eth_sendTransaction`)
|
- Sign transactions requested by connected sites (`eth_sendTransaction`)
|
||||||
- Sign messages (`personal_sign`, `eth_sign`)
|
- Sign messages (`personal_sign`, `eth_sign`)
|
||||||
- Sign typed data (`eth_signTypedData_v4`, `eth_signTypedData`)
|
- Sign typed data (`eth_signTypedData_v4`, `eth_signTypedData`)
|
||||||
|
- Switch network at a connected site's request, once the user approves it
|
||||||
|
(`wallet_switchEthereumChain`)
|
||||||
- Human-readable transaction decoding (ERC-20, Uniswap Universal Router)
|
- Human-readable transaction decoding (ERC-20, Uniswap Universal Router)
|
||||||
- ETH/USD and token/USD price display
|
- ETH/USD and token/USD price display
|
||||||
- Configurable RPC endpoint and Blockscout API
|
- Configurable RPC endpoint and Blockscout API
|
||||||
@@ -2604,7 +2695,7 @@ Currently supported:
|
|||||||
|
|
||||||
### Non-Goals for 1.0
|
### Non-Goals for 1.0
|
||||||
|
|
||||||
- Multi-chain support (Ethereum mainnet only)
|
- Chains other than Ethereum mainnet and the Sepolia testnet
|
||||||
- Hardware wallet support
|
- Hardware wallet support
|
||||||
|
|
||||||
## TODO
|
## TODO
|
||||||
@@ -2638,7 +2729,10 @@ Currently supported:
|
|||||||
## Policies
|
## Policies
|
||||||
|
|
||||||
- We don't mention "the other wallet" by name in code or documentation. We're
|
- We don't mention "the other wallet" by name in code or documentation. We're
|
||||||
our own thing.
|
our own thing. Written exception: the injected provider in
|
||||||
|
`src/content/inpage.js` sets the flag named after the other wallet to `true`.
|
||||||
|
It is an interface-compatibility flag many dApps check, and without it the
|
||||||
|
wallet stops working on their sites.
|
||||||
- The README is the complete authoritative technical documentation. It's ok if
|
- The README is the complete authoritative technical documentation. It's ok if
|
||||||
it gets big.
|
it gets big.
|
||||||
|
|
||||||
|
|||||||
@@ -118,4 +118,7 @@ contradicts either, the originals govern.
|
|||||||
- [ ] "Address" not "account" or "derived key"
|
- [ ] "Address" not "account" or "derived key"
|
||||||
- [ ] "Password" not "encryption key" or "vault passphrase"
|
- [ ] "Password" not "encryption key" or "vault passphrase"
|
||||||
- [ ] Error messages are full sentences
|
- [ ] Error messages are full sentences
|
||||||
- [ ] No competitor mentioned by name in code or documentation
|
- [ ] No competitor mentioned by name in code or documentation. Written
|
||||||
|
exception: the injected provider in `src/content/inpage.js` sets the flag
|
||||||
|
named after the other wallet to `true`, an interface-compatibility flag
|
||||||
|
many dApps check (README.md, Policies)
|
||||||
|
|||||||
@@ -23,28 +23,149 @@
|
|||||||
|
|
||||||
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
||||||
milestone is in flight on `next`; its `next` -> `main` PR is
|
milestone is in flight on `next`; its `next` -> `main` PR is
|
||||||
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified
|
[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces
|
||||||
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces
|
`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them
|
||||||
`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to
|
against the build's own receipt to hold exactly the regular files and symlinks
|
||||||
hold exactly the regular files and symlinks that build emitted, with `DEBUG`
|
that build emitted.
|
||||||
compiled off.
|
|
||||||
|
|
||||||
The backlog lives on the
|
The backlog lives on the
|
||||||
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
||||||
authoritative; this file does not duplicate it. Full policy file set present.
|
authoritative; this file does not duplicate it. Full policy file set present.
|
||||||
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
||||||
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does
|
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the
|
||||||
static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both
|
tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml`
|
||||||
of them on every push.
|
runs both of them on every push.
|
||||||
|
|
||||||
# Next Step
|
# Next Step
|
||||||
|
|
||||||
Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
Cut 1.0.0 once the
|
||||||
input validation) before any 1.0rc tag. Individual filed issues are parts of it,
|
[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty,
|
||||||
but the review is broader than any of them.
|
then continue tagging as milestones land.
|
||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-08: The browser suites no longer read a screen before the page has
|
||||||
|
shown it ([#502](https://git.eeqj.de/sneak/AutistMask/issues/502)). Their wait
|
||||||
|
for a screen used to pass as soon as the element laid out, which every view
|
||||||
|
does until the page's stylesheet has applied, so an approval test could read
|
||||||
|
the prompt's fields before the page's script had filled them. `visible()` in
|
||||||
|
`tests/e2e/harness.js` and `waitVisible()` in `tests/e2e/firefox/driver.js`
|
||||||
|
now also wait for the page to finish loading and for neither the element nor
|
||||||
|
anything around it to carry the `hidden` class that `showView()` puts on every
|
||||||
|
view but the current one. No caller changed.
|
||||||
|
|
||||||
|
- 2026-10-08: Switching the network in Settings now tells open pages
|
||||||
|
([#500](https://git.eeqj.de/sneak/AutistMask/issues/500)). Once the switch is
|
||||||
|
saved, Settings asks the background to send `chainChanged` with the new chain
|
||||||
|
id to every open tab, through the same function an approved site request uses.
|
||||||
|
Choosing the network already active changes nothing and sends nothing. Only
|
||||||
|
the extension's own pages can ask for this. `tests/chainSwitchGate.test.js`
|
||||||
|
drives the real Settings view against the background, and the Chrome suite
|
||||||
|
checks that the test page hears both switches.
|
||||||
|
|
||||||
|
- 2026-10-07: A site can no longer switch the wallet's network by itself
|
||||||
|
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)). A connected site's
|
||||||
|
`wallet_switchEthereumChain` request for the other supported network opens a
|
||||||
|
prompt in its own window, through the same approval machinery as the
|
||||||
|
transaction and signature prompts, naming the site, the current network and
|
||||||
|
the requested one. The network, its endpoints, the balances and the caches
|
||||||
|
change, and `chainChanged` is sent, only when the user approves it; rejecting
|
||||||
|
or closing the prompt answers 4001. One such prompt per site at a time. The
|
||||||
|
approval window no longer shows the connection prompt while it waits for the
|
||||||
|
background to describe the approval, because that prompt's "Allow" answers on
|
||||||
|
the same port as the new one; `tests/approvalWindow.test.js` checks that it
|
||||||
|
shows no screen until then. `tests/chainSwitchGate.test.js` and both browser
|
||||||
|
suites drive the prompt.
|
||||||
|
|
||||||
|
- 2026-10-07: Two contradictions between the documents and the code are resolved
|
||||||
|
as ruled on [#165](https://git.eeqj.de/sneak/AutistMask/issues/165). The
|
||||||
|
README's 1.0 non-goal now puts Ethereum mainnet and the Sepolia testnet in
|
||||||
|
scope and other chains out of it. The injected provider's flag named after the
|
||||||
|
other wallet stays, as an interface-compatibility flag many dApps check, and
|
||||||
|
is written down as an exception to the rule against naming competitors in the
|
||||||
|
README's Policies section, in `RULES.md` and in a comment beside it in
|
||||||
|
`src/content/inpage.js`. `script/check-censored` already allows that flag only
|
||||||
|
in that file and its built copies, so it is unchanged.
|
||||||
|
|
||||||
|
- 2026-10-07: Two holes in what `tests/persistedFieldContract.test.js` checks
|
||||||
|
are closed ([#379](https://git.eeqj.de/sneak/AutistMask/issues/379)). The
|
||||||
|
check that every swept field is driven both truthy and falsy counts only
|
||||||
|
`hostile` and `falsy` values, which the sweep drives onto every restorable
|
||||||
|
view, and no longer a `hostileRestore` value, which reaches only the views its
|
||||||
|
entry names; the stale index 5 moves into `hostile` for `selectedWallet` and
|
||||||
|
`selectedAddress`, as the one value of either still truthy after the floor.
|
||||||
|
Each `hostileRestore` entry declares whether its boot lands on its view or
|
||||||
|
falls back to Home, and is held to it. The limits that remain, fields that
|
||||||
|
share a slot on one boot and anything no stored record reaches by itself, are
|
||||||
|
restated as built in the file's header and the README, which now also say
|
||||||
|
which boots are held to where the popup lands and that a healthy profile is
|
||||||
|
booted onto every restorable view.
|
||||||
|
|
||||||
|
- 2026-10-07: Every password error in the popup is shown the same way
|
||||||
|
([#493](https://git.eeqj.de/sneak/AutistMask/issues/493)): with `showError()`
|
||||||
|
and `hideError()` in a fixed-height error line below the password field, as
|
||||||
|
the send confirmation and approval screens already did. The add wallet screen
|
||||||
|
showed a missing, short or mismatched password in the flash line, and the
|
||||||
|
private key export, recovery phrase and delete wallet screens each had a line
|
||||||
|
of their own above the field. On the add wallet screen the line sits beside
|
||||||
|
the Import button, so the button stays where it was at 360x600. Each line
|
||||||
|
clears when the screen is shown again and when the password is tried again.
|
||||||
|
The add wallet screen's other messages, such as an invalid recovery phrase, a
|
||||||
|
duplicate wallet and the address scan, stay in the flash line.
|
||||||
|
`tests/passwordErrorLines.test.js` drives all four screens in the popup.
|
||||||
|
|
||||||
|
- 2026-10-07: Pre-1.0 security review of the extension
|
||||||
|
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
|
||||||
|
`99292b9` for key handling, the DEBUG mode policy, and what the background
|
||||||
|
accepts from pages, the configured RPC endpoint and the explorer, with what
|
||||||
|
the approval screens show from it; the site permission model and storage were
|
||||||
|
read as well. Its summary on that issue lists ten findings, each filed as its
|
||||||
|
own issue, and all ten are fixed on `next`; one,
|
||||||
|
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
|
||||||
|
Three decisions it raised are still open with the owner: the Argon2id cost for
|
||||||
|
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
|
||||||
|
connected site switching the network with no prompt
|
||||||
|
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
|
||||||
|
signing as a personal message
|
||||||
|
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
|
||||||
|
end-to-end suites were not run, the bundled phishing blocklist and token list
|
||||||
|
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
|
||||||
|
taken as audited, and nothing was tried against a real network with real funds
|
||||||
|
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
|
||||||
|
independent second check of each finding did not run; the findings rest on the
|
||||||
|
reviewer's own reading of the code.
|
||||||
|
|
||||||
|
- 2026-10-07: Stale branches pruned from `origin`
|
||||||
|
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
|
||||||
|
classifies each branch it lists, with the evidence. The eighteen still on
|
||||||
|
`origin` that it classifies as landed, or superseded by merged pull requests,
|
||||||
|
were deleted. `feat/message-signing` and `fix/59-transaction-view-ui-policies`
|
||||||
|
had been deleted on 2026-09-09; both landed and stay deleted. Four are kept
|
||||||
|
because their work is not in `next`: `fix/consistent-error-display`,
|
||||||
|
`fix/87-consistent-error-display` and `fix/87-consistent-error-display-v2`,
|
||||||
|
the change for [#87](https://git.eeqj.de/sneak/AutistMask/issues/87) that
|
||||||
|
never landed, as reference for
|
||||||
|
[#493](https://git.eeqj.de/sneak/AutistMask/issues/493); and
|
||||||
|
`chore/token-list-enrichment`, deleted on 2026-09-09 and re-created at
|
||||||
|
`f7a2437`, whose `scripts/` tooling waits on
|
||||||
|
[#495](https://git.eeqj.de/sneak/AutistMask/issues/495).
|
||||||
|
|
||||||
|
- 2026-10-07: The README says that the wallet never clears the clipboard after
|
||||||
|
the private key or the recovery phrase is copied, and why
|
||||||
|
([#492](https://git.eeqj.de/sneak/AutistMask/issues/492)): the clipboard is
|
||||||
|
the user's, clearing it would go against what they expect, and it could
|
||||||
|
destroy something else they copied since. It is under ExportPrivKey, with a
|
||||||
|
line under ShowRecoveryPhrase, and names the warning each password screen
|
||||||
|
actually shows, which says nothing about the clipboard.
|
||||||
|
|
||||||
|
- 2026-10-07: The Firefox end-to-end suite no longer tolerates any uncaught
|
||||||
|
extension error ([#487](https://git.eeqj.de/sneak/AutistMask/issues/487)). Its
|
||||||
|
one entry, Firefox reporting a popup promise that settled after the page
|
||||||
|
unloaded, had lost its cause with
|
||||||
|
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275); the entry and the
|
||||||
|
code that printed tolerated errors are gone from `tests/e2e/firefox/run.js`,
|
||||||
|
and so is the README paragraph that described it.
|
||||||
|
|
||||||
- 2026-10-07: The toolbar icons in `icons/` can be redrawn in the tree
|
- 2026-10-07: The toolbar icons in `icons/` can be redrawn in the tree
|
||||||
([#378](https://git.eeqj.de/sneak/AutistMask/issues/378)): `make icons` runs
|
([#378](https://git.eeqj.de/sneak/AutistMask/issues/378)): `make icons` runs
|
||||||
`script/lib/icons.js`, which draws the mark and writes each PNG with node's
|
`script/lib/icons.js`, which draws the mark and writes each PNG with node's
|
||||||
@@ -55,6 +176,20 @@ but the review is broader than any of them.
|
|||||||
zlib that made the committed files did. `build.js` now copies each manifest
|
zlib that made the committed files did. `build.js` now copies each manifest
|
||||||
from the same path `copyIcons()` reads its icons from.
|
from the same path `copyIcons()` reads its icons from.
|
||||||
|
|
||||||
|
- 2026-10-07: The README's end-to-end limits now match what the two browser
|
||||||
|
suites do to the extension
|
||||||
|
([#293](https://git.eeqj.de/sneak/AutistMask/issues/293)). The `window.close`
|
||||||
|
override the issue named went with
|
||||||
|
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275), so it needs no entry.
|
||||||
|
Added: both suites load the popup in a tab rather than from the toolbar;
|
||||||
|
Chrome waits 1.5 seconds before each site-connection request, records what
|
||||||
|
approval windows send and click, grants clipboard permission, writes text
|
||||||
|
straight into the page in two layout tests, and forces the leave during a
|
||||||
|
decrypt; Firefox forces the site-connection prompt into a window. Corrected:
|
||||||
|
Firefox's one tolerated error, whose cause that fix removed (the entry goes in
|
||||||
|
[#487](https://git.eeqj.de/sneak/AutistMask/issues/487)), the phishing
|
||||||
|
blocklist the extension no longer fetches, and two stale figures.
|
||||||
|
|
||||||
- 2026-10-07: Back from Settings no longer shows Settings again after the
|
- 2026-10-07: Back from Settings no longer shows Settings again after the
|
||||||
settings gear was pressed on the recovery phrase or a delete wallet screen
|
settings gear was pressed on the recovery phrase or a delete wallet screen
|
||||||
opened from Settings, with or without a reopen in between
|
opened from Settings, with or without a reopen in between
|
||||||
@@ -1842,6 +1977,3 @@ but the review is broader than any of them.
|
|||||||
|
|
||||||
Only work that has no issue of its own belongs here; everything else is on the
|
Only work that has no issue of its own belongs here; everything else is on the
|
||||||
tracker.
|
tracker.
|
||||||
|
|
||||||
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
|
||||||
land.
|
|
||||||
|
|||||||
+80
-19
@@ -137,11 +137,12 @@ function releaseTxApprovalSlotFor(approvalId) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// One site-connection approval and one sign approval per site at a time: a
|
// One site-connection approval, one sign approval and one network-switch
|
||||||
// page that asks again before the user has answered is refused with the code
|
// approval per site at a time: a page that asks again before the user has
|
||||||
// above instead of opening another window, so it cannot bury the user in
|
// answered is refused with the code above instead of opening another window,
|
||||||
// prompts. The pending approval itself holds the place, so a caller must test
|
// so it cannot bury the user in prompts. The pending approval itself holds the
|
||||||
// this and raise its approval with nothing awaited in between.
|
// place, so a caller must test this and raise its approval with nothing awaited
|
||||||
|
// in between.
|
||||||
function findPendingApproval(origin, type) {
|
function findPendingApproval(origin, type) {
|
||||||
return Object.values(pendingApprovals).find(
|
return Object.values(pendingApprovals).find(
|
||||||
(approval) => approval.origin === origin && approval.type === type,
|
(approval) => approval.origin === origin && approval.type === type,
|
||||||
@@ -348,8 +349,9 @@ function settleApproval(id, result, options) {
|
|||||||
|
|
||||||
// What a pending approval resolves to when it is given up on rather than
|
// What a pending approval resolves to when it is given up on rather than
|
||||||
// answered: the window was closed, or could not be opened at all. A tx or sign
|
// answered: the window was closed, or could not be opened at all. A tx or sign
|
||||||
// approval answers the requesting page in EIP-1193 shape; a site-connection
|
// approval answers the requesting page in EIP-1193 shape; a site-connection or
|
||||||
// approval answers the connection handler in its own.
|
// network-switch approval answers its handler in the shape the popup's
|
||||||
|
// decision has, as a refusal.
|
||||||
function abandonedResult(approval, code, message) {
|
function abandonedResult(approval, code, message) {
|
||||||
if (approval.type === "tx" || approval.type === "sign") {
|
if (approval.type === "tx" || approval.type === "sign") {
|
||||||
return { error: { code, message } };
|
return { error: { code, message } };
|
||||||
@@ -588,6 +590,26 @@ function requestSignApproval(origin, signParams, approvedFrom) {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Open a network-switch approval popup and return a promise that resolves with
|
||||||
|
// { approved }. Opened in a window, as tx and sign approvals are, because a
|
||||||
|
// site's request is not a user gesture. The popup answers on the approval port,
|
||||||
|
// as a site-connection approval does.
|
||||||
|
function requestNetworkApproval(origin, currentNetworkId, requestedNetworkId) {
|
||||||
|
return new Promise((resolve) => {
|
||||||
|
const id = crypto.randomUUID();
|
||||||
|
pendingApprovals[id] = {
|
||||||
|
id,
|
||||||
|
origin,
|
||||||
|
currentNetworkId,
|
||||||
|
requestedNetworkId,
|
||||||
|
resolve,
|
||||||
|
type: "network",
|
||||||
|
};
|
||||||
|
|
||||||
|
openApprovalWindow(id);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Anything only the extension's own pages may say. A content script speaks
|
// Anything only the extension's own pages may say. A content script speaks
|
||||||
// with the page's URL, so this is what separates the popup from the site the
|
// with the page's URL, so this is what separates the popup from the site the
|
||||||
// popup is being asked about.
|
// popup is being asked about.
|
||||||
@@ -597,8 +619,8 @@ function isExtensionSender(sender) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// The approval popup's port: it carries the user's decision on a
|
// The approval popup's port: it carries the user's decision on a
|
||||||
// site-connection approval, and its disconnect is how that approval learns the
|
// site-connection or network-switch approval, and its disconnect is how that
|
||||||
// popup closed without one.
|
// approval learns the popup closed without one.
|
||||||
//
|
//
|
||||||
// The decision travels this port rather than a one-off runtime.sendMessage()
|
// The decision travels this port rather than a one-off runtime.sendMessage()
|
||||||
// for exactly one reason: the port is also what the popup's window.close()
|
// for exactly one reason: the port is also what the popup's window.close()
|
||||||
@@ -806,6 +828,10 @@ async function handleRpc(method, params, origin) {
|
|||||||
// tab is served from, so a page the user never connected to must
|
// tab is served from, so a page the user never connected to must
|
||||||
// not be able to do it. Ungated, any page could clear the
|
// not be able to do it. Ungated, any page could clear the
|
||||||
// [TESTNET] banner under a user who believed they were on Sepolia.
|
// [TESTNET] banner under a user who believed they were on Sepolia.
|
||||||
|
//
|
||||||
|
// A connected site does not switch it either: only the user does,
|
||||||
|
// by approving the request on the prompt below
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||||
const s = await getState();
|
const s = await getState();
|
||||||
const activeAddress = activeAddressOf(s);
|
const activeAddress = activeAddressOf(s);
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
@@ -827,6 +853,27 @@ async function handleRpc(method, params, origin) {
|
|||||||
}
|
}
|
||||||
if (SUPPORTED_CHAIN_IDS.has(chainId)) {
|
if (SUPPORTED_CHAIN_IDS.has(chainId)) {
|
||||||
const target = networkByChainId(chainId);
|
const target = networkByChainId(chainId);
|
||||||
|
if (findPendingApproval(origin, "network")) {
|
||||||
|
return {
|
||||||
|
error: {
|
||||||
|
code: APPROVAL_PENDING_CODE,
|
||||||
|
message: APPROVAL_PENDING_MESSAGE,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
const decision = await requestNetworkApproval(
|
||||||
|
origin,
|
||||||
|
s.networkId,
|
||||||
|
target.id,
|
||||||
|
);
|
||||||
|
if (!decision.approved) {
|
||||||
|
return {
|
||||||
|
error: {
|
||||||
|
code: APPROVAL_REJECTED_CODE,
|
||||||
|
message: APPROVAL_REJECTED_MESSAGE,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
// Read-modify-write against storage. The old path went through
|
// Read-modify-write against storage. The old path went through
|
||||||
// onChainSwitch(), which mutates the singleton and then persists
|
// onChainSwitch(), which mutates the singleton and then persists
|
||||||
// every field of it — on an unloaded worker that wrote empty
|
// every field of it — on an unloaded worker that wrote empty
|
||||||
@@ -1345,20 +1392,21 @@ startBackgroundJobs();
|
|||||||
// which then fails retryably settles instead of waiting in a window that no
|
// which then fails retryably settles instead of waiting in a window that no
|
||||||
// longer exists.
|
// longer exists.
|
||||||
//
|
//
|
||||||
// A site-connection approval whose popup connected its port is not decided
|
// A site-connection or network-switch approval whose popup connected its port
|
||||||
// here. That popup approves and closes in the same breath, and this event
|
// is not decided here. That popup approves and closes in the same breath, and
|
||||||
// races the decision on a channel of its own — the same race the port exists
|
// this event races the decision on a channel of its own — the same race the
|
||||||
// to end. Its port disconnect says the same thing this event does, in an order
|
// port exists to end. Its port disconnect says the same thing this event does,
|
||||||
// that is defined, so the disconnect is left to say it. The window closing
|
// in an order that is defined, so the disconnect is left to say it. The window
|
||||||
// before any port connected is the one case with nothing else to speak for it,
|
// closing before any port connected is the one case with nothing else to speak
|
||||||
// and is rejected here so the dApp is not left waiting on a window that is
|
// for it, and is rejected here so the dApp is not left waiting on a window that
|
||||||
// gone.
|
// is gone.
|
||||||
if (windowsNs && windowsNs.onRemoved) {
|
if (windowsNs && windowsNs.onRemoved) {
|
||||||
windowsNs.onRemoved.addListener((windowId) => {
|
windowsNs.onRemoved.addListener((windowId) => {
|
||||||
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
||||||
if (approval.windowId !== windowId) continue;
|
if (approval.windowId !== windowId) continue;
|
||||||
const isSite = approval.type !== "tx" && approval.type !== "sign";
|
const decidedOnPort =
|
||||||
if (isSite && approval.portConnected) continue;
|
approval.type !== "tx" && approval.type !== "sign";
|
||||||
|
if (decidedOnPort && approval.portConnected) continue;
|
||||||
const rejection = abandonedResult(
|
const rejection = abandonedResult(
|
||||||
approval,
|
approval,
|
||||||
APPROVAL_REJECTED_CODE,
|
APPROVAL_REJECTED_CODE,
|
||||||
@@ -1423,6 +1471,7 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
"AUTISTMASK_ADDRESSES_REMOVED",
|
"AUTISTMASK_ADDRESSES_REMOVED",
|
||||||
"AUTISTMASK_GET_CONNECTED_SITES",
|
"AUTISTMASK_GET_CONNECTED_SITES",
|
||||||
"AUTISTMASK_REMOVE_SITE",
|
"AUTISTMASK_REMOVE_SITE",
|
||||||
|
"AUTISTMASK_NETWORK_CHANGED",
|
||||||
];
|
];
|
||||||
if (POPUP_ONLY_TYPES.includes(msg.type) && !isExtensionSender(sender)) {
|
if (POPUP_ONLY_TYPES.includes(msg.type) && !isExtensionSender(sender)) {
|
||||||
sendResponse({ error: "Unauthorized sender" });
|
sendResponse({ error: "Unauthorized sender" });
|
||||||
@@ -1446,6 +1495,11 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
resp.signParams = approval.signParams;
|
resp.signParams = approval.signParams;
|
||||||
resp.approvedFrom = approval.approvedFrom;
|
resp.approvedFrom = approval.approvedFrom;
|
||||||
}
|
}
|
||||||
|
if (approval.type === "network") {
|
||||||
|
resp.type = "network";
|
||||||
|
resp.currentNetworkId = approval.currentNetworkId;
|
||||||
|
resp.requestedNetworkId = approval.requestedNetworkId;
|
||||||
|
}
|
||||||
// Flag if the requesting domain is on the phishing blocklist.
|
// Flag if the requesting domain is on the phishing blocklist.
|
||||||
resp.isPhishingDomain = isPhishingDomain(
|
resp.isPhishingDomain = isPhishingDomain(
|
||||||
extractHostname(approval.origin),
|
extractHostname(approval.origin),
|
||||||
@@ -1801,6 +1855,13 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
broadcastSiteRemoved(msg.origin);
|
broadcastSiteRemoved(msg.origin);
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Settings switched the network and has saved it. Open tabs are told the
|
||||||
|
// new chain id the same way as after a site's approved switch request.
|
||||||
|
if (msg.type === "AUTISTMASK_NETWORK_CHANGED") {
|
||||||
|
broadcastChainChanged(msg.chainId);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
module.exports = { PROXY_METHODS };
|
module.exports = { PROXY_METHODS };
|
||||||
|
|||||||
@@ -99,7 +99,10 @@
|
|||||||
|
|
||||||
const provider = {
|
const provider = {
|
||||||
isAutistMask: true,
|
isAutistMask: true,
|
||||||
isMetaMask: true, // compatibility — many dApps check this
|
// An interface-compatibility flag many dApps check. Kept as a written
|
||||||
|
// exception to the rule that no competitor is named in code: see
|
||||||
|
// Policies in README.md, and RULES.md.
|
||||||
|
isMetaMask: true,
|
||||||
chainId: currentChainId,
|
chainId: currentChainId,
|
||||||
networkVersion: currentNetworkVersion,
|
networkVersion: currentNetworkVersion,
|
||||||
selectedAddress: null,
|
selectedAddress: null,
|
||||||
|
|||||||
+72
-14
@@ -207,12 +207,22 @@
|
|||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
<!-- The error line sits beside Import, not above it: at
|
||||||
|
360x600 the button already starts near the bottom of
|
||||||
|
the popup, and a line of its own would push it below
|
||||||
|
the fold. The longest error fits on one line here. -->
|
||||||
|
<div class="flex items-center gap-2">
|
||||||
<button
|
<button
|
||||||
id="btn-add-wallet-confirm"
|
id="btn-add-wallet-confirm"
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
>
|
>
|
||||||
Import
|
Import
|
||||||
</button>
|
</button>
|
||||||
|
<div
|
||||||
|
id="add-wallet-password-error"
|
||||||
|
class="text-xs min-h-[1.25rem] invisible"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ -->
|
<!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ -->
|
||||||
@@ -396,10 +406,6 @@
|
|||||||
Warning: anyone with this private key can access and
|
Warning: anyone with this private key can access and
|
||||||
transfer all funds from this address. Never share it.
|
transfer all funds from this address. Never share it.
|
||||||
</p>
|
</p>
|
||||||
<div
|
|
||||||
id="export-privkey-flash"
|
|
||||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
|
||||||
></div>
|
|
||||||
<div id="export-privkey-password-section" class="mb-2">
|
<div id="export-privkey-password-section" class="mb-2">
|
||||||
<label class="block mb-1">Password</label>
|
<label class="block mb-1">Password</label>
|
||||||
<input
|
<input
|
||||||
@@ -408,9 +414,13 @@
|
|||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||||
placeholder="Enter your password to continue"
|
placeholder="Enter your password to continue"
|
||||||
/>
|
/>
|
||||||
|
<div
|
||||||
|
id="export-privkey-password-error"
|
||||||
|
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
|
||||||
|
></div>
|
||||||
<button
|
<button
|
||||||
id="btn-export-privkey-confirm"
|
id="btn-export-privkey-confirm"
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
>
|
>
|
||||||
Reveal
|
Reveal
|
||||||
</button>
|
</button>
|
||||||
@@ -1116,10 +1126,6 @@
|
|||||||
<strong id="delete-wallet-name"></strong> is permanent. Any
|
<strong id="delete-wallet-name"></strong> is permanent. Any
|
||||||
funds will be unrecoverable without your recovery phrase.
|
funds will be unrecoverable without your recovery phrase.
|
||||||
</p>
|
</p>
|
||||||
<div
|
|
||||||
id="delete-wallet-flash"
|
|
||||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
|
||||||
></div>
|
|
||||||
<div class="mb-2">
|
<div class="mb-2">
|
||||||
<label class="block mb-1">Password</label>
|
<label class="block mb-1">Password</label>
|
||||||
<input
|
<input
|
||||||
@@ -1129,6 +1135,10 @@
|
|||||||
placeholder="Enter your password to confirm"
|
placeholder="Enter your password to confirm"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
<div
|
||||||
|
id="delete-wallet-password-error"
|
||||||
|
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||||
|
></div>
|
||||||
<button
|
<button
|
||||||
id="btn-delete-wallet-confirm"
|
id="btn-delete-wallet-confirm"
|
||||||
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
@@ -1273,10 +1283,6 @@
|
|||||||
this wallet, from any device, without your password. Never
|
this wallet, from any device, without your password. Never
|
||||||
type them into a website and never show them to anyone.
|
type them into a website and never show them to anyone.
|
||||||
</div>
|
</div>
|
||||||
<div
|
|
||||||
id="show-phrase-flash"
|
|
||||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
|
||||||
></div>
|
|
||||||
<div id="show-phrase-password-section" class="mb-2">
|
<div id="show-phrase-password-section" class="mb-2">
|
||||||
<label class="block mb-1">Password</label>
|
<label class="block mb-1">Password</label>
|
||||||
<input
|
<input
|
||||||
@@ -1285,9 +1291,13 @@
|
|||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||||
placeholder="Enter your password to continue"
|
placeholder="Enter your password to continue"
|
||||||
/>
|
/>
|
||||||
|
<div
|
||||||
|
id="show-phrase-password-error"
|
||||||
|
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
|
||||||
|
></div>
|
||||||
<button
|
<button
|
||||||
id="btn-show-phrase-reveal"
|
id="btn-show-phrase-reveal"
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
>
|
>
|
||||||
Reveal
|
Reveal
|
||||||
</button>
|
</button>
|
||||||
@@ -1731,6 +1741,54 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- ============ NETWORK SWITCH APPROVAL ============ -->
|
||||||
|
<div id="view-approve-network" class="view hidden">
|
||||||
|
<h2 class="font-bold mb-2">Network Switch Request</h2>
|
||||||
|
<div
|
||||||
|
id="approve-network-phishing-warning"
|
||||||
|
class="mb-3 p-2 text-xs font-bold hidden bg-red-100 text-red-800 border-2 border-red-600 rounded-md"
|
||||||
|
>
|
||||||
|
⚠️ PHISHING WARNING: This site is on a known phishing
|
||||||
|
blocklist. Proceed with extreme caution.
|
||||||
|
</div>
|
||||||
|
<p class="mb-2">
|
||||||
|
<span id="approve-network-origin" class="font-bold"></span>
|
||||||
|
wants to switch the wallet's network.
|
||||||
|
</p>
|
||||||
|
<div class="mb-3">
|
||||||
|
<div class="text-xs text-muted mb-1">Current network</div>
|
||||||
|
<div
|
||||||
|
id="approve-network-current"
|
||||||
|
class="text-xs font-bold"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
<div class="mb-3">
|
||||||
|
<div class="text-xs text-muted mb-1">Requested network</div>
|
||||||
|
<div
|
||||||
|
id="approve-network-requested"
|
||||||
|
class="text-xs font-bold"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
<p class="mb-3 text-xs">
|
||||||
|
Switching changes the network for the whole wallet and for
|
||||||
|
every site, not only for this one.
|
||||||
|
</p>
|
||||||
|
<div class="flex justify-between">
|
||||||
|
<button
|
||||||
|
id="btn-approve-network"
|
||||||
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
|
>
|
||||||
|
Switch
|
||||||
|
</button>
|
||||||
|
<button
|
||||||
|
id="btn-reject-network"
|
||||||
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
|
>
|
||||||
|
Reject
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<!-- ============ STATE RECOVERY ============ -->
|
<!-- ============ STATE RECOVERY ============ -->
|
||||||
<!--
|
<!--
|
||||||
Shown when the stored profile cannot be read at all. Every
|
Shown when the stored profile cannot be read at all. Every
|
||||||
|
|||||||
+2
-2
@@ -238,9 +238,9 @@ async function init() {
|
|||||||
// rejection rather than an uncaught error — measured as still failing
|
// rejection rather than an uncaught error — measured as still failing
|
||||||
// the run on both harnesses (Playwright `pageerror`, and the Firefox
|
// the run on both harnesses (Playwright `pageerror`, and the Firefox
|
||||||
// driver's console-service drain), so nothing is lost by leaving it
|
// driver's console-service drain), so nothing is lost by leaving it
|
||||||
// on that path.
|
// on that path. show() puts the approval's own screen up once the
|
||||||
|
// background has described it.
|
||||||
approval.show(approvalId);
|
approval.show(approvalId);
|
||||||
showView("approve-site");
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,8 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
showError,
|
||||||
|
hideError,
|
||||||
goBack,
|
goBack,
|
||||||
clearViewStack,
|
clearViewStack,
|
||||||
onViewLeave,
|
onViewLeave,
|
||||||
@@ -98,6 +100,7 @@ function clear() {
|
|||||||
$("add-wallet-password").value = "";
|
$("add-wallet-password").value = "";
|
||||||
$("add-wallet-password-confirm").value = "";
|
$("add-wallet-password-confirm").value = "";
|
||||||
$("add-wallet-phrase-warning").style.visibility = "hidden";
|
$("add-wallet-phrase-warning").style.visibility = "hidden";
|
||||||
|
hideError("add-wallet-password-error");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Each wallet has its own password (its own encryptedSecret), so adding a
|
// Each wallet has its own password (its own encryptedSecret), so adding a
|
||||||
@@ -125,15 +128,18 @@ function validatePassword() {
|
|||||||
const pw = $("add-wallet-password").value;
|
const pw = $("add-wallet-password").value;
|
||||||
const pw2 = $("add-wallet-password-confirm").value;
|
const pw2 = $("add-wallet-password-confirm").value;
|
||||||
if (!pw) {
|
if (!pw) {
|
||||||
showFlash("Please choose a password.");
|
showError("add-wallet-password-error", "Please choose a password.");
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
if (pw.length < 12) {
|
if (pw.length < 12) {
|
||||||
showFlash("Password must be at least 12 characters.");
|
showError(
|
||||||
|
"add-wallet-password-error",
|
||||||
|
"Password must be at least 12 characters.",
|
||||||
|
);
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
if (pw !== pw2) {
|
if (pw !== pw2) {
|
||||||
showFlash("Passwords do not match.");
|
showError("add-wallet-password-error", "Passwords do not match.");
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
return pw;
|
return pw;
|
||||||
@@ -342,8 +348,10 @@ function init(ctx) {
|
|||||||
$("add-wallet-phrase-warning").style.visibility = "visible";
|
$("add-wallet-phrase-warning").style.visibility = "visible";
|
||||||
});
|
});
|
||||||
|
|
||||||
// Import / confirm
|
// Import / confirm. Each press starts with no password error on screen:
|
||||||
|
// validatePassword() puts it back if the password is still wrong.
|
||||||
$("btn-add-wallet-confirm").addEventListener("click", async () => {
|
$("btn-add-wallet-confirm").addEventListener("click", async () => {
|
||||||
|
hideError("add-wallet-password-error");
|
||||||
if (currentMode === "mnemonic") {
|
if (currentMode === "mnemonic") {
|
||||||
await importMnemonic(ctx);
|
await importMnemonic(ctx);
|
||||||
} else if (currentMode === "privkey") {
|
} else if (currentMode === "privkey") {
|
||||||
|
|||||||
+49
-14
@@ -14,6 +14,7 @@ const {
|
|||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState } = require("../../shared/state");
|
||||||
const {
|
const {
|
||||||
|
networkById,
|
||||||
networkByChainId,
|
networkByChainId,
|
||||||
nativeCurrencyByChainId,
|
nativeCurrencyByChainId,
|
||||||
} = require("../../shared/networks");
|
} = require("../../shared/networks");
|
||||||
@@ -328,9 +329,9 @@ function showTxApproval(details) {
|
|||||||
const ethUsd = ethPrice ? parseFloat(ethValueFormatted) * ethPrice : null;
|
const ethUsd = ethPrice ? parseFloat(ethValueFormatted) * ethPrice : null;
|
||||||
const usdStr = formatUsd(ethUsd);
|
const usdStr = formatUsd(ethUsd);
|
||||||
// In the native currency of the network the transaction is for, which the
|
// In the native currency of the network the transaction is for, which the
|
||||||
// Network line names, not the active network's: a site can switch the
|
// Network line names, not the active network's: the active network can
|
||||||
// active network after this transaction is prepared and back before it is
|
// change, in Settings or when the user approves a site's request, after
|
||||||
// signed.
|
// this transaction is prepared and change back before it is signed.
|
||||||
$("approve-tx-value").textContent =
|
$("approve-tx-value").textContent =
|
||||||
ethValueFormatted +
|
ethValueFormatted +
|
||||||
" " +
|
" " +
|
||||||
@@ -752,9 +753,29 @@ function showSignApproval(details) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function showNetworkApproval(details) {
|
||||||
|
showPhishingWarning(
|
||||||
|
"approve-network-phishing-warning",
|
||||||
|
details.isPhishingDomain,
|
||||||
|
);
|
||||||
|
$("approve-network-origin").textContent = details.origin;
|
||||||
|
$("approve-network-current").textContent = networkById(
|
||||||
|
details.currentNetworkId,
|
||||||
|
).name;
|
||||||
|
$("approve-network-requested").textContent = networkById(
|
||||||
|
details.requestedNetworkId,
|
||||||
|
).name;
|
||||||
|
showView("approve-network");
|
||||||
|
}
|
||||||
|
|
||||||
// Awaited by nobody: the popup entry point calls this and moves on. It
|
// Awaited by nobody: the popup entry point calls this and moves on. It
|
||||||
// therefore has to absorb its own failure, and a background that cannot
|
// therefore has to absorb its own failure, and a background that cannot
|
||||||
// describe the approval is the same outcome as an approval that is gone.
|
// describe the approval is the same outcome as an approval that is gone.
|
||||||
|
//
|
||||||
|
// Nothing is on screen until the background has described the approval, so
|
||||||
|
// the screen shown is always the one for the approval this window answers:
|
||||||
|
// the connection prompt's "Allow" and the network switch prompt's "Switch"
|
||||||
|
// answer on the same port, and either would approve the other.
|
||||||
async function show(id) {
|
async function show(id) {
|
||||||
approvalId = id;
|
approvalId = id;
|
||||||
approvalPort = runtimeApi().connect({ name: "approval:" + id });
|
approvalPort = runtimeApi().connect({ name: "approval:" + id });
|
||||||
@@ -778,6 +799,10 @@ async function show(id) {
|
|||||||
showSignApproval(details);
|
showSignApproval(details);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
if (details.type === "network") {
|
||||||
|
showNetworkApproval(details);
|
||||||
|
return;
|
||||||
|
}
|
||||||
// Site connection approval
|
// Site connection approval
|
||||||
showPhishingWarning(
|
showPhishingWarning(
|
||||||
"approve-site-phishing-warning",
|
"approve-site-phishing-warning",
|
||||||
@@ -787,6 +812,7 @@ async function show(id) {
|
|||||||
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
||||||
attachCopyHandlers("view-approve-site");
|
attachCopyHandlers("view-approve-site");
|
||||||
$("approve-remember").checked = state.rememberSiteChoice;
|
$("approve-remember").checked = state.rememberSiteChoice;
|
||||||
|
showView("approve-site");
|
||||||
}
|
}
|
||||||
|
|
||||||
let approvalId = null;
|
let approvalId = null;
|
||||||
@@ -866,20 +892,21 @@ function clearSignPassword() {
|
|||||||
hideError("approve-sign-error");
|
hideError("approve-sign-error");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Answer a site-connection approval and close. The decision goes out on the
|
// Answer a site-connection or network-switch approval and close. The decision
|
||||||
// approval port — see approvalPort above for why — and carries no approval id,
|
// goes out on the approval port — see approvalPort above for why — and carries
|
||||||
// because the port name already names the approval the background will settle.
|
// no approval id, because the port name already names the approval the
|
||||||
// The post is guarded because a throw must not cost the close: posting on a
|
// background will settle. `remember` means something only for a site
|
||||||
// port whose background worker has been torn down throws, and the approval it
|
// connection. The post is guarded because a throw must not cost the close:
|
||||||
// would have settled died with that worker, so the only thing left to do is
|
// posting on a port whose background worker has been torn down throws, and the
|
||||||
// what the user asked for — go away.
|
// approval it would have settled died with that worker, so the only thing left
|
||||||
function decideSite(approved) {
|
// to do is what the user asked for — go away.
|
||||||
|
function decide(approved, remember) {
|
||||||
if (approvalPort) {
|
if (approvalPort) {
|
||||||
try {
|
try {
|
||||||
approvalPort.postMessage({
|
approvalPort.postMessage({
|
||||||
type: "AUTISTMASK_APPROVAL_DECISION",
|
type: "AUTISTMASK_APPROVAL_DECISION",
|
||||||
approved,
|
approved,
|
||||||
remember: $("approve-remember").checked,
|
remember,
|
||||||
});
|
});
|
||||||
} catch {
|
} catch {
|
||||||
// Nothing to report it to; the window closes either way.
|
// Nothing to report it to; the window closes either way.
|
||||||
@@ -898,11 +925,19 @@ function init(_ctx) {
|
|||||||
});
|
});
|
||||||
|
|
||||||
$("btn-approve").addEventListener("click", () => {
|
$("btn-approve").addEventListener("click", () => {
|
||||||
decideSite(true);
|
decide(true, $("approve-remember").checked);
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-reject").addEventListener("click", () => {
|
$("btn-reject").addEventListener("click", () => {
|
||||||
decideSite(false);
|
decide(false, $("approve-remember").checked);
|
||||||
|
});
|
||||||
|
|
||||||
|
$("btn-approve-network").addEventListener("click", () => {
|
||||||
|
decide(true, false);
|
||||||
|
});
|
||||||
|
|
||||||
|
$("btn-reject-network").addEventListener("click", () => {
|
||||||
|
decide(false, false);
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-approve-tx").addEventListener("click", async () => {
|
$("btn-approve-tx").addEventListener("click", async () => {
|
||||||
|
|||||||
@@ -2,6 +2,8 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
showError,
|
||||||
|
hideError,
|
||||||
goBack,
|
goBack,
|
||||||
clearViewStack,
|
clearViewStack,
|
||||||
onViewLeave,
|
onViewLeave,
|
||||||
@@ -55,8 +57,7 @@ function confirmKey(name) {
|
|||||||
function clear() {
|
function clear() {
|
||||||
deleteWalletIndex = null;
|
deleteWalletIndex = null;
|
||||||
$("delete-wallet-password").value = "";
|
$("delete-wallet-password").value = "";
|
||||||
$("delete-wallet-flash").textContent = "";
|
hideError("delete-wallet-password-error");
|
||||||
$("delete-wallet-flash").style.visibility = "hidden";
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// The lost-password screen holds no secret — a wallet name is not one —
|
// The lost-password screen holds no secret — a wallet name is not one —
|
||||||
@@ -232,19 +233,22 @@ function init(_ctx) {
|
|||||||
$("btn-delete-wallet-confirm").addEventListener("click", async () => {
|
$("btn-delete-wallet-confirm").addEventListener("click", async () => {
|
||||||
const pw = $("delete-wallet-password").value;
|
const pw = $("delete-wallet-password").value;
|
||||||
if (!pw) {
|
if (!pw) {
|
||||||
$("delete-wallet-flash").textContent =
|
showError(
|
||||||
"Please enter your password.";
|
"delete-wallet-password-error",
|
||||||
$("delete-wallet-flash").style.visibility = "visible";
|
"Please enter your password.",
|
||||||
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (deleteWalletIndex === null) {
|
if (deleteWalletIndex === null) {
|
||||||
$("delete-wallet-flash").textContent =
|
showError(
|
||||||
"No wallet selected for deletion.";
|
"delete-wallet-password-error",
|
||||||
$("delete-wallet-flash").style.visibility = "visible";
|
"No wallet selected for deletion.",
|
||||||
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
hideError("delete-wallet-password-error");
|
||||||
const btn = $("btn-delete-wallet-confirm");
|
const btn = $("btn-delete-wallet-confirm");
|
||||||
btn.disabled = true;
|
btn.disabled = true;
|
||||||
btn.classList.add("text-muted");
|
btn.classList.add("text-muted");
|
||||||
@@ -256,9 +260,10 @@ function init(_ctx) {
|
|||||||
try {
|
try {
|
||||||
await decryptWithPassword(wallet.encryptedSecret, pw);
|
await decryptWithPassword(wallet.encryptedSecret, pw);
|
||||||
} catch {
|
} catch {
|
||||||
$("delete-wallet-flash").textContent =
|
showError(
|
||||||
"That password is incorrect. Please try again.";
|
"delete-wallet-password-error",
|
||||||
$("delete-wallet-flash").style.visibility = "visible";
|
"That password is incorrect. Please try again.",
|
||||||
|
);
|
||||||
btn.disabled = false;
|
btn.disabled = false;
|
||||||
btn.classList.remove("text-muted");
|
btn.classList.remove("text-muted");
|
||||||
return;
|
return;
|
||||||
|
|||||||
@@ -20,6 +20,8 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
showError,
|
||||||
|
hideError,
|
||||||
flashCopyFeedback,
|
flashCopyFeedback,
|
||||||
goBack,
|
goBack,
|
||||||
onViewLeave,
|
onViewLeave,
|
||||||
@@ -56,11 +58,6 @@ function isCurrentReveal(generation) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
function fail(message) {
|
|
||||||
$("export-privkey-flash").textContent = message;
|
|
||||||
$("export-privkey-flash").style.visibility = "visible";
|
|
||||||
}
|
|
||||||
|
|
||||||
// Wipe every trace of the key and drop the address selection. Safe to call
|
// Wipe every trace of the key and drop the address selection. Safe to call
|
||||||
// when nothing was ever revealed, and safe to call twice.
|
// when nothing was ever revealed, and safe to call twice.
|
||||||
function clear() {
|
function clear() {
|
||||||
@@ -71,8 +68,7 @@ function clear() {
|
|||||||
$("export-privkey-password").value = "";
|
$("export-privkey-password").value = "";
|
||||||
$("export-privkey-result").classList.add("hidden");
|
$("export-privkey-result").classList.add("hidden");
|
||||||
$("export-privkey-password-section").classList.remove("hidden");
|
$("export-privkey-password-section").classList.remove("hidden");
|
||||||
$("export-privkey-flash").textContent = "";
|
hideError("export-privkey-password-error");
|
||||||
$("export-privkey-flash").style.visibility = "hidden";
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function show(walletIdx, addrIdx) {
|
function show(walletIdx, addrIdx) {
|
||||||
@@ -112,15 +108,19 @@ function show(walletIdx, addrIdx) {
|
|||||||
async function reveal() {
|
async function reveal() {
|
||||||
const password = $("export-privkey-password").value;
|
const password = $("export-privkey-password").value;
|
||||||
if (!password) {
|
if (!password) {
|
||||||
fail("Please enter your password.");
|
showError(
|
||||||
|
"export-privkey-password-error",
|
||||||
|
"Please enter your password.",
|
||||||
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (walletIndex === null) {
|
if (walletIndex === null) {
|
||||||
fail("No address is selected.");
|
showError("export-privkey-password-error", "No address is selected.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const wallet = state.wallets[walletIndex];
|
const wallet = state.wallets[walletIndex];
|
||||||
|
|
||||||
|
hideError("export-privkey-password-error");
|
||||||
const btn = $("btn-export-privkey-confirm");
|
const btn = $("btn-export-privkey-confirm");
|
||||||
btn.disabled = true;
|
btn.disabled = true;
|
||||||
btn.classList.add("text-muted");
|
btn.classList.add("text-muted");
|
||||||
@@ -140,11 +140,12 @@ async function reveal() {
|
|||||||
$("export-privkey-password-section").classList.add("hidden");
|
$("export-privkey-password-section").classList.add("hidden");
|
||||||
$("export-privkey-value").textContent = signer.privateKey;
|
$("export-privkey-value").textContent = signer.privateKey;
|
||||||
$("export-privkey-result").classList.remove("hidden");
|
$("export-privkey-result").classList.remove("hidden");
|
||||||
$("export-privkey-flash").textContent = "";
|
|
||||||
$("export-privkey-flash").style.visibility = "hidden";
|
|
||||||
} catch {
|
} catch {
|
||||||
if (!isCurrentReveal(generation)) return;
|
if (!isCurrentReveal(generation)) return;
|
||||||
fail("That password is incorrect. Please try again.");
|
showError(
|
||||||
|
"export-privkey-password-error",
|
||||||
|
"That password is incorrect. Please try again.",
|
||||||
|
);
|
||||||
} finally {
|
} finally {
|
||||||
btn.disabled = false;
|
btn.disabled = false;
|
||||||
btn.classList.remove("text-muted");
|
btn.classList.remove("text-muted");
|
||||||
|
|||||||
@@ -51,6 +51,7 @@ const VIEWS = [
|
|||||||
"approve-site",
|
"approve-site",
|
||||||
"approve-tx",
|
"approve-tx",
|
||||||
"approve-sign",
|
"approve-sign",
|
||||||
|
"approve-network",
|
||||||
"export-privkey",
|
"export-privkey",
|
||||||
"show-phrase",
|
"show-phrase",
|
||||||
// Shown by src/popup/views/stateRecovery.js when the stored profile
|
// Shown by src/popup/views/stateRecovery.js when the stored profile
|
||||||
|
|||||||
@@ -316,7 +316,11 @@ function init(ctx) {
|
|||||||
const networkSelect = $("settings-network");
|
const networkSelect = $("settings-network");
|
||||||
networkSelect.addEventListener("change", async () => {
|
networkSelect.addEventListener("change", async () => {
|
||||||
const newId = networkSelect.value;
|
const newId = networkSelect.value;
|
||||||
|
if (newId === state.networkId) return;
|
||||||
const net = await onChainSwitch(newId);
|
const net = await onChainSwitch(newId);
|
||||||
|
// Open pages are told by the background, as after a site's approved
|
||||||
|
// switch request.
|
||||||
|
notify({ type: "AUTISTMASK_NETWORK_CHANGED", chainId: net.chainId });
|
||||||
$("settings-rpc").value = state.rpcUrl;
|
$("settings-rpc").value = state.rpcUrl;
|
||||||
$("settings-blockscout").value = state.blockscoutUrl;
|
$("settings-blockscout").value = state.blockscoutUrl;
|
||||||
showFlash("Switched to " + net.name + ".");
|
showFlash("Switched to " + net.name + ".");
|
||||||
|
|||||||
@@ -21,6 +21,8 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
showError,
|
||||||
|
hideError,
|
||||||
flashCopyFeedback,
|
flashCopyFeedback,
|
||||||
goBack,
|
goBack,
|
||||||
onViewLeave,
|
onViewLeave,
|
||||||
@@ -52,11 +54,6 @@ function isCurrentReveal(generation) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
function fail(message) {
|
|
||||||
$("show-phrase-flash").textContent = message;
|
|
||||||
$("show-phrase-flash").style.visibility = "visible";
|
|
||||||
}
|
|
||||||
|
|
||||||
// Wipe every trace of the phrase and drop the wallet selection. Safe to
|
// Wipe every trace of the phrase and drop the wallet selection. Safe to
|
||||||
// call when nothing was ever revealed, and safe to call twice.
|
// call when nothing was ever revealed, and safe to call twice.
|
||||||
function clear() {
|
function clear() {
|
||||||
@@ -66,8 +63,7 @@ function clear() {
|
|||||||
$("show-phrase-password").value = "";
|
$("show-phrase-password").value = "";
|
||||||
$("show-phrase-result").classList.add("hidden");
|
$("show-phrase-result").classList.add("hidden");
|
||||||
$("show-phrase-password-section").classList.remove("hidden");
|
$("show-phrase-password-section").classList.remove("hidden");
|
||||||
$("show-phrase-flash").textContent = "";
|
hideError("show-phrase-password-error");
|
||||||
$("show-phrase-flash").style.visibility = "hidden";
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function show(walletIdx) {
|
function show(walletIdx) {
|
||||||
@@ -90,19 +86,23 @@ function show(walletIdx) {
|
|||||||
async function reveal() {
|
async function reveal() {
|
||||||
const password = $("show-phrase-password").value;
|
const password = $("show-phrase-password").value;
|
||||||
if (!password) {
|
if (!password) {
|
||||||
fail("Please enter your password.");
|
showError("show-phrase-password-error", "Please enter your password.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (walletIndex === null) {
|
if (walletIndex === null) {
|
||||||
fail("No wallet is selected.");
|
showError("show-phrase-password-error", "No wallet is selected.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const wallet = state.wallets[walletIndex];
|
const wallet = state.wallets[walletIndex];
|
||||||
if (!walletHasRecoveryPhrase(wallet)) {
|
if (!walletHasRecoveryPhrase(wallet)) {
|
||||||
fail("This wallet does not have a recovery phrase.");
|
showError(
|
||||||
|
"show-phrase-password-error",
|
||||||
|
"This wallet does not have a recovery phrase.",
|
||||||
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
hideError("show-phrase-password-error");
|
||||||
const btn = $("btn-show-phrase-reveal");
|
const btn = $("btn-show-phrase-reveal");
|
||||||
btn.disabled = true;
|
btn.disabled = true;
|
||||||
btn.classList.add("text-muted");
|
btn.classList.add("text-muted");
|
||||||
@@ -120,13 +120,14 @@ async function reveal() {
|
|||||||
$("show-phrase-password-section").classList.add("hidden");
|
$("show-phrase-password-section").classList.add("hidden");
|
||||||
$("show-phrase-value").textContent = phrase;
|
$("show-phrase-value").textContent = phrase;
|
||||||
$("show-phrase-result").classList.remove("hidden");
|
$("show-phrase-result").classList.remove("hidden");
|
||||||
$("show-phrase-flash").textContent = "";
|
|
||||||
$("show-phrase-flash").style.visibility = "hidden";
|
|
||||||
} catch {
|
} catch {
|
||||||
if (!isCurrentReveal(generation)) return;
|
if (!isCurrentReveal(generation)) return;
|
||||||
// Deliberately not the caught error: the message is fixed so that
|
// Deliberately not the caught error: the message is fixed so that
|
||||||
// nothing derived from the ciphertext or the attempt can surface.
|
// nothing derived from the ciphertext or the attempt can surface.
|
||||||
fail("That password is incorrect. Please try again.");
|
showError(
|
||||||
|
"show-phrase-password-error",
|
||||||
|
"That password is incorrect. Please try again.",
|
||||||
|
);
|
||||||
} finally {
|
} finally {
|
||||||
btn.disabled = false;
|
btn.disabled = false;
|
||||||
btn.classList.remove("text-muted");
|
btn.classList.remove("text-muted");
|
||||||
|
|||||||
@@ -84,8 +84,9 @@ function show(tx) {
|
|||||||
contractAddress: tx.contractAddress || null,
|
contractAddress: tx.contractAddress || null,
|
||||||
// The network the history entry was read from. The type line and
|
// The network the history entry was read from. The type line and
|
||||||
// the fee are in its native currency, not the active network's:
|
// the fee are in its native currency, not the active network's:
|
||||||
// a site can switch the active network before a later popup
|
// the active network can change, in Settings or when the user
|
||||||
// shows this screen again.
|
// approves a site's request, before a later popup shows this
|
||||||
|
// screen again.
|
||||||
chainId: tx.chainId,
|
chainId: tx.chainId,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -89,8 +89,9 @@ function startWait(txInfo, txHash, broadcastTime, pollNow) {
|
|||||||
|
|
||||||
// A native amount, here and on the success and error screens, is in the
|
// A native amount, here and on the success and error screens, is in the
|
||||||
// native currency of txInfo.chainId, the network the transaction was sent
|
// native currency of txInfo.chainId, the network the transaction was sent
|
||||||
// on, not the active network's: a site can switch the active network
|
// on, not the active network's: the active network can change, in
|
||||||
// while this screen is open or before a later popup resumes it.
|
// Settings or when the user approves a site's request, while this screen
|
||||||
|
// is open or before a later popup resumes it.
|
||||||
const symbol =
|
const symbol =
|
||||||
txInfo.token === "ETH"
|
txInfo.token === "ETH"
|
||||||
? nativeCurrencyByChainId(txInfo.chainId)
|
? nativeCurrencyByChainId(txInfo.chainId)
|
||||||
|
|||||||
@@ -39,6 +39,8 @@ jest.doMock("../src/popup/views/helpers", () => ({
|
|||||||
$: element,
|
$: element,
|
||||||
showView: () => {},
|
showView: () => {},
|
||||||
showFlash: () => {},
|
showFlash: () => {},
|
||||||
|
showError: () => {},
|
||||||
|
hideError: () => {},
|
||||||
goBack: () => {},
|
goBack: () => {},
|
||||||
clearViewStack: () => {},
|
clearViewStack: () => {},
|
||||||
onViewLeave: () => {},
|
onViewLeave: () => {},
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
// The connection, transaction and signature prompts name the site by its full
|
// The connection, transaction, signature and network switch prompts name the
|
||||||
// origin, scheme and port included, not by its bare hostname
|
// site by its full origin, scheme and port included, not by its bare hostname
|
||||||
// (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http,
|
// (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http,
|
||||||
// or on another port, of a host the user trusts over https must not raise a
|
// or on another port, of a host the user trusts over https must not raise a
|
||||||
// prompt that reads as that trusted site.
|
// prompt that reads as that trusted site.
|
||||||
@@ -104,6 +104,7 @@ beforeEach(() => {
|
|||||||
test("the connection prompt shows the origin", async () => {
|
test("the connection prompt shows the origin", async () => {
|
||||||
await openApproval({});
|
await openApproval({});
|
||||||
expect(node("approve-origin").textContent).toBe(ORIGIN);
|
expect(node("approve-origin").textContent).toBe(ORIGIN);
|
||||||
|
expect(node("view-approve-site").classList.contains("hidden")).toBe(false);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("the transaction prompt shows the origin", async () => {
|
test("the transaction prompt shows the origin", async () => {
|
||||||
@@ -138,3 +139,24 @@ test("the signature prompt shows the origin", async () => {
|
|||||||
});
|
});
|
||||||
expect(node("approve-sign-origin").textContent).toBe(ORIGIN);
|
expect(node("approve-sign-origin").textContent).toBe(ORIGIN);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("the network switch prompt shows the origin and both networks", async () => {
|
||||||
|
await openApproval({
|
||||||
|
type: "network",
|
||||||
|
currentNetworkId: "mainnet",
|
||||||
|
requestedNetworkId: "sepolia",
|
||||||
|
});
|
||||||
|
expect(node("approve-network-origin").textContent).toBe(ORIGIN);
|
||||||
|
expect(node("approve-network-current").textContent).toBe(
|
||||||
|
"Ethereum Mainnet",
|
||||||
|
);
|
||||||
|
expect(node("approve-network-requested").textContent).toBe(
|
||||||
|
"Sepolia Testnet",
|
||||||
|
);
|
||||||
|
// Its own screen, and not the connection prompt, whose "Allow" answers
|
||||||
|
// on the same port.
|
||||||
|
expect(node("view-approve-network").classList.contains("hidden")).toBe(
|
||||||
|
false,
|
||||||
|
);
|
||||||
|
expect(node("view-approve-site").classList.contains("hidden")).toBe(true);
|
||||||
|
});
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
// The approval window shows no screen until the background has described the
|
||||||
|
// approval it answers (https://git.eeqj.de/sneak/AutistMask/issues/408). The
|
||||||
|
// connection prompt's "Allow" and the network switch prompt's "Switch" answer
|
||||||
|
// on the same port, so a window that showed the connection prompt while it
|
||||||
|
// waited could approve a network switch.
|
||||||
|
//
|
||||||
|
// Booted through the real popup entry point, which is where the connection
|
||||||
|
// prompt used to be put up before the background had answered.
|
||||||
|
|
||||||
|
const {
|
||||||
|
bootPopup,
|
||||||
|
cleanupPopup,
|
||||||
|
settle,
|
||||||
|
unversionedValidProfile,
|
||||||
|
} = require("./support/popupBoot");
|
||||||
|
|
||||||
|
afterEach(cleanupPopup);
|
||||||
|
|
||||||
|
test("the approval window shows no screen until the background describes the approval", async () => {
|
||||||
|
// The background's answer, held until the test gives it.
|
||||||
|
let answer = null;
|
||||||
|
const env = await bootPopup(unversionedValidProfile(), {
|
||||||
|
search: "?approval=approval-1",
|
||||||
|
runtime: {
|
||||||
|
connect: () => ({ postMessage: () => {} }),
|
||||||
|
sendMessage: (msg, reply) => {
|
||||||
|
if (msg.type === "AUTISTMASK_GET_APPROVAL") answer = reply;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(answer).not.toBeNull();
|
||||||
|
// No screen at all, the connection prompt included.
|
||||||
|
expect(env.visibleViews()).toEqual([]);
|
||||||
|
|
||||||
|
answer({
|
||||||
|
type: "network",
|
||||||
|
origin: "https://dapp.example",
|
||||||
|
currentNetworkId: "mainnet",
|
||||||
|
requestedNetworkId: "sepolia",
|
||||||
|
isPhishingDomain: false,
|
||||||
|
});
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(env.visibleViews()).toEqual(["approve-network"]);
|
||||||
|
expect(env.pageErrors).toEqual([]);
|
||||||
|
});
|
||||||
@@ -25,6 +25,7 @@
|
|||||||
|
|
||||||
const { Wallet } = require("ethers");
|
const { Wallet } = require("ethers");
|
||||||
const { networkById } = require("../src/shared/networks");
|
const { networkById } = require("../src/shared/networks");
|
||||||
|
const { applyChainSwitchFields } = require("../src/shared/chainSwitchFields");
|
||||||
const { makeStorageStub } = require("./support/storageStub");
|
const { makeStorageStub } = require("./support/storageStub");
|
||||||
|
|
||||||
const SIGNER_KEY =
|
const SIGNER_KEY =
|
||||||
@@ -240,8 +241,8 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
|||||||
// The artifact is verified against the chain read at the top of the
|
// The artifact is verified against the chain read at the top of the
|
||||||
// attempt. Whatever endpoint it is then broadcast to has to be that same
|
// attempt. Whatever endpoint it is then broadcast to has to be that same
|
||||||
// chain's — otherwise the wallet checks a transaction against Sepolia and
|
// chain's — otherwise the wallet checks a transaction against Sepolia and
|
||||||
// sends it to a mainnet node. A connected site can switch the chain at any
|
// sends it to a mainnet node. The user can switch the network in Settings
|
||||||
// moment, including this one.
|
// at any moment, including this one.
|
||||||
test("the artifact is broadcast to the endpoint of the chain it was verified against", async () => {
|
test("the artifact is broadcast to the endpoint of the chain it was verified against", async () => {
|
||||||
const bg = loadWorker("sepolia");
|
const bg = loadWorker("sepolia");
|
||||||
|
|
||||||
@@ -264,9 +265,9 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
|||||||
populated(Number(SEPOLIA.networkVersion)),
|
populated(Number(SEPOLIA.networkVersion)),
|
||||||
);
|
);
|
||||||
|
|
||||||
// A connected site switches the chain while the attempt is running,
|
// The user switches the network in Settings while the attempt is
|
||||||
// and the switch is committed to storage in full before the attempt
|
// running: the popup writes the switched record to storage in full
|
||||||
// goes any further.
|
// before the attempt goes any further.
|
||||||
//
|
//
|
||||||
// It is fired from inside the attempt's SECOND state read, because
|
// It is fired from inside the attempt's SECOND state read, because
|
||||||
// that is where the window used to be: the chain id was captured at
|
// that is where the window used to be: the chain id was captured at
|
||||||
@@ -277,18 +278,18 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
|||||||
// this to fire on, and the switch below runs after the attempt is
|
// this to fire on, and the switch below runs after the attempt is
|
||||||
// done instead — which is the point.
|
// done instead — which is the point.
|
||||||
let reads = 0;
|
let reads = 0;
|
||||||
let switched = null;
|
let switched = false;
|
||||||
const doSwitch = async () => {
|
const doSwitch = () => {
|
||||||
switched = bg.rpc("wallet_switchEthereumChain", [
|
const record = bg.persisted();
|
||||||
{ chainId: MAINNET.chainId },
|
applyChainSwitchFields(record, MAINNET.id);
|
||||||
]);
|
global.chrome.storage.write("autistmask", record);
|
||||||
await settle();
|
switched = true;
|
||||||
};
|
};
|
||||||
bg.setGetHook(async () => {
|
bg.setGetHook(async () => {
|
||||||
reads++;
|
reads++;
|
||||||
if (reads !== 2) return;
|
if (reads !== 2) return;
|
||||||
bg.setGetHook(null);
|
bg.setGetHook(null);
|
||||||
await doSwitch();
|
doSwitch();
|
||||||
});
|
});
|
||||||
|
|
||||||
const attempt = bg.send(
|
const attempt = bg.send(
|
||||||
@@ -303,8 +304,7 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
|||||||
await settle();
|
await settle();
|
||||||
|
|
||||||
bg.setGetHook(null);
|
bg.setGetHook(null);
|
||||||
if (!switched) await doSwitch();
|
if (!switched) doSwitch();
|
||||||
expect(switched.result()).toEqual({ result: null });
|
|
||||||
expect(bg.persisted().networkId).toBe("mainnet");
|
expect(bg.persisted().networkId).toBe("mainnet");
|
||||||
await settle();
|
await settle();
|
||||||
|
|
||||||
|
|||||||
+328
-42
@@ -1,16 +1,24 @@
|
|||||||
// Who may move the active chain.
|
// Who may move the active chain, and when.
|
||||||
//
|
//
|
||||||
// wallet_switchEthereumChain used to be answered for any origin at all, with
|
// wallet_switchEthereumChain used to be answered for any origin at all, with
|
||||||
// no connection check and no prompt, so a page the user had never connected
|
// no connection check and no prompt, so a page the user had never connected
|
||||||
// to could clear the [TESTNET] banner under someone who believed they were
|
// to could clear the [TESTNET] banner under someone who believed they were
|
||||||
// on Sepolia (https://git.eeqj.de/sneak/AutistMask/issues/308). The refusal
|
// on Sepolia (https://git.eeqj.de/sneak/AutistMask/issues/308). Gated on the
|
||||||
// is asserted as a refusal to ACT — the state unmoved and no chainChanged
|
// connection, a connected site could still move the wallet between mainnet and
|
||||||
// broadcast — because an error code alone would not distinguish a gate from
|
// Sepolia without asking. Only the user switches the network: a connected
|
||||||
// a switch that happened and then reported a failure.
|
// site's request opens a prompt, and nothing changes unless the user approves
|
||||||
|
// it there (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||||
//
|
//
|
||||||
// The endpoint half of that issue lives in tests/networkEndpoints.test.js,
|
// Every refusal is asserted as a refusal to ACT — the stored record unmoved
|
||||||
// which covers the popup's chain switch; this file covers the background's,
|
// and no chainChanged broadcast — because an error code alone would not
|
||||||
// which goes through storage rather than the shared state singleton.
|
// distinguish a refusal from a switch that happened and then reported a
|
||||||
|
// failure.
|
||||||
|
//
|
||||||
|
// The endpoint half of #308 lives in tests/networkEndpoints.test.js, which
|
||||||
|
// covers the popup's chain switch; this file covers the background's, which
|
||||||
|
// goes through storage rather than the shared state singleton. The last block
|
||||||
|
// covers what the background tells open tabs when the user switches the
|
||||||
|
// network in Settings.
|
||||||
|
|
||||||
const { networkById } = require("../src/shared/networks");
|
const { networkById } = require("../src/shared/networks");
|
||||||
const { makeStorageStub } = require("./support/storageStub");
|
const { makeStorageStub } = require("./support/storageStub");
|
||||||
@@ -21,18 +29,23 @@ const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
|||||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
const STRANGER_ORIGIN = "https://stranger.example";
|
const STRANGER_ORIGIN = "https://stranger.example";
|
||||||
|
|
||||||
|
const EXT_URL = "chrome-extension://autistmask/";
|
||||||
|
|
||||||
const MAINNET = networkById("mainnet");
|
const MAINNET = networkById("mainnet");
|
||||||
const SEPOLIA = networkById("sepolia");
|
const SEPOLIA = networkById("sepolia");
|
||||||
|
|
||||||
// The user's own node, so a switch that happens is visible as the loss of it.
|
// The user's own node, so a switch that happens is visible as the loss of it.
|
||||||
const CUSTOM_RPC = "http://127.0.0.1:8545";
|
const CUSTOM_RPC = "http://127.0.0.1:8545";
|
||||||
|
|
||||||
|
// A balance a switch would clear, so a switch that happens is visible here too.
|
||||||
function walletFixture() {
|
function walletFixture() {
|
||||||
return [
|
return [
|
||||||
{
|
{
|
||||||
name: "Wallet 1",
|
name: "Wallet 1",
|
||||||
type: "hd",
|
type: "hd",
|
||||||
addresses: [{ address: ADDRESS, balance: "0", tokenBalances: [] }],
|
addresses: [
|
||||||
|
{ address: ADDRESS, balance: "1.5", tokenBalances: [] },
|
||||||
|
],
|
||||||
},
|
},
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
@@ -47,10 +60,6 @@ afterEach(() => {
|
|||||||
delete global.chrome;
|
delete global.chrome;
|
||||||
});
|
});
|
||||||
|
|
||||||
// ---------------------------------------------------------------------------
|
|
||||||
// The gate: which origins the background will switch the chain for.
|
|
||||||
// ---------------------------------------------------------------------------
|
|
||||||
|
|
||||||
// Load the background worker against stubbed browser APIs, with the real
|
// Load the background worker against stubbed browser APIs, with the real
|
||||||
// chain-switch and persistence modules behind it, and return the handles to
|
// chain-switch and persistence modules behind it, and return the handles to
|
||||||
// drive it.
|
// drive it.
|
||||||
@@ -91,30 +100,46 @@ function loadBackground() {
|
|||||||
const storage = makeStorageStub({ autistmask: persisted });
|
const storage = makeStorageStub({ autistmask: persisted });
|
||||||
|
|
||||||
let messageListener = null;
|
let messageListener = null;
|
||||||
|
let connectListener = null;
|
||||||
|
let windowRemovedListener = null;
|
||||||
|
// The URL of every approval window the background opened. The approval id
|
||||||
|
// is in it, and that is how the popup learns which approval it answers.
|
||||||
|
const opened = [];
|
||||||
// Every message the background pushed at a content script. chainChanged
|
// Every message the background pushed at a content script. chainChanged
|
||||||
// is what tells a page the wallet moved, so an ungated switch is visible
|
// is what tells a page the wallet moved, so a switch is visible here as
|
||||||
// here as well as in the state.
|
// well as in the state.
|
||||||
const toTabs = [];
|
const toTabs = [];
|
||||||
|
|
||||||
global.chrome = {
|
global.chrome = {
|
||||||
storage,
|
storage,
|
||||||
runtime: {
|
runtime: {
|
||||||
getURL: (path) => "chrome-extension://autistmask/" + path,
|
getURL: (path) => EXT_URL + path,
|
||||||
onMessage: {
|
onMessage: {
|
||||||
addListener: (fn) => {
|
addListener: (fn) => {
|
||||||
messageListener = fn;
|
messageListener = fn;
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
onConnect: { addListener: () => {} },
|
onConnect: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
connectListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
lastError: null,
|
lastError: null,
|
||||||
},
|
},
|
||||||
windows: {
|
windows: {
|
||||||
getLastFocused: (cb) => cb(null),
|
getLastFocused: (cb) => cb(null),
|
||||||
create: (options, cb) => cb({ id: 1 }),
|
create: (options, cb) => {
|
||||||
|
opened.push(options.url);
|
||||||
|
cb({ id: opened.length });
|
||||||
|
},
|
||||||
remove: (id, cb) => {
|
remove: (id, cb) => {
|
||||||
if (cb) cb();
|
if (cb) cb();
|
||||||
},
|
},
|
||||||
onRemoved: { addListener: () => {} },
|
onRemoved: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
windowRemovedListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
},
|
},
|
||||||
tabs: {
|
tabs: {
|
||||||
query: (queryInfo, cb) => cb([{ id: 1 }]),
|
query: (queryInfo, cb) => cb([{ id: 1 }]),
|
||||||
@@ -128,6 +153,8 @@ function loadBackground() {
|
|||||||
|
|
||||||
require("../src/background/index");
|
require("../src/background/index");
|
||||||
|
|
||||||
|
// A page's request. Its answer is read with result(), which is null for as
|
||||||
|
// long as the request is waiting on the user.
|
||||||
async function switchChain(chainId, origin) {
|
async function switchChain(chainId, origin) {
|
||||||
let result = null;
|
let result = null;
|
||||||
messageListener(
|
messageListener(
|
||||||
@@ -142,55 +169,309 @@ function loadBackground() {
|
|||||||
},
|
},
|
||||||
);
|
);
|
||||||
await settle();
|
await settle();
|
||||||
return result;
|
return { result: () => result };
|
||||||
|
}
|
||||||
|
|
||||||
|
function promptId() {
|
||||||
|
return new URL(opened[opened.length - 1]).searchParams.get("approval");
|
||||||
|
}
|
||||||
|
|
||||||
|
// What the popup is told to show for the prompt.
|
||||||
|
function describePrompt() {
|
||||||
|
let reply = null;
|
||||||
|
messageListener(
|
||||||
|
{ type: "AUTISTMASK_GET_APPROVAL", id: promptId() },
|
||||||
|
{ url: EXT_URL + "src/popup/index.html" },
|
||||||
|
(r) => {
|
||||||
|
reply = r;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
return reply;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The user's answer, as the popup sends it: on the port named for the
|
||||||
|
// approval, from the extension's own page, and then the window closes.
|
||||||
|
async function answerPrompt(approved) {
|
||||||
|
const onMessage = [];
|
||||||
|
const onDisconnect = [];
|
||||||
|
const port = {
|
||||||
|
name: "approval:" + promptId(),
|
||||||
|
sender: { url: EXT_URL + "src/popup/index.html" },
|
||||||
|
onMessage: { addListener: (fn) => onMessage.push(fn) },
|
||||||
|
onDisconnect: { addListener: (fn) => onDisconnect.push(fn) },
|
||||||
|
};
|
||||||
|
connectListener(port);
|
||||||
|
for (const fn of onMessage) {
|
||||||
|
fn(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_APPROVAL_DECISION",
|
||||||
|
approved,
|
||||||
|
remember: false,
|
||||||
|
},
|
||||||
|
port,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
for (const fn of onDisconnect) fn(port);
|
||||||
|
await settle();
|
||||||
|
}
|
||||||
|
|
||||||
|
// The user closes the prompt window without answering it.
|
||||||
|
async function closePrompt() {
|
||||||
|
windowRemovedListener(opened.length);
|
||||||
|
await settle();
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
switchChain,
|
switchChain,
|
||||||
|
describePrompt,
|
||||||
|
answerPrompt,
|
||||||
|
closePrompt,
|
||||||
|
opened,
|
||||||
|
// A message to the background from `sender`, and its answer.
|
||||||
|
send: (msg, sender) => {
|
||||||
|
let reply = null;
|
||||||
|
messageListener(msg, sender, (r) => {
|
||||||
|
reply = r;
|
||||||
|
});
|
||||||
|
return reply;
|
||||||
|
},
|
||||||
walletState: () => storage.read("autistmask"),
|
walletState: () => storage.read("autistmask"),
|
||||||
chainChangedEvents: () =>
|
chainChangedEvents: () =>
|
||||||
toTabs.filter((m) => m.eventName === "chainChanged"),
|
toTabs.filter((m) => m.eventName === "chainChanged"),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const USER_REJECTED = { code: 4001, message: "User rejected the request." };
|
||||||
|
|
||||||
describe("wallet_switchEthereumChain is gated on the connection", () => {
|
describe("wallet_switchEthereumChain is gated on the connection", () => {
|
||||||
test("an origin the wallet was never connected to is refused with 4100", async () => {
|
test("an origin the wallet was never connected to is refused with 4100", async () => {
|
||||||
const bg = loadBackground();
|
const bg = loadBackground();
|
||||||
|
const before = bg.walletState();
|
||||||
|
|
||||||
const result = await bg.switchChain(SEPOLIA.chainId, STRANGER_ORIGIN);
|
const request = await bg.switchChain(SEPOLIA.chainId, STRANGER_ORIGIN);
|
||||||
|
|
||||||
expect(result.error).toEqual({ code: 4100, message: "Unauthorized" });
|
expect(request.result().error).toEqual({
|
||||||
expect(result.result).toBeUndefined();
|
code: 4100,
|
||||||
|
message: "Unauthorized",
|
||||||
|
});
|
||||||
|
expect(request.result().result).toBeUndefined();
|
||||||
// The refusal has to be a refusal to ACT, not just an error string:
|
// The refusal has to be a refusal to ACT, not just an error string:
|
||||||
// the wallet is still on mainnet, still on the user's own node, and
|
// the wallet is still on mainnet, still on the user's own node, and
|
||||||
// no page was told the chain moved.
|
// no page was told the chain moved. Nor was the user asked.
|
||||||
expect(bg.walletState().networkId).toBe("mainnet");
|
expect(bg.walletState()).toEqual(before);
|
||||||
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
|
|
||||||
expect(bg.chainChangedEvents()).toEqual([]);
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
|
expect(bg.opened).toEqual([]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("an unconnected origin is refused even for the chain already active", async () => {
|
test("an unconnected origin is refused even for the chain already active", async () => {
|
||||||
const bg = loadBackground();
|
const bg = loadBackground();
|
||||||
|
|
||||||
const result = await bg.switchChain(MAINNET.chainId, STRANGER_ORIGIN);
|
const request = await bg.switchChain(MAINNET.chainId, STRANGER_ORIGIN);
|
||||||
|
|
||||||
expect(result.error).toEqual({ code: 4100, message: "Unauthorized" });
|
expect(request.result().error).toEqual({
|
||||||
|
code: 4100,
|
||||||
|
message: "Unauthorized",
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
test("an unconnected origin is refused before the unsupported-chain answer", async () => {
|
test("an unconnected origin is refused before the unsupported-chain answer", async () => {
|
||||||
const bg = loadBackground();
|
const bg = loadBackground();
|
||||||
|
|
||||||
const result = await bg.switchChain("0x89", STRANGER_ORIGIN);
|
const request = await bg.switchChain("0x89", STRANGER_ORIGIN);
|
||||||
|
|
||||||
expect(result.error.code).toBe(4100);
|
expect(request.result().error.code).toBe(4100);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("only the user switches the network", () => {
|
||||||
|
test("a connected site's request changes nothing while the prompt is open", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const before = bg.walletState();
|
||||||
|
|
||||||
|
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
|
||||||
|
// Waiting on the user, with one prompt on screen naming the site and
|
||||||
|
// both networks.
|
||||||
|
expect(request.result()).toBeNull();
|
||||||
|
expect(bg.opened).toHaveLength(1);
|
||||||
|
expect(bg.describePrompt()).toMatchObject({
|
||||||
|
origin: CONNECTED_ORIGIN,
|
||||||
|
type: "network",
|
||||||
|
currentNetworkId: "mainnet",
|
||||||
|
requestedNetworkId: "sepolia",
|
||||||
});
|
});
|
||||||
|
|
||||||
test("a connected origin switches the chain", async () => {
|
// The network, the endpoints and the balances are as they were, and
|
||||||
|
// no page was told otherwise.
|
||||||
|
expect(bg.walletState()).toEqual(before);
|
||||||
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("approving the prompt switches the network", async () => {
|
||||||
const bg = loadBackground();
|
const bg = loadBackground();
|
||||||
|
|
||||||
const result = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
await bg.answerPrompt(true);
|
||||||
|
|
||||||
|
expect(request.result()).toEqual({ result: null });
|
||||||
|
const after = bg.walletState();
|
||||||
|
expect(after.networkId).toBe("sepolia");
|
||||||
|
expect(after.rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
|
||||||
|
expect(after.wallets[0].addresses[0].balance).toBe("0");
|
||||||
|
expect(bg.chainChangedEvents()).toEqual([
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_EVENT",
|
||||||
|
eventName: "chainChanged",
|
||||||
|
data: SEPOLIA.chainId,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("rejecting the prompt changes nothing and answers 4001", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const before = bg.walletState();
|
||||||
|
|
||||||
|
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
await bg.answerPrompt(false);
|
||||||
|
|
||||||
|
expect(request.result()).toEqual({ error: USER_REJECTED });
|
||||||
|
expect(bg.walletState()).toEqual(before);
|
||||||
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("closing the prompt without answering changes nothing and answers 4001", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const before = bg.walletState();
|
||||||
|
|
||||||
|
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
await bg.closePrompt();
|
||||||
|
|
||||||
|
expect(request.result()).toEqual({ error: USER_REJECTED });
|
||||||
|
expect(bg.walletState()).toEqual(before);
|
||||||
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a request for the chain already active opens no prompt", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const before = bg.walletState();
|
||||||
|
|
||||||
|
const request = await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
|
||||||
|
|
||||||
|
expect(request.result()).toEqual({ result: null });
|
||||||
|
expect(bg.opened).toEqual([]);
|
||||||
|
expect(bg.walletState()).toEqual(before);
|
||||||
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a second request while the prompt is open is refused with -32002", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
|
||||||
|
const first = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
const second = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
|
||||||
|
expect(second.result().error.code).toBe(-32002);
|
||||||
|
expect(bg.opened).toHaveLength(1);
|
||||||
|
|
||||||
|
// The first prompt still decides.
|
||||||
|
await bg.answerPrompt(true);
|
||||||
|
expect(first.result()).toEqual({ result: null });
|
||||||
|
expect(bg.walletState().networkId).toBe("sepolia");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a request for an unsupported chain still gets 4902 and no prompt", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
|
||||||
|
const request = await bg.switchChain("0x89", CONNECTED_ORIGIN);
|
||||||
|
|
||||||
|
expect(request.result().error.code).toBe(4902);
|
||||||
|
expect(bg.opened).toEqual([]);
|
||||||
|
expect(bg.walletState().networkId).toBe("mainnet");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an approved switch keeps the user's endpoint", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
|
||||||
|
await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||||
|
await bg.answerPrompt(true);
|
||||||
|
expect(bg.walletState().rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
|
||||||
|
|
||||||
|
await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
|
||||||
|
await bg.answerPrompt(true);
|
||||||
|
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// Switching the network in Settings tells open pages, as an approved site
|
||||||
|
// request does (https://git.eeqj.de/sneak/AutistMask/issues/500). These drive
|
||||||
|
// the real Settings view over the background's storage, with what it sends
|
||||||
|
// delivered to the background from the extension's own page.
|
||||||
|
describe("switching the network in Settings tells every open tab", () => {
|
||||||
|
const POPUP = { url: EXT_URL + "src/popup/index.html" };
|
||||||
|
|
||||||
|
// A stand-in for one DOM node: enough of an element for init() to set
|
||||||
|
// properties on it and hang listeners off it.
|
||||||
|
function fakeElement() {
|
||||||
|
return {
|
||||||
|
value: "",
|
||||||
|
checked: false,
|
||||||
|
textContent: "",
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
classList: { add() {}, remove() {} },
|
||||||
|
listeners: {},
|
||||||
|
addEventListener(event, handler) {
|
||||||
|
this.listeners[event] = handler;
|
||||||
|
},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Settings, opened the way the popup opens it. Returns its network
|
||||||
|
// selector.
|
||||||
|
async function openSettings(bg) {
|
||||||
|
const elements = {};
|
||||||
|
const element = (id) => (elements[id] ||= fakeElement());
|
||||||
|
jest.doMock("../src/popup/views/helpers", () => ({
|
||||||
|
$: element,
|
||||||
|
showView: () => {},
|
||||||
|
updateDebugBanner: () => {},
|
||||||
|
showFlash: () => {},
|
||||||
|
escapeHtml: (s) => s,
|
||||||
|
flashCopyFeedback: () => {},
|
||||||
|
goBack: () => {},
|
||||||
|
pushCurrentView: () => {},
|
||||||
|
onViewLeave: () => {},
|
||||||
|
VIEWS: [],
|
||||||
|
}));
|
||||||
|
global.chrome.runtime.sendMessage = (msg) => {
|
||||||
|
bg.send(msg, POPUP);
|
||||||
|
};
|
||||||
|
await require("../src/shared/state").loadState();
|
||||||
|
require("../src/popup/views/settings").init({
|
||||||
|
pageClosed: new AbortController().signal,
|
||||||
|
});
|
||||||
|
const select = element("settings-network");
|
||||||
|
select.value = "mainnet";
|
||||||
|
return select;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The user picks `networkId` in the selector.
|
||||||
|
async function choose(select, networkId) {
|
||||||
|
select.value = networkId;
|
||||||
|
await select.listeners.change();
|
||||||
|
await settle();
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
jest.dontMock("../src/popup/views/helpers");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("switching to the other network sends chainChanged once, with its chain id", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const select = await openSettings(bg);
|
||||||
|
|
||||||
|
await choose(select, "sepolia");
|
||||||
|
|
||||||
expect(result).toEqual({ result: null });
|
|
||||||
expect(bg.walletState().networkId).toBe("sepolia");
|
expect(bg.walletState().networkId).toBe("sepolia");
|
||||||
expect(bg.chainChangedEvents()).toEqual([
|
expect(bg.chainChangedEvents()).toEqual([
|
||||||
{
|
{
|
||||||
@@ -201,22 +482,27 @@ describe("wallet_switchEthereumChain is gated on the connection", () => {
|
|||||||
]);
|
]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("a connected origin asking for an unsupported chain still gets 4902", async () => {
|
test("choosing the network already active changes nothing and sends nothing", async () => {
|
||||||
const bg = loadBackground();
|
const bg = loadBackground();
|
||||||
|
const select = await openSettings(bg);
|
||||||
|
const before = bg.walletState();
|
||||||
|
|
||||||
const result = await bg.switchChain("0x89", CONNECTED_ORIGIN);
|
await choose(select, "mainnet");
|
||||||
|
|
||||||
expect(result.error.code).toBe(4902);
|
expect(bg.walletState()).toEqual(before);
|
||||||
expect(bg.walletState().networkId).toBe("mainnet");
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("a switch by a connected origin keeps the user's endpoint", async () => {
|
test("a page cannot make the background send chainChanged", async () => {
|
||||||
const bg = loadBackground();
|
const bg = loadBackground();
|
||||||
|
|
||||||
await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
const reply = bg.send(
|
||||||
expect(bg.walletState().rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
|
{ type: "AUTISTMASK_NETWORK_CHANGED", chainId: SEPOLIA.chainId },
|
||||||
|
{ url: CONNECTED_ORIGIN + "/" },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
|
expect(reply).toEqual({ error: "Unauthorized sender" });
|
||||||
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
|
expect(bg.chainChangedEvents()).toEqual([]);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -14,6 +14,10 @@
|
|||||||
// itself: the handler has to do it. tests/chainSwitchGate.test.js mocks the
|
// itself: the handler has to do it. tests/chainSwitchGate.test.js mocks the
|
||||||
// state module wholesale and tests/networkEndpoints.test.js always loads
|
// state module wholesale and tests/networkEndpoints.test.js always loads
|
||||||
// first, so neither can see this.
|
// first, so neither can see this.
|
||||||
|
//
|
||||||
|
// A site's switch happens only once the user approves it on a prompt
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/408), so every switch here is
|
||||||
|
// approved the way the popup approves one.
|
||||||
|
|
||||||
const { networkById } = require("../src/shared/networks");
|
const { networkById } = require("../src/shared/networks");
|
||||||
const { makeStorageStub } = require("./support/storageStub");
|
const { makeStorageStub } = require("./support/storageStub");
|
||||||
@@ -90,6 +94,9 @@ function loadColdWorker(networkId) {
|
|||||||
const storage = makeStorageStub({ autistmask: storedProfile(networkId) });
|
const storage = makeStorageStub({ autistmask: storedProfile(networkId) });
|
||||||
|
|
||||||
let messageListener = null;
|
let messageListener = null;
|
||||||
|
let connectListener = null;
|
||||||
|
// The URL of every approval window opened; the approval id is in it.
|
||||||
|
const opened = [];
|
||||||
const toTabs = [];
|
const toTabs = [];
|
||||||
|
|
||||||
global.chrome = {
|
global.chrome = {
|
||||||
@@ -101,12 +108,19 @@ function loadColdWorker(networkId) {
|
|||||||
messageListener = fn;
|
messageListener = fn;
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
onConnect: { addListener: () => {} },
|
onConnect: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
connectListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
lastError: null,
|
lastError: null,
|
||||||
},
|
},
|
||||||
windows: {
|
windows: {
|
||||||
getLastFocused: (cb) => cb(null),
|
getLastFocused: (cb) => cb(null),
|
||||||
create: (options, cb) => cb({ id: 1 }),
|
create: (options, cb) => {
|
||||||
|
opened.push(options.url);
|
||||||
|
cb({ id: opened.length });
|
||||||
|
},
|
||||||
remove: (id, cb) => {
|
remove: (id, cb) => {
|
||||||
if (cb) cb();
|
if (cb) cb();
|
||||||
},
|
},
|
||||||
@@ -124,6 +138,32 @@ function loadColdWorker(networkId) {
|
|||||||
|
|
||||||
require("../src/background/index");
|
require("../src/background/index");
|
||||||
|
|
||||||
|
// The user approves the prompt the request opened, as the popup does: a
|
||||||
|
// decision on the port named for the approval, from the extension's own
|
||||||
|
// page.
|
||||||
|
function approvePrompt() {
|
||||||
|
const id = new URL(opened[opened.length - 1]).searchParams.get(
|
||||||
|
"approval",
|
||||||
|
);
|
||||||
|
let onDecision = null;
|
||||||
|
const port = {
|
||||||
|
name: "approval:" + id,
|
||||||
|
sender: { url: "chrome-extension://autistmask/src/popup/" },
|
||||||
|
onMessage: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
onDecision = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
onDisconnect: { addListener: () => {} },
|
||||||
|
};
|
||||||
|
connectListener(port);
|
||||||
|
onDecision(
|
||||||
|
{ type: "AUTISTMASK_APPROVAL_DECISION", approved: true },
|
||||||
|
port,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// A connected site asks for `chainId`, and the user approves it.
|
||||||
async function switchChain(chainId) {
|
async function switchChain(chainId) {
|
||||||
let result = null;
|
let result = null;
|
||||||
messageListener(
|
messageListener(
|
||||||
@@ -138,6 +178,8 @@ function loadColdWorker(networkId) {
|
|||||||
},
|
},
|
||||||
);
|
);
|
||||||
await settle();
|
await settle();
|
||||||
|
approvePrompt();
|
||||||
|
await settle();
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -253,7 +253,7 @@ describe("reaching the screen", () => {
|
|||||||
const { decryptWithPassword } = require("../src/shared/vault");
|
const { decryptWithPassword } = require("../src/shared/vault");
|
||||||
decryptWithPassword.mockRejectedValue(new Error("nope"));
|
decryptWithPassword.mockRejectedValue(new Error("nope"));
|
||||||
await click("btn-delete-wallet-confirm");
|
await click("btn-delete-wallet-confirm");
|
||||||
expect(node("delete-wallet-flash").textContent).toBe(
|
expect(node("delete-wallet-password-error").textContent).toBe(
|
||||||
"That password is incorrect. Please try again.",
|
"That password is incorrect. Please try again.",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -279,12 +279,18 @@ class Driver {
|
|||||||
|
|
||||||
// Shown means shown: in the popup a view is switched by toggling a
|
// Shown means shown: in the popup a view is switched by toggling a
|
||||||
// "hidden" class, and an element that is present but collapsed is not
|
// "hidden" class, and an element that is present but collapsed is not
|
||||||
// the thing a test means by visible.
|
// the thing a test means by visible. Until the page's stylesheet has
|
||||||
|
// applied that class hides nothing and every view lays out, so the page
|
||||||
|
// must also have finished loading, which it does only after its
|
||||||
|
// stylesheet, and neither the element nor anything enclosing it may
|
||||||
|
// carry the class (https://git.eeqj.de/sneak/AutistMask/issues/502).
|
||||||
async waitVisible(selector, timeout = DEFAULT_WAIT_MS) {
|
async waitVisible(selector, timeout = DEFAULT_WAIT_MS) {
|
||||||
return this.waitFor(
|
return this.waitFor(
|
||||||
"selector " + selector + " to be visible",
|
"selector " + selector + " to be visible",
|
||||||
`const el = document.querySelector(arguments[0]);
|
`const el = document.querySelector(arguments[0]);
|
||||||
if (!el) return false;
|
if (document.readyState !== "complete" || !el) return false;
|
||||||
|
if (el.closest(".hidden")) return false;
|
||||||
|
if (getComputedStyle(el).visibility !== "visible") return false;
|
||||||
const r = el.getBoundingClientRect();
|
const r = el.getBoundingClientRect();
|
||||||
return r.width > 0 && r.height > 0;`,
|
return r.width > 0 && r.height > 0;`,
|
||||||
[selector],
|
[selector],
|
||||||
|
|||||||
+155
-52
@@ -63,6 +63,7 @@ const {
|
|||||||
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
|
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
|
||||||
const { startDappServer } = require("./dapp");
|
const { startDappServer } = require("./dapp");
|
||||||
const { STUB_COUNTERPARTY } = require("../network");
|
const { STUB_COUNTERPARTY } = require("../network");
|
||||||
|
const { NETWORKS } = require("../../../src/shared/networks");
|
||||||
const {
|
const {
|
||||||
STATE_SCHEMA_VERSION,
|
STATE_SCHEMA_VERSION,
|
||||||
stateProblem,
|
stateProblem,
|
||||||
@@ -684,6 +685,159 @@ step(
|
|||||||
},
|
},
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// The network fields of the stored record, read on the popup page, the one
|
||||||
|
// moz-extension:// document the suite has open.
|
||||||
|
async function storedNetwork(env) {
|
||||||
|
const d = env.driver;
|
||||||
|
await d.switchToWindow(env.popupWindow);
|
||||||
|
const stored = await d.executeAsync(
|
||||||
|
`const done = arguments[arguments.length - 1];
|
||||||
|
const api = typeof browser !== "undefined" ? browser : chrome;
|
||||||
|
Promise.resolve(api.storage.local.get("autistmask")).then(
|
||||||
|
(r) => done({
|
||||||
|
networkId: r.autistmask.networkId,
|
||||||
|
rpcUrl: r.autistmask.rpcUrl,
|
||||||
|
blockscoutUrl: r.autistmask.blockscoutUrl,
|
||||||
|
}),
|
||||||
|
(e) => done({ error: String((e && e.message) || e) }),
|
||||||
|
);`,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
stored && !stored.error,
|
||||||
|
"could not read the stored network: " + (stored && stored.error),
|
||||||
|
);
|
||||||
|
return stored;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Every chainChanged event the test page has been sent, waiting up to
|
||||||
|
// `timeout` for there to be `count` of them: the background sends the event
|
||||||
|
// alongside its answer to the request, so it can arrive just after it. Leaves
|
||||||
|
// the driver on the page.
|
||||||
|
async function chainChangedEvents(env, count = 0, timeout = 5000) {
|
||||||
|
const d = env.driver;
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
const deadline = Date.now() + timeout;
|
||||||
|
for (;;) {
|
||||||
|
const events = (await dappMessages(d, "AUTISTMASK_EVENT")).filter(
|
||||||
|
(m) => m.eventName === "chainChanged",
|
||||||
|
);
|
||||||
|
if (events.length >= count || Date.now() > deadline) return events;
|
||||||
|
await sleep(100);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Ask, from the page, to switch from network `from` to network `to`, and
|
||||||
|
// return the prompt that opens, checked to name the site and both networks.
|
||||||
|
// Leaves the driver on the prompt.
|
||||||
|
async function openNetworkPrompt(env, key, from, to) {
|
||||||
|
const d = env.driver;
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await startRequest(d, key, "wallet_switchEthereumChain", [
|
||||||
|
{ chainId: to.chainId },
|
||||||
|
]);
|
||||||
|
const popup = await waitForApprovalWindow(d);
|
||||||
|
await d.switchToWindow(popup);
|
||||||
|
await d.waitVisible("#view-approve-network");
|
||||||
|
const screen = {
|
||||||
|
origin: await d.text("#approve-network-origin"),
|
||||||
|
current: await d.text("#approve-network-current"),
|
||||||
|
requested: await d.text("#approve-network-requested"),
|
||||||
|
};
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(screen, {
|
||||||
|
origin: env.server.origin,
|
||||||
|
current: from.name,
|
||||||
|
requested: to.name,
|
||||||
|
}),
|
||||||
|
"the network switch prompt shows " + JSON.stringify(screen),
|
||||||
|
);
|
||||||
|
return popup;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Only the user switches the network. A connected site's request opens a
|
||||||
|
// prompt, and until the user approves it the stored network does not move and
|
||||||
|
// no page is told it did (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||||
|
// The wallet goes back to mainnet the same way at the end, for the transaction
|
||||||
|
// step after this one.
|
||||||
|
step(
|
||||||
|
"a site's network switch changes nothing until the user approves it",
|
||||||
|
async (env) => {
|
||||||
|
const d = env.driver;
|
||||||
|
const { mainnet, sepolia } = NETWORKS;
|
||||||
|
const before = await storedNetwork(env);
|
||||||
|
assert(
|
||||||
|
before.networkId === "mainnet",
|
||||||
|
"this step starts on mainnet, not on " + before.networkId,
|
||||||
|
);
|
||||||
|
const eventsBefore = (await chainChangedEvents(env)).length;
|
||||||
|
|
||||||
|
const rejected = await openNetworkPrompt(
|
||||||
|
env,
|
||||||
|
"switch-reject",
|
||||||
|
mainnet,
|
||||||
|
sepolia,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env), before),
|
||||||
|
"the network moved while its prompt was still open",
|
||||||
|
);
|
||||||
|
// Nothing else closes this window, so a click that did not land
|
||||||
|
// leaves the request unanswered and the assertion below fails.
|
||||||
|
await d.switchToWindow(rejected);
|
||||||
|
await d.click("#btn-reject-network");
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
await assertUserRejection(
|
||||||
|
d,
|
||||||
|
"switch-reject",
|
||||||
|
"the network switch rejection",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env), before),
|
||||||
|
"a rejected network switch moved the network",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
(await chainChangedEvents(env)).length === eventsBefore,
|
||||||
|
"a rejected network switch told the page the chain changed",
|
||||||
|
);
|
||||||
|
|
||||||
|
await openNetworkPrompt(env, "switch-approve", mainnet, sepolia);
|
||||||
|
await d.click("#btn-approve-network");
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
let outcome = await settleRequest(d, "switch-approve");
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved" && outcome.result === null,
|
||||||
|
"the approved network switch did not resolve: " +
|
||||||
|
JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
(await storedNetwork(env)).networkId === "sepolia",
|
||||||
|
"the approved network switch did not move the network",
|
||||||
|
);
|
||||||
|
const events = await chainChangedEvents(env, eventsBefore + 1);
|
||||||
|
assert(
|
||||||
|
events.length === eventsBefore + 1 &&
|
||||||
|
events[events.length - 1].data === sepolia.chainId,
|
||||||
|
"the page was not told of the approved switch: " +
|
||||||
|
JSON.stringify(events),
|
||||||
|
);
|
||||||
|
|
||||||
|
await openNetworkPrompt(env, "switch-restore", sepolia, mainnet);
|
||||||
|
await d.click("#btn-approve-network");
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
outcome = await settleRequest(d, "switch-restore");
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved",
|
||||||
|
"switching back to mainnet did not resolve: " +
|
||||||
|
JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env), before),
|
||||||
|
"switching back did not restore the mainnet network and endpoints",
|
||||||
|
);
|
||||||
|
await d.switchToWindow(env.dappWindow);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
step(
|
step(
|
||||||
"eth_sendTransaction shows the transaction and returns its hash",
|
"eth_sendTransaction shows the transaction and returns its hash",
|
||||||
async (env) => {
|
async (env) => {
|
||||||
@@ -854,37 +1008,6 @@ step(
|
|||||||
|
|
||||||
// ------------------------------------------------------------- runner
|
// ------------------------------------------------------------- runner
|
||||||
|
|
||||||
// Uncaught extension errors that are known, tracked and deliberately
|
|
||||||
// tolerated, in the same spirit as ALLOWED_ERRORS in tests/e2e/harness.js:
|
|
||||||
// every entry names the issue that will delete it, and every occurrence is
|
|
||||||
// still printed, so tolerating one is visible in the log rather than silent.
|
|
||||||
// This is the only concession in an otherwise zero-tolerance policy.
|
|
||||||
const ALLOWED_ERRORS = [
|
|
||||||
{
|
|
||||||
// The site-connection buttons in src/popup/views/approval.js send
|
|
||||||
// their decision and call window.close() on the next line. Firefox's
|
|
||||||
// BaseContext.wrapPromise reports, through Cu.reportError, any
|
|
||||||
// extension-API promise that settles after its context unloaded —
|
|
||||||
// whether or not the caller attached a handler, so notify()'s catch
|
|
||||||
// cannot suppress it.
|
|
||||||
//
|
|
||||||
// Pre-existing, and not introduced by the promise shim: the send was
|
|
||||||
// already unawaited, and this suite is merely the first thing to
|
|
||||||
// drive that window on Firefox. It is the same teardown ordering as
|
|
||||||
// the issue below, whose fix — making the outcome independent of when
|
|
||||||
// the popup closes — removes this entry with it.
|
|
||||||
pattern: /Promise (?:resolved|rejected) after context unloaded/,
|
|
||||||
source: /\/src\/popup\/index\.js$/,
|
|
||||||
issue: "https://git.eeqj.de/sneak/AutistMask/issues/275",
|
|
||||||
},
|
|
||||||
];
|
|
||||||
|
|
||||||
function allowedFor(e) {
|
|
||||||
return ALLOWED_ERRORS.find(
|
|
||||||
(a) => a.pattern.test(e.msg) && a.source.test(e.src),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function formatError(e) {
|
function formatError(e) {
|
||||||
return (
|
return (
|
||||||
e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")"
|
e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")"
|
||||||
@@ -1001,20 +1124,6 @@ async function main() {
|
|||||||
installFailure = null;
|
installFailure = null;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Tolerated errors are set aside, never dropped: each one is
|
|
||||||
// printed with the issue that keeps it on the list, so the
|
|
||||||
// concession stays in the run output.
|
|
||||||
const tolerated = found.filter((e) => allowedFor(e));
|
|
||||||
found = found.filter((e) => !allowedFor(e));
|
|
||||||
for (const e of tolerated) {
|
|
||||||
console.log(
|
|
||||||
"# tolerated (" +
|
|
||||||
allowedFor(e).issue +
|
|
||||||
"): " +
|
|
||||||
formatError(e),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Any uncaught error from an extension source fails the step
|
// Any uncaught error from an extension source fails the step
|
||||||
// that provoked it, whether or not its assertions passed.
|
// that provoked it, whether or not its assertions passed.
|
||||||
if (!failure && found.length > 0) {
|
if (!failure && found.length > 0) {
|
||||||
@@ -1039,13 +1148,7 @@ async function main() {
|
|||||||
// blamed on any one step, but they are still reported and they
|
// blamed on any one step, but they are still reported and they
|
||||||
// still fail the run.
|
// still fail the run.
|
||||||
await sleep(1000);
|
await sleep(1000);
|
||||||
const trailingAll = await errors.take();
|
const trailing = await errors.take();
|
||||||
for (const e of trailingAll.filter((x) => allowedFor(x))) {
|
|
||||||
console.log(
|
|
||||||
"# tolerated (" + allowedFor(e).issue + "): " + formatError(e),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const trailing = trailingAll.filter((e) => !allowedFor(e));
|
|
||||||
console.log(
|
console.log(
|
||||||
"# " +
|
"# " +
|
||||||
(steps.length - failed) +
|
(steps.length - failed) +
|
||||||
|
|||||||
+26
-1
@@ -333,8 +333,33 @@ async function launch(routeOpts) {
|
|||||||
|
|
||||||
const PASSWORD = "e2e-harness-password";
|
const PASSWORD = "e2e-harness-password";
|
||||||
|
|
||||||
|
// Waits until the page shows `selector`, not only until it lays out. Until the
|
||||||
|
// page's stylesheet has applied, the `hidden` class that showView() keeps on
|
||||||
|
// every view but the current one hides nothing and every view lays out, so a
|
||||||
|
// test could read a screen before the page's script had filled it
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/502). So the page must also
|
||||||
|
// have finished loading, which it does only after its stylesheet, and neither
|
||||||
|
// the element nor anything enclosing it may carry `hidden`. Polled on a timer:
|
||||||
|
// animation frames are not guaranteed to a window that is not in front.
|
||||||
async function visible(page, selector, timeout = 15000) {
|
async function visible(page, selector, timeout = 15000) {
|
||||||
await page.waitForSelector(selector, { state: "visible", timeout });
|
await page
|
||||||
|
.waitForFunction(
|
||||||
|
(sel) => {
|
||||||
|
const el = document.querySelector(sel);
|
||||||
|
if (document.readyState !== "complete" || !el) return false;
|
||||||
|
if (el.closest(".hidden")) return false;
|
||||||
|
if (getComputedStyle(el).visibility !== "visible") return false;
|
||||||
|
const r = el.getBoundingClientRect();
|
||||||
|
return r.width > 0 && r.height > 0;
|
||||||
|
},
|
||||||
|
selector,
|
||||||
|
{ polling: 50, timeout },
|
||||||
|
)
|
||||||
|
.catch((e) => {
|
||||||
|
throw new Error(
|
||||||
|
"the page did not show " + selector + ": " + e.message,
|
||||||
|
);
|
||||||
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// An empty WebAssembly module: magic number and version header, no
|
// An empty WebAssembly module: magic number and version header, no
|
||||||
|
|||||||
+301
-13
@@ -809,7 +809,7 @@ async function secretScreenState(page, view) {
|
|||||||
return page.evaluate(
|
return page.evaluate(
|
||||||
(v) => ({
|
(v) => ({
|
||||||
value: document.getElementById(v + "-value").textContent,
|
value: document.getElementById(v + "-value").textContent,
|
||||||
error: document.getElementById(v + "-flash").textContent,
|
error: document.getElementById(v + "-password-error").textContent,
|
||||||
html: document.getElementById("view-" + v).innerHTML,
|
html: document.getElementById("view-" + v).innerHTML,
|
||||||
resultHidden: document
|
resultHidden: document
|
||||||
.getElementById(v + "-result")
|
.getElementById(v + "-result")
|
||||||
@@ -906,7 +906,8 @@ test("a wrong password reveals nothing (#161)", async (env) => {
|
|||||||
await env.page.click("#btn-show-phrase-reveal");
|
await env.page.click("#btn-show-phrase-reveal");
|
||||||
await env.page.waitForFunction(
|
await env.page.waitForFunction(
|
||||||
() =>
|
() =>
|
||||||
document.getElementById("show-phrase-flash").textContent.length > 0,
|
document.getElementById("show-phrase-password-error").textContent
|
||||||
|
.length > 0,
|
||||||
null,
|
null,
|
||||||
{ timeout: 60000 },
|
{ timeout: 60000 },
|
||||||
);
|
);
|
||||||
@@ -1993,13 +1994,14 @@ test("an over-long flash message keeps to one line (#252)", async (env) => {
|
|||||||
|
|
||||||
// Every screen that asks for a password reserves room for one line of error.
|
// Every screen that asks for a password reserves room for one line of error.
|
||||||
// The two on the dApp approval screens also have a border and padding, which
|
// The two on the dApp approval screens also have a border and padding, which
|
||||||
// that reserved height has to cover too.
|
// that reserved height has to cover too. The add wallet screen's line sits
|
||||||
|
// beside its button rather than above it, and has its own test below.
|
||||||
const PASSWORD_ERROR_CONTAINERS = [
|
const PASSWORD_ERROR_CONTAINERS = [
|
||||||
"approve-tx-error",
|
"approve-tx-error",
|
||||||
"approve-sign-error",
|
"approve-sign-error",
|
||||||
"export-privkey-flash",
|
"export-privkey-password-error",
|
||||||
"show-phrase-flash",
|
"show-phrase-password-error",
|
||||||
"delete-wallet-flash",
|
"delete-wallet-password-error",
|
||||||
"confirm-tx-password-error",
|
"confirm-tx-password-error",
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -2064,6 +2066,107 @@ test("a password error moves nothing on any screen (#297)", async (env) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// ------------------------------------------ add wallet Import button (#493)
|
||||||
|
|
||||||
|
// At 360x600 the add wallet screen's Import button already starts near the
|
||||||
|
// bottom of the popup, so its password error line sits beside the button
|
||||||
|
// rather than above it. Measures the button and the line empty and again
|
||||||
|
// filled with the longest error addWallet.js puts there. Runs in the page.
|
||||||
|
function measureImportButton() {
|
||||||
|
const button = document.getElementById("btn-add-wallet-confirm");
|
||||||
|
const line = document.getElementById("add-wallet-password-error");
|
||||||
|
const measure = () => {
|
||||||
|
const b = button.getBoundingClientRect();
|
||||||
|
const l = line.getBoundingClientRect();
|
||||||
|
return {
|
||||||
|
buttonTop: b.top + window.scrollY,
|
||||||
|
buttonBottom: b.bottom + window.scrollY,
|
||||||
|
lineTop: l.top + window.scrollY,
|
||||||
|
lineBottom: l.bottom + window.scrollY,
|
||||||
|
};
|
||||||
|
};
|
||||||
|
const empty = measure();
|
||||||
|
line.textContent = "Password must be at least 12 characters.";
|
||||||
|
line.style.visibility = "visible";
|
||||||
|
const filled = measure();
|
||||||
|
line.textContent = "";
|
||||||
|
line.style.visibility = "hidden";
|
||||||
|
return { empty, filled };
|
||||||
|
}
|
||||||
|
|
||||||
|
test("the add wallet password error leaves Import where it was (#493)", async (env) => {
|
||||||
|
const page = await openPopup(env.ctx, env.popupUrl);
|
||||||
|
try {
|
||||||
|
await page.setViewportSize(POPUP_VIEWPORT);
|
||||||
|
// Brought up by toggling classes, as in the test above. The note
|
||||||
|
// addWallet.js shows once a wallet exists is the only part of the
|
||||||
|
// screen that differs between the first wallet and a later one.
|
||||||
|
await page.evaluate(() => {
|
||||||
|
const screen = document.getElementById("view-add-wallet");
|
||||||
|
for (const view of document.querySelectorAll(".view")) {
|
||||||
|
view.classList.toggle("hidden", view !== screen);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
for (const walletExists of [false, true]) {
|
||||||
|
await page.evaluate(
|
||||||
|
(shown) =>
|
||||||
|
document
|
||||||
|
.getElementById("add-wallet-separate-password-note")
|
||||||
|
.classList.toggle("hidden", !shown),
|
||||||
|
walletExists,
|
||||||
|
);
|
||||||
|
for (const tab of ["tab-mnemonic", "tab-privkey", "tab-xprv"]) {
|
||||||
|
await page.click("#" + tab);
|
||||||
|
const { empty, filled } =
|
||||||
|
await page.evaluate(measureImportButton);
|
||||||
|
const where =
|
||||||
|
"#" +
|
||||||
|
tab +
|
||||||
|
(walletExists
|
||||||
|
? " with a wallet already added"
|
||||||
|
: " for the first wallet");
|
||||||
|
// Printed pass or fail, as the dust threshold test does.
|
||||||
|
console.log(
|
||||||
|
"# add wallet Import top, " +
|
||||||
|
where +
|
||||||
|
": " +
|
||||||
|
empty.buttonTop +
|
||||||
|
"px",
|
||||||
|
);
|
||||||
|
for (const m of [empty, filled]) {
|
||||||
|
assert(
|
||||||
|
m.lineTop >= m.buttonTop &&
|
||||||
|
m.lineBottom <= m.buttonBottom,
|
||||||
|
"the error line on " +
|
||||||
|
where +
|
||||||
|
" does not fit beside Import, so it adds height: " +
|
||||||
|
JSON.stringify(m),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
assert(
|
||||||
|
filled.buttonTop === empty.buttonTop,
|
||||||
|
"Import moved " +
|
||||||
|
(filled.buttonTop - empty.buttonTop) +
|
||||||
|
"px when the error appeared on " +
|
||||||
|
where,
|
||||||
|
);
|
||||||
|
if (!walletExists) {
|
||||||
|
assert(
|
||||||
|
empty.buttonTop < POPUP_VIEWPORT.height,
|
||||||
|
"Import starts at " +
|
||||||
|
empty.buttonTop +
|
||||||
|
"px on " +
|
||||||
|
where +
|
||||||
|
", below the fold",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
await page.close();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
// --------------------------------------------- confirmation screen (#238)
|
// --------------------------------------------- confirmation screen (#238)
|
||||||
//
|
//
|
||||||
// The screen that decides what gets signed. The arithmetic underneath it
|
// The screen that decides what gets signed. The arithmetic underneath it
|
||||||
@@ -3396,7 +3499,7 @@ async function closeApprovalPages(ctx) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Click a button whose own handler closes the window it lives in — every
|
// Click a button whose own handler closes the window it lives in — every
|
||||||
// Reject, and Allow on the site prompt.
|
// Reject, Allow on the site prompt, and Switch on the network switch prompt.
|
||||||
//
|
//
|
||||||
// page.click() dispatches the click and then waits for the renderer to
|
// page.click() dispatches the click and then waits for the renderer to
|
||||||
// acknowledge it, and a page torn down by the handler never gets to. The
|
// acknowledge it, and a page torn down by the handler never gets to. The
|
||||||
@@ -3411,12 +3514,13 @@ async function closeApprovalPages(ctx) {
|
|||||||
// #btn-reject-sign, #btn-reject-tx — their disconnect leaves the approval
|
// #btn-reject-sign, #btn-reject-tx — their disconnect leaves the approval
|
||||||
// pending, so a click that never landed leaves the dApp promise unsettled
|
// pending, so a click that never landed leaves the dApp promise unsettled
|
||||||
// and the assertion after the call fails on its own.
|
// and the assertion after the call fails on its own.
|
||||||
// #btn-approve — only a decision resolves the promise, and a swallowed click
|
// #btn-approve, #btn-approve-network — only a decision resolves the promise,
|
||||||
// cannot produce settled === "resolved".
|
// and a swallowed click cannot produce settled === "resolved".
|
||||||
// #btn-reject on the site prompt — NOT self-proving. A page that went away
|
// #btn-reject on the site prompt, #btn-reject-network — NOT self-proving. A
|
||||||
// without the click landing disconnects the approval port, the background
|
// page that went away without the click landing disconnects the approval
|
||||||
// settles that as 4001, and 4001 is exactly what assertUserRejection
|
// port, the background settles that as 4001, and 4001 is exactly what
|
||||||
// accepts. Both call sites arm the click trace below and assert it.
|
// assertUserRejection accepts. Every call site arms the click trace below
|
||||||
|
// and asserts it.
|
||||||
//
|
//
|
||||||
// A button that is missing or unclickable raises a different error, which is
|
// A button that is missing or unclickable raises a different error, which is
|
||||||
// rethrown.
|
// rethrown.
|
||||||
@@ -4286,6 +4390,190 @@ test("a prompt raised while another approval window has focus opens its own (#29
|
|||||||
await assertUserRejection(env.dapp, "focus-sign", "the sign prompt");
|
await assertUserRejection(env.dapp, "focus-sign", "the sign prompt");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// The network fields of the stored record.
|
||||||
|
async function storedNetwork(page) {
|
||||||
|
const s = await storedRecord(page);
|
||||||
|
return {
|
||||||
|
networkId: s.networkId,
|
||||||
|
rpcUrl: s.rpcUrl,
|
||||||
|
blockscoutUrl: s.blockscoutUrl,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Every chainChanged event the test page has been sent, waiting up to
|
||||||
|
// `timeout` for there to be `count` of them: the background sends the event
|
||||||
|
// alongside its answer to the request, so it can arrive just after it.
|
||||||
|
async function chainChangedEvents(page, count = 0, timeout = 5000) {
|
||||||
|
const deadline = Date.now() + timeout;
|
||||||
|
for (;;) {
|
||||||
|
const events = (await dappMessages(page, "AUTISTMASK_EVENT")).filter(
|
||||||
|
(m) => m.eventName === "chainChanged",
|
||||||
|
);
|
||||||
|
if (events.length >= count || Date.now() > deadline) return events;
|
||||||
|
await sleep(50);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Ask, from the test page, to switch from network `from` to network `to`, and
|
||||||
|
// return the prompt that opens, checked to name the site and both networks.
|
||||||
|
async function openNetworkPrompt(env, key, from, to) {
|
||||||
|
await startRequest(env.dapp, key, "wallet_switchEthereumChain", [
|
||||||
|
{ chainId: to.chainId },
|
||||||
|
]);
|
||||||
|
const popup = await waitForApprovalWindow(env.ctx);
|
||||||
|
await visible(popup, "#view-approve-network");
|
||||||
|
const screen = await popup.evaluate(() => ({
|
||||||
|
origin: document.getElementById("approve-network-origin").textContent,
|
||||||
|
current: document.getElementById("approve-network-current").textContent,
|
||||||
|
requested: document.getElementById("approve-network-requested")
|
||||||
|
.textContent,
|
||||||
|
}));
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(screen, {
|
||||||
|
origin: DAPP_ORIGIN,
|
||||||
|
current: from.name,
|
||||||
|
requested: to.name,
|
||||||
|
}),
|
||||||
|
"the network switch prompt shows " + JSON.stringify(screen),
|
||||||
|
);
|
||||||
|
return popup;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Only the user switches the network. A connected site's request opens a
|
||||||
|
// prompt, and until the user approves it the stored network does not move and
|
||||||
|
// no page is told it did (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||||
|
// The wallet goes back to mainnet the same way at the end, for the tests after
|
||||||
|
// this one.
|
||||||
|
test("a site's network switch changes nothing until the user approves it (#408)", async (env) => {
|
||||||
|
const { mainnet, sepolia } = NETWORKS;
|
||||||
|
const before = await storedNetwork(env.page);
|
||||||
|
assert(
|
||||||
|
before.networkId === "mainnet",
|
||||||
|
"this test starts on mainnet, not on " + before.networkId,
|
||||||
|
);
|
||||||
|
const eventsBefore = (await chainChangedEvents(env.dapp)).length;
|
||||||
|
|
||||||
|
const rejected = await openNetworkPrompt(
|
||||||
|
env,
|
||||||
|
"switch-reject",
|
||||||
|
mainnet,
|
||||||
|
sepolia,
|
||||||
|
);
|
||||||
|
try {
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||||
|
"the network moved while its prompt was still open",
|
||||||
|
);
|
||||||
|
// Closing the prompt unanswered is also a rejection, so the click
|
||||||
|
// itself is witnessed.
|
||||||
|
await armClickTrace(env, rejected, "#btn-reject-network");
|
||||||
|
await clickAndClose(rejected, "#btn-reject-network");
|
||||||
|
await assertClickLanded(env, "#btn-reject-network");
|
||||||
|
await assertUserRejection(
|
||||||
|
env.dapp,
|
||||||
|
"switch-reject",
|
||||||
|
"the network switch rejection",
|
||||||
|
);
|
||||||
|
} finally {
|
||||||
|
await closeApprovalPages(env.ctx);
|
||||||
|
}
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||||
|
"a rejected network switch moved the network",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
(await chainChangedEvents(env.dapp)).length === eventsBefore,
|
||||||
|
"a rejected network switch told the page the chain changed",
|
||||||
|
);
|
||||||
|
|
||||||
|
const approved = await openNetworkPrompt(
|
||||||
|
env,
|
||||||
|
"switch-approve",
|
||||||
|
mainnet,
|
||||||
|
sepolia,
|
||||||
|
);
|
||||||
|
let outcome;
|
||||||
|
try {
|
||||||
|
await clickAndClose(approved, "#btn-approve-network");
|
||||||
|
outcome = await settleRequest(env.dapp, "switch-approve");
|
||||||
|
} finally {
|
||||||
|
await closeApprovalPages(env.ctx);
|
||||||
|
}
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved" && outcome.result === null,
|
||||||
|
"the approved network switch did not resolve: " +
|
||||||
|
JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
(await storedNetwork(env.page)).networkId === "sepolia",
|
||||||
|
"the approved network switch did not move the network",
|
||||||
|
);
|
||||||
|
const events = await chainChangedEvents(env.dapp, eventsBefore + 1);
|
||||||
|
assert(
|
||||||
|
events.length === eventsBefore + 1 &&
|
||||||
|
events[events.length - 1].data === sepolia.chainId,
|
||||||
|
"the page was not told of the approved switch: " +
|
||||||
|
JSON.stringify(events),
|
||||||
|
);
|
||||||
|
|
||||||
|
const restored = await openNetworkPrompt(
|
||||||
|
env,
|
||||||
|
"switch-restore",
|
||||||
|
sepolia,
|
||||||
|
mainnet,
|
||||||
|
);
|
||||||
|
try {
|
||||||
|
await clickAndClose(restored, "#btn-approve-network");
|
||||||
|
outcome = await settleRequest(env.dapp, "switch-restore");
|
||||||
|
} finally {
|
||||||
|
await closeApprovalPages(env.ctx);
|
||||||
|
}
|
||||||
|
assert(
|
||||||
|
outcome.settled === "resolved",
|
||||||
|
"switching back to mainnet did not resolve: " + JSON.stringify(outcome),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||||
|
"switching back did not restore the mainnet network and endpoints",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Switching the network in Settings tells the page too, as an approved site
|
||||||
|
// request does (https://git.eeqj.de/sneak/AutistMask/issues/500). The wallet
|
||||||
|
// goes back to mainnet the same way at the end.
|
||||||
|
test("a network switch in Settings tells the page (#500)", async (env) => {
|
||||||
|
const { mainnet, sepolia } = NETWORKS;
|
||||||
|
const before = await storedNetwork(env.page);
|
||||||
|
assert(
|
||||||
|
before.networkId === "mainnet",
|
||||||
|
"this test starts on mainnet, not on " + before.networkId,
|
||||||
|
);
|
||||||
|
const eventsBefore = (await chainChangedEvents(env.dapp)).length;
|
||||||
|
await openSettings(env.page);
|
||||||
|
|
||||||
|
await env.page.selectOption("#settings-network", "sepolia");
|
||||||
|
let events = await chainChangedEvents(env.dapp, eventsBefore + 1);
|
||||||
|
assert(
|
||||||
|
events.length === eventsBefore + 1 &&
|
||||||
|
events[events.length - 1].data === sepolia.chainId,
|
||||||
|
"the page was not told of the switch to Sepolia: " +
|
||||||
|
JSON.stringify(events),
|
||||||
|
);
|
||||||
|
|
||||||
|
await env.page.selectOption("#settings-network", "mainnet");
|
||||||
|
events = await chainChangedEvents(env.dapp, eventsBefore + 2);
|
||||||
|
assert(
|
||||||
|
events.length === eventsBefore + 2 &&
|
||||||
|
events[events.length - 1].data === mainnet.chainId,
|
||||||
|
"the page was not told of the switch back to mainnet: " +
|
||||||
|
JSON.stringify(events),
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||||
|
"switching back did not restore the mainnet network and endpoints",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
// The closing pass over both boundaries at once. Every message the section
|
// The closing pass over both boundaries at once. Every message the section
|
||||||
// put on either channel is re-read here and required to be free of the
|
// put on either channel is re-read here and required to be free of the
|
||||||
// password — and required to be there at all, method by method, so the
|
// password — and required to be there at all, method by method, so the
|
||||||
|
|||||||
@@ -207,7 +207,7 @@ describe("a decrypt still running when the screen is left", () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
// Same hole on the failure path: a wrong-password error written after
|
// Same hole on the failure path: a wrong-password error written after
|
||||||
// the wipe would restore the flash line on a screen the user has left.
|
// the wipe would restore the error line on a screen the user has left.
|
||||||
test("never writes the failure message either", async () => {
|
test("never writes the failure message either", async () => {
|
||||||
const { helpers, vault, exportPrivkey } = load();
|
const { helpers, vault, exportPrivkey } = load();
|
||||||
exportPrivkey.show(0, 0);
|
exportPrivkey.show(0, 0);
|
||||||
@@ -217,8 +217,10 @@ describe("a decrypt still running when the screen is left", () => {
|
|||||||
reveal.reject(new Error("decryption failed"));
|
reveal.reject(new Error("decryption failed"));
|
||||||
await reveal.pending;
|
await reveal.pending;
|
||||||
|
|
||||||
expect(node("export-privkey-flash").textContent).toBe("");
|
expect(node("export-privkey-password-error").textContent).toBe("");
|
||||||
expect(node("export-privkey-flash").style.visibility).toBe("hidden");
|
expect(node("export-privkey-password-error").style.visibility).toBe(
|
||||||
|
"hidden",
|
||||||
|
);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -260,7 +262,7 @@ describe("a reveal that is not interrupted", () => {
|
|||||||
await reveal.pending;
|
await reveal.pending;
|
||||||
|
|
||||||
expect(node("export-privkey-value").textContent).toBe("");
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
expect(node("export-privkey-flash").textContent).toBe(
|
expect(node("export-privkey-password-error").textContent).toBe(
|
||||||
"That password is incorrect. Please try again.",
|
"That password is incorrect. Please try again.",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -345,10 +345,10 @@ describe.each([
|
|||||||
});
|
});
|
||||||
|
|
||||||
// A transaction's value and fee are in the native currency of the network the
|
// A transaction's value and fee are in the native currency of the network the
|
||||||
// transaction is on, which need not be the active one. A site can switch the
|
// transaction is on, which need not be the active one. The active network can
|
||||||
// active network after its transaction is prepared and back before it is
|
// change, in Settings or when the user approves a site's request, after a
|
||||||
// signed, and a popup opened after a switch shows a sent or listed transaction
|
// transaction is prepared and change back before it is signed, and a popup
|
||||||
// again. The wallet's balances follow the active network; these do not.
|
// opened after a switch shows a sent or listed transaction again. The wallet's balances follow the active network; these do not.
|
||||||
describe.each([
|
describe.each([
|
||||||
["mainnet", "sepolia", "ETH"],
|
["mainnet", "sepolia", "ETH"],
|
||||||
["sepolia", "mainnet", "SepoliaETH"],
|
["sepolia", "mainnet", "SepoliaETH"],
|
||||||
|
|||||||
@@ -0,0 +1,159 @@
|
|||||||
|
// Every screen that asks for a password shows a password error the same way:
|
||||||
|
// through showError() and hideError() in src/popup/views/helpers.js, in a
|
||||||
|
// fixed-height error line below the password field, and never in the flash
|
||||||
|
// line at the top of the popup
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/493). These boot the real popup
|
||||||
|
// over src/popup/index.html, so each error line has to exist in the markup,
|
||||||
|
// and check that the error appears in it and clears again.
|
||||||
|
|
||||||
|
jest.mock("../src/shared/vault", () => ({
|
||||||
|
decryptWithPassword: jest.fn(),
|
||||||
|
encryptWithPassword: jest.fn(),
|
||||||
|
}));
|
||||||
|
|
||||||
|
const {
|
||||||
|
bootPopup,
|
||||||
|
cleanupPopup,
|
||||||
|
unversionedValidProfile,
|
||||||
|
} = require("./support/popupBoot");
|
||||||
|
|
||||||
|
const PASSWORD = "correct horse battery staple";
|
||||||
|
const WRONG_PASSWORD = "That password is incorrect. Please try again.";
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
cleanupPopup();
|
||||||
|
});
|
||||||
|
|
||||||
|
// The error line as the user sees it.
|
||||||
|
function errorLine(page, id) {
|
||||||
|
return {
|
||||||
|
inMarkup: page.document.authoredIds.has(id),
|
||||||
|
text: page.text(id),
|
||||||
|
visibility: page.node(id).style.visibility,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function shown(text) {
|
||||||
|
return { inMarkup: true, text, visibility: "visible" };
|
||||||
|
}
|
||||||
|
|
||||||
|
const cleared = { inMarkup: true, text: "", visibility: "hidden" };
|
||||||
|
|
||||||
|
describe("the add wallet screen", () => {
|
||||||
|
const ERROR = "add-wallet-password-error";
|
||||||
|
|
||||||
|
// First run: Welcome, "Add wallet", then the die for a valid phrase.
|
||||||
|
async function openAddWallet() {
|
||||||
|
const page = await bootPopup(undefined);
|
||||||
|
await page.click("btn-welcome-add");
|
||||||
|
await page.click("btn-generate-phrase");
|
||||||
|
return page;
|
||||||
|
}
|
||||||
|
|
||||||
|
function setPasswords(page, password, confirm) {
|
||||||
|
page.node("add-wallet-password").value = password;
|
||||||
|
page.node("add-wallet-password-confirm").value = confirm;
|
||||||
|
}
|
||||||
|
|
||||||
|
test("shows a password problem below the password fields, and clears it on the next press", async () => {
|
||||||
|
const page = await openAddWallet();
|
||||||
|
setPasswords(page, "short", "short");
|
||||||
|
await page.click("btn-add-wallet-confirm");
|
||||||
|
expect(errorLine(page, ERROR)).toEqual(
|
||||||
|
shown("Password must be at least 12 characters."),
|
||||||
|
);
|
||||||
|
expect(page.text("flash-msg")).toBe("");
|
||||||
|
|
||||||
|
// The password is fixed and the phrase emptied: the password error
|
||||||
|
// goes, and the phrase problem is still reported in the flash line.
|
||||||
|
setPasswords(page, PASSWORD, PASSWORD);
|
||||||
|
page.node("wallet-mnemonic").value = "";
|
||||||
|
await page.click("btn-add-wallet-confirm");
|
||||||
|
expect(errorLine(page, ERROR)).toEqual(cleared);
|
||||||
|
expect(page.text("flash-msg")).toBe(
|
||||||
|
"Enter a recovery phrase, or press the die.",
|
||||||
|
);
|
||||||
|
|
||||||
|
// Leaving clears the flash line and stops its timer, which would
|
||||||
|
// otherwise fire after this page is gone.
|
||||||
|
await page.click("btn-add-wallet-back");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("clears the error when the screen is shown again", async () => {
|
||||||
|
const page = await openAddWallet();
|
||||||
|
setPasswords(page, PASSWORD, PASSWORD + " typo");
|
||||||
|
await page.click("btn-add-wallet-confirm");
|
||||||
|
expect(errorLine(page, ERROR)).toEqual(
|
||||||
|
shown("Passwords do not match."),
|
||||||
|
);
|
||||||
|
|
||||||
|
await page.click("btn-add-wallet-back");
|
||||||
|
await page.click("btn-welcome-add");
|
||||||
|
expect(errorLine(page, ERROR)).toEqual(cleared);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe.each([
|
||||||
|
{
|
||||||
|
screen: "the private key export screen",
|
||||||
|
open: () => require("../src/popup/views/exportPrivkey").show(0, 0),
|
||||||
|
field: "export-privkey-password",
|
||||||
|
button: "btn-export-privkey-confirm",
|
||||||
|
error: "export-privkey-password-error",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
screen: "the recovery phrase screen",
|
||||||
|
open: () => require("../src/popup/views/showPhrase").show(0),
|
||||||
|
field: "show-phrase-password",
|
||||||
|
button: "btn-show-phrase-reveal",
|
||||||
|
error: "show-phrase-password-error",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
screen: "the delete wallet screen",
|
||||||
|
open: () => require("../src/popup/views/deleteWallet").show(0),
|
||||||
|
field: "delete-wallet-password",
|
||||||
|
button: "btn-delete-wallet-confirm",
|
||||||
|
error: "delete-wallet-password-error",
|
||||||
|
},
|
||||||
|
])("$screen", ({ open, field, button, error }) => {
|
||||||
|
// Opens the screen and enters a password the vault rejects.
|
||||||
|
async function failedAttempt() {
|
||||||
|
const page = await bootPopup(unversionedValidProfile());
|
||||||
|
open();
|
||||||
|
const { decryptWithPassword } = require("../src/shared/vault");
|
||||||
|
decryptWithPassword.mockRejectedValue(new Error("wrong password"));
|
||||||
|
page.node(field).value = "not the password";
|
||||||
|
await page.click(button);
|
||||||
|
return { page, decryptWithPassword };
|
||||||
|
}
|
||||||
|
|
||||||
|
test("shows a wrong password below the password field", async () => {
|
||||||
|
const { page } = await failedAttempt();
|
||||||
|
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
|
||||||
|
});
|
||||||
|
|
||||||
|
test("clears the error while the next password is checked", async () => {
|
||||||
|
const { page, decryptWithPassword } = await failedAttempt();
|
||||||
|
let rejectDecrypt;
|
||||||
|
decryptWithPassword.mockReturnValue(
|
||||||
|
new Promise((resolve, reject) => {
|
||||||
|
rejectDecrypt = reject;
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
|
page.node(field).value = "another guess";
|
||||||
|
const pressed = page.click(button);
|
||||||
|
await page.settle();
|
||||||
|
expect(errorLine(page, error)).toEqual(cleared);
|
||||||
|
|
||||||
|
rejectDecrypt(new Error("wrong password"));
|
||||||
|
await pressed;
|
||||||
|
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
|
||||||
|
});
|
||||||
|
|
||||||
|
test("clears the error when the screen is shown again", async () => {
|
||||||
|
const { page } = await failedAttempt();
|
||||||
|
open();
|
||||||
|
expect(errorLine(page, error)).toEqual(cleared);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -49,22 +49,37 @@
|
|||||||
// every path a stored record takes, and the difference is the whole of what
|
// every path a stored record takes, and the difference is the whole of what
|
||||||
// this file does not cover:
|
// this file does not cover:
|
||||||
//
|
//
|
||||||
// - Only the values in the table, in the SLOT arrangement below: four value
|
// - Only the values in the table, in the SLOT arrangement below. On the
|
||||||
// combinations per view, not the product of twelve fields. A dereference
|
// restore path the twelve fields the router does not read are corrupted
|
||||||
// reached only under a pairing no slot produces is not driven at all.
|
// together, every field on the same slot, so a view gets four value
|
||||||
// - Only what a stored record reaches by ITSELF. A view only forward
|
// combinations of them, not their product. A branch entered only when one
|
||||||
// navigation opens, and anything behind a click, is not driven.
|
// of them is truthy and another falsy is reached only where the falsy
|
||||||
// - Nothing about the paths a HEALTHY profile takes, which is most of the
|
// slot happens to pair a field that cannot be falsy with one that is.
|
||||||
// popup. This file is a floor under one defect class, not a proof about
|
// Each field the router reads is corrupted alone, over an otherwise
|
||||||
// the renderers.
|
// well-formed record.
|
||||||
|
// - Only what a stored record reaches by ITSELF, as the boot renders it. A
|
||||||
|
// view only forward navigation opens, anything behind a click, and
|
||||||
|
// anything behind a timer (bootPopup() records every interval, and this
|
||||||
|
// file never runs one) is not driven.
|
||||||
|
// - Of the paths a HEALTHY profile takes, only its boot onto each
|
||||||
|
// restorable view ("the base profile the sweep corrupts" below). The rest
|
||||||
|
// of the popup is not covered: this file is a floor under one defect
|
||||||
|
// class, not a proof about the renderers.
|
||||||
//
|
//
|
||||||
// Within that boundary it is unconditional: if one of these boots leaves the
|
// Within that boundary it is unconditional: if a boot that corrupts a field
|
||||||
// popup unhealthy or off the view it stored, this file goes red — including
|
// leaves the popup unhealthy, this file goes red — including when it takes
|
||||||
// when it takes two corrupted fields at once, because the verdict is the
|
// two corrupted fields at once, because the verdict is the combined boot
|
||||||
// combined boot itself and the per-field re-boot below can only decorate the
|
// itself and the per-field re-boot below can only decorate the message. That
|
||||||
// message. That last part is the one thing an earlier version got wrong: it
|
// last part is the one thing an earlier version got wrong: it asserted on the
|
||||||
// asserted on the per-field list, so an observed dead popup that no single
|
// per-field list, so an observed dead popup that no single field reproduced
|
||||||
// field reproduced was reported green.
|
// was reported green.
|
||||||
|
//
|
||||||
|
// Where the popup lands is held for some of those boots and not others. The
|
||||||
|
// combined boot must land on the view it stored, and each `hostileRestore`
|
||||||
|
// value must land on its view, or fall back to Home, as its entry declares.
|
||||||
|
// The boots in "a hostile routing value restoring onto" are held to health
|
||||||
|
// alone, because a value in a field the router reads legitimately changes
|
||||||
|
// which view renders; so are the boots onto Home, which store no view.
|
||||||
//
|
//
|
||||||
// Booting every field separately at every value would be several hundred boots
|
// Booting every field separately at every value would be several hundred boots
|
||||||
// and most of the suite's budget; this is forty-four. Widening it further is
|
// and most of the suite's budget; this is forty-four. Widening it further is
|
||||||
@@ -128,7 +143,11 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
|
|||||||
// list short and pointed. `floorOnly` is extra values checked against the
|
// list short and pointed. `floorOnly` is extra values checked against the
|
||||||
// floor alone, which is pure and free. `hostileRestore` is extra values driven
|
// floor alone, which is pure and free. `hostileRestore` is extra values driven
|
||||||
// through the restore path only, for a value that means nothing until a
|
// through the restore path only, for a value that means nothing until a
|
||||||
// particular branch's gate has let it past.
|
// particular branch's gate has let it past. Each of its entries names the
|
||||||
|
// `views` it is driven onto and declares whether the boot lands on them
|
||||||
|
// (`restored: true`) or falls back to Home (`restored: false`), so a value
|
||||||
|
// written for one renderer cannot stop reaching it unnoticed. A value driven
|
||||||
|
// onto every restorable view is written with everyRestorableView() below.
|
||||||
//
|
//
|
||||||
// `falsy` is the other POLARITY of a swept field, driven for the same reason.
|
// `falsy` is the other POLARITY of a swept field, driven for the same reason.
|
||||||
// It is not a value src/ never writes — for three of these fields it is the
|
// It is not a value src/ never writes — for three of these fields it is the
|
||||||
@@ -139,6 +158,23 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
|
|||||||
// falsy value stored under that field comes back TRUTHY from the floor, so no
|
// falsy value stored under that field comes back TRUTHY from the floor, so no
|
||||||
// `!state.x` branch is reachable from a stored record at all.
|
// `!state.x` branch is reachable from a stored record at all.
|
||||||
|
|
||||||
|
// The `hostileRestore` entries for a value driven onto every restorable view:
|
||||||
|
// it falls back to Home on the views listed in `fallsBackOn` and lands on every
|
||||||
|
// other one, so a view added to RESTORABLE_VIEWS is driven, and expected to
|
||||||
|
// land, without editing the row.
|
||||||
|
function everyRestorableView(value, fallsBackOn) {
|
||||||
|
return [
|
||||||
|
{ value, views: fallsBackOn, restored: false },
|
||||||
|
{
|
||||||
|
value,
|
||||||
|
views: [...RESTORABLE_VIEWS].filter(
|
||||||
|
(view) => !fallsBackOn.includes(view),
|
||||||
|
),
|
||||||
|
restored: true,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
const CONTRACT = [
|
const CONTRACT = [
|
||||||
{
|
{
|
||||||
field: "wallets",
|
field: "wallets",
|
||||||
@@ -280,28 +316,38 @@ const CONTRACT = [
|
|||||||
kind: KIND.SCALAR,
|
kind: KIND.SCALAR,
|
||||||
// The prototype members are the whole point: `wallets["map"]` is
|
// The prototype members are the whole point: `wallets["map"]` is
|
||||||
// TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and
|
// TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and
|
||||||
// `.addresses[…]` throws. A stale INTEGER is the safe case.
|
// `.addresses[…]` throws. A stale INTEGER is the safe case and has to
|
||||||
hostile: ["map", "__proto__", { a: 1 }],
|
// stay so. 5 is one, out of range for the one wallet in the profile,
|
||||||
|
// and it is also this field's truthy polarity: every other value here
|
||||||
|
// comes back from the floor as null.
|
||||||
|
hostile: ["map", "__proto__", { a: 1 }, 5],
|
||||||
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
||||||
holds: isIndexOrNull,
|
holds: isIndexOrNull,
|
||||||
// SCALAR, and swept anyway: the restore path is precisely why this
|
// SCALAR, and swept anyway: the restore path is precisely why this
|
||||||
// field gained a floor, so the sweep is the regression guard on it.
|
// field gained a floor, so the sweep is the regression guard on it.
|
||||||
alsoSweep: true,
|
alsoSweep: true,
|
||||||
routes: true,
|
routes: true,
|
||||||
// A stale INTEGER index, which reaches the restore path by a different
|
// Comes back from the floor as null, which hasValidAddress() reads as
|
||||||
// route from the prototype members above — falsy or out of range
|
// nothing selected: the popup falls back to Home on the five views
|
||||||
// rather than truthy — and has to keep being the safe case.
|
// that need an address, and lands on every other one.
|
||||||
hostileRestore: [{ value: "length" }, { value: 5 }],
|
hostileRestore: everyRestorableView("length", [
|
||||||
|
"address",
|
||||||
|
"address-token",
|
||||||
|
"receive",
|
||||||
|
"transaction",
|
||||||
|
"confirm-tx",
|
||||||
|
]),
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
field: "selectedAddress",
|
field: "selectedAddress",
|
||||||
kind: KIND.SCALAR,
|
kind: KIND.SCALAR,
|
||||||
hostile: ["map", "__proto__", { a: 1 }],
|
// 5 for the same reason as in selectedWallet: a stale index, and the
|
||||||
|
// one value here still truthy after the floor.
|
||||||
|
hostile: ["map", "__proto__", { a: 1 }, 5],
|
||||||
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
||||||
holds: isIndexOrNull,
|
holds: isIndexOrNull,
|
||||||
alsoSweep: true,
|
alsoSweep: true,
|
||||||
routes: true,
|
routes: true,
|
||||||
hostileRestore: [{ value: 5 }],
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
field: "currentView",
|
field: "currentView",
|
||||||
@@ -325,7 +371,9 @@ const CONTRACT = [
|
|||||||
// container shapes below onto every restorable view; hostileRestore
|
// container shapes below onto every restorable view; hostileRestore
|
||||||
// adds the records that PASS a branch's gate and then hand its
|
// adds the records that PASS a branch's gate and then hand its
|
||||||
// renderer something it dereferences, which is where the entries are
|
// renderer something it dereferences, which is where the entries are
|
||||||
// actually decided.
|
// actually decided. The guard refuses each single-view record below,
|
||||||
|
// so each is declared to fall back to Home: one that started landing
|
||||||
|
// would be reaching the renderer it was written against.
|
||||||
hostile: [42, "notarecord", { a: 1 }, [1, 2]],
|
hostile: [42, "notarecord", { a: 1 }, [1, 2]],
|
||||||
// `structuredClone(saved.viewData || {})`: the container is never falsy
|
// `structuredClone(saved.viewData || {})`: the container is never falsy
|
||||||
// in state whatever was stored, so no `!state.viewData` branch exists to
|
// in state whatever was stored, so no `!state.viewData` branch exists to
|
||||||
@@ -334,11 +382,20 @@ const CONTRACT = [
|
|||||||
hostileRestore: [
|
hostileRestore: [
|
||||||
// success-tx passes on `data.hash`, and renderSuccess() then calls
|
// success-tx passes on `data.hash`, and renderSuccess() then calls
|
||||||
// toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase().
|
// toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase().
|
||||||
{ value: { hash: "0x1" }, views: ["success-tx"] },
|
{
|
||||||
{ value: { hash: "0x1", to: 42 }, views: ["success-tx"] },
|
value: { hash: "0x1" },
|
||||||
|
views: ["success-tx"],
|
||||||
|
restored: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
value: { hash: "0x1", to: 42 },
|
||||||
|
views: ["success-tx"],
|
||||||
|
restored: false,
|
||||||
|
},
|
||||||
{
|
{
|
||||||
value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } },
|
value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } },
|
||||||
views: ["success-tx"],
|
views: ["success-tx"],
|
||||||
|
restored: false,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
value: {
|
value: {
|
||||||
@@ -347,12 +404,25 @@ const CONTRACT = [
|
|||||||
decoded: { details: [{ address: 42 }] },
|
decoded: { details: [{ address: 42 }] },
|
||||||
},
|
},
|
||||||
views: ["success-tx"],
|
views: ["success-tx"],
|
||||||
|
restored: false,
|
||||||
},
|
},
|
||||||
// error-tx passes on `data.message`, same dereference.
|
// error-tx passes on `data.message`, same dereference.
|
||||||
{ value: { message: "boom" }, views: ["error-tx"] },
|
{
|
||||||
{ value: { message: "boom", to: 42 }, views: ["error-tx"] },
|
value: { message: "boom" },
|
||||||
|
views: ["error-tx"],
|
||||||
|
restored: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
value: { message: "boom", to: 42 },
|
||||||
|
views: ["error-tx"],
|
||||||
|
restored: false,
|
||||||
|
},
|
||||||
// transaction passes on `data.tx`.
|
// transaction passes on `data.tx`.
|
||||||
{ value: { tx: { hash: "0x1" } }, views: ["transaction"] },
|
{
|
||||||
|
value: { tx: { hash: "0x1" } },
|
||||||
|
views: ["transaction"],
|
||||||
|
restored: false,
|
||||||
|
},
|
||||||
{
|
{
|
||||||
value: {
|
value: {
|
||||||
tx: {
|
tx: {
|
||||||
@@ -363,9 +433,14 @@ const CONTRACT = [
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
views: ["transaction"],
|
views: ["transaction"],
|
||||||
|
restored: false,
|
||||||
},
|
},
|
||||||
// confirm-tx passes on `data.pendingTx`.
|
// confirm-tx passes on `data.pendingTx`.
|
||||||
{ value: { pendingTx: { amount: "1" } }, views: ["confirm-tx"] },
|
{
|
||||||
|
value: { pendingTx: { amount: "1" } },
|
||||||
|
views: ["confirm-tx"],
|
||||||
|
restored: false,
|
||||||
|
},
|
||||||
{
|
{
|
||||||
value: {
|
value: {
|
||||||
pendingTx: {
|
pendingTx: {
|
||||||
@@ -376,6 +451,7 @@ const CONTRACT = [
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
views: ["confirm-tx"],
|
views: ["confirm-tx"],
|
||||||
|
restored: false,
|
||||||
},
|
},
|
||||||
// wait-tx passes on `pendingWait.hash`; restoreWait() has checked
|
// wait-tx passes on `pendingWait.hash`; restoreWait() has checked
|
||||||
// the fields below it since it was written, and this is the
|
// the fields below it since it was written, and this is the
|
||||||
@@ -388,20 +464,29 @@ const CONTRACT = [
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
views: ["wait-tx"],
|
views: ["wait-tx"],
|
||||||
|
restored: false,
|
||||||
},
|
},
|
||||||
// A record that passes EVERY branch's gate at once, driven onto
|
// A record that passes EVERY branch's gate at once, driven onto
|
||||||
// every restorable view: a branch a view does not read must stay
|
// every restorable view: a branch a view does not read must stay
|
||||||
// one it does not read, and each renderer must survive the fields
|
// one it does not read. The five views with a viewData branch
|
||||||
// another branch left behind.
|
// refuse it; every other one renders it, and must survive the
|
||||||
|
// fields every branch left behind.
|
||||||
|
...everyRestorableView(
|
||||||
{
|
{
|
||||||
value: {
|
|
||||||
hash: "0x1",
|
hash: "0x1",
|
||||||
message: "boom",
|
message: "boom",
|
||||||
tx: { hash: "0x1" },
|
tx: { hash: "0x1" },
|
||||||
pendingTx: { amount: "1" },
|
pendingTx: { amount: "1" },
|
||||||
pendingWait: { hash: "0x1" },
|
pendingWait: { hash: "0x1" },
|
||||||
},
|
},
|
||||||
},
|
[
|
||||||
|
"confirm-tx",
|
||||||
|
"transaction",
|
||||||
|
"wait-tx",
|
||||||
|
"success-tx",
|
||||||
|
"error-tx",
|
||||||
|
],
|
||||||
|
),
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -583,6 +668,11 @@ const HEALTHY = { errors: [], blank: false };
|
|||||||
// set is all-truthy by construction, so without a falsy slot a dereference
|
// set is all-truthy by construction, so without a falsy slot a dereference
|
||||||
// behind `if (!state.x)` is never reached on the boot that corrupts x — the
|
// behind `if (!state.x)` is never reached on the boot that corrupts x — the
|
||||||
// same falsy-collapse blind spot the fields below were floored for.
|
// same falsy-collapse blind spot the fields below were floored for.
|
||||||
|
//
|
||||||
|
// Only `hostile` and `falsy` values count. Those go through the sweep below,
|
||||||
|
// which covers every restorable view; a `hostileRestore` entry is driven onto
|
||||||
|
// only the views it names, so a polarity it alone supplied might reach a single
|
||||||
|
// renderer.
|
||||||
describe("both polarities of every swept field are driven", () => {
|
describe("both polarities of every swept field are driven", () => {
|
||||||
const FALSY_STORED = [0, "", false, null];
|
const FALSY_STORED = [0, "", false, null];
|
||||||
const floored = (field, value) =>
|
const floored = (field, value) =>
|
||||||
@@ -606,10 +696,9 @@ describe("both polarities of every swept field are driven", () => {
|
|||||||
test(`${row.field}: truthy and falsy`, () => {
|
test(`${row.field}: truthy and falsy`, () => {
|
||||||
// What the boots below actually drive, floored the way a renderer
|
// What the boots below actually drive, floored the way a renderer
|
||||||
// sees it — not what the row says it drives.
|
// sees it — not what the row says it drives.
|
||||||
const driven = [
|
const driven = sweptValues(row).map((value) =>
|
||||||
...sweptValues(row),
|
floored(row.field, value),
|
||||||
...(row.hostileRestore || []).map((entry) => entry.value),
|
);
|
||||||
].map((value) => floored(row.field, value));
|
|
||||||
|
|
||||||
expect({
|
expect({
|
||||||
truthy: driven.some((value) => Boolean(value)),
|
truthy: driven.some((value) => Boolean(value)),
|
||||||
@@ -865,20 +954,27 @@ describe("every field the router does not read, corrupted at once, onto", () =>
|
|||||||
|
|
||||||
// The values that only mean something on the restore path: a viewData that
|
// The values that only mean something on the restore path: a viewData that
|
||||||
// PASSES a branch's gate and then hands its renderer something dereferenced,
|
// PASSES a branch's gate and then hands its renderer something dereferenced,
|
||||||
// and the index values whose route through hasValidAddress() differs from the
|
// and a selectedWallet the floor turns into nothing selected. Each boot must
|
||||||
// row's own hostile set.
|
// throw nothing and show exactly the view its entry says it lands on: its own,
|
||||||
|
// or Home, so a value written for one renderer cannot stop reaching it and
|
||||||
|
// still pass.
|
||||||
describe("a restore-only hostile value onto", () => {
|
describe("a restore-only hostile value onto", () => {
|
||||||
for (const row of CONTRACT) {
|
for (const row of CONTRACT) {
|
||||||
for (const entry of row.hostileRestore || []) {
|
for (const entry of row.hostileRestore || []) {
|
||||||
for (const view of entry.views || RESTORABLE_VIEWS) {
|
for (const view of entry.views) {
|
||||||
test(`${view}: ${row.field} = ${JSON.stringify(
|
test(`${view}: ${row.field} = ${JSON.stringify(
|
||||||
entry.value,
|
entry.value,
|
||||||
)}`, async () => {
|
)}`, async () => {
|
||||||
await expect(
|
const env = await bootPopup(
|
||||||
bootHealth(
|
|
||||||
restoringOnto(view, { [row.field]: entry.value }),
|
restoringOnto(view, { [row.field]: entry.value }),
|
||||||
),
|
);
|
||||||
).resolves.toEqual(HEALTHY);
|
expect({
|
||||||
|
errors: env.pageErrors,
|
||||||
|
visible: env.visibleViews(),
|
||||||
|
}).toEqual({
|
||||||
|
errors: [],
|
||||||
|
visible: [entry.restored ? view : "main"],
|
||||||
|
});
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -238,6 +238,10 @@ async function settle() {
|
|||||||
* @param {object} [options]
|
* @param {object} [options]
|
||||||
* @param {object} [options.storage] a storage stub from makeStorageStub(), for
|
* @param {object} [options.storage] a storage stub from makeStorageStub(), for
|
||||||
* a test that needs to make writes fail or to watch the round trips.
|
* a test that needs to make writes fail or to watch the round trips.
|
||||||
|
* @param {string} [options.search] the page URL's query string, such as
|
||||||
|
* "?approval=" and an id for the popup opened as an approval window.
|
||||||
|
* @param {object} [options.runtime] members of chrome.runtime that replace the
|
||||||
|
* stub's own, for a test that has to answer the background's messages.
|
||||||
* @returns {Promise<object>} handles onto the booted page.
|
* @returns {Promise<object>} handles onto the booted page.
|
||||||
*/
|
*/
|
||||||
async function bootPopup(stored, options) {
|
async function bootPopup(stored, options) {
|
||||||
@@ -281,12 +285,13 @@ async function bootPopup(stored, options) {
|
|||||||
sendMessage: jest.fn(async () => ({})),
|
sendMessage: jest.fn(async () => ({})),
|
||||||
getURL: (p) => "chrome-extension://autistmask/" + p,
|
getURL: (p) => "chrome-extension://autistmask/" + p,
|
||||||
onMessage: { addListener: () => {} },
|
onMessage: { addListener: () => {} },
|
||||||
|
...(options && options.runtime),
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
globalThis.document = document;
|
globalThis.document = document;
|
||||||
globalThis.window = {
|
globalThis.window = {
|
||||||
location: {
|
location: {
|
||||||
search: "",
|
search: (options && options.search) || "",
|
||||||
href: "chrome-extension://autistmask/src/popup/index.html",
|
href: "chrome-extension://autistmask/src/popup/index.html",
|
||||||
reload: () => reloads.push(Date.now()),
|
reload: () => reloads.push(Date.now()),
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user