Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
248057a25d | ||
|
|
de3f7a9a11 | ||
|
|
1144fdb71b | ||
|
|
f24b5bca19 | ||
|
|
9f0e88e963 | ||
|
|
45f11ee920 | ||
|
|
a68f30c480 | ||
|
|
43c236451f | ||
|
|
1247c24c4d |
+5
-6
@@ -8,12 +8,11 @@ WORKDIR /app
|
||||
# image sets it.
|
||||
ENV AUTISTMASK_LINT_NATIVE=1
|
||||
|
||||
# script/test's default 30s bound is the host figure, against a suite that
|
||||
# runs in about 8s there. In here the same suite starts on a cold jest cache
|
||||
# and shares the runner with the rest of the build, so 30s is marginal rather
|
||||
# than a bound — it killed a healthy suite at 30.6s on a cold CI cache. 180s
|
||||
# still catches a hang in three minutes and cannot be tripped by a suite that
|
||||
# is merely running on contended hardware.
|
||||
# script/test's default 30s bound is the host figure. In here the same suite
|
||||
# starts on a cold jest cache and shares the runner with the rest of the build,
|
||||
# so 30s is too tight — it killed a healthy suite at 30.6s on a cold CI cache.
|
||||
# 180s still catches a hang in three minutes and cannot be tripped by a suite
|
||||
# that is merely running on contended hardware.
|
||||
ENV AUTISTMASK_TEST_TIMEOUT=180
|
||||
|
||||
# script/bootstrap installs all prerequisites (make via apt here; node
|
||||
|
||||
@@ -949,6 +949,13 @@ and compare against. Reading the stored field directly instead answers `null`
|
||||
for a bundled or tracked token the explorer merely omitted, which is not a
|
||||
refusal the wallet has any reason to make.
|
||||
|
||||
The Send screen also consults every address's explorer reports, so a contract
|
||||
two addresses report different `decimals` for has no scale there, and the stored
|
||||
balance, formatted at one of those scales, is withdrawn with it. The Send
|
||||
screen's `Current balance` and the confirmation screen's balance line then both
|
||||
read `unknown (SYMBOL)`. The balance list formats each explorer row as it is
|
||||
fetched, without that cross-address check, and shows the row's figure.
|
||||
|
||||
**Decoded amount lines on the transaction approval screen:** the `Amount` line
|
||||
of a decoded ERC-20 call, and the `Amount` and `Min. received` lines of a
|
||||
decoded swap (see TxApproval below), do not always read as a number. They can
|
||||
@@ -1150,7 +1157,7 @@ each caught only by a reviewer re-deriving thirty fields by hand.
|
||||
The `allowedSites` case is why the entry check is not optional. A stored
|
||||
`{"0x…": "notalist"}` is a well-formed object holding a malformed entry: it
|
||||
passed the gate, rendered a completely healthy popup, and then threw inside
|
||||
`saveState()`'s per-hostname merge, so every save from that moment on failed and
|
||||
`saveState()`'s per-origin merge, so every save from that moment on failed and
|
||||
the user went on operating a wallet that was persisting nothing
|
||||
([#362](https://git.eeqj.de/sneak/AutistMask/issues/362)). A save that fails is
|
||||
now also reported rather than swallowed: `onSaveFailure()` in
|
||||
@@ -1409,7 +1416,9 @@ view would leave a wallet one click from deletion.
|
||||
- What to send: token dropdown (or static display with contract address when
|
||||
locked from AddressToken)
|
||||
- To: address or ENS name input, with an inline validation message
|
||||
- Amount input with current balance display
|
||||
- Amount input with current balance display, which reads
|
||||
`Current balance: unknown (SYMBOL)` for a token whose scale is unknown, as
|
||||
ConfirmTx's balance line does (see Unknown token scale)
|
||||
- "Review" button, disabled until the recipient validates
|
||||
- **Transitions**:
|
||||
- "Review" (valid inputs, ENS resolved) → **ConfirmTx**
|
||||
@@ -1427,7 +1436,8 @@ view would leave a wallet one click from deletion.
|
||||
- From: blockie + color dot + full address + etherscan link + wallet title
|
||||
- To: blockie + color dot + full address + etherscan link + ENS name
|
||||
- Amount: value + symbol (USD in parentheses)
|
||||
- Your balance: value + symbol (USD in parentheses)
|
||||
- Your balance: value + symbol (USD in parentheses), or `unknown (SYMBOL)`
|
||||
for a token whose scale is unknown
|
||||
- Network fee: "Estimating..." then two lines, or "Unable to estimate",
|
||||
fetched async. The first line is what the transfer is expected to cost,
|
||||
`gasLimit * gasPrice` (USD in parentheses); the second is the
|
||||
@@ -1443,7 +1453,11 @@ view would leave a wallet one click from deletion.
|
||||
amount plus the fee exceeds the balance (ETH transfers), not enough ETH to
|
||||
pay the fee for the transfer (ERC-20 transfers), and the fee could not be
|
||||
estimated. The first two are mutually exclusive per transfer type, so only
|
||||
the applicable one holds space
|
||||
the applicable one holds space. The last names its cause: for a token
|
||||
whose scale is unknown the fee can never be estimated, and it says the
|
||||
wallet does not know how many decimal places the token uses and that the
|
||||
transaction cannot be sent; for any other failure it asks the user to go
|
||||
back and try again
|
||||
- Password: an inline field on this screen, not a modal, with its own error
|
||||
line
|
||||
- "Sign & Send" button (disabled if errors, and while the network fee
|
||||
@@ -1617,13 +1631,13 @@ view would leave a wallet one click from deletion.
|
||||
a value carrying its unit, hex (`0x10`) or exponent (`1e3`) notation —
|
||||
is refused with a flash message and the field snaps back to the stored
|
||||
threshold, so a number the user did not type is never stored.
|
||||
- Allowed Sites: the hostnames remembered as allowed, under any address,
|
||||
with remove buttons
|
||||
- Connected Sites: the hostnames of the sites allowed without "Remember my
|
||||
- Allowed Sites: the origins (scheme, host and port) remembered as allowed,
|
||||
under any address, with remove buttons
|
||||
- Connected Sites: the origins of the sites allowed without "Remember my
|
||||
choice" that are still connected, with remove buttons. Only the background
|
||||
holds these, in memory, and Settings asks it for them with
|
||||
`AUTISTMASK_GET_CONNECTED_SITES`
|
||||
- Denied Sites: the hostnames remembered as denied, under any address, with
|
||||
- Denied Sites: the origins remembered as denied, under any address, with
|
||||
remove buttons
|
||||
- About: project link, license, author, version, release date, and the
|
||||
commit, which links to the commit in the repository
|
||||
@@ -1637,10 +1651,11 @@ view would leave a wallet one click from deletion.
|
||||
- Tap wallet name → inline rename field (no screen change)
|
||||
- `[x]` on a tracked token → removes it in place (no screen change)
|
||||
- `[x]` on an allowed or connected site → disconnects that site, in place:
|
||||
its hostname is dropped from Allowed Sites under every address, and
|
||||
its origin is dropped from Allowed Sites under every address, and
|
||||
`AUTISTMASK_REMOVE_SITE` has the background end every connection approved
|
||||
without "Remember" from an origin with that hostname, under any address,
|
||||
and send `accountsChanged` with an empty list to the site's open tabs.
|
||||
without "Remember" from that origin, under any address, and send
|
||||
`accountsChanged` with an empty list to the open tabs of that origin. The
|
||||
same host under another scheme or port is another site and is left alone.
|
||||
Only the extension's own pages may send either message
|
||||
- `[x]` on a denied site → forgets the refusal, in place; it connects
|
||||
nothing and tells the background nothing
|
||||
@@ -1824,14 +1839,18 @@ view would leave a wallet one click from deletion.
|
||||
|
||||
- **When**: A website requests wallet access via `eth_requestAccounts` or
|
||||
`wallet_requestPermissions` and is on neither the allowed nor the denied list.
|
||||
The background script prefers the toolbar popup (`action.openPopup()`) and
|
||||
falls back to a separate popup window (`src/background/index.js`,
|
||||
A site is its full origin, `scheme://host[:port]`, on both lists and for a
|
||||
connection allowed without "Remember": a choice for `https://dapp.example`
|
||||
says nothing about `http://dapp.example` or another port of that host. The
|
||||
background script prefers the toolbar popup (`action.openPopup()`) and falls
|
||||
back to a separate popup window (`src/background/index.js`,
|
||||
`requestApproval()`).
|
||||
- **Elements**:
|
||||
- "Connection Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
blocklist)
|
||||
- Site hostname (bold) + "wants to connect to your wallet"
|
||||
- Site origin (bold, scheme and port included) + "wants to connect to your
|
||||
wallet"
|
||||
- Address that will be shared (color dot + full address + etherscan link)
|
||||
- "Remember my choice for this site" checkbox
|
||||
- "Allow" / "Deny" buttons
|
||||
@@ -1850,18 +1869,22 @@ view would leave a wallet one click from deletion.
|
||||
programmatically rather than by a user gesture. The background populates the
|
||||
transaction (nonce, gas limit, fees, chain id) against the RPC node _before_
|
||||
opening the window, so the screen shows a complete transaction and the signed
|
||||
artifact can be compared with it field for field. A request that cannot be
|
||||
populated — unreachable node, reverting gas estimate — opens no window and is
|
||||
failed back to the site. Only one transaction approval exists at a time:
|
||||
populating fixes the nonce, so a second `eth_sendTransaction` arriving while
|
||||
one is unanswered is refused with EIP-1193 code `-32002` rather than being
|
||||
populated at the same nonce. It opens no window and takes no nonce, and the
|
||||
site can send it again once the pending one is answered.
|
||||
artifact can be compared with it field for field. A nonce the site supplies is
|
||||
ignored: the nonce is always the account's next nonce from the node, so a site
|
||||
cannot replace one of the user's pending transactions or leave this one stuck
|
||||
behind a gap. A request that cannot be populated — unreachable node, reverting
|
||||
gas estimate — opens no window and is failed back to the site. Only one
|
||||
transaction approval exists at a time: populating fixes the nonce, so a second
|
||||
`eth_sendTransaction` arriving while one is unanswered is refused with
|
||||
EIP-1193 code `-32002` rather than being populated at the same nonce. It opens
|
||||
no window and takes no nonce, and the site can send it again once the pending
|
||||
one is answered.
|
||||
- **Elements**:
|
||||
- "Transaction Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
blocklist)
|
||||
- Site hostname (bold) + "wants to send a transaction"
|
||||
- Site origin (bold, scheme and port included) + "wants to send a
|
||||
transaction"
|
||||
- Decoded action (if calldata is recognized): action name, token details,
|
||||
amounts, steps, deadline (see Transaction Decoding)
|
||||
- From: color dot + full address + etherscan link
|
||||
@@ -1892,12 +1915,18 @@ view would leave a wallet one click from deletion.
|
||||
- "Signature Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
blocklist)
|
||||
- Site hostname (bold) + "wants you to sign a message"
|
||||
- Site origin (bold, scheme and port included) + "wants you to sign a
|
||||
message"
|
||||
- Danger warning box (shown for `eth_sign`, which signs a raw hash)
|
||||
- Type: "Personal message" or "Typed data (EIP-712)"
|
||||
- From: color dot + full address + etherscan link
|
||||
- Message: decoded UTF-8 text (personal_sign) or formatted domain/type/
|
||||
message fields (EIP-712 typed data). The primary type shown is the one
|
||||
- Message: for `personal_sign` and `eth_sign`, the text the message's bytes
|
||||
decode to as UTF-8, with each control or format character (zero-width and
|
||||
bidirectional characters among them) shown as a bordered `U+XXXX` mark
|
||||
instead of acting on the text, so it reads in the order of the bytes that
|
||||
are signed; a line feed is shown as a line break. Bytes that are not UTF-8
|
||||
are shown as "This message is not text." For typed data, formatted
|
||||
domain/type/message fields (EIP-712). The primary type shown is the one
|
||||
ethers signs, derived from the typed data's `types`, not the type the site
|
||||
states.
|
||||
- Token permission warning, at the top of the message (typed data whose
|
||||
@@ -1911,12 +1940,20 @@ view would leave a wallet one click from deletion.
|
||||
domain's `verifyingContract`; any those fields do not give is shown as
|
||||
`Unknown`, and the domain, type and message lines still follow. Only typed
|
||||
data that cannot be read at all is shown as raw text.
|
||||
- Raw data (`personal_sign` and `eth_sign`): the message's hex exactly as
|
||||
the site sent it. The bytes it encodes are what is signed, as an EIP-191
|
||||
personal message.
|
||||
- Password input and an error line
|
||||
- "Sign" / "Reject" buttons
|
||||
- **Transitions**:
|
||||
- Typed data that states no primary type, or one other than the type it
|
||||
would be signed as, or that cannot be read → shown with the error line
|
||||
saying so and "Sign" disabled; only "Reject" remains
|
||||
- A `personal_sign` or `eth_sign` message that is not hex (`0x` and an even
|
||||
number of hex digits) → shown as plain text, with the error line "This
|
||||
message is plain text, not hex, so it cannot be signed." and "Sign"
|
||||
disabled; signing takes the bytes from the hex, so such a message has none
|
||||
to sign
|
||||
- "Sign" (correct password) → signs locally → closes popup (returns
|
||||
signature)
|
||||
- "Sign" (wrong password, or a signing failure) → error line, no screen
|
||||
|
||||
@@ -45,6 +45,67 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: The signature screen shows a personal message as the bytes that
|
||||
are signed ([#403](https://git.eeqj.de/sneak/AutistMask/issues/403)). It
|
||||
showed only the decoded text, with bidirectional and zero-width characters
|
||||
acting on it, so a site could make the message read differently from what is
|
||||
signed, and a message that was not hex was shown as NUL characters. The hex is
|
||||
now shown as "Raw data" alongside the decoded text, control and format
|
||||
characters in the text are shown as `U+XXXX` marks, and a message that is not
|
||||
hex is shown as plain text with "Sign" disabled, since signing takes the bytes
|
||||
from the hex and such a message has none to sign.
|
||||
|
||||
- 2026-10-04: A nonce the site supplies with `eth_sendTransaction` is ignored
|
||||
([#404](https://git.eeqj.de/sneak/AutistMask/issues/404)). It was passed on to
|
||||
the transaction, so a site could replace one of the user's pending
|
||||
transactions (same nonce, higher fee) or leave the new one stuck behind a gap,
|
||||
and the approval screen showed it as a bare number. `nonce` is no longer one
|
||||
of the fields taken from the request in `src/shared/approvalTx.js`, so the
|
||||
transaction always gets the account's next nonce from the node, and that is
|
||||
the nonce the approval screen shows and the popup signs.
|
||||
|
||||
- 2026-10-04: Remembered site permissions are held by full origin
|
||||
([#402](https://git.eeqj.de/sneak/AutistMask/issues/402)). `allowedSites` and
|
||||
`deniedSites` stored the hostname alone, so a grant to `https://dapp.example`
|
||||
also authorised `http://dapp.example` and every port on that host, and the
|
||||
prompts named only the hostname. Both lists now store and match the origin
|
||||
(`scheme://host[:port]`), the key the connections approved without "Remember"
|
||||
already used, in `src/background/index.js` and in Settings, whose site lists
|
||||
and `AUTISTMASK_REMOVE_SITE` carry the origin too. The connection, transaction
|
||||
and signature prompts show the origin. Entries saved by hostname before this
|
||||
change are not migrated (pre-1.0): they match no site, and Settings lists them
|
||||
until they are removed.
|
||||
|
||||
- 2026-10-04: A page's request is credited only to the site the browser says
|
||||
sent it ([#407](https://git.eeqj.de/sneak/AutistMask/issues/407)). Where the
|
||||
browser does not give the sender's origin (Firefox before 126), the background
|
||||
used the tab's page, so a frame from another site would have been treated as
|
||||
the site embedding it, and with no tab it used an origin the page wrote into
|
||||
the message. It now uses the URL of the frame that sent the message, and
|
||||
refuses the request with code 4100 when the browser gives neither. The content
|
||||
script no longer writes an origin into the message.
|
||||
|
||||
- 2026-10-04: `make test` takes 8-13s on the shared build host, down from
|
||||
17-25s, measured in alternating runs before and after the change
|
||||
([#428](https://git.eeqj.de/sneak/AutistMask/issues/428)). Each popup boot in
|
||||
the tests (`tests/support/popupBoot.js`) resets jest's module registry so that
|
||||
everything under `src/` loads fresh, and that also reloaded `ethers`,
|
||||
`libsodium-wrappers-sumo`, `qrcode` and `ethereum-blockies-base64` every time.
|
||||
Those four libraries are now loaded once per test file and handed to every
|
||||
boot. No test or assertion changed.
|
||||
|
||||
- 2026-10-04: A token whose scale is unknown reads the same on the Send screen
|
||||
as on the confirmation screen
|
||||
([#377](https://git.eeqj.de/sneak/AutistMask/issues/377)). When two addresses'
|
||||
explorer reports disagree on a token's `decimals`, the Send screen showed the
|
||||
stored figure while the confirmation screen it leads to said
|
||||
`unknown (SYMBOL)`; both now say `unknown (SYMBOL)`, from one function in
|
||||
`src/popup/views/send.js`. The confirmation screen's fee-unknown message names
|
||||
its cause: for an unknown scale it says the wallet does not know how many
|
||||
decimal places the token uses and that the transaction cannot be sent, instead
|
||||
of asking the user to go back and try again, which cannot help. For any other
|
||||
cause it is unchanged.
|
||||
|
||||
- 2026-10-04: A Uniswap V2 exact-out swap (Universal Router command `0x09`) is
|
||||
decoded on the approval screen
|
||||
([#283](https://git.eeqj.de/sneak/AutistMask/issues/283)). `decode()` in
|
||||
@@ -60,6 +121,27 @@ but the review is broader than any of them.
|
||||
`Token Out` and `Min. received` keep the output side's own token and figure.
|
||||
V3 exact-out (`0x01`) is still not decoded.
|
||||
|
||||
- 2026-10-04: `make test` runs jest in three worker processes
|
||||
([#426](https://git.eeqj.de/sneak/AutistMask/issues/426)). The `test` and
|
||||
`test:verbose` scripts in `package.json` ran `jest --forceExit`, which starts
|
||||
one worker per CPU core: about 47 processes and 7-8 GiB per run on the shared
|
||||
48-core build host. They now pass `--maxWorkers=3`, and the suite takes 23-29s
|
||||
there: inside the 30-second cap in `script/test`, which is unchanged, but not
|
||||
by much, because `tests/persistedFieldContract.test.js` alone takes most of it
|
||||
([#428](https://git.eeqj.de/sneak/AutistMask/issues/428)). One or two workers
|
||||
went past the cap. `make check`, the pre-commit hook and `script/cibuild` all
|
||||
run the suite through these scripts.
|
||||
|
||||
- 2026-10-04: The error container on each dApp approval screen keeps its height
|
||||
when an error appears
|
||||
([#297](https://git.eeqj.de/sneak/AutistMask/issues/297)). `#approve-tx-error`
|
||||
and `#approve-sign-error` reserved 20px, but their border and padding took
|
||||
10px of it, so a one-line error grew them to 26px and pushed the buttons below
|
||||
down 6px. They now reserve 30px. A new test in `tests/e2e/run.js` shows each
|
||||
of the six password error containers on its own screen, empty and then with an
|
||||
error, and fails if one changes height or the element below it moves. Some of
|
||||
the longer messages these two containers can show still take two lines.
|
||||
|
||||
- 2026-10-04: A transaction with no `to` says "This transaction creates a new
|
||||
contract. It has no recipient." on its recipient line and in its transaction
|
||||
history row ([#250](https://git.eeqj.de/sneak/AutistMask/issues/250)). The
|
||||
|
||||
+5
-3
@@ -285,11 +285,13 @@ not appear and may be permanently lost.
|
||||
AutistMask injects a standard `window.ethereum` provider (EIP-1193) into web
|
||||
pages. When a site requests access to your wallet:
|
||||
|
||||
1. A popup appears showing the site's hostname and the address that will be
|
||||
shared.
|
||||
1. A popup appears showing the site's origin (its scheme, host and port, for
|
||||
example `https://app.example`) and the address that will be shared.
|
||||
2. Click "Allow" to connect or "Deny" to reject.
|
||||
3. Optionally check "Remember my choice for this site" to skip the prompt next
|
||||
time.
|
||||
time. The choice applies to that exact origin only: a choice remembered for
|
||||
`https://app.example` does not cover `http://app.example` or another port of
|
||||
the same host, which ask again.
|
||||
|
||||
When a connected site requests a transaction, a separate approval popup appears
|
||||
showing the transaction details (from, to, value, data, network fee, network and
|
||||
|
||||
+2
-2
@@ -6,8 +6,8 @@
|
||||
"license": "GPL-3.0",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"test": "jest --forceExit",
|
||||
"test:verbose": "jest --forceExit --verbose",
|
||||
"test": "jest --forceExit --maxWorkers=3",
|
||||
"test:verbose": "jest --forceExit --maxWorkers=3 --verbose",
|
||||
"build": "node build.js",
|
||||
"lint": "eslint . && prettier --check .",
|
||||
"fmt": "prettier --write .",
|
||||
|
||||
+8
-5
@@ -1,11 +1,14 @@
|
||||
#!/bin/sh
|
||||
# script/test: run the test suite.
|
||||
#
|
||||
# The timeout bounds a hung suite; it is not a performance budget. On a
|
||||
# developer host the suite finishes in about 8s and REPO_POLICIES' 30s cap is
|
||||
# the bound. Inside the image the same suite also pays a cold jest cache and
|
||||
# shares the runner with the rest of the build, which is not what that budget
|
||||
# describes, so the Dockerfile raises the bound through
|
||||
# jest runs three worker processes (package.json), not one per CPU core: on a
|
||||
# many-core shared host one per core took gigabytes of RAM per run.
|
||||
#
|
||||
# The timeout bounds a hung suite; it is not a performance budget. On the busy
|
||||
# shared build host the suite takes 8-13s with three workers, inside
|
||||
# REPO_POLICIES' 20s budget. Inside the image the same suite also pays a cold
|
||||
# jest cache and shares the runner with the rest of the build, which is not what
|
||||
# that budget describes, so the Dockerfile raises the bound through
|
||||
# AUTISTMASK_TEST_TIMEOUT. A cap a healthy suite can trip on a cold cache
|
||||
# produces a red that means nothing, and teaches "just run it again".
|
||||
set -eu
|
||||
|
||||
+55
-55
@@ -57,9 +57,13 @@ const windowsNs = windowsApi();
|
||||
const actionNs = actionApi();
|
||||
|
||||
// Connected sites (in-memory, non-persisted): { "origin:address": true }
|
||||
//
|
||||
// A site is its full origin (scheme://host[:port]), here and in the
|
||||
// remembered allowedSites/deniedSites lists alike: a grant to
|
||||
// https://dapp.example says nothing about http://dapp.example or another port.
|
||||
const connectedSites = {};
|
||||
|
||||
// Pending approval requests: { id: { origin, hostname, resolve } }
|
||||
// Pending approval requests: { id: { origin, resolve } }
|
||||
const pendingApprovals = {};
|
||||
|
||||
// One transaction approval at a time, wallet-wide.
|
||||
@@ -459,10 +463,10 @@ async function openApprovalWindow(id) {
|
||||
|
||||
// Open an approval popup and return a promise that resolves with the user decision.
|
||||
// Prefers the browser-action popup (anchored to toolbar, no macOS Space switch).
|
||||
function requestApproval(origin, hostname) {
|
||||
function requestApproval(origin) {
|
||||
return new Promise((resolve) => {
|
||||
const id = crypto.randomUUID();
|
||||
pendingApprovals[id] = { id, origin, hostname, resolve };
|
||||
pendingApprovals[id] = { id, origin, resolve };
|
||||
|
||||
if (actionNs && typeof actionNs.openPopup === "function") {
|
||||
actionNs.setPopup({
|
||||
@@ -495,13 +499,12 @@ function requestApproval(origin, hostname) {
|
||||
// screen never named.
|
||||
// `slot` is the transaction-approval slot its caller holds. Handing the
|
||||
// approval's id to it is what makes retiring the approval free the slot.
|
||||
function requestTxApproval(origin, hostname, approvedTx, approvedFrom, slot) {
|
||||
function requestTxApproval(origin, approvedTx, approvedFrom, slot) {
|
||||
return new Promise((resolve) => {
|
||||
const id = crypto.randomUUID();
|
||||
pendingApprovals[id] = {
|
||||
id,
|
||||
origin,
|
||||
hostname,
|
||||
approvedTx,
|
||||
approvedFrom,
|
||||
resolve,
|
||||
@@ -517,13 +520,12 @@ function requestTxApproval(origin, hostname, approvedTx, approvedFrom, slot) {
|
||||
// Uses windows.create() directly because sign approvals are triggered programmatically
|
||||
// (from a dApp RPC call), not from a user gesture, so action.openPopup() is
|
||||
// unreliable in this context.
|
||||
function requestSignApproval(origin, hostname, signParams, approvedFrom) {
|
||||
function requestSignApproval(origin, signParams, approvedFrom) {
|
||||
return new Promise((resolve) => {
|
||||
const id = crypto.randomUUID();
|
||||
pendingApprovals[id] = {
|
||||
id,
|
||||
origin,
|
||||
hostname,
|
||||
signParams,
|
||||
approvedFrom,
|
||||
resolve,
|
||||
@@ -601,11 +603,11 @@ runtime.onConnect.addListener((port) => {
|
||||
// in the worker — a balance refresh in flight, another site's approval — has
|
||||
// gone on running the whole time. Loading here used to replace the very
|
||||
// objects that work was holding.
|
||||
async function rememberSiteChoice(field, address, hostname) {
|
||||
async function rememberSiteChoice(field, address, origin) {
|
||||
await updateState((s) => {
|
||||
if (!s[field][address]) s[field][address] = [];
|
||||
if (!s[field][address].includes(hostname)) {
|
||||
s[field][address].push(hostname);
|
||||
if (!s[field][address].includes(origin)) {
|
||||
s[field][address].push(origin);
|
||||
}
|
||||
});
|
||||
}
|
||||
@@ -618,12 +620,11 @@ async function handleConnectionRequest(origin) {
|
||||
return { error: { message: "No accounts available" } };
|
||||
}
|
||||
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
const denied = s.deniedSites[activeAddress] || [];
|
||||
|
||||
// Check denied list
|
||||
if (denied.includes(hostname)) {
|
||||
if (denied.includes(origin)) {
|
||||
return {
|
||||
error: {
|
||||
code: 4001,
|
||||
@@ -634,25 +635,25 @@ async function handleConnectionRequest(origin) {
|
||||
|
||||
// Check allowed list or in-memory connected
|
||||
if (
|
||||
allowed.includes(hostname) ||
|
||||
allowed.includes(origin) ||
|
||||
connectedSites[origin + ":" + activeAddress]
|
||||
) {
|
||||
return { result: [activeAddress] };
|
||||
}
|
||||
|
||||
// Open approval popup
|
||||
const decision = await requestApproval(origin, hostname);
|
||||
const decision = await requestApproval(origin);
|
||||
|
||||
if (decision.approved) {
|
||||
if (decision.remember) {
|
||||
await rememberSiteChoice("allowedSites", activeAddress, hostname);
|
||||
await rememberSiteChoice("allowedSites", activeAddress, origin);
|
||||
} else {
|
||||
connectedSites[origin + ":" + activeAddress] = true;
|
||||
}
|
||||
return { result: [activeAddress] };
|
||||
} else {
|
||||
if (decision.remember) {
|
||||
await rememberSiteChoice("deniedSites", activeAddress, hostname);
|
||||
await rememberSiteChoice("deniedSites", activeAddress, origin);
|
||||
}
|
||||
return {
|
||||
error: {
|
||||
@@ -698,10 +699,9 @@ async function handleRpc(method, params, origin) {
|
||||
const s = await getState();
|
||||
const activeAddress = activeAddressOf(s);
|
||||
if (!activeAddress) return { result: [] };
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
if (
|
||||
allowed.includes(hostname) ||
|
||||
allowed.includes(origin) ||
|
||||
connectedSites[origin + ":" + activeAddress]
|
||||
) {
|
||||
return { result: [activeAddress] };
|
||||
@@ -731,10 +731,9 @@ async function handleRpc(method, params, origin) {
|
||||
// [TESTNET] banner under a user who believed they were on Sepolia.
|
||||
const s = await getState();
|
||||
const activeAddress = activeAddressOf(s);
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
if (
|
||||
!allowed.includes(hostname) &&
|
||||
!allowed.includes(origin) &&
|
||||
!connectedSites[origin + ":" + activeAddress]
|
||||
) {
|
||||
return { error: { code: 4100, message: "Unauthorized" } };
|
||||
@@ -806,10 +805,9 @@ async function handleRpc(method, params, origin) {
|
||||
if (method === "wallet_getPermissions") {
|
||||
const s = await getState();
|
||||
const activeAddress = activeAddressOf(s);
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
const isConnected =
|
||||
allowed.includes(hostname) ||
|
||||
allowed.includes(origin) ||
|
||||
connectedSites[origin + ":" + activeAddress];
|
||||
if (!isConnected || !activeAddress) {
|
||||
return { result: [] };
|
||||
@@ -835,10 +833,9 @@ async function handleRpc(method, params, origin) {
|
||||
if (!activeAddress)
|
||||
return { error: { message: "No accounts available" } };
|
||||
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
if (
|
||||
!allowed.includes(hostname) &&
|
||||
!allowed.includes(origin) &&
|
||||
!connectedSites[origin + ":" + activeAddress]
|
||||
) {
|
||||
return { error: { code: 4100, message: "Unauthorized" } };
|
||||
@@ -870,7 +867,6 @@ async function handleRpc(method, params, origin) {
|
||||
|
||||
const decision = await requestSignApproval(
|
||||
origin,
|
||||
hostname,
|
||||
signParams,
|
||||
activeAddress,
|
||||
);
|
||||
@@ -884,10 +880,9 @@ async function handleRpc(method, params, origin) {
|
||||
if (!activeAddress)
|
||||
return { error: { message: "No accounts available" } };
|
||||
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
if (
|
||||
!allowed.includes(hostname) &&
|
||||
!allowed.includes(origin) &&
|
||||
!connectedSites[origin + ":" + activeAddress]
|
||||
) {
|
||||
return { error: { code: 4100, message: "Unauthorized" } };
|
||||
@@ -905,7 +900,6 @@ async function handleRpc(method, params, origin) {
|
||||
}
|
||||
const decision = await requestSignApproval(
|
||||
origin,
|
||||
hostname,
|
||||
signParams,
|
||||
activeAddress,
|
||||
);
|
||||
@@ -946,10 +940,9 @@ async function handleSendTransaction(params, origin) {
|
||||
const activeAddress = activeAddressOf(s);
|
||||
if (!activeAddress) return { error: { message: "No accounts available" } };
|
||||
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
if (
|
||||
!allowed.includes(hostname) &&
|
||||
!allowed.includes(origin) &&
|
||||
!connectedSites[origin + ":" + activeAddress]
|
||||
) {
|
||||
return { error: { code: 4100, message: "Unauthorized" } };
|
||||
@@ -1023,7 +1016,6 @@ async function handleSendTransaction(params, origin) {
|
||||
|
||||
const decision = await requestTxApproval(
|
||||
origin,
|
||||
hostname,
|
||||
approvedTx,
|
||||
activeAddress,
|
||||
slot,
|
||||
@@ -1097,10 +1089,9 @@ async function broadcastAccountsChanged() {
|
||||
}
|
||||
for (const tab of tabs) {
|
||||
const origin = tab.url ? new URL(tab.url).origin : "";
|
||||
const hostname = extractHostname(origin);
|
||||
const hasPermission =
|
||||
activeAddress &&
|
||||
(allowed.includes(hostname) ||
|
||||
(allowed.includes(origin) ||
|
||||
connectedSites[origin + ":" + activeAddress]);
|
||||
// Same as chainChanged above: a tab without our content script
|
||||
// rejects, and that is expected rather than a fault.
|
||||
@@ -1113,7 +1104,7 @@ async function broadcastAccountsChanged() {
|
||||
}
|
||||
|
||||
// Tell every open tab of a site Settings removed that it has no account.
|
||||
async function broadcastSiteRemoved(hostname) {
|
||||
async function broadcastSiteRemoved(origin) {
|
||||
let tabs;
|
||||
try {
|
||||
tabs = await tabsQuery({});
|
||||
@@ -1121,7 +1112,7 @@ async function broadcastSiteRemoved(hostname) {
|
||||
return;
|
||||
}
|
||||
for (const tab of tabs) {
|
||||
if (!tab.url || extractHostname(tab.url) !== hostname) continue;
|
||||
if (!tab.url || new URL(tab.url).origin !== origin) continue;
|
||||
tabsSendMessage(tab.id, {
|
||||
type: "AUTISTMASK_EVENT",
|
||||
eventName: "accountsChanged",
|
||||
@@ -1288,18 +1279,29 @@ if (windowsNs && windowsNs.onRemoved) {
|
||||
// Listen for messages from content scripts and popup
|
||||
runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
if (msg.type === "AUTISTMASK_RPC") {
|
||||
// Derive origin from trusted sender info to prevent origin spoofing.
|
||||
// Chrome MV3 provides sender.origin; Firefox MV2 fallback uses sender.tab.url.
|
||||
let trustedOrigin = msg.origin; // fallback only if sender info unavailable
|
||||
if (sender.origin) {
|
||||
trustedOrigin = sender.origin;
|
||||
} else if (sender.tab && sender.tab.url) {
|
||||
// The origin is the one the browser reports for the sender, never one
|
||||
// the message carries. Firefox before 126 gives no sender.origin, so
|
||||
// the origin of sender.url is used: the frame that sent the message,
|
||||
// not the tab's page, which may be another site embedding that
|
||||
// frame. With neither, the request is refused.
|
||||
let trustedOrigin = sender.origin;
|
||||
if (!trustedOrigin && sender.url) {
|
||||
try {
|
||||
trustedOrigin = new URL(sender.tab.url).origin;
|
||||
trustedOrigin = new URL(sender.url).origin;
|
||||
} catch {
|
||||
// keep fallback
|
||||
// an unparseable URL leaves the origin unknown
|
||||
}
|
||||
}
|
||||
if (!trustedOrigin) {
|
||||
sendResponse({
|
||||
error: {
|
||||
code: 4100,
|
||||
message:
|
||||
"The wallet could not tell which site sent this request.",
|
||||
},
|
||||
});
|
||||
return false;
|
||||
}
|
||||
handleRpc(msg.method, msg.params, trustedOrigin)
|
||||
.then((response) => {
|
||||
sendResponse(response);
|
||||
@@ -1337,10 +1339,7 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
if (msg.type === "AUTISTMASK_GET_APPROVAL") {
|
||||
const approval = pendingApprovals[msg.id];
|
||||
if (approval) {
|
||||
const resp = {
|
||||
hostname: approval.hostname,
|
||||
origin: approval.origin,
|
||||
};
|
||||
const resp = { origin: approval.origin };
|
||||
if (approval.type === "tx") {
|
||||
resp.type = "tx";
|
||||
// The populated transaction, and the address it was raised
|
||||
@@ -1355,7 +1354,9 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
resp.approvedFrom = approval.approvedFrom;
|
||||
}
|
||||
// Flag if the requesting domain is on the phishing blocklist.
|
||||
resp.isPhishingDomain = isPhishingDomain(approval.hostname);
|
||||
resp.isPhishingDomain = isPhishingDomain(
|
||||
extractHostname(approval.origin),
|
||||
);
|
||||
sendResponse(resp);
|
||||
} else {
|
||||
sendResponse(null);
|
||||
@@ -1689,23 +1690,22 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
if (msg.type === "AUTISTMASK_GET_CONNECTED_SITES") {
|
||||
sendResponse(
|
||||
Object.keys(connectedSites).map((key) =>
|
||||
extractHostname(key.slice(0, key.lastIndexOf(":"))),
|
||||
key.slice(0, key.lastIndexOf(":")),
|
||||
),
|
||||
);
|
||||
return false;
|
||||
}
|
||||
|
||||
// Settings removed this site and has already dropped its remembered
|
||||
// entries. Its connections approved without "Remember" end here, under
|
||||
// every address, and its open tabs are told it has no account.
|
||||
// Settings removed this site (msg.origin) and has already dropped its
|
||||
// remembered entries. Its connections approved without "Remember" end
|
||||
// here, under every address, and its open tabs are told it has no account.
|
||||
if (msg.type === "AUTISTMASK_REMOVE_SITE") {
|
||||
for (const key of Object.keys(connectedSites)) {
|
||||
const origin = key.slice(0, key.lastIndexOf(":"));
|
||||
if (extractHostname(origin) === msg.hostname) {
|
||||
if (key.slice(0, key.lastIndexOf(":")) === msg.origin) {
|
||||
delete connectedSites[key];
|
||||
}
|
||||
}
|
||||
broadcastSiteRemoved(msg.hostname);
|
||||
broadcastSiteRemoved(msg.origin);
|
||||
return false;
|
||||
}
|
||||
});
|
||||
|
||||
@@ -30,7 +30,6 @@ window.addEventListener("message", (event) => {
|
||||
id,
|
||||
method,
|
||||
params,
|
||||
origin: location.origin,
|
||||
})
|
||||
.then((response) => {
|
||||
if (response) {
|
||||
|
||||
+17
-10
@@ -698,15 +698,13 @@
|
||||
You do not have enough ETH to pay the network fee for this
|
||||
transfer. Please add ETH to this address and try again.
|
||||
</div>
|
||||
<!-- Its sentence names why the fee could not be estimated,
|
||||
so show() in confirmTx.js sets it. -->
|
||||
<div
|
||||
id="confirm-fee-unknown-error"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
The network fee could not be estimated, so this transaction
|
||||
cannot be checked against your balance. Please go back and
|
||||
try again.
|
||||
</div>
|
||||
></div>
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1 text-xs">Password</label>
|
||||
<input
|
||||
@@ -1563,7 +1561,7 @@
|
||||
with extreme caution.
|
||||
</div>
|
||||
<p class="mb-2">
|
||||
<span id="approve-tx-hostname" class="font-bold"></span>
|
||||
<span id="approve-tx-origin" class="font-bold"></span>
|
||||
wants to send a transaction.
|
||||
</p>
|
||||
|
||||
@@ -1633,7 +1631,7 @@
|
||||
</div>
|
||||
<div
|
||||
id="approve-tx-error"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem]"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="flex justify-between">
|
||||
@@ -1664,7 +1662,7 @@
|
||||
funds. Proceed with extreme caution.
|
||||
</div>
|
||||
<p class="mb-2">
|
||||
<span id="approve-sign-hostname" class="font-bold"></span>
|
||||
<span id="approve-sign-origin" class="font-bold"></span>
|
||||
wants you to sign a message.
|
||||
</p>
|
||||
|
||||
@@ -1700,6 +1698,15 @@
|
||||
></div>
|
||||
</div>
|
||||
|
||||
<div id="approve-sign-hex-section" class="mb-3 hidden">
|
||||
<div class="text-xs text-muted mb-1">Raw data</div>
|
||||
<div
|
||||
id="approve-sign-hex"
|
||||
class="text-xs break-all"
|
||||
style="max-height: 6rem; overflow-y: auto"
|
||||
></div>
|
||||
</div>
|
||||
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1 text-xs">Password</label>
|
||||
<input
|
||||
@@ -1710,7 +1717,7 @@
|
||||
</div>
|
||||
<div
|
||||
id="approve-sign-error"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem]"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="flex justify-between">
|
||||
@@ -1742,7 +1749,7 @@
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<p class="mb-2">
|
||||
<span id="approve-hostname" class="font-bold"></span>
|
||||
<span id="approve-origin" class="font-bold"></span>
|
||||
wants to connect to your wallet.
|
||||
</p>
|
||||
<div class="text-xs text-muted mb-1">
|
||||
|
||||
+36
-14
@@ -20,6 +20,7 @@ const {
|
||||
getBigInt,
|
||||
getBytes,
|
||||
Interface,
|
||||
isHexString,
|
||||
MaxUint256,
|
||||
toUtf8String,
|
||||
TypedDataEncoder,
|
||||
@@ -306,7 +307,7 @@ function showTxApproval(details) {
|
||||
};
|
||||
}
|
||||
|
||||
$("approve-tx-hostname").textContent = details.hostname;
|
||||
$("approve-tx-origin").textContent = details.origin;
|
||||
$("approve-tx-from").innerHTML = approvalAddressHtml(details.approvedFrom);
|
||||
|
||||
// Show token symbol next to contract address if known
|
||||
@@ -380,20 +381,28 @@ function showTxApproval(details) {
|
||||
);
|
||||
}
|
||||
|
||||
// The text the hex message's bytes decode to as UTF-8, or null when they are
|
||||
// not UTF-8. The caller has checked that the message is hex.
|
||||
function decodeHexMessage(hex) {
|
||||
try {
|
||||
const bytes = Uint8Array.from(
|
||||
hex
|
||||
.slice(2)
|
||||
.match(/.{1,2}/g)
|
||||
.map((b) => parseInt(b, 16)),
|
||||
);
|
||||
return toUtf8String(bytes);
|
||||
return toUtf8String(getBytes(hex));
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
// The text as HTML, with each control or format character (zero-width and
|
||||
// bidirectional characters among them) shown as a bordered U+XXXX mark
|
||||
// instead of acting on the text, so it reads in the order of its bytes. Line
|
||||
// feeds are shown as line breaks.
|
||||
function markControlCharacters(text) {
|
||||
return escapeHtml(text).replace(/[\p{Cc}\p{Cf}]/gu, (c) => {
|
||||
if (c === "\n") return "<br>";
|
||||
const code = c.codePointAt(0).toString(16).toUpperCase();
|
||||
return `<span class="border border-border">U+${code.padStart(4, "0")}</span>`;
|
||||
});
|
||||
}
|
||||
|
||||
// The type ethers will sign typed data as. ethers does not read the page's
|
||||
// `primaryType`: it takes the one struct in `types` that no other struct
|
||||
// refers to. Throws when the types name no such single struct, which ethers
|
||||
@@ -645,7 +654,7 @@ function showSignApproval(details) {
|
||||
pendingSignParams = sp;
|
||||
pendingSignFrom = details.approvedFrom;
|
||||
|
||||
$("approve-sign-hostname").textContent = details.hostname;
|
||||
$("approve-sign-origin").textContent = details.origin;
|
||||
$("approve-sign-from").innerHTML = approvalAddressHtml(
|
||||
details.approvedFrom,
|
||||
);
|
||||
@@ -657,15 +666,29 @@ function showSignApproval(details) {
|
||||
? "Typed data (EIP-712)"
|
||||
: "Personal message";
|
||||
|
||||
// A personal message is signed as the bytes its hex encodes, so the hex
|
||||
// is shown as well as any text it decodes to. Signing reads the bytes
|
||||
// from the hex, so a message that is not hex cannot be signed: it is
|
||||
// shown as the text it is, and refused.
|
||||
let refusal = null;
|
||||
$("approve-sign-hex-section").classList.add("hidden");
|
||||
if (isTyped) {
|
||||
$("approve-sign-message").innerHTML = formatTypedDataHtml(sp.typedData);
|
||||
} else {
|
||||
refusal = typedDataRefusal(sp);
|
||||
} else if (isHexString(sp.message, true)) {
|
||||
const decoded = decodeHexMessage(sp.message);
|
||||
if (decoded !== null) {
|
||||
$("approve-sign-message").textContent = decoded;
|
||||
$("approve-sign-message").innerHTML =
|
||||
markControlCharacters(decoded);
|
||||
} else {
|
||||
$("approve-sign-message").textContent = sp.message;
|
||||
$("approve-sign-message").textContent = "This message is not text.";
|
||||
}
|
||||
$("approve-sign-hex").textContent = sp.message;
|
||||
$("approve-sign-hex-section").classList.remove("hidden");
|
||||
} else {
|
||||
$("approve-sign-message").innerHTML = markControlCharacters(sp.message);
|
||||
refusal =
|
||||
"This message is plain text, not hex, so it cannot be signed.";
|
||||
}
|
||||
|
||||
// Display danger warning for eth_sign (raw hash signing)
|
||||
@@ -687,7 +710,6 @@ function showSignApproval(details) {
|
||||
|
||||
showView("approve-sign");
|
||||
attachCopyHandlers("view-approve-sign");
|
||||
const refusal = typedDataRefusal(sp);
|
||||
if (refusal) {
|
||||
showError("approve-sign-error", refusal);
|
||||
$("btn-approve-sign").disabled = true;
|
||||
@@ -732,7 +754,7 @@ async function show(id) {
|
||||
"approve-site-phishing-warning",
|
||||
details.isPhishingDomain,
|
||||
);
|
||||
$("approve-hostname").textContent = details.hostname;
|
||||
$("approve-origin").textContent = details.origin;
|
||||
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
||||
attachCopyHandlers("view-approve-site");
|
||||
$("approve-remember").checked = state.rememberSiteChoice;
|
||||
|
||||
@@ -198,6 +198,19 @@ function show(txInfo) {
|
||||
$("confirm-amount-fee-error").classList.toggle("hidden", isErc20);
|
||||
$("confirm-gas-error").classList.toggle("hidden", !isErc20);
|
||||
|
||||
// The fee-unknown message names its cause, which is also known here.
|
||||
// Without the token's scale estimateGas() cannot encode the transfer, so
|
||||
// the estimate fails every time and going back cannot help; any other
|
||||
// failure may clear on a retry.
|
||||
$("confirm-fee-unknown-error").textContent =
|
||||
isErc20 && txInfo.tokenDecimals == null
|
||||
? "The network fee could not be estimated, because this wallet" +
|
||||
" does not know how many decimal places this token uses, so" +
|
||||
" this transaction cannot be sent."
|
||||
: "The network fee could not be estimated, so this transaction" +
|
||||
" cannot be checked against your balance. Please go back and" +
|
||||
" try again.";
|
||||
|
||||
renderValidation(txInfo);
|
||||
|
||||
// Reset password field and error
|
||||
@@ -244,7 +257,8 @@ function renderValidation(txInfo) {
|
||||
});
|
||||
|
||||
// Messages carrying the user's own numbers are built here; the fixed
|
||||
// sentences live in the reserved elements in index.html.
|
||||
// sentences live in the reserved elements in index.html, except the
|
||||
// fee-unknown one, which show() sets.
|
||||
const messages = [];
|
||||
if (codes.includes(CODES.AMOUNT_INVALID)) {
|
||||
messages.push("Please enter a valid amount to send.");
|
||||
|
||||
+52
-52
@@ -146,6 +146,50 @@ function renderSendTokenSelect(addr) {
|
||||
}
|
||||
}
|
||||
|
||||
// The token balance and scale the Send screen states and hands the
|
||||
// confirmation screen, so the two screens describe the holding the same way.
|
||||
//
|
||||
// The scale is resolved the same way balances.js resolved the scale it
|
||||
// DISPLAYED this token's balance at: bundled list, then the user's tracked
|
||||
// tokens, then the explorer. The stored tokenBalances[].decimals is the
|
||||
// explorer's own answer alone, so reading it raw carries a null forward for a
|
||||
// token the wallet does know the scale of — and displayedDecimals() then throws
|
||||
// inside estimateGas(), which the confirmation screen reports as an unestimable
|
||||
// fee. Unsendable, over a scale that was never in doubt
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/349). Still null when nothing
|
||||
// knows: no fallback.
|
||||
//
|
||||
// Resolved WITH `wallets`, which balances.js does not pass: that adds
|
||||
// explorerDecimals()'s cross-address check, so a contract two addresses report
|
||||
// different scales for answers null rather than picking one. That check has to
|
||||
// apply here, because this scale encodes the transfer — it is carried forward
|
||||
// so the transfer is encoded with the number the user read rather than with
|
||||
// whatever the contract answers at signing time (see
|
||||
// src/shared/transferAmount.js). balances.js is formatting one explorer row at
|
||||
// fetch time and cannot consult a state it is in the middle of replacing.
|
||||
//
|
||||
// The two resolutions can therefore differ, and where they do, the stored
|
||||
// `balance` is a quantity computed at a scale this screen has just declined to
|
||||
// stand behind. Stating it would leave validateTransfer() checking the amount
|
||||
// against a number the wallet does not vouch for, so it is withdrawn: unknown
|
||||
// scale means unknown balance. It is null rather than "0": both screens state
|
||||
// an unknown balance as unknown, and validateTransfer() treats it as no balance
|
||||
// to spend from, which is the fail-closed side of an amount nobody can check.
|
||||
// Only a stored quantity is withdrawn: the "0" for a token that has no row at
|
||||
// all is an absence of holdings, which is true at every scale.
|
||||
function tokenBalanceAndDecimals(addr, token) {
|
||||
const tb = (addr.tokenBalances || []).find(
|
||||
(t) => t.address.toLowerCase() === token.toLowerCase(),
|
||||
);
|
||||
const tokenDecimals = resolveTokenDecimals(token, {
|
||||
trackedTokens: state.trackedTokens,
|
||||
wallets: state.wallets,
|
||||
});
|
||||
if (!tb) return { tokenBalance: "0", tokenDecimals };
|
||||
if (tokenDecimals === null) return { tokenBalance: null, tokenDecimals };
|
||||
return { tokenBalance: tb.balance ?? null, tokenDecimals };
|
||||
}
|
||||
|
||||
function updateSendBalance() {
|
||||
const addr = currentAddress();
|
||||
if (!addr) return;
|
||||
@@ -162,18 +206,16 @@ function updateSendBalance() {
|
||||
truncateAmountNeverZero(addr.balance || "0") +
|
||||
" ETH";
|
||||
} else {
|
||||
const tb = (addr.tokenBalances || []).find(
|
||||
(t) => t.address.toLowerCase() === token.toLowerCase(),
|
||||
);
|
||||
const symbol = resolveSymbol(
|
||||
token,
|
||||
addr.tokenBalances,
|
||||
state.trackedTokens,
|
||||
);
|
||||
// A null balance is a holding whose scale nothing knows. Saying "0"
|
||||
// for it would be a claim about the amount; the send itself is
|
||||
// A null balance is a holding whose scale is unknown. Saying a figure
|
||||
// for it would be a claim about the amount, so it reads as the
|
||||
// confirmation screen's balance line reads it; the send itself is
|
||||
// refused later by transferAmountUnits() for the same missing scale.
|
||||
const bal = tb ? tb.balance : "0";
|
||||
const bal = tokenBalanceAndDecimals(addr, token).tokenBalance;
|
||||
$("send-balance").textContent =
|
||||
bal == null
|
||||
? "Current balance: unknown (" + symbol + ")"
|
||||
@@ -240,59 +282,17 @@ function init(_ctx) {
|
||||
|
||||
let tokenSymbol = null;
|
||||
let tokenBalance = null;
|
||||
// The scale the amount and the balance below are rendered at, carried
|
||||
// forward so the transfer is encoded with the number the user read
|
||||
// rather than with whatever the contract answers at signing time. See
|
||||
// src/shared/transferAmount.js.
|
||||
let tokenDecimals = null;
|
||||
if (token !== "ETH") {
|
||||
const tb = (addr.tokenBalances || []).find(
|
||||
(t) => t.address.toLowerCase() === token.toLowerCase(),
|
||||
);
|
||||
tokenSymbol = resolveSymbol(
|
||||
token,
|
||||
addr.tokenBalances,
|
||||
state.trackedTokens,
|
||||
);
|
||||
// null carried through rather than flattened to "0": the confirm
|
||||
// screen states an unknown balance as unknown, and
|
||||
// validateTransfer() treats it as no balance to spend from, which
|
||||
// is the fail-closed side of an amount nobody can check.
|
||||
tokenBalance = tb ? (tb.balance ?? null) : "0";
|
||||
// Resolved the same way balances.js resolved the scale it
|
||||
// DISPLAYED this token's balance at: bundled list, then the user's
|
||||
// tracked tokens, then the explorer. The stored
|
||||
// tokenBalances[].decimals is the explorer's own answer alone, so
|
||||
// reading it raw carries a null forward for a token the wallet
|
||||
// does know the scale of — and displayedDecimals() then throws
|
||||
// inside estimateGas(), which the confirmation screen reports as
|
||||
// an unestimable fee. Unsendable, over a scale that was never in
|
||||
// doubt (https://git.eeqj.de/sneak/AutistMask/issues/349).
|
||||
// Still null when nothing knows: no fallback.
|
||||
//
|
||||
// Resolved WITH `wallets`, which balances.js does not pass: that
|
||||
// adds explorerDecimals()'s cross-address check, so a contract two
|
||||
// addresses report different scales for answers null rather than
|
||||
// picking one. That check has to apply here, because this value
|
||||
// encodes a transfer; balances.js is formatting one explorer row
|
||||
// at fetch time and cannot consult a state it is in the middle of
|
||||
// replacing.
|
||||
tokenDecimals = resolveTokenDecimals(token, {
|
||||
trackedTokens: state.trackedTokens,
|
||||
wallets: state.wallets,
|
||||
});
|
||||
// The two resolutions can therefore differ, and where they do, the
|
||||
// stored `balance` is a quantity computed at a scale this screen
|
||||
// has just declined to stand behind. Stating it would leave
|
||||
// validateTransfer() checking the amount against a number the
|
||||
// wallet does not vouch for, and — since the unknown-balance path
|
||||
// is gated on the balance, not on the scale — would leave the
|
||||
// fee-estimate failure as the only thing on the confirmation
|
||||
// screen, which says nothing about decimals. Unknown scale means
|
||||
// unknown balance. Only a stored quantity is withdrawn: the "0"
|
||||
// for a token that has no row at all is an absence of holdings,
|
||||
// which is true at every scale.
|
||||
if (tb && tokenDecimals === null) tokenBalance = null;
|
||||
({ tokenBalance, tokenDecimals } = tokenBalanceAndDecimals(
|
||||
addr,
|
||||
token,
|
||||
));
|
||||
}
|
||||
|
||||
ctx.showConfirmTx({
|
||||
|
||||
+17
-17
@@ -34,35 +34,35 @@ const { notify, sendMessage } = require("../../shared/browserApi");
|
||||
let versionClickCount = 0;
|
||||
let versionClickTimer = null;
|
||||
|
||||
// One row per hostname, however many addresses or origins it appears under,
|
||||
// each with an [x] that hands it to onRemove.
|
||||
function renderSiteList(containerId, hostnames, onRemove) {
|
||||
// One row per site origin, however many addresses it appears under, each with
|
||||
// an [x] that hands it to onRemove.
|
||||
function renderSiteList(containerId, origins, onRemove) {
|
||||
const container = $(containerId);
|
||||
const unique = [...new Set(hostnames)];
|
||||
const unique = [...new Set(origins)];
|
||||
if (unique.length === 0) {
|
||||
container.innerHTML = '<p class="text-xs text-muted">None</p>';
|
||||
return;
|
||||
}
|
||||
let html = "";
|
||||
unique.forEach((hostname) => {
|
||||
unique.forEach((origin) => {
|
||||
html += `<div class="flex justify-between items-center text-xs py-1 border-b border-border-light">`;
|
||||
// A hostname the URL parser produced cannot carry a delimiter, so
|
||||
// An origin the URL parser produced cannot carry a delimiter, so
|
||||
// this is escaped for the rule rather than for a known hole — the
|
||||
// rule being that nothing reaches innerHTML unescaped.
|
||||
html += `<span>${escapeHtml(hostname)}</span>`;
|
||||
html += `<button class="btn-remove-site border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-hostname="${escapeHtml(hostname)}">[x]</button>`;
|
||||
html += `<span>${escapeHtml(origin)}</span>`;
|
||||
html += `<button class="btn-remove-site border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-origin="${escapeHtml(origin)}">[x]</button>`;
|
||||
html += `</div>`;
|
||||
});
|
||||
container.innerHTML = html;
|
||||
container.querySelectorAll(".btn-remove-site").forEach((btn) => {
|
||||
btn.addEventListener("click", () => onRemove(btn.dataset.hostname));
|
||||
btn.addEventListener("click", () => onRemove(btn.dataset.origin));
|
||||
});
|
||||
}
|
||||
|
||||
// Drop a hostname from a remembered site list under every address.
|
||||
function forgetHostname(siteMap, hostname) {
|
||||
// Drop a site origin from a remembered site list under every address.
|
||||
function forgetOrigin(siteMap, origin) {
|
||||
for (const addr of Object.keys(siteMap)) {
|
||||
siteMap[addr] = siteMap[addr].filter((h) => h !== hostname);
|
||||
siteMap[addr] = siteMap[addr].filter((o) => o !== origin);
|
||||
if (siteMap[addr].length === 0) {
|
||||
delete siteMap[addr];
|
||||
}
|
||||
@@ -72,16 +72,16 @@ function forgetHostname(siteMap, hostname) {
|
||||
// Removing a site from Allowed Sites or Connected Sites disconnects it: it is
|
||||
// no longer allowed under any address, and the background ends its
|
||||
// connections approved without "Remember" and tells its open tabs.
|
||||
async function removeAllowedSite(hostname) {
|
||||
forgetHostname(state.allowedSites, hostname);
|
||||
async function removeAllowedSite(origin) {
|
||||
forgetOrigin(state.allowedSites, origin);
|
||||
await saveState();
|
||||
notify({ type: "AUTISTMASK_REMOVE_SITE", hostname });
|
||||
notify({ type: "AUTISTMASK_REMOVE_SITE", origin });
|
||||
await renderSiteLists();
|
||||
}
|
||||
|
||||
// Removing a denied site only forgets the refusal; it connects nothing.
|
||||
async function removeDeniedSite(hostname) {
|
||||
forgetHostname(state.deniedSites, hostname);
|
||||
async function removeDeniedSite(origin) {
|
||||
forgetOrigin(state.deniedSites, origin);
|
||||
await saveState();
|
||||
await renderSiteLists();
|
||||
}
|
||||
|
||||
@@ -51,11 +51,15 @@ const POPULATE_TIMEOUT_MS = 20000;
|
||||
// passed to ethers: the object is page-controlled, and a future ethers that
|
||||
// learns to carry a new transaction field must not start picking one up out of
|
||||
// it without this module knowing.
|
||||
//
|
||||
// The nonce is not taken from the page; it is always the account's next nonce
|
||||
// from the network. A page that chose it could replace one of the user's
|
||||
// pending transactions (the same nonce at a higher fee) or leave this one stuck
|
||||
// behind a gap (a nonce above the next one).
|
||||
const REQUEST_FIELDS = [
|
||||
"to",
|
||||
"value",
|
||||
"data",
|
||||
"nonce",
|
||||
"gasLimit",
|
||||
"gasPrice",
|
||||
"maxFeePerGas",
|
||||
|
||||
@@ -102,11 +102,11 @@ function tokenRefs(value) {
|
||||
|
||||
// A list of strings, for the fields whose entries are dereferenced as text:
|
||||
// fraudContracts (`a.toLowerCase()` in src/popup/views/send.js and
|
||||
// src/shared/transactions.js) and each address's hostname list in the site maps
|
||||
// below (`h !== host` filters, `list.includes(hostname)` in the background).
|
||||
// src/shared/transactions.js) and each address's origin list in the site maps
|
||||
// below (`o !== origin` filters, `list.includes(origin)` in the background).
|
||||
//
|
||||
// Same rule as tokenRefs(), for the same reason: the container AND the entries,
|
||||
// with a malformed entry DROPPED rather than repaired. A number in a hostname
|
||||
// with a malformed entry DROPPED rather than repaired. A number in an origin
|
||||
// list names no site and a number in fraudContracts names no contract, so there
|
||||
// is nothing to repair either to, and the empty list is a legitimate value that
|
||||
// survives. The result is a fresh array of primitives, so it shares no
|
||||
@@ -116,21 +116,22 @@ function textList(value) {
|
||||
return value.filter((entry) => typeof entry === "string");
|
||||
}
|
||||
|
||||
// allowedSites / deniedSites: { [address]: [hostname, ...] }.
|
||||
// allowedSites / deniedSites: { [address]: [origin, ...] }, each origin the
|
||||
// full scheme://host[:port] of a site.
|
||||
//
|
||||
// The container check these had (truthy and not an array) is not the floor:
|
||||
// `{"0xabc…": "notalist"}` IS a non-array object, and the dereference is one
|
||||
// level below it. saveState() merges these maps per key and then per hostname
|
||||
// level below it. saveState() merges these maps per key and then per origin
|
||||
// WITHIN each key, so a stored value that is not a list reaches `base.map()` in
|
||||
// mergeListByIdentity() (src/shared/state.js) and throws — after the popup has
|
||||
// rendered, which is why every save from then on failed while the UI looked
|
||||
// healthy (https://git.eeqj.de/sneak/AutistMask/issues/362). The Settings
|
||||
// revoke button (`list.filter()`), and the background's
|
||||
// `allowed.includes(hostname)` gate, dereference it the same way; on that last
|
||||
// `allowed.includes(origin)` gate, dereference it the same way; on that last
|
||||
// one a stored string would also answer a SUBSTRING match, so a corrupt map
|
||||
// could widen a site permission rather than merely throw.
|
||||
//
|
||||
// An address key whose value is not a list of hostnames is dropped entirely: it
|
||||
// An address key whose value is not a list of origins is dropped entirely: it
|
||||
// grants and denies nothing, and dropping it fails closed. A stored own
|
||||
// "__proto__" key — which JSON can carry — is dropped for the same reason: it
|
||||
// can never be a wallet address, so it grants nothing either, and keeping it
|
||||
@@ -143,9 +144,9 @@ function siteMap(value) {
|
||||
if (!isRecord(value)) return out;
|
||||
for (const address of Object.keys(value)) {
|
||||
if (address === "__proto__") continue;
|
||||
const hostnames = textList(value[address]);
|
||||
if (hostnames.length === 0) continue;
|
||||
defineOwn(out, address, hostnames);
|
||||
const origins = textList(value[address]);
|
||||
if (origins.length === 0) continue;
|
||||
defineOwn(out, address, origins);
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
+10
-10
@@ -304,7 +304,7 @@ function mergeAddress(base, ours, theirs) {
|
||||
}
|
||||
|
||||
// Merge a plain object keyed by string (allowedSites/deniedSites: address ->
|
||||
// hostname list; networkEndpoints: networkId -> {rpcUrl, blockscoutUrl}) the
|
||||
// origin list; networkEndpoints: networkId -> {rpcUrl, blockscoutUrl}) the
|
||||
// same way mergeListByIdentity() merges an array — by key, not by whole-
|
||||
// object diff — so a key one page added or removed applies independently of
|
||||
// a key another page edited. Unlike an array's identity function, an object
|
||||
@@ -353,25 +353,25 @@ function mergeMapByKey(base, ours, theirs, mergeLeaf) {
|
||||
return result;
|
||||
}
|
||||
|
||||
// allowedSites/deniedSites: { [address]: [hostname, ...] }. The hostname
|
||||
// allowedSites/deniedSites: { [address]: [origin, ...] }. The origin
|
||||
// list is itself membership, not a leaf — the background appends a newly
|
||||
// approved/denied hostname to it, and the Settings "revoke" button
|
||||
// (src/popup/views/settings.js) filters a hostname out of it in place, from a
|
||||
// approved/denied origin to it, and the Settings "revoke" button
|
||||
// (src/popup/views/settings.js) filters an origin out of it in place, from a
|
||||
// different page. Merge it the same way wallets are merged: identity is the
|
||||
// hostname itself, so a merged pair is always equal and mergeItem is a no-op
|
||||
// origin itself, so a merged pair is always equal and mergeItem is a no-op
|
||||
// pick.
|
||||
function mergeHostnameList(base, ours, theirs) {
|
||||
function mergeOriginList(base, ours, theirs) {
|
||||
return mergeListByIdentity(
|
||||
base,
|
||||
ours,
|
||||
theirs,
|
||||
(hostname) => hostname,
|
||||
(origin) => origin,
|
||||
(b, o, t) => t,
|
||||
);
|
||||
}
|
||||
|
||||
function mergeSiteMap(base, ours, theirs) {
|
||||
return mergeMapByKey(base, ours, theirs, mergeHostnameList);
|
||||
return mergeMapByKey(base, ours, theirs, mergeOriginList);
|
||||
}
|
||||
|
||||
// networkEndpoints: { [networkId]: {rpcUrl, blockscoutUrl} }.
|
||||
@@ -422,8 +422,8 @@ function mergeNetworkEndpoints(base, ours, theirs) {
|
||||
// address) apply independently instead of colliding as the same field.
|
||||
//
|
||||
// `allowedSites` and `deniedSites` get the same treatment (mergeSiteMap(),
|
||||
// by address key and then by hostname within each address's list), for the
|
||||
// identical reason: the background appends a newly approved/denied hostname
|
||||
// by address key and then by origin within each address's list), for the
|
||||
// identical reason: the background appends a newly approved/denied origin
|
||||
// to them, and the Settings "revoke" button (src/popup/views/settings.js)
|
||||
// filters one out in place, from a different page. A whole-field diff here
|
||||
// doesn't just lose data, it is a security defect — a stale page's save can
|
||||
|
||||
@@ -0,0 +1,167 @@
|
||||
// A nonce the page supplies is not used
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/404). With it a page could
|
||||
// replace one of the user's pending transactions (the same nonce at a higher
|
||||
// fee) or leave the new one stuck behind a gap, so the transaction is always
|
||||
// given the account's next nonce from the network.
|
||||
//
|
||||
// Driven through the preparation the background runs on a page's
|
||||
// eth_sendTransaction (src/shared/approvalTx.js) and the real approval screen,
|
||||
// password and Confirm included, against a minimal DOM stub in the shape
|
||||
// tests/approvalOrigin.test.js uses. The vault is mocked so that no password
|
||||
// has to be hashed.
|
||||
|
||||
jest.mock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: jest.fn(),
|
||||
}));
|
||||
|
||||
globalThis.chrome = {
|
||||
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||
};
|
||||
|
||||
const { Network, Transaction } = require("ethers");
|
||||
const { state } = require("../src/shared/state");
|
||||
const { decryptWithPassword } = require("../src/shared/vault");
|
||||
const { prepareApprovalTx } = require("../src/shared/approvalTx");
|
||||
const approval = require("../src/popup/views/approval");
|
||||
|
||||
// A well-known test phrase, and its first address.
|
||||
const PHRASE = "test test test test test test test test test test test junk";
|
||||
const FROM = "0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266";
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
// The account's next nonce, as the network reports it.
|
||||
const NETWORK_NONCE = 7;
|
||||
|
||||
const network = {
|
||||
getNetwork: async () => Network.from(1),
|
||||
getTransactionCount: async () => NETWORK_NONCE,
|
||||
estimateGas: async () => 21000n,
|
||||
getFeeData: async () => ({
|
||||
gasPrice: 2000000000n,
|
||||
maxFeePerGas: 2000000000n,
|
||||
maxPriorityFeePerGas: 1000000000n,
|
||||
}),
|
||||
};
|
||||
|
||||
function makeElement(id) {
|
||||
const classes = new Set();
|
||||
const el = {
|
||||
id,
|
||||
textContent: "",
|
||||
value: "",
|
||||
innerHTML: "",
|
||||
disabled: false,
|
||||
style: {},
|
||||
dataset: {},
|
||||
listeners: {},
|
||||
classList: {
|
||||
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||
contains: (n) => classes.has(n),
|
||||
toggle: (n, force) => {
|
||||
const on = force === undefined ? !classes.has(n) : force;
|
||||
if (on) classes.add(n);
|
||||
else classes.delete(n);
|
||||
return on;
|
||||
},
|
||||
},
|
||||
addEventListener: (name, fn) => {
|
||||
el.listeners[name] = el.listeners[name] || [];
|
||||
el.listeners[name].push(fn);
|
||||
},
|
||||
querySelectorAll: () => [],
|
||||
appendChild: () => {},
|
||||
};
|
||||
// Views reach for .parentElement to hide whole sections.
|
||||
Object.defineProperty(el, "parentElement", {
|
||||
get: () => node(id + "-parent"),
|
||||
});
|
||||
return el;
|
||||
}
|
||||
|
||||
function makeDocument() {
|
||||
const els = new Map();
|
||||
return {
|
||||
getElementById(id) {
|
||||
// The debug banner is created on demand by helpers.js; absent
|
||||
// is the state a non-debug, non-testnet popup is in.
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement(id));
|
||||
return els.get(id);
|
||||
},
|
||||
createElement: () => makeElement("created"),
|
||||
body: { prepend: () => {} },
|
||||
};
|
||||
}
|
||||
|
||||
function node(id) {
|
||||
return globalThis.document.getElementById(id);
|
||||
}
|
||||
|
||||
function click(id) {
|
||||
return Promise.all((node(id).listeners.click || []).map((fn) => fn()));
|
||||
}
|
||||
|
||||
// Open the transaction approval screen the way the popup does: the background
|
||||
// hands over the populated transaction and show() draws it. Returns every
|
||||
// message the screen sends to the background. The background's answer to the
|
||||
// signed transaction does not matter here; a retryable refusal keeps the
|
||||
// screen where it is.
|
||||
async function openTxApproval(approvedTx) {
|
||||
const sent = [];
|
||||
globalThis.document = makeDocument();
|
||||
globalThis.window = { location: { search: "" }, close: () => {} };
|
||||
globalThis.chrome.runtime = {
|
||||
connect: () => ({ postMessage: () => {} }),
|
||||
sendMessage: (msg, reply) => {
|
||||
sent.push(msg);
|
||||
if (!reply) return;
|
||||
if (msg.type !== "AUTISTMASK_GET_APPROVAL") {
|
||||
return reply({ error: "Not sent.", retryable: true });
|
||||
}
|
||||
reply({
|
||||
type: "tx",
|
||||
origin: "https://dapp.example",
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: FROM,
|
||||
approvedTx,
|
||||
});
|
||||
},
|
||||
};
|
||||
state.activeAddress = FROM;
|
||||
state.wallets = [
|
||||
{
|
||||
type: "hd",
|
||||
name: "Wallet 1",
|
||||
xpub: "xpub-wallet-1",
|
||||
encryptedSecret: "encrypted-secret-1",
|
||||
nextIndex: 1,
|
||||
addresses: [{ address: FROM, balance: "0", tokenBalances: [] }],
|
||||
},
|
||||
];
|
||||
approval.init({});
|
||||
await approval.show(1);
|
||||
return sent;
|
||||
}
|
||||
|
||||
test("a page's nonce is replaced by the network's, on screen and in the signed transaction", async () => {
|
||||
// What the background does with the page's request before it opens the
|
||||
// approval window.
|
||||
const approvedTx = await prepareApprovalTx(network, FROM, {
|
||||
from: FROM,
|
||||
to: RECIPIENT,
|
||||
value: "0x0",
|
||||
data: "0x",
|
||||
nonce: "0x2",
|
||||
});
|
||||
|
||||
const sent = await openTxApproval(approvedTx);
|
||||
expect(node("approve-tx-nonce").textContent).toBe("7");
|
||||
|
||||
decryptWithPassword.mockResolvedValue(PHRASE);
|
||||
node("approve-tx-password").value = "any password";
|
||||
await click("btn-approve-tx");
|
||||
|
||||
const response = sent.find((msg) => msg.type === "AUTISTMASK_TX_RESPONSE");
|
||||
expect(Transaction.from(response.rawSignedTx).nonce).toBe(NETWORK_NONCE);
|
||||
});
|
||||
@@ -0,0 +1,140 @@
|
||||
// The connection, transaction and signature prompts name the site by its full
|
||||
// origin, scheme and port included, not by its bare hostname
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http,
|
||||
// or on another port, of a host the user trusts over https must not raise a
|
||||
// prompt that reads as that trusted site.
|
||||
//
|
||||
// Driven against a minimal DOM stub in the shape
|
||||
// tests/contractCreation.test.js uses.
|
||||
|
||||
globalThis.chrome = {
|
||||
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||
};
|
||||
|
||||
const { state } = require("../src/shared/state");
|
||||
const approval = require("../src/popup/views/approval");
|
||||
|
||||
// The site asking, in cleartext and on a port, which is what the hostname
|
||||
// alone, dapp.example, used to hide.
|
||||
const ORIGIN = "http://dapp.example:8080";
|
||||
const FROM = "0x0000000000000000000000000000000000000a11";
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
function makeElement(id) {
|
||||
const classes = new Set();
|
||||
const el = {
|
||||
id,
|
||||
textContent: "",
|
||||
value: "",
|
||||
innerHTML: "",
|
||||
disabled: false,
|
||||
style: {},
|
||||
dataset: {},
|
||||
classList: {
|
||||
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||
contains: (n) => classes.has(n),
|
||||
toggle: (n, force) => {
|
||||
const on = force === undefined ? !classes.has(n) : force;
|
||||
if (on) classes.add(n);
|
||||
else classes.delete(n);
|
||||
return on;
|
||||
},
|
||||
},
|
||||
addEventListener: () => {},
|
||||
querySelectorAll: () => [],
|
||||
appendChild: () => {},
|
||||
};
|
||||
// Views reach for .parentElement to hide whole sections.
|
||||
Object.defineProperty(el, "parentElement", {
|
||||
get: () => node(id + "-parent"),
|
||||
});
|
||||
return el;
|
||||
}
|
||||
|
||||
function makeDocument() {
|
||||
const els = new Map();
|
||||
return {
|
||||
getElementById(id) {
|
||||
// The debug banner is created on demand by helpers.js; absent
|
||||
// is the state a non-debug, non-testnet popup is in.
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement(id));
|
||||
return els.get(id);
|
||||
},
|
||||
createElement: () => makeElement("created"),
|
||||
body: { prepend: () => {} },
|
||||
};
|
||||
}
|
||||
|
||||
function node(id) {
|
||||
return globalThis.document.getElementById(id);
|
||||
}
|
||||
|
||||
// Open the prompt the background describes with `details`, the way the popup
|
||||
// does: it asks for the approval and show() draws it.
|
||||
async function openApproval(details) {
|
||||
globalThis.document = makeDocument();
|
||||
globalThis.window = { location: { search: "" } };
|
||||
globalThis.chrome.runtime = {
|
||||
connect: () => ({ postMessage: () => {} }),
|
||||
sendMessage: (msg, reply) => {
|
||||
if (!reply) return;
|
||||
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||
reply({
|
||||
origin: ORIGIN,
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: FROM,
|
||||
...details,
|
||||
});
|
||||
},
|
||||
};
|
||||
approval.init({});
|
||||
await approval.show(1);
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
state.wallets = [];
|
||||
state.activeAddress = FROM;
|
||||
state.viewData = {};
|
||||
state.viewStack = [];
|
||||
state.currentView = null;
|
||||
});
|
||||
|
||||
test("the connection prompt shows the origin", async () => {
|
||||
await openApproval({});
|
||||
expect(node("approve-origin").textContent).toBe(ORIGIN);
|
||||
});
|
||||
|
||||
test("the transaction prompt shows the origin", async () => {
|
||||
await openApproval({
|
||||
type: "tx",
|
||||
approvedTx: {
|
||||
type: 2,
|
||||
from: FROM,
|
||||
chainId: "0x1",
|
||||
nonce: "0x7",
|
||||
gasLimit: "0x5208",
|
||||
maxPriorityFeePerGas: "0x3b9aca00",
|
||||
maxFeePerGas: "0x77359400",
|
||||
to: RECIPIENT,
|
||||
value: "0x0",
|
||||
data: "0x",
|
||||
accessList: [],
|
||||
},
|
||||
});
|
||||
expect(node("approve-tx-origin").textContent).toBe(ORIGIN);
|
||||
});
|
||||
|
||||
test("the signature prompt shows the origin", async () => {
|
||||
await openApproval({
|
||||
type: "sign",
|
||||
// "Hello" as the hex a dApp passes to personal_sign.
|
||||
signParams: {
|
||||
method: "personal_sign",
|
||||
message: "0x48656c6c6f",
|
||||
from: FROM,
|
||||
},
|
||||
});
|
||||
expect(node("approve-sign-origin").textContent).toBe(ORIGIN);
|
||||
});
|
||||
@@ -121,7 +121,7 @@ describe("prepareApprovalTx", () => {
|
||||
);
|
||||
});
|
||||
|
||||
test("keeps a nonce, gas limit and fee the request did fix", async () => {
|
||||
test("keeps a gas limit and fee the request did fix, but not its nonce", async () => {
|
||||
const approved = await prepareApprovalTx(
|
||||
providerWith(),
|
||||
signer.address,
|
||||
@@ -133,7 +133,7 @@ describe("prepareApprovalTx", () => {
|
||||
maxPriorityFeePerGas: "0x3b9aca00",
|
||||
},
|
||||
);
|
||||
expect(approved.nonce).toBe("0x2");
|
||||
expect(approved.nonce).toBe("0x7");
|
||||
expect(approved.gasLimit).toBe("0x30d40");
|
||||
expect(approved.maxFeePerGas).toBe("0x12a05f200");
|
||||
});
|
||||
|
||||
@@ -39,7 +39,6 @@ const other = new Wallet(OTHER_KEY);
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
const ORIGIN = "https://dapp.example";
|
||||
const HOSTNAME = "dapp.example";
|
||||
// A page the wallet has never been connected to, whose requests are refused.
|
||||
const UNCONNECTED_ORIGIN = "https://stranger.example";
|
||||
const EXT_URL = "chrome-extension://autistmask/";
|
||||
@@ -199,7 +198,7 @@ function loadBackground(options) {
|
||||
networkId: "mainnet",
|
||||
rpcUrl: "https://rpc.invalid",
|
||||
activeAddress: signer.address,
|
||||
allowedSites: { [signer.address]: [HOSTNAME] },
|
||||
allowedSites: { [signer.address]: [ORIGIN] },
|
||||
deniedSites: {},
|
||||
};
|
||||
|
||||
@@ -2193,12 +2192,54 @@ describe("removing an address ends a site's connection to it", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// A remembered permission belongs to the origin it was granted to, scheme and
|
||||
// port included (https://git.eeqj.de/sneak/AutistMask/issues/402). The stored
|
||||
// state allows ORIGIN, https://dapp.example. A cleartext page on the same host,
|
||||
// which a network attacker can serve, and another port on it are other sites.
|
||||
describe("a remembered permission is held by the full origin", () => {
|
||||
for (const origin of ["http://dapp.example", "https://dapp.example:8443"]) {
|
||||
test(`an https grant does not authorise ${origin}`, async () => {
|
||||
const bg = loadBackground();
|
||||
expect(await siteAccounts(bg, ORIGIN)).toEqual({
|
||||
result: [signer.address],
|
||||
});
|
||||
|
||||
expect(await siteAccounts(bg, origin)).toEqual({ result: [] });
|
||||
const send = bg.requestTx(TX_PARAMS, origin);
|
||||
await settle();
|
||||
expect(send.result()).toEqual({
|
||||
error: { code: 4100, message: "Unauthorized" },
|
||||
});
|
||||
expect(send.id()).toBeNull();
|
||||
});
|
||||
}
|
||||
|
||||
test("Remember stores the origin, so the cleartext page on that host is asked again", async () => {
|
||||
const bg = loadBackground({ actionPopup: true });
|
||||
const granted = bg.requestSite(FRESH_ORIGIN);
|
||||
await settle();
|
||||
const grantedId = granted.id();
|
||||
bg.connectApproval(grantedId).decide(true, true);
|
||||
await settle();
|
||||
expect(granted.result()).toEqual({ result: [signer.address] });
|
||||
expect(
|
||||
bg.storage.read("autistmask").allowedSites[signer.address],
|
||||
).toEqual([ORIGIN, FRESH_ORIGIN]);
|
||||
|
||||
const cleartext = bg.requestSite("http://fresh.example");
|
||||
await settle();
|
||||
// Unanswered: it is waiting on a prompt of its own.
|
||||
expect(cleartext.result()).toBeNull();
|
||||
expect(cleartext.id()).not.toBe(grantedId);
|
||||
});
|
||||
});
|
||||
|
||||
// Settings lists the sites allowed without "Remember", which only the
|
||||
// background holds, and removing a site there, from either list, disconnects
|
||||
// it. These drive the real Settings view against the real background and
|
||||
// click the [x] the user clicks.
|
||||
describe("removing a site in Settings disconnects it", () => {
|
||||
// FRESH_ORIGIN on another port, so its hostname is FRESH_ORIGIN's.
|
||||
// The host of FRESH_ORIGIN on another port, which makes it another site.
|
||||
const FRESH_OTHER_PORT = "https://fresh.example:8443";
|
||||
|
||||
// A site list's container. Its [x] buttons, data attributes and all, are
|
||||
@@ -2226,9 +2267,9 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
return list;
|
||||
}
|
||||
|
||||
// The hostnames a site list shows.
|
||||
// The origins a site list shows.
|
||||
function listed(list) {
|
||||
return [...list.innerHTML.matchAll(/data-hostname="([^"]*)"/g)].map(
|
||||
return [...list.innerHTML.matchAll(/data-origin="([^"]*)"/g)].map(
|
||||
(match) => match[1],
|
||||
);
|
||||
}
|
||||
@@ -2259,10 +2300,10 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
allowed: element("settings-allowed-sites"),
|
||||
connected: element("settings-connected-sites"),
|
||||
// Click the [x] beside a site, and let what it sends run.
|
||||
remove: async (list, hostname) => {
|
||||
expect(listed(list)).toContain(hostname);
|
||||
remove: async (list, origin) => {
|
||||
expect(listed(list)).toContain(origin);
|
||||
const button = list.buttons.find(
|
||||
(b) => b.dataset.hostname === hostname,
|
||||
(b) => b.dataset.origin === origin,
|
||||
);
|
||||
await button.click();
|
||||
await settle();
|
||||
@@ -2274,14 +2315,15 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
delete global.document;
|
||||
});
|
||||
|
||||
test("Settings lists a site connected without Remember", async () => {
|
||||
test("Settings lists each site by its origin", async () => {
|
||||
const bg = loadBackground({ actionPopup: true });
|
||||
await connect(bg, FRESH_ORIGIN, false);
|
||||
await connect(bg, FRESH_OTHER_PORT, true);
|
||||
|
||||
const settings = await openSettings(bg);
|
||||
|
||||
expect(listed(settings.connected)).toEqual(["fresh.example"]);
|
||||
expect(listed(settings.allowed)).toEqual([HOSTNAME]);
|
||||
expect(listed(settings.connected)).toEqual([FRESH_ORIGIN]);
|
||||
expect(listed(settings.allowed)).toEqual([ORIGIN, FRESH_OTHER_PORT]);
|
||||
});
|
||||
|
||||
test("removing a site connected without Remember disconnects it and tells its tabs", async () => {
|
||||
@@ -2293,6 +2335,7 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
cb([
|
||||
{ id: 1, url: FRESH_ORIGIN + "/app" },
|
||||
{ id: 2, url: ORIGIN + "/app" },
|
||||
{ id: 3, url: FRESH_OTHER_PORT + "/app" },
|
||||
]),
|
||||
sendMessage: (tabId, msg, cb) => {
|
||||
sentToTabs.push({ tabId, msg });
|
||||
@@ -2301,7 +2344,7 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
};
|
||||
const settings = await openSettings(bg);
|
||||
|
||||
await settings.remove(settings.connected, "fresh.example");
|
||||
await settings.remove(settings.connected, FRESH_ORIGIN);
|
||||
|
||||
expect(await siteAccounts(bg)).toEqual({ result: [] });
|
||||
expect(sentToTabs).toEqual([
|
||||
@@ -2321,20 +2364,45 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// The same hostname can hold both kinds of connection: one origin allowed
|
||||
// without Remember, then another, on a different port, allowed with it.
|
||||
// One origin can hold both kinds of connection under two addresses:
|
||||
// remembered for one, allowed without Remember for the other.
|
||||
test("removing a remembered site also ends its connection made without Remember", async () => {
|
||||
const bg = loadBackground({ actionPopup: true });
|
||||
const stored = bg.storage.read("autistmask");
|
||||
stored.wallets[0].addresses.push({
|
||||
address: other.address,
|
||||
balance: "0",
|
||||
tokenBalances: [],
|
||||
});
|
||||
bg.storage.write("autistmask", stored);
|
||||
await connect(bg, FRESH_ORIGIN, true);
|
||||
bg.setActiveAddress(other.address);
|
||||
const pending = bg.requestSite(FRESH_ORIGIN);
|
||||
await settle();
|
||||
bg.connectApproval(pending.id()).decide(true, false);
|
||||
await settle();
|
||||
expect(pending.result()).toEqual({ result: [other.address] });
|
||||
const settings = await openSettings(bg);
|
||||
|
||||
await settings.remove(settings.allowed, FRESH_ORIGIN);
|
||||
|
||||
expect(await siteAccounts(bg, FRESH_ORIGIN)).toEqual({ result: [] });
|
||||
});
|
||||
|
||||
test("removing a remembered site leaves the same host on another port connected", async () => {
|
||||
const bg = loadBackground({ actionPopup: true });
|
||||
await connect(bg, FRESH_ORIGIN, false);
|
||||
await connect(bg, FRESH_OTHER_PORT, true);
|
||||
const settings = await openSettings(bg);
|
||||
|
||||
await settings.remove(settings.allowed, "fresh.example");
|
||||
await settings.remove(settings.allowed, FRESH_OTHER_PORT);
|
||||
|
||||
expect(await siteAccounts(bg, FRESH_OTHER_PORT)).toEqual({
|
||||
result: [],
|
||||
});
|
||||
expect(await siteAccounts(bg, FRESH_ORIGIN)).toEqual({ result: [] });
|
||||
expect(await siteAccounts(bg, FRESH_ORIGIN)).toEqual({
|
||||
result: [signer.address],
|
||||
});
|
||||
});
|
||||
|
||||
test("a page can neither remove a site nor list the connected ones", async () => {
|
||||
@@ -2343,7 +2411,7 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
const page = { url: FRESH_ORIGIN + "/index.html" };
|
||||
|
||||
const remove = bg.send(
|
||||
{ type: "AUTISTMASK_REMOVE_SITE", hostname: "fresh.example" },
|
||||
{ type: "AUTISTMASK_REMOVE_SITE", origin: FRESH_ORIGIN },
|
||||
page,
|
||||
);
|
||||
const list = bg.send({ type: "AUTISTMASK_GET_CONNECTED_SITES" }, page);
|
||||
|
||||
@@ -33,7 +33,6 @@ const signer = new Wallet(SIGNER_KEY);
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const CONNECTED_HOSTNAME = "dapp.example";
|
||||
const EXT_URL = "chrome-extension://autistmask/";
|
||||
|
||||
const MAINNET = networkById("mainnet");
|
||||
@@ -81,7 +80,7 @@ function storedProfile(networkId) {
|
||||
networkId,
|
||||
rpcUrl: net.defaultRpcUrl,
|
||||
blockscoutUrl: net.defaultBlockscoutUrl,
|
||||
allowedSites: { [signer.address]: [CONNECTED_HOSTNAME] },
|
||||
allowedSites: { [signer.address]: [CONNECTED_ORIGIN] },
|
||||
deniedSites: {},
|
||||
trackedTokens: [],
|
||||
lastBalanceRefresh: 0,
|
||||
|
||||
@@ -19,7 +19,6 @@ const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
// The site the persisted state has connected, and one it has never heard of.
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const CONNECTED_HOSTNAME = "dapp.example";
|
||||
const STRANGER_ORIGIN = "https://stranger.example";
|
||||
|
||||
const MAINNET = networkById("mainnet");
|
||||
@@ -86,7 +85,7 @@ function loadBackground() {
|
||||
tokenHolderCache: {},
|
||||
fraudContracts: [],
|
||||
activeAddress: ADDRESS,
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_HOSTNAME] },
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||
deniedSites: {},
|
||||
};
|
||||
const storage = makeStorageStub({ autistmask: persisted });
|
||||
|
||||
@@ -17,7 +17,6 @@ const { networkById } = require("../src/shared/networks");
|
||||
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const CONNECTED_HOSTNAME = "dapp.example";
|
||||
const UNKNOWN_ORIGIN = "https://stranger.example";
|
||||
|
||||
const MAINNET = networkById("mainnet");
|
||||
@@ -41,7 +40,7 @@ function storedProfile(networkId) {
|
||||
networkId,
|
||||
rpcUrl: networkById(networkId).defaultRpcUrl,
|
||||
blockscoutUrl: networkById(networkId).defaultBlockscoutUrl,
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_HOSTNAME] },
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||
deniedSites: {},
|
||||
trackedTokens: [],
|
||||
};
|
||||
|
||||
@@ -21,7 +21,6 @@ const { makeStorageStub } = require("./support/storageStub");
|
||||
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const CONNECTED_HOSTNAME = "dapp.example";
|
||||
|
||||
const MAINNET = networkById("mainnet");
|
||||
const SEPOLIA = networkById("sepolia");
|
||||
@@ -50,7 +49,7 @@ function storedProfile(networkId) {
|
||||
networkId,
|
||||
rpcUrl: CUSTOM_RPC,
|
||||
blockscoutUrl: CUSTOM_BLOCKSCOUT,
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_HOSTNAME] },
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||
deniedSites: {},
|
||||
trackedTokens: [{ address: TOKEN, symbol: "DAI", decimals: 18 }],
|
||||
theme: "dark",
|
||||
@@ -168,7 +167,7 @@ describe("a chain switch on a worker that never loaded state", () => {
|
||||
expect(after.wallets).toEqual(walletFixture());
|
||||
expect(after.hasWallet).toBe(true);
|
||||
expect(after.activeAddress).toBe(ADDRESS);
|
||||
expect(after.allowedSites).toEqual({ [ADDRESS]: [CONNECTED_HOSTNAME] });
|
||||
expect(after.allowedSites).toEqual({ [ADDRESS]: [CONNECTED_ORIGIN] });
|
||||
expect(after.trackedTokens).toEqual([
|
||||
{ address: TOKEN, symbol: "DAI", decimals: 18 },
|
||||
]);
|
||||
|
||||
@@ -29,7 +29,6 @@ const signer = new Wallet(SIGNER_KEY);
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const CONNECTED_HOSTNAME = "dapp.example";
|
||||
const EXT_URL = "chrome-extension://autistmask/";
|
||||
|
||||
const SEPOLIA = networkById("sepolia");
|
||||
@@ -67,7 +66,7 @@ function storedProfile(networkId) {
|
||||
networkId,
|
||||
rpcUrl: net.defaultRpcUrl,
|
||||
blockscoutUrl: net.defaultBlockscoutUrl,
|
||||
allowedSites: { [signer.address]: [CONNECTED_HOSTNAME] },
|
||||
allowedSites: { [signer.address]: [CONNECTED_ORIGIN] },
|
||||
deniedSites: {},
|
||||
trackedTokens: [],
|
||||
};
|
||||
|
||||
@@ -150,7 +150,7 @@ async function openTxApproval(to, data) {
|
||||
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||
reply({
|
||||
type: "tx",
|
||||
hostname: "dapp.example",
|
||||
origin: "https://dapp.example",
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: FROM,
|
||||
approvedTx: {
|
||||
|
||||
@@ -140,8 +140,14 @@ function load() {
|
||||
state.selectedWallet = 0;
|
||||
state.selectedAddress = 0;
|
||||
state.activeAddress = A0;
|
||||
state.allowedSites = { [A0]: ["a.example"], [B0]: ["b.example"] };
|
||||
state.deniedSites = { [B0]: ["c.example"], [C0]: ["d.example"] };
|
||||
state.allowedSites = {
|
||||
[A0]: ["https://a.example"],
|
||||
[B0]: ["https://b.example"],
|
||||
};
|
||||
state.deniedSites = {
|
||||
[B0]: ["https://c.example"],
|
||||
[C0]: ["https://d.example"],
|
||||
};
|
||||
state.viewStack = ["main", "settings"];
|
||||
state.currentView = "settings";
|
||||
|
||||
@@ -388,8 +394,8 @@ describe("deleting without the password", () => {
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
const saved = (await storage.get("autistmask")).autistmask;
|
||||
expect(saved.allowedSites).toEqual({ [A0]: ["a.example"] });
|
||||
expect(saved.deniedSites).toEqual({ [C0]: ["d.example"] });
|
||||
expect(saved.allowedSites).toEqual({ [A0]: ["https://a.example"] });
|
||||
expect(saved.deniedSites).toEqual({ [C0]: ["https://d.example"] });
|
||||
});
|
||||
|
||||
// The route shares finishDelete() with the password route, so the
|
||||
@@ -437,7 +443,7 @@ describe("deleting without the password", () => {
|
||||
test("deleting the last wallet lands on Welcome with nothing left", async () => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets = [wallet("Wallet 1", "secret-one", [A0])];
|
||||
state.allowedSites = { [A0]: ["a.example"] };
|
||||
state.allowedSites = { [A0]: ["https://a.example"] };
|
||||
state.deniedSites = {};
|
||||
|
||||
await openLostPassword(deleteWallet, 0);
|
||||
|
||||
@@ -438,11 +438,10 @@ step(
|
||||
await d.switchToWindow(popup);
|
||||
await d.waitVisible("#view-approve-site");
|
||||
|
||||
const hostname = await d.text("#approve-hostname");
|
||||
const origin = await d.text("#approve-origin");
|
||||
assert(
|
||||
hostname === "127.0.0.1",
|
||||
"the site prompt names the wrong origin: " +
|
||||
JSON.stringify(hostname),
|
||||
origin === env.server.origin,
|
||||
"the site prompt names the wrong origin: " + JSON.stringify(origin),
|
||||
);
|
||||
const shown = await d.text("#approve-address");
|
||||
assert(
|
||||
@@ -494,16 +493,16 @@ step(
|
||||
|
||||
const screen = await d.execute(
|
||||
`return {
|
||||
hostname: document.getElementById("approve-sign-hostname").textContent,
|
||||
origin: document.getElementById("approve-sign-origin").textContent,
|
||||
type: document.getElementById("approve-sign-type").textContent,
|
||||
message: document.getElementById("approve-sign-message").textContent,
|
||||
from: document.getElementById("approve-sign-from").textContent,
|
||||
};`,
|
||||
);
|
||||
assert(
|
||||
screen.hostname === "127.0.0.1",
|
||||
screen.origin === env.server.origin,
|
||||
"the sign prompt names the wrong origin: " +
|
||||
JSON.stringify(screen.hostname),
|
||||
JSON.stringify(screen.origin),
|
||||
);
|
||||
assert(
|
||||
screen.type === "Personal message",
|
||||
@@ -571,7 +570,7 @@ step(
|
||||
|
||||
const screen = await d.execute(
|
||||
`return {
|
||||
hostname: document.getElementById("approve-tx-hostname").textContent,
|
||||
origin: document.getElementById("approve-tx-origin").textContent,
|
||||
from: document.getElementById("approve-tx-from").textContent,
|
||||
to: document.getElementById("approve-tx-to").textContent,
|
||||
value: document.getElementById("approve-tx-value").textContent,
|
||||
@@ -582,9 +581,9 @@ step(
|
||||
};`,
|
||||
);
|
||||
assert(
|
||||
screen.hostname === "127.0.0.1",
|
||||
screen.origin === env.server.origin,
|
||||
"the transaction prompt names the wrong origin: " +
|
||||
JSON.stringify(screen.hostname),
|
||||
JSON.stringify(screen.origin),
|
||||
);
|
||||
assert(
|
||||
screen.from.toLowerCase().includes(env.address.toLowerCase()),
|
||||
|
||||
+91
-19
@@ -35,6 +35,7 @@ const {
|
||||
const {
|
||||
DAPP_ORIGIN,
|
||||
DAPP_URL,
|
||||
PHISHING_DAPP_ORIGIN,
|
||||
PHISHING_DAPP_URL,
|
||||
FEE_ESTIMATE_WEI,
|
||||
FEE_RESERVE_WEI,
|
||||
@@ -1449,6 +1450,81 @@ test("an over-long flash message keeps to one line (#252)", async (env) => {
|
||||
}
|
||||
});
|
||||
|
||||
// --------------------------------------- password error containers (#297)
|
||||
|
||||
// Every screen that asks for a password reserves room for one line of error.
|
||||
// The two on the dApp approval screens also have a border and padding, which
|
||||
// that reserved height has to cover too.
|
||||
const PASSWORD_ERROR_CONTAINERS = [
|
||||
"approve-tx-error",
|
||||
"approve-sign-error",
|
||||
"export-privkey-flash",
|
||||
"show-phrase-flash",
|
||||
"delete-wallet-flash",
|
||||
"confirm-tx-password-error",
|
||||
];
|
||||
|
||||
// Shows only the screen holding the container, then measures the container
|
||||
// and the element below it empty and again filled the way showError() in
|
||||
// src/popup/views/helpers.js fills it. Runs in the page.
|
||||
function measurePasswordError(id) {
|
||||
const container = document.getElementById(id);
|
||||
const screen = container.closest(".view");
|
||||
for (const view of document.querySelectorAll(".view")) {
|
||||
view.classList.toggle("hidden", view !== screen);
|
||||
}
|
||||
const below = container.nextElementSibling;
|
||||
const measure = () => ({
|
||||
height: container.getBoundingClientRect().height,
|
||||
belowTop: below.getBoundingClientRect().top + window.scrollY,
|
||||
belowHeight: below.getBoundingClientRect().height,
|
||||
});
|
||||
const empty = measure();
|
||||
container.textContent = "Please enter your password.";
|
||||
container.style.visibility = "visible";
|
||||
const filled = measure();
|
||||
container.textContent = "";
|
||||
container.style.visibility = "hidden";
|
||||
return { empty, filled };
|
||||
}
|
||||
|
||||
test("a password error moves nothing on any screen (#297)", async (env) => {
|
||||
const page = await openPopup(env.ctx, env.popupUrl);
|
||||
try {
|
||||
await page.setViewportSize(POPUP_VIEWPORT);
|
||||
for (const id of PASSWORD_ERROR_CONTAINERS) {
|
||||
const { empty, filled } = await page.evaluate(
|
||||
measurePasswordError,
|
||||
id,
|
||||
);
|
||||
assert(
|
||||
empty.belowHeight > 0,
|
||||
"nothing is shown below #" + id + ", so nothing was measured",
|
||||
);
|
||||
assert(
|
||||
filled.height === empty.height,
|
||||
"#" +
|
||||
id +
|
||||
" is " +
|
||||
empty.height +
|
||||
"px empty and " +
|
||||
filled.height +
|
||||
"px with an error",
|
||||
);
|
||||
assert(
|
||||
filled.belowTop === empty.belowTop,
|
||||
"the element below #" +
|
||||
id +
|
||||
" moved " +
|
||||
(filled.belowTop - empty.belowTop) +
|
||||
"px when the error appeared",
|
||||
);
|
||||
}
|
||||
} finally {
|
||||
await page.close();
|
||||
}
|
||||
});
|
||||
|
||||
// --------------------------------------------- confirmation screen (#238)
|
||||
//
|
||||
// The screen that decides what gets signed. The arithmetic underneath it
|
||||
@@ -2396,8 +2472,6 @@ test("a token whose symbol() returns markup renders as text (#307)", async (env)
|
||||
// dApp, with real funds, against a real network. The RPC is stubbed
|
||||
// throughout. That pass stays on the human list before 1.0.0.
|
||||
|
||||
const DAPP_HOSTNAME = new URL(DAPP_URL).hostname;
|
||||
|
||||
// The personal_sign payload. Sent as hex, which is what dApps send and what
|
||||
// the popup requires — it calls getBytes() on the message — and displayed on
|
||||
// the approval screen as the decoded text, which is what the user is agreeing
|
||||
@@ -2941,11 +3015,10 @@ test("eth_requestAccounts rejected at the prompt returns a rejection (#183)", as
|
||||
try {
|
||||
await visible(popup, "#view-approve-site");
|
||||
|
||||
const hostname = await popup.locator("#approve-hostname").innerText();
|
||||
const origin = await popup.locator("#approve-origin").innerText();
|
||||
assert(
|
||||
hostname === DAPP_HOSTNAME,
|
||||
"the site prompt names the wrong origin: " +
|
||||
JSON.stringify(hostname),
|
||||
origin === DAPP_ORIGIN,
|
||||
"the site prompt names the wrong origin: " + JSON.stringify(origin),
|
||||
);
|
||||
|
||||
// The control for the phishing test below: this origin is not on the
|
||||
@@ -3026,7 +3099,6 @@ test("a connect request from a blocklisted site is flagged (#219)", async (env)
|
||||
// check and the real approval screen. Nothing about the list is stubbed —
|
||||
// there is nothing left to stub, since the extension no longer fetches it.
|
||||
const phishingDapp = await openDapp(env.ctx, PHISHING_DAPP_URL);
|
||||
const hostname = new URL(PHISHING_DAPP_URL).hostname;
|
||||
try {
|
||||
await reserveApprovalTab(env);
|
||||
await startRequest(
|
||||
@@ -3039,15 +3111,15 @@ test("a connect request from a blocklisted site is flagged (#219)", async (env)
|
||||
try {
|
||||
await visible(popup, "#view-approve-site");
|
||||
|
||||
const shown = await popup.locator("#approve-hostname").innerText();
|
||||
const shown = await popup.locator("#approve-origin").innerText();
|
||||
assert(
|
||||
shown === hostname,
|
||||
shown === PHISHING_DAPP_ORIGIN,
|
||||
"the site prompt names the wrong origin: " +
|
||||
JSON.stringify(shown),
|
||||
);
|
||||
|
||||
await visible(popup, "#approve-site-phishing-warning");
|
||||
console.log("# phishing warning shown for " + hostname);
|
||||
console.log("# phishing warning shown for " + PHISHING_DAPP_ORIGIN);
|
||||
|
||||
// Not remembered: a remembered decision for this origin would
|
||||
// outlive the test.
|
||||
@@ -3077,15 +3149,15 @@ test("personal_sign signs, and the signature recovers to the address (#183)", as
|
||||
const boundary = await watchApprovalBoundary(popup, env);
|
||||
|
||||
const screen = await popup.evaluate(() => ({
|
||||
hostname: document.getElementById("approve-sign-hostname").textContent,
|
||||
origin: document.getElementById("approve-sign-origin").textContent,
|
||||
type: document.getElementById("approve-sign-type").textContent,
|
||||
message: document.getElementById("approve-sign-message").textContent,
|
||||
from: document.getElementById("approve-sign-from").textContent,
|
||||
}));
|
||||
assert(
|
||||
screen.hostname === DAPP_HOSTNAME,
|
||||
screen.origin === DAPP_ORIGIN,
|
||||
"the sign prompt names the wrong origin: " +
|
||||
JSON.stringify(screen.hostname),
|
||||
JSON.stringify(screen.origin),
|
||||
);
|
||||
assert(
|
||||
screen.type === "Personal message",
|
||||
@@ -3170,15 +3242,15 @@ test("eth_signTypedData_v4 signs, and the signature recovers (#183)", async (env
|
||||
const boundary = await watchApprovalBoundary(popup, env);
|
||||
|
||||
const screen = await popup.evaluate(() => ({
|
||||
hostname: document.getElementById("approve-sign-hostname").textContent,
|
||||
origin: document.getElementById("approve-sign-origin").textContent,
|
||||
type: document.getElementById("approve-sign-type").textContent,
|
||||
message: document.getElementById("approve-sign-message").innerText,
|
||||
from: document.getElementById("approve-sign-from").textContent,
|
||||
}));
|
||||
assert(
|
||||
screen.hostname === DAPP_HOSTNAME,
|
||||
screen.origin === DAPP_ORIGIN,
|
||||
"the typed data prompt names the wrong origin: " +
|
||||
JSON.stringify(screen.hostname),
|
||||
JSON.stringify(screen.origin),
|
||||
);
|
||||
assert(
|
||||
screen.type === "Typed data (EIP-712)",
|
||||
@@ -3276,7 +3348,7 @@ test("eth_sendTransaction signs the approved transaction and broadcasts it (#183
|
||||
const boundary = await watchApprovalBoundary(popup, env);
|
||||
|
||||
const screen = await popup.evaluate(() => ({
|
||||
hostname: document.getElementById("approve-tx-hostname").textContent,
|
||||
origin: document.getElementById("approve-tx-origin").textContent,
|
||||
from: document.getElementById("approve-tx-from").textContent,
|
||||
to: document.getElementById("approve-tx-to").textContent,
|
||||
value: document.getElementById("approve-tx-value").textContent,
|
||||
@@ -3286,9 +3358,9 @@ test("eth_sendTransaction signs the approved transaction and broadcasts it (#183
|
||||
.classList.contains("hidden"),
|
||||
}));
|
||||
assert(
|
||||
screen.hostname === DAPP_HOSTNAME,
|
||||
screen.origin === DAPP_ORIGIN,
|
||||
"the transaction prompt names the wrong origin: " +
|
||||
JSON.stringify(screen.hostname),
|
||||
JSON.stringify(screen.origin),
|
||||
);
|
||||
assert(
|
||||
screen.from.toLowerCase().includes(env.expectedAddress.toLowerCase()),
|
||||
|
||||
@@ -59,24 +59,32 @@ describe("the floor under allowedSites and deniedSites", () => {
|
||||
}
|
||||
});
|
||||
|
||||
test(`an ${field} entry whose value is not a hostname list is dropped`, () => {
|
||||
for (const bad of ["dapp.example", 42, null, { a: 1 }, true]) {
|
||||
test(`an ${field} entry whose value is not an origin list is dropped`, () => {
|
||||
for (const bad of [
|
||||
"https://dapp.example",
|
||||
42,
|
||||
null,
|
||||
{ a: 1 },
|
||||
true,
|
||||
]) {
|
||||
expect(
|
||||
normalizePersisted({ [field]: { [ADDRESS]: bad } })[field],
|
||||
).toEqual({});
|
||||
}
|
||||
});
|
||||
|
||||
test(`a hostname that is not text is dropped from an ${field} entry`, () => {
|
||||
test(`an origin that is not text is dropped from an ${field} entry`, () => {
|
||||
expect(
|
||||
normalizePersisted({
|
||||
[field]: { [ADDRESS]: [42, null, "dapp.example", {}] },
|
||||
[field]: {
|
||||
[ADDRESS]: [42, null, "https://dapp.example", {}],
|
||||
},
|
||||
})[field],
|
||||
).toEqual({ [ADDRESS]: ["dapp.example"] });
|
||||
).toEqual({ [ADDRESS]: ["https://dapp.example"] });
|
||||
});
|
||||
|
||||
test(`a real ${field} map survives, copied not shared`, () => {
|
||||
const saved = { [field]: { [ADDRESS]: ["dapp.example"] } };
|
||||
const saved = { [field]: { [ADDRESS]: ["https://dapp.example"] } };
|
||||
|
||||
const out = normalizePersisted(saved);
|
||||
|
||||
@@ -87,10 +95,13 @@ describe("the floor under allowedSites and deniedSites", () => {
|
||||
|
||||
test(`a good ${field} entry beside a malformed one survives`, () => {
|
||||
const out = normalizePersisted({
|
||||
[field]: { [ADDRESS]: ["dapp.example"], [TOKEN_ADDRESS]: 42 },
|
||||
[field]: {
|
||||
[ADDRESS]: ["https://dapp.example"],
|
||||
[TOKEN_ADDRESS]: 42,
|
||||
},
|
||||
});
|
||||
|
||||
expect(out[field]).toEqual({ [ADDRESS]: ["dapp.example"] });
|
||||
expect(out[field]).toEqual({ [ADDRESS]: ["https://dapp.example"] });
|
||||
});
|
||||
|
||||
test(`a stored own "__proto__" key in ${field} is dropped`, () => {
|
||||
@@ -100,7 +111,7 @@ describe("the floor under allowedSites and deniedSites", () => {
|
||||
// saveState()'s merge hands to the prototype setter on the next
|
||||
// write.
|
||||
const saved = JSON.parse(
|
||||
'{"' + field + '":{"__proto__":["evil.invalid"]}}',
|
||||
'{"' + field + '":{"__proto__":["https://evil.invalid"]}}',
|
||||
);
|
||||
|
||||
const out = normalizePersisted(saved);
|
||||
@@ -197,7 +208,7 @@ describe("a malformed allowedSites entry", () => {
|
||||
const MALFORMED = [
|
||||
{ name: "a string", value: "notalist" },
|
||||
{ name: "a number", value: 42 },
|
||||
{ name: "a record", value: { hostnames: ["dapp.example"] } },
|
||||
{ name: "a record", value: { origins: ["https://dapp.example"] } },
|
||||
];
|
||||
|
||||
for (const { name, value } of MALFORMED) {
|
||||
@@ -231,7 +242,7 @@ describe("a malformed allowedSites entry", () => {
|
||||
const env = await bootPopup(
|
||||
unversionedValidProfile({
|
||||
allowedSites: {
|
||||
[ADDRESS]: ["dapp.example"],
|
||||
[ADDRESS]: ["https://dapp.example"],
|
||||
[TOKEN_ADDRESS]: "notalist",
|
||||
},
|
||||
}),
|
||||
@@ -239,7 +250,7 @@ describe("a malformed allowedSites entry", () => {
|
||||
|
||||
expect(env.pageErrors).toEqual([]);
|
||||
expect(env.storage.read("autistmask").allowedSites).toEqual({
|
||||
[ADDRESS]: ["dapp.example"],
|
||||
[ADDRESS]: ["https://dapp.example"],
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
@@ -165,7 +165,7 @@ const CONTRACT = [
|
||||
[ADDRESS],
|
||||
{ [ADDRESS]: 42 },
|
||||
{ [ADDRESS]: [42, null, {}] },
|
||||
JSON.parse('{"__proto__":["evil.invalid"]}'),
|
||||
JSON.parse('{"__proto__":["https://evil.invalid"]}'),
|
||||
],
|
||||
holds: siteMapHolds,
|
||||
},
|
||||
@@ -177,7 +177,7 @@ const CONTRACT = [
|
||||
[ADDRESS],
|
||||
{ [ADDRESS]: 42 },
|
||||
{ [ADDRESS]: [42, null, {}] },
|
||||
JSON.parse('{"__proto__":["evil.invalid"]}'),
|
||||
JSON.parse('{"__proto__":["https://evil.invalid"]}'),
|
||||
],
|
||||
holds: siteMapHolds,
|
||||
},
|
||||
|
||||
@@ -0,0 +1,162 @@
|
||||
// The signature prompt shows a personal message as the bytes that are signed
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/403): the raw data in hex, the
|
||||
// text it decodes to with control, zero-width and bidirectional characters
|
||||
// marked rather than obeyed, and a message that is not hex as plain text that
|
||||
// cannot be signed.
|
||||
//
|
||||
// Driven against a minimal DOM stub in the shape
|
||||
// tests/approvalOrigin.test.js uses.
|
||||
|
||||
globalThis.chrome = {
|
||||
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||
};
|
||||
|
||||
const { hexlify, toUtf8Bytes } = require("ethers");
|
||||
const { state } = require("../src/shared/state");
|
||||
const approval = require("../src/popup/views/approval");
|
||||
|
||||
const FROM = "0x0000000000000000000000000000000000000a11";
|
||||
|
||||
// Built from their code points so that this file holds none of them.
|
||||
const RIGHT_TO_LEFT_OVERRIDE = String.fromCodePoint(0x202e);
|
||||
const POP_DIRECTIONAL_FORMATTING = String.fromCodePoint(0x202c);
|
||||
const ZERO_WIDTH_SPACE = String.fromCodePoint(0x200b);
|
||||
|
||||
function makeElement(id) {
|
||||
const classes = new Set();
|
||||
return {
|
||||
id,
|
||||
textContent: "",
|
||||
value: "",
|
||||
innerHTML: "",
|
||||
disabled: false,
|
||||
style: {},
|
||||
dataset: {},
|
||||
classList: {
|
||||
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||
contains: (n) => classes.has(n),
|
||||
toggle: (n, force) => {
|
||||
const on = force === undefined ? !classes.has(n) : force;
|
||||
if (on) classes.add(n);
|
||||
else classes.delete(n);
|
||||
return on;
|
||||
},
|
||||
},
|
||||
addEventListener: () => {},
|
||||
querySelectorAll: () => [],
|
||||
appendChild: () => {},
|
||||
};
|
||||
}
|
||||
|
||||
function makeDocument() {
|
||||
const els = new Map();
|
||||
return {
|
||||
getElementById(id) {
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement(id));
|
||||
return els.get(id);
|
||||
},
|
||||
createElement: () => makeElement("created"),
|
||||
body: { prepend: () => {} },
|
||||
};
|
||||
}
|
||||
|
||||
function node(id) {
|
||||
return globalThis.document.getElementById(id);
|
||||
}
|
||||
|
||||
// Open the signature prompt for a personal_sign of `message`, the way the
|
||||
// popup does: it asks the background for the approval and show() draws it.
|
||||
async function openPersonalSign(message) {
|
||||
globalThis.document = makeDocument();
|
||||
globalThis.window = { location: { search: "" } };
|
||||
globalThis.chrome.runtime = {
|
||||
connect: () => ({ postMessage: () => {} }),
|
||||
sendMessage: (msg, reply) => {
|
||||
if (!reply) return;
|
||||
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||
reply({
|
||||
type: "sign",
|
||||
origin: "https://dapp.example",
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: FROM,
|
||||
signParams: { method: "personal_sign", message, from: FROM },
|
||||
});
|
||||
},
|
||||
};
|
||||
approval.init({});
|
||||
await approval.show(1);
|
||||
}
|
||||
|
||||
// The message box's markup as the text a reader sees: tags dropped.
|
||||
function shownMessage() {
|
||||
return node("approve-sign-message").innerHTML.replace(/<[^>]*>/g, "");
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
state.wallets = [];
|
||||
state.activeAddress = FROM;
|
||||
state.viewData = {};
|
||||
state.viewStack = [];
|
||||
state.currentView = null;
|
||||
});
|
||||
|
||||
test("a right-to-left override is marked, so the text reads in byte order", async () => {
|
||||
// Obeyed, the override shows "0001" as "1000".
|
||||
const text =
|
||||
"Pay " +
|
||||
RIGHT_TO_LEFT_OVERRIDE +
|
||||
"0001" +
|
||||
POP_DIRECTIONAL_FORMATTING +
|
||||
" ETH";
|
||||
await openPersonalSign(hexlify(toUtf8Bytes(text)));
|
||||
const html = node("approve-sign-message").innerHTML;
|
||||
expect(html).not.toContain(RIGHT_TO_LEFT_OVERRIDE);
|
||||
expect(html).not.toContain(POP_DIRECTIONAL_FORMATTING);
|
||||
expect(shownMessage()).toBe("Pay U+202E0001U+202C ETH");
|
||||
});
|
||||
|
||||
test("a zero-width character is marked", async () => {
|
||||
await openPersonalSign(
|
||||
hexlify(toUtf8Bytes("pay" + ZERO_WIDTH_SPACE + "pal.com")),
|
||||
);
|
||||
expect(node("approve-sign-message").innerHTML).not.toContain(
|
||||
ZERO_WIDTH_SPACE,
|
||||
);
|
||||
expect(shownMessage()).toBe("payU+200Bpal.com");
|
||||
});
|
||||
|
||||
test("a line feed is shown as a line break", async () => {
|
||||
await openPersonalSign(hexlify(toUtf8Bytes("Sign in\nNonce: 7")));
|
||||
expect(node("approve-sign-message").innerHTML).toBe("Sign in<br>Nonce: 7");
|
||||
});
|
||||
|
||||
test("the raw hex is shown alongside the text", async () => {
|
||||
await openPersonalSign("0x48656c6c6f");
|
||||
expect(shownMessage()).toBe("Hello");
|
||||
expect(node("approve-sign-hex").textContent).toBe("0x48656c6c6f");
|
||||
expect(node("approve-sign-hex-section").classList.contains("hidden")).toBe(
|
||||
false,
|
||||
);
|
||||
});
|
||||
|
||||
test("bytes that are not text are shown only as hex", async () => {
|
||||
await openPersonalSign("0xff00");
|
||||
expect(node("approve-sign-message").textContent).toBe(
|
||||
"This message is not text.",
|
||||
);
|
||||
expect(node("approve-sign-hex").textContent).toBe("0xff00");
|
||||
});
|
||||
|
||||
test("a message that is not hex is shown as text and cannot be signed", async () => {
|
||||
await openPersonalSign("Hello world");
|
||||
expect(shownMessage()).toBe("Hello world");
|
||||
expect(node("approve-sign-error").textContent).toBe(
|
||||
"This message is plain text, not hex, so it cannot be signed.",
|
||||
);
|
||||
expect(node("btn-approve-sign").disabled).toBe(true);
|
||||
expect(node("approve-sign-hex-section").classList.contains("hidden")).toBe(
|
||||
true,
|
||||
);
|
||||
});
|
||||
@@ -0,0 +1,146 @@
|
||||
// Which site a page's request is attributed to.
|
||||
//
|
||||
// The background takes a request's origin from what the browser says sent the
|
||||
// message: sender.origin, or on Firefox before 126, which has no
|
||||
// sender.origin, the origin of sender.url — the frame that sent it. It used to
|
||||
// fall back to the tab's page and then to an origin the message itself
|
||||
// carried, so a request from a frame was credited to the site embedding it,
|
||||
// and a request the browser said nothing about was credited to whatever the
|
||||
// page wrote (https://git.eeqj.de/sneak/AutistMask/issues/407).
|
||||
//
|
||||
// Every sender here lacks sender.origin, as on old Firefox. The connection
|
||||
// check on eth_accounts is what shows which site a request was credited to.
|
||||
|
||||
const { makeStorageStub } = require("./support/storageStub");
|
||||
|
||||
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
// The site the persisted state has connected, and one it has never heard of.
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const STRANGER_ORIGIN = "https://stranger.example";
|
||||
|
||||
async function settle() {
|
||||
for (let i = 0; i < 50; i++) await Promise.resolve();
|
||||
}
|
||||
|
||||
afterEach(() => {
|
||||
delete global.chrome;
|
||||
});
|
||||
|
||||
function loadBackground() {
|
||||
jest.resetModules();
|
||||
|
||||
jest.doMock("../src/shared/balances", () => ({
|
||||
getProvider: () => ({}),
|
||||
refreshBalances: jest.fn(async () => {}),
|
||||
}));
|
||||
jest.doMock("../src/shared/phishingDomains", () => ({
|
||||
isPhishingDomain: () => false,
|
||||
}));
|
||||
jest.doMock("../src/shared/alarms", () => ({
|
||||
BALANCE_REFRESH_ALARM: "balance",
|
||||
BALANCE_REFRESH_PERIOD_MINUTES: 1,
|
||||
ensureRecurringAlarms: jest.fn(async () => {}),
|
||||
registerAlarmHandlers: jest.fn(),
|
||||
}));
|
||||
|
||||
const storage = makeStorageStub({
|
||||
autistmask: {
|
||||
networkId: "mainnet",
|
||||
wallets: [
|
||||
{
|
||||
name: "Wallet 1",
|
||||
type: "hd",
|
||||
addresses: [
|
||||
{ address: ADDRESS, balance: "0", tokenBalances: [] },
|
||||
],
|
||||
},
|
||||
],
|
||||
activeAddress: ADDRESS,
|
||||
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||
deniedSites: {},
|
||||
},
|
||||
});
|
||||
|
||||
let messageListener = null;
|
||||
global.chrome = {
|
||||
storage,
|
||||
runtime: {
|
||||
getURL: (path) => "chrome-extension://autistmask/" + path,
|
||||
onMessage: {
|
||||
addListener: (fn) => {
|
||||
messageListener = fn;
|
||||
},
|
||||
},
|
||||
onConnect: { addListener: () => {} },
|
||||
lastError: null,
|
||||
},
|
||||
windows: { onRemoved: { addListener: () => {} } },
|
||||
action: { setPopup: () => {} },
|
||||
};
|
||||
|
||||
require("../src/background/index");
|
||||
|
||||
// Ask for eth_accounts. `claimedOrigin` is an origin written into the
|
||||
// message, as the content script used to send.
|
||||
return async function accounts(sender, claimedOrigin) {
|
||||
let result = null;
|
||||
messageListener(
|
||||
{
|
||||
type: "AUTISTMASK_RPC",
|
||||
method: "eth_accounts",
|
||||
params: [],
|
||||
origin: claimedOrigin,
|
||||
},
|
||||
sender,
|
||||
(r) => {
|
||||
result = r;
|
||||
},
|
||||
);
|
||||
await settle();
|
||||
return result;
|
||||
};
|
||||
}
|
||||
|
||||
describe("a request is attributed to the frame that sent it", () => {
|
||||
test("a stranger's frame on a connected site gets no address", async () => {
|
||||
const accounts = loadBackground();
|
||||
|
||||
const result = await accounts({
|
||||
url: STRANGER_ORIGIN + "/frame.html",
|
||||
tab: { url: CONNECTED_ORIGIN + "/" },
|
||||
});
|
||||
|
||||
expect(result).toEqual({ result: [] });
|
||||
});
|
||||
|
||||
test("a connected site's frame on a stranger's page gets the address", async () => {
|
||||
const accounts = loadBackground();
|
||||
|
||||
const result = await accounts({
|
||||
url: CONNECTED_ORIGIN + "/frame.html",
|
||||
tab: { url: STRANGER_ORIGIN + "/" },
|
||||
});
|
||||
|
||||
expect(result).toEqual({ result: [ADDRESS] });
|
||||
});
|
||||
});
|
||||
|
||||
describe("a request the browser does not say the sender of", () => {
|
||||
test("is refused, whatever the tab or the message says", async () => {
|
||||
const accounts = loadBackground();
|
||||
|
||||
const result = await accounts(
|
||||
{ tab: { url: CONNECTED_ORIGIN + "/" } },
|
||||
CONNECTED_ORIGIN,
|
||||
);
|
||||
|
||||
expect(result).toEqual({
|
||||
error: {
|
||||
code: 4100,
|
||||
message:
|
||||
"The wallet could not tell which site sent this request.",
|
||||
},
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -232,7 +232,7 @@ async function confirmSend(amount, token = "ETH") {
|
||||
async function approveTxWithFeePerGas(maxFeePerGas) {
|
||||
approvalDetails = {
|
||||
type: "tx",
|
||||
hostname: "dapp.example",
|
||||
origin: "https://dapp.example",
|
||||
approvedFrom: HOLDER,
|
||||
approvedTx: {
|
||||
to: RECIPIENT,
|
||||
|
||||
+33
-31
@@ -270,31 +270,32 @@ describe("background refresh racing a wallet deleted on another page", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// allowedSites/deniedSites: { [address]: [hostname, ...] }. Mutated in place
|
||||
// from two different contexts — src/background/index.js:592-599 pushes a
|
||||
// newly approved hostname onto state.allowedSites[activeAddress], and the
|
||||
// Settings "revoke" button (src/popup/views/settings.js:55-68) filters a
|
||||
// hostname out of state[key][addr] in place, deleting the address key
|
||||
// entirely once its list is empty — the exact membership-vs-whole-field
|
||||
// pattern that made the whole-field `wallets` diff unsafe, on a
|
||||
// security-relevant field: a stale whole-field save here can resurrect a
|
||||
// revoked permission or wipe a freshly granted one.
|
||||
// allowedSites/deniedSites: { [address]: [origin, ...] }. Mutated in place
|
||||
// from two different contexts — rememberSiteChoice() in
|
||||
// src/background/index.js pushes a newly approved origin onto
|
||||
// state.allowedSites[activeAddress], and the Settings "revoke" button
|
||||
// (forgetOrigin() in src/popup/views/settings.js) filters an origin out of
|
||||
// state[key][addr] in place, deleting the address key entirely once its list
|
||||
// is empty — the exact membership-vs-whole-field pattern that made the
|
||||
// whole-field `wallets` diff unsafe, on a security-relevant field: a stale
|
||||
// whole-field save here can resurrect a revoked permission or wipe a freshly
|
||||
// granted one.
|
||||
const ADDR1 = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
const ADDR2 = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
||||
|
||||
function approveSite(pageState, address, hostname) {
|
||||
function approveSite(pageState, address, origin) {
|
||||
if (!pageState.allowedSites[address]) {
|
||||
pageState.allowedSites[address] = [];
|
||||
}
|
||||
if (!pageState.allowedSites[address].includes(hostname)) {
|
||||
pageState.allowedSites[address].push(hostname);
|
||||
if (!pageState.allowedSites[address].includes(origin)) {
|
||||
pageState.allowedSites[address].push(origin);
|
||||
}
|
||||
}
|
||||
|
||||
function revokeSite(pageState, hostname) {
|
||||
function revokeSite(pageState, origin) {
|
||||
for (const addr of Object.keys(pageState.allowedSites)) {
|
||||
pageState.allowedSites[addr] = pageState.allowedSites[addr].filter(
|
||||
(h) => h !== hostname,
|
||||
(o) => o !== origin,
|
||||
);
|
||||
if (pageState.allowedSites[addr].length === 0) {
|
||||
delete pageState.allowedSites[addr];
|
||||
@@ -308,7 +309,7 @@ describe("a dApp approval racing a stale Settings page's later save", () => {
|
||||
await storage.set({
|
||||
autistmask: {
|
||||
wallets: [W1],
|
||||
allowedSites: { [ADDR2]: ["other.example"] },
|
||||
allowedSites: { [ADDR2]: ["https://other.example"] },
|
||||
},
|
||||
});
|
||||
|
||||
@@ -318,24 +319,24 @@ describe("a dApp approval racing a stale Settings page's later save", () => {
|
||||
await settings.state.loadState();
|
||||
|
||||
// A dApp approval window, opened later, approves a new site for a
|
||||
// different address and saves — the real sequence at
|
||||
// src/background/index.js:592-599.
|
||||
// different address and saves — the real sequence in
|
||||
// rememberSiteChoice(), src/background/index.js.
|
||||
const approval = loadPage(storage);
|
||||
await approval.state.loadState();
|
||||
approveSite(approval.state.state, ADDR1, "dapp.example");
|
||||
approveSite(approval.state.state, ADDR1, "https://dapp.example");
|
||||
await approval.state.saveState();
|
||||
expect(
|
||||
(await storage.get("autistmask")).autistmask.allowedSites[ADDR1],
|
||||
).toEqual(["dapp.example"]);
|
||||
).toEqual(["https://dapp.example"]);
|
||||
|
||||
// Settings revokes its own, unrelated site — the real sequence at
|
||||
// src/popup/views/settings.js:55-68 — and saves from state loaded
|
||||
// before the dApp approval ever happened.
|
||||
revokeSite(settings.state.state, "other.example");
|
||||
// Settings revokes its own, unrelated site — the real sequence in
|
||||
// forgetOrigin(), src/popup/views/settings.js — and saves from state
|
||||
// loaded before the dApp approval ever happened.
|
||||
revokeSite(settings.state.state, "https://other.example");
|
||||
await settings.state.saveState();
|
||||
|
||||
const persisted = (await storage.get("autistmask")).autistmask;
|
||||
expect(persisted.allowedSites[ADDR1]).toEqual(["dapp.example"]);
|
||||
expect(persisted.allowedSites[ADDR1]).toEqual(["https://dapp.example"]);
|
||||
expect(persisted.allowedSites[ADDR2]).toBeUndefined();
|
||||
});
|
||||
});
|
||||
@@ -346,7 +347,7 @@ describe("a revoked site permission against a stale page's later save", () => {
|
||||
await storage.set({
|
||||
autistmask: {
|
||||
wallets: [W1],
|
||||
allowedSites: { [ADDR1]: ["evil.example"] },
|
||||
allowedSites: { [ADDR1]: ["https://evil.example"] },
|
||||
},
|
||||
});
|
||||
|
||||
@@ -354,23 +355,24 @@ describe("a revoked site permission against a stale page's later save", () => {
|
||||
const stale = loadPage(storage);
|
||||
await stale.state.loadState();
|
||||
|
||||
// Settings revokes it — src/popup/views/settings.js:55-68 — from a
|
||||
// second page.
|
||||
// Settings revokes it — forgetOrigin(), src/popup/views/settings.js —
|
||||
// from a second page.
|
||||
const settings = loadPage(storage);
|
||||
await settings.state.loadState();
|
||||
revokeSite(settings.state.state, "evil.example");
|
||||
revokeSite(settings.state.state, "https://evil.example");
|
||||
await settings.state.saveState();
|
||||
expect(
|
||||
(await storage.get("autistmask")).autistmask.allowedSites[ADDR1],
|
||||
).toBeUndefined();
|
||||
|
||||
// The stale page, unaware of the revoke, approves an unrelated site
|
||||
// for a different address and saves — src/background/index.js:592-599.
|
||||
approveSite(stale.state.state, ADDR2, "good.example");
|
||||
// for a different address and saves — rememberSiteChoice(),
|
||||
// src/background/index.js.
|
||||
approveSite(stale.state.state, ADDR2, "https://good.example");
|
||||
await stale.state.saveState();
|
||||
|
||||
const persisted = (await storage.get("autistmask")).autistmask;
|
||||
expect(persisted.allowedSites[ADDR2]).toEqual(["good.example"]);
|
||||
expect(persisted.allowedSites[ADDR2]).toEqual(["https://good.example"]);
|
||||
expect(persisted.allowedSites[ADDR1]).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -167,7 +167,9 @@ describe("an unversioned profile that is perfectly valid", () => {
|
||||
expect(stored.wallets[0].encryptedSecret).toBe("encrypted-secret-1");
|
||||
expect(stored.wallets[0].addresses[0].address).toBe(ADDRESS);
|
||||
expect(stored.activeAddress).toBe(ADDRESS);
|
||||
expect(stored.allowedSites).toEqual({ [ADDRESS]: ["dapp.example"] });
|
||||
expect(stored.allowedSites).toEqual({
|
||||
[ADDRESS]: ["https://dapp.example"],
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
@@ -20,6 +20,26 @@ const path = require("path");
|
||||
|
||||
const { makeStorageStub } = require("./storageStub");
|
||||
|
||||
// The four libraries the popup loads from node_modules, loaded once per test
|
||||
// file and handed to every boot. jest.resetModules() in bootPopup() empties the
|
||||
// module cache but keeps what jest.doMock() registered, so these registrations
|
||||
// hold for every boot in the file and the libraries are not loaded again. None
|
||||
// of them holds popup state; everything under src/ is still loaded fresh on
|
||||
// each boot.
|
||||
//
|
||||
// A test's own mock of one of them: a jest.doMock() made inside the test
|
||||
// replaces the registration here, as it would for any module. A top-of-file
|
||||
// jest.mock() is what the require() below gets, so it is kept, but its factory
|
||||
// runs once per file and every boot shares the same mock object.
|
||||
const ethers = require("ethers");
|
||||
const sodium = require("libsodium-wrappers-sumo");
|
||||
const QRCode = require("qrcode");
|
||||
const makeBlockie = require("ethereum-blockies-base64");
|
||||
jest.doMock("ethers", () => ethers);
|
||||
jest.doMock("libsodium-wrappers-sumo", () => sodium);
|
||||
jest.doMock("qrcode", () => QRCode);
|
||||
jest.doMock("ethereum-blockies-base64", () => makeBlockie);
|
||||
|
||||
const POPUP_HTML = fs.readFileSync(
|
||||
path.join(__dirname, "..", "..", "src", "popup", "index.html"),
|
||||
"utf8",
|
||||
@@ -51,7 +71,7 @@ function unversionedValidProfile(extra) {
|
||||
networkId: "mainnet",
|
||||
rpcUrl: "https://ethereum-rpc.publicnode.com",
|
||||
blockscoutUrl: "https://eth.blockscout.com/api/v2",
|
||||
allowedSites: { [ADDRESS]: ["dapp.example"] },
|
||||
allowedSites: { [ADDRESS]: ["https://dapp.example"] },
|
||||
deniedSites: {},
|
||||
trackedTokens: [],
|
||||
theme: "system",
|
||||
|
||||
@@ -471,7 +471,7 @@ async function openSignScreen(data) {
|
||||
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||
reply({
|
||||
type: "sign",
|
||||
hostname: "dapp.example",
|
||||
origin: "https://dapp.example",
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: OWNER,
|
||||
signParams: request(data),
|
||||
|
||||
@@ -382,8 +382,56 @@ describe("a scale the explorer's own rows disagree about", () => {
|
||||
);
|
||||
});
|
||||
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/377. The Send screen read the
|
||||
// stored balance and said "5.0000 NOVEL", the confirmation screen it leads
|
||||
// to said "unknown (NOVEL)", and the fee message asked the user to go back
|
||||
// and try again, which cannot supply a scale.
|
||||
test("reads the same on the Send screen and the confirmation screen, and the fee message names the scale", async () => {
|
||||
await fetchOntoBoth([novel("6", 5000000n)], [novel("18", FIVE_WETH)]);
|
||||
state.selectedToken = NOVEL;
|
||||
send.updateSendBalance();
|
||||
expect(text("send-balance")).toBe("Current balance: unknown (NOVEL)");
|
||||
|
||||
const txInfo = await reviewSend(NOVEL, "1.5");
|
||||
confirmTx.show(txInfo);
|
||||
await settle();
|
||||
expect(text("confirm-balance")).toBe("unknown (NOVEL)");
|
||||
expect(text("confirm-fee-unknown-error")).toBe(
|
||||
"The network fee could not be estimated, because this wallet" +
|
||||
" does not know how many decimal places this token uses, so" +
|
||||
" this transaction cannot be sent.",
|
||||
);
|
||||
expect(el("confirm-fee-unknown-error").style.visibility).toBe(
|
||||
"visible",
|
||||
);
|
||||
});
|
||||
|
||||
test("while a fee that fails for any other reason keeps its retry", async () => {
|
||||
await fetchOntoBoth([novel("6", 5000000n)], [novel("6", 5000000n)]);
|
||||
const txInfo = await reviewSend(NOVEL, "1.5");
|
||||
const getFeeData = mockProvider.getFeeData;
|
||||
mockProvider.getFeeData = async () => {
|
||||
throw new Error("the node did not answer");
|
||||
};
|
||||
try {
|
||||
confirmTx.show(txInfo);
|
||||
await settle();
|
||||
} finally {
|
||||
mockProvider.getFeeData = getFeeData;
|
||||
}
|
||||
expect(text("confirm-fee-amount")).toBe("Unable to estimate");
|
||||
expect(text("confirm-fee-unknown-error")).toBe(
|
||||
"The network fee could not be estimated, so this transaction" +
|
||||
" cannot be checked against your balance. Please go back and" +
|
||||
" try again.",
|
||||
);
|
||||
});
|
||||
|
||||
test("while agreeing rows leave the scale usable", async () => {
|
||||
await fetchOntoBoth([novel("6", 5000000n)], [novel("6", 5000000n)]);
|
||||
state.selectedToken = NOVEL;
|
||||
send.updateSendBalance();
|
||||
expect(text("send-balance")).toBe("Current balance: 5.0000 NOVEL");
|
||||
const txInfo = await reviewSend(NOVEL, "1.5");
|
||||
expect(txInfo.tokenDecimals).toBe(6);
|
||||
expect(txInfo.tokenBalance).toBe("5.0");
|
||||
|
||||
+20
-11
@@ -28,11 +28,14 @@ function makeState(overrides = {}) {
|
||||
selectedAddress: 0,
|
||||
activeAddress: A0,
|
||||
allowedSites: {
|
||||
[A0]: ["a.example"],
|
||||
[A1]: ["b.example"],
|
||||
[B0]: ["c.example"],
|
||||
[A0]: ["https://a.example"],
|
||||
[A1]: ["https://b.example"],
|
||||
[B0]: ["https://c.example"],
|
||||
},
|
||||
deniedSites: {
|
||||
[A1]: ["https://d.example"],
|
||||
[C0]: ["https://e.example"],
|
||||
},
|
||||
deniedSites: { [A1]: ["d.example"], [C0]: ["e.example"] },
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
@@ -41,7 +44,7 @@ describe("removeWalletFromState", () => {
|
||||
test("deleting the last wallet clears hasWallet", () => {
|
||||
const state = makeState({
|
||||
wallets: [wallet("A", [A0])],
|
||||
allowedSites: { [A0]: ["a.example"] },
|
||||
allowedSites: { [A0]: ["https://a.example"] },
|
||||
deniedSites: {},
|
||||
});
|
||||
|
||||
@@ -109,8 +112,8 @@ describe("removeWalletFromState", () => {
|
||||
|
||||
removeWalletFromState(state, 0);
|
||||
|
||||
expect(state.allowedSites).toEqual({ [B0]: ["c.example"] });
|
||||
expect(state.deniedSites).toEqual({ [C0]: ["e.example"] });
|
||||
expect(state.allowedSites).toEqual({ [B0]: ["https://c.example"] });
|
||||
expect(state.deniedSites).toEqual({ [C0]: ["https://e.example"] });
|
||||
});
|
||||
});
|
||||
|
||||
@@ -126,8 +129,14 @@ function makeAddressState(overrides = {}) {
|
||||
selectedWallet: 0,
|
||||
selectedAddress: 0,
|
||||
activeAddress: A0,
|
||||
allowedSites: { [A0]: ["a.example"], [A1]: ["b.example"] },
|
||||
deniedSites: { [A1]: ["d.example"], [B0]: ["e.example"] },
|
||||
allowedSites: {
|
||||
[A0]: ["https://a.example"],
|
||||
[A1]: ["https://b.example"],
|
||||
},
|
||||
deniedSites: {
|
||||
[A1]: ["https://d.example"],
|
||||
[B0]: ["https://e.example"],
|
||||
},
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
@@ -273,8 +282,8 @@ describe("removeAddressFromState", () => {
|
||||
|
||||
removeAddressFromState(state, 0, 1);
|
||||
|
||||
expect(state.allowedSites).toEqual({ [A0]: ["a.example"] });
|
||||
expect(state.deniedSites).toEqual({ [B0]: ["e.example"] });
|
||||
expect(state.allowedSites).toEqual({ [A0]: ["https://a.example"] });
|
||||
expect(state.deniedSites).toEqual({ [B0]: ["https://e.example"] });
|
||||
});
|
||||
|
||||
// The derivation counter is a high-water mark, never rewound: "+" derives
|
||||
|
||||
Reference in New Issue
Block a user