Compare commits
19
Commits
457dd18642
..
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3b713809c8 | ||
|
|
8ac2c87c2c | ||
|
|
d1751beb32 | ||
|
|
de3f7a9a11 | ||
|
|
1144fdb71b | ||
|
|
f24b5bca19 | ||
|
|
9f0e88e963 | ||
|
|
45f11ee920 | ||
|
|
a68f30c480 | ||
|
|
43c236451f | ||
|
|
1247c24c4d | ||
|
|
bec20aa2bb | ||
|
|
467b849a13 | ||
|
|
5bf8b5ff1f | ||
|
|
4b62e31e80 | ||
|
|
49a7da87e8 | ||
|
|
5f54fcbb24 | ||
|
|
00d6193ee7 | ||
|
|
6c70a82de8 |
+5
-6
@@ -8,12 +8,11 @@ WORKDIR /app
|
|||||||
# image sets it.
|
# image sets it.
|
||||||
ENV AUTISTMASK_LINT_NATIVE=1
|
ENV AUTISTMASK_LINT_NATIVE=1
|
||||||
|
|
||||||
# script/test's default 30s bound is the host figure, against a suite that
|
# script/test's default 30s bound is the host figure. In here the same suite
|
||||||
# runs in about 8s there. In here the same suite starts on a cold jest cache
|
# starts on a cold jest cache and shares the runner with the rest of the build,
|
||||||
# and shares the runner with the rest of the build, so 30s is marginal rather
|
# so 30s is too tight — it killed a healthy suite at 30.6s on a cold CI cache.
|
||||||
# than a bound — it killed a healthy suite at 30.6s on a cold CI cache. 180s
|
# 180s still catches a hang in three minutes and cannot be tripped by a suite
|
||||||
# still catches a hang in three minutes and cannot be tripped by a suite that
|
# that is merely running on contended hardware.
|
||||||
# is merely running on contended hardware.
|
|
||||||
ENV AUTISTMASK_TEST_TIMEOUT=180
|
ENV AUTISTMASK_TEST_TIMEOUT=180
|
||||||
|
|
||||||
# script/bootstrap installs all prerequisites (make via apt here; node
|
# script/bootstrap installs all prerequisites (make via apt here; node
|
||||||
|
|||||||
@@ -882,19 +882,31 @@ On those screens, when the truncated string would contain no digit from 1 to 9
|
|||||||
and the value does, the amount is extended to its first significant digit
|
and the value does, the amount is extended to its first significant digit
|
||||||
instead: `0.000000000000000001 DAI`, not `0.0000 DAI`. The test is on the whole
|
instead: `0.000000000000000001 DAI`, not `0.0000 DAI`. The test is on the whole
|
||||||
truncated string, integer part included, so `1.00005` still shows as `1.0000` —
|
truncated string, integer part included, so `1.00005` still shows as `1.0000` —
|
||||||
the exception only fires where the entire displayed figure would read as zero. A
|
the exception only fires where the entire displayed figure would read as zero.
|
||||||
genuine zero still renders `0.0000`, and truncation stays truncation: `0.99999`
|
Truncation stays truncation: `0.99999` shows as `0.9999`, never rounded up. The
|
||||||
shows as `0.9999`, never rounded up.
|
rule still renders a genuine zero as `0.0000`. Two lines of a swap say a zero in
|
||||||
|
words instead: `Min. received` reads `None (no minimum guaranteed)` for a zero
|
||||||
|
minimum, and `Amount` reads `All available (V4 open delta)` when the amount it
|
||||||
|
shows is a V4 exact-in `amountIn` of zero.
|
||||||
|
|
||||||
The rule and its exception live in `src/shared/amountDisplay.js` as
|
The rule and its exception live in `src/shared/amountDisplay.js` as
|
||||||
`truncateAmount()` and `truncateAmountNeverZero()`. Everything the approval and
|
`truncateAmount()` and `truncateAmountNeverZero()`. Everything the approval and
|
||||||
confirmation screens display goes through the floored one — the ERC-20 amount,
|
confirmation screens display goes through the floored one — the ERC-20 amount,
|
||||||
the ETH value and max fee (`src/popup/views/approval.js`), and the swap's
|
the ETH value and max fee (`src/popup/views/approval.js`), the swap's `Amount`
|
||||||
`Amount` and `Min. received` lines (`src/shared/uniswap.js`). The history and
|
and `Min. received` lines (`src/shared/uniswap.js`), the Send screen's
|
||||||
balance lists (`src/shared/transactions.js`) use the unfloored one: the
|
`Current balance` (`src/popup/views/send.js`), and the balance and network fee
|
||||||
transaction detail view is the authoritative record and already shows exact
|
on the confirmation screen for the wallet's own send
|
||||||
precision. The 4-decimal rule is unchanged everywhere else, including for
|
(`src/popup/views/confirmTx.js`). Both screens render a network fee through
|
||||||
amounts at or above the floor on the approval screens.
|
`formatFee()` in `src/popup/views/helpers.js`, which prices the exact fee in USD
|
||||||
|
rather than its truncated figure, so the same fee reads the same on both, USD
|
||||||
|
value included. Balances are stored exactly (`src/shared/balances.js`), whatever
|
||||||
|
decimals a token declares, so a balance below the floor reaches these screens as
|
||||||
|
it is. The history list (`src/shared/transactions.js`) uses the unfloored one:
|
||||||
|
the transaction detail view is the authoritative record and already shows exact
|
||||||
|
precision. The balance lists use neither: they round to four places with
|
||||||
|
`toFixed(4)` (`balanceLine()` in `src/popup/views/helpers.js`). The 4-decimal
|
||||||
|
rule is unchanged everywhere else, including for amounts at or above the floor
|
||||||
|
on the approval screens.
|
||||||
|
|
||||||
The floor applies only where the token's scale is known. Where it is not, the
|
The floor applies only where the token's scale is known. Where it is not, the
|
||||||
approval screen states base units instead of a quantity — see Unknown token
|
approval screen states base units instead of a quantity — see Unknown token
|
||||||
@@ -914,7 +926,10 @@ rule: the ERC-20 `transfer`/`approve` line (`src/popup/views/approval.js`) and
|
|||||||
the swap's `Amount` and `Min. received` lines (`src/shared/uniswap.js`). The
|
the swap's `Amount` and `Min. received` lines (`src/shared/uniswap.js`). The
|
||||||
token permission warning on the signature screen takes the same rule for its
|
token permission warning on the signature screen takes the same rule for its
|
||||||
amounts. An unbounded allowance or permit needs no scale to describe and is
|
amounts. An unbounded allowance or permit needs no scale to describe and is
|
||||||
still shown as `Unlimited`.
|
still shown as `Unlimited`. A source's answer counts only if it is a whole
|
||||||
|
number from 0 to 80: `decimals()` returns a `uint8`, but `formatUnits()` cannot
|
||||||
|
format more than 80 decimal places, so a token that reports 81 to 255 is shown
|
||||||
|
as one whose scale nothing knows.
|
||||||
|
|
||||||
The rule holds only if nothing invents a scale UPSTREAM of it. Those three
|
The rule holds only if nothing invents a scale UPSTREAM of it. Those three
|
||||||
sources are read as authoritative, so a value written into one of them cannot be
|
sources are read as authoritative, so a value written into one of them cannot be
|
||||||
@@ -937,6 +952,62 @@ and compare against. Reading the stored field directly instead answers `null`
|
|||||||
for a bundled or tracked token the explorer merely omitted, which is not a
|
for a bundled or tracked token the explorer merely omitted, which is not a
|
||||||
refusal the wallet has any reason to make.
|
refusal the wallet has any reason to make.
|
||||||
|
|
||||||
|
The Send screen also consults every address's explorer reports, so a contract
|
||||||
|
two addresses report different `decimals` for has no scale there, and the stored
|
||||||
|
balance, formatted at one of those scales, is withdrawn with it. The Send
|
||||||
|
screen's `Current balance` and the confirmation screen's balance line then both
|
||||||
|
read `unknown (SYMBOL)`. The balance list formats each explorer row as it is
|
||||||
|
fetched, without that cross-address check, and shows the row's figure.
|
||||||
|
|
||||||
|
**Decoded amount lines on the transaction approval screen:** the `Amount` line
|
||||||
|
of a decoded ERC-20 call, and the `Amount` and `Min. received` lines of a
|
||||||
|
decoded swap (see TxApproval below), do not always read as a number. They can
|
||||||
|
read:
|
||||||
|
|
||||||
|
- A formatted quantity, e.g. `17.1900 USDT`, when the token's scale is known:
|
||||||
|
truncated to four decimals, with the floor and the zero cases described above.
|
||||||
|
- `<amount> base units (decimals unknown)` when the scale is unknown: the
|
||||||
|
base-unit integer, rather than a figure at a guessed scale (see Unknown token
|
||||||
|
scale above).
|
||||||
|
- `Unlimited`: on the ERC-20 `Amount` line, an `approve` of the `uint256`
|
||||||
|
maximum, an unbounded allowance. On the swap's `Amount` line, any amount at or
|
||||||
|
above the `uint160` maximum, whichever step set the line: a `PERMIT2_PERMIT`
|
||||||
|
amount at that maximum, which is an unbounded permit, or a V2 or V3 exact-in,
|
||||||
|
V2 exact-out or `WRAP_ETH` amount that large, which is not an allowance. The
|
||||||
|
router's whole-balance value, `CONTRACT_BALANCE` (`2^255`), is one such
|
||||||
|
amount.
|
||||||
|
- `Up to <amount>`: the swap's `Amount` line, when the transaction has a V2
|
||||||
|
exact-out step, whichever step set the line, including the `WRAP_ETH` of a
|
||||||
|
swap paid in ETH and a `PERMIT2_PERMIT`. The swap spends at most that figure,
|
||||||
|
not necessarily all of it; the wait, success and error screens show it with
|
||||||
|
the same words. `Unlimited` and `All available (V4 open delta)` keep their
|
||||||
|
wording. When a V2 exact-out step sets `Min. received`, that line shows its
|
||||||
|
`amountOut`, the exact amount it buys.
|
||||||
|
- `All available (V4 open delta)`: the swap's `Amount` line, when the amount it
|
||||||
|
shows is a V4 exact-in `amountIn` of zero. V4 reads that zero as "use the
|
||||||
|
whole open delta", so the calldata states no quantity. The line shows the
|
||||||
|
amount of one step that names an input token or amount: the last
|
||||||
|
`PERMIT2_PERMIT` step if there is one, otherwise the first V2 or V3 exact-in,
|
||||||
|
V2 exact-out, `WRAP_ETH` or V4 swap step. A V2 exact-out step gives its
|
||||||
|
`amountInMax`, and a V4 swap step the `amountIn` of its first readable
|
||||||
|
exact-in action.
|
||||||
|
- `None (no minimum guaranteed)`: the swap's `Min. received` line, when the
|
||||||
|
minimum it shows is zero, whether a V2, V3 or V4 swap's minimum or a
|
||||||
|
`BALANCE_CHECK_ERC20` step's `minBalance`. Before
|
||||||
|
[#359](https://git.eeqj.de/sneak/AutistMask/issues/359), a zero `minBalance`
|
||||||
|
read `0.0000` when the token's scale was known.
|
||||||
|
|
||||||
|
The swap's `Token In` and `Token Out` lines name a currency, not an amount; each
|
||||||
|
reads `Unknown (not named in the calldata)` when the decoder found no token for
|
||||||
|
that side. An `UNWRAP_WETH` step makes `Token Out` ETH only when the output side
|
||||||
|
is WETH, on mainnet or Sepolia, or when no step set the output side; a WETH
|
||||||
|
`Min. received` figure then reads in ETH. Otherwise `Token Out` and
|
||||||
|
`Min. received` keep the output side's own token and figure, whether the swap
|
||||||
|
was paid in ETH or in a token: a V2 exact-out swap that buys USDC and then
|
||||||
|
unwraps the WETH it did not spend shows USDC. The token permission warning on
|
||||||
|
the signature screen has its own amount wording, including `Unknown`; the
|
||||||
|
SignApproval section below describes it.
|
||||||
|
|
||||||
#### Partial USD totals
|
#### Partial USD totals
|
||||||
|
|
||||||
Prices are fetched for the top 25 tokens only, so an address can hold assets the
|
Prices are fetched for the top 25 tokens only, so an address can hold assets the
|
||||||
@@ -1017,8 +1088,13 @@ list from any other contract address is always dropped, and so is any token
|
|||||||
claiming a symbol that belongs to the native asset and therefore has no
|
claiming a symbol that belongs to the native asset and therefore has no
|
||||||
legitimate contract at all (`"ETH"`). That filter is unconditional — the "Hide
|
legitimate contract at all (`"ETH"`). That filter is unconditional — the "Hide
|
||||||
tokens with fewer than 1,000 holders" setting governs the transaction history
|
tokens with fewer than 1,000 holders" setting governs the transaction history
|
||||||
and the send-screen token selector, not this list. Tracked tokens with a zero
|
and the send-screen token selector, not this list. `fetchTokenBalances()` stores
|
||||||
balance are listed as well while "Show tracked tokens with zero balance" is on.
|
every nonzero holding of a token it admits, however small, but a holding below
|
||||||
|
0.000001 is left out of the balance lists, the send-screen token selector, the
|
||||||
|
address total and the remove-address warning (`isBelowOneMillionth()` in
|
||||||
|
`src/shared/amountDisplay.js`). The Send and confirmation screens show it when
|
||||||
|
its token is the one being sent. Tracked tokens with a zero balance are listed
|
||||||
|
as well while "Show tracked tokens with zero balance" is on.
|
||||||
|
|
||||||
#### Stored state and its version
|
#### Stored state and its version
|
||||||
|
|
||||||
@@ -1084,7 +1160,7 @@ each caught only by a reviewer re-deriving thirty fields by hand.
|
|||||||
The `allowedSites` case is why the entry check is not optional. A stored
|
The `allowedSites` case is why the entry check is not optional. A stored
|
||||||
`{"0x…": "notalist"}` is a well-formed object holding a malformed entry: it
|
`{"0x…": "notalist"}` is a well-formed object holding a malformed entry: it
|
||||||
passed the gate, rendered a completely healthy popup, and then threw inside
|
passed the gate, rendered a completely healthy popup, and then threw inside
|
||||||
`saveState()`'s per-hostname merge, so every save from that moment on failed and
|
`saveState()`'s per-origin merge, so every save from that moment on failed and
|
||||||
the user went on operating a wallet that was persisting nothing
|
the user went on operating a wallet that was persisting nothing
|
||||||
([#362](https://git.eeqj.de/sneak/AutistMask/issues/362)). A save that fails is
|
([#362](https://git.eeqj.de/sneak/AutistMask/issues/362)). A save that fails is
|
||||||
now also reported rather than swallowed: `onSaveFailure()` in
|
now also reported rather than swallowed: `onSaveFailure()` in
|
||||||
@@ -1206,7 +1282,10 @@ view would leave a wallet one click from deletion.
|
|||||||
of every wallet, deduplicated by hash and filtered. Each row is three
|
of every wallet, deduplicated by hash and filtered. Each row is three
|
||||||
lines: age and direction, then the counterparty's colour dot (with our own
|
lines: age and direction, then the counterparty's colour dot (with our own
|
||||||
name for it, where it is one of our addresses) and the amount, then the
|
name for it, where it is one of our addresses) and the amount, then the
|
||||||
counterparty's full address on a row of its own
|
counterparty's full address on a row of its own. A contract creation has
|
||||||
|
no counterparty: its second line is the amount alone and its third line
|
||||||
|
says "This transaction creates a new contract. It has no recipient." The
|
||||||
|
transaction lists on AddressDetail and AddressToken draw the same rows
|
||||||
- "Add additional wallet..." link at bottom
|
- "Add additional wallet..." link at bottom
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
- Tap address row → sets the active address and broadcasts
|
- Tap address row → sets the active address and broadcasts
|
||||||
@@ -1340,7 +1419,9 @@ view would leave a wallet one click from deletion.
|
|||||||
- What to send: token dropdown (or static display with contract address when
|
- What to send: token dropdown (or static display with contract address when
|
||||||
locked from AddressToken)
|
locked from AddressToken)
|
||||||
- To: address or ENS name input, with an inline validation message
|
- To: address or ENS name input, with an inline validation message
|
||||||
- Amount input with current balance display
|
- Amount input with current balance display, which reads
|
||||||
|
`Current balance: unknown (SYMBOL)` for a token whose scale is unknown, as
|
||||||
|
ConfirmTx's balance line does (see Unknown token scale)
|
||||||
- "Review" button, disabled until the recipient validates
|
- "Review" button, disabled until the recipient validates
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
- "Review" (valid inputs, ENS resolved) → **ConfirmTx**
|
- "Review" (valid inputs, ENS resolved) → **ConfirmTx**
|
||||||
@@ -1358,7 +1439,8 @@ view would leave a wallet one click from deletion.
|
|||||||
- From: blockie + color dot + full address + etherscan link + wallet title
|
- From: blockie + color dot + full address + etherscan link + wallet title
|
||||||
- To: blockie + color dot + full address + etherscan link + ENS name
|
- To: blockie + color dot + full address + etherscan link + ENS name
|
||||||
- Amount: value + symbol (USD in parentheses)
|
- Amount: value + symbol (USD in parentheses)
|
||||||
- Your balance: value + symbol (USD in parentheses)
|
- Your balance: value + symbol (USD in parentheses), or `unknown (SYMBOL)`
|
||||||
|
for a token whose scale is unknown
|
||||||
- Network fee: "Estimating..." then two lines, or "Unable to estimate",
|
- Network fee: "Estimating..." then two lines, or "Unable to estimate",
|
||||||
fetched async. The first line is what the transfer is expected to cost,
|
fetched async. The first line is what the transfer is expected to cost,
|
||||||
`gasLimit * gasPrice` (USD in parentheses); the second is the
|
`gasLimit * gasPrice` (USD in parentheses); the second is the
|
||||||
@@ -1374,7 +1456,11 @@ view would leave a wallet one click from deletion.
|
|||||||
amount plus the fee exceeds the balance (ETH transfers), not enough ETH to
|
amount plus the fee exceeds the balance (ETH transfers), not enough ETH to
|
||||||
pay the fee for the transfer (ERC-20 transfers), and the fee could not be
|
pay the fee for the transfer (ERC-20 transfers), and the fee could not be
|
||||||
estimated. The first two are mutually exclusive per transfer type, so only
|
estimated. The first two are mutually exclusive per transfer type, so only
|
||||||
the applicable one holds space
|
the applicable one holds space. The last names its cause: for a token
|
||||||
|
whose scale is unknown the fee can never be estimated, and it says the
|
||||||
|
wallet does not know how many decimal places the token uses and that the
|
||||||
|
transaction cannot be sent; for any other failure it asks the user to go
|
||||||
|
back and try again
|
||||||
- Password: an inline field on this screen, not a modal, with its own error
|
- Password: an inline field on this screen, not a modal, with its own error
|
||||||
line
|
line
|
||||||
- "Sign & Send" button (disabled if errors, and while the network fee
|
- "Sign & Send" button (disabled if errors, and while the network fee
|
||||||
@@ -1399,7 +1485,9 @@ view would leave a wallet one click from deletion.
|
|||||||
- **Elements**:
|
- **Elements**:
|
||||||
- "Transaction Broadcast" heading (no back button — tx is irreversible)
|
- "Transaction Broadcast" heading (no back button — tx is irreversible)
|
||||||
- Amount + symbol
|
- Amount + symbol
|
||||||
- To: color dot + full address + etherscan link
|
- To: color dot + full address + etherscan link; for a contract creation,
|
||||||
|
which has no recipient, "This transaction creates a new contract. It has
|
||||||
|
no recipient." instead
|
||||||
- Transaction hash: full hash (tap to copy) + etherscan link
|
- Transaction hash: full hash (tap to copy) + etherscan link
|
||||||
- Count-up timer: "Waiting for confirmation... Ns"
|
- Count-up timer: "Waiting for confirmation... Ns"
|
||||||
- **Behavior**: Polls `getTransactionReceipt` every 10 seconds. The wait is
|
- **Behavior**: Polls `getTransactionReceipt` every 10 seconds. The wait is
|
||||||
@@ -1428,7 +1516,8 @@ view would leave a wallet one click from deletion.
|
|||||||
- Decoded action well (shown when the transaction carried recognized
|
- Decoded action well (shown when the transaction carried recognized
|
||||||
calldata; the top-level Amount and To are hidden in that case)
|
calldata; the top-level Amount and To are hidden in that case)
|
||||||
- Amount + symbol
|
- Amount + symbol
|
||||||
- To: color dot + full address + etherscan link
|
- To: color dot + full address + etherscan link, or for a contract creation
|
||||||
|
the same sentence as on WaitTx
|
||||||
- Block number
|
- Block number
|
||||||
- Transaction hash: full hash (tap to copy) + etherscan link
|
- Transaction hash: full hash (tap to copy) + etherscan link
|
||||||
- "Done" button
|
- "Done" button
|
||||||
@@ -1443,7 +1532,8 @@ view would leave a wallet one click from deletion.
|
|||||||
- **Elements**:
|
- **Elements**:
|
||||||
- "Transaction Failed" heading
|
- "Transaction Failed" heading
|
||||||
- Amount + symbol
|
- Amount + symbol
|
||||||
- To: color dot + full address + etherscan link
|
- To: color dot + full address + etherscan link, or for a contract creation
|
||||||
|
the same sentence as on WaitTx
|
||||||
- Error message (dashed border box)
|
- Error message (dashed border box)
|
||||||
- Transaction hash section (hidden if broadcast failed before getting hash):
|
- Transaction hash section (hidden if broadcast failed before getting hash):
|
||||||
full hash (tap to copy) + etherscan link
|
full hash (tap to copy) + etherscan link
|
||||||
@@ -1481,7 +1571,7 @@ view would leave a wallet one click from deletion.
|
|||||||
- From: blockie + color dot + full address (tap to copy) + etherscan link;
|
- From: blockie + color dot + full address (tap to copy) + etherscan link;
|
||||||
ENS name if available
|
ENS name if available
|
||||||
- To: blockie + color dot + full address (tap to copy) + etherscan link; ENS
|
- To: blockie + color dot + full address (tap to copy) + etherscan link; ENS
|
||||||
name if available
|
name if available. For a contract creation, the same sentence as on WaitTx
|
||||||
- Time: ISO datetime + relative age in parentheses
|
- Time: ISO datetime + relative age in parentheses
|
||||||
- Block: block number (tap to copy) + etherscan block link
|
- Block: block number (tap to copy) + etherscan block link
|
||||||
- Amount: value + symbol (bold)
|
- Amount: value + symbol (bold)
|
||||||
@@ -1544,8 +1634,14 @@ view would leave a wallet one click from deletion.
|
|||||||
a value carrying its unit, hex (`0x10`) or exponent (`1e3`) notation —
|
a value carrying its unit, hex (`0x10`) or exponent (`1e3`) notation —
|
||||||
is refused with a flash message and the field snaps back to the stored
|
is refused with a flash message and the field snaps back to the stored
|
||||||
threshold, so a number the user did not type is never stored.
|
threshold, so a number the user did not type is never stored.
|
||||||
- Allowed Sites: list with remove buttons
|
- Allowed Sites: the origins (scheme, host and port) remembered as allowed,
|
||||||
- Denied Sites: list with remove buttons
|
under any address, with remove buttons
|
||||||
|
- Connected Sites: the origins of the sites allowed without "Remember my
|
||||||
|
choice" that are still connected, with remove buttons. Only the background
|
||||||
|
holds these, in memory, and Settings asks it for them with
|
||||||
|
`AUTISTMASK_GET_CONNECTED_SITES`
|
||||||
|
- Denied Sites: the origins remembered as denied, under any address, with
|
||||||
|
remove buttons
|
||||||
- About: project link, license, author, version, release date, and the
|
- About: project link, license, author, version, release date, and the
|
||||||
commit, which links to the commit in the repository
|
commit, which links to the commit in the repository
|
||||||
- Debug: hidden until revealed, then an "Enable debug mode" checkbox that
|
- Debug: hidden until revealed, then an "Enable debug mode" checkbox that
|
||||||
@@ -1556,8 +1652,16 @@ view would leave a wallet one click from deletion.
|
|||||||
- `[recovery phrase]` on an HD wallet → **ShowRecoveryPhrase**
|
- `[recovery phrase]` on an HD wallet → **ShowRecoveryPhrase**
|
||||||
- `[x]` on a wallet → **DeleteWallet**
|
- `[x]` on a wallet → **DeleteWallet**
|
||||||
- Tap wallet name → inline rename field (no screen change)
|
- Tap wallet name → inline rename field (no screen change)
|
||||||
- `[x]` on a tracked token or a site → removes it in place (no screen
|
- `[x]` on a tracked token → removes it in place (no screen change)
|
||||||
change)
|
- `[x]` on an allowed or connected site → disconnects that site, in place:
|
||||||
|
its origin is dropped from Allowed Sites under every address, and
|
||||||
|
`AUTISTMASK_REMOVE_SITE` has the background end every connection approved
|
||||||
|
without "Remember" from that origin, under any address, and send
|
||||||
|
`accountsChanged` with an empty list to the open tabs of that origin. The
|
||||||
|
same host under another scheme or port is another site and is left alone.
|
||||||
|
Only the extension's own pages may send either message
|
||||||
|
- `[x]` on a denied site → forgets the refusal, in place; it connects
|
||||||
|
nothing and tells the background nothing
|
||||||
- Ten clicks on the version → reveals the Debug well (no screen change)
|
- Ten clicks on the version → reveals the Debug well (no screen change)
|
||||||
- "Back" (or Settings gear again) → previous screen (Home)
|
- "Back" (or Settings gear again) → previous screen (Home)
|
||||||
|
|
||||||
@@ -1608,6 +1712,10 @@ view would leave a wallet one click from deletion.
|
|||||||
- Either way, the active address moves only if it belonged to the deleted
|
- Either way, the active address moves only if it belonged to the deleted
|
||||||
wallet, and `AUTISTMASK_ACTIVE_CHANGED` is broadcast when it does
|
wallet, and `AUTISTMASK_ACTIVE_CHANGED` is broadcast when it does
|
||||||
(`src/shared/walletDelete.js`)
|
(`src/shared/walletDelete.js`)
|
||||||
|
- Either way, every address the wallet held loses its site permissions of
|
||||||
|
both kinds: the remembered ones in storage, and the connections approved
|
||||||
|
without "Remember", which only the background holds, in memory, and drops
|
||||||
|
on `AUTISTMASK_ADDRESSES_REMOVED`
|
||||||
- "Confirm Delete" (wrong password) → "That password is incorrect. Please
|
- "Confirm Delete" (wrong password) → "That password is incorrect. Please
|
||||||
try again." on the error line, nothing deleted
|
try again." on the error line, nothing deleted
|
||||||
- "I have lost my password" → **DeleteWalletLostPassword**
|
- "I have lost my password" → **DeleteWalletLostPassword**
|
||||||
@@ -1704,6 +1812,10 @@ view would leave a wallet one click from deletion.
|
|||||||
so a connected site stops being told about an address the user removed
|
so a connected site stops being told about an address the user removed
|
||||||
(`src/shared/walletDelete.js`). A selection in any other wallet is left alone;
|
(`src/shared/walletDelete.js`). A selection in any other wallet is left alone;
|
||||||
one in this wallet follows the splice.
|
one in this wallet follows the splice.
|
||||||
|
- The address loses its site permissions of both kinds, whether or not it was
|
||||||
|
the active one: the remembered ones in storage, and any connection approved
|
||||||
|
without "Remember", which only the background holds, in memory, and drops on
|
||||||
|
`AUTISTMASK_ADDRESSES_REMOVED`.
|
||||||
- The wallet's derivation counter (`nextIndex`) is not rewound, so "+" derives a
|
- The wallet's derivation counter (`nextIndex`) is not rewound, so "+" derives a
|
||||||
fresh address rather than handing back the one just removed.
|
fresh address rather than handing back the one just removed.
|
||||||
|
|
||||||
@@ -1730,21 +1842,30 @@ view would leave a wallet one click from deletion.
|
|||||||
|
|
||||||
- **When**: A website requests wallet access via `eth_requestAccounts` or
|
- **When**: A website requests wallet access via `eth_requestAccounts` or
|
||||||
`wallet_requestPermissions` and is on neither the allowed nor the denied list.
|
`wallet_requestPermissions` and is on neither the allowed nor the denied list.
|
||||||
The background script prefers the toolbar popup (`action.openPopup()`) and
|
A site is its full origin, `scheme://host[:port]`, on both lists and for a
|
||||||
falls back to a separate popup window (`src/background/index.js`,
|
connection allowed without "Remember": a choice for `https://dapp.example`
|
||||||
`requestApproval()`).
|
says nothing about `http://dapp.example` or another port of that host. The
|
||||||
|
background script prefers the toolbar popup (`action.openPopup()`) and falls
|
||||||
|
back to a separate popup window (`src/background/index.js`,
|
||||||
|
`requestApproval()`). Only one exists per site at a time: a further connection
|
||||||
|
request from a site whose prompt is still unanswered is refused with EIP-1193
|
||||||
|
code `-32002` and opens no new prompt. If that prompt was in a toolbar popup
|
||||||
|
that closed before it connected, and the toolbar popup has since been set to
|
||||||
|
open something else, the refused request shows that prompt again.
|
||||||
- **Elements**:
|
- **Elements**:
|
||||||
- "Connection Request" heading
|
- "Connection Request" heading
|
||||||
- Phishing warning banner (shown when the hostname is on the phishing
|
- Phishing warning banner (shown when the hostname is on the phishing
|
||||||
blocklist)
|
blocklist)
|
||||||
- Site hostname (bold) + "wants to connect to your wallet"
|
- Site origin (bold, scheme and port included) + "wants to connect to your
|
||||||
|
wallet"
|
||||||
- Address that will be shared (color dot + full address + etherscan link)
|
- Address that will be shared (color dot + full address + etherscan link)
|
||||||
- "Remember my choice for this site" checkbox
|
- "Remember my choice for this site" checkbox
|
||||||
- "Allow" / "Deny" buttons
|
- "Allow" / "Deny" buttons
|
||||||
- **Transitions**:
|
- **Transitions**:
|
||||||
- "Allow" / "Deny" → closes popup (returns result to background script; the
|
- "Allow" / "Deny" → closes popup (returns result to background script; the
|
||||||
choice is persisted to the allowed or denied list when "Remember" is
|
choice is persisted to the allowed or denied list when "Remember" is
|
||||||
checked)
|
checked, and an "Allow" without it is listed under Connected Sites in
|
||||||
|
**Settings**)
|
||||||
- Popup closed without answering → treated as a denial
|
- Popup closed without answering → treated as a denial
|
||||||
|
|
||||||
#### TxApproval (`approve-tx`)
|
#### TxApproval (`approve-tx`)
|
||||||
@@ -1755,23 +1876,27 @@ view would leave a wallet one click from deletion.
|
|||||||
programmatically rather than by a user gesture. The background populates the
|
programmatically rather than by a user gesture. The background populates the
|
||||||
transaction (nonce, gas limit, fees, chain id) against the RPC node _before_
|
transaction (nonce, gas limit, fees, chain id) against the RPC node _before_
|
||||||
opening the window, so the screen shows a complete transaction and the signed
|
opening the window, so the screen shows a complete transaction and the signed
|
||||||
artifact can be compared with it field for field. A request that cannot be
|
artifact can be compared with it field for field. A nonce the site supplies is
|
||||||
populated — unreachable node, reverting gas estimate — opens no window and is
|
ignored: the nonce is always the account's next nonce from the node, so a site
|
||||||
failed back to the site. Only one transaction approval exists at a time:
|
cannot replace one of the user's pending transactions or leave this one stuck
|
||||||
populating fixes the nonce, so a second `eth_sendTransaction` arriving while
|
behind a gap. A request that cannot be populated — unreachable node, reverting
|
||||||
one is unanswered is refused with EIP-1193 code `-32002` rather than being
|
gas estimate — opens no window and is failed back to the site. Only one
|
||||||
populated at the same nonce. It opens no window and takes no nonce, and the
|
transaction approval exists at a time: populating fixes the nonce, so a second
|
||||||
site can send it again once the pending one is answered.
|
`eth_sendTransaction` arriving while one is unanswered is refused with
|
||||||
|
EIP-1193 code `-32002` rather than being populated at the same nonce. It opens
|
||||||
|
no window and takes no nonce, and the site can send it again once the pending
|
||||||
|
one is answered.
|
||||||
- **Elements**:
|
- **Elements**:
|
||||||
- "Transaction Request" heading
|
- "Transaction Request" heading
|
||||||
- Phishing warning banner (shown when the hostname is on the phishing
|
- Phishing warning banner (shown when the hostname is on the phishing
|
||||||
blocklist)
|
blocklist)
|
||||||
- Site hostname (bold) + "wants to send a transaction"
|
- Site origin (bold, scheme and port included) + "wants to send a
|
||||||
|
transaction"
|
||||||
- Decoded action (if calldata is recognized): action name, token details,
|
- Decoded action (if calldata is recognized): action name, token details,
|
||||||
amounts, steps, deadline (see Transaction Decoding)
|
amounts, steps, deadline (see Transaction Decoding)
|
||||||
- From: color dot + full address + etherscan link
|
- From: color dot + full address + etherscan link
|
||||||
- Contract: color dot + full address + etherscan link (or "contract
|
- Contract: color dot + full address + etherscan link, token symbol label if
|
||||||
creation"), token symbol label if known
|
known; for a contract creation, the same sentence as on WaitTx
|
||||||
- Value: amount in ETH (4 decimal places, USD in parentheses)
|
- Value: amount in ETH (4 decimal places, USD in parentheses)
|
||||||
- Network fee (max): gas limit × fee per gas in ETH (4 decimal places, USD
|
- Network fee (max): gas limit × fee per gas in ETH (4 decimal places, USD
|
||||||
in parentheses), with the gas limit and the fee per gas in gwei below it
|
in parentheses), with the gas limit and the fee per gas in gwei below it
|
||||||
@@ -1792,12 +1917,16 @@ view would leave a wallet one click from deletion.
|
|||||||
|
|
||||||
- **When**: A connected website requests a message signature via
|
- **When**: A connected website requests a message signature via
|
||||||
`personal_sign`, `eth_sign`, or `eth_signTypedData_v4`. Opened the same way as
|
`personal_sign`, `eth_sign`, or `eth_signTypedData_v4`. Opened the same way as
|
||||||
TxApproval, in a separate popup window.
|
TxApproval, in a separate popup window. Only one exists per site at a time: a
|
||||||
|
further signature request, by any of these methods, from a site whose
|
||||||
|
signature request is still unanswered is refused with EIP-1193 code `-32002`
|
||||||
|
and opens no window.
|
||||||
- **Elements**:
|
- **Elements**:
|
||||||
- "Signature Request" heading
|
- "Signature Request" heading
|
||||||
- Phishing warning banner (shown when the hostname is on the phishing
|
- Phishing warning banner (shown when the hostname is on the phishing
|
||||||
blocklist)
|
blocklist)
|
||||||
- Site hostname (bold) + "wants you to sign a message"
|
- Site origin (bold, scheme and port included) + "wants you to sign a
|
||||||
|
message"
|
||||||
- Danger warning box (shown for `eth_sign`, which signs a raw hash)
|
- Danger warning box (shown for `eth_sign`, which signs a raw hash)
|
||||||
- Type: "Personal message" or "Typed data (EIP-712)"
|
- Type: "Personal message" or "Typed data (EIP-712)"
|
||||||
- From: color dot + full address + etherscan link
|
- From: color dot + full address + etherscan link
|
||||||
@@ -2042,6 +2171,17 @@ the log level and turns the banner on, and that is all it may ever do: it feeds
|
|||||||
constant directly, so no runtime toggle in a release build can reach the
|
constant directly, so no runtime toggle in a release build can reach the
|
||||||
hardcoded test phrase.
|
hardcoded test phrase.
|
||||||
|
|
||||||
|
At the raised log level the console also shows the wallet's addresses with their
|
||||||
|
balances and ENS names, the token contracts looked up, and a line for each
|
||||||
|
request made through `debugFetch` in `src/shared/log.js` (the explorer, the
|
||||||
|
price feed, the RPC calls a site makes, and the endpoint checks in settings) and
|
||||||
|
for its response. A request is logged by its HTTP method, the origin of its URL
|
||||||
|
(scheme, host and port) and, for a JSON-RPC call, the method name; the balance
|
||||||
|
refresh, the token lookup and a failed endpoint check in settings name the
|
||||||
|
endpoint by its origin too. The URL's path and query string, where RPC providers
|
||||||
|
put API keys, any user name and password in it, and the request body are never
|
||||||
|
logged.
|
||||||
|
|
||||||
### Key Decisions
|
### Key Decisions
|
||||||
|
|
||||||
- **No framework**: The popup UI is vanilla JS and HTML. The extension is small
|
- **No framework**: The popup UI is vanilla JS and HTML. The extension is small
|
||||||
|
|||||||
@@ -45,6 +45,196 @@ but the review is broader than any of them.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-04: A token that reports more than 80 decimal places has no known
|
||||||
|
scale ([#350](https://git.eeqj.de/sneak/AutistMask/issues/350)). The shared
|
||||||
|
scale check `toDecimals()` accepted any `uint8`, but `formatUnits()` throws
|
||||||
|
above 80, so such a token left a swap or an ERC-20 call on the approval screen
|
||||||
|
undecoded, with nothing saying why. The check now stops at 80, and both
|
||||||
|
approval paths show the base-unit amount with the scale stated as unknown. The
|
||||||
|
balance list and the history list use the same check, so the same token no
|
||||||
|
longer stops an address's token balances from refreshing or its history from
|
||||||
|
loading.
|
||||||
|
- 2026-10-04: Debug mode no longer writes RPC API keys to the console
|
||||||
|
([#410](https://git.eeqj.de/sneak/AutistMask/issues/410)). `debugFetch` logged
|
||||||
|
every request's full URL and body, so an RPC endpoint with a key in its path
|
||||||
|
or query string printed that key on every request. It now logs the HTTP
|
||||||
|
method, the URL's origin and, for a JSON-RPC call, the method name. The
|
||||||
|
balance refresh and token lookup log the RPC endpoint by its origin too. A
|
||||||
|
failed RPC call's error line prints the error's short message, which names the
|
||||||
|
HTTP status, not its full message, which carries the request URL. A failed
|
||||||
|
endpoint check in settings names the endpoint by its origin, not the `fetch`
|
||||||
|
error's message, which carries the whole URL, password included, for a URL
|
||||||
|
with a user name and password. The README's DEBUG Mode Policy says what debug
|
||||||
|
mode logs.
|
||||||
|
|
||||||
|
- 2026-10-04: A site has at most one connection prompt and one signature prompt
|
||||||
|
open at a time ([#405](https://git.eeqj.de/sneak/AutistMask/issues/405)). Each
|
||||||
|
`eth_requestAccounts` or `personal_sign` call opened another approval window,
|
||||||
|
so a page calling in a loop could cover the screen with identical prompts. A
|
||||||
|
further request of the same kind from a site whose prompt is still unanswered
|
||||||
|
is now refused with EIP-1193 `-32002`, the code a second transaction already
|
||||||
|
gets, and opens no window. Signing by `personal_sign`, `eth_sign` and
|
||||||
|
`eth_signTypedData_v4` counts as one kind. Other sites are not affected, and
|
||||||
|
the site may ask again once the user has answered. A connection prompt whose
|
||||||
|
toolbar popup closed before it connected, and which nothing shows any more, is
|
||||||
|
shown again when the site asks again.
|
||||||
|
|
||||||
|
- 2026-10-04: A nonce the site supplies with `eth_sendTransaction` is ignored
|
||||||
|
([#404](https://git.eeqj.de/sneak/AutistMask/issues/404)). It was passed on to
|
||||||
|
the transaction, so a site could replace one of the user's pending
|
||||||
|
transactions (same nonce, higher fee) or leave the new one stuck behind a gap,
|
||||||
|
and the approval screen showed it as a bare number. `nonce` is no longer one
|
||||||
|
of the fields taken from the request in `src/shared/approvalTx.js`, so the
|
||||||
|
transaction always gets the account's next nonce from the node, and that is
|
||||||
|
the nonce the approval screen shows and the popup signs.
|
||||||
|
|
||||||
|
- 2026-10-04: Remembered site permissions are held by full origin
|
||||||
|
([#402](https://git.eeqj.de/sneak/AutistMask/issues/402)). `allowedSites` and
|
||||||
|
`deniedSites` stored the hostname alone, so a grant to `https://dapp.example`
|
||||||
|
also authorised `http://dapp.example` and every port on that host, and the
|
||||||
|
prompts named only the hostname. Both lists now store and match the origin
|
||||||
|
(`scheme://host[:port]`), the key the connections approved without "Remember"
|
||||||
|
already used, in `src/background/index.js` and in Settings, whose site lists
|
||||||
|
and `AUTISTMASK_REMOVE_SITE` carry the origin too. The connection, transaction
|
||||||
|
and signature prompts show the origin. Entries saved by hostname before this
|
||||||
|
change are not migrated (pre-1.0): they match no site, and Settings lists them
|
||||||
|
until they are removed.
|
||||||
|
|
||||||
|
- 2026-10-04: A page's request is credited only to the site the browser says
|
||||||
|
sent it ([#407](https://git.eeqj.de/sneak/AutistMask/issues/407)). Where the
|
||||||
|
browser does not give the sender's origin (Firefox before 126), the background
|
||||||
|
used the tab's page, so a frame from another site would have been treated as
|
||||||
|
the site embedding it, and with no tab it used an origin the page wrote into
|
||||||
|
the message. It now uses the URL of the frame that sent the message, and
|
||||||
|
refuses the request with code 4100 when the browser gives neither. The content
|
||||||
|
script no longer writes an origin into the message.
|
||||||
|
|
||||||
|
- 2026-10-04: `make test` takes 8-13s on the shared build host, down from
|
||||||
|
17-25s, measured in alternating runs before and after the change
|
||||||
|
([#428](https://git.eeqj.de/sneak/AutistMask/issues/428)). Each popup boot in
|
||||||
|
the tests (`tests/support/popupBoot.js`) resets jest's module registry so that
|
||||||
|
everything under `src/` loads fresh, and that also reloaded `ethers`,
|
||||||
|
`libsodium-wrappers-sumo`, `qrcode` and `ethereum-blockies-base64` every time.
|
||||||
|
Those four libraries are now loaded once per test file and handed to every
|
||||||
|
boot. No test or assertion changed.
|
||||||
|
|
||||||
|
- 2026-10-04: A token whose scale is unknown reads the same on the Send screen
|
||||||
|
as on the confirmation screen
|
||||||
|
([#377](https://git.eeqj.de/sneak/AutistMask/issues/377)). When two addresses'
|
||||||
|
explorer reports disagree on a token's `decimals`, the Send screen showed the
|
||||||
|
stored figure while the confirmation screen it leads to said
|
||||||
|
`unknown (SYMBOL)`; both now say `unknown (SYMBOL)`, from one function in
|
||||||
|
`src/popup/views/send.js`. The confirmation screen's fee-unknown message names
|
||||||
|
its cause: for an unknown scale it says the wallet does not know how many
|
||||||
|
decimal places the token uses and that the transaction cannot be sent, instead
|
||||||
|
of asking the user to go back and try again, which cannot help. For any other
|
||||||
|
cause it is unchanged.
|
||||||
|
|
||||||
|
- 2026-10-04: A Uniswap V2 exact-out swap (Universal Router command `0x09`) is
|
||||||
|
decoded on the approval screen
|
||||||
|
([#283](https://git.eeqj.de/sneak/AutistMask/issues/283)). `decode()` in
|
||||||
|
`src/shared/uniswap.js` had no arm for it, so the screen named the step and
|
||||||
|
showed no token or amount. The input side is the path's first token with
|
||||||
|
`amountInMax`, the output side the last token with `amountOut`. When the
|
||||||
|
transaction has such a step, the `Amount` figure reads `Up to <amount>`,
|
||||||
|
whichever step set it, there and on the wait, success and error screens,
|
||||||
|
except where it reads `Unlimited` (an unbounded `PERMIT2_PERMIT`, or any
|
||||||
|
amount at or above the `uint160` maximum) or `All available (V4 open delta)`.
|
||||||
|
In every swap, `UNWRAP_WETH` makes `Token Out` ETH only when the output side
|
||||||
|
is WETH, on mainnet or Sepolia, or when no step set the output side; otherwise
|
||||||
|
`Token Out` and `Min. received` keep the output side's own token and figure.
|
||||||
|
V3 exact-out (`0x01`) is still not decoded.
|
||||||
|
|
||||||
|
- 2026-10-04: `make test` runs jest in three worker processes
|
||||||
|
([#426](https://git.eeqj.de/sneak/AutistMask/issues/426)). The `test` and
|
||||||
|
`test:verbose` scripts in `package.json` ran `jest --forceExit`, which starts
|
||||||
|
one worker per CPU core: about 47 processes and 7-8 GiB per run on the shared
|
||||||
|
48-core build host. They now pass `--maxWorkers=3`, and the suite takes 23-29s
|
||||||
|
there: inside the 30-second cap in `script/test`, which is unchanged, but not
|
||||||
|
by much, because `tests/persistedFieldContract.test.js` alone takes most of it
|
||||||
|
([#428](https://git.eeqj.de/sneak/AutistMask/issues/428)). One or two workers
|
||||||
|
went past the cap. `make check`, the pre-commit hook and `script/cibuild` all
|
||||||
|
run the suite through these scripts.
|
||||||
|
|
||||||
|
- 2026-10-04: The error container on each dApp approval screen keeps its height
|
||||||
|
when an error appears
|
||||||
|
([#297](https://git.eeqj.de/sneak/AutistMask/issues/297)). `#approve-tx-error`
|
||||||
|
and `#approve-sign-error` reserved 20px, but their border and padding took
|
||||||
|
10px of it, so a one-line error grew them to 26px and pushed the buttons below
|
||||||
|
down 6px. They now reserve 30px. A new test in `tests/e2e/run.js` shows each
|
||||||
|
of the six password error containers on its own screen, empty and then with an
|
||||||
|
error, and fails if one changes height or the element below it moves. Some of
|
||||||
|
the longer messages these two containers can show still take two lines.
|
||||||
|
|
||||||
|
- 2026-10-04: A transaction with no `to` says "This transaction creates a new
|
||||||
|
contract. It has no recipient." on its recipient line and in its transaction
|
||||||
|
history row ([#250](https://git.eeqj.de/sneak/AutistMask/issues/250)). The
|
||||||
|
wait, success and error screens, the transaction detail view and the history
|
||||||
|
rows on Home, AddressDetail and AddressToken showed a blank address there,
|
||||||
|
with a colour dot whose colour was `undefined`; the approval screen showed
|
||||||
|
"(contract creation)". A transaction with a real `to` is unchanged.
|
||||||
|
|
||||||
|
- 2026-10-04: The Send and confirmation screens no longer show an ETH balance, a
|
||||||
|
token balance or a network fee below 0.000001 as zero
|
||||||
|
([#343](https://git.eeqj.de/sneak/AutistMask/issues/343)). The stored balances
|
||||||
|
(`src/shared/balances.js`) and the confirmation screen's fee were each cut to
|
||||||
|
six decimal places by a rule of their own, and a token holding cut to zero was
|
||||||
|
dropped. Balances are now stored exactly, whatever decimals a token declares,
|
||||||
|
and every nonzero token holding is kept; the balance check reads a token
|
||||||
|
balance to its first 18 places, the most an amount can have. The balance
|
||||||
|
lists, the send-screen token selector, the address total and the
|
||||||
|
remove-address warning leave out a holding below 0.000001 themselves, as
|
||||||
|
before. The Send screen's `Current balance`, and the confirmation screen's
|
||||||
|
balance, fee, reserve and insufficient-balance messages, go through
|
||||||
|
`truncateAmountNeverZero()` in `src/shared/amountDisplay.js`, the helper the
|
||||||
|
approval screen already used. The confirmation and approval screens both
|
||||||
|
render the fee through `formatFee()` in `src/popup/views/helpers.js`, which
|
||||||
|
prices the exact fee in USD, so the same fee reads the same on both, USD value
|
||||||
|
included.
|
||||||
|
|
||||||
|
- 2026-10-04: The flash line keeps to the one line it reserves at any message
|
||||||
|
length ([#252](https://git.eeqj.de/sneak/AutistMask/issues/252)). A message
|
||||||
|
that wrapped pushed the whole screen below it down. `#flash-msg` no longer
|
||||||
|
wraps: text too long for the line is cut with an ellipsis, and `showFlash()`
|
||||||
|
puts the whole message in the line's title. Every message is also reworded to
|
||||||
|
at most 50 characters so none is cut; none carries a wallet name or text from
|
||||||
|
a server, and the add-token screens flash a fixed line for any error other
|
||||||
|
than a contract that is not a token. A new test in `tests/e2e/run.js` puts a
|
||||||
|
message several lines long on the line and fails if the line or the screen
|
||||||
|
below it moves. The two approval-screen error boxes are left to
|
||||||
|
[#297](https://git.eeqj.de/sneak/AutistMask/issues/297).
|
||||||
|
|
||||||
|
- 2026-10-04: A method the wallet does not implement is refused with EIP-1193
|
||||||
|
code `4200` ([#279](https://git.eeqj.de/sneak/AutistMask/issues/279)). The
|
||||||
|
background's `Unsupported method: <method>` error carried no code, so a site
|
||||||
|
probing for an optional method could not tell "not implemented" from "the call
|
||||||
|
failed". The message is unchanged; the background's other errors with no code
|
||||||
|
are untouched.
|
||||||
|
|
||||||
|
- 2026-10-04: Settings lists the sites connected without "Remember", and
|
||||||
|
removing a site there disconnects it
|
||||||
|
([#406](https://git.eeqj.de/sneak/AutistMask/issues/406)). Such a connection
|
||||||
|
lives only in the background's in-memory `connectedSites` map, so Settings
|
||||||
|
never showed it and the user could not end it; `AUTISTMASK_REMOVE_SITE`, sent
|
||||||
|
on every remove, did nothing. Settings now asks the background for those sites
|
||||||
|
(`AUTISTMASK_GET_CONNECTED_SITES`) and lists them under Connected Sites.
|
||||||
|
Removing a site from Allowed Sites or Connected Sites drops its remembered
|
||||||
|
entry under every address and sends `AUTISTMASK_REMOVE_SITE` with the
|
||||||
|
hostname; the background deletes every `connectedSites` entry for that
|
||||||
|
hostname and sends `accountsChanged` with an empty list to its open tabs. Only
|
||||||
|
the extension's own pages may send either message. Removing a denied site no
|
||||||
|
longer sends it, since forgetting a refusal ends no connection.
|
||||||
|
- 2026-10-04: Removing an address or deleting a wallet ends every site
|
||||||
|
connection approved without "Remember" for the addresses removed
|
||||||
|
([#245](https://git.eeqj.de/sneak/AutistMask/issues/245)). Such a connection
|
||||||
|
lives only in the background's in-memory `connectedSites` map. Both removal
|
||||||
|
paths dropped the remembered `allowedSites`/`deniedSites` entries, but nothing
|
||||||
|
told the background, so its entry was cleared only as a side effect: every
|
||||||
|
change of active address empties the whole map, and removing the active
|
||||||
|
address changes it. `dropSitePermissions()` in `src/shared/walletDelete.js`,
|
||||||
|
shared by both paths, now also sends `AUTISTMASK_ADDRESSES_REMOVED` with the
|
||||||
|
removed addresses, and the background deletes their `connectedSites` entries;
|
||||||
|
only the extension's own pages may send it.
|
||||||
- 2026-10-03: The typed-data signing screen warns for a token permission, and
|
- 2026-10-03: The typed-data signing screen warns for a token permission, and
|
||||||
names the primary type ethers signs
|
names the primary type ethers signs
|
||||||
([#400](https://git.eeqj.de/sneak/AutistMask/issues/400)). A Permit or Permit2
|
([#400](https://git.eeqj.de/sneak/AutistMask/issues/400)). A Permit or Permit2
|
||||||
@@ -173,6 +363,20 @@ but the review is broader than any of them.
|
|||||||
standalone storage entry, never part of the versioned `autistmask` profile, so
|
standalone storage entry, never part of the versioned `autistmask` profile, so
|
||||||
the state schema is untouched and no existing profile is affected.
|
the state schema is untouched and no existing profile is affected.
|
||||||
|
|
||||||
|
- 2026-09-21: `README.md` no longer says a genuine zero always renders `0.0000`
|
||||||
|
([#369](https://git.eeqj.de/sneak/AutistMask/issues/369)). The amount rule
|
||||||
|
still renders one as `0.0000`, but two swap lines say a zero in words instead:
|
||||||
|
`Min. received` reads `None (no minimum guaranteed)` for a zero minimum, and
|
||||||
|
`Amount` reads `All available (V4 open delta)` when the amount it shows is a
|
||||||
|
V4 exact-in `amountIn` of zero. A new list says what the decoded ERC-20 and
|
||||||
|
swap amount lines on the transaction approval screen can read: a formatted
|
||||||
|
quantity, base units with decimals unknown, `Unlimited`,
|
||||||
|
`All available (V4 open delta)` and `None (no minimum guaranteed)`, which a
|
||||||
|
zero `minBalance` on a `BALANCE_CHECK_ERC20` step now reads instead of
|
||||||
|
`0.0000` at a known scale. The README also names
|
||||||
|
`Unknown (not named in the calldata)` on the swap's token lines, and points to
|
||||||
|
SignApproval for the token permission warning's own wording. Docs only.
|
||||||
|
|
||||||
- 2026-08-30: An address no longer wraps, or is shortened to fit, in any of the
|
- 2026-08-30: An address no longer wraps, or is shortened to fit, in any of the
|
||||||
common views ([#380](https://git.eeqj.de/sneak/AutistMask/issues/380)). The
|
common views ([#380](https://git.eeqj.de/sneak/AutistMask/issues/380)). The
|
||||||
wallet list was the reported case: the address shared one row with the
|
wallet list was the reported case: the address shared one row with the
|
||||||
|
|||||||
+5
-3
@@ -285,11 +285,13 @@ not appear and may be permanently lost.
|
|||||||
AutistMask injects a standard `window.ethereum` provider (EIP-1193) into web
|
AutistMask injects a standard `window.ethereum` provider (EIP-1193) into web
|
||||||
pages. When a site requests access to your wallet:
|
pages. When a site requests access to your wallet:
|
||||||
|
|
||||||
1. A popup appears showing the site's hostname and the address that will be
|
1. A popup appears showing the site's origin (its scheme, host and port, for
|
||||||
shared.
|
example `https://app.example`) and the address that will be shared.
|
||||||
2. Click "Allow" to connect or "Deny" to reject.
|
2. Click "Allow" to connect or "Deny" to reject.
|
||||||
3. Optionally check "Remember my choice for this site" to skip the prompt next
|
3. Optionally check "Remember my choice for this site" to skip the prompt next
|
||||||
time.
|
time. The choice applies to that exact origin only: a choice remembered for
|
||||||
|
`https://app.example` does not cover `http://app.example` or another port of
|
||||||
|
the same host, which ask again.
|
||||||
|
|
||||||
When a connected site requests a transaction, a separate approval popup appears
|
When a connected site requests a transaction, a separate approval popup appears
|
||||||
showing the transaction details (from, to, value, data, network fee, network and
|
showing the transaction details (from, to, value, data, network fee, network and
|
||||||
|
|||||||
+2
-2
@@ -6,8 +6,8 @@
|
|||||||
"license": "GPL-3.0",
|
"license": "GPL-3.0",
|
||||||
"private": true,
|
"private": true,
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"test": "jest --forceExit",
|
"test": "jest --forceExit --maxWorkers=3",
|
||||||
"test:verbose": "jest --forceExit --verbose",
|
"test:verbose": "jest --forceExit --maxWorkers=3 --verbose",
|
||||||
"build": "node build.js",
|
"build": "node build.js",
|
||||||
"lint": "eslint . && prettier --check .",
|
"lint": "eslint . && prettier --check .",
|
||||||
"fmt": "prettier --write .",
|
"fmt": "prettier --write .",
|
||||||
|
|||||||
+8
-5
@@ -1,11 +1,14 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# script/test: run the test suite.
|
# script/test: run the test suite.
|
||||||
#
|
#
|
||||||
# The timeout bounds a hung suite; it is not a performance budget. On a
|
# jest runs three worker processes (package.json), not one per CPU core: on a
|
||||||
# developer host the suite finishes in about 8s and REPO_POLICIES' 30s cap is
|
# many-core shared host one per core took gigabytes of RAM per run.
|
||||||
# the bound. Inside the image the same suite also pays a cold jest cache and
|
#
|
||||||
# shares the runner with the rest of the build, which is not what that budget
|
# The timeout bounds a hung suite; it is not a performance budget. On the busy
|
||||||
# describes, so the Dockerfile raises the bound through
|
# shared build host the suite takes 8-13s with three workers, inside
|
||||||
|
# REPO_POLICIES' 20s budget. Inside the image the same suite also pays a cold
|
||||||
|
# jest cache and shares the runner with the rest of the build, which is not what
|
||||||
|
# that budget describes, so the Dockerfile raises the bound through
|
||||||
# AUTISTMASK_TEST_TIMEOUT. A cap a healthy suite can trip on a cold cache
|
# AUTISTMASK_TEST_TIMEOUT. A cap a healthy suite can trip on a cold cache
|
||||||
# produces a red that means nothing, and teaches "just run it again".
|
# produces a red that means nothing, and teaches "just run it again".
|
||||||
set -eu
|
set -eu
|
||||||
|
|||||||
+189
-62
@@ -57,9 +57,13 @@ const windowsNs = windowsApi();
|
|||||||
const actionNs = actionApi();
|
const actionNs = actionApi();
|
||||||
|
|
||||||
// Connected sites (in-memory, non-persisted): { "origin:address": true }
|
// Connected sites (in-memory, non-persisted): { "origin:address": true }
|
||||||
|
//
|
||||||
|
// A site is its full origin (scheme://host[:port]), here and in the
|
||||||
|
// remembered allowedSites/deniedSites lists alike: a grant to
|
||||||
|
// https://dapp.example says nothing about http://dapp.example or another port.
|
||||||
const connectedSites = {};
|
const connectedSites = {};
|
||||||
|
|
||||||
// Pending approval requests: { id: { origin, hostname, resolve } }
|
// Pending approval requests: { id: { origin, resolve } }
|
||||||
const pendingApprovals = {};
|
const pendingApprovals = {};
|
||||||
|
|
||||||
// One transaction approval at a time, wallet-wide.
|
// One transaction approval at a time, wallet-wide.
|
||||||
@@ -83,7 +87,8 @@ const pendingApprovals = {};
|
|||||||
// authority on a nonce the network has not accepted, which an abandoned
|
// authority on a nonce the network has not accepted, which an abandoned
|
||||||
// approval then leaves a hole in.
|
// approval then leaves a hole in.
|
||||||
//
|
//
|
||||||
// Sign approvals are not gated: a signature consumes no nonce.
|
// Sign approvals do not take this slot: a signature consumes no nonce. They are
|
||||||
|
// limited per site instead; see findPendingApproval().
|
||||||
//
|
//
|
||||||
// The slot is null when free, and otherwise the handle of the request holding
|
// The slot is null when free, and otherwise the handle of the request holding
|
||||||
// it. Once that request has raised its approval the handle carries the
|
// it. Once that request has raised its approval the handle carries the
|
||||||
@@ -95,7 +100,7 @@ let txApprovalSlot = null;
|
|||||||
|
|
||||||
// EIP-1474 "resource unavailable": the standard code for a request that is
|
// EIP-1474 "resource unavailable": the standard code for a request that is
|
||||||
// refused because another one is already pending.
|
// refused because another one is already pending.
|
||||||
const TX_APPROVAL_PENDING_CODE = -32002;
|
const APPROVAL_PENDING_CODE = -32002;
|
||||||
|
|
||||||
// True at every moment this can be sent: the slot is taken immediately before
|
// True at every moment this can be sent: the slot is taken immediately before
|
||||||
// the transaction is populated, so the other request is either being prepared
|
// the transaction is populated, so the other request is either being prepared
|
||||||
@@ -132,6 +137,22 @@ function releaseTxApprovalSlotFor(approvalId) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// One site-connection approval and one sign approval per site at a time: a
|
||||||
|
// page that asks again before the user has answered is refused with the code
|
||||||
|
// above instead of opening another window, so it cannot bury the user in
|
||||||
|
// prompts. The pending approval itself holds the place, so a caller must test
|
||||||
|
// this and raise its approval with nothing awaited in between.
|
||||||
|
function findPendingApproval(origin, type) {
|
||||||
|
return Object.values(pendingApprovals).find(
|
||||||
|
(approval) => approval.origin === origin && approval.type === type,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const APPROVAL_PENDING_MESSAGE =
|
||||||
|
"AutistMask is already waiting for your answer to a request of this kind" +
|
||||||
|
" from this site, so this one was not shown. Please answer that one," +
|
||||||
|
" then send this one again.";
|
||||||
|
|
||||||
// Nonces this worker has already handed to the node, per chain and address.
|
// Nonces this worker has already handed to the node, per chain and address.
|
||||||
// This is the wallet's own knowledge that a nonce is spent, and it is checked
|
// This is the wallet's own knowledge that a nonce is spent, and it is checked
|
||||||
// before a broadcast rather than after: a node's pending count can lag a
|
// before a broadcast rather than after: a node's pending count can lag a
|
||||||
@@ -284,7 +305,12 @@ async function proxyRpc(method, params) {
|
|||||||
return json.result;
|
return json.result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The site-connection approval the toolbar popup is set to open, or null while
|
||||||
|
// it opens the wallet. Set only by resetPopupUrl() and showInToolbarPopup().
|
||||||
|
let toolbarPopupApprovalId = null;
|
||||||
|
|
||||||
function resetPopupUrl() {
|
function resetPopupUrl() {
|
||||||
|
toolbarPopupApprovalId = null;
|
||||||
if (actionNs && typeof actionNs.setPopup === "function") {
|
if (actionNs && typeof actionNs.setPopup === "function") {
|
||||||
actionNs.setPopup({ popup: "src/popup/index.html" });
|
actionNs.setPopup({ popup: "src/popup/index.html" });
|
||||||
}
|
}
|
||||||
@@ -459,29 +485,36 @@ async function openApprovalWindow(id) {
|
|||||||
|
|
||||||
// Open an approval popup and return a promise that resolves with the user decision.
|
// Open an approval popup and return a promise that resolves with the user decision.
|
||||||
// Prefers the browser-action popup (anchored to toolbar, no macOS Space switch).
|
// Prefers the browser-action popup (anchored to toolbar, no macOS Space switch).
|
||||||
function requestApproval(origin, hostname) {
|
function requestApproval(origin) {
|
||||||
return new Promise((resolve) => {
|
return new Promise((resolve) => {
|
||||||
const id = crypto.randomUUID();
|
const id = crypto.randomUUID();
|
||||||
pendingApprovals[id] = { id, origin, hostname, resolve };
|
pendingApprovals[id] = { id, origin, resolve, type: "site" };
|
||||||
|
|
||||||
if (actionNs && typeof actionNs.openPopup === "function") {
|
if (actionNs && typeof actionNs.openPopup === "function") {
|
||||||
actionNs.setPopup({
|
showInToolbarPopup(id);
|
||||||
popup: "src/popup/index.html?approval=" + id,
|
|
||||||
});
|
|
||||||
try {
|
|
||||||
const result = actionNs.openPopup();
|
|
||||||
if (result && typeof result.catch === "function") {
|
|
||||||
result.catch(() => openApprovalWindow(id));
|
|
||||||
}
|
|
||||||
} catch {
|
|
||||||
openApprovalWindow(id);
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
openApprovalWindow(id);
|
openApprovalWindow(id);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Show a site-connection approval in the toolbar popup, or in a separate popup
|
||||||
|
// window when the browser will not open the toolbar popup.
|
||||||
|
function showInToolbarPopup(id) {
|
||||||
|
toolbarPopupApprovalId = id;
|
||||||
|
actionNs.setPopup({
|
||||||
|
popup: "src/popup/index.html?approval=" + id,
|
||||||
|
});
|
||||||
|
try {
|
||||||
|
const result = actionNs.openPopup();
|
||||||
|
if (result && typeof result.catch === "function") {
|
||||||
|
result.catch(() => openApprovalWindow(id));
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
openApprovalWindow(id);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Open a tx-approval popup and return a promise that resolves with txHash or error.
|
// Open a tx-approval popup and return a promise that resolves with txHash or error.
|
||||||
// Uses windows.create() directly because tx approvals are triggered programmatically
|
// Uses windows.create() directly because tx approvals are triggered programmatically
|
||||||
// (from a dApp RPC call), not from a user gesture, so action.openPopup() is
|
// (from a dApp RPC call), not from a user gesture, so action.openPopup() is
|
||||||
@@ -495,13 +528,12 @@ function requestApproval(origin, hostname) {
|
|||||||
// screen never named.
|
// screen never named.
|
||||||
// `slot` is the transaction-approval slot its caller holds. Handing the
|
// `slot` is the transaction-approval slot its caller holds. Handing the
|
||||||
// approval's id to it is what makes retiring the approval free the slot.
|
// approval's id to it is what makes retiring the approval free the slot.
|
||||||
function requestTxApproval(origin, hostname, approvedTx, approvedFrom, slot) {
|
function requestTxApproval(origin, approvedTx, approvedFrom, slot) {
|
||||||
return new Promise((resolve) => {
|
return new Promise((resolve) => {
|
||||||
const id = crypto.randomUUID();
|
const id = crypto.randomUUID();
|
||||||
pendingApprovals[id] = {
|
pendingApprovals[id] = {
|
||||||
id,
|
id,
|
||||||
origin,
|
origin,
|
||||||
hostname,
|
|
||||||
approvedTx,
|
approvedTx,
|
||||||
approvedFrom,
|
approvedFrom,
|
||||||
resolve,
|
resolve,
|
||||||
@@ -517,13 +549,12 @@ function requestTxApproval(origin, hostname, approvedTx, approvedFrom, slot) {
|
|||||||
// Uses windows.create() directly because sign approvals are triggered programmatically
|
// Uses windows.create() directly because sign approvals are triggered programmatically
|
||||||
// (from a dApp RPC call), not from a user gesture, so action.openPopup() is
|
// (from a dApp RPC call), not from a user gesture, so action.openPopup() is
|
||||||
// unreliable in this context.
|
// unreliable in this context.
|
||||||
function requestSignApproval(origin, hostname, signParams, approvedFrom) {
|
function requestSignApproval(origin, signParams, approvedFrom) {
|
||||||
return new Promise((resolve) => {
|
return new Promise((resolve) => {
|
||||||
const id = crypto.randomUUID();
|
const id = crypto.randomUUID();
|
||||||
pendingApprovals[id] = {
|
pendingApprovals[id] = {
|
||||||
id,
|
id,
|
||||||
origin,
|
origin,
|
||||||
hostname,
|
|
||||||
signParams,
|
signParams,
|
||||||
approvedFrom,
|
approvedFrom,
|
||||||
resolve,
|
resolve,
|
||||||
@@ -601,11 +632,11 @@ runtime.onConnect.addListener((port) => {
|
|||||||
// in the worker — a balance refresh in flight, another site's approval — has
|
// in the worker — a balance refresh in flight, another site's approval — has
|
||||||
// gone on running the whole time. Loading here used to replace the very
|
// gone on running the whole time. Loading here used to replace the very
|
||||||
// objects that work was holding.
|
// objects that work was holding.
|
||||||
async function rememberSiteChoice(field, address, hostname) {
|
async function rememberSiteChoice(field, address, origin) {
|
||||||
await updateState((s) => {
|
await updateState((s) => {
|
||||||
if (!s[field][address]) s[field][address] = [];
|
if (!s[field][address]) s[field][address] = [];
|
||||||
if (!s[field][address].includes(hostname)) {
|
if (!s[field][address].includes(origin)) {
|
||||||
s[field][address].push(hostname);
|
s[field][address].push(origin);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -618,12 +649,11 @@ async function handleConnectionRequest(origin) {
|
|||||||
return { error: { message: "No accounts available" } };
|
return { error: { message: "No accounts available" } };
|
||||||
}
|
}
|
||||||
|
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
const denied = s.deniedSites[activeAddress] || [];
|
const denied = s.deniedSites[activeAddress] || [];
|
||||||
|
|
||||||
// Check denied list
|
// Check denied list
|
||||||
if (denied.includes(hostname)) {
|
if (denied.includes(origin)) {
|
||||||
return {
|
return {
|
||||||
error: {
|
error: {
|
||||||
code: 4001,
|
code: 4001,
|
||||||
@@ -634,25 +664,50 @@ async function handleConnectionRequest(origin) {
|
|||||||
|
|
||||||
// Check allowed list or in-memory connected
|
// Check allowed list or in-memory connected
|
||||||
if (
|
if (
|
||||||
allowed.includes(hostname) ||
|
allowed.includes(origin) ||
|
||||||
connectedSites[origin + ":" + activeAddress]
|
connectedSites[origin + ":" + activeAddress]
|
||||||
) {
|
) {
|
||||||
return { result: [activeAddress] };
|
return { result: [activeAddress] };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const pending = findPendingApproval(origin, "site");
|
||||||
|
if (pending) {
|
||||||
|
// A toolbar popup that closed before it connected leaves its prompt
|
||||||
|
// pending, and once the toolbar popup is set to open something else
|
||||||
|
// nothing shows that prompt: the site would be refused until the
|
||||||
|
// address changed. Show it again. A prompt in a window or in a
|
||||||
|
// connected popup is settled when that closes, and one the toolbar
|
||||||
|
// popup is still set to open is a click away, so those are left alone.
|
||||||
|
if (
|
||||||
|
actionNs &&
|
||||||
|
typeof actionNs.openPopup === "function" &&
|
||||||
|
!pending.windowId &&
|
||||||
|
!pending.portConnected &&
|
||||||
|
toolbarPopupApprovalId !== pending.id
|
||||||
|
) {
|
||||||
|
showInToolbarPopup(pending.id);
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
error: {
|
||||||
|
code: APPROVAL_PENDING_CODE,
|
||||||
|
message: APPROVAL_PENDING_MESSAGE,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
// Open approval popup
|
// Open approval popup
|
||||||
const decision = await requestApproval(origin, hostname);
|
const decision = await requestApproval(origin);
|
||||||
|
|
||||||
if (decision.approved) {
|
if (decision.approved) {
|
||||||
if (decision.remember) {
|
if (decision.remember) {
|
||||||
await rememberSiteChoice("allowedSites", activeAddress, hostname);
|
await rememberSiteChoice("allowedSites", activeAddress, origin);
|
||||||
} else {
|
} else {
|
||||||
connectedSites[origin + ":" + activeAddress] = true;
|
connectedSites[origin + ":" + activeAddress] = true;
|
||||||
}
|
}
|
||||||
return { result: [activeAddress] };
|
return { result: [activeAddress] };
|
||||||
} else {
|
} else {
|
||||||
if (decision.remember) {
|
if (decision.remember) {
|
||||||
await rememberSiteChoice("deniedSites", activeAddress, hostname);
|
await rememberSiteChoice("deniedSites", activeAddress, origin);
|
||||||
}
|
}
|
||||||
return {
|
return {
|
||||||
error: {
|
error: {
|
||||||
@@ -698,10 +753,9 @@ async function handleRpc(method, params, origin) {
|
|||||||
const s = await getState();
|
const s = await getState();
|
||||||
const activeAddress = activeAddressOf(s);
|
const activeAddress = activeAddressOf(s);
|
||||||
if (!activeAddress) return { result: [] };
|
if (!activeAddress) return { result: [] };
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
if (
|
if (
|
||||||
allowed.includes(hostname) ||
|
allowed.includes(origin) ||
|
||||||
connectedSites[origin + ":" + activeAddress]
|
connectedSites[origin + ":" + activeAddress]
|
||||||
) {
|
) {
|
||||||
return { result: [activeAddress] };
|
return { result: [activeAddress] };
|
||||||
@@ -731,10 +785,9 @@ async function handleRpc(method, params, origin) {
|
|||||||
// [TESTNET] banner under a user who believed they were on Sepolia.
|
// [TESTNET] banner under a user who believed they were on Sepolia.
|
||||||
const s = await getState();
|
const s = await getState();
|
||||||
const activeAddress = activeAddressOf(s);
|
const activeAddress = activeAddressOf(s);
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
if (
|
if (
|
||||||
!allowed.includes(hostname) &&
|
!allowed.includes(origin) &&
|
||||||
!connectedSites[origin + ":" + activeAddress]
|
!connectedSites[origin + ":" + activeAddress]
|
||||||
) {
|
) {
|
||||||
return { error: { code: 4100, message: "Unauthorized" } };
|
return { error: { code: 4100, message: "Unauthorized" } };
|
||||||
@@ -806,10 +859,9 @@ async function handleRpc(method, params, origin) {
|
|||||||
if (method === "wallet_getPermissions") {
|
if (method === "wallet_getPermissions") {
|
||||||
const s = await getState();
|
const s = await getState();
|
||||||
const activeAddress = activeAddressOf(s);
|
const activeAddress = activeAddressOf(s);
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
const isConnected =
|
const isConnected =
|
||||||
allowed.includes(hostname) ||
|
allowed.includes(origin) ||
|
||||||
connectedSites[origin + ":" + activeAddress];
|
connectedSites[origin + ":" + activeAddress];
|
||||||
if (!isConnected || !activeAddress) {
|
if (!isConnected || !activeAddress) {
|
||||||
return { result: [] };
|
return { result: [] };
|
||||||
@@ -835,10 +887,9 @@ async function handleRpc(method, params, origin) {
|
|||||||
if (!activeAddress)
|
if (!activeAddress)
|
||||||
return { error: { message: "No accounts available" } };
|
return { error: { message: "No accounts available" } };
|
||||||
|
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
if (
|
if (
|
||||||
!allowed.includes(hostname) &&
|
!allowed.includes(origin) &&
|
||||||
!connectedSites[origin + ":" + activeAddress]
|
!connectedSites[origin + ":" + activeAddress]
|
||||||
) {
|
) {
|
||||||
return { error: { code: 4100, message: "Unauthorized" } };
|
return { error: { code: 4100, message: "Unauthorized" } };
|
||||||
@@ -868,9 +919,16 @@ async function handleRpc(method, params, origin) {
|
|||||||
"Only proceed if you fully understand what you are signing.";
|
"Only proceed if you fully understand what you are signing.";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (findPendingApproval(origin, "sign")) {
|
||||||
|
return {
|
||||||
|
error: {
|
||||||
|
code: APPROVAL_PENDING_CODE,
|
||||||
|
message: APPROVAL_PENDING_MESSAGE,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
const decision = await requestSignApproval(
|
const decision = await requestSignApproval(
|
||||||
origin,
|
origin,
|
||||||
hostname,
|
|
||||||
signParams,
|
signParams,
|
||||||
activeAddress,
|
activeAddress,
|
||||||
);
|
);
|
||||||
@@ -884,10 +942,9 @@ async function handleRpc(method, params, origin) {
|
|||||||
if (!activeAddress)
|
if (!activeAddress)
|
||||||
return { error: { message: "No accounts available" } };
|
return { error: { message: "No accounts available" } };
|
||||||
|
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
if (
|
if (
|
||||||
!allowed.includes(hostname) &&
|
!allowed.includes(origin) &&
|
||||||
!connectedSites[origin + ":" + activeAddress]
|
!connectedSites[origin + ":" + activeAddress]
|
||||||
) {
|
) {
|
||||||
return { error: { code: 4100, message: "Unauthorized" } };
|
return { error: { code: 4100, message: "Unauthorized" } };
|
||||||
@@ -903,9 +960,16 @@ async function handleRpc(method, params, origin) {
|
|||||||
},
|
},
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
if (findPendingApproval(origin, "sign")) {
|
||||||
|
return {
|
||||||
|
error: {
|
||||||
|
code: APPROVAL_PENDING_CODE,
|
||||||
|
message: APPROVAL_PENDING_MESSAGE,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
const decision = await requestSignApproval(
|
const decision = await requestSignApproval(
|
||||||
origin,
|
origin,
|
||||||
hostname,
|
|
||||||
signParams,
|
signParams,
|
||||||
activeAddress,
|
activeAddress,
|
||||||
);
|
);
|
||||||
@@ -932,7 +996,9 @@ async function handleRpc(method, params, origin) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return { error: { message: "Unsupported method: " + method } };
|
// EIP-1193 4200 lets a site tell "this wallet does not implement that"
|
||||||
|
// from "that call failed", and fall back.
|
||||||
|
return { error: { code: 4200, message: "Unsupported method: " + method } };
|
||||||
}
|
}
|
||||||
|
|
||||||
// The body of eth_sendTransaction, from the connection check through to the
|
// The body of eth_sendTransaction, from the connection check through to the
|
||||||
@@ -944,10 +1010,9 @@ async function handleSendTransaction(params, origin) {
|
|||||||
const activeAddress = activeAddressOf(s);
|
const activeAddress = activeAddressOf(s);
|
||||||
if (!activeAddress) return { error: { message: "No accounts available" } };
|
if (!activeAddress) return { error: { message: "No accounts available" } };
|
||||||
|
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const allowed = s.allowedSites[activeAddress] || [];
|
const allowed = s.allowedSites[activeAddress] || [];
|
||||||
if (
|
if (
|
||||||
!allowed.includes(hostname) &&
|
!allowed.includes(origin) &&
|
||||||
!connectedSites[origin + ":" + activeAddress]
|
!connectedSites[origin + ":" + activeAddress]
|
||||||
) {
|
) {
|
||||||
return { error: { code: 4100, message: "Unauthorized" } };
|
return { error: { code: 4100, message: "Unauthorized" } };
|
||||||
@@ -974,7 +1039,7 @@ async function handleSendTransaction(params, origin) {
|
|||||||
if (!slot) {
|
if (!slot) {
|
||||||
return {
|
return {
|
||||||
error: {
|
error: {
|
||||||
code: TX_APPROVAL_PENDING_CODE,
|
code: APPROVAL_PENDING_CODE,
|
||||||
message: TX_APPROVAL_PENDING_MESSAGE,
|
message: TX_APPROVAL_PENDING_MESSAGE,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
@@ -1021,7 +1086,6 @@ async function handleSendTransaction(params, origin) {
|
|||||||
|
|
||||||
const decision = await requestTxApproval(
|
const decision = await requestTxApproval(
|
||||||
origin,
|
origin,
|
||||||
hostname,
|
|
||||||
approvedTx,
|
approvedTx,
|
||||||
activeAddress,
|
activeAddress,
|
||||||
slot,
|
slot,
|
||||||
@@ -1095,10 +1159,9 @@ async function broadcastAccountsChanged() {
|
|||||||
}
|
}
|
||||||
for (const tab of tabs) {
|
for (const tab of tabs) {
|
||||||
const origin = tab.url ? new URL(tab.url).origin : "";
|
const origin = tab.url ? new URL(tab.url).origin : "";
|
||||||
const hostname = extractHostname(origin);
|
|
||||||
const hasPermission =
|
const hasPermission =
|
||||||
activeAddress &&
|
activeAddress &&
|
||||||
(allowed.includes(hostname) ||
|
(allowed.includes(origin) ||
|
||||||
connectedSites[origin + ":" + activeAddress]);
|
connectedSites[origin + ":" + activeAddress]);
|
||||||
// Same as chainChanged above: a tab without our content script
|
// Same as chainChanged above: a tab without our content script
|
||||||
// rejects, and that is expected rather than a fault.
|
// rejects, and that is expected rather than a fault.
|
||||||
@@ -1110,6 +1173,24 @@ async function broadcastAccountsChanged() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Tell every open tab of a site Settings removed that it has no account.
|
||||||
|
async function broadcastSiteRemoved(origin) {
|
||||||
|
let tabs;
|
||||||
|
try {
|
||||||
|
tabs = await tabsQuery({});
|
||||||
|
} catch {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
for (const tab of tabs) {
|
||||||
|
if (!tab.url || new URL(tab.url).origin !== origin) continue;
|
||||||
|
tabsSendMessage(tab.id, {
|
||||||
|
type: "AUTISTMASK_EVENT",
|
||||||
|
eventName: "accountsChanged",
|
||||||
|
data: [],
|
||||||
|
}).catch(() => {});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Background balance refresh: every 60 seconds when the popup isn't open.
|
// Background balance refresh: every 60 seconds when the popup isn't open.
|
||||||
// When the popup IS open, its 10-second interval keeps lastBalanceRefresh
|
// When the popup IS open, its 10-second interval keeps lastBalanceRefresh
|
||||||
// fresh, so this naturally skips.
|
// fresh, so this naturally skips.
|
||||||
@@ -1268,18 +1349,29 @@ if (windowsNs && windowsNs.onRemoved) {
|
|||||||
// Listen for messages from content scripts and popup
|
// Listen for messages from content scripts and popup
|
||||||
runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||||
if (msg.type === "AUTISTMASK_RPC") {
|
if (msg.type === "AUTISTMASK_RPC") {
|
||||||
// Derive origin from trusted sender info to prevent origin spoofing.
|
// The origin is the one the browser reports for the sender, never one
|
||||||
// Chrome MV3 provides sender.origin; Firefox MV2 fallback uses sender.tab.url.
|
// the message carries. Firefox before 126 gives no sender.origin, so
|
||||||
let trustedOrigin = msg.origin; // fallback only if sender info unavailable
|
// the origin of sender.url is used: the frame that sent the message,
|
||||||
if (sender.origin) {
|
// not the tab's page, which may be another site embedding that
|
||||||
trustedOrigin = sender.origin;
|
// frame. With neither, the request is refused.
|
||||||
} else if (sender.tab && sender.tab.url) {
|
let trustedOrigin = sender.origin;
|
||||||
|
if (!trustedOrigin && sender.url) {
|
||||||
try {
|
try {
|
||||||
trustedOrigin = new URL(sender.tab.url).origin;
|
trustedOrigin = new URL(sender.url).origin;
|
||||||
} catch {
|
} catch {
|
||||||
// keep fallback
|
// an unparseable URL leaves the origin unknown
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (!trustedOrigin) {
|
||||||
|
sendResponse({
|
||||||
|
error: {
|
||||||
|
code: 4100,
|
||||||
|
message:
|
||||||
|
"The wallet could not tell which site sent this request.",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
handleRpc(msg.method, msg.params, trustedOrigin)
|
handleRpc(msg.method, msg.params, trustedOrigin)
|
||||||
.then((response) => {
|
.then((response) => {
|
||||||
sendResponse(response);
|
sendResponse(response);
|
||||||
@@ -1305,6 +1397,9 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
"AUTISTMASK_GET_APPROVAL",
|
"AUTISTMASK_GET_APPROVAL",
|
||||||
"AUTISTMASK_TX_RESPONSE",
|
"AUTISTMASK_TX_RESPONSE",
|
||||||
"AUTISTMASK_SIGN_RESPONSE",
|
"AUTISTMASK_SIGN_RESPONSE",
|
||||||
|
"AUTISTMASK_ADDRESSES_REMOVED",
|
||||||
|
"AUTISTMASK_GET_CONNECTED_SITES",
|
||||||
|
"AUTISTMASK_REMOVE_SITE",
|
||||||
];
|
];
|
||||||
if (POPUP_ONLY_TYPES.includes(msg.type) && !isExtensionSender(sender)) {
|
if (POPUP_ONLY_TYPES.includes(msg.type) && !isExtensionSender(sender)) {
|
||||||
sendResponse({ error: "Unauthorized sender" });
|
sendResponse({ error: "Unauthorized sender" });
|
||||||
@@ -1314,10 +1409,7 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
if (msg.type === "AUTISTMASK_GET_APPROVAL") {
|
if (msg.type === "AUTISTMASK_GET_APPROVAL") {
|
||||||
const approval = pendingApprovals[msg.id];
|
const approval = pendingApprovals[msg.id];
|
||||||
if (approval) {
|
if (approval) {
|
||||||
const resp = {
|
const resp = { origin: approval.origin };
|
||||||
hostname: approval.hostname,
|
|
||||||
origin: approval.origin,
|
|
||||||
};
|
|
||||||
if (approval.type === "tx") {
|
if (approval.type === "tx") {
|
||||||
resp.type = "tx";
|
resp.type = "tx";
|
||||||
// The populated transaction, and the address it was raised
|
// The populated transaction, and the address it was raised
|
||||||
@@ -1332,7 +1424,9 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
resp.approvedFrom = approval.approvedFrom;
|
resp.approvedFrom = approval.approvedFrom;
|
||||||
}
|
}
|
||||||
// Flag if the requesting domain is on the phishing blocklist.
|
// Flag if the requesting domain is on the phishing blocklist.
|
||||||
resp.isPhishingDomain = isPhishingDomain(approval.hostname);
|
resp.isPhishingDomain = isPhishingDomain(
|
||||||
|
extractHostname(approval.origin),
|
||||||
|
);
|
||||||
sendResponse(resp);
|
sendResponse(resp);
|
||||||
} else {
|
} else {
|
||||||
sendResponse(null);
|
sendResponse(null);
|
||||||
@@ -1647,8 +1741,41 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The popup removed these addresses, so no site stays connected to them.
|
||||||
|
// A connectedSites key is origin + ":" + address, and an origin can carry
|
||||||
|
// a port, so the address is what follows the last colon.
|
||||||
|
if (msg.type === "AUTISTMASK_ADDRESSES_REMOVED") {
|
||||||
|
const removed = Array.isArray(msg.addresses) ? msg.addresses : [];
|
||||||
|
for (const key of Object.keys(connectedSites)) {
|
||||||
|
const address = key.slice(key.lastIndexOf(":") + 1);
|
||||||
|
if (removed.some((a) => sameAddress(a, address))) {
|
||||||
|
delete connectedSites[key];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Settings lists the sites connected without "Remember", which only this
|
||||||
|
// worker knows. The origin is what precedes the key's last colon.
|
||||||
|
if (msg.type === "AUTISTMASK_GET_CONNECTED_SITES") {
|
||||||
|
sendResponse(
|
||||||
|
Object.keys(connectedSites).map((key) =>
|
||||||
|
key.slice(0, key.lastIndexOf(":")),
|
||||||
|
),
|
||||||
|
);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Settings removed this site (msg.origin) and has already dropped its
|
||||||
|
// remembered entries. Its connections approved without "Remember" end
|
||||||
|
// here, under every address, and its open tabs are told it has no account.
|
||||||
if (msg.type === "AUTISTMASK_REMOVE_SITE") {
|
if (msg.type === "AUTISTMASK_REMOVE_SITE") {
|
||||||
// Popup already saved state; nothing else needed
|
for (const key of Object.keys(connectedSites)) {
|
||||||
|
if (key.slice(0, key.lastIndexOf(":")) === msg.origin) {
|
||||||
|
delete connectedSites[key];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
broadcastSiteRemoved(msg.origin);
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -30,7 +30,6 @@ window.addEventListener("message", (event) => {
|
|||||||
id,
|
id,
|
||||||
method,
|
method,
|
||||||
params,
|
params,
|
||||||
origin: location.origin,
|
|
||||||
})
|
})
|
||||||
.then((response) => {
|
.then((response) => {
|
||||||
if (response) {
|
if (response) {
|
||||||
|
|||||||
@@ -31,11 +31,12 @@
|
|||||||
// an error instead of accepting the refusal.
|
// an error instead of accepting the refusal.
|
||||||
//
|
//
|
||||||
// Whatever code arrived is passed through verbatim rather than being
|
// Whatever code arrived is passed through verbatim rather than being
|
||||||
// matched against a list: the extension emits 4001, 4100 and 4902 today,
|
// matched against a list: the extension emits codes such as 4001, 4100,
|
||||||
// and a code this file has never heard of is still the truth about what
|
// 4200 and 4902, and a code this file has never heard of is still the
|
||||||
// happened. An error reported with no code at all stays a plain Error —
|
// truth about what happened. An error reported with no code at all stays
|
||||||
// a ProviderRpcError whose `code` is undefined would advertise a
|
// a plain Error — a ProviderRpcError whose `code` is undefined would
|
||||||
// conformance it does not have. `message` is untouched in every case.
|
// advertise a conformance it does not have. `message` is untouched in
|
||||||
|
// every case.
|
||||||
function toPageError(error) {
|
function toPageError(error) {
|
||||||
const message = (error && error.message) || "Request failed";
|
const message = (error && error.message) || "Request failed";
|
||||||
if (error && error.code !== undefined && error.code !== null) {
|
if (error && error.code !== undefined && error.code !== null) {
|
||||||
|
|||||||
@@ -19,13 +19,9 @@
|
|||||||
// that the user did not type — the same silent substitution the visible
|
// that the user did not type — the same silent substitution the visible
|
||||||
// rejection message exists to end.
|
// rejection message exists to end.
|
||||||
|
|
||||||
// Must render on ONE line of #flash-msg, whose reserved height
|
// Must render on ONE line of #flash-msg; see showFlash() in
|
||||||
// (min-h-[1.25rem]) is exactly one line at text-xs. A string long enough to
|
// src/popup/views/helpers.js for how long that is.
|
||||||
// wrap to two lines pushes the settings view down, which the No Layout Shift
|
const DUST_THRESHOLD_MESSAGE = "Enter a whole number of gwei, zero or greater.";
|
||||||
// policy forbids. Do not lengthen this without re-running the layout test in
|
|
||||||
// tests/e2e/run.js, which measures the flash line and goes red on a shift.
|
|
||||||
const DUST_THRESHOLD_MESSAGE =
|
|
||||||
"Please enter a whole number of gwei, zero or greater.";
|
|
||||||
|
|
||||||
// Returns the threshold in gwei, or null if the input is not one.
|
// Returns the threshold in gwei, or null if the input is not one.
|
||||||
function parseDustThresholdGwei(raw) {
|
function parseDustThresholdGwei(raw) {
|
||||||
|
|||||||
+18
-11
@@ -33,7 +33,7 @@
|
|||||||
<!-- ============ FLASH MESSAGE AREA ============ -->
|
<!-- ============ FLASH MESSAGE AREA ============ -->
|
||||||
<div
|
<div
|
||||||
id="flash-msg"
|
id="flash-msg"
|
||||||
class="text-xs text-muted min-h-[1.25rem] mb-1"
|
class="text-xs text-muted min-h-[1.25rem] mb-1 truncate"
|
||||||
></div>
|
></div>
|
||||||
|
|
||||||
<!-- ============ WELCOME / FIRST USE ============ -->
|
<!-- ============ WELCOME / FIRST USE ============ -->
|
||||||
@@ -698,15 +698,13 @@
|
|||||||
You do not have enough ETH to pay the network fee for this
|
You do not have enough ETH to pay the network fee for this
|
||||||
transfer. Please add ETH to this address and try again.
|
transfer. Please add ETH to this address and try again.
|
||||||
</div>
|
</div>
|
||||||
|
<!-- Its sentence names why the fee could not be estimated,
|
||||||
|
so show() in confirmTx.js sets it. -->
|
||||||
<div
|
<div
|
||||||
id="confirm-fee-unknown-error"
|
id="confirm-fee-unknown-error"
|
||||||
class="mb-2 border border-border border-dashed p-2 text-xs"
|
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||||
style="visibility: hidden"
|
style="visibility: hidden"
|
||||||
>
|
></div>
|
||||||
The network fee could not be estimated, so this transaction
|
|
||||||
cannot be checked against your balance. Please go back and
|
|
||||||
try again.
|
|
||||||
</div>
|
|
||||||
<div class="mb-2">
|
<div class="mb-2">
|
||||||
<label class="block mb-1 text-xs">Password</label>
|
<label class="block mb-1 text-xs">Password</label>
|
||||||
<input
|
<input
|
||||||
@@ -1064,6 +1062,15 @@
|
|||||||
<div id="settings-allowed-sites"></div>
|
<div id="settings-allowed-sites"></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<h3 class="font-bold mb-1">Connected Sites</h3>
|
||||||
|
<p class="text-xs text-muted mb-2">
|
||||||
|
Sites you allowed without "Remember my choice".
|
||||||
|
Switching address disconnects them.
|
||||||
|
</p>
|
||||||
|
<div id="settings-connected-sites"></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<div class="bg-well p-3 mx-1 mb-3">
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
<h3 class="font-bold mb-1">Denied Sites</h3>
|
<h3 class="font-bold mb-1">Denied Sites</h3>
|
||||||
<p class="text-xs text-muted mb-2">
|
<p class="text-xs text-muted mb-2">
|
||||||
@@ -1554,7 +1561,7 @@
|
|||||||
with extreme caution.
|
with extreme caution.
|
||||||
</div>
|
</div>
|
||||||
<p class="mb-2">
|
<p class="mb-2">
|
||||||
<span id="approve-tx-hostname" class="font-bold"></span>
|
<span id="approve-tx-origin" class="font-bold"></span>
|
||||||
wants to send a transaction.
|
wants to send a transaction.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
@@ -1624,7 +1631,7 @@
|
|||||||
</div>
|
</div>
|
||||||
<div
|
<div
|
||||||
id="approve-tx-error"
|
id="approve-tx-error"
|
||||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem]"
|
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem]"
|
||||||
style="visibility: hidden"
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div class="flex justify-between">
|
<div class="flex justify-between">
|
||||||
@@ -1655,7 +1662,7 @@
|
|||||||
funds. Proceed with extreme caution.
|
funds. Proceed with extreme caution.
|
||||||
</div>
|
</div>
|
||||||
<p class="mb-2">
|
<p class="mb-2">
|
||||||
<span id="approve-sign-hostname" class="font-bold"></span>
|
<span id="approve-sign-origin" class="font-bold"></span>
|
||||||
wants you to sign a message.
|
wants you to sign a message.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
@@ -1701,7 +1708,7 @@
|
|||||||
</div>
|
</div>
|
||||||
<div
|
<div
|
||||||
id="approve-sign-error"
|
id="approve-sign-error"
|
||||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem]"
|
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem]"
|
||||||
style="visibility: hidden"
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div class="flex justify-between">
|
<div class="flex justify-between">
|
||||||
@@ -1733,7 +1740,7 @@
|
|||||||
</div>
|
</div>
|
||||||
<div class="mb-3">
|
<div class="mb-3">
|
||||||
<p class="mb-2">
|
<p class="mb-2">
|
||||||
<span id="approve-hostname" class="font-bold"></span>
|
<span id="approve-origin" class="font-bold"></span>
|
||||||
wants to connect to your wallet.
|
wants to connect to your wallet.
|
||||||
</p>
|
</p>
|
||||||
<div class="text-xs text-muted mb-1">
|
<div class="text-xs text-muted mb-1">
|
||||||
|
|||||||
@@ -28,9 +28,7 @@ function init(ctx) {
|
|||||||
$("btn-add-token-confirm").addEventListener("click", async () => {
|
$("btn-add-token-confirm").addEventListener("click", async () => {
|
||||||
const contractAddr = $("add-token-address").value.trim();
|
const contractAddr = $("add-token-address").value.trim();
|
||||||
if (!contractAddr || !contractAddr.startsWith("0x")) {
|
if (!contractAddr || !contractAddr.startsWith("0x")) {
|
||||||
showFlash(
|
showFlash("Enter a valid contract address starting with 0x.");
|
||||||
"Please enter a valid contract address starting with 0x.",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const already = state.trackedTokens.find(
|
const already = state.trackedTokens.find(
|
||||||
@@ -71,8 +69,15 @@ function init(ctx) {
|
|||||||
require("./addressDetail").show();
|
require("./addressDetail").show();
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
const detail = e.shortMessage || e.message || String(e);
|
const detail = e.shortMessage || e.message || String(e);
|
||||||
log.errorf("Token lookup failed for", contractAddr, detail);
|
log.errorf("Adding token failed for", contractAddr, detail);
|
||||||
showFlash(detail);
|
// lookupTokenInfo() rejects a contract with a one-line message
|
||||||
|
// starting "Not a valid ERC-20 token". Any other error, such as a
|
||||||
|
// failed save, can be far longer, so it is only logged.
|
||||||
|
showFlash(
|
||||||
|
detail.startsWith("Not a valid ERC-20 token")
|
||||||
|
? detail
|
||||||
|
: "Could not add the token.",
|
||||||
|
);
|
||||||
infoEl.textContent = "";
|
infoEl.textContent = "";
|
||||||
infoEl.style.visibility = "hidden";
|
infoEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -142,15 +142,13 @@ function validatePassword() {
|
|||||||
async function importMnemonic(ctx) {
|
async function importMnemonic(ctx) {
|
||||||
const mnemonic = $("wallet-mnemonic").value.trim();
|
const mnemonic = $("wallet-mnemonic").value.trim();
|
||||||
if (!mnemonic) {
|
if (!mnemonic) {
|
||||||
showFlash("Enter a recovery phrase or press the die to generate one.");
|
showFlash("Enter a recovery phrase, or press the die.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const words = mnemonic.split(/\s+/);
|
const words = mnemonic.split(/\s+/);
|
||||||
if (words.length !== 12 && words.length !== 24) {
|
if (words.length !== 12 && words.length !== 24) {
|
||||||
showFlash(
|
showFlash(
|
||||||
"Recovery phrase must be 12 or 24 words. You entered " +
|
"Recovery phrase must be 12 or 24 words, not " + words.length + ".",
|
||||||
words.length +
|
|
||||||
".",
|
|
||||||
);
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -163,14 +161,12 @@ async function importMnemonic(ctx) {
|
|||||||
const { xpub, firstAddress } = hdWalletFromMnemonic(mnemonic);
|
const { xpub, firstAddress } = hdWalletFromMnemonic(mnemonic);
|
||||||
const xpubDup = findWalletByXpub(xpub);
|
const xpubDup = findWalletByXpub(xpub);
|
||||||
if (xpubDup) {
|
if (xpubDup) {
|
||||||
showFlash(
|
showFlash("This recovery phrase is already added.");
|
||||||
"This recovery phrase is already added (" + xpubDup.name + ").",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const addrDup = findWalletByAddress(firstAddress);
|
const addrDup = findWalletByAddress(firstAddress);
|
||||||
if (addrDup) {
|
if (addrDup) {
|
||||||
showFlash("Address already exists in wallet (" + addrDup.name + ").");
|
showFlash("Address already exists in a wallet.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const encrypted = await encryptWithPassword(mnemonic, pw);
|
const encrypted = await encryptWithPassword(mnemonic, pw);
|
||||||
@@ -229,9 +225,7 @@ async function importPrivateKey(ctx) {
|
|||||||
if (!pw) return;
|
if (!pw) return;
|
||||||
const duplicate = findWalletByAddress(addr);
|
const duplicate = findWalletByAddress(addr);
|
||||||
if (duplicate) {
|
if (duplicate) {
|
||||||
showFlash(
|
showFlash("This address already exists in a wallet.");
|
||||||
"This address already exists in wallet (" + duplicate.name + ").",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const encrypted = await encryptWithPassword(key, pw);
|
const encrypted = await encryptWithPassword(key, pw);
|
||||||
@@ -258,36 +252,29 @@ async function importXprvKey(ctx) {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (!isValidXprv(xprv)) {
|
if (!isValidXprv(xprv)) {
|
||||||
showFlash(
|
showFlash("That extended private key is not valid.");
|
||||||
"That extended private key is not valid. Please check it and try again.",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (!isMasterExtendedKey(xprv)) {
|
if (!isMasterExtendedKey(xprv)) {
|
||||||
showFlash(
|
showFlash("Please paste the master key, not a child key.");
|
||||||
"That is an account-level or child key, which cannot be imported. " +
|
|
||||||
"Please paste the master extended private key for the wallet.",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
let result;
|
let result;
|
||||||
try {
|
try {
|
||||||
result = hdWalletFromXprv(xprv);
|
result = hdWalletFromXprv(xprv);
|
||||||
} catch {
|
} catch {
|
||||||
showFlash(
|
showFlash("That extended private key is not valid.");
|
||||||
"That extended private key is not valid. Please check it and try again.",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const { xpub, firstAddress } = result;
|
const { xpub, firstAddress } = result;
|
||||||
const xpubDup = findWalletByXpub(xpub);
|
const xpubDup = findWalletByXpub(xpub);
|
||||||
if (xpubDup) {
|
if (xpubDup) {
|
||||||
showFlash("This key is already added (" + xpubDup.name + ").");
|
showFlash("This key is already added.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const addrDup = findWalletByAddress(firstAddress);
|
const addrDup = findWalletByAddress(firstAddress);
|
||||||
if (addrDup) {
|
if (addrDup) {
|
||||||
showFlash("Address already exists in wallet (" + addrDup.name + ").");
|
showFlash("Address already exists in a wallet.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const pw = validatePassword();
|
const pw = validatePassword();
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ const {
|
|||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
balanceLinesForAddress,
|
balanceLinesForAddress,
|
||||||
addressDotHtml,
|
txCounterpartyHtml,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
displaySymbol,
|
displaySymbol,
|
||||||
@@ -233,16 +233,13 @@ function renderTransactions(txs) {
|
|||||||
// is shown whole; the title or ENS name, where there is one, names
|
// is shown whole; the title or ENS name, where there is one, names
|
||||||
// it on the line above rather than replacing it.
|
// it on the line above rather than replacing it.
|
||||||
const nameStr = escapeHtml(title || ensName || "");
|
const nameStr = escapeHtml(title || ensName || "");
|
||||||
const addrStr = escapeHtml(counterparty);
|
|
||||||
const dot = addressDotHtml(counterparty);
|
|
||||||
const err = tx.isError ? " (failed)" : "";
|
const err = tx.isError ? " (failed)" : "";
|
||||||
const opacity = tx.isError ? " opacity:0.5;" : "";
|
const opacity = tx.isError ? " opacity:0.5;" : "";
|
||||||
const ago = escapeHtml(timeAgo(tx.timestamp));
|
const ago = escapeHtml(timeAgo(tx.timestamp));
|
||||||
const iso = escapeHtml(isoDate(tx.timestamp));
|
const iso = escapeHtml(isoDate(tx.timestamp));
|
||||||
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
||||||
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
||||||
html += `<div class="flex justify-between"><span class="flex items-center">${dot}${nameStr}</span><span>${amountStr}</span></div>`;
|
html += txCounterpartyHtml(counterparty, nameStr, amountStr);
|
||||||
html += `<div class="am-address">${addrStr}</div>`;
|
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
i++;
|
i++;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ const {
|
|||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
flashCopyFeedback,
|
flashCopyFeedback,
|
||||||
addressDotHtml,
|
txCounterpartyHtml,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
displaySymbol,
|
displaySymbol,
|
||||||
@@ -309,16 +309,13 @@ function renderTransactions(txs) {
|
|||||||
// is shown whole; the title or ENS name, where there is one, names
|
// is shown whole; the title or ENS name, where there is one, names
|
||||||
// it on the line above rather than replacing it.
|
// it on the line above rather than replacing it.
|
||||||
const nameStr = escapeHtml(title || ensName || "");
|
const nameStr = escapeHtml(title || ensName || "");
|
||||||
const addrStr = escapeHtml(counterparty);
|
|
||||||
const dot = addressDotHtml(counterparty);
|
|
||||||
const err = tx.isError ? " (failed)" : "";
|
const err = tx.isError ? " (failed)" : "";
|
||||||
const opacity = tx.isError ? " opacity:0.5;" : "";
|
const opacity = tx.isError ? " opacity:0.5;" : "";
|
||||||
const ago = escapeHtml(timeAgo(tx.timestamp));
|
const ago = escapeHtml(timeAgo(tx.timestamp));
|
||||||
const iso = escapeHtml(isoDate(tx.timestamp));
|
const iso = escapeHtml(isoDate(tx.timestamp));
|
||||||
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
||||||
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
||||||
html += `<div class="flex justify-between"><span class="flex items-center">${dot}${nameStr}</span><span>${amountStr}</span></div>`;
|
html += txCounterpartyHtml(counterparty, nameStr, amountStr);
|
||||||
html += `<div class="am-address">${addrStr}</div>`;
|
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
i++;
|
i++;
|
||||||
}
|
}
|
||||||
|
|||||||
+11
-12
@@ -1,6 +1,7 @@
|
|||||||
const {
|
const {
|
||||||
$,
|
$,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
|
CONTRACT_CREATION_TEXT,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
showView,
|
showView,
|
||||||
showError,
|
showError,
|
||||||
@@ -8,6 +9,7 @@ const {
|
|||||||
renderAddressHtml,
|
renderAddressHtml,
|
||||||
attachCopyHandlers,
|
attachCopyHandlers,
|
||||||
onViewLeave,
|
onViewLeave,
|
||||||
|
formatFee,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState } = require("../../shared/state");
|
||||||
const { networkByChainId } = require("../../shared/networks");
|
const { networkByChainId } = require("../../shared/networks");
|
||||||
@@ -207,7 +209,7 @@ function showPhishingWarning(elementId, isPhishing) {
|
|||||||
// and the nonce. The background compares every one of them against the signed
|
// and the nonce. The background compares every one of them against the signed
|
||||||
// artifact, so every one of them has to be on the screen — a number that is
|
// artifact, so every one of them has to be on the screen — a number that is
|
||||||
// verified but never displayed is verified against nothing the user agreed to.
|
// verified but never displayed is verified against nothing the user agreed to.
|
||||||
function showTxFee(approvedTx, ethPrice) {
|
function showTxFee(approvedTx) {
|
||||||
const network = networkByChainId(approvedTx.chainId);
|
const network = networkByChainId(approvedTx.chainId);
|
||||||
$("approve-tx-network").textContent = network
|
$("approve-tx-network").textContent = network
|
||||||
? network.name
|
? network.name
|
||||||
@@ -215,12 +217,9 @@ function showTxFee(approvedTx, ethPrice) {
|
|||||||
|
|
||||||
const gasLimit = BigInt(approvedTx.gasLimit);
|
const gasLimit = BigInt(approvedTx.gasLimit);
|
||||||
const feePerGas = BigInt(approvedTx.maxFeePerGas || approvedTx.gasPrice);
|
const feePerGas = BigInt(approvedTx.maxFeePerGas || approvedTx.gasPrice);
|
||||||
const maxFeeEth = formatTxValue(formatEther(gasLimit * feePerGas));
|
// Through formatFee(), as the confirmation screen's fee is, so the same
|
||||||
const usdStr = formatUsd(
|
// fee reads the same on both.
|
||||||
ethPrice ? parseFloat(maxFeeEth) * ethPrice : null,
|
$("approve-tx-fee").textContent = formatFee(gasLimit * feePerGas);
|
||||||
);
|
|
||||||
$("approve-tx-fee").textContent =
|
|
||||||
maxFeeEth + " ETH" + (usdStr ? " (" + usdStr + ")" : "");
|
|
||||||
|
|
||||||
let detail =
|
let detail =
|
||||||
gasLimit.toString() +
|
gasLimit.toString() +
|
||||||
@@ -307,7 +306,7 @@ function showTxApproval(details) {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
$("approve-tx-hostname").textContent = details.hostname;
|
$("approve-tx-origin").textContent = details.origin;
|
||||||
$("approve-tx-from").innerHTML = approvalAddressHtml(details.approvedFrom);
|
$("approve-tx-from").innerHTML = approvalAddressHtml(details.approvedFrom);
|
||||||
|
|
||||||
// Show token symbol next to contract address if known
|
// Show token symbol next to contract address if known
|
||||||
@@ -320,7 +319,7 @@ function showTxApproval(details) {
|
|||||||
toHtml += approvalAddressHtml(toAddr);
|
toHtml += approvalAddressHtml(toAddr);
|
||||||
$("approve-tx-to").innerHTML = toHtml;
|
$("approve-tx-to").innerHTML = toHtml;
|
||||||
} else {
|
} else {
|
||||||
$("approve-tx-to").innerHTML = escapeHtml("(contract creation)");
|
$("approve-tx-to").innerHTML = escapeHtml(CONTRACT_CREATION_TEXT);
|
||||||
}
|
}
|
||||||
|
|
||||||
const ethValueFormatted = formatTxValue(
|
const ethValueFormatted = formatTxValue(
|
||||||
@@ -332,7 +331,7 @@ function showTxApproval(details) {
|
|||||||
$("approve-tx-value").textContent =
|
$("approve-tx-value").textContent =
|
||||||
ethValueFormatted + " ETH" + (usdStr ? " (" + usdStr + ")" : "");
|
ethValueFormatted + " ETH" + (usdStr ? " (" + usdStr + ")" : "");
|
||||||
|
|
||||||
showTxFee(approvedTx, ethPrice);
|
showTxFee(approvedTx);
|
||||||
|
|
||||||
// Decode calldata (reuse decoded from above)
|
// Decode calldata (reuse decoded from above)
|
||||||
const decodedEl = $("approve-tx-decoded");
|
const decodedEl = $("approve-tx-decoded");
|
||||||
@@ -646,7 +645,7 @@ function showSignApproval(details) {
|
|||||||
pendingSignParams = sp;
|
pendingSignParams = sp;
|
||||||
pendingSignFrom = details.approvedFrom;
|
pendingSignFrom = details.approvedFrom;
|
||||||
|
|
||||||
$("approve-sign-hostname").textContent = details.hostname;
|
$("approve-sign-origin").textContent = details.origin;
|
||||||
$("approve-sign-from").innerHTML = approvalAddressHtml(
|
$("approve-sign-from").innerHTML = approvalAddressHtml(
|
||||||
details.approvedFrom,
|
details.approvedFrom,
|
||||||
);
|
);
|
||||||
@@ -733,7 +732,7 @@ async function show(id) {
|
|||||||
"approve-site-phishing-warning",
|
"approve-site-phishing-warning",
|
||||||
details.isPhishingDomain,
|
details.isPhishingDomain,
|
||||||
);
|
);
|
||||||
$("approve-hostname").textContent = details.hostname;
|
$("approve-origin").textContent = details.origin;
|
||||||
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
||||||
attachCopyHandlers("view-approve-site");
|
attachCopyHandlers("view-approve-site");
|
||||||
$("approve-remember").checked = state.rememberSiteChoice;
|
$("approve-remember").checked = state.rememberSiteChoice;
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ const {
|
|||||||
attachCopyHandlers,
|
attachCopyHandlers,
|
||||||
goBack,
|
goBack,
|
||||||
onViewLeave,
|
onViewLeave,
|
||||||
|
formatFee,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state } = require("../../shared/state");
|
const { state } = require("../../shared/state");
|
||||||
const { getSignerForAddress } = require("../../shared/wallet");
|
const { getSignerForAddress } = require("../../shared/wallet");
|
||||||
@@ -31,6 +32,9 @@ const {
|
|||||||
transferAmountUnits,
|
transferAmountUnits,
|
||||||
} = require("../../shared/transferAmount");
|
} = require("../../shared/transferAmount");
|
||||||
const { assertWithinCeilings } = require("../../shared/approvalVerify");
|
const { assertWithinCeilings } = require("../../shared/approvalVerify");
|
||||||
|
// The balance lines, the fee reserve and the insufficient-balance messages go
|
||||||
|
// through it, as the approval screen's amounts do.
|
||||||
|
const { truncateAmountNeverZero } = require("../../shared/amountDisplay");
|
||||||
const {
|
const {
|
||||||
CODES,
|
CODES,
|
||||||
FEE_PENDING,
|
FEE_PENDING,
|
||||||
@@ -150,11 +154,17 @@ function show(txInfo) {
|
|||||||
$("confirm-balance").textContent =
|
$("confirm-balance").textContent =
|
||||||
bal == null
|
bal == null
|
||||||
? "unknown (" + symbol + ")"
|
? "unknown (" + symbol + ")"
|
||||||
: valueWithUsd(bal + " " + symbol, balUsd);
|
: valueWithUsd(
|
||||||
|
truncateAmountNeverZero(bal) + " " + symbol,
|
||||||
|
balUsd,
|
||||||
|
);
|
||||||
} else {
|
} else {
|
||||||
const bal = txInfo.balance || "0";
|
const bal = txInfo.balance || "0";
|
||||||
const balUsd = ethPrice ? parseFloat(bal) * ethPrice : null;
|
const balUsd = ethPrice ? parseFloat(bal) * ethPrice : null;
|
||||||
$("confirm-balance").textContent = valueWithUsd(bal + " ETH", balUsd);
|
$("confirm-balance").textContent = valueWithUsd(
|
||||||
|
truncateAmountNeverZero(bal) + " ETH",
|
||||||
|
balUsd,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check for warnings (synchronous local checks)
|
// Check for warnings (synchronous local checks)
|
||||||
@@ -188,6 +198,19 @@ function show(txInfo) {
|
|||||||
$("confirm-amount-fee-error").classList.toggle("hidden", isErc20);
|
$("confirm-amount-fee-error").classList.toggle("hidden", isErc20);
|
||||||
$("confirm-gas-error").classList.toggle("hidden", !isErc20);
|
$("confirm-gas-error").classList.toggle("hidden", !isErc20);
|
||||||
|
|
||||||
|
// The fee-unknown message names its cause, which is also known here.
|
||||||
|
// Without the token's scale estimateGas() cannot encode the transfer, so
|
||||||
|
// the estimate fails every time and going back cannot help; any other
|
||||||
|
// failure may clear on a retry.
|
||||||
|
$("confirm-fee-unknown-error").textContent =
|
||||||
|
isErc20 && txInfo.tokenDecimals == null
|
||||||
|
? "The network fee could not be estimated, because this wallet" +
|
||||||
|
" does not know how many decimal places this token uses, so" +
|
||||||
|
" this transaction cannot be sent."
|
||||||
|
: "The network fee could not be estimated, so this transaction" +
|
||||||
|
" cannot be checked against your balance. Please go back and" +
|
||||||
|
" try again.";
|
||||||
|
|
||||||
renderValidation(txInfo);
|
renderValidation(txInfo);
|
||||||
|
|
||||||
// Reset password field and error
|
// Reset password field and error
|
||||||
@@ -234,7 +257,8 @@ function renderValidation(txInfo) {
|
|||||||
});
|
});
|
||||||
|
|
||||||
// Messages carrying the user's own numbers are built here; the fixed
|
// Messages carrying the user's own numbers are built here; the fixed
|
||||||
// sentences live in the reserved elements in index.html.
|
// sentences live in the reserved elements in index.html, except the
|
||||||
|
// fee-unknown one, which show() sets.
|
||||||
const messages = [];
|
const messages = [];
|
||||||
if (codes.includes(CODES.AMOUNT_INVALID)) {
|
if (codes.includes(CODES.AMOUNT_INVALID)) {
|
||||||
messages.push("Please enter a valid amount to send.");
|
messages.push("Please enter a valid amount to send.");
|
||||||
@@ -249,7 +273,7 @@ function renderValidation(txInfo) {
|
|||||||
: "Insufficient " +
|
: "Insufficient " +
|
||||||
symbol +
|
symbol +
|
||||||
" balance. You have " +
|
" balance. You have " +
|
||||||
txInfo.tokenBalance +
|
truncateAmountNeverZero(txInfo.tokenBalance) +
|
||||||
" " +
|
" " +
|
||||||
symbol +
|
symbol +
|
||||||
" but are trying to send " +
|
" but are trying to send " +
|
||||||
@@ -262,7 +286,7 @@ function renderValidation(txInfo) {
|
|||||||
if (codes.includes(CODES.INSUFFICIENT_ETH)) {
|
if (codes.includes(CODES.INSUFFICIENT_ETH)) {
|
||||||
messages.push(
|
messages.push(
|
||||||
"Insufficient balance. You have " +
|
"Insufficient balance. You have " +
|
||||||
txInfo.balance +
|
truncateAmountNeverZero(txInfo.balance || "0") +
|
||||||
" ETH but are trying to send " +
|
" ETH but are trying to send " +
|
||||||
txInfo.amount +
|
txInfo.amount +
|
||||||
" ETH.",
|
" ETH.",
|
||||||
@@ -305,14 +329,6 @@ function setVisible(id, visible) {
|
|||||||
$(id).style.visibility = visible ? "visible" : "hidden";
|
$(id).style.visibility = visible ? "visible" : "hidden";
|
||||||
}
|
}
|
||||||
|
|
||||||
// A fee in wei as an ETH string, truncated to 6 decimal places.
|
|
||||||
function formatFeeEth(wei) {
|
|
||||||
const parts = formatEther(wei).split(".");
|
|
||||||
const dec =
|
|
||||||
parts.length > 1 ? parts[1].slice(0, 6).replace(/0+$/, "") || "0" : "0";
|
|
||||||
return parts[0] + "." + dec + " ETH";
|
|
||||||
}
|
|
||||||
|
|
||||||
async function estimateGas(txInfo) {
|
async function estimateGas(txInfo) {
|
||||||
try {
|
try {
|
||||||
const provider = getProvider(state.rpcUrl, state.networkId);
|
const provider = getProvider(state.rpcUrl, state.networkId);
|
||||||
@@ -359,33 +375,27 @@ async function estimateGas(txInfo) {
|
|||||||
// flight; a stale fee must not reach the screen or the balance check.
|
// flight; a stale fee must not reach the screen or the balance check.
|
||||||
if (pendingTx !== txInfo) return;
|
if (pendingTx !== txInfo) return;
|
||||||
|
|
||||||
const ethPrice = getPrice("ETH");
|
// The fee line goes through formatFee(), as the approval screen's
|
||||||
const usd = (wei) =>
|
// does, so the same fee reads the same on both.
|
||||||
ethPrice ? parseFloat(formatEther(wei)) * ethPrice : null;
|
|
||||||
|
|
||||||
if (estimateWei !== null && estimateWei < gasCostWei) {
|
if (estimateWei !== null && estimateWei < gasCostWei) {
|
||||||
$("confirm-fee-amount").textContent = valueWithUsd(
|
$("confirm-fee-amount").textContent = "~" + formatFee(estimateWei);
|
||||||
"~" + formatFeeEth(estimateWei),
|
|
||||||
usd(estimateWei),
|
|
||||||
);
|
|
||||||
$("confirm-fee-reserve").textContent =
|
$("confirm-fee-reserve").textContent =
|
||||||
"up to " + formatFeeEth(gasCostWei) + " reserved";
|
"up to " +
|
||||||
|
truncateAmountNeverZero(formatEther(gasCostWei)) +
|
||||||
|
" ETH reserved";
|
||||||
setVisible("confirm-fee-reserve", true);
|
setVisible("confirm-fee-reserve", true);
|
||||||
} else {
|
} else {
|
||||||
// No spread to report: either there is no estimate, or the node
|
// No spread to report: either there is no estimate, or the node
|
||||||
// quotes a gas price at or above maxFeePerGas, so the expected
|
// quotes a gas price at or above maxFeePerGas, so the expected
|
||||||
// cost is not below the reserve. Show the reserve alone.
|
// cost is not below the reserve. Show the reserve alone.
|
||||||
$("confirm-fee-amount").textContent = valueWithUsd(
|
$("confirm-fee-amount").textContent = formatFee(gasCostWei);
|
||||||
formatFeeEth(gasCostWei),
|
|
||||||
usd(gasCostWei),
|
|
||||||
);
|
|
||||||
setVisible("confirm-fee-reserve", false);
|
setVisible("confirm-fee-reserve", false);
|
||||||
}
|
}
|
||||||
feeStatus = FEE_KNOWN;
|
feeStatus = FEE_KNOWN;
|
||||||
feeWei = gasCostWei;
|
feeWei = gasCostWei;
|
||||||
renderValidation(txInfo);
|
renderValidation(txInfo);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.errorf("gas estimation failed:", e.message);
|
log.errorf("gas estimation failed:", e.shortMessage || e.message);
|
||||||
if (pendingTx !== txInfo) return;
|
if (pendingTx !== txInfo) return;
|
||||||
$("confirm-fee-amount").textContent = "Unable to estimate";
|
$("confirm-fee-amount").textContent = "Unable to estimate";
|
||||||
setVisible("confirm-fee-reserve", false);
|
setVisible("confirm-fee-reserve", false);
|
||||||
|
|||||||
@@ -87,7 +87,8 @@ function recoveryPathText(wallet) {
|
|||||||
// AddressDetail, followed by the USD total when there is one to give — no
|
// AddressDetail, followed by the USD total when there is one to give — no
|
||||||
// total line at all on testnet or before the first price fetch, and no figure
|
// total line at all on testnet or before the first price fetch, and no figure
|
||||||
// when every holding here is one with no price, since "$0.00" directly under
|
// when every holding here is one with no price, since "$0.00" directly under
|
||||||
// "This address holds a balance." is a contradiction.
|
// "This address holds a balance." is a contradiction. A token holding below
|
||||||
|
// 0.000001 does not count, as the lines below leave it out.
|
||||||
function balanceWarningHtml(addr) {
|
function balanceWarningHtml(addr) {
|
||||||
if (!addressHoldsFunds(addr)) return " ";
|
if (!addressHoldsFunds(addr)) return " ";
|
||||||
const line = formatAddressTotal(getAddressValue(addr));
|
const line = formatAddressTotal(getAddressValue(addr));
|
||||||
|
|||||||
@@ -12,6 +12,11 @@
|
|||||||
// escapeHtml lives in src/shared/html.js, where the escape and the
|
// escapeHtml lives in src/shared/html.js, where the escape and the
|
||||||
// reasoning behind it are; it is re-exported below so views keep importing
|
// reasoning behind it are; it is re-exported below so views keep importing
|
||||||
// it from here.
|
// it from here.
|
||||||
|
const { formatEther } = require("ethers");
|
||||||
|
const {
|
||||||
|
truncateAmountNeverZero,
|
||||||
|
isBelowOneMillionth,
|
||||||
|
} = require("../../shared/amountDisplay");
|
||||||
const { DEBUG } = require("../../shared/constants");
|
const { DEBUG } = require("../../shared/constants");
|
||||||
const { escapeHtml } = require("../../shared/html");
|
const { escapeHtml } = require("../../shared/html");
|
||||||
const { isDebug } = require("../../shared/log");
|
const { isDebug } = require("../../shared/log");
|
||||||
@@ -223,15 +228,19 @@ function clearFlash() {
|
|||||||
flashTimer = null;
|
flashTimer = null;
|
||||||
}
|
}
|
||||||
$("flash-msg").textContent = "";
|
$("flash-msg").textContent = "";
|
||||||
|
$("flash-msg").title = "";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The flash line reserves exactly one line, and a message that wrapped would
|
||||||
|
// push the screen below it down (README, No Layout Shift). So #flash-msg never
|
||||||
|
// wraps: text too long for the line is cut with an ellipsis, and the whole
|
||||||
|
// message is also put in the line's title. Write messages to fit, at most 50
|
||||||
|
// characters, so none is cut.
|
||||||
function showFlash(msg, duration = 2000) {
|
function showFlash(msg, duration = 2000) {
|
||||||
clearFlash();
|
clearFlash();
|
||||||
$("flash-msg").textContent = msg;
|
$("flash-msg").textContent = msg;
|
||||||
flashTimer = setTimeout(() => {
|
$("flash-msg").title = msg;
|
||||||
$("flash-msg").textContent = "";
|
flashTimer = setTimeout(clearFlash, duration);
|
||||||
flashTimer = null;
|
|
||||||
}, duration);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// A stored token balance as a number, or null when there is no number in it.
|
// A stored token balance as a number, or null when there is no number in it.
|
||||||
@@ -243,6 +252,19 @@ function unknownableAmount(balance) {
|
|||||||
return Number.isFinite(n) ? n : null;
|
return Number.isFinite(n) ? n : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A network fee in wei as the confirmation and approval screens both show it:
|
||||||
|
// the ETH figure through truncateAmountNeverZero(), then its USD value when the
|
||||||
|
// ETH price is known. The USD value is of the exact fee, not of the truncated
|
||||||
|
// figure.
|
||||||
|
function formatFee(wei) {
|
||||||
|
const eth = formatEther(wei);
|
||||||
|
const ethPrice = getPrice("ETH");
|
||||||
|
const usd = ethPrice ? formatUsd(parseFloat(eth) * ethPrice) : "";
|
||||||
|
return (
|
||||||
|
truncateAmountNeverZero(eth) + " ETH" + (usd ? " (" + usd + ")" : "")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// One row of the balance list: symbol, quantity, fiat value.
|
// One row of the balance list: symbol, quantity, fiat value.
|
||||||
//
|
//
|
||||||
// `symbol` is the ERC-20's own symbol() as the block explorer reported it,
|
// `symbol` is the ERC-20's own symbol() as the block explorer reported it,
|
||||||
@@ -288,6 +310,9 @@ function balanceLinesForAddress(addr, trackedTokens, showZero) {
|
|||||||
);
|
);
|
||||||
const seen = new Set();
|
const seen = new Set();
|
||||||
for (const t of addr.tokenBalances || []) {
|
for (const t of addr.tokenBalances || []) {
|
||||||
|
// A holding below 0.000001 is not listed, tracked or not. A tracked
|
||||||
|
// token then gets the zero row below while showZero is on.
|
||||||
|
if (isBelowOneMillionth(t.balance)) continue;
|
||||||
// A null balance is a holding of an unstatable amount, not a holding
|
// A null balance is a holding of an unstatable amount, not a holding
|
||||||
// of zero, so the show-zero setting has no say over it: hiding it
|
// of zero, so the show-zero setting has no say over it: hiding it
|
||||||
// would be asserting the zero nobody established. Anything that does
|
// would be asserting the zero nobody established. Anything that does
|
||||||
@@ -318,14 +343,16 @@ function balanceLinesForAddress(addr, trackedTokens, showZero) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Whether an address holds anything at all: ETH or any ERC-20 the wallet
|
// Whether an address holds anything at all: ETH or any ERC-20 the wallet
|
||||||
// knows about. Deliberately unrounded — the rendered lines round to four
|
// knows about, except a token holding below 0.000001, which the balance list
|
||||||
// decimals, so a dust balance displays as 0.0000 while still being real
|
// under the remove-address warning leaves out too. Deliberately unrounded —
|
||||||
// money at a real address. Callers that warn about holdings must ask this,
|
// the rendered lines round to four decimals, so a dust balance displays as
|
||||||
// not the rendered figure.
|
// 0.0000 while still being real money at a real address. Callers that warn
|
||||||
|
// about holdings must ask this, not the rendered figure.
|
||||||
function addressHoldsFunds(addr) {
|
function addressHoldsFunds(addr) {
|
||||||
if (!addr) return false;
|
if (!addr) return false;
|
||||||
if (parseFloat(addr.balance || "0") > 0) return true;
|
if (parseFloat(addr.balance || "0") > 0) return true;
|
||||||
for (const t of addr.tokenBalances || []) {
|
for (const t of addr.tokenBalances || []) {
|
||||||
|
if (isBelowOneMillionth(t.balance)) continue;
|
||||||
// A null balance is a holding whose amount could not be stated —
|
// A null balance is a holding whose amount could not be stated —
|
||||||
// balances.js drops a row of zero base units before the scale is
|
// balances.js drops a row of zero base units before the scale is
|
||||||
// consulted, so a row that survived with no quantity is holding
|
// consulted, so a row that survived with no quantity is holding
|
||||||
@@ -404,6 +431,29 @@ function addressTitle(address, wallets) {
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// What every recipient line and history row says for a transaction with no
|
||||||
|
// `to`. Such a transaction creates a contract, so there is no address to show,
|
||||||
|
// and a blank line on these screens reads as a rendering fault.
|
||||||
|
const CONTRACT_CREATION_TEXT =
|
||||||
|
"This transaction creates a new contract. It has no recipient.";
|
||||||
|
|
||||||
|
// The last two lines of a transaction history row: the counterparty's colour
|
||||||
|
// dot and name beside the amount, then its full address. A contract creation
|
||||||
|
// the user sent has no counterparty (its `to` is ""), so its row has the
|
||||||
|
// amount alone and the contract creation sentence in place of the address.
|
||||||
|
function txCounterpartyHtml(address, nameHtml, amountHtml) {
|
||||||
|
if (!address) {
|
||||||
|
return (
|
||||||
|
`<div class="flex justify-between"><span></span><span>${amountHtml}</span></div>` +
|
||||||
|
`<div>${escapeHtml(CONTRACT_CREATION_TEXT)}</div>`
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return (
|
||||||
|
`<div class="flex justify-between"><span class="flex items-center">${addressDotHtml(address)}${nameHtml}</span><span>${amountHtml}</span></div>` +
|
||||||
|
`<div class="am-address">${escapeHtml(address)}</div>`
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Render an address with color dot, optional ENS name, optional title,
|
// Render an address with color dot, optional ENS name, optional title,
|
||||||
// and optional truncation. Title and ENS are shown as bold labels above
|
// and optional truncation. Title and ENS are shown as bold labels above
|
||||||
// the full address.
|
// the full address.
|
||||||
@@ -610,11 +660,14 @@ module.exports = {
|
|||||||
balanceLinesForAddress,
|
balanceLinesForAddress,
|
||||||
addressHoldsFunds,
|
addressHoldsFunds,
|
||||||
unknownableAmount,
|
unknownableAmount,
|
||||||
|
formatFee,
|
||||||
addressColor,
|
addressColor,
|
||||||
addressDotHtml,
|
addressDotHtml,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
displaySymbol,
|
displaySymbol,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
|
CONTRACT_CREATION_TEXT,
|
||||||
|
txCounterpartyHtml,
|
||||||
formatAddressHtml,
|
formatAddressHtml,
|
||||||
renderAddressHtml,
|
renderAddressHtml,
|
||||||
copyableHtml,
|
copyableHtml,
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ const {
|
|||||||
isoDate,
|
isoDate,
|
||||||
timeAgo,
|
timeAgo,
|
||||||
addressDotHtml,
|
addressDotHtml,
|
||||||
|
txCounterpartyHtml,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
displaySymbol,
|
displaySymbol,
|
||||||
@@ -122,16 +123,13 @@ function renderHomeTxList(ctx) {
|
|||||||
// names it on the line above rather than replacing it.
|
// names it on the line above rather than replacing it.
|
||||||
const title = addressTitle(counterparty, state.wallets);
|
const title = addressTitle(counterparty, state.wallets);
|
||||||
const titleStr = title ? escapeHtml(title) : "";
|
const titleStr = title ? escapeHtml(title) : "";
|
||||||
const addrStr = escapeHtml(counterparty);
|
|
||||||
const dot = addressDotHtml(counterparty);
|
|
||||||
const err = tx.isError ? " (failed)" : "";
|
const err = tx.isError ? " (failed)" : "";
|
||||||
const opacity = tx.isError ? " opacity:0.5;" : "";
|
const opacity = tx.isError ? " opacity:0.5;" : "";
|
||||||
const ago = escapeHtml(timeAgo(tx.timestamp));
|
const ago = escapeHtml(timeAgo(tx.timestamp));
|
||||||
const iso = escapeHtml(isoDate(tx.timestamp));
|
const iso = escapeHtml(isoDate(tx.timestamp));
|
||||||
html += `<div class="home-tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
html += `<div class="home-tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
||||||
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
||||||
html += `<div class="flex justify-between"><span class="flex items-center">${dot}${titleStr}</span><span>${amountStr}</span></div>`;
|
html += txCounterpartyHtml(counterparty, titleStr, amountStr);
|
||||||
html += `<div class="am-address">${addrStr}</div>`;
|
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
i++;
|
i++;
|
||||||
}
|
}
|
||||||
|
|||||||
+70
-57
@@ -16,6 +16,10 @@ const { resolveTokenDecimals } = require("../../shared/approvalAmount");
|
|||||||
const { resolveSymbol } = require("../../shared/tokenList");
|
const { resolveSymbol } = require("../../shared/tokenList");
|
||||||
const { isLowHolderCount } = require("../../shared/holders");
|
const { isLowHolderCount } = require("../../shared/holders");
|
||||||
const { isSpoofedSymbol } = require("../../shared/symbolSpoof");
|
const { isSpoofedSymbol } = require("../../shared/symbolSpoof");
|
||||||
|
const {
|
||||||
|
truncateAmountNeverZero,
|
||||||
|
isBelowOneMillionth,
|
||||||
|
} = require("../../shared/amountDisplay");
|
||||||
const { getAddress } = require("ethers");
|
const { getAddress } = require("ethers");
|
||||||
|
|
||||||
const ZERO_ADDRESS = "0x0000000000000000000000000000000000000000";
|
const ZERO_ADDRESS = "0x0000000000000000000000000000000000000000";
|
||||||
@@ -63,13 +67,13 @@ function validateToAddress(value) {
|
|||||||
if (checksummed !== v) {
|
if (checksummed !== v) {
|
||||||
return {
|
return {
|
||||||
valid: false,
|
valid: false,
|
||||||
error: "Address checksum is invalid. Please double-check the address.",
|
error: "Address checksum is invalid. Check the address.",
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
} catch {
|
} catch {
|
||||||
return {
|
return {
|
||||||
valid: false,
|
valid: false,
|
||||||
error: "Address checksum is invalid. Please double-check the address.",
|
error: "Address checksum is invalid. Check the address.",
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -125,6 +129,10 @@ function renderSendTokenSelect(addr) {
|
|||||||
(state.fraudContracts || []).map((a) => a.toLowerCase()),
|
(state.fraudContracts || []).map((a) => a.toLowerCase()),
|
||||||
);
|
);
|
||||||
for (const t of addr.tokenBalances || []) {
|
for (const t of addr.tokenBalances || []) {
|
||||||
|
// A holding below 0.000001 is left out, as the balance lists leave it
|
||||||
|
// out. Its token's own screen can still send it: there
|
||||||
|
// state.selectedToken picks the token, not this list.
|
||||||
|
if (isBelowOneMillionth(t.balance)) continue;
|
||||||
if (isSpoofedSymbol(t.symbol, t.address)) continue;
|
if (isSpoofedSymbol(t.symbol, t.address)) continue;
|
||||||
if (fraudSet.has(t.address.toLowerCase())) continue;
|
if (fraudSet.has(t.address.toLowerCase())) continue;
|
||||||
// An unknown holder count does not withhold a token the user holds:
|
// An unknown holder count does not withhold a token the user holds:
|
||||||
@@ -138,6 +146,50 @@ function renderSendTokenSelect(addr) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The token balance and scale the Send screen states and hands the
|
||||||
|
// confirmation screen, so the two screens describe the holding the same way.
|
||||||
|
//
|
||||||
|
// The scale is resolved the same way balances.js resolved the scale it
|
||||||
|
// DISPLAYED this token's balance at: bundled list, then the user's tracked
|
||||||
|
// tokens, then the explorer. The stored tokenBalances[].decimals is the
|
||||||
|
// explorer's own answer alone, so reading it raw carries a null forward for a
|
||||||
|
// token the wallet does know the scale of — and displayedDecimals() then throws
|
||||||
|
// inside estimateGas(), which the confirmation screen reports as an unestimable
|
||||||
|
// fee. Unsendable, over a scale that was never in doubt
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/349). Still null when nothing
|
||||||
|
// knows: no fallback.
|
||||||
|
//
|
||||||
|
// Resolved WITH `wallets`, which balances.js does not pass: that adds
|
||||||
|
// explorerDecimals()'s cross-address check, so a contract two addresses report
|
||||||
|
// different scales for answers null rather than picking one. That check has to
|
||||||
|
// apply here, because this scale encodes the transfer — it is carried forward
|
||||||
|
// so the transfer is encoded with the number the user read rather than with
|
||||||
|
// whatever the contract answers at signing time (see
|
||||||
|
// src/shared/transferAmount.js). balances.js is formatting one explorer row at
|
||||||
|
// fetch time and cannot consult a state it is in the middle of replacing.
|
||||||
|
//
|
||||||
|
// The two resolutions can therefore differ, and where they do, the stored
|
||||||
|
// `balance` is a quantity computed at a scale this screen has just declined to
|
||||||
|
// stand behind. Stating it would leave validateTransfer() checking the amount
|
||||||
|
// against a number the wallet does not vouch for, so it is withdrawn: unknown
|
||||||
|
// scale means unknown balance. It is null rather than "0": both screens state
|
||||||
|
// an unknown balance as unknown, and validateTransfer() treats it as no balance
|
||||||
|
// to spend from, which is the fail-closed side of an amount nobody can check.
|
||||||
|
// Only a stored quantity is withdrawn: the "0" for a token that has no row at
|
||||||
|
// all is an absence of holdings, which is true at every scale.
|
||||||
|
function tokenBalanceAndDecimals(addr, token) {
|
||||||
|
const tb = (addr.tokenBalances || []).find(
|
||||||
|
(t) => t.address.toLowerCase() === token.toLowerCase(),
|
||||||
|
);
|
||||||
|
const tokenDecimals = resolveTokenDecimals(token, {
|
||||||
|
trackedTokens: state.trackedTokens,
|
||||||
|
wallets: state.wallets,
|
||||||
|
});
|
||||||
|
if (!tb) return { tokenBalance: "0", tokenDecimals };
|
||||||
|
if (tokenDecimals === null) return { tokenBalance: null, tokenDecimals };
|
||||||
|
return { tokenBalance: tb.balance ?? null, tokenDecimals };
|
||||||
|
}
|
||||||
|
|
||||||
function updateSendBalance() {
|
function updateSendBalance() {
|
||||||
const addr = currentAddress();
|
const addr = currentAddress();
|
||||||
if (!addr) return;
|
if (!addr) return;
|
||||||
@@ -150,24 +202,27 @@ function updateSendBalance() {
|
|||||||
const token = state.selectedToken || $("send-token").value;
|
const token = state.selectedToken || $("send-token").value;
|
||||||
if (token === "ETH") {
|
if (token === "ETH") {
|
||||||
$("send-balance").textContent =
|
$("send-balance").textContent =
|
||||||
"Current balance: " + (addr.balance || "0") + " ETH";
|
"Current balance: " +
|
||||||
|
truncateAmountNeverZero(addr.balance || "0") +
|
||||||
|
" ETH";
|
||||||
} else {
|
} else {
|
||||||
const tb = (addr.tokenBalances || []).find(
|
|
||||||
(t) => t.address.toLowerCase() === token.toLowerCase(),
|
|
||||||
);
|
|
||||||
const symbol = resolveSymbol(
|
const symbol = resolveSymbol(
|
||||||
token,
|
token,
|
||||||
addr.tokenBalances,
|
addr.tokenBalances,
|
||||||
state.trackedTokens,
|
state.trackedTokens,
|
||||||
);
|
);
|
||||||
// A null balance is a holding whose scale nothing knows. Saying "0"
|
// A null balance is a holding whose scale is unknown. Saying a figure
|
||||||
// for it would be a claim about the amount; the send itself is
|
// for it would be a claim about the amount, so it reads as the
|
||||||
|
// confirmation screen's balance line reads it; the send itself is
|
||||||
// refused later by transferAmountUnits() for the same missing scale.
|
// refused later by transferAmountUnits() for the same missing scale.
|
||||||
const bal = tb ? tb.balance : "0";
|
const bal = tokenBalanceAndDecimals(addr, token).tokenBalance;
|
||||||
$("send-balance").textContent =
|
$("send-balance").textContent =
|
||||||
bal == null
|
bal == null
|
||||||
? "Current balance: unknown (" + symbol + ")"
|
? "Current balance: unknown (" + symbol + ")"
|
||||||
: "Current balance: " + bal + " " + symbol;
|
: "Current balance: " +
|
||||||
|
truncateAmountNeverZero(bal) +
|
||||||
|
" " +
|
||||||
|
symbol;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -211,7 +266,7 @@ function init(_ctx) {
|
|||||||
const provider = getProvider(state.rpcUrl, state.networkId);
|
const provider = getProvider(state.rpcUrl, state.networkId);
|
||||||
const resolved = await provider.resolveName(to);
|
const resolved = await provider.resolveName(to);
|
||||||
if (!resolved) {
|
if (!resolved) {
|
||||||
showFlash("Could not resolve " + to);
|
showFlash("That ENS name has no address.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
resolvedTo = resolved;
|
resolvedTo = resolved;
|
||||||
@@ -227,59 +282,17 @@ function init(_ctx) {
|
|||||||
|
|
||||||
let tokenSymbol = null;
|
let tokenSymbol = null;
|
||||||
let tokenBalance = null;
|
let tokenBalance = null;
|
||||||
// The scale the amount and the balance below are rendered at, carried
|
|
||||||
// forward so the transfer is encoded with the number the user read
|
|
||||||
// rather than with whatever the contract answers at signing time. See
|
|
||||||
// src/shared/transferAmount.js.
|
|
||||||
let tokenDecimals = null;
|
let tokenDecimals = null;
|
||||||
if (token !== "ETH") {
|
if (token !== "ETH") {
|
||||||
const tb = (addr.tokenBalances || []).find(
|
|
||||||
(t) => t.address.toLowerCase() === token.toLowerCase(),
|
|
||||||
);
|
|
||||||
tokenSymbol = resolveSymbol(
|
tokenSymbol = resolveSymbol(
|
||||||
token,
|
token,
|
||||||
addr.tokenBalances,
|
addr.tokenBalances,
|
||||||
state.trackedTokens,
|
state.trackedTokens,
|
||||||
);
|
);
|
||||||
// null carried through rather than flattened to "0": the confirm
|
({ tokenBalance, tokenDecimals } = tokenBalanceAndDecimals(
|
||||||
// screen states an unknown balance as unknown, and
|
addr,
|
||||||
// validateTransfer() treats it as no balance to spend from, which
|
token,
|
||||||
// is the fail-closed side of an amount nobody can check.
|
));
|
||||||
tokenBalance = tb ? (tb.balance ?? null) : "0";
|
|
||||||
// Resolved the same way balances.js resolved the scale it
|
|
||||||
// DISPLAYED this token's balance at: bundled list, then the user's
|
|
||||||
// tracked tokens, then the explorer. The stored
|
|
||||||
// tokenBalances[].decimals is the explorer's own answer alone, so
|
|
||||||
// reading it raw carries a null forward for a token the wallet
|
|
||||||
// does know the scale of — and displayedDecimals() then throws
|
|
||||||
// inside estimateGas(), which the confirmation screen reports as
|
|
||||||
// an unestimable fee. Unsendable, over a scale that was never in
|
|
||||||
// doubt (https://git.eeqj.de/sneak/AutistMask/issues/349).
|
|
||||||
// Still null when nothing knows: no fallback.
|
|
||||||
//
|
|
||||||
// Resolved WITH `wallets`, which balances.js does not pass: that
|
|
||||||
// adds explorerDecimals()'s cross-address check, so a contract two
|
|
||||||
// addresses report different scales for answers null rather than
|
|
||||||
// picking one. That check has to apply here, because this value
|
|
||||||
// encodes a transfer; balances.js is formatting one explorer row
|
|
||||||
// at fetch time and cannot consult a state it is in the middle of
|
|
||||||
// replacing.
|
|
||||||
tokenDecimals = resolveTokenDecimals(token, {
|
|
||||||
trackedTokens: state.trackedTokens,
|
|
||||||
wallets: state.wallets,
|
|
||||||
});
|
|
||||||
// The two resolutions can therefore differ, and where they do, the
|
|
||||||
// stored `balance` is a quantity computed at a scale this screen
|
|
||||||
// has just declined to stand behind. Stating it would leave
|
|
||||||
// validateTransfer() checking the amount against a number the
|
|
||||||
// wallet does not vouch for, and — since the unknown-balance path
|
|
||||||
// is gated on the balance, not on the scale — would leave the
|
|
||||||
// fee-estimate failure as the only thing on the confirmation
|
|
||||||
// screen, which says nothing about decimals. Unknown scale means
|
|
||||||
// unknown balance. Only a stored quantity is withdrawn: the "0"
|
|
||||||
// for a token that has no row at all is an absence of holdings,
|
|
||||||
// which is true at every scale.
|
|
||||||
if (tb && tokenDecimals === null) tokenBalance = null;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
ctx.showConfirmTx({
|
ctx.showConfirmTx({
|
||||||
|
|||||||
+69
-38
@@ -16,7 +16,12 @@ const {
|
|||||||
} = require("../dustThreshold");
|
} = require("../dustThreshold");
|
||||||
const { state, saveState, currentNetwork } = require("../../shared/state");
|
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||||
const { onChainSwitch } = require("../../shared/chainSwitch");
|
const { onChainSwitch } = require("../../shared/chainSwitch");
|
||||||
const { log, debugFetch, setRuntimeDebug } = require("../../shared/log");
|
const {
|
||||||
|
log,
|
||||||
|
debugFetch,
|
||||||
|
urlOrigin,
|
||||||
|
setRuntimeDebug,
|
||||||
|
} = require("../../shared/log");
|
||||||
const deleteWallet = require("./deleteWallet");
|
const deleteWallet = require("./deleteWallet");
|
||||||
const showPhrase = require("./showPhrase");
|
const showPhrase = require("./showPhrase");
|
||||||
const { walletHasRecoveryPhrase } = require("../../shared/wallet");
|
const { walletHasRecoveryPhrase } = require("../../shared/wallet");
|
||||||
@@ -29,46 +34,63 @@ const {
|
|||||||
GITEA_COMMIT_URL,
|
GITEA_COMMIT_URL,
|
||||||
} = require("../../shared/buildInfo");
|
} = require("../../shared/buildInfo");
|
||||||
|
|
||||||
const { notify } = require("../../shared/browserApi");
|
const { notify, sendMessage } = require("../../shared/browserApi");
|
||||||
|
|
||||||
let versionClickCount = 0;
|
let versionClickCount = 0;
|
||||||
let versionClickTimer = null;
|
let versionClickTimer = null;
|
||||||
|
|
||||||
function renderSiteList(containerId, siteMap, stateKey) {
|
// One row per site origin, however many addresses it appears under, each with
|
||||||
|
// an [x] that hands it to onRemove.
|
||||||
|
function renderSiteList(containerId, origins, onRemove) {
|
||||||
const container = $(containerId);
|
const container = $(containerId);
|
||||||
const hostnames = [...new Set(Object.values(siteMap).flat())];
|
const unique = [...new Set(origins)];
|
||||||
if (hostnames.length === 0) {
|
if (unique.length === 0) {
|
||||||
container.innerHTML = '<p class="text-xs text-muted">None</p>';
|
container.innerHTML = '<p class="text-xs text-muted">None</p>';
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
let html = "";
|
let html = "";
|
||||||
hostnames.forEach((hostname) => {
|
unique.forEach((origin) => {
|
||||||
html += `<div class="flex justify-between items-center text-xs py-1 border-b border-border-light">`;
|
html += `<div class="flex justify-between items-center text-xs py-1 border-b border-border-light">`;
|
||||||
// A hostname the URL parser produced cannot carry a delimiter, so
|
// An origin the URL parser produced cannot carry a delimiter, so
|
||||||
// this is escaped for the rule rather than for a known hole — the
|
// this is escaped for the rule rather than for a known hole — the
|
||||||
// rule being that nothing reaches innerHTML unescaped.
|
// rule being that nothing reaches innerHTML unescaped.
|
||||||
html += `<span>${escapeHtml(hostname)}</span>`;
|
html += `<span>${escapeHtml(origin)}</span>`;
|
||||||
html += `<button class="btn-remove-site border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-key="${escapeHtml(stateKey)}" data-hostname="${escapeHtml(hostname)}">[x]</button>`;
|
html += `<button class="btn-remove-site border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-origin="${escapeHtml(origin)}">[x]</button>`;
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
});
|
});
|
||||||
container.innerHTML = html;
|
container.innerHTML = html;
|
||||||
container.querySelectorAll(".btn-remove-site").forEach((btn) => {
|
container.querySelectorAll(".btn-remove-site").forEach((btn) => {
|
||||||
btn.addEventListener("click", async () => {
|
btn.addEventListener("click", () => onRemove(btn.dataset.origin));
|
||||||
const key = btn.dataset.key;
|
|
||||||
const host = btn.dataset.hostname;
|
|
||||||
for (const addr of Object.keys(state[key])) {
|
|
||||||
state[key][addr] = state[key][addr].filter((h) => h !== host);
|
|
||||||
if (state[key][addr].length === 0) {
|
|
||||||
delete state[key][addr];
|
|
||||||
}
|
|
||||||
}
|
|
||||||
await saveState();
|
|
||||||
notify({ type: "AUTISTMASK_REMOVE_SITE" });
|
|
||||||
renderSiteList(containerId, state[key], key);
|
|
||||||
});
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Drop a site origin from a remembered site list under every address.
|
||||||
|
function forgetOrigin(siteMap, origin) {
|
||||||
|
for (const addr of Object.keys(siteMap)) {
|
||||||
|
siteMap[addr] = siteMap[addr].filter((o) => o !== origin);
|
||||||
|
if (siteMap[addr].length === 0) {
|
||||||
|
delete siteMap[addr];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Removing a site from Allowed Sites or Connected Sites disconnects it: it is
|
||||||
|
// no longer allowed under any address, and the background ends its
|
||||||
|
// connections approved without "Remember" and tells its open tabs.
|
||||||
|
async function removeAllowedSite(origin) {
|
||||||
|
forgetOrigin(state.allowedSites, origin);
|
||||||
|
await saveState();
|
||||||
|
notify({ type: "AUTISTMASK_REMOVE_SITE", origin });
|
||||||
|
await renderSiteLists();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Removing a denied site only forgets the refusal; it connects nothing.
|
||||||
|
async function removeDeniedSite(origin) {
|
||||||
|
forgetOrigin(state.deniedSites, origin);
|
||||||
|
await saveState();
|
||||||
|
await renderSiteLists();
|
||||||
|
}
|
||||||
|
|
||||||
function renderTrackedTokens() {
|
function renderTrackedTokens() {
|
||||||
const container = $("settings-tracked-tokens");
|
const container = $("settings-tracked-tokens");
|
||||||
if (state.trackedTokens.length === 0) {
|
if (state.trackedTokens.length === 0) {
|
||||||
@@ -202,13 +224,24 @@ function show() {
|
|||||||
showView("settings");
|
showView("settings");
|
||||||
}
|
}
|
||||||
|
|
||||||
function renderSiteLists() {
|
async function renderSiteLists() {
|
||||||
renderSiteList(
|
renderSiteList(
|
||||||
"settings-allowed-sites",
|
"settings-allowed-sites",
|
||||||
state.allowedSites,
|
Object.values(state.allowedSites).flat(),
|
||||||
"allowedSites",
|
removeAllowedSite,
|
||||||
|
);
|
||||||
|
renderSiteList(
|
||||||
|
"settings-denied-sites",
|
||||||
|
Object.values(state.deniedSites).flat(),
|
||||||
|
removeDeniedSite,
|
||||||
|
);
|
||||||
|
// Sites allowed without "Remember" are held only by the background, in
|
||||||
|
// memory, so it is asked for them.
|
||||||
|
renderSiteList(
|
||||||
|
"settings-connected-sites",
|
||||||
|
await sendMessage({ type: "AUTISTMASK_GET_CONNECTED_SITES" }),
|
||||||
|
removeAllowedSite,
|
||||||
);
|
);
|
||||||
renderSiteList("settings-denied-sites", state.deniedSites, "deniedSites");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function init(ctx) {
|
function init(ctx) {
|
||||||
@@ -236,22 +269,19 @@ function init(ctx) {
|
|||||||
const json = await resp.json();
|
const json = await resp.json();
|
||||||
if (json.error) {
|
if (json.error) {
|
||||||
log.errorf("RPC validation error:", json.error);
|
log.errorf("RPC validation error:", json.error);
|
||||||
showFlash("Endpoint returned error: " + json.error.message);
|
showFlash("Endpoint returned an error.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const net = currentNetwork();
|
const net = currentNetwork();
|
||||||
if (json.result !== net.chainId) {
|
if (json.result !== net.chainId) {
|
||||||
showFlash(
|
showFlash("Wrong network: expected " + net.name + ".");
|
||||||
"Wrong network (expected " +
|
|
||||||
net.name +
|
|
||||||
", got chain " +
|
|
||||||
json.result +
|
|
||||||
").",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
} catch (e) {
|
} catch {
|
||||||
log.errorf("RPC validation fetch failed:", e.message);
|
// Not the error's message: fetch puts the whole URL, password and
|
||||||
|
// key included, in the message of the error it throws for a URL
|
||||||
|
// with a user name and password or one it cannot parse.
|
||||||
|
log.errorf("RPC validation fetch failed:", urlOrigin(url));
|
||||||
showFlash("Could not reach endpoint.");
|
showFlash("Could not reach endpoint.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -273,8 +303,9 @@ function init(ctx) {
|
|||||||
showFlash("Endpoint returned HTTP " + resp.status + ".");
|
showFlash("Endpoint returned HTTP " + resp.status + ".");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
} catch (e) {
|
} catch {
|
||||||
log.errorf("Blockscout validation failed:", e.message);
|
// Not the error's message, as for the RPC check above.
|
||||||
|
log.errorf("Blockscout validation failed:", urlOrigin(url));
|
||||||
showFlash("Could not reach endpoint.");
|
showFlash("Could not reach endpoint.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -115,9 +115,7 @@ function init(_ctx) {
|
|||||||
$("btn-settings-addtoken-manual").addEventListener("click", async () => {
|
$("btn-settings-addtoken-manual").addEventListener("click", async () => {
|
||||||
const addr = $("settings-addtoken-address").value.trim();
|
const addr = $("settings-addtoken-address").value.trim();
|
||||||
if (!addr || !addr.startsWith("0x")) {
|
if (!addr || !addr.startsWith("0x")) {
|
||||||
showFlash(
|
showFlash("Enter a valid contract address starting with 0x.");
|
||||||
"Please enter a valid contract address starting with 0x.",
|
|
||||||
);
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (isTracked(addr)) {
|
if (isTracked(addr)) {
|
||||||
@@ -155,8 +153,15 @@ function init(_ctx) {
|
|||||||
ctx.doRefreshAndRender();
|
ctx.doRefreshAndRender();
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
const detail = e.shortMessage || e.message || String(e);
|
const detail = e.shortMessage || e.message || String(e);
|
||||||
log.errorf("Token lookup failed for", addr, detail);
|
log.errorf("Adding token failed for", addr, detail);
|
||||||
showFlash(detail);
|
// lookupTokenInfo() rejects a contract with a one-line message
|
||||||
|
// starting "Not a valid ERC-20 token". Any other error, such as a
|
||||||
|
// failed save, can be far longer, so it is only logged.
|
||||||
|
showFlash(
|
||||||
|
detail.startsWith("Not a valid ERC-20 token")
|
||||||
|
? detail
|
||||||
|
: "Could not add the token.",
|
||||||
|
);
|
||||||
infoEl.textContent = "";
|
infoEl.textContent = "";
|
||||||
infoEl.style.visibility = "hidden";
|
infoEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ const {
|
|||||||
showFlash,
|
showFlash,
|
||||||
flashCopyFeedback,
|
flashCopyFeedback,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
|
CONTRACT_CREATION_TEXT,
|
||||||
addressDotHtml,
|
addressDotHtml,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
isoDate,
|
isoDate,
|
||||||
@@ -94,13 +95,18 @@ function render() {
|
|||||||
$("tx-detail-hash").innerHTML = txHashHtml(tx.hash);
|
$("tx-detail-hash").innerHTML = txHashHtml(tx.hash);
|
||||||
|
|
||||||
const fromTitle = addressTitle(tx.from, state.wallets);
|
const fromTitle = addressTitle(tx.from, state.wallets);
|
||||||
const toTitle = addressTitle(tx.to, state.wallets);
|
|
||||||
$("tx-detail-from").innerHTML = txAddressHtml(
|
$("tx-detail-from").innerHTML = txAddressHtml(
|
||||||
tx.from,
|
tx.from,
|
||||||
tx.fromEns,
|
tx.fromEns,
|
||||||
fromTitle,
|
fromTitle,
|
||||||
);
|
);
|
||||||
$("tx-detail-to").innerHTML = txAddressHtml(tx.to, tx.toEns, toTitle);
|
// A contract creation has no recipient: transactions.js gives it `to: ""`.
|
||||||
|
if (tx.to) {
|
||||||
|
const toTitle = addressTitle(tx.to, state.wallets);
|
||||||
|
$("tx-detail-to").innerHTML = txAddressHtml(tx.to, tx.toEns, toTitle);
|
||||||
|
} else {
|
||||||
|
$("tx-detail-to").innerHTML = escapeHtml(CONTRACT_CREATION_TEXT);
|
||||||
|
}
|
||||||
|
|
||||||
// Exact amount (full precision, copyable)
|
// Exact amount (full precision, copyable)
|
||||||
const detailSym = displaySymbol(tx.symbol);
|
const detailSym = displaySymbol(tx.symbol);
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
|
CONTRACT_CREATION_TEXT,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
renderAddressHtml,
|
renderAddressHtml,
|
||||||
attachCopyHandlers,
|
attachCopyHandlers,
|
||||||
@@ -58,7 +59,10 @@ function endWait() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A contract creation reaches these screens with `to` as "" (approval.js
|
||||||
|
// writes `to: toAddr || ""`).
|
||||||
function toAddressHtml(address) {
|
function toAddressHtml(address) {
|
||||||
|
if (!address) return escapeHtml(CONTRACT_CREATION_TEXT);
|
||||||
const title = addressTitle(address, state.wallets);
|
const title = addressTitle(address, state.wallets);
|
||||||
return renderAddressHtml(address, { title });
|
return renderAddressHtml(address, { title });
|
||||||
}
|
}
|
||||||
@@ -129,7 +133,7 @@ function startWait(txInfo, txHash, broadcastTime, pollNow) {
|
|||||||
// failed — which matters most on a resumed wait, where the
|
// failed — which matters most on a resumed wait, where the
|
||||||
// first poll is already past the deadline.
|
// first poll is already past the deadline.
|
||||||
answered = false;
|
answered = false;
|
||||||
log.errorf("poll receipt failed:", e.message);
|
log.errorf("poll receipt failed:", e.shortMessage || e.message);
|
||||||
}
|
}
|
||||||
// The lookup is async: the wait may have ended while it was in
|
// The lookup is async: the wait may have ended while it was in
|
||||||
// flight, in which case this result must not touch the view.
|
// flight, in which case this result must not touch the view.
|
||||||
@@ -202,8 +206,9 @@ function restoreWait() {
|
|||||||
if (!info || typeof info !== "object" || Array.isArray(info)) return false;
|
if (!info || typeof info !== "object" || Array.isArray(info)) return false;
|
||||||
// A string is the whole requirement: the empty string is what a
|
// A string is the whole requirement: the empty string is what a
|
||||||
// contract-deployment approval persists (approval.js writes `to: toAddr
|
// contract-deployment approval persists (approval.js writes `to: toAddr
|
||||||
// || ""`), and both fields render harmlessly when empty, so refusing it
|
// || ""`), an empty `to` renders as a contract creation and an empty
|
||||||
// would abandon a wait the live path itself created.
|
// amount renders harmlessly, so refusing it would abandon a wait the live
|
||||||
|
// path itself created.
|
||||||
if (typeof info.to !== "string") return false;
|
if (typeof info.to !== "string") return false;
|
||||||
if (typeof info.amount !== "string") return false;
|
if (typeof info.amount !== "string") return false;
|
||||||
if (typeof w.broadcastTime !== "number" || !isFinite(w.broadcastTime)) {
|
if (typeof w.broadcastTime !== "number" || !isFinite(w.broadcastTime)) {
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ async function getFullWarnings(address, provider, options = {}) {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.errorf("contract check failed:", e.message);
|
log.errorf("contract check failed:", e.shortMessage || e.message);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Skip tx count check for contracts — they may legitimately have
|
// Skip tx count check for contracts — they may legitimately have
|
||||||
@@ -92,7 +92,7 @@ async function getFullWarnings(address, provider, options = {}) {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.errorf("tx count check failed:", e.message);
|
log.errorf("tx count check failed:", e.shortMessage || e.message);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -6,10 +6,10 @@
|
|||||||
// (`src/shared/uniswap.js`) — and a fix applied to one of them left the other
|
// (`src/shared/uniswap.js`) — and a fix applied to one of them left the other
|
||||||
// two showing a different number for the same value.
|
// two showing a different number for the same value.
|
||||||
//
|
//
|
||||||
// The two functions below are the two policies, not two implementations of
|
// The two truncation functions below are the two policies, not two
|
||||||
// one: summary lists truncate, and the screens that state what is being
|
// implementations of one: summary lists truncate, and the screens that state
|
||||||
// authorized truncate with a floor. Keeping them adjacent is the point, so a
|
// what is being authorized truncate with a floor. Keeping them adjacent is the
|
||||||
// change to the rule cannot reach one screen and miss another.
|
// point, so a change to the rule cannot reach one screen and miss another.
|
||||||
|
|
||||||
// Truncate to exactly four decimal places. Truncation, never rounding: an
|
// Truncate to exactly four decimal places. Truncation, never rounding: an
|
||||||
// amount must never be displayed as larger than it is, so 0.99999 stays
|
// amount must never be displayed as larger than it is, so 0.99999 stays
|
||||||
@@ -43,4 +43,18 @@ function truncateAmountNeverZero(val) {
|
|||||||
return parts[0] + "." + parts[1].slice(0, sig + 1);
|
return parts[0] + "." + parts[1].slice(0, sig + 1);
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { truncateAmount, truncateAmountNeverZero };
|
// Whether a stored token balance is a holding below 0.000001. The balance
|
||||||
|
// lists, the send-screen token selector, the address total and the
|
||||||
|
// remove-address warning leave such a holding out; the Send and confirmation
|
||||||
|
// screens show it when its token is the one being sent. Exact, because
|
||||||
|
// src/shared/balances.js stores plain decimal digits: below 0.000001 the
|
||||||
|
// balance reads "0.000000" and then more digits.
|
||||||
|
function isBelowOneMillionth(balance) {
|
||||||
|
return typeof balance === "string" && balance.startsWith("0.000000");
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
truncateAmount,
|
||||||
|
truncateAmountNeverZero,
|
||||||
|
isBelowOneMillionth,
|
||||||
|
};
|
||||||
|
|||||||
@@ -23,11 +23,11 @@
|
|||||||
// disputed is refused rather than guessed at.
|
// disputed is refused rather than guessed at.
|
||||||
|
|
||||||
// Solidity's decimals() is a uint8, and every source here is ultimately
|
// Solidity's decimals() is a uint8, and every source here is ultimately
|
||||||
// reporting that call's result. toDecimals() is that check, shared with the
|
// reporting that call's result. toDecimals() is that check, stopping at the 80
|
||||||
// send path rather than copied: the bundled list stores numbers, the
|
// places formatUnits() accepts, and shared with the send path rather than
|
||||||
// explorer's copy arrives as a string, and a token the user added by hand
|
// copied: the bundled list stores numbers, the explorer's copy arrives as a
|
||||||
// carries whatever lookupTokenInfo() got back, so the accepted types are
|
// string, and a token the user added by hand carries whatever lookupTokenInfo()
|
||||||
// enumerated rather than coerced.
|
// got back, so the accepted types are enumerated rather than coerced.
|
||||||
const { toDecimals } = require("./transferAmount");
|
const { toDecimals } = require("./transferAmount");
|
||||||
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
||||||
const { isSpoofedSymbol } = require("./symbolSpoof");
|
const { isSpoofedSymbol } = require("./symbolSpoof");
|
||||||
|
|||||||
@@ -51,11 +51,15 @@ const POPULATE_TIMEOUT_MS = 20000;
|
|||||||
// passed to ethers: the object is page-controlled, and a future ethers that
|
// passed to ethers: the object is page-controlled, and a future ethers that
|
||||||
// learns to carry a new transaction field must not start picking one up out of
|
// learns to carry a new transaction field must not start picking one up out of
|
||||||
// it without this module knowing.
|
// it without this module knowing.
|
||||||
|
//
|
||||||
|
// The nonce is not taken from the page; it is always the account's next nonce
|
||||||
|
// from the network. A page that chose it could replace one of the user's
|
||||||
|
// pending transactions (the same nonce at a higher fee) or leave this one stuck
|
||||||
|
// behind a gap (a nonce above the next one).
|
||||||
const REQUEST_FIELDS = [
|
const REQUEST_FIELDS = [
|
||||||
"to",
|
"to",
|
||||||
"value",
|
"value",
|
||||||
"data",
|
"data",
|
||||||
"nonce",
|
|
||||||
"gasLimit",
|
"gasLimit",
|
||||||
"gasPrice",
|
"gasPrice",
|
||||||
"maxFeePerGas",
|
"maxFeePerGas",
|
||||||
|
|||||||
+17
-19
@@ -10,7 +10,7 @@ const {
|
|||||||
} = require("ethers");
|
} = require("ethers");
|
||||||
const { ERC20_ABI } = require("./constants");
|
const { ERC20_ABI } = require("./constants");
|
||||||
const { NETWORKS } = require("./networks");
|
const { NETWORKS } = require("./networks");
|
||||||
const { log, debugFetch } = require("./log");
|
const { log, debugFetch, urlOrigin } = require("./log");
|
||||||
const { deriveAddressFromXpub } = require("./wallet");
|
const { deriveAddressFromXpub } = require("./wallet");
|
||||||
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
||||||
const { LOW_HOLDER_THRESHOLD, parseHoldersCount } = require("./holders");
|
const { LOW_HOLDER_THRESHOLD, parseHoldersCount } = require("./holders");
|
||||||
@@ -52,19 +52,16 @@ function requireNetworkId(networkId) {
|
|||||||
return net;
|
return net;
|
||||||
}
|
}
|
||||||
|
|
||||||
function formatBalance(wei) {
|
// A token balance as an exact decimal string, never cut: a cut stores a small
|
||||||
const eth = formatEther(wei);
|
// nonzero holding as zero. fetchTokenBalances() stores every nonzero holding of
|
||||||
const parts = eth.split(".");
|
// a token it admits, however small; the screens that leave out one below
|
||||||
if (parts.length === 1) return eth + ".0";
|
// 0.000001 decide that themselves, through isBelowOneMillionth() in
|
||||||
const dec = parts[1].slice(0, 6).replace(/0+$/, "") || "0";
|
// src/shared/amountDisplay.js.
|
||||||
return parts[0] + "." + dec;
|
|
||||||
}
|
|
||||||
|
|
||||||
function formatTokenBalance(raw, decimals) {
|
function formatTokenBalance(raw, decimals) {
|
||||||
const val = formatUnits(raw, decimals);
|
const val = formatUnits(raw, decimals);
|
||||||
const parts = val.split(".");
|
const parts = val.split(".");
|
||||||
if (parts.length === 1) return val + ".0";
|
if (parts.length === 1) return val + ".0";
|
||||||
const dec = parts[1].slice(0, 6).replace(/0+$/, "") || "0";
|
const dec = parts[1].replace(/0+$/, "") || "0";
|
||||||
return parts[0] + "." + dec;
|
return parts[0] + "." + dec;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -149,11 +146,7 @@ async function fetchTokenBalances(address, blockscoutUrl, trackedTokens) {
|
|||||||
const scale = known !== null ? known : decimals;
|
const scale = known !== null ? known : decimals;
|
||||||
// null is a holding of an amount that cannot be stated, which is
|
// null is a holding of an amount that cannot be stated, which is
|
||||||
// not the same as a holding of zero, and must never render as one.
|
// not the same as a holding of zero, and must never render as one.
|
||||||
// With a scale, the display filter proper applies: a balance that
|
|
||||||
// rounds to zero at six places is dust and is not listed. Without
|
|
||||||
// one there is no such judgement to make, and the row is kept.
|
|
||||||
const bal = scale === null ? null : formatTokenBalance(raw, scale);
|
const bal = scale === null ? null : formatTokenBalance(raw, scale);
|
||||||
if (bal === "0.0") continue;
|
|
||||||
// null means the explorer reported no count, which is not the
|
// null means the explorer reported no count, which is not the
|
||||||
// same as a count of zero. This gate is not the low-holder
|
// same as a count of zero. This gate is not the low-holder
|
||||||
// display filter: it has no user-facing off switch and governs
|
// display filter: it has no user-facing off switch and governs
|
||||||
@@ -210,7 +203,7 @@ async function refreshBalances(
|
|||||||
trackedTokens,
|
trackedTokens,
|
||||||
networkId,
|
networkId,
|
||||||
) {
|
) {
|
||||||
log.debugf("refreshBalances start, rpc:", rpcUrl);
|
log.debugf("refreshBalances start, rpc:", urlOrigin(rpcUrl));
|
||||||
const provider = getProvider(rpcUrl, networkId);
|
const provider = getProvider(rpcUrl, networkId);
|
||||||
const updates = [];
|
const updates = [];
|
||||||
|
|
||||||
@@ -221,7 +214,9 @@ async function refreshBalances(
|
|||||||
provider
|
provider
|
||||||
.getBalance(addr.address)
|
.getBalance(addr.address)
|
||||||
.then((bal) => {
|
.then((bal) => {
|
||||||
addr.balance = formatBalance(bal);
|
// Exact, never cut: a cut here stores a small nonzero
|
||||||
|
// balance as zero.
|
||||||
|
addr.balance = formatEther(bal);
|
||||||
log.debugf("ETH balance", addr.address, addr.balance);
|
log.debugf("ETH balance", addr.address, addr.balance);
|
||||||
})
|
})
|
||||||
.catch((e) => {
|
.catch((e) => {
|
||||||
@@ -251,7 +246,7 @@ async function refreshBalances(
|
|||||||
log.errorf(
|
log.errorf(
|
||||||
"ENS reverse failed",
|
"ENS reverse failed",
|
||||||
addr.address,
|
addr.address,
|
||||||
e.message,
|
e.shortMessage || e.message,
|
||||||
);
|
);
|
||||||
// Keep existing addr.ensName if we had one
|
// Keep existing addr.ensName if we had one
|
||||||
}),
|
}),
|
||||||
@@ -285,7 +280,7 @@ async function refreshBalances(
|
|||||||
// Look up token metadata from its contract.
|
// Look up token metadata from its contract.
|
||||||
// Calls symbol() and decimals() to verify it implements ERC-20.
|
// Calls symbol() and decimals() to verify it implements ERC-20.
|
||||||
async function lookupTokenInfo(contractAddress, rpcUrl, networkId) {
|
async function lookupTokenInfo(contractAddress, rpcUrl, networkId) {
|
||||||
log.debugf("lookupTokenInfo", contractAddress, "rpc:", rpcUrl);
|
log.debugf("lookupTokenInfo", contractAddress, "rpc:", urlOrigin(rpcUrl));
|
||||||
const provider = getProvider(rpcUrl, networkId);
|
const provider = getProvider(rpcUrl, networkId);
|
||||||
const contract = new Contract(contractAddress, ERC20_ABI, provider);
|
const contract = new Contract(contractAddress, ERC20_ABI, provider);
|
||||||
|
|
||||||
@@ -310,7 +305,10 @@ async function lookupTokenInfo(contractAddress, rpcUrl, networkId) {
|
|||||||
name = await contract.name();
|
name = await contract.name();
|
||||||
log.debugf("name() =", name);
|
log.debugf("name() =", name);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.warnf("name() failed, using symbol as name:", e.message);
|
log.warnf(
|
||||||
|
"name() failed, using symbol as name:",
|
||||||
|
e.shortMessage || e.message,
|
||||||
|
);
|
||||||
name = symbol;
|
name = symbol;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+5
-1
@@ -42,7 +42,11 @@ async function resolveEnsName(address, rpcUrl, networkId) {
|
|||||||
setCache(address, name);
|
setCache(address, name);
|
||||||
return name;
|
return name;
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.errorf("ENS reverse lookup failed", address, e.message);
|
log.errorf(
|
||||||
|
"ENS reverse lookup failed",
|
||||||
|
address,
|
||||||
|
e.shortMessage || e.message,
|
||||||
|
);
|
||||||
// Don't cache failures — let subsequent lookups retry
|
// Don't cache failures — let subsequent lookups retry
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|||||||
+25
-5
@@ -42,14 +42,34 @@ const log = {
|
|||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
// Fetch wrapper that debug-logs every request and response.
|
// The origin (scheme, host and port) of a URL, for logging in place of the
|
||||||
|
// URL: RPC providers put API keys in the path or the query string, and a URL
|
||||||
|
// can carry a user name and password, which the origin leaves out. A URL that
|
||||||
|
// does not parse gives "", so logging never stops a request.
|
||||||
|
function urlOrigin(url) {
|
||||||
|
try {
|
||||||
|
return new URL(url).origin;
|
||||||
|
} catch {
|
||||||
|
return "";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Fetch wrapper that debug-logs every request and response. It logs the
|
||||||
|
// URL's origin and, for a JSON-RPC body, the method name: never the full URL
|
||||||
|
// or body, which can carry an API key or a signed transaction.
|
||||||
async function debugFetch(url, opts) {
|
async function debugFetch(url, opts) {
|
||||||
const method = (opts && opts.method) || "GET";
|
const method = (opts && opts.method) || "GET";
|
||||||
const body = opts && opts.body;
|
const origin = urlOrigin(url);
|
||||||
log.debugf("fetch →", method, url, body || "");
|
let rpcMethod = "";
|
||||||
|
try {
|
||||||
|
rpcMethod = JSON.parse(opts.body).method || "";
|
||||||
|
} catch {
|
||||||
|
// no body, or a body that is not JSON
|
||||||
|
}
|
||||||
|
log.debugf("fetch →", method, origin, rpcMethod);
|
||||||
const resp = await fetch(url, opts);
|
const resp = await fetch(url, opts);
|
||||||
log.debugf("fetch ←", resp.status, url);
|
log.debugf("fetch ←", resp.status, origin);
|
||||||
return resp;
|
return resp;
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { log, debugFetch, setRuntimeDebug, isDebug };
|
module.exports = { log, debugFetch, urlOrigin, setRuntimeDebug, isDebug };
|
||||||
|
|||||||
@@ -102,11 +102,11 @@ function tokenRefs(value) {
|
|||||||
|
|
||||||
// A list of strings, for the fields whose entries are dereferenced as text:
|
// A list of strings, for the fields whose entries are dereferenced as text:
|
||||||
// fraudContracts (`a.toLowerCase()` in src/popup/views/send.js and
|
// fraudContracts (`a.toLowerCase()` in src/popup/views/send.js and
|
||||||
// src/shared/transactions.js) and each address's hostname list in the site maps
|
// src/shared/transactions.js) and each address's origin list in the site maps
|
||||||
// below (`h !== host` filters, `list.includes(hostname)` in the background).
|
// below (`o !== origin` filters, `list.includes(origin)` in the background).
|
||||||
//
|
//
|
||||||
// Same rule as tokenRefs(), for the same reason: the container AND the entries,
|
// Same rule as tokenRefs(), for the same reason: the container AND the entries,
|
||||||
// with a malformed entry DROPPED rather than repaired. A number in a hostname
|
// with a malformed entry DROPPED rather than repaired. A number in an origin
|
||||||
// list names no site and a number in fraudContracts names no contract, so there
|
// list names no site and a number in fraudContracts names no contract, so there
|
||||||
// is nothing to repair either to, and the empty list is a legitimate value that
|
// is nothing to repair either to, and the empty list is a legitimate value that
|
||||||
// survives. The result is a fresh array of primitives, so it shares no
|
// survives. The result is a fresh array of primitives, so it shares no
|
||||||
@@ -116,21 +116,22 @@ function textList(value) {
|
|||||||
return value.filter((entry) => typeof entry === "string");
|
return value.filter((entry) => typeof entry === "string");
|
||||||
}
|
}
|
||||||
|
|
||||||
// allowedSites / deniedSites: { [address]: [hostname, ...] }.
|
// allowedSites / deniedSites: { [address]: [origin, ...] }, each origin the
|
||||||
|
// full scheme://host[:port] of a site.
|
||||||
//
|
//
|
||||||
// The container check these had (truthy and not an array) is not the floor:
|
// The container check these had (truthy and not an array) is not the floor:
|
||||||
// `{"0xabc…": "notalist"}` IS a non-array object, and the dereference is one
|
// `{"0xabc…": "notalist"}` IS a non-array object, and the dereference is one
|
||||||
// level below it. saveState() merges these maps per key and then per hostname
|
// level below it. saveState() merges these maps per key and then per origin
|
||||||
// WITHIN each key, so a stored value that is not a list reaches `base.map()` in
|
// WITHIN each key, so a stored value that is not a list reaches `base.map()` in
|
||||||
// mergeListByIdentity() (src/shared/state.js) and throws — after the popup has
|
// mergeListByIdentity() (src/shared/state.js) and throws — after the popup has
|
||||||
// rendered, which is why every save from then on failed while the UI looked
|
// rendered, which is why every save from then on failed while the UI looked
|
||||||
// healthy (https://git.eeqj.de/sneak/AutistMask/issues/362). The Settings
|
// healthy (https://git.eeqj.de/sneak/AutistMask/issues/362). The Settings
|
||||||
// revoke button (`list.filter()`), and the background's
|
// revoke button (`list.filter()`), and the background's
|
||||||
// `allowed.includes(hostname)` gate, dereference it the same way; on that last
|
// `allowed.includes(origin)` gate, dereference it the same way; on that last
|
||||||
// one a stored string would also answer a SUBSTRING match, so a corrupt map
|
// one a stored string would also answer a SUBSTRING match, so a corrupt map
|
||||||
// could widen a site permission rather than merely throw.
|
// could widen a site permission rather than merely throw.
|
||||||
//
|
//
|
||||||
// An address key whose value is not a list of hostnames is dropped entirely: it
|
// An address key whose value is not a list of origins is dropped entirely: it
|
||||||
// grants and denies nothing, and dropping it fails closed. A stored own
|
// grants and denies nothing, and dropping it fails closed. A stored own
|
||||||
// "__proto__" key — which JSON can carry — is dropped for the same reason: it
|
// "__proto__" key — which JSON can carry — is dropped for the same reason: it
|
||||||
// can never be a wallet address, so it grants nothing either, and keeping it
|
// can never be a wallet address, so it grants nothing either, and keeping it
|
||||||
@@ -143,9 +144,9 @@ function siteMap(value) {
|
|||||||
if (!isRecord(value)) return out;
|
if (!isRecord(value)) return out;
|
||||||
for (const address of Object.keys(value)) {
|
for (const address of Object.keys(value)) {
|
||||||
if (address === "__proto__") continue;
|
if (address === "__proto__") continue;
|
||||||
const hostnames = textList(value[address]);
|
const origins = textList(value[address]);
|
||||||
if (hostnames.length === 0) continue;
|
if (origins.length === 0) continue;
|
||||||
defineOwn(out, address, hostnames);
|
defineOwn(out, address, origins);
|
||||||
}
|
}
|
||||||
return out;
|
return out;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
// Price fetching with 5-minute cache, USD formatting, value aggregation.
|
// Price fetching with 5-minute cache, USD formatting, value aggregation.
|
||||||
|
|
||||||
const { getTopTokenPrices } = require("./tokenList");
|
const { getTopTokenPrices } = require("./tokenList");
|
||||||
|
const { isBelowOneMillionth } = require("./amountDisplay");
|
||||||
|
|
||||||
const PRICE_CACHE_TTL = 300000; // 5 minutes
|
const PRICE_CACHE_TTL = 300000; // 5 minutes
|
||||||
|
|
||||||
@@ -78,6 +79,9 @@ function getAddressValue(addr) {
|
|||||||
let usd = parseFloat(addr.balance || "0") * prices.ETH;
|
let usd = parseFloat(addr.balance || "0") * prices.ETH;
|
||||||
let partial = false;
|
let partial = false;
|
||||||
for (const token of addr.tokenBalances || []) {
|
for (const token of addr.tokenBalances || []) {
|
||||||
|
// A holding below 0.000001 is left out, as the balance lists leave it
|
||||||
|
// out, so the total never counts a holding the list does not show.
|
||||||
|
if (isBelowOneMillionth(token.balance)) continue;
|
||||||
// A null balance is a holding whose scale nothing knows, so it has no
|
// A null balance is a holding whose scale nothing knows, so it has no
|
||||||
// quantity to price — but it is still a holding, and a total that
|
// quantity to price — but it is still a holding, and a total that
|
||||||
// silently omits it would read as complete. That is exactly what
|
// silently omits it would read as complete. That is exactly what
|
||||||
|
|||||||
+10
-10
@@ -304,7 +304,7 @@ function mergeAddress(base, ours, theirs) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Merge a plain object keyed by string (allowedSites/deniedSites: address ->
|
// Merge a plain object keyed by string (allowedSites/deniedSites: address ->
|
||||||
// hostname list; networkEndpoints: networkId -> {rpcUrl, blockscoutUrl}) the
|
// origin list; networkEndpoints: networkId -> {rpcUrl, blockscoutUrl}) the
|
||||||
// same way mergeListByIdentity() merges an array — by key, not by whole-
|
// same way mergeListByIdentity() merges an array — by key, not by whole-
|
||||||
// object diff — so a key one page added or removed applies independently of
|
// object diff — so a key one page added or removed applies independently of
|
||||||
// a key another page edited. Unlike an array's identity function, an object
|
// a key another page edited. Unlike an array's identity function, an object
|
||||||
@@ -353,25 +353,25 @@ function mergeMapByKey(base, ours, theirs, mergeLeaf) {
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
// allowedSites/deniedSites: { [address]: [hostname, ...] }. The hostname
|
// allowedSites/deniedSites: { [address]: [origin, ...] }. The origin
|
||||||
// list is itself membership, not a leaf — the background appends a newly
|
// list is itself membership, not a leaf — the background appends a newly
|
||||||
// approved/denied hostname to it, and the Settings "revoke" button
|
// approved/denied origin to it, and the Settings "revoke" button
|
||||||
// (src/popup/views/settings.js) filters a hostname out of it in place, from a
|
// (src/popup/views/settings.js) filters an origin out of it in place, from a
|
||||||
// different page. Merge it the same way wallets are merged: identity is the
|
// different page. Merge it the same way wallets are merged: identity is the
|
||||||
// hostname itself, so a merged pair is always equal and mergeItem is a no-op
|
// origin itself, so a merged pair is always equal and mergeItem is a no-op
|
||||||
// pick.
|
// pick.
|
||||||
function mergeHostnameList(base, ours, theirs) {
|
function mergeOriginList(base, ours, theirs) {
|
||||||
return mergeListByIdentity(
|
return mergeListByIdentity(
|
||||||
base,
|
base,
|
||||||
ours,
|
ours,
|
||||||
theirs,
|
theirs,
|
||||||
(hostname) => hostname,
|
(origin) => origin,
|
||||||
(b, o, t) => t,
|
(b, o, t) => t,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
function mergeSiteMap(base, ours, theirs) {
|
function mergeSiteMap(base, ours, theirs) {
|
||||||
return mergeMapByKey(base, ours, theirs, mergeHostnameList);
|
return mergeMapByKey(base, ours, theirs, mergeOriginList);
|
||||||
}
|
}
|
||||||
|
|
||||||
// networkEndpoints: { [networkId]: {rpcUrl, blockscoutUrl} }.
|
// networkEndpoints: { [networkId]: {rpcUrl, blockscoutUrl} }.
|
||||||
@@ -422,8 +422,8 @@ function mergeNetworkEndpoints(base, ours, theirs) {
|
|||||||
// address) apply independently instead of colliding as the same field.
|
// address) apply independently instead of colliding as the same field.
|
||||||
//
|
//
|
||||||
// `allowedSites` and `deniedSites` get the same treatment (mergeSiteMap(),
|
// `allowedSites` and `deniedSites` get the same treatment (mergeSiteMap(),
|
||||||
// by address key and then by hostname within each address's list), for the
|
// by address key and then by origin within each address's list), for the
|
||||||
// identical reason: the background appends a newly approved/denied hostname
|
// identical reason: the background appends a newly approved/denied origin
|
||||||
// to them, and the Settings "revoke" button (src/popup/views/settings.js)
|
// to them, and the Settings "revoke" button (src/popup/views/settings.js)
|
||||||
// filters one out in place, from a different page. A whole-field diff here
|
// filters one out in place, from a different page. A whole-field diff here
|
||||||
// doesn't just lose data, it is a security defect — a stale page's save can
|
// doesn't just lose data, it is a security defect — a stale page's save can
|
||||||
|
|||||||
@@ -27,9 +27,11 @@
|
|||||||
|
|
||||||
const { parseUnits } = require("ethers");
|
const { parseUnits } = require("ethers");
|
||||||
|
|
||||||
// Solidity's decimals() returns a uint8, so anything outside that range is not
|
// Solidity's decimals() returns a uint8, but ethers' formatUnits() and
|
||||||
// an answer this wallet can use.
|
// parseUnits() refuse more than 80 decimal places ("invalid FixedNumber
|
||||||
const MAX_DECIMALS = 255;
|
// decimals (too large)"). A scale of 81 to 255 can be neither displayed nor
|
||||||
|
// encoded, so it is not an answer this wallet can use, the same as no answer.
|
||||||
|
const MAX_DECIMALS = 80;
|
||||||
|
|
||||||
const UNKNOWN_DISPLAYED_DECIMALS_MESSAGE =
|
const UNKNOWN_DISPLAYED_DECIMALS_MESSAGE =
|
||||||
"The transfer was not sent, because the number of decimal places this" +
|
"The transfer was not sent, because the number of decimal places this" +
|
||||||
@@ -55,7 +57,7 @@ function mismatchMessage(displayed, onChain) {
|
|||||||
// A decimals value from any source as a number, or null if it is not one.
|
// A decimals value from any source as a number, or null if it is not one.
|
||||||
// decimals() comes back from ethers as a bigint and the explorer's copy arrives
|
// decimals() comes back from ethers as a bigint and the explorer's copy arrives
|
||||||
// as a string, so both of those are accepted alongside a plain number; anything
|
// as a string, so both of those are accepted alongside a plain number; anything
|
||||||
// fractional, negative, out of uint8 range, or of any other type at all is not.
|
// fractional, negative, above MAX_DECIMALS, or of any other type at all is not.
|
||||||
//
|
//
|
||||||
// The types are enumerated rather than coerced because Number() is far too
|
// The types are enumerated rather than coerced because Number() is far too
|
||||||
// willing: Number([]) is 0 and Number(true) is 1, so a coercing check would
|
// willing: Number([]) is 0 and Number(true) is 1, so a coercing check would
|
||||||
|
|||||||
@@ -139,7 +139,15 @@ function validateTransfer({
|
|||||||
const feeFp = known ? feeWei : null;
|
const feeFp = known ? feeWei : null;
|
||||||
|
|
||||||
if (isErc20) {
|
if (isErc20) {
|
||||||
const tokenFp = toFixedPoint(tokenBalance) ?? 0n;
|
// A token can declare more than 18 decimals, and its balance is
|
||||||
|
// stored with all of them. Only the first 18 places (SCALE_DECIMALS)
|
||||||
|
// are read: an amount with more was refused above, so the places
|
||||||
|
// after them cannot decide whether the amount fits.
|
||||||
|
const tokenText =
|
||||||
|
typeof tokenBalance === "string"
|
||||||
|
? tokenBalance.replace(/(\.\d{18})\d+$/, "$1")
|
||||||
|
: tokenBalance;
|
||||||
|
const tokenFp = toFixedPoint(tokenText) ?? 0n;
|
||||||
if (amountFp > tokenFp) codes.push(CODES.INSUFFICIENT_TOKEN);
|
if (amountFp > tokenFp) codes.push(CODES.INSUFFICIENT_TOKEN);
|
||||||
if (feeFp !== null && feeFp > ethFp) {
|
if (feeFp !== null && feeFp > ethFp) {
|
||||||
codes.push(CODES.INSUFFICIENT_ETH_FOR_FEE);
|
codes.push(CODES.INSUFFICIENT_ETH_FOR_FEE);
|
||||||
|
|||||||
+41
-10
@@ -100,6 +100,13 @@ const NO_MINIMUM = "None (no minimum guaranteed)";
|
|||||||
// Permit2 amounts are uint160; the maximum is Permit2's "unbounded".
|
// Permit2 amounts are uint160; the maximum is Permit2's "unbounded".
|
||||||
const MAX_UINT160 = BigInt("0xffffffffffffffffffffffffffffffffffffffff");
|
const MAX_UINT160 = BigInt("0xffffffffffffffffffffffffffffffffffffffff");
|
||||||
|
|
||||||
|
// WETH, the token UNWRAP_WETH turns into ETH: on mainnet, then on Sepolia.
|
||||||
|
// decode() is not told the network, so it takes either.
|
||||||
|
const WETH_ADDRESSES = [
|
||||||
|
"0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2",
|
||||||
|
"0xfff9976782d46cc05630d1f6ebab18b2324d6b14",
|
||||||
|
];
|
||||||
|
|
||||||
// `decimals` is null when nothing knows this token's scale. It is not
|
// `decimals` is null when nothing knows this token's scale. It is not
|
||||||
// defaulted to 18: the swap lines land on the same approval screen as the
|
// defaulted to 18: the swap lines land on the same approval screen as the
|
||||||
// ERC-20 line, and a scale guessed there is what showed a 1,000 USDT swap as
|
// ERC-20 line, and a scale guessed there is what showed a 1,000 USDT swap as
|
||||||
@@ -198,11 +205,6 @@ function decodeV2SwapExactIn(input) {
|
|||||||
// Decode V2_SWAP_EXACT_OUT (command 0x09) input bytes.
|
// Decode V2_SWAP_EXACT_OUT (command 0x09) input bytes.
|
||||||
// ABI: (address recipient, uint256 amountOut, uint256 amountInMax,
|
// ABI: (address recipient, uint256 amountOut, uint256 amountInMax,
|
||||||
// address[] path, bool payerIsUser)
|
// address[] path, bool payerIsUser)
|
||||||
//
|
|
||||||
// Nothing calls this: decode() has no 0x09 arm, so a V2 exact-out swap gets
|
|
||||||
// its command name and no token or amount detail. Kept for the fix, which is
|
|
||||||
// https://git.eeqj.de/sneak/AutistMask/issues/283.
|
|
||||||
// eslint-disable-next-line no-unused-vars
|
|
||||||
function decodeV2SwapExactOut(input) {
|
function decodeV2SwapExactOut(input) {
|
||||||
try {
|
try {
|
||||||
const d = coder.decode(
|
const d = coder.decode(
|
||||||
@@ -447,6 +449,7 @@ function decode(data, toAddress, sources) {
|
|||||||
let outputToken = null;
|
let outputToken = null;
|
||||||
let minOutput = null;
|
let minOutput = null;
|
||||||
let hasUnwrapWeth = false;
|
let hasUnwrapWeth = false;
|
||||||
|
let hasV2ExactOut = false;
|
||||||
const commandNames = [];
|
const commandNames = [];
|
||||||
|
|
||||||
// THE INVARIANT: an amount and the token it is counted in always come
|
// THE INVARIANT: an amount and the token it is counted in always come
|
||||||
@@ -521,6 +524,16 @@ function decode(data, toAddress, sources) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (cmdId === 0x09) {
|
||||||
|
// Buys exactly amountOut and spends at most amountInMax.
|
||||||
|
hasV2ExactOut = true;
|
||||||
|
const s = decodeV2SwapExactOut(inputs[i]);
|
||||||
|
if (s) {
|
||||||
|
setInputOnce(s.tokenIn, s.amountInMax);
|
||||||
|
setOutput(s.tokenOut, s.amountOut);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (cmdId === 0x0b) {
|
if (cmdId === 0x0b) {
|
||||||
const w = decodeWrapEth(inputs[i]);
|
const w = decodeWrapEth(inputs[i]);
|
||||||
if (w) {
|
if (w) {
|
||||||
@@ -559,12 +572,19 @@ function decode(data, toAddress, sources) {
|
|||||||
|
|
||||||
// Resolve token info. A null token on either side means the calldata
|
// Resolve token info. A null token on either side means the calldata
|
||||||
// named no currency for it; tokenInfo() refuses rather than calling it
|
// named no currency for it; tokenInfo() refuses rather than calling it
|
||||||
// ETH. UNWRAP_WETH is the one output that is ETH without a currency to
|
// ETH. UNWRAP_WETH turns WETH into ETH, so it makes the output ETH
|
||||||
// decode, and it is answered here rather than left to that rule.
|
// when the output side is WETH, or when no step set the output side.
|
||||||
|
// Any other output keeps its own token and figure: a swap that buys
|
||||||
|
// USDC and then unwraps the WETH it did not spend receives USDC.
|
||||||
|
const outputIsWeth =
|
||||||
|
present(outputToken) &&
|
||||||
|
WETH_ADDRESSES.includes(outputToken.toLowerCase());
|
||||||
|
const outputUnset = !present(outputToken) && !present(minOutput);
|
||||||
const inInfo = tokenInfo(inputToken, sources);
|
const inInfo = tokenInfo(inputToken, sources);
|
||||||
const outInfo = hasUnwrapWeth
|
const outInfo =
|
||||||
? { symbol: "ETH", decimals: 18, address: null }
|
hasUnwrapWeth && (outputIsWeth || outputUnset)
|
||||||
: tokenInfo(outputToken, sources);
|
? { symbol: "ETH", decimals: 18, address: null }
|
||||||
|
: tokenInfo(outputToken, sources);
|
||||||
|
|
||||||
const inSymbol = inInfo.symbol;
|
const inSymbol = inInfo.symbol;
|
||||||
const outSymbol = outInfo.symbol;
|
const outSymbol = outInfo.symbol;
|
||||||
@@ -613,6 +633,17 @@ function decode(data, toAddress, sources) {
|
|||||||
amount = { raw: OPEN_DELTA_AMOUNT, display: OPEN_DELTA_AMOUNT };
|
amount = { raw: OPEN_DELTA_AMOUNT, display: OPEN_DELTA_AMOUNT };
|
||||||
} else if (inputAmount >= MAX_UINT160) {
|
} else if (inputAmount >= MAX_UINT160) {
|
||||||
amount = { raw: "Unlimited", display: "Unlimited" };
|
amount = { raw: "Unlimited", display: "Unlimited" };
|
||||||
|
} else if (hasV2ExactOut) {
|
||||||
|
// A V2 exact-out swap spends at most this figure, whichever
|
||||||
|
// step set the line (its amountInMax, the WRAP_ETH of a swap
|
||||||
|
// paid in ETH, a permit), so it is said to be a maximum, in
|
||||||
|
// `raw` too: the wait, success and error screens show `raw` as
|
||||||
|
// the transaction's amount.
|
||||||
|
const most = amountText(inputAmount, inInfo);
|
||||||
|
amount = {
|
||||||
|
raw: "Up to " + most.raw,
|
||||||
|
display: "Up to " + most.display,
|
||||||
|
};
|
||||||
} else {
|
} else {
|
||||||
amount = amountText(inputAmount, inInfo);
|
amount = amountText(inputAmount, inInfo);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -41,12 +41,10 @@ const DEFECTS = {
|
|||||||
"changed or removed, and this wallet stays until you delete " +
|
"changed or removed, and this wallet stays until you delete " +
|
||||||
"it yourself.",
|
"it yourself.",
|
||||||
],
|
],
|
||||||
// One sentence for the places that have room for one: the flash on a
|
// One line, for the flash on a blocked Send and the inline error on
|
||||||
// blocked Send, the inline error on the approval screens.
|
// the approval screens. It must fit on the flash line; see showFlash()
|
||||||
shortMessage:
|
// in src/popup/views/helpers.js.
|
||||||
"This wallet cannot sign, because it was imported from an " +
|
shortMessage: "This wallet cannot sign. See the wallet list.",
|
||||||
"extended private key that is not a master key. The wallet list " +
|
|
||||||
"explains what happened.",
|
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -12,12 +12,15 @@ function sameAddress(a, b) {
|
|||||||
return String(a).toLowerCase() === String(b).toLowerCase();
|
return String(a).toLowerCase() === String(b).toLowerCase();
|
||||||
}
|
}
|
||||||
|
|
||||||
// Forget every site permission held against the given addresses.
|
// Forget every site permission held against the given addresses: the
|
||||||
|
// remembered ones in `state`, and the connections approved without
|
||||||
|
// "Remember", which only the background holds, in memory.
|
||||||
function dropSitePermissions(state, addresses) {
|
function dropSitePermissions(state, addresses) {
|
||||||
for (const addr of addresses) {
|
for (const addr of addresses) {
|
||||||
delete state.allowedSites[addr];
|
delete state.allowedSites[addr];
|
||||||
delete state.deniedSites[addr];
|
delete state.deniedSites[addr];
|
||||||
}
|
}
|
||||||
|
notify({ type: "AUTISTMASK_ADDRESSES_REMOVED", addresses });
|
||||||
}
|
}
|
||||||
|
|
||||||
// Remove wallet `walletIdx` from `state` and repair the derived state.
|
// Remove wallet `walletIdx` from `state` and repair the derived state.
|
||||||
|
|||||||
@@ -184,6 +184,22 @@ describe("decodeCalldata amount", () => {
|
|||||||
expect(line).not.toMatch(/0\.0000/);
|
expect(line).not.toMatch(/0\.0000/);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// A token added by hand carries whatever its decimals() returned, and a
|
||||||
|
// uint8 reaches 255, but formatUnits() throws above 80. The throw left the
|
||||||
|
// call undecoded rather than refused
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/350).
|
||||||
|
test("a token reporting more than 80 decimals shows base units", () => {
|
||||||
|
state.trackedTokens = [
|
||||||
|
{ address: NOVEL_TOKEN, symbol: "NOVEL", decimals: 81 },
|
||||||
|
];
|
||||||
|
expect(
|
||||||
|
amountLine(transferData(FIVE_THOUSAND_AT_SIX), NOVEL_TOKEN),
|
||||||
|
).toBe("5000000000 base units (decimals unknown)");
|
||||||
|
expect(amountLine(approveData(FIVE_THOUSAND_AT_SIX), NOVEL_TOKEN)).toBe(
|
||||||
|
"5000000000 base units (decimals unknown)",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
test("an unbounded allowance is still named, with or without a scale", () => {
|
test("an unbounded allowance is still named, with or without a scale", () => {
|
||||||
expect(amountLine(approveData(MAX_UINT256), NOVEL_TOKEN)).toBe(
|
expect(amountLine(approveData(MAX_UINT256), NOVEL_TOKEN)).toBe(
|
||||||
"Unlimited",
|
"Unlimited",
|
||||||
|
|||||||
@@ -0,0 +1,167 @@
|
|||||||
|
// A nonce the page supplies is not used
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/404). With it a page could
|
||||||
|
// replace one of the user's pending transactions (the same nonce at a higher
|
||||||
|
// fee) or leave the new one stuck behind a gap, so the transaction is always
|
||||||
|
// given the account's next nonce from the network.
|
||||||
|
//
|
||||||
|
// Driven through the preparation the background runs on a page's
|
||||||
|
// eth_sendTransaction (src/shared/approvalTx.js) and the real approval screen,
|
||||||
|
// password and Confirm included, against a minimal DOM stub in the shape
|
||||||
|
// tests/approvalOrigin.test.js uses. The vault is mocked so that no password
|
||||||
|
// has to be hashed.
|
||||||
|
|
||||||
|
jest.mock("../src/shared/vault", () => ({
|
||||||
|
decryptWithPassword: jest.fn(),
|
||||||
|
}));
|
||||||
|
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const { Network, Transaction } = require("ethers");
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const { decryptWithPassword } = require("../src/shared/vault");
|
||||||
|
const { prepareApprovalTx } = require("../src/shared/approvalTx");
|
||||||
|
const approval = require("../src/popup/views/approval");
|
||||||
|
|
||||||
|
// A well-known test phrase, and its first address.
|
||||||
|
const PHRASE = "test test test test test test test test test test test junk";
|
||||||
|
const FROM = "0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266";
|
||||||
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
|
// The account's next nonce, as the network reports it.
|
||||||
|
const NETWORK_NONCE = 7;
|
||||||
|
|
||||||
|
const network = {
|
||||||
|
getNetwork: async () => Network.from(1),
|
||||||
|
getTransactionCount: async () => NETWORK_NONCE,
|
||||||
|
estimateGas: async () => 21000n,
|
||||||
|
getFeeData: async () => ({
|
||||||
|
gasPrice: 2000000000n,
|
||||||
|
maxFeePerGas: 2000000000n,
|
||||||
|
maxPriorityFeePerGas: 1000000000n,
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
|
||||||
|
function makeElement(id) {
|
||||||
|
const classes = new Set();
|
||||||
|
const el = {
|
||||||
|
id,
|
||||||
|
textContent: "",
|
||||||
|
value: "",
|
||||||
|
innerHTML: "",
|
||||||
|
disabled: false,
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
listeners: {},
|
||||||
|
classList: {
|
||||||
|
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||||
|
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||||
|
contains: (n) => classes.has(n),
|
||||||
|
toggle: (n, force) => {
|
||||||
|
const on = force === undefined ? !classes.has(n) : force;
|
||||||
|
if (on) classes.add(n);
|
||||||
|
else classes.delete(n);
|
||||||
|
return on;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
addEventListener: (name, fn) => {
|
||||||
|
el.listeners[name] = el.listeners[name] || [];
|
||||||
|
el.listeners[name].push(fn);
|
||||||
|
},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
appendChild: () => {},
|
||||||
|
};
|
||||||
|
// Views reach for .parentElement to hide whole sections.
|
||||||
|
Object.defineProperty(el, "parentElement", {
|
||||||
|
get: () => node(id + "-parent"),
|
||||||
|
});
|
||||||
|
return el;
|
||||||
|
}
|
||||||
|
|
||||||
|
function makeDocument() {
|
||||||
|
const els = new Map();
|
||||||
|
return {
|
||||||
|
getElementById(id) {
|
||||||
|
// The debug banner is created on demand by helpers.js; absent
|
||||||
|
// is the state a non-debug, non-testnet popup is in.
|
||||||
|
if (id === "debug-banner") return null;
|
||||||
|
if (!els.has(id)) els.set(id, makeElement(id));
|
||||||
|
return els.get(id);
|
||||||
|
},
|
||||||
|
createElement: () => makeElement("created"),
|
||||||
|
body: { prepend: () => {} },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function node(id) {
|
||||||
|
return globalThis.document.getElementById(id);
|
||||||
|
}
|
||||||
|
|
||||||
|
function click(id) {
|
||||||
|
return Promise.all((node(id).listeners.click || []).map((fn) => fn()));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Open the transaction approval screen the way the popup does: the background
|
||||||
|
// hands over the populated transaction and show() draws it. Returns every
|
||||||
|
// message the screen sends to the background. The background's answer to the
|
||||||
|
// signed transaction does not matter here; a retryable refusal keeps the
|
||||||
|
// screen where it is.
|
||||||
|
async function openTxApproval(approvedTx) {
|
||||||
|
const sent = [];
|
||||||
|
globalThis.document = makeDocument();
|
||||||
|
globalThis.window = { location: { search: "" }, close: () => {} };
|
||||||
|
globalThis.chrome.runtime = {
|
||||||
|
connect: () => ({ postMessage: () => {} }),
|
||||||
|
sendMessage: (msg, reply) => {
|
||||||
|
sent.push(msg);
|
||||||
|
if (!reply) return;
|
||||||
|
if (msg.type !== "AUTISTMASK_GET_APPROVAL") {
|
||||||
|
return reply({ error: "Not sent.", retryable: true });
|
||||||
|
}
|
||||||
|
reply({
|
||||||
|
type: "tx",
|
||||||
|
origin: "https://dapp.example",
|
||||||
|
isPhishingDomain: false,
|
||||||
|
approvedFrom: FROM,
|
||||||
|
approvedTx,
|
||||||
|
});
|
||||||
|
},
|
||||||
|
};
|
||||||
|
state.activeAddress = FROM;
|
||||||
|
state.wallets = [
|
||||||
|
{
|
||||||
|
type: "hd",
|
||||||
|
name: "Wallet 1",
|
||||||
|
xpub: "xpub-wallet-1",
|
||||||
|
encryptedSecret: "encrypted-secret-1",
|
||||||
|
nextIndex: 1,
|
||||||
|
addresses: [{ address: FROM, balance: "0", tokenBalances: [] }],
|
||||||
|
},
|
||||||
|
];
|
||||||
|
approval.init({});
|
||||||
|
await approval.show(1);
|
||||||
|
return sent;
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a page's nonce is replaced by the network's, on screen and in the signed transaction", async () => {
|
||||||
|
// What the background does with the page's request before it opens the
|
||||||
|
// approval window.
|
||||||
|
const approvedTx = await prepareApprovalTx(network, FROM, {
|
||||||
|
from: FROM,
|
||||||
|
to: RECIPIENT,
|
||||||
|
value: "0x0",
|
||||||
|
data: "0x",
|
||||||
|
nonce: "0x2",
|
||||||
|
});
|
||||||
|
|
||||||
|
const sent = await openTxApproval(approvedTx);
|
||||||
|
expect(node("approve-tx-nonce").textContent).toBe("7");
|
||||||
|
|
||||||
|
decryptWithPassword.mockResolvedValue(PHRASE);
|
||||||
|
node("approve-tx-password").value = "any password";
|
||||||
|
await click("btn-approve-tx");
|
||||||
|
|
||||||
|
const response = sent.find((msg) => msg.type === "AUTISTMASK_TX_RESPONSE");
|
||||||
|
expect(Transaction.from(response.rawSignedTx).nonce).toBe(NETWORK_NONCE);
|
||||||
|
});
|
||||||
@@ -0,0 +1,140 @@
|
|||||||
|
// The connection, transaction and signature prompts name the site by its full
|
||||||
|
// origin, scheme and port included, not by its bare hostname
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http,
|
||||||
|
// or on another port, of a host the user trusts over https must not raise a
|
||||||
|
// prompt that reads as that trusted site.
|
||||||
|
//
|
||||||
|
// Driven against a minimal DOM stub in the shape
|
||||||
|
// tests/contractCreation.test.js uses.
|
||||||
|
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const approval = require("../src/popup/views/approval");
|
||||||
|
|
||||||
|
// The site asking, in cleartext and on a port, which is what the hostname
|
||||||
|
// alone, dapp.example, used to hide.
|
||||||
|
const ORIGIN = "http://dapp.example:8080";
|
||||||
|
const FROM = "0x0000000000000000000000000000000000000a11";
|
||||||
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
|
function makeElement(id) {
|
||||||
|
const classes = new Set();
|
||||||
|
const el = {
|
||||||
|
id,
|
||||||
|
textContent: "",
|
||||||
|
value: "",
|
||||||
|
innerHTML: "",
|
||||||
|
disabled: false,
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
classList: {
|
||||||
|
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||||
|
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||||
|
contains: (n) => classes.has(n),
|
||||||
|
toggle: (n, force) => {
|
||||||
|
const on = force === undefined ? !classes.has(n) : force;
|
||||||
|
if (on) classes.add(n);
|
||||||
|
else classes.delete(n);
|
||||||
|
return on;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
addEventListener: () => {},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
appendChild: () => {},
|
||||||
|
};
|
||||||
|
// Views reach for .parentElement to hide whole sections.
|
||||||
|
Object.defineProperty(el, "parentElement", {
|
||||||
|
get: () => node(id + "-parent"),
|
||||||
|
});
|
||||||
|
return el;
|
||||||
|
}
|
||||||
|
|
||||||
|
function makeDocument() {
|
||||||
|
const els = new Map();
|
||||||
|
return {
|
||||||
|
getElementById(id) {
|
||||||
|
// The debug banner is created on demand by helpers.js; absent
|
||||||
|
// is the state a non-debug, non-testnet popup is in.
|
||||||
|
if (id === "debug-banner") return null;
|
||||||
|
if (!els.has(id)) els.set(id, makeElement(id));
|
||||||
|
return els.get(id);
|
||||||
|
},
|
||||||
|
createElement: () => makeElement("created"),
|
||||||
|
body: { prepend: () => {} },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function node(id) {
|
||||||
|
return globalThis.document.getElementById(id);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Open the prompt the background describes with `details`, the way the popup
|
||||||
|
// does: it asks for the approval and show() draws it.
|
||||||
|
async function openApproval(details) {
|
||||||
|
globalThis.document = makeDocument();
|
||||||
|
globalThis.window = { location: { search: "" } };
|
||||||
|
globalThis.chrome.runtime = {
|
||||||
|
connect: () => ({ postMessage: () => {} }),
|
||||||
|
sendMessage: (msg, reply) => {
|
||||||
|
if (!reply) return;
|
||||||
|
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||||
|
reply({
|
||||||
|
origin: ORIGIN,
|
||||||
|
isPhishingDomain: false,
|
||||||
|
approvedFrom: FROM,
|
||||||
|
...details,
|
||||||
|
});
|
||||||
|
},
|
||||||
|
};
|
||||||
|
approval.init({});
|
||||||
|
await approval.show(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
state.wallets = [];
|
||||||
|
state.activeAddress = FROM;
|
||||||
|
state.viewData = {};
|
||||||
|
state.viewStack = [];
|
||||||
|
state.currentView = null;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the connection prompt shows the origin", async () => {
|
||||||
|
await openApproval({});
|
||||||
|
expect(node("approve-origin").textContent).toBe(ORIGIN);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the transaction prompt shows the origin", async () => {
|
||||||
|
await openApproval({
|
||||||
|
type: "tx",
|
||||||
|
approvedTx: {
|
||||||
|
type: 2,
|
||||||
|
from: FROM,
|
||||||
|
chainId: "0x1",
|
||||||
|
nonce: "0x7",
|
||||||
|
gasLimit: "0x5208",
|
||||||
|
maxPriorityFeePerGas: "0x3b9aca00",
|
||||||
|
maxFeePerGas: "0x77359400",
|
||||||
|
to: RECIPIENT,
|
||||||
|
value: "0x0",
|
||||||
|
data: "0x",
|
||||||
|
accessList: [],
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(node("approve-tx-origin").textContent).toBe(ORIGIN);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the signature prompt shows the origin", async () => {
|
||||||
|
await openApproval({
|
||||||
|
type: "sign",
|
||||||
|
// "Hello" as the hex a dApp passes to personal_sign.
|
||||||
|
signParams: {
|
||||||
|
method: "personal_sign",
|
||||||
|
message: "0x48656c6c6f",
|
||||||
|
from: FROM,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(node("approve-sign-origin").textContent).toBe(ORIGIN);
|
||||||
|
});
|
||||||
@@ -121,7 +121,7 @@ describe("prepareApprovalTx", () => {
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("keeps a nonce, gas limit and fee the request did fix", async () => {
|
test("keeps a gas limit and fee the request did fix, but not its nonce", async () => {
|
||||||
const approved = await prepareApprovalTx(
|
const approved = await prepareApprovalTx(
|
||||||
providerWith(),
|
providerWith(),
|
||||||
signer.address,
|
signer.address,
|
||||||
@@ -133,7 +133,7 @@ describe("prepareApprovalTx", () => {
|
|||||||
maxPriorityFeePerGas: "0x3b9aca00",
|
maxPriorityFeePerGas: "0x3b9aca00",
|
||||||
},
|
},
|
||||||
);
|
);
|
||||||
expect(approved.nonce).toBe("0x2");
|
expect(approved.nonce).toBe("0x7");
|
||||||
expect(approved.gasLimit).toBe("0x30d40");
|
expect(approved.gasLimit).toBe("0x30d40");
|
||||||
expect(approved.maxFeePerGas).toBe("0x12a05f200");
|
expect(approved.maxFeePerGas).toBe("0x12a05f200");
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -25,6 +25,10 @@ const { Network, Wallet } = require("ethers");
|
|||||||
// what the user is actually shown.
|
// what the user is actually shown.
|
||||||
const { describeSigningFailure } = require("../src/shared/approvalVerify");
|
const { describeSigningFailure } = require("../src/shared/approvalVerify");
|
||||||
const { makeStorageStub } = require("./support/storageStub");
|
const { makeStorageStub } = require("./support/storageStub");
|
||||||
|
const {
|
||||||
|
removeAddressFromState,
|
||||||
|
removeWalletFromState,
|
||||||
|
} = require("../src/shared/walletDelete");
|
||||||
|
|
||||||
const SIGNER_KEY =
|
const SIGNER_KEY =
|
||||||
"0x59c6995e998f97a5a0044966f0945389dc9e86dae88c7a8412f4603b6b78690d";
|
"0x59c6995e998f97a5a0044966f0945389dc9e86dae88c7a8412f4603b6b78690d";
|
||||||
@@ -35,7 +39,6 @@ const other = new Wallet(OTHER_KEY);
|
|||||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
const ORIGIN = "https://dapp.example";
|
const ORIGIN = "https://dapp.example";
|
||||||
const HOSTNAME = "dapp.example";
|
|
||||||
// A page the wallet has never been connected to, whose requests are refused.
|
// A page the wallet has never been connected to, whose requests are refused.
|
||||||
const UNCONNECTED_ORIGIN = "https://stranger.example";
|
const UNCONNECTED_ORIGIN = "https://stranger.example";
|
||||||
const EXT_URL = "chrome-extension://autistmask/";
|
const EXT_URL = "chrome-extension://autistmask/";
|
||||||
@@ -71,6 +74,22 @@ const NONCE = 7;
|
|||||||
// "Hello AutistMask" as the hex string a dApp passes to personal_sign.
|
// "Hello AutistMask" as the hex string a dApp passes to personal_sign.
|
||||||
const MESSAGE = "0x48656c6c6f204175746973744d61736b";
|
const MESSAGE = "0x48656c6c6f204175746973744d61736b";
|
||||||
|
|
||||||
|
// An EIP-712 document as a dApp passes it to eth_signTypedData_v4. The
|
||||||
|
// background only carries it to the approval screen, so a small one does.
|
||||||
|
const TYPED_DATA = JSON.stringify({
|
||||||
|
domain: { name: "AutistMask Test", version: "1", chainId: 1 },
|
||||||
|
primaryType: "Note",
|
||||||
|
types: {
|
||||||
|
EIP712Domain: [
|
||||||
|
{ name: "name", type: "string" },
|
||||||
|
{ name: "version", type: "string" },
|
||||||
|
{ name: "chainId", type: "uint256" },
|
||||||
|
],
|
||||||
|
Note: [{ name: "contents", type: "string" }],
|
||||||
|
},
|
||||||
|
message: { contents: "Hello AutistMask" },
|
||||||
|
});
|
||||||
|
|
||||||
// The transaction the background populates and the approval screen displays.
|
// The transaction the background populates and the approval screen displays.
|
||||||
// The nonce is a parameter because the duplicate case turns on two artifacts
|
// The nonce is a parameter because the duplicate case turns on two artifacts
|
||||||
// differing in a field the dApp fixed nothing for.
|
// differing in a field the dApp fixed nothing for.
|
||||||
@@ -195,7 +214,7 @@ function loadBackground(options) {
|
|||||||
networkId: "mainnet",
|
networkId: "mainnet",
|
||||||
rpcUrl: "https://rpc.invalid",
|
rpcUrl: "https://rpc.invalid",
|
||||||
activeAddress: signer.address,
|
activeAddress: signer.address,
|
||||||
allowedSites: { [signer.address]: [HOSTNAME] },
|
allowedSites: { [signer.address]: [ORIGIN] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -226,6 +245,7 @@ function loadBackground(options) {
|
|||||||
// raised through action.openPopup() opens no window at all, so this is
|
// raised through action.openPopup() opens no window at all, so this is
|
||||||
// the only place its id appears.
|
// the only place its id appears.
|
||||||
const actionPopups = [];
|
const actionPopups = [];
|
||||||
|
const openPopup = jest.fn(() => Promise.resolve());
|
||||||
|
|
||||||
global.chrome = {
|
global.chrome = {
|
||||||
storage,
|
storage,
|
||||||
@@ -280,7 +300,7 @@ function loadBackground(options) {
|
|||||||
// popup: no window is created, so windows.onRemoved can never
|
// popup: no window is created, so windows.onRemoved can never
|
||||||
// fire for it and the port disconnect is the only close signal
|
// fire for it and the port disconnect is the only close signal
|
||||||
// that exists.
|
// that exists.
|
||||||
...(opts.actionPopup ? { openPopup: () => Promise.resolve() } : {}),
|
...(opts.actionPopup ? { openPopup } : {}),
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -327,7 +347,7 @@ function loadBackground(options) {
|
|||||||
|
|
||||||
// The same for a message-signing approval, which pins the signing address
|
// The same for a message-signing approval, which pins the signing address
|
||||||
// at approval time in exactly the same way.
|
// at approval time in exactly the same way.
|
||||||
function requestSign(from) {
|
function requestSign(from, origin) {
|
||||||
let rpcResult = null;
|
let rpcResult = null;
|
||||||
messageListener(
|
messageListener(
|
||||||
{
|
{
|
||||||
@@ -335,7 +355,7 @@ function loadBackground(options) {
|
|||||||
method: "personal_sign",
|
method: "personal_sign",
|
||||||
params: [MESSAGE, from || signer.address],
|
params: [MESSAGE, from || signer.address],
|
||||||
},
|
},
|
||||||
{ origin: ORIGIN },
|
{ origin: origin || ORIGIN },
|
||||||
(r) => {
|
(r) => {
|
||||||
rpcResult = r;
|
rpcResult = r;
|
||||||
},
|
},
|
||||||
@@ -349,6 +369,24 @@ function loadBackground(options) {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The same through eth_signTypedData_v4, whose params name the address
|
||||||
|
// first and the typed data second.
|
||||||
|
function requestTypedData() {
|
||||||
|
let rpcResult = null;
|
||||||
|
messageListener(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_RPC",
|
||||||
|
method: "eth_signTypedData_v4",
|
||||||
|
params: [signer.address, TYPED_DATA],
|
||||||
|
},
|
||||||
|
{ origin: ORIGIN },
|
||||||
|
(r) => {
|
||||||
|
rpcResult = r;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
return { result: () => rpcResult };
|
||||||
|
}
|
||||||
|
|
||||||
// A dApp asking to connect. The origin defaults to one the persisted
|
// A dApp asking to connect. The origin defaults to one the persisted
|
||||||
// state has never allowed, so the request really does raise a prompt
|
// state has never allowed, so the request really does raise a prompt
|
||||||
// instead of being answered from allowedSites.
|
// instead of being answered from allowedSites.
|
||||||
@@ -423,12 +461,15 @@ function loadBackground(options) {
|
|||||||
send,
|
send,
|
||||||
requestTx,
|
requestTx,
|
||||||
requestSign,
|
requestSign,
|
||||||
|
requestTypedData,
|
||||||
requestSite,
|
requestSite,
|
||||||
connectApproval,
|
connectApproval,
|
||||||
closeWindow,
|
closeWindow,
|
||||||
broadcastTransaction,
|
broadcastTransaction,
|
||||||
created,
|
created,
|
||||||
removed,
|
removed,
|
||||||
|
actionPopups,
|
||||||
|
openPopup,
|
||||||
storage,
|
storage,
|
||||||
// The user switching account in the toolbar popup, as the background
|
// The user switching account in the toolbar popup, as the background
|
||||||
// sees it: the persisted active address changes underneath a pending
|
// sees it: the persisted active address changes underneath a pending
|
||||||
@@ -818,6 +859,238 @@ describe("one transaction approval at a time", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// A page that asks again before the user has answered its last connection or
|
||||||
|
// signature request is refused, instead of opening one more window per call.
|
||||||
|
describe("one connection and one signature approval per site at a time", () => {
|
||||||
|
const PENDING_REFUSAL = {
|
||||||
|
error: {
|
||||||
|
code: -32002,
|
||||||
|
message: expect.stringMatching(/already waiting for your answer/),
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
test("a loop of eth_requestAccounts opens one approval and refuses the rest", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const requests = [];
|
||||||
|
for (let i = 0; i < 5; i++) requests.push(bg.requestSite());
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.created).toHaveLength(1);
|
||||||
|
expect(requests[0].result()).toBeNull();
|
||||||
|
for (const extra of requests.slice(1)) {
|
||||||
|
expect(extra.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Once the user has answered, the site may ask again.
|
||||||
|
bg.closeWindow(1);
|
||||||
|
await settle();
|
||||||
|
expect(requests[0].result()).toEqual({
|
||||||
|
error: { code: 4001, message: "User rejected the request." },
|
||||||
|
});
|
||||||
|
const again = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
expect(again.result()).toBeNull();
|
||||||
|
expect(bg.created).toHaveLength(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a loop of personal_sign opens one approval and refuses the rest", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const requests = [];
|
||||||
|
for (let i = 0; i < 5; i++) requests.push(bg.requestSign());
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.created).toHaveLength(1);
|
||||||
|
expect(requests[0].result()).toBeNull();
|
||||||
|
for (const extra of requests.slice(1)) {
|
||||||
|
expect(extra.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a loop of eth_signTypedData_v4 opens one approval and refuses the rest", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const requests = [];
|
||||||
|
for (let i = 0; i < 5; i++) requests.push(bg.requestTypedData());
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.created).toHaveLength(1);
|
||||||
|
expect(requests[0].result()).toBeNull();
|
||||||
|
for (const extra of requests.slice(1)) {
|
||||||
|
expect(extra.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a pending personal_sign also refuses eth_signTypedData_v4", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
bg.requestSign();
|
||||||
|
const typed = bg.requestTypedData();
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(typed.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(bg.created).toHaveLength(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("in the toolbar popup, a loop of eth_requestAccounts opens it once", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const requests = [];
|
||||||
|
for (let i = 0; i < 5; i++) requests.push(bg.requestSite());
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.openPopup).toHaveBeenCalledTimes(1);
|
||||||
|
for (const extra of requests.slice(1)) {
|
||||||
|
expect(extra.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// A toolbar popup that closes before it connects tells the background
|
||||||
|
// nothing, so its prompt stays pending. Once the toolbar popup has been set
|
||||||
|
// to open something else, nothing shows that prompt, and the site asking
|
||||||
|
// again must show it again rather than be refused for good.
|
||||||
|
test("a toolbar prompt nothing shows any more is shown again when the site asks again", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const first = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
const id = first.id();
|
||||||
|
|
||||||
|
// Its popup closed without connecting. Another site's prompt takes the
|
||||||
|
// toolbar popup and is answered, which sets it back to the wallet.
|
||||||
|
const other = bg.requestSite(UNCONNECTED_ORIGIN);
|
||||||
|
await settle();
|
||||||
|
const otherPort = bg.connectApproval(other.id());
|
||||||
|
otherPort.decide(false, false);
|
||||||
|
otherPort.disconnect();
|
||||||
|
await settle();
|
||||||
|
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
|
||||||
|
"src/popup/index.html",
|
||||||
|
);
|
||||||
|
|
||||||
|
const repeat = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
expect(repeat.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(bg.openPopup).toHaveBeenCalledTimes(3);
|
||||||
|
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
|
||||||
|
"src/popup/index.html?approval=" + id,
|
||||||
|
);
|
||||||
|
|
||||||
|
// The user answers it, and the first request gets that answer.
|
||||||
|
bg.connectApproval(id).decide(true, false);
|
||||||
|
await settle();
|
||||||
|
expect(first.result()).toEqual({ result: [signer.address] });
|
||||||
|
});
|
||||||
|
|
||||||
|
// The user rejects a signature request from another site, which is
|
||||||
|
// connected already. Answering any approval sets the toolbar popup back to
|
||||||
|
// the wallet.
|
||||||
|
async function rejectSignatureFromAnotherSite(bg) {
|
||||||
|
const sign = bg.requestSign(undefined, ORIGIN);
|
||||||
|
await settle();
|
||||||
|
bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_SIGN_RESPONSE",
|
||||||
|
id: sign.id(),
|
||||||
|
approved: false,
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(sign.result()).toEqual({
|
||||||
|
error: { code: 4001, message: "User rejected the request." },
|
||||||
|
});
|
||||||
|
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
|
||||||
|
"src/popup/index.html",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a toolbar prompt is shown again after another site's signature request is answered", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const first = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
const id = first.id();
|
||||||
|
|
||||||
|
// Its popup closed without connecting.
|
||||||
|
await rejectSignatureFromAnotherSite(bg);
|
||||||
|
|
||||||
|
const repeat = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
expect(repeat.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(bg.openPopup).toHaveBeenCalledTimes(2);
|
||||||
|
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
|
||||||
|
"src/popup/index.html?approval=" + id,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a prompt in a window is not opened again when the site asks again", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
// The browser will not open the toolbar popup, so the prompt goes to a
|
||||||
|
// window of its own.
|
||||||
|
bg.openPopup.mockImplementation(() =>
|
||||||
|
Promise.reject(new Error("no toolbar popup")),
|
||||||
|
);
|
||||||
|
bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
expect(bg.created).toHaveLength(1);
|
||||||
|
|
||||||
|
await rejectSignatureFromAnotherSite(bg);
|
||||||
|
expect(bg.created).toHaveLength(2);
|
||||||
|
|
||||||
|
const repeat = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
expect(repeat.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(bg.openPopup).toHaveBeenCalledTimes(1);
|
||||||
|
expect(bg.created).toHaveLength(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a prompt in a connected toolbar popup is not opened again when the site asks again", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const first = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
// The popup is open and showing the prompt.
|
||||||
|
bg.connectApproval(first.id());
|
||||||
|
|
||||||
|
await rejectSignatureFromAnotherSite(bg);
|
||||||
|
|
||||||
|
const repeat = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
expect(repeat.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(bg.openPopup).toHaveBeenCalledTimes(1);
|
||||||
|
expect(bg.actionPopups[bg.actionPopups.length - 1]).toBe(
|
||||||
|
"src/popup/index.html",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("another site's connection request is not held up", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
bg.requestSite();
|
||||||
|
const repeat = bg.requestSite();
|
||||||
|
const other = bg.requestSite(UNCONNECTED_ORIGIN);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(repeat.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(other.result()).toBeNull();
|
||||||
|
expect(bg.created).toHaveLength(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("another site's signature request is not held up", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
// Connect a second site, so that it may ask for a signature at all.
|
||||||
|
const connecting = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
const port = bg.connectApproval(connecting.id());
|
||||||
|
port.decide(true, false);
|
||||||
|
port.disconnect();
|
||||||
|
await settle();
|
||||||
|
expect(connecting.result()).toEqual({ result: [signer.address] });
|
||||||
|
|
||||||
|
bg.requestSign();
|
||||||
|
const repeat = bg.requestSign();
|
||||||
|
const other = bg.requestSign(signer.address, FRESH_ORIGIN);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(repeat.result()).toEqual(PENDING_REFUSAL);
|
||||||
|
expect(other.result()).toBeNull();
|
||||||
|
expect(bg.created).toHaveLength(3);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
// A nonce collision found before the transaction reaches the network is the
|
// A nonce collision found before the transaction reaches the network is the
|
||||||
// one send failure the wallet can speak about with certainty. The user is told
|
// one send failure the wallet can speak about with certainty. The user is told
|
||||||
// it did not go out and to send it again, rather than being warned it might
|
// it did not go out and to send it again, rather than being warned it might
|
||||||
@@ -2096,3 +2369,329 @@ describe("a site connection decided as the popup closes", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// What a site is told when it asks which account it may use.
|
||||||
|
async function siteAccounts(bg, origin) {
|
||||||
|
const { sendResponse } = bg.send(
|
||||||
|
{ type: "AUTISTMASK_RPC", method: "eth_accounts", params: [] },
|
||||||
|
{ origin: origin || FRESH_ORIGIN },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
return sendResponse.mock.calls[0][0];
|
||||||
|
}
|
||||||
|
|
||||||
|
// A site connected without "Remember" is held only in the background's memory,
|
||||||
|
// keyed to the address it was connected to. Removing that address, or the
|
||||||
|
// wallet holding it, must end the connection as part of the removal itself.
|
||||||
|
// The accountsChanged broadcast the views send afterwards also clears it, but
|
||||||
|
// only when the active address moved, and nothing waits for it to arrive.
|
||||||
|
//
|
||||||
|
// Each test asks the background while storage still names the removed address
|
||||||
|
// as active, because the popup has not saved yet, so the answer turns on the
|
||||||
|
// connection alone.
|
||||||
|
describe("removing an address ends a site's connection to it", () => {
|
||||||
|
// FRESH_ORIGIN connected to the active address without "Remember", in a
|
||||||
|
// wallet holding a second address so that one can be removed at all. The
|
||||||
|
// popup's messages reach the background as they would from the popup.
|
||||||
|
async function connectedBackground() {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const stored = bg.storage.read("autistmask");
|
||||||
|
stored.wallets[0].addresses.push({
|
||||||
|
address: other.address,
|
||||||
|
balance: "0",
|
||||||
|
tokenBalances: [],
|
||||||
|
});
|
||||||
|
bg.storage.write("autistmask", stored);
|
||||||
|
|
||||||
|
const pending = bg.requestSite();
|
||||||
|
await settle();
|
||||||
|
bg.connectApproval(pending.id()).decide(true, false);
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toEqual({ result: [signer.address] });
|
||||||
|
|
||||||
|
global.chrome.runtime.sendMessage = (msg) => {
|
||||||
|
bg.send(msg, bg.fromPopup);
|
||||||
|
};
|
||||||
|
return bg;
|
||||||
|
}
|
||||||
|
|
||||||
|
test("removing the connected address ends the connection", async () => {
|
||||||
|
const bg = await connectedBackground();
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [signer.address] });
|
||||||
|
|
||||||
|
const popupState = bg.storage.read("autistmask");
|
||||||
|
expect(removeAddressFromState(popupState, 0, 0).removed).toBe(true);
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [] });
|
||||||
|
});
|
||||||
|
|
||||||
|
test("deleting the wallet holding the connected address ends the connection", async () => {
|
||||||
|
const bg = await connectedBackground();
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [signer.address] });
|
||||||
|
|
||||||
|
const popupState = bg.storage.read("autistmask");
|
||||||
|
removeWalletFromState(popupState, 0);
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [] });
|
||||||
|
});
|
||||||
|
|
||||||
|
test("removing a different address leaves the connection alone", async () => {
|
||||||
|
const bg = await connectedBackground();
|
||||||
|
|
||||||
|
const popupState = bg.storage.read("autistmask");
|
||||||
|
expect(removeAddressFromState(popupState, 0, 1).removed).toBe(true);
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [signer.address] });
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a page cannot end the connection", async () => {
|
||||||
|
const bg = await connectedBackground();
|
||||||
|
|
||||||
|
const spoof = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_ADDRESSES_REMOVED",
|
||||||
|
addresses: [signer.address],
|
||||||
|
},
|
||||||
|
{ url: FRESH_ORIGIN + "/index.html" },
|
||||||
|
);
|
||||||
|
|
||||||
|
expect(spoof.sendResponse).toHaveBeenCalledWith({
|
||||||
|
error: "Unauthorized sender",
|
||||||
|
});
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [signer.address] });
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// A remembered permission belongs to the origin it was granted to, scheme and
|
||||||
|
// port included (https://git.eeqj.de/sneak/AutistMask/issues/402). The stored
|
||||||
|
// state allows ORIGIN, https://dapp.example. A cleartext page on the same host,
|
||||||
|
// which a network attacker can serve, and another port on it are other sites.
|
||||||
|
describe("a remembered permission is held by the full origin", () => {
|
||||||
|
for (const origin of ["http://dapp.example", "https://dapp.example:8443"]) {
|
||||||
|
test(`an https grant does not authorise ${origin}`, async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
expect(await siteAccounts(bg, ORIGIN)).toEqual({
|
||||||
|
result: [signer.address],
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg, origin)).toEqual({ result: [] });
|
||||||
|
const send = bg.requestTx(TX_PARAMS, origin);
|
||||||
|
await settle();
|
||||||
|
expect(send.result()).toEqual({
|
||||||
|
error: { code: 4100, message: "Unauthorized" },
|
||||||
|
});
|
||||||
|
expect(send.id()).toBeNull();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
test("Remember stores the origin, so the cleartext page on that host is asked again", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const granted = bg.requestSite(FRESH_ORIGIN);
|
||||||
|
await settle();
|
||||||
|
const grantedId = granted.id();
|
||||||
|
bg.connectApproval(grantedId).decide(true, true);
|
||||||
|
await settle();
|
||||||
|
expect(granted.result()).toEqual({ result: [signer.address] });
|
||||||
|
expect(
|
||||||
|
bg.storage.read("autistmask").allowedSites[signer.address],
|
||||||
|
).toEqual([ORIGIN, FRESH_ORIGIN]);
|
||||||
|
|
||||||
|
const cleartext = bg.requestSite("http://fresh.example");
|
||||||
|
await settle();
|
||||||
|
// Unanswered: it is waiting on a prompt of its own.
|
||||||
|
expect(cleartext.result()).toBeNull();
|
||||||
|
expect(cleartext.id()).not.toBe(grantedId);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// Settings lists the sites allowed without "Remember", which only the
|
||||||
|
// background holds, and removing a site there, from either list, disconnects
|
||||||
|
// it. These drive the real Settings view against the real background and
|
||||||
|
// click the [x] the user clicks.
|
||||||
|
describe("removing a site in Settings disconnects it", () => {
|
||||||
|
// The host of FRESH_ORIGIN on another port, which makes it another site.
|
||||||
|
const FRESH_OTHER_PORT = "https://fresh.example:8443";
|
||||||
|
|
||||||
|
// A site list's container. Its [x] buttons, data attributes and all, are
|
||||||
|
// read back out of the rows the view wrote into it, so clicking one runs
|
||||||
|
// the handler the view attached to it.
|
||||||
|
function fakeSiteList() {
|
||||||
|
const list = {
|
||||||
|
innerHTML: "",
|
||||||
|
buttons: [],
|
||||||
|
querySelectorAll() {
|
||||||
|
const tags = list.innerHTML.match(/<button[^>]*>/g) || [];
|
||||||
|
list.buttons = tags.map((tag) => ({
|
||||||
|
dataset: Object.fromEntries(
|
||||||
|
[...tag.matchAll(/data-(\w+)="([^"]*)"/g)].map(
|
||||||
|
(match) => [match[1], match[2]],
|
||||||
|
),
|
||||||
|
),
|
||||||
|
addEventListener(event, handler) {
|
||||||
|
this[event] = handler;
|
||||||
|
},
|
||||||
|
}));
|
||||||
|
return list.buttons;
|
||||||
|
},
|
||||||
|
};
|
||||||
|
return list;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The origins a site list shows.
|
||||||
|
function listed(list) {
|
||||||
|
return [...list.innerHTML.matchAll(/data-origin="([^"]*)"/g)].map(
|
||||||
|
(match) => match[1],
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// A site connected the way the user does it, in the approval popup.
|
||||||
|
async function connect(bg, origin, remember) {
|
||||||
|
const pending = bg.requestSite(origin);
|
||||||
|
await settle();
|
||||||
|
bg.connectApproval(pending.id()).decide(true, remember);
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toEqual({ result: [signer.address] });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Settings, opened over the background's storage and wired to it the way
|
||||||
|
// the popup is: what Settings sends reaches the background from the
|
||||||
|
// extension's own page, and the answer comes back.
|
||||||
|
async function openSettings(bg) {
|
||||||
|
const lists = {};
|
||||||
|
const element = (id) => (lists[id] ||= fakeSiteList());
|
||||||
|
global.document = { getElementById: element };
|
||||||
|
global.chrome.runtime.sendMessage = (msg, callback) => {
|
||||||
|
const { sendResponse } = bg.send(msg, bg.fromPopup);
|
||||||
|
if (callback) callback(sendResponse.mock.calls[0]?.[0]);
|
||||||
|
};
|
||||||
|
await require("../src/shared/state").loadState();
|
||||||
|
await require("../src/popup/views/settings").renderSiteLists();
|
||||||
|
return {
|
||||||
|
allowed: element("settings-allowed-sites"),
|
||||||
|
connected: element("settings-connected-sites"),
|
||||||
|
// Click the [x] beside a site, and let what it sends run.
|
||||||
|
remove: async (list, origin) => {
|
||||||
|
expect(listed(list)).toContain(origin);
|
||||||
|
const button = list.buttons.find(
|
||||||
|
(b) => b.dataset.origin === origin,
|
||||||
|
);
|
||||||
|
await button.click();
|
||||||
|
await settle();
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.document;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("Settings lists each site by its origin", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
await connect(bg, FRESH_ORIGIN, false);
|
||||||
|
await connect(bg, FRESH_OTHER_PORT, true);
|
||||||
|
|
||||||
|
const settings = await openSettings(bg);
|
||||||
|
|
||||||
|
expect(listed(settings.connected)).toEqual([FRESH_ORIGIN]);
|
||||||
|
expect(listed(settings.allowed)).toEqual([ORIGIN, FRESH_OTHER_PORT]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("removing a site connected without Remember disconnects it and tells its tabs", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
await connect(bg, FRESH_ORIGIN, false);
|
||||||
|
const sentToTabs = [];
|
||||||
|
global.chrome.tabs = {
|
||||||
|
query: (q, cb) =>
|
||||||
|
cb([
|
||||||
|
{ id: 1, url: FRESH_ORIGIN + "/app" },
|
||||||
|
{ id: 2, url: ORIGIN + "/app" },
|
||||||
|
{ id: 3, url: FRESH_OTHER_PORT + "/app" },
|
||||||
|
]),
|
||||||
|
sendMessage: (tabId, msg, cb) => {
|
||||||
|
sentToTabs.push({ tabId, msg });
|
||||||
|
cb();
|
||||||
|
},
|
||||||
|
};
|
||||||
|
const settings = await openSettings(bg);
|
||||||
|
|
||||||
|
await settings.remove(settings.connected, FRESH_ORIGIN);
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [] });
|
||||||
|
expect(sentToTabs).toEqual([
|
||||||
|
{
|
||||||
|
tabId: 1,
|
||||||
|
msg: {
|
||||||
|
type: "AUTISTMASK_EVENT",
|
||||||
|
eventName: "accountsChanged",
|
||||||
|
data: [],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
expect(listed(settings.connected)).toEqual([]);
|
||||||
|
// The other site is untouched.
|
||||||
|
expect(await siteAccounts(bg, ORIGIN)).toEqual({
|
||||||
|
result: [signer.address],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// One origin can hold both kinds of connection under two addresses:
|
||||||
|
// remembered for one, allowed without Remember for the other.
|
||||||
|
test("removing a remembered site also ends its connection made without Remember", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
const stored = bg.storage.read("autistmask");
|
||||||
|
stored.wallets[0].addresses.push({
|
||||||
|
address: other.address,
|
||||||
|
balance: "0",
|
||||||
|
tokenBalances: [],
|
||||||
|
});
|
||||||
|
bg.storage.write("autistmask", stored);
|
||||||
|
await connect(bg, FRESH_ORIGIN, true);
|
||||||
|
bg.setActiveAddress(other.address);
|
||||||
|
const pending = bg.requestSite(FRESH_ORIGIN);
|
||||||
|
await settle();
|
||||||
|
bg.connectApproval(pending.id()).decide(true, false);
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toEqual({ result: [other.address] });
|
||||||
|
const settings = await openSettings(bg);
|
||||||
|
|
||||||
|
await settings.remove(settings.allowed, FRESH_ORIGIN);
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg, FRESH_ORIGIN)).toEqual({ result: [] });
|
||||||
|
});
|
||||||
|
|
||||||
|
test("removing a remembered site leaves the same host on another port connected", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
await connect(bg, FRESH_ORIGIN, false);
|
||||||
|
await connect(bg, FRESH_OTHER_PORT, true);
|
||||||
|
const settings = await openSettings(bg);
|
||||||
|
|
||||||
|
await settings.remove(settings.allowed, FRESH_OTHER_PORT);
|
||||||
|
|
||||||
|
expect(await siteAccounts(bg, FRESH_OTHER_PORT)).toEqual({
|
||||||
|
result: [],
|
||||||
|
});
|
||||||
|
expect(await siteAccounts(bg, FRESH_ORIGIN)).toEqual({
|
||||||
|
result: [signer.address],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a page can neither remove a site nor list the connected ones", async () => {
|
||||||
|
const bg = loadBackground({ actionPopup: true });
|
||||||
|
await connect(bg, FRESH_ORIGIN, false);
|
||||||
|
const page = { url: FRESH_ORIGIN + "/index.html" };
|
||||||
|
|
||||||
|
const remove = bg.send(
|
||||||
|
{ type: "AUTISTMASK_REMOVE_SITE", origin: FRESH_ORIGIN },
|
||||||
|
page,
|
||||||
|
);
|
||||||
|
const list = bg.send({ type: "AUTISTMASK_GET_CONNECTED_SITES" }, page);
|
||||||
|
|
||||||
|
expect(remove.sendResponse).toHaveBeenCalledWith({
|
||||||
|
error: "Unauthorized sender",
|
||||||
|
});
|
||||||
|
expect(list.sendResponse).toHaveBeenCalledWith({
|
||||||
|
error: "Unauthorized sender",
|
||||||
|
});
|
||||||
|
expect(await siteAccounts(bg)).toEqual({ result: [signer.address] });
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|||||||
@@ -33,7 +33,6 @@ const signer = new Wallet(SIGNER_KEY);
|
|||||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
const CONNECTED_HOSTNAME = "dapp.example";
|
|
||||||
const EXT_URL = "chrome-extension://autistmask/";
|
const EXT_URL = "chrome-extension://autistmask/";
|
||||||
|
|
||||||
const MAINNET = networkById("mainnet");
|
const MAINNET = networkById("mainnet");
|
||||||
@@ -81,7 +80,7 @@ function storedProfile(networkId) {
|
|||||||
networkId,
|
networkId,
|
||||||
rpcUrl: net.defaultRpcUrl,
|
rpcUrl: net.defaultRpcUrl,
|
||||||
blockscoutUrl: net.defaultBlockscoutUrl,
|
blockscoutUrl: net.defaultBlockscoutUrl,
|
||||||
allowedSites: { [signer.address]: [CONNECTED_HOSTNAME] },
|
allowedSites: { [signer.address]: [CONNECTED_ORIGIN] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
trackedTokens: [],
|
trackedTokens: [],
|
||||||
lastBalanceRefresh: 0,
|
lastBalanceRefresh: 0,
|
||||||
|
|||||||
@@ -19,7 +19,6 @@ const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
|||||||
|
|
||||||
// The site the persisted state has connected, and one it has never heard of.
|
// The site the persisted state has connected, and one it has never heard of.
|
||||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
const CONNECTED_HOSTNAME = "dapp.example";
|
|
||||||
const STRANGER_ORIGIN = "https://stranger.example";
|
const STRANGER_ORIGIN = "https://stranger.example";
|
||||||
|
|
||||||
const MAINNET = networkById("mainnet");
|
const MAINNET = networkById("mainnet");
|
||||||
@@ -86,7 +85,7 @@ function loadBackground() {
|
|||||||
tokenHolderCache: {},
|
tokenHolderCache: {},
|
||||||
fraudContracts: [],
|
fraudContracts: [],
|
||||||
activeAddress: ADDRESS,
|
activeAddress: ADDRESS,
|
||||||
allowedSites: { [ADDRESS]: [CONNECTED_HOSTNAME] },
|
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
};
|
};
|
||||||
const storage = makeStorageStub({ autistmask: persisted });
|
const storage = makeStorageStub({ autistmask: persisted });
|
||||||
|
|||||||
@@ -17,7 +17,6 @@ const { networkById } = require("../src/shared/networks");
|
|||||||
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
const CONNECTED_HOSTNAME = "dapp.example";
|
|
||||||
const UNKNOWN_ORIGIN = "https://stranger.example";
|
const UNKNOWN_ORIGIN = "https://stranger.example";
|
||||||
|
|
||||||
const MAINNET = networkById("mainnet");
|
const MAINNET = networkById("mainnet");
|
||||||
@@ -41,7 +40,7 @@ function storedProfile(networkId) {
|
|||||||
networkId,
|
networkId,
|
||||||
rpcUrl: networkById(networkId).defaultRpcUrl,
|
rpcUrl: networkById(networkId).defaultRpcUrl,
|
||||||
blockscoutUrl: networkById(networkId).defaultBlockscoutUrl,
|
blockscoutUrl: networkById(networkId).defaultBlockscoutUrl,
|
||||||
allowedSites: { [ADDRESS]: [CONNECTED_HOSTNAME] },
|
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
trackedTokens: [],
|
trackedTokens: [],
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -21,7 +21,6 @@ const { makeStorageStub } = require("./support/storageStub");
|
|||||||
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
const CONNECTED_HOSTNAME = "dapp.example";
|
|
||||||
|
|
||||||
const MAINNET = networkById("mainnet");
|
const MAINNET = networkById("mainnet");
|
||||||
const SEPOLIA = networkById("sepolia");
|
const SEPOLIA = networkById("sepolia");
|
||||||
@@ -50,7 +49,7 @@ function storedProfile(networkId) {
|
|||||||
networkId,
|
networkId,
|
||||||
rpcUrl: CUSTOM_RPC,
|
rpcUrl: CUSTOM_RPC,
|
||||||
blockscoutUrl: CUSTOM_BLOCKSCOUT,
|
blockscoutUrl: CUSTOM_BLOCKSCOUT,
|
||||||
allowedSites: { [ADDRESS]: [CONNECTED_HOSTNAME] },
|
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
trackedTokens: [{ address: TOKEN, symbol: "DAI", decimals: 18 }],
|
trackedTokens: [{ address: TOKEN, symbol: "DAI", decimals: 18 }],
|
||||||
theme: "dark",
|
theme: "dark",
|
||||||
@@ -168,7 +167,7 @@ describe("a chain switch on a worker that never loaded state", () => {
|
|||||||
expect(after.wallets).toEqual(walletFixture());
|
expect(after.wallets).toEqual(walletFixture());
|
||||||
expect(after.hasWallet).toBe(true);
|
expect(after.hasWallet).toBe(true);
|
||||||
expect(after.activeAddress).toBe(ADDRESS);
|
expect(after.activeAddress).toBe(ADDRESS);
|
||||||
expect(after.allowedSites).toEqual({ [ADDRESS]: [CONNECTED_HOSTNAME] });
|
expect(after.allowedSites).toEqual({ [ADDRESS]: [CONNECTED_ORIGIN] });
|
||||||
expect(after.trackedTokens).toEqual([
|
expect(after.trackedTokens).toEqual([
|
||||||
{ address: TOKEN, symbol: "DAI", decimals: 18 },
|
{ address: TOKEN, symbol: "DAI", decimals: 18 },
|
||||||
]);
|
]);
|
||||||
|
|||||||
@@ -29,7 +29,6 @@ const signer = new Wallet(SIGNER_KEY);
|
|||||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
const CONNECTED_HOSTNAME = "dapp.example";
|
|
||||||
const EXT_URL = "chrome-extension://autistmask/";
|
const EXT_URL = "chrome-extension://autistmask/";
|
||||||
|
|
||||||
const SEPOLIA = networkById("sepolia");
|
const SEPOLIA = networkById("sepolia");
|
||||||
@@ -67,7 +66,7 @@ function storedProfile(networkId) {
|
|||||||
networkId,
|
networkId,
|
||||||
rpcUrl: net.defaultRpcUrl,
|
rpcUrl: net.defaultRpcUrl,
|
||||||
blockscoutUrl: net.defaultBlockscoutUrl,
|
blockscoutUrl: net.defaultBlockscoutUrl,
|
||||||
allowedSites: { [signer.address]: [CONNECTED_HOSTNAME] },
|
allowedSites: { [signer.address]: [CONNECTED_ORIGIN] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
trackedTokens: [],
|
trackedTokens: [],
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,315 @@
|
|||||||
|
// The recipient line of a contract creation
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/250).
|
||||||
|
//
|
||||||
|
// A transaction with no `to` creates a contract. The approval screen, the
|
||||||
|
// wait, success and error screens, the transaction detail view and the
|
||||||
|
// transaction history rows each say so in a sentence, where they used to show
|
||||||
|
// a blank line (an empty address, with a colour dot whose colour was
|
||||||
|
// `undefined`) or, on the approval screen, "(contract creation)". A
|
||||||
|
// transaction with a real `to` still shows that address.
|
||||||
|
//
|
||||||
|
// Driven against a minimal DOM stub in the shape
|
||||||
|
// tests/typedDataPermit.test.js uses.
|
||||||
|
|
||||||
|
jest.mock("../src/shared/log", () => ({
|
||||||
|
log: {
|
||||||
|
debugf: () => {},
|
||||||
|
infof: () => {},
|
||||||
|
warnf: () => {},
|
||||||
|
errorf: () => {},
|
||||||
|
},
|
||||||
|
// The transaction detail view fetches on-chain details after drawing; an
|
||||||
|
// answer that is not ok leaves the drawn lines as they are.
|
||||||
|
debugFetch: async () => ({ ok: false }),
|
||||||
|
setRuntimeDebug: () => {},
|
||||||
|
isDebug: () => false,
|
||||||
|
}));
|
||||||
|
|
||||||
|
// The wait screen polls for a receipt; this one never arrives.
|
||||||
|
jest.mock("../src/shared/balances", () => ({
|
||||||
|
getProvider: () => ({ getTransactionReceipt: () => new Promise(() => {}) }),
|
||||||
|
refreshBalances: () => {},
|
||||||
|
}));
|
||||||
|
|
||||||
|
// The history lists ask the explorer for their transactions and resolve ENS
|
||||||
|
// names for them; here the explorer answers with mockHistory and no name
|
||||||
|
// resolves.
|
||||||
|
let mockHistory = [];
|
||||||
|
jest.mock("../src/shared/transactions", () => ({
|
||||||
|
...jest.requireActual("../src/shared/transactions"),
|
||||||
|
fetchRecentTransactions: async () => mockHistory,
|
||||||
|
}));
|
||||||
|
jest.mock("../src/shared/ens", () => ({
|
||||||
|
...jest.requireActual("../src/shared/ens"),
|
||||||
|
resolveEnsNames: async () => new Map(),
|
||||||
|
}));
|
||||||
|
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const approval = require("../src/popup/views/approval");
|
||||||
|
const txStatus = require("../src/popup/views/txStatus");
|
||||||
|
const transactionDetail = require("../src/popup/views/transactionDetail");
|
||||||
|
const home = require("../src/popup/views/home");
|
||||||
|
const addressDetail = require("../src/popup/views/addressDetail");
|
||||||
|
const addressToken = require("../src/popup/views/addressToken");
|
||||||
|
|
||||||
|
const SENTENCE =
|
||||||
|
"This transaction creates a new contract. It has no recipient.";
|
||||||
|
|
||||||
|
const FROM = "0x0000000000000000000000000000000000000a11";
|
||||||
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
const TX_HASH =
|
||||||
|
"0x85215772ed26ea8b39c2b3b18779030487efbe0b5fd7e882592b2f62b837be84";
|
||||||
|
// Init code for a contract creation's data.
|
||||||
|
const INIT_CODE = "0x600160005500";
|
||||||
|
|
||||||
|
function makeElement(id) {
|
||||||
|
const classes = new Set();
|
||||||
|
const el = {
|
||||||
|
id,
|
||||||
|
textContent: "",
|
||||||
|
value: "",
|
||||||
|
innerHTML: "",
|
||||||
|
disabled: false,
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
classList: {
|
||||||
|
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||||
|
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||||
|
contains: (n) => classes.has(n),
|
||||||
|
toggle: (n, force) => {
|
||||||
|
const on = force === undefined ? !classes.has(n) : force;
|
||||||
|
if (on) classes.add(n);
|
||||||
|
else classes.delete(n);
|
||||||
|
return on;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
addEventListener: () => {},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
appendChild: () => {},
|
||||||
|
};
|
||||||
|
// Views reach for .parentElement to hide whole sections.
|
||||||
|
Object.defineProperty(el, "parentElement", {
|
||||||
|
get: () => node(id + "-parent"),
|
||||||
|
});
|
||||||
|
return el;
|
||||||
|
}
|
||||||
|
|
||||||
|
function makeDocument() {
|
||||||
|
const els = new Map();
|
||||||
|
return {
|
||||||
|
getElementById(id) {
|
||||||
|
// The debug banner is created on demand by helpers.js; absent
|
||||||
|
// is the state a non-debug, non-testnet popup is in.
|
||||||
|
if (id === "debug-banner") return null;
|
||||||
|
if (!els.has(id)) els.set(id, makeElement(id));
|
||||||
|
return els.get(id);
|
||||||
|
},
|
||||||
|
createElement: () => makeElement("created"),
|
||||||
|
body: { prepend: () => {} },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function node(id) {
|
||||||
|
return globalThis.document.getElementById(id);
|
||||||
|
}
|
||||||
|
|
||||||
|
// The line a transaction with a real `to` shows: that address, and nothing
|
||||||
|
// left over from an empty one.
|
||||||
|
function expectAddressLine(html) {
|
||||||
|
expect(html).toContain(RECIPIENT);
|
||||||
|
expect(html).not.toContain(SENTENCE);
|
||||||
|
expect(html).not.toContain("undefined");
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
globalThis.document = makeDocument();
|
||||||
|
globalThis.window = { location: { search: "" } };
|
||||||
|
state.wallets = [];
|
||||||
|
state.trackedTokens = [];
|
||||||
|
state.viewData = {};
|
||||||
|
state.viewStack = [];
|
||||||
|
state.currentView = null;
|
||||||
|
txStatus.init({ doRefreshAndRender: () => {} });
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
txStatus.endWait();
|
||||||
|
});
|
||||||
|
|
||||||
|
// Open the transaction approval screen the way the popup does: the background
|
||||||
|
// hands over the populated transaction and show() draws it.
|
||||||
|
async function openTxApproval(to, data) {
|
||||||
|
globalThis.chrome.runtime = {
|
||||||
|
connect: () => ({ postMessage: () => {} }),
|
||||||
|
sendMessage: (msg, reply) => {
|
||||||
|
if (!reply) return;
|
||||||
|
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||||
|
reply({
|
||||||
|
type: "tx",
|
||||||
|
origin: "https://dapp.example",
|
||||||
|
isPhishingDomain: false,
|
||||||
|
approvedFrom: FROM,
|
||||||
|
approvedTx: {
|
||||||
|
type: 2,
|
||||||
|
from: FROM,
|
||||||
|
chainId: "0x1",
|
||||||
|
nonce: "0x7",
|
||||||
|
gasLimit: "0x5208",
|
||||||
|
maxPriorityFeePerGas: "0x3b9aca00",
|
||||||
|
maxFeePerGas: "0x77359400",
|
||||||
|
to,
|
||||||
|
value: "0x0",
|
||||||
|
data,
|
||||||
|
accessList: [],
|
||||||
|
},
|
||||||
|
});
|
||||||
|
},
|
||||||
|
};
|
||||||
|
approval.init({});
|
||||||
|
await approval.show(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("the transaction approval screen", () => {
|
||||||
|
test("a contract creation says so instead of naming a contract", async () => {
|
||||||
|
await openTxApproval(null, INIT_CODE);
|
||||||
|
expect(node("approve-tx-to").innerHTML).toBe(SENTENCE);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a transaction with a recipient shows its address", async () => {
|
||||||
|
await openTxApproval(RECIPIENT, "0x");
|
||||||
|
expectAddressLine(node("approve-tx-to").innerHTML);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// approval.js carries a contract creation to these screens with `to` as "".
|
||||||
|
describe("the wait, success and error screens", () => {
|
||||||
|
const creation = {
|
||||||
|
to: "",
|
||||||
|
amount: "0.0000",
|
||||||
|
token: "ETH",
|
||||||
|
tokenSymbol: null,
|
||||||
|
};
|
||||||
|
const transfer = { ...creation, to: RECIPIENT };
|
||||||
|
|
||||||
|
test("a contract creation says so on the wait screen", () => {
|
||||||
|
txStatus.showWait(creation, TX_HASH);
|
||||||
|
expect(node("wait-tx-to").innerHTML).toBe(SENTENCE);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a transaction with a recipient shows its address on the wait screen", () => {
|
||||||
|
txStatus.showWait(transfer, TX_HASH);
|
||||||
|
expectAddressLine(node("wait-tx-to").innerHTML);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a contract creation says so on the success and error screens", () => {
|
||||||
|
state.viewData = {
|
||||||
|
amount: "0.0000",
|
||||||
|
symbol: "ETH",
|
||||||
|
to: "",
|
||||||
|
hash: TX_HASH,
|
||||||
|
blockNumber: 1,
|
||||||
|
};
|
||||||
|
txStatus.renderSuccess();
|
||||||
|
expect(node("success-tx-to").innerHTML).toBe(SENTENCE);
|
||||||
|
|
||||||
|
txStatus.showError(creation, TX_HASH, "The transaction failed.");
|
||||||
|
expect(node("error-tx-to").innerHTML).toBe(SENTENCE);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a transaction with a recipient shows its address on the success and error screens", () => {
|
||||||
|
state.viewData = {
|
||||||
|
amount: "0.0050",
|
||||||
|
symbol: "ETH",
|
||||||
|
to: RECIPIENT,
|
||||||
|
hash: TX_HASH,
|
||||||
|
blockNumber: 1,
|
||||||
|
};
|
||||||
|
txStatus.renderSuccess();
|
||||||
|
expectAddressLine(node("success-tx-to").innerHTML);
|
||||||
|
|
||||||
|
txStatus.showError(transfer, TX_HASH, "The transaction failed.");
|
||||||
|
expectAddressLine(node("error-tx-to").innerHTML);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// A transaction FROM sent, as the history lists hold it. The explorer reports a
|
||||||
|
// contract creation with no `to`, which src/shared/transactions.js turns into
|
||||||
|
// `to: ""`.
|
||||||
|
function historyTx(to) {
|
||||||
|
return {
|
||||||
|
hash: TX_HASH,
|
||||||
|
from: FROM,
|
||||||
|
to,
|
||||||
|
value: "0.0000",
|
||||||
|
exactValue: "0.0",
|
||||||
|
rawAmount: "0",
|
||||||
|
rawUnit: "wei",
|
||||||
|
symbol: "ETH",
|
||||||
|
timestamp: 1790000000,
|
||||||
|
isError: false,
|
||||||
|
directionLabel: "Sent",
|
||||||
|
direction: "sent",
|
||||||
|
contractAddress: null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// The detail view is opened with the transaction a history row holds.
|
||||||
|
describe("the transaction detail view", () => {
|
||||||
|
test("a contract creation says so", () => {
|
||||||
|
transactionDetail.show(historyTx(""));
|
||||||
|
expect(node("tx-detail-to").innerHTML).toBe(SENTENCE);
|
||||||
|
expect(node("tx-detail-type").textContent).toBe("Contract Creation");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a transaction with a recipient shows its address", () => {
|
||||||
|
transactionDetail.show(historyTx(RECIPIENT));
|
||||||
|
expectAddressLine(node("tx-detail-to").innerHTML);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The same rows are drawn on Home, AddressDetail and AddressToken (for ETH).
|
||||||
|
describe.each([
|
||||||
|
["Home", "home-tx-list", () => home.render({})],
|
||||||
|
["AddressDetail", "tx-list", () => addressDetail.show()],
|
||||||
|
["AddressToken", "address-token-tx-list", () => addressToken.show()],
|
||||||
|
])("the transaction history on %s", (_name, listId, open) => {
|
||||||
|
async function rowsFor(tx) {
|
||||||
|
mockHistory = [tx];
|
||||||
|
open();
|
||||||
|
// The list is drawn once the history has been fetched.
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 0));
|
||||||
|
return node(listId).innerHTML;
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
state.wallets = [
|
||||||
|
{
|
||||||
|
name: "Main",
|
||||||
|
type: "key",
|
||||||
|
addresses: [{ address: FROM, balance: "0.0000" }],
|
||||||
|
},
|
||||||
|
];
|
||||||
|
state.selectedWallet = 0;
|
||||||
|
state.selectedAddress = 0;
|
||||||
|
state.selectedToken = "ETH";
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a contract creation's row says so, with no colour dot and no address line", async () => {
|
||||||
|
const html = await rowsFor(historyTx(""));
|
||||||
|
expect(html).toContain(SENTENCE);
|
||||||
|
expect(html).not.toContain("background:");
|
||||||
|
expect(html).not.toContain("am-address");
|
||||||
|
expect(html).not.toContain("undefined");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a transaction with a recipient shows its colour dot and address", async () => {
|
||||||
|
const html = await rowsFor(historyTx(RECIPIENT));
|
||||||
|
expectAddressLine(html);
|
||||||
|
expect(html).toContain("background:#");
|
||||||
|
expect(html).toContain(`<div class="am-address">${RECIPIENT}</div>`);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
// What debugFetch writes to the console in debug mode.
|
||||||
|
//
|
||||||
|
// RPC providers put the API key in the URL's path or query string, and the
|
||||||
|
// debug log used to print the whole URL and request body, so turning debug
|
||||||
|
// mode on wrote the key to the console
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/410). The log now names the
|
||||||
|
// HTTP method, the URL's origin and the JSON-RPC method, and nothing else of
|
||||||
|
// the request.
|
||||||
|
|
||||||
|
const { debugFetch, urlOrigin, setRuntimeDebug } = require("../src/shared/log");
|
||||||
|
|
||||||
|
const realFetch = globalThis.fetch;
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
globalThis.fetch = realFetch;
|
||||||
|
setRuntimeDebug(false);
|
||||||
|
jest.restoreAllMocks();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("logs the origin and JSON-RPC method, not the key in the URL", async () => {
|
||||||
|
setRuntimeDebug(true);
|
||||||
|
const consoleLog = jest.spyOn(console, "log").mockImplementation(() => {});
|
||||||
|
globalThis.fetch = jest.fn(async () => ({ status: 200 }));
|
||||||
|
|
||||||
|
await debugFetch(
|
||||||
|
"https://rpc.example.invalid/v3/PATHKEY123?token=QUERYTOKEN456",
|
||||||
|
{
|
||||||
|
method: "POST",
|
||||||
|
headers: { "Content-Type": "application/json" },
|
||||||
|
body: JSON.stringify({
|
||||||
|
jsonrpc: "2.0",
|
||||||
|
id: 1,
|
||||||
|
method: "eth_chainId",
|
||||||
|
params: [],
|
||||||
|
}),
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
const logged = consoleLog.mock.calls.flat().join(" ");
|
||||||
|
expect(logged).not.toContain("PATHKEY123");
|
||||||
|
expect(logged).not.toContain("QUERYTOKEN456");
|
||||||
|
expect(logged).toContain("https://rpc.example.invalid");
|
||||||
|
expect(logged).toContain("eth_chainId");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the origin leaves out a user name and password in the URL", () => {
|
||||||
|
expect(
|
||||||
|
urlOrigin("https://user:SECRETPASS@rpc.example.invalid/v3/KEY"),
|
||||||
|
).toBe("https://rpc.example.invalid");
|
||||||
|
expect(urlOrigin("wss://user:SECRETPASS@rpc.example.invalid:8546/")).toBe(
|
||||||
|
"wss://rpc.example.invalid:8546",
|
||||||
|
);
|
||||||
|
});
|
||||||
@@ -140,8 +140,14 @@ function load() {
|
|||||||
state.selectedWallet = 0;
|
state.selectedWallet = 0;
|
||||||
state.selectedAddress = 0;
|
state.selectedAddress = 0;
|
||||||
state.activeAddress = A0;
|
state.activeAddress = A0;
|
||||||
state.allowedSites = { [A0]: ["a.example"], [B0]: ["b.example"] };
|
state.allowedSites = {
|
||||||
state.deniedSites = { [B0]: ["c.example"], [C0]: ["d.example"] };
|
[A0]: ["https://a.example"],
|
||||||
|
[B0]: ["https://b.example"],
|
||||||
|
};
|
||||||
|
state.deniedSites = {
|
||||||
|
[B0]: ["https://c.example"],
|
||||||
|
[C0]: ["https://d.example"],
|
||||||
|
};
|
||||||
state.viewStack = ["main", "settings"];
|
state.viewStack = ["main", "settings"];
|
||||||
state.currentView = "settings";
|
state.currentView = "settings";
|
||||||
|
|
||||||
@@ -388,8 +394,8 @@ describe("deleting without the password", () => {
|
|||||||
await click("btn-delete-wallet-lost-confirm");
|
await click("btn-delete-wallet-lost-confirm");
|
||||||
|
|
||||||
const saved = (await storage.get("autistmask")).autistmask;
|
const saved = (await storage.get("autistmask")).autistmask;
|
||||||
expect(saved.allowedSites).toEqual({ [A0]: ["a.example"] });
|
expect(saved.allowedSites).toEqual({ [A0]: ["https://a.example"] });
|
||||||
expect(saved.deniedSites).toEqual({ [C0]: ["d.example"] });
|
expect(saved.deniedSites).toEqual({ [C0]: ["https://d.example"] });
|
||||||
});
|
});
|
||||||
|
|
||||||
// The route shares finishDelete() with the password route, so the
|
// The route shares finishDelete() with the password route, so the
|
||||||
@@ -407,7 +413,9 @@ describe("deleting without the password", () => {
|
|||||||
expect(saved.activeAddress).toBe(A0);
|
expect(saved.activeAddress).toBe(A0);
|
||||||
expect(saved.selectedWallet).toBe(0);
|
expect(saved.selectedWallet).toBe(0);
|
||||||
expect(saved.selectedAddress).toBe(0);
|
expect(saved.selectedAddress).toBe(0);
|
||||||
expect(sent).toEqual([]);
|
expect(sent).toEqual([
|
||||||
|
{ type: "AUTISTMASK_ADDRESSES_REMOVED", addresses: [B0] },
|
||||||
|
]);
|
||||||
// Settings is stubbed, so this is where the route hands over, not
|
// Settings is stubbed, so this is where the route hands over, not
|
||||||
// where it renders.
|
// where it renders.
|
||||||
expect(mockSettingsShow).toHaveBeenCalled();
|
expect(mockSettingsShow).toHaveBeenCalled();
|
||||||
@@ -426,13 +434,16 @@ describe("deleting without the password", () => {
|
|||||||
"Wallet 3",
|
"Wallet 3",
|
||||||
]);
|
]);
|
||||||
expect(saved.activeAddress).toBe(B0);
|
expect(saved.activeAddress).toBe(B0);
|
||||||
expect(sent).toEqual([{ type: "AUTISTMASK_ACTIVE_CHANGED" }]);
|
expect(sent).toEqual([
|
||||||
|
{ type: "AUTISTMASK_ADDRESSES_REMOVED", addresses: [A0, A1] },
|
||||||
|
{ type: "AUTISTMASK_ACTIVE_CHANGED" },
|
||||||
|
]);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("deleting the last wallet lands on Welcome with nothing left", async () => {
|
test("deleting the last wallet lands on Welcome with nothing left", async () => {
|
||||||
const { deleteWallet, state, storage } = load();
|
const { deleteWallet, state, storage } = load();
|
||||||
state.wallets = [wallet("Wallet 1", "secret-one", [A0])];
|
state.wallets = [wallet("Wallet 1", "secret-one", [A0])];
|
||||||
state.allowedSites = { [A0]: ["a.example"] };
|
state.allowedSites = { [A0]: ["https://a.example"] };
|
||||||
state.deniedSites = {};
|
state.deniedSites = {};
|
||||||
|
|
||||||
await openLostPassword(deleteWallet, 0);
|
await openLostPassword(deleteWallet, 0);
|
||||||
|
|||||||
@@ -99,12 +99,13 @@ describe("the flash line the message is shown in", () => {
|
|||||||
// length, including one that wrapped to two lines and pushed the
|
// length, including one that wrapped to two lines and pushed the
|
||||||
// settings view down 12px.
|
// settings view down 12px.
|
||||||
//
|
//
|
||||||
// The assertion that actually measures — empty line vs. the message,
|
// The line cuts a message too long for it with an ellipsis (see
|
||||||
// real Chromium, documented 360x600 popup — is
|
// showFlash() in src/popup/views/helpers.js). The assertions that
|
||||||
// "a rejected dust threshold shifts no layout (#233)" in
|
// measure that, in a real browser at the documented 360x600 popup, are
|
||||||
// tests/e2e/run.js, run by make test-e2e. It is not in make check
|
// "a rejected dust threshold shifts no layout (#233)" and "an over-long
|
||||||
// because REPO_POLICIES.md caps make test at 20 seconds and a browser
|
// flash message keeps to one line (#252)" in tests/e2e/run.js, run by
|
||||||
// suite does not fit; run it before changing the wording.
|
// make test-e2e. They are not in make check because REPO_POLICIES.md
|
||||||
|
// caps make test at 20 seconds and a browser suite does not fit.
|
||||||
test("reserves its height in the markup", () => {
|
test("reserves its height in the markup", () => {
|
||||||
const flashLine = POPUP_HTML.match(
|
const flashLine = POPUP_HTML.match(
|
||||||
/<div\s+id="flash-msg"\s+class="([^"]*)"/,
|
/<div\s+id="flash-msg"\s+class="([^"]*)"/,
|
||||||
|
|||||||
@@ -438,11 +438,10 @@ step(
|
|||||||
await d.switchToWindow(popup);
|
await d.switchToWindow(popup);
|
||||||
await d.waitVisible("#view-approve-site");
|
await d.waitVisible("#view-approve-site");
|
||||||
|
|
||||||
const hostname = await d.text("#approve-hostname");
|
const origin = await d.text("#approve-origin");
|
||||||
assert(
|
assert(
|
||||||
hostname === "127.0.0.1",
|
origin === env.server.origin,
|
||||||
"the site prompt names the wrong origin: " +
|
"the site prompt names the wrong origin: " + JSON.stringify(origin),
|
||||||
JSON.stringify(hostname),
|
|
||||||
);
|
);
|
||||||
const shown = await d.text("#approve-address");
|
const shown = await d.text("#approve-address");
|
||||||
assert(
|
assert(
|
||||||
@@ -494,16 +493,16 @@ step(
|
|||||||
|
|
||||||
const screen = await d.execute(
|
const screen = await d.execute(
|
||||||
`return {
|
`return {
|
||||||
hostname: document.getElementById("approve-sign-hostname").textContent,
|
origin: document.getElementById("approve-sign-origin").textContent,
|
||||||
type: document.getElementById("approve-sign-type").textContent,
|
type: document.getElementById("approve-sign-type").textContent,
|
||||||
message: document.getElementById("approve-sign-message").textContent,
|
message: document.getElementById("approve-sign-message").textContent,
|
||||||
from: document.getElementById("approve-sign-from").textContent,
|
from: document.getElementById("approve-sign-from").textContent,
|
||||||
};`,
|
};`,
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.hostname === "127.0.0.1",
|
screen.origin === env.server.origin,
|
||||||
"the sign prompt names the wrong origin: " +
|
"the sign prompt names the wrong origin: " +
|
||||||
JSON.stringify(screen.hostname),
|
JSON.stringify(screen.origin),
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.type === "Personal message",
|
screen.type === "Personal message",
|
||||||
@@ -571,7 +570,7 @@ step(
|
|||||||
|
|
||||||
const screen = await d.execute(
|
const screen = await d.execute(
|
||||||
`return {
|
`return {
|
||||||
hostname: document.getElementById("approve-tx-hostname").textContent,
|
origin: document.getElementById("approve-tx-origin").textContent,
|
||||||
from: document.getElementById("approve-tx-from").textContent,
|
from: document.getElementById("approve-tx-from").textContent,
|
||||||
to: document.getElementById("approve-tx-to").textContent,
|
to: document.getElementById("approve-tx-to").textContent,
|
||||||
value: document.getElementById("approve-tx-value").textContent,
|
value: document.getElementById("approve-tx-value").textContent,
|
||||||
@@ -582,9 +581,9 @@ step(
|
|||||||
};`,
|
};`,
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.hostname === "127.0.0.1",
|
screen.origin === env.server.origin,
|
||||||
"the transaction prompt names the wrong origin: " +
|
"the transaction prompt names the wrong origin: " +
|
||||||
JSON.stringify(screen.hostname),
|
JSON.stringify(screen.origin),
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.from.toLowerCase().includes(env.address.toLowerCase()),
|
screen.from.toLowerCase().includes(env.address.toLowerCase()),
|
||||||
|
|||||||
+169
-49
@@ -35,6 +35,7 @@ const {
|
|||||||
const {
|
const {
|
||||||
DAPP_ORIGIN,
|
DAPP_ORIGIN,
|
||||||
DAPP_URL,
|
DAPP_URL,
|
||||||
|
PHISHING_DAPP_ORIGIN,
|
||||||
PHISHING_DAPP_URL,
|
PHISHING_DAPP_URL,
|
||||||
FEE_ESTIMATE_WEI,
|
FEE_ESTIMATE_WEI,
|
||||||
FEE_RESERVE_WEI,
|
FEE_RESERVE_WEI,
|
||||||
@@ -1320,17 +1321,13 @@ async function waitForFilledFlashLine(page) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// README, No Layout Shift: the rejection message goes into #flash-msg,
|
// README, No Layout Shift: the rejection message goes into #flash-msg,
|
||||||
// whose min-h-[1.25rem] reserves exactly ONE line at text-xs. Reserving
|
// whose min-h-[1.25rem] reserves exactly ONE line at text-xs, and which
|
||||||
// the space is not enough on its own — a message too long for one line
|
// cuts a message too long for that line with an ellipsis rather than wrap
|
||||||
// wraps and pushes everything below it down anyway, which is what the
|
// it. This shows the real message and measures that nothing moves; the
|
||||||
// first version of this change shipped: 75 characters, 32px, the settings
|
// test after it does the same with a message several lines long. Both
|
||||||
// view and the threshold field 12px lower than with an empty line.
|
// measure rather than inspect markup: the unit suite runs on the node
|
||||||
//
|
// environment with no layout engine, where every height is zero (see the
|
||||||
// So this measures rather than inspects markup. It is the only assertion
|
// note in tests/dustThreshold.test.js).
|
||||||
// in the repo that can see the wording grow: the unit suite runs on the
|
|
||||||
// node environment with no layout engine, where every height is zero (see
|
|
||||||
// the note in tests/dustThreshold.test.js). Lengthen
|
|
||||||
// DUST_THRESHOLD_MESSAGE past one line and this test goes red.
|
|
||||||
test("a rejected dust threshold shifts no layout (#233)", async (env) => {
|
test("a rejected dust threshold shifts no layout (#233)", async (env) => {
|
||||||
const page = await openPopup(env.ctx, env.popupUrl);
|
const page = await openPopup(env.ctx, env.popupUrl);
|
||||||
try {
|
try {
|
||||||
@@ -1377,11 +1374,11 @@ test("a rejected dust threshold shifts no layout (#233)", async (env) => {
|
|||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
after.flashHeight === before.flashHeight,
|
after.flashHeight === before.flashHeight,
|
||||||
"the message does not fit the reserved line: " +
|
"the message does not keep to the reserved line: " +
|
||||||
before.flashHeight +
|
before.flashHeight +
|
||||||
"px empty vs " +
|
"px empty vs " +
|
||||||
after.flashHeight +
|
after.flashHeight +
|
||||||
"px with the message. Shorten DUST_THRESHOLD_MESSAGE",
|
"px with the message",
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
after.settingsTop === before.settingsTop,
|
after.settingsTop === before.settingsTop,
|
||||||
@@ -1400,6 +1397,134 @@ test("a rejected dust threshold shifts no layout (#233)", async (env) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// ------------------------------------------------ the flash line (#252)
|
||||||
|
|
||||||
|
// #flash-msg never wraps: a message too long for its one line is cut with an
|
||||||
|
// ellipsis (see showFlash() in src/popup/views/helpers.js). This puts a
|
||||||
|
// message several lines long into it and measures that the line and the
|
||||||
|
// screen below it stay where they were.
|
||||||
|
test("an over-long flash message keeps to one line (#252)", async (env) => {
|
||||||
|
const page = await openPopup(env.ctx, env.popupUrl);
|
||||||
|
try {
|
||||||
|
await page.setViewportSize(POPUP_VIEWPORT);
|
||||||
|
await openSettings(page);
|
||||||
|
|
||||||
|
const before = await page.evaluate(measureFlashLine);
|
||||||
|
const overflows = await page.evaluate(() => {
|
||||||
|
const line = document.getElementById("flash-msg");
|
||||||
|
line.textContent =
|
||||||
|
"This message is far too long for one line. ".repeat(5);
|
||||||
|
return line.scrollWidth > line.clientWidth;
|
||||||
|
});
|
||||||
|
const after = await page.evaluate(measureFlashLine);
|
||||||
|
|
||||||
|
assert(
|
||||||
|
after.flashHeight === before.flashHeight,
|
||||||
|
"the flash line is " +
|
||||||
|
before.flashHeight +
|
||||||
|
"px before and " +
|
||||||
|
after.flashHeight +
|
||||||
|
"px with an over-long message, so it wraps",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
after.settingsTop === before.settingsTop,
|
||||||
|
"the settings view moved " +
|
||||||
|
(after.settingsTop - before.settingsTop) +
|
||||||
|
"px when the message appeared",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
after.fieldTop === before.fieldTop,
|
||||||
|
"the dust threshold field moved " +
|
||||||
|
(after.fieldTop - before.fieldTop) +
|
||||||
|
"px when the message appeared",
|
||||||
|
);
|
||||||
|
// Checked last: a line that wraps does not run past its right edge,
|
||||||
|
// so this only shows the message really was cut once nothing moved.
|
||||||
|
assert(
|
||||||
|
overflows,
|
||||||
|
"the message fits on the line, so it proves nothing: " +
|
||||||
|
JSON.stringify(after.text),
|
||||||
|
);
|
||||||
|
} finally {
|
||||||
|
await page.close();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// --------------------------------------- password error containers (#297)
|
||||||
|
|
||||||
|
// Every screen that asks for a password reserves room for one line of error.
|
||||||
|
// The two on the dApp approval screens also have a border and padding, which
|
||||||
|
// that reserved height has to cover too.
|
||||||
|
const PASSWORD_ERROR_CONTAINERS = [
|
||||||
|
"approve-tx-error",
|
||||||
|
"approve-sign-error",
|
||||||
|
"export-privkey-flash",
|
||||||
|
"show-phrase-flash",
|
||||||
|
"delete-wallet-flash",
|
||||||
|
"confirm-tx-password-error",
|
||||||
|
];
|
||||||
|
|
||||||
|
// Shows only the screen holding the container, then measures the container
|
||||||
|
// and the element below it empty and again filled the way showError() in
|
||||||
|
// src/popup/views/helpers.js fills it. Runs in the page.
|
||||||
|
function measurePasswordError(id) {
|
||||||
|
const container = document.getElementById(id);
|
||||||
|
const screen = container.closest(".view");
|
||||||
|
for (const view of document.querySelectorAll(".view")) {
|
||||||
|
view.classList.toggle("hidden", view !== screen);
|
||||||
|
}
|
||||||
|
const below = container.nextElementSibling;
|
||||||
|
const measure = () => ({
|
||||||
|
height: container.getBoundingClientRect().height,
|
||||||
|
belowTop: below.getBoundingClientRect().top + window.scrollY,
|
||||||
|
belowHeight: below.getBoundingClientRect().height,
|
||||||
|
});
|
||||||
|
const empty = measure();
|
||||||
|
container.textContent = "Please enter your password.";
|
||||||
|
container.style.visibility = "visible";
|
||||||
|
const filled = measure();
|
||||||
|
container.textContent = "";
|
||||||
|
container.style.visibility = "hidden";
|
||||||
|
return { empty, filled };
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a password error moves nothing on any screen (#297)", async (env) => {
|
||||||
|
const page = await openPopup(env.ctx, env.popupUrl);
|
||||||
|
try {
|
||||||
|
await page.setViewportSize(POPUP_VIEWPORT);
|
||||||
|
for (const id of PASSWORD_ERROR_CONTAINERS) {
|
||||||
|
const { empty, filled } = await page.evaluate(
|
||||||
|
measurePasswordError,
|
||||||
|
id,
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
empty.belowHeight > 0,
|
||||||
|
"nothing is shown below #" + id + ", so nothing was measured",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
filled.height === empty.height,
|
||||||
|
"#" +
|
||||||
|
id +
|
||||||
|
" is " +
|
||||||
|
empty.height +
|
||||||
|
"px empty and " +
|
||||||
|
filled.height +
|
||||||
|
"px with an error",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
filled.belowTop === empty.belowTop,
|
||||||
|
"the element below #" +
|
||||||
|
id +
|
||||||
|
" moved " +
|
||||||
|
(filled.belowTop - empty.belowTop) +
|
||||||
|
"px when the error appeared",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
await page.close();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
// --------------------------------------------- confirmation screen (#238)
|
// --------------------------------------------- confirmation screen (#238)
|
||||||
//
|
//
|
||||||
// The screen that decides what gets signed. The arithmetic underneath it
|
// The screen that decides what gets signed. The arithmetic underneath it
|
||||||
@@ -1414,9 +1539,10 @@ test("a rejected dust threshold shifts no layout (#233)", async (env) => {
|
|||||||
// on opposite sides of the reserve while sitting on the same side of the
|
// on opposite sides of the reserve while sitting on the same side of the
|
||||||
// estimate.
|
// estimate.
|
||||||
|
|
||||||
// The balance the funded fixture serves, and the amounts sent against it.
|
// The balance the funded fixture serves, as the Send and confirmation screens
|
||||||
|
// show it, and the amounts sent against it.
|
||||||
const FUNDED_ETH_WEI = 10n ** 18n;
|
const FUNDED_ETH_WEI = 10n ** 18n;
|
||||||
const FUNDED_ETH_TEXT = "1.0";
|
const FUNDED_ETH_TEXT = "1.0000";
|
||||||
const COMFORTABLE_AMOUNT = "0.1";
|
const COMFORTABLE_AMOUNT = "0.1";
|
||||||
const OVER_BALANCE_AMOUNT = "2.0";
|
const OVER_BALANCE_AMOUNT = "2.0";
|
||||||
|
|
||||||
@@ -1430,7 +1556,7 @@ const GAP_AMOUNT = formatEther(FUNDED_ETH_WEI - FEE_ESTIMATE_WEI);
|
|||||||
// fee test: it covers the expected cost to the wei and falls short of the
|
// fee test: it covers the expected cost to the wei and falls short of the
|
||||||
// reserve, so the same swap flips this assertion too — through a different
|
// reserve, so the same swap flips this assertion too — through a different
|
||||||
// balance and a different message than the ETH path uses.
|
// balance and a different message than the ETH path uses.
|
||||||
const TOKEN_BALANCE_TEXT = "1.5";
|
const TOKEN_BALANCE_TEXT = "1.5000";
|
||||||
const TOKEN_AMOUNT = "0.25";
|
const TOKEN_AMOUNT = "0.25";
|
||||||
const OVER_TOKEN_AMOUNT = "9.0";
|
const OVER_TOKEN_AMOUNT = "9.0";
|
||||||
const FEE_ONLY_ETH_WEI = FEE_ESTIMATE_WEI;
|
const FEE_ONLY_ETH_WEI = FEE_ESTIMATE_WEI;
|
||||||
@@ -1439,16 +1565,15 @@ function toHexWei(wei) {
|
|||||||
return "0x" + wei.toString(16);
|
return "0x" + wei.toString(16);
|
||||||
}
|
}
|
||||||
|
|
||||||
// A fee in wei as the confirmation screen writes it. Deliberately a second
|
// A fee in wei as the confirmation screen writes it: truncated to four decimal
|
||||||
// implementation of formatFeeEth() from src/popup/views/confirmTx.js rather
|
// places (README.md, Display Consistency). Deliberately a second
|
||||||
// than an import of it: that module pulls in the whole popup and cannot be
|
// implementation rather than an import of src/shared/amountDisplay.js:
|
||||||
// required outside a browser, and asserting against an independent rendering
|
// asserting against an independent rendering is stronger than asserting a
|
||||||
// is stronger than asserting a function equals itself.
|
// function equals itself. The fixture's fees are above 0.0001 ETH, so the
|
||||||
|
// nonzero floor never applies here.
|
||||||
function feeEth(wei) {
|
function feeEth(wei) {
|
||||||
const parts = formatEther(wei).split(".");
|
const [whole, frac = ""] = formatEther(wei).split(".");
|
||||||
const dec =
|
return whole + "." + (frac + "0000").slice(0, 4) + " ETH";
|
||||||
parts.length > 1 ? parts[1].slice(0, 6).replace(/0+$/, "") || "0" : "0";
|
|
||||||
return parts[0] + "." + dec + " ETH";
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// What the confirmation screen is showing right now, read out of the DOM in
|
// What the confirmation screen is showing right now, read out of the DOM in
|
||||||
@@ -1505,11 +1630,10 @@ async function backToAddress(page) {
|
|||||||
|
|
||||||
// Drive the popup to the confirmation screen for one send.
|
// Drive the popup to the confirmation screen for one send.
|
||||||
//
|
//
|
||||||
// It waits for the send screen to be showing `balance` before filling
|
// It waits for the send screen to be showing `balance`, the fixture's balance
|
||||||
// anything in. That figure is the exact number the spend gate compares
|
// as that screen displays it, before filling anything in. Waiting for it —
|
||||||
// against, so waiting for it — rather than for a refresh to have probably
|
// rather than for a refresh to have probably landed — is what keeps every
|
||||||
// landed — is what keeps every assertion below deterministic after a
|
// assertion below deterministic after a fixture change.
|
||||||
// fixture change.
|
|
||||||
async function goToConfirm(page, { token, balance, amount }) {
|
async function goToConfirm(page, { token, balance, amount }) {
|
||||||
await backToAddress(page);
|
await backToAddress(page);
|
||||||
await page.click("#btn-send");
|
await page.click("#btn-send");
|
||||||
@@ -2348,8 +2472,6 @@ test("a token whose symbol() returns markup renders as text (#307)", async (env)
|
|||||||
// dApp, with real funds, against a real network. The RPC is stubbed
|
// dApp, with real funds, against a real network. The RPC is stubbed
|
||||||
// throughout. That pass stays on the human list before 1.0.0.
|
// throughout. That pass stays on the human list before 1.0.0.
|
||||||
|
|
||||||
const DAPP_HOSTNAME = new URL(DAPP_URL).hostname;
|
|
||||||
|
|
||||||
// The personal_sign payload. Sent as hex, which is what dApps send and what
|
// The personal_sign payload. Sent as hex, which is what dApps send and what
|
||||||
// the popup requires — it calls getBytes() on the message — and displayed on
|
// the popup requires — it calls getBytes() on the message — and displayed on
|
||||||
// the approval screen as the decoded text, which is what the user is agreeing
|
// the approval screen as the decoded text, which is what the user is agreeing
|
||||||
@@ -2893,11 +3015,10 @@ test("eth_requestAccounts rejected at the prompt returns a rejection (#183)", as
|
|||||||
try {
|
try {
|
||||||
await visible(popup, "#view-approve-site");
|
await visible(popup, "#view-approve-site");
|
||||||
|
|
||||||
const hostname = await popup.locator("#approve-hostname").innerText();
|
const origin = await popup.locator("#approve-origin").innerText();
|
||||||
assert(
|
assert(
|
||||||
hostname === DAPP_HOSTNAME,
|
origin === DAPP_ORIGIN,
|
||||||
"the site prompt names the wrong origin: " +
|
"the site prompt names the wrong origin: " + JSON.stringify(origin),
|
||||||
JSON.stringify(hostname),
|
|
||||||
);
|
);
|
||||||
|
|
||||||
// The control for the phishing test below: this origin is not on the
|
// The control for the phishing test below: this origin is not on the
|
||||||
@@ -2978,7 +3099,6 @@ test("a connect request from a blocklisted site is flagged (#219)", async (env)
|
|||||||
// check and the real approval screen. Nothing about the list is stubbed —
|
// check and the real approval screen. Nothing about the list is stubbed —
|
||||||
// there is nothing left to stub, since the extension no longer fetches it.
|
// there is nothing left to stub, since the extension no longer fetches it.
|
||||||
const phishingDapp = await openDapp(env.ctx, PHISHING_DAPP_URL);
|
const phishingDapp = await openDapp(env.ctx, PHISHING_DAPP_URL);
|
||||||
const hostname = new URL(PHISHING_DAPP_URL).hostname;
|
|
||||||
try {
|
try {
|
||||||
await reserveApprovalTab(env);
|
await reserveApprovalTab(env);
|
||||||
await startRequest(
|
await startRequest(
|
||||||
@@ -2991,15 +3111,15 @@ test("a connect request from a blocklisted site is flagged (#219)", async (env)
|
|||||||
try {
|
try {
|
||||||
await visible(popup, "#view-approve-site");
|
await visible(popup, "#view-approve-site");
|
||||||
|
|
||||||
const shown = await popup.locator("#approve-hostname").innerText();
|
const shown = await popup.locator("#approve-origin").innerText();
|
||||||
assert(
|
assert(
|
||||||
shown === hostname,
|
shown === PHISHING_DAPP_ORIGIN,
|
||||||
"the site prompt names the wrong origin: " +
|
"the site prompt names the wrong origin: " +
|
||||||
JSON.stringify(shown),
|
JSON.stringify(shown),
|
||||||
);
|
);
|
||||||
|
|
||||||
await visible(popup, "#approve-site-phishing-warning");
|
await visible(popup, "#approve-site-phishing-warning");
|
||||||
console.log("# phishing warning shown for " + hostname);
|
console.log("# phishing warning shown for " + PHISHING_DAPP_ORIGIN);
|
||||||
|
|
||||||
// Not remembered: a remembered decision for this origin would
|
// Not remembered: a remembered decision for this origin would
|
||||||
// outlive the test.
|
// outlive the test.
|
||||||
@@ -3029,15 +3149,15 @@ test("personal_sign signs, and the signature recovers to the address (#183)", as
|
|||||||
const boundary = await watchApprovalBoundary(popup, env);
|
const boundary = await watchApprovalBoundary(popup, env);
|
||||||
|
|
||||||
const screen = await popup.evaluate(() => ({
|
const screen = await popup.evaluate(() => ({
|
||||||
hostname: document.getElementById("approve-sign-hostname").textContent,
|
origin: document.getElementById("approve-sign-origin").textContent,
|
||||||
type: document.getElementById("approve-sign-type").textContent,
|
type: document.getElementById("approve-sign-type").textContent,
|
||||||
message: document.getElementById("approve-sign-message").textContent,
|
message: document.getElementById("approve-sign-message").textContent,
|
||||||
from: document.getElementById("approve-sign-from").textContent,
|
from: document.getElementById("approve-sign-from").textContent,
|
||||||
}));
|
}));
|
||||||
assert(
|
assert(
|
||||||
screen.hostname === DAPP_HOSTNAME,
|
screen.origin === DAPP_ORIGIN,
|
||||||
"the sign prompt names the wrong origin: " +
|
"the sign prompt names the wrong origin: " +
|
||||||
JSON.stringify(screen.hostname),
|
JSON.stringify(screen.origin),
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.type === "Personal message",
|
screen.type === "Personal message",
|
||||||
@@ -3122,15 +3242,15 @@ test("eth_signTypedData_v4 signs, and the signature recovers (#183)", async (env
|
|||||||
const boundary = await watchApprovalBoundary(popup, env);
|
const boundary = await watchApprovalBoundary(popup, env);
|
||||||
|
|
||||||
const screen = await popup.evaluate(() => ({
|
const screen = await popup.evaluate(() => ({
|
||||||
hostname: document.getElementById("approve-sign-hostname").textContent,
|
origin: document.getElementById("approve-sign-origin").textContent,
|
||||||
type: document.getElementById("approve-sign-type").textContent,
|
type: document.getElementById("approve-sign-type").textContent,
|
||||||
message: document.getElementById("approve-sign-message").innerText,
|
message: document.getElementById("approve-sign-message").innerText,
|
||||||
from: document.getElementById("approve-sign-from").textContent,
|
from: document.getElementById("approve-sign-from").textContent,
|
||||||
}));
|
}));
|
||||||
assert(
|
assert(
|
||||||
screen.hostname === DAPP_HOSTNAME,
|
screen.origin === DAPP_ORIGIN,
|
||||||
"the typed data prompt names the wrong origin: " +
|
"the typed data prompt names the wrong origin: " +
|
||||||
JSON.stringify(screen.hostname),
|
JSON.stringify(screen.origin),
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.type === "Typed data (EIP-712)",
|
screen.type === "Typed data (EIP-712)",
|
||||||
@@ -3228,7 +3348,7 @@ test("eth_sendTransaction signs the approved transaction and broadcasts it (#183
|
|||||||
const boundary = await watchApprovalBoundary(popup, env);
|
const boundary = await watchApprovalBoundary(popup, env);
|
||||||
|
|
||||||
const screen = await popup.evaluate(() => ({
|
const screen = await popup.evaluate(() => ({
|
||||||
hostname: document.getElementById("approve-tx-hostname").textContent,
|
origin: document.getElementById("approve-tx-origin").textContent,
|
||||||
from: document.getElementById("approve-tx-from").textContent,
|
from: document.getElementById("approve-tx-from").textContent,
|
||||||
to: document.getElementById("approve-tx-to").textContent,
|
to: document.getElementById("approve-tx-to").textContent,
|
||||||
value: document.getElementById("approve-tx-value").textContent,
|
value: document.getElementById("approve-tx-value").textContent,
|
||||||
@@ -3238,9 +3358,9 @@ test("eth_sendTransaction signs the approved transaction and broadcasts it (#183
|
|||||||
.classList.contains("hidden"),
|
.classList.contains("hidden"),
|
||||||
}));
|
}));
|
||||||
assert(
|
assert(
|
||||||
screen.hostname === DAPP_HOSTNAME,
|
screen.origin === DAPP_ORIGIN,
|
||||||
"the transaction prompt names the wrong origin: " +
|
"the transaction prompt names the wrong origin: " +
|
||||||
JSON.stringify(screen.hostname),
|
JSON.stringify(screen.origin),
|
||||||
);
|
);
|
||||||
assert(
|
assert(
|
||||||
screen.from.toLowerCase().includes(env.expectedAddress.toLowerCase()),
|
screen.from.toLowerCase().includes(env.expectedAddress.toLowerCase()),
|
||||||
|
|||||||
@@ -0,0 +1,130 @@
|
|||||||
|
// The flash line (#252). #flash-msg reserves one line and cuts a message too
|
||||||
|
// long for it with an ellipsis; that is measured in a real browser by
|
||||||
|
// tests/e2e/run.js. Here: showFlash() keeps the whole message readable in the
|
||||||
|
// line's title, and the two add-token screens flash a fixed line, not the text
|
||||||
|
// of whatever error adding the token threw.
|
||||||
|
|
||||||
|
const ADDRESS = "0x1111111111111111111111111111111111111111";
|
||||||
|
|
||||||
|
let elements;
|
||||||
|
|
||||||
|
function fakeElement() {
|
||||||
|
return {
|
||||||
|
value: "",
|
||||||
|
textContent: "",
|
||||||
|
title: "",
|
||||||
|
style: {},
|
||||||
|
listeners: {},
|
||||||
|
addEventListener(event, handler) {
|
||||||
|
this.listeners[event] = handler;
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Stands in for document.getElementById(): one fake element per id.
|
||||||
|
function element(id) {
|
||||||
|
return (elements[id] ||= fakeElement());
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
jest.resetModules();
|
||||||
|
elements = {};
|
||||||
|
globalThis.document = { getElementById: element };
|
||||||
|
// state.js reads chrome.storage.local at load.
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
jest.dontMock("../src/popup/views/helpers");
|
||||||
|
jest.dontMock("../src/shared/state");
|
||||||
|
jest.dontMock("../src/shared/balances");
|
||||||
|
jest.restoreAllMocks();
|
||||||
|
jest.useRealTimers();
|
||||||
|
delete globalThis.document;
|
||||||
|
delete globalThis.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("showFlash() puts the whole message in the title, and clears both", () => {
|
||||||
|
jest.useFakeTimers();
|
||||||
|
const { showFlash } = require("../src/popup/views/helpers");
|
||||||
|
|
||||||
|
showFlash("Saved.");
|
||||||
|
expect(element("flash-msg").textContent).toBe("Saved.");
|
||||||
|
expect(element("flash-msg").title).toBe("Saved.");
|
||||||
|
|
||||||
|
jest.advanceTimersByTime(2000);
|
||||||
|
expect(element("flash-msg").textContent).toBe("");
|
||||||
|
expect(element("flash-msg").title).toBe("");
|
||||||
|
});
|
||||||
|
|
||||||
|
describe.each([
|
||||||
|
["addToken", "add-token-address", "btn-add-token-confirm"],
|
||||||
|
[
|
||||||
|
"settingsAddToken",
|
||||||
|
"settings-addtoken-address",
|
||||||
|
"btn-settings-addtoken-manual",
|
||||||
|
],
|
||||||
|
])("adding a token on %s", (view, field, button) => {
|
||||||
|
let flashes;
|
||||||
|
let errors;
|
||||||
|
|
||||||
|
// Clicks the screen's add button with lookupTokenInfo() and saveState()
|
||||||
|
// replaced by the given functions.
|
||||||
|
async function add(lookupTokenInfo, saveState) {
|
||||||
|
flashes = [];
|
||||||
|
errors = jest.spyOn(console, "error").mockImplementation(() => {});
|
||||||
|
jest.spyOn(console, "log").mockImplementation(() => {});
|
||||||
|
jest.doMock("../src/shared/balances", () => ({ lookupTokenInfo }));
|
||||||
|
jest.doMock("../src/shared/state", () => ({
|
||||||
|
state: { trackedTokens: [] },
|
||||||
|
saveState,
|
||||||
|
}));
|
||||||
|
jest.doMock("../src/popup/views/helpers", () => ({
|
||||||
|
$: element,
|
||||||
|
showView: () => {},
|
||||||
|
showFlash: (msg) => flashes.push(msg),
|
||||||
|
escapeHtml: (s) => s,
|
||||||
|
goBack: () => {},
|
||||||
|
}));
|
||||||
|
|
||||||
|
require("../src/popup/views/" + view).init({
|
||||||
|
doRefreshAndRender: () => {},
|
||||||
|
});
|
||||||
|
element(field).value = ADDRESS;
|
||||||
|
await element(button).listeners.click();
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a failed save flashes a fixed line and logs the error", async () => {
|
||||||
|
const detail = "A sentence about the stored record. ".repeat(4);
|
||||||
|
|
||||||
|
await add(
|
||||||
|
async () => ({ symbol: "TKN", decimals: 18, name: "Token" }),
|
||||||
|
async () => {
|
||||||
|
throw new Error(detail);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
expect(flashes).toEqual(["Could not add the token."]);
|
||||||
|
expect(errors).toHaveBeenCalledWith(
|
||||||
|
"[AutistMask]",
|
||||||
|
"Adding token failed for",
|
||||||
|
ADDRESS,
|
||||||
|
detail,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a contract that is not a token flashes the lookup message", async () => {
|
||||||
|
const detail = "Not a valid ERC-20 token (symbol() failed).";
|
||||||
|
|
||||||
|
await add(
|
||||||
|
async () => {
|
||||||
|
throw new Error(detail);
|
||||||
|
},
|
||||||
|
async () => {},
|
||||||
|
);
|
||||||
|
|
||||||
|
expect(flashes).toEqual([detail]);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -49,11 +49,12 @@ class StubCustomEvent extends StubEvent {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Every code the background emits on the RPC path today, read out of
|
// Examples of codes the background emits on the RPC path, read out of
|
||||||
// src/background/index.js. The provider must not know this list — it passes
|
// src/background/index.js. The provider must not know any list of codes — it
|
||||||
// through whatever arrived — but the cases below are the real ones.
|
// passes through whatever arrived — but the cases below are real ones.
|
||||||
const REJECTED = 4001; // user rejected the request
|
const REJECTED = 4001; // user rejected the request
|
||||||
const UNAUTHORIZED = 4100; // site not connected / wrong address
|
const UNAUTHORIZED = 4100; // site not connected / wrong address
|
||||||
|
const UNSUPPORTED_METHOD = 4200; // a method the wallet does not implement
|
||||||
const UNRECOGNIZED_CHAIN = 4902; // switch/add to an unsupported chain
|
const UNRECOGNIZED_CHAIN = 4902; // switch/add to an unsupported chain
|
||||||
|
|
||||||
// A stub window with the four things inpage.js touches: message listeners,
|
// A stub window with the four things inpage.js touches: message listeners,
|
||||||
@@ -115,6 +116,41 @@ async function rejectionFrom(start, response) {
|
|||||||
return outcome.error;
|
return outcome.error;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The reply the real background worker (src/background/index.js) sends for
|
||||||
|
// `method`, loaded against just enough of the extension API to receive one
|
||||||
|
// RPC message. Same shape as tests/coldWorkerChainId.test.js.
|
||||||
|
function backgroundReply(method) {
|
||||||
|
jest.resetModules();
|
||||||
|
jest.doMock("../src/shared/alarms", () => ({
|
||||||
|
BALANCE_REFRESH_ALARM: "balance",
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES: 1,
|
||||||
|
ensureRecurringAlarms: async () => {},
|
||||||
|
registerAlarmHandlers: () => {},
|
||||||
|
}));
|
||||||
|
|
||||||
|
let messageListener = null;
|
||||||
|
global.chrome = {
|
||||||
|
runtime: {
|
||||||
|
onMessage: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
messageListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
onConnect: { addListener: () => {} },
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
require("../src/background/index");
|
||||||
|
|
||||||
|
return new Promise((resolve) => {
|
||||||
|
messageListener(
|
||||||
|
{ type: "AUTISTMASK_RPC", method, params: [] },
|
||||||
|
{ origin: "https://dapp.example" },
|
||||||
|
resolve,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
describe("an EIP-1193 code reaches the page", () => {
|
describe("an EIP-1193 code reaches the page", () => {
|
||||||
test("a user rejection arrives as code 4001", async () => {
|
test("a user rejection arrives as code 4001", async () => {
|
||||||
const err = await rejectionFrom(
|
const err = await rejectionFrom(
|
||||||
@@ -164,8 +200,9 @@ describe("an EIP-1193 code reaches the page", () => {
|
|||||||
expect(err.message).toBe(message);
|
expect(err.message).toBe(message);
|
||||||
});
|
});
|
||||||
|
|
||||||
// The provider is not allowed to know the list above: a code added to the
|
// The provider is not allowed to know the codes above: any other code,
|
||||||
// background later must reach the page without this file being edited.
|
// including one added to the background later, must reach the page
|
||||||
|
// without inpage.js being edited.
|
||||||
test("a code the provider has never heard of is passed through", async () => {
|
test("a code the provider has never heard of is passed through", async () => {
|
||||||
const err = await rejectionFrom(
|
const err = await rejectionFrom(
|
||||||
(p) => p.request({ method: "eth_accounts" }),
|
(p) => p.request({ method: "eth_accounts" }),
|
||||||
@@ -203,6 +240,26 @@ describe("an EIP-1193 code reaches the page", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// The reply here is the background's own, not one written in this file: it
|
||||||
|
// used to carry no code for a method the wallet does not implement
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/279), so a site probing for an
|
||||||
|
// optional method could not tell "not implemented" from "the call failed".
|
||||||
|
describe("a method the wallet does not implement", () => {
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("reaches the page as code 4200", async () => {
|
||||||
|
const method = "wallet_noSuchMethod";
|
||||||
|
const err = await rejectionFrom(
|
||||||
|
(p) => p.request({ method }),
|
||||||
|
await backgroundReply(method),
|
||||||
|
);
|
||||||
|
expect(err.code).toBe(UNSUPPORTED_METHOD);
|
||||||
|
expect(err.message).toBe("Unsupported method: " + method);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
describe("the message is untouched", () => {
|
describe("the message is untouched", () => {
|
||||||
test("a coded error keeps the message byte for byte", async () => {
|
test("a coded error keeps the message byte for byte", async () => {
|
||||||
const message =
|
const message =
|
||||||
|
|||||||
@@ -59,24 +59,32 @@ describe("the floor under allowedSites and deniedSites", () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
test(`an ${field} entry whose value is not a hostname list is dropped`, () => {
|
test(`an ${field} entry whose value is not an origin list is dropped`, () => {
|
||||||
for (const bad of ["dapp.example", 42, null, { a: 1 }, true]) {
|
for (const bad of [
|
||||||
|
"https://dapp.example",
|
||||||
|
42,
|
||||||
|
null,
|
||||||
|
{ a: 1 },
|
||||||
|
true,
|
||||||
|
]) {
|
||||||
expect(
|
expect(
|
||||||
normalizePersisted({ [field]: { [ADDRESS]: bad } })[field],
|
normalizePersisted({ [field]: { [ADDRESS]: bad } })[field],
|
||||||
).toEqual({});
|
).toEqual({});
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
test(`a hostname that is not text is dropped from an ${field} entry`, () => {
|
test(`an origin that is not text is dropped from an ${field} entry`, () => {
|
||||||
expect(
|
expect(
|
||||||
normalizePersisted({
|
normalizePersisted({
|
||||||
[field]: { [ADDRESS]: [42, null, "dapp.example", {}] },
|
[field]: {
|
||||||
|
[ADDRESS]: [42, null, "https://dapp.example", {}],
|
||||||
|
},
|
||||||
})[field],
|
})[field],
|
||||||
).toEqual({ [ADDRESS]: ["dapp.example"] });
|
).toEqual({ [ADDRESS]: ["https://dapp.example"] });
|
||||||
});
|
});
|
||||||
|
|
||||||
test(`a real ${field} map survives, copied not shared`, () => {
|
test(`a real ${field} map survives, copied not shared`, () => {
|
||||||
const saved = { [field]: { [ADDRESS]: ["dapp.example"] } };
|
const saved = { [field]: { [ADDRESS]: ["https://dapp.example"] } };
|
||||||
|
|
||||||
const out = normalizePersisted(saved);
|
const out = normalizePersisted(saved);
|
||||||
|
|
||||||
@@ -87,10 +95,13 @@ describe("the floor under allowedSites and deniedSites", () => {
|
|||||||
|
|
||||||
test(`a good ${field} entry beside a malformed one survives`, () => {
|
test(`a good ${field} entry beside a malformed one survives`, () => {
|
||||||
const out = normalizePersisted({
|
const out = normalizePersisted({
|
||||||
[field]: { [ADDRESS]: ["dapp.example"], [TOKEN_ADDRESS]: 42 },
|
[field]: {
|
||||||
|
[ADDRESS]: ["https://dapp.example"],
|
||||||
|
[TOKEN_ADDRESS]: 42,
|
||||||
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
expect(out[field]).toEqual({ [ADDRESS]: ["dapp.example"] });
|
expect(out[field]).toEqual({ [ADDRESS]: ["https://dapp.example"] });
|
||||||
});
|
});
|
||||||
|
|
||||||
test(`a stored own "__proto__" key in ${field} is dropped`, () => {
|
test(`a stored own "__proto__" key in ${field} is dropped`, () => {
|
||||||
@@ -100,7 +111,7 @@ describe("the floor under allowedSites and deniedSites", () => {
|
|||||||
// saveState()'s merge hands to the prototype setter on the next
|
// saveState()'s merge hands to the prototype setter on the next
|
||||||
// write.
|
// write.
|
||||||
const saved = JSON.parse(
|
const saved = JSON.parse(
|
||||||
'{"' + field + '":{"__proto__":["evil.invalid"]}}',
|
'{"' + field + '":{"__proto__":["https://evil.invalid"]}}',
|
||||||
);
|
);
|
||||||
|
|
||||||
const out = normalizePersisted(saved);
|
const out = normalizePersisted(saved);
|
||||||
@@ -197,7 +208,7 @@ describe("a malformed allowedSites entry", () => {
|
|||||||
const MALFORMED = [
|
const MALFORMED = [
|
||||||
{ name: "a string", value: "notalist" },
|
{ name: "a string", value: "notalist" },
|
||||||
{ name: "a number", value: 42 },
|
{ name: "a number", value: 42 },
|
||||||
{ name: "a record", value: { hostnames: ["dapp.example"] } },
|
{ name: "a record", value: { origins: ["https://dapp.example"] } },
|
||||||
];
|
];
|
||||||
|
|
||||||
for (const { name, value } of MALFORMED) {
|
for (const { name, value } of MALFORMED) {
|
||||||
@@ -231,7 +242,7 @@ describe("a malformed allowedSites entry", () => {
|
|||||||
const env = await bootPopup(
|
const env = await bootPopup(
|
||||||
unversionedValidProfile({
|
unversionedValidProfile({
|
||||||
allowedSites: {
|
allowedSites: {
|
||||||
[ADDRESS]: ["dapp.example"],
|
[ADDRESS]: ["https://dapp.example"],
|
||||||
[TOKEN_ADDRESS]: "notalist",
|
[TOKEN_ADDRESS]: "notalist",
|
||||||
},
|
},
|
||||||
}),
|
}),
|
||||||
@@ -239,7 +250,7 @@ describe("a malformed allowedSites entry", () => {
|
|||||||
|
|
||||||
expect(env.pageErrors).toEqual([]);
|
expect(env.pageErrors).toEqual([]);
|
||||||
expect(env.storage.read("autistmask").allowedSites).toEqual({
|
expect(env.storage.read("autistmask").allowedSites).toEqual({
|
||||||
[ADDRESS]: ["dapp.example"],
|
[ADDRESS]: ["https://dapp.example"],
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -165,7 +165,7 @@ const CONTRACT = [
|
|||||||
[ADDRESS],
|
[ADDRESS],
|
||||||
{ [ADDRESS]: 42 },
|
{ [ADDRESS]: 42 },
|
||||||
{ [ADDRESS]: [42, null, {}] },
|
{ [ADDRESS]: [42, null, {}] },
|
||||||
JSON.parse('{"__proto__":["evil.invalid"]}'),
|
JSON.parse('{"__proto__":["https://evil.invalid"]}'),
|
||||||
],
|
],
|
||||||
holds: siteMapHolds,
|
holds: siteMapHolds,
|
||||||
},
|
},
|
||||||
@@ -177,7 +177,7 @@ const CONTRACT = [
|
|||||||
[ADDRESS],
|
[ADDRESS],
|
||||||
{ [ADDRESS]: 42 },
|
{ [ADDRESS]: 42 },
|
||||||
{ [ADDRESS]: [42, null, {}] },
|
{ [ADDRESS]: [42, null, {}] },
|
||||||
JSON.parse('{"__proto__":["evil.invalid"]}'),
|
JSON.parse('{"__proto__":["https://evil.invalid"]}'),
|
||||||
],
|
],
|
||||||
holds: siteMapHolds,
|
holds: siteMapHolds,
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
// What reaches the console when the RPC endpoint answers with an HTTP error.
|
||||||
|
//
|
||||||
|
// RPC providers put the API key in the endpoint URL's path or query string.
|
||||||
|
// When the endpoint answers with an HTTP error (a wrong or expired key, a rate
|
||||||
|
// limit, a server error), the error ethers throws carries the full request URL
|
||||||
|
// in its message, so a line logging that message printed the key
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/410). Those lines log the
|
||||||
|
// error's short message, which names the HTTP status and not the URL.
|
||||||
|
//
|
||||||
|
// The real ethers provider runs; only its HTTP transport is replaced, by one
|
||||||
|
// that answers every request with 401 Unauthorized. Debug mode is on, so
|
||||||
|
// every log level is printed.
|
||||||
|
|
||||||
|
const { FetchRequest } = require("ethers");
|
||||||
|
const {
|
||||||
|
getProvider,
|
||||||
|
lookupTokenInfo,
|
||||||
|
refreshBalances,
|
||||||
|
} = require("../src/shared/balances");
|
||||||
|
const { getFullWarnings } = require("../src/shared/addressWarnings");
|
||||||
|
const { resolveEnsName } = require("../src/shared/ens");
|
||||||
|
const { setRuntimeDebug } = require("../src/shared/log");
|
||||||
|
|
||||||
|
const RPC_URL = "https://rpc.example.invalid/v3/PATHKEY123?token=QUERYTOKEN456";
|
||||||
|
const ADDRESS = "0x1111111111111111111111111111111111111111";
|
||||||
|
|
||||||
|
const realFetch = globalThis.fetch;
|
||||||
|
let printed;
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
setRuntimeDebug(true);
|
||||||
|
printed = [];
|
||||||
|
for (const method of ["log", "warn", "error"]) {
|
||||||
|
jest.spyOn(console, method).mockImplementation((...args) => {
|
||||||
|
printed.push(args.map(String).join(" "));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
FetchRequest.registerGetUrl(async () => ({
|
||||||
|
statusCode: 401,
|
||||||
|
statusMessage: "Unauthorized",
|
||||||
|
headers: {},
|
||||||
|
body: new Uint8Array(),
|
||||||
|
}));
|
||||||
|
// The explorer requests the balance refresh makes go nowhere.
|
||||||
|
globalThis.fetch = jest.fn(async () => {
|
||||||
|
throw new Error("tests must not perform network requests");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
FetchRequest.registerGetUrl(FetchRequest.createGetUrlFunc());
|
||||||
|
globalThis.fetch = realFetch;
|
||||||
|
setRuntimeDebug(false);
|
||||||
|
jest.restoreAllMocks();
|
||||||
|
});
|
||||||
|
|
||||||
|
// The line carrying `label` was printed and names the HTTP status, and nothing
|
||||||
|
// printed carries the key.
|
||||||
|
function expectFailureLoggedWithoutKey(label) {
|
||||||
|
const line = printed.find((text) => text.includes(label));
|
||||||
|
expect(line).toContain("401");
|
||||||
|
const all = printed.join("\n");
|
||||||
|
expect(all).not.toContain("PATHKEY123");
|
||||||
|
expect(all).not.toContain("QUERYTOKEN456");
|
||||||
|
}
|
||||||
|
|
||||||
|
test("ethers puts the URL in the error message, not in the short message", async () => {
|
||||||
|
const provider = getProvider(RPC_URL, "mainnet");
|
||||||
|
const error = await provider.getCode(ADDRESS).catch((e) => e);
|
||||||
|
expect(error.message).toContain("PATHKEY123");
|
||||||
|
expect(error.shortMessage).not.toContain("PATHKEY123");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the recipient checks before a send", async () => {
|
||||||
|
await getFullWarnings(ADDRESS, getProvider(RPC_URL, "mainnet"));
|
||||||
|
expectFailureLoggedWithoutKey("contract check failed");
|
||||||
|
expectFailureLoggedWithoutKey("tx count check failed");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the ENS reverse lookup", async () => {
|
||||||
|
expect(await resolveEnsName(ADDRESS, RPC_URL, "mainnet")).toBeNull();
|
||||||
|
expectFailureLoggedWithoutKey("ENS reverse lookup failed");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the balance refresh", async () => {
|
||||||
|
const wallets = [{ addresses: [{ address: ADDRESS }] }];
|
||||||
|
await refreshBalances(
|
||||||
|
wallets,
|
||||||
|
RPC_URL,
|
||||||
|
"https://explorer.example.invalid/api/v2",
|
||||||
|
[],
|
||||||
|
"mainnet",
|
||||||
|
);
|
||||||
|
expectFailureLoggedWithoutKey("ETH balance failed");
|
||||||
|
expectFailureLoggedWithoutKey("ENS reverse failed");
|
||||||
|
});
|
||||||
|
|
||||||
|
// The lookup's first line, at debug level, names the RPC endpoint; the check
|
||||||
|
// of everything printed covers it too.
|
||||||
|
test("the token lookup", async () => {
|
||||||
|
await expect(lookupTokenInfo(ADDRESS, RPC_URL, "mainnet")).rejects.toThrow(
|
||||||
|
"Not a valid ERC-20 token",
|
||||||
|
);
|
||||||
|
expectFailureLoggedWithoutKey("symbol() failed:");
|
||||||
|
});
|
||||||
@@ -0,0 +1,146 @@
|
|||||||
|
// Which site a page's request is attributed to.
|
||||||
|
//
|
||||||
|
// The background takes a request's origin from what the browser says sent the
|
||||||
|
// message: sender.origin, or on Firefox before 126, which has no
|
||||||
|
// sender.origin, the origin of sender.url — the frame that sent it. It used to
|
||||||
|
// fall back to the tab's page and then to an origin the message itself
|
||||||
|
// carried, so a request from a frame was credited to the site embedding it,
|
||||||
|
// and a request the browser said nothing about was credited to whatever the
|
||||||
|
// page wrote (https://git.eeqj.de/sneak/AutistMask/issues/407).
|
||||||
|
//
|
||||||
|
// Every sender here lacks sender.origin, as on old Firefox. The connection
|
||||||
|
// check on eth_accounts is what shows which site a request was credited to.
|
||||||
|
|
||||||
|
const { makeStorageStub } = require("./support/storageStub");
|
||||||
|
|
||||||
|
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
|
// The site the persisted state has connected, and one it has never heard of.
|
||||||
|
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||||
|
const STRANGER_ORIGIN = "https://stranger.example";
|
||||||
|
|
||||||
|
async function settle() {
|
||||||
|
for (let i = 0; i < 50; i++) await Promise.resolve();
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
function loadBackground() {
|
||||||
|
jest.resetModules();
|
||||||
|
|
||||||
|
jest.doMock("../src/shared/balances", () => ({
|
||||||
|
getProvider: () => ({}),
|
||||||
|
refreshBalances: jest.fn(async () => {}),
|
||||||
|
}));
|
||||||
|
jest.doMock("../src/shared/phishingDomains", () => ({
|
||||||
|
isPhishingDomain: () => false,
|
||||||
|
}));
|
||||||
|
jest.doMock("../src/shared/alarms", () => ({
|
||||||
|
BALANCE_REFRESH_ALARM: "balance",
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES: 1,
|
||||||
|
ensureRecurringAlarms: jest.fn(async () => {}),
|
||||||
|
registerAlarmHandlers: jest.fn(),
|
||||||
|
}));
|
||||||
|
|
||||||
|
const storage = makeStorageStub({
|
||||||
|
autistmask: {
|
||||||
|
networkId: "mainnet",
|
||||||
|
wallets: [
|
||||||
|
{
|
||||||
|
name: "Wallet 1",
|
||||||
|
type: "hd",
|
||||||
|
addresses: [
|
||||||
|
{ address: ADDRESS, balance: "0", tokenBalances: [] },
|
||||||
|
],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
activeAddress: ADDRESS,
|
||||||
|
allowedSites: { [ADDRESS]: [CONNECTED_ORIGIN] },
|
||||||
|
deniedSites: {},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
let messageListener = null;
|
||||||
|
global.chrome = {
|
||||||
|
storage,
|
||||||
|
runtime: {
|
||||||
|
getURL: (path) => "chrome-extension://autistmask/" + path,
|
||||||
|
onMessage: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
messageListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
onConnect: { addListener: () => {} },
|
||||||
|
lastError: null,
|
||||||
|
},
|
||||||
|
windows: { onRemoved: { addListener: () => {} } },
|
||||||
|
action: { setPopup: () => {} },
|
||||||
|
};
|
||||||
|
|
||||||
|
require("../src/background/index");
|
||||||
|
|
||||||
|
// Ask for eth_accounts. `claimedOrigin` is an origin written into the
|
||||||
|
// message, as the content script used to send.
|
||||||
|
return async function accounts(sender, claimedOrigin) {
|
||||||
|
let result = null;
|
||||||
|
messageListener(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_RPC",
|
||||||
|
method: "eth_accounts",
|
||||||
|
params: [],
|
||||||
|
origin: claimedOrigin,
|
||||||
|
},
|
||||||
|
sender,
|
||||||
|
(r) => {
|
||||||
|
result = r;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
return result;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("a request is attributed to the frame that sent it", () => {
|
||||||
|
test("a stranger's frame on a connected site gets no address", async () => {
|
||||||
|
const accounts = loadBackground();
|
||||||
|
|
||||||
|
const result = await accounts({
|
||||||
|
url: STRANGER_ORIGIN + "/frame.html",
|
||||||
|
tab: { url: CONNECTED_ORIGIN + "/" },
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(result).toEqual({ result: [] });
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a connected site's frame on a stranger's page gets the address", async () => {
|
||||||
|
const accounts = loadBackground();
|
||||||
|
|
||||||
|
const result = await accounts({
|
||||||
|
url: CONNECTED_ORIGIN + "/frame.html",
|
||||||
|
tab: { url: STRANGER_ORIGIN + "/" },
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(result).toEqual({ result: [ADDRESS] });
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("a request the browser does not say the sender of", () => {
|
||||||
|
test("is refused, whatever the tab or the message says", async () => {
|
||||||
|
const accounts = loadBackground();
|
||||||
|
|
||||||
|
const result = await accounts(
|
||||||
|
{ tab: { url: CONNECTED_ORIGIN + "/" } },
|
||||||
|
CONNECTED_ORIGIN,
|
||||||
|
);
|
||||||
|
|
||||||
|
expect(result).toEqual({
|
||||||
|
error: {
|
||||||
|
code: 4100,
|
||||||
|
message:
|
||||||
|
"The wallet could not tell which site sent this request.",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,453 @@
|
|||||||
|
// The balance and fee lines of the Send and confirmation screens, and the fee
|
||||||
|
// line they must share with the approval screen.
|
||||||
|
//
|
||||||
|
// An ETH balance, a token balance or a fee below 0.000001 rendered as zero on
|
||||||
|
// these screens (https://git.eeqj.de/sneak/AutistMask/issues/343): the stored
|
||||||
|
// balances and the fee were each cut to six decimal places, a rule of their
|
||||||
|
// own, and a token holding cut to zero was dropped, while the approval screen
|
||||||
|
// showed the same fee through src/shared/amountDisplay.js with the nonzero
|
||||||
|
// floor. The balances are now stored exactly, every nonzero token holding
|
||||||
|
// kept, and the screens show them and the fee through that helper.
|
||||||
|
//
|
||||||
|
// Driven through the real refreshBalances(), Send screen, confirmation screen
|
||||||
|
// and approval screen, with only the node, the explorer and the DOM stubbed: a
|
||||||
|
// balance written onto state by hand would skip the place the cut happened.
|
||||||
|
|
||||||
|
"use strict";
|
||||||
|
|
||||||
|
// What the stub node answers. Each test sets what it needs.
|
||||||
|
const mockNode = {
|
||||||
|
balanceWei: 0n,
|
||||||
|
feeData: { maxFeePerGas: 1n, gasPrice: 1n },
|
||||||
|
};
|
||||||
|
|
||||||
|
// The token rows the stub explorer reports for the address.
|
||||||
|
const mockExplorer = { items: [] };
|
||||||
|
|
||||||
|
jest.mock("ethers", () => {
|
||||||
|
const actual = jest.requireActual("ethers");
|
||||||
|
class StubProvider {
|
||||||
|
async getBalance() {
|
||||||
|
return mockNode.balanceWei;
|
||||||
|
}
|
||||||
|
async lookupAddress() {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
async getFeeData() {
|
||||||
|
return mockNode.feeData;
|
||||||
|
}
|
||||||
|
async estimateGas() {
|
||||||
|
return 21000n;
|
||||||
|
}
|
||||||
|
async getCode() {
|
||||||
|
return "0x";
|
||||||
|
}
|
||||||
|
async getTransactionCount() {
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
...actual,
|
||||||
|
JsonRpcProvider: StubProvider,
|
||||||
|
Network: { from: () => ({}) },
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
jest.mock("../src/shared/log", () => ({
|
||||||
|
log: {
|
||||||
|
debugf: () => {},
|
||||||
|
infof: () => {},
|
||||||
|
warnf: () => {},
|
||||||
|
errorf: () => {},
|
||||||
|
},
|
||||||
|
// The explorer's token list, which refreshBalances() also fetches.
|
||||||
|
debugFetch: jest.fn(async () => ({
|
||||||
|
ok: true,
|
||||||
|
status: 200,
|
||||||
|
json: async () => mockExplorer.items,
|
||||||
|
})),
|
||||||
|
urlOrigin: () => "",
|
||||||
|
setRuntimeDebug: () => {},
|
||||||
|
isDebug: () => false,
|
||||||
|
}));
|
||||||
|
|
||||||
|
// The confirmation screen's Etherscan label lookup is the only fetch() these
|
||||||
|
// screens make; it fails, as it does offline.
|
||||||
|
global.fetch = jest.fn(() => {
|
||||||
|
throw new Error("tests must not perform network requests");
|
||||||
|
});
|
||||||
|
|
||||||
|
// The approval the background hands the approval screen. Set per test.
|
||||||
|
let approvalDetails = null;
|
||||||
|
|
||||||
|
const { makeStorageStub } = require("./support/storageStub");
|
||||||
|
global.chrome = {
|
||||||
|
storage: makeStorageStub(),
|
||||||
|
runtime: {
|
||||||
|
connect: () => ({
|
||||||
|
postMessage() {},
|
||||||
|
disconnect() {},
|
||||||
|
onDisconnect: { addListener() {} },
|
||||||
|
}),
|
||||||
|
sendMessage(message, callback) {
|
||||||
|
callback(
|
||||||
|
message.type === "AUTISTMASK_GET_APPROVAL"
|
||||||
|
? approvalDetails
|
||||||
|
: undefined,
|
||||||
|
);
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
// A stub DOM: every id resolves to a recording element.
|
||||||
|
const elements = new Map();
|
||||||
|
|
||||||
|
function makeEl(id) {
|
||||||
|
const handlers = new Map();
|
||||||
|
return {
|
||||||
|
id,
|
||||||
|
textContent: "",
|
||||||
|
innerHTML: "",
|
||||||
|
value: "",
|
||||||
|
disabled: false,
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
classList: {
|
||||||
|
add() {},
|
||||||
|
remove() {},
|
||||||
|
toggle() {},
|
||||||
|
contains: () => false,
|
||||||
|
},
|
||||||
|
handlers,
|
||||||
|
children: [],
|
||||||
|
addEventListener(name, fn) {
|
||||||
|
handlers.set(name, fn);
|
||||||
|
},
|
||||||
|
appendChild(child) {
|
||||||
|
this.children.push(child);
|
||||||
|
return child;
|
||||||
|
},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
querySelector: () => null,
|
||||||
|
remove() {},
|
||||||
|
focus() {},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
global.document = {
|
||||||
|
getElementById(id) {
|
||||||
|
if (!elements.has(id)) elements.set(id, makeEl(id));
|
||||||
|
return elements.get(id);
|
||||||
|
},
|
||||||
|
createElement: (tag) => makeEl(tag),
|
||||||
|
body: { prepend() {}, appendChild() {} },
|
||||||
|
addEventListener() {},
|
||||||
|
};
|
||||||
|
global.navigator = { clipboard: { writeText() {} } };
|
||||||
|
|
||||||
|
const { refreshBalances } = require("../src/shared/balances");
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const {
|
||||||
|
prices,
|
||||||
|
clearPrices,
|
||||||
|
formatAddressTotal,
|
||||||
|
getAddressValue,
|
||||||
|
} = require("../src/shared/prices");
|
||||||
|
const send = require("../src/popup/views/send");
|
||||||
|
const confirmTx = require("../src/popup/views/confirmTx");
|
||||||
|
const approval = require("../src/popup/views/approval");
|
||||||
|
const {
|
||||||
|
addressHoldsFunds,
|
||||||
|
balanceLinesForAddress,
|
||||||
|
} = require("../src/popup/views/helpers");
|
||||||
|
|
||||||
|
const HOLDER = "0x" + "a".repeat(40);
|
||||||
|
const RECIPIENT = "0xC0FfEE0000000000000000000000000000c0fFEe";
|
||||||
|
|
||||||
|
// 0.0000005 ETH, or 0.0000005 of an 18-decimal token.
|
||||||
|
const HALF_MICRO_ETH = 500000000000n;
|
||||||
|
|
||||||
|
// A token the bundled list does not know.
|
||||||
|
const TOKEN = "0x" + "d".repeat(40);
|
||||||
|
|
||||||
|
// The explorer's row for TOKEN, holding `value` base units. With only five
|
||||||
|
// holders, it is listed only when the user tracks the token.
|
||||||
|
function tokenRow(value, token = {}) {
|
||||||
|
return {
|
||||||
|
value: String(value),
|
||||||
|
token: {
|
||||||
|
type: "ERC-20",
|
||||||
|
address_hash: TOKEN,
|
||||||
|
symbol: "TOK",
|
||||||
|
name: "Token",
|
||||||
|
decimals: "18",
|
||||||
|
holders_count: "5",
|
||||||
|
...token,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function text(id) {
|
||||||
|
return global.document.getElementById(id).textContent;
|
||||||
|
}
|
||||||
|
|
||||||
|
function errors() {
|
||||||
|
return global.document.getElementById("confirm-errors").innerHTML;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The ETH balance the node reports and the token rows the explorer reports,
|
||||||
|
// fetched and stored exactly where the popup stores them.
|
||||||
|
async function refreshWith(balanceWei, tokenItems = []) {
|
||||||
|
mockNode.balanceWei = balanceWei;
|
||||||
|
mockExplorer.items = tokenItems;
|
||||||
|
state.wallets = [{ name: "Wallet 1", addresses: [{ address: HOLDER }] }];
|
||||||
|
state.selectedWallet = 0;
|
||||||
|
state.selectedAddress = 0;
|
||||||
|
await refreshBalances(
|
||||||
|
state.wallets,
|
||||||
|
"https://rpc.example.invalid",
|
||||||
|
"https://blockscout.example/api/v2",
|
||||||
|
state.trackedTokens,
|
||||||
|
"mainnet",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Press Review on the Send screen for a send of `token` ("ETH" or a token
|
||||||
|
// address), and show the confirmation screen it leads to with its fee estimate
|
||||||
|
// settled.
|
||||||
|
async function confirmSend(amount, token = "ETH") {
|
||||||
|
let txInfo = null;
|
||||||
|
send.init({ showConfirmTx: (info) => (txInfo = info) });
|
||||||
|
state.selectedToken = token;
|
||||||
|
global.document.getElementById("send-to").value = RECIPIENT;
|
||||||
|
global.document.getElementById("send-amount").value = amount;
|
||||||
|
await global.document
|
||||||
|
.getElementById("btn-send-review")
|
||||||
|
.handlers.get("click")();
|
||||||
|
confirmTx.show(txInfo);
|
||||||
|
for (let i = 0; i < 10; i++) await new Promise((r) => setTimeout(r, 0));
|
||||||
|
}
|
||||||
|
|
||||||
|
// The approval screen for a dApp transaction of 21000 gas, the gas the stub
|
||||||
|
// node estimates for the send above.
|
||||||
|
async function approveTxWithFeePerGas(maxFeePerGas) {
|
||||||
|
approvalDetails = {
|
||||||
|
type: "tx",
|
||||||
|
origin: "https://dapp.example",
|
||||||
|
approvedFrom: HOLDER,
|
||||||
|
approvedTx: {
|
||||||
|
to: RECIPIENT,
|
||||||
|
value: "0",
|
||||||
|
data: "0x",
|
||||||
|
chainId: "0x1",
|
||||||
|
gasLimit: "21000",
|
||||||
|
maxFeePerGas: String(maxFeePerGas),
|
||||||
|
nonce: 0,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
await approval.show("1");
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
elements.clear();
|
||||||
|
state.selectedToken = null;
|
||||||
|
state.trackedTokens = [];
|
||||||
|
state.fraudContracts = [];
|
||||||
|
state.currentView = null;
|
||||||
|
mockNode.feeData = { maxFeePerGas: 1n, gasPrice: 1n };
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("an ETH balance below 0.000001 never renders as zero", () => {
|
||||||
|
test("on the Send screen", async () => {
|
||||||
|
await refreshWith(HALF_MICRO_ETH);
|
||||||
|
state.selectedToken = "ETH";
|
||||||
|
send.updateSendBalance();
|
||||||
|
expect(text("send-balance")).toBe("Current balance: 0.0000005 ETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("on the confirmation screen", async () => {
|
||||||
|
await refreshWith(HALF_MICRO_ETH);
|
||||||
|
await confirmSend("0.0000001");
|
||||||
|
expect(text("confirm-balance")).toBe("0.0000005 ETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("while a balance above the floor keeps four decimals", async () => {
|
||||||
|
await refreshWith(1234567890000000000n);
|
||||||
|
await confirmSend("0.1");
|
||||||
|
expect(text("confirm-balance")).toBe("1.2345 ETH");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// A token the user tracks stays on the balance list when the explorer's row is
|
||||||
|
// dropped, so a holding of it below 0.000001 reached these screens as zero, and
|
||||||
|
// the send was checked against zero.
|
||||||
|
describe("a tracked token holding below 0.000001 never renders as zero", () => {
|
||||||
|
beforeEach(() => {
|
||||||
|
state.trackedTokens = [
|
||||||
|
{ address: TOKEN, symbol: "TOK", name: "Token", decimals: 18 },
|
||||||
|
];
|
||||||
|
});
|
||||||
|
|
||||||
|
test("on the Send screen", async () => {
|
||||||
|
await refreshWith(10n ** 18n, [tokenRow(HALF_MICRO_ETH)]);
|
||||||
|
state.selectedToken = TOKEN;
|
||||||
|
send.updateSendBalance();
|
||||||
|
expect(text("send-balance")).toBe("Current balance: 0.0000005 TOK");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("on the confirmation screen, which checks the send against it", async () => {
|
||||||
|
await refreshWith(10n ** 18n, [tokenRow(HALF_MICRO_ETH)]);
|
||||||
|
await confirmSend("0.0000005", TOKEN);
|
||||||
|
expect(text("confirm-balance")).toBe("0.0000005 TOK");
|
||||||
|
expect(errors()).toBe("");
|
||||||
|
await confirmSend("0.0000006", TOKEN);
|
||||||
|
expect(errors()).toContain(
|
||||||
|
"You have 0.0000005 TOK but are trying to send 0.0000006 TOK.",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The stored balance keeps all 24 places, and the balance check reads the
|
||||||
|
// first 18 of them rather than refusing it as no balance at all.
|
||||||
|
test("with more than 18 decimals, the send is checked against 18 of them", async () => {
|
||||||
|
state.trackedTokens[0].decimals = 24;
|
||||||
|
// 1.5 plus one base unit.
|
||||||
|
const value = 15n * 10n ** 23n + 1n;
|
||||||
|
await refreshWith(10n ** 18n, [tokenRow(value, { decimals: "24" })]);
|
||||||
|
await confirmSend("1.5", TOKEN);
|
||||||
|
expect(text("confirm-balance")).toBe("1.5000 TOK");
|
||||||
|
expect(errors()).toBe("");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("with more than 18 decimals and a holding below 10^-18", async () => {
|
||||||
|
state.trackedTokens[0].decimals = 24;
|
||||||
|
// One base unit, 0.000000000000000000000001 TOK.
|
||||||
|
await refreshWith(10n ** 18n, [tokenRow(1n, { decimals: "24" })]);
|
||||||
|
state.selectedToken = TOKEN;
|
||||||
|
send.updateSendBalance();
|
||||||
|
expect(text("send-balance")).toBe(
|
||||||
|
"Current balance: 0.000000000000000000000001 TOK",
|
||||||
|
);
|
||||||
|
await confirmSend("0.000000000000000001", TOKEN);
|
||||||
|
expect(text("confirm-balance")).toBe("0.000000000000000000000001 TOK");
|
||||||
|
expect(errors()).toContain(
|
||||||
|
"You have 0.000000000000000000000001 TOK but are trying to send" +
|
||||||
|
" 0.000000000000000001 TOK.",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// A token the user does not track, with enough holders to be admitted. The
|
||||||
|
// balance fetch dropped a holding of it below 0.000001, but the token stays
|
||||||
|
// selected while its own screen is open: after sending 2 of a 2.0000003
|
||||||
|
// holding, the user is back on that screen, and Send read the missing row as
|
||||||
|
// zero.
|
||||||
|
describe("an untracked token holding below 0.000001 never renders as zero", () => {
|
||||||
|
const row = () => tokenRow(HALF_MICRO_ETH, { holders_count: "50000" });
|
||||||
|
|
||||||
|
test("on the Send screen", async () => {
|
||||||
|
await refreshWith(10n ** 18n, [row()]);
|
||||||
|
state.selectedToken = TOKEN;
|
||||||
|
send.updateSendBalance();
|
||||||
|
expect(text("send-balance")).toBe("Current balance: 0.0000005 TOK");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("on the confirmation screen, which checks the send against it", async () => {
|
||||||
|
await refreshWith(10n ** 18n, [row()]);
|
||||||
|
await confirmSend("0.0000005", TOKEN);
|
||||||
|
expect(text("confirm-balance")).toBe("0.0000005 TOK");
|
||||||
|
expect(errors()).toBe("");
|
||||||
|
await confirmSend("0.0000006", TOKEN);
|
||||||
|
expect(errors()).toContain(
|
||||||
|
"You have 0.0000005 TOK but are trying to send 0.0000006 TOK.",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The fetch keeps every holding, so the screens that showed only what it kept
|
||||||
|
// leave out a holding below 0.000001 themselves, and look as they did.
|
||||||
|
describe("a token holding below 0.000001 is still not listed", () => {
|
||||||
|
afterEach(() => {
|
||||||
|
clearPrices();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("for a token the user does not track", async () => {
|
||||||
|
prices.ETH = 3000;
|
||||||
|
await refreshWith(0n, [
|
||||||
|
tokenRow(HALF_MICRO_ETH, { holders_count: "50000" }),
|
||||||
|
]);
|
||||||
|
const addr = state.wallets[0].addresses[0];
|
||||||
|
expect(balanceLinesForAddress(addr, [], true)).not.toContain(TOKEN);
|
||||||
|
expect(balanceLinesForAddress(addr, [], false)).not.toContain(TOKEN);
|
||||||
|
send.renderSendTokenSelect(addr);
|
||||||
|
const options = global.document.getElementById("send-token").children;
|
||||||
|
expect(options.map((o) => o.value)).toEqual([]);
|
||||||
|
// Not an unpriced token in the total, and not funds on the
|
||||||
|
// remove-address warning.
|
||||||
|
expect(formatAddressTotal(getAddressValue(addr))).toBe("Total: $0.00");
|
||||||
|
expect(addressHoldsFunds(addr)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
// As a tracked token holding nothing: listed only while zero balances are
|
||||||
|
// shown.
|
||||||
|
test("for a tracked token, unless zero balances are shown", async () => {
|
||||||
|
state.trackedTokens = [
|
||||||
|
{ address: TOKEN, symbol: "TOK", name: "Token", decimals: 18 },
|
||||||
|
];
|
||||||
|
await refreshWith(0n, [tokenRow(HALF_MICRO_ETH)]);
|
||||||
|
const addr = state.wallets[0].addresses[0];
|
||||||
|
expect(
|
||||||
|
balanceLinesForAddress(addr, state.trackedTokens, false),
|
||||||
|
).not.toContain(TOKEN);
|
||||||
|
expect(
|
||||||
|
balanceLinesForAddress(addr, state.trackedTokens, true),
|
||||||
|
).toContain(`data-token="${TOKEN}"`);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("a fee below 0.000001 ETH never renders as zero", () => {
|
||||||
|
test("when the estimate and the reserve are the same", async () => {
|
||||||
|
await refreshWith(10n ** 18n);
|
||||||
|
await confirmSend("0.1");
|
||||||
|
// 21000 gas at 1 wei is 0.000000000000021 ETH, shown to its first
|
||||||
|
// significant digit.
|
||||||
|
expect(text("confirm-fee-amount")).toBe("0.00000000000002 ETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("when they differ, on both lines", async () => {
|
||||||
|
mockNode.feeData = { maxFeePerGas: 2n, gasPrice: 1n };
|
||||||
|
await refreshWith(10n ** 18n);
|
||||||
|
await confirmSend("0.1");
|
||||||
|
expect(text("confirm-fee-amount")).toBe("~0.00000000000002 ETH");
|
||||||
|
expect(text("confirm-fee-reserve")).toBe(
|
||||||
|
"up to 0.00000000000004 ETH reserved",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The confirmation screen shows the reserve alone when the node quotes no
|
||||||
|
// cheaper estimate, and that reserve is the same gas limit times maximum fee
|
||||||
|
// per gas that the approval screen calls the max fee. An ETH price is set, as
|
||||||
|
// it is on mainnet, so the USD value has to match too.
|
||||||
|
describe("the same fee reads the same on the confirmation and approval screens", () => {
|
||||||
|
beforeEach(() => {
|
||||||
|
prices.ETH = 3000;
|
||||||
|
});
|
||||||
|
afterEach(() => {
|
||||||
|
clearPrices();
|
||||||
|
});
|
||||||
|
|
||||||
|
test.each([
|
||||||
|
// 21000 gas at 1 wei.
|
||||||
|
["below the floor", 1n, "0.00000000000002 ETH (< $0.01)"],
|
||||||
|
// 0.001235294117631 ETH, which is $3.71. Pricing the truncated
|
||||||
|
// 0.0012 instead would read $3.60.
|
||||||
|
["with more than four decimals", 58823529411n, "0.0012 ETH ($3.71)"],
|
||||||
|
])("%s", async (_label, feePerGas, expected) => {
|
||||||
|
mockNode.feeData = { maxFeePerGas: feePerGas, gasPrice: feePerGas };
|
||||||
|
await refreshWith(10n ** 18n);
|
||||||
|
await confirmSend("0.1");
|
||||||
|
expect(text("confirm-fee-amount")).toBe(expected);
|
||||||
|
await approveTxWithFeePerGas(feePerGas);
|
||||||
|
expect(text("approve-tx-fee")).toBe(expected);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,148 @@
|
|||||||
|
// What reaches the console when an endpoint check in Settings fails.
|
||||||
|
//
|
||||||
|
// fetch refuses a URL with a user name and password in it, or one it cannot
|
||||||
|
// parse, with an error whose message carries the whole URL: the password, and
|
||||||
|
// any API key in the path or query string. The checks behind the RPC and
|
||||||
|
// Blockscout Save buttons printed that message
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/410); they now name the
|
||||||
|
// endpoint by its origin.
|
||||||
|
//
|
||||||
|
// The real fetch runs; it throws before making any request. Debug mode is on,
|
||||||
|
// so every log level is printed.
|
||||||
|
|
||||||
|
const SECRETS = ["SECRETPASS789", "PATHKEY123", "QUERYTOKEN456"];
|
||||||
|
const RPC_WITH_PASSWORD =
|
||||||
|
"https://user:SECRETPASS789@rpc.example.invalid/v3/PATHKEY123?token=QUERYTOKEN456";
|
||||||
|
// Port 99999 is out of range, so the URL does not parse.
|
||||||
|
const RPC_UNPARSEABLE =
|
||||||
|
"https://rpc.example.invalid:99999/v3/PATHKEY123?token=QUERYTOKEN456";
|
||||||
|
const BLOCKSCOUT_WITH_PASSWORD =
|
||||||
|
"https://user:SECRETPASS789@explorer.example.invalid/PATHKEY123/api/v2";
|
||||||
|
|
||||||
|
const SAVED_RPC = "https://saved-rpc.example.invalid";
|
||||||
|
const SAVED_BLOCKSCOUT = "https://saved-explorer.example.invalid/api/v2";
|
||||||
|
|
||||||
|
let elements;
|
||||||
|
let flashes;
|
||||||
|
let printed;
|
||||||
|
let state;
|
||||||
|
|
||||||
|
// A stand-in for one DOM node: enough of an element for init() to set
|
||||||
|
// properties on it and hang listeners off it.
|
||||||
|
function fakeElement() {
|
||||||
|
return {
|
||||||
|
value: "",
|
||||||
|
checked: false,
|
||||||
|
textContent: "",
|
||||||
|
href: "",
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
classList: { add() {}, remove() {} },
|
||||||
|
listeners: {},
|
||||||
|
addEventListener(event, handler) {
|
||||||
|
this.listeners[event] = handler;
|
||||||
|
},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function element(id) {
|
||||||
|
return (elements[id] ||= fakeElement());
|
||||||
|
}
|
||||||
|
|
||||||
|
function loadSettingsView() {
|
||||||
|
elements = {};
|
||||||
|
flashes = [];
|
||||||
|
|
||||||
|
jest.resetModules();
|
||||||
|
|
||||||
|
jest.doMock("../src/popup/views/helpers", () => ({
|
||||||
|
$: element,
|
||||||
|
showView: () => {},
|
||||||
|
updateDebugBanner: () => {},
|
||||||
|
showFlash: (msg) => flashes.push(msg),
|
||||||
|
escapeHtml: (s) => s,
|
||||||
|
flashCopyFeedback: () => {},
|
||||||
|
goBack: () => {},
|
||||||
|
pushCurrentView: () => {},
|
||||||
|
onViewLeave: () => {},
|
||||||
|
VIEWS: [],
|
||||||
|
}));
|
||||||
|
|
||||||
|
state = require("../src/shared/state").state;
|
||||||
|
state.rpcUrl = SAVED_RPC;
|
||||||
|
state.blockscoutUrl = SAVED_BLOCKSCOUT;
|
||||||
|
require("../src/shared/log").setRuntimeDebug(true);
|
||||||
|
|
||||||
|
require("../src/popup/views/settings").init({});
|
||||||
|
}
|
||||||
|
|
||||||
|
async function save(fieldId, buttonId, typed) {
|
||||||
|
element(fieldId).value = typed;
|
||||||
|
await element(buttonId).listeners.click();
|
||||||
|
}
|
||||||
|
|
||||||
|
// The check failed, nothing was saved, and nothing printed carries the
|
||||||
|
// password or the key.
|
||||||
|
function expectFailedWithoutSecrets(label) {
|
||||||
|
expect(flashes).toContain("Could not reach endpoint.");
|
||||||
|
expect(state.rpcUrl).toBe(SAVED_RPC);
|
||||||
|
expect(state.blockscoutUrl).toBe(SAVED_BLOCKSCOUT);
|
||||||
|
const line = printed.find((text) => text.includes(label));
|
||||||
|
expect(line).toBeDefined();
|
||||||
|
const all = printed.join("\n");
|
||||||
|
for (const secret of SECRETS) {
|
||||||
|
expect(all).not.toContain(secret);
|
||||||
|
}
|
||||||
|
return line;
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
printed = [];
|
||||||
|
for (const method of ["log", "warn", "error"]) {
|
||||||
|
jest.spyOn(console, method).mockImplementation((...args) => {
|
||||||
|
printed.push(args.map(String).join(" "));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
globalThis.chrome = {
|
||||||
|
runtime: { sendMessage: () => {} },
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
jest.dontMock("../src/popup/views/helpers");
|
||||||
|
delete globalThis.chrome;
|
||||||
|
jest.restoreAllMocks();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("fetch puts the whole URL in the error it throws for such a URL", async () => {
|
||||||
|
for (const url of [RPC_WITH_PASSWORD, RPC_UNPARSEABLE]) {
|
||||||
|
const error = await fetch(url).catch((e) => e);
|
||||||
|
expect(error.message).toContain("PATHKEY123");
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the RPC check of a URL with a user name and password", async () => {
|
||||||
|
loadSettingsView();
|
||||||
|
await save("settings-rpc", "btn-save-rpc", RPC_WITH_PASSWORD);
|
||||||
|
const line = expectFailedWithoutSecrets("RPC validation fetch failed");
|
||||||
|
expect(line).toContain("https://rpc.example.invalid");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the RPC check of a URL that does not parse", async () => {
|
||||||
|
loadSettingsView();
|
||||||
|
await save("settings-rpc", "btn-save-rpc", RPC_UNPARSEABLE);
|
||||||
|
expectFailedWithoutSecrets("RPC validation fetch failed");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the Blockscout check of a URL with a user name and password", async () => {
|
||||||
|
loadSettingsView();
|
||||||
|
await save(
|
||||||
|
"settings-blockscout",
|
||||||
|
"btn-save-blockscout",
|
||||||
|
BLOCKSCOUT_WITH_PASSWORD,
|
||||||
|
);
|
||||||
|
const line = expectFailedWithoutSecrets("Blockscout validation failed");
|
||||||
|
expect(line).toContain("https://explorer.example.invalid");
|
||||||
|
});
|
||||||
+33
-31
@@ -270,31 +270,32 @@ describe("background refresh racing a wallet deleted on another page", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
// allowedSites/deniedSites: { [address]: [hostname, ...] }. Mutated in place
|
// allowedSites/deniedSites: { [address]: [origin, ...] }. Mutated in place
|
||||||
// from two different contexts — src/background/index.js:592-599 pushes a
|
// from two different contexts — rememberSiteChoice() in
|
||||||
// newly approved hostname onto state.allowedSites[activeAddress], and the
|
// src/background/index.js pushes a newly approved origin onto
|
||||||
// Settings "revoke" button (src/popup/views/settings.js:55-68) filters a
|
// state.allowedSites[activeAddress], and the Settings "revoke" button
|
||||||
// hostname out of state[key][addr] in place, deleting the address key
|
// (forgetOrigin() in src/popup/views/settings.js) filters an origin out of
|
||||||
// entirely once its list is empty — the exact membership-vs-whole-field
|
// state[key][addr] in place, deleting the address key entirely once its list
|
||||||
// pattern that made the whole-field `wallets` diff unsafe, on a
|
// is empty — the exact membership-vs-whole-field pattern that made the
|
||||||
// security-relevant field: a stale whole-field save here can resurrect a
|
// whole-field `wallets` diff unsafe, on a security-relevant field: a stale
|
||||||
// revoked permission or wipe a freshly granted one.
|
// whole-field save here can resurrect a revoked permission or wipe a freshly
|
||||||
|
// granted one.
|
||||||
const ADDR1 = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const ADDR1 = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
const ADDR2 = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
const ADDR2 = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
||||||
|
|
||||||
function approveSite(pageState, address, hostname) {
|
function approveSite(pageState, address, origin) {
|
||||||
if (!pageState.allowedSites[address]) {
|
if (!pageState.allowedSites[address]) {
|
||||||
pageState.allowedSites[address] = [];
|
pageState.allowedSites[address] = [];
|
||||||
}
|
}
|
||||||
if (!pageState.allowedSites[address].includes(hostname)) {
|
if (!pageState.allowedSites[address].includes(origin)) {
|
||||||
pageState.allowedSites[address].push(hostname);
|
pageState.allowedSites[address].push(origin);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function revokeSite(pageState, hostname) {
|
function revokeSite(pageState, origin) {
|
||||||
for (const addr of Object.keys(pageState.allowedSites)) {
|
for (const addr of Object.keys(pageState.allowedSites)) {
|
||||||
pageState.allowedSites[addr] = pageState.allowedSites[addr].filter(
|
pageState.allowedSites[addr] = pageState.allowedSites[addr].filter(
|
||||||
(h) => h !== hostname,
|
(o) => o !== origin,
|
||||||
);
|
);
|
||||||
if (pageState.allowedSites[addr].length === 0) {
|
if (pageState.allowedSites[addr].length === 0) {
|
||||||
delete pageState.allowedSites[addr];
|
delete pageState.allowedSites[addr];
|
||||||
@@ -308,7 +309,7 @@ describe("a dApp approval racing a stale Settings page's later save", () => {
|
|||||||
await storage.set({
|
await storage.set({
|
||||||
autistmask: {
|
autistmask: {
|
||||||
wallets: [W1],
|
wallets: [W1],
|
||||||
allowedSites: { [ADDR2]: ["other.example"] },
|
allowedSites: { [ADDR2]: ["https://other.example"] },
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -318,24 +319,24 @@ describe("a dApp approval racing a stale Settings page's later save", () => {
|
|||||||
await settings.state.loadState();
|
await settings.state.loadState();
|
||||||
|
|
||||||
// A dApp approval window, opened later, approves a new site for a
|
// A dApp approval window, opened later, approves a new site for a
|
||||||
// different address and saves — the real sequence at
|
// different address and saves — the real sequence in
|
||||||
// src/background/index.js:592-599.
|
// rememberSiteChoice(), src/background/index.js.
|
||||||
const approval = loadPage(storage);
|
const approval = loadPage(storage);
|
||||||
await approval.state.loadState();
|
await approval.state.loadState();
|
||||||
approveSite(approval.state.state, ADDR1, "dapp.example");
|
approveSite(approval.state.state, ADDR1, "https://dapp.example");
|
||||||
await approval.state.saveState();
|
await approval.state.saveState();
|
||||||
expect(
|
expect(
|
||||||
(await storage.get("autistmask")).autistmask.allowedSites[ADDR1],
|
(await storage.get("autistmask")).autistmask.allowedSites[ADDR1],
|
||||||
).toEqual(["dapp.example"]);
|
).toEqual(["https://dapp.example"]);
|
||||||
|
|
||||||
// Settings revokes its own, unrelated site — the real sequence at
|
// Settings revokes its own, unrelated site — the real sequence in
|
||||||
// src/popup/views/settings.js:55-68 — and saves from state loaded
|
// forgetOrigin(), src/popup/views/settings.js — and saves from state
|
||||||
// before the dApp approval ever happened.
|
// loaded before the dApp approval ever happened.
|
||||||
revokeSite(settings.state.state, "other.example");
|
revokeSite(settings.state.state, "https://other.example");
|
||||||
await settings.state.saveState();
|
await settings.state.saveState();
|
||||||
|
|
||||||
const persisted = (await storage.get("autistmask")).autistmask;
|
const persisted = (await storage.get("autistmask")).autistmask;
|
||||||
expect(persisted.allowedSites[ADDR1]).toEqual(["dapp.example"]);
|
expect(persisted.allowedSites[ADDR1]).toEqual(["https://dapp.example"]);
|
||||||
expect(persisted.allowedSites[ADDR2]).toBeUndefined();
|
expect(persisted.allowedSites[ADDR2]).toBeUndefined();
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
@@ -346,7 +347,7 @@ describe("a revoked site permission against a stale page's later save", () => {
|
|||||||
await storage.set({
|
await storage.set({
|
||||||
autistmask: {
|
autistmask: {
|
||||||
wallets: [W1],
|
wallets: [W1],
|
||||||
allowedSites: { [ADDR1]: ["evil.example"] },
|
allowedSites: { [ADDR1]: ["https://evil.example"] },
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -354,23 +355,24 @@ describe("a revoked site permission against a stale page's later save", () => {
|
|||||||
const stale = loadPage(storage);
|
const stale = loadPage(storage);
|
||||||
await stale.state.loadState();
|
await stale.state.loadState();
|
||||||
|
|
||||||
// Settings revokes it — src/popup/views/settings.js:55-68 — from a
|
// Settings revokes it — forgetOrigin(), src/popup/views/settings.js —
|
||||||
// second page.
|
// from a second page.
|
||||||
const settings = loadPage(storage);
|
const settings = loadPage(storage);
|
||||||
await settings.state.loadState();
|
await settings.state.loadState();
|
||||||
revokeSite(settings.state.state, "evil.example");
|
revokeSite(settings.state.state, "https://evil.example");
|
||||||
await settings.state.saveState();
|
await settings.state.saveState();
|
||||||
expect(
|
expect(
|
||||||
(await storage.get("autistmask")).autistmask.allowedSites[ADDR1],
|
(await storage.get("autistmask")).autistmask.allowedSites[ADDR1],
|
||||||
).toBeUndefined();
|
).toBeUndefined();
|
||||||
|
|
||||||
// The stale page, unaware of the revoke, approves an unrelated site
|
// The stale page, unaware of the revoke, approves an unrelated site
|
||||||
// for a different address and saves — src/background/index.js:592-599.
|
// for a different address and saves — rememberSiteChoice(),
|
||||||
approveSite(stale.state.state, ADDR2, "good.example");
|
// src/background/index.js.
|
||||||
|
approveSite(stale.state.state, ADDR2, "https://good.example");
|
||||||
await stale.state.saveState();
|
await stale.state.saveState();
|
||||||
|
|
||||||
const persisted = (await storage.get("autistmask")).autistmask;
|
const persisted = (await storage.get("autistmask")).autistmask;
|
||||||
expect(persisted.allowedSites[ADDR2]).toEqual(["good.example"]);
|
expect(persisted.allowedSites[ADDR2]).toEqual(["https://good.example"]);
|
||||||
expect(persisted.allowedSites[ADDR1]).toBeUndefined();
|
expect(persisted.allowedSites[ADDR1]).toBeUndefined();
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -167,7 +167,9 @@ describe("an unversioned profile that is perfectly valid", () => {
|
|||||||
expect(stored.wallets[0].encryptedSecret).toBe("encrypted-secret-1");
|
expect(stored.wallets[0].encryptedSecret).toBe("encrypted-secret-1");
|
||||||
expect(stored.wallets[0].addresses[0].address).toBe(ADDRESS);
|
expect(stored.wallets[0].addresses[0].address).toBe(ADDRESS);
|
||||||
expect(stored.activeAddress).toBe(ADDRESS);
|
expect(stored.activeAddress).toBe(ADDRESS);
|
||||||
expect(stored.allowedSites).toEqual({ [ADDRESS]: ["dapp.example"] });
|
expect(stored.allowedSites).toEqual({
|
||||||
|
[ADDRESS]: ["https://dapp.example"],
|
||||||
|
});
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -20,6 +20,26 @@ const path = require("path");
|
|||||||
|
|
||||||
const { makeStorageStub } = require("./storageStub");
|
const { makeStorageStub } = require("./storageStub");
|
||||||
|
|
||||||
|
// The four libraries the popup loads from node_modules, loaded once per test
|
||||||
|
// file and handed to every boot. jest.resetModules() in bootPopup() empties the
|
||||||
|
// module cache but keeps what jest.doMock() registered, so these registrations
|
||||||
|
// hold for every boot in the file and the libraries are not loaded again. None
|
||||||
|
// of them holds popup state; everything under src/ is still loaded fresh on
|
||||||
|
// each boot.
|
||||||
|
//
|
||||||
|
// A test's own mock of one of them: a jest.doMock() made inside the test
|
||||||
|
// replaces the registration here, as it would for any module. A top-of-file
|
||||||
|
// jest.mock() is what the require() below gets, so it is kept, but its factory
|
||||||
|
// runs once per file and every boot shares the same mock object.
|
||||||
|
const ethers = require("ethers");
|
||||||
|
const sodium = require("libsodium-wrappers-sumo");
|
||||||
|
const QRCode = require("qrcode");
|
||||||
|
const makeBlockie = require("ethereum-blockies-base64");
|
||||||
|
jest.doMock("ethers", () => ethers);
|
||||||
|
jest.doMock("libsodium-wrappers-sumo", () => sodium);
|
||||||
|
jest.doMock("qrcode", () => QRCode);
|
||||||
|
jest.doMock("ethereum-blockies-base64", () => makeBlockie);
|
||||||
|
|
||||||
const POPUP_HTML = fs.readFileSync(
|
const POPUP_HTML = fs.readFileSync(
|
||||||
path.join(__dirname, "..", "..", "src", "popup", "index.html"),
|
path.join(__dirname, "..", "..", "src", "popup", "index.html"),
|
||||||
"utf8",
|
"utf8",
|
||||||
@@ -51,7 +71,7 @@ function unversionedValidProfile(extra) {
|
|||||||
networkId: "mainnet",
|
networkId: "mainnet",
|
||||||
rpcUrl: "https://ethereum-rpc.publicnode.com",
|
rpcUrl: "https://ethereum-rpc.publicnode.com",
|
||||||
blockscoutUrl: "https://eth.blockscout.com/api/v2",
|
blockscoutUrl: "https://eth.blockscout.com/api/v2",
|
||||||
allowedSites: { [ADDRESS]: ["dapp.example"] },
|
allowedSites: { [ADDRESS]: ["https://dapp.example"] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
trackedTokens: [],
|
trackedTokens: [],
|
||||||
theme: "system",
|
theme: "system",
|
||||||
|
|||||||
@@ -44,6 +44,7 @@ jest.mock("../src/shared/log", () => ({
|
|||||||
errorf: () => {},
|
errorf: () => {},
|
||||||
},
|
},
|
||||||
debugFetch: jest.fn(),
|
debugFetch: jest.fn(),
|
||||||
|
urlOrigin: () => "",
|
||||||
setRuntimeDebug: () => {},
|
setRuntimeDebug: () => {},
|
||||||
isDebug: () => false,
|
isDebug: () => false,
|
||||||
}));
|
}));
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
// contract at signing time, with nothing comparing the two, so a token whose
|
// contract at signing time, with nothing comparing the two, so a token whose
|
||||||
// on-chain scale differed signed an amount that was never displayed.
|
// on-chain scale differed signed an amount that was never displayed.
|
||||||
|
|
||||||
const { parseUnits } = require("ethers");
|
const { formatUnits, parseUnits } = require("ethers");
|
||||||
const {
|
const {
|
||||||
displayedDecimals,
|
displayedDecimals,
|
||||||
transferAmountUnits,
|
transferAmountUnits,
|
||||||
@@ -25,7 +25,17 @@ describe("displayedDecimals", () => {
|
|||||||
expect(displayedDecimals(MAX_DECIMALS)).toBe(MAX_DECIMALS);
|
expect(displayedDecimals(MAX_DECIMALS)).toBe(MAX_DECIMALS);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("refuses anything that is not a uint8", () => {
|
// decimals() is a uint8, but formatUnits() and parseUnits() stop at 80
|
||||||
|
// places, so a larger scale cannot be shown or encoded
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/350).
|
||||||
|
test("accepts exactly the scales the formatter accepts", () => {
|
||||||
|
expect(() => formatUnits(1n, MAX_DECIMALS)).not.toThrow();
|
||||||
|
expect(() => parseUnits("1", MAX_DECIMALS)).not.toThrow();
|
||||||
|
expect(() => formatUnits(1n, MAX_DECIMALS + 1)).toThrow();
|
||||||
|
expect(() => parseUnits("1", MAX_DECIMALS + 1)).toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("refuses anything that is not a uint8 the formatter accepts", () => {
|
||||||
for (const bad of [
|
for (const bad of [
|
||||||
null,
|
null,
|
||||||
undefined,
|
undefined,
|
||||||
|
|||||||
@@ -471,7 +471,7 @@ async function openSignScreen(data) {
|
|||||||
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
if (msg.type !== "AUTISTMASK_GET_APPROVAL") return reply(null);
|
||||||
reply({
|
reply({
|
||||||
type: "sign",
|
type: "sign",
|
||||||
hostname: "dapp.example",
|
origin: "https://dapp.example",
|
||||||
isPhishingDomain: false,
|
isPhishingDomain: false,
|
||||||
approvedFrom: OWNER,
|
approvedFrom: OWNER,
|
||||||
signParams: request(data),
|
signParams: request(data),
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ const ROUTER_ADDR = "0x66a9893cc07d91d95644aedd05d03f95e1dba8af";
|
|||||||
const USDT_ADDR = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
const USDT_ADDR = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
||||||
const WETH_ADDR = "0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2";
|
const WETH_ADDR = "0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2";
|
||||||
const USDC_ADDR = "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48";
|
const USDC_ADDR = "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48";
|
||||||
|
const DAI_ADDR = "0x6B175474E89094C44Da98b954EedeAC495271d0F";
|
||||||
|
const SEPOLIA_WETH_ADDR = "0xfFf9976782d46CC05630D1f6eBAb18b2324d6B14";
|
||||||
const USER_ADDR = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
const USER_ADDR = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
// AutistMask's first-ever swap, 2026-02-27.
|
// AutistMask's first-ever swap, 2026-02-27.
|
||||||
@@ -75,6 +77,14 @@ function encodeV2SwapExactIn(recipient, amountIn, amountOutMin, pathAddrs) {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Helper: encode a V2_SWAP_EXACT_OUT input (command 0x09)
|
||||||
|
function encodeV2SwapExactOut(recipient, amountOut, amountInMax, pathAddrs) {
|
||||||
|
return coder.encode(
|
||||||
|
["address", "uint256", "uint256", "address[]", "bool"],
|
||||||
|
[recipient, amountOut, amountInMax, pathAddrs, true],
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Helper: encode a V3_SWAP_EXACT_IN input (command 0x00)
|
// Helper: encode a V3_SWAP_EXACT_IN input (command 0x00)
|
||||||
function encodeV3SwapExactIn(recipient, amountIn, amountOutMin, pathTokens) {
|
function encodeV3SwapExactIn(recipient, amountIn, amountOutMin, pathTokens) {
|
||||||
// V3 path: token(20) + fee(3) + token(20) ...
|
// V3 path: token(20) + fee(3) + token(20) ...
|
||||||
@@ -223,6 +233,233 @@ describe("uniswap decoder", () => {
|
|||||||
expect(minOut.value).toContain("WETH");
|
expect(minOut.value).toContain("WETH");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Buy exactly 0.5 WETH for at most 1,500 USDC, paid by the user, sent to
|
||||||
|
// the caller (the router's MSG_SENDER recipient, address(1)).
|
||||||
|
test("decodes V2_SWAP_EXACT_OUT, stating the input amount as a maximum", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
"0x09", // V2_SWAP_EXACT_OUT
|
||||||
|
[
|
||||||
|
encodeV2SwapExactOut(
|
||||||
|
"0x0000000000000000000000000000000000000001",
|
||||||
|
500000000000000000n, // amountOut: 0.5 WETH
|
||||||
|
1500000000n, // amountInMax: 1,500 USDC (6 decimals)
|
||||||
|
[USDC_ADDR, WETH_ADDR],
|
||||||
|
),
|
||||||
|
],
|
||||||
|
1767225600n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(result.name).toBe("Swap USDC → WETH");
|
||||||
|
expect(detail(result, "Token In").address).toBe(USDC_ADDR);
|
||||||
|
expect(detail(result, "Token Out").address).toBe(WETH_ADDR);
|
||||||
|
|
||||||
|
// The wait, success and error screens show rawValue as the amount, so
|
||||||
|
// it says "Up to" as well.
|
||||||
|
const amount = detail(result, "Amount");
|
||||||
|
expect(amount.value).toBe("Up to 1500.0000 USDC");
|
||||||
|
expect(amount.rawValue).toBe("Up to 1500.0000");
|
||||||
|
|
||||||
|
expect(detail(result, "Min. received").value).toBe("0.5000 WETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
// Buy exactly 1,500 USDC for at most 0.5 ETH: WRAP_ETH of the maximum, the
|
||||||
|
// swap, then UNWRAP_WETH of 0, which returns the ETH the swap did not spend.
|
||||||
|
test("a V2 exact-out swap paid in ETH shows the token it buys and a maximum", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(["uint8", "uint8", "uint8"], [0x0b, 0x09, 0x0c]),
|
||||||
|
[
|
||||||
|
encodeWrapEth(ROUTER_ADDR, 500000000000000000n),
|
||||||
|
encodeV2SwapExactOut(
|
||||||
|
USER_ADDR,
|
||||||
|
1500000000n, // amountOut: 1,500 USDC
|
||||||
|
500000000000000000n, // amountInMax: 0.5 WETH
|
||||||
|
[WETH_ADDR, USDC_ADDR],
|
||||||
|
),
|
||||||
|
encodeWrapEth(USER_ADDR, 0n), // UNWRAP_WETH same encoding
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(result.name).toBe("Swap ETH → USDC");
|
||||||
|
|
||||||
|
const amount = detail(result, "Amount");
|
||||||
|
expect(amount.value).toBe("Up to 0.5000 ETH");
|
||||||
|
expect(amount.rawValue).toBe("Up to 0.5000");
|
||||||
|
|
||||||
|
expect(detail(result, "Token Out").address).toBe(USDC_ADDR);
|
||||||
|
expect(detail(result, "Min. received").value).toBe("1500.0000 USDC");
|
||||||
|
});
|
||||||
|
|
||||||
|
// Buy exactly 0.5 ETH for at most 1,500 USDC under a permit: the swap buys
|
||||||
|
// WETH and UNWRAP_WETH turns it into ETH.
|
||||||
|
test("a V2 exact-out swap that buys ETH shows ETH and the permit as a maximum", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(["uint8", "uint8", "uint8"], [0x0a, 0x09, 0x0c]),
|
||||||
|
[
|
||||||
|
encodePermit2(USDC_ADDR, 1500000000n, ROUTER_ADDR),
|
||||||
|
encodeV2SwapExactOut(
|
||||||
|
ROUTER_ADDR,
|
||||||
|
500000000000000000n, // amountOut: 0.5 WETH
|
||||||
|
1500000000n, // amountInMax: 1,500 USDC
|
||||||
|
[USDC_ADDR, WETH_ADDR],
|
||||||
|
),
|
||||||
|
encodeWrapEth(USER_ADDR, 500000000000000000n), // UNWRAP_WETH
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(result.name).toBe("Swap USDC → ETH");
|
||||||
|
expect(detail(result, "Amount").value).toBe("Up to 1500.0000 USDC");
|
||||||
|
expect(detail(result, "Token Out").value).toBe("ETH");
|
||||||
|
expect(detail(result, "Min. received").value).toBe("0.5000 ETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
// Paid in a token, an UNWRAP_WETH of 0 after a swap that buys something
|
||||||
|
// other than WETH leaves the output side as it is: Token Out and Min.
|
||||||
|
// received are the token bought and its figure, not ETH.
|
||||||
|
test.each([
|
||||||
|
{
|
||||||
|
paidIn: "WETH",
|
||||||
|
tokenIn: WETH_ADDR,
|
||||||
|
amountInMax: 500000000000000000n, // 0.5 WETH
|
||||||
|
tokenOut: USDC_ADDR,
|
||||||
|
amountOut: 1300000000n, // 1,300 USDC
|
||||||
|
minReceived: "1300.0000 USDC",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
paidIn: "USDC",
|
||||||
|
tokenIn: USDC_ADDR,
|
||||||
|
amountInMax: 8000000n, // 8 USDC
|
||||||
|
tokenOut: DAI_ADDR,
|
||||||
|
amountOut: 7000000000000000000n, // 7 DAI
|
||||||
|
minReceived: "7.0000 DAI",
|
||||||
|
},
|
||||||
|
])(
|
||||||
|
"a V2 exact-out swap paid in $paidIn, then UNWRAP_WETH, shows the token it buys",
|
||||||
|
({ tokenIn, amountInMax, tokenOut, amountOut, minReceived }) => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(["uint8", "uint8", "uint8"], [0x0a, 0x09, 0x0c]),
|
||||||
|
[
|
||||||
|
encodePermit2(tokenIn, amountInMax, ROUTER_ADDR),
|
||||||
|
encodeV2SwapExactOut(USER_ADDR, amountOut, amountInMax, [
|
||||||
|
tokenIn,
|
||||||
|
tokenOut,
|
||||||
|
]),
|
||||||
|
encodeWrapEth(USER_ADDR, 0n), // UNWRAP_WETH
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(detail(result, "Token Out").address).toBe(tokenOut);
|
||||||
|
expect(detail(result, "Min. received").value).toBe(minReceived);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
// An exact-in swap is held to the same rule: buying USDC, then UNWRAP_WETH,
|
||||||
|
// receives USDC.
|
||||||
|
test("an exact-in swap to a token other than WETH, then UNWRAP_WETH, shows that token", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(["uint8", "uint8"], [0x08, 0x0c]),
|
||||||
|
[
|
||||||
|
encodeV2SwapExactIn(USER_ADDR, 2000000n, 1900000n, [
|
||||||
|
USDT_ADDR,
|
||||||
|
USDC_ADDR,
|
||||||
|
]),
|
||||||
|
encodeWrapEth(USER_ADDR, 0n), // UNWRAP_WETH
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(result.name).toBe("Swap USDT → USDC");
|
||||||
|
expect(detail(result, "Token Out").address).toBe(USDC_ADDR);
|
||||||
|
expect(detail(result, "Min. received").value).toBe("1.9000 USDC");
|
||||||
|
});
|
||||||
|
|
||||||
|
// Paid in ETH, with an exact-out step, the last swap step buys WETH, so
|
||||||
|
// UNWRAP_WETH makes the output ETH.
|
||||||
|
test("an ETH-paid swap whose last step buys WETH, then UNWRAP_WETH, shows ETH", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(
|
||||||
|
["uint8", "uint8", "uint8", "uint8"],
|
||||||
|
[0x0b, 0x09, 0x08, 0x0c],
|
||||||
|
),
|
||||||
|
[
|
||||||
|
encodeWrapEth(ROUTER_ADDR, 500000000000000000n),
|
||||||
|
encodeV2SwapExactOut(
|
||||||
|
ROUTER_ADDR,
|
||||||
|
1500000000n, // amountOut: 1,500 USDC
|
||||||
|
500000000000000000n, // amountInMax: 0.5 WETH
|
||||||
|
[WETH_ADDR, USDC_ADDR],
|
||||||
|
),
|
||||||
|
encodeV2SwapExactIn(
|
||||||
|
ROUTER_ADDR,
|
||||||
|
1500000000n, // amountIn: 1,500 USDC
|
||||||
|
400000000000000000n, // amountOutMin: 0.4 WETH
|
||||||
|
[USDC_ADDR, WETH_ADDR],
|
||||||
|
),
|
||||||
|
encodeWrapEth(USER_ADDR, 0n), // UNWRAP_WETH
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(detail(result, "Token Out").value).toBe("ETH");
|
||||||
|
expect(detail(result, "Min. received").value).toBe("0.4000 ETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
// Sepolia's WETH is a different contract; UNWRAP_WETH makes it ETH too.
|
||||||
|
test("a swap to Sepolia WETH, then UNWRAP_WETH, shows ETH", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(["uint8", "uint8"], [0x08, 0x0c]),
|
||||||
|
[
|
||||||
|
encodeV2SwapExactIn(USER_ADDR, 1000000n, 500000000000000n, [
|
||||||
|
USDC_ADDR,
|
||||||
|
SEPOLIA_WETH_ADDR,
|
||||||
|
]),
|
||||||
|
encodeWrapEth(USER_ADDR, 0n), // UNWRAP_WETH
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(detail(result, "Token Out").value).toBe("ETH");
|
||||||
|
expect(detail(result, "Min. received").value).toBe("0.0005 ETH");
|
||||||
|
});
|
||||||
|
|
||||||
|
// A step that states a Min. received figure but names no output token has
|
||||||
|
// set the output side, so UNWRAP_WETH does not make it ETH: nothing says
|
||||||
|
// the figure is counted in WETH.
|
||||||
|
test("a step with a minimum but no output token, then UNWRAP_WETH, names no token", () => {
|
||||||
|
const data = buildExecute(
|
||||||
|
solidityPacked(["uint8", "uint8"], [0x10, 0x0c]),
|
||||||
|
[
|
||||||
|
encodeV4Swap(new Uint8Array([V4_SWAP_EXACT_IN]), [
|
||||||
|
encodeV4ExactIn(
|
||||||
|
USDC_ADDR,
|
||||||
|
[], // no path: this step names no output currency
|
||||||
|
1000000000n, // 1,000 USDC
|
||||||
|
400000000000000000n, // amountOutMin
|
||||||
|
),
|
||||||
|
]),
|
||||||
|
encodeWrapEth(USER_ADDR, 0n), // UNWRAP_WETH
|
||||||
|
],
|
||||||
|
9999999999n,
|
||||||
|
);
|
||||||
|
|
||||||
|
const result = uniswap.decode(data, ROUTER_ADDR);
|
||||||
|
expect(detail(result, "Token Out").value).toBe(
|
||||||
|
"Unknown (not named in the calldata)",
|
||||||
|
);
|
||||||
|
expect(detail(result, "Min. received").value).toBe(
|
||||||
|
"400000000000000000 base units (decimals unknown)",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
test("decodes V3_SWAP_EXACT_IN with known tokens", () => {
|
test("decodes V3_SWAP_EXACT_IN with known tokens", () => {
|
||||||
const data = buildExecute(
|
const data = buildExecute(
|
||||||
"0x00", // V3_SWAP_EXACT_IN
|
"0x00", // V3_SWAP_EXACT_IN
|
||||||
|
|||||||
@@ -126,6 +126,19 @@ describe("a swap of a token outside the bundled list", () => {
|
|||||||
test("a bundled token on the other side still formats", () => {
|
test("a bundled token on the other side still formats", () => {
|
||||||
expect(swapDetail(data(), "Min. received").value).toBe("0.5000 WETH");
|
expect(swapDetail(data(), "Min. received").value).toBe("0.5000 WETH");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// A token added by hand carries whatever its decimals() returned, and a
|
||||||
|
// uint8 reaches 255, but formatUnits() throws above 80. The throw left the
|
||||||
|
// whole swap undecoded rather than refused
|
||||||
|
// (https://git.eeqj.de/sneak/AutistMask/issues/350).
|
||||||
|
test("refuses to format when the token reports more than 80 decimals", () => {
|
||||||
|
state.trackedTokens = [
|
||||||
|
{ address: NOVEL, symbol: "NOVEL", decimals: 81 },
|
||||||
|
];
|
||||||
|
expect(swapDetail(data(), "Amount").value).toBe(
|
||||||
|
"1000000000 base units (decimals unknown)",
|
||||||
|
);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("the Min. received line takes the same rule", () => {
|
describe("the Min. received line takes the same rule", () => {
|
||||||
|
|||||||
@@ -382,14 +382,62 @@ describe("a scale the explorer's own rows disagree about", () => {
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// https://git.eeqj.de/sneak/AutistMask/issues/377. The Send screen read the
|
||||||
|
// stored balance and said "5.0000 NOVEL", the confirmation screen it leads
|
||||||
|
// to said "unknown (NOVEL)", and the fee message asked the user to go back
|
||||||
|
// and try again, which cannot supply a scale.
|
||||||
|
test("reads the same on the Send screen and the confirmation screen, and the fee message names the scale", async () => {
|
||||||
|
await fetchOntoBoth([novel("6", 5000000n)], [novel("18", FIVE_WETH)]);
|
||||||
|
state.selectedToken = NOVEL;
|
||||||
|
send.updateSendBalance();
|
||||||
|
expect(text("send-balance")).toBe("Current balance: unknown (NOVEL)");
|
||||||
|
|
||||||
|
const txInfo = await reviewSend(NOVEL, "1.5");
|
||||||
|
confirmTx.show(txInfo);
|
||||||
|
await settle();
|
||||||
|
expect(text("confirm-balance")).toBe("unknown (NOVEL)");
|
||||||
|
expect(text("confirm-fee-unknown-error")).toBe(
|
||||||
|
"The network fee could not be estimated, because this wallet" +
|
||||||
|
" does not know how many decimal places this token uses, so" +
|
||||||
|
" this transaction cannot be sent.",
|
||||||
|
);
|
||||||
|
expect(el("confirm-fee-unknown-error").style.visibility).toBe(
|
||||||
|
"visible",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("while a fee that fails for any other reason keeps its retry", async () => {
|
||||||
|
await fetchOntoBoth([novel("6", 5000000n)], [novel("6", 5000000n)]);
|
||||||
|
const txInfo = await reviewSend(NOVEL, "1.5");
|
||||||
|
const getFeeData = mockProvider.getFeeData;
|
||||||
|
mockProvider.getFeeData = async () => {
|
||||||
|
throw new Error("the node did not answer");
|
||||||
|
};
|
||||||
|
try {
|
||||||
|
confirmTx.show(txInfo);
|
||||||
|
await settle();
|
||||||
|
} finally {
|
||||||
|
mockProvider.getFeeData = getFeeData;
|
||||||
|
}
|
||||||
|
expect(text("confirm-fee-amount")).toBe("Unable to estimate");
|
||||||
|
expect(text("confirm-fee-unknown-error")).toBe(
|
||||||
|
"The network fee could not be estimated, so this transaction" +
|
||||||
|
" cannot be checked against your balance. Please go back and" +
|
||||||
|
" try again.",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
test("while agreeing rows leave the scale usable", async () => {
|
test("while agreeing rows leave the scale usable", async () => {
|
||||||
await fetchOntoBoth([novel("6", 5000000n)], [novel("6", 5000000n)]);
|
await fetchOntoBoth([novel("6", 5000000n)], [novel("6", 5000000n)]);
|
||||||
|
state.selectedToken = NOVEL;
|
||||||
|
send.updateSendBalance();
|
||||||
|
expect(text("send-balance")).toBe("Current balance: 5.0000 NOVEL");
|
||||||
const txInfo = await reviewSend(NOVEL, "1.5");
|
const txInfo = await reviewSend(NOVEL, "1.5");
|
||||||
expect(txInfo.tokenDecimals).toBe(6);
|
expect(txInfo.tokenDecimals).toBe(6);
|
||||||
expect(txInfo.tokenBalance).toBe("5.0");
|
expect(txInfo.tokenBalance).toBe("5.0");
|
||||||
confirmTx.show(txInfo);
|
confirmTx.show(txInfo);
|
||||||
await settle();
|
await settle();
|
||||||
expect(text("confirm-balance")).toBe("5.0 NOVEL");
|
expect(text("confirm-balance")).toBe("5.0000 NOVEL");
|
||||||
expect(errors()).toBe("");
|
expect(errors()).toBe("");
|
||||||
expect(sendDisabled()).toBe(false);
|
expect(sendDisabled()).toBe(false);
|
||||||
});
|
});
|
||||||
@@ -431,7 +479,7 @@ describe("the confirmation screen tells an unknown balance from a zero one", ()
|
|||||||
const zero = await render("0.0");
|
const zero = await render("0.0");
|
||||||
expect(unknown.balance).not.toBe(zero.balance);
|
expect(unknown.balance).not.toBe(zero.balance);
|
||||||
expect(unknown.balance).toBe("unknown (NOVEL)");
|
expect(unknown.balance).toBe("unknown (NOVEL)");
|
||||||
expect(zero.balance).toBe("0.0 NOVEL");
|
expect(zero.balance).toBe("0.0000 NOVEL");
|
||||||
});
|
});
|
||||||
|
|
||||||
// Both hit INSUFFICIENT_TOKEN — an unknown balance is treated as nothing to
|
// Both hit INSUFFICIENT_TOKEN — an unknown balance is treated as nothing to
|
||||||
@@ -443,7 +491,7 @@ describe("the confirmation screen tells an unknown balance from a zero one", ()
|
|||||||
expect(unknown.errors).not.toBe(zero.errors);
|
expect(unknown.errors).not.toBe(zero.errors);
|
||||||
expect(unknown.errors).toContain("This token's balance is unknown");
|
expect(unknown.errors).toContain("This token's balance is unknown");
|
||||||
expect(unknown.errors).not.toContain("You have");
|
expect(unknown.errors).not.toContain("You have");
|
||||||
expect(zero.errors).toContain("You have 0.0 NOVEL");
|
expect(zero.errors).toContain("You have 0.0000 NOVEL");
|
||||||
expect(zero.errors).not.toContain("balance is unknown");
|
expect(zero.errors).not.toContain("balance is unknown");
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
+20
-11
@@ -28,11 +28,14 @@ function makeState(overrides = {}) {
|
|||||||
selectedAddress: 0,
|
selectedAddress: 0,
|
||||||
activeAddress: A0,
|
activeAddress: A0,
|
||||||
allowedSites: {
|
allowedSites: {
|
||||||
[A0]: ["a.example"],
|
[A0]: ["https://a.example"],
|
||||||
[A1]: ["b.example"],
|
[A1]: ["https://b.example"],
|
||||||
[B0]: ["c.example"],
|
[B0]: ["https://c.example"],
|
||||||
|
},
|
||||||
|
deniedSites: {
|
||||||
|
[A1]: ["https://d.example"],
|
||||||
|
[C0]: ["https://e.example"],
|
||||||
},
|
},
|
||||||
deniedSites: { [A1]: ["d.example"], [C0]: ["e.example"] },
|
|
||||||
...overrides,
|
...overrides,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -41,7 +44,7 @@ describe("removeWalletFromState", () => {
|
|||||||
test("deleting the last wallet clears hasWallet", () => {
|
test("deleting the last wallet clears hasWallet", () => {
|
||||||
const state = makeState({
|
const state = makeState({
|
||||||
wallets: [wallet("A", [A0])],
|
wallets: [wallet("A", [A0])],
|
||||||
allowedSites: { [A0]: ["a.example"] },
|
allowedSites: { [A0]: ["https://a.example"] },
|
||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -109,8 +112,8 @@ describe("removeWalletFromState", () => {
|
|||||||
|
|
||||||
removeWalletFromState(state, 0);
|
removeWalletFromState(state, 0);
|
||||||
|
|
||||||
expect(state.allowedSites).toEqual({ [B0]: ["c.example"] });
|
expect(state.allowedSites).toEqual({ [B0]: ["https://c.example"] });
|
||||||
expect(state.deniedSites).toEqual({ [C0]: ["e.example"] });
|
expect(state.deniedSites).toEqual({ [C0]: ["https://e.example"] });
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -126,8 +129,14 @@ function makeAddressState(overrides = {}) {
|
|||||||
selectedWallet: 0,
|
selectedWallet: 0,
|
||||||
selectedAddress: 0,
|
selectedAddress: 0,
|
||||||
activeAddress: A0,
|
activeAddress: A0,
|
||||||
allowedSites: { [A0]: ["a.example"], [A1]: ["b.example"] },
|
allowedSites: {
|
||||||
deniedSites: { [A1]: ["d.example"], [B0]: ["e.example"] },
|
[A0]: ["https://a.example"],
|
||||||
|
[A1]: ["https://b.example"],
|
||||||
|
},
|
||||||
|
deniedSites: {
|
||||||
|
[A1]: ["https://d.example"],
|
||||||
|
[B0]: ["https://e.example"],
|
||||||
|
},
|
||||||
...overrides,
|
...overrides,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -273,8 +282,8 @@ describe("removeAddressFromState", () => {
|
|||||||
|
|
||||||
removeAddressFromState(state, 0, 1);
|
removeAddressFromState(state, 0, 1);
|
||||||
|
|
||||||
expect(state.allowedSites).toEqual({ [A0]: ["a.example"] });
|
expect(state.allowedSites).toEqual({ [A0]: ["https://a.example"] });
|
||||||
expect(state.deniedSites).toEqual({ [B0]: ["e.example"] });
|
expect(state.deniedSites).toEqual({ [B0]: ["https://e.example"] });
|
||||||
});
|
});
|
||||||
|
|
||||||
// The derivation counter is a high-water mark, never rewound: "+" derives
|
// The derivation counter is a high-water mark, never rewound: "+" derives
|
||||||
|
|||||||
Reference in New Issue
Block a user