Compare commits
14
Commits
50a332f5a0
...
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ca18beb97f | ||
|
|
bb60b399ec | ||
|
|
447d714313 | ||
|
|
29ba54d5b6 | ||
|
|
e3dd0e44da | ||
|
|
860db6034c | ||
|
|
cd8e45ae0c | ||
|
|
eeb10c20ef | ||
|
|
0aaa94471f | ||
|
|
763b50b0e5 | ||
|
|
4dafd88fad | ||
|
|
1cfd69e72d | ||
|
|
e14f6e9eb5 | ||
|
|
e865099c5b |
@@ -1,4 +1,4 @@
|
||||
.PHONY: bootstrap setup install test test-e2e test-e2e-firefox lint fmt fmt-check check check-censored docker hooks build build-debug package vendor-blocklist clean dev
|
||||
.PHONY: bootstrap setup install test test-e2e test-e2e-firefox lint fmt fmt-check check check-censored docker hooks build build-debug package vendor-blocklist icons clean dev
|
||||
|
||||
# Standard targets are thin shims; the implementations live in script/
|
||||
# per the scripts-to-rule-them-all pattern (see the Entrypoints section
|
||||
@@ -104,6 +104,13 @@ build-debug:
|
||||
vendor-blocklist:
|
||||
@script/vendor-blocklist
|
||||
|
||||
# Redraw the toolbar icons in icons/ from script/lib/icons.js, at every size
|
||||
# manifest/chrome.json declares, leaving alone a file that already holds the
|
||||
# drawn image. Commit the result with the drawing: tests/icons.test.js fails
|
||||
# while the two disagree.
|
||||
icons:
|
||||
@node script/lib/icons.js
|
||||
|
||||
clean:
|
||||
@rm -rf dist/ release/
|
||||
|
||||
|
||||
@@ -218,7 +218,9 @@ development workflow, and the Makefile targets are thin shims that call them. We
|
||||
provide:
|
||||
|
||||
- `script/bootstrap` — install all dependencies (pinned node via nvm if needed,
|
||||
yarn via corepack, `yarn install --frozen-lockfile`)
|
||||
yarn via corepack, `yarn install --frozen-lockfile`), then fail, naming the
|
||||
package, if node cannot find a package listed in `dependencies` or
|
||||
`devDependencies` of `package.json`
|
||||
- `script/setup` — make a fresh clone ready for development: bootstrap plus the
|
||||
git pre-commit hook
|
||||
- `script/projectname` — print the project name (used for the Docker image tag)
|
||||
@@ -275,7 +277,7 @@ provide:
|
||||
step's exit status, saying on stderr that it did and why. Every step of
|
||||
`make build` runs through it; `make build-debug` runs none of them through it.
|
||||
A step that succeeds removes nothing, and a removal that cannot be completed
|
||||
is reported as loudly as one that was
|
||||
is reported as loudly as one that was.
|
||||
- `script/test-verify-build` — exercise every failure mode of
|
||||
`script/verify-build` against a fixture tree in a temp dir, asserting the exit
|
||||
status and the message of each, assert the state of `dist/` on disk after a
|
||||
@@ -315,6 +317,11 @@ The Makefile shims to those. It also carries a few targets that have no
|
||||
- `make build-debug` — the same build with `AUTISTMASK_DEBUG=1`, verified as a
|
||||
debug build, and keeping its `dist/` on failure (see
|
||||
[Debug Builds](#debug-builds))
|
||||
- `make icons` — redraw the toolbar icons in `icons/` from
|
||||
`script/lib/icons.js`, at every size `manifest/chrome.json` declares. A file
|
||||
that already holds the drawn image, the same IHDR and every pixel, is left
|
||||
untouched. Commit the files with the drawing: `make check` fails while their
|
||||
image differs from what it draws
|
||||
- `make clean` — remove `dist/` and `release/`
|
||||
- `make dev` — run the build `make build` runs, without the checks that follow
|
||||
it, then run it again after every change to a file under `src/`, `manifest/`
|
||||
@@ -332,7 +339,9 @@ There are two suites, one per browser, and they share no code. Chrome runs on
|
||||
Playwright; Firefox has its own WebDriver client, because Playwright cannot
|
||||
observe errors on a Firefox extension page at all — see
|
||||
[Firefox](#firefox-make-test-e2e-firefox) below. Both require docker, and both
|
||||
are outside `make check`.
|
||||
are outside `make check`. Neither opens the popup from the toolbar button: both
|
||||
load its page in an ordinary tab, so what the toolbar popup itself adds, its
|
||||
size and its closing when it loses focus, is covered by neither.
|
||||
|
||||
### Chrome (`make test-e2e`)
|
||||
|
||||
@@ -418,14 +427,36 @@ required to be present, so that check cannot pass by observing nothing. That
|
||||
last one is the standing floor under
|
||||
[#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
||||
|
||||
Two limits of that coverage, neither of them papered over. The RPC is stubbed
|
||||
throughout, so this is **not** a real dApp against a real network with real
|
||||
funds; that remains a human pass before 1.0.0. The site-connection prompt is
|
||||
raised through `chrome.action.openPopup()`, and headless Chromium's
|
||||
browser-action popup is not a page Playwright can see or click, so that one
|
||||
prompt is driven at the URL the extension itself puts on the action — the same
|
||||
page and the same approval id, but whether a real toolbar click shows it is not
|
||||
observable here.
|
||||
The limits of that coverage and of the rest of the Chrome suite, none of them
|
||||
papered over:
|
||||
|
||||
- The RPC is stubbed throughout, so this is **not** a real dApp against a real
|
||||
network with real funds; that remains a human pass before 1.0.0.
|
||||
- The site-connection prompt is raised through `chrome.action.openPopup()`, and
|
||||
headless Chromium's browser-action popup is not a page Playwright can see or
|
||||
click, so that one prompt is driven at the URL the extension itself puts on
|
||||
the action — the same page and the same approval id, but whether a real
|
||||
toolbar click shows it is not observable here.
|
||||
- Each site-connection request is made 1.5 seconds after the tab it will be
|
||||
driven in is opened (`APPROVAL_TAB_SETTLE_MS` in `tests/e2e/run.js`), because
|
||||
opening that tab closes the previous prompt's toolbar popup; a request made
|
||||
just after that popup closes is not covered.
|
||||
- In the tests that approve a signature or a transaction, the approval window
|
||||
runs with `chrome.runtime.sendMessage` wrapped to record what it sends, and in
|
||||
the tests that reject a site connection the prompt gets a click listener that
|
||||
records that Reject was pressed; neither changes what the window does.
|
||||
- The tap to copy test first grants clipboard permission to every page in the
|
||||
browser, which the manifest does not ask for, so whether a real popup may
|
||||
write to the clipboard on a click alone is not covered.
|
||||
- The layout tests for an over-long flash message and for the password error
|
||||
lines write the text straight into the page instead of letting the popup's
|
||||
code put it there, and the second brings each screen up by toggling its
|
||||
`hidden` class rather than navigating to it; they cover the layout, not the
|
||||
code that fills it.
|
||||
- Leaving the recovery phrase or private key screen while its decrypt runs is
|
||||
forced by clicking Reveal and the settings gear in one page task, which a
|
||||
person cannot do; the case a person can hit, the first decrypt after the popup
|
||||
opens while libsodium is still loading, is not driven.
|
||||
|
||||
Any test that drives a failure path on purpose declares the `console.error` it
|
||||
is about to provoke, via `errors.expect()`. That is not a mute: the declaration
|
||||
@@ -439,8 +470,8 @@ collecting for a fixed grace period after the last test returns
|
||||
the context. A request whose _first_ dispatch falls after that window is never
|
||||
seen at all and cannot fail the run. In practice a request a test fires without
|
||||
awaiting reaches the route handler about 10ms later, and anything on a repeating
|
||||
timer gets observed on an earlier tick during the ~20s suite — but a one-shot
|
||||
call deliberately deferred past the window will escape.
|
||||
timer gets observed on an earlier tick during the suite — but a one-shot call
|
||||
deliberately deferred past the window will escape.
|
||||
|
||||
That interception covers the MV3 background service worker as well as the popup
|
||||
page, which it does not by default — `script/test-e2e` sets
|
||||
@@ -572,25 +603,18 @@ without an `await`. Demonstrated, not assumed: a `throw` placed past the first
|
||||
and on Chrome (`pageerror`), with the rest of the run unaffected because the
|
||||
approval view had already rendered.
|
||||
|
||||
One error is tolerated rather than fatal, listed in `ALLOWED_ERRORS` in
|
||||
`tests/e2e/firefox/run.js` with the issue that will delete it, and printed on
|
||||
every occurrence so the concession stays visible in the run output. It is
|
||||
Firefox reporting the site-approval popup's unawaited `sendMessage` settling
|
||||
after `window.close()` unloaded the context — the same teardown ordering as
|
||||
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275), and unsuppressable from
|
||||
the calling code, because `BaseContext.wrapPromise` reports it whether or not a
|
||||
handler is attached. Errors are read from the privileged `nsIConsoleService` in
|
||||
Marionette's chrome context and filtered to non-warning entries whose
|
||||
`sourceName` is the extension origin. That mechanism is not a stylistic choice.
|
||||
WebDriver BiDi's `log.entryAdded` delivers **nothing** for extension pages: on a
|
||||
plain `http://` page it reports uncaught errors with stack traces, and on the
|
||||
`moz-extension://` popup it reports zero events, because Firefox's remote agent
|
||||
excludes extension browsing contexts from BiDi observation. Any harness built on
|
||||
Playwright-BiDi or Puppeteer-BiDi would therefore see nothing and report
|
||||
success, which is exactly the vacuous check this repo has already shipped twice.
|
||||
Do not migrate this suite to BiDi.
|
||||
Errors are read from the privileged `nsIConsoleService` in Marionette's chrome
|
||||
context and filtered to non-warning entries whose `sourceName` is the extension
|
||||
origin. That mechanism is not a stylistic choice. WebDriver BiDi's
|
||||
`log.entryAdded` delivers **nothing** for extension pages: on a plain `http://`
|
||||
page it reports uncaught errors with stack traces, and on the `moz-extension://`
|
||||
popup it reports zero events, because Firefox's remote agent excludes extension
|
||||
browsing contexts from BiDi observation. Any harness built on Playwright-BiDi or
|
||||
Puppeteer-BiDi would therefore see nothing and report success, which is exactly
|
||||
the vacuous check this repo has already shipped twice. Do not migrate this suite
|
||||
to BiDi.
|
||||
|
||||
Two limits are worth knowing, both real differences from the Chrome suite:
|
||||
Three limits are worth knowing, all real differences from the Chrome suite:
|
||||
|
||||
- **Error capture is poll-based, not event-streamed.** The console is drained at
|
||||
each step boundary, so an error is attributed to the step it was drained
|
||||
@@ -607,24 +631,30 @@ Two limits are worth knowing, both real differences from the Chrome suite:
|
||||
and silently evicts the oldest, so more than 250 console messages between two
|
||||
drains destroys the excess unread. 400 throws inside one step are reported as
|
||||
exactly the newest 250, three runs running. That buffer is shared with
|
||||
Firefox's own console noise; a clean run peaks at 4 of 250 at the install
|
||||
drain and 0 at every later drain, so the three steps here have wide headroom,
|
||||
but a step that logs heavily could evict unread errors. What poll-based costs
|
||||
is location, not coverage: an error cannot be placed within a step the way the
|
||||
Chrome suite's `pageerror` events place it.
|
||||
Firefox's own console noise; a clean run, measured when the suite had three
|
||||
steps (popup load, wallet creation and Add Token), peaked at 4 of 250 at the
|
||||
install drain and 0 at every later drain, but a step that logs heavily could
|
||||
evict unread errors. What poll-based costs is location, not coverage: an error
|
||||
cannot be placed within a step the way the Chrome suite's `pageerror` events
|
||||
place it.
|
||||
- **Almost nothing is stubbed, which inverts the coverage of network-dependent
|
||||
code.** The container still runs with `--network none`, so the run is offline
|
||||
and no request can escape. The one thing it can reach is the loopback fixture
|
||||
in `tests/e2e/firefox/dapp.js`, which serves the dApp page and a JSON-RPC node
|
||||
and which the extension's `rpcUrl` is pointed at for the dApp steps; a
|
||||
JSON-RPC method that fixture does not model fails the run rather than
|
||||
answering `null`. Everything else — Blockscout, the price feed, the phishing
|
||||
blocklist — has no fixture and simply fails, and the extension swallows its
|
||||
own fetch failures, so only the _failure_ branches of that code are ever
|
||||
executed. A `ReferenceError` in the success path of `renderTransactions`, or
|
||||
of price rendering, passes this suite green. The offline run is also weaker
|
||||
than the Chrome suite's interception for those calls: it proves nothing got
|
||||
out, but it cannot report which requests were attempted.
|
||||
answering `null`. Everything else, Blockscout and the price feed among it, has
|
||||
no fixture and simply fails, and the extension swallows its own fetch
|
||||
failures, so only the _failure_ branches of that code are ever executed. A
|
||||
`ReferenceError` in the success path of `renderTransactions`, or of price
|
||||
rendering, passes this suite green. The offline run is also weaker than the
|
||||
Chrome suite's interception for those calls: it proves nothing got out, but it
|
||||
cannot report which requests were attempted.
|
||||
- **The site-connection prompt always opens in a window of its own.** The
|
||||
profile turns off `extensions.openPopupWithoutUserGesture.enabled`, so
|
||||
`src/background/index.js` falls back from the toolbar popup, which WebDriver
|
||||
cannot see, to `windows.create()`; the toolbar popup path is not covered on
|
||||
Firefox.
|
||||
|
||||
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
||||
`make test`. `REPO_POLICIES.md` caps `make test` at 60 seconds and a browser
|
||||
@@ -1233,14 +1263,21 @@ path rather than on the home screen. Read the claim narrowly, as that file
|
||||
states it: what those boots prove is no structural dereference on the code paths
|
||||
a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes.
|
||||
Not driven: any pairing of values the four slots do not produce, a view only
|
||||
forward navigation opens, anything behind a click, and everything a healthy
|
||||
profile reaches. Within that boundary the verdict is unconditional — if one of
|
||||
those boots leaves the popup unhealthy or off the view it stored, `make check`
|
||||
fails, including when it takes two corrupted fields at once, because the verdict
|
||||
is the combined boot and the per-field re-boot that names a culprit can only
|
||||
decorate the message. So does a field that gains a floor while its row still
|
||||
claims it has none, and so does a field added to `PERSISTED_FIELDS` with no row
|
||||
at all. The per-field justification that used to live in the header of
|
||||
forward navigation opens, anything behind a click or a timer, and, of what a
|
||||
healthy profile reaches, anything beyond its boot onto each view the popup can
|
||||
reopen onto. The fields the router does not read share a slot on each boot, so
|
||||
one of them truthy while another is falsy is reached only where the falsy slot
|
||||
pairs a field that cannot be falsy with one that is. Within that boundary the
|
||||
verdict is unconditional — if one of those boots leaves the popup unhealthy,
|
||||
`make check` fails, including when it takes two corrupted fields at once,
|
||||
because the verdict is the combined boot and the per-field re-boot that names a
|
||||
culprit can only decorate the message. The combined boot must also land on the
|
||||
view it stored, and each value driven only onto the restore path must land on
|
||||
its view, or fall back to Home, as its row declares; a field the router reads
|
||||
can legitimately change which view renders, so its own sweep is held to health
|
||||
alone. `make check` also fails on a field that gains a floor while its row still
|
||||
claims it has none, and on a field added to `PERSISTED_FIELDS` with no row at
|
||||
all. The per-field justification that used to live in the header of
|
||||
`src/shared/stateSchema.js` shipped a false claim in three consecutive changes,
|
||||
each caught only by a reviewer re-deriving thirty fields by hand.
|
||||
|
||||
@@ -1281,11 +1318,14 @@ behind a "···" menu.
|
||||
|
||||
Navigation uses a stack model (like iOS): each forward action pushes the current
|
||||
screen onto `state.viewStack`, and "Back" pops it (`pushCurrentView()` and
|
||||
`goBack()` in `src/popup/views/helpers.js`). The root screen is either Welcome
|
||||
(no wallets) or Home (has wallets). Each screen below gives its view id in
|
||||
parentheses; the registry of view ids is the `VIEWS` array in
|
||||
`src/popup/views/helpers.js`, and the markup for a screen is the element with id
|
||||
`view-` plus that view id in `src/popup/index.html`.
|
||||
`goBack()` in `src/popup/views/helpers.js`). "Back" skips an entry for the
|
||||
screen already showing: ShowRecoveryPhrase and the two delete screens take
|
||||
themselves off the stack when left, so the Settings gear on one of them leaves
|
||||
Settings under Settings, and "Back" from there goes to the screen before
|
||||
Settings. The root screen is either Welcome (no wallets) or Home (has wallets).
|
||||
Each screen below gives its view id in parentheses; the registry of view ids is
|
||||
the `VIEWS` array in `src/popup/views/helpers.js`, and the markup for a screen
|
||||
is the element with id `view-` plus that view id in `src/popup/index.html`.
|
||||
|
||||
Three elements sit outside the screens and are present on all of them: the title
|
||||
bar ("AutistMask by @sneak" plus the Settings gear), the flash message line
|
||||
@@ -1411,14 +1451,17 @@ view would leave a wallet one click from deletion.
|
||||
without it, the lost-password route on DeleteWallet is the first they
|
||||
would hear of it. The hint line reserves its height, so switching tabs
|
||||
cannot move the password fields under the pointer.
|
||||
- "Import" button
|
||||
- "Import" button, with the error line beside it so that it adds no height
|
||||
to a screen whose button already starts near the bottom of the popup
|
||||
- **Transitions**:
|
||||
- "Import" with a valid entry and a matching password of at least 12
|
||||
characters → creates the wallet, clears the navigation stack, and →
|
||||
**Home**. The phrase and xprv modes then scan for further used addresses
|
||||
and report the count as a flash message.
|
||||
- "Import" with an invalid entry, a duplicate wallet or address, or a short
|
||||
or mismatched password → flash message, no screen change
|
||||
- "Import" with a missing, short or mismatched password → full-sentence
|
||||
error on the error line, no screen change
|
||||
- "Import" with an invalid entry or a duplicate wallet or address → flash
|
||||
message, no screen change
|
||||
- "Back" → previous screen (Welcome, Home, or Settings)
|
||||
|
||||
#### AddressDetail (`address`)
|
||||
@@ -1457,8 +1500,8 @@ view would leave a wallet one click from deletion.
|
||||
copy)
|
||||
- Warning that anyone holding the private key can transfer all funds from
|
||||
the address
|
||||
- Error line
|
||||
- Password input and "Reveal" button, shown until the key is revealed
|
||||
- Password input, error line and "Reveal" button, shown until the key is
|
||||
revealed
|
||||
- The private key on a highlighted background, tap to copy, shown only after
|
||||
the password has been accepted
|
||||
- **Transitions**:
|
||||
@@ -1468,12 +1511,23 @@ view would leave a wallet one click from deletion.
|
||||
- "Reveal" (wrong password) → full-sentence error on the error line, nothing
|
||||
revealed (no screen change)
|
||||
- "Back" → previous screen (AddressDetail)
|
||||
- Settings gear → **Settings**, whose "Back" goes to AddressDetail: leaving
|
||||
drops the address the screen was showing, so it also takes the screen off
|
||||
the Back stack
|
||||
- **Secret handling**: nothing is decrypted, no key is derived, and nothing is
|
||||
written into the page until the password is accepted; the key is never stored
|
||||
in state, and it is wiped from the page whenever the screen is left by any
|
||||
route, including the Settings gear. A decrypt still running when the screen is
|
||||
left is discarded rather than written. The screen is not restorable, so
|
||||
reopening the popup lands on Home rather than back on the key.
|
||||
- **Clipboard**: tapping the key copies it to the clipboard, and the wallet
|
||||
never clears the clipboard afterwards; leaving the screen wipes the key from
|
||||
the page only. The clipboard is the user's, not the wallet's. Clearing it
|
||||
would go against what the user expects, and by then they may have copied
|
||||
something else vital that the clear would destroy. The user knows the key is
|
||||
secret from the warning above the password input, which says that anyone with
|
||||
it can access and transfer all funds from the address, and knows it is on the
|
||||
clipboard because they copied it. From then on it is theirs to manage.
|
||||
|
||||
#### AddressToken (`address-token`)
|
||||
|
||||
@@ -1785,8 +1839,8 @@ view would leave a wallet one click from deletion.
|
||||
- Wallet name
|
||||
- Warning box stating that anyone holding these words can take everything in
|
||||
the wallet, from any device, without the password
|
||||
- Error line
|
||||
- Password input + "Reveal" button, shown until the password is accepted
|
||||
- Password input, error line and "Reveal" button, shown until the password
|
||||
is accepted
|
||||
- The recovery phrase itself, in full and click-to-copy, shown only after a
|
||||
correct password and in place of the password prompt
|
||||
- **Transitions**:
|
||||
@@ -1795,12 +1849,18 @@ view would leave a wallet one click from deletion.
|
||||
- "Reveal" (wrong password) → full-sentence error, nothing revealed (no
|
||||
screen change)
|
||||
- "Back" → previous screen (Settings)
|
||||
- Settings gear → **Settings**, whose "Back" never lands back on this
|
||||
screen: leaving drops the wallet the screen was showing, so it also takes
|
||||
the screen off the Back stack
|
||||
- **Secret handling**: nothing is decrypted or written into the page until the
|
||||
password is accepted; the phrase is never stored in state, and it is wiped
|
||||
from the page whenever the screen is left by any route, including the Settings
|
||||
gear. A decrypt still running when the screen is left is discarded rather than
|
||||
written. The screen is not restorable, so reopening the popup lands on Home
|
||||
rather than back on the phrase.
|
||||
- **Clipboard**: tapping the phrase copies it, and the wallet never clears the
|
||||
clipboard afterwards, for the reasons given under ExportPrivKey; here the
|
||||
warning box above the password input is what tells the user it is secret.
|
||||
|
||||
#### DeleteWallet (`delete-wallet-confirm`)
|
||||
|
||||
@@ -1809,8 +1869,8 @@ view would leave a wallet one click from deletion.
|
||||
- "Back" button, "Delete Wallet" heading
|
||||
- Warning naming the wallet and stating that deletion is permanent and any
|
||||
funds are unrecoverable without the recovery phrase
|
||||
- Error line
|
||||
- Password input
|
||||
- Error line
|
||||
- "Confirm Delete" button
|
||||
- An underlined "I have lost my password" control
|
||||
- **Transitions**:
|
||||
@@ -1830,6 +1890,9 @@ view would leave a wallet one click from deletion.
|
||||
try again." on the error line, nothing deleted
|
||||
- "I have lost my password" → **DeleteWalletLostPassword**
|
||||
- "Back" → previous screen (Settings)
|
||||
- Settings gear → **Settings**, whose "Back" never lands back on this
|
||||
screen: leaving drops the wallet the screen was showing, so it also takes
|
||||
the screen off the Back stack
|
||||
|
||||
#### DeleteWalletLostPassword (`delete-wallet-lost-password`)
|
||||
|
||||
@@ -1868,6 +1931,9 @@ view would leave a wallet one click from deletion.
|
||||
selection comes back with it. The two delete screens are siblings rather
|
||||
than parent and child: nothing is pushed on the way here, so both have
|
||||
Settings as their Back target.
|
||||
- Settings gear → **Settings**, whose "Back" never lands back on this
|
||||
screen: leaving drops the wallet the screen was showing, so it also takes
|
||||
the screen off the Back stack
|
||||
- **Deliberately not password-gated.** A password in front of _discarding_ a
|
||||
secret protects nobody: an attacker at the popup who wants the wallet gone can
|
||||
uninstall the extension, so the only person such a gate stops is the owner who
|
||||
@@ -2582,7 +2648,7 @@ Currently supported:
|
||||
|
||||
### Non-Goals for 1.0
|
||||
|
||||
- Multi-chain support (Ethereum mainnet only)
|
||||
- Chains other than Ethereum mainnet and the Sepolia testnet
|
||||
- Hardware wallet support
|
||||
|
||||
## TODO
|
||||
@@ -2616,7 +2682,10 @@ Currently supported:
|
||||
## Policies
|
||||
|
||||
- We don't mention "the other wallet" by name in code or documentation. We're
|
||||
our own thing.
|
||||
our own thing. Written exception: the injected provider in
|
||||
`src/content/inpage.js` sets the flag named after the other wallet to `true`.
|
||||
It is an interface-compatibility flag many dApps check, and without it the
|
||||
wallet stops working on their sites.
|
||||
- The README is the complete authoritative technical documentation. It's ok if
|
||||
it gets big.
|
||||
|
||||
|
||||
@@ -118,4 +118,7 @@ contradicts either, the originals govern.
|
||||
- [ ] "Address" not "account" or "derived key"
|
||||
- [ ] "Password" not "encryption key" or "vault passphrase"
|
||||
- [ ] Error messages are full sentences
|
||||
- [ ] No competitor mentioned by name in code or documentation
|
||||
- [ ] No competitor mentioned by name in code or documentation. Written
|
||||
exception: the injected provider in `src/content/inpage.js` sets the flag
|
||||
named after the other wallet to `true`, an interface-compatibility flag
|
||||
many dApps check (README.md, Policies)
|
||||
|
||||
@@ -23,28 +23,190 @@
|
||||
|
||||
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
||||
milestone is in flight on `next`; its `next` -> `main` PR is
|
||||
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified
|
||||
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces
|
||||
`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to
|
||||
hold exactly the regular files and symlinks that build emitted, with `DEBUG`
|
||||
compiled off.
|
||||
[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces
|
||||
`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them
|
||||
against the build's own receipt to hold exactly the regular files and symlinks
|
||||
that build emitted.
|
||||
|
||||
The backlog lives on the
|
||||
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
||||
authoritative; this file does not duplicate it. Full policy file set present.
|
||||
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
||||
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does
|
||||
static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both
|
||||
of them on every push.
|
||||
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the
|
||||
tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml`
|
||||
runs both of them on every push.
|
||||
|
||||
# Next Step
|
||||
|
||||
Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
||||
input validation) before any 1.0rc tag. Individual filed issues are parts of it,
|
||||
but the review is broader than any of them.
|
||||
Cut 1.0.0 once the
|
||||
[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty,
|
||||
then continue tagging as milestones land.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-07: Two contradictions between the documents and the code are resolved
|
||||
as ruled on [#165](https://git.eeqj.de/sneak/AutistMask/issues/165). The
|
||||
README's 1.0 non-goal now puts Ethereum mainnet and the Sepolia testnet in
|
||||
scope and other chains out of it. The injected provider's flag named after the
|
||||
other wallet stays, as an interface-compatibility flag many dApps check, and
|
||||
is written down as an exception to the rule against naming competitors in the
|
||||
README's Policies section, in `RULES.md` and in a comment beside it in
|
||||
`src/content/inpage.js`. `script/check-censored` already allows that flag only
|
||||
in that file and its built copies, so it is unchanged.
|
||||
|
||||
- 2026-10-07: Two holes in what `tests/persistedFieldContract.test.js` checks
|
||||
are closed ([#379](https://git.eeqj.de/sneak/AutistMask/issues/379)). The
|
||||
check that every swept field is driven both truthy and falsy counts only
|
||||
`hostile` and `falsy` values, which the sweep drives onto every restorable
|
||||
view, and no longer a `hostileRestore` value, which reaches only the views its
|
||||
entry names; the stale index 5 moves into `hostile` for `selectedWallet` and
|
||||
`selectedAddress`, as the one value of either still truthy after the floor.
|
||||
Each `hostileRestore` entry declares whether its boot lands on its view or
|
||||
falls back to Home, and is held to it. The limits that remain, fields that
|
||||
share a slot on one boot and anything no stored record reaches by itself, are
|
||||
restated as built in the file's header and the README, which now also say
|
||||
which boots are held to where the popup lands and that a healthy profile is
|
||||
booted onto every restorable view.
|
||||
|
||||
- 2026-10-07: Every password error in the popup is shown the same way
|
||||
([#493](https://git.eeqj.de/sneak/AutistMask/issues/493)): with `showError()`
|
||||
and `hideError()` in a fixed-height error line below the password field, as
|
||||
the send confirmation and approval screens already did. The add wallet screen
|
||||
showed a missing, short or mismatched password in the flash line, and the
|
||||
private key export, recovery phrase and delete wallet screens each had a line
|
||||
of their own above the field. On the add wallet screen the line sits beside
|
||||
the Import button, so the button stays where it was at 360x600. Each line
|
||||
clears when the screen is shown again and when the password is tried again.
|
||||
The add wallet screen's other messages, such as an invalid recovery phrase, a
|
||||
duplicate wallet and the address scan, stay in the flash line.
|
||||
`tests/passwordErrorLines.test.js` drives all four screens in the popup.
|
||||
|
||||
- 2026-10-07: Pre-1.0 security review of the extension
|
||||
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
|
||||
`99292b9` for key handling, the DEBUG mode policy, and what the background
|
||||
accepts from pages, the configured RPC endpoint and the explorer, with what
|
||||
the approval screens show from it; the site permission model and storage were
|
||||
read as well. Its summary on that issue lists ten findings, each filed as its
|
||||
own issue, and all ten are fixed on `next`; one,
|
||||
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
|
||||
Three decisions it raised are still open with the owner: the Argon2id cost for
|
||||
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
|
||||
connected site switching the network with no prompt
|
||||
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
|
||||
signing as a personal message
|
||||
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
|
||||
end-to-end suites were not run, the bundled phishing blocklist and token list
|
||||
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
|
||||
taken as audited, and nothing was tried against a real network with real funds
|
||||
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
|
||||
independent second check of each finding did not run; the findings rest on the
|
||||
reviewer's own reading of the code.
|
||||
|
||||
- 2026-10-07: Stale branches pruned from `origin`
|
||||
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
|
||||
classifies each branch it lists, with the evidence. The eighteen still on
|
||||
`origin` that it classifies as landed, or superseded by merged pull requests,
|
||||
were deleted. `feat/message-signing` and `fix/59-transaction-view-ui-policies`
|
||||
had been deleted on 2026-09-09; both landed and stay deleted. Four are kept
|
||||
because their work is not in `next`: `fix/consistent-error-display`,
|
||||
`fix/87-consistent-error-display` and `fix/87-consistent-error-display-v2`,
|
||||
the change for [#87](https://git.eeqj.de/sneak/AutistMask/issues/87) that
|
||||
never landed, as reference for
|
||||
[#493](https://git.eeqj.de/sneak/AutistMask/issues/493); and
|
||||
`chore/token-list-enrichment`, deleted on 2026-09-09 and re-created at
|
||||
`f7a2437`, whose `scripts/` tooling waits on
|
||||
[#495](https://git.eeqj.de/sneak/AutistMask/issues/495).
|
||||
|
||||
- 2026-10-07: The README says that the wallet never clears the clipboard after
|
||||
the private key or the recovery phrase is copied, and why
|
||||
([#492](https://git.eeqj.de/sneak/AutistMask/issues/492)): the clipboard is
|
||||
the user's, clearing it would go against what they expect, and it could
|
||||
destroy something else they copied since. It is under ExportPrivKey, with a
|
||||
line under ShowRecoveryPhrase, and names the warning each password screen
|
||||
actually shows, which says nothing about the clipboard.
|
||||
|
||||
- 2026-10-07: The Firefox end-to-end suite no longer tolerates any uncaught
|
||||
extension error ([#487](https://git.eeqj.de/sneak/AutistMask/issues/487)). Its
|
||||
one entry, Firefox reporting a popup promise that settled after the page
|
||||
unloaded, had lost its cause with
|
||||
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275); the entry and the
|
||||
code that printed tolerated errors are gone from `tests/e2e/firefox/run.js`,
|
||||
and so is the README paragraph that described it.
|
||||
|
||||
- 2026-10-07: The toolbar icons in `icons/` can be redrawn in the tree
|
||||
([#378](https://git.eeqj.de/sneak/AutistMask/issues/378)): `make icons` runs
|
||||
`script/lib/icons.js`, which draws the mark and writes each PNG with node's
|
||||
own `zlib`, no new dependency, leaving alone a file that already holds the
|
||||
drawn image. `tests/icons.test.js` requires each committed file to hold
|
||||
exactly that image, the same IHDR and every pixel. The compressed bytes are
|
||||
not compared, because node's bundled zlib does not compress them as the stock
|
||||
zlib that made the committed files did. `build.js` now copies each manifest
|
||||
from the same path `copyIcons()` reads its icons from.
|
||||
|
||||
- 2026-10-07: The README's end-to-end limits now match what the two browser
|
||||
suites do to the extension
|
||||
([#293](https://git.eeqj.de/sneak/AutistMask/issues/293)). The `window.close`
|
||||
override the issue named went with
|
||||
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275), so it needs no entry.
|
||||
Added: both suites load the popup in a tab rather than from the toolbar;
|
||||
Chrome waits 1.5 seconds before each site-connection request, records what
|
||||
approval windows send and click, grants clipboard permission, writes text
|
||||
straight into the page in two layout tests, and forces the leave during a
|
||||
decrypt; Firefox forces the site-connection prompt into a window. Corrected:
|
||||
Firefox's one tolerated error, whose cause that fix removed (the entry goes in
|
||||
[#487](https://git.eeqj.de/sneak/AutistMask/issues/487)), the phishing
|
||||
blocklist the extension no longer fetches, and two stale figures.
|
||||
|
||||
- 2026-10-07: Back from Settings no longer shows Settings again after the
|
||||
settings gear was pressed on the recovery phrase or a delete wallet screen
|
||||
opened from Settings, with or without a reopen in between
|
||||
([#481](https://git.eeqj.de/sneak/AutistMask/issues/481)). Those screens take
|
||||
themselves off the Back stack when left, which leaves Settings under Settings;
|
||||
`goBack()` now skips an entry for the screen already showing.
|
||||
`tests/showPhrase.test.js`, `tests/deleteWalletLostPassword.test.js` and
|
||||
`tests/backNavigation.test.js` drive each path.
|
||||
|
||||
- 2026-10-07: `script/discard-dist-on-failure` returns the failed step's own
|
||||
exit status even when it cannot write its message, to a closed stderr or to a
|
||||
pipe nobody reads any more
|
||||
([#342](https://git.eeqj.de/sneak/AutistMask/issues/342)); it used to return 2
|
||||
or 141 instead. An interrupt while a step runs now removes nothing and says
|
||||
nothing whichever shell `/bin/sh` is, even when the step catches it and exits
|
||||
with a status of its own, as `script/check-censored` does: the wrapper exits
|
||||
with 130 once the step has ended. Under bash such a step used to have `dist/`
|
||||
removed. A failed `check-censored --require-dist` still removes `dist/` like
|
||||
any other step, because a `dist/` not cleared of the name `RULES.md` bars must
|
||||
not ship. The header states both. `script/test-verify-build` runs the wrapper
|
||||
with stderr closed and with stderr a pipe nobody reads, and interrupts it
|
||||
under dash and under bash.
|
||||
|
||||
- 2026-10-06: Back from Settings no longer lands on the delete wallet or
|
||||
lost-password screen after either was left by the settings gear
|
||||
([#480](https://git.eeqj.de/sneak/AutistMask/issues/480)), the defect
|
||||
[#461](https://git.eeqj.de/sneak/AutistMask/issues/461) fixed for the two
|
||||
secret screens. Leaving drops the screen's wallet selection, so its leave
|
||||
handler now also takes it off the Back stack, as a reopened popup already
|
||||
does. `tests/deleteWalletLostPassword.test.js` drives the gear and then Back
|
||||
on both screens.
|
||||
|
||||
- 2026-10-06: `script/bootstrap` no longer reports success while node cannot
|
||||
find a package listed in `dependencies` or `devDependencies` of `package.json`
|
||||
([#263](https://git.eeqj.de/sneak/AutistMask/issues/263)). After the install
|
||||
it asks node for each one's `package.json`, and fails naming the missing
|
||||
package and the fix. yarn skips the install whenever
|
||||
`node_modules/.yarn-integrity` matches `yarn.lock`, so a package deleted from
|
||||
`node_modules` stayed deleted while bootstrap said it was complete. The
|
||||
fresh-clone failure the issue reports did not reproduce.
|
||||
|
||||
- 2026-10-06: Back from Settings no longer lands on the private key export or
|
||||
recovery phrase screen after either was left by the settings gear
|
||||
([#461](https://git.eeqj.de/sneak/AutistMask/issues/461)). Leaving drops the
|
||||
screen's selection, so its leave handler now also takes it off the Back stack,
|
||||
as a reopened popup already does. `tests/exportPrivkey.test.js` and
|
||||
`tests/showPhrase.test.js` drive the gear and then Back, and
|
||||
`leavePrivkeyScreen()` in `tests/e2e/run.js` expects the address screen after
|
||||
Settings.
|
||||
|
||||
- 2026-10-06: A token symbol or name read off a contract is no longer stored cut
|
||||
between the two halves of an emoji
|
||||
([#458](https://git.eeqj.de/sneak/AutistMask/issues/458)). `lookupTokenInfo()`
|
||||
@@ -1782,6 +1944,3 @@ but the review is broader than any of them.
|
||||
|
||||
Only work that has no issue of its own belongs here; everything else is on the
|
||||
tracker.
|
||||
|
||||
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
||||
land.
|
||||
|
||||
@@ -588,15 +588,10 @@ async function build() {
|
||||
copyIcons(distDir);
|
||||
}
|
||||
|
||||
// copy manifests
|
||||
copyEmitted(
|
||||
path.join(__dirname, "manifest", "chrome.json"),
|
||||
path.join(DIST_CHROME, "manifest.json"),
|
||||
);
|
||||
copyEmitted(
|
||||
path.join(__dirname, "manifest", "firefox.json"),
|
||||
path.join(DIST_FIREFOX, "manifest.json"),
|
||||
);
|
||||
// copy manifests, the same files copyIcons() read
|
||||
for (const [distDir, manifestPath] of MANIFEST_SOURCES) {
|
||||
copyEmitted(manifestPath, path.join(distDir, "manifest.json"));
|
||||
}
|
||||
|
||||
assertForbiddenTableCovered(forbiddenRecord);
|
||||
|
||||
|
||||
@@ -127,6 +127,40 @@ install_js_deps() {
|
||||
fi
|
||||
}
|
||||
|
||||
# run_node: run node from the repo root, through nvm when node is not on PATH;
|
||||
# the script comes on stdin
|
||||
run_node() {
|
||||
if missing node && [ -s "$HOME/.nvm/nvm.sh" ]; then
|
||||
nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && node"
|
||||
else
|
||||
node
|
||||
fi
|
||||
}
|
||||
|
||||
# yarn install exits 0 without touching node_modules once
|
||||
# node_modules/.yarn-integrity matches yarn.lock, so a package deleted from
|
||||
# node_modules stays deleted. Fail unless node finds every package listed in
|
||||
# dependencies and devDependencies of package.json, by its package.json. When a
|
||||
# package's exports does not list that file, node throws
|
||||
# ERR_PACKAGE_PATH_NOT_EXPORTED, which it can only do once it has found the
|
||||
# package, so that error counts as found.
|
||||
check_js_deps() {
|
||||
run_node <<'EOF'
|
||||
const { dependencies, devDependencies } = require("./package.json");
|
||||
for (const name of Object.keys({ ...dependencies, ...devDependencies })) {
|
||||
try {
|
||||
require.resolve(name + "/package.json");
|
||||
} catch (e) {
|
||||
if (e.code !== "ERR_PACKAGE_PATH_NOT_EXPORTED") {
|
||||
console.error(`bootstrap: node cannot find ${name} after yarn install`);
|
||||
console.error(" fix: rm -rf node_modules && make bootstrap");
|
||||
process.exit(1);
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
|
||||
@@ -136,6 +170,7 @@ main() {
|
||||
ensure_node
|
||||
ensure_yarn
|
||||
install_js_deps
|
||||
check_js_deps
|
||||
|
||||
echo "bootstrap complete"
|
||||
}
|
||||
|
||||
@@ -3,22 +3,21 @@
|
||||
# step fails, remove dist/ before returning its exit status. Our own extension
|
||||
# to scripts-to-rule-them-all, wrapped around every step of make build.
|
||||
#
|
||||
# Why: with AUTISTMASK_DEBUG=1 exported in the calling shell, make build
|
||||
# compiles a debug bundle and then fails on it in script/verify-build — but the
|
||||
# bundle is already written. It is loadable, and every wallet it creates gets
|
||||
# the publicly committed test recovery phrase from src/shared/constants.js. A
|
||||
# failed release build that leaves that behind is a smaller version of the trap
|
||||
# the verifier exists to close, and "the failure was loud" only works on an
|
||||
# operator who does not load dist/chrome/ anyway. Removing the artifact does not
|
||||
# depend on that.
|
||||
# Why: with AUTISTMASK_DEBUG=1 exported, make build compiles a debug bundle and
|
||||
# then fails on it in script/verify-build, after the bundle is written. It is
|
||||
# loadable, and every wallet it creates gets the publicly committed test
|
||||
# recovery phrase from src/shared/constants.js, so a failed build must not leave
|
||||
# it behind. The removal is never silent: it says on stderr that dist/ is gone
|
||||
# and why.
|
||||
#
|
||||
# Two things this deliberately does not do. It does not wrap make build-debug: a
|
||||
# debug build that failed is not a mistakable artifact, and its output is the
|
||||
# evidence of what went wrong. And it never removes anything on a step that
|
||||
# SUCCEEDS, including the final check-censored --require-dist pass.
|
||||
#
|
||||
# The removal is never silent: it says dist/ is gone and why, on stderr, above
|
||||
# the build's own failure.
|
||||
# A failed check-censored --require-dist removes dist/ like any other step: a
|
||||
# dist/ not cleared of the name RULES.md bars must not ship either. A step that
|
||||
# succeeds removes nothing. An interrupt (Ctrl-C) while a step runs removes
|
||||
# nothing and says nothing, even when the step catches it and exits with a
|
||||
# status of its own: the wrapper exits with 130 once the step has ended. An
|
||||
# interrupt is not a build failure, and whoever interrupted the build knows it
|
||||
# did not finish. make build-debug is not wrapped: a debug build that failed is
|
||||
# not a mistakable artifact, and its output is the evidence of what went wrong.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
@@ -66,12 +65,20 @@ main() {
|
||||
exit 1
|
||||
}
|
||||
|
||||
# An interrupt is not a build failure: once the step has ended, exit
|
||||
# without removing anything, even if the step caught the interrupt and
|
||||
# exited with a status of its own. bash as /bin/sh would otherwise carry on.
|
||||
trap 'exit 130' INT
|
||||
|
||||
_status=0
|
||||
"$@" || _status=$?
|
||||
|
||||
[ "$_status" -ne 0 ] || return 0
|
||||
|
||||
discard_dist
|
||||
# A message that cannot be written, to a closed stderr or to a pipe nobody
|
||||
# reads any more, must not replace the step's status.
|
||||
trap '' PIPE
|
||||
discard_dist || true
|
||||
exit "$_status"
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,203 @@
|
||||
// Draws the toolbar icon and writes it to every file manifest/chrome.json
|
||||
// declares under "icons". Run by `make icons`; tests/icons.test.js checks that
|
||||
// the committed files hold exactly the image this draws.
|
||||
//
|
||||
// The icon is a dark-navy rounded square carrying a teal triangle with a
|
||||
// smaller triangle cut out of it. Every coordinate below is a fraction of the
|
||||
// icon's side, so one drawing serves every size. A pixel's colour is the
|
||||
// average of an 8x8 grid of samples, one at the centre of each cell, which
|
||||
// smooths the edges.
|
||||
//
|
||||
// The PNG is written here rather than by a library: RGBA at 8 bits per
|
||||
// channel, filter type 0 (none) on every row, one IDAT chunk compressed by
|
||||
// node's zlib at level 9. The committed files were compressed by stock zlib,
|
||||
// which node's bundled zlib does not reproduce byte for byte, so the image is
|
||||
// compared rather than the file: the IHDR and every pixel.
|
||||
|
||||
"use strict";
|
||||
|
||||
const fs = require("fs");
|
||||
const path = require("path");
|
||||
const zlib = require("zlib");
|
||||
|
||||
const { icons } = require("../../manifest/chrome.json");
|
||||
|
||||
const NAVY = [0x10, 0x1a, 0x2e];
|
||||
const TEAL = [0x35, 0xe0, 0xc2];
|
||||
const CORNER_RADIUS = 0.22;
|
||||
const OUTER_TRIANGLE = [
|
||||
[0.5, 0.15],
|
||||
[0.115, 0.855],
|
||||
[0.885, 0.855],
|
||||
];
|
||||
const INNER_TRIANGLE = [
|
||||
[0.5, 0.4],
|
||||
[0.29, 0.7],
|
||||
[0.71, 0.7],
|
||||
];
|
||||
const SAMPLES_PER_SIDE = 8;
|
||||
|
||||
const PNG_SIGNATURE = Buffer.from([
|
||||
0x89, 0x50, 0x4e, 0x47, 0x0d, 0x0a, 0x1a, 0x0a,
|
||||
]);
|
||||
|
||||
// Points are in pixels from the icon's top-left corner.
|
||||
function insideRoundedSquare(x, y, size) {
|
||||
const r = CORNER_RADIUS * size;
|
||||
// How far the point is past the start of a corner's curve, on each axis.
|
||||
const dx = Math.max(r - x, 0, x - (size - r));
|
||||
const dy = Math.max(r - y, 0, y - (size - r));
|
||||
return dx * dx + dy * dy <= r * r;
|
||||
}
|
||||
|
||||
// Inside or on an edge: the point is not on opposite sides of two edges.
|
||||
function insideTriangle(x, y, [a, b, c]) {
|
||||
const side = (p, q) =>
|
||||
(q[0] - p[0]) * (y - p[1]) - (q[1] - p[1]) * (x - p[0]);
|
||||
const sides = [side(a, b), side(b, c), side(c, a)];
|
||||
return !(sides.some((s) => s < 0) && sides.some((s) => s > 0));
|
||||
}
|
||||
|
||||
// Rounds to the nearest integer and a half to the even neighbour, as the
|
||||
// committed icons were made. Math.round takes a half up, which would change
|
||||
// some pixels by one.
|
||||
function roundHalfToEven(v) {
|
||||
const down = Math.floor(v);
|
||||
if (v - down !== 0.5) {
|
||||
return Math.round(v);
|
||||
}
|
||||
return down % 2 === 0 ? down : down + 1;
|
||||
}
|
||||
|
||||
// The RGBA bytes of the pixel whose top-left corner is (px, py).
|
||||
function pixel(px, py, size, outer, inner) {
|
||||
let inSquare = 0;
|
||||
let inTeal = 0;
|
||||
for (let j = 0; j < SAMPLES_PER_SIDE; j++) {
|
||||
const y = py + (j + 0.5) / SAMPLES_PER_SIDE;
|
||||
for (let i = 0; i < SAMPLES_PER_SIDE; i++) {
|
||||
const x = px + (i + 0.5) / SAMPLES_PER_SIDE;
|
||||
if (!insideRoundedSquare(x, y, size)) {
|
||||
continue;
|
||||
}
|
||||
inSquare++;
|
||||
if (insideTriangle(x, y, outer) && !insideTriangle(x, y, inner)) {
|
||||
inTeal++;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (inSquare === 0) {
|
||||
return [0, 0, 0, 0];
|
||||
}
|
||||
const colour = NAVY.map((navy, k) =>
|
||||
roundHalfToEven(navy + ((TEAL[k] - navy) * inTeal) / inSquare),
|
||||
);
|
||||
const alpha = roundHalfToEven((255 * inSquare) / SAMPLES_PER_SIDE ** 2);
|
||||
return [...colour, alpha];
|
||||
}
|
||||
|
||||
// A PNG chunk: the data's length, the type, the data, then the CRC-32 of the
|
||||
// type and the data.
|
||||
function chunk(type, data) {
|
||||
const typeAndData = Buffer.concat([Buffer.from(type, "ascii"), data]);
|
||||
const length = Buffer.alloc(4);
|
||||
length.writeUInt32BE(data.length);
|
||||
const crc = Buffer.alloc(4);
|
||||
crc.writeUInt32BE(zlib.crc32(typeAndData));
|
||||
return Buffer.concat([length, typeAndData, crc]);
|
||||
}
|
||||
|
||||
// The complete PNG file for the icon at `size` pixels square.
|
||||
function drawIcon(size) {
|
||||
const toPixels = (corners) => corners.map(([x, y]) => [x * size, y * size]);
|
||||
const outer = toPixels(OUTER_TRIANGLE);
|
||||
const inner = toPixels(INNER_TRIANGLE);
|
||||
|
||||
const rows = [];
|
||||
for (let py = 0; py < size; py++) {
|
||||
const row = [0]; // filter type 0: the row's bytes are stored as they are
|
||||
for (let px = 0; px < size; px++) {
|
||||
row.push(...pixel(px, py, size, outer, inner));
|
||||
}
|
||||
rows.push(Buffer.from(row));
|
||||
}
|
||||
|
||||
const header = Buffer.alloc(13); // compression, filter, interlace: all 0
|
||||
header.writeUInt32BE(size, 0); // width
|
||||
header.writeUInt32BE(size, 4); // height
|
||||
header[8] = 8; // bits per channel
|
||||
header[9] = 6; // colour type: RGBA
|
||||
|
||||
return Buffer.concat([
|
||||
PNG_SIGNATURE,
|
||||
chunk("IHDR", header),
|
||||
chunk("IDAT", zlib.deflateSync(Buffer.concat(rows), { level: 9 })),
|
||||
chunk("IEND", Buffer.alloc(0)),
|
||||
]);
|
||||
}
|
||||
|
||||
// The image in a PNG: its IHDR data, and its rows after decompression, each
|
||||
// row's filter type byte first. With filter type 0 on every row, as drawIcon
|
||||
// writes, the rows are the pixels themselves; a file using another filter does
|
||||
// not match even where its pixels do. Refuses a file that is not a PNG, a chunk
|
||||
// whose CRC-32 is wrong, and any chunk but IHDR, IDAT and IEND, rather than
|
||||
// ignoring what it cannot compare.
|
||||
function decodePng(png) {
|
||||
if (!png.subarray(0, 8).equals(PNG_SIGNATURE)) {
|
||||
throw new Error("not a PNG");
|
||||
}
|
||||
let header = null;
|
||||
const idat = [];
|
||||
for (let pos = 8; pos < png.length; ) {
|
||||
const length = png.readUInt32BE(pos);
|
||||
const typeAndData = png.subarray(pos + 4, pos + 8 + length);
|
||||
const type = typeAndData.toString("ascii", 0, 4);
|
||||
if (zlib.crc32(typeAndData) !== png.readUInt32BE(pos + 8 + length)) {
|
||||
throw new Error(`the ${type} chunk fails its CRC-32`);
|
||||
}
|
||||
if (type === "IHDR") {
|
||||
header = typeAndData.subarray(4);
|
||||
} else if (type === "IDAT") {
|
||||
idat.push(typeAndData.subarray(4));
|
||||
} else if (type !== "IEND") {
|
||||
throw new Error(`unexpected ${type} chunk`);
|
||||
}
|
||||
pos += 12 + length;
|
||||
}
|
||||
if (header === null) {
|
||||
throw new Error("no IHDR chunk");
|
||||
}
|
||||
return { header, rows: zlib.inflateSync(Buffer.concat(idat)) };
|
||||
}
|
||||
|
||||
// True when `file` already holds the image in `png`. A file that is missing or
|
||||
// cannot be read as a PNG does not, and is written over.
|
||||
function holdsSameImage(file, png) {
|
||||
let existing;
|
||||
try {
|
||||
existing = decodePng(fs.readFileSync(file));
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
const drawn = decodePng(png);
|
||||
return (
|
||||
existing.header.equals(drawn.header) && existing.rows.equals(drawn.rows)
|
||||
);
|
||||
}
|
||||
|
||||
// A file already holding the drawn image is left alone, so running this does
|
||||
// not rewrite the committed icons with node's compression.
|
||||
if (require.main === module) {
|
||||
for (const [size, file] of Object.entries(icons)) {
|
||||
const target = path.join(__dirname, "..", "..", file);
|
||||
const png = drawIcon(Number(size));
|
||||
if (holdsSameImage(target, png)) {
|
||||
console.log(`icons: ${file} already holds this image`);
|
||||
continue;
|
||||
}
|
||||
fs.writeFileSync(target, png);
|
||||
console.log(`icons: wrote ${file}`);
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { drawIcon, decodePng };
|
||||
@@ -915,6 +915,76 @@ run_cases() {
|
||||
discard_case "the wrapper given no command removes nothing" \
|
||||
c_control 1 kept "no command given" ""
|
||||
|
||||
# With stderr closed the wrapper cannot write its message, and must still
|
||||
# remove dist/ and return the step's own status.
|
||||
build_fixture
|
||||
_status=0
|
||||
(cd "$FIXTURE" &&
|
||||
"$FIXTURE/script/discard-dist-on-failure" sh -c 'exit 6' 2>&-) ||
|
||||
_status=$?
|
||||
if [ "$_status" -eq 6 ] && [ ! -e "$FIXTURE/dist" ]; then
|
||||
PASSED=$((PASSED + 1))
|
||||
echo " ok: a failed step's status survives a closed stderr"
|
||||
else
|
||||
FAILED=$((FAILED + 1))
|
||||
echo " FAIL: a failed step's status survives a closed stderr"
|
||||
echo " exit status $_status, wanted 6, and dist/ must be gone"
|
||||
fi
|
||||
|
||||
# The same with stderr a pipe nobody reads any more, where the write would
|
||||
# kill the wrapper with SIGPIPE. The FIFO's only reader opens it, exits and
|
||||
# is waited for before the wrapper runs, so the pipe never has a reader.
|
||||
build_fixture
|
||||
mkfifo "$WORK/stderr-fifo"
|
||||
_status=0
|
||||
(
|
||||
: <"$WORK/stderr-fifo" &
|
||||
exec 3>"$WORK/stderr-fifo"
|
||||
wait "$!"
|
||||
cd "$FIXTURE" &&
|
||||
"$FIXTURE/script/discard-dist-on-failure" sh -c 'exit 6' 2>&3
|
||||
) || _status=$?
|
||||
if [ "$_status" -eq 6 ] && [ ! -e "$FIXTURE/dist" ]; then
|
||||
PASSED=$((PASSED + 1))
|
||||
echo " ok: a failed step's status survives a pipe nobody reads"
|
||||
else
|
||||
FAILED=$((FAILED + 1))
|
||||
echo " FAIL: a failed step's status survives a pipe nobody reads"
|
||||
echo " exit status $_status, wanted 6, and dist/ must be gone"
|
||||
fi
|
||||
|
||||
# An interrupt while a step runs removes nothing and says nothing, even
|
||||
# when the step catches it and exits with a status of its own, as
|
||||
# script/check-censored does. The step interrupts the wrapper and then
|
||||
# itself, as Ctrl-C interrupts every process of the build at once. Run
|
||||
# under dash and under bash, which /bin/sh may each be: bash carries on
|
||||
# after such a step unless the wrapper stops it.
|
||||
for _shell in dash bash; do
|
||||
_name="an interrupt under $_shell removes nothing"
|
||||
if ! command -v "$_shell" >/dev/null 2>&1; then
|
||||
SKIPPED=$((SKIPPED + 1))
|
||||
SKIPPED_NAMES="$SKIPPED_NAMES## - $_name ($_shell not found)$NEWLINE"
|
||||
echo " SKIP ($_shell not found): $_name"
|
||||
continue
|
||||
fi
|
||||
build_fixture
|
||||
_status=0
|
||||
_out="$(cd "$FIXTURE" && "$_shell" \
|
||||
"$FIXTURE/script/discard-dist-on-failure" \
|
||||
sh -c 'trap "exit 4" INT; kill -INT "$PPID" $$; exit 5' 2>&1)" ||
|
||||
_status=$?
|
||||
if [ "$_status" -eq 130 ] && [ -z "$_out" ] &&
|
||||
[ -f "$FIXTURE/dist/chrome/src/popup/index.js" ]; then
|
||||
PASSED=$((PASSED + 1))
|
||||
echo " ok: $_name"
|
||||
else
|
||||
FAILED=$((FAILED + 1))
|
||||
echo " FAIL: $_name"
|
||||
echo " exit status $_status, wanted 130; dist/ must be intact" \
|
||||
"and nothing said. Output: $_out"
|
||||
fi
|
||||
done
|
||||
|
||||
check_makefile_wiring
|
||||
}
|
||||
|
||||
|
||||
@@ -99,7 +99,10 @@
|
||||
|
||||
const provider = {
|
||||
isAutistMask: true,
|
||||
isMetaMask: true, // compatibility — many dApps check this
|
||||
// An interface-compatibility flag many dApps check. Kept as a written
|
||||
// exception to the rule that no competitor is named in code: see
|
||||
// Policies in README.md, and RULES.md.
|
||||
isMetaMask: true,
|
||||
chainId: currentChainId,
|
||||
networkVersion: currentNetworkVersion,
|
||||
selectedAddress: null,
|
||||
|
||||
+30
-20
@@ -207,12 +207,22 @@
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
/>
|
||||
</div>
|
||||
<button
|
||||
id="btn-add-wallet-confirm"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Import
|
||||
</button>
|
||||
<!-- The error line sits beside Import, not above it: at
|
||||
360x600 the button already starts near the bottom of
|
||||
the popup, and a line of its own would push it below
|
||||
the fold. The longest error fits on one line here. -->
|
||||
<div class="flex items-center gap-2">
|
||||
<button
|
||||
id="btn-add-wallet-confirm"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Import
|
||||
</button>
|
||||
<div
|
||||
id="add-wallet-password-error"
|
||||
class="text-xs min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ -->
|
||||
@@ -396,10 +406,6 @@
|
||||
Warning: anyone with this private key can access and
|
||||
transfer all funds from this address. Never share it.
|
||||
</p>
|
||||
<div
|
||||
id="export-privkey-flash"
|
||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<div id="export-privkey-password-section" class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
<input
|
||||
@@ -408,9 +414,13 @@
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
placeholder="Enter your password to continue"
|
||||
/>
|
||||
<div
|
||||
id="export-privkey-password-error"
|
||||
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<button
|
||||
id="btn-export-privkey-confirm"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Reveal
|
||||
</button>
|
||||
@@ -1116,10 +1126,6 @@
|
||||
<strong id="delete-wallet-name"></strong> is permanent. Any
|
||||
funds will be unrecoverable without your recovery phrase.
|
||||
</p>
|
||||
<div
|
||||
id="delete-wallet-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
<input
|
||||
@@ -1129,6 +1135,10 @@
|
||||
placeholder="Enter your password to confirm"
|
||||
/>
|
||||
</div>
|
||||
<div
|
||||
id="delete-wallet-password-error"
|
||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<button
|
||||
id="btn-delete-wallet-confirm"
|
||||
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
@@ -1273,10 +1283,6 @@
|
||||
this wallet, from any device, without your password. Never
|
||||
type them into a website and never show them to anyone.
|
||||
</div>
|
||||
<div
|
||||
id="show-phrase-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<div id="show-phrase-password-section" class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
<input
|
||||
@@ -1285,9 +1291,13 @@
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
placeholder="Enter your password to continue"
|
||||
/>
|
||||
<div
|
||||
id="show-phrase-password-error"
|
||||
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<button
|
||||
id="btn-show-phrase-reveal"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Reveal
|
||||
</button>
|
||||
|
||||
@@ -2,6 +2,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
goBack,
|
||||
clearViewStack,
|
||||
onViewLeave,
|
||||
@@ -98,6 +100,7 @@ function clear() {
|
||||
$("add-wallet-password").value = "";
|
||||
$("add-wallet-password-confirm").value = "";
|
||||
$("add-wallet-phrase-warning").style.visibility = "hidden";
|
||||
hideError("add-wallet-password-error");
|
||||
}
|
||||
|
||||
// Each wallet has its own password (its own encryptedSecret), so adding a
|
||||
@@ -125,15 +128,18 @@ function validatePassword() {
|
||||
const pw = $("add-wallet-password").value;
|
||||
const pw2 = $("add-wallet-password-confirm").value;
|
||||
if (!pw) {
|
||||
showFlash("Please choose a password.");
|
||||
showError("add-wallet-password-error", "Please choose a password.");
|
||||
return null;
|
||||
}
|
||||
if (pw.length < 12) {
|
||||
showFlash("Password must be at least 12 characters.");
|
||||
showError(
|
||||
"add-wallet-password-error",
|
||||
"Password must be at least 12 characters.",
|
||||
);
|
||||
return null;
|
||||
}
|
||||
if (pw !== pw2) {
|
||||
showFlash("Passwords do not match.");
|
||||
showError("add-wallet-password-error", "Passwords do not match.");
|
||||
return null;
|
||||
}
|
||||
return pw;
|
||||
@@ -342,8 +348,10 @@ function init(ctx) {
|
||||
$("add-wallet-phrase-warning").style.visibility = "visible";
|
||||
});
|
||||
|
||||
// Import / confirm
|
||||
// Import / confirm. Each press starts with no password error on screen:
|
||||
// validatePassword() puts it back if the password is still wrong.
|
||||
$("btn-add-wallet-confirm").addEventListener("click", async () => {
|
||||
hideError("add-wallet-password-error");
|
||||
if (currentMode === "mnemonic") {
|
||||
await importMnemonic(ctx);
|
||||
} else if (currentMode === "privkey") {
|
||||
|
||||
@@ -2,6 +2,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
goBack,
|
||||
clearViewStack,
|
||||
onViewLeave,
|
||||
@@ -49,14 +51,13 @@ function confirmKey(name) {
|
||||
}
|
||||
|
||||
// Drop the password from the DOM and the wallet selection from the
|
||||
// closure. Registered as the view-leave handler as well as run on entry,
|
||||
// so the typed password does not sit in the hidden view after the user
|
||||
// navigates away by any route, including the Settings gear.
|
||||
// closure. Run by the view-leave handler as well as on entry, so the typed
|
||||
// password does not sit in the hidden view after the user navigates away
|
||||
// by any route, including the Settings gear.
|
||||
function clear() {
|
||||
deleteWalletIndex = null;
|
||||
$("delete-wallet-password").value = "";
|
||||
$("delete-wallet-flash").textContent = "";
|
||||
$("delete-wallet-flash").style.visibility = "hidden";
|
||||
hideError("delete-wallet-password-error");
|
||||
}
|
||||
|
||||
// The lost-password screen holds no secret — a wallet name is not one —
|
||||
@@ -147,8 +148,25 @@ async function finishDelete(walletIdx) {
|
||||
function init(_ctx) {
|
||||
ctx = _ctx;
|
||||
|
||||
onViewLeave("delete-wallet-confirm", clear);
|
||||
onViewLeave("delete-wallet-lost-password", clearLostPassword);
|
||||
// Leaving drops the wallet selection, so each screen also comes off the
|
||||
// Back stack, where the settings gear has just put it: Back from
|
||||
// Settings must not land on a screen whose button can only answer "No
|
||||
// wallet selected for deletion." A reopened popup drops them from the
|
||||
// stack the same way (https://git.eeqj.de/sneak/AutistMask/issues/480).
|
||||
onViewLeave("delete-wallet-confirm", () => {
|
||||
clear();
|
||||
const stack = state.viewStack;
|
||||
if (stack[stack.length - 1] === "delete-wallet-confirm") {
|
||||
stack.pop();
|
||||
}
|
||||
});
|
||||
onViewLeave("delete-wallet-lost-password", () => {
|
||||
clearLostPassword();
|
||||
const stack = state.viewStack;
|
||||
if (stack[stack.length - 1] === "delete-wallet-lost-password") {
|
||||
stack.pop();
|
||||
}
|
||||
});
|
||||
|
||||
// No wipe here: goBack() routes through showView(), which runs the
|
||||
// leave hook.
|
||||
@@ -215,19 +233,22 @@ function init(_ctx) {
|
||||
$("btn-delete-wallet-confirm").addEventListener("click", async () => {
|
||||
const pw = $("delete-wallet-password").value;
|
||||
if (!pw) {
|
||||
$("delete-wallet-flash").textContent =
|
||||
"Please enter your password.";
|
||||
$("delete-wallet-flash").style.visibility = "visible";
|
||||
showError(
|
||||
"delete-wallet-password-error",
|
||||
"Please enter your password.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
if (deleteWalletIndex === null) {
|
||||
$("delete-wallet-flash").textContent =
|
||||
"No wallet selected for deletion.";
|
||||
$("delete-wallet-flash").style.visibility = "visible";
|
||||
showError(
|
||||
"delete-wallet-password-error",
|
||||
"No wallet selected for deletion.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
hideError("delete-wallet-password-error");
|
||||
const btn = $("btn-delete-wallet-confirm");
|
||||
btn.disabled = true;
|
||||
btn.classList.add("text-muted");
|
||||
@@ -239,9 +260,10 @@ function init(_ctx) {
|
||||
try {
|
||||
await decryptWithPassword(wallet.encryptedSecret, pw);
|
||||
} catch {
|
||||
$("delete-wallet-flash").textContent =
|
||||
"That password is incorrect. Please try again.";
|
||||
$("delete-wallet-flash").style.visibility = "visible";
|
||||
showError(
|
||||
"delete-wallet-password-error",
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
btn.disabled = false;
|
||||
btn.classList.remove("text-muted");
|
||||
return;
|
||||
|
||||
@@ -20,6 +20,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
flashCopyFeedback,
|
||||
goBack,
|
||||
onViewLeave,
|
||||
@@ -56,11 +58,6 @@ function isCurrentReveal(generation) {
|
||||
);
|
||||
}
|
||||
|
||||
function fail(message) {
|
||||
$("export-privkey-flash").textContent = message;
|
||||
$("export-privkey-flash").style.visibility = "visible";
|
||||
}
|
||||
|
||||
// Wipe every trace of the key and drop the address selection. Safe to call
|
||||
// when nothing was ever revealed, and safe to call twice.
|
||||
function clear() {
|
||||
@@ -71,8 +68,7 @@ function clear() {
|
||||
$("export-privkey-password").value = "";
|
||||
$("export-privkey-result").classList.add("hidden");
|
||||
$("export-privkey-password-section").classList.remove("hidden");
|
||||
$("export-privkey-flash").textContent = "";
|
||||
$("export-privkey-flash").style.visibility = "hidden";
|
||||
hideError("export-privkey-password-error");
|
||||
}
|
||||
|
||||
function show(walletIdx, addrIdx) {
|
||||
@@ -112,15 +108,19 @@ function show(walletIdx, addrIdx) {
|
||||
async function reveal() {
|
||||
const password = $("export-privkey-password").value;
|
||||
if (!password) {
|
||||
fail("Please enter your password.");
|
||||
showError(
|
||||
"export-privkey-password-error",
|
||||
"Please enter your password.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
if (walletIndex === null) {
|
||||
fail("No address is selected.");
|
||||
showError("export-privkey-password-error", "No address is selected.");
|
||||
return;
|
||||
}
|
||||
const wallet = state.wallets[walletIndex];
|
||||
|
||||
hideError("export-privkey-password-error");
|
||||
const btn = $("btn-export-privkey-confirm");
|
||||
btn.disabled = true;
|
||||
btn.classList.add("text-muted");
|
||||
@@ -140,11 +140,12 @@ async function reveal() {
|
||||
$("export-privkey-password-section").classList.add("hidden");
|
||||
$("export-privkey-value").textContent = signer.privateKey;
|
||||
$("export-privkey-result").classList.remove("hidden");
|
||||
$("export-privkey-flash").textContent = "";
|
||||
$("export-privkey-flash").style.visibility = "hidden";
|
||||
} catch {
|
||||
if (!isCurrentReveal(generation)) return;
|
||||
fail("That password is incorrect. Please try again.");
|
||||
showError(
|
||||
"export-privkey-password-error",
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
btn.classList.remove("text-muted");
|
||||
@@ -152,7 +153,16 @@ async function reveal() {
|
||||
}
|
||||
|
||||
function init() {
|
||||
onViewLeave(VIEW, clear);
|
||||
// Leaving drops the address selection, so the screen also comes off the
|
||||
// Back stack, where the settings gear has just put it: Back from Settings
|
||||
// must not land on a password prompt that can only fail. A reopened popup
|
||||
// drops it from the stack the same way
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/461).
|
||||
onViewLeave(VIEW, () => {
|
||||
clear();
|
||||
const stack = state.viewStack;
|
||||
if (stack[stack.length - 1] === VIEW) stack.pop();
|
||||
});
|
||||
|
||||
// No wipe here: goBack() routes through showView(), which runs the
|
||||
// leave hook. A per-button wipe would only cover this one path.
|
||||
|
||||
@@ -216,10 +216,21 @@ function pushCurrentView() {
|
||||
|
||||
// Pop the navigation stack and show the previous view. If the stack
|
||||
// is empty, fall back to the main (home) view.
|
||||
//
|
||||
// An entry for the view already showing is skipped: landing on it would
|
||||
// make Back seem to do nothing. Settings, the recovery phrase or delete
|
||||
// wallet screen, then the gear leaves Settings under Settings, because that
|
||||
// screen takes itself off the stack when left, and a reopened popup cuts it
|
||||
// off the restored stack the same way
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/481).
|
||||
function goBack() {
|
||||
const stack = state.viewStack;
|
||||
while (stack.length > 0 && stack[stack.length - 1] === state.currentView) {
|
||||
stack.pop();
|
||||
}
|
||||
let target;
|
||||
if (state.viewStack.length > 0) {
|
||||
target = state.viewStack.pop();
|
||||
if (stack.length > 0) {
|
||||
target = stack.pop();
|
||||
} else {
|
||||
target = "main";
|
||||
}
|
||||
|
||||
@@ -21,6 +21,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
flashCopyFeedback,
|
||||
goBack,
|
||||
onViewLeave,
|
||||
@@ -52,11 +54,6 @@ function isCurrentReveal(generation) {
|
||||
);
|
||||
}
|
||||
|
||||
function fail(message) {
|
||||
$("show-phrase-flash").textContent = message;
|
||||
$("show-phrase-flash").style.visibility = "visible";
|
||||
}
|
||||
|
||||
// Wipe every trace of the phrase and drop the wallet selection. Safe to
|
||||
// call when nothing was ever revealed, and safe to call twice.
|
||||
function clear() {
|
||||
@@ -66,8 +63,7 @@ function clear() {
|
||||
$("show-phrase-password").value = "";
|
||||
$("show-phrase-result").classList.add("hidden");
|
||||
$("show-phrase-password-section").classList.remove("hidden");
|
||||
$("show-phrase-flash").textContent = "";
|
||||
$("show-phrase-flash").style.visibility = "hidden";
|
||||
hideError("show-phrase-password-error");
|
||||
}
|
||||
|
||||
function show(walletIdx) {
|
||||
@@ -90,19 +86,23 @@ function show(walletIdx) {
|
||||
async function reveal() {
|
||||
const password = $("show-phrase-password").value;
|
||||
if (!password) {
|
||||
fail("Please enter your password.");
|
||||
showError("show-phrase-password-error", "Please enter your password.");
|
||||
return;
|
||||
}
|
||||
if (walletIndex === null) {
|
||||
fail("No wallet is selected.");
|
||||
showError("show-phrase-password-error", "No wallet is selected.");
|
||||
return;
|
||||
}
|
||||
const wallet = state.wallets[walletIndex];
|
||||
if (!walletHasRecoveryPhrase(wallet)) {
|
||||
fail("This wallet does not have a recovery phrase.");
|
||||
showError(
|
||||
"show-phrase-password-error",
|
||||
"This wallet does not have a recovery phrase.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
hideError("show-phrase-password-error");
|
||||
const btn = $("btn-show-phrase-reveal");
|
||||
btn.disabled = true;
|
||||
btn.classList.add("text-muted");
|
||||
@@ -120,13 +120,14 @@ async function reveal() {
|
||||
$("show-phrase-password-section").classList.add("hidden");
|
||||
$("show-phrase-value").textContent = phrase;
|
||||
$("show-phrase-result").classList.remove("hidden");
|
||||
$("show-phrase-flash").textContent = "";
|
||||
$("show-phrase-flash").style.visibility = "hidden";
|
||||
} catch {
|
||||
if (!isCurrentReveal(generation)) return;
|
||||
// Deliberately not the caught error: the message is fixed so that
|
||||
// nothing derived from the ciphertext or the attempt can surface.
|
||||
fail("That password is incorrect. Please try again.");
|
||||
showError(
|
||||
"show-phrase-password-error",
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
btn.classList.remove("text-muted");
|
||||
@@ -134,7 +135,16 @@ async function reveal() {
|
||||
}
|
||||
|
||||
function init() {
|
||||
onViewLeave(VIEW, clear);
|
||||
// Leaving drops the wallet selection, so the screen also comes off the
|
||||
// Back stack, where the settings gear has just put it: Back from Settings
|
||||
// must not land on a password prompt that can only fail. A reopened popup
|
||||
// drops it from the stack the same way
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/461).
|
||||
onViewLeave(VIEW, () => {
|
||||
clear();
|
||||
const stack = state.viewStack;
|
||||
if (stack[stack.length - 1] === VIEW) stack.pop();
|
||||
});
|
||||
|
||||
$("btn-show-phrase-back").addEventListener("click", () => {
|
||||
goBack();
|
||||
|
||||
@@ -39,6 +39,8 @@ jest.doMock("../src/popup/views/helpers", () => ({
|
||||
$: element,
|
||||
showView: () => {},
|
||||
showFlash: () => {},
|
||||
showError: () => {},
|
||||
hideError: () => {},
|
||||
goBack: () => {},
|
||||
clearViewStack: () => {},
|
||||
onViewLeave: () => {},
|
||||
|
||||
@@ -52,6 +52,7 @@ const {
|
||||
resetRenderedViews,
|
||||
} = require("../src/popup/viewRouter");
|
||||
const { state } = require("../src/shared/state");
|
||||
const { restorableStack } = require("../src/shared/persistedState");
|
||||
|
||||
const ADDRESS = "0x1111111111111111111111111111111111111111";
|
||||
const TOKEN = "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48";
|
||||
@@ -209,6 +210,23 @@ describe("Back onto a view the reopened popup never rendered", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/481. Settings, the recovery
|
||||
// phrase or delete wallet screen, the gear, then a reopen: the restored stack
|
||||
// is cut at the screen the gear left, which leaves Settings under the Settings
|
||||
// the popup reopens onto.
|
||||
describe("Back from Settings reopened over its own entry", () => {
|
||||
test.each(["show-phrase", "delete-wallet-confirm"])(
|
||||
"goes to the screen under it after leaving %s",
|
||||
(left) => {
|
||||
const stored = ["main", "settings", left];
|
||||
reopenedOn("settings", restorableStack(stored, "settings"));
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
},
|
||||
);
|
||||
});
|
||||
|
||||
// The guards are restoreView()'s, so a popped view whose backing data is
|
||||
// gone lands on Home rather than on an empty template.
|
||||
describe("Back onto a view whose backing data is gone", () => {
|
||||
|
||||
@@ -253,7 +253,7 @@ describe("reaching the screen", () => {
|
||||
const { decryptWithPassword } = require("../src/shared/vault");
|
||||
decryptWithPassword.mockRejectedValue(new Error("nope"));
|
||||
await click("btn-delete-wallet-confirm");
|
||||
expect(node("delete-wallet-flash").textContent).toBe(
|
||||
expect(node("delete-wallet-password-error").textContent).toBe(
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
});
|
||||
@@ -615,3 +615,46 @@ describe("the password route's confirm button", () => {
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/480: leaving either delete
|
||||
// screen drops its wallet selection, so Back onto one showed a screen whose
|
||||
// button could only answer "No wallet selected for deletion." Taking the
|
||||
// screen off the stack leaves Settings under Settings, and Back must not land
|
||||
// there either (https://git.eeqj.de/sneak/AutistMask/issues/481).
|
||||
describe("Back from Settings after leaving by the settings gear", () => {
|
||||
test("goes past the delete screen to the screen under Settings", () => {
|
||||
const { helpers, deleteWallet, state } = load();
|
||||
deleteWallet.show(1);
|
||||
// The settings gear: push the current view, then show Settings.
|
||||
helpers.pushCurrentView();
|
||||
helpers.showView("settings");
|
||||
|
||||
expect(state.viewStack).toEqual(["main", "settings"]);
|
||||
helpers.goBack();
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("goes past the lost-password screen to the screen under Settings", async () => {
|
||||
const { helpers, deleteWallet, state } = load();
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
// The settings gear: push the current view, then show Settings.
|
||||
helpers.pushCurrentView();
|
||||
helpers.showView("settings");
|
||||
|
||||
expect(state.viewStack).toEqual(["main", "settings"]);
|
||||
helpers.goBack();
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
// The lost-password screen's own Back is "Back returns to the delete
|
||||
// screen with its wallet still chosen", above.
|
||||
test("the delete screen's own Back leaves the rest of the stack alone", async () => {
|
||||
const { deleteWallet, state } = load();
|
||||
deleteWallet.show(1);
|
||||
|
||||
await click("btn-delete-wallet-back");
|
||||
|
||||
expect(state.currentView).toBe("settings");
|
||||
expect(state.viewStack).toEqual(["main"]);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -854,37 +854,6 @@ step(
|
||||
|
||||
// ------------------------------------------------------------- runner
|
||||
|
||||
// Uncaught extension errors that are known, tracked and deliberately
|
||||
// tolerated, in the same spirit as ALLOWED_ERRORS in tests/e2e/harness.js:
|
||||
// every entry names the issue that will delete it, and every occurrence is
|
||||
// still printed, so tolerating one is visible in the log rather than silent.
|
||||
// This is the only concession in an otherwise zero-tolerance policy.
|
||||
const ALLOWED_ERRORS = [
|
||||
{
|
||||
// The site-connection buttons in src/popup/views/approval.js send
|
||||
// their decision and call window.close() on the next line. Firefox's
|
||||
// BaseContext.wrapPromise reports, through Cu.reportError, any
|
||||
// extension-API promise that settles after its context unloaded —
|
||||
// whether or not the caller attached a handler, so notify()'s catch
|
||||
// cannot suppress it.
|
||||
//
|
||||
// Pre-existing, and not introduced by the promise shim: the send was
|
||||
// already unawaited, and this suite is merely the first thing to
|
||||
// drive that window on Firefox. It is the same teardown ordering as
|
||||
// the issue below, whose fix — making the outcome independent of when
|
||||
// the popup closes — removes this entry with it.
|
||||
pattern: /Promise (?:resolved|rejected) after context unloaded/,
|
||||
source: /\/src\/popup\/index\.js$/,
|
||||
issue: "https://git.eeqj.de/sneak/AutistMask/issues/275",
|
||||
},
|
||||
];
|
||||
|
||||
function allowedFor(e) {
|
||||
return ALLOWED_ERRORS.find(
|
||||
(a) => a.pattern.test(e.msg) && a.source.test(e.src),
|
||||
);
|
||||
}
|
||||
|
||||
function formatError(e) {
|
||||
return (
|
||||
e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")"
|
||||
@@ -1001,20 +970,6 @@ async function main() {
|
||||
installFailure = null;
|
||||
}
|
||||
|
||||
// Tolerated errors are set aside, never dropped: each one is
|
||||
// printed with the issue that keeps it on the list, so the
|
||||
// concession stays in the run output.
|
||||
const tolerated = found.filter((e) => allowedFor(e));
|
||||
found = found.filter((e) => !allowedFor(e));
|
||||
for (const e of tolerated) {
|
||||
console.log(
|
||||
"# tolerated (" +
|
||||
allowedFor(e).issue +
|
||||
"): " +
|
||||
formatError(e),
|
||||
);
|
||||
}
|
||||
|
||||
// Any uncaught error from an extension source fails the step
|
||||
// that provoked it, whether or not its assertions passed.
|
||||
if (!failure && found.length > 0) {
|
||||
@@ -1039,13 +994,7 @@ async function main() {
|
||||
// blamed on any one step, but they are still reported and they
|
||||
// still fail the run.
|
||||
await sleep(1000);
|
||||
const trailingAll = await errors.take();
|
||||
for (const e of trailingAll.filter((x) => allowedFor(x))) {
|
||||
console.log(
|
||||
"# tolerated (" + allowedFor(e).issue + "): " + formatError(e),
|
||||
);
|
||||
}
|
||||
const trailing = trailingAll.filter((e) => !allowedFor(e));
|
||||
const trailing = await errors.take();
|
||||
console.log(
|
||||
"# " +
|
||||
(steps.length - failed) +
|
||||
|
||||
+112
-9
@@ -809,7 +809,7 @@ async function secretScreenState(page, view) {
|
||||
return page.evaluate(
|
||||
(v) => ({
|
||||
value: document.getElementById(v + "-value").textContent,
|
||||
error: document.getElementById(v + "-flash").textContent,
|
||||
error: document.getElementById(v + "-password-error").textContent,
|
||||
html: document.getElementById("view-" + v).innerHTML,
|
||||
resultHidden: document
|
||||
.getElementById(v + "-result")
|
||||
@@ -906,7 +906,8 @@ test("a wrong password reveals nothing (#161)", async (env) => {
|
||||
await env.page.click("#btn-show-phrase-reveal");
|
||||
await env.page.waitForFunction(
|
||||
() =>
|
||||
document.getElementById("show-phrase-flash").textContent.length > 0,
|
||||
document.getElementById("show-phrase-password-error").textContent
|
||||
.length > 0,
|
||||
null,
|
||||
{ timeout: 60000 },
|
||||
);
|
||||
@@ -1075,13 +1076,13 @@ async function revealPrivkey(page) {
|
||||
}
|
||||
|
||||
// Leave the export screen, or the Settings screen the gear left it for, for
|
||||
// Home. The gear put the export screen on the Back stack, so from Settings the
|
||||
// way home passes through it, already emptied
|
||||
// Home. Leaving takes the export screen off the Back stack, so from Settings
|
||||
// Back goes to the address screen it was opened from
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/461).
|
||||
async function leavePrivkeyScreen(page) {
|
||||
if (await page.isVisible("#view-settings")) {
|
||||
await page.click("#btn-settings-back");
|
||||
await visible(page, "#view-export-privkey");
|
||||
await visible(page, "#view-address");
|
||||
}
|
||||
if (await page.isVisible("#view-export-privkey")) {
|
||||
await page.click("#btn-export-privkey-back");
|
||||
@@ -1993,13 +1994,14 @@ test("an over-long flash message keeps to one line (#252)", async (env) => {
|
||||
|
||||
// Every screen that asks for a password reserves room for one line of error.
|
||||
// The two on the dApp approval screens also have a border and padding, which
|
||||
// that reserved height has to cover too.
|
||||
// that reserved height has to cover too. The add wallet screen's line sits
|
||||
// beside its button rather than above it, and has its own test below.
|
||||
const PASSWORD_ERROR_CONTAINERS = [
|
||||
"approve-tx-error",
|
||||
"approve-sign-error",
|
||||
"export-privkey-flash",
|
||||
"show-phrase-flash",
|
||||
"delete-wallet-flash",
|
||||
"export-privkey-password-error",
|
||||
"show-phrase-password-error",
|
||||
"delete-wallet-password-error",
|
||||
"confirm-tx-password-error",
|
||||
];
|
||||
|
||||
@@ -2064,6 +2066,107 @@ test("a password error moves nothing on any screen (#297)", async (env) => {
|
||||
}
|
||||
});
|
||||
|
||||
// ------------------------------------------ add wallet Import button (#493)
|
||||
|
||||
// At 360x600 the add wallet screen's Import button already starts near the
|
||||
// bottom of the popup, so its password error line sits beside the button
|
||||
// rather than above it. Measures the button and the line empty and again
|
||||
// filled with the longest error addWallet.js puts there. Runs in the page.
|
||||
function measureImportButton() {
|
||||
const button = document.getElementById("btn-add-wallet-confirm");
|
||||
const line = document.getElementById("add-wallet-password-error");
|
||||
const measure = () => {
|
||||
const b = button.getBoundingClientRect();
|
||||
const l = line.getBoundingClientRect();
|
||||
return {
|
||||
buttonTop: b.top + window.scrollY,
|
||||
buttonBottom: b.bottom + window.scrollY,
|
||||
lineTop: l.top + window.scrollY,
|
||||
lineBottom: l.bottom + window.scrollY,
|
||||
};
|
||||
};
|
||||
const empty = measure();
|
||||
line.textContent = "Password must be at least 12 characters.";
|
||||
line.style.visibility = "visible";
|
||||
const filled = measure();
|
||||
line.textContent = "";
|
||||
line.style.visibility = "hidden";
|
||||
return { empty, filled };
|
||||
}
|
||||
|
||||
test("the add wallet password error leaves Import where it was (#493)", async (env) => {
|
||||
const page = await openPopup(env.ctx, env.popupUrl);
|
||||
try {
|
||||
await page.setViewportSize(POPUP_VIEWPORT);
|
||||
// Brought up by toggling classes, as in the test above. The note
|
||||
// addWallet.js shows once a wallet exists is the only part of the
|
||||
// screen that differs between the first wallet and a later one.
|
||||
await page.evaluate(() => {
|
||||
const screen = document.getElementById("view-add-wallet");
|
||||
for (const view of document.querySelectorAll(".view")) {
|
||||
view.classList.toggle("hidden", view !== screen);
|
||||
}
|
||||
});
|
||||
for (const walletExists of [false, true]) {
|
||||
await page.evaluate(
|
||||
(shown) =>
|
||||
document
|
||||
.getElementById("add-wallet-separate-password-note")
|
||||
.classList.toggle("hidden", !shown),
|
||||
walletExists,
|
||||
);
|
||||
for (const tab of ["tab-mnemonic", "tab-privkey", "tab-xprv"]) {
|
||||
await page.click("#" + tab);
|
||||
const { empty, filled } =
|
||||
await page.evaluate(measureImportButton);
|
||||
const where =
|
||||
"#" +
|
||||
tab +
|
||||
(walletExists
|
||||
? " with a wallet already added"
|
||||
: " for the first wallet");
|
||||
// Printed pass or fail, as the dust threshold test does.
|
||||
console.log(
|
||||
"# add wallet Import top, " +
|
||||
where +
|
||||
": " +
|
||||
empty.buttonTop +
|
||||
"px",
|
||||
);
|
||||
for (const m of [empty, filled]) {
|
||||
assert(
|
||||
m.lineTop >= m.buttonTop &&
|
||||
m.lineBottom <= m.buttonBottom,
|
||||
"the error line on " +
|
||||
where +
|
||||
" does not fit beside Import, so it adds height: " +
|
||||
JSON.stringify(m),
|
||||
);
|
||||
}
|
||||
assert(
|
||||
filled.buttonTop === empty.buttonTop,
|
||||
"Import moved " +
|
||||
(filled.buttonTop - empty.buttonTop) +
|
||||
"px when the error appeared on " +
|
||||
where,
|
||||
);
|
||||
if (!walletExists) {
|
||||
assert(
|
||||
empty.buttonTop < POPUP_VIEWPORT.height,
|
||||
"Import starts at " +
|
||||
empty.buttonTop +
|
||||
"px on " +
|
||||
where +
|
||||
", below the fold",
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
await page.close();
|
||||
}
|
||||
});
|
||||
|
||||
// --------------------------------------------- confirmation screen (#238)
|
||||
//
|
||||
// The screen that decides what gets signed. The arithmetic underneath it
|
||||
|
||||
@@ -207,7 +207,7 @@ describe("a decrypt still running when the screen is left", () => {
|
||||
});
|
||||
|
||||
// Same hole on the failure path: a wrong-password error written after
|
||||
// the wipe would restore the flash line on a screen the user has left.
|
||||
// the wipe would restore the error line on a screen the user has left.
|
||||
test("never writes the failure message either", async () => {
|
||||
const { helpers, vault, exportPrivkey } = load();
|
||||
exportPrivkey.show(0, 0);
|
||||
@@ -217,8 +217,10 @@ describe("a decrypt still running when the screen is left", () => {
|
||||
reveal.reject(new Error("decryption failed"));
|
||||
await reveal.pending;
|
||||
|
||||
expect(node("export-privkey-flash").textContent).toBe("");
|
||||
expect(node("export-privkey-flash").style.visibility).toBe("hidden");
|
||||
expect(node("export-privkey-password-error").textContent).toBe("");
|
||||
expect(node("export-privkey-password-error").style.visibility).toBe(
|
||||
"hidden",
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -260,7 +262,7 @@ describe("a reveal that is not interrupted", () => {
|
||||
await reveal.pending;
|
||||
|
||||
expect(node("export-privkey-value").textContent).toBe("");
|
||||
expect(node("export-privkey-flash").textContent).toBe(
|
||||
expect(node("export-privkey-password-error").textContent).toBe(
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
});
|
||||
@@ -336,6 +338,36 @@ describe("opening the screen again in the same popup session", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("Back from Settings after leaving by the settings gear", () => {
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/461: leaving drops the
|
||||
// address selection, so Back onto this screen showed a password prompt
|
||||
// that could only answer "No address is selected."
|
||||
test("goes to the address screen it was opened from", () => {
|
||||
const { helpers, state, exportPrivkey } = load();
|
||||
state.viewStack = ["main"];
|
||||
exportPrivkey.show(0, 0);
|
||||
// The settings gear: push the current view, then show Settings.
|
||||
helpers.pushCurrentView();
|
||||
helpers.showView("settings");
|
||||
|
||||
helpers.goBack();
|
||||
|
||||
expect(state.currentView).toBe("address");
|
||||
expect(state.viewStack).toEqual(["main"]);
|
||||
});
|
||||
|
||||
test("its own Back button leaves the rest of the stack alone", async () => {
|
||||
const { state, exportPrivkey } = load();
|
||||
state.viewStack = ["main"];
|
||||
exportPrivkey.show(0, 0);
|
||||
|
||||
await click("btn-export-privkey-back");
|
||||
|
||||
expect(state.currentView).toBe("address");
|
||||
expect(state.viewStack).toEqual(["main"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("views the popup may reopen onto", () => {
|
||||
// Restoring onto this screen would put a private key on display with no
|
||||
// password prompt in front of it, on a popup reopened by accident.
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
// The toolbar icons in icons/ are drawn by script/lib/icons.js (`make icons`).
|
||||
// Each committed file must hold exactly the image it draws, the same IHDR and
|
||||
// every pixel, so the drawing and the files cannot drift apart. The compressed
|
||||
// bytes are not compared: the committed files were compressed by stock zlib,
|
||||
// and node's bundled zlib compresses the same pixels differently.
|
||||
|
||||
const fs = require("fs");
|
||||
const path = require("path");
|
||||
|
||||
const { icons } = require("../manifest/chrome.json");
|
||||
const { drawIcon, decodePng } = require("../script/lib/icons");
|
||||
|
||||
describe("toolbar icons", () => {
|
||||
test.each(Object.entries(icons))(
|
||||
"the %spx icon %s holds the image script/lib/icons.js draws",
|
||||
(size, file) => {
|
||||
const side = Number(size);
|
||||
const committed = decodePng(
|
||||
fs.readFileSync(path.join(__dirname, "..", file)),
|
||||
);
|
||||
const drawn = decodePng(drawIcon(side));
|
||||
|
||||
expect(committed.header).toEqual(drawn.header);
|
||||
// Each row is its filter type byte, then 4 bytes per pixel.
|
||||
expect(drawn.rows.length).toBe(side * (side * 4 + 1));
|
||||
expect(committed.rows.length).toBe(drawn.rows.length);
|
||||
// The offset of the first byte that differs, not a diff of all.
|
||||
expect(
|
||||
committed.rows.findIndex((byte, i) => byte !== drawn.rows[i]),
|
||||
).toBe(-1);
|
||||
},
|
||||
);
|
||||
});
|
||||
@@ -0,0 +1,159 @@
|
||||
// Every screen that asks for a password shows a password error the same way:
|
||||
// through showError() and hideError() in src/popup/views/helpers.js, in a
|
||||
// fixed-height error line below the password field, and never in the flash
|
||||
// line at the top of the popup
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/493). These boot the real popup
|
||||
// over src/popup/index.html, so each error line has to exist in the markup,
|
||||
// and check that the error appears in it and clears again.
|
||||
|
||||
jest.mock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: jest.fn(),
|
||||
encryptWithPassword: jest.fn(),
|
||||
}));
|
||||
|
||||
const {
|
||||
bootPopup,
|
||||
cleanupPopup,
|
||||
unversionedValidProfile,
|
||||
} = require("./support/popupBoot");
|
||||
|
||||
const PASSWORD = "correct horse battery staple";
|
||||
const WRONG_PASSWORD = "That password is incorrect. Please try again.";
|
||||
|
||||
afterEach(() => {
|
||||
cleanupPopup();
|
||||
});
|
||||
|
||||
// The error line as the user sees it.
|
||||
function errorLine(page, id) {
|
||||
return {
|
||||
inMarkup: page.document.authoredIds.has(id),
|
||||
text: page.text(id),
|
||||
visibility: page.node(id).style.visibility,
|
||||
};
|
||||
}
|
||||
|
||||
function shown(text) {
|
||||
return { inMarkup: true, text, visibility: "visible" };
|
||||
}
|
||||
|
||||
const cleared = { inMarkup: true, text: "", visibility: "hidden" };
|
||||
|
||||
describe("the add wallet screen", () => {
|
||||
const ERROR = "add-wallet-password-error";
|
||||
|
||||
// First run: Welcome, "Add wallet", then the die for a valid phrase.
|
||||
async function openAddWallet() {
|
||||
const page = await bootPopup(undefined);
|
||||
await page.click("btn-welcome-add");
|
||||
await page.click("btn-generate-phrase");
|
||||
return page;
|
||||
}
|
||||
|
||||
function setPasswords(page, password, confirm) {
|
||||
page.node("add-wallet-password").value = password;
|
||||
page.node("add-wallet-password-confirm").value = confirm;
|
||||
}
|
||||
|
||||
test("shows a password problem below the password fields, and clears it on the next press", async () => {
|
||||
const page = await openAddWallet();
|
||||
setPasswords(page, "short", "short");
|
||||
await page.click("btn-add-wallet-confirm");
|
||||
expect(errorLine(page, ERROR)).toEqual(
|
||||
shown("Password must be at least 12 characters."),
|
||||
);
|
||||
expect(page.text("flash-msg")).toBe("");
|
||||
|
||||
// The password is fixed and the phrase emptied: the password error
|
||||
// goes, and the phrase problem is still reported in the flash line.
|
||||
setPasswords(page, PASSWORD, PASSWORD);
|
||||
page.node("wallet-mnemonic").value = "";
|
||||
await page.click("btn-add-wallet-confirm");
|
||||
expect(errorLine(page, ERROR)).toEqual(cleared);
|
||||
expect(page.text("flash-msg")).toBe(
|
||||
"Enter a recovery phrase, or press the die.",
|
||||
);
|
||||
|
||||
// Leaving clears the flash line and stops its timer, which would
|
||||
// otherwise fire after this page is gone.
|
||||
await page.click("btn-add-wallet-back");
|
||||
});
|
||||
|
||||
test("clears the error when the screen is shown again", async () => {
|
||||
const page = await openAddWallet();
|
||||
setPasswords(page, PASSWORD, PASSWORD + " typo");
|
||||
await page.click("btn-add-wallet-confirm");
|
||||
expect(errorLine(page, ERROR)).toEqual(
|
||||
shown("Passwords do not match."),
|
||||
);
|
||||
|
||||
await page.click("btn-add-wallet-back");
|
||||
await page.click("btn-welcome-add");
|
||||
expect(errorLine(page, ERROR)).toEqual(cleared);
|
||||
});
|
||||
});
|
||||
|
||||
describe.each([
|
||||
{
|
||||
screen: "the private key export screen",
|
||||
open: () => require("../src/popup/views/exportPrivkey").show(0, 0),
|
||||
field: "export-privkey-password",
|
||||
button: "btn-export-privkey-confirm",
|
||||
error: "export-privkey-password-error",
|
||||
},
|
||||
{
|
||||
screen: "the recovery phrase screen",
|
||||
open: () => require("../src/popup/views/showPhrase").show(0),
|
||||
field: "show-phrase-password",
|
||||
button: "btn-show-phrase-reveal",
|
||||
error: "show-phrase-password-error",
|
||||
},
|
||||
{
|
||||
screen: "the delete wallet screen",
|
||||
open: () => require("../src/popup/views/deleteWallet").show(0),
|
||||
field: "delete-wallet-password",
|
||||
button: "btn-delete-wallet-confirm",
|
||||
error: "delete-wallet-password-error",
|
||||
},
|
||||
])("$screen", ({ open, field, button, error }) => {
|
||||
// Opens the screen and enters a password the vault rejects.
|
||||
async function failedAttempt() {
|
||||
const page = await bootPopup(unversionedValidProfile());
|
||||
open();
|
||||
const { decryptWithPassword } = require("../src/shared/vault");
|
||||
decryptWithPassword.mockRejectedValue(new Error("wrong password"));
|
||||
page.node(field).value = "not the password";
|
||||
await page.click(button);
|
||||
return { page, decryptWithPassword };
|
||||
}
|
||||
|
||||
test("shows a wrong password below the password field", async () => {
|
||||
const { page } = await failedAttempt();
|
||||
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
|
||||
});
|
||||
|
||||
test("clears the error while the next password is checked", async () => {
|
||||
const { page, decryptWithPassword } = await failedAttempt();
|
||||
let rejectDecrypt;
|
||||
decryptWithPassword.mockReturnValue(
|
||||
new Promise((resolve, reject) => {
|
||||
rejectDecrypt = reject;
|
||||
}),
|
||||
);
|
||||
|
||||
page.node(field).value = "another guess";
|
||||
const pressed = page.click(button);
|
||||
await page.settle();
|
||||
expect(errorLine(page, error)).toEqual(cleared);
|
||||
|
||||
rejectDecrypt(new Error("wrong password"));
|
||||
await pressed;
|
||||
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
|
||||
});
|
||||
|
||||
test("clears the error when the screen is shown again", async () => {
|
||||
const { page } = await failedAttempt();
|
||||
open();
|
||||
expect(errorLine(page, error)).toEqual(cleared);
|
||||
});
|
||||
});
|
||||
@@ -49,22 +49,37 @@
|
||||
// every path a stored record takes, and the difference is the whole of what
|
||||
// this file does not cover:
|
||||
//
|
||||
// - Only the values in the table, in the SLOT arrangement below: four value
|
||||
// combinations per view, not the product of twelve fields. A dereference
|
||||
// reached only under a pairing no slot produces is not driven at all.
|
||||
// - Only what a stored record reaches by ITSELF. A view only forward
|
||||
// navigation opens, and anything behind a click, is not driven.
|
||||
// - Nothing about the paths a HEALTHY profile takes, which is most of the
|
||||
// popup. This file is a floor under one defect class, not a proof about
|
||||
// the renderers.
|
||||
// - Only the values in the table, in the SLOT arrangement below. On the
|
||||
// restore path the twelve fields the router does not read are corrupted
|
||||
// together, every field on the same slot, so a view gets four value
|
||||
// combinations of them, not their product. A branch entered only when one
|
||||
// of them is truthy and another falsy is reached only where the falsy
|
||||
// slot happens to pair a field that cannot be falsy with one that is.
|
||||
// Each field the router reads is corrupted alone, over an otherwise
|
||||
// well-formed record.
|
||||
// - Only what a stored record reaches by ITSELF, as the boot renders it. A
|
||||
// view only forward navigation opens, anything behind a click, and
|
||||
// anything behind a timer (bootPopup() records every interval, and this
|
||||
// file never runs one) is not driven.
|
||||
// - Of the paths a HEALTHY profile takes, only its boot onto each
|
||||
// restorable view ("the base profile the sweep corrupts" below). The rest
|
||||
// of the popup is not covered: this file is a floor under one defect
|
||||
// class, not a proof about the renderers.
|
||||
//
|
||||
// Within that boundary it is unconditional: if one of these boots leaves the
|
||||
// popup unhealthy or off the view it stored, this file goes red — including
|
||||
// when it takes two corrupted fields at once, because the verdict is the
|
||||
// combined boot itself and the per-field re-boot below can only decorate the
|
||||
// message. That last part is the one thing an earlier version got wrong: it
|
||||
// asserted on the per-field list, so an observed dead popup that no single
|
||||
// field reproduced was reported green.
|
||||
// Within that boundary it is unconditional: if a boot that corrupts a field
|
||||
// leaves the popup unhealthy, this file goes red — including when it takes
|
||||
// two corrupted fields at once, because the verdict is the combined boot
|
||||
// itself and the per-field re-boot below can only decorate the message. That
|
||||
// last part is the one thing an earlier version got wrong: it asserted on the
|
||||
// per-field list, so an observed dead popup that no single field reproduced
|
||||
// was reported green.
|
||||
//
|
||||
// Where the popup lands is held for some of those boots and not others. The
|
||||
// combined boot must land on the view it stored, and each `hostileRestore`
|
||||
// value must land on its view, or fall back to Home, as its entry declares.
|
||||
// The boots in "a hostile routing value restoring onto" are held to health
|
||||
// alone, because a value in a field the router reads legitimately changes
|
||||
// which view renders; so are the boots onto Home, which store no view.
|
||||
//
|
||||
// Booting every field separately at every value would be several hundred boots
|
||||
// and most of the suite's budget; this is forty-four. Widening it further is
|
||||
@@ -128,7 +143,11 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
|
||||
// list short and pointed. `floorOnly` is extra values checked against the
|
||||
// floor alone, which is pure and free. `hostileRestore` is extra values driven
|
||||
// through the restore path only, for a value that means nothing until a
|
||||
// particular branch's gate has let it past.
|
||||
// particular branch's gate has let it past. Each of its entries names the
|
||||
// `views` it is driven onto and declares whether the boot lands on them
|
||||
// (`restored: true`) or falls back to Home (`restored: false`), so a value
|
||||
// written for one renderer cannot stop reaching it unnoticed. A value driven
|
||||
// onto every restorable view is written with everyRestorableView() below.
|
||||
//
|
||||
// `falsy` is the other POLARITY of a swept field, driven for the same reason.
|
||||
// It is not a value src/ never writes — for three of these fields it is the
|
||||
@@ -139,6 +158,23 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
|
||||
// falsy value stored under that field comes back TRUTHY from the floor, so no
|
||||
// `!state.x` branch is reachable from a stored record at all.
|
||||
|
||||
// The `hostileRestore` entries for a value driven onto every restorable view:
|
||||
// it falls back to Home on the views listed in `fallsBackOn` and lands on every
|
||||
// other one, so a view added to RESTORABLE_VIEWS is driven, and expected to
|
||||
// land, without editing the row.
|
||||
function everyRestorableView(value, fallsBackOn) {
|
||||
return [
|
||||
{ value, views: fallsBackOn, restored: false },
|
||||
{
|
||||
value,
|
||||
views: [...RESTORABLE_VIEWS].filter(
|
||||
(view) => !fallsBackOn.includes(view),
|
||||
),
|
||||
restored: true,
|
||||
},
|
||||
];
|
||||
}
|
||||
|
||||
const CONTRACT = [
|
||||
{
|
||||
field: "wallets",
|
||||
@@ -280,28 +316,38 @@ const CONTRACT = [
|
||||
kind: KIND.SCALAR,
|
||||
// The prototype members are the whole point: `wallets["map"]` is
|
||||
// TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and
|
||||
// `.addresses[…]` throws. A stale INTEGER is the safe case.
|
||||
hostile: ["map", "__proto__", { a: 1 }],
|
||||
// `.addresses[…]` throws. A stale INTEGER is the safe case and has to
|
||||
// stay so. 5 is one, out of range for the one wallet in the profile,
|
||||
// and it is also this field's truthy polarity: every other value here
|
||||
// comes back from the floor as null.
|
||||
hostile: ["map", "__proto__", { a: 1 }, 5],
|
||||
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
||||
holds: isIndexOrNull,
|
||||
// SCALAR, and swept anyway: the restore path is precisely why this
|
||||
// field gained a floor, so the sweep is the regression guard on it.
|
||||
alsoSweep: true,
|
||||
routes: true,
|
||||
// A stale INTEGER index, which reaches the restore path by a different
|
||||
// route from the prototype members above — falsy or out of range
|
||||
// rather than truthy — and has to keep being the safe case.
|
||||
hostileRestore: [{ value: "length" }, { value: 5 }],
|
||||
// Comes back from the floor as null, which hasValidAddress() reads as
|
||||
// nothing selected: the popup falls back to Home on the five views
|
||||
// that need an address, and lands on every other one.
|
||||
hostileRestore: everyRestorableView("length", [
|
||||
"address",
|
||||
"address-token",
|
||||
"receive",
|
||||
"transaction",
|
||||
"confirm-tx",
|
||||
]),
|
||||
},
|
||||
{
|
||||
field: "selectedAddress",
|
||||
kind: KIND.SCALAR,
|
||||
hostile: ["map", "__proto__", { a: 1 }],
|
||||
// 5 for the same reason as in selectedWallet: a stale index, and the
|
||||
// one value here still truthy after the floor.
|
||||
hostile: ["map", "__proto__", { a: 1 }, 5],
|
||||
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
||||
holds: isIndexOrNull,
|
||||
alsoSweep: true,
|
||||
routes: true,
|
||||
hostileRestore: [{ value: 5 }],
|
||||
},
|
||||
{
|
||||
field: "currentView",
|
||||
@@ -325,7 +371,9 @@ const CONTRACT = [
|
||||
// container shapes below onto every restorable view; hostileRestore
|
||||
// adds the records that PASS a branch's gate and then hand its
|
||||
// renderer something it dereferences, which is where the entries are
|
||||
// actually decided.
|
||||
// actually decided. The guard refuses each single-view record below,
|
||||
// so each is declared to fall back to Home: one that started landing
|
||||
// would be reaching the renderer it was written against.
|
||||
hostile: [42, "notarecord", { a: 1 }, [1, 2]],
|
||||
// `structuredClone(saved.viewData || {})`: the container is never falsy
|
||||
// in state whatever was stored, so no `!state.viewData` branch exists to
|
||||
@@ -334,11 +382,20 @@ const CONTRACT = [
|
||||
hostileRestore: [
|
||||
// success-tx passes on `data.hash`, and renderSuccess() then calls
|
||||
// toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase().
|
||||
{ value: { hash: "0x1" }, views: ["success-tx"] },
|
||||
{ value: { hash: "0x1", to: 42 }, views: ["success-tx"] },
|
||||
{
|
||||
value: { hash: "0x1" },
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: { hash: "0x1", to: 42 },
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } },
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: {
|
||||
@@ -347,12 +404,25 @@ const CONTRACT = [
|
||||
decoded: { details: [{ address: 42 }] },
|
||||
},
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// error-tx passes on `data.message`, same dereference.
|
||||
{ value: { message: "boom" }, views: ["error-tx"] },
|
||||
{ value: { message: "boom", to: 42 }, views: ["error-tx"] },
|
||||
{
|
||||
value: { message: "boom" },
|
||||
views: ["error-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: { message: "boom", to: 42 },
|
||||
views: ["error-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// transaction passes on `data.tx`.
|
||||
{ value: { tx: { hash: "0x1" } }, views: ["transaction"] },
|
||||
{
|
||||
value: { tx: { hash: "0x1" } },
|
||||
views: ["transaction"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: {
|
||||
tx: {
|
||||
@@ -363,9 +433,14 @@ const CONTRACT = [
|
||||
},
|
||||
},
|
||||
views: ["transaction"],
|
||||
restored: false,
|
||||
},
|
||||
// confirm-tx passes on `data.pendingTx`.
|
||||
{ value: { pendingTx: { amount: "1" } }, views: ["confirm-tx"] },
|
||||
{
|
||||
value: { pendingTx: { amount: "1" } },
|
||||
views: ["confirm-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: {
|
||||
pendingTx: {
|
||||
@@ -376,6 +451,7 @@ const CONTRACT = [
|
||||
},
|
||||
},
|
||||
views: ["confirm-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// wait-tx passes on `pendingWait.hash`; restoreWait() has checked
|
||||
// the fields below it since it was written, and this is the
|
||||
@@ -388,20 +464,29 @@ const CONTRACT = [
|
||||
},
|
||||
},
|
||||
views: ["wait-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// A record that passes EVERY branch's gate at once, driven onto
|
||||
// every restorable view: a branch a view does not read must stay
|
||||
// one it does not read, and each renderer must survive the fields
|
||||
// another branch left behind.
|
||||
{
|
||||
value: {
|
||||
// one it does not read. The five views with a viewData branch
|
||||
// refuse it; every other one renders it, and must survive the
|
||||
// fields every branch left behind.
|
||||
...everyRestorableView(
|
||||
{
|
||||
hash: "0x1",
|
||||
message: "boom",
|
||||
tx: { hash: "0x1" },
|
||||
pendingTx: { amount: "1" },
|
||||
pendingWait: { hash: "0x1" },
|
||||
},
|
||||
},
|
||||
[
|
||||
"confirm-tx",
|
||||
"transaction",
|
||||
"wait-tx",
|
||||
"success-tx",
|
||||
"error-tx",
|
||||
],
|
||||
),
|
||||
],
|
||||
},
|
||||
{
|
||||
@@ -583,6 +668,11 @@ const HEALTHY = { errors: [], blank: false };
|
||||
// set is all-truthy by construction, so without a falsy slot a dereference
|
||||
// behind `if (!state.x)` is never reached on the boot that corrupts x — the
|
||||
// same falsy-collapse blind spot the fields below were floored for.
|
||||
//
|
||||
// Only `hostile` and `falsy` values count. Those go through the sweep below,
|
||||
// which covers every restorable view; a `hostileRestore` entry is driven onto
|
||||
// only the views it names, so a polarity it alone supplied might reach a single
|
||||
// renderer.
|
||||
describe("both polarities of every swept field are driven", () => {
|
||||
const FALSY_STORED = [0, "", false, null];
|
||||
const floored = (field, value) =>
|
||||
@@ -606,10 +696,9 @@ describe("both polarities of every swept field are driven", () => {
|
||||
test(`${row.field}: truthy and falsy`, () => {
|
||||
// What the boots below actually drive, floored the way a renderer
|
||||
// sees it — not what the row says it drives.
|
||||
const driven = [
|
||||
...sweptValues(row),
|
||||
...(row.hostileRestore || []).map((entry) => entry.value),
|
||||
].map((value) => floored(row.field, value));
|
||||
const driven = sweptValues(row).map((value) =>
|
||||
floored(row.field, value),
|
||||
);
|
||||
|
||||
expect({
|
||||
truthy: driven.some((value) => Boolean(value)),
|
||||
@@ -865,20 +954,27 @@ describe("every field the router does not read, corrupted at once, onto", () =>
|
||||
|
||||
// The values that only mean something on the restore path: a viewData that
|
||||
// PASSES a branch's gate and then hands its renderer something dereferenced,
|
||||
// and the index values whose route through hasValidAddress() differs from the
|
||||
// row's own hostile set.
|
||||
// and a selectedWallet the floor turns into nothing selected. Each boot must
|
||||
// throw nothing and show exactly the view its entry says it lands on: its own,
|
||||
// or Home, so a value written for one renderer cannot stop reaching it and
|
||||
// still pass.
|
||||
describe("a restore-only hostile value onto", () => {
|
||||
for (const row of CONTRACT) {
|
||||
for (const entry of row.hostileRestore || []) {
|
||||
for (const view of entry.views || RESTORABLE_VIEWS) {
|
||||
for (const view of entry.views) {
|
||||
test(`${view}: ${row.field} = ${JSON.stringify(
|
||||
entry.value,
|
||||
)}`, async () => {
|
||||
await expect(
|
||||
bootHealth(
|
||||
restoringOnto(view, { [row.field]: entry.value }),
|
||||
),
|
||||
).resolves.toEqual(HEALTHY);
|
||||
const env = await bootPopup(
|
||||
restoringOnto(view, { [row.field]: entry.value }),
|
||||
);
|
||||
expect({
|
||||
errors: env.pageErrors,
|
||||
visible: env.visibleViews(),
|
||||
}).toEqual({
|
||||
errors: [],
|
||||
visible: [entry.restored ? view : "main"],
|
||||
});
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
+108
-7
@@ -1,12 +1,17 @@
|
||||
// Tests for the recovery phrase display (issue #161).
|
||||
//
|
||||
// These cover the parts that do not need a DOM: which wallet types may be
|
||||
// offered the action at all, the exclusion of the screen from the set of
|
||||
// views the popup may reopen onto, and the absence of any path from this
|
||||
// module to the logger. The DOM behaviour it guards — nothing rendered
|
||||
// before the password is accepted, a wrong password revealing nothing, and
|
||||
// the wipe on leaving — is driven against the real popup in a real browser
|
||||
// by tests/e2e/run.js, which is where every other view behaviour is tested.
|
||||
// These cover which wallet types may be offered the action at all, the
|
||||
// exclusion of the screen from the set of views the popup may reopen onto,
|
||||
// the absence of any path from this module to the logger, and, against a
|
||||
// minimal DOM stub, where Back goes after the screen is left by the settings
|
||||
// gear or by its own Back. The rest of the DOM behaviour it guards — nothing rendered before the
|
||||
// password is accepted, a wrong password revealing nothing, and the wipe on
|
||||
// leaving — is driven against the real popup in a real browser by
|
||||
// tests/e2e/run.js, which is where every other view behaviour is tested.
|
||||
|
||||
jest.mock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: jest.fn(),
|
||||
}));
|
||||
|
||||
const fs = require("fs");
|
||||
const path = require("path");
|
||||
@@ -74,6 +79,102 @@ describe("views the popup may reopen onto", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// Just enough document for helpers.showView() and this view: every element
|
||||
// is made on first lookup and keeps what the view writes to it, its click
|
||||
// handler included.
|
||||
function makeDocument() {
|
||||
const els = new Map();
|
||||
function makeElement() {
|
||||
const classes = new Set();
|
||||
const el = {
|
||||
textContent: "",
|
||||
value: "",
|
||||
style: {},
|
||||
classList: {
|
||||
add: (name) => classes.add(name),
|
||||
remove: (name) => classes.delete(name),
|
||||
contains: (name) => classes.has(name),
|
||||
toggle: (name, on) =>
|
||||
on ? classes.add(name) : classes.delete(name),
|
||||
},
|
||||
addEventListener: (name, fn) => {
|
||||
if (name === "click") el.onClick = fn;
|
||||
},
|
||||
};
|
||||
return el;
|
||||
}
|
||||
return {
|
||||
getElementById(id) {
|
||||
// Created on demand by helpers.js; absent on a mainnet popup
|
||||
// that is not a debug build.
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement());
|
||||
return els.get(id);
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
describe("Back from Settings after leaving by the settings gear", () => {
|
||||
// On Settings, opened from Home.
|
||||
function load() {
|
||||
jest.resetModules();
|
||||
globalThis.document = makeDocument();
|
||||
const helpers = loadHelpers();
|
||||
const { state } = require("../src/shared/state");
|
||||
const showPhrase = require("../src/popup/views/showPhrase");
|
||||
showPhrase.init();
|
||||
state.wallets = [{ name: "Wallet 1", type: "hd", addresses: [] }];
|
||||
state.currentView = "settings";
|
||||
state.viewStack = ["main"];
|
||||
return { helpers, state, showPhrase };
|
||||
}
|
||||
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/461: leaving drops the
|
||||
// wallet selection, so Back onto this screen showed a password prompt
|
||||
// that could only answer "No wallet is selected." Taking the screen off
|
||||
// the stack leaves Settings under Settings, and Back must not land there
|
||||
// either (https://git.eeqj.de/sneak/AutistMask/issues/481).
|
||||
test("goes to the screen under Settings", () => {
|
||||
const { helpers, state, showPhrase } = load();
|
||||
|
||||
// Opened from the wallet list in Settings, then left by the gear:
|
||||
// push the current view, then show Settings.
|
||||
showPhrase.show(0);
|
||||
helpers.pushCurrentView();
|
||||
helpers.showView("settings");
|
||||
|
||||
expect(state.viewStack).toEqual(["main", "settings"]);
|
||||
helpers.goBack();
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
// Each round trip leaves one more Settings under Settings.
|
||||
test("goes to the screen under Settings after two round trips", () => {
|
||||
const { helpers, state, showPhrase } = load();
|
||||
for (let i = 0; i < 2; i++) {
|
||||
showPhrase.show(0);
|
||||
helpers.pushCurrentView();
|
||||
helpers.showView("settings");
|
||||
}
|
||||
|
||||
expect(state.viewStack).toEqual(["main", "settings", "settings"]);
|
||||
helpers.goBack();
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
// This Back takes Settings off the stack before the screen is left, so
|
||||
// the stack's top is then the entry Back from Settings will need.
|
||||
test("its own Back button leaves the rest of the stack alone", () => {
|
||||
const { state, showPhrase } = load();
|
||||
showPhrase.show(0);
|
||||
|
||||
globalThis.document.getElementById("btn-show-phrase-back").onClick();
|
||||
|
||||
expect(state.currentView).toBe("settings");
|
||||
expect(state.viewStack).toEqual(["main"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("the phrase cannot reach the logger", () => {
|
||||
const source = fs.readFileSync(
|
||||
path.join(__dirname, "..", "src", "popup", "views", "showPhrase.js"),
|
||||
|
||||
Reference in New Issue
Block a user