Compare commits

..
1 Commits
Author SHA1 Message Date
sneak fc0530cc41 fix: refuse an unsupported method with EIP-1193 code 4200 (closes #279)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 2s
e2e / e2e-firefox (push) Failing after 2s
handleRpc() answered a method it does not implement with
"Unsupported method: <method>" and no code, so a site probing for an
optional method could not tell "not implemented" from "the call failed"
and fall back. It now carries code 4200, which EIP-1193 defines for this
case; the message is unchanged. The provider already passes any code
through to the page.

The new test hands the real background's reply to the provider and
checks the page sees 4200.

Model: opus-5-5
2026-10-04 06:42:16 +00:00
+6 -5
View File
@@ -49,9 +49,9 @@ class StubCustomEvent extends StubEvent {
}
}
// Every code the background emits on the RPC path today, read out of
// src/background/index.js. The provider must not know this list — it passes
// through whatever arrived — but the cases below are the real ones.
// Examples of codes the background emits on the RPC path, read out of
// src/background/index.js. The provider must not know any list of codes — it
// passes through whatever arrived — but the cases below are real ones.
const REJECTED = 4001; // user rejected the request
const UNAUTHORIZED = 4100; // site not connected / wrong address
const UNSUPPORTED_METHOD = 4200; // a method the wallet does not implement
@@ -200,8 +200,9 @@ describe("an EIP-1193 code reaches the page", () => {
expect(err.message).toBe(message);
});
// The provider is not allowed to know the list above: a code added to the
// background later must reach the page without this file being edited.
// The provider is not allowed to know the codes above: any other code,
// including one added to the background later, must reach the page
// without inpage.js being edited.
test("a code the provider has never heard of is passed through", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_accounts" }),