4 Commits
Author SHA1 Message Date
clawbot bb60b399ec test: tighten two checks in the persisted-field harness (closes #379)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
The polarity check now counts only `hostile` and `falsy` values, not a
`hostileRestore` value, which reaches only the views its entry names.
The stale index 5 moves into `hostile` for `selectedWallet` and
`selectedAddress`, as each field's one value still truthy after the
floor.

Each `hostileRestore` entry declares whether its boot lands on its view
or falls back to Home, and the test checks the one view on screen. A
value driven onto every restorable view lists only the views it falls
back on, so a view added later is driven by default.

The header and the README restate the remaining limits as built and say
which boots are held to where the popup lands.

Model: opus-5-5
2026-10-07 11:59:14 +02:00
clawbot 447d714313 fix: show every password error in its own fixed-height line (closes #493)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
The add wallet screen reported a missing, short or mismatched password in
the flash line at the top of the popup, and the private key export,
recovery phrase and delete wallet screens each wrote to a line of their own
above the password field. All four now use showError() and hideError() with
a fixed-height error line below the field, as the send confirmation and
approval screens do. On the add wallet screen the line sits beside the
Import button, which keeps its place at 360x600. The line clears when the
screen is shown again and when the password is tried again. Other add
wallet messages stay in the flash line.

Model: opus-5-5
2026-10-07 10:59:16 +02:00
clawbot 29ba54d5b6 docs: record the pre-1.0 security review in TODO.md (closes #383)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
The security review moves from Next Step to Completed Steps, saying what it
read (the tree at 99292b9), that its ten findings are filed and fixed on next,
which owner decisions it raised are still open, and what it did not cover.
Next Step takes the one Future Steps item, cutting 1.0.0 once the milestone is
empty. Status drops a dated gate result and links the current milestone PR.

Model: opus-5-5
2026-10-07 09:43:07 +02:00
clawbot e3dd0e44da chore: prune landed remote branches (closes #167)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
Eighteen branches on origin that the issue classifies as landed, or
superseded by merged pull requests, were deleted; the evidence for each
is on the issue. Four whose work is not in next are kept: the three
issue 87 error-display branches, reference for issue 493, and
chore/token-list-enrichment, re-created at f7a2437, pending issue 495.
TODO.md records this.

The branch-pruning Future Step had already left TODO.md in the issue 191
rewrite, so only the Completed Steps entry is added.

Model: opus-5-5
2026-10-07 09:09:07 +02:00
13 changed files with 595 additions and 159 deletions
+26 -16
View File
@@ -1263,14 +1263,21 @@ path rather than on the home screen. Read the claim narrowly, as that file
states it: what those boots prove is no structural dereference on the code paths states it: what those boots prove is no structural dereference on the code paths
a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes. a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes.
Not driven: any pairing of values the four slots do not produce, a view only Not driven: any pairing of values the four slots do not produce, a view only
forward navigation opens, anything behind a click, and everything a healthy forward navigation opens, anything behind a click or a timer, and, of what a
profile reaches. Within that boundary the verdict is unconditional — if one of healthy profile reaches, anything beyond its boot onto each view the popup can
those boots leaves the popup unhealthy or off the view it stored, `make check` reopen onto. The fields the router does not read share a slot on each boot, so
fails, including when it takes two corrupted fields at once, because the verdict one of them truthy while another is falsy is reached only where the falsy slot
is the combined boot and the per-field re-boot that names a culprit can only pairs a field that cannot be falsy with one that is. Within that boundary the
decorate the message. So does a field that gains a floor while its row still verdict is unconditional — if one of those boots leaves the popup unhealthy,
claims it has none, and so does a field added to `PERSISTED_FIELDS` with no row `make check` fails, including when it takes two corrupted fields at once,
at all. The per-field justification that used to live in the header of because the verdict is the combined boot and the per-field re-boot that names a
culprit can only decorate the message. The combined boot must also land on the
view it stored, and each value driven only onto the restore path must land on
its view, or fall back to Home, as its row declares; a field the router reads
can legitimately change which view renders, so its own sweep is held to health
alone. `make check` also fails on a field that gains a floor while its row still
claims it has none, and on a field added to `PERSISTED_FIELDS` with no row at
all. The per-field justification that used to live in the header of
`src/shared/stateSchema.js` shipped a false claim in three consecutive changes, `src/shared/stateSchema.js` shipped a false claim in three consecutive changes,
each caught only by a reviewer re-deriving thirty fields by hand. each caught only by a reviewer re-deriving thirty fields by hand.
@@ -1444,14 +1451,17 @@ view would leave a wallet one click from deletion.
without it, the lost-password route on DeleteWallet is the first they without it, the lost-password route on DeleteWallet is the first they
would hear of it. The hint line reserves its height, so switching tabs would hear of it. The hint line reserves its height, so switching tabs
cannot move the password fields under the pointer. cannot move the password fields under the pointer.
- "Import" button - "Import" button, with the error line beside it so that it adds no height
to a screen whose button already starts near the bottom of the popup
- **Transitions**: - **Transitions**:
- "Import" with a valid entry and a matching password of at least 12 - "Import" with a valid entry and a matching password of at least 12
characters → creates the wallet, clears the navigation stack, and → characters → creates the wallet, clears the navigation stack, and →
**Home**. The phrase and xprv modes then scan for further used addresses **Home**. The phrase and xprv modes then scan for further used addresses
and report the count as a flash message. and report the count as a flash message.
- "Import" with an invalid entry, a duplicate wallet or address, or a short - "Import" with a missing, short or mismatched password → full-sentence
or mismatched password → flash message, no screen change error on the error line, no screen change
- "Import" with an invalid entry or a duplicate wallet or address → flash
message, no screen change
- "Back" → previous screen (Welcome, Home, or Settings) - "Back" → previous screen (Welcome, Home, or Settings)
#### AddressDetail (`address`) #### AddressDetail (`address`)
@@ -1490,8 +1500,8 @@ view would leave a wallet one click from deletion.
copy) copy)
- Warning that anyone holding the private key can transfer all funds from - Warning that anyone holding the private key can transfer all funds from
the address the address
- Error line - Password input, error line and "Reveal" button, shown until the key is
- Password input and "Reveal" button, shown until the key is revealed revealed
- The private key on a highlighted background, tap to copy, shown only after - The private key on a highlighted background, tap to copy, shown only after
the password has been accepted the password has been accepted
- **Transitions**: - **Transitions**:
@@ -1829,8 +1839,8 @@ view would leave a wallet one click from deletion.
- Wallet name - Wallet name
- Warning box stating that anyone holding these words can take everything in - Warning box stating that anyone holding these words can take everything in
the wallet, from any device, without the password the wallet, from any device, without the password
- Error line - Password input, error line and "Reveal" button, shown until the password
- Password input + "Reveal" button, shown until the password is accepted is accepted
- The recovery phrase itself, in full and click-to-copy, shown only after a - The recovery phrase itself, in full and click-to-copy, shown only after a
correct password and in place of the password prompt correct password and in place of the password prompt
- **Transitions**: - **Transitions**:
@@ -1859,8 +1869,8 @@ view would leave a wallet one click from deletion.
- "Back" button, "Delete Wallet" heading - "Back" button, "Delete Wallet" heading
- Warning naming the wallet and stating that deletion is permanent and any - Warning naming the wallet and stating that deletion is permanent and any
funds are unrecoverable without the recovery phrase funds are unrecoverable without the recovery phrase
- Error line
- Password input - Password input
- Error line
- "Confirm Delete" button - "Confirm Delete" button
- An underlined "I have lost my password" control - An underlined "I have lost my password" control
- **Transitions**: - **Transitions**:
+63 -24
View File
@@ -23,47 +23,89 @@
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
milestone is in flight on `next`; its `next` -> `main` PR is milestone is in flight on `next`; its `next` -> `main` PR is
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified [#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces `dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them
`dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to against the build's own receipt to hold exactly the regular files and symlinks
hold exactly the regular files and symlinks that build emitted, with `DEBUG` that build emitted.
compiled off.
The backlog lives on the The backlog lives on the
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is [Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
authoritative; this file does not duplicate it. Full policy file set present. authoritative; this file does not duplicate it. Full policy file set present.
Real-browser end-to-end suites (`make test-e2e` for Chrome, Real-browser end-to-end suites (`make test-e2e` for Chrome,
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does `make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the
static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml`
of them on every push. runs both of them on every push.
# Next Step # Next Step
Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC Cut 1.0.0 once the
input validation) before any 1.0rc tag. Individual filed issues are parts of it, [1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty,
but the review is broader than any of them. then continue tagging as milestones land.
# Completed Steps # Completed Steps
- 2026-10-07: Two holes in what `tests/persistedFieldContract.test.js` checks
are closed ([#379](https://git.eeqj.de/sneak/AutistMask/issues/379)). The
check that every swept field is driven both truthy and falsy counts only
`hostile` and `falsy` values, which the sweep drives onto every restorable
view, and no longer a `hostileRestore` value, which reaches only the views its
entry names; the stale index 5 moves into `hostile` for `selectedWallet` and
`selectedAddress`, as the one value of either still truthy after the floor.
Each `hostileRestore` entry declares whether its boot lands on its view or
falls back to Home, and is held to it. The limits that remain, fields that
share a slot on one boot and anything no stored record reaches by itself, are
restated as built in the file's header and the README, which now also say
which boots are held to where the popup lands and that a healthy profile is
booted onto every restorable view.
- 2026-10-07: Every password error in the popup is shown the same way
([#493](https://git.eeqj.de/sneak/AutistMask/issues/493)): with `showError()`
and `hideError()` in a fixed-height error line below the password field, as
the send confirmation and approval screens already did. The add wallet screen
showed a missing, short or mismatched password in the flash line, and the
private key export, recovery phrase and delete wallet screens each had a line
of their own above the field. On the add wallet screen the line sits beside
the Import button, so the button stays where it was at 360x600. Each line
clears when the screen is shown again and when the password is tried again.
The add wallet screen's other messages, such as an invalid recovery phrase, a
duplicate wallet and the address scan, stay in the flash line.
`tests/passwordErrorLines.test.js` drives all four screens in the popup.
- 2026-10-07: Pre-1.0 security review of the extension
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
`99292b9` for key handling, the DEBUG mode policy, and what the background
accepts from pages, the configured RPC endpoint and the explorer, with what
the approval screens show from it; the site permission model and storage were
read as well. Its summary on that issue lists ten findings, each filed as its
own issue, and all ten are fixed on `next`; one,
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
Three decisions it raised are still open with the owner: the Argon2id cost for
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
connected site switching the network with no prompt
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
signing as a personal message
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
end-to-end suites were not run, the bundled phishing blocklist and token list
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
taken as audited, and nothing was tried against a real network with real funds
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
independent second check of each finding did not run; the findings rest on the
reviewer's own reading of the code.
- 2026-10-07: Stale branches pruned from `origin` - 2026-10-07: Stale branches pruned from `origin`
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue ([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
classifies each branch it lists, with the evidence. The seventeen still on classifies each branch it lists, with the evidence. The eighteen still on
`origin` that it classifies as landed, or superseded by a merged pull request, `origin` that it classifies as landed, or superseded by merged pull requests,
were deleted. `feat/message-signing` and `fix/59-transaction-view-ui-policies` were deleted. `feat/message-signing` and `fix/59-transaction-view-ui-policies`
had been deleted on 2026-09-09; both landed and stay deleted. Five are kept had been deleted on 2026-09-09; both landed and stay deleted. Four are kept
because their work is not in `next`: `fix/consistent-error-display`, because their work is not in `next`: `fix/consistent-error-display`,
`fix/87-consistent-error-display` and `fix/87-consistent-error-display-v2`, `fix/87-consistent-error-display` and `fix/87-consistent-error-display-v2`,
the change for [#87](https://git.eeqj.de/sneak/AutistMask/issues/87) that the change for [#87](https://git.eeqj.de/sneak/AutistMask/issues/87) that
never landed, as reference for never landed, as reference for
[#493](https://git.eeqj.de/sneak/AutistMask/issues/493); [#493](https://git.eeqj.de/sneak/AutistMask/issues/493); and
`feature/show-private-key`, whose README clipboard policy section was the
reference for [#492](https://git.eeqj.de/sneak/AutistMask/issues/492); and
`chore/token-list-enrichment`, deleted on 2026-09-09 and re-created at `chore/token-list-enrichment`, deleted on 2026-09-09 and re-created at
`f7a2437`, whose `scripts/` tooling waits on `f7a2437`, whose `scripts/` tooling waits on
[#495](https://git.eeqj.de/sneak/AutistMask/issues/495). Afterwards [#495](https://git.eeqj.de/sneak/AutistMask/issues/495).
`git ls-remote --heads origin` showed `main`, `next`, these five, and
`issue-167-prune-branches`, the head of
[#491](https://git.eeqj.de/sneak/AutistMask/pulls/491).
- 2026-10-07: The README says that the wallet never clears the clipboard after - 2026-10-07: The README says that the wallet never clears the clipboard after
the private key or the recovery phrase is copied, and why the private key or the recovery phrase is copied, and why
@@ -1892,6 +1934,3 @@ but the review is broader than any of them.
Only work that has no issue of its own belongs here; everything else is on the Only work that has no issue of its own belongs here; everything else is on the
tracker. tracker.
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
land.
+30 -20
View File
@@ -207,12 +207,22 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg" class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
/> />
</div> </div>
<button <!-- The error line sits beside Import, not above it: at
id="btn-add-wallet-confirm" 360x600 the button already starts near the bottom of
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer" the popup, and a line of its own would push it below
> the fold. The longest error fits on one line here. -->
Import <div class="flex items-center gap-2">
</button> <button
id="btn-add-wallet-confirm"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
>
Import
</button>
<div
id="add-wallet-password-error"
class="text-xs min-h-[1.25rem] invisible"
></div>
</div>
</div> </div>
<!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ --> <!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ -->
@@ -396,10 +406,6 @@
Warning: anyone with this private key can access and Warning: anyone with this private key can access and
transfer all funds from this address. Never share it. transfer all funds from this address. Never share it.
</p> </p>
<div
id="export-privkey-flash"
class="text-xs mb-2 min-h-[1.25rem] invisible"
></div>
<div id="export-privkey-password-section" class="mb-2"> <div id="export-privkey-password-section" class="mb-2">
<label class="block mb-1">Password</label> <label class="block mb-1">Password</label>
<input <input
@@ -408,9 +414,13 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg" class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
placeholder="Enter your password to continue" placeholder="Enter your password to continue"
/> />
<div
id="export-privkey-password-error"
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
></div>
<button <button
id="btn-export-privkey-confirm" id="btn-export-privkey-confirm"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2" class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
> >
Reveal Reveal
</button> </button>
@@ -1116,10 +1126,6 @@
<strong id="delete-wallet-name"></strong> is permanent. Any <strong id="delete-wallet-name"></strong> is permanent. Any
funds will be unrecoverable without your recovery phrase. funds will be unrecoverable without your recovery phrase.
</p> </p>
<div
id="delete-wallet-flash"
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
></div>
<div class="mb-2"> <div class="mb-2">
<label class="block mb-1">Password</label> <label class="block mb-1">Password</label>
<input <input
@@ -1129,6 +1135,10 @@
placeholder="Enter your password to confirm" placeholder="Enter your password to confirm"
/> />
</div> </div>
<div
id="delete-wallet-password-error"
class="text-xs mb-2 min-h-[1.25rem] invisible"
></div>
<button <button
id="btn-delete-wallet-confirm" id="btn-delete-wallet-confirm"
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer" class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
@@ -1273,10 +1283,6 @@
this wallet, from any device, without your password. Never this wallet, from any device, without your password. Never
type them into a website and never show them to anyone. type them into a website and never show them to anyone.
</div> </div>
<div
id="show-phrase-flash"
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
></div>
<div id="show-phrase-password-section" class="mb-2"> <div id="show-phrase-password-section" class="mb-2">
<label class="block mb-1">Password</label> <label class="block mb-1">Password</label>
<input <input
@@ -1285,9 +1291,13 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg" class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
placeholder="Enter your password to continue" placeholder="Enter your password to continue"
/> />
<div
id="show-phrase-password-error"
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
></div>
<button <button
id="btn-show-phrase-reveal" id="btn-show-phrase-reveal"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2" class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
> >
Reveal Reveal
</button> </button>
+12 -4
View File
@@ -2,6 +2,8 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
goBack, goBack,
clearViewStack, clearViewStack,
onViewLeave, onViewLeave,
@@ -98,6 +100,7 @@ function clear() {
$("add-wallet-password").value = ""; $("add-wallet-password").value = "";
$("add-wallet-password-confirm").value = ""; $("add-wallet-password-confirm").value = "";
$("add-wallet-phrase-warning").style.visibility = "hidden"; $("add-wallet-phrase-warning").style.visibility = "hidden";
hideError("add-wallet-password-error");
} }
// Each wallet has its own password (its own encryptedSecret), so adding a // Each wallet has its own password (its own encryptedSecret), so adding a
@@ -125,15 +128,18 @@ function validatePassword() {
const pw = $("add-wallet-password").value; const pw = $("add-wallet-password").value;
const pw2 = $("add-wallet-password-confirm").value; const pw2 = $("add-wallet-password-confirm").value;
if (!pw) { if (!pw) {
showFlash("Please choose a password."); showError("add-wallet-password-error", "Please choose a password.");
return null; return null;
} }
if (pw.length < 12) { if (pw.length < 12) {
showFlash("Password must be at least 12 characters."); showError(
"add-wallet-password-error",
"Password must be at least 12 characters.",
);
return null; return null;
} }
if (pw !== pw2) { if (pw !== pw2) {
showFlash("Passwords do not match."); showError("add-wallet-password-error", "Passwords do not match.");
return null; return null;
} }
return pw; return pw;
@@ -342,8 +348,10 @@ function init(ctx) {
$("add-wallet-phrase-warning").style.visibility = "visible"; $("add-wallet-phrase-warning").style.visibility = "visible";
}); });
// Import / confirm // Import / confirm. Each press starts with no password error on screen:
// validatePassword() puts it back if the password is still wrong.
$("btn-add-wallet-confirm").addEventListener("click", async () => { $("btn-add-wallet-confirm").addEventListener("click", async () => {
hideError("add-wallet-password-error");
if (currentMode === "mnemonic") { if (currentMode === "mnemonic") {
await importMnemonic(ctx); await importMnemonic(ctx);
} else if (currentMode === "privkey") { } else if (currentMode === "privkey") {
+16 -11
View File
@@ -2,6 +2,8 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
goBack, goBack,
clearViewStack, clearViewStack,
onViewLeave, onViewLeave,
@@ -55,8 +57,7 @@ function confirmKey(name) {
function clear() { function clear() {
deleteWalletIndex = null; deleteWalletIndex = null;
$("delete-wallet-password").value = ""; $("delete-wallet-password").value = "";
$("delete-wallet-flash").textContent = ""; hideError("delete-wallet-password-error");
$("delete-wallet-flash").style.visibility = "hidden";
} }
// The lost-password screen holds no secret — a wallet name is not one — // The lost-password screen holds no secret — a wallet name is not one —
@@ -232,19 +233,22 @@ function init(_ctx) {
$("btn-delete-wallet-confirm").addEventListener("click", async () => { $("btn-delete-wallet-confirm").addEventListener("click", async () => {
const pw = $("delete-wallet-password").value; const pw = $("delete-wallet-password").value;
if (!pw) { if (!pw) {
$("delete-wallet-flash").textContent = showError(
"Please enter your password."; "delete-wallet-password-error",
$("delete-wallet-flash").style.visibility = "visible"; "Please enter your password.",
);
return; return;
} }
if (deleteWalletIndex === null) { if (deleteWalletIndex === null) {
$("delete-wallet-flash").textContent = showError(
"No wallet selected for deletion."; "delete-wallet-password-error",
$("delete-wallet-flash").style.visibility = "visible"; "No wallet selected for deletion.",
);
return; return;
} }
hideError("delete-wallet-password-error");
const btn = $("btn-delete-wallet-confirm"); const btn = $("btn-delete-wallet-confirm");
btn.disabled = true; btn.disabled = true;
btn.classList.add("text-muted"); btn.classList.add("text-muted");
@@ -256,9 +260,10 @@ function init(_ctx) {
try { try {
await decryptWithPassword(wallet.encryptedSecret, pw); await decryptWithPassword(wallet.encryptedSecret, pw);
} catch { } catch {
$("delete-wallet-flash").textContent = showError(
"That password is incorrect. Please try again."; "delete-wallet-password-error",
$("delete-wallet-flash").style.visibility = "visible"; "That password is incorrect. Please try again.",
);
btn.disabled = false; btn.disabled = false;
btn.classList.remove("text-muted"); btn.classList.remove("text-muted");
return; return;
+13 -12
View File
@@ -20,6 +20,8 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
flashCopyFeedback, flashCopyFeedback,
goBack, goBack,
onViewLeave, onViewLeave,
@@ -56,11 +58,6 @@ function isCurrentReveal(generation) {
); );
} }
function fail(message) {
$("export-privkey-flash").textContent = message;
$("export-privkey-flash").style.visibility = "visible";
}
// Wipe every trace of the key and drop the address selection. Safe to call // Wipe every trace of the key and drop the address selection. Safe to call
// when nothing was ever revealed, and safe to call twice. // when nothing was ever revealed, and safe to call twice.
function clear() { function clear() {
@@ -71,8 +68,7 @@ function clear() {
$("export-privkey-password").value = ""; $("export-privkey-password").value = "";
$("export-privkey-result").classList.add("hidden"); $("export-privkey-result").classList.add("hidden");
$("export-privkey-password-section").classList.remove("hidden"); $("export-privkey-password-section").classList.remove("hidden");
$("export-privkey-flash").textContent = ""; hideError("export-privkey-password-error");
$("export-privkey-flash").style.visibility = "hidden";
} }
function show(walletIdx, addrIdx) { function show(walletIdx, addrIdx) {
@@ -112,15 +108,19 @@ function show(walletIdx, addrIdx) {
async function reveal() { async function reveal() {
const password = $("export-privkey-password").value; const password = $("export-privkey-password").value;
if (!password) { if (!password) {
fail("Please enter your password."); showError(
"export-privkey-password-error",
"Please enter your password.",
);
return; return;
} }
if (walletIndex === null) { if (walletIndex === null) {
fail("No address is selected."); showError("export-privkey-password-error", "No address is selected.");
return; return;
} }
const wallet = state.wallets[walletIndex]; const wallet = state.wallets[walletIndex];
hideError("export-privkey-password-error");
const btn = $("btn-export-privkey-confirm"); const btn = $("btn-export-privkey-confirm");
btn.disabled = true; btn.disabled = true;
btn.classList.add("text-muted"); btn.classList.add("text-muted");
@@ -140,11 +140,12 @@ async function reveal() {
$("export-privkey-password-section").classList.add("hidden"); $("export-privkey-password-section").classList.add("hidden");
$("export-privkey-value").textContent = signer.privateKey; $("export-privkey-value").textContent = signer.privateKey;
$("export-privkey-result").classList.remove("hidden"); $("export-privkey-result").classList.remove("hidden");
$("export-privkey-flash").textContent = "";
$("export-privkey-flash").style.visibility = "hidden";
} catch { } catch {
if (!isCurrentReveal(generation)) return; if (!isCurrentReveal(generation)) return;
fail("That password is incorrect. Please try again."); showError(
"export-privkey-password-error",
"That password is incorrect. Please try again.",
);
} finally { } finally {
btn.disabled = false; btn.disabled = false;
btn.classList.remove("text-muted"); btn.classList.remove("text-muted");
+14 -13
View File
@@ -21,6 +21,8 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
flashCopyFeedback, flashCopyFeedback,
goBack, goBack,
onViewLeave, onViewLeave,
@@ -52,11 +54,6 @@ function isCurrentReveal(generation) {
); );
} }
function fail(message) {
$("show-phrase-flash").textContent = message;
$("show-phrase-flash").style.visibility = "visible";
}
// Wipe every trace of the phrase and drop the wallet selection. Safe to // Wipe every trace of the phrase and drop the wallet selection. Safe to
// call when nothing was ever revealed, and safe to call twice. // call when nothing was ever revealed, and safe to call twice.
function clear() { function clear() {
@@ -66,8 +63,7 @@ function clear() {
$("show-phrase-password").value = ""; $("show-phrase-password").value = "";
$("show-phrase-result").classList.add("hidden"); $("show-phrase-result").classList.add("hidden");
$("show-phrase-password-section").classList.remove("hidden"); $("show-phrase-password-section").classList.remove("hidden");
$("show-phrase-flash").textContent = ""; hideError("show-phrase-password-error");
$("show-phrase-flash").style.visibility = "hidden";
} }
function show(walletIdx) { function show(walletIdx) {
@@ -90,19 +86,23 @@ function show(walletIdx) {
async function reveal() { async function reveal() {
const password = $("show-phrase-password").value; const password = $("show-phrase-password").value;
if (!password) { if (!password) {
fail("Please enter your password."); showError("show-phrase-password-error", "Please enter your password.");
return; return;
} }
if (walletIndex === null) { if (walletIndex === null) {
fail("No wallet is selected."); showError("show-phrase-password-error", "No wallet is selected.");
return; return;
} }
const wallet = state.wallets[walletIndex]; const wallet = state.wallets[walletIndex];
if (!walletHasRecoveryPhrase(wallet)) { if (!walletHasRecoveryPhrase(wallet)) {
fail("This wallet does not have a recovery phrase."); showError(
"show-phrase-password-error",
"This wallet does not have a recovery phrase.",
);
return; return;
} }
hideError("show-phrase-password-error");
const btn = $("btn-show-phrase-reveal"); const btn = $("btn-show-phrase-reveal");
btn.disabled = true; btn.disabled = true;
btn.classList.add("text-muted"); btn.classList.add("text-muted");
@@ -120,13 +120,14 @@ async function reveal() {
$("show-phrase-password-section").classList.add("hidden"); $("show-phrase-password-section").classList.add("hidden");
$("show-phrase-value").textContent = phrase; $("show-phrase-value").textContent = phrase;
$("show-phrase-result").classList.remove("hidden"); $("show-phrase-result").classList.remove("hidden");
$("show-phrase-flash").textContent = "";
$("show-phrase-flash").style.visibility = "hidden";
} catch { } catch {
if (!isCurrentReveal(generation)) return; if (!isCurrentReveal(generation)) return;
// Deliberately not the caught error: the message is fixed so that // Deliberately not the caught error: the message is fixed so that
// nothing derived from the ciphertext or the attempt can surface. // nothing derived from the ciphertext or the attempt can surface.
fail("That password is incorrect. Please try again."); showError(
"show-phrase-password-error",
"That password is incorrect. Please try again.",
);
} finally { } finally {
btn.disabled = false; btn.disabled = false;
btn.classList.remove("text-muted"); btn.classList.remove("text-muted");
+2
View File
@@ -39,6 +39,8 @@ jest.doMock("../src/popup/views/helpers", () => ({
$: element, $: element,
showView: () => {}, showView: () => {},
showFlash: () => {}, showFlash: () => {},
showError: () => {},
hideError: () => {},
goBack: () => {}, goBack: () => {},
clearViewStack: () => {}, clearViewStack: () => {},
onViewLeave: () => {}, onViewLeave: () => {},
+1 -1
View File
@@ -253,7 +253,7 @@ describe("reaching the screen", () => {
const { decryptWithPassword } = require("../src/shared/vault"); const { decryptWithPassword } = require("../src/shared/vault");
decryptWithPassword.mockRejectedValue(new Error("nope")); decryptWithPassword.mockRejectedValue(new Error("nope"));
await click("btn-delete-wallet-confirm"); await click("btn-delete-wallet-confirm");
expect(node("delete-wallet-flash").textContent).toBe( expect(node("delete-wallet-password-error").textContent).toBe(
"That password is incorrect. Please try again.", "That password is incorrect. Please try again.",
); );
}); });
+109 -6
View File
@@ -809,7 +809,7 @@ async function secretScreenState(page, view) {
return page.evaluate( return page.evaluate(
(v) => ({ (v) => ({
value: document.getElementById(v + "-value").textContent, value: document.getElementById(v + "-value").textContent,
error: document.getElementById(v + "-flash").textContent, error: document.getElementById(v + "-password-error").textContent,
html: document.getElementById("view-" + v).innerHTML, html: document.getElementById("view-" + v).innerHTML,
resultHidden: document resultHidden: document
.getElementById(v + "-result") .getElementById(v + "-result")
@@ -906,7 +906,8 @@ test("a wrong password reveals nothing (#161)", async (env) => {
await env.page.click("#btn-show-phrase-reveal"); await env.page.click("#btn-show-phrase-reveal");
await env.page.waitForFunction( await env.page.waitForFunction(
() => () =>
document.getElementById("show-phrase-flash").textContent.length > 0, document.getElementById("show-phrase-password-error").textContent
.length > 0,
null, null,
{ timeout: 60000 }, { timeout: 60000 },
); );
@@ -1993,13 +1994,14 @@ test("an over-long flash message keeps to one line (#252)", async (env) => {
// Every screen that asks for a password reserves room for one line of error. // Every screen that asks for a password reserves room for one line of error.
// The two on the dApp approval screens also have a border and padding, which // The two on the dApp approval screens also have a border and padding, which
// that reserved height has to cover too. // that reserved height has to cover too. The add wallet screen's line sits
// beside its button rather than above it, and has its own test below.
const PASSWORD_ERROR_CONTAINERS = [ const PASSWORD_ERROR_CONTAINERS = [
"approve-tx-error", "approve-tx-error",
"approve-sign-error", "approve-sign-error",
"export-privkey-flash", "export-privkey-password-error",
"show-phrase-flash", "show-phrase-password-error",
"delete-wallet-flash", "delete-wallet-password-error",
"confirm-tx-password-error", "confirm-tx-password-error",
]; ];
@@ -2064,6 +2066,107 @@ test("a password error moves nothing on any screen (#297)", async (env) => {
} }
}); });
// ------------------------------------------ add wallet Import button (#493)
// At 360x600 the add wallet screen's Import button already starts near the
// bottom of the popup, so its password error line sits beside the button
// rather than above it. Measures the button and the line empty and again
// filled with the longest error addWallet.js puts there. Runs in the page.
function measureImportButton() {
const button = document.getElementById("btn-add-wallet-confirm");
const line = document.getElementById("add-wallet-password-error");
const measure = () => {
const b = button.getBoundingClientRect();
const l = line.getBoundingClientRect();
return {
buttonTop: b.top + window.scrollY,
buttonBottom: b.bottom + window.scrollY,
lineTop: l.top + window.scrollY,
lineBottom: l.bottom + window.scrollY,
};
};
const empty = measure();
line.textContent = "Password must be at least 12 characters.";
line.style.visibility = "visible";
const filled = measure();
line.textContent = "";
line.style.visibility = "hidden";
return { empty, filled };
}
test("the add wallet password error leaves Import where it was (#493)", async (env) => {
const page = await openPopup(env.ctx, env.popupUrl);
try {
await page.setViewportSize(POPUP_VIEWPORT);
// Brought up by toggling classes, as in the test above. The note
// addWallet.js shows once a wallet exists is the only part of the
// screen that differs between the first wallet and a later one.
await page.evaluate(() => {
const screen = document.getElementById("view-add-wallet");
for (const view of document.querySelectorAll(".view")) {
view.classList.toggle("hidden", view !== screen);
}
});
for (const walletExists of [false, true]) {
await page.evaluate(
(shown) =>
document
.getElementById("add-wallet-separate-password-note")
.classList.toggle("hidden", !shown),
walletExists,
);
for (const tab of ["tab-mnemonic", "tab-privkey", "tab-xprv"]) {
await page.click("#" + tab);
const { empty, filled } =
await page.evaluate(measureImportButton);
const where =
"#" +
tab +
(walletExists
? " with a wallet already added"
: " for the first wallet");
// Printed pass or fail, as the dust threshold test does.
console.log(
"# add wallet Import top, " +
where +
": " +
empty.buttonTop +
"px",
);
for (const m of [empty, filled]) {
assert(
m.lineTop >= m.buttonTop &&
m.lineBottom <= m.buttonBottom,
"the error line on " +
where +
" does not fit beside Import, so it adds height: " +
JSON.stringify(m),
);
}
assert(
filled.buttonTop === empty.buttonTop,
"Import moved " +
(filled.buttonTop - empty.buttonTop) +
"px when the error appeared on " +
where,
);
if (!walletExists) {
assert(
empty.buttonTop < POPUP_VIEWPORT.height,
"Import starts at " +
empty.buttonTop +
"px on " +
where +
", below the fold",
);
}
}
}
} finally {
await page.close();
}
});
// --------------------------------------------- confirmation screen (#238) // --------------------------------------------- confirmation screen (#238)
// //
// The screen that decides what gets signed. The arithmetic underneath it // The screen that decides what gets signed. The arithmetic underneath it
+6 -4
View File
@@ -207,7 +207,7 @@ describe("a decrypt still running when the screen is left", () => {
}); });
// Same hole on the failure path: a wrong-password error written after // Same hole on the failure path: a wrong-password error written after
// the wipe would restore the flash line on a screen the user has left. // the wipe would restore the error line on a screen the user has left.
test("never writes the failure message either", async () => { test("never writes the failure message either", async () => {
const { helpers, vault, exportPrivkey } = load(); const { helpers, vault, exportPrivkey } = load();
exportPrivkey.show(0, 0); exportPrivkey.show(0, 0);
@@ -217,8 +217,10 @@ describe("a decrypt still running when the screen is left", () => {
reveal.reject(new Error("decryption failed")); reveal.reject(new Error("decryption failed"));
await reveal.pending; await reveal.pending;
expect(node("export-privkey-flash").textContent).toBe(""); expect(node("export-privkey-password-error").textContent).toBe("");
expect(node("export-privkey-flash").style.visibility).toBe("hidden"); expect(node("export-privkey-password-error").style.visibility).toBe(
"hidden",
);
}); });
}); });
@@ -260,7 +262,7 @@ describe("a reveal that is not interrupted", () => {
await reveal.pending; await reveal.pending;
expect(node("export-privkey-value").textContent).toBe(""); expect(node("export-privkey-value").textContent).toBe("");
expect(node("export-privkey-flash").textContent).toBe( expect(node("export-privkey-password-error").textContent).toBe(
"That password is incorrect. Please try again.", "That password is incorrect. Please try again.",
); );
}); });
+159
View File
@@ -0,0 +1,159 @@
// Every screen that asks for a password shows a password error the same way:
// through showError() and hideError() in src/popup/views/helpers.js, in a
// fixed-height error line below the password field, and never in the flash
// line at the top of the popup
// (https://git.eeqj.de/sneak/AutistMask/issues/493). These boot the real popup
// over src/popup/index.html, so each error line has to exist in the markup,
// and check that the error appears in it and clears again.
jest.mock("../src/shared/vault", () => ({
decryptWithPassword: jest.fn(),
encryptWithPassword: jest.fn(),
}));
const {
bootPopup,
cleanupPopup,
unversionedValidProfile,
} = require("./support/popupBoot");
const PASSWORD = "correct horse battery staple";
const WRONG_PASSWORD = "That password is incorrect. Please try again.";
afterEach(() => {
cleanupPopup();
});
// The error line as the user sees it.
function errorLine(page, id) {
return {
inMarkup: page.document.authoredIds.has(id),
text: page.text(id),
visibility: page.node(id).style.visibility,
};
}
function shown(text) {
return { inMarkup: true, text, visibility: "visible" };
}
const cleared = { inMarkup: true, text: "", visibility: "hidden" };
describe("the add wallet screen", () => {
const ERROR = "add-wallet-password-error";
// First run: Welcome, "Add wallet", then the die for a valid phrase.
async function openAddWallet() {
const page = await bootPopup(undefined);
await page.click("btn-welcome-add");
await page.click("btn-generate-phrase");
return page;
}
function setPasswords(page, password, confirm) {
page.node("add-wallet-password").value = password;
page.node("add-wallet-password-confirm").value = confirm;
}
test("shows a password problem below the password fields, and clears it on the next press", async () => {
const page = await openAddWallet();
setPasswords(page, "short", "short");
await page.click("btn-add-wallet-confirm");
expect(errorLine(page, ERROR)).toEqual(
shown("Password must be at least 12 characters."),
);
expect(page.text("flash-msg")).toBe("");
// The password is fixed and the phrase emptied: the password error
// goes, and the phrase problem is still reported in the flash line.
setPasswords(page, PASSWORD, PASSWORD);
page.node("wallet-mnemonic").value = "";
await page.click("btn-add-wallet-confirm");
expect(errorLine(page, ERROR)).toEqual(cleared);
expect(page.text("flash-msg")).toBe(
"Enter a recovery phrase, or press the die.",
);
// Leaving clears the flash line and stops its timer, which would
// otherwise fire after this page is gone.
await page.click("btn-add-wallet-back");
});
test("clears the error when the screen is shown again", async () => {
const page = await openAddWallet();
setPasswords(page, PASSWORD, PASSWORD + " typo");
await page.click("btn-add-wallet-confirm");
expect(errorLine(page, ERROR)).toEqual(
shown("Passwords do not match."),
);
await page.click("btn-add-wallet-back");
await page.click("btn-welcome-add");
expect(errorLine(page, ERROR)).toEqual(cleared);
});
});
describe.each([
{
screen: "the private key export screen",
open: () => require("../src/popup/views/exportPrivkey").show(0, 0),
field: "export-privkey-password",
button: "btn-export-privkey-confirm",
error: "export-privkey-password-error",
},
{
screen: "the recovery phrase screen",
open: () => require("../src/popup/views/showPhrase").show(0),
field: "show-phrase-password",
button: "btn-show-phrase-reveal",
error: "show-phrase-password-error",
},
{
screen: "the delete wallet screen",
open: () => require("../src/popup/views/deleteWallet").show(0),
field: "delete-wallet-password",
button: "btn-delete-wallet-confirm",
error: "delete-wallet-password-error",
},
])("$screen", ({ open, field, button, error }) => {
// Opens the screen and enters a password the vault rejects.
async function failedAttempt() {
const page = await bootPopup(unversionedValidProfile());
open();
const { decryptWithPassword } = require("../src/shared/vault");
decryptWithPassword.mockRejectedValue(new Error("wrong password"));
page.node(field).value = "not the password";
await page.click(button);
return { page, decryptWithPassword };
}
test("shows a wrong password below the password field", async () => {
const { page } = await failedAttempt();
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
});
test("clears the error while the next password is checked", async () => {
const { page, decryptWithPassword } = await failedAttempt();
let rejectDecrypt;
decryptWithPassword.mockReturnValue(
new Promise((resolve, reject) => {
rejectDecrypt = reject;
}),
);
page.node(field).value = "another guess";
const pressed = page.click(button);
await page.settle();
expect(errorLine(page, error)).toEqual(cleared);
rejectDecrypt(new Error("wrong password"));
await pressed;
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
});
test("clears the error when the screen is shown again", async () => {
const { page } = await failedAttempt();
open();
expect(errorLine(page, error)).toEqual(cleared);
});
});
+144 -48
View File
@@ -49,22 +49,37 @@
// every path a stored record takes, and the difference is the whole of what // every path a stored record takes, and the difference is the whole of what
// this file does not cover: // this file does not cover:
// //
// - Only the values in the table, in the SLOT arrangement below: four value // - Only the values in the table, in the SLOT arrangement below. On the
// combinations per view, not the product of twelve fields. A dereference // restore path the twelve fields the router does not read are corrupted
// reached only under a pairing no slot produces is not driven at all. // together, every field on the same slot, so a view gets four value
// - Only what a stored record reaches by ITSELF. A view only forward // combinations of them, not their product. A branch entered only when one
// navigation opens, and anything behind a click, is not driven. // of them is truthy and another falsy is reached only where the falsy
// - Nothing about the paths a HEALTHY profile takes, which is most of the // slot happens to pair a field that cannot be falsy with one that is.
// popup. This file is a floor under one defect class, not a proof about // Each field the router reads is corrupted alone, over an otherwise
// the renderers. // well-formed record.
// - Only what a stored record reaches by ITSELF, as the boot renders it. A
// view only forward navigation opens, anything behind a click, and
// anything behind a timer (bootPopup() records every interval, and this
// file never runs one) is not driven.
// - Of the paths a HEALTHY profile takes, only its boot onto each
// restorable view ("the base profile the sweep corrupts" below). The rest
// of the popup is not covered: this file is a floor under one defect
// class, not a proof about the renderers.
// //
// Within that boundary it is unconditional: if one of these boots leaves the // Within that boundary it is unconditional: if a boot that corrupts a field
// popup unhealthy or off the view it stored, this file goes red — including // leaves the popup unhealthy, this file goes red — including when it takes
// when it takes two corrupted fields at once, because the verdict is the // two corrupted fields at once, because the verdict is the combined boot
// combined boot itself and the per-field re-boot below can only decorate the // itself and the per-field re-boot below can only decorate the message. That
// message. That last part is the one thing an earlier version got wrong: it // last part is the one thing an earlier version got wrong: it asserted on the
// asserted on the per-field list, so an observed dead popup that no single // per-field list, so an observed dead popup that no single field reproduced
// field reproduced was reported green. // was reported green.
//
// Where the popup lands is held for some of those boots and not others. The
// combined boot must land on the view it stored, and each `hostileRestore`
// value must land on its view, or fall back to Home, as its entry declares.
// The boots in "a hostile routing value restoring onto" are held to health
// alone, because a value in a field the router reads legitimately changes
// which view renders; so are the boots onto Home, which store no view.
// //
// Booting every field separately at every value would be several hundred boots // Booting every field separately at every value would be several hundred boots
// and most of the suite's budget; this is forty-four. Widening it further is // and most of the suite's budget; this is forty-four. Widening it further is
@@ -128,7 +143,11 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
// list short and pointed. `floorOnly` is extra values checked against the // list short and pointed. `floorOnly` is extra values checked against the
// floor alone, which is pure and free. `hostileRestore` is extra values driven // floor alone, which is pure and free. `hostileRestore` is extra values driven
// through the restore path only, for a value that means nothing until a // through the restore path only, for a value that means nothing until a
// particular branch's gate has let it past. // particular branch's gate has let it past. Each of its entries names the
// `views` it is driven onto and declares whether the boot lands on them
// (`restored: true`) or falls back to Home (`restored: false`), so a value
// written for one renderer cannot stop reaching it unnoticed. A value driven
// onto every restorable view is written with everyRestorableView() below.
// //
// `falsy` is the other POLARITY of a swept field, driven for the same reason. // `falsy` is the other POLARITY of a swept field, driven for the same reason.
// It is not a value src/ never writes — for three of these fields it is the // It is not a value src/ never writes — for three of these fields it is the
@@ -139,6 +158,23 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
// falsy value stored under that field comes back TRUTHY from the floor, so no // falsy value stored under that field comes back TRUTHY from the floor, so no
// `!state.x` branch is reachable from a stored record at all. // `!state.x` branch is reachable from a stored record at all.
// The `hostileRestore` entries for a value driven onto every restorable view:
// it falls back to Home on the views listed in `fallsBackOn` and lands on every
// other one, so a view added to RESTORABLE_VIEWS is driven, and expected to
// land, without editing the row.
function everyRestorableView(value, fallsBackOn) {
return [
{ value, views: fallsBackOn, restored: false },
{
value,
views: [...RESTORABLE_VIEWS].filter(
(view) => !fallsBackOn.includes(view),
),
restored: true,
},
];
}
const CONTRACT = [ const CONTRACT = [
{ {
field: "wallets", field: "wallets",
@@ -280,28 +316,38 @@ const CONTRACT = [
kind: KIND.SCALAR, kind: KIND.SCALAR,
// The prototype members are the whole point: `wallets["map"]` is // The prototype members are the whole point: `wallets["map"]` is
// TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and // TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and
// `.addresses[…]` throws. A stale INTEGER is the safe case. // `.addresses[…]` throws. A stale INTEGER is the safe case and has to
hostile: ["map", "__proto__", { a: 1 }], // stay so. 5 is one, out of range for the one wallet in the profile,
// and it is also this field's truthy polarity: every other value here
// comes back from the floor as null.
hostile: ["map", "__proto__", { a: 1 }, 5],
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true], floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
holds: isIndexOrNull, holds: isIndexOrNull,
// SCALAR, and swept anyway: the restore path is precisely why this // SCALAR, and swept anyway: the restore path is precisely why this
// field gained a floor, so the sweep is the regression guard on it. // field gained a floor, so the sweep is the regression guard on it.
alsoSweep: true, alsoSweep: true,
routes: true, routes: true,
// A stale INTEGER index, which reaches the restore path by a different // Comes back from the floor as null, which hasValidAddress() reads as
// route from the prototype members above — falsy or out of range // nothing selected: the popup falls back to Home on the five views
// rather than truthy — and has to keep being the safe case. // that need an address, and lands on every other one.
hostileRestore: [{ value: "length" }, { value: 5 }], hostileRestore: everyRestorableView("length", [
"address",
"address-token",
"receive",
"transaction",
"confirm-tx",
]),
}, },
{ {
field: "selectedAddress", field: "selectedAddress",
kind: KIND.SCALAR, kind: KIND.SCALAR,
hostile: ["map", "__proto__", { a: 1 }], // 5 for the same reason as in selectedWallet: a stale index, and the
// one value here still truthy after the floor.
hostile: ["map", "__proto__", { a: 1 }, 5],
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true], floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
holds: isIndexOrNull, holds: isIndexOrNull,
alsoSweep: true, alsoSweep: true,
routes: true, routes: true,
hostileRestore: [{ value: 5 }],
}, },
{ {
field: "currentView", field: "currentView",
@@ -325,7 +371,9 @@ const CONTRACT = [
// container shapes below onto every restorable view; hostileRestore // container shapes below onto every restorable view; hostileRestore
// adds the records that PASS a branch's gate and then hand its // adds the records that PASS a branch's gate and then hand its
// renderer something it dereferences, which is where the entries are // renderer something it dereferences, which is where the entries are
// actually decided. // actually decided. The guard refuses each single-view record below,
// so each is declared to fall back to Home: one that started landing
// would be reaching the renderer it was written against.
hostile: [42, "notarecord", { a: 1 }, [1, 2]], hostile: [42, "notarecord", { a: 1 }, [1, 2]],
// `structuredClone(saved.viewData || {})`: the container is never falsy // `structuredClone(saved.viewData || {})`: the container is never falsy
// in state whatever was stored, so no `!state.viewData` branch exists to // in state whatever was stored, so no `!state.viewData` branch exists to
@@ -334,11 +382,20 @@ const CONTRACT = [
hostileRestore: [ hostileRestore: [
// success-tx passes on `data.hash`, and renderSuccess() then calls // success-tx passes on `data.hash`, and renderSuccess() then calls
// toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase(). // toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase().
{ value: { hash: "0x1" }, views: ["success-tx"] }, {
{ value: { hash: "0x1", to: 42 }, views: ["success-tx"] }, value: { hash: "0x1" },
views: ["success-tx"],
restored: false,
},
{
value: { hash: "0x1", to: 42 },
views: ["success-tx"],
restored: false,
},
{ {
value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } }, value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } },
views: ["success-tx"], views: ["success-tx"],
restored: false,
}, },
{ {
value: { value: {
@@ -347,12 +404,25 @@ const CONTRACT = [
decoded: { details: [{ address: 42 }] }, decoded: { details: [{ address: 42 }] },
}, },
views: ["success-tx"], views: ["success-tx"],
restored: false,
}, },
// error-tx passes on `data.message`, same dereference. // error-tx passes on `data.message`, same dereference.
{ value: { message: "boom" }, views: ["error-tx"] }, {
{ value: { message: "boom", to: 42 }, views: ["error-tx"] }, value: { message: "boom" },
views: ["error-tx"],
restored: false,
},
{
value: { message: "boom", to: 42 },
views: ["error-tx"],
restored: false,
},
// transaction passes on `data.tx`. // transaction passes on `data.tx`.
{ value: { tx: { hash: "0x1" } }, views: ["transaction"] }, {
value: { tx: { hash: "0x1" } },
views: ["transaction"],
restored: false,
},
{ {
value: { value: {
tx: { tx: {
@@ -363,9 +433,14 @@ const CONTRACT = [
}, },
}, },
views: ["transaction"], views: ["transaction"],
restored: false,
}, },
// confirm-tx passes on `data.pendingTx`. // confirm-tx passes on `data.pendingTx`.
{ value: { pendingTx: { amount: "1" } }, views: ["confirm-tx"] }, {
value: { pendingTx: { amount: "1" } },
views: ["confirm-tx"],
restored: false,
},
{ {
value: { value: {
pendingTx: { pendingTx: {
@@ -376,6 +451,7 @@ const CONTRACT = [
}, },
}, },
views: ["confirm-tx"], views: ["confirm-tx"],
restored: false,
}, },
// wait-tx passes on `pendingWait.hash`; restoreWait() has checked // wait-tx passes on `pendingWait.hash`; restoreWait() has checked
// the fields below it since it was written, and this is the // the fields below it since it was written, and this is the
@@ -388,20 +464,29 @@ const CONTRACT = [
}, },
}, },
views: ["wait-tx"], views: ["wait-tx"],
restored: false,
}, },
// A record that passes EVERY branch's gate at once, driven onto // A record that passes EVERY branch's gate at once, driven onto
// every restorable view: a branch a view does not read must stay // every restorable view: a branch a view does not read must stay
// one it does not read, and each renderer must survive the fields // one it does not read. The five views with a viewData branch
// another branch left behind. // refuse it; every other one renders it, and must survive the
{ // fields every branch left behind.
value: { ...everyRestorableView(
{
hash: "0x1", hash: "0x1",
message: "boom", message: "boom",
tx: { hash: "0x1" }, tx: { hash: "0x1" },
pendingTx: { amount: "1" }, pendingTx: { amount: "1" },
pendingWait: { hash: "0x1" }, pendingWait: { hash: "0x1" },
}, },
}, [
"confirm-tx",
"transaction",
"wait-tx",
"success-tx",
"error-tx",
],
),
], ],
}, },
{ {
@@ -583,6 +668,11 @@ const HEALTHY = { errors: [], blank: false };
// set is all-truthy by construction, so without a falsy slot a dereference // set is all-truthy by construction, so without a falsy slot a dereference
// behind `if (!state.x)` is never reached on the boot that corrupts x — the // behind `if (!state.x)` is never reached on the boot that corrupts x — the
// same falsy-collapse blind spot the fields below were floored for. // same falsy-collapse blind spot the fields below were floored for.
//
// Only `hostile` and `falsy` values count. Those go through the sweep below,
// which covers every restorable view; a `hostileRestore` entry is driven onto
// only the views it names, so a polarity it alone supplied might reach a single
// renderer.
describe("both polarities of every swept field are driven", () => { describe("both polarities of every swept field are driven", () => {
const FALSY_STORED = [0, "", false, null]; const FALSY_STORED = [0, "", false, null];
const floored = (field, value) => const floored = (field, value) =>
@@ -606,10 +696,9 @@ describe("both polarities of every swept field are driven", () => {
test(`${row.field}: truthy and falsy`, () => { test(`${row.field}: truthy and falsy`, () => {
// What the boots below actually drive, floored the way a renderer // What the boots below actually drive, floored the way a renderer
// sees it — not what the row says it drives. // sees it — not what the row says it drives.
const driven = [ const driven = sweptValues(row).map((value) =>
...sweptValues(row), floored(row.field, value),
...(row.hostileRestore || []).map((entry) => entry.value), );
].map((value) => floored(row.field, value));
expect({ expect({
truthy: driven.some((value) => Boolean(value)), truthy: driven.some((value) => Boolean(value)),
@@ -865,20 +954,27 @@ describe("every field the router does not read, corrupted at once, onto", () =>
// The values that only mean something on the restore path: a viewData that // The values that only mean something on the restore path: a viewData that
// PASSES a branch's gate and then hands its renderer something dereferenced, // PASSES a branch's gate and then hands its renderer something dereferenced,
// and the index values whose route through hasValidAddress() differs from the // and a selectedWallet the floor turns into nothing selected. Each boot must
// row's own hostile set. // throw nothing and show exactly the view its entry says it lands on: its own,
// or Home, so a value written for one renderer cannot stop reaching it and
// still pass.
describe("a restore-only hostile value onto", () => { describe("a restore-only hostile value onto", () => {
for (const row of CONTRACT) { for (const row of CONTRACT) {
for (const entry of row.hostileRestore || []) { for (const entry of row.hostileRestore || []) {
for (const view of entry.views || RESTORABLE_VIEWS) { for (const view of entry.views) {
test(`${view}: ${row.field} = ${JSON.stringify( test(`${view}: ${row.field} = ${JSON.stringify(
entry.value, entry.value,
)}`, async () => { )}`, async () => {
await expect( const env = await bootPopup(
bootHealth( restoringOnto(view, { [row.field]: entry.value }),
restoringOnto(view, { [row.field]: entry.value }), );
), expect({
).resolves.toEqual(HEALTHY); errors: env.pageErrors,
visible: env.visibleViews(),
}).toEqual({
errors: [],
visible: [entry.restored ? view : "main"],
});
}); });
} }
} }