Compare commits
3
Commits
e4116ecd4a
...
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ca18beb97f | ||
|
|
bb60b399ec | ||
|
|
447d714313 |
@@ -1263,14 +1263,21 @@ path rather than on the home screen. Read the claim narrowly, as that file
|
||||
states it: what those boots prove is no structural dereference on the code paths
|
||||
a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes.
|
||||
Not driven: any pairing of values the four slots do not produce, a view only
|
||||
forward navigation opens, anything behind a click, and everything a healthy
|
||||
profile reaches. Within that boundary the verdict is unconditional — if one of
|
||||
those boots leaves the popup unhealthy or off the view it stored, `make check`
|
||||
fails, including when it takes two corrupted fields at once, because the verdict
|
||||
is the combined boot and the per-field re-boot that names a culprit can only
|
||||
decorate the message. So does a field that gains a floor while its row still
|
||||
claims it has none, and so does a field added to `PERSISTED_FIELDS` with no row
|
||||
at all. The per-field justification that used to live in the header of
|
||||
forward navigation opens, anything behind a click or a timer, and, of what a
|
||||
healthy profile reaches, anything beyond its boot onto each view the popup can
|
||||
reopen onto. The fields the router does not read share a slot on each boot, so
|
||||
one of them truthy while another is falsy is reached only where the falsy slot
|
||||
pairs a field that cannot be falsy with one that is. Within that boundary the
|
||||
verdict is unconditional — if one of those boots leaves the popup unhealthy,
|
||||
`make check` fails, including when it takes two corrupted fields at once,
|
||||
because the verdict is the combined boot and the per-field re-boot that names a
|
||||
culprit can only decorate the message. The combined boot must also land on the
|
||||
view it stored, and each value driven only onto the restore path must land on
|
||||
its view, or fall back to Home, as its row declares; a field the router reads
|
||||
can legitimately change which view renders, so its own sweep is held to health
|
||||
alone. `make check` also fails on a field that gains a floor while its row still
|
||||
claims it has none, and on a field added to `PERSISTED_FIELDS` with no row at
|
||||
all. The per-field justification that used to live in the header of
|
||||
`src/shared/stateSchema.js` shipped a false claim in three consecutive changes,
|
||||
each caught only by a reviewer re-deriving thirty fields by hand.
|
||||
|
||||
@@ -1444,14 +1451,17 @@ view would leave a wallet one click from deletion.
|
||||
without it, the lost-password route on DeleteWallet is the first they
|
||||
would hear of it. The hint line reserves its height, so switching tabs
|
||||
cannot move the password fields under the pointer.
|
||||
- "Import" button
|
||||
- "Import" button, with the error line beside it so that it adds no height
|
||||
to a screen whose button already starts near the bottom of the popup
|
||||
- **Transitions**:
|
||||
- "Import" with a valid entry and a matching password of at least 12
|
||||
characters → creates the wallet, clears the navigation stack, and →
|
||||
**Home**. The phrase and xprv modes then scan for further used addresses
|
||||
and report the count as a flash message.
|
||||
- "Import" with an invalid entry, a duplicate wallet or address, or a short
|
||||
or mismatched password → flash message, no screen change
|
||||
- "Import" with a missing, short or mismatched password → full-sentence
|
||||
error on the error line, no screen change
|
||||
- "Import" with an invalid entry or a duplicate wallet or address → flash
|
||||
message, no screen change
|
||||
- "Back" → previous screen (Welcome, Home, or Settings)
|
||||
|
||||
#### AddressDetail (`address`)
|
||||
@@ -1490,8 +1500,8 @@ view would leave a wallet one click from deletion.
|
||||
copy)
|
||||
- Warning that anyone holding the private key can transfer all funds from
|
||||
the address
|
||||
- Error line
|
||||
- Password input and "Reveal" button, shown until the key is revealed
|
||||
- Password input, error line and "Reveal" button, shown until the key is
|
||||
revealed
|
||||
- The private key on a highlighted background, tap to copy, shown only after
|
||||
the password has been accepted
|
||||
- **Transitions**:
|
||||
@@ -1829,8 +1839,8 @@ view would leave a wallet one click from deletion.
|
||||
- Wallet name
|
||||
- Warning box stating that anyone holding these words can take everything in
|
||||
the wallet, from any device, without the password
|
||||
- Error line
|
||||
- Password input + "Reveal" button, shown until the password is accepted
|
||||
- Password input, error line and "Reveal" button, shown until the password
|
||||
is accepted
|
||||
- The recovery phrase itself, in full and click-to-copy, shown only after a
|
||||
correct password and in place of the password prompt
|
||||
- **Transitions**:
|
||||
@@ -1859,8 +1869,8 @@ view would leave a wallet one click from deletion.
|
||||
- "Back" button, "Delete Wallet" heading
|
||||
- Warning naming the wallet and stating that deletion is permanent and any
|
||||
funds are unrecoverable without the recovery phrase
|
||||
- Error line
|
||||
- Password input
|
||||
- Error line
|
||||
- "Confirm Delete" button
|
||||
- An underlined "I have lost my password" control
|
||||
- **Transitions**:
|
||||
@@ -2638,7 +2648,7 @@ Currently supported:
|
||||
|
||||
### Non-Goals for 1.0
|
||||
|
||||
- Multi-chain support (Ethereum mainnet only)
|
||||
- Chains other than Ethereum mainnet and the Sepolia testnet
|
||||
- Hardware wallet support
|
||||
|
||||
## TODO
|
||||
@@ -2672,7 +2682,10 @@ Currently supported:
|
||||
## Policies
|
||||
|
||||
- We don't mention "the other wallet" by name in code or documentation. We're
|
||||
our own thing.
|
||||
our own thing. Written exception: the injected provider in
|
||||
`src/content/inpage.js` sets the flag named after the other wallet to `true`.
|
||||
It is an interface-compatibility flag many dApps check, and without it the
|
||||
wallet stops working on their sites.
|
||||
- The README is the complete authoritative technical documentation. It's ok if
|
||||
it gets big.
|
||||
|
||||
|
||||
@@ -118,4 +118,7 @@ contradicts either, the originals govern.
|
||||
- [ ] "Address" not "account" or "derived key"
|
||||
- [ ] "Password" not "encryption key" or "vault passphrase"
|
||||
- [ ] Error messages are full sentences
|
||||
- [ ] No competitor mentioned by name in code or documentation
|
||||
- [ ] No competitor mentioned by name in code or documentation. Written
|
||||
exception: the injected provider in `src/content/inpage.js` sets the flag
|
||||
named after the other wallet to `true`, an interface-compatibility flag
|
||||
many dApps check (README.md, Policies)
|
||||
|
||||
@@ -44,6 +44,43 @@ then continue tagging as milestones land.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-07: Two contradictions between the documents and the code are resolved
|
||||
as ruled on [#165](https://git.eeqj.de/sneak/AutistMask/issues/165). The
|
||||
README's 1.0 non-goal now puts Ethereum mainnet and the Sepolia testnet in
|
||||
scope and other chains out of it. The injected provider's flag named after the
|
||||
other wallet stays, as an interface-compatibility flag many dApps check, and
|
||||
is written down as an exception to the rule against naming competitors in the
|
||||
README's Policies section, in `RULES.md` and in a comment beside it in
|
||||
`src/content/inpage.js`. `script/check-censored` already allows that flag only
|
||||
in that file and its built copies, so it is unchanged.
|
||||
|
||||
- 2026-10-07: Two holes in what `tests/persistedFieldContract.test.js` checks
|
||||
are closed ([#379](https://git.eeqj.de/sneak/AutistMask/issues/379)). The
|
||||
check that every swept field is driven both truthy and falsy counts only
|
||||
`hostile` and `falsy` values, which the sweep drives onto every restorable
|
||||
view, and no longer a `hostileRestore` value, which reaches only the views its
|
||||
entry names; the stale index 5 moves into `hostile` for `selectedWallet` and
|
||||
`selectedAddress`, as the one value of either still truthy after the floor.
|
||||
Each `hostileRestore` entry declares whether its boot lands on its view or
|
||||
falls back to Home, and is held to it. The limits that remain, fields that
|
||||
share a slot on one boot and anything no stored record reaches by itself, are
|
||||
restated as built in the file's header and the README, which now also say
|
||||
which boots are held to where the popup lands and that a healthy profile is
|
||||
booted onto every restorable view.
|
||||
|
||||
- 2026-10-07: Every password error in the popup is shown the same way
|
||||
([#493](https://git.eeqj.de/sneak/AutistMask/issues/493)): with `showError()`
|
||||
and `hideError()` in a fixed-height error line below the password field, as
|
||||
the send confirmation and approval screens already did. The add wallet screen
|
||||
showed a missing, short or mismatched password in the flash line, and the
|
||||
private key export, recovery phrase and delete wallet screens each had a line
|
||||
of their own above the field. On the add wallet screen the line sits beside
|
||||
the Import button, so the button stays where it was at 360x600. Each line
|
||||
clears when the screen is shown again and when the password is tried again.
|
||||
The add wallet screen's other messages, such as an invalid recovery phrase, a
|
||||
duplicate wallet and the address scan, stay in the flash line.
|
||||
`tests/passwordErrorLines.test.js` drives all four screens in the popup.
|
||||
|
||||
- 2026-10-07: Pre-1.0 security review of the extension
|
||||
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
|
||||
`99292b9` for key handling, the DEBUG mode policy, and what the background
|
||||
|
||||
@@ -99,7 +99,10 @@
|
||||
|
||||
const provider = {
|
||||
isAutistMask: true,
|
||||
isMetaMask: true, // compatibility — many dApps check this
|
||||
// An interface-compatibility flag many dApps check. Kept as a written
|
||||
// exception to the rule that no competitor is named in code: see
|
||||
// Policies in README.md, and RULES.md.
|
||||
isMetaMask: true,
|
||||
chainId: currentChainId,
|
||||
networkVersion: currentNetworkVersion,
|
||||
selectedAddress: null,
|
||||
|
||||
+30
-20
@@ -207,12 +207,22 @@
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
/>
|
||||
</div>
|
||||
<button
|
||||
id="btn-add-wallet-confirm"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Import
|
||||
</button>
|
||||
<!-- The error line sits beside Import, not above it: at
|
||||
360x600 the button already starts near the bottom of
|
||||
the popup, and a line of its own would push it below
|
||||
the fold. The longest error fits on one line here. -->
|
||||
<div class="flex items-center gap-2">
|
||||
<button
|
||||
id="btn-add-wallet-confirm"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Import
|
||||
</button>
|
||||
<div
|
||||
id="add-wallet-password-error"
|
||||
class="text-xs min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ -->
|
||||
@@ -396,10 +406,6 @@
|
||||
Warning: anyone with this private key can access and
|
||||
transfer all funds from this address. Never share it.
|
||||
</p>
|
||||
<div
|
||||
id="export-privkey-flash"
|
||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<div id="export-privkey-password-section" class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
<input
|
||||
@@ -408,9 +414,13 @@
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
placeholder="Enter your password to continue"
|
||||
/>
|
||||
<div
|
||||
id="export-privkey-password-error"
|
||||
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<button
|
||||
id="btn-export-privkey-confirm"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Reveal
|
||||
</button>
|
||||
@@ -1116,10 +1126,6 @@
|
||||
<strong id="delete-wallet-name"></strong> is permanent. Any
|
||||
funds will be unrecoverable without your recovery phrase.
|
||||
</p>
|
||||
<div
|
||||
id="delete-wallet-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
<input
|
||||
@@ -1129,6 +1135,10 @@
|
||||
placeholder="Enter your password to confirm"
|
||||
/>
|
||||
</div>
|
||||
<div
|
||||
id="delete-wallet-password-error"
|
||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<button
|
||||
id="btn-delete-wallet-confirm"
|
||||
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
@@ -1273,10 +1283,6 @@
|
||||
this wallet, from any device, without your password. Never
|
||||
type them into a website and never show them to anyone.
|
||||
</div>
|
||||
<div
|
||||
id="show-phrase-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<div id="show-phrase-password-section" class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
<input
|
||||
@@ -1285,9 +1291,13 @@
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
placeholder="Enter your password to continue"
|
||||
/>
|
||||
<div
|
||||
id="show-phrase-password-error"
|
||||
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
|
||||
></div>
|
||||
<button
|
||||
id="btn-show-phrase-reveal"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Reveal
|
||||
</button>
|
||||
|
||||
@@ -2,6 +2,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
goBack,
|
||||
clearViewStack,
|
||||
onViewLeave,
|
||||
@@ -98,6 +100,7 @@ function clear() {
|
||||
$("add-wallet-password").value = "";
|
||||
$("add-wallet-password-confirm").value = "";
|
||||
$("add-wallet-phrase-warning").style.visibility = "hidden";
|
||||
hideError("add-wallet-password-error");
|
||||
}
|
||||
|
||||
// Each wallet has its own password (its own encryptedSecret), so adding a
|
||||
@@ -125,15 +128,18 @@ function validatePassword() {
|
||||
const pw = $("add-wallet-password").value;
|
||||
const pw2 = $("add-wallet-password-confirm").value;
|
||||
if (!pw) {
|
||||
showFlash("Please choose a password.");
|
||||
showError("add-wallet-password-error", "Please choose a password.");
|
||||
return null;
|
||||
}
|
||||
if (pw.length < 12) {
|
||||
showFlash("Password must be at least 12 characters.");
|
||||
showError(
|
||||
"add-wallet-password-error",
|
||||
"Password must be at least 12 characters.",
|
||||
);
|
||||
return null;
|
||||
}
|
||||
if (pw !== pw2) {
|
||||
showFlash("Passwords do not match.");
|
||||
showError("add-wallet-password-error", "Passwords do not match.");
|
||||
return null;
|
||||
}
|
||||
return pw;
|
||||
@@ -342,8 +348,10 @@ function init(ctx) {
|
||||
$("add-wallet-phrase-warning").style.visibility = "visible";
|
||||
});
|
||||
|
||||
// Import / confirm
|
||||
// Import / confirm. Each press starts with no password error on screen:
|
||||
// validatePassword() puts it back if the password is still wrong.
|
||||
$("btn-add-wallet-confirm").addEventListener("click", async () => {
|
||||
hideError("add-wallet-password-error");
|
||||
if (currentMode === "mnemonic") {
|
||||
await importMnemonic(ctx);
|
||||
} else if (currentMode === "privkey") {
|
||||
|
||||
@@ -2,6 +2,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
goBack,
|
||||
clearViewStack,
|
||||
onViewLeave,
|
||||
@@ -55,8 +57,7 @@ function confirmKey(name) {
|
||||
function clear() {
|
||||
deleteWalletIndex = null;
|
||||
$("delete-wallet-password").value = "";
|
||||
$("delete-wallet-flash").textContent = "";
|
||||
$("delete-wallet-flash").style.visibility = "hidden";
|
||||
hideError("delete-wallet-password-error");
|
||||
}
|
||||
|
||||
// The lost-password screen holds no secret — a wallet name is not one —
|
||||
@@ -232,19 +233,22 @@ function init(_ctx) {
|
||||
$("btn-delete-wallet-confirm").addEventListener("click", async () => {
|
||||
const pw = $("delete-wallet-password").value;
|
||||
if (!pw) {
|
||||
$("delete-wallet-flash").textContent =
|
||||
"Please enter your password.";
|
||||
$("delete-wallet-flash").style.visibility = "visible";
|
||||
showError(
|
||||
"delete-wallet-password-error",
|
||||
"Please enter your password.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
if (deleteWalletIndex === null) {
|
||||
$("delete-wallet-flash").textContent =
|
||||
"No wallet selected for deletion.";
|
||||
$("delete-wallet-flash").style.visibility = "visible";
|
||||
showError(
|
||||
"delete-wallet-password-error",
|
||||
"No wallet selected for deletion.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
hideError("delete-wallet-password-error");
|
||||
const btn = $("btn-delete-wallet-confirm");
|
||||
btn.disabled = true;
|
||||
btn.classList.add("text-muted");
|
||||
@@ -256,9 +260,10 @@ function init(_ctx) {
|
||||
try {
|
||||
await decryptWithPassword(wallet.encryptedSecret, pw);
|
||||
} catch {
|
||||
$("delete-wallet-flash").textContent =
|
||||
"That password is incorrect. Please try again.";
|
||||
$("delete-wallet-flash").style.visibility = "visible";
|
||||
showError(
|
||||
"delete-wallet-password-error",
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
btn.disabled = false;
|
||||
btn.classList.remove("text-muted");
|
||||
return;
|
||||
|
||||
@@ -20,6 +20,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
flashCopyFeedback,
|
||||
goBack,
|
||||
onViewLeave,
|
||||
@@ -56,11 +58,6 @@ function isCurrentReveal(generation) {
|
||||
);
|
||||
}
|
||||
|
||||
function fail(message) {
|
||||
$("export-privkey-flash").textContent = message;
|
||||
$("export-privkey-flash").style.visibility = "visible";
|
||||
}
|
||||
|
||||
// Wipe every trace of the key and drop the address selection. Safe to call
|
||||
// when nothing was ever revealed, and safe to call twice.
|
||||
function clear() {
|
||||
@@ -71,8 +68,7 @@ function clear() {
|
||||
$("export-privkey-password").value = "";
|
||||
$("export-privkey-result").classList.add("hidden");
|
||||
$("export-privkey-password-section").classList.remove("hidden");
|
||||
$("export-privkey-flash").textContent = "";
|
||||
$("export-privkey-flash").style.visibility = "hidden";
|
||||
hideError("export-privkey-password-error");
|
||||
}
|
||||
|
||||
function show(walletIdx, addrIdx) {
|
||||
@@ -112,15 +108,19 @@ function show(walletIdx, addrIdx) {
|
||||
async function reveal() {
|
||||
const password = $("export-privkey-password").value;
|
||||
if (!password) {
|
||||
fail("Please enter your password.");
|
||||
showError(
|
||||
"export-privkey-password-error",
|
||||
"Please enter your password.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
if (walletIndex === null) {
|
||||
fail("No address is selected.");
|
||||
showError("export-privkey-password-error", "No address is selected.");
|
||||
return;
|
||||
}
|
||||
const wallet = state.wallets[walletIndex];
|
||||
|
||||
hideError("export-privkey-password-error");
|
||||
const btn = $("btn-export-privkey-confirm");
|
||||
btn.disabled = true;
|
||||
btn.classList.add("text-muted");
|
||||
@@ -140,11 +140,12 @@ async function reveal() {
|
||||
$("export-privkey-password-section").classList.add("hidden");
|
||||
$("export-privkey-value").textContent = signer.privateKey;
|
||||
$("export-privkey-result").classList.remove("hidden");
|
||||
$("export-privkey-flash").textContent = "";
|
||||
$("export-privkey-flash").style.visibility = "hidden";
|
||||
} catch {
|
||||
if (!isCurrentReveal(generation)) return;
|
||||
fail("That password is incorrect. Please try again.");
|
||||
showError(
|
||||
"export-privkey-password-error",
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
btn.classList.remove("text-muted");
|
||||
|
||||
@@ -21,6 +21,8 @@ const {
|
||||
$,
|
||||
showView,
|
||||
showFlash,
|
||||
showError,
|
||||
hideError,
|
||||
flashCopyFeedback,
|
||||
goBack,
|
||||
onViewLeave,
|
||||
@@ -52,11 +54,6 @@ function isCurrentReveal(generation) {
|
||||
);
|
||||
}
|
||||
|
||||
function fail(message) {
|
||||
$("show-phrase-flash").textContent = message;
|
||||
$("show-phrase-flash").style.visibility = "visible";
|
||||
}
|
||||
|
||||
// Wipe every trace of the phrase and drop the wallet selection. Safe to
|
||||
// call when nothing was ever revealed, and safe to call twice.
|
||||
function clear() {
|
||||
@@ -66,8 +63,7 @@ function clear() {
|
||||
$("show-phrase-password").value = "";
|
||||
$("show-phrase-result").classList.add("hidden");
|
||||
$("show-phrase-password-section").classList.remove("hidden");
|
||||
$("show-phrase-flash").textContent = "";
|
||||
$("show-phrase-flash").style.visibility = "hidden";
|
||||
hideError("show-phrase-password-error");
|
||||
}
|
||||
|
||||
function show(walletIdx) {
|
||||
@@ -90,19 +86,23 @@ function show(walletIdx) {
|
||||
async function reveal() {
|
||||
const password = $("show-phrase-password").value;
|
||||
if (!password) {
|
||||
fail("Please enter your password.");
|
||||
showError("show-phrase-password-error", "Please enter your password.");
|
||||
return;
|
||||
}
|
||||
if (walletIndex === null) {
|
||||
fail("No wallet is selected.");
|
||||
showError("show-phrase-password-error", "No wallet is selected.");
|
||||
return;
|
||||
}
|
||||
const wallet = state.wallets[walletIndex];
|
||||
if (!walletHasRecoveryPhrase(wallet)) {
|
||||
fail("This wallet does not have a recovery phrase.");
|
||||
showError(
|
||||
"show-phrase-password-error",
|
||||
"This wallet does not have a recovery phrase.",
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
hideError("show-phrase-password-error");
|
||||
const btn = $("btn-show-phrase-reveal");
|
||||
btn.disabled = true;
|
||||
btn.classList.add("text-muted");
|
||||
@@ -120,13 +120,14 @@ async function reveal() {
|
||||
$("show-phrase-password-section").classList.add("hidden");
|
||||
$("show-phrase-value").textContent = phrase;
|
||||
$("show-phrase-result").classList.remove("hidden");
|
||||
$("show-phrase-flash").textContent = "";
|
||||
$("show-phrase-flash").style.visibility = "hidden";
|
||||
} catch {
|
||||
if (!isCurrentReveal(generation)) return;
|
||||
// Deliberately not the caught error: the message is fixed so that
|
||||
// nothing derived from the ciphertext or the attempt can surface.
|
||||
fail("That password is incorrect. Please try again.");
|
||||
showError(
|
||||
"show-phrase-password-error",
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
btn.classList.remove("text-muted");
|
||||
|
||||
@@ -39,6 +39,8 @@ jest.doMock("../src/popup/views/helpers", () => ({
|
||||
$: element,
|
||||
showView: () => {},
|
||||
showFlash: () => {},
|
||||
showError: () => {},
|
||||
hideError: () => {},
|
||||
goBack: () => {},
|
||||
clearViewStack: () => {},
|
||||
onViewLeave: () => {},
|
||||
|
||||
@@ -253,7 +253,7 @@ describe("reaching the screen", () => {
|
||||
const { decryptWithPassword } = require("../src/shared/vault");
|
||||
decryptWithPassword.mockRejectedValue(new Error("nope"));
|
||||
await click("btn-delete-wallet-confirm");
|
||||
expect(node("delete-wallet-flash").textContent).toBe(
|
||||
expect(node("delete-wallet-password-error").textContent).toBe(
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
});
|
||||
|
||||
+109
-6
@@ -809,7 +809,7 @@ async function secretScreenState(page, view) {
|
||||
return page.evaluate(
|
||||
(v) => ({
|
||||
value: document.getElementById(v + "-value").textContent,
|
||||
error: document.getElementById(v + "-flash").textContent,
|
||||
error: document.getElementById(v + "-password-error").textContent,
|
||||
html: document.getElementById("view-" + v).innerHTML,
|
||||
resultHidden: document
|
||||
.getElementById(v + "-result")
|
||||
@@ -906,7 +906,8 @@ test("a wrong password reveals nothing (#161)", async (env) => {
|
||||
await env.page.click("#btn-show-phrase-reveal");
|
||||
await env.page.waitForFunction(
|
||||
() =>
|
||||
document.getElementById("show-phrase-flash").textContent.length > 0,
|
||||
document.getElementById("show-phrase-password-error").textContent
|
||||
.length > 0,
|
||||
null,
|
||||
{ timeout: 60000 },
|
||||
);
|
||||
@@ -1993,13 +1994,14 @@ test("an over-long flash message keeps to one line (#252)", async (env) => {
|
||||
|
||||
// Every screen that asks for a password reserves room for one line of error.
|
||||
// The two on the dApp approval screens also have a border and padding, which
|
||||
// that reserved height has to cover too.
|
||||
// that reserved height has to cover too. The add wallet screen's line sits
|
||||
// beside its button rather than above it, and has its own test below.
|
||||
const PASSWORD_ERROR_CONTAINERS = [
|
||||
"approve-tx-error",
|
||||
"approve-sign-error",
|
||||
"export-privkey-flash",
|
||||
"show-phrase-flash",
|
||||
"delete-wallet-flash",
|
||||
"export-privkey-password-error",
|
||||
"show-phrase-password-error",
|
||||
"delete-wallet-password-error",
|
||||
"confirm-tx-password-error",
|
||||
];
|
||||
|
||||
@@ -2064,6 +2066,107 @@ test("a password error moves nothing on any screen (#297)", async (env) => {
|
||||
}
|
||||
});
|
||||
|
||||
// ------------------------------------------ add wallet Import button (#493)
|
||||
|
||||
// At 360x600 the add wallet screen's Import button already starts near the
|
||||
// bottom of the popup, so its password error line sits beside the button
|
||||
// rather than above it. Measures the button and the line empty and again
|
||||
// filled with the longest error addWallet.js puts there. Runs in the page.
|
||||
function measureImportButton() {
|
||||
const button = document.getElementById("btn-add-wallet-confirm");
|
||||
const line = document.getElementById("add-wallet-password-error");
|
||||
const measure = () => {
|
||||
const b = button.getBoundingClientRect();
|
||||
const l = line.getBoundingClientRect();
|
||||
return {
|
||||
buttonTop: b.top + window.scrollY,
|
||||
buttonBottom: b.bottom + window.scrollY,
|
||||
lineTop: l.top + window.scrollY,
|
||||
lineBottom: l.bottom + window.scrollY,
|
||||
};
|
||||
};
|
||||
const empty = measure();
|
||||
line.textContent = "Password must be at least 12 characters.";
|
||||
line.style.visibility = "visible";
|
||||
const filled = measure();
|
||||
line.textContent = "";
|
||||
line.style.visibility = "hidden";
|
||||
return { empty, filled };
|
||||
}
|
||||
|
||||
test("the add wallet password error leaves Import where it was (#493)", async (env) => {
|
||||
const page = await openPopup(env.ctx, env.popupUrl);
|
||||
try {
|
||||
await page.setViewportSize(POPUP_VIEWPORT);
|
||||
// Brought up by toggling classes, as in the test above. The note
|
||||
// addWallet.js shows once a wallet exists is the only part of the
|
||||
// screen that differs between the first wallet and a later one.
|
||||
await page.evaluate(() => {
|
||||
const screen = document.getElementById("view-add-wallet");
|
||||
for (const view of document.querySelectorAll(".view")) {
|
||||
view.classList.toggle("hidden", view !== screen);
|
||||
}
|
||||
});
|
||||
for (const walletExists of [false, true]) {
|
||||
await page.evaluate(
|
||||
(shown) =>
|
||||
document
|
||||
.getElementById("add-wallet-separate-password-note")
|
||||
.classList.toggle("hidden", !shown),
|
||||
walletExists,
|
||||
);
|
||||
for (const tab of ["tab-mnemonic", "tab-privkey", "tab-xprv"]) {
|
||||
await page.click("#" + tab);
|
||||
const { empty, filled } =
|
||||
await page.evaluate(measureImportButton);
|
||||
const where =
|
||||
"#" +
|
||||
tab +
|
||||
(walletExists
|
||||
? " with a wallet already added"
|
||||
: " for the first wallet");
|
||||
// Printed pass or fail, as the dust threshold test does.
|
||||
console.log(
|
||||
"# add wallet Import top, " +
|
||||
where +
|
||||
": " +
|
||||
empty.buttonTop +
|
||||
"px",
|
||||
);
|
||||
for (const m of [empty, filled]) {
|
||||
assert(
|
||||
m.lineTop >= m.buttonTop &&
|
||||
m.lineBottom <= m.buttonBottom,
|
||||
"the error line on " +
|
||||
where +
|
||||
" does not fit beside Import, so it adds height: " +
|
||||
JSON.stringify(m),
|
||||
);
|
||||
}
|
||||
assert(
|
||||
filled.buttonTop === empty.buttonTop,
|
||||
"Import moved " +
|
||||
(filled.buttonTop - empty.buttonTop) +
|
||||
"px when the error appeared on " +
|
||||
where,
|
||||
);
|
||||
if (!walletExists) {
|
||||
assert(
|
||||
empty.buttonTop < POPUP_VIEWPORT.height,
|
||||
"Import starts at " +
|
||||
empty.buttonTop +
|
||||
"px on " +
|
||||
where +
|
||||
", below the fold",
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
await page.close();
|
||||
}
|
||||
});
|
||||
|
||||
// --------------------------------------------- confirmation screen (#238)
|
||||
//
|
||||
// The screen that decides what gets signed. The arithmetic underneath it
|
||||
|
||||
@@ -207,7 +207,7 @@ describe("a decrypt still running when the screen is left", () => {
|
||||
});
|
||||
|
||||
// Same hole on the failure path: a wrong-password error written after
|
||||
// the wipe would restore the flash line on a screen the user has left.
|
||||
// the wipe would restore the error line on a screen the user has left.
|
||||
test("never writes the failure message either", async () => {
|
||||
const { helpers, vault, exportPrivkey } = load();
|
||||
exportPrivkey.show(0, 0);
|
||||
@@ -217,8 +217,10 @@ describe("a decrypt still running when the screen is left", () => {
|
||||
reveal.reject(new Error("decryption failed"));
|
||||
await reveal.pending;
|
||||
|
||||
expect(node("export-privkey-flash").textContent).toBe("");
|
||||
expect(node("export-privkey-flash").style.visibility).toBe("hidden");
|
||||
expect(node("export-privkey-password-error").textContent).toBe("");
|
||||
expect(node("export-privkey-password-error").style.visibility).toBe(
|
||||
"hidden",
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -260,7 +262,7 @@ describe("a reveal that is not interrupted", () => {
|
||||
await reveal.pending;
|
||||
|
||||
expect(node("export-privkey-value").textContent).toBe("");
|
||||
expect(node("export-privkey-flash").textContent).toBe(
|
||||
expect(node("export-privkey-password-error").textContent).toBe(
|
||||
"That password is incorrect. Please try again.",
|
||||
);
|
||||
});
|
||||
|
||||
@@ -0,0 +1,159 @@
|
||||
// Every screen that asks for a password shows a password error the same way:
|
||||
// through showError() and hideError() in src/popup/views/helpers.js, in a
|
||||
// fixed-height error line below the password field, and never in the flash
|
||||
// line at the top of the popup
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/493). These boot the real popup
|
||||
// over src/popup/index.html, so each error line has to exist in the markup,
|
||||
// and check that the error appears in it and clears again.
|
||||
|
||||
jest.mock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: jest.fn(),
|
||||
encryptWithPassword: jest.fn(),
|
||||
}));
|
||||
|
||||
const {
|
||||
bootPopup,
|
||||
cleanupPopup,
|
||||
unversionedValidProfile,
|
||||
} = require("./support/popupBoot");
|
||||
|
||||
const PASSWORD = "correct horse battery staple";
|
||||
const WRONG_PASSWORD = "That password is incorrect. Please try again.";
|
||||
|
||||
afterEach(() => {
|
||||
cleanupPopup();
|
||||
});
|
||||
|
||||
// The error line as the user sees it.
|
||||
function errorLine(page, id) {
|
||||
return {
|
||||
inMarkup: page.document.authoredIds.has(id),
|
||||
text: page.text(id),
|
||||
visibility: page.node(id).style.visibility,
|
||||
};
|
||||
}
|
||||
|
||||
function shown(text) {
|
||||
return { inMarkup: true, text, visibility: "visible" };
|
||||
}
|
||||
|
||||
const cleared = { inMarkup: true, text: "", visibility: "hidden" };
|
||||
|
||||
describe("the add wallet screen", () => {
|
||||
const ERROR = "add-wallet-password-error";
|
||||
|
||||
// First run: Welcome, "Add wallet", then the die for a valid phrase.
|
||||
async function openAddWallet() {
|
||||
const page = await bootPopup(undefined);
|
||||
await page.click("btn-welcome-add");
|
||||
await page.click("btn-generate-phrase");
|
||||
return page;
|
||||
}
|
||||
|
||||
function setPasswords(page, password, confirm) {
|
||||
page.node("add-wallet-password").value = password;
|
||||
page.node("add-wallet-password-confirm").value = confirm;
|
||||
}
|
||||
|
||||
test("shows a password problem below the password fields, and clears it on the next press", async () => {
|
||||
const page = await openAddWallet();
|
||||
setPasswords(page, "short", "short");
|
||||
await page.click("btn-add-wallet-confirm");
|
||||
expect(errorLine(page, ERROR)).toEqual(
|
||||
shown("Password must be at least 12 characters."),
|
||||
);
|
||||
expect(page.text("flash-msg")).toBe("");
|
||||
|
||||
// The password is fixed and the phrase emptied: the password error
|
||||
// goes, and the phrase problem is still reported in the flash line.
|
||||
setPasswords(page, PASSWORD, PASSWORD);
|
||||
page.node("wallet-mnemonic").value = "";
|
||||
await page.click("btn-add-wallet-confirm");
|
||||
expect(errorLine(page, ERROR)).toEqual(cleared);
|
||||
expect(page.text("flash-msg")).toBe(
|
||||
"Enter a recovery phrase, or press the die.",
|
||||
);
|
||||
|
||||
// Leaving clears the flash line and stops its timer, which would
|
||||
// otherwise fire after this page is gone.
|
||||
await page.click("btn-add-wallet-back");
|
||||
});
|
||||
|
||||
test("clears the error when the screen is shown again", async () => {
|
||||
const page = await openAddWallet();
|
||||
setPasswords(page, PASSWORD, PASSWORD + " typo");
|
||||
await page.click("btn-add-wallet-confirm");
|
||||
expect(errorLine(page, ERROR)).toEqual(
|
||||
shown("Passwords do not match."),
|
||||
);
|
||||
|
||||
await page.click("btn-add-wallet-back");
|
||||
await page.click("btn-welcome-add");
|
||||
expect(errorLine(page, ERROR)).toEqual(cleared);
|
||||
});
|
||||
});
|
||||
|
||||
describe.each([
|
||||
{
|
||||
screen: "the private key export screen",
|
||||
open: () => require("../src/popup/views/exportPrivkey").show(0, 0),
|
||||
field: "export-privkey-password",
|
||||
button: "btn-export-privkey-confirm",
|
||||
error: "export-privkey-password-error",
|
||||
},
|
||||
{
|
||||
screen: "the recovery phrase screen",
|
||||
open: () => require("../src/popup/views/showPhrase").show(0),
|
||||
field: "show-phrase-password",
|
||||
button: "btn-show-phrase-reveal",
|
||||
error: "show-phrase-password-error",
|
||||
},
|
||||
{
|
||||
screen: "the delete wallet screen",
|
||||
open: () => require("../src/popup/views/deleteWallet").show(0),
|
||||
field: "delete-wallet-password",
|
||||
button: "btn-delete-wallet-confirm",
|
||||
error: "delete-wallet-password-error",
|
||||
},
|
||||
])("$screen", ({ open, field, button, error }) => {
|
||||
// Opens the screen and enters a password the vault rejects.
|
||||
async function failedAttempt() {
|
||||
const page = await bootPopup(unversionedValidProfile());
|
||||
open();
|
||||
const { decryptWithPassword } = require("../src/shared/vault");
|
||||
decryptWithPassword.mockRejectedValue(new Error("wrong password"));
|
||||
page.node(field).value = "not the password";
|
||||
await page.click(button);
|
||||
return { page, decryptWithPassword };
|
||||
}
|
||||
|
||||
test("shows a wrong password below the password field", async () => {
|
||||
const { page } = await failedAttempt();
|
||||
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
|
||||
});
|
||||
|
||||
test("clears the error while the next password is checked", async () => {
|
||||
const { page, decryptWithPassword } = await failedAttempt();
|
||||
let rejectDecrypt;
|
||||
decryptWithPassword.mockReturnValue(
|
||||
new Promise((resolve, reject) => {
|
||||
rejectDecrypt = reject;
|
||||
}),
|
||||
);
|
||||
|
||||
page.node(field).value = "another guess";
|
||||
const pressed = page.click(button);
|
||||
await page.settle();
|
||||
expect(errorLine(page, error)).toEqual(cleared);
|
||||
|
||||
rejectDecrypt(new Error("wrong password"));
|
||||
await pressed;
|
||||
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
|
||||
});
|
||||
|
||||
test("clears the error when the screen is shown again", async () => {
|
||||
const { page } = await failedAttempt();
|
||||
open();
|
||||
expect(errorLine(page, error)).toEqual(cleared);
|
||||
});
|
||||
});
|
||||
@@ -49,22 +49,37 @@
|
||||
// every path a stored record takes, and the difference is the whole of what
|
||||
// this file does not cover:
|
||||
//
|
||||
// - Only the values in the table, in the SLOT arrangement below: four value
|
||||
// combinations per view, not the product of twelve fields. A dereference
|
||||
// reached only under a pairing no slot produces is not driven at all.
|
||||
// - Only what a stored record reaches by ITSELF. A view only forward
|
||||
// navigation opens, and anything behind a click, is not driven.
|
||||
// - Nothing about the paths a HEALTHY profile takes, which is most of the
|
||||
// popup. This file is a floor under one defect class, not a proof about
|
||||
// the renderers.
|
||||
// - Only the values in the table, in the SLOT arrangement below. On the
|
||||
// restore path the twelve fields the router does not read are corrupted
|
||||
// together, every field on the same slot, so a view gets four value
|
||||
// combinations of them, not their product. A branch entered only when one
|
||||
// of them is truthy and another falsy is reached only where the falsy
|
||||
// slot happens to pair a field that cannot be falsy with one that is.
|
||||
// Each field the router reads is corrupted alone, over an otherwise
|
||||
// well-formed record.
|
||||
// - Only what a stored record reaches by ITSELF, as the boot renders it. A
|
||||
// view only forward navigation opens, anything behind a click, and
|
||||
// anything behind a timer (bootPopup() records every interval, and this
|
||||
// file never runs one) is not driven.
|
||||
// - Of the paths a HEALTHY profile takes, only its boot onto each
|
||||
// restorable view ("the base profile the sweep corrupts" below). The rest
|
||||
// of the popup is not covered: this file is a floor under one defect
|
||||
// class, not a proof about the renderers.
|
||||
//
|
||||
// Within that boundary it is unconditional: if one of these boots leaves the
|
||||
// popup unhealthy or off the view it stored, this file goes red — including
|
||||
// when it takes two corrupted fields at once, because the verdict is the
|
||||
// combined boot itself and the per-field re-boot below can only decorate the
|
||||
// message. That last part is the one thing an earlier version got wrong: it
|
||||
// asserted on the per-field list, so an observed dead popup that no single
|
||||
// field reproduced was reported green.
|
||||
// Within that boundary it is unconditional: if a boot that corrupts a field
|
||||
// leaves the popup unhealthy, this file goes red — including when it takes
|
||||
// two corrupted fields at once, because the verdict is the combined boot
|
||||
// itself and the per-field re-boot below can only decorate the message. That
|
||||
// last part is the one thing an earlier version got wrong: it asserted on the
|
||||
// per-field list, so an observed dead popup that no single field reproduced
|
||||
// was reported green.
|
||||
//
|
||||
// Where the popup lands is held for some of those boots and not others. The
|
||||
// combined boot must land on the view it stored, and each `hostileRestore`
|
||||
// value must land on its view, or fall back to Home, as its entry declares.
|
||||
// The boots in "a hostile routing value restoring onto" are held to health
|
||||
// alone, because a value in a field the router reads legitimately changes
|
||||
// which view renders; so are the boots onto Home, which store no view.
|
||||
//
|
||||
// Booting every field separately at every value would be several hundred boots
|
||||
// and most of the suite's budget; this is forty-four. Widening it further is
|
||||
@@ -128,7 +143,11 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
|
||||
// list short and pointed. `floorOnly` is extra values checked against the
|
||||
// floor alone, which is pure and free. `hostileRestore` is extra values driven
|
||||
// through the restore path only, for a value that means nothing until a
|
||||
// particular branch's gate has let it past.
|
||||
// particular branch's gate has let it past. Each of its entries names the
|
||||
// `views` it is driven onto and declares whether the boot lands on them
|
||||
// (`restored: true`) or falls back to Home (`restored: false`), so a value
|
||||
// written for one renderer cannot stop reaching it unnoticed. A value driven
|
||||
// onto every restorable view is written with everyRestorableView() below.
|
||||
//
|
||||
// `falsy` is the other POLARITY of a swept field, driven for the same reason.
|
||||
// It is not a value src/ never writes — for three of these fields it is the
|
||||
@@ -139,6 +158,23 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
|
||||
// falsy value stored under that field comes back TRUTHY from the floor, so no
|
||||
// `!state.x` branch is reachable from a stored record at all.
|
||||
|
||||
// The `hostileRestore` entries for a value driven onto every restorable view:
|
||||
// it falls back to Home on the views listed in `fallsBackOn` and lands on every
|
||||
// other one, so a view added to RESTORABLE_VIEWS is driven, and expected to
|
||||
// land, without editing the row.
|
||||
function everyRestorableView(value, fallsBackOn) {
|
||||
return [
|
||||
{ value, views: fallsBackOn, restored: false },
|
||||
{
|
||||
value,
|
||||
views: [...RESTORABLE_VIEWS].filter(
|
||||
(view) => !fallsBackOn.includes(view),
|
||||
),
|
||||
restored: true,
|
||||
},
|
||||
];
|
||||
}
|
||||
|
||||
const CONTRACT = [
|
||||
{
|
||||
field: "wallets",
|
||||
@@ -280,28 +316,38 @@ const CONTRACT = [
|
||||
kind: KIND.SCALAR,
|
||||
// The prototype members are the whole point: `wallets["map"]` is
|
||||
// TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and
|
||||
// `.addresses[…]` throws. A stale INTEGER is the safe case.
|
||||
hostile: ["map", "__proto__", { a: 1 }],
|
||||
// `.addresses[…]` throws. A stale INTEGER is the safe case and has to
|
||||
// stay so. 5 is one, out of range for the one wallet in the profile,
|
||||
// and it is also this field's truthy polarity: every other value here
|
||||
// comes back from the floor as null.
|
||||
hostile: ["map", "__proto__", { a: 1 }, 5],
|
||||
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
||||
holds: isIndexOrNull,
|
||||
// SCALAR, and swept anyway: the restore path is precisely why this
|
||||
// field gained a floor, so the sweep is the regression guard on it.
|
||||
alsoSweep: true,
|
||||
routes: true,
|
||||
// A stale INTEGER index, which reaches the restore path by a different
|
||||
// route from the prototype members above — falsy or out of range
|
||||
// rather than truthy — and has to keep being the safe case.
|
||||
hostileRestore: [{ value: "length" }, { value: 5 }],
|
||||
// Comes back from the floor as null, which hasValidAddress() reads as
|
||||
// nothing selected: the popup falls back to Home on the five views
|
||||
// that need an address, and lands on every other one.
|
||||
hostileRestore: everyRestorableView("length", [
|
||||
"address",
|
||||
"address-token",
|
||||
"receive",
|
||||
"transaction",
|
||||
"confirm-tx",
|
||||
]),
|
||||
},
|
||||
{
|
||||
field: "selectedAddress",
|
||||
kind: KIND.SCALAR,
|
||||
hostile: ["map", "__proto__", { a: 1 }],
|
||||
// 5 for the same reason as in selectedWallet: a stale index, and the
|
||||
// one value here still truthy after the floor.
|
||||
hostile: ["map", "__proto__", { a: 1 }, 5],
|
||||
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
|
||||
holds: isIndexOrNull,
|
||||
alsoSweep: true,
|
||||
routes: true,
|
||||
hostileRestore: [{ value: 5 }],
|
||||
},
|
||||
{
|
||||
field: "currentView",
|
||||
@@ -325,7 +371,9 @@ const CONTRACT = [
|
||||
// container shapes below onto every restorable view; hostileRestore
|
||||
// adds the records that PASS a branch's gate and then hand its
|
||||
// renderer something it dereferences, which is where the entries are
|
||||
// actually decided.
|
||||
// actually decided. The guard refuses each single-view record below,
|
||||
// so each is declared to fall back to Home: one that started landing
|
||||
// would be reaching the renderer it was written against.
|
||||
hostile: [42, "notarecord", { a: 1 }, [1, 2]],
|
||||
// `structuredClone(saved.viewData || {})`: the container is never falsy
|
||||
// in state whatever was stored, so no `!state.viewData` branch exists to
|
||||
@@ -334,11 +382,20 @@ const CONTRACT = [
|
||||
hostileRestore: [
|
||||
// success-tx passes on `data.hash`, and renderSuccess() then calls
|
||||
// toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase().
|
||||
{ value: { hash: "0x1" }, views: ["success-tx"] },
|
||||
{ value: { hash: "0x1", to: 42 }, views: ["success-tx"] },
|
||||
{
|
||||
value: { hash: "0x1" },
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: { hash: "0x1", to: 42 },
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } },
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: {
|
||||
@@ -347,12 +404,25 @@ const CONTRACT = [
|
||||
decoded: { details: [{ address: 42 }] },
|
||||
},
|
||||
views: ["success-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// error-tx passes on `data.message`, same dereference.
|
||||
{ value: { message: "boom" }, views: ["error-tx"] },
|
||||
{ value: { message: "boom", to: 42 }, views: ["error-tx"] },
|
||||
{
|
||||
value: { message: "boom" },
|
||||
views: ["error-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: { message: "boom", to: 42 },
|
||||
views: ["error-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// transaction passes on `data.tx`.
|
||||
{ value: { tx: { hash: "0x1" } }, views: ["transaction"] },
|
||||
{
|
||||
value: { tx: { hash: "0x1" } },
|
||||
views: ["transaction"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: {
|
||||
tx: {
|
||||
@@ -363,9 +433,14 @@ const CONTRACT = [
|
||||
},
|
||||
},
|
||||
views: ["transaction"],
|
||||
restored: false,
|
||||
},
|
||||
// confirm-tx passes on `data.pendingTx`.
|
||||
{ value: { pendingTx: { amount: "1" } }, views: ["confirm-tx"] },
|
||||
{
|
||||
value: { pendingTx: { amount: "1" } },
|
||||
views: ["confirm-tx"],
|
||||
restored: false,
|
||||
},
|
||||
{
|
||||
value: {
|
||||
pendingTx: {
|
||||
@@ -376,6 +451,7 @@ const CONTRACT = [
|
||||
},
|
||||
},
|
||||
views: ["confirm-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// wait-tx passes on `pendingWait.hash`; restoreWait() has checked
|
||||
// the fields below it since it was written, and this is the
|
||||
@@ -388,20 +464,29 @@ const CONTRACT = [
|
||||
},
|
||||
},
|
||||
views: ["wait-tx"],
|
||||
restored: false,
|
||||
},
|
||||
// A record that passes EVERY branch's gate at once, driven onto
|
||||
// every restorable view: a branch a view does not read must stay
|
||||
// one it does not read, and each renderer must survive the fields
|
||||
// another branch left behind.
|
||||
{
|
||||
value: {
|
||||
// one it does not read. The five views with a viewData branch
|
||||
// refuse it; every other one renders it, and must survive the
|
||||
// fields every branch left behind.
|
||||
...everyRestorableView(
|
||||
{
|
||||
hash: "0x1",
|
||||
message: "boom",
|
||||
tx: { hash: "0x1" },
|
||||
pendingTx: { amount: "1" },
|
||||
pendingWait: { hash: "0x1" },
|
||||
},
|
||||
},
|
||||
[
|
||||
"confirm-tx",
|
||||
"transaction",
|
||||
"wait-tx",
|
||||
"success-tx",
|
||||
"error-tx",
|
||||
],
|
||||
),
|
||||
],
|
||||
},
|
||||
{
|
||||
@@ -583,6 +668,11 @@ const HEALTHY = { errors: [], blank: false };
|
||||
// set is all-truthy by construction, so without a falsy slot a dereference
|
||||
// behind `if (!state.x)` is never reached on the boot that corrupts x — the
|
||||
// same falsy-collapse blind spot the fields below were floored for.
|
||||
//
|
||||
// Only `hostile` and `falsy` values count. Those go through the sweep below,
|
||||
// which covers every restorable view; a `hostileRestore` entry is driven onto
|
||||
// only the views it names, so a polarity it alone supplied might reach a single
|
||||
// renderer.
|
||||
describe("both polarities of every swept field are driven", () => {
|
||||
const FALSY_STORED = [0, "", false, null];
|
||||
const floored = (field, value) =>
|
||||
@@ -606,10 +696,9 @@ describe("both polarities of every swept field are driven", () => {
|
||||
test(`${row.field}: truthy and falsy`, () => {
|
||||
// What the boots below actually drive, floored the way a renderer
|
||||
// sees it — not what the row says it drives.
|
||||
const driven = [
|
||||
...sweptValues(row),
|
||||
...(row.hostileRestore || []).map((entry) => entry.value),
|
||||
].map((value) => floored(row.field, value));
|
||||
const driven = sweptValues(row).map((value) =>
|
||||
floored(row.field, value),
|
||||
);
|
||||
|
||||
expect({
|
||||
truthy: driven.some((value) => Boolean(value)),
|
||||
@@ -865,20 +954,27 @@ describe("every field the router does not read, corrupted at once, onto", () =>
|
||||
|
||||
// The values that only mean something on the restore path: a viewData that
|
||||
// PASSES a branch's gate and then hands its renderer something dereferenced,
|
||||
// and the index values whose route through hasValidAddress() differs from the
|
||||
// row's own hostile set.
|
||||
// and a selectedWallet the floor turns into nothing selected. Each boot must
|
||||
// throw nothing and show exactly the view its entry says it lands on: its own,
|
||||
// or Home, so a value written for one renderer cannot stop reaching it and
|
||||
// still pass.
|
||||
describe("a restore-only hostile value onto", () => {
|
||||
for (const row of CONTRACT) {
|
||||
for (const entry of row.hostileRestore || []) {
|
||||
for (const view of entry.views || RESTORABLE_VIEWS) {
|
||||
for (const view of entry.views) {
|
||||
test(`${view}: ${row.field} = ${JSON.stringify(
|
||||
entry.value,
|
||||
)}`, async () => {
|
||||
await expect(
|
||||
bootHealth(
|
||||
restoringOnto(view, { [row.field]: entry.value }),
|
||||
),
|
||||
).resolves.toEqual(HEALTHY);
|
||||
const env = await bootPopup(
|
||||
restoringOnto(view, { [row.field]: entry.value }),
|
||||
);
|
||||
expect({
|
||||
errors: env.pageErrors,
|
||||
visible: env.visibleViews(),
|
||||
}).toEqual({
|
||||
errors: [],
|
||||
visible: [entry.restored ? view : "main"],
|
||||
});
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user