Compare commits
92 Commits
fix/99-blo
...
5092cf162a
| Author | SHA1 | Date | |
|---|---|---|---|
| 5092cf162a | |||
| c6a1f97247 | |||
| 0a1786b406 | |||
| 937f699fb1 | |||
| 1f41a07df2 | |||
| 78a1cb067e | |||
| afe6ddaea0 | |||
| 23712b53cb | |||
| bd4bdcafc7 | |||
| ce4a0d7b8d | |||
| bf1dbec87c | |||
| ba35282092 | |||
| 158278d251 | |||
| 6f6bc2e7b5 | |||
| 74c137dadf | |||
| edea22f7ed | |||
| b155c0fcd6 | |||
| fb9e8f5542 | |||
| 3e5d6323ce | |||
| 12acf4dc8c | |||
| f455b0ae7f | |||
| 86cdea5e4e | |||
| f271bcd7b4 | |||
| 93e3f6e4e2 | |||
| 9b957ffd69 | |||
| cf5f582be9 | |||
| b9bc226ae1 | |||
| 19cb1ca1b0 | |||
| b882cede9f | |||
| d93eda31a0 | |||
| e9fa8bec47 | |||
| ad9162d057 | |||
| 188882d635 | |||
| e8ad8325c8 | |||
| f7f141a757 | |||
| 23aeae4841 | |||
| d046a24115 | |||
| 3ffc0bec80 | |||
| a22f33d511 | |||
| 39db06c83d | |||
| df031fd07d | |||
| a138a36710 | |||
| 6b40fa8836 | |||
| bc2aedaab6 | |||
| e53420f2e2 | |||
| d35bfb7d23 | |||
| 3bf60ff162 | |||
| 6aeab54e8c | |||
| f65764d501 | |||
| 4e097c1e32 | |||
|
|
3f6f98dcaf | ||
|
|
3e900dc14c | ||
|
|
5dfc6e332b | ||
| a182aa534b | |||
| a388100262 | |||
| dd3cabf816 | |||
|
|
235e5e7fa7 | ||
|
|
be06bd8f0c | ||
|
|
a72359432b | ||
|
|
2bdb547995 | ||
| 834228b572 | |||
|
|
813993f17c | ||
| 5f01d9f111 | |||
|
|
d78af3ec80 | ||
| 753fb5658a | |||
| bdb2031d46 | |||
| 25ecaee128 | |||
|
|
ff4b5ee24d | ||
|
|
ca6e9054f9 | ||
| 09c52b2519 | |||
| 1fb9fade51 | |||
| bc04482fb5 | |||
|
|
045328f3b9 | ||
|
|
576fe3ab15 | ||
|
|
35bb6b9806 | ||
|
|
e56e15e34c | ||
|
|
cc69ce39ed | ||
|
|
9476724284 | ||
|
|
9246959777 | ||
|
|
0f6daf3200 | ||
|
|
435669b6b6 | ||
|
|
f75a258125 | ||
|
|
4d120e5ea9 | ||
|
|
57959b70c3 | ||
|
|
7a7f9c5135 | ||
|
|
8c071ae508 | ||
|
|
a3c2b8227a | ||
|
|
f9f3e7b85a | ||
| 812fc01a98 | |||
|
|
811c125cb9 | ||
|
|
3005813f2c | ||
|
|
5565e76796 |
@@ -1,4 +1,6 @@
|
|||||||
.git
|
# .git is deliberately NOT excluded: build.js shells out to `git rev-parse` for
|
||||||
|
# build-info stamping and the Dockerfile runs `make build`, so excluding it
|
||||||
|
# would make every built extension report commitHash "unknown".
|
||||||
node_modules
|
node_modules
|
||||||
.DS_Store
|
.DS_Store
|
||||||
dist
|
dist
|
||||||
|
|||||||
@@ -6,4 +6,4 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
# actions/checkout v4.2.2, 2026-02-22
|
# actions/checkout v4.2.2, 2026-02-22
|
||||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||||
- run: docker build .
|
- run: script/cibuild
|
||||||
|
|||||||
10
Dockerfile
10
Dockerfile
@@ -1,13 +1,15 @@
|
|||||||
# node:22-slim (22.x LTS), 2026-02-24
|
# node:22-slim (22.x LTS), 2026-02-24
|
||||||
FROM node@sha256:5373f1906319b3a1f291da5d102f4ce5c77ccbe29eb637f072b6c7b70443fc36
|
FROM node@sha256:5373f1906319b3a1f291da5d102f4ce5c77ccbe29eb637f072b6c7b70443fc36
|
||||||
|
|
||||||
RUN apt-get update && apt-get install -y --no-install-recommends make && rm -rf /var/lib/apt/lists/*
|
|
||||||
RUN corepack enable && corepack prepare yarn@1.22.22 --activate
|
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
# script/bootstrap installs all prerequisites (make via apt here; node
|
||||||
|
# is already in the base image, yarn comes via corepack) and runs
|
||||||
|
# yarn install --frozen-lockfile. Dependency manifests are copied first
|
||||||
|
# so the bootstrap layer is cached until they change.
|
||||||
|
COPY script/ script/
|
||||||
COPY package.json yarn.lock ./
|
COPY package.json yarn.lock ./
|
||||||
RUN yarn install --frozen-lockfile
|
RUN script/bootstrap
|
||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
|
|||||||
107
LICENSE
107
LICENSE
@@ -672,3 +672,110 @@ may consider it more useful to permit linking proprietary applications with
|
|||||||
the library. If this is what you want to do, use the GNU Lesser General
|
the library. If this is what you want to do, use the GNU Lesser General
|
||||||
Public License instead of this License. But first, please read
|
Public License instead of this License. But first, please read
|
||||||
<https://www.gnu.org/licenses/why-not-lgpl.html>.
|
<https://www.gnu.org/licenses/why-not-lgpl.html>.
|
||||||
|
|
||||||
|
===========================================================================
|
||||||
|
THIRD-PARTY FILES
|
||||||
|
===========================================================================
|
||||||
|
|
||||||
|
The following files are not original to this project and are distributed
|
||||||
|
under their own licenses. They are NOT covered by the GPL-3.0 license above.
|
||||||
|
|
||||||
|
---------------------------------------------------------------------------
|
||||||
|
File: src/shared/phishingBlocklist.json
|
||||||
|
Source: https://github.com/AugurProject/eth-phishing-detect (config.json)
|
||||||
|
Copyright: Copyright (c) 2018 kumavis
|
||||||
|
License: Don't Be a Dick Public License (DBAD), Version 1.2
|
||||||
|
---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
DON'T BE A DICK PUBLIC LICENSE
|
||||||
|
|
||||||
|
Version 1.2, February 2021
|
||||||
|
|
||||||
|
Copyright (C) 2018 kumavis
|
||||||
|
|
||||||
|
Everyone is permitted to copy and distribute verbatim or modified
|
||||||
|
copies of this license document.
|
||||||
|
|
||||||
|
DON'T BE A DICK PUBLIC LICENSE
|
||||||
|
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
|
||||||
|
|
||||||
|
1. Do whatever you like with the original work, just don't be a dick.
|
||||||
|
|
||||||
|
Being a dick includes - but is not limited to - the following instances:
|
||||||
|
|
||||||
|
1a. Outright copyright infringement - Don't just copy the original
|
||||||
|
work/works and change the name.
|
||||||
|
1b. Selling the unmodified original with no work done what-so-ever,
|
||||||
|
that's REALLY being a dick.
|
||||||
|
1c. Modifying the original work to contain hidden harmful content.
|
||||||
|
That would make you a PROPER dick.
|
||||||
|
|
||||||
|
2. If you become rich through modifications, related works/services, or
|
||||||
|
supporting the original work, share the love. Only a dick would make
|
||||||
|
loads off this work and not buy the original work's creator(s) a pint.
|
||||||
|
|
||||||
|
3. Code is provided with no warranty. Using somebody else's code and
|
||||||
|
bitching when it goes wrong makes you a DONKEY dick. Fix the problem
|
||||||
|
yourself. A non-dick would submit the fix back or submit a bug report.
|
||||||
|
|
||||||
|
4. If you use code, calling it your own would make you a ROYAL dick.
|
||||||
|
Alternatively, even just a comment giving attribution to where you found
|
||||||
|
the code would be OK.
|
||||||
|
|
||||||
|
---------------------------------------------------------------------------
|
||||||
|
File: src/shared/scamlist.js (address data from MyEtherWallet ethereum-lists)
|
||||||
|
Source: https://github.com/MyEtherWallet/ethereum-lists (addresses-darklist.json)
|
||||||
|
Copyright: Copyright (c) 2020 MyEtherWallet
|
||||||
|
License: MIT License
|
||||||
|
---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
MIT License
|
||||||
|
|
||||||
|
Copyright (c) 2020 MyEtherWallet
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
in the Software without restriction, including without limitation the rights
|
||||||
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all
|
||||||
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
|
SOFTWARE.
|
||||||
|
|
||||||
|
---------------------------------------------------------------------------
|
||||||
|
File: src/shared/scamlist.js (address data from EtherScamDB)
|
||||||
|
Source: https://github.com/MrLuit/EtherScamDB (scams.yaml)
|
||||||
|
Copyright: Copyright (c) 2018 Luit Hollander
|
||||||
|
License: MIT License
|
||||||
|
---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
MIT License
|
||||||
|
|
||||||
|
Copyright (c) 2018 Luit Hollander
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
in the Software without restriction, including without limitation the rights
|
||||||
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all
|
||||||
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
|
SOFTWARE.
|
||||||
|
|||||||
65
Makefile
65
Makefile
@@ -1,29 +1,60 @@
|
|||||||
.PHONY: install test lint fmt fmt-check check docker hooks build clean dev
|
.PHONY: bootstrap setup install test test-e2e lint fmt fmt-check check docker hooks build build-debug verify-build clean dev
|
||||||
|
|
||||||
|
# Standard targets are thin shims; the implementations live in script/
|
||||||
|
# per the scripts-to-rule-them-all pattern (see the Entrypoints section
|
||||||
|
# of README.md).
|
||||||
|
|
||||||
|
bootstrap:
|
||||||
|
@script/bootstrap
|
||||||
|
|
||||||
|
setup:
|
||||||
|
@script/setup
|
||||||
|
|
||||||
install:
|
install:
|
||||||
@yarn install
|
@yarn install --frozen-lockfile
|
||||||
|
|
||||||
test:
|
test:
|
||||||
@echo "Running tests..."
|
@script/test
|
||||||
@timeout 30 yarn run test 2>&1
|
|
||||||
|
# Browser end-to-end suite. Requires docker; not part of check.
|
||||||
|
test-e2e:
|
||||||
|
@script/test-e2e
|
||||||
|
|
||||||
lint:
|
lint:
|
||||||
@echo "Linting..."
|
@script/lint
|
||||||
@yarn run lint 2>&1
|
|
||||||
|
|
||||||
fmt:
|
fmt:
|
||||||
@echo "Formatting..."
|
@script/fmt
|
||||||
@yarn run fmt 2>&1
|
|
||||||
|
|
||||||
fmt-check:
|
fmt-check:
|
||||||
@echo "Checking formatting..."
|
@script/fmt-check
|
||||||
@yarn run fmt-check 2>&1
|
|
||||||
|
|
||||||
check: test lint fmt-check
|
check:
|
||||||
|
@script/check
|
||||||
|
|
||||||
|
docker:
|
||||||
|
@script/docker
|
||||||
|
|
||||||
|
hooks:
|
||||||
|
@script/install-precommit
|
||||||
|
|
||||||
build:
|
build:
|
||||||
@echo "Building extension..."
|
@echo "Building extension..."
|
||||||
@yarn run build 2>&1
|
@yarn run build 2>&1
|
||||||
|
@script/verify-build
|
||||||
|
|
||||||
|
# Development-only build: enables the red DEBUG / INSECURE banner and makes
|
||||||
|
# the hardcoded test recovery phrase the output of wallet creation. Never
|
||||||
|
# distribute the artifacts this produces.
|
||||||
|
build-debug:
|
||||||
|
@echo "Building extension (DEBUG)..."
|
||||||
|
@AUTISTMASK_DEBUG=1 yarn run build 2>&1
|
||||||
|
@AUTISTMASK_DEBUG=1 script/verify-build
|
||||||
|
|
||||||
|
# Assert the compiled DEBUG state of the bundles already in dist/. Runs at
|
||||||
|
# the end of build and build-debug; separate target for re-running it alone.
|
||||||
|
verify-build:
|
||||||
|
@script/verify-build
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
@rm -rf dist/
|
@rm -rf dist/
|
||||||
@@ -31,15 +62,3 @@ clean:
|
|||||||
dev:
|
dev:
|
||||||
@echo "Building in watch mode..."
|
@echo "Building in watch mode..."
|
||||||
@yarn run build --watch 2>&1
|
@yarn run build --watch 2>&1
|
||||||
|
|
||||||
docker:
|
|
||||||
@docker build -t autistmask .
|
|
||||||
|
|
||||||
hooks:
|
|
||||||
@echo "Installing pre-commit hook..."
|
|
||||||
@mkdir -p .git/hooks
|
|
||||||
@echo '#!/usr/bin/env bash' > .git/hooks/pre-commit
|
|
||||||
@echo 'set -euo pipefail' >> .git/hooks/pre-commit
|
|
||||||
@echo 'make check' >> .git/hooks/pre-commit
|
|
||||||
@chmod +x .git/hooks/pre-commit
|
|
||||||
@echo "Pre-commit hook installed."
|
|
||||||
|
|||||||
252
REPO_POLICIES.md
252
REPO_POLICIES.md
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Repository Policies
|
title: Repository Policies
|
||||||
last_modified: 2026-02-22
|
last_modified: 2026-07-06
|
||||||
---
|
---
|
||||||
|
|
||||||
This document covers repository structure, tooling, and workflow standards. Code
|
This document covers repository structure, tooling, and workflow standards. Code
|
||||||
@@ -34,10 +34,46 @@ style conventions are in separate documents:
|
|||||||
every file before committing. There are zero exceptions to this rule.
|
every file before committing. There are zero exceptions to this rule.
|
||||||
|
|
||||||
- Every repo with software must have a root `Makefile` with these targets:
|
- Every repo with software must have a root `Makefile` with these targets:
|
||||||
`make test`, `make lint`, `make fmt` (writes), `make fmt-check` (read-only),
|
`make bootstrap`, `make setup`, `make test`, `make lint`, `make fmt` (writes),
|
||||||
`make check` (prereqs: `test`, `lint`, `fmt-check`), `make docker`, and
|
`make fmt-check` (read-only), `make check` (runs `test`, `lint`, `fmt-check`),
|
||||||
`make hooks` (installs pre-commit hook). A model Makefile is at
|
`make docker`, and `make hooks` (installs pre-commit hook). A model Makefile
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/Makefile`.
|
is at `https://git.eeqj.de/sneak/prompts/raw/branch/main/Makefile`.
|
||||||
|
|
||||||
|
- Repos follow the
|
||||||
|
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
|
||||||
|
pattern: the implementation of each Makefile target lives in an executable
|
||||||
|
script in `script/` (`script/bootstrap`, `script/setup`, `script/test`,
|
||||||
|
`script/lint`, `script/fmt`, `script/fmt-check`, `script/check`,
|
||||||
|
`script/docker`), and the Makefile targets are thin shims that call them. The
|
||||||
|
scripts must be POSIX sh (`#!/bin/sh`, `set -eu`, no bashisms) so they run in
|
||||||
|
minimal containers (e.g. alpine images have no bash); locate the repo root
|
||||||
|
with `$(cd "$(dirname "$0")/.." && pwd -P)` and `cd` there before acting. From
|
||||||
|
the standard's canonical set we use `bootstrap`, `setup` (make the repo ready
|
||||||
|
for development after a fresh clone: runs `bootstrap`, then
|
||||||
|
`install-precommit`, plus any repo-specific initialization), `test`, and
|
||||||
|
`cibuild`. `script/bootstrap` installs all dependencies idempotently and
|
||||||
|
assumes nothing is present: base tools come from nix, apt, brew, or apk
|
||||||
|
(detected in that order; apt runs noninteractive). For node it uses the
|
||||||
|
installed node if present; otherwise it installs a PINNED node version via
|
||||||
|
nvm, first installing nvm itself if missing — from a hash-verified GitHub
|
||||||
|
release archive (never `curl | sh`), with bash installed as an explicit
|
||||||
|
prerequisite since nvm requires bash. yarn is then pinned via
|
||||||
|
`corepack prepare yarn@<version> --activate`. Never install "latest" or "lts";
|
||||||
|
always exact versions. `script/cibuild` runs the CI build: it changes to the
|
||||||
|
repo root and runs `docker build .`; the Gitea workflow calls it. Four further
|
||||||
|
scripts are our own extensions to the standard: `script/check` runs
|
||||||
|
`script/test`, `script/lint`, and `script/fmt-check`; `script/precommit` is
|
||||||
|
what the git pre-commit hook runs, and it calls `script/check`;
|
||||||
|
`script/install-precommit` installs the git pre-commit hook (the `make hooks`
|
||||||
|
target shims to it); and `script/projectname` (literally that filename) simply
|
||||||
|
outputs the project's name. Scripts that need the name call
|
||||||
|
`script/projectname` — e.g. `script/docker` assembles its image tag from it —
|
||||||
|
so those scripts stay byte-identical across all repos. Repo-type-specific
|
||||||
|
pre-commit extras (e.g. `go mod tidy` verification in Go repos) belong in
|
||||||
|
`script/precommit`, not in the hook itself. Model scripts are at
|
||||||
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/script/<name>`. The README
|
||||||
|
must document the provided scripts in an **Entrypoints** section (see the
|
||||||
|
README requirements below).
|
||||||
|
|
||||||
- Always use Makefile targets (`make fmt`, `make test`, `make lint`, etc.)
|
- Always use Makefile targets (`make fmt`, `make test`, `make lint`, etc.)
|
||||||
instead of invoking the underlying tools directly. The Makefile is the single
|
instead of invoking the underlying tools directly. The Makefile is the single
|
||||||
@@ -57,11 +93,83 @@ style conventions are in separate documents:
|
|||||||
as a build step so the build fails if the branch is not green. For non-server
|
as a build step so the build fails if the branch is not green. For non-server
|
||||||
repos, the Dockerfile should bring up a development environment and run
|
repos, the Dockerfile should bring up a development environment and run
|
||||||
`make check`. For server repos, `make check` should run as an early build
|
`make check`. For server repos, `make check` should run as an early build
|
||||||
stage before the final image is assembled.
|
stage before the final image is assembled. Dockerfiles install development
|
||||||
|
prerequisites by running `script/bootstrap` rather than duplicating installs
|
||||||
|
inline; COPY `script/` and the dependency manifests (`package.json` +
|
||||||
|
`yarn.lock`, `go.mod` + `go.sum`, etc.) before running it so the bootstrap
|
||||||
|
layer stays cached until dependencies change.
|
||||||
|
|
||||||
|
- **Dockerfiles must use a separate lint stage for fail-fast feedback.** Go
|
||||||
|
repos use a multistage build where linting runs in an independent stage based
|
||||||
|
on the `golangci/golangci-lint` image (pinned by hash). This stage runs
|
||||||
|
`make fmt-check` and `make lint` before the full build begins. The build stage
|
||||||
|
then declares an explicit dependency on the lint stage via
|
||||||
|
`COPY --from=lint /src/go.sum /dev/null`, which forces BuildKit to complete
|
||||||
|
linting before proceeding to compilation and tests. This ensures lint failures
|
||||||
|
surface in seconds rather than minutes, without blocking on dependency
|
||||||
|
download or compilation in the build stage.
|
||||||
|
|
||||||
|
The standard pattern for a Go repo Dockerfile is:
|
||||||
|
|
||||||
|
```dockerfile
|
||||||
|
# Lint stage — fast feedback on formatting and lint issues
|
||||||
|
# golangci/golangci-lint:v2.x.x, YYYY-MM-DD
|
||||||
|
FROM golangci/golangci-lint@sha256:... AS lint
|
||||||
|
WORKDIR /src
|
||||||
|
COPY go.mod go.sum ./
|
||||||
|
RUN go mod download
|
||||||
|
COPY . .
|
||||||
|
RUN make fmt-check
|
||||||
|
RUN make lint
|
||||||
|
|
||||||
|
# Build stage
|
||||||
|
# golang:1.x-alpine, YYYY-MM-DD
|
||||||
|
FROM golang@sha256:... AS builder
|
||||||
|
WORKDIR /src
|
||||||
|
|
||||||
|
# Force BuildKit to run the lint stage before proceeding
|
||||||
|
COPY --from=lint /src/go.sum /dev/null
|
||||||
|
|
||||||
|
COPY go.mod go.sum ./
|
||||||
|
RUN go mod download
|
||||||
|
COPY . .
|
||||||
|
RUN make test
|
||||||
|
|
||||||
|
ARG VERSION=dev
|
||||||
|
RUN CGO_ENABLED=0 go build -trimpath \
|
||||||
|
-ldflags="-s -w -X main.Version=${VERSION}" \
|
||||||
|
-o /app ./cmd/app/
|
||||||
|
|
||||||
|
# Runtime stage
|
||||||
|
FROM alpine@sha256:...
|
||||||
|
COPY --from=builder /app /usr/local/bin/app
|
||||||
|
ENTRYPOINT ["app"]
|
||||||
|
```
|
||||||
|
|
||||||
|
Key points:
|
||||||
|
- The lint stage uses the `golangci/golangci-lint` image directly (it
|
||||||
|
includes both Go and the linter), so there is no need to install the
|
||||||
|
linter separately.
|
||||||
|
- `COPY --from=lint /src/go.sum /dev/null` is a no-op file copy that creates
|
||||||
|
a stage dependency. BuildKit runs stages in parallel by default; without
|
||||||
|
this line, the build stage would not wait for lint to finish and a lint
|
||||||
|
failure might not fail the overall build.
|
||||||
|
- If the project uses `//go:embed` directives that reference build artifacts
|
||||||
|
(e.g. a web frontend compiled in a separate stage), the lint stage must
|
||||||
|
create placeholder files so the embed directives resolve. Example:
|
||||||
|
`RUN mkdir -p web/dist && touch web/dist/index.html web/dist/style.css`.
|
||||||
|
The lint stage should not depend on the actual build output — it exists to
|
||||||
|
fail fast.
|
||||||
|
- If the project requires CGO or system libraries for linting (e.g.
|
||||||
|
`vips-dev`), install them in the lint stage with `apk add`.
|
||||||
|
- The build stage runs `make test` after compilation setup. Tests run in the
|
||||||
|
build stage, not the lint stage, because they may require compiled
|
||||||
|
artifacts or heavier dependencies.
|
||||||
|
|
||||||
- Every repo should have a Gitea Actions workflow (`.gitea/workflows/`) that
|
- Every repo should have a Gitea Actions workflow (`.gitea/workflows/`) that
|
||||||
runs `docker build .` on push. Since the Dockerfile already runs `make check`,
|
runs `script/cibuild` (which runs `docker build .`) on push. Since the
|
||||||
a successful build implies all checks pass.
|
Dockerfile already runs `make check`, a successful build implies all checks
|
||||||
|
pass.
|
||||||
|
|
||||||
- Use platform-standard formatters: `black` for Python, `prettier` for
|
- Use platform-standard formatters: `black` for Python, `prettier` for
|
||||||
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
|
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
|
||||||
@@ -69,9 +177,11 @@ style conventions are in separate documents:
|
|||||||
Markdown (hard-wrap at 80 columns). Documentation and writing repos (Markdown,
|
Markdown (hard-wrap at 80 columns). Documentation and writing repos (Markdown,
|
||||||
HTML, CSS) should also have `.prettierrc` and `.prettierignore`.
|
HTML, CSS) should also have `.prettierrc` and `.prettierignore`.
|
||||||
|
|
||||||
- Pre-commit hook: `make check` if local testing is possible, otherwise
|
- Pre-commit hook: runs `script/precommit`, which calls `script/check`. If local
|
||||||
`make lint && make fmt-check`. The Makefile should provide a `make hooks`
|
testing is not possible in the repo, `script/precommit` may skip `script/test`
|
||||||
target to install the pre-commit hook.
|
and run only `script/lint` and `script/fmt-check`. The hook is installed by
|
||||||
|
`script/install-precommit`; the Makefile must provide a `make hooks` target
|
||||||
|
that shims to it.
|
||||||
|
|
||||||
- All repos with software must have tests that run via the platform-standard
|
- All repos with software must have tests that run via the platform-standard
|
||||||
test framework (`go test`, `pytest`, `jest`/`vitest`, etc.). If no meaningful
|
test framework (`go test`, `pytest`, `jest`/`vitest`, etc.). If no meaningful
|
||||||
@@ -82,6 +192,42 @@ style conventions are in separate documents:
|
|||||||
- `make test` must complete in under 20 seconds. Add a 30-second timeout in the
|
- `make test` must complete in under 20 seconds. Add a 30-second timeout in the
|
||||||
Makefile.
|
Makefile.
|
||||||
|
|
||||||
|
- **`make test` should use the conditional verbose rerun pattern.** Run tests
|
||||||
|
without `-v` (verbose) first. If tests fail, automatically rerun with `-v` to
|
||||||
|
show full output. This keeps CI logs and `docker build` output clean on
|
||||||
|
success (just package/suite summaries) while providing full diagnostic detail
|
||||||
|
on failure (every test case, every assertion). The general shell pattern:
|
||||||
|
|
||||||
|
```makefile
|
||||||
|
test:
|
||||||
|
@<test-command> || \
|
||||||
|
{ echo "--- Rerunning with -v for details ---"; \
|
||||||
|
<test-command-with-v>; exit 1; }
|
||||||
|
```
|
||||||
|
|
||||||
|
Go example:
|
||||||
|
|
||||||
|
```makefile
|
||||||
|
test:
|
||||||
|
@go test -timeout 30s -race -cover ./... || \
|
||||||
|
{ echo "--- Rerunning with -v for details ---"; \
|
||||||
|
go test -timeout 30s -race -v ./...; exit 1; }
|
||||||
|
```
|
||||||
|
|
||||||
|
Python example:
|
||||||
|
|
||||||
|
```makefile
|
||||||
|
test:
|
||||||
|
@python -m pytest || \
|
||||||
|
{ echo "--- Rerunning with -v for details ---"; \
|
||||||
|
python -m pytest -v; exit 1; }
|
||||||
|
```
|
||||||
|
|
||||||
|
The `exit 1` ensures the target always fails after a rerun — the first run
|
||||||
|
already proved the tests are broken, so the build must not pass even if a
|
||||||
|
flaky test happens to succeed on the second attempt. The rerun exists solely
|
||||||
|
for diagnostic output.
|
||||||
|
|
||||||
- Docker builds must complete in under 5 minutes.
|
- Docker builds must complete in under 5 minutes.
|
||||||
|
|
||||||
- `make check` must not modify any files in the repo. Tests may use temporary
|
- `make check` must not modify any files in the repo. Tests may use temporary
|
||||||
@@ -98,6 +244,13 @@ style conventions are in separate documents:
|
|||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` when setting up
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` when setting up
|
||||||
a new repo.
|
a new repo.
|
||||||
|
|
||||||
|
- **No build artifacts in version control.** Code-derived data (compiled
|
||||||
|
bundles, minified output, generated assets) must never be committed to the
|
||||||
|
repository if it can be avoided. The build process (e.g. Dockerfile, Makefile)
|
||||||
|
should generate these at build time. Notable exception: Go protobuf generated
|
||||||
|
files (`.pb.go`) ARE committed because repos need to work with `go get`, which
|
||||||
|
downloads code but does not execute code generation.
|
||||||
|
|
||||||
- Never use `git add -A` or `git add .`. Always stage files explicitly by name.
|
- Never use `git add -A` or `git add .`. Always stage files explicitly by name.
|
||||||
|
|
||||||
- Never force-push to `main`.
|
- Never force-push to `main`.
|
||||||
@@ -121,12 +274,76 @@ style conventions are in separate documents:
|
|||||||
- Dockerized web services listen on port 8080 by default, overridable with
|
- Dockerized web services listen on port 8080 by default, overridable with
|
||||||
`PORT`.
|
`PORT`.
|
||||||
|
|
||||||
|
- **HTTP/web services must be hardened for production internet exposure before
|
||||||
|
tagging 1.0.** This means full compliance with security best practices
|
||||||
|
including, without limitation, all of the following:
|
||||||
|
- **Security headers** on every response:
|
||||||
|
- `Strict-Transport-Security` (HSTS) with `max-age` of at least one year
|
||||||
|
and `includeSubDomains`.
|
||||||
|
- `Content-Security-Policy` (CSP) with a restrictive default policy
|
||||||
|
(`default-src 'self'` as a baseline, tightened per-resource as
|
||||||
|
needed). Never use `unsafe-inline` or `unsafe-eval` unless
|
||||||
|
unavoidable, and document the reason.
|
||||||
|
- `X-Frame-Options: DENY` (or `SAMEORIGIN` if framing is required).
|
||||||
|
Prefer the `frame-ancestors` CSP directive as the primary control.
|
||||||
|
- `X-Content-Type-Options: nosniff`.
|
||||||
|
- `Referrer-Policy: strict-origin-when-cross-origin` (or stricter).
|
||||||
|
- `Permissions-Policy` restricting access to browser features the
|
||||||
|
application does not use (camera, microphone, geolocation, etc.).
|
||||||
|
- **Request and response limits:**
|
||||||
|
- Maximum request body size enforced on all endpoints (e.g. Go
|
||||||
|
`http.MaxBytesReader`). Choose a sane default per-route; never accept
|
||||||
|
unbounded input.
|
||||||
|
- Maximum response body size where applicable (e.g. paginated APIs).
|
||||||
|
- `ReadTimeout` and `ReadHeaderTimeout` on the `http.Server` to defend
|
||||||
|
against slowloris attacks.
|
||||||
|
- `WriteTimeout` on the `http.Server`.
|
||||||
|
- `IdleTimeout` on the `http.Server`.
|
||||||
|
- Per-handler execution time limits via `context.WithTimeout` or
|
||||||
|
chi/stdlib `middleware.Timeout`.
|
||||||
|
- **Authentication and session security:**
|
||||||
|
- Rate limiting on password-based authentication endpoints. API keys are
|
||||||
|
high-entropy and not susceptible to brute force, so they are exempt.
|
||||||
|
- CSRF tokens on all state-mutating HTML forms. API endpoints
|
||||||
|
authenticated via `Authorization` header (Bearer token, API key) are
|
||||||
|
exempt because the browser does not attach these automatically.
|
||||||
|
- Passwords stored using bcrypt, scrypt, or argon2 — never plain-text,
|
||||||
|
MD5, or SHA.
|
||||||
|
- Session cookies set with `HttpOnly`, `Secure`, and `SameSite=Lax` (or
|
||||||
|
`Strict`) attributes.
|
||||||
|
- **Reverse proxy awareness:**
|
||||||
|
- True client IP detection when behind a reverse proxy
|
||||||
|
(`X-Forwarded-For`, `X-Real-IP`). The application must accept
|
||||||
|
forwarded headers only from a configured set of trusted proxy
|
||||||
|
addresses — never trust `X-Forwarded-For` unconditionally.
|
||||||
|
- **CORS:**
|
||||||
|
- Authenticated endpoints must restrict `Access-Control-Allow-Origin` to
|
||||||
|
an explicit allowlist of known origins. Wildcard (`*`) is acceptable
|
||||||
|
only for public, unauthenticated read-only APIs.
|
||||||
|
- **Error handling:**
|
||||||
|
- Internal errors must never leak stack traces, SQL queries, file paths,
|
||||||
|
or other implementation details to the client. Return generic error
|
||||||
|
messages in production; detailed errors only when `DEBUG` is enabled.
|
||||||
|
- **TLS:**
|
||||||
|
- Services never terminate TLS directly. They are always deployed behind
|
||||||
|
a TLS-terminating reverse proxy. The service itself listens on plain
|
||||||
|
HTTP. However, HSTS headers and `Secure` cookie flags must still be
|
||||||
|
set by the application so that the browser enforces HTTPS end-to-end.
|
||||||
|
|
||||||
|
This list is non-exhaustive. Apply defense-in-depth: if a standard security
|
||||||
|
hardening measure exists for HTTP services and is not listed here, it is
|
||||||
|
still expected. When in doubt, harden.
|
||||||
|
|
||||||
- `README.md` is the primary documentation. Required sections:
|
- `README.md` is the primary documentation. Required sections:
|
||||||
- **Description**: First line must include the project name, purpose,
|
- **Description**: First line must include the project name, purpose,
|
||||||
category (web server, SPA, CLI tool, etc.), license, and author. Example:
|
category (web server, SPA, CLI tool, etc.), license, and author. Example:
|
||||||
"µPaaS is an MIT-licensed Go web application by @sneak that receives
|
"µPaaS is an MIT-licensed Go web application by @sneak that receives
|
||||||
git-frontend webhooks and deploys applications via Docker in realtime."
|
git-frontend webhooks and deploys applications via Docker in realtime."
|
||||||
- **Getting Started**: Copy-pasteable install/usage code block.
|
- **Getting Started**: Copy-pasteable install/usage code block.
|
||||||
|
- **Entrypoints**: Opens by stating that the repo adheres to the
|
||||||
|
[Scripts to Rule Them All](https://github.com/github/scripts-to-rule-them-all)
|
||||||
|
standard (with that link), then documents each provided `script/`
|
||||||
|
entrypoint and its purpose.
|
||||||
- **Rationale**: Why does this exist?
|
- **Rationale**: Why does this exist?
|
||||||
- **Design**: How is the program structured?
|
- **Design**: How is the program structured?
|
||||||
- **TODO**: Update meticulously, even between commits. When planning, put
|
- **TODO**: Update meticulously, even between commits. When planning, put
|
||||||
@@ -144,8 +361,14 @@ style conventions are in separate documents:
|
|||||||
- Use SemVer.
|
- Use SemVer.
|
||||||
|
|
||||||
- Database migrations live in `internal/db/migrations/` and must be embedded in
|
- Database migrations live in `internal/db/migrations/` and must be embedded in
|
||||||
the binary. Pre-1.0.0: modify existing migrations (no installed base assumed).
|
the binary.
|
||||||
Post-1.0.0: add new migration files.
|
- `000_migration.sql` — contains ONLY the creation of the migrations
|
||||||
|
tracking table itself. Nothing else.
|
||||||
|
- `001_schema.sql` — the full application schema.
|
||||||
|
- **Pre-1.0.0:** never add additional migration files (002, 003, etc.).
|
||||||
|
There is no installed base to migrate. Edit `001_schema.sql` directly.
|
||||||
|
- **Post-1.0.0:** add new numbered migration files for each schema change.
|
||||||
|
Never edit existing migrations after release.
|
||||||
|
|
||||||
- All repos should have an `.editorconfig` enforcing the project's indentation
|
- All repos should have an `.editorconfig` enforcing the project's indentation
|
||||||
settings.
|
settings.
|
||||||
@@ -175,6 +398,9 @@ style conventions are in separate documents:
|
|||||||
- `README.md`, `.git`, `.gitignore`, `.editorconfig`
|
- `README.md`, `.git`, `.gitignore`, `.editorconfig`
|
||||||
- `LICENSE`, `REPO_POLICIES.md` (copy from the `prompts` repo)
|
- `LICENSE`, `REPO_POLICIES.md` (copy from the `prompts` repo)
|
||||||
- `Makefile`
|
- `Makefile`
|
||||||
|
- `script/` entrypoints (`bootstrap`, `setup`, `projectname`, `test`,
|
||||||
|
`lint`, `fmt`, `fmt-check`, `check`, `docker`, `cibuild`, `precommit`,
|
||||||
|
`install-precommit`)
|
||||||
- `Dockerfile`, `.dockerignore`
|
- `Dockerfile`, `.dockerignore`
|
||||||
- `.gitea/workflows/check.yml`
|
- `.gitea/workflows/check.yml`
|
||||||
- Go: `go.mod`, `go.sum`, `.golangci.yml`
|
- Go: `go.mod`, `go.sum`, `.golangci.yml`
|
||||||
|
|||||||
252
TODO.md
Normal file
252
TODO.md
Normal file
@@ -0,0 +1,252 @@
|
|||||||
|
# Workflow
|
||||||
|
|
||||||
|
- `git pull` `next` and cut a branch from it — one branch per issue, named
|
||||||
|
`issue-<N>-<slug>`. Never branch from `main`.
|
||||||
|
- Do the work as one commit whose title ends with ` (closes #N)`, with the
|
||||||
|
`TODO.md` update in that same commit.
|
||||||
|
- Move Next Step to the top of Completed Steps; move the top item of Future
|
||||||
|
Steps into Next Step.
|
||||||
|
- Run `make fmt`, then `make check`. A feature branch may be red; `next` and
|
||||||
|
`main` may not.
|
||||||
|
- Rebase onto current `next` immediately before pushing — other branches land on
|
||||||
|
`next` continuously — and re-run `make check` after resolving, because a clean
|
||||||
|
textual merge can still break the build.
|
||||||
|
- Push the branch and open one PR per issue with base `next`. Never base `main`.
|
||||||
|
- An independent reviewer who did not write the change gates the merge. On a
|
||||||
|
passed review the PR is squash-merged into `next`.
|
||||||
|
- `next` is the branch for the next milestone. It is kept green and mergeable to
|
||||||
|
`main` at any moment, without notice.
|
||||||
|
- `main` receives exactly one PR per milestone, from `next`. Releases are tagged
|
||||||
|
from `main`.
|
||||||
|
|
||||||
|
# Status
|
||||||
|
|
||||||
|
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
|
||||||
|
milestone is in flight on `next`; its `next` -> `main` PR is
|
||||||
|
[#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified
|
||||||
|
green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces
|
||||||
|
`dist/chrome/` and `dist/firefox/` with every bundle verified to have `DEBUG`
|
||||||
|
compiled off.
|
||||||
|
|
||||||
|
The backlog lives on the
|
||||||
|
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
|
||||||
|
authoritative; this file does not duplicate it. Full policy file set present. A
|
||||||
|
real-browser end-to-end suite (`make test-e2e`) now sits alongside `make check`,
|
||||||
|
which cannot see a runtime `ReferenceError` in a popup view.
|
||||||
|
|
||||||
|
# Next Step
|
||||||
|
|
||||||
|
Land [#152](https://git.eeqj.de/sneak/AutistMask/issues/152): add ESLint to
|
||||||
|
`script/lint`. `make check` is `prettier --check` only today and cannot catch
|
||||||
|
undefined identifiers, which is how
|
||||||
|
[#150](https://git.eeqj.de/sneak/AutistMask/issues/150) and
|
||||||
|
[#151](https://git.eeqj.de/sneak/AutistMask/issues/151) shipped.
|
||||||
|
|
||||||
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-08-12: The transaction confirmation screen has browser coverage. The
|
||||||
|
end-to-end suite reaches ConfirmTx for both the native ETH and the ERC-20 path
|
||||||
|
off a funded-balance fixture, and asserts the pending, funded, over-balance
|
||||||
|
and estimate-failed states, the fee block quoting the estimate and the reserve
|
||||||
|
separately, and a constant view height across every one of those transitions.
|
||||||
|
The load-bearing assertion is that the spend gate reads the reserve and not
|
||||||
|
the displayed estimate: swapping the two fails the suite
|
||||||
|
([#238](https://git.eeqj.de/sneak/AutistMask/issues/238)).
|
||||||
|
- 2026-08-12: The dust threshold field now explains a rejection instead of
|
||||||
|
snapping back in silence, with the parse in a pure, unit-tested module that
|
||||||
|
accepts plain decimal digits only — hex and exponent notation are refused
|
||||||
|
rather than read as 16 and 1000
|
||||||
|
([#233](https://git.eeqj.de/sneak/AutistMask/issues/233)).
|
||||||
|
- 2026-08-12: Approval verification became an allowlist — transaction type
|
||||||
|
restricted to 0/1/2 so an EIP-7702 delegation can no longer ride along on an
|
||||||
|
approved transfer, every consequential field compared, the artifact
|
||||||
|
re-serialized from the checked fields alone and its exact bytes required to be
|
||||||
|
the canonical encoding of what was broadcast. One approval now yields at most
|
||||||
|
one broadcast, and every path that retires a pending approval — popup close,
|
||||||
|
active-address change, a late reject — goes through a single chokepoint that
|
||||||
|
refuses to settle an attempt already claimed for signing and broadcast
|
||||||
|
([#174](https://git.eeqj.de/sneak/AutistMask/issues/174)).
|
||||||
|
- 2026-08-12: An address can be removed from an HD or xprv wallet behind a
|
||||||
|
confirmation screen that states nothing is destroyed, sharing the deletion
|
||||||
|
state transitions with wallet deletion so the selection, site permissions and
|
||||||
|
active-address broadcast follow the same rules
|
||||||
|
([#162](https://git.eeqj.de/sneak/AutistMask/issues/162)).
|
||||||
|
- 2026-08-12: The known-symbol spoof rule moved into `src/shared/symbolSpoof.js`
|
||||||
|
and is now the only copy. The balance list had exempted symbols the token list
|
||||||
|
maps to `null` — `"ETH"` alone — so a fake ETH ERC-20 was hidden from the
|
||||||
|
transaction history and the Send selector but listed as a holding named ETH. A
|
||||||
|
symbol with no legitimate contract may now be borne by no contract on any of
|
||||||
|
the three surfaces, and the native exemption is "has no contract address", so
|
||||||
|
a second null-mapped symbol needs no call-site change. The user's real ETH
|
||||||
|
balance is read over RPC and never passes through the rule
|
||||||
|
([#235](https://git.eeqj.de/sneak/AutistMask/issues/235)).
|
||||||
|
- 2026-08-12: `script/verify-build`'s failure modes are now a committed target,
|
||||||
|
`script/test-verify-build`, run by `make check`. It asserts the exit status
|
||||||
|
and the message of every case against a fixture tree in a temp dir, and drops
|
||||||
|
privileges (proving the runner against a mode-000 file first) for the cases
|
||||||
|
that only mean something when file permissions are in force
|
||||||
|
([#227](https://git.eeqj.de/sneak/AutistMask/issues/227)).
|
||||||
|
- 2026-08-12: WaitTx lifecycle: a receipt and the 60-second timeout can no
|
||||||
|
longer both render on one tick, no timer or in-flight lookup outlives its
|
||||||
|
wait, a failed receipt lookup no longer counts as a timeout (but six in a row
|
||||||
|
end the wait, reported as an unreachable network rather than as a timeout),
|
||||||
|
and the wait now resumes after a popup close
|
||||||
|
([#155](https://git.eeqj.de/sneak/AutistMask/issues/155)).
|
||||||
|
- 2026-08-12: The private key export screen now wipes the key from the page
|
||||||
|
whenever it is left by any route, and a decrypt still in flight when the
|
||||||
|
screen is left is discarded instead of written; the same `onViewLeave()`
|
||||||
|
cleanup was extended to every other screen holding secret material in the DOM
|
||||||
|
(AddWallet, ConfirmTx, DeleteWallet, ApproveTx, ApproveSign)
|
||||||
|
([#221](https://git.eeqj.de/sneak/AutistMask/issues/221)).
|
||||||
|
- 2026-08-12: An xprv wallet already in storage that was imported from a
|
||||||
|
non-master key is detected from the depth of its stored `xpub`, explained in
|
||||||
|
the wallet list, and blocked from signing, sending and private-key export
|
||||||
|
instead of throwing on the send screen
|
||||||
|
([#234](https://git.eeqj.de/sneak/AutistMask/issues/234)).
|
||||||
|
- 2026-08-12: An unreported `holders_count` is now parsed as `null` rather than
|
||||||
|
`0`, so the low-holder rule declines to judge an unknown count instead of
|
||||||
|
hiding a legitimate token as spam, in both the transaction history and the
|
||||||
|
Send token selector ([#230](https://git.eeqj.de/sneak/AutistMask/issues/230)).
|
||||||
|
- 2026-08-12: Bundled token list documentation no longer states a count. The
|
||||||
|
four "top 250" claims in `README.md` and the "roughly 500" claim in
|
||||||
|
`docs/README.md` are replaced with a description of how the list is actually
|
||||||
|
selected — a point-in-time CoinGecko snapshot of the highest-market-cap
|
||||||
|
Ethereum mainnet ERC-20s — with `TOKENS` in `src/shared/tokenList.js` named as
|
||||||
|
the authoritative set
|
||||||
|
([#239](https://git.eeqj.de/sneak/AutistMask/issues/239)).
|
||||||
|
- 2026-08-11: libsodium runs on WebAssembly in the shipped builds —
|
||||||
|
`'wasm-unsafe-eval'` added to both manifest CSPs after measuring the wasm2js
|
||||||
|
fallback at 20x the Argon2id cost, pinned in both directions by
|
||||||
|
`tests/manifest.test.js` and observed in the real popup by the e2e suite
|
||||||
|
([#182](https://git.eeqj.de/sneak/AutistMask/issues/182)).
|
||||||
|
- 2026-08-11: Known-symbol spoof verification became a Settings toggle
|
||||||
|
(`hideSpoofedSymbols`), on by default, governing the transaction-history
|
||||||
|
filter and the fraud-contract learning it feeds
|
||||||
|
([#176](https://git.eeqj.de/sneak/AutistMask/issues/176)).
|
||||||
|
- 2026-08-11: `script/verify-build` now walks `dist/` NUL-delimited and asserts
|
||||||
|
`dist/` is a real directory, so a path with a trailing space or a newline can
|
||||||
|
no longer carry a debug marker past the unlisted-bundle check
|
||||||
|
([#223](https://git.eeqj.de/sneak/AutistMask/issues/223)).
|
||||||
|
- 2026-08-11: UTC Timestamps checkbox moved from the Token Spam Protection well
|
||||||
|
into Display, next to the theme selector
|
||||||
|
([#212](https://git.eeqj.de/sneak/AutistMask/issues/212)).
|
||||||
|
- 2026-08-11: Network fee counted in the confirmation-screen balance check for
|
||||||
|
both ETH and ERC-20 sends, reserving what the node actually charges a type-2
|
||||||
|
transaction, with the arithmetic in a pure, unit-tested
|
||||||
|
`src/shared/txValidation.js`
|
||||||
|
([#154](https://git.eeqj.de/sneak/AutistMask/issues/154)).
|
||||||
|
- 2026-08-11: A dust threshold of `0` now means "hide nothing" instead of
|
||||||
|
falling back to the 100,000 gwei default, and every address comparison in
|
||||||
|
`src/shared/transactions.js` goes through one case-normalising helper so a
|
||||||
|
checksummed genuine contract is no longer read as a spoof
|
||||||
|
([#179](https://git.eeqj.de/sneak/AutistMask/issues/179)).
|
||||||
|
- 2026-08-11: Password-gated recovery phrase display for HD wallets, reached
|
||||||
|
from the wallet row in Settings, wiped on leaving the screen and excluded from
|
||||||
|
the views the popup can reopen onto
|
||||||
|
([#161](https://git.eeqj.de/sneak/AutistMask/issues/161)).
|
||||||
|
- 2026-08-11: Extended-key import hardened — the base58 checksum is now enforced
|
||||||
|
on every xprv and xpub, and a non-master key is refused with an explanation
|
||||||
|
instead of being derived beneath
|
||||||
|
([#210](https://git.eeqj.de/sneak/AutistMask/issues/210)).
|
||||||
|
- 2026-08-11: the balance refresh and the 24-hour phishing list refresh moved
|
||||||
|
from `setInterval` to the extension alarms API, with the phishing delta and
|
||||||
|
its fetch timestamps persisted to extension storage, so neither job dies with
|
||||||
|
the MV3 service worker. Each job's freshness guard was decoupled from its
|
||||||
|
alarm period at the same time — timed to the period, a guard vetoes its own
|
||||||
|
scheduled tick and halves the real refresh rate
|
||||||
|
([#158](https://git.eeqj.de/sneak/AutistMask/issues/158)).
|
||||||
|
- 2026-08-11: Policy compliance sweep — conditional verbose test rerun, local
|
||||||
|
Tailwind binary instead of `npx`, `--frozen-lockfile` on `make install`, and
|
||||||
|
the Makefile-only targets documented in the README
|
||||||
|
([#166](https://git.eeqj.de/sneak/AutistMask/issues/166)).
|
||||||
|
- 2026-08-11: `script/verify-build` diagnostics corrected: the both-markers
|
||||||
|
message now states what is and is not proven, an unreadable bundle is
|
||||||
|
diagnosed as an I/O fault rather than as changed output, the `*.js` assumption
|
||||||
|
lives only in `build.js`, and the unlisted-bundle scan hard-fails when it
|
||||||
|
cannot enumerate `dist/`
|
||||||
|
([#180](https://git.eeqj.de/sneak/AutistMask/issues/180)).
|
||||||
|
- 2026-08-11: Known-answer test coverage for the crypto core — BIP-39/BIP-32
|
||||||
|
derivation in `wallet.js` and the Argon2id vault in `vault.js`
|
||||||
|
([#159](https://git.eeqj.de/sneak/AutistMask/issues/159)).
|
||||||
|
- 2026-08-11: Three `README.md` claims corrected against the code — blocklist
|
||||||
|
attribution, token-display rule, navigation model
|
||||||
|
([#213](https://git.eeqj.de/sneak/AutistMask/issues/213)).
|
||||||
|
- 2026-08-11: README Screen Map rebuilt from the code — every screen, element
|
||||||
|
and transition re-verified against `src/popup/`
|
||||||
|
([#164](https://git.eeqj.de/sneak/AutistMask/issues/164)).
|
||||||
|
- 2026-08-11: `docs/README.md` rewritten against the code: no competitor names,
|
||||||
|
all five network destinations documented, password/Settings/Add Wallet
|
||||||
|
sections corrected ([#163](https://git.eeqj.de/sneak/AutistMask/issues/163)).
|
||||||
|
- 2026-08-11: `loadState()` now derives `hasWallet` from the wallet list instead
|
||||||
|
of trusting the persisted flag, so a profile already saved inconsistent no
|
||||||
|
longer stays broken on every load
|
||||||
|
([#195](https://git.eeqj.de/sneak/AutistMask/issues/195)).
|
||||||
|
- 2026-08-11: Wallet deletion repairs its own state — `hasWallet` follows the
|
||||||
|
remaining wallets, the selection only moves when it was deleted, and the
|
||||||
|
active-address change is broadcast to connected sites
|
||||||
|
([#156](https://git.eeqj.de/sneak/AutistMask/issues/156)).
|
||||||
|
- 2026-08-11: One row per on-chain value movement in transaction history: the
|
||||||
|
merge moved into the pure `mergeTransactions` and the zero-ETH native side of
|
||||||
|
a plain ERC-20 transfer absorbed into its token row
|
||||||
|
([#177](https://git.eeqj.de/sneak/AutistMask/issues/177)).
|
||||||
|
- 2026-08-11: `TODO.md` Workflow rewritten to the branch-and-PR-per-issue model
|
||||||
|
on `next`, with Status and Next Step refreshed
|
||||||
|
([#191](https://git.eeqj.de/sneak/AutistMask/issues/191)).
|
||||||
|
- 2026-08-09: `DEBUG` became a build-time constant defaulting to off, injected
|
||||||
|
as the `__BUILD_DEBUG__` esbuild define and turned on with
|
||||||
|
`AUTISTMASK_DEBUG=1`, so a plain `make build` no longer hands every newly
|
||||||
|
created wallet the publicly committed test recovery phrase
|
||||||
|
([#149](https://git.eeqj.de/sneak/AutistMask/issues/149)).
|
||||||
|
- 2026-08-09: dApp approval signing moved into the popup — the password no
|
||||||
|
longer crosses the extension messaging boundary; the background broadcasts and
|
||||||
|
resolves approvals only, and verifies the signed artifact against the approval
|
||||||
|
it holds (#157).
|
||||||
|
- 2026-08-09: Post-build assertion that every emitted bundle containing
|
||||||
|
`constants.js` has `DEBUG` compiled off, via `script/verify-build` on the
|
||||||
|
`make build` path (#170).
|
||||||
|
- 2026-08-09: Containerized Chrome end-to-end harness (`make test-e2e` /
|
||||||
|
`script/test-e2e`) driving the real popup with all network intercepted, plus
|
||||||
|
the two used-but-not-imported crashes it caught: AddToken unreachable (#150)
|
||||||
|
and TransactionDetail broken for every ERC-20 transfer (#151). Harness
|
||||||
|
demonstrated failing before the fixes and passing after (#181). Interception
|
||||||
|
covers the MV3 background service worker, not just the popup page, and a
|
||||||
|
launch-time canary aborts the suite if worker traffic starts escaping.
|
||||||
|
- 2026-08-09: Reviewed the repo end to end and filed the 1.0.0 backlog
|
||||||
|
(#149-#168).
|
||||||
|
- 2026-08-09: Test coverage for the address-poisoning defense in
|
||||||
|
`src/shared/transactions.js` (#160)
|
||||||
|
- 2026-07-26: About well in settings with build info, repo link and the version
|
||||||
|
click easter egg (#145); proper view navigation stack (#146).
|
||||||
|
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
|
||||||
|
shims, README Entrypoints section (#148)
|
||||||
|
- 2026-03-01: USD display suppressed on testnets (#142); estimated USD for ETH
|
||||||
|
in approve-tx view (#141).
|
||||||
|
- Sepolia testnet support (#137); etherscan links go to token-specific URLs
|
||||||
|
(#136).
|
||||||
|
- Transaction detail improvements: Type field and on-chain details (#130),
|
||||||
|
txid-first reordering (#133), swap display corrections (#128), expanded
|
||||||
|
confirm-tx warnings (#118).
|
||||||
|
- Dark mode theme setting (Light/Dark/System) with contrast fixes (#126);
|
||||||
|
timestamps include timezone offset (#120); layout shift audit, reserved space
|
||||||
|
for error messages (#124).
|
||||||
|
- Copy-flash visual feedback with timing tune (#113, #121); cross-wallet-type
|
||||||
|
duplicate detection (#115).
|
||||||
|
- 2026-02-27: v0.1.0 tagged.
|
||||||
|
- 2026-02-24: Initial scaffolding: popup UI, BIP-39 wallet creation via
|
||||||
|
ethers.js, wallet persistence, real ETH balances over RPC, ENS forward and
|
||||||
|
reverse resolution.
|
||||||
|
|
||||||
|
# Future Steps
|
||||||
|
|
||||||
|
Only work that has no issue of its own belongs here; everything else is on the
|
||||||
|
tracker.
|
||||||
|
|
||||||
|
- Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
||||||
|
input validation) before any 1.0rc tag. Individual filed issues are parts of
|
||||||
|
it, but the review is broader than any of them.
|
||||||
|
- Decide whether docker-in-docker makes `make test-e2e` runnable in the Gitea
|
||||||
|
workflow. Extending the suite itself is tracked as
|
||||||
|
[#183](https://git.eeqj.de/sneak/AutistMask/issues/183) and
|
||||||
|
[#184](https://git.eeqj.de/sneak/AutistMask/issues/184).
|
||||||
|
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
||||||
|
land.
|
||||||
200
build.js
200
build.js
@@ -3,75 +3,183 @@ const path = require("path");
|
|||||||
const { execSync } = require("child_process");
|
const { execSync } = require("child_process");
|
||||||
const esbuild = require("esbuild");
|
const esbuild = require("esbuild");
|
||||||
|
|
||||||
const DIST_CHROME = path.join(__dirname, "dist", "chrome");
|
const DIST = path.join(__dirname, "dist");
|
||||||
const DIST_FIREFOX = path.join(__dirname, "dist", "firefox");
|
const DIST_CHROME = path.join(DIST, "chrome");
|
||||||
|
const DIST_FIREFOX = path.join(DIST, "firefox");
|
||||||
const SRC = path.join(__dirname, "src");
|
const SRC = path.join(__dirname, "src");
|
||||||
|
|
||||||
|
// The module whose compiled DEBUG state script/verify-build asserts, and the
|
||||||
|
// manifest naming every emitted bundle that ends up containing it. The
|
||||||
|
// manifest is derived from esbuild's own dependency graph rather than from a
|
||||||
|
// hardcoded list, so it tracks the bundle layout instead of rotting with it.
|
||||||
|
const AUDITED_MODULE = "src/shared/constants.js";
|
||||||
|
const BUNDLE_MANIFEST = path.join(DIST, "constants-bundles.txt");
|
||||||
|
|
||||||
function ensureDir(dir) {
|
function ensureDir(dir) {
|
||||||
fs.mkdirSync(dir, { recursive: true });
|
fs.mkdirSync(dir, { recursive: true });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Repo-relative, forward-slashed, so the manifest reads the same on every
|
||||||
|
// platform and can be consumed by a POSIX shell script without further work.
|
||||||
|
function repoRelative(p) {
|
||||||
|
return path.relative(__dirname, p).split(path.sep).join("/");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Collect the outputs of one esbuild run that bundle AUDITED_MODULE. esbuild
|
||||||
|
// reports every input that contributed to an output in the metafile, which is
|
||||||
|
// the authoritative answer to "is constants.js in this bundle" — unlike
|
||||||
|
// searching the minified text, it does not depend on what survived minification.
|
||||||
|
//
|
||||||
|
// The ".js" filter below is the only place that assumption lives:
|
||||||
|
// script/verify-build searches every file and symlink under dist/ for a
|
||||||
|
// marker, without filtering by extension, and hard-fails if it cannot walk the
|
||||||
|
// whole tree, so a bundle emitted under some other extension fails there as
|
||||||
|
// unlisted rather than escaping both checks at once.
|
||||||
|
function outputsContainingAuditedModule(metafile) {
|
||||||
|
return Object.entries(metafile.outputs)
|
||||||
|
.filter(([outFile, info]) => {
|
||||||
|
if (!outFile.endsWith(".js")) return false;
|
||||||
|
return Object.keys(info.inputs).some(
|
||||||
|
(input) => repoRelative(input) === AUDITED_MODULE,
|
||||||
|
);
|
||||||
|
})
|
||||||
|
.map(([outFile]) => repoRelative(outFile));
|
||||||
|
}
|
||||||
|
|
||||||
|
// DEBUG is a build-time flag, off unless explicitly requested. It is the only
|
||||||
|
// thing that makes the hardcoded test mnemonic reachable, so the opt-in must be
|
||||||
|
// exact: anything other than the literal "1" (unset, empty, "true", a typo)
|
||||||
|
// produces a release build. Failing towards the safe mode is deliberate.
|
||||||
|
function isDebugBuild() {
|
||||||
|
return process.env.AUTISTMASK_DEBUG === "1";
|
||||||
|
}
|
||||||
|
|
||||||
|
function getBuildInfo() {
|
||||||
|
const pkg = JSON.parse(
|
||||||
|
fs.readFileSync(path.join(__dirname, "package.json"), "utf8"),
|
||||||
|
);
|
||||||
|
let commitHash = "unknown";
|
||||||
|
try {
|
||||||
|
commitHash = execSync("git rev-parse --short HEAD", {
|
||||||
|
encoding: "utf8",
|
||||||
|
}).trim();
|
||||||
|
} catch (_) {
|
||||||
|
// not a git repo or git not available
|
||||||
|
}
|
||||||
|
let commitHashFull = "unknown";
|
||||||
|
try {
|
||||||
|
commitHashFull = execSync("git rev-parse HEAD", {
|
||||||
|
encoding: "utf8",
|
||||||
|
}).trim();
|
||||||
|
} catch (_) {
|
||||||
|
// not a git repo or git not available
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
version: pkg.version,
|
||||||
|
license: pkg.license,
|
||||||
|
author: pkg.author,
|
||||||
|
commitHash,
|
||||||
|
commitHashFull,
|
||||||
|
buildDate: new Date().toISOString().slice(0, 10),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
async function build() {
|
async function build() {
|
||||||
console.log("Building AutistMask extension...");
|
console.log("Building AutistMask extension...");
|
||||||
|
|
||||||
|
const buildInfo = getBuildInfo();
|
||||||
|
console.log("Build info:", buildInfo);
|
||||||
|
|
||||||
|
const debugBuild = isDebugBuild();
|
||||||
|
console.log(
|
||||||
|
debugBuild
|
||||||
|
? "Build mode: DEBUG (INSECURE - hardcoded test mnemonic, do not ship)"
|
||||||
|
: "Build mode: release (DEBUG off)",
|
||||||
|
);
|
||||||
|
|
||||||
|
const define = {
|
||||||
|
__BUILD_DEBUG__: JSON.stringify(debugBuild),
|
||||||
|
__BUILD_VERSION__: JSON.stringify(buildInfo.version),
|
||||||
|
__BUILD_LICENSE__: JSON.stringify(buildInfo.license),
|
||||||
|
__BUILD_AUTHOR__: JSON.stringify(buildInfo.author),
|
||||||
|
__BUILD_COMMIT__: JSON.stringify(buildInfo.commitHash),
|
||||||
|
__BUILD_COMMIT_FULL__: JSON.stringify(buildInfo.commitHashFull),
|
||||||
|
__BUILD_DATE__: JSON.stringify(buildInfo.buildDate),
|
||||||
|
};
|
||||||
|
|
||||||
|
// Emitted bundles that contain constants.js, accumulated across every
|
||||||
|
// esbuild run below and written out for script/verify-build.
|
||||||
|
const auditedBundles = [];
|
||||||
|
|
||||||
// compile tailwind CSS
|
// compile tailwind CSS
|
||||||
console.log("Compiling Tailwind CSS...");
|
console.log("Compiling Tailwind CSS...");
|
||||||
const tailwindInput = path.join(SRC, "popup", "styles", "main.css");
|
const tailwindInput = path.join(SRC, "popup", "styles", "main.css");
|
||||||
const tailwindOutput = path.join(__dirname, "dist", "styles.css");
|
const tailwindOutput = path.join(DIST, "styles.css");
|
||||||
ensureDir(path.join(__dirname, "dist"));
|
ensureDir(DIST);
|
||||||
|
|
||||||
|
// Drop any manifest from a previous build before emitting anything, so a
|
||||||
|
// build that never gets around to writing one cannot be verified against
|
||||||
|
// a stale list.
|
||||||
|
fs.rmSync(BUNDLE_MANIFEST, { force: true });
|
||||||
|
// The locally installed binary, not `npx` — npx silently fetches from the
|
||||||
|
// registry when the binary is absent, which is an unpinned network fetch
|
||||||
|
// in the middle of a build.
|
||||||
|
const tailwindBin = path.join(
|
||||||
|
__dirname,
|
||||||
|
"node_modules",
|
||||||
|
".bin",
|
||||||
|
"tailwindcss",
|
||||||
|
);
|
||||||
execSync(
|
execSync(
|
||||||
`npx @tailwindcss/cli -i ${tailwindInput} -o ${tailwindOutput} --minify`,
|
`"${tailwindBin}" -i "${tailwindInput}" -o "${tailwindOutput}" --minify`,
|
||||||
{ stdio: "inherit" },
|
{ stdio: "inherit" },
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Every bundle goes through here, so metafile collection cannot be
|
||||||
|
// forgotten when a new entry point is added.
|
||||||
|
async function bundle(entryPoint, outfile) {
|
||||||
|
const result = await esbuild.build({
|
||||||
|
entryPoints: [entryPoint],
|
||||||
|
bundle: true,
|
||||||
|
format: "iife",
|
||||||
|
outfile,
|
||||||
|
platform: "browser",
|
||||||
|
target: ["chrome110", "firefox110"],
|
||||||
|
minify: true,
|
||||||
|
metafile: true,
|
||||||
|
define,
|
||||||
|
});
|
||||||
|
auditedBundles.push(...outputsContainingAuditedModule(result.metafile));
|
||||||
|
}
|
||||||
|
|
||||||
for (const distDir of [DIST_CHROME, DIST_FIREFOX]) {
|
for (const distDir of [DIST_CHROME, DIST_FIREFOX]) {
|
||||||
ensureDir(path.join(distDir, "src", "popup"));
|
ensureDir(path.join(distDir, "src", "popup"));
|
||||||
ensureDir(path.join(distDir, "src", "background"));
|
ensureDir(path.join(distDir, "src", "background"));
|
||||||
ensureDir(path.join(distDir, "src", "content"));
|
ensureDir(path.join(distDir, "src", "content"));
|
||||||
|
|
||||||
// bundle popup JS with esbuild (inlines ethers, libsodium, etc.)
|
// bundle popup JS with esbuild (inlines ethers, libsodium, etc.)
|
||||||
await esbuild.build({
|
await bundle(
|
||||||
entryPoints: [path.join(SRC, "popup", "index.js")],
|
path.join(SRC, "popup", "index.js"),
|
||||||
bundle: true,
|
path.join(distDir, "src", "popup", "index.js"),
|
||||||
format: "iife",
|
);
|
||||||
outfile: path.join(distDir, "src", "popup", "index.js"),
|
|
||||||
platform: "browser",
|
|
||||||
target: ["chrome110", "firefox110"],
|
|
||||||
minify: true,
|
|
||||||
});
|
|
||||||
|
|
||||||
// bundle background script
|
// bundle background script
|
||||||
await esbuild.build({
|
await bundle(
|
||||||
entryPoints: [path.join(SRC, "background", "index.js")],
|
path.join(SRC, "background", "index.js"),
|
||||||
bundle: true,
|
path.join(distDir, "src", "background", "index.js"),
|
||||||
format: "iife",
|
);
|
||||||
outfile: path.join(distDir, "src", "background", "index.js"),
|
|
||||||
platform: "browser",
|
|
||||||
target: ["chrome110", "firefox110"],
|
|
||||||
minify: true,
|
|
||||||
});
|
|
||||||
|
|
||||||
// bundle content script
|
// bundle content script
|
||||||
await esbuild.build({
|
await bundle(
|
||||||
entryPoints: [path.join(SRC, "content", "index.js")],
|
path.join(SRC, "content", "index.js"),
|
||||||
bundle: true,
|
path.join(distDir, "src", "content", "index.js"),
|
||||||
format: "iife",
|
);
|
||||||
outfile: path.join(distDir, "src", "content", "index.js"),
|
|
||||||
platform: "browser",
|
|
||||||
target: ["chrome110", "firefox110"],
|
|
||||||
minify: true,
|
|
||||||
});
|
|
||||||
|
|
||||||
// bundle inpage script (injected into page context, separate file)
|
// bundle inpage script (injected into page context, separate file)
|
||||||
await esbuild.build({
|
await bundle(
|
||||||
entryPoints: [path.join(SRC, "content", "inpage.js")],
|
path.join(SRC, "content", "inpage.js"),
|
||||||
bundle: true,
|
path.join(distDir, "src", "content", "inpage.js"),
|
||||||
format: "iife",
|
);
|
||||||
outfile: path.join(distDir, "src", "content", "inpage.js"),
|
|
||||||
platform: "browser",
|
|
||||||
target: ["chrome110", "firefox110"],
|
|
||||||
minify: true,
|
|
||||||
});
|
|
||||||
|
|
||||||
// copy popup HTML
|
// copy popup HTML
|
||||||
fs.copyFileSync(
|
fs.copyFileSync(
|
||||||
@@ -96,6 +204,16 @@ async function build() {
|
|||||||
path.join(DIST_FIREFOX, "manifest.json"),
|
path.join(DIST_FIREFOX, "manifest.json"),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Written last so a build that died partway through leaves no manifest
|
||||||
|
// at all, which script/verify-build treats as a hard failure rather than
|
||||||
|
// as "nothing to check".
|
||||||
|
const manifest = [...new Set(auditedBundles)].sort();
|
||||||
|
fs.writeFileSync(BUNDLE_MANIFEST, manifest.map((p) => `${p}\n`).join(""));
|
||||||
|
console.log(
|
||||||
|
`Bundles containing ${AUDITED_MODULE}: ${manifest.length} ` +
|
||||||
|
`(listed in ${repoRelative(BUNDLE_MANIFEST)})`,
|
||||||
|
);
|
||||||
|
|
||||||
console.log("Build complete: dist/chrome/ and dist/firefox/");
|
console.log("Build complete: dist/chrome/ and dist/firefox/");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
253
docs/README.md
253
docs/README.md
@@ -6,10 +6,10 @@ and ERC-20 tokens, and connects to web3 sites. Nothing else.
|
|||||||
|
|
||||||
## Why AutistMask Exists
|
## Why AutistMask Exists
|
||||||
|
|
||||||
MetaMask has become bloated with swap UIs, portfolio dashboards, analytics,
|
The most popular browser-based EVM wallet has become bloated with swap UIs,
|
||||||
tracking, and advertisements. It is no longer a simple wallet. Most alternatives
|
portfolio dashboards, analytics, tracking, and advertisements. It is no longer a
|
||||||
(Rabby, Rainbow, etc.) only support Chromium browsers, leaving Firefox users
|
simple wallet. The common alternatives only support Chromium browsers, leaving
|
||||||
without a usable option.
|
Firefox users without a usable option.
|
||||||
|
|
||||||
AutistMask exists because a wallet should be a wallet. You should be able to see
|
AutistMask exists because a wallet should be a wallet. You should be able to see
|
||||||
your balances, send tokens, receive tokens, and connect to sites. That is all a
|
your balances, send tokens, receive tokens, and connect to sites. That is all a
|
||||||
@@ -27,9 +27,10 @@ analytics, use a portfolio tracker. The wallet is not the place for any of that.
|
|||||||
|
|
||||||
- **Encrypt your recovery phrase and private keys at rest.** Your secrets are
|
- **Encrypt your recovery phrase and private keys at rest.** Your secrets are
|
||||||
encrypted on disk using Argon2id key derivation and XSalsa20-Poly1305
|
encrypted on disk using Argon2id key derivation and XSalsa20-Poly1305
|
||||||
authenticated encryption (via libsodium). Your password is required only when
|
authenticated encryption (via libsodium). Your password is required whenever a
|
||||||
signing a transaction. Viewing balances and addresses never requires a
|
secret has to be decrypted: signing a transaction, signing a message or typed
|
||||||
password.
|
data, exporting a private key, and deleting a wallet. Viewing balances and
|
||||||
|
addresses never requires a password.
|
||||||
|
|
||||||
- **Let you choose your own RPC endpoint.** The default is a public Ethereum
|
- **Let you choose your own RPC endpoint.** The default is a public Ethereum
|
||||||
RPC, but you can point it at your own node or any provider you trust. No
|
RPC, but you can point it at your own node or any provider you trust. No
|
||||||
@@ -56,23 +57,25 @@ analytics, use a portfolio tracker. The wallet is not the place for any of that.
|
|||||||
|
|
||||||
- **No NFT galleries or portfolio views.** This is a wallet, not a dashboard.
|
- **No NFT galleries or portfolio views.** This is a wallet, not a dashboard.
|
||||||
|
|
||||||
- **No token auto-discovery.** AutistMask does not scan the blockchain for
|
- **No third-party token list APIs.** Token balances come from the same block
|
||||||
tokens you might hold. You add tokens manually by contract address. This
|
explorer you configure for transaction history, and the extension ships its
|
||||||
prevents scam tokens from appearing in your wallet uninvited.
|
own hardcoded list of top ERC-20 contract addresses for symbol-spoofing
|
||||||
|
detection. Any token you want tracked across all your addresses, you add
|
||||||
|
yourself by contract address.
|
||||||
|
|
||||||
- **No phishing blocklists from third parties.** AutistMask does not phone home
|
- **No backend servers operated by the developer.** Nothing is sent to any
|
||||||
to check URLs against a remote blocklist. It does maintain a local list of
|
server run by AutistMask. Every network destination is listed below.
|
||||||
known scam addresses, but this is shipped with the extension, not fetched from
|
|
||||||
a server.
|
|
||||||
|
|
||||||
## How It Works
|
## How It Works
|
||||||
|
|
||||||
AutistMask is a browser extension that runs entirely in your browser. It does
|
AutistMask is a browser extension that runs entirely in your browser. It does
|
||||||
not have a backend server. It communicates with three external services:
|
not have a backend server. It communicates with five external destinations:
|
||||||
|
three you configure yourself, and two fixed ones used for scam detection.
|
||||||
|
|
||||||
### External Services
|
### External Services
|
||||||
|
|
||||||
**Ethereum JSON-RPC endpoint** (default: `ethereum-rpc.publicnode.com`)
|
**Ethereum JSON-RPC endpoint** (default: `ethereum-rpc.publicnode.com`;
|
||||||
|
`ethereum-sepolia-rpc.publicnode.com` on Sepolia)
|
||||||
|
|
||||||
This is how AutistMask talks to the Ethereum network. Every wallet needs an
|
This is how AutistMask talks to the Ethereum network. Every wallet needs an
|
||||||
Ethereum node to check balances, estimate gas, broadcast transactions, and
|
Ethereum node to check balances, estimate gas, broadcast transactions, and
|
||||||
@@ -80,27 +83,77 @@ verify confirmations. The default is a free public RPC endpoint. You can change
|
|||||||
this in Settings to any Ethereum JSON-RPC endpoint, including your own local
|
this in Settings to any Ethereum JSON-RPC endpoint, including your own local
|
||||||
node.
|
node.
|
||||||
|
|
||||||
What gets sent: standard Ethereum JSON-RPC requests (balance queries,
|
When it is contacted: on every balance refresh (every 10 seconds while the popup
|
||||||
transaction broadcasts, gas estimates, ENS lookups). Your addresses are
|
is open, every 60 seconds in the background), when you type an ENS name into the
|
||||||
necessarily visible to the RPC provider when querying balances.
|
Send screen, when a send is prepared and broadcast, while a pending transaction
|
||||||
|
is polled for its receipt, and for the reverse ENS lookups used to label
|
||||||
|
addresses (cached for 12 hours).
|
||||||
|
|
||||||
**Blockscout API** (default: `eth.blockscout.com/api/v2`)
|
What gets sent: standard Ethereum JSON-RPC requests (balance queries,
|
||||||
|
transaction broadcasts, gas estimates, ENS lookups, contract-code checks). Your
|
||||||
|
addresses are necessarily visible to the RPC provider when querying balances.
|
||||||
|
|
||||||
|
**Blockscout API** (default: `eth.blockscout.com/api/v2`;
|
||||||
|
`eth-sepolia.blockscout.com/api/v2` on Sepolia)
|
||||||
|
|
||||||
Used to fetch token balances and transaction history. Blockscout is an
|
Used to fetch token balances and transaction history. Blockscout is an
|
||||||
open-source blockchain explorer. AutistMask queries it for your ERC-20 token
|
open-source blockchain explorer. AutistMask queries it for your ERC-20 token
|
||||||
balances and recent transactions. You can change this in Settings to a
|
balances (including the holder counts used for spam filtering) and your recent
|
||||||
|
transactions and token transfers. You can change this in Settings to a
|
||||||
self-hosted Blockscout instance.
|
self-hosted Blockscout instance.
|
||||||
|
|
||||||
|
When it is contacted: on every balance refresh, and whenever a screen showing
|
||||||
|
transaction history is opened.
|
||||||
|
|
||||||
What gets sent: your Ethereum addresses (to look up balances and transactions).
|
What gets sent: your Ethereum addresses (to look up balances and transactions).
|
||||||
|
|
||||||
**CoinDesk CADLI price API** (`data-api.coindesk.com`)
|
**CoinDesk CADLI price API** (`data-api.coindesk.com`)
|
||||||
|
|
||||||
Used to fetch current USD prices for ETH and ERC-20 tokens. Prices are cached
|
Used to fetch current USD prices for ETH and the top 25 tokens. Prices are
|
||||||
for 5 minutes. No API key is required. No user data is sent -- only a list of
|
cached for 5 minutes. No API key is required. This endpoint is not
|
||||||
token symbols (e.g. "ETH", "USDC") to get their prices.
|
user-configurable, and it is not contacted at all while you are on a testnet,
|
||||||
|
where no USD values are shown.
|
||||||
|
|
||||||
What gets sent: token symbol names. No addresses, no balances, no identifying
|
When it is contacted: while the popup is open, at most once every 5 minutes.
|
||||||
information.
|
|
||||||
|
What gets sent: token symbol names (e.g. "ETH", "USDC"). No addresses, no
|
||||||
|
balances, no identifying information. As with any request, CoinDesk sees your IP
|
||||||
|
address.
|
||||||
|
|
||||||
|
**Phishing domain blocklist** (`raw.githubusercontent.com`)
|
||||||
|
|
||||||
|
A community-maintained list of phishing domains, used to warn you when a site
|
||||||
|
that asks to connect, or to have a transaction or signature approved, is a known
|
||||||
|
scam. A copy is bundled into the extension at build time, so the protection
|
||||||
|
works before any network request happens. At runtime the extension fetches the
|
||||||
|
live list to pick up newly added domains, keeping only the entries not already
|
||||||
|
in the bundled copy (persisted locally if under 256 KiB). This endpoint is not
|
||||||
|
user-configurable.
|
||||||
|
|
||||||
|
When it is contacted: when the background script starts, if the last fetch was
|
||||||
|
more than 24 hours ago, and every 24 hours after that. The time of the last
|
||||||
|
fetch is remembered across browser and background restarts, so restarting does
|
||||||
|
not cause a re-download. If a fetch fails, or the list is too large to keep, the
|
||||||
|
extension waits an hour before trying again outside that 24-hour schedule rather
|
||||||
|
than retrying on every restart. It is a plain download of a public file —
|
||||||
|
nothing about you is sent, but the host sees your IP address. If the fetch
|
||||||
|
fails, the bundled copy is still used.
|
||||||
|
|
||||||
|
**Etherscan address labels** (`etherscan.io`; `sepolia.etherscan.io` on Sepolia)
|
||||||
|
|
||||||
|
When you review a send, AutistMask fetches the recipient's public Etherscan
|
||||||
|
address page and looks for a "Fake_Phishing"/"Phish/Hack" label or a scam
|
||||||
|
warning, and shows a red warning if it finds one. This is a plain page fetch
|
||||||
|
with no API key, made by your browser. It is best-effort: if it fails, it is
|
||||||
|
silently ignored. This endpoint is not user-configurable.
|
||||||
|
|
||||||
|
When it is contacted: each time you reach the send confirmation screen.
|
||||||
|
|
||||||
|
What gets sent: the recipient address you are about to send to, and your IP
|
||||||
|
address. Your own addresses are not sent.
|
||||||
|
|
||||||
|
Etherscan links shown elsewhere in the UI (on addresses, transactions, and token
|
||||||
|
contracts) are ordinary links. They contact nothing until you click them.
|
||||||
|
|
||||||
### What Stays Local
|
### What Stays Local
|
||||||
|
|
||||||
@@ -123,8 +176,11 @@ word recovery phrase can restore your wallet on any device without your
|
|||||||
password. The password only protects the copy stored in this browser. If you
|
password. The password only protects the copy stored in this browser. If you
|
||||||
lose your recovery phrase, your password cannot help you recover it.
|
lose your recovery phrase, your password cannot help you recover it.
|
||||||
|
|
||||||
Your password is only requested when you send a transaction. Viewing balances,
|
Your password is requested whenever an encrypted secret must be decrypted: when
|
||||||
receiving funds, and browsing transaction history never require your password.
|
you send a transaction, when a site asks you to sign a message or typed data,
|
||||||
|
when you export an address's private key, and when you delete a wallet. Viewing
|
||||||
|
balances, receiving funds, and browsing transaction history never require your
|
||||||
|
password.
|
||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|
||||||
@@ -147,34 +203,46 @@ receiving funds, and browsing transaction history never require your password.
|
|||||||
### Creating a New Wallet
|
### Creating a New Wallet
|
||||||
|
|
||||||
1. Click the AutistMask icon in your browser toolbar.
|
1. Click the AutistMask icon in your browser toolbar.
|
||||||
2. Click "Add wallet".
|
2. Click "Add wallet" (on first use), or open Settings and click "+ Add wallet".
|
||||||
3. Click the die button to generate a random 12-word recovery phrase.
|
3. On the "From Phrase" tab, click the die button to generate a random 12-word
|
||||||
|
recovery phrase.
|
||||||
4. **Write down the recovery phrase and store it safely.** Anyone with these
|
4. **Write down the recovery phrase and store it safely.** Anyone with these
|
||||||
words can take your funds. If you lose them, your wallet is gone. AutistMask
|
words can take your funds. If you lose them, your wallet is gone. AutistMask
|
||||||
cannot recover them for you.
|
cannot recover them for you.
|
||||||
5. Choose a password. This encrypts your recovery phrase on this device.
|
5. Choose a password and confirm it. This encrypts your recovery phrase on this
|
||||||
6. Click "Add".
|
device.
|
||||||
|
6. Click "Import".
|
||||||
|
|
||||||
### Importing an Existing Wallet
|
### Importing an Existing Wallet
|
||||||
|
|
||||||
**From a recovery phrase:** Follow the same steps as creating a wallet, but
|
The Add Wallet screen has three tabs:
|
||||||
paste your existing 12 or 24 word recovery phrase instead of generating a new
|
|
||||||
one. AutistMask uses the same derivation path as MetaMask (`m/44'/60'/0'/0`), so
|
|
||||||
your addresses will match.
|
|
||||||
|
|
||||||
**From a private key:** On the Add Wallet screen, click "Have a private key
|
**From Phrase:** Paste your existing 12 or 24 word recovery phrase instead of
|
||||||
instead?" and paste your private key. This creates a single-address wallet.
|
generating a new one. AutistMask uses the standard BIP-44 Ethereum derivation
|
||||||
|
path (`m/44'/60'/0'/0`), which is what other wallets use by default, so your
|
||||||
|
addresses will match and your phrase stays portable in both directions.
|
||||||
|
|
||||||
|
**From Key:** Paste a single private key. This creates a single-address wallet.
|
||||||
|
|
||||||
|
**From xprv:** Paste an extended private key. This imports the HD wallet and
|
||||||
|
scans for used addresses.
|
||||||
|
|
||||||
|
All three tabs ask for the same password fields, and the "Import" button
|
||||||
|
finishes the job.
|
||||||
|
|
||||||
### Adding More Addresses
|
### Adding More Addresses
|
||||||
|
|
||||||
HD wallets (created from a recovery phrase) can derive multiple addresses. On
|
HD wallets (created from a recovery phrase or an xprv) can derive multiple
|
||||||
the home screen, click the "+" button next to a wallet name to add the next
|
addresses. On the home screen, click the "+" button next to a wallet name to add
|
||||||
address. These are deterministic -- the same recovery phrase will always produce
|
the next address. These are deterministic -- the same recovery phrase will
|
||||||
the same sequence of addresses.
|
always produce the same sequence of addresses.
|
||||||
|
|
||||||
### Adding ERC-20 Tokens
|
### Adding ERC-20 Tokens
|
||||||
|
|
||||||
AutistMask does not auto-discover tokens. To track a token:
|
Tokens you hold show up automatically only if they are in the extension's
|
||||||
|
bundled list of well-known tokens or have at least 1,000 holders; everything
|
||||||
|
else is treated as spam and hidden. To track a token explicitly (which also
|
||||||
|
shows it at zero balance), add it by contract address:
|
||||||
|
|
||||||
1. Go to an address detail view (click `[info]` on any address).
|
1. Go to an address detail view (click `[info]` on any address).
|
||||||
2. Click "+ Token".
|
2. Click "+ Token".
|
||||||
@@ -183,12 +251,13 @@ AutistMask does not auto-discover tokens. To track a token:
|
|||||||
4. Click "Add".
|
4. Click "Add".
|
||||||
|
|
||||||
The token balance will appear on the address detail screen and on the home
|
The token balance will appear on the address detail screen and on the home
|
||||||
screen.
|
screen. Tokens can also be added from Settings, under "Tracked Tokens".
|
||||||
|
|
||||||
## Sending
|
## Sending
|
||||||
|
|
||||||
1. Click "Send" from the home screen or an address detail view.
|
1. Click "Send" from the home screen or an address detail view.
|
||||||
2. Select what to send (ETH or any tracked ERC-20 token).
|
2. Select what to send (ETH, or any ERC-20 token with a balance on this address
|
||||||
|
that survives the spam filters).
|
||||||
3. Enter the recipient address or ENS name (e.g. `vitalik.eth`).
|
3. Enter the recipient address or ENS name (e.g. `vitalik.eth`).
|
||||||
4. Enter the amount.
|
4. Enter the amount.
|
||||||
5. Click "Review" to see the confirmation screen.
|
5. Click "Review" to see the confirmation screen.
|
||||||
@@ -200,12 +269,18 @@ The confirmation screen shows:
|
|||||||
- **From and To addresses** with identicons and Etherscan links
|
- **From and To addresses** with identicons and Etherscan links
|
||||||
- **Amount** with USD estimate
|
- **Amount** with USD estimate
|
||||||
- **Your current balance** with USD estimate
|
- **Your current balance** with USD estimate
|
||||||
- **Estimated network fee** in ETH with USD estimate
|
- **Network fee** — what the transfer is expected to cost, in ETH with a USD
|
||||||
|
estimate, and below it the larger amount reserved until it confirms. The
|
||||||
|
reserve is what the network requires up front and what the balance check gates
|
||||||
|
on; the refund of the difference is why the two differ
|
||||||
|
- **Warnings** if the recipient is a contract, a burn address, one of your own
|
||||||
|
addresses, on the bundled scam-address list, or labelled as a phisher on
|
||||||
|
Etherscan
|
||||||
|
|
||||||
After reviewing, click "Send" and enter your password. The transaction will be
|
After reviewing, enter your password and click "Sign & Send". The transaction
|
||||||
broadcast to the network and you will see a waiting screen with a timer. Once
|
will be broadcast to the network and you will see a waiting screen with a timer.
|
||||||
confirmed (or after 60 seconds), you will see either a success or error screen
|
Once confirmed (or after 60 seconds), you will see either a success or error
|
||||||
with the transaction hash and an Etherscan link.
|
screen with the transaction hash and an Etherscan link.
|
||||||
|
|
||||||
### Sending a Specific Token
|
### Sending a Specific Token
|
||||||
|
|
||||||
@@ -219,10 +294,10 @@ cannot accidentally switch to a different one.
|
|||||||
1. Click "Receive" from the home screen or an address detail view.
|
1. Click "Receive" from the home screen or an address detail view.
|
||||||
2. Share the QR code or copy the address using the "Copy address" button.
|
2. Share the QR code or copy the address using the "Copy address" button.
|
||||||
|
|
||||||
When receiving ERC-20 tokens, make sure the sender is sending on the Ethereum
|
When receiving ERC-20 tokens, make sure the sender is sending on the network you
|
||||||
network. AutistMask is an Ethereum mainnet wallet. Tokens sent on other networks
|
are using. AutistMask supports Ethereum mainnet and the Sepolia testnet. Tokens
|
||||||
(Polygon, Arbitrum, BSC, etc.) to the same address will not appear and may be
|
sent on other networks (Polygon, Arbitrum, BSC, etc.) to the same address will
|
||||||
permanently lost.
|
not appear and may be permanently lost.
|
||||||
|
|
||||||
## Connecting to Web3 Sites
|
## Connecting to Web3 Sites
|
||||||
|
|
||||||
@@ -237,7 +312,12 @@ pages. When a site requests access to your wallet:
|
|||||||
|
|
||||||
When a connected site requests a transaction, a separate approval popup appears
|
When a connected site requests a transaction, a separate approval popup appears
|
||||||
showing the transaction details (from, to, value, data). You must enter your
|
showing the transaction details (from, to, value, data). You must enter your
|
||||||
password and click "Confirm" to authorize it.
|
password and click "Confirm" to authorize it. Message and typed-data signature
|
||||||
|
requests work the same way, with a "Sign" button, and also require your
|
||||||
|
password.
|
||||||
|
|
||||||
|
If the requesting site's domain is on the phishing blocklist, all three approval
|
||||||
|
screens show a red phishing warning before you decide.
|
||||||
|
|
||||||
You can manage site permissions in Settings. Allowed and denied sites can be
|
You can manage site permissions in Settings. Allowed and denied sites can be
|
||||||
individually removed to reset their permissions.
|
individually removed to reset their permissions.
|
||||||
@@ -247,15 +327,25 @@ individually removed to reset their permissions.
|
|||||||
AutistMask includes several defenses against common Ethereum scams, all enabled
|
AutistMask includes several defenses against common Ethereum scams, all enabled
|
||||||
by default:
|
by default:
|
||||||
|
|
||||||
**Known token symbol verification.** AutistMask ships a list of ~250 legitimate
|
**Known token symbol verification.** AutistMask ships a bundled list of
|
||||||
ERC-20 tokens with their contract addresses. If a transaction claims to involve
|
high-market-cap ERC-20 tokens with their legitimate contract addresses — a
|
||||||
a known symbol (like "ETH" or "USDT") but comes from an unrecognized contract,
|
point-in-time snapshot of the highest-market-cap Ethereum mainnet ERC-20s, fixed
|
||||||
it is identified as a spoof and hidden.
|
at build time and updated only when a new release ships a newer snapshot. If a
|
||||||
|
transaction or balance claims to involve a known symbol (like "ETH" or "USDT")
|
||||||
|
but comes from an unrecognized contract, it is identified as a spoof and hidden.
|
||||||
|
In your transaction history this is the "Hide fake tokens impersonating a known
|
||||||
|
symbol" setting, which you can switch off; doing so also stops new entries being
|
||||||
|
added to the fraud contract blocklist below, since detecting a spoof is what
|
||||||
|
fills it. The send token list always applies the check. Your balances apply it
|
||||||
|
too, with one exception: a token claiming the symbol "ETH" is not filtered
|
||||||
|
there, so a fake "ETH" token can still show up in your balance list even though
|
||||||
|
it is hidden from your transaction history and from the send token list.
|
||||||
|
|
||||||
**Low-holder token filtering.** Tokens with fewer than 1,000 holders are hidden
|
**Low-holder token filtering.** Tokens with fewer than 1,000 holders are hidden
|
||||||
from transaction history and the send token list. Legitimate tokens have
|
from transaction history and the send token list, and are left out of your
|
||||||
substantial holder counts; scam tokens deployed for address poisoning typically
|
balances unless they are on the bundled known-token list or you added them
|
||||||
have zero.
|
yourself. Legitimate tokens have substantial holder counts; scam tokens deployed
|
||||||
|
for address poisoning typically have zero.
|
||||||
|
|
||||||
**Fraud contract blocklist.** When AutistMask detects a fraudulent transfer, it
|
**Fraud contract blocklist.** When AutistMask detects a fraudulent transfer, it
|
||||||
adds the contract address to a local blocklist. Future transactions from that
|
adds the contract address to a local blocklist. Future transactions from that
|
||||||
@@ -266,15 +356,29 @@ ETH by default) are hidden. Scammers send dust from look-alike addresses to
|
|||||||
plant them in your transaction history. The threshold is configurable in
|
plant them in your transaction history. The threshold is configurable in
|
||||||
Settings.
|
Settings.
|
||||||
|
|
||||||
All of these filters can be individually disabled in Settings if you prefer to
|
**Scam address list.** A list of known fraud, drainer, and phishing addresses is
|
||||||
|
shipped with the extension. Sending to one of them raises a warning on the
|
||||||
|
confirmation screen. It contains only addresses involved in fraud -- it is not a
|
||||||
|
sanctions list.
|
||||||
|
|
||||||
|
**Phishing domain warnings.** Sites asking to connect or to have something
|
||||||
|
approved are checked against the phishing domain blocklist described under
|
||||||
|
External Services, and flagged with a red banner if they match.
|
||||||
|
|
||||||
|
The first four filters can be individually disabled in Settings if you prefer to
|
||||||
see everything unfiltered.
|
see everything unfiltered.
|
||||||
|
|
||||||
## Settings
|
## Settings
|
||||||
|
|
||||||
Click the gear icon on the home screen to access settings:
|
Click the gear icon on the home screen to access settings:
|
||||||
|
|
||||||
- **Wallets**: Add a new wallet.
|
- **Wallets**: Your wallets, and "+ Add wallet".
|
||||||
- **Display**: Toggle whether tracked tokens with zero balance are shown.
|
- **Tracked Tokens**: The ERC-20 tokens tracked across all addresses, and "+ Add
|
||||||
|
token".
|
||||||
|
- **Display**: Toggle whether tracked tokens with zero balance are shown, switch
|
||||||
|
timestamps to UTC, and choose the theme (System, Light, or Dark).
|
||||||
|
- **Network**: Switch between Ethereum Mainnet and Sepolia Testnet. Switching
|
||||||
|
resets the RPC and Blockscout endpoints to that network's defaults.
|
||||||
- **Ethereum RPC**: Change the Ethereum node endpoint. Default is a public RPC.
|
- **Ethereum RPC**: Change the Ethereum node endpoint. Default is a public RPC.
|
||||||
You can use your own node for maximum privacy.
|
You can use your own node for maximum privacy.
|
||||||
- **Blockscout API**: Change the Blockscout instance used for token balances and
|
- **Blockscout API**: Change the Blockscout instance used for token balances and
|
||||||
@@ -282,15 +386,17 @@ Click the gear icon on the home screen to access settings:
|
|||||||
- **Token Spam Protection**: Toggle individual scam filters and set the dust
|
- **Token Spam Protection**: Toggle individual scam filters and set the dust
|
||||||
transaction threshold.
|
transaction threshold.
|
||||||
- **Allowed Sites / Denied Sites**: View and manage web3 site permissions.
|
- **Allowed Sites / Denied Sites**: View and manage web3 site permissions.
|
||||||
|
- **About**: License, author, version, release date, and a link to the commit
|
||||||
|
this build came from.
|
||||||
|
|
||||||
## Frequently Asked Questions
|
## Frequently Asked Questions
|
||||||
|
|
||||||
**Is AutistMask compatible with MetaMask?**
|
**Can I use AutistMask alongside another wallet?**
|
||||||
|
|
||||||
Yes. AutistMask uses the same derivation path (`m/44'/60'/0'/0`) as MetaMask. If
|
Yes. AutistMask uses the standard `m/44'/60'/0'/0` derivation path, so importing
|
||||||
you import the same recovery phrase, you will get the same addresses. You can
|
the same recovery phrase gives you the same addresses as any other wallet using
|
||||||
use both wallets side by side, though only one can be the active
|
that path. Two wallet extensions can be installed side by side, though only one
|
||||||
`window.ethereum` provider at a time.
|
can be the active `window.ethereum` provider at a time.
|
||||||
|
|
||||||
**Can I use AutistMask with a hardware wallet?**
|
**Can I use AutistMask with a hardware wallet?**
|
||||||
|
|
||||||
@@ -298,8 +404,9 @@ Not yet. Hardware wallet support may be added in the future.
|
|||||||
|
|
||||||
**Does AutistMask support networks other than Ethereum mainnet?**
|
**Does AutistMask support networks other than Ethereum mainnet?**
|
||||||
|
|
||||||
Not currently. AutistMask is Ethereum mainnet only. Multi-chain support may be
|
Ethereum mainnet and the Sepolia testnet, selectable in Settings. No other
|
||||||
added in the future.
|
networks are supported today. On Sepolia, USD values are not shown, because
|
||||||
|
testnet tokens have no market value.
|
||||||
|
|
||||||
**Where is my data stored?**
|
**Where is my data stored?**
|
||||||
|
|
||||||
@@ -312,7 +419,7 @@ to any server operated by AutistMask.
|
|||||||
|
|
||||||
Your data is deleted. Make sure you have your recovery phrase backed up before
|
Your data is deleted. Make sure you have your recovery phrase backed up before
|
||||||
uninstalling. With your recovery phrase, you can restore your wallet in
|
uninstalling. With your recovery phrase, you can restore your wallet in
|
||||||
AutistMask or any other compatible wallet (MetaMask, etc.) at any time.
|
AutistMask or any other wallet that uses the standard derivation path.
|
||||||
|
|
||||||
**What happens if a transaction times out?**
|
**What happens if a transaction times out?**
|
||||||
|
|
||||||
|
|||||||
@@ -3,8 +3,11 @@
|
|||||||
"name": "AutistMask",
|
"name": "AutistMask",
|
||||||
"version": "0.1.0",
|
"version": "0.1.0",
|
||||||
"description": "Minimal Ethereum wallet for Chrome",
|
"description": "Minimal Ethereum wallet for Chrome",
|
||||||
"permissions": ["storage", "activeTab"],
|
"permissions": ["storage", "activeTab", "alarms"],
|
||||||
"host_permissions": ["<all_urls>"],
|
"host_permissions": ["<all_urls>"],
|
||||||
|
"content_security_policy": {
|
||||||
|
"extension_pages": "script-src 'self' 'wasm-unsafe-eval'; object-src 'self'"
|
||||||
|
},
|
||||||
"action": {
|
"action": {
|
||||||
"default_popup": "src/popup/index.html"
|
"default_popup": "src/popup/index.html"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -3,7 +3,8 @@
|
|||||||
"name": "AutistMask",
|
"name": "AutistMask",
|
||||||
"version": "0.1.0",
|
"version": "0.1.0",
|
||||||
"description": "Minimal Ethereum wallet for Firefox",
|
"description": "Minimal Ethereum wallet for Firefox",
|
||||||
"permissions": ["storage", "activeTab", "<all_urls>"],
|
"permissions": ["storage", "activeTab", "alarms", "<all_urls>"],
|
||||||
|
"content_security_policy": "script-src 'self' 'wasm-unsafe-eval'; object-src 'self'",
|
||||||
"browser_action": {
|
"browser_action": {
|
||||||
"default_popup": "src/popup/index.html"
|
"default_popup": "src/popup/index.html"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -7,6 +7,7 @@
|
|||||||
"private": true,
|
"private": true,
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"test": "jest --forceExit",
|
"test": "jest --forceExit",
|
||||||
|
"test:verbose": "jest --forceExit --verbose",
|
||||||
"build": "node build.js",
|
"build": "node build.js",
|
||||||
"lint": "prettier --check .",
|
"lint": "prettier --check .",
|
||||||
"fmt": "prettier --write .",
|
"fmt": "prettier --write .",
|
||||||
@@ -16,6 +17,7 @@
|
|||||||
"@tailwindcss/cli": "^4.2.1",
|
"@tailwindcss/cli": "^4.2.1",
|
||||||
"esbuild": "^0.27.3",
|
"esbuild": "^0.27.3",
|
||||||
"jest": "^30.2.0",
|
"jest": "^30.2.0",
|
||||||
|
"playwright-core": "1.56.0",
|
||||||
"prettier": "^3.8.1",
|
"prettier": "^3.8.1",
|
||||||
"tailwindcss": "^4.2.1"
|
"tailwindcss": "^4.2.1"
|
||||||
},
|
},
|
||||||
|
|||||||
143
script/bootstrap
Executable file
143
script/bootstrap
Executable file
@@ -0,0 +1,143 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/bootstrap: install all dependencies needed to build and develop
|
||||||
|
# this repo. Idempotent: every install is guarded by a check so already
|
||||||
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
||||||
|
# or apk (detected in that order); assumes nothing is present. Node is
|
||||||
|
# used directly if installed; otherwise it is installed at a pinned
|
||||||
|
# version via nvm (installing nvm itself first, from a hash-verified
|
||||||
|
# release archive, never curl | sh).
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
# Pinned versions, 2026-07-07
|
||||||
|
NODE_VERSION="22.17.0"
|
||||||
|
NVM_VERSION="0.40.3"
|
||||||
|
# sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz
|
||||||
|
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
|
||||||
|
YARN_VERSION="1.22.22"
|
||||||
|
|
||||||
|
PKGMGR=""
|
||||||
|
SUDO=""
|
||||||
|
APT_UPDATED=""
|
||||||
|
|
||||||
|
detect_pkgmgr() {
|
||||||
|
[ -n "$PKGMGR" ] && return 0
|
||||||
|
if command -v nix-env >/dev/null 2>&1; then
|
||||||
|
PKGMGR="nix"
|
||||||
|
elif command -v apt-get >/dev/null 2>&1; then
|
||||||
|
PKGMGR="apt"
|
||||||
|
elif command -v brew >/dev/null 2>&1; then
|
||||||
|
PKGMGR="brew"
|
||||||
|
elif command -v apk >/dev/null 2>&1; then
|
||||||
|
PKGMGR="apk"
|
||||||
|
else
|
||||||
|
echo "bootstrap: no supported package manager (nix, apt, brew, apk)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if [ "$PKGMGR" = "apt" ]; then
|
||||||
|
export DEBIAN_FRONTEND=noninteractive
|
||||||
|
if [ "$(id -u)" != "0" ]; then
|
||||||
|
SUDO="sudo"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# pkg_install <nix-attr> <apt-pkg> <brew-formula> <apk-pkg>
|
||||||
|
pkg_install() {
|
||||||
|
detect_pkgmgr
|
||||||
|
case "$PKGMGR" in
|
||||||
|
nix) nix-env -iA "nixpkgs.$1" ;;
|
||||||
|
apt)
|
||||||
|
if [ -z "$APT_UPDATED" ]; then
|
||||||
|
$SUDO env DEBIAN_FRONTEND=noninteractive apt-get update
|
||||||
|
APT_UPDATED=1
|
||||||
|
fi
|
||||||
|
$SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2"
|
||||||
|
;;
|
||||||
|
brew) brew install "$3" ;;
|
||||||
|
apk) apk add --no-cache "$4" ;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
missing() {
|
||||||
|
! command -v "$1" >/dev/null 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
|
# verify_sha256 <file> <expected-hash>
|
||||||
|
verify_sha256() {
|
||||||
|
if command -v sha256sum >/dev/null 2>&1; then
|
||||||
|
actual="$(sha256sum "$1" | cut -d' ' -f1)"
|
||||||
|
else
|
||||||
|
actual="$(shasum -a 256 "$1" | cut -d' ' -f1)"
|
||||||
|
fi
|
||||||
|
if [ "$actual" != "$2" ]; then
|
||||||
|
echo "bootstrap: sha256 mismatch for $1" >&2
|
||||||
|
echo " expected: $2" >&2
|
||||||
|
echo " actual: $actual" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# nvm is a bash script; run a command in a bash with nvm loaded
|
||||||
|
nvm_sh() {
|
||||||
|
bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*"
|
||||||
|
}
|
||||||
|
|
||||||
|
ensure_nvm() {
|
||||||
|
[ -s "$HOME/.nvm/nvm.sh" ] && return 0
|
||||||
|
# nvm prerequisites; nvm itself requires bash
|
||||||
|
if missing bash; then pkg_install bash bash bash bash; fi
|
||||||
|
if missing curl; then pkg_install curl curl curl curl; fi
|
||||||
|
if missing git; then pkg_install git git git git; fi
|
||||||
|
tmp="$(mktemp -d)"
|
||||||
|
curl -fsSL -o "$tmp/nvm.tar.gz" \
|
||||||
|
"https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz"
|
||||||
|
verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256"
|
||||||
|
mkdir -p "$HOME/.nvm"
|
||||||
|
tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1
|
||||||
|
rm -rf "$tmp"
|
||||||
|
}
|
||||||
|
|
||||||
|
ensure_node() {
|
||||||
|
if ! missing node; then return 0; fi
|
||||||
|
ensure_nvm
|
||||||
|
nvm_sh "nvm install $NODE_VERSION"
|
||||||
|
}
|
||||||
|
|
||||||
|
ensure_yarn() {
|
||||||
|
if ! missing yarn; then return 0; fi
|
||||||
|
if ! missing corepack; then
|
||||||
|
corepack enable
|
||||||
|
corepack prepare "yarn@$YARN_VERSION" --activate
|
||||||
|
elif [ -s "$HOME/.nvm/nvm.sh" ]; then
|
||||||
|
nvm_sh "nvm use $NODE_VERSION >/dev/null && corepack enable && \
|
||||||
|
corepack prepare yarn@$YARN_VERSION --activate"
|
||||||
|
else
|
||||||
|
npm install -g "yarn@$YARN_VERSION"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
install_js_deps() {
|
||||||
|
if missing yarn && [ -s "$HOME/.nvm/nvm.sh" ]; then
|
||||||
|
nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && \
|
||||||
|
yarn install --frozen-lockfile"
|
||||||
|
else
|
||||||
|
yarn install --frozen-lockfile
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
|
||||||
|
if missing make; then pkg_install gnumake make make make; fi
|
||||||
|
if missing git; then pkg_install git git git git; fi
|
||||||
|
|
||||||
|
ensure_node
|
||||||
|
ensure_yarn
|
||||||
|
install_js_deps
|
||||||
|
|
||||||
|
echo "bootstrap complete"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
15
script/check
Executable file
15
script/check
Executable file
@@ -0,0 +1,15 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/check: run all checks (test, test-verify-build, lint, fmt-check).
|
||||||
|
# Our own extension to scripts-to-rule-them-all. Must not modify any files.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
"$SCRIPT_DIR/test"
|
||||||
|
"$SCRIPT_DIR/test-verify-build"
|
||||||
|
"$SCRIPT_DIR/lint"
|
||||||
|
"$SCRIPT_DIR/fmt-check"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
13
script/cibuild
Executable file
13
script/cibuild
Executable file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/cibuild: run the CI build. The Dockerfile runs make check, so
|
||||||
|
# a successful build implies all checks pass.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
docker build .
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
14
script/docker
Executable file
14
script/docker
Executable file
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/docker: build the Docker image tagged with the project name.
|
||||||
|
# Identical in all repos; the tag comes from script/projectname.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
docker build -t "$("$SCRIPT_DIR/projectname")" .
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
13
script/fmt
Executable file
13
script/fmt
Executable file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/fmt: format all files (writes).
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
echo "Formatting..."
|
||||||
|
yarn run fmt 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
14
script/fmt-check
Executable file
14
script/fmt-check
Executable file
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/fmt-check: check formatting (read-only). Same scope as
|
||||||
|
# script/fmt, but fails instead of writing.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
echo "Checking formatting..."
|
||||||
|
yarn run fmt-check 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
16
script/install-precommit
Executable file
16
script/install-precommit
Executable file
@@ -0,0 +1,16 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/install-precommit: install the git pre-commit hook that runs
|
||||||
|
# script/precommit. Our own extension to scripts-to-rule-them-all.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
hook=".git/hooks/pre-commit"
|
||||||
|
printf '#!/bin/sh\nset -e\nscript/precommit\n' > "$hook"
|
||||||
|
chmod +x "$hook"
|
||||||
|
echo "pre-commit hook installed: runs script/precommit"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
13
script/lint
Executable file
13
script/lint
Executable file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/lint: run the linter.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
echo "Linting..."
|
||||||
|
yarn run lint 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
12
script/precommit
Executable file
12
script/precommit
Executable file
@@ -0,0 +1,12 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/precommit: run by the git pre-commit hook; fails the commit if
|
||||||
|
# checks fail. Our own extension to scripts-to-rule-them-all.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
"$SCRIPT_DIR/check"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
12
script/projectname
Executable file
12
script/projectname
Executable file
@@ -0,0 +1,12 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/projectname: output the name of this project. Our own
|
||||||
|
# extension to scripts-to-rule-them-all. Other scripts that need the
|
||||||
|
# name (e.g. script/docker) call this, so they can stay identical
|
||||||
|
# across all repos.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
main() {
|
||||||
|
echo "autistmask"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
13
script/setup
Executable file
13
script/setup
Executable file
@@ -0,0 +1,13 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/setup: set up the repo for development after a fresh clone:
|
||||||
|
# installs dependencies and the git pre-commit hook.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
"$SCRIPT_DIR/bootstrap"
|
||||||
|
"$SCRIPT_DIR/install-precommit"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
19
script/test
Executable file
19
script/test
Executable file
@@ -0,0 +1,19 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/test: run the test suite.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
echo "Running tests..."
|
||||||
|
timeout 30 yarn run test 2>&1 || {
|
||||||
|
echo "--- Rerunning with --verbose for details ---"
|
||||||
|
timeout 30 yarn run test:verbose 2>&1 || true
|
||||||
|
# Always fail: the first run already proved the tests are broken, so a
|
||||||
|
# flaky pass on the rerun must not turn the build green.
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
64
script/test-e2e
Executable file
64
script/test-e2e
Executable file
@@ -0,0 +1,64 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/test-e2e: build the extension and drive the real popup in a real
|
||||||
|
# Chromium inside a pinned container. Our own extension to
|
||||||
|
# scripts-to-rule-them-all.
|
||||||
|
#
|
||||||
|
# Deliberately NOT called by script/check or script/test: REPO_POLICIES.md
|
||||||
|
# caps make test at 20 seconds and a browser suite does not fit. Run it
|
||||||
|
# yourself before touching popup views; it is the only check that can see
|
||||||
|
# a used-but-not-imported identifier blow up at runtime.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
# mcr.microsoft.com/playwright:v1.56.0-noble, 2026-08-09
|
||||||
|
#
|
||||||
|
# The playwright-core devDependency is pinned to the matching Playwright
|
||||||
|
# version (1.56.0) and the two must be bumped together: the browsers ship
|
||||||
|
# inside this image, and playwright-core looks for the exact browser
|
||||||
|
# revision its own version expects. A mismatch fails at launch.
|
||||||
|
IMAGE="mcr.microsoft.com/playwright@sha256:35246d87a7c88ea9b771c65d33171b2611b02a8253b4b12ce6f94376c55f99f2"
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
|
||||||
|
if ! command -v docker >/dev/null 2>&1; then
|
||||||
|
echo "test-e2e: docker is required to run the e2e suite" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Building extension for e2e..."
|
||||||
|
yarn run build 2>&1
|
||||||
|
|
||||||
|
echo "Running e2e suite in the pinned Playwright container..."
|
||||||
|
# --ipc=host: Chromium's shared-memory needs more than the default
|
||||||
|
# 64MB /dev/shm or renderers crash.
|
||||||
|
# --user: keep files the suite touches owned by the caller, not root.
|
||||||
|
# HOME=/tmp: the mapped uid has no home directory in the image.
|
||||||
|
# PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1: without it,
|
||||||
|
# ctx.route() intercepts page requests only, and every fetch made by
|
||||||
|
# the MV3 background service worker — including the phishing
|
||||||
|
# blocklist fetch that src/background/index.js issues at worker
|
||||||
|
# startup — goes to the real internet. The flag is experimental and
|
||||||
|
# Playwright may drop or rename it. It cannot break silently: the
|
||||||
|
# harness probes service-worker interception at launch and aborts
|
||||||
|
# the whole suite if it is not in effect (see the interception
|
||||||
|
# canary in tests/e2e/harness.js). If a future Playwright removes
|
||||||
|
# the flag, that probe is what will fail, and the fix is either a
|
||||||
|
# replacement mechanism or an honest downgrade of the isolation
|
||||||
|
# claim in tests/e2e/network.js and README.md — not deleting the
|
||||||
|
# probe. The image is pinned by digest, so this can only ever bite
|
||||||
|
# on a deliberate bump.
|
||||||
|
docker run --rm \
|
||||||
|
--ipc=host \
|
||||||
|
--user "$(id -u):$(id -g)" \
|
||||||
|
-e HOME=/tmp \
|
||||||
|
-e PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1 \
|
||||||
|
-e "E2E_TRACE_NETWORK=${E2E_TRACE_NETWORK:-0}" \
|
||||||
|
-v "$ROOT:/work" \
|
||||||
|
-w /work \
|
||||||
|
"$IMAGE" \
|
||||||
|
node tests/e2e/run.js
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
444
script/test-verify-build
Executable file
444
script/test-verify-build
Executable file
@@ -0,0 +1,444 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/test-verify-build: exercise every failure mode of
|
||||||
|
# script/verify-build. Our own extension to scripts-to-rule-them-all, run
|
||||||
|
# from script/check so make check covers it.
|
||||||
|
#
|
||||||
|
# Why this exists: verify-build is the build-integrity guard, and three
|
||||||
|
# separate reviews of it each found a fresh vacuous pass — the grep exit-2
|
||||||
|
# conflation, the discarded find status, the line-delimited walk. Every one
|
||||||
|
# was caught by someone building a tree by hand, because nothing in make check
|
||||||
|
# could catch it. This is that hand battery, committed and automated.
|
||||||
|
#
|
||||||
|
# Each case asserts the exit status AND a substring of the message. A guard
|
||||||
|
# that fails for the wrong reason (right status, different fault) is itself a
|
||||||
|
# defect, so matching the status alone would not be a test of anything.
|
||||||
|
#
|
||||||
|
# The fixture is a temp tree containing script/verify-build as a SYMLINK to
|
||||||
|
# the real script: verify-build takes its ROOT from dirname "$0"/.., so it
|
||||||
|
# operates on the fixture's dist/ and never reads or writes the repo's build
|
||||||
|
# output. The symlink rather than a copy is what makes a deliberate break in
|
||||||
|
# the real script fail here.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
VERIFY_BUILD="$ROOT/script/verify-build"
|
||||||
|
|
||||||
|
MARKER_ON="autistmask-build-debug=on"
|
||||||
|
MARKER_OFF="autistmask-build-debug=off"
|
||||||
|
|
||||||
|
NEWLINE='
|
||||||
|
'
|
||||||
|
|
||||||
|
PASSED=0
|
||||||
|
FAILED=0
|
||||||
|
SKIPPED=0
|
||||||
|
SKIPPED_NAMES=""
|
||||||
|
|
||||||
|
# The command prefix that runs the permission-dependent cases as a user who
|
||||||
|
# is actually subject to file permissions, and whether those cases can run at
|
||||||
|
# all. Both are decided by probe_permission_runner, never assumed.
|
||||||
|
UNPRIV=""
|
||||||
|
PERM_ENABLED=no
|
||||||
|
PERM_HOW=""
|
||||||
|
|
||||||
|
WORK=""
|
||||||
|
|
||||||
|
cleanup() {
|
||||||
|
[ -n "$WORK" ] || return 0
|
||||||
|
# The cases chmod 000 files and directories on purpose.
|
||||||
|
chmod -R u+rwX "$WORK" 2>/dev/null || true
|
||||||
|
rm -rf "$WORK"
|
||||||
|
}
|
||||||
|
trap cleanup EXIT INT TERM
|
||||||
|
|
||||||
|
WORK="$(mktemp -d "${TMPDIR:-/tmp}/autistmask-test-verify-build.XXXXXX")"
|
||||||
|
FIXTURE="$WORK/fixture"
|
||||||
|
|
||||||
|
# verify-build mktemps its dist/ listing under TMPDIR. Pointing that inside
|
||||||
|
# our work dir keeps the run leaving no residue, and keeps it writable for the
|
||||||
|
# unprivileged user the permission cases run as.
|
||||||
|
TMPDIR="$WORK/tmp"
|
||||||
|
export TMPDIR
|
||||||
|
mkdir -p "$TMPDIR"
|
||||||
|
chmod 1777 "$TMPDIR"
|
||||||
|
chmod 755 "$WORK"
|
||||||
|
|
||||||
|
# --- fixture ---------------------------------------------------------------
|
||||||
|
|
||||||
|
# A stand-in for an emitted bundle: some text plus one marker literal, which
|
||||||
|
# is all verify-build reads out of the real thing.
|
||||||
|
write_bundle() {
|
||||||
|
printf 'var a=1;/* %s */\nvar b=2;\n' "$2" >"$1"
|
||||||
|
}
|
||||||
|
|
||||||
|
# A dist/ shaped like a real build: two listed bundles under different
|
||||||
|
# browsers, an unlisted subtree to make unwalkable, and unlisted files that
|
||||||
|
# carry no marker and must not be objected to.
|
||||||
|
build_fixture() {
|
||||||
|
chmod -R u+rwX "$FIXTURE" 2>/dev/null || true
|
||||||
|
rm -rf "$FIXTURE"
|
||||||
|
|
||||||
|
mkdir -p "$FIXTURE/script"
|
||||||
|
ln -s "$VERIFY_BUILD" "$FIXTURE/script/verify-build"
|
||||||
|
|
||||||
|
mkdir -p "$FIXTURE/dist/chrome/src/popup" \
|
||||||
|
"$FIXTURE/dist/chrome/src/content" \
|
||||||
|
"$FIXTURE/dist/firefox/src/popup"
|
||||||
|
|
||||||
|
write_bundle "$FIXTURE/dist/chrome/src/popup/index.js" "$MARKER_OFF"
|
||||||
|
write_bundle "$FIXTURE/dist/firefox/src/popup/index.js" "$MARKER_OFF"
|
||||||
|
printf 'body{color:#000}\n' >"$FIXTURE/dist/styles.css"
|
||||||
|
printf 'var c=3;\n' >"$FIXTURE/dist/chrome/src/content/content.js"
|
||||||
|
|
||||||
|
{
|
||||||
|
echo "dist/chrome/src/popup/index.js"
|
||||||
|
echo "dist/firefox/src/popup/index.js"
|
||||||
|
} >"$FIXTURE/dist/constants-bundles.txt"
|
||||||
|
|
||||||
|
# Readable and traversable by the unprivileged user the permission cases
|
||||||
|
# run as, before those cases take that away again on purpose.
|
||||||
|
chmod -R a+rX "$FIXTURE"
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- permission runner ------------------------------------------------------
|
||||||
|
|
||||||
|
# Run a command through the current unprivileged runner. Unquoted on purpose:
|
||||||
|
# UNPRIV is a command prefix that has to word-split.
|
||||||
|
run_unpriv() {
|
||||||
|
# shellcheck disable=SC2086
|
||||||
|
$UNPRIV "$@"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Decide whether the permission-dependent cases can run, and prove it rather
|
||||||
|
# than assuming it.
|
||||||
|
#
|
||||||
|
# The problem: the CI image declares no USER, so CI runs as root, and root is
|
||||||
|
# not subject to file permissions — chmod 000 stops neither find nor grep. A
|
||||||
|
# permission case run as root passes vacuously, which is worse than no case at
|
||||||
|
# all because it reads as coverage.
|
||||||
|
#
|
||||||
|
# So the runner is validated with two probes before any permission case is
|
||||||
|
# counted:
|
||||||
|
#
|
||||||
|
# - a mode-644 file MUST be readable through it. If not, the runner itself
|
||||||
|
# is broken (missing helper, no such user, sandbox), and every case run
|
||||||
|
# through it would fail for the wrong reason.
|
||||||
|
# - a mode-000 file MUST NOT be readable through it. If it is, permissions
|
||||||
|
# are not in force and the cases would pass without proving anything.
|
||||||
|
#
|
||||||
|
# Unprivileged: the runner is empty and both probes are about this process,
|
||||||
|
# which is the honest answer. Root: setpriv and runuser are tried, both
|
||||||
|
# present in the pinned CI base image. Only when no candidate passes both
|
||||||
|
# probes are the cases skipped, and a skipped run says so unmistakably.
|
||||||
|
probe_permission_runner() {
|
||||||
|
_probe="$WORK/probe"
|
||||||
|
mkdir -p "$_probe"
|
||||||
|
printf 'readable\n' >"$_probe/public"
|
||||||
|
printf 'secret\n' >"$_probe/private"
|
||||||
|
chmod 755 "$_probe"
|
||||||
|
chmod 644 "$_probe/public"
|
||||||
|
chmod 000 "$_probe/private"
|
||||||
|
|
||||||
|
if [ "$(id -u)" -eq 0 ]; then
|
||||||
|
_candidates="setpriv|setpriv --reuid=65534 --regid=65534 --clear-groups --
|
||||||
|
runuser|runuser -u nobody --"
|
||||||
|
else
|
||||||
|
_candidates="direct|"
|
||||||
|
fi
|
||||||
|
|
||||||
|
_tried=""
|
||||||
|
_saved_ifs="$IFS"
|
||||||
|
IFS="$NEWLINE"
|
||||||
|
for _line in $_candidates; do
|
||||||
|
IFS="$_saved_ifs"
|
||||||
|
_label="${_line%%|*}"
|
||||||
|
_cmd="${_line#*|}"
|
||||||
|
_tried="${_tried:+$_tried, }$_label"
|
||||||
|
|
||||||
|
if [ -n "$_cmd" ]; then
|
||||||
|
_bin="${_cmd%% *}"
|
||||||
|
command -v "$_bin" >/dev/null 2>&1 || continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
UNPRIV="$_cmd"
|
||||||
|
# Broken or unusable runner: the cases would fail for the wrong
|
||||||
|
# reason. Reaching the script under test is part of usable.
|
||||||
|
run_unpriv cat "$_probe/public" >/dev/null 2>&1 || continue
|
||||||
|
run_unpriv cat "$VERIFY_BUILD" >/dev/null 2>&1 || continue
|
||||||
|
# Permissions not in force through this runner: the cases would pass
|
||||||
|
# without testing anything.
|
||||||
|
if run_unpriv cat "$_probe/private" >/dev/null 2>&1; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
PERM_ENABLED=yes
|
||||||
|
PERM_HOW="$_label"
|
||||||
|
IFS="$_saved_ifs"
|
||||||
|
return 0
|
||||||
|
done
|
||||||
|
IFS="$_saved_ifs"
|
||||||
|
|
||||||
|
UNPRIV=""
|
||||||
|
PERM_ENABLED=no
|
||||||
|
PERM_HOW="$_tried"
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- case runner ------------------------------------------------------------
|
||||||
|
|
||||||
|
# check_case <name> <perm:yes|no> <mode:release|debug> <status> <text> <setup>
|
||||||
|
#
|
||||||
|
# Rebuilds the fixture, applies <setup> inside it, runs verify-build, and
|
||||||
|
# requires both the exit status and the message. <perm> marks a case that only
|
||||||
|
# means anything when file permissions are in force.
|
||||||
|
check_case() {
|
||||||
|
_name="$1"
|
||||||
|
_perm="$2"
|
||||||
|
_mode="$3"
|
||||||
|
_want_status="$4"
|
||||||
|
_want_text="$5"
|
||||||
|
_setup="$6"
|
||||||
|
|
||||||
|
if [ "$_perm" = yes ] && [ "$PERM_ENABLED" != yes ]; then
|
||||||
|
SKIPPED=$((SKIPPED + 1))
|
||||||
|
SKIPPED_NAMES="$SKIPPED_NAMES## - $_name$NEWLINE"
|
||||||
|
echo " SKIP (permissions not in force): $_name"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
build_fixture
|
||||||
|
if ! (cd "$FIXTURE" && "$_setup") >/dev/null 2>&1; then
|
||||||
|
FAILED=$((FAILED + 1))
|
||||||
|
echo " FAIL: $_name"
|
||||||
|
echo " the case's own setup failed, so nothing was tested."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$_mode" = debug ]; then
|
||||||
|
_debug=1
|
||||||
|
else
|
||||||
|
_debug=""
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Exported rather than set as a command prefix: run_unpriv is a function,
|
||||||
|
# and an assignment prefixed to a function call is not portable.
|
||||||
|
AUTISTMASK_DEBUG="$_debug"
|
||||||
|
export AUTISTMASK_DEBUG
|
||||||
|
|
||||||
|
_status=0
|
||||||
|
if [ "$_perm" = yes ]; then
|
||||||
|
_out="$(run_unpriv "$FIXTURE/script/verify-build" 2>&1)" || _status=$?
|
||||||
|
else
|
||||||
|
_out="$("$FIXTURE/script/verify-build" 2>&1)" || _status=$?
|
||||||
|
fi
|
||||||
|
|
||||||
|
_ok=yes
|
||||||
|
_why=""
|
||||||
|
|
||||||
|
if [ "$_status" -ne "$_want_status" ]; then
|
||||||
|
_ok=no
|
||||||
|
_why="exit status $_status, wanted $_want_status"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Same discipline verify-build itself applies to grep: 0 and 1 are
|
||||||
|
# answers, anything else is not, and must not be read as "no match".
|
||||||
|
_g=0
|
||||||
|
printf '%s\n' "$_out" | grep -q -F -e "$_want_text" || _g=$?
|
||||||
|
case "$_g" in
|
||||||
|
0) ;;
|
||||||
|
1)
|
||||||
|
_ok=no
|
||||||
|
_why="${_why:+$_why; }message did not contain: $_want_text"
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
_ok=no
|
||||||
|
_why="${_why:+$_why; }grep exited $_g matching the message, so the
|
||||||
|
message was never checked"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
if [ "$_ok" = yes ]; then
|
||||||
|
PASSED=$((PASSED + 1))
|
||||||
|
echo " ok: $_name"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
FAILED=$((FAILED + 1))
|
||||||
|
echo " FAIL: $_name"
|
||||||
|
echo " $_why"
|
||||||
|
echo " --- verify-build output ---"
|
||||||
|
printf '%s\n' "$_out" | sed 's/^/ /'
|
||||||
|
echo " --- end output ---"
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- cases ------------------------------------------------------------------
|
||||||
|
#
|
||||||
|
# Each runs with the fixture as its working directory.
|
||||||
|
|
||||||
|
c_control() { :; }
|
||||||
|
|
||||||
|
c_trailing_space() {
|
||||||
|
cp dist/chrome/src/popup/index.js "dist/chrome/src/popup/index.js "
|
||||||
|
}
|
||||||
|
|
||||||
|
c_embedded_newline() {
|
||||||
|
cp dist/chrome/src/popup/index.js "dist/chrome/src/popup/index.js$NEWLINE"
|
||||||
|
}
|
||||||
|
|
||||||
|
c_dist_symlink() {
|
||||||
|
mv dist dist.real
|
||||||
|
ln -s dist.real dist
|
||||||
|
}
|
||||||
|
|
||||||
|
c_unwalkable_subtree() { chmod 000 dist/chrome/src/content; }
|
||||||
|
|
||||||
|
c_dangling_symlink() {
|
||||||
|
ln -s /nonexistent-target-for-test-verify-build dist/chrome/dangling.js
|
||||||
|
}
|
||||||
|
|
||||||
|
c_dir_symlink() { ln -s src dist/chrome/link-to-dir; }
|
||||||
|
|
||||||
|
c_alias_symlink() { ln -s popup/index.js dist/chrome/src/aliased.js; }
|
||||||
|
|
||||||
|
c_manifest_missing() { rm dist/constants-bundles.txt; }
|
||||||
|
|
||||||
|
c_manifest_empty() { : >dist/constants-bundles.txt; }
|
||||||
|
|
||||||
|
c_manifest_unreadable() { chmod 000 dist/constants-bundles.txt; }
|
||||||
|
|
||||||
|
c_bundle_missing() { rm dist/chrome/src/popup/index.js; }
|
||||||
|
|
||||||
|
c_bundle_empty() { : >dist/chrome/src/popup/index.js; }
|
||||||
|
|
||||||
|
c_bundle_unreadable() { chmod 000 dist/chrome/src/popup/index.js; }
|
||||||
|
|
||||||
|
c_unlisted_extension() {
|
||||||
|
cp dist/chrome/src/popup/index.js dist/chrome/src/popup/extra.mjs
|
||||||
|
}
|
||||||
|
|
||||||
|
c_no_marker() { printf 'var d=4;\n' >dist/chrome/src/popup/index.js; }
|
||||||
|
|
||||||
|
c_both_markers() {
|
||||||
|
printf '/* %s */\n' "$MARKER_ON" >>dist/chrome/src/popup/index.js
|
||||||
|
}
|
||||||
|
|
||||||
|
run_cases() {
|
||||||
|
check_case "control: untouched dist passes" \
|
||||||
|
no release 0 "2 bundle(s) verified $MARKER_OFF" c_control
|
||||||
|
|
||||||
|
check_case "unlisted marker-carrying file, trailing space in name" \
|
||||||
|
no release 1 "carries a debug marker but is absent from" \
|
||||||
|
c_trailing_space
|
||||||
|
|
||||||
|
check_case "unlisted marker-carrying file, newline in name" \
|
||||||
|
no release 1 "carries a debug marker but is absent from" \
|
||||||
|
c_embedded_newline
|
||||||
|
|
||||||
|
check_case "dist/ replaced by a symlink" \
|
||||||
|
no release 1 "dist is a symlink, not a directory." c_dist_symlink
|
||||||
|
|
||||||
|
check_case "unwalkable subtree under dist/" \
|
||||||
|
yes release 1 "enumerating dist/, so part of the tree" \
|
||||||
|
c_unwalkable_subtree
|
||||||
|
|
||||||
|
check_case "dangling symlink under dist/" \
|
||||||
|
no release 1 \
|
||||||
|
"reading dist/chrome/dangling.js, so the file could not be" \
|
||||||
|
c_dangling_symlink
|
||||||
|
|
||||||
|
check_case "symlink to a directory under dist/" \
|
||||||
|
no release 1 \
|
||||||
|
"reading dist/chrome/link-to-dir, so the file could not be" \
|
||||||
|
c_dir_symlink
|
||||||
|
|
||||||
|
check_case "symlink to a listed bundle under an unlisted path" \
|
||||||
|
no release 1 \
|
||||||
|
"dist/chrome/src/aliased.js carries a debug marker but is absent" \
|
||||||
|
c_alias_symlink
|
||||||
|
|
||||||
|
check_case "manifest missing" \
|
||||||
|
no release 1 "dist/constants-bundles.txt is missing." \
|
||||||
|
c_manifest_missing
|
||||||
|
|
||||||
|
check_case "manifest empty" \
|
||||||
|
no release 1 "is empty, so no emitted bundle was found to contain" \
|
||||||
|
c_manifest_empty
|
||||||
|
|
||||||
|
check_case "manifest unreadable" \
|
||||||
|
yes release 1 "is not readable, so nothing was inspected." \
|
||||||
|
c_manifest_unreadable
|
||||||
|
|
||||||
|
check_case "listed bundle missing" \
|
||||||
|
no release 1 \
|
||||||
|
"lists dist/chrome/src/popup/index.js, which does not exist." \
|
||||||
|
c_bundle_missing
|
||||||
|
|
||||||
|
check_case "listed bundle empty" \
|
||||||
|
no release 1 "which is empty. An empty bundle" c_bundle_empty
|
||||||
|
|
||||||
|
check_case "listed bundle unreadable" \
|
||||||
|
yes release 1 \
|
||||||
|
"reading dist/chrome/src/popup/index.js, so the file could not be" \
|
||||||
|
c_bundle_unreadable
|
||||||
|
|
||||||
|
check_case "unlisted extension carrying a marker" \
|
||||||
|
no release 1 \
|
||||||
|
"dist/chrome/src/popup/extra.mjs carries a debug marker but is" \
|
||||||
|
c_unlisted_extension
|
||||||
|
|
||||||
|
check_case "listed bundle carries no marker" \
|
||||||
|
no release 1 "carries no debug marker, so its DEBUG state cannot be" \
|
||||||
|
c_no_marker
|
||||||
|
|
||||||
|
check_case "listed bundle carries both markers" \
|
||||||
|
no release 1 "carries both debug markers, so DEBUG was not resolved" \
|
||||||
|
c_both_markers
|
||||||
|
|
||||||
|
check_case "wrong marker for the requested mode" \
|
||||||
|
no debug 1 "is $MARKER_OFF but this build expects $MARKER_ON" \
|
||||||
|
c_control
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- main --------------------------------------------------------------------
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
|
||||||
|
[ -x "$VERIFY_BUILD" ] || {
|
||||||
|
echo "test-verify-build: $VERIFY_BUILD is missing or not executable" >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
echo "Testing script/verify-build failure modes..."
|
||||||
|
probe_permission_runner
|
||||||
|
if [ "$PERM_ENABLED" = yes ]; then
|
||||||
|
echo " permission cases: enabled (runner: $PERM_HOW, proved against" \
|
||||||
|
"a mode-000 file)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
run_cases
|
||||||
|
|
||||||
|
if [ "$FAILED" -ne 0 ]; then
|
||||||
|
echo "test-verify-build: $FAILED case(s) FAILED," \
|
||||||
|
"$PASSED passed, $SKIPPED skipped" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$SKIPPED" -ne 0 ]; then
|
||||||
|
cat <<EOF
|
||||||
|
################################################################################
|
||||||
|
## WARNING: $SKIPPED PERMISSION CASE(S) DID NOT RUN, AND THIS RUN DOES NOT
|
||||||
|
## PROVE THEM. This process is uid $(id -u), and no runner subject to file
|
||||||
|
## permissions was available. Tried: $PERM_HOW.
|
||||||
|
## Under root, chmod 000 stops neither find nor grep, so these cases would
|
||||||
|
## have passed without testing anything. They were skipped, not counted:
|
||||||
|
$SKIPPED_NAMES################################################################################
|
||||||
|
EOF
|
||||||
|
echo "test-verify-build: $PASSED case(s) passed," \
|
||||||
|
"$SKIPPED SKIPPED AND NOT PROVEN (see the warning above)"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "test-verify-build: $PASSED case(s) passed"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
295
script/verify-build
Executable file
295
script/verify-build
Executable file
@@ -0,0 +1,295 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# script/verify-build: assert the compiled DEBUG state of the emitted
|
||||||
|
# bundles. Our own extension to scripts-to-rule-them-all, run at the end of
|
||||||
|
# make build / make build-debug.
|
||||||
|
#
|
||||||
|
# Why this exists: DEBUG makes the publicly committed test recovery phrase the
|
||||||
|
# output of wallet creation, so a release artifact built with it live hands
|
||||||
|
# every new wallet to anyone who reads the repo. The test suite cannot see
|
||||||
|
# this, because it loads src/shared/constants.js outside a bundle and takes
|
||||||
|
# the fallback branch; the property only exists in the emitted output, so it
|
||||||
|
# has to be asserted against the emitted output.
|
||||||
|
#
|
||||||
|
# What it reads: dist/constants-bundles.txt, written by build.js from
|
||||||
|
# esbuild's metafile, naming every emitted bundle that contains
|
||||||
|
# src/shared/constants.js. Each of those must carry exactly one of the two
|
||||||
|
# BUILD_DEBUG_MARKER literals that constants.js folds down to.
|
||||||
|
#
|
||||||
|
# It fails rather than passes whenever it cannot determine a bundle's state.
|
||||||
|
# Minified output is not a stable contract, so "matched neither form" is not
|
||||||
|
# evidence of anything and must never read as green.
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
|
# Absolute path to this script, resolved before anything cd's anywhere.
|
||||||
|
# check_unlisted_bundles re-invokes it through xargs, and $0 on its own may be
|
||||||
|
# relative to a directory we are about to leave.
|
||||||
|
SELF="$(cd "$(dirname "$0")" && pwd -P)/$(basename "$0")"
|
||||||
|
|
||||||
|
# Internal re-entry flag; see scan_dist_paths.
|
||||||
|
SCAN_FLAG="--scan-dist-paths"
|
||||||
|
|
||||||
|
# A literal newline, for the is_listed guard.
|
||||||
|
NEWLINE='
|
||||||
|
'
|
||||||
|
|
||||||
|
MANIFEST="dist/constants-bundles.txt"
|
||||||
|
MARKER_ON="autistmask-build-debug=on"
|
||||||
|
MARKER_OFF="autistmask-build-debug=off"
|
||||||
|
|
||||||
|
# Set by read_marker.
|
||||||
|
MARKER=""
|
||||||
|
|
||||||
|
# Temporary file holding the NUL-delimited dist/ listing, removed by the EXIT
|
||||||
|
# trap because fail() exits from wherever it is called.
|
||||||
|
LISTING=""
|
||||||
|
|
||||||
|
fail() {
|
||||||
|
echo "verify-build: FAIL: $*" >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
cleanup() {
|
||||||
|
[ -z "$LISTING" ] || rm -f "$LISTING"
|
||||||
|
}
|
||||||
|
trap cleanup EXIT
|
||||||
|
|
||||||
|
# Is the literal $1 present in the file $2? Match (grep exit 0) and no-match
|
||||||
|
# (exit 1) are answers about the emitted output. Anything else (exit 2: the
|
||||||
|
# file could not be read) is not an answer at all, and must not be reported as
|
||||||
|
# "no marker" — that would blame the bundle for a permissions or I/O fault.
|
||||||
|
has_marker() {
|
||||||
|
_hm_status=0
|
||||||
|
grep -q -F -e "$1" -- "$2" || _hm_status=$?
|
||||||
|
case "$_hm_status" in
|
||||||
|
0) return 0 ;;
|
||||||
|
1) return 1 ;;
|
||||||
|
*)
|
||||||
|
fail "grep exited $_hm_status reading $2, so the file could not be
|
||||||
|
searched and its DEBUG state was not checked at all. That is a permissions
|
||||||
|
or I/O fault on the artifact, not a change in the emitted output. Refusing
|
||||||
|
to report success."
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
# Does the manifest list the path $1, as a whole line? Same discipline as
|
||||||
|
# has_marker: exit 0 and 1 are answers about the manifest, exit 2 means the
|
||||||
|
# manifest could not be read and is not an answer at all. Without this, an
|
||||||
|
# unreadable manifest reads as "this file is not listed" and every emitted
|
||||||
|
# bundle gets reported as an unlisted one.
|
||||||
|
#
|
||||||
|
# A path containing a newline is answered without asking grep, because grep
|
||||||
|
# would read the pattern as two patterns and report a match on either. That is
|
||||||
|
# how such a path escaped this check even once the walk stopped splitting it:
|
||||||
|
# the half before the newline matched a listed line and the file was skipped.
|
||||||
|
# The manifest is line-delimited, so it cannot name such a path at all, and
|
||||||
|
# "not listed" is the only true answer.
|
||||||
|
is_listed() {
|
||||||
|
case "$1" in
|
||||||
|
*"$NEWLINE"*) return 1 ;;
|
||||||
|
esac
|
||||||
|
_il_status=0
|
||||||
|
grep -q -x -F -e "$1" -- "$MANIFEST" || _il_status=$?
|
||||||
|
case "$_il_status" in
|
||||||
|
0) return 0 ;;
|
||||||
|
1) return 1 ;;
|
||||||
|
*)
|
||||||
|
fail "grep exited $_il_status reading $MANIFEST, so it could not be
|
||||||
|
searched and nothing was established about which bundles it lists. That is
|
||||||
|
a permissions or I/O fault on the manifest, not a stale manifest. Refusing
|
||||||
|
to report success."
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
# Read one bundle's DEBUG state into MARKER. Exactly one marker must be
|
||||||
|
# present. Both means the ternary in constants.js was never folded, which is
|
||||||
|
# what happens when the __BUILD_DEBUG__ define goes missing from build.js:
|
||||||
|
# DEBUG stops being known at build time. Neither means we are reading output
|
||||||
|
# we do not understand. Both are hard failures; neither is ever treated as
|
||||||
|
# absence of a problem.
|
||||||
|
read_marker() {
|
||||||
|
_file="$1"
|
||||||
|
_on=no
|
||||||
|
_off=no
|
||||||
|
if has_marker "$MARKER_ON" "$_file"; then _on=yes; fi
|
||||||
|
if has_marker "$MARKER_OFF" "$_file"; then _off=yes; fi
|
||||||
|
|
||||||
|
if [ "$_on" = yes ] && [ "$_off" = yes ]; then
|
||||||
|
fail "$_file carries both debug markers, so DEBUG was not resolved at
|
||||||
|
build time: the ternary in src/shared/constants.js survived into the
|
||||||
|
emitted output. This does not mean the debug branch is live in this
|
||||||
|
artifact: an unresolved __BUILD_DEBUG__ is undeclared in extension
|
||||||
|
context, so DEBUG evaluates to false at runtime. It does mean the
|
||||||
|
release/debug distinction is no longer enforced at build time, and which
|
||||||
|
way that fallback happens to evaluate is then an accident a refactor can
|
||||||
|
flip. Check that build.js still defines __BUILD_DEBUG__."
|
||||||
|
fi
|
||||||
|
if [ "$_on" = no ] && [ "$_off" = no ]; then
|
||||||
|
fail "$_file carries no debug marker, so its DEBUG state cannot be
|
||||||
|
determined. Either BUILD_DEBUG_MARKER is gone from src/shared/constants.js
|
||||||
|
or the emitted output changed shape. Refusing to report success."
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$_on" = yes ]; then
|
||||||
|
MARKER="$MARKER_ON"
|
||||||
|
else
|
||||||
|
MARKER="$MARKER_OFF"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# The manifest says which bundles must carry a marker. This says no other
|
||||||
|
# emitted file may carry one, which catches a manifest that has gone stale
|
||||||
|
# or short rather than trusting whatever it happens to list.
|
||||||
|
#
|
||||||
|
# Deliberately unfiltered by extension. build.js selects manifest entries with
|
||||||
|
# an endsWith(".js") test; repeating that literal here would mean a bundle
|
||||||
|
# emitted under some other extension escaped the manifest AND this check at
|
||||||
|
# once, which is the correlated blind spot the two-source design exists to
|
||||||
|
# avoid. Every regular file and every symlink under dist/ is searched — that
|
||||||
|
# is the whole of what a build emits — so build.js's filter is the only place
|
||||||
|
# the assumption lives and this check is what catches it being wrong.
|
||||||
|
#
|
||||||
|
# That claim only holds if the walk is exhaustive and every name survives it
|
||||||
|
# intact, so four things are enforced here rather than assumed:
|
||||||
|
#
|
||||||
|
# - the walk is NUL-delimited and the paths reach the check as arguments, so
|
||||||
|
# no name can be reshaped on the way in. Read line by line, a name with a
|
||||||
|
# trailing space lost it to read's field splitting and the remnant then
|
||||||
|
# matched a manifest line, and a name containing a newline arrived as a
|
||||||
|
# listed path plus an empty one. Both left a marker-carrying, unlisted file
|
||||||
|
# unchecked while the script still reported success. Delivering such a name
|
||||||
|
# intact is only half of it; is_listed also has to keep it out of grep's
|
||||||
|
# pattern, for the same reason.
|
||||||
|
# - find's exit status is checked. A subtree it cannot descend is reported on
|
||||||
|
# stderr and then simply missing from the listing, so an unchecked status
|
||||||
|
# turns "could not look" into "nothing was there" — the same conflation
|
||||||
|
# has_marker exists to prevent. The status cannot be read off a pipeline,
|
||||||
|
# so the listing lands in a file that xargs then reads back.
|
||||||
|
# - symlinks are walked too (-type l), not skipped. A marker-carrying bundle
|
||||||
|
# reachable under an unlisted path in dist/ is a stale manifest whether the
|
||||||
|
# path is a link or a file, and grep reads through the link. A link that
|
||||||
|
# cannot be read through — dangling, or pointing at a directory — fails
|
||||||
|
# hard via has_marker's exit-2 path, which is the fail-closed answer: the
|
||||||
|
# build emits neither, so their DEBUG state is unproven, not fine.
|
||||||
|
# - dist/ itself must be a directory and not a symlink, which main asserts
|
||||||
|
# before anything reads through it. find does not follow a symlink named on
|
||||||
|
# its own command line, so a linked dist/ collapses this walk to one entry
|
||||||
|
# and cross-checks nothing.
|
||||||
|
#
|
||||||
|
# Types other than regular files and symlinks are left out on purpose: a build
|
||||||
|
# emits none of them, and grep on a fifo would hang rather than fail.
|
||||||
|
check_unlisted_bundles() {
|
||||||
|
LISTING="$(mktemp "${TMPDIR:-/tmp}/verify-build-dist.XXXXXX")" ||
|
||||||
|
fail "could not create a temporary file for the dist/ listing, so the
|
||||||
|
tree was never walked. Refusing to report success."
|
||||||
|
|
||||||
|
_find_status=0
|
||||||
|
find dist \( -type f -o -type l \) -print0 >"$LISTING" || _find_status=$?
|
||||||
|
[ "$_find_status" -eq 0 ] ||
|
||||||
|
fail "find exited $_find_status enumerating dist/, so part of the tree
|
||||||
|
was never walked and nothing was established about the files in it. Any
|
||||||
|
unlisted bundle there went unchecked. That is a permissions or I/O fault on
|
||||||
|
the artifact, not a stale manifest. Refusing to report success."
|
||||||
|
|
||||||
|
_scan_status=0
|
||||||
|
xargs -0 "$SELF" "$SCAN_FLAG" <"$LISTING" || _scan_status=$?
|
||||||
|
[ "$_scan_status" -eq 0 ] ||
|
||||||
|
fail "the unlisted-bundle scan exited $_scan_status: either a path
|
||||||
|
under dist/ failed the check reported above, or the scan could not be run
|
||||||
|
at all. Refusing to report success."
|
||||||
|
}
|
||||||
|
|
||||||
|
# The per-path half of check_unlisted_bundles. It runs in a re-invocation of
|
||||||
|
# this script, so it uses the same is_listed and has_marker as the rest of the
|
||||||
|
# file rather than a second copy of them that could drift. Paths arrive as
|
||||||
|
# arguments and are never split, joined or trimmed.
|
||||||
|
scan_dist_paths() {
|
||||||
|
for _file in "$@"; do
|
||||||
|
if is_listed "$_file"; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
if has_marker "$MARKER_ON" "$_file" ||
|
||||||
|
has_marker "$MARKER_OFF" "$_file"; then
|
||||||
|
fail "$_file carries a debug marker but is absent from $MANIFEST,
|
||||||
|
so the manifest no longer describes the emitted bundles."
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
# The requested mode, read from our own environment using build.js's exact
|
||||||
|
# rule: only the literal 1 opts in. Deliberately not taken from anything
|
||||||
|
# build.js records about itself, so build.js cannot vouch for build.js.
|
||||||
|
expected_marker() {
|
||||||
|
if [ "${AUTISTMASK_DEBUG-}" = "1" ]; then
|
||||||
|
echo "$MARKER_ON"
|
||||||
|
else
|
||||||
|
echo "$MARKER_OFF"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
|
||||||
|
# Internal re-entry from check_unlisted_bundles' xargs. Not part of the
|
||||||
|
# command-line interface: nothing else invokes it, and it is a distinct
|
||||||
|
# entry point rather than a mode flag threaded through the checks below.
|
||||||
|
if [ "${1-}" = "$SCAN_FLAG" ]; then
|
||||||
|
shift
|
||||||
|
scan_dist_paths "$@"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
expected="$(expected_marker)"
|
||||||
|
echo "Verifying emitted bundles (expecting $expected)..."
|
||||||
|
|
||||||
|
# Asserted here rather than left to grep. A symlinked dist/ used to fail
|
||||||
|
# only because GNU grep exits 2 on a directory, so check_unlisted_bundles'
|
||||||
|
# single entry hit has_marker's I/O path by luck; under a grep that exits 1
|
||||||
|
# instead, the whole cross-check would have collapsed into a pass.
|
||||||
|
if [ -h dist ]; then
|
||||||
|
fail "dist is a symlink, not a directory. find does not follow a
|
||||||
|
symlink named on its own command line, so the unlisted-bundle cross-check
|
||||||
|
would see one entry instead of the emitted tree and establish nothing about
|
||||||
|
it. Refusing to report success."
|
||||||
|
fi
|
||||||
|
[ -d dist ] ||
|
||||||
|
fail "dist is not a directory, so there is no emitted tree to verify.
|
||||||
|
build.js writes it; run make build first."
|
||||||
|
|
||||||
|
[ -f "$MANIFEST" ] ||
|
||||||
|
fail "$MANIFEST is missing. build.js writes it at the end of a
|
||||||
|
successful build; run make build first."
|
||||||
|
[ -s "$MANIFEST" ] ||
|
||||||
|
fail "$MANIFEST is empty, so no emitted bundle was found to contain
|
||||||
|
src/shared/constants.js. That is never correct, so it is a failure and not
|
||||||
|
a pass."
|
||||||
|
[ -r "$MANIFEST" ] ||
|
||||||
|
fail "$MANIFEST is not readable, so nothing was inspected. That is a
|
||||||
|
permissions or I/O fault, not a pass."
|
||||||
|
|
||||||
|
count=0
|
||||||
|
while read -r file; do
|
||||||
|
[ -n "$file" ] || continue
|
||||||
|
[ -f "$file" ] ||
|
||||||
|
fail "$MANIFEST lists $file, which does not exist."
|
||||||
|
[ -s "$file" ] ||
|
||||||
|
fail "$MANIFEST lists $file, which is empty. An empty bundle
|
||||||
|
carries no marker and proves nothing, so this is a failure and not a pass."
|
||||||
|
read_marker "$file"
|
||||||
|
[ "$MARKER" = "$expected" ] ||
|
||||||
|
fail "$file is $MARKER but this build expects $expected."
|
||||||
|
echo " ok: $file ($MARKER)"
|
||||||
|
count=$((count + 1))
|
||||||
|
done <"$MANIFEST"
|
||||||
|
|
||||||
|
[ "$count" -gt 0 ] || fail "no bundles were inspected."
|
||||||
|
|
||||||
|
check_unlisted_bundles
|
||||||
|
|
||||||
|
echo "verify-build: $count bundle(s) verified $expected"
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
@@ -2,16 +2,39 @@
|
|||||||
// Handles EIP-1193 RPC requests from content scripts and proxies
|
// Handles EIP-1193 RPC requests from content scripts and proxies
|
||||||
// non-sensitive calls to the configured Ethereum JSON-RPC endpoint.
|
// non-sensitive calls to the configured Ethereum JSON-RPC endpoint.
|
||||||
|
|
||||||
|
const { DEFAULT_RPC_URL } = require("../shared/constants");
|
||||||
|
const { SUPPORTED_CHAIN_IDS, networkByChainId } = require("../shared/networks");
|
||||||
|
const { onChainSwitch } = require("../shared/chainSwitch");
|
||||||
const {
|
const {
|
||||||
ETHEREUM_MAINNET_CHAIN_ID,
|
state,
|
||||||
DEFAULT_RPC_URL,
|
loadState,
|
||||||
} = require("../shared/constants");
|
saveState,
|
||||||
const { getBytes } = require("ethers");
|
currentNetwork,
|
||||||
const { state, loadState, saveState } = require("../shared/state");
|
} = require("../shared/state");
|
||||||
const { refreshBalances, getProvider } = require("../shared/balances");
|
const { refreshBalances, getProvider } = require("../shared/balances");
|
||||||
const { debugFetch } = require("../shared/log");
|
const { debugFetch, log } = require("../shared/log");
|
||||||
const { decryptWithPassword } = require("../shared/vault");
|
const {
|
||||||
const { getSignerForAddress } = require("../shared/wallet");
|
verifySignedTx,
|
||||||
|
verifySignature,
|
||||||
|
failureIsRetryable,
|
||||||
|
describeTxFailure,
|
||||||
|
TX_STAGE_SIGN,
|
||||||
|
TX_STAGE_VERIFY,
|
||||||
|
TX_STAGE_BROADCAST,
|
||||||
|
TX_STAGE_INFLIGHT,
|
||||||
|
} = require("../shared/approvalVerify");
|
||||||
|
const {
|
||||||
|
isPhishingDomain,
|
||||||
|
refreshPhishingListOnSchedule,
|
||||||
|
initPhishingList,
|
||||||
|
} = require("../shared/phishingDomains");
|
||||||
|
const {
|
||||||
|
BALANCE_REFRESH_ALARM,
|
||||||
|
PHISHING_REFRESH_ALARM,
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES,
|
||||||
|
ensureRecurringAlarms,
|
||||||
|
registerAlarmHandlers,
|
||||||
|
} = require("../shared/alarms");
|
||||||
|
|
||||||
const storageApi =
|
const storageApi =
|
||||||
typeof browser !== "undefined"
|
typeof browser !== "undefined"
|
||||||
@@ -93,6 +116,55 @@ function resetPopupUrl() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Settle a pending approval: hand `result` to the promise the requesting page
|
||||||
|
// is waiting on and retire the approval. This is the ONLY place an approval is
|
||||||
|
// resolved or removed — the popup closing, an active-address switch, a reject
|
||||||
|
// from the popup and the attempt that signs and broadcasts all come through
|
||||||
|
// here — because a settlement that bypasses the claim below is a fund-loss bug
|
||||||
|
// and enumerating the call sites has repeatedly missed one.
|
||||||
|
//
|
||||||
|
// A claimed approval belongs to the attempt holding the claim, and only that
|
||||||
|
// attempt may settle it. Anything else settling first would leave the attempt
|
||||||
|
// running to completion against an already-settled promise: the transaction
|
||||||
|
// reaches the chain while the page is told "User rejected the request", and the
|
||||||
|
// user's natural response is to send it again at a fresh nonce.
|
||||||
|
//
|
||||||
|
// Returns false when the approval is gone or claimed by someone else, so the
|
||||||
|
// caller can refuse instead of assuming it settled.
|
||||||
|
function settleApproval(id, result, options) {
|
||||||
|
const approval = pendingApprovals[id];
|
||||||
|
if (!approval) return false;
|
||||||
|
const holdsClaim = !!(options && options.holdsClaim);
|
||||||
|
if (approval.attemptInFlight && !holdsClaim) return false;
|
||||||
|
delete pendingApprovals[id];
|
||||||
|
approval.resolve(result);
|
||||||
|
resetPopupUrl();
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Take exclusive hold of a pending approval for one attempt, or refuse.
|
||||||
|
//
|
||||||
|
// An approval that failed retryably has to stay in pendingApprovals, so its
|
||||||
|
// presence cannot be the interlock against a second attempt; this flag is. It
|
||||||
|
// is set synchronously, before the handler's first await, so a second response
|
||||||
|
// carrying the same id — a reloaded approval window re-rendering a live
|
||||||
|
// Approve button, a popup that emits the message twice — finds the attempt
|
||||||
|
// already running instead of starting an independent verify and broadcast.
|
||||||
|
// Without it one approval can put two transactions on the chain: with the
|
||||||
|
// ordinary dApp approval shape the page fixes no nonce, so two artifacts
|
||||||
|
// signed at different nonces both verify.
|
||||||
|
function claimApproval(approval) {
|
||||||
|
if (approval.attemptInFlight) return false;
|
||||||
|
approval.attemptInFlight = true;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Release an approval whose attempt failed in a way the user can retry.
|
||||||
|
// Nothing was broadcast, so the next attempt may claim it.
|
||||||
|
function releaseApproval(approval) {
|
||||||
|
approval.attemptInFlight = false;
|
||||||
|
}
|
||||||
|
|
||||||
// Open approval in a separate popup window.
|
// Open approval in a separate popup window.
|
||||||
// This is the primary mechanism for tx/sign approvals (triggered programmatically,
|
// This is the primary mechanism for tx/sign approvals (triggered programmatically,
|
||||||
// not from a user gesture) and the fallback for site-connection approvals.
|
// not from a user gesture) and the fallback for site-connection approvals.
|
||||||
@@ -201,8 +273,7 @@ runtime.onConnect.addListener((port) => {
|
|||||||
// Keep pending — user can reopen the toolbar popup
|
// Keep pending — user can reopen the toolbar popup
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
approval.resolve({ approved: false, remember: false });
|
settleApproval(id, { approved: false, remember: false });
|
||||||
delete pendingApprovals[id];
|
|
||||||
}
|
}
|
||||||
resetPopupUrl();
|
resetPopupUrl();
|
||||||
});
|
});
|
||||||
@@ -324,31 +395,43 @@ async function handleRpc(method, params, origin) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (method === "eth_chainId") {
|
if (method === "eth_chainId") {
|
||||||
return { result: ETHEREUM_MAINNET_CHAIN_ID };
|
return { result: currentNetwork().chainId };
|
||||||
}
|
}
|
||||||
|
|
||||||
if (method === "net_version") {
|
if (method === "net_version") {
|
||||||
return { result: "1" };
|
return { result: currentNetwork().networkVersion };
|
||||||
}
|
}
|
||||||
|
|
||||||
if (method === "wallet_switchEthereumChain") {
|
if (method === "wallet_switchEthereumChain") {
|
||||||
const chainId = params?.[0]?.chainId;
|
const chainId = params?.[0]?.chainId;
|
||||||
if (chainId === ETHEREUM_MAINNET_CHAIN_ID) {
|
if (chainId === currentNetwork().chainId) {
|
||||||
|
return { result: null };
|
||||||
|
}
|
||||||
|
if (SUPPORTED_CHAIN_IDS.has(chainId)) {
|
||||||
|
const target = networkByChainId(chainId);
|
||||||
|
await onChainSwitch(target.id);
|
||||||
|
broadcastChainChanged(target.chainId);
|
||||||
return { result: null };
|
return { result: null };
|
||||||
}
|
}
|
||||||
return {
|
return {
|
||||||
error: {
|
error: {
|
||||||
code: 4902,
|
code: 4902,
|
||||||
message: "AutistMask only supports Ethereum mainnet.",
|
message:
|
||||||
|
"AutistMask supports Ethereum Mainnet and Sepolia Testnet only.",
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
if (method === "wallet_addEthereumChain") {
|
if (method === "wallet_addEthereumChain") {
|
||||||
|
const chainId = params?.[0]?.chainId;
|
||||||
|
if (SUPPORTED_CHAIN_IDS.has(chainId)) {
|
||||||
|
return { result: null };
|
||||||
|
}
|
||||||
return {
|
return {
|
||||||
error: {
|
error: {
|
||||||
code: 4902,
|
code: 4902,
|
||||||
message: "AutistMask only supports Ethereum mainnet.",
|
message:
|
||||||
|
"AutistMask supports Ethereum Mainnet and Sepolia Testnet only.",
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -494,21 +577,48 @@ async function handleRpc(method, params, origin) {
|
|||||||
return { error: { message: "Unsupported method: " + method } };
|
return { error: { message: "Unsupported method: " + method } };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Broadcast chainChanged to all tabs when the network is switched.
|
||||||
|
function broadcastChainChanged(chainId) {
|
||||||
|
tabsApi.query({}, (tabs) => {
|
||||||
|
for (const tab of tabs) {
|
||||||
|
tabsApi.sendMessage(
|
||||||
|
tab.id,
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_EVENT",
|
||||||
|
eventName: "chainChanged",
|
||||||
|
data: chainId,
|
||||||
|
},
|
||||||
|
() => {
|
||||||
|
if (runtime.lastError) {
|
||||||
|
// expected for tabs without our content script
|
||||||
|
}
|
||||||
|
},
|
||||||
|
);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Broadcast accountsChanged to all tabs, respecting per-address permissions
|
// Broadcast accountsChanged to all tabs, respecting per-address permissions
|
||||||
async function broadcastAccountsChanged() {
|
async function broadcastAccountsChanged() {
|
||||||
// Clear non-remembered approvals on address switch
|
// Clear non-remembered approvals on address switch
|
||||||
for (const key of Object.keys(connectedSites)) {
|
for (const key of Object.keys(connectedSites)) {
|
||||||
delete connectedSites[key];
|
delete connectedSites[key];
|
||||||
}
|
}
|
||||||
// Reject and close any pending approval popups so they don't hang
|
// Reject and close any pending approval popups so they don't hang. An
|
||||||
|
// approval an attempt has already claimed is left alone entirely: it is
|
||||||
|
// being signed and broadcast right now, and neither rejecting it to the
|
||||||
|
// page nor closing the window it is reporting into is survivable.
|
||||||
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
||||||
if (approval.type === "tx" || approval.type === "sign") {
|
const rejection =
|
||||||
approval.resolve({
|
approval.type === "tx" || approval.type === "sign"
|
||||||
error: { code: 4001, message: "User rejected the request." },
|
? {
|
||||||
});
|
error: {
|
||||||
} else {
|
code: 4001,
|
||||||
approval.resolve({ approved: false, remember: false });
|
message: "User rejected the request.",
|
||||||
}
|
},
|
||||||
|
}
|
||||||
|
: { approved: false, remember: false };
|
||||||
|
if (!settleApproval(id, rejection)) continue;
|
||||||
if (approval.windowId) {
|
if (approval.windowId) {
|
||||||
windowsApi.remove(approval.windowId, () => {
|
windowsApi.remove(approval.windowId, () => {
|
||||||
if (runtime.lastError) {
|
if (runtime.lastError) {
|
||||||
@@ -516,7 +626,6 @@ async function broadcastAccountsChanged() {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
delete pendingApprovals[id];
|
|
||||||
}
|
}
|
||||||
resetPopupUrl();
|
resetPopupUrl();
|
||||||
const s = await getState();
|
const s = await getState();
|
||||||
@@ -551,12 +660,22 @@ async function broadcastAccountsChanged() {
|
|||||||
// Background balance refresh: every 60 seconds when the popup isn't open.
|
// Background balance refresh: every 60 seconds when the popup isn't open.
|
||||||
// When the popup IS open, its 10-second interval keeps lastBalanceRefresh
|
// When the popup IS open, its 10-second interval keeps lastBalanceRefresh
|
||||||
// fresh, so this naturally skips.
|
// fresh, so this naturally skips.
|
||||||
const BACKGROUND_REFRESH_INTERVAL = 60000;
|
//
|
||||||
|
// The alarm period alone sets the cadence; this guard only suppresses a
|
||||||
|
// refresh something else has just done, so it must stay strictly shorter than
|
||||||
|
// the period. Timed to the period it would veto every tick it gates —
|
||||||
|
// lastBalanceRefresh is stamped after the refresh runs, so a tick one period
|
||||||
|
// after the last one always lands inside a guard of equal length and the real
|
||||||
|
// cadence becomes two periods. Half the period keeps it comfortably above the
|
||||||
|
// popup's 10-second refresh, so an open popup still suppresses the background
|
||||||
|
// job, and comfortably below the alarm period, so the schedule always wins.
|
||||||
|
const BALANCE_REFRESH_PERIOD_MS = BALANCE_REFRESH_PERIOD_MINUTES * 60 * 1000;
|
||||||
|
const RECENT_BALANCE_REFRESH_MS = Math.floor(BALANCE_REFRESH_PERIOD_MS / 2);
|
||||||
|
|
||||||
async function backgroundRefresh() {
|
async function backgroundRefresh() {
|
||||||
await loadState();
|
await loadState();
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
if (now - (state.lastBalanceRefresh || 0) < BACKGROUND_REFRESH_INTERVAL)
|
if (now - (state.lastBalanceRefresh || 0) < RECENT_BALANCE_REFRESH_MS)
|
||||||
return;
|
return;
|
||||||
if (state.wallets.length === 0) return;
|
if (state.wallets.length === 0) return;
|
||||||
await refreshBalances(
|
await refreshBalances(
|
||||||
@@ -569,25 +688,79 @@ async function backgroundRefresh() {
|
|||||||
await saveState();
|
await saveState();
|
||||||
}
|
}
|
||||||
|
|
||||||
setInterval(backgroundRefresh, BACKGROUND_REFRESH_INTERVAL);
|
// Both recurring jobs run off alarms, not timers. On Chrome MV3 this file is
|
||||||
|
// a service worker that the browser terminates after about 30 seconds idle,
|
||||||
|
// so a setInterval would only ever survive until the first idle period and
|
||||||
|
// module-level state does not outlive it. Alarms are held by the browser and
|
||||||
|
// wake the worker to deliver them.
|
||||||
|
registerAlarmHandlers({
|
||||||
|
[BALANCE_REFRESH_ALARM]: backgroundRefresh,
|
||||||
|
// The scheduled refresh, which restores persisted state on a freshly
|
||||||
|
// revived worker and then fetches unconditionally. The freshness guards
|
||||||
|
// belong to the startup path; applying them here would make the tick skip
|
||||||
|
// itself.
|
||||||
|
[PHISHING_REFRESH_ALARM]: refreshPhishingListOnSchedule,
|
||||||
|
});
|
||||||
|
|
||||||
// When approval window is closed without a response, treat as rejection
|
// Everything the background context needs re-established on start. This runs
|
||||||
|
// on a fresh install, on browser startup, and on every revival of a
|
||||||
|
// terminated worker, so it must be idempotent: ensureRecurringAlarms() only
|
||||||
|
// creates alarms that are missing or carrying a stale period, and
|
||||||
|
// initPhishingList() fetches only when the persisted timestamps say the list
|
||||||
|
// is stale.
|
||||||
|
//
|
||||||
|
// On a fresh install the top-level call and the onInstalled listener both run,
|
||||||
|
// close enough together that both could see an alarm missing and create it.
|
||||||
|
// Sharing one in-flight run makes the "create only when missing" check
|
||||||
|
// race-free; the memo is dropped once it settles so a later onStartup runs
|
||||||
|
// again.
|
||||||
|
let backgroundJobsRun = null;
|
||||||
|
|
||||||
|
function startBackgroundJobs() {
|
||||||
|
if (backgroundJobsRun) return backgroundJobsRun;
|
||||||
|
backgroundJobsRun = Promise.all([
|
||||||
|
ensureRecurringAlarms(),
|
||||||
|
initPhishingList(),
|
||||||
|
])
|
||||||
|
.catch((err) => {
|
||||||
|
// An alarm that failed to schedule means a recurring job silently
|
||||||
|
// never runs again; it must not be an unhandled rejection.
|
||||||
|
log.errorf("background job startup failed:", err);
|
||||||
|
})
|
||||||
|
.finally(() => {
|
||||||
|
backgroundJobsRun = null;
|
||||||
|
});
|
||||||
|
return backgroundJobsRun;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (runtime.onInstalled) {
|
||||||
|
runtime.onInstalled.addListener(startBackgroundJobs);
|
||||||
|
}
|
||||||
|
if (runtime.onStartup) {
|
||||||
|
runtime.onStartup.addListener(startBackgroundJobs);
|
||||||
|
}
|
||||||
|
startBackgroundJobs();
|
||||||
|
|
||||||
|
// When approval window is closed without a response, treat as rejection.
|
||||||
|
// "Without a response" is the operative part: the popup stays open across the
|
||||||
|
// verify and broadcast it is waiting on, so a user closing an apparently-hung
|
||||||
|
// window is an ordinary event with an attempt already in flight behind it.
|
||||||
|
// settleApproval() refuses those, which leaves the attempt to report its real
|
||||||
|
// outcome to the page.
|
||||||
if (windowsApi && windowsApi.onRemoved) {
|
if (windowsApi && windowsApi.onRemoved) {
|
||||||
windowsApi.onRemoved.addListener((windowId) => {
|
windowsApi.onRemoved.addListener((windowId) => {
|
||||||
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
||||||
if (approval.windowId === windowId) {
|
if (approval.windowId !== windowId) continue;
|
||||||
if (approval.type === "tx" || approval.type === "sign") {
|
const rejection =
|
||||||
approval.resolve({
|
approval.type === "tx" || approval.type === "sign"
|
||||||
error: {
|
? {
|
||||||
code: 4001,
|
error: {
|
||||||
message: "User rejected the request.",
|
code: 4001,
|
||||||
},
|
message: "User rejected the request.",
|
||||||
});
|
},
|
||||||
} else {
|
}
|
||||||
approval.resolve({ approved: false, remember: false });
|
: { approved: false, remember: false };
|
||||||
}
|
settleApproval(id, rejection);
|
||||||
delete pendingApprovals[id];
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -643,6 +816,8 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
resp.type = "sign";
|
resp.type = "sign";
|
||||||
resp.signParams = approval.signParams;
|
resp.signParams = approval.signParams;
|
||||||
}
|
}
|
||||||
|
// Flag if the requesting domain is on the phishing blocklist.
|
||||||
|
resp.isPhishingDomain = isPhishingDomain(approval.hostname);
|
||||||
sendResponse(resp);
|
sendResponse(resp);
|
||||||
} else {
|
} else {
|
||||||
sendResponse(null);
|
sendResponse(null);
|
||||||
@@ -651,14 +826,10 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (msg.type === "AUTISTMASK_APPROVAL_RESPONSE") {
|
if (msg.type === "AUTISTMASK_APPROVAL_RESPONSE") {
|
||||||
const approval = pendingApprovals[msg.id];
|
settleApproval(msg.id, {
|
||||||
if (approval) {
|
approved: msg.approved,
|
||||||
approval.resolve({
|
remember: msg.remember,
|
||||||
approved: msg.approved,
|
});
|
||||||
remember: msg.remember,
|
|
||||||
});
|
|
||||||
delete pendingApprovals[msg.id];
|
|
||||||
}
|
|
||||||
resetPopupUrl();
|
resetPopupUrl();
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
@@ -666,57 +837,116 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
if (msg.type === "AUTISTMASK_TX_RESPONSE") {
|
if (msg.type === "AUTISTMASK_TX_RESPONSE") {
|
||||||
const approval = pendingApprovals[msg.id];
|
const approval = pendingApprovals[msg.id];
|
||||||
if (!approval) return false;
|
if (!approval) return false;
|
||||||
delete pendingApprovals[msg.id];
|
|
||||||
resetPopupUrl();
|
|
||||||
|
|
||||||
|
// A reject arriving while an attempt holds the approval is refused,
|
||||||
|
// not honoured: the attempt is on its way to broadcasting the
|
||||||
|
// transaction, and resolving 4001 here would tell the page the request
|
||||||
|
// was rejected while it goes out.
|
||||||
if (!msg.approved) {
|
if (!msg.approved) {
|
||||||
approval.resolve({
|
if (
|
||||||
error: { code: 4001, message: "User rejected the request." },
|
!settleApproval(msg.id, {
|
||||||
});
|
error: {
|
||||||
|
code: 4001,
|
||||||
|
message: "User rejected the request.",
|
||||||
|
},
|
||||||
|
})
|
||||||
|
) {
|
||||||
|
sendResponse({
|
||||||
|
error: "This transaction is already being sent.",
|
||||||
|
retryable: false,
|
||||||
|
stage: TX_STAGE_BROADCAST,
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The popup signs; it reports back here when it could not. Keep the
|
||||||
|
// approval so the user can correct the problem and try again with the
|
||||||
|
// transaction they already saw.
|
||||||
|
if (msg.error) {
|
||||||
|
const outcome = describeTxFailure(TX_STAGE_SIGN, msg.error);
|
||||||
|
sendResponse({
|
||||||
|
error: outcome.error,
|
||||||
|
retryable: outcome.retryable,
|
||||||
|
stage: TX_STAGE_SIGN,
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Exactly one broadcast per approval, whatever the popup sends.
|
||||||
|
if (!claimApproval(approval)) {
|
||||||
|
sendResponse({
|
||||||
|
error: "This transaction is already being sent.",
|
||||||
|
retryable: false,
|
||||||
|
stage: TX_STAGE_BROADCAST,
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
(async () => {
|
(async () => {
|
||||||
try {
|
try {
|
||||||
await loadState();
|
await loadState();
|
||||||
const activeAddress = await getActiveAddress();
|
const activeAddress = await getActiveAddress();
|
||||||
let wallet, addrIndex;
|
// The popup holds the secret, but the background stays the
|
||||||
for (const w of state.wallets) {
|
// authority on what is broadcast: the raw transaction must be
|
||||||
for (let i = 0; i < w.addresses.length; i++) {
|
// the approved one, signed by the approved address, on the
|
||||||
if (w.addresses[i].address === activeAddress) {
|
// network that is selected.
|
||||||
wallet = w;
|
verifySignedTx(
|
||||||
addrIndex = i;
|
msg.rawSignedTx,
|
||||||
break;
|
approval.txParams,
|
||||||
}
|
activeAddress,
|
||||||
}
|
currentNetwork().chainId,
|
||||||
if (wallet) break;
|
);
|
||||||
|
} catch (e) {
|
||||||
|
// A signed transaction that is not the approved one is not
|
||||||
|
// retried against that approval; it is refused outright.
|
||||||
|
// Anything else that failed before the check ran is the
|
||||||
|
// user's to retry.
|
||||||
|
const outcome = describeTxFailure(TX_STAGE_VERIFY, e);
|
||||||
|
if (outcome.spendApproval) {
|
||||||
|
settleApproval(
|
||||||
|
msg.id,
|
||||||
|
{ error: { message: outcome.error } },
|
||||||
|
{ holdsClaim: true },
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
releaseApproval(approval);
|
||||||
}
|
}
|
||||||
if (!wallet) throw new Error("Wallet not found");
|
sendResponse({
|
||||||
// TODO(security): Move decryption to popup to avoid sending password via runtime.sendMessage
|
error: outcome.error,
|
||||||
let decrypted = await decryptWithPassword(
|
retryable: outcome.retryable,
|
||||||
wallet.encryptedSecret,
|
stage: TX_STAGE_VERIFY,
|
||||||
msg.password,
|
});
|
||||||
);
|
return;
|
||||||
const signer = getSignerForAddress(
|
}
|
||||||
wallet,
|
|
||||||
addrIndex,
|
try {
|
||||||
decrypted,
|
|
||||||
);
|
|
||||||
// Best-effort: clear decrypted secret after use.
|
|
||||||
// Note: JS strings are immutable; this nulls the reference but
|
|
||||||
// the original string may persist in memory until GC.
|
|
||||||
decrypted = null;
|
|
||||||
const provider = getProvider(state.rpcUrl);
|
const provider = getProvider(state.rpcUrl);
|
||||||
const connected = signer.connect(provider);
|
const tx = await provider.broadcastTransaction(msg.rawSignedTx);
|
||||||
const tx = await connected.sendTransaction(approval.txParams);
|
settleApproval(
|
||||||
approval.resolve({ txHash: tx.hash });
|
msg.id,
|
||||||
|
{ txHash: tx.hash },
|
||||||
|
{ holdsClaim: true },
|
||||||
|
);
|
||||||
sendResponse({ txHash: tx.hash });
|
sendResponse({ txHash: tx.hash });
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
const errMsg = e.shortMessage || e.message;
|
// Terminal, never retried: the node may have accepted the
|
||||||
approval.resolve({
|
// transaction and still failed to answer, and the popup's
|
||||||
error: { message: errMsg },
|
// retry re-signs at a freshly fetched nonce rather than
|
||||||
|
// re-broadcasting these bytes. Retrying would send the
|
||||||
|
// approved transfer a second time.
|
||||||
|
const outcome = describeTxFailure(TX_STAGE_BROADCAST, e);
|
||||||
|
settleApproval(
|
||||||
|
msg.id,
|
||||||
|
{ error: { message: outcome.error } },
|
||||||
|
{ holdsClaim: true },
|
||||||
|
);
|
||||||
|
sendResponse({
|
||||||
|
error: outcome.error,
|
||||||
|
retryable: outcome.retryable,
|
||||||
|
stage: TX_STAGE_BROADCAST,
|
||||||
});
|
});
|
||||||
sendResponse({ error: errMsg });
|
|
||||||
}
|
}
|
||||||
})();
|
})();
|
||||||
return true;
|
return true;
|
||||||
@@ -725,73 +955,70 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
|||||||
if (msg.type === "AUTISTMASK_SIGN_RESPONSE") {
|
if (msg.type === "AUTISTMASK_SIGN_RESPONSE") {
|
||||||
const approval = pendingApprovals[msg.id];
|
const approval = pendingApprovals[msg.id];
|
||||||
if (!approval) return false;
|
if (!approval) return false;
|
||||||
delete pendingApprovals[msg.id];
|
|
||||||
resetPopupUrl();
|
|
||||||
|
|
||||||
|
// Same as the transaction path: a reject cannot retire an approval an
|
||||||
|
// attempt already holds.
|
||||||
if (!msg.approved) {
|
if (!msg.approved) {
|
||||||
approval.resolve({
|
if (
|
||||||
error: { code: 4001, message: "User rejected the request." },
|
!settleApproval(msg.id, {
|
||||||
});
|
error: {
|
||||||
|
code: 4001,
|
||||||
|
message: "User rejected the request.",
|
||||||
|
},
|
||||||
|
})
|
||||||
|
) {
|
||||||
|
sendResponse({
|
||||||
|
error: "This request is already being signed.",
|
||||||
|
retryable: false,
|
||||||
|
stage: TX_STAGE_INFLIGHT,
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The popup signs; it reports back here when it could not. Keep the
|
||||||
|
// approval so the user can correct the problem and try again with the
|
||||||
|
// message they already saw.
|
||||||
|
if (msg.error) {
|
||||||
|
sendResponse({ error: msg.error, retryable: true });
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Exactly one signature handed back per approval.
|
||||||
|
if (!claimApproval(approval)) {
|
||||||
|
sendResponse({
|
||||||
|
error: "This request is already being signed.",
|
||||||
|
retryable: false,
|
||||||
|
stage: TX_STAGE_INFLIGHT,
|
||||||
|
});
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
(async () => {
|
(async () => {
|
||||||
try {
|
try {
|
||||||
await loadState();
|
|
||||||
const activeAddress = await getActiveAddress();
|
const activeAddress = await getActiveAddress();
|
||||||
let wallet, addrIndex;
|
// The popup holds the secret, but the background stays the
|
||||||
for (const w of state.wallets) {
|
// authority on what is handed back to the page: the signature
|
||||||
for (let i = 0; i < w.addresses.length; i++) {
|
// must cover the approved payload and recover to the approved
|
||||||
if (w.addresses[i].address === activeAddress) {
|
// address.
|
||||||
wallet = w;
|
const signature = msg.signature;
|
||||||
addrIndex = i;
|
verifySignature(approval.signParams, signature, activeAddress);
|
||||||
break;
|
settleApproval(msg.id, { signature }, { holdsClaim: true });
|
||||||
}
|
|
||||||
}
|
|
||||||
if (wallet) break;
|
|
||||||
}
|
|
||||||
if (!wallet) throw new Error("Wallet not found");
|
|
||||||
// TODO(security): Move decryption to popup to avoid sending password via runtime.sendMessage
|
|
||||||
let decrypted = await decryptWithPassword(
|
|
||||||
wallet.encryptedSecret,
|
|
||||||
msg.password,
|
|
||||||
);
|
|
||||||
const signer = getSignerForAddress(
|
|
||||||
wallet,
|
|
||||||
addrIndex,
|
|
||||||
decrypted,
|
|
||||||
);
|
|
||||||
// Best-effort: clear decrypted secret after use.
|
|
||||||
// Note: JS strings are immutable; this nulls the reference but
|
|
||||||
// the original string may persist in memory until GC.
|
|
||||||
decrypted = null;
|
|
||||||
|
|
||||||
const sp = approval.signParams;
|
|
||||||
let signature;
|
|
||||||
|
|
||||||
if (sp.method === "personal_sign" || sp.method === "eth_sign") {
|
|
||||||
signature = await signer.signMessage(getBytes(sp.message));
|
|
||||||
} else {
|
|
||||||
// eth_signTypedData_v4 / eth_signTypedData
|
|
||||||
const typedData = JSON.parse(sp.typedData);
|
|
||||||
const { domain, types, message } = typedData;
|
|
||||||
// ethers handles EIP712Domain internally
|
|
||||||
delete types.EIP712Domain;
|
|
||||||
signature = await signer.signTypedData(
|
|
||||||
domain,
|
|
||||||
types,
|
|
||||||
message,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
approval.resolve({ signature });
|
|
||||||
sendResponse({ signature });
|
sendResponse({ signature });
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
const errMsg = e.shortMessage || e.message;
|
const errMsg = e.shortMessage || e.message;
|
||||||
approval.resolve({
|
const retryable = failureIsRetryable(e);
|
||||||
error: { message: errMsg },
|
if (!retryable) {
|
||||||
});
|
settleApproval(
|
||||||
sendResponse({ error: errMsg });
|
msg.id,
|
||||||
|
{ error: { message: errMsg } },
|
||||||
|
{ holdsClaim: true },
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
releaseApproval(approval);
|
||||||
|
}
|
||||||
|
sendResponse({ error: errMsg, retryable });
|
||||||
}
|
}
|
||||||
})();
|
})();
|
||||||
return true;
|
return true;
|
||||||
|
|||||||
@@ -2,7 +2,10 @@
|
|||||||
// Creates window.ethereum (EIP-1193 provider) and announces via EIP-6963.
|
// Creates window.ethereum (EIP-1193 provider) and announces via EIP-6963.
|
||||||
|
|
||||||
(function () {
|
(function () {
|
||||||
const CHAIN_ID = "0x1"; // Ethereum mainnet
|
// Defaults to mainnet; updated dynamically via eth_chainId on init and
|
||||||
|
// chainChanged events from the extension.
|
||||||
|
let currentChainId = "0x1";
|
||||||
|
let currentNetworkVersion = "1";
|
||||||
|
|
||||||
const listeners = {};
|
const listeners = {};
|
||||||
let nextId = 1;
|
let nextId = 1;
|
||||||
@@ -28,6 +31,12 @@
|
|||||||
if (event.source !== window) return;
|
if (event.source !== window) return;
|
||||||
if (event.data?.type !== "AUTISTMASK_EVENT") return;
|
if (event.data?.type !== "AUTISTMASK_EVENT") return;
|
||||||
const { eventName, data } = event.data;
|
const { eventName, data } = event.data;
|
||||||
|
if (eventName === "chainChanged") {
|
||||||
|
currentChainId = data;
|
||||||
|
currentNetworkVersion = String(parseInt(data, 16));
|
||||||
|
provider.chainId = currentChainId;
|
||||||
|
provider.networkVersion = currentNetworkVersion;
|
||||||
|
}
|
||||||
emit(eventName, data);
|
emit(eventName, data);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -57,8 +66,8 @@
|
|||||||
const provider = {
|
const provider = {
|
||||||
isAutistMask: true,
|
isAutistMask: true,
|
||||||
isMetaMask: true, // compatibility — many dApps check this
|
isMetaMask: true, // compatibility — many dApps check this
|
||||||
chainId: CHAIN_ID,
|
chainId: currentChainId,
|
||||||
networkVersion: "1",
|
networkVersion: currentNetworkVersion,
|
||||||
selectedAddress: null,
|
selectedAddress: null,
|
||||||
|
|
||||||
async request(args) {
|
async request(args) {
|
||||||
@@ -75,6 +84,12 @@
|
|||||||
? result[0]
|
? result[0]
|
||||||
: null;
|
: null;
|
||||||
}
|
}
|
||||||
|
if (args.method === "eth_chainId" && result) {
|
||||||
|
currentChainId = result;
|
||||||
|
currentNetworkVersion = String(parseInt(result, 16));
|
||||||
|
provider.chainId = currentChainId;
|
||||||
|
provider.networkVersion = currentNetworkVersion;
|
||||||
|
}
|
||||||
return result;
|
return result;
|
||||||
},
|
},
|
||||||
|
|
||||||
@@ -189,4 +204,19 @@
|
|||||||
|
|
||||||
window.addEventListener("eip6963:requestProvider", announceProvider);
|
window.addEventListener("eip6963:requestProvider", announceProvider);
|
||||||
announceProvider();
|
announceProvider();
|
||||||
|
|
||||||
|
// Fetch the current chain ID from the extension on load so the provider
|
||||||
|
// reflects the selected network immediately (covers Sepolia etc.).
|
||||||
|
sendRequest({ method: "eth_chainId", params: [] })
|
||||||
|
.then((chainId) => {
|
||||||
|
if (chainId) {
|
||||||
|
currentChainId = chainId;
|
||||||
|
currentNetworkVersion = String(parseInt(chainId, 16));
|
||||||
|
provider.chainId = currentChainId;
|
||||||
|
provider.networkVersion = currentNetworkVersion;
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.catch(() => {
|
||||||
|
// Best-effort — keep defaults.
|
||||||
|
});
|
||||||
})();
|
})();
|
||||||
|
|||||||
42
src/popup/dustThreshold.js
Normal file
42
src/popup/dustThreshold.js
Normal file
@@ -0,0 +1,42 @@
|
|||||||
|
// Parsing for the dust threshold field in Settings.
|
||||||
|
//
|
||||||
|
// Pure: no DOM, no state, so the accepted set can be unit tested directly
|
||||||
|
// instead of through the settings view.
|
||||||
|
//
|
||||||
|
// Accepted input is plain decimal digits only, meaning a whole number of
|
||||||
|
// gwei, zero or greater. Zero is a real setting: it hides nothing.
|
||||||
|
//
|
||||||
|
// Deliberately rejected, not coerced:
|
||||||
|
// "" nothing to save
|
||||||
|
// "-1" a negative threshold has no meaning
|
||||||
|
// "1.5" fractional gwei is not a threshold the filter can use
|
||||||
|
// "100 gwei" the unit is already printed beside the field
|
||||||
|
// "0x10" hex, which Number() would silently read as 16
|
||||||
|
// "1e3" exponent notation, which Number() would silently read as 1000
|
||||||
|
//
|
||||||
|
// The last two are the reason this is a digit test and not a Number() test.
|
||||||
|
// Number() accepts both, and accepting them would put a number in the field
|
||||||
|
// that the user did not type — the same silent substitution the visible
|
||||||
|
// rejection message exists to end.
|
||||||
|
|
||||||
|
// Must render on ONE line of #flash-msg, whose reserved height
|
||||||
|
// (min-h-[1.25rem]) is exactly one line at text-xs. A string long enough to
|
||||||
|
// wrap to two lines pushes the settings view down, which the No Layout Shift
|
||||||
|
// policy forbids. Do not lengthen this without re-running the layout test in
|
||||||
|
// tests/e2e/run.js, which measures the flash line and goes red on a shift.
|
||||||
|
const DUST_THRESHOLD_MESSAGE =
|
||||||
|
"Please enter a whole number of gwei, zero or greater.";
|
||||||
|
|
||||||
|
// Returns the threshold in gwei, or null if the input is not one.
|
||||||
|
function parseDustThresholdGwei(raw) {
|
||||||
|
if (typeof raw !== "string") return null;
|
||||||
|
const trimmed = raw.trim();
|
||||||
|
if (!/^[0-9]+$/.test(trimmed)) return null;
|
||||||
|
const val = Number(trimmed);
|
||||||
|
// A run of digits long enough to exceed Number's exact integer range
|
||||||
|
// would round on the way in, so it is not a threshold we can store.
|
||||||
|
if (!Number.isSafeInteger(val)) return null;
|
||||||
|
return val;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { DUST_THRESHOLD_MESSAGE, parseDustThresholdGwei };
|
||||||
@@ -56,37 +56,107 @@
|
|||||||
< Back
|
< Back
|
||||||
</button>
|
</button>
|
||||||
<h2 class="font-bold mb-2">Add Wallet</h2>
|
<h2 class="font-bold mb-2">Add Wallet</h2>
|
||||||
<p class="mb-2">
|
|
||||||
Enter your 12 or 24 word recovery phrase below, or click the
|
<!-- Mode selector tabs -->
|
||||||
button to roll the die for a new one.
|
<div
|
||||||
</p>
|
class="flex border-b border-border mb-3"
|
||||||
<div class="mb-1 flex justify-end">
|
id="add-wallet-tabs"
|
||||||
|
>
|
||||||
<button
|
<button
|
||||||
id="btn-generate-phrase"
|
id="tab-mnemonic"
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer text-xs"
|
class="px-3 py-1.5 cursor-pointer text-xs font-bold border border-border border-b-bg bg-bg -mb-px"
|
||||||
title="Generate a random recovery phrase"
|
|
||||||
>
|
>
|
||||||
[⚀]
|
From Phrase
|
||||||
|
</button>
|
||||||
|
<button
|
||||||
|
id="tab-privkey"
|
||||||
|
class="px-3 py-1.5 cursor-pointer text-xs text-muted border border-dashed border-border-light border-b-transparent -mb-px hover:bg-fg hover:text-bg"
|
||||||
|
>
|
||||||
|
From Key
|
||||||
|
</button>
|
||||||
|
<button
|
||||||
|
id="tab-xprv"
|
||||||
|
class="px-3 py-1.5 cursor-pointer text-xs text-muted border border-dashed border-border-light border-b-transparent -mb-px hover:bg-fg hover:text-bg"
|
||||||
|
>
|
||||||
|
From xprv
|
||||||
</button>
|
</button>
|
||||||
</div>
|
</div>
|
||||||
<div class="mb-2">
|
|
||||||
<textarea
|
<!-- Mnemonic form section -->
|
||||||
id="wallet-mnemonic"
|
<div id="add-wallet-section-mnemonic">
|
||||||
rows="3"
|
<p class="mb-2">
|
||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg resize-y"
|
Enter your 12 or 24 word recovery phrase below, or click
|
||||||
placeholder="word word word ..."
|
the button to roll the die for a new one.
|
||||||
></textarea>
|
</p>
|
||||||
|
<div class="mb-1 flex justify-end">
|
||||||
|
<button
|
||||||
|
id="btn-generate-phrase"
|
||||||
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer text-xs"
|
||||||
|
title="Generate a random recovery phrase"
|
||||||
|
>
|
||||||
|
[⚀]
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
<div class="mb-2">
|
||||||
|
<textarea
|
||||||
|
id="wallet-mnemonic"
|
||||||
|
rows="3"
|
||||||
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg resize-y"
|
||||||
|
placeholder="word word word ..."
|
||||||
|
></textarea>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="add-wallet-phrase-warning"
|
||||||
|
class="text-xs mb-2 border border-border border-dashed p-2"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
Write these words down and keep them safe. Anyone with
|
||||||
|
them can take your funds; if you lose them, your wallet
|
||||||
|
is gone.
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div
|
|
||||||
id="add-wallet-phrase-warning"
|
<!-- Private key form section -->
|
||||||
class="text-xs mb-2 border border-border border-dashed p-2 hidden"
|
<div id="add-wallet-section-privkey" class="hidden">
|
||||||
>
|
<p class="mb-2">
|
||||||
Write these words down and keep them safe. Anyone with them
|
Paste your private key below. This wallet will have a
|
||||||
can take your funds; if you lose them, your wallet is gone.
|
single address.
|
||||||
|
</p>
|
||||||
|
<div class="mb-2">
|
||||||
|
<input
|
||||||
|
type="password"
|
||||||
|
id="import-private-key"
|
||||||
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||||
|
placeholder="0x..."
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- Extended key (xprv) form section -->
|
||||||
|
<div id="add-wallet-section-xprv" class="hidden">
|
||||||
|
<p class="mb-2">
|
||||||
|
Paste your extended private key (xprv) below. This will
|
||||||
|
import the HD wallet and scan for used addresses. It
|
||||||
|
must be the master key for the wallet; an account-level
|
||||||
|
or child key is not supported.
|
||||||
|
</p>
|
||||||
|
<div class="mb-2">
|
||||||
|
<input
|
||||||
|
type="password"
|
||||||
|
id="import-xprv-key"
|
||||||
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||||
|
placeholder="xprv..."
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- Shared password fields -->
|
||||||
<div class="mb-2" id="add-wallet-password-section">
|
<div class="mb-2" id="add-wallet-password-section">
|
||||||
<label class="block mb-1">Choose a password</label>
|
<label class="block mb-1">Choose a password</label>
|
||||||
<p class="text-xs text-muted mb-1">
|
<p
|
||||||
|
class="text-xs text-muted mb-1"
|
||||||
|
id="add-wallet-password-hint"
|
||||||
|
>
|
||||||
This password encrypts your recovery phrase on this
|
This password encrypts your recovery phrase on this
|
||||||
device. You will need it to send funds.
|
device. You will need it to send funds.
|
||||||
</p>
|
</p>
|
||||||
@@ -107,64 +177,6 @@
|
|||||||
<button
|
<button
|
||||||
id="btn-add-wallet-confirm"
|
id="btn-add-wallet-confirm"
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
>
|
|
||||||
Add
|
|
||||||
</button>
|
|
||||||
<div class="mt-3 text-xs text-muted">
|
|
||||||
Have a private key instead?
|
|
||||||
<button
|
|
||||||
id="btn-add-wallet-import-key"
|
|
||||||
class="underline cursor-pointer bg-transparent border-none text-fg text-xs font-mono p-0"
|
|
||||||
>
|
|
||||||
Import private key
|
|
||||||
</button>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<!-- ============ IMPORT PRIVATE KEY ============ -->
|
|
||||||
<div id="view-import-key" class="view hidden">
|
|
||||||
<button
|
|
||||||
id="btn-import-key-back"
|
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mb-2"
|
|
||||||
>
|
|
||||||
< Back
|
|
||||||
</button>
|
|
||||||
<h2 class="font-bold mb-2">Import Private Key</h2>
|
|
||||||
<p class="mb-2">
|
|
||||||
Paste your private key below. This wallet will have a single
|
|
||||||
address.
|
|
||||||
</p>
|
|
||||||
<div class="mb-2">
|
|
||||||
<input
|
|
||||||
type="password"
|
|
||||||
id="import-private-key"
|
|
||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
|
||||||
placeholder="0x..."
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<div class="mb-2" id="import-key-password-section">
|
|
||||||
<label class="block mb-1">Choose a password</label>
|
|
||||||
<p class="text-xs text-muted mb-1">
|
|
||||||
This password encrypts your private key on this device.
|
|
||||||
You will need it to send funds.
|
|
||||||
</p>
|
|
||||||
<input
|
|
||||||
type="password"
|
|
||||||
id="import-key-password"
|
|
||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<div class="mb-2" id="import-key-password-confirm-section">
|
|
||||||
<label class="block mb-1">Confirm password</label>
|
|
||||||
<input
|
|
||||||
type="password"
|
|
||||||
id="import-key-password-confirm"
|
|
||||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<button
|
|
||||||
id="btn-import-key-confirm"
|
|
||||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
|
||||||
>
|
>
|
||||||
Import
|
Import
|
||||||
</button>
|
</button>
|
||||||
@@ -175,7 +187,7 @@
|
|||||||
<!-- active address headline -->
|
<!-- active address headline -->
|
||||||
<div
|
<div
|
||||||
id="total-value"
|
id="total-value"
|
||||||
class="text-2xl font-bold min-h-[2rem]"
|
class="text-2xl font-bold min-h-[2rem] text-fg"
|
||||||
></div>
|
></div>
|
||||||
<div
|
<div
|
||||||
id="total-value-sub"
|
id="total-value-sub"
|
||||||
@@ -366,7 +378,8 @@
|
|||||||
</p>
|
</p>
|
||||||
<div
|
<div
|
||||||
id="export-privkey-flash"
|
id="export-privkey-flash"
|
||||||
class="text-xs mb-2 hidden"
|
class="text-xs mb-2 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div id="export-privkey-password-section" class="mb-2">
|
<div id="export-privkey-password-section" class="mb-2">
|
||||||
<label class="block mb-1">Password</label>
|
<label class="block mb-1">Password</label>
|
||||||
@@ -570,17 +583,105 @@
|
|||||||
<div class="text-xs text-muted mb-1">Your balance</div>
|
<div class="text-xs text-muted mb-1">Your balance</div>
|
||||||
<div id="confirm-balance" class="text-xs"></div>
|
<div id="confirm-balance" class="text-xs"></div>
|
||||||
</div>
|
</div>
|
||||||
<div id="confirm-fee" class="mb-3 hidden">
|
<div id="confirm-fee" class="mb-3" style="visibility: hidden">
|
||||||
<div class="text-xs text-muted mb-1">
|
<div class="text-xs text-muted mb-1">Network fee</div>
|
||||||
Estimated network fee
|
|
||||||
</div>
|
|
||||||
<div id="confirm-fee-amount" class="text-xs"></div>
|
<div id="confirm-fee-amount" class="text-xs"></div>
|
||||||
|
<!-- Holds its one line of space from the first paint, so
|
||||||
|
the reserve appearing when the estimate lands moves
|
||||||
|
nothing. The placeholder is never seen. -->
|
||||||
|
<div
|
||||||
|
id="confirm-fee-reserve"
|
||||||
|
class="text-xs text-muted"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
reserve pending
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="confirm-warnings"
|
||||||
|
class="mb-2"
|
||||||
|
style="visibility: hidden"
|
||||||
|
></div>
|
||||||
|
<div
|
||||||
|
id="confirm-recipient-warning"
|
||||||
|
class="mb-2"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
<div
|
||||||
|
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||||
|
>
|
||||||
|
WARNING: The recipient address has ZERO transaction
|
||||||
|
history. This may indicate a fresh or unused address.
|
||||||
|
Double-check the address before sending.
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="confirm-contract-warning"
|
||||||
|
class="mb-2"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
<div
|
||||||
|
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||||
|
>
|
||||||
|
WARNING: The recipient is a smart contract. Sending ETH
|
||||||
|
or tokens directly to a contract may result in permanent
|
||||||
|
loss of funds.
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="confirm-burn-warning"
|
||||||
|
class="mb-2"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
<div
|
||||||
|
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||||
|
>
|
||||||
|
WARNING: This is a known null/burn address. Funds sent
|
||||||
|
here are permanently destroyed and cannot be recovered.
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="confirm-etherscan-warning"
|
||||||
|
class="mb-2"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
<div
|
||||||
|
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||||
|
>
|
||||||
|
WARNING: Etherscan has flagged this address as
|
||||||
|
phishing/scam. Do not send funds to this address.
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div id="confirm-warnings" class="mb-2 hidden"></div>
|
|
||||||
<div
|
<div
|
||||||
id="confirm-errors"
|
id="confirm-errors"
|
||||||
class="mb-2 border border-border border-dashed p-2 hidden"
|
class="mb-2 border border-border border-dashed p-2"
|
||||||
|
style="visibility: hidden; min-height: 1.25rem"
|
||||||
></div>
|
></div>
|
||||||
|
<div
|
||||||
|
id="confirm-amount-fee-error"
|
||||||
|
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
Your balance does not cover this amount plus the network
|
||||||
|
fee. Please go back and send a smaller amount.
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="confirm-gas-error"
|
||||||
|
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
You do not have enough ETH to pay the network fee for this
|
||||||
|
transfer. Please add ETH to this address and try again.
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="confirm-fee-unknown-error"
|
||||||
|
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||||
|
style="visibility: hidden"
|
||||||
|
>
|
||||||
|
The network fee could not be estimated, so this transaction
|
||||||
|
cannot be checked against your balance. Please go back and
|
||||||
|
try again.
|
||||||
|
</div>
|
||||||
<div class="mb-2">
|
<div class="mb-2">
|
||||||
<label class="block mb-1 text-xs">Password</label>
|
<label class="block mb-1 text-xs">Password</label>
|
||||||
<input
|
<input
|
||||||
@@ -592,6 +693,7 @@
|
|||||||
<div
|
<div
|
||||||
id="confirm-tx-password-error"
|
id="confirm-tx-password-error"
|
||||||
class="text-xs mb-2 min-h-[1.25rem]"
|
class="text-xs mb-2 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<button
|
<button
|
||||||
id="btn-confirm-send"
|
id="btn-confirm-send"
|
||||||
@@ -706,7 +808,8 @@
|
|||||||
</button>
|
</button>
|
||||||
<div
|
<div
|
||||||
id="receive-erc20-warning"
|
id="receive-erc20-warning"
|
||||||
class="text-xs border border-border border-dashed p-2 mt-3 hidden"
|
class="text-xs border border-border border-dashed p-2 mt-3"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -734,7 +837,8 @@
|
|||||||
</div>
|
</div>
|
||||||
<div
|
<div
|
||||||
id="add-token-info"
|
id="add-token-info"
|
||||||
class="text-xs text-muted mb-2 hidden"
|
class="text-xs text-muted mb-2 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div class="mb-2">
|
<div class="mb-2">
|
||||||
<label class="block mb-1 text-xs text-muted"
|
<label class="block mb-1 text-xs text-muted"
|
||||||
@@ -792,7 +896,7 @@
|
|||||||
<div class="bg-well p-3 mx-1 mb-3">
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
<h3 class="font-bold mb-1">Display</h3>
|
<h3 class="font-bold mb-1">Display</h3>
|
||||||
<label
|
<label
|
||||||
class="text-xs flex items-center gap-1 cursor-pointer"
|
class="text-xs flex items-center gap-1 cursor-pointer mb-2"
|
||||||
>
|
>
|
||||||
<input
|
<input
|
||||||
type="checkbox"
|
type="checkbox"
|
||||||
@@ -800,6 +904,41 @@
|
|||||||
/>
|
/>
|
||||||
Show tracked tokens with zero balance
|
Show tracked tokens with zero balance
|
||||||
</label>
|
</label>
|
||||||
|
<label
|
||||||
|
class="text-xs flex items-center gap-1 cursor-pointer mb-2"
|
||||||
|
>
|
||||||
|
<input type="checkbox" id="settings-utc-timestamps" />
|
||||||
|
UTC Timestamps
|
||||||
|
</label>
|
||||||
|
<div class="text-xs flex items-center gap-1">
|
||||||
|
<label for="settings-theme">Theme:</label>
|
||||||
|
<select
|
||||||
|
id="settings-theme"
|
||||||
|
class="border border-border p-1 bg-bg text-fg text-xs cursor-pointer"
|
||||||
|
>
|
||||||
|
<option value="system">System</option>
|
||||||
|
<option value="light">Light</option>
|
||||||
|
<option value="dark">Dark</option>
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<h3 class="font-bold mb-1">Network</h3>
|
||||||
|
<p class="text-xs text-muted mb-1">
|
||||||
|
Select the Ethereum network. Switching networks will
|
||||||
|
update the RPC and Blockscout endpoints to their
|
||||||
|
defaults.
|
||||||
|
</p>
|
||||||
|
<div class="text-xs flex items-center gap-1">
|
||||||
|
<select
|
||||||
|
id="settings-network"
|
||||||
|
class="border border-border p-1 bg-bg text-fg text-xs cursor-pointer"
|
||||||
|
>
|
||||||
|
<option value="mainnet">Ethereum Mainnet</option>
|
||||||
|
<option value="sepolia">Sepolia Testnet</option>
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="bg-well p-3 mx-1 mb-3">
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
@@ -850,6 +989,15 @@
|
|||||||
transfers and prevent interaction with suspicious
|
transfers and prevent interaction with suspicious
|
||||||
tokens.
|
tokens.
|
||||||
</p>
|
</p>
|
||||||
|
<label
|
||||||
|
class="text-xs flex items-center gap-1 cursor-pointer mb-2"
|
||||||
|
>
|
||||||
|
<input
|
||||||
|
type="checkbox"
|
||||||
|
id="settings-hide-spoofed-symbols"
|
||||||
|
/>
|
||||||
|
Hide fake tokens impersonating a known symbol
|
||||||
|
</label>
|
||||||
<label
|
<label
|
||||||
class="text-xs flex items-center gap-1 cursor-pointer mb-2"
|
class="text-xs flex items-center gap-1 cursor-pointer mb-2"
|
||||||
>
|
>
|
||||||
@@ -898,6 +1046,64 @@
|
|||||||
</p>
|
</p>
|
||||||
<div id="settings-denied-sites"></div>
|
<div id="settings-denied-sites"></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<h3 class="font-bold mb-1">About</h3>
|
||||||
|
<p class="text-xs mb-2">
|
||||||
|
<a
|
||||||
|
href="https://git.eeqj.de/sneak/AutistMask"
|
||||||
|
class="underline decoration-dashed"
|
||||||
|
target="_blank"
|
||||||
|
rel="noopener noreferrer"
|
||||||
|
>AutistMask</a
|
||||||
|
>
|
||||||
|
— Minimal Ethereum wallet browser extension.
|
||||||
|
</p>
|
||||||
|
<div class="text-xs">
|
||||||
|
<div class="mb-1">
|
||||||
|
<span class="text-muted">License:</span>
|
||||||
|
<span id="about-license"></span>
|
||||||
|
</div>
|
||||||
|
<div class="mb-1">
|
||||||
|
<span class="text-muted">Author:</span>
|
||||||
|
<span id="about-author"></span>
|
||||||
|
</div>
|
||||||
|
<div class="mb-1">
|
||||||
|
<span class="text-muted">Version:</span>
|
||||||
|
<span
|
||||||
|
id="about-version"
|
||||||
|
class="cursor-pointer select-none"
|
||||||
|
></span>
|
||||||
|
</div>
|
||||||
|
<div class="mb-1">
|
||||||
|
<span class="text-muted">Release date:</span>
|
||||||
|
<span id="about-release-date"></span>
|
||||||
|
</div>
|
||||||
|
<div>
|
||||||
|
<span class="text-muted">Commit:</span>
|
||||||
|
<a
|
||||||
|
id="about-commit-link"
|
||||||
|
class="underline decoration-dashed"
|
||||||
|
target="_blank"
|
||||||
|
rel="noopener noreferrer"
|
||||||
|
></a>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div
|
||||||
|
id="settings-debug-well"
|
||||||
|
class="bg-well p-3 mx-1 mb-3"
|
||||||
|
style="display: none"
|
||||||
|
>
|
||||||
|
<h3 class="font-bold mb-1">Debug</h3>
|
||||||
|
<label
|
||||||
|
class="text-xs flex items-center gap-1 cursor-pointer"
|
||||||
|
>
|
||||||
|
<input type="checkbox" id="settings-debug-mode" />
|
||||||
|
Enable debug mode
|
||||||
|
</label>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<!-- ============ DELETE WALLET CONFIRM ============ -->
|
<!-- ============ DELETE WALLET CONFIRM ============ -->
|
||||||
@@ -916,7 +1122,8 @@
|
|||||||
</p>
|
</p>
|
||||||
<div
|
<div
|
||||||
id="delete-wallet-flash"
|
id="delete-wallet-flash"
|
||||||
class="text-xs text-red-500 mb-2 hidden"
|
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div class="mb-2">
|
<div class="mb-2">
|
||||||
<label class="block mb-1">Password</label>
|
<label class="block mb-1">Password</label>
|
||||||
@@ -935,6 +1142,108 @@
|
|||||||
</button>
|
</button>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- ============ DELETE ADDRESS CONFIRM ============ -->
|
||||||
|
<div id="view-delete-address-confirm" class="view hidden">
|
||||||
|
<button
|
||||||
|
id="btn-delete-address-back"
|
||||||
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mb-2"
|
||||||
|
>
|
||||||
|
< Back
|
||||||
|
</button>
|
||||||
|
<h2 class="font-bold mb-3">Remove Address</h2>
|
||||||
|
<p class="text-xs mb-2">
|
||||||
|
You are about to remove
|
||||||
|
<strong id="delete-address-label"></strong> from
|
||||||
|
<strong id="delete-address-wallet-name"></strong>.
|
||||||
|
</p>
|
||||||
|
<div
|
||||||
|
id="delete-address-value"
|
||||||
|
class="text-xs mb-2 break-all min-h-[1rem]"
|
||||||
|
></div>
|
||||||
|
<div
|
||||||
|
class="text-xs mb-2 border border-border border-dashed p-2"
|
||||||
|
>
|
||||||
|
This only stops this wallet from tracking the address.
|
||||||
|
Nothing is destroyed and no key is deleted. Any funds at the
|
||||||
|
address stay exactly where they are, and the address remains
|
||||||
|
yours. Any site permissions granted to this address are
|
||||||
|
forgotten.
|
||||||
|
</div>
|
||||||
|
<!-- Filled by src/popup/views/deleteAddress.js: the route
|
||||||
|
back names the wallet's own kind of key material. -->
|
||||||
|
<div
|
||||||
|
id="delete-address-recovery"
|
||||||
|
class="text-xs mb-2 border border-border border-dashed p-2"
|
||||||
|
></div>
|
||||||
|
<div
|
||||||
|
id="delete-address-balance"
|
||||||
|
class="text-xs mb-2 min-h-[1.25rem] pointer-events-none"
|
||||||
|
>
|
||||||
|
|
||||||
|
</div>
|
||||||
|
<p class="text-xs text-muted mb-3">
|
||||||
|
A wallet always keeps at least one address. To remove the
|
||||||
|
last one, delete the whole wallet from Settings instead.
|
||||||
|
</p>
|
||||||
|
<div
|
||||||
|
id="delete-address-flash"
|
||||||
|
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
|
></div>
|
||||||
|
<button
|
||||||
|
id="btn-delete-address-confirm"
|
||||||
|
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||||
|
>
|
||||||
|
Remove Address
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- ============ SHOW RECOVERY PHRASE ============ -->
|
||||||
|
<div id="view-show-phrase" class="view hidden">
|
||||||
|
<button
|
||||||
|
id="btn-show-phrase-back"
|
||||||
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mb-2"
|
||||||
|
>
|
||||||
|
< Back
|
||||||
|
</button>
|
||||||
|
<h2 class="font-bold mb-1">Recovery Phrase</h2>
|
||||||
|
<p class="text-xs mb-3" id="show-phrase-wallet-name"></p>
|
||||||
|
<div
|
||||||
|
class="text-xs mb-3 border border-border border-dashed p-2"
|
||||||
|
>
|
||||||
|
Anyone who has these words can take every coin and token in
|
||||||
|
this wallet, from any device, without your password. Never
|
||||||
|
type them into a website and never show them to anyone.
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="show-phrase-flash"
|
||||||
|
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
|
></div>
|
||||||
|
<div id="show-phrase-password-section" class="mb-2">
|
||||||
|
<label class="block mb-1">Password</label>
|
||||||
|
<input
|
||||||
|
type="password"
|
||||||
|
id="show-phrase-password"
|
||||||
|
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||||
|
placeholder="Enter your password to continue"
|
||||||
|
/>
|
||||||
|
<button
|
||||||
|
id="btn-show-phrase-reveal"
|
||||||
|
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
|
||||||
|
>
|
||||||
|
Reveal
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
<div id="show-phrase-result" class="hidden">
|
||||||
|
<div
|
||||||
|
id="show-phrase-value"
|
||||||
|
class="bg-danger-well rounded p-2 font-mono text-xs break-all cursor-pointer mb-1"
|
||||||
|
title="Click to copy"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<!-- ============ SETTINGS: ADD TOKEN ============ -->
|
<!-- ============ SETTINGS: ADD TOKEN ============ -->
|
||||||
<div id="view-settings-addtoken" class="view hidden">
|
<div id="view-settings-addtoken" class="view hidden">
|
||||||
<button
|
<button
|
||||||
@@ -991,7 +1300,8 @@
|
|||||||
/>
|
/>
|
||||||
<div
|
<div
|
||||||
id="settings-addtoken-info"
|
id="settings-addtoken-info"
|
||||||
class="text-xs text-muted mt-1 hidden"
|
class="text-xs text-muted mt-1 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<button
|
<button
|
||||||
id="btn-settings-addtoken-manual"
|
id="btn-settings-addtoken-manual"
|
||||||
@@ -1013,66 +1323,149 @@
|
|||||||
<h2 id="tx-detail-heading" class="font-bold mb-2">
|
<h2 id="tx-detail-heading" class="font-bold mb-2">
|
||||||
Transaction
|
Transaction
|
||||||
</h2>
|
</h2>
|
||||||
<div id="tx-detail-type-section" class="mb-4 hidden">
|
|
||||||
<div class="text-xs text-muted mb-1">Type</div>
|
<!-- ── Identity ── -->
|
||||||
<div id="tx-detail-type" class="text-xs font-bold"></div>
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
</div>
|
<div class="mb-2">
|
||||||
<div class="mb-4">
|
<div class="text-xs text-muted mb-1">
|
||||||
<div class="text-xs text-muted mb-1">Status</div>
|
Transaction hash
|
||||||
<div id="tx-detail-status" class="text-xs"></div>
|
</div>
|
||||||
</div>
|
|
||||||
<div class="mb-4">
|
|
||||||
<div class="text-xs text-muted mb-1">Time</div>
|
|
||||||
<div id="tx-detail-time" class="text-xs"></div>
|
|
||||||
</div>
|
|
||||||
<div class="mb-4">
|
|
||||||
<div class="text-xs text-muted mb-1">Amount</div>
|
|
||||||
<div id="tx-detail-value" class="text-xs"></div>
|
|
||||||
</div>
|
|
||||||
<div class="mb-4 hidden">
|
|
||||||
<div class="text-xs text-muted mb-1">Native quantity</div>
|
|
||||||
<div id="tx-detail-native" class="text-xs"></div>
|
|
||||||
</div>
|
|
||||||
<div class="mb-4">
|
|
||||||
<div class="text-xs text-muted mb-1">From</div>
|
|
||||||
<div id="tx-detail-from" class="text-xs break-all"></div>
|
|
||||||
</div>
|
|
||||||
<div class="mb-4">
|
|
||||||
<div class="text-xs text-muted mb-1">To</div>
|
|
||||||
<div id="tx-detail-to" class="text-xs break-all"></div>
|
|
||||||
</div>
|
|
||||||
<div id="tx-detail-calldata-section" class="mb-4 hidden">
|
|
||||||
<div
|
|
||||||
id="tx-detail-calldata-well"
|
|
||||||
class="mb-3 border border-border border-dashed p-2"
|
|
||||||
>
|
|
||||||
<div class="text-xs text-muted mb-1">Action</div>
|
|
||||||
<div
|
<div
|
||||||
id="tx-detail-calldata-action"
|
id="tx-detail-hash"
|
||||||
class="text-xs font-bold mb-2"
|
class="text-xs break-all"
|
||||||
></div>
|
></div>
|
||||||
|
</div>
|
||||||
|
<div id="tx-detail-type-section" class="mb-2 hidden">
|
||||||
|
<div class="text-xs text-muted mb-1">Type</div>
|
||||||
<div
|
<div
|
||||||
id="tx-detail-calldata-details"
|
id="tx-detail-type"
|
||||||
class="text-xs"
|
class="text-xs font-bold"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
<div class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">Status</div>
|
||||||
|
<div id="tx-detail-status" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">From</div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-from"
|
||||||
|
class="text-xs break-all"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
<div class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">To</div>
|
||||||
|
<div id="tx-detail-to" class="text-xs break-all"></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- ── Timing ── -->
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<div class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">Time</div>
|
||||||
|
<div id="tx-detail-time" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div id="tx-detail-block-section" class="mb-2 hidden">
|
||||||
|
<div class="text-xs text-muted mb-1">Block</div>
|
||||||
|
<div id="tx-detail-block" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- ── Value ── -->
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<div class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">Amount</div>
|
||||||
|
<div id="tx-detail-value" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div class="mb-2 hidden">
|
||||||
|
<div class="text-xs text-muted mb-1">
|
||||||
|
Native quantity
|
||||||
|
</div>
|
||||||
|
<div id="tx-detail-native" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-token-contract-section"
|
||||||
|
class="mb-2 hidden"
|
||||||
|
>
|
||||||
|
<div class="text-xs text-muted mb-1">
|
||||||
|
Token contract
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-token-contract"
|
||||||
|
class="text-xs break-all"
|
||||||
></div>
|
></div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="mb-4">
|
|
||||||
<div class="text-xs text-muted mb-1">Transaction hash</div>
|
<!-- ── Decoded details ── -->
|
||||||
<div id="tx-detail-hash" class="text-xs break-all"></div>
|
<div id="tx-detail-calldata-section" class="hidden">
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<div id="tx-detail-calldata-well" class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">Action</div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-calldata-action"
|
||||||
|
class="text-xs font-bold mb-2"
|
||||||
|
></div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-calldata-details"
|
||||||
|
class="text-xs"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div id="tx-detail-rawdata-section" class="mb-4 hidden">
|
|
||||||
<div class="text-xs text-muted mb-1">Raw data</div>
|
<!-- ── Network details ── -->
|
||||||
<div
|
<div id="tx-detail-network-section" class="hidden">
|
||||||
id="tx-detail-rawdata"
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
class="text-xs break-all font-mono border border-border border-dashed p-2"
|
<div id="tx-detail-nonce-section" class="mb-2 hidden">
|
||||||
></div>
|
<div class="text-xs text-muted mb-1">Nonce</div>
|
||||||
|
<div id="tx-detail-nonce" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-gasprice-section"
|
||||||
|
class="mb-2 hidden"
|
||||||
|
>
|
||||||
|
<div class="text-xs text-muted mb-1">Gas price</div>
|
||||||
|
<div id="tx-detail-gasprice" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div id="tx-detail-gasused-section" class="mb-2 hidden">
|
||||||
|
<div class="text-xs text-muted mb-1">Gas used</div>
|
||||||
|
<div id="tx-detail-gasused" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
<div id="tx-detail-fee-section" class="mb-2 hidden">
|
||||||
|
<div class="text-xs text-muted mb-1">
|
||||||
|
Transaction fee
|
||||||
|
</div>
|
||||||
|
<div id="tx-detail-fee" class="text-xs"></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<!-- ── Raw data ── -->
|
||||||
|
<div id="tx-detail-rawdata-section" class="hidden">
|
||||||
|
<div class="bg-well p-3 mx-1 mb-3">
|
||||||
|
<div class="mb-2">
|
||||||
|
<div class="text-xs text-muted mb-1">Raw data</div>
|
||||||
|
<div
|
||||||
|
id="tx-detail-rawdata"
|
||||||
|
class="text-xs break-all font-mono border border-border border-dashed p-2"
|
||||||
|
></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<!-- ============ TRANSACTION APPROVAL ============ -->
|
<!-- ============ TRANSACTION APPROVAL ============ -->
|
||||||
<div id="view-approve-tx" class="view hidden">
|
<div id="view-approve-tx" class="view hidden">
|
||||||
<h2 class="font-bold mb-2">Transaction Request</h2>
|
<h2 class="font-bold mb-2">Transaction Request</h2>
|
||||||
|
<div
|
||||||
|
id="approve-tx-phishing-warning"
|
||||||
|
class="mb-3 p-2 text-xs font-bold hidden bg-red-100 text-red-800 border-2 border-red-600 rounded-md"
|
||||||
|
>
|
||||||
|
⚠️ PHISHING WARNING: This site is on a known phishing
|
||||||
|
blocklist. This transaction may steal your funds. Proceed
|
||||||
|
with extreme caution.
|
||||||
|
</div>
|
||||||
<p class="mb-2">
|
<p class="mb-2">
|
||||||
<span id="approve-tx-hostname" class="font-bold"></span>
|
<span id="approve-tx-hostname" class="font-bold"></span>
|
||||||
wants to send a transaction.
|
wants to send a transaction.
|
||||||
@@ -1117,7 +1510,8 @@
|
|||||||
</div>
|
</div>
|
||||||
<div
|
<div
|
||||||
id="approve-tx-error"
|
id="approve-tx-error"
|
||||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem] hidden"
|
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div class="flex justify-between">
|
<div class="flex justify-between">
|
||||||
<button
|
<button
|
||||||
@@ -1138,6 +1532,14 @@
|
|||||||
<!-- ============ SIGNATURE APPROVAL ============ -->
|
<!-- ============ SIGNATURE APPROVAL ============ -->
|
||||||
<div id="view-approve-sign" class="view hidden">
|
<div id="view-approve-sign" class="view hidden">
|
||||||
<h2 class="font-bold mb-2">Signature Request</h2>
|
<h2 class="font-bold mb-2">Signature Request</h2>
|
||||||
|
<div
|
||||||
|
id="approve-sign-phishing-warning"
|
||||||
|
class="mb-3 p-2 text-xs font-bold hidden bg-red-100 text-red-800 border-2 border-red-600 rounded-md"
|
||||||
|
>
|
||||||
|
⚠️ PHISHING WARNING: This site is on a known phishing
|
||||||
|
blocklist. Signing this message may authorize theft of your
|
||||||
|
funds. Proceed with extreme caution.
|
||||||
|
</div>
|
||||||
<p class="mb-2">
|
<p class="mb-2">
|
||||||
<span id="approve-sign-hostname" class="font-bold"></span>
|
<span id="approve-sign-hostname" class="font-bold"></span>
|
||||||
wants you to sign a message.
|
wants you to sign a message.
|
||||||
@@ -1145,8 +1547,10 @@
|
|||||||
|
|
||||||
<div
|
<div
|
||||||
id="approve-sign-danger-warning"
|
id="approve-sign-danger-warning"
|
||||||
class="hidden mb-3 p-2 text-xs font-bold"
|
class="mb-3 p-2 text-xs font-bold"
|
||||||
style="
|
style="
|
||||||
|
visibility: hidden;
|
||||||
|
min-height: 1.25rem;
|
||||||
background: #fee2e2;
|
background: #fee2e2;
|
||||||
color: #991b1b;
|
color: #991b1b;
|
||||||
border: 2px solid #dc2626;
|
border: 2px solid #dc2626;
|
||||||
@@ -1183,7 +1587,8 @@
|
|||||||
</div>
|
</div>
|
||||||
<div
|
<div
|
||||||
id="approve-sign-error"
|
id="approve-sign-error"
|
||||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem] hidden"
|
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.25rem]"
|
||||||
|
style="visibility: hidden"
|
||||||
></div>
|
></div>
|
||||||
<div class="flex justify-between">
|
<div class="flex justify-between">
|
||||||
<button
|
<button
|
||||||
@@ -1204,6 +1609,14 @@
|
|||||||
<!-- ============ SITE APPROVAL ============ -->
|
<!-- ============ SITE APPROVAL ============ -->
|
||||||
<div id="view-approve-site" class="view hidden">
|
<div id="view-approve-site" class="view hidden">
|
||||||
<h2 class="font-bold mb-2">Connection Request</h2>
|
<h2 class="font-bold mb-2">Connection Request</h2>
|
||||||
|
<div
|
||||||
|
id="approve-site-phishing-warning"
|
||||||
|
class="mb-3 p-2 text-xs font-bold hidden bg-red-100 text-red-800 border-2 border-red-600 rounded-md"
|
||||||
|
>
|
||||||
|
⚠️ PHISHING WARNING: This site is on a known phishing
|
||||||
|
blocklist. Connecting your wallet may result in loss of
|
||||||
|
funds. Proceed with extreme caution.
|
||||||
|
</div>
|
||||||
<div class="mb-3">
|
<div class="mb-3">
|
||||||
<p class="mb-2">
|
<p class="mb-2">
|
||||||
<span id="approve-hostname" class="font-bold"></span>
|
<span id="approve-hostname" class="font-bold"></span>
|
||||||
|
|||||||
@@ -1,16 +1,28 @@
|
|||||||
// AutistMask popup entry point.
|
// AutistMask popup entry point.
|
||||||
// Loads state, initializes views, triggers first render.
|
// Loads state, initializes views, triggers first render.
|
||||||
|
|
||||||
const { DEBUG } = require("../shared/constants");
|
|
||||||
const { state, saveState, loadState } = require("../shared/state");
|
const { state, saveState, loadState } = require("../shared/state");
|
||||||
|
const { setRuntimeDebug } = require("../shared/log");
|
||||||
const { refreshPrices } = require("../shared/prices");
|
const { refreshPrices } = require("../shared/prices");
|
||||||
const { refreshBalances } = require("../shared/balances");
|
const { refreshBalances } = require("../shared/balances");
|
||||||
const { $, showView } = require("./views/helpers");
|
const {
|
||||||
|
$,
|
||||||
|
showView,
|
||||||
|
updateDebugBanner,
|
||||||
|
setRenderMain,
|
||||||
|
pushCurrentView,
|
||||||
|
goBack,
|
||||||
|
clearViewStack,
|
||||||
|
} = require("./views/helpers");
|
||||||
|
const { applyTheme } = require("./theme");
|
||||||
|
// Views that can be fully re-rendered from persisted state. All others fall
|
||||||
|
// back to the nearest restorable parent; see the module for why the
|
||||||
|
// secret-bearing views are absent.
|
||||||
|
const { RESTORABLE_VIEWS } = require("./restorableViews");
|
||||||
|
|
||||||
const home = require("./views/home");
|
const home = require("./views/home");
|
||||||
const welcome = require("./views/welcome");
|
const welcome = require("./views/welcome");
|
||||||
const addWallet = require("./views/addWallet");
|
const addWallet = require("./views/addWallet");
|
||||||
const importKey = require("./views/importKey");
|
|
||||||
const addressDetail = require("./views/addressDetail");
|
const addressDetail = require("./views/addressDetail");
|
||||||
const addressToken = require("./views/addressToken");
|
const addressToken = require("./views/addressToken");
|
||||||
const send = require("./views/send");
|
const send = require("./views/send");
|
||||||
@@ -21,6 +33,7 @@ const receive = require("./views/receive");
|
|||||||
const addToken = require("./views/addToken");
|
const addToken = require("./views/addToken");
|
||||||
const settings = require("./views/settings");
|
const settings = require("./views/settings");
|
||||||
const settingsAddToken = require("./views/settingsAddToken");
|
const settingsAddToken = require("./views/settingsAddToken");
|
||||||
|
const deleteAddress = require("./views/deleteAddress");
|
||||||
const approval = require("./views/approval");
|
const approval = require("./views/approval");
|
||||||
|
|
||||||
function renderWalletList() {
|
function renderWalletList() {
|
||||||
@@ -53,33 +66,48 @@ async function doRefreshAndRender() {
|
|||||||
const ctx = {
|
const ctx = {
|
||||||
renderWalletList,
|
renderWalletList,
|
||||||
doRefreshAndRender,
|
doRefreshAndRender,
|
||||||
showAddWalletView: () => addWallet.show(),
|
showAddWalletView: () => {
|
||||||
showImportKeyView: () => importKey.show(),
|
pushCurrentView();
|
||||||
showAddressDetail: () => addressDetail.show(),
|
addWallet.show();
|
||||||
showAddressToken: () => addressToken.show(),
|
},
|
||||||
showAddTokenView: () => addToken.show(),
|
showAddressDetail: () => {
|
||||||
showConfirmTx: (txInfo) => confirmTx.show(txInfo),
|
pushCurrentView();
|
||||||
showReceive: () => receive.show(),
|
addressDetail.show();
|
||||||
showTransactionDetail: (tx) => transactionDetail.show(tx),
|
},
|
||||||
showSettingsView: () => settings.show(),
|
showAddressToken: () => {
|
||||||
showSettingsAddTokenView: () => settingsAddToken.show(),
|
pushCurrentView();
|
||||||
|
addressToken.show();
|
||||||
|
},
|
||||||
|
showAddTokenView: () => {
|
||||||
|
pushCurrentView();
|
||||||
|
addToken.show();
|
||||||
|
},
|
||||||
|
showConfirmTx: (txInfo) => {
|
||||||
|
pushCurrentView();
|
||||||
|
confirmTx.show(txInfo);
|
||||||
|
},
|
||||||
|
showReceive: () => {
|
||||||
|
pushCurrentView();
|
||||||
|
receive.show();
|
||||||
|
},
|
||||||
|
showTransactionDetail: (tx) => {
|
||||||
|
pushCurrentView();
|
||||||
|
transactionDetail.show(tx);
|
||||||
|
},
|
||||||
|
showSettingsView: () => {
|
||||||
|
pushCurrentView();
|
||||||
|
settings.show();
|
||||||
|
},
|
||||||
|
showSettingsAddTokenView: () => {
|
||||||
|
pushCurrentView();
|
||||||
|
settingsAddToken.show();
|
||||||
|
},
|
||||||
|
showDeleteAddress: (walletIdx, addrIdx) => {
|
||||||
|
pushCurrentView();
|
||||||
|
deleteAddress.show(walletIdx, addrIdx);
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
// Views that can be fully re-rendered from persisted state.
|
|
||||||
// All others fall back to the nearest restorable parent.
|
|
||||||
const RESTORABLE_VIEWS = new Set([
|
|
||||||
"main",
|
|
||||||
"address",
|
|
||||||
"address-token",
|
|
||||||
"receive",
|
|
||||||
"settings",
|
|
||||||
"settings-addtoken",
|
|
||||||
"confirm-tx",
|
|
||||||
"transaction",
|
|
||||||
"success-tx",
|
|
||||||
"error-tx",
|
|
||||||
]);
|
|
||||||
|
|
||||||
function needsAddress(view) {
|
function needsAddress(view) {
|
||||||
return (
|
return (
|
||||||
view === "address" ||
|
view === "address" ||
|
||||||
@@ -142,6 +170,12 @@ function restoreView() {
|
|||||||
fallbackView();
|
fallbackView();
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
case "wait-tx":
|
||||||
|
// Resumes the receipt poll from the persisted broadcast time.
|
||||||
|
if (!txStatus.restoreWait()) {
|
||||||
|
fallbackView();
|
||||||
|
}
|
||||||
|
break;
|
||||||
case "success-tx":
|
case "success-tx":
|
||||||
if (state.viewData && state.viewData.hash) {
|
if (state.viewData && state.viewData.hash) {
|
||||||
txStatus.renderSuccess();
|
txStatus.renderSuccess();
|
||||||
@@ -168,16 +202,14 @@ function fallbackView() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async function init() {
|
async function init() {
|
||||||
if (DEBUG) {
|
|
||||||
const banner = document.createElement("div");
|
|
||||||
banner.id = "debug-banner";
|
|
||||||
banner.textContent = "DEBUG / INSECURE";
|
|
||||||
banner.style.cssText =
|
|
||||||
"background:#c00;color:#fff;text-align:center;font-size:10px;padding:1px 0;font-family:monospace;position:sticky;top:0;z-index:9999;";
|
|
||||||
document.body.prepend(banner);
|
|
||||||
}
|
|
||||||
|
|
||||||
await loadState();
|
await loadState();
|
||||||
|
applyTheme(state.theme);
|
||||||
|
|
||||||
|
// Sync runtime debug flag from persisted state before first render
|
||||||
|
setRuntimeDebug(state.debugMode);
|
||||||
|
|
||||||
|
// Create the debug/testnet banner if needed (uses runtime debug state)
|
||||||
|
updateDebugBanner();
|
||||||
|
|
||||||
// Auto-default active address
|
// Auto-default active address
|
||||||
if (
|
if (
|
||||||
@@ -208,16 +240,17 @@ async function init() {
|
|||||||
.getElementById("view-settings")
|
.getElementById("view-settings")
|
||||||
.classList.contains("hidden")
|
.classList.contains("hidden")
|
||||||
) {
|
) {
|
||||||
renderWalletList();
|
goBack();
|
||||||
showView("main");
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
pushCurrentView();
|
||||||
settings.show();
|
settings.show();
|
||||||
});
|
});
|
||||||
|
|
||||||
|
setRenderMain(renderWalletList);
|
||||||
|
|
||||||
welcome.init(ctx);
|
welcome.init(ctx);
|
||||||
addWallet.init(ctx);
|
addWallet.init(ctx);
|
||||||
importKey.init(ctx);
|
|
||||||
home.init(ctx);
|
home.init(ctx);
|
||||||
addressDetail.init(ctx);
|
addressDetail.init(ctx);
|
||||||
addressToken.init(ctx);
|
addressToken.init(ctx);
|
||||||
@@ -228,6 +261,7 @@ async function init() {
|
|||||||
addToken.init(ctx);
|
addToken.init(ctx);
|
||||||
settings.init(ctx);
|
settings.init(ctx);
|
||||||
settingsAddToken.init(ctx);
|
settingsAddToken.init(ctx);
|
||||||
|
deleteAddress.init(ctx);
|
||||||
|
|
||||||
if (!state.hasWallet) {
|
if (!state.hasWallet) {
|
||||||
showView("welcome");
|
showView("welcome");
|
||||||
|
|||||||
30
src/popup/restorableViews.js
Normal file
30
src/popup/restorableViews.js
Normal file
@@ -0,0 +1,30 @@
|
|||||||
|
// Views the popup may reopen onto.
|
||||||
|
//
|
||||||
|
// The popup persists the current view so that reopening the toolbar popup
|
||||||
|
// lands the user back where they were. Only views that can be fully
|
||||||
|
// re-rendered from persisted state belong here; every other view falls back
|
||||||
|
// to the nearest restorable parent (src/popup/index.js restoreView()).
|
||||||
|
//
|
||||||
|
// A view that displays a secret must NEVER be listed. Restoring onto one
|
||||||
|
// would put a private key or a recovery phrase on screen with no password
|
||||||
|
// prompt in front of it, on a popup the user may have reopened by accident.
|
||||||
|
// That is why "export-privkey" and "show-phrase" are absent.
|
||||||
|
//
|
||||||
|
// Kept in its own module, with no dependencies, so tests can assert the
|
||||||
|
// exclusion directly rather than trusting a reading of the popup entry
|
||||||
|
// point, which cannot be required outside a browser.
|
||||||
|
const RESTORABLE_VIEWS = new Set([
|
||||||
|
"main",
|
||||||
|
"address",
|
||||||
|
"address-token",
|
||||||
|
"receive",
|
||||||
|
"settings",
|
||||||
|
"settings-addtoken",
|
||||||
|
"confirm-tx",
|
||||||
|
"transaction",
|
||||||
|
"wait-tx",
|
||||||
|
"success-tx",
|
||||||
|
"error-tx",
|
||||||
|
]);
|
||||||
|
|
||||||
|
module.exports = { RESTORABLE_VIEWS };
|
||||||
@@ -10,12 +10,37 @@
|
|||||||
--color-border: #000000;
|
--color-border: #000000;
|
||||||
--color-border-light: #cccccc;
|
--color-border-light: #cccccc;
|
||||||
--color-hover: #eeeeee;
|
--color-hover: #eeeeee;
|
||||||
--color-well: #f5f5f5;
|
--color-well: #e8e8e8;
|
||||||
--color-danger-well: #fef2f2;
|
--color-danger-well: #fef2f2;
|
||||||
--color-section: #dddddd;
|
--color-section: #dddddd;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
html.dark {
|
||||||
|
--color-bg: #000000;
|
||||||
|
--color-fg: #ffffff;
|
||||||
|
--color-muted: #aaaaaa;
|
||||||
|
--color-border: #ffffff;
|
||||||
|
--color-border-light: #444444;
|
||||||
|
--color-hover: #222222;
|
||||||
|
--color-well: #1a1a1a;
|
||||||
|
--color-danger-well: #2a0a0a;
|
||||||
|
--color-section: #2a2a2a;
|
||||||
|
}
|
||||||
|
|
||||||
body {
|
body {
|
||||||
width: 396px;
|
width: 396px;
|
||||||
overflow-x: hidden;
|
overflow-x: hidden;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Copy-flash feedback: inverts colors then fades back */
|
||||||
|
.copy-flash-active {
|
||||||
|
background-color: var(--color-fg) !important;
|
||||||
|
color: var(--color-bg) !important;
|
||||||
|
transition: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.copy-flash-fade {
|
||||||
|
transition:
|
||||||
|
background-color 225ms ease-out,
|
||||||
|
color 225ms ease-out;
|
||||||
|
}
|
||||||
|
|||||||
33
src/popup/theme.js
Normal file
33
src/popup/theme.js
Normal file
@@ -0,0 +1,33 @@
|
|||||||
|
// Theme management: applies light/dark class to <html> based on preference.
|
||||||
|
|
||||||
|
let mediaQuery = null;
|
||||||
|
let mediaHandler = null;
|
||||||
|
|
||||||
|
function applyTheme(theme) {
|
||||||
|
// Clean up previous system listener
|
||||||
|
if (mediaQuery && mediaHandler) {
|
||||||
|
mediaQuery.removeEventListener("change", mediaHandler);
|
||||||
|
mediaHandler = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (theme === "dark") {
|
||||||
|
document.documentElement.classList.add("dark");
|
||||||
|
} else if (theme === "light") {
|
||||||
|
document.documentElement.classList.remove("dark");
|
||||||
|
} else {
|
||||||
|
// system
|
||||||
|
mediaQuery = window.matchMedia("(prefers-color-scheme: dark)");
|
||||||
|
const update = () => {
|
||||||
|
if (mediaQuery.matches) {
|
||||||
|
document.documentElement.classList.add("dark");
|
||||||
|
} else {
|
||||||
|
document.documentElement.classList.remove("dark");
|
||||||
|
}
|
||||||
|
};
|
||||||
|
mediaHandler = update;
|
||||||
|
mediaQuery.addEventListener("change", update);
|
||||||
|
update();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { applyTheme };
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
const { $, showView, showFlash } = require("./helpers");
|
const { $, showView, showFlash, goBack } = require("./helpers");
|
||||||
const { getTopTokens } = require("../../shared/tokenList");
|
const { getTopTokens } = require("../../shared/tokenList");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState } = require("../../shared/state");
|
||||||
const { lookupTokenInfo } = require("../../shared/balances");
|
const { lookupTokenInfo } = require("../../shared/balances");
|
||||||
@@ -7,7 +7,8 @@ const { log } = require("../../shared/log");
|
|||||||
|
|
||||||
function show() {
|
function show() {
|
||||||
$("add-token-address").value = "";
|
$("add-token-address").value = "";
|
||||||
$("add-token-info").classList.add("hidden");
|
$("add-token-info").textContent = "";
|
||||||
|
$("add-token-info").style.visibility = "hidden";
|
||||||
const list = $("common-token-list");
|
const list = $("common-token-list");
|
||||||
list.innerHTML = getTopTokens(25)
|
list.innerHTML = getTopTokens(25)
|
||||||
.map(
|
.map(
|
||||||
@@ -45,7 +46,7 @@ function init(ctx) {
|
|||||||
}
|
}
|
||||||
const infoEl = $("add-token-info");
|
const infoEl = $("add-token-info");
|
||||||
infoEl.textContent = "Looking up token...";
|
infoEl.textContent = "Looking up token...";
|
||||||
infoEl.classList.remove("hidden");
|
infoEl.style.visibility = "visible";
|
||||||
log.debugf("Looking up token contract", contractAddr);
|
log.debugf("Looking up token contract", contractAddr);
|
||||||
try {
|
try {
|
||||||
const info = await lookupTokenInfo(contractAddr, state.rpcUrl);
|
const info = await lookupTokenInfo(contractAddr, state.rpcUrl);
|
||||||
@@ -58,16 +59,24 @@ function init(ctx) {
|
|||||||
});
|
});
|
||||||
await saveState();
|
await saveState();
|
||||||
ctx.doRefreshAndRender();
|
ctx.doRefreshAndRender();
|
||||||
ctx.showAddressDetail();
|
// Pop the stack (back to address detail) and re-render it
|
||||||
|
// so the newly added token is visible immediately.
|
||||||
|
if (state.viewStack.length > 0) {
|
||||||
|
state.viewStack.pop();
|
||||||
|
}
|
||||||
|
require("./addressDetail").show();
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
const detail = e.shortMessage || e.message || String(e);
|
const detail = e.shortMessage || e.message || String(e);
|
||||||
log.errorf("Token lookup failed for", contractAddr, detail);
|
log.errorf("Token lookup failed for", contractAddr, detail);
|
||||||
showFlash(detail);
|
showFlash(detail);
|
||||||
infoEl.classList.add("hidden");
|
infoEl.textContent = "";
|
||||||
|
infoEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-add-token-back").addEventListener("click", ctx.showAddressDetail);
|
$("btn-add-token-back").addEventListener("click", () => {
|
||||||
|
goBack();
|
||||||
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { init, show };
|
module.exports = { init, show };
|
||||||
|
|||||||
@@ -1,129 +1,338 @@
|
|||||||
const { $, showView, showFlash } = require("./helpers");
|
const {
|
||||||
|
$,
|
||||||
|
showView,
|
||||||
|
showFlash,
|
||||||
|
goBack,
|
||||||
|
clearViewStack,
|
||||||
|
onViewLeave,
|
||||||
|
} = require("./helpers");
|
||||||
const {
|
const {
|
||||||
generateMnemonic,
|
generateMnemonic,
|
||||||
hdWalletFromMnemonic,
|
hdWalletFromMnemonic,
|
||||||
isValidMnemonic,
|
isValidMnemonic,
|
||||||
|
addressFromPrivateKey,
|
||||||
|
hdWalletFromXprv,
|
||||||
|
isValidXprv,
|
||||||
|
isMasterExtendedKey,
|
||||||
} = require("../../shared/wallet");
|
} = require("../../shared/wallet");
|
||||||
const { encryptWithPassword } = require("../../shared/vault");
|
const { encryptWithPassword } = require("../../shared/vault");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState } = require("../../shared/state");
|
||||||
const { scanForAddresses } = require("../../shared/balances");
|
const { scanForAddresses } = require("../../shared/balances");
|
||||||
|
|
||||||
function show() {
|
/**
|
||||||
$("wallet-mnemonic").value = "";
|
* Check if an address already exists in ANY wallet (hd, xprv, or key).
|
||||||
$("add-wallet-password").value = "";
|
* Returns the wallet object if found, or undefined.
|
||||||
$("add-wallet-password-confirm").value = "";
|
*/
|
||||||
$("add-wallet-phrase-warning").classList.add("hidden");
|
function findWalletByAddress(addr) {
|
||||||
showView("add-wallet");
|
const lower = addr.toLowerCase();
|
||||||
}
|
return state.wallets.find((w) =>
|
||||||
|
w.addresses.some((a) => a.address.toLowerCase() === lower),
|
||||||
function init(ctx) {
|
|
||||||
$("btn-generate-phrase").addEventListener("click", () => {
|
|
||||||
$("wallet-mnemonic").value = generateMnemonic();
|
|
||||||
$("add-wallet-phrase-warning").classList.remove("hidden");
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-add-wallet-confirm").addEventListener("click", async () => {
|
|
||||||
const mnemonic = $("wallet-mnemonic").value.trim();
|
|
||||||
if (!mnemonic) {
|
|
||||||
showFlash(
|
|
||||||
"Enter a recovery phrase or press the die to generate one.",
|
|
||||||
);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const words = mnemonic.split(/\s+/);
|
|
||||||
if (words.length !== 12 && words.length !== 24) {
|
|
||||||
showFlash(
|
|
||||||
"Recovery phrase must be 12 or 24 words. You entered " +
|
|
||||||
words.length +
|
|
||||||
".",
|
|
||||||
);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (!isValidMnemonic(mnemonic)) {
|
|
||||||
showFlash("Invalid recovery phrase. Check for typos.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const pw = $("add-wallet-password").value;
|
|
||||||
const pw2 = $("add-wallet-password-confirm").value;
|
|
||||||
if (!pw) {
|
|
||||||
showFlash("Please choose a password.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (pw.length < 12) {
|
|
||||||
showFlash("Password must be at least 12 characters.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (pw !== pw2) {
|
|
||||||
showFlash("Passwords do not match.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const { xpub, firstAddress } = hdWalletFromMnemonic(mnemonic);
|
|
||||||
const duplicate = state.wallets.find(
|
|
||||||
(w) =>
|
|
||||||
w.type === "hd" &&
|
|
||||||
w.addresses[0] &&
|
|
||||||
w.addresses[0].address.toLowerCase() ===
|
|
||||||
firstAddress.toLowerCase(),
|
|
||||||
);
|
|
||||||
if (duplicate) {
|
|
||||||
showFlash(
|
|
||||||
"This recovery phrase is already added (" +
|
|
||||||
duplicate.name +
|
|
||||||
").",
|
|
||||||
);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const encrypted = await encryptWithPassword(mnemonic, pw);
|
|
||||||
const walletNum = state.wallets.length + 1;
|
|
||||||
const wallet = {
|
|
||||||
type: "hd",
|
|
||||||
name: "Wallet " + walletNum,
|
|
||||||
xpub: xpub,
|
|
||||||
encryptedSecret: encrypted,
|
|
||||||
nextIndex: 1,
|
|
||||||
addresses: [
|
|
||||||
{ address: firstAddress, balance: "0.0000", tokenBalances: [] },
|
|
||||||
],
|
|
||||||
};
|
|
||||||
state.wallets.push(wallet);
|
|
||||||
state.hasWallet = true;
|
|
||||||
await saveState();
|
|
||||||
ctx.renderWalletList();
|
|
||||||
showView("main");
|
|
||||||
|
|
||||||
// Scan for used HD addresses beyond index 0.
|
|
||||||
showFlash("Scanning for addresses...", 30000);
|
|
||||||
const scan = await scanForAddresses(xpub, state.rpcUrl);
|
|
||||||
if (scan.addresses.length > 1) {
|
|
||||||
wallet.addresses = scan.addresses.map((a) => ({
|
|
||||||
address: a.address,
|
|
||||||
balance: "0.0000",
|
|
||||||
tokenBalances: [],
|
|
||||||
}));
|
|
||||||
wallet.nextIndex = scan.nextIndex;
|
|
||||||
await saveState();
|
|
||||||
ctx.renderWalletList();
|
|
||||||
showFlash("Found " + scan.addresses.length + " addresses.");
|
|
||||||
} else {
|
|
||||||
showFlash("Ready.", 1000);
|
|
||||||
}
|
|
||||||
|
|
||||||
ctx.doRefreshAndRender();
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-add-wallet-back").addEventListener("click", () => {
|
|
||||||
if (!state.hasWallet) {
|
|
||||||
showView("welcome");
|
|
||||||
} else {
|
|
||||||
ctx.renderWalletList();
|
|
||||||
showView("main");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-add-wallet-import-key").addEventListener(
|
|
||||||
"click",
|
|
||||||
ctx.showImportKeyView,
|
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check if an xpub already exists in any HD-type wallet (hd or xprv).
|
||||||
|
* Returns the wallet object if found, or undefined.
|
||||||
|
*/
|
||||||
|
function findWalletByXpub(xpub) {
|
||||||
|
return state.wallets.find((w) => w.xpub && w.xpub === xpub);
|
||||||
|
}
|
||||||
|
|
||||||
|
let currentMode = "mnemonic";
|
||||||
|
|
||||||
|
const MODES = ["mnemonic", "privkey", "xprv"];
|
||||||
|
|
||||||
|
const PASSWORD_HINTS = {
|
||||||
|
mnemonic:
|
||||||
|
"This password encrypts your recovery phrase on this device. You will need it to send funds.",
|
||||||
|
privkey:
|
||||||
|
"This password encrypts your private key on this device. You will need it to send funds.",
|
||||||
|
xprv: "This password encrypts your key on this device. You will need it to send funds.",
|
||||||
|
};
|
||||||
|
|
||||||
|
function switchMode(mode) {
|
||||||
|
currentMode = mode;
|
||||||
|
for (const m of MODES) {
|
||||||
|
$("add-wallet-section-" + m).classList.toggle("hidden", m !== mode);
|
||||||
|
const tab = $("tab-" + m);
|
||||||
|
const isActive = m === mode;
|
||||||
|
// Active: bold, solid border on top/sides, no bottom border (connects to content)
|
||||||
|
tab.classList.toggle("font-bold", isActive);
|
||||||
|
tab.classList.toggle("border-solid", isActive);
|
||||||
|
tab.classList.toggle("border-border", isActive);
|
||||||
|
tab.classList.toggle("border-b-bg", isActive);
|
||||||
|
tab.classList.toggle("bg-bg", isActive);
|
||||||
|
// Inactive: muted text, dashed border on top/sides, transparent bottom, hover invert
|
||||||
|
tab.classList.toggle("text-muted", !isActive);
|
||||||
|
tab.classList.toggle("border-dashed", !isActive);
|
||||||
|
tab.classList.toggle("border-border-light", !isActive);
|
||||||
|
tab.classList.toggle("border-b-transparent", !isActive);
|
||||||
|
tab.classList.toggle("hover:bg-fg", !isActive);
|
||||||
|
tab.classList.toggle("hover:text-bg", !isActive);
|
||||||
|
}
|
||||||
|
$("add-wallet-password-hint").textContent = PASSWORD_HINTS[mode];
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wipe the secret material this screen holds in the DOM: a generated or
|
||||||
|
// pasted recovery phrase, an imported private key or extended private key,
|
||||||
|
// and the password that would encrypt them. Registered as the view-leave
|
||||||
|
// handler as well as run on entry, so none of it survives in the hidden
|
||||||
|
// view after the user navigates away by any route, including the Settings
|
||||||
|
// gear and the import itself.
|
||||||
|
function clear() {
|
||||||
|
$("wallet-mnemonic").value = "";
|
||||||
|
$("import-private-key").value = "";
|
||||||
|
$("import-xprv-key").value = "";
|
||||||
|
$("add-wallet-password").value = "";
|
||||||
|
$("add-wallet-password-confirm").value = "";
|
||||||
|
$("add-wallet-phrase-warning").style.visibility = "hidden";
|
||||||
|
}
|
||||||
|
|
||||||
|
function show() {
|
||||||
|
clear();
|
||||||
|
switchMode("mnemonic");
|
||||||
|
showView("add-wallet");
|
||||||
|
}
|
||||||
|
|
||||||
|
function validatePassword() {
|
||||||
|
const pw = $("add-wallet-password").value;
|
||||||
|
const pw2 = $("add-wallet-password-confirm").value;
|
||||||
|
if (!pw) {
|
||||||
|
showFlash("Please choose a password.");
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
if (pw.length < 12) {
|
||||||
|
showFlash("Password must be at least 12 characters.");
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
if (pw !== pw2) {
|
||||||
|
showFlash("Passwords do not match.");
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
return pw;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function importMnemonic(ctx) {
|
||||||
|
const mnemonic = $("wallet-mnemonic").value.trim();
|
||||||
|
if (!mnemonic) {
|
||||||
|
showFlash("Enter a recovery phrase or press the die to generate one.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const words = mnemonic.split(/\s+/);
|
||||||
|
if (words.length !== 12 && words.length !== 24) {
|
||||||
|
showFlash(
|
||||||
|
"Recovery phrase must be 12 or 24 words. You entered " +
|
||||||
|
words.length +
|
||||||
|
".",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (!isValidMnemonic(mnemonic)) {
|
||||||
|
showFlash("Invalid recovery phrase. Check for typos.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const pw = validatePassword();
|
||||||
|
if (!pw) return;
|
||||||
|
const { xpub, firstAddress } = hdWalletFromMnemonic(mnemonic);
|
||||||
|
const xpubDup = findWalletByXpub(xpub);
|
||||||
|
if (xpubDup) {
|
||||||
|
showFlash(
|
||||||
|
"This recovery phrase is already added (" + xpubDup.name + ").",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const addrDup = findWalletByAddress(firstAddress);
|
||||||
|
if (addrDup) {
|
||||||
|
showFlash("Address already exists in wallet (" + addrDup.name + ").");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const encrypted = await encryptWithPassword(mnemonic, pw);
|
||||||
|
const walletNum = state.wallets.length + 1;
|
||||||
|
const wallet = {
|
||||||
|
type: "hd",
|
||||||
|
name: "Wallet " + walletNum,
|
||||||
|
xpub: xpub,
|
||||||
|
encryptedSecret: encrypted,
|
||||||
|
nextIndex: 1,
|
||||||
|
addresses: [
|
||||||
|
{ address: firstAddress, balance: "0.0000", tokenBalances: [] },
|
||||||
|
],
|
||||||
|
};
|
||||||
|
state.wallets.push(wallet);
|
||||||
|
state.hasWallet = true;
|
||||||
|
await saveState();
|
||||||
|
clearViewStack();
|
||||||
|
ctx.renderWalletList();
|
||||||
|
showView("main");
|
||||||
|
|
||||||
|
// Scan for used HD addresses beyond index 0.
|
||||||
|
showFlash("Scanning for addresses...", 30000);
|
||||||
|
const scan = await scanForAddresses(xpub, state.rpcUrl);
|
||||||
|
if (scan.addresses.length > 1) {
|
||||||
|
wallet.addresses = scan.addresses.map((a) => ({
|
||||||
|
address: a.address,
|
||||||
|
balance: "0.0000",
|
||||||
|
tokenBalances: [],
|
||||||
|
}));
|
||||||
|
wallet.nextIndex = scan.nextIndex;
|
||||||
|
await saveState();
|
||||||
|
ctx.renderWalletList();
|
||||||
|
showFlash("Found " + scan.addresses.length + " addresses.");
|
||||||
|
} else {
|
||||||
|
showFlash("Ready.", 1000);
|
||||||
|
}
|
||||||
|
|
||||||
|
ctx.doRefreshAndRender();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function importPrivateKey(ctx) {
|
||||||
|
const key = $("import-private-key").value.trim();
|
||||||
|
if (!key) {
|
||||||
|
showFlash("Please enter your private key.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
let addr;
|
||||||
|
try {
|
||||||
|
addr = addressFromPrivateKey(key);
|
||||||
|
} catch (e) {
|
||||||
|
showFlash("Invalid private key.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const pw = validatePassword();
|
||||||
|
if (!pw) return;
|
||||||
|
const duplicate = findWalletByAddress(addr);
|
||||||
|
if (duplicate) {
|
||||||
|
showFlash(
|
||||||
|
"This address already exists in wallet (" + duplicate.name + ").",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const encrypted = await encryptWithPassword(key, pw);
|
||||||
|
const walletNum = state.wallets.length + 1;
|
||||||
|
state.wallets.push({
|
||||||
|
type: "key",
|
||||||
|
name: "Wallet " + walletNum,
|
||||||
|
encryptedSecret: encrypted,
|
||||||
|
addresses: [{ address: addr, balance: "0.0000", tokenBalances: [] }],
|
||||||
|
});
|
||||||
|
state.hasWallet = true;
|
||||||
|
await saveState();
|
||||||
|
clearViewStack();
|
||||||
|
ctx.renderWalletList();
|
||||||
|
showView("main");
|
||||||
|
|
||||||
|
ctx.doRefreshAndRender();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function importXprvKey(ctx) {
|
||||||
|
const xprv = $("import-xprv-key").value.trim();
|
||||||
|
if (!xprv) {
|
||||||
|
showFlash("Please enter your extended private key.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (!isValidXprv(xprv)) {
|
||||||
|
showFlash(
|
||||||
|
"That extended private key is not valid. Please check it and try again.",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (!isMasterExtendedKey(xprv)) {
|
||||||
|
showFlash(
|
||||||
|
"That is an account-level or child key, which cannot be imported. " +
|
||||||
|
"Please paste the master extended private key for the wallet.",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
let result;
|
||||||
|
try {
|
||||||
|
result = hdWalletFromXprv(xprv);
|
||||||
|
} catch (e) {
|
||||||
|
showFlash(
|
||||||
|
"That extended private key is not valid. Please check it and try again.",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const { xpub, firstAddress } = result;
|
||||||
|
const xpubDup = findWalletByXpub(xpub);
|
||||||
|
if (xpubDup) {
|
||||||
|
showFlash("This key is already added (" + xpubDup.name + ").");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const addrDup = findWalletByAddress(firstAddress);
|
||||||
|
if (addrDup) {
|
||||||
|
showFlash("Address already exists in wallet (" + addrDup.name + ").");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const pw = validatePassword();
|
||||||
|
if (!pw) return;
|
||||||
|
const encrypted = await encryptWithPassword(xprv, pw);
|
||||||
|
const walletNum = state.wallets.length + 1;
|
||||||
|
const wallet = {
|
||||||
|
type: "xprv",
|
||||||
|
name: "Wallet " + walletNum,
|
||||||
|
xpub: xpub,
|
||||||
|
encryptedSecret: encrypted,
|
||||||
|
nextIndex: 1,
|
||||||
|
addresses: [
|
||||||
|
{ address: firstAddress, balance: "0.0000", tokenBalances: [] },
|
||||||
|
],
|
||||||
|
};
|
||||||
|
state.wallets.push(wallet);
|
||||||
|
state.hasWallet = true;
|
||||||
|
await saveState();
|
||||||
|
clearViewStack();
|
||||||
|
ctx.renderWalletList();
|
||||||
|
showView("main");
|
||||||
|
|
||||||
|
// Scan for used HD addresses beyond index 0.
|
||||||
|
showFlash("Scanning for addresses...", 30000);
|
||||||
|
const scan = await scanForAddresses(xpub, state.rpcUrl);
|
||||||
|
if (scan.addresses.length > 1) {
|
||||||
|
wallet.addresses = scan.addresses.map((a) => ({
|
||||||
|
address: a.address,
|
||||||
|
balance: "0.0000",
|
||||||
|
tokenBalances: [],
|
||||||
|
}));
|
||||||
|
wallet.nextIndex = scan.nextIndex;
|
||||||
|
await saveState();
|
||||||
|
ctx.renderWalletList();
|
||||||
|
showFlash("Found " + scan.addresses.length + " addresses.");
|
||||||
|
} else {
|
||||||
|
showFlash("Ready.", 1000);
|
||||||
|
}
|
||||||
|
|
||||||
|
ctx.doRefreshAndRender();
|
||||||
|
}
|
||||||
|
|
||||||
|
function init(ctx) {
|
||||||
|
onViewLeave("add-wallet", clear);
|
||||||
|
|
||||||
|
// Tab click handlers
|
||||||
|
$("tab-mnemonic").addEventListener("click", () => switchMode("mnemonic"));
|
||||||
|
$("tab-privkey").addEventListener("click", () => switchMode("privkey"));
|
||||||
|
$("tab-xprv").addEventListener("click", () => switchMode("xprv"));
|
||||||
|
|
||||||
|
// Generate mnemonic
|
||||||
|
$("btn-generate-phrase").addEventListener("click", () => {
|
||||||
|
$("wallet-mnemonic").value = generateMnemonic();
|
||||||
|
$("add-wallet-phrase-warning").style.visibility = "visible";
|
||||||
|
});
|
||||||
|
|
||||||
|
// Import / confirm
|
||||||
|
$("btn-add-wallet-confirm").addEventListener("click", async () => {
|
||||||
|
if (currentMode === "mnemonic") {
|
||||||
|
await importMnemonic(ctx);
|
||||||
|
} else if (currentMode === "privkey") {
|
||||||
|
await importPrivateKey(ctx);
|
||||||
|
} else if (currentMode === "xprv") {
|
||||||
|
await importXprvKey(ctx);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// Back button
|
||||||
|
$("btn-add-wallet-back").addEventListener("click", () => {
|
||||||
|
goBack();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
module.exports = { init, show };
|
module.exports = { init, show };
|
||||||
|
|||||||
@@ -7,6 +7,10 @@ const {
|
|||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
truncateMiddle,
|
truncateMiddle,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
goBack,
|
||||||
|
pushCurrentView,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, currentAddress, saveState } = require("../../shared/state");
|
const { state, currentAddress, saveState } = require("../../shared/state");
|
||||||
const { formatUsd, getAddressValueUsd } = require("../../shared/prices");
|
const { formatUsd, getAddressValueUsd } = require("../../shared/prices");
|
||||||
@@ -22,22 +26,20 @@ const {
|
|||||||
} = require("./send");
|
} = require("./send");
|
||||||
const { log } = require("../../shared/log");
|
const { log } = require("../../shared/log");
|
||||||
const makeBlockie = require("ethereum-blockies-base64");
|
const makeBlockie = require("ethereum-blockies-base64");
|
||||||
const { decryptWithPassword } = require("../../shared/vault");
|
const exportPrivkey = require("./exportPrivkey");
|
||||||
const { getSignerForAddress } = require("../../shared/wallet");
|
const { walletDefect } = require("../../shared/walletDefects");
|
||||||
|
|
||||||
|
// The defect of the wallet the selected address belongs to, or null. Both the
|
||||||
|
// send and the private-key export path check it before asking for a password,
|
||||||
|
// so a wallet that cannot derive its keys says so instead of failing after the
|
||||||
|
// user has typed one in.
|
||||||
|
function selectedWalletDefect() {
|
||||||
|
if (state.selectedWallet === null) return null;
|
||||||
|
return walletDefect(state.wallets[state.selectedWallet]);
|
||||||
|
}
|
||||||
|
|
||||||
let ctx;
|
let ctx;
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
function etherscanAddressLink(address) {
|
|
||||||
return `https://etherscan.io/address/${address}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function show() {
|
function show() {
|
||||||
state.selectedToken = null;
|
state.selectedToken = null;
|
||||||
const wallet = state.wallets[state.selectedWallet];
|
const wallet = state.wallets[state.selectedWallet];
|
||||||
@@ -55,22 +57,18 @@ function show() {
|
|||||||
img.style.imageRendering = "pixelated";
|
img.style.imageRendering = "pixelated";
|
||||||
img.style.borderRadius = "50%";
|
img.style.borderRadius = "50%";
|
||||||
blockieEl.appendChild(img);
|
blockieEl.appendChild(img);
|
||||||
$("address-dot").innerHTML = addressDotHtml(addr.address);
|
const addrTitle = addressTitle(addr.address, state.wallets);
|
||||||
$("address-full").dataset.full = addr.address;
|
$("address-line").innerHTML = renderAddressHtml(addr.address, {
|
||||||
$("address-full").textContent = addr.address;
|
title: addrTitle,
|
||||||
const addrLink = etherscanAddressLink(addr.address);
|
ensName: addr.ensName,
|
||||||
$("address-etherscan-link").innerHTML =
|
});
|
||||||
`<a href="${addrLink}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
$("address-line").dataset.full = addr.address;
|
||||||
|
attachCopyHandlers($("address-line"));
|
||||||
const usdTotal = formatUsd(getAddressValueUsd(addr));
|
const usdTotal = formatUsd(getAddressValueUsd(addr));
|
||||||
$("address-usd-total").innerHTML = usdTotal || " ";
|
$("address-usd-total").innerHTML = usdTotal || " ";
|
||||||
const ensEl = $("address-ens");
|
const ensEl = $("address-ens");
|
||||||
if (addr.ensName) {
|
// ENS is now shown inside renderAddressHtml, hide the separate element
|
||||||
ensEl.innerHTML =
|
ensEl.classList.add("hidden");
|
||||||
addressDotHtml(addr.address) + escapeHtml(addr.ensName);
|
|
||||||
ensEl.classList.remove("hidden");
|
|
||||||
} else {
|
|
||||||
ensEl.classList.add("hidden");
|
|
||||||
}
|
|
||||||
$("address-balances").innerHTML = balanceLinesForAddress(
|
$("address-balances").innerHTML = balanceLinesForAddress(
|
||||||
addr,
|
addr,
|
||||||
state.trackedTokens,
|
state.trackedTokens,
|
||||||
@@ -94,18 +92,39 @@ function show() {
|
|||||||
function isoDate(timestamp) {
|
function isoDate(timestamp) {
|
||||||
const d = new Date(timestamp * 1000);
|
const d = new Date(timestamp * 1000);
|
||||||
const pad = (n) => String(n).padStart(2, "0");
|
const pad = (n) => String(n).padStart(2, "0");
|
||||||
|
if (state.utcTimestamps) {
|
||||||
|
return (
|
||||||
|
d.getUTCFullYear() +
|
||||||
|
"-" +
|
||||||
|
pad(d.getUTCMonth() + 1) +
|
||||||
|
"-" +
|
||||||
|
pad(d.getUTCDate()) +
|
||||||
|
"T" +
|
||||||
|
pad(d.getUTCHours()) +
|
||||||
|
":" +
|
||||||
|
pad(d.getUTCMinutes()) +
|
||||||
|
":" +
|
||||||
|
pad(d.getUTCSeconds()) +
|
||||||
|
"Z"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
const offsetMin = -d.getTimezoneOffset();
|
||||||
|
const sign = offsetMin >= 0 ? "+" : "-";
|
||||||
|
const absOff = Math.abs(offsetMin);
|
||||||
|
const tzStr = sign + pad(Math.floor(absOff / 60)) + ":" + pad(absOff % 60);
|
||||||
return (
|
return (
|
||||||
d.getFullYear() +
|
d.getFullYear() +
|
||||||
"-" +
|
"-" +
|
||||||
pad(d.getMonth() + 1) +
|
pad(d.getMonth() + 1) +
|
||||||
"-" +
|
"-" +
|
||||||
pad(d.getDate()) +
|
pad(d.getDate()) +
|
||||||
" " +
|
"T" +
|
||||||
pad(d.getHours()) +
|
pad(d.getHours()) +
|
||||||
":" +
|
":" +
|
||||||
pad(d.getMinutes()) +
|
pad(d.getMinutes()) +
|
||||||
":" +
|
":" +
|
||||||
pad(d.getSeconds())
|
pad(d.getSeconds()) +
|
||||||
|
tzStr
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -137,6 +156,7 @@ async function loadTransactions(address) {
|
|||||||
state.blockscoutUrl,
|
state.blockscoutUrl,
|
||||||
);
|
);
|
||||||
const result = filterTransactions(rawTxs, {
|
const result = filterTransactions(rawTxs, {
|
||||||
|
hideSpoofedSymbols: state.hideSpoofedSymbols,
|
||||||
hideLowHolderTokens: state.hideLowHolderTokens,
|
hideLowHolderTokens: state.hideLowHolderTokens,
|
||||||
hideFraudContracts: state.hideFraudContracts,
|
hideFraudContracts: state.hideFraudContracts,
|
||||||
hideDustTransactions: state.hideDustTransactions,
|
hideDustTransactions: state.hideDustTransactions,
|
||||||
@@ -236,20 +256,17 @@ function renderTransactions(txs) {
|
|||||||
|
|
||||||
function init(_ctx) {
|
function init(_ctx) {
|
||||||
ctx = _ctx;
|
ctx = _ctx;
|
||||||
$("address-full").addEventListener("click", () => {
|
|
||||||
const addr = $("address-full").dataset.full;
|
|
||||||
if (addr) {
|
|
||||||
navigator.clipboard.writeText(addr);
|
|
||||||
showFlash("Copied!");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-address-back").addEventListener("click", () => {
|
$("btn-address-back").addEventListener("click", () => {
|
||||||
ctx.renderWalletList();
|
goBack();
|
||||||
showView("main");
|
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-send").addEventListener("click", () => {
|
$("btn-send").addEventListener("click", () => {
|
||||||
|
const defect = selectedWalletDefect();
|
||||||
|
if (defect) {
|
||||||
|
showFlash(defect.shortMessage);
|
||||||
|
return;
|
||||||
|
}
|
||||||
const addr =
|
const addr =
|
||||||
state.wallets[state.selectedWallet].addresses[
|
state.wallets[state.selectedWallet].addresses[
|
||||||
state.selectedAddress
|
state.selectedAddress
|
||||||
@@ -264,6 +281,7 @@ function init(_ctx) {
|
|||||||
$("send-token-static").classList.add("hidden");
|
$("send-token-static").classList.add("hidden");
|
||||||
updateSendBalance();
|
updateSendBalance();
|
||||||
resetSendValidation();
|
resetSendValidation();
|
||||||
|
pushCurrentView();
|
||||||
showView("send");
|
showView("send");
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -293,87 +311,20 @@ function init(_ctx) {
|
|||||||
$("btn-export-privkey").addEventListener("click", () => {
|
$("btn-export-privkey").addEventListener("click", () => {
|
||||||
moreDropdown.classList.add("hidden");
|
moreDropdown.classList.add("hidden");
|
||||||
moreBtn.classList.remove("bg-fg", "text-bg");
|
moreBtn.classList.remove("bg-fg", "text-bg");
|
||||||
const wallet = state.wallets[state.selectedWallet];
|
// There is no private key to export for an address this wallet
|
||||||
const addr = wallet.addresses[state.selectedAddress];
|
// cannot derive. Without this the export screen would take a
|
||||||
const blockieEl = $("export-privkey-jazzicon");
|
// password and then report it as wrong.
|
||||||
blockieEl.innerHTML = "";
|
const defect = selectedWalletDefect();
|
||||||
const bImg = document.createElement("img");
|
if (defect) {
|
||||||
bImg.src = makeBlockie(addr.address);
|
showFlash(defect.shortMessage);
|
||||||
bImg.width = 48;
|
|
||||||
bImg.height = 48;
|
|
||||||
bImg.style.imageRendering = "pixelated";
|
|
||||||
bImg.style.borderRadius = "50%";
|
|
||||||
blockieEl.appendChild(bImg);
|
|
||||||
$("export-privkey-title").textContent =
|
|
||||||
wallet.name + " \u2014 Address " + (state.selectedAddress + 1);
|
|
||||||
$("export-privkey-dot").innerHTML = addressDotHtml(addr.address);
|
|
||||||
$("export-privkey-address").textContent = addr.address;
|
|
||||||
$("export-privkey-address").dataset.full = addr.address;
|
|
||||||
$("export-privkey-password").value = "";
|
|
||||||
$("export-privkey-flash").classList.add("hidden");
|
|
||||||
$("export-privkey-flash").textContent = "";
|
|
||||||
$("export-privkey-password-section").classList.remove("hidden");
|
|
||||||
$("export-privkey-result").classList.add("hidden");
|
|
||||||
$("export-privkey-value").textContent = "";
|
|
||||||
showView("export-privkey");
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-export-privkey-confirm").addEventListener("click", async () => {
|
|
||||||
const password = $("export-privkey-password").value;
|
|
||||||
if (!password) {
|
|
||||||
$("export-privkey-flash").textContent = "Password is required.";
|
|
||||||
$("export-privkey-flash").classList.remove("hidden");
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const btn = $("btn-export-privkey-confirm");
|
// No pushCurrentView() here: exportPrivkey.show() can return
|
||||||
btn.disabled = true;
|
// without navigating, so it does its own push.
|
||||||
btn.classList.add("text-muted");
|
exportPrivkey.show(state.selectedWallet, state.selectedAddress);
|
||||||
const wallet = state.wallets[state.selectedWallet];
|
|
||||||
try {
|
|
||||||
const secret = await decryptWithPassword(
|
|
||||||
wallet.encryptedSecret,
|
|
||||||
password,
|
|
||||||
);
|
|
||||||
const signer = getSignerForAddress(
|
|
||||||
wallet,
|
|
||||||
state.selectedAddress,
|
|
||||||
secret,
|
|
||||||
);
|
|
||||||
const privateKey = signer.privateKey;
|
|
||||||
$("export-privkey-password-section").classList.add("hidden");
|
|
||||||
$("export-privkey-value").textContent = privateKey;
|
|
||||||
$("export-privkey-result").classList.remove("hidden");
|
|
||||||
$("export-privkey-flash").classList.add("hidden");
|
|
||||||
} catch {
|
|
||||||
$("export-privkey-flash").textContent = "Wrong password.";
|
|
||||||
$("export-privkey-flash").classList.remove("hidden");
|
|
||||||
} finally {
|
|
||||||
btn.disabled = false;
|
|
||||||
btn.classList.remove("text-muted");
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
|
|
||||||
$("export-privkey-value").addEventListener("click", () => {
|
exportPrivkey.init();
|
||||||
const key = $("export-privkey-value").textContent;
|
|
||||||
if (key) {
|
|
||||||
navigator.clipboard.writeText(key);
|
|
||||||
showFlash("Copied!");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
$("export-privkey-address").addEventListener("click", () => {
|
|
||||||
const full = $("export-privkey-address").dataset.full;
|
|
||||||
if (full) {
|
|
||||||
navigator.clipboard.writeText(full);
|
|
||||||
showFlash("Copied!");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-export-privkey-back").addEventListener("click", () => {
|
|
||||||
$("export-privkey-value").textContent = "";
|
|
||||||
$("export-privkey-password").value = "";
|
|
||||||
show();
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { init, show };
|
module.exports = { init, show };
|
||||||
|
|||||||
@@ -5,11 +5,16 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
addressDotHtml,
|
addressDotHtml,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
truncateMiddle,
|
truncateMiddle,
|
||||||
balanceLine,
|
balanceLine,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
goBack,
|
||||||
|
pushCurrentView,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, currentAddress, saveState } = require("../../shared/state");
|
const { state, currentAddress, saveState } = require("../../shared/state");
|
||||||
const { TOKEN_BY_ADDRESS, resolveSymbol } = require("../../shared/tokenList");
|
const { TOKEN_BY_ADDRESS, resolveSymbol } = require("../../shared/tokenList");
|
||||||
@@ -30,35 +35,46 @@ const {
|
|||||||
} = require("./send");
|
} = require("./send");
|
||||||
const { log } = require("../../shared/log");
|
const { log } = require("../../shared/log");
|
||||||
const makeBlockie = require("ethereum-blockies-base64");
|
const makeBlockie = require("ethereum-blockies-base64");
|
||||||
|
const { walletDefect } = require("../../shared/walletDefects");
|
||||||
|
|
||||||
let ctx;
|
let ctx;
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
function etherscanAddressLink(address) {
|
|
||||||
return `https://etherscan.io/address/${address}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function isoDate(timestamp) {
|
function isoDate(timestamp) {
|
||||||
const d = new Date(timestamp * 1000);
|
const d = new Date(timestamp * 1000);
|
||||||
const pad = (n) => String(n).padStart(2, "0");
|
const pad = (n) => String(n).padStart(2, "0");
|
||||||
|
if (state.utcTimestamps) {
|
||||||
|
return (
|
||||||
|
d.getUTCFullYear() +
|
||||||
|
"-" +
|
||||||
|
pad(d.getUTCMonth() + 1) +
|
||||||
|
"-" +
|
||||||
|
pad(d.getUTCDate()) +
|
||||||
|
"T" +
|
||||||
|
pad(d.getUTCHours()) +
|
||||||
|
":" +
|
||||||
|
pad(d.getUTCMinutes()) +
|
||||||
|
":" +
|
||||||
|
pad(d.getUTCSeconds()) +
|
||||||
|
"Z"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
const offsetMin = -d.getTimezoneOffset();
|
||||||
|
const sign = offsetMin >= 0 ? "+" : "-";
|
||||||
|
const absOff = Math.abs(offsetMin);
|
||||||
|
const tzStr = sign + pad(Math.floor(absOff / 60)) + ":" + pad(absOff % 60);
|
||||||
return (
|
return (
|
||||||
d.getFullYear() +
|
d.getFullYear() +
|
||||||
"-" +
|
"-" +
|
||||||
pad(d.getMonth() + 1) +
|
pad(d.getMonth() + 1) +
|
||||||
"-" +
|
"-" +
|
||||||
pad(d.getDate()) +
|
pad(d.getDate()) +
|
||||||
" " +
|
"T" +
|
||||||
pad(d.getHours()) +
|
pad(d.getHours()) +
|
||||||
":" +
|
":" +
|
||||||
pad(d.getMinutes()) +
|
pad(d.getMinutes()) +
|
||||||
":" +
|
":" +
|
||||||
pad(d.getSeconds())
|
pad(d.getSeconds()) +
|
||||||
|
tzStr
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -126,15 +142,16 @@ function show() {
|
|||||||
blockieEl.appendChild(img);
|
blockieEl.appendChild(img);
|
||||||
|
|
||||||
// Address line
|
// Address line
|
||||||
$("address-token-dot").innerHTML = addressDotHtml(addr.address);
|
const addrTitle = addressTitle(addr.address, state.wallets);
|
||||||
$("address-token-full").dataset.full = addr.address;
|
$("address-token-line").innerHTML = renderAddressHtml(addr.address, {
|
||||||
$("address-token-full").textContent = addr.address;
|
title: addrTitle,
|
||||||
const addrLink = etherscanAddressLink(addr.address);
|
ensName: addr.ensName,
|
||||||
$("address-token-etherscan-link").innerHTML =
|
});
|
||||||
`<a href="${addrLink}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
$("address-token-line").dataset.full = addr.address;
|
||||||
|
attachCopyHandlers($("address-token-line"));
|
||||||
|
|
||||||
// USD total for this token only
|
// USD total for this token only
|
||||||
const usdVal = price ? amount * price : 0;
|
const usdVal = price ? amount * price : null;
|
||||||
const usdStr = formatUsd(usdVal);
|
const usdStr = formatUsd(usdVal);
|
||||||
$("address-token-usd-total").innerHTML = usdStr || " ";
|
$("address-token-usd-total").innerHTML = usdStr || " ";
|
||||||
|
|
||||||
@@ -171,15 +188,9 @@ function show() {
|
|||||||
? knownToken.decimals
|
? knownToken.decimals
|
||||||
: null;
|
: null;
|
||||||
const tokenHolders = tb && tb.holders != null ? tb.holders : null;
|
const tokenHolders = tb && tb.holders != null ? tb.holders : null;
|
||||||
const dot = addressDotHtml(tokenId);
|
|
||||||
const tokenLink = `https://etherscan.io/token/${escapeHtml(tokenId)}`;
|
|
||||||
const projectUrl = knownToken && knownToken.url ? knownToken.url : null;
|
const projectUrl = knownToken && knownToken.url ? knownToken.url : null;
|
||||||
let infoHtml = `<div class="font-bold mb-2">Contract Address</div>`;
|
let infoHtml = `<div class="font-bold mb-2">Contract Address</div>`;
|
||||||
infoHtml +=
|
infoHtml += `<div class="mb-2">${renderAddressHtml(tokenId)}</div>`;
|
||||||
`<div class="flex items-center mb-2">${dot}` +
|
|
||||||
`<span class="break-all underline decoration-dashed cursor-pointer" id="address-token-contract-copy" data-copy="${escapeHtml(tokenId)}">${escapeHtml(tokenId)}</span>` +
|
|
||||||
`<a href="${tokenLink}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>` +
|
|
||||||
`</div>`;
|
|
||||||
if (tokenName)
|
if (tokenName)
|
||||||
infoHtml += `<div class="mb-1"><span class="text-muted">Name:</span> ${tokenName}</div>`;
|
infoHtml += `<div class="mb-1"><span class="text-muted">Name:</span> ${tokenName}</div>`;
|
||||||
if (tokenSymbol)
|
if (tokenSymbol)
|
||||||
@@ -191,6 +202,7 @@ function show() {
|
|||||||
if (projectUrl)
|
if (projectUrl)
|
||||||
infoHtml += `<div class="mb-1"><span class="text-muted">Website:</span> <a href="${escapeHtml(projectUrl)}" target="_blank" rel="noopener" class="underline decoration-dashed">${escapeHtml(projectUrl)}</a></div>`;
|
infoHtml += `<div class="mb-1"><span class="text-muted">Website:</span> <a href="${escapeHtml(projectUrl)}" target="_blank" rel="noopener" class="underline decoration-dashed">${escapeHtml(projectUrl)}</a></div>`;
|
||||||
contractInfo.innerHTML = infoHtml;
|
contractInfo.innerHTML = infoHtml;
|
||||||
|
attachCopyHandlers(contractInfo);
|
||||||
contractInfo.classList.remove("hidden");
|
contractInfo.classList.remove("hidden");
|
||||||
} else {
|
} else {
|
||||||
contractInfo.innerHTML = "";
|
contractInfo.innerHTML = "";
|
||||||
@@ -211,6 +223,7 @@ async function loadTransactions(address, tokenId) {
|
|||||||
state.blockscoutUrl,
|
state.blockscoutUrl,
|
||||||
);
|
);
|
||||||
const result = filterTransactions(rawTxs, {
|
const result = filterTransactions(rawTxs, {
|
||||||
|
hideSpoofedSymbols: state.hideSpoofedSymbols,
|
||||||
hideLowHolderTokens: state.hideLowHolderTokens,
|
hideLowHolderTokens: state.hideLowHolderTokens,
|
||||||
hideFraudContracts: state.hideFraudContracts,
|
hideFraudContracts: state.hideFraudContracts,
|
||||||
hideDustTransactions: state.hideDustTransactions,
|
hideDustTransactions: state.hideDustTransactions,
|
||||||
@@ -312,27 +325,25 @@ function renderTransactions(txs) {
|
|||||||
|
|
||||||
function init(_ctx) {
|
function init(_ctx) {
|
||||||
ctx = _ctx;
|
ctx = _ctx;
|
||||||
$("address-token-full").addEventListener("click", () => {
|
|
||||||
const addr = $("address-token-full").dataset.full;
|
|
||||||
if (addr) {
|
|
||||||
navigator.clipboard.writeText(addr);
|
|
||||||
showFlash("Copied!");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
$("address-token-contract-info").addEventListener("click", (e) => {
|
$("address-token-contract-info").addEventListener("click", (e) => {
|
||||||
const copyEl = e.target.closest("[data-copy]");
|
const copyEl = e.target.closest("[data-copy]");
|
||||||
if (copyEl) {
|
if (copyEl) {
|
||||||
navigator.clipboard.writeText(copyEl.dataset.copy);
|
navigator.clipboard.writeText(copyEl.dataset.copy);
|
||||||
showFlash("Copied!");
|
showFlash("Copied!");
|
||||||
|
flashCopyFeedback(copyEl);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-address-token-back").addEventListener("click", () => {
|
$("btn-address-token-back").addEventListener("click", () => {
|
||||||
ctx.showAddressDetail();
|
goBack();
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-address-token-send").addEventListener("click", () => {
|
$("btn-address-token-send").addEventListener("click", () => {
|
||||||
|
const defect = walletDefect(state.wallets[state.selectedWallet]);
|
||||||
|
if (defect) {
|
||||||
|
showFlash(defect.shortMessage);
|
||||||
|
return;
|
||||||
|
}
|
||||||
const addr =
|
const addr =
|
||||||
state.wallets[state.selectedWallet].addresses[
|
state.wallets[state.selectedWallet].addresses[
|
||||||
state.selectedAddress
|
state.selectedAddress
|
||||||
@@ -356,27 +367,14 @@ function init(_ctx) {
|
|||||||
$("send-token").classList.add("hidden");
|
$("send-token").classList.add("hidden");
|
||||||
let staticHtml = `<div class="font-bold">${escapeHtml(currentSymbol)}</div>`;
|
let staticHtml = `<div class="font-bold">${escapeHtml(currentSymbol)}</div>`;
|
||||||
if (tokenId !== "ETH") {
|
if (tokenId !== "ETH") {
|
||||||
const dot = addressDotHtml(tokenId);
|
staticHtml += `<div class="text-xs">${renderAddressHtml(tokenId)}</div>`;
|
||||||
const link = `https://etherscan.io/token/${tokenId}`;
|
|
||||||
const extLink = `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
|
||||||
staticHtml +=
|
|
||||||
`<div class="flex items-center text-xs">${dot}` +
|
|
||||||
`<span class="break-all underline decoration-dashed cursor-pointer" data-copy="${escapeHtml(tokenId)}">${escapeHtml(tokenId)}</span>` +
|
|
||||||
extLink +
|
|
||||||
`</div>`;
|
|
||||||
}
|
}
|
||||||
$("send-token-static").innerHTML = staticHtml;
|
$("send-token-static").innerHTML = staticHtml;
|
||||||
$("send-token-static").classList.remove("hidden");
|
$("send-token-static").classList.remove("hidden");
|
||||||
// Attach copy handler for the contract address
|
attachCopyHandlers($("send-token-static"));
|
||||||
const copyEl = $("send-token-static").querySelector("[data-copy]");
|
|
||||||
if (copyEl) {
|
|
||||||
copyEl.addEventListener("click", () => {
|
|
||||||
navigator.clipboard.writeText(copyEl.dataset.copy);
|
|
||||||
showFlash("Copied!");
|
|
||||||
});
|
|
||||||
}
|
|
||||||
updateSendBalance();
|
updateSendBalance();
|
||||||
resetSendValidation();
|
resetSendValidation();
|
||||||
|
pushCurrentView();
|
||||||
showView("send");
|
showView("send");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -1,44 +1,40 @@
|
|||||||
const {
|
const {
|
||||||
$,
|
$,
|
||||||
addressDotHtml,
|
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
showView,
|
showView,
|
||||||
showError,
|
showError,
|
||||||
hideError,
|
hideError,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
onViewLeave,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||||
const { formatEther, formatUnits, Interface, toUtf8String } = require("ethers");
|
const {
|
||||||
|
formatEther,
|
||||||
|
formatUnits,
|
||||||
|
getBytes,
|
||||||
|
Interface,
|
||||||
|
toUtf8String,
|
||||||
|
} = require("ethers");
|
||||||
|
const { getPrice, formatUsd } = require("../../shared/prices");
|
||||||
const { ERC20_ABI } = require("../../shared/constants");
|
const { ERC20_ABI } = require("../../shared/constants");
|
||||||
const { TOKEN_BY_ADDRESS } = require("../../shared/tokenList");
|
const { TOKEN_BY_ADDRESS } = require("../../shared/tokenList");
|
||||||
|
const { decryptWithPassword } = require("../../shared/vault");
|
||||||
|
const { getSignerForAddress } = require("../../shared/wallet");
|
||||||
|
const { walletDefect } = require("../../shared/walletDefects");
|
||||||
|
const { getProvider } = require("../../shared/balances");
|
||||||
|
const { describeSigningFailure } = require("../../shared/approvalVerify");
|
||||||
const txStatus = require("./txStatus");
|
const txStatus = require("./txStatus");
|
||||||
const uniswap = require("../../shared/uniswap");
|
const uniswap = require("../../shared/uniswap");
|
||||||
|
|
||||||
const runtime =
|
const runtime =
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
const erc20Iface = new Interface(ERC20_ABI);
|
const erc20Iface = new Interface(ERC20_ABI);
|
||||||
|
|
||||||
function approvalAddressHtml(address) {
|
function approvalAddressHtml(address) {
|
||||||
const dot = addressDotHtml(address);
|
|
||||||
const link = `https://etherscan.io/address/${address}`;
|
|
||||||
const extLink = `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
|
||||||
const title = addressTitle(address, state.wallets);
|
const title = addressTitle(address, state.wallets);
|
||||||
let html = "";
|
return renderAddressHtml(address, { title });
|
||||||
if (title) {
|
|
||||||
html += `<div class="flex items-center font-bold">${dot}${escapeHtml(title)}</div>`;
|
|
||||||
html += `<div class="break-all">${escapeHtml(address)}${extLink}</div>`;
|
|
||||||
} else {
|
|
||||||
html += `<div class="flex items-center">${dot}<span class="break-all">${escapeHtml(address)}</span>${extLink}</div>`;
|
|
||||||
}
|
|
||||||
return html;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function formatTxValue(val) {
|
function formatTxValue(val) {
|
||||||
@@ -53,10 +49,6 @@ function tokenLabel(address) {
|
|||||||
return t ? t.symbol : null;
|
return t ? t.symbol : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
function etherscanTokenLink(address) {
|
|
||||||
return `https://etherscan.io/token/${address}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Try to decode calldata using known ABIs.
|
// Try to decode calldata using known ABIs.
|
||||||
// Returns { name, description, details } or null.
|
// Returns { name, description, details } or null.
|
||||||
function decodeCalldata(data, toAddress) {
|
function decodeCalldata(data, toAddress) {
|
||||||
@@ -155,7 +147,26 @@ function decodeCalldata(data, toAddress) {
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function showPhishingWarning(elementId, isPhishing) {
|
||||||
|
const el = $(elementId);
|
||||||
|
if (!el) return;
|
||||||
|
// The background script performs the authoritative phishing domain check
|
||||||
|
// and passes the result via the isPhishingDomain flag.
|
||||||
|
if (isPhishing) {
|
||||||
|
el.classList.remove("hidden");
|
||||||
|
} else {
|
||||||
|
el.classList.add("hidden");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
function showTxApproval(details) {
|
function showTxApproval(details) {
|
||||||
|
showPhishingWarning(
|
||||||
|
"approve-tx-phishing-warning",
|
||||||
|
details.isPhishingDomain,
|
||||||
|
);
|
||||||
|
|
||||||
|
pendingTxParams = details.txParams;
|
||||||
|
|
||||||
const toAddr = details.txParams.to;
|
const toAddr = details.txParams.to;
|
||||||
const token = toAddr ? TOKEN_BY_ADDRESS.get(toAddr.toLowerCase()) : null;
|
const token = toAddr ? TOKEN_BY_ADDRESS.get(toAddr.toLowerCase()) : null;
|
||||||
const ethValue = formatEther(details.txParams.value || "0");
|
const ethValue = formatEther(details.txParams.value || "0");
|
||||||
@@ -218,17 +229,19 @@ function showTxApproval(details) {
|
|||||||
toHtml += `<div class="font-bold mb-1">${escapeHtml(symbol)}</div>`;
|
toHtml += `<div class="font-bold mb-1">${escapeHtml(symbol)}</div>`;
|
||||||
}
|
}
|
||||||
toHtml += approvalAddressHtml(toAddr);
|
toHtml += approvalAddressHtml(toAddr);
|
||||||
if (symbol) {
|
|
||||||
const link = etherscanTokenLink(toAddr);
|
|
||||||
toHtml = toHtml.replace("</div>", "") + ""; // approvalAddressHtml already has etherscan link
|
|
||||||
}
|
|
||||||
$("approve-tx-to").innerHTML = toHtml;
|
$("approve-tx-to").innerHTML = toHtml;
|
||||||
} else {
|
} else {
|
||||||
$("approve-tx-to").innerHTML = escapeHtml("(contract creation)");
|
$("approve-tx-to").innerHTML = escapeHtml("(contract creation)");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const ethValueFormatted = formatTxValue(
|
||||||
|
formatEther(details.txParams.value || "0"),
|
||||||
|
);
|
||||||
|
const ethPrice = getPrice("ETH");
|
||||||
|
const ethUsd = ethPrice ? parseFloat(ethValueFormatted) * ethPrice : null;
|
||||||
|
const usdStr = formatUsd(ethUsd);
|
||||||
$("approve-tx-value").textContent =
|
$("approve-tx-value").textContent =
|
||||||
formatTxValue(formatEther(details.txParams.value || "0")) + " ETH";
|
ethValueFormatted + " ETH" + (usdStr ? " (" + usdStr + ")" : "");
|
||||||
|
|
||||||
// Decode calldata (reuse decoded from above)
|
// Decode calldata (reuse decoded from above)
|
||||||
const decodedEl = $("approve-tx-decoded");
|
const decodedEl = $("approve-tx-decoded");
|
||||||
@@ -243,12 +256,9 @@ function showTxApproval(details) {
|
|||||||
detailsHtml += `<div class="text-muted">${escapeHtml(d.label)}</div>`;
|
detailsHtml += `<div class="text-muted">${escapeHtml(d.label)}</div>`;
|
||||||
if (d.address) {
|
if (d.address) {
|
||||||
if (d.isToken) {
|
if (d.isToken) {
|
||||||
const tLink = etherscanTokenLink(d.address);
|
|
||||||
detailsHtml += `<div class="font-bold">${escapeHtml(tokenLabel(d.address) || "Unknown token")}</div>`;
|
detailsHtml += `<div class="font-bold">${escapeHtml(tokenLabel(d.address) || "Unknown token")}</div>`;
|
||||||
detailsHtml += approvalAddressHtml(d.address);
|
|
||||||
} else {
|
|
||||||
detailsHtml += approvalAddressHtml(d.address);
|
|
||||||
}
|
}
|
||||||
|
detailsHtml += approvalAddressHtml(d.address);
|
||||||
} else {
|
} else {
|
||||||
detailsHtml += `<div class="font-bold">${escapeHtml(d.value)}</div>`;
|
detailsHtml += `<div class="font-bold">${escapeHtml(d.value)}</div>`;
|
||||||
}
|
}
|
||||||
@@ -269,9 +279,11 @@ function showTxApproval(details) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
$("approve-tx-password").value = "";
|
$("approve-tx-password").value = "";
|
||||||
$("approve-tx-error").classList.add("hidden");
|
hideError("approve-tx-error");
|
||||||
|
|
||||||
showView("approve-tx");
|
showView("approve-tx");
|
||||||
|
attachCopyHandlers("view-approve-tx");
|
||||||
|
gateOnWalletDefect("approve-tx-error", "btn-approve-tx");
|
||||||
}
|
}
|
||||||
|
|
||||||
function decodeHexMessage(hex) {
|
function decodeHexMessage(hex) {
|
||||||
@@ -323,7 +335,13 @@ function formatTypedDataHtml(jsonStr) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function showSignApproval(details) {
|
function showSignApproval(details) {
|
||||||
|
showPhishingWarning(
|
||||||
|
"approve-sign-phishing-warning",
|
||||||
|
details.isPhishingDomain,
|
||||||
|
);
|
||||||
|
|
||||||
const sp = details.signParams;
|
const sp = details.signParams;
|
||||||
|
pendingSignParams = sp;
|
||||||
|
|
||||||
$("approve-sign-hostname").textContent = details.hostname;
|
$("approve-sign-hostname").textContent = details.hostname;
|
||||||
$("approve-sign-from").innerHTML = approvalAddressHtml(sp.from);
|
$("approve-sign-from").innerHTML = approvalAddressHtml(sp.from);
|
||||||
@@ -351,10 +369,10 @@ function showSignApproval(details) {
|
|||||||
if (warningEl) {
|
if (warningEl) {
|
||||||
if (sp.dangerWarning) {
|
if (sp.dangerWarning) {
|
||||||
warningEl.textContent = sp.dangerWarning;
|
warningEl.textContent = sp.dangerWarning;
|
||||||
warningEl.classList.remove("hidden");
|
warningEl.style.visibility = "visible";
|
||||||
} else {
|
} else {
|
||||||
warningEl.textContent = "";
|
warningEl.textContent = "";
|
||||||
warningEl.classList.add("hidden");
|
warningEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -364,6 +382,8 @@ function showSignApproval(details) {
|
|||||||
$("btn-approve-sign").classList.remove("text-muted");
|
$("btn-approve-sign").classList.remove("text-muted");
|
||||||
|
|
||||||
showView("approve-sign");
|
showView("approve-sign");
|
||||||
|
attachCopyHandlers("view-approve-sign");
|
||||||
|
gateOnWalletDefect("approve-sign-error", "btn-approve-sign");
|
||||||
}
|
}
|
||||||
|
|
||||||
function show(id) {
|
function show(id) {
|
||||||
@@ -382,18 +402,85 @@ function show(id) {
|
|||||||
showSignApproval(details);
|
showSignApproval(details);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
// Site connection approval
|
||||||
|
showPhishingWarning(
|
||||||
|
"approve-site-phishing-warning",
|
||||||
|
details.isPhishingDomain,
|
||||||
|
);
|
||||||
$("approve-hostname").textContent = details.hostname;
|
$("approve-hostname").textContent = details.hostname;
|
||||||
$("approve-address").innerHTML = approvalAddressHtml(
|
$("approve-address").innerHTML = approvalAddressHtml(
|
||||||
state.activeAddress,
|
state.activeAddress,
|
||||||
);
|
);
|
||||||
|
attachCopyHandlers("view-approve-site");
|
||||||
$("approve-remember").checked = state.rememberSiteChoice;
|
$("approve-remember").checked = state.rememberSiteChoice;
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
let approvalId = null;
|
let approvalId = null;
|
||||||
let pendingTxDetails = null;
|
let pendingTxDetails = null;
|
||||||
|
// The exact parameters shown to the user, kept so the popup signs what it
|
||||||
|
// displayed rather than re-fetching anything at approval time. Both are
|
||||||
|
// repopulated by show() when the popup is closed and reopened.
|
||||||
|
let pendingTxParams = null;
|
||||||
|
let pendingSignParams = null;
|
||||||
|
|
||||||
|
// Approve buttons stay disabled and muted while the popup derives the key and
|
||||||
|
// signs, which is slow enough (Argon2id) that a double click is likely.
|
||||||
|
function setTxButtonBusy(busy) {
|
||||||
|
$("btn-approve-tx").disabled = busy;
|
||||||
|
$("btn-approve-tx").classList.toggle("text-muted", busy);
|
||||||
|
}
|
||||||
|
|
||||||
|
function setSignButtonBusy(busy) {
|
||||||
|
$("btn-approve-sign").disabled = busy;
|
||||||
|
$("btn-approve-sign").classList.toggle("text-muted", busy);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Say so on the approval screen itself, and disable the approve button, when
|
||||||
|
// the active address belongs to a wallet whose keys cannot be derived. Without
|
||||||
|
// this the screen would take a password and fail after deriving it. Reject
|
||||||
|
// stays available; the wallet is not touched. Returns true when it gated.
|
||||||
|
function gateOnWalletDefect(errorId, buttonId) {
|
||||||
|
const active = findActiveWallet();
|
||||||
|
const defect = active ? walletDefect(active.wallet) : null;
|
||||||
|
if (!defect) return false;
|
||||||
|
showError(errorId, defect.shortMessage);
|
||||||
|
$(buttonId).disabled = true;
|
||||||
|
$(buttonId).classList.add("text-muted");
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Locate the wallet and the address index owning the currently active
|
||||||
|
// address. Returns null when no wallet holds it.
|
||||||
|
function findActiveWallet() {
|
||||||
|
for (const wallet of state.wallets) {
|
||||||
|
for (let i = 0; i < wallet.addresses.length; i++) {
|
||||||
|
if (wallet.addresses[i].address === state.activeAddress) {
|
||||||
|
return { wallet, addrIndex: i };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Drop the password from the DOM when either approval screen is left. The
|
||||||
|
// approval window navigates on after a signature — approve-tx goes to the
|
||||||
|
// wait screen — and the password must not sit in the hidden view for the
|
||||||
|
// life of that window.
|
||||||
|
function clearTxPassword() {
|
||||||
|
$("approve-tx-password").value = "";
|
||||||
|
hideError("approve-tx-error");
|
||||||
|
}
|
||||||
|
|
||||||
|
function clearSignPassword() {
|
||||||
|
$("approve-sign-password").value = "";
|
||||||
|
hideError("approve-sign-error");
|
||||||
|
}
|
||||||
|
|
||||||
function init(ctx) {
|
function init(ctx) {
|
||||||
|
onViewLeave("approve-tx", clearTxPassword);
|
||||||
|
onViewLeave("approve-sign", clearSignPassword);
|
||||||
|
|
||||||
$("approve-remember").addEventListener("change", async () => {
|
$("approve-remember").addEventListener("change", async () => {
|
||||||
state.rememberSiteChoice = $("approve-remember").checked;
|
state.rememberSiteChoice = $("approve-remember").checked;
|
||||||
await saveState();
|
await saveState();
|
||||||
@@ -421,34 +508,104 @@ function init(ctx) {
|
|||||||
window.close();
|
window.close();
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-approve-tx").addEventListener("click", () => {
|
$("btn-approve-tx").addEventListener("click", async () => {
|
||||||
const password = $("approve-tx-password").value;
|
let password = $("approve-tx-password").value;
|
||||||
if (!password) {
|
if (!password) {
|
||||||
showError("approve-tx-error", "Please enter your password.");
|
showError("approve-tx-error", "Please enter your password.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
hideError("approve-tx-error");
|
hideError("approve-tx-error");
|
||||||
$("btn-approve-tx").disabled = true;
|
setTxButtonBusy(true);
|
||||||
$("btn-approve-tx").classList.add("text-muted");
|
|
||||||
|
|
||||||
runtime.sendMessage(
|
const active = findActiveWallet();
|
||||||
{
|
if (!active) {
|
||||||
type: "AUTISTMASK_TX_RESPONSE",
|
password = null;
|
||||||
id: approvalId,
|
showError(
|
||||||
approved: true,
|
"approve-tx-error",
|
||||||
// TODO(security): Move decryption to popup to avoid sending password via runtime.sendMessage
|
"No wallet was found for the active address.",
|
||||||
password: password,
|
);
|
||||||
},
|
setTxButtonBusy(false);
|
||||||
(response) => {
|
return;
|
||||||
if (response && response.txHash) {
|
}
|
||||||
txStatus.showWait(pendingTxDetails, response.txHash);
|
|
||||||
} else {
|
const defect = walletDefect(active.wallet);
|
||||||
const msg =
|
if (defect) {
|
||||||
(response && response.error) || "Transaction failed.";
|
password = null;
|
||||||
txStatus.showError(pendingTxDetails, null, msg);
|
showError("approve-tx-error", defect.shortMessage);
|
||||||
}
|
setTxButtonBusy(false);
|
||||||
},
|
return;
|
||||||
);
|
}
|
||||||
|
|
||||||
|
// Decrypt here, in the popup. The password must never cross the
|
||||||
|
// extension messaging boundary; only the signed transaction does.
|
||||||
|
let decryptedSecret;
|
||||||
|
try {
|
||||||
|
decryptedSecret = await decryptWithPassword(
|
||||||
|
active.wallet.encryptedSecret,
|
||||||
|
password,
|
||||||
|
);
|
||||||
|
} catch {
|
||||||
|
showError(
|
||||||
|
"approve-tx-error",
|
||||||
|
"That password is incorrect. Please try again.",
|
||||||
|
);
|
||||||
|
setTxButtonBusy(false);
|
||||||
|
return;
|
||||||
|
} finally {
|
||||||
|
// Best-effort: drop the password as soon as the key derivation
|
||||||
|
// is done. Note that JS strings are immutable; this clears the
|
||||||
|
// reference but the original string may persist until GC.
|
||||||
|
password = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
const payload = {
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id: approvalId,
|
||||||
|
approved: true,
|
||||||
|
};
|
||||||
|
try {
|
||||||
|
const signer = getSignerForAddress(
|
||||||
|
active.wallet,
|
||||||
|
active.addrIndex,
|
||||||
|
decryptedSecret,
|
||||||
|
);
|
||||||
|
const provider = getProvider(state.rpcUrl);
|
||||||
|
const connected = signer.connect(provider);
|
||||||
|
// This is the sequence ethers' own sendTransaction() runs
|
||||||
|
// internally, so nonce, gas, fee and chain id population are
|
||||||
|
// identical to when the background did the signing.
|
||||||
|
const populated =
|
||||||
|
await connected.populateTransaction(pendingTxParams);
|
||||||
|
delete populated.from;
|
||||||
|
payload.rawSignedTx = await connected.signTransaction(populated);
|
||||||
|
} catch (e) {
|
||||||
|
payload.error =
|
||||||
|
e.shortMessage || e.message || "Transaction signing failed.";
|
||||||
|
} finally {
|
||||||
|
// Best-effort: clear the decrypted secret after use, with the
|
||||||
|
// same immutability caveat as the password above.
|
||||||
|
decryptedSecret = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
runtime.sendMessage(payload, (response) => {
|
||||||
|
if (response && response.txHash) {
|
||||||
|
txStatus.showWait(pendingTxDetails, response.txHash);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
// A retryable failure leaves the approval pending in the
|
||||||
|
// background, so stay on this screen with a live button rather
|
||||||
|
// than sending the user to a dead end.
|
||||||
|
const outcome = describeSigningFailure(
|
||||||
|
response,
|
||||||
|
"The transaction could not be sent.",
|
||||||
|
);
|
||||||
|
if (outcome.retryable) {
|
||||||
|
showError("approve-tx-error", outcome.message);
|
||||||
|
setTxButtonBusy(false);
|
||||||
|
} else {
|
||||||
|
txStatus.showError(pendingTxDetails, null, outcome.message);
|
||||||
|
}
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-reject-tx").addEventListener("click", () => {
|
$("btn-reject-tx").addEventListener("click", () => {
|
||||||
@@ -460,36 +617,108 @@ function init(ctx) {
|
|||||||
window.close();
|
window.close();
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-approve-sign").addEventListener("click", () => {
|
$("btn-approve-sign").addEventListener("click", async () => {
|
||||||
const password = $("approve-sign-password").value;
|
let password = $("approve-sign-password").value;
|
||||||
if (!password) {
|
if (!password) {
|
||||||
showError("approve-sign-error", "Please enter your password.");
|
showError("approve-sign-error", "Please enter your password.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
hideError("approve-sign-error");
|
hideError("approve-sign-error");
|
||||||
$("btn-approve-sign").disabled = true;
|
setSignButtonBusy(true);
|
||||||
$("btn-approve-sign").classList.add("text-muted");
|
|
||||||
|
|
||||||
runtime.sendMessage(
|
const active = findActiveWallet();
|
||||||
{
|
if (!active) {
|
||||||
type: "AUTISTMASK_SIGN_RESPONSE",
|
password = null;
|
||||||
id: approvalId,
|
showError(
|
||||||
approved: true,
|
"approve-sign-error",
|
||||||
// TODO(security): Move decryption to popup to avoid sending password via runtime.sendMessage
|
"No wallet was found for the active address.",
|
||||||
password: password,
|
);
|
||||||
},
|
setSignButtonBusy(false);
|
||||||
(response) => {
|
return;
|
||||||
if (response && response.signature) {
|
}
|
||||||
window.close();
|
|
||||||
} else {
|
const defect = walletDefect(active.wallet);
|
||||||
const msg =
|
if (defect) {
|
||||||
(response && response.error) || "Signing failed.";
|
password = null;
|
||||||
showError("approve-sign-error", msg);
|
showError("approve-sign-error", defect.shortMessage);
|
||||||
$("btn-approve-sign").disabled = false;
|
setSignButtonBusy(false);
|
||||||
$("btn-approve-sign").classList.remove("text-muted");
|
return;
|
||||||
}
|
}
|
||||||
},
|
|
||||||
);
|
// Decrypt here, in the popup. The password must never cross the
|
||||||
|
// extension messaging boundary; only the signature does.
|
||||||
|
let decryptedSecret;
|
||||||
|
try {
|
||||||
|
decryptedSecret = await decryptWithPassword(
|
||||||
|
active.wallet.encryptedSecret,
|
||||||
|
password,
|
||||||
|
);
|
||||||
|
} catch {
|
||||||
|
showError(
|
||||||
|
"approve-sign-error",
|
||||||
|
"That password is incorrect. Please try again.",
|
||||||
|
);
|
||||||
|
setSignButtonBusy(false);
|
||||||
|
return;
|
||||||
|
} finally {
|
||||||
|
// Best-effort: drop the password as soon as the key derivation
|
||||||
|
// is done. Note that JS strings are immutable; this clears the
|
||||||
|
// reference but the original string may persist until GC.
|
||||||
|
password = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
const payload = {
|
||||||
|
type: "AUTISTMASK_SIGN_RESPONSE",
|
||||||
|
id: approvalId,
|
||||||
|
approved: true,
|
||||||
|
};
|
||||||
|
try {
|
||||||
|
const signer = getSignerForAddress(
|
||||||
|
active.wallet,
|
||||||
|
active.addrIndex,
|
||||||
|
decryptedSecret,
|
||||||
|
);
|
||||||
|
const sp = pendingSignParams;
|
||||||
|
if (sp.method === "personal_sign" || sp.method === "eth_sign") {
|
||||||
|
payload.signature = await signer.signMessage(
|
||||||
|
getBytes(sp.message),
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
// eth_signTypedData_v4 / eth_signTypedData
|
||||||
|
const typedData = JSON.parse(sp.typedData);
|
||||||
|
const { domain, types, message } = typedData;
|
||||||
|
// ethers handles EIP712Domain internally
|
||||||
|
delete types.EIP712Domain;
|
||||||
|
payload.signature = await signer.signTypedData(
|
||||||
|
domain,
|
||||||
|
types,
|
||||||
|
message,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
payload.error = e.shortMessage || e.message || "Signing failed.";
|
||||||
|
} finally {
|
||||||
|
// Best-effort: clear the decrypted secret after use, with the
|
||||||
|
// same immutability caveat as the password above.
|
||||||
|
decryptedSecret = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
runtime.sendMessage(payload, (response) => {
|
||||||
|
if (response && response.signature) {
|
||||||
|
window.close();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
// The button comes back only when the approval is still pending in
|
||||||
|
// the background; otherwise it stays disabled and the message says
|
||||||
|
// why, because a control that cannot succeed must not look like it
|
||||||
|
// can.
|
||||||
|
const outcome = describeSigningFailure(
|
||||||
|
response,
|
||||||
|
"The message could not be signed.",
|
||||||
|
);
|
||||||
|
showError("approve-sign-error", outcome.message);
|
||||||
|
if (outcome.retryable) setSignButtonBusy(false);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-reject-sign").addEventListener("click", () => {
|
$("btn-reject-sign").addEventListener("click", () => {
|
||||||
|
|||||||
@@ -15,29 +15,42 @@ const {
|
|||||||
hideError,
|
hideError,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
addressDotHtml,
|
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
goBack,
|
||||||
|
onViewLeave,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state } = require("../../shared/state");
|
const { state, currentNetwork } = require("../../shared/state");
|
||||||
const { getSignerForAddress } = require("../../shared/wallet");
|
const { getSignerForAddress } = require("../../shared/wallet");
|
||||||
const { decryptWithPassword } = require("../../shared/vault");
|
const { decryptWithPassword } = require("../../shared/vault");
|
||||||
const { formatUsd, getPrice } = require("../../shared/prices");
|
const { formatUsd, getPrice } = require("../../shared/prices");
|
||||||
const { getProvider } = require("../../shared/balances");
|
const { getProvider } = require("../../shared/balances");
|
||||||
const { isScamAddress } = require("../../shared/scamlist");
|
const {
|
||||||
const { ERC20_ABI } = require("../../shared/constants");
|
getLocalWarnings,
|
||||||
|
getFullWarnings,
|
||||||
|
} = require("../../shared/addressWarnings");
|
||||||
|
const { ERC20_ABI, isBurnAddress } = require("../../shared/constants");
|
||||||
|
const {
|
||||||
|
CODES,
|
||||||
|
FEE_PENDING,
|
||||||
|
FEE_KNOWN,
|
||||||
|
FEE_UNAVAILABLE,
|
||||||
|
feeReserveWei,
|
||||||
|
feeEstimateWei,
|
||||||
|
validateTransfer,
|
||||||
|
} = require("../../shared/txValidation");
|
||||||
const { log } = require("../../shared/log");
|
const { log } = require("../../shared/log");
|
||||||
const makeBlockie = require("ethereum-blockies-base64");
|
const makeBlockie = require("ethereum-blockies-base64");
|
||||||
const txStatus = require("./txStatus");
|
const txStatus = require("./txStatus");
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
let pendingTx = null;
|
let pendingTx = null;
|
||||||
|
// Network fee for the transaction currently on screen. Reset by show() and
|
||||||
|
// filled in by estimateGas() when the estimate resolves or fails.
|
||||||
|
let feeStatus = FEE_PENDING;
|
||||||
|
let feeWei = null;
|
||||||
|
|
||||||
function restore() {
|
function restore() {
|
||||||
const d = state.viewData;
|
const d = state.viewData;
|
||||||
@@ -46,14 +59,6 @@ function restore() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function etherscanTokenLink(address) {
|
|
||||||
return `https://etherscan.io/token/${address}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function etherscanAddressLink(address) {
|
|
||||||
return `https://etherscan.io/address/${address}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function blockieHtml(address) {
|
function blockieHtml(address) {
|
||||||
const src = makeBlockie(address);
|
const src = makeBlockie(address);
|
||||||
return `<img src="${src}" width="48" height="48" style="image-rendering:pixelated;border-radius:50%;display:inline-block">`;
|
return `<img src="${src}" width="48" height="48" style="image-rendering:pixelated;border-radius:50%;display:inline-block">`;
|
||||||
@@ -61,22 +66,10 @@ function blockieHtml(address) {
|
|||||||
|
|
||||||
function confirmAddressHtml(address, ensName, title) {
|
function confirmAddressHtml(address, ensName, title) {
|
||||||
const blockie = blockieHtml(address);
|
const blockie = blockieHtml(address);
|
||||||
const dot = addressDotHtml(address);
|
return (
|
||||||
const link = etherscanAddressLink(address);
|
`<div class="mb-1">${blockie}</div>` +
|
||||||
const extLink = `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
renderAddressHtml(address, { title, ensName })
|
||||||
let html = `<div class="mb-1">${blockie}</div>`;
|
);
|
||||||
if (title) {
|
|
||||||
html += `<div class="flex items-center font-bold">${dot}${escapeHtml(title)}</div>`;
|
|
||||||
}
|
|
||||||
if (ensName) {
|
|
||||||
html += `<div class="flex items-center font-bold">${title ? "" : dot}${escapeHtml(ensName)}</div>`;
|
|
||||||
}
|
|
||||||
html +=
|
|
||||||
`<div class="flex items-center">${title || ensName ? "" : dot}` +
|
|
||||||
`<span class="break-all">${escapeHtml(address)}</span>` +
|
|
||||||
extLink +
|
|
||||||
`</div>`;
|
|
||||||
return html;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function valueWithUsd(text, usdAmount) {
|
function valueWithUsd(text, usdAmount) {
|
||||||
@@ -88,6 +81,8 @@ function valueWithUsd(text, usdAmount) {
|
|||||||
|
|
||||||
function show(txInfo) {
|
function show(txInfo) {
|
||||||
pendingTx = txInfo;
|
pendingTx = txInfo;
|
||||||
|
feeStatus = FEE_PENDING;
|
||||||
|
feeWei = null;
|
||||||
|
|
||||||
const isErc20 = txInfo.token !== "ETH";
|
const isErc20 = txInfo.token !== "ETH";
|
||||||
const symbol = isErc20 ? txInfo.tokenSymbol || "?" : "ETH";
|
const symbol = isErc20 ? txInfo.tokenSymbol || "?" : "ETH";
|
||||||
@@ -103,22 +98,12 @@ function show(txInfo) {
|
|||||||
// Token contract section (ERC-20 only)
|
// Token contract section (ERC-20 only)
|
||||||
const tokenSection = $("confirm-token-section");
|
const tokenSection = $("confirm-token-section");
|
||||||
if (isErc20) {
|
if (isErc20) {
|
||||||
const dot = addressDotHtml(txInfo.token);
|
$("confirm-token-contract").innerHTML = renderAddressHtml(
|
||||||
const link = etherscanTokenLink(txInfo.token);
|
txInfo.token,
|
||||||
$("confirm-token-contract").innerHTML =
|
{},
|
||||||
`<div class="flex items-center">${dot}` +
|
);
|
||||||
`<span class="break-all underline decoration-dashed cursor-pointer" data-copy="${escapeHtml(txInfo.token)}">${escapeHtml(txInfo.token)}</span>` +
|
|
||||||
`<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>` +
|
|
||||||
`</div>`;
|
|
||||||
tokenSection.classList.remove("hidden");
|
tokenSection.classList.remove("hidden");
|
||||||
// Attach click-to-copy on the contract address
|
attachCopyHandlers(tokenSection);
|
||||||
const copyEl = tokenSection.querySelector("[data-copy]");
|
|
||||||
if (copyEl) {
|
|
||||||
copyEl.onclick = () => {
|
|
||||||
navigator.clipboard.writeText(copyEl.dataset.copy);
|
|
||||||
showFlash("Copied!");
|
|
||||||
};
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
tokenSection.classList.add("hidden");
|
tokenSection.classList.add("hidden");
|
||||||
}
|
}
|
||||||
@@ -165,51 +150,100 @@ function show(txInfo) {
|
|||||||
$("confirm-balance").textContent = valueWithUsd(bal + " ETH", balUsd);
|
$("confirm-balance").textContent = valueWithUsd(bal + " ETH", balUsd);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check for warnings
|
// Check for warnings (synchronous local checks)
|
||||||
const warnings = [];
|
const localWarnings = getLocalWarnings(txInfo.to, {
|
||||||
if (isScamAddress(txInfo.to)) {
|
fromAddress: txInfo.from,
|
||||||
warnings.push(
|
});
|
||||||
"This address is on a known scam/fraud list. Do not send funds to this address.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (txInfo.to.toLowerCase() === txInfo.from.toLowerCase()) {
|
|
||||||
warnings.push("You are sending to your own address.");
|
|
||||||
}
|
|
||||||
|
|
||||||
const warningsEl = $("confirm-warnings");
|
const warningsEl = $("confirm-warnings");
|
||||||
if (warnings.length > 0) {
|
if (localWarnings.length > 0) {
|
||||||
warningsEl.innerHTML = warnings
|
warningsEl.innerHTML = localWarnings
|
||||||
.map(
|
.map(
|
||||||
(w) =>
|
(w) =>
|
||||||
`<div class="border border-border border-dashed p-2 mb-1 text-xs font-bold">WARNING: ${w}</div>`,
|
`<div class="border border-border border-dashed p-2 mb-1 text-xs font-bold">WARNING: ${w.message}</div>`,
|
||||||
)
|
)
|
||||||
.join("");
|
.join("");
|
||||||
warningsEl.classList.remove("hidden");
|
warningsEl.style.visibility = "visible";
|
||||||
} else {
|
} else {
|
||||||
warningsEl.classList.add("hidden");
|
warningsEl.innerHTML = "";
|
||||||
|
warningsEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check for errors
|
// The two fee messages are mutually exclusive per transaction type, and
|
||||||
const errors = [];
|
// the type is known here, before the first paint. Drop the one that can
|
||||||
if (isErc20) {
|
// never apply and reserve the space of the one that can, so the async
|
||||||
const tokenBal = parseFloat(txInfo.tokenBalance || "0");
|
// estimate landing later never moves anything.
|
||||||
if (parseFloat(txInfo.amount) > tokenBal) {
|
$("confirm-amount-fee-error").classList.toggle("hidden", isErc20);
|
||||||
errors.push(
|
$("confirm-gas-error").classList.toggle("hidden", !isErc20);
|
||||||
"Insufficient " +
|
|
||||||
symbol +
|
renderValidation(txInfo);
|
||||||
" balance. You have " +
|
|
||||||
txInfo.tokenBalance +
|
// Reset password field and error
|
||||||
" " +
|
$("confirm-tx-password").value = "";
|
||||||
symbol +
|
hideError("confirm-tx-password-error");
|
||||||
" but are trying to send " +
|
|
||||||
txInfo.amount +
|
// Gas estimate — show placeholder then fetch async
|
||||||
" " +
|
$("confirm-fee").style.visibility = "visible";
|
||||||
symbol +
|
$("confirm-fee-amount").textContent = "Estimating...";
|
||||||
".",
|
setVisible("confirm-fee-reserve", false);
|
||||||
);
|
state.viewData = { pendingTx: txInfo };
|
||||||
}
|
showView("confirm-tx");
|
||||||
} else if (parseFloat(txInfo.amount) > parseFloat(txInfo.balance)) {
|
attachCopyHandlers("view-confirm-tx");
|
||||||
errors.push(
|
|
||||||
|
// Reset async warnings to hidden (space always reserved, no layout shift)
|
||||||
|
$("confirm-recipient-warning").style.visibility = "hidden";
|
||||||
|
$("confirm-contract-warning").style.visibility = "hidden";
|
||||||
|
$("confirm-burn-warning").style.visibility = "hidden";
|
||||||
|
$("confirm-etherscan-warning").style.visibility = "hidden";
|
||||||
|
|
||||||
|
// Show burn warning via reserved element (in addition to inline warning)
|
||||||
|
if (isBurnAddress(txInfo.to)) {
|
||||||
|
$("confirm-burn-warning").style.visibility = "visible";
|
||||||
|
}
|
||||||
|
|
||||||
|
estimateGas(txInfo);
|
||||||
|
checkRecipientHistory(txInfo);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Render the balance check for the transaction on screen. Called once during
|
||||||
|
// show() and again when the fee estimate resolves or fails. Every element it
|
||||||
|
// touches already occupies its space, so re-running it never moves anything.
|
||||||
|
function renderValidation(txInfo) {
|
||||||
|
const isErc20 = txInfo.token !== "ETH";
|
||||||
|
const symbol = isErc20 ? txInfo.tokenSymbol || "?" : "ETH";
|
||||||
|
|
||||||
|
const { canSend, codes } = validateTransfer({
|
||||||
|
isErc20,
|
||||||
|
amount: txInfo.amount,
|
||||||
|
ethBalance: txInfo.balance,
|
||||||
|
tokenBalance: txInfo.tokenBalance,
|
||||||
|
feeStatus,
|
||||||
|
feeWei,
|
||||||
|
});
|
||||||
|
|
||||||
|
// Messages carrying the user's own numbers are built here; the fixed
|
||||||
|
// sentences live in the reserved elements in index.html.
|
||||||
|
const messages = [];
|
||||||
|
if (codes.includes(CODES.AMOUNT_INVALID)) {
|
||||||
|
messages.push("Please enter a valid amount to send.");
|
||||||
|
}
|
||||||
|
if (codes.includes(CODES.INSUFFICIENT_TOKEN)) {
|
||||||
|
messages.push(
|
||||||
|
"Insufficient " +
|
||||||
|
symbol +
|
||||||
|
" balance. You have " +
|
||||||
|
txInfo.tokenBalance +
|
||||||
|
" " +
|
||||||
|
symbol +
|
||||||
|
" but are trying to send " +
|
||||||
|
txInfo.amount +
|
||||||
|
" " +
|
||||||
|
symbol +
|
||||||
|
".",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (codes.includes(CODES.INSUFFICIENT_ETH)) {
|
||||||
|
messages.push(
|
||||||
"Insufficient balance. You have " +
|
"Insufficient balance. You have " +
|
||||||
txInfo.balance +
|
txInfo.balance +
|
||||||
" ETH but are trying to send " +
|
" ETH but are trying to send " +
|
||||||
@@ -219,38 +253,53 @@ function show(txInfo) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const errorsEl = $("confirm-errors");
|
const errorsEl = $("confirm-errors");
|
||||||
const sendBtn = $("btn-confirm-send");
|
if (messages.length > 0) {
|
||||||
if (errors.length > 0) {
|
errorsEl.innerHTML = messages
|
||||||
errorsEl.innerHTML = errors
|
.map((m) => `<div class="text-xs">${escapeHtml(m)}</div>`)
|
||||||
.map((e) => `<div class="text-xs">${e}</div>`)
|
|
||||||
.join("");
|
.join("");
|
||||||
errorsEl.classList.remove("hidden");
|
errorsEl.style.visibility = "visible";
|
||||||
sendBtn.disabled = true;
|
|
||||||
sendBtn.classList.add("text-muted");
|
|
||||||
} else {
|
} else {
|
||||||
errorsEl.classList.add("hidden");
|
errorsEl.innerHTML = "";
|
||||||
sendBtn.disabled = false;
|
errorsEl.style.visibility = "hidden";
|
||||||
sendBtn.classList.remove("text-muted");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Reset password field and error
|
setVisible(
|
||||||
$("confirm-tx-password").value = "";
|
"confirm-amount-fee-error",
|
||||||
hideError("confirm-tx-password-error");
|
codes.includes(CODES.INSUFFICIENT_ETH_WITH_FEE),
|
||||||
|
);
|
||||||
|
setVisible(
|
||||||
|
"confirm-gas-error",
|
||||||
|
codes.includes(CODES.INSUFFICIENT_ETH_FOR_FEE),
|
||||||
|
);
|
||||||
|
setVisible(
|
||||||
|
"confirm-fee-unknown-error",
|
||||||
|
codes.includes(CODES.FEE_UNAVAILABLE),
|
||||||
|
);
|
||||||
|
|
||||||
// Gas estimate — show placeholder then fetch async
|
// While the estimate is in flight there is no error to show — the fee
|
||||||
$("confirm-fee").classList.remove("hidden");
|
// line already reads "Estimating..." — but sending stays blocked so a
|
||||||
$("confirm-fee-amount").textContent = "Estimating...";
|
// transaction the fee would break cannot be signed in the meantime.
|
||||||
state.viewData = { pendingTx: txInfo };
|
const sendBtn = $("btn-confirm-send");
|
||||||
showView("confirm-tx");
|
sendBtn.disabled = !canSend;
|
||||||
|
sendBtn.classList.toggle("text-muted", !canSend);
|
||||||
|
}
|
||||||
|
|
||||||
estimateGas(txInfo);
|
function setVisible(id, visible) {
|
||||||
|
$(id).style.visibility = visible ? "visible" : "hidden";
|
||||||
|
}
|
||||||
|
|
||||||
|
// A fee in wei as an ETH string, truncated to 6 decimal places.
|
||||||
|
function formatFeeEth(wei) {
|
||||||
|
const parts = formatEther(wei).split(".");
|
||||||
|
const dec =
|
||||||
|
parts.length > 1 ? parts[1].slice(0, 6).replace(/0+$/, "") || "0" : "0";
|
||||||
|
return parts[0] + "." + dec + " ETH";
|
||||||
}
|
}
|
||||||
|
|
||||||
async function estimateGas(txInfo) {
|
async function estimateGas(txInfo) {
|
||||||
try {
|
try {
|
||||||
const provider = getProvider(state.rpcUrl);
|
const provider = getProvider(state.rpcUrl);
|
||||||
const feeData = await provider.getFeeData();
|
const feeData = await provider.getFeeData();
|
||||||
const gasPrice = feeData.gasPrice;
|
|
||||||
let gasLimit;
|
let gasLimit;
|
||||||
|
|
||||||
if (txInfo.token === "ETH") {
|
if (txInfo.token === "ETH") {
|
||||||
@@ -268,25 +317,91 @@ async function estimateGas(txInfo) {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const gasCostWei = gasLimit * gasPrice;
|
// What the node will require to be reserved, which is what the gate
|
||||||
const gasCostEth = formatEther(gasCostWei);
|
// must be: the send pins no fee fields, so it is broadcast as a
|
||||||
// Format to 6 significant decimal places
|
// type-2 transaction priced at maxFeePerGas.
|
||||||
const parts = gasCostEth.split(".");
|
const gasCostWei = feeReserveWei(gasLimit, feeData);
|
||||||
const dec =
|
if (gasCostWei === null) {
|
||||||
parts.length > 1
|
throw new Error("no usable gas price from the provider");
|
||||||
? parts[1].slice(0, 6).replace(/0+$/, "") || "0"
|
}
|
||||||
: "0";
|
// What the transaction is expected to cost, which is a different and
|
||||||
const feeStr = parts[0] + "." + dec + " ETH";
|
// usually much smaller number. Both are shown: quoting only the
|
||||||
|
// reserve overstates the typical cost by roughly double on mainnet,
|
||||||
|
// and quoting only the estimate contradicts the balance check.
|
||||||
|
const estimateWei = feeEstimateWei(gasLimit, feeData);
|
||||||
|
// The user may have left this transaction while the estimate was in
|
||||||
|
// flight; a stale fee must not reach the screen or the balance check.
|
||||||
|
if (pendingTx !== txInfo) return;
|
||||||
|
|
||||||
const ethPrice = getPrice("ETH");
|
const ethPrice = getPrice("ETH");
|
||||||
const feeUsd = ethPrice ? parseFloat(gasCostEth) * ethPrice : null;
|
const usd = (wei) =>
|
||||||
$("confirm-fee-amount").textContent = valueWithUsd(feeStr, feeUsd);
|
ethPrice ? parseFloat(formatEther(wei)) * ethPrice : null;
|
||||||
|
|
||||||
|
if (estimateWei !== null && estimateWei < gasCostWei) {
|
||||||
|
$("confirm-fee-amount").textContent = valueWithUsd(
|
||||||
|
"~" + formatFeeEth(estimateWei),
|
||||||
|
usd(estimateWei),
|
||||||
|
);
|
||||||
|
$("confirm-fee-reserve").textContent =
|
||||||
|
"up to " + formatFeeEth(gasCostWei) + " reserved";
|
||||||
|
setVisible("confirm-fee-reserve", true);
|
||||||
|
} else {
|
||||||
|
// No spread to report: either there is no estimate, or the node
|
||||||
|
// quotes a gas price at or above maxFeePerGas, so the expected
|
||||||
|
// cost is not below the reserve. Show the reserve alone.
|
||||||
|
$("confirm-fee-amount").textContent = valueWithUsd(
|
||||||
|
formatFeeEth(gasCostWei),
|
||||||
|
usd(gasCostWei),
|
||||||
|
);
|
||||||
|
setVisible("confirm-fee-reserve", false);
|
||||||
|
}
|
||||||
|
feeStatus = FEE_KNOWN;
|
||||||
|
feeWei = gasCostWei;
|
||||||
|
renderValidation(txInfo);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.errorf("gas estimation failed:", e.message);
|
log.errorf("gas estimation failed:", e.message);
|
||||||
|
if (pendingTx !== txInfo) return;
|
||||||
$("confirm-fee-amount").textContent = "Unable to estimate";
|
$("confirm-fee-amount").textContent = "Unable to estimate";
|
||||||
|
setVisible("confirm-fee-reserve", false);
|
||||||
|
feeStatus = FEE_UNAVAILABLE;
|
||||||
|
feeWei = null;
|
||||||
|
renderValidation(txInfo);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async function checkRecipientHistory(txInfo) {
|
||||||
|
try {
|
||||||
|
const provider = getProvider(state.rpcUrl);
|
||||||
|
const asyncWarnings = await getFullWarnings(txInfo.to, provider, {
|
||||||
|
fromAddress: txInfo.from,
|
||||||
|
});
|
||||||
|
for (const w of asyncWarnings) {
|
||||||
|
if (w.type === "contract") {
|
||||||
|
$("confirm-contract-warning").style.visibility = "visible";
|
||||||
|
}
|
||||||
|
if (w.type === "new-address") {
|
||||||
|
$("confirm-recipient-warning").style.visibility = "visible";
|
||||||
|
}
|
||||||
|
if (w.type === "etherscan-phishing") {
|
||||||
|
$("confirm-etherscan-warning").style.visibility = "visible";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
log.errorf("recipient history check failed:", e.message);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Drop the password from the DOM. Registered as the view-leave handler so
|
||||||
|
// it does not sit in the hidden view once the screen navigates on — to the
|
||||||
|
// wait screen after a send, or anywhere else the user goes.
|
||||||
|
function clearPassword() {
|
||||||
|
$("confirm-tx-password").value = "";
|
||||||
|
hideError("confirm-tx-password-error");
|
||||||
|
}
|
||||||
|
|
||||||
function init(ctx) {
|
function init(ctx) {
|
||||||
|
onViewLeave("confirm-tx", clearPassword);
|
||||||
|
|
||||||
$("btn-confirm-send").addEventListener("click", async () => {
|
$("btn-confirm-send").addEventListener("click", async () => {
|
||||||
const password = $("confirm-tx-password").value;
|
const password = $("confirm-tx-password").value;
|
||||||
if (!password) {
|
if (!password) {
|
||||||
@@ -356,7 +471,7 @@ function init(ctx) {
|
|||||||
});
|
});
|
||||||
|
|
||||||
$("btn-confirm-back").addEventListener("click", () => {
|
$("btn-confirm-back").addEventListener("click", () => {
|
||||||
showView("send");
|
goBack();
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
176
src/popup/views/deleteAddress.js
Normal file
176
src/popup/views/deleteAddress.js
Normal file
@@ -0,0 +1,176 @@
|
|||||||
|
// Confirmation screen for removing one address from a wallet that derives
|
||||||
|
// its addresses from an extended key.
|
||||||
|
//
|
||||||
|
// No password is asked for, unlike delete-wallet. A password gates the
|
||||||
|
// disclosure or destruction of a secret, and this does neither: the address
|
||||||
|
// is derived from key material the wallet still holds, so removing it only
|
||||||
|
// stops the wallet tracking it. An explicit confirmation screen is the
|
||||||
|
// proportionate treatment.
|
||||||
|
|
||||||
|
const {
|
||||||
|
$,
|
||||||
|
showView,
|
||||||
|
showFlash,
|
||||||
|
goBack,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
addressHoldsFunds,
|
||||||
|
balanceLinesForAddress,
|
||||||
|
} = require("./helpers");
|
||||||
|
const { formatUsd, getAddressValueUsd } = require("../../shared/prices");
|
||||||
|
const { walletHasRecoveryPhrase } = require("../../shared/wallet");
|
||||||
|
const { state, saveState } = require("../../shared/state");
|
||||||
|
const {
|
||||||
|
canRemoveAddress,
|
||||||
|
removeAddressFromState,
|
||||||
|
broadcastActiveChanged,
|
||||||
|
} = require("../../shared/walletDelete");
|
||||||
|
|
||||||
|
// The wallet and address indices this screen is confirming, or null when it
|
||||||
|
// is not confirming anything.
|
||||||
|
let target = null;
|
||||||
|
let ctx = null;
|
||||||
|
|
||||||
|
function setFlash(msg) {
|
||||||
|
const el = $("delete-address-flash");
|
||||||
|
el.textContent = msg;
|
||||||
|
el.style.visibility = msg ? "visible" : "hidden";
|
||||||
|
}
|
||||||
|
|
||||||
|
// What it actually takes to get the address back, which is not what the
|
||||||
|
// screen used to claim.
|
||||||
|
//
|
||||||
|
// Neither obvious route works: "+" derives the next unused index, because
|
||||||
|
// wallet.nextIndex is a high-water mark and is deliberately not rewound; and
|
||||||
|
// re-importing this wallet's key material is refused as a duplicate by
|
||||||
|
// findWalletByXpub() for as long as the wallet is here. What remains is to
|
||||||
|
// delete the whole wallet in Settings — which asks for the password and
|
||||||
|
// destroys the stored secret — and import again, after which
|
||||||
|
// scanForAddresses() rediscovers the address only if it has on-chain
|
||||||
|
// activity. An address that was never used is not found by that scan, and
|
||||||
|
// the copy must not imply otherwise.
|
||||||
|
//
|
||||||
|
// The noun follows the wallet: an xprv wallet holds no recovery phrase, and
|
||||||
|
// this screen is offered on xprv wallets too.
|
||||||
|
function recoveryPathText(wallet) {
|
||||||
|
const secret = walletHasRecoveryPhrase(wallet)
|
||||||
|
? "recovery phrase"
|
||||||
|
: "extended private key";
|
||||||
|
return (
|
||||||
|
"Getting the address back into this list is not easy, so be sure. " +
|
||||||
|
"Adding an address derives the next unused one, not this one, and " +
|
||||||
|
"importing this " +
|
||||||
|
secret +
|
||||||
|
" again is refused while this wallet is still here. The way back is " +
|
||||||
|
"to delete the whole wallet in Settings, which asks for your " +
|
||||||
|
"password and destroys the stored " +
|
||||||
|
secret +
|
||||||
|
", and then import that " +
|
||||||
|
secret +
|
||||||
|
" again. The scan that follows only finds addresses that have " +
|
||||||
|
"on-chain activity, so an address that has never been used is not " +
|
||||||
|
"found by it."
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// The balance warning, or a blank line when the address holds nothing.
|
||||||
|
//
|
||||||
|
// A balance is a reason to be careful, not a reason to refuse: the funds are
|
||||||
|
// at the address, not in this list, and stay there either way.
|
||||||
|
//
|
||||||
|
// "Holds" means ETH or any ERC-20 the wallet knows about — an address with no
|
||||||
|
// ETH and a five-figure stablecoin position must not get the blank line on
|
||||||
|
// the one screen whose job is to warn. The sentence names no figure of its
|
||||||
|
// own: the rendered lines round to four decimals, so a sentence built from a
|
||||||
|
// rounded number would report "0.0000 ETH" for an address holding real money.
|
||||||
|
// The lines below it carry the amounts, in the same format as Home and
|
||||||
|
// AddressDetail, followed by the USD total when prices are known (null on
|
||||||
|
// testnet and before the first price fetch, where the line is left off rather
|
||||||
|
// than printed as $0.00).
|
||||||
|
function balanceWarningHtml(addr) {
|
||||||
|
if (!addressHoldsFunds(addr)) return " ";
|
||||||
|
const usd = getAddressValueUsd(addr);
|
||||||
|
const total =
|
||||||
|
usd === null
|
||||||
|
? ""
|
||||||
|
: `<div class="text-xs text-muted mt-1">Total: ${formatUsd(usd)}</div>`;
|
||||||
|
return (
|
||||||
|
`<p class="mb-1">This address holds a balance. Removing it does not ` +
|
||||||
|
`move or spend anything; the balance stays at the address.</p>` +
|
||||||
|
balanceLinesForAddress(addr, state.trackedTokens, false) +
|
||||||
|
total
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function show(walletIdx, addrIdx) {
|
||||||
|
const wallet = state.wallets[walletIdx];
|
||||||
|
const addr = wallet && wallet.addresses[addrIdx];
|
||||||
|
if (!addr) return;
|
||||||
|
target = { walletIdx, addrIdx };
|
||||||
|
|
||||||
|
$("delete-address-label").textContent = "Address " + (addrIdx + 1);
|
||||||
|
$("delete-address-wallet-name").textContent =
|
||||||
|
wallet.name || "Wallet " + (walletIdx + 1);
|
||||||
|
|
||||||
|
const value = $("delete-address-value");
|
||||||
|
value.innerHTML = renderAddressHtml(addr.address, {
|
||||||
|
ensName: addr.ensName,
|
||||||
|
});
|
||||||
|
attachCopyHandlers(value);
|
||||||
|
|
||||||
|
$("delete-address-recovery").textContent = recoveryPathText(wallet);
|
||||||
|
$("delete-address-balance").innerHTML = balanceWarningHtml(addr);
|
||||||
|
|
||||||
|
setFlash("");
|
||||||
|
showView("delete-address-confirm");
|
||||||
|
}
|
||||||
|
|
||||||
|
function init(_ctx) {
|
||||||
|
ctx = _ctx;
|
||||||
|
|
||||||
|
$("btn-delete-address-back").addEventListener("click", () => {
|
||||||
|
target = null;
|
||||||
|
goBack();
|
||||||
|
});
|
||||||
|
|
||||||
|
$("btn-delete-address-confirm").addEventListener("click", async () => {
|
||||||
|
if (target === null) {
|
||||||
|
setFlash("No address is selected for removal.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const { walletIdx, addrIdx } = target;
|
||||||
|
if (!canRemoveAddress(state.wallets[walletIdx])) {
|
||||||
|
setFlash(
|
||||||
|
"This address cannot be removed, because a wallet always " +
|
||||||
|
"keeps at least one address.",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const { removed, activeAddressChanged } = removeAddressFromState(
|
||||||
|
state,
|
||||||
|
walletIdx,
|
||||||
|
addrIdx,
|
||||||
|
);
|
||||||
|
if (!removed) {
|
||||||
|
setFlash("This address could not be removed.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
target = null;
|
||||||
|
// Save before broadcasting: the background reads the active address
|
||||||
|
// back out of storage to build accountsChanged.
|
||||||
|
await saveState();
|
||||||
|
if (activeAddressChanged) broadcastActiveChanged();
|
||||||
|
|
||||||
|
ctx.renderWalletList();
|
||||||
|
goBack();
|
||||||
|
showFlash("Address removed.");
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// recoveryPathText and balanceWarningHtml are exported so the two pieces of
|
||||||
|
// copy that carry the screen's substance can be tested without a DOM; show()
|
||||||
|
// is a one-line assignment for each.
|
||||||
|
module.exports = { init, show, recoveryPathText, balanceWarningHtml };
|
||||||
@@ -1,27 +1,50 @@
|
|||||||
const { $, showView, showFlash } = require("./helpers");
|
const {
|
||||||
|
$,
|
||||||
|
showView,
|
||||||
|
showFlash,
|
||||||
|
goBack,
|
||||||
|
clearViewStack,
|
||||||
|
onViewLeave,
|
||||||
|
} = require("./helpers");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState } = require("../../shared/state");
|
||||||
const { decryptWithPassword } = require("../../shared/vault");
|
const { decryptWithPassword } = require("../../shared/vault");
|
||||||
|
const {
|
||||||
|
removeWalletFromState,
|
||||||
|
broadcastActiveChanged,
|
||||||
|
} = require("../../shared/walletDelete");
|
||||||
|
|
||||||
let deleteWalletIndex = null;
|
let deleteWalletIndex = null;
|
||||||
let ctx = null;
|
let ctx = null;
|
||||||
|
|
||||||
|
// Drop the password from the DOM and the wallet selection from the
|
||||||
|
// closure. Registered as the view-leave handler as well as run on entry,
|
||||||
|
// so the typed password does not sit in the hidden view after the user
|
||||||
|
// navigates away by any route, including the Settings gear.
|
||||||
|
function clear() {
|
||||||
|
deleteWalletIndex = null;
|
||||||
|
$("delete-wallet-password").value = "";
|
||||||
|
$("delete-wallet-flash").textContent = "";
|
||||||
|
$("delete-wallet-flash").style.visibility = "hidden";
|
||||||
|
}
|
||||||
|
|
||||||
function show(walletIdx) {
|
function show(walletIdx) {
|
||||||
|
clear();
|
||||||
deleteWalletIndex = walletIdx;
|
deleteWalletIndex = walletIdx;
|
||||||
const wallet = state.wallets[walletIdx];
|
const wallet = state.wallets[walletIdx];
|
||||||
$("delete-wallet-name").textContent =
|
$("delete-wallet-name").textContent =
|
||||||
wallet.name || "Wallet " + (walletIdx + 1);
|
wallet.name || "Wallet " + (walletIdx + 1);
|
||||||
$("delete-wallet-password").value = "";
|
|
||||||
$("delete-wallet-flash").textContent = "";
|
|
||||||
$("delete-wallet-flash").classList.add("hidden");
|
|
||||||
showView("delete-wallet-confirm");
|
showView("delete-wallet-confirm");
|
||||||
}
|
}
|
||||||
|
|
||||||
function init(_ctx) {
|
function init(_ctx) {
|
||||||
ctx = _ctx;
|
ctx = _ctx;
|
||||||
|
|
||||||
|
onViewLeave("delete-wallet-confirm", clear);
|
||||||
|
|
||||||
|
// No wipe here: goBack() routes through showView(), which runs the
|
||||||
|
// leave hook.
|
||||||
$("btn-delete-wallet-back").addEventListener("click", () => {
|
$("btn-delete-wallet-back").addEventListener("click", () => {
|
||||||
deleteWalletIndex = null;
|
goBack();
|
||||||
ctx.showSettingsView();
|
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-delete-wallet-confirm").addEventListener("click", async () => {
|
$("btn-delete-wallet-confirm").addEventListener("click", async () => {
|
||||||
@@ -29,14 +52,14 @@ function init(_ctx) {
|
|||||||
if (!pw) {
|
if (!pw) {
|
||||||
$("delete-wallet-flash").textContent =
|
$("delete-wallet-flash").textContent =
|
||||||
"Please enter your password.";
|
"Please enter your password.";
|
||||||
$("delete-wallet-flash").classList.remove("hidden");
|
$("delete-wallet-flash").style.visibility = "visible";
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (deleteWalletIndex === null) {
|
if (deleteWalletIndex === null) {
|
||||||
$("delete-wallet-flash").textContent =
|
$("delete-wallet-flash").textContent =
|
||||||
"No wallet selected for deletion.";
|
"No wallet selected for deletion.";
|
||||||
$("delete-wallet-flash").classList.remove("hidden");
|
$("delete-wallet-flash").style.visibility = "visible";
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -52,42 +75,38 @@ function init(_ctx) {
|
|||||||
await decryptWithPassword(wallet.encryptedSecret, pw);
|
await decryptWithPassword(wallet.encryptedSecret, pw);
|
||||||
} catch (_e) {
|
} catch (_e) {
|
||||||
$("delete-wallet-flash").textContent = "Wrong password.";
|
$("delete-wallet-flash").textContent = "Wrong password.";
|
||||||
$("delete-wallet-flash").classList.remove("hidden");
|
$("delete-wallet-flash").style.visibility = "visible";
|
||||||
btn.disabled = false;
|
btn.disabled = false;
|
||||||
btn.classList.remove("text-muted");
|
btn.classList.remove("text-muted");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Collect addresses to clean up from allowedSites/deniedSites
|
// Remove the wallet and repair selection, permissions and hasWallet
|
||||||
const addresses = (wallet.addresses || []).map((a) => a.address);
|
const { activeAddressChanged } = removeWalletFromState(
|
||||||
|
state,
|
||||||
// Remove wallet
|
walletIdx,
|
||||||
state.wallets.splice(walletIdx, 1);
|
);
|
||||||
|
|
||||||
// Clean up site permissions for deleted addresses
|
|
||||||
for (const addr of addresses) {
|
|
||||||
delete state.allowedSites[addr];
|
|
||||||
delete state.deniedSites[addr];
|
|
||||||
}
|
|
||||||
|
|
||||||
deleteWalletIndex = null;
|
deleteWalletIndex = null;
|
||||||
|
|
||||||
if (state.wallets.length === 0) {
|
if (!state.hasWallet) {
|
||||||
// No wallets left — reset selection and show welcome
|
clearViewStack();
|
||||||
state.selectedWallet = null;
|
|
||||||
state.selectedAddress = null;
|
|
||||||
state.activeAddress = null;
|
|
||||||
await saveState();
|
await saveState();
|
||||||
|
// Save before broadcasting: the background reads the active
|
||||||
|
// address back out of storage to build accountsChanged.
|
||||||
|
if (activeAddressChanged) broadcastActiveChanged();
|
||||||
showView("welcome");
|
showView("welcome");
|
||||||
} else {
|
} else {
|
||||||
// Switch to first wallet if deleted wallet was active
|
|
||||||
state.selectedWallet = 0;
|
|
||||||
state.selectedAddress = 0;
|
|
||||||
state.activeAddress =
|
|
||||||
state.wallets[0].addresses[0]?.address || null;
|
|
||||||
await saveState();
|
await saveState();
|
||||||
|
if (activeAddressChanged) broadcastActiveChanged();
|
||||||
|
// Reset stack to [main] so Settings back goes home.
|
||||||
|
// Use require() lazily to avoid circular dependency
|
||||||
|
// (settings.js requires deleteWallet.js).
|
||||||
|
clearViewStack();
|
||||||
|
state.viewStack.push("main");
|
||||||
ctx.renderWalletList();
|
ctx.renderWalletList();
|
||||||
ctx.showSettingsView();
|
const settings = require("./settings");
|
||||||
|
settings.show();
|
||||||
showFlash("Wallet deleted.");
|
showFlash("Wallet deleted.");
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
174
src/popup/views/exportPrivkey.js
Normal file
174
src/popup/views/exportPrivkey.js
Normal file
@@ -0,0 +1,174 @@
|
|||||||
|
// Private key export for a single address.
|
||||||
|
//
|
||||||
|
// The key controls the address outright — anyone holding it can move every
|
||||||
|
// token in it, from any device, forever — so this screen is handled under
|
||||||
|
// the same rules as the recovery phrase screen (./showPhrase.js):
|
||||||
|
//
|
||||||
|
// 1. Nothing is decrypted, no key is derived, and nothing is written into
|
||||||
|
// the DOM until decryptWithPassword has accepted the password.
|
||||||
|
// 2. Leaving the screen by any path wipes it, via the onViewLeave hook,
|
||||||
|
// and a decrypt still in flight when that happens is discarded
|
||||||
|
// instead of written (revealGeneration).
|
||||||
|
// 3. The key never reaches the logger. This module deliberately does not
|
||||||
|
// import src/shared/log.js.
|
||||||
|
//
|
||||||
|
// The key is also never assigned to `state`, so it cannot be persisted to
|
||||||
|
// extension storage, and "export-privkey" is excluded from RESTORABLE_VIEWS
|
||||||
|
// so the popup can never reopen onto it.
|
||||||
|
|
||||||
|
const {
|
||||||
|
$,
|
||||||
|
showView,
|
||||||
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
|
goBack,
|
||||||
|
onViewLeave,
|
||||||
|
pushCurrentView,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
} = require("./helpers");
|
||||||
|
const { state } = require("../../shared/state");
|
||||||
|
const { decryptWithPassword } = require("../../shared/vault");
|
||||||
|
const { getSignerForAddress } = require("../../shared/wallet");
|
||||||
|
const makeBlockie = require("ethereum-blockies-base64");
|
||||||
|
|
||||||
|
const VIEW = "export-privkey";
|
||||||
|
|
||||||
|
let walletIndex = null;
|
||||||
|
let addressIndex = null;
|
||||||
|
|
||||||
|
// Bumped by every clear(), which is what leaving the screen runs. reveal()
|
||||||
|
// captures it before awaiting the decrypt and refuses to touch the DOM if
|
||||||
|
// it has moved: a decrypt still in flight when the screen is left would
|
||||||
|
// otherwise write the key *after* the wipe, with nothing scheduled to wipe
|
||||||
|
// it again, leaving it in the hidden view for the life of the popup.
|
||||||
|
let revealGeneration = 0;
|
||||||
|
|
||||||
|
// True only if the reveal that captured `generation` is still the live one:
|
||||||
|
// the screen has not been left, cleared, or re-entered for another address
|
||||||
|
// since it started.
|
||||||
|
function isCurrentReveal(generation) {
|
||||||
|
return (
|
||||||
|
generation === revealGeneration &&
|
||||||
|
walletIndex !== null &&
|
||||||
|
addressIndex !== null &&
|
||||||
|
state.currentView === VIEW
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function fail(message) {
|
||||||
|
$("export-privkey-flash").textContent = message;
|
||||||
|
$("export-privkey-flash").style.visibility = "visible";
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wipe every trace of the key and drop the address selection. Safe to call
|
||||||
|
// when nothing was ever revealed, and safe to call twice.
|
||||||
|
function clear() {
|
||||||
|
walletIndex = null;
|
||||||
|
addressIndex = null;
|
||||||
|
revealGeneration += 1;
|
||||||
|
$("export-privkey-value").textContent = "";
|
||||||
|
$("export-privkey-password").value = "";
|
||||||
|
$("export-privkey-result").classList.add("hidden");
|
||||||
|
$("export-privkey-password-section").classList.remove("hidden");
|
||||||
|
$("export-privkey-flash").textContent = "";
|
||||||
|
$("export-privkey-flash").style.visibility = "hidden";
|
||||||
|
}
|
||||||
|
|
||||||
|
function show(walletIdx, addrIdx) {
|
||||||
|
const wallet = state.wallets[walletIdx];
|
||||||
|
const addr = wallet && wallet.addresses[addrIdx];
|
||||||
|
if (!addr) {
|
||||||
|
showFlash("That address is no longer available.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
clear();
|
||||||
|
walletIndex = walletIdx;
|
||||||
|
addressIndex = addrIdx;
|
||||||
|
|
||||||
|
const blockieEl = $("export-privkey-jazzicon");
|
||||||
|
blockieEl.innerHTML = "";
|
||||||
|
const img = document.createElement("img");
|
||||||
|
img.src = makeBlockie(addr.address);
|
||||||
|
img.width = 48;
|
||||||
|
img.height = 48;
|
||||||
|
img.style.imageRendering = "pixelated";
|
||||||
|
img.style.borderRadius = "50%";
|
||||||
|
blockieEl.appendChild(img);
|
||||||
|
|
||||||
|
$("export-privkey-title").textContent =
|
||||||
|
wallet.name + " — Address " + (addrIdx + 1);
|
||||||
|
const addrContainer = $("export-privkey-dot").parentElement;
|
||||||
|
addrContainer.innerHTML = renderAddressHtml(addr.address);
|
||||||
|
attachCopyHandlers(addrContainer);
|
||||||
|
|
||||||
|
// Pushed here rather than by the caller: this function can return
|
||||||
|
// without navigating, and a push that happened anyway would leave an
|
||||||
|
// entry on the stack that no screen transition matches.
|
||||||
|
pushCurrentView();
|
||||||
|
showView(VIEW);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function reveal() {
|
||||||
|
const password = $("export-privkey-password").value;
|
||||||
|
if (!password) {
|
||||||
|
fail("Password is required.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (walletIndex === null) {
|
||||||
|
fail("No address is selected.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const wallet = state.wallets[walletIndex];
|
||||||
|
|
||||||
|
const btn = $("btn-export-privkey-confirm");
|
||||||
|
btn.disabled = true;
|
||||||
|
btn.classList.add("text-muted");
|
||||||
|
const generation = revealGeneration;
|
||||||
|
try {
|
||||||
|
const secret = await decryptWithPassword(
|
||||||
|
wallet.encryptedSecret,
|
||||||
|
password,
|
||||||
|
);
|
||||||
|
// The only suspension point in this view, and the gate on the only
|
||||||
|
// place a secret is written: if the screen was left while the
|
||||||
|
// decrypt ran, the wipe has already happened, so the key is not
|
||||||
|
// even derived, let alone written.
|
||||||
|
if (!isCurrentReveal(generation)) return;
|
||||||
|
const signer = getSignerForAddress(wallet, addressIndex, secret);
|
||||||
|
$("export-privkey-password").value = "";
|
||||||
|
$("export-privkey-password-section").classList.add("hidden");
|
||||||
|
$("export-privkey-value").textContent = signer.privateKey;
|
||||||
|
$("export-privkey-result").classList.remove("hidden");
|
||||||
|
$("export-privkey-flash").textContent = "";
|
||||||
|
$("export-privkey-flash").style.visibility = "hidden";
|
||||||
|
} catch {
|
||||||
|
if (!isCurrentReveal(generation)) return;
|
||||||
|
fail("That password is not correct. Please try again.");
|
||||||
|
} finally {
|
||||||
|
btn.disabled = false;
|
||||||
|
btn.classList.remove("text-muted");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function init() {
|
||||||
|
onViewLeave(VIEW, clear);
|
||||||
|
|
||||||
|
// No wipe here: goBack() routes through showView(), which runs the
|
||||||
|
// leave hook. A per-button wipe would only cover this one path.
|
||||||
|
$("btn-export-privkey-back").addEventListener("click", () => {
|
||||||
|
goBack();
|
||||||
|
});
|
||||||
|
|
||||||
|
$("btn-export-privkey-confirm").addEventListener("click", reveal);
|
||||||
|
|
||||||
|
$("export-privkey-value").addEventListener("click", () => {
|
||||||
|
const key = $("export-privkey-value").textContent;
|
||||||
|
if (!key) return;
|
||||||
|
navigator.clipboard.writeText(key);
|
||||||
|
showFlash("Copied!");
|
||||||
|
flashCopyFeedback($("export-privkey-value"));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { init, show };
|
||||||
@@ -1,19 +1,18 @@
|
|||||||
// Shared DOM helpers used by all views.
|
// Shared DOM helpers used by all views.
|
||||||
|
|
||||||
const { DEBUG } = require("../../shared/constants");
|
const { isDebug } = require("../../shared/log");
|
||||||
const {
|
const {
|
||||||
formatUsd,
|
formatUsd,
|
||||||
getPrice,
|
getPrice,
|
||||||
getAddressValueUsd,
|
getAddressValueUsd,
|
||||||
} = require("../../shared/prices");
|
} = require("../../shared/prices");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||||
|
|
||||||
// When views are added, removed, or transitions between them change,
|
// When views are added, removed, or transitions between them change,
|
||||||
// update the view-navigation documentation in README.md to match.
|
// update the view-navigation documentation in README.md to match.
|
||||||
const VIEWS = [
|
const VIEWS = [
|
||||||
"welcome",
|
"welcome",
|
||||||
"add-wallet",
|
"add-wallet",
|
||||||
"import-key",
|
|
||||||
"main",
|
"main",
|
||||||
"address",
|
"address",
|
||||||
"address-token",
|
"address-token",
|
||||||
@@ -26,14 +25,27 @@ const VIEWS = [
|
|||||||
"add-token",
|
"add-token",
|
||||||
"settings",
|
"settings",
|
||||||
"delete-wallet-confirm",
|
"delete-wallet-confirm",
|
||||||
|
"delete-address-confirm",
|
||||||
"settings-addtoken",
|
"settings-addtoken",
|
||||||
"transaction",
|
"transaction",
|
||||||
"approve-site",
|
"approve-site",
|
||||||
"approve-tx",
|
"approve-tx",
|
||||||
"approve-sign",
|
"approve-sign",
|
||||||
"export-privkey",
|
"export-privkey",
|
||||||
|
"show-phrase",
|
||||||
];
|
];
|
||||||
|
|
||||||
|
// Cleanup callbacks for views that hold a secret in the DOM. The view
|
||||||
|
// registers one for itself and showView() runs it whenever that view is
|
||||||
|
// navigated away from, so the secret is wiped no matter which control
|
||||||
|
// caused the navigation — "Back", the settings gear, or a jump from
|
||||||
|
// anywhere else. A per-button clear would only cover the one path.
|
||||||
|
const viewLeaveHandlers = new Map();
|
||||||
|
|
||||||
|
function onViewLeave(name, fn) {
|
||||||
|
viewLeaveHandlers.set(name, fn);
|
||||||
|
}
|
||||||
|
|
||||||
function $(id) {
|
function $(id) {
|
||||||
return document.getElementById(id);
|
return document.getElementById(id);
|
||||||
}
|
}
|
||||||
@@ -41,14 +53,21 @@ function $(id) {
|
|||||||
function showError(id, msg) {
|
function showError(id, msg) {
|
||||||
const el = $(id);
|
const el = $(id);
|
||||||
el.textContent = msg;
|
el.textContent = msg;
|
||||||
el.classList.remove("hidden");
|
el.style.visibility = "visible";
|
||||||
}
|
}
|
||||||
|
|
||||||
function hideError(id) {
|
function hideError(id) {
|
||||||
$(id).classList.add("hidden");
|
const el = $(id);
|
||||||
|
el.textContent = "";
|
||||||
|
el.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
|
|
||||||
function showView(name) {
|
function showView(name) {
|
||||||
|
const leaving = state.currentView;
|
||||||
|
if (leaving && leaving !== name) {
|
||||||
|
const onLeave = viewLeaveHandlers.get(leaving);
|
||||||
|
if (onLeave) onLeave();
|
||||||
|
}
|
||||||
for (const v of VIEWS) {
|
for (const v of VIEWS) {
|
||||||
const el = document.getElementById(`view-${v}`);
|
const el = document.getElementById(`view-${v}`);
|
||||||
if (el) {
|
if (el) {
|
||||||
@@ -58,14 +77,77 @@ function showView(name) {
|
|||||||
clearFlash();
|
clearFlash();
|
||||||
state.currentView = name;
|
state.currentView = name;
|
||||||
saveState();
|
saveState();
|
||||||
if (DEBUG) {
|
updateDebugBanner(name);
|
||||||
const banner = document.getElementById("debug-banner");
|
}
|
||||||
if (banner) {
|
|
||||||
banner.textContent = "DEBUG / INSECURE (" + name + ")";
|
// Create or update the debug/insecure warning banner.
|
||||||
|
// Called on every view switch and after the settings debug toggle changes.
|
||||||
|
// The banner is shown when the compile-time DEBUG constant is true OR when
|
||||||
|
// the user has enabled runtime debug mode via the settings easter egg, OR
|
||||||
|
// when the active network is a testnet.
|
||||||
|
function updateDebugBanner(viewName) {
|
||||||
|
const debug = isDebug();
|
||||||
|
const net = currentNetwork();
|
||||||
|
const show = debug || net.isTestnet;
|
||||||
|
let banner = document.getElementById("debug-banner");
|
||||||
|
if (show) {
|
||||||
|
if (!banner) {
|
||||||
|
banner = document.createElement("div");
|
||||||
|
banner.id = "debug-banner";
|
||||||
|
banner.style.cssText =
|
||||||
|
"background:#c00;color:#fff;text-align:center;font-size:10px;padding:1px 0;font-family:monospace;position:sticky;top:0;z-index:9999;";
|
||||||
|
document.body.prepend(banner);
|
||||||
}
|
}
|
||||||
|
const suffix = viewName ? " (" + viewName + ")" : "";
|
||||||
|
if (debug && net.isTestnet) {
|
||||||
|
banner.textContent = "DEBUG / INSECURE [TESTNET]" + suffix;
|
||||||
|
} else if (net.isTestnet) {
|
||||||
|
banner.textContent = "[TESTNET]" + suffix;
|
||||||
|
} else {
|
||||||
|
banner.textContent = "DEBUG / INSECURE" + suffix;
|
||||||
|
}
|
||||||
|
} else if (banner) {
|
||||||
|
banner.remove();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Callback to re-render the main/home view when navigating back to it.
|
||||||
|
// Set once by index.js via setRenderMain().
|
||||||
|
let _renderMain = null;
|
||||||
|
|
||||||
|
function setRenderMain(fn) {
|
||||||
|
_renderMain = fn;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Push the current view onto the navigation stack so goBack() can
|
||||||
|
// return to it. Call this before any forward navigation.
|
||||||
|
function pushCurrentView() {
|
||||||
|
if (state.currentView) {
|
||||||
|
state.viewStack.push(state.currentView);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Pop the navigation stack and show the previous view. If the stack
|
||||||
|
// is empty, fall back to the main (home) view.
|
||||||
|
function goBack() {
|
||||||
|
let target;
|
||||||
|
if (state.viewStack.length > 0) {
|
||||||
|
target = state.viewStack.pop();
|
||||||
|
} else {
|
||||||
|
target = "main";
|
||||||
|
}
|
||||||
|
if (target === "main" && _renderMain) {
|
||||||
|
_renderMain();
|
||||||
|
}
|
||||||
|
showView(target);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Clear the entire navigation stack (used when resetting to root,
|
||||||
|
// e.g. after adding or deleting a wallet).
|
||||||
|
function clearViewStack() {
|
||||||
|
state.viewStack = [];
|
||||||
|
}
|
||||||
|
|
||||||
let flashTimer = null;
|
let flashTimer = null;
|
||||||
|
|
||||||
function clearFlash() {
|
function clearFlash() {
|
||||||
@@ -136,6 +218,20 @@ function balanceLinesForAddress(addr, trackedTokens, showZero) {
|
|||||||
return html;
|
return html;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Whether an address holds anything at all: ETH or any ERC-20 the wallet
|
||||||
|
// knows about. Deliberately unrounded — the rendered lines round to four
|
||||||
|
// decimals, so a dust balance displays as 0.0000 while still being real
|
||||||
|
// money at a real address. Callers that warn about holdings must ask this,
|
||||||
|
// not the rendered figure.
|
||||||
|
function addressHoldsFunds(addr) {
|
||||||
|
if (!addr) return false;
|
||||||
|
if (parseFloat(addr.balance || "0") > 0) return true;
|
||||||
|
for (const t of addr.tokenBalances || []) {
|
||||||
|
if (parseFloat(t.balance || "0") > 0) return true;
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
// Truncate the middle of a string, replacing removed characters with "…".
|
// Truncate the middle of a string, replacing removed characters with "…".
|
||||||
// Safety: refuses to truncate more than 10 characters, which is the maximum
|
// Safety: refuses to truncate more than 10 characters, which is the maximum
|
||||||
// that still prevents address spoofing attacks (see Display Consistency in
|
// that still prevents address spoofing attacks (see Display Consistency in
|
||||||
@@ -207,38 +303,47 @@ function addressTitle(address, wallets) {
|
|||||||
// Render an address with color dot, optional ENS name, optional title,
|
// Render an address with color dot, optional ENS name, optional title,
|
||||||
// and optional truncation. Title and ENS are shown as bold labels above
|
// and optional truncation. Title and ENS are shown as bold labels above
|
||||||
// the full address.
|
// the full address.
|
||||||
|
// Delegates to renderAddressHtml for consistent output.
|
||||||
function formatAddressHtml(address, ensName, maxLen, title) {
|
function formatAddressHtml(address, ensName, maxLen, title) {
|
||||||
const dot = addressDotHtml(address);
|
return renderAddressHtml(address, { title, ensName, maxLen });
|
||||||
const displayAddr = maxLen ? truncateMiddle(address, maxLen) : address;
|
|
||||||
if (title || ensName) {
|
|
||||||
let html = "";
|
|
||||||
if (title) {
|
|
||||||
html += `<div class="flex items-center font-bold">${dot}${escapeHtml(title)}</div>`;
|
|
||||||
}
|
|
||||||
if (ensName) {
|
|
||||||
html += `<div class="flex items-center font-bold">${title ? "" : dot}${escapeHtml(ensName)}</div>`;
|
|
||||||
}
|
|
||||||
html += `<div class="break-all">${escapeHtml(displayAddr)}</div>`;
|
|
||||||
return html;
|
|
||||||
}
|
|
||||||
return `<div class="flex items-center">${dot}<span class="break-all">${escapeHtml(displayAddr)}</span></div>`;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function isoDate(timestamp) {
|
function isoDate(timestamp) {
|
||||||
const d = new Date(timestamp * 1000);
|
const d = new Date(timestamp * 1000);
|
||||||
const pad = (n) => String(n).padStart(2, "0");
|
const pad = (n) => String(n).padStart(2, "0");
|
||||||
|
if (state.utcTimestamps) {
|
||||||
|
return (
|
||||||
|
d.getUTCFullYear() +
|
||||||
|
"-" +
|
||||||
|
pad(d.getUTCMonth() + 1) +
|
||||||
|
"-" +
|
||||||
|
pad(d.getUTCDate()) +
|
||||||
|
"T" +
|
||||||
|
pad(d.getUTCHours()) +
|
||||||
|
":" +
|
||||||
|
pad(d.getUTCMinutes()) +
|
||||||
|
":" +
|
||||||
|
pad(d.getUTCSeconds()) +
|
||||||
|
"Z"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
const offsetMin = -d.getTimezoneOffset();
|
||||||
|
const sign = offsetMin >= 0 ? "+" : "-";
|
||||||
|
const absOff = Math.abs(offsetMin);
|
||||||
|
const tzStr = sign + pad(Math.floor(absOff / 60)) + ":" + pad(absOff % 60);
|
||||||
return (
|
return (
|
||||||
d.getFullYear() +
|
d.getFullYear() +
|
||||||
"-" +
|
"-" +
|
||||||
pad(d.getMonth() + 1) +
|
pad(d.getMonth() + 1) +
|
||||||
"-" +
|
"-" +
|
||||||
pad(d.getDate()) +
|
pad(d.getDate()) +
|
||||||
" " +
|
"T" +
|
||||||
pad(d.getHours()) +
|
pad(d.getHours()) +
|
||||||
":" +
|
":" +
|
||||||
pad(d.getMinutes()) +
|
pad(d.getMinutes()) +
|
||||||
":" +
|
":" +
|
||||||
pad(d.getSeconds())
|
pad(d.getSeconds()) +
|
||||||
|
tzStr
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -259,19 +364,132 @@ function timeAgo(timestamp) {
|
|||||||
return years + " year" + (years !== 1 ? "s" : "") + " ago";
|
return years + " year" + (years !== 1 ? "s" : "") + " ago";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Shared external-link icon SVG used across all views.
|
||||||
|
const EXT_ICON =
|
||||||
|
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
||||||
|
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
||||||
|
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
||||||
|
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
||||||
|
`</svg></span>`;
|
||||||
|
|
||||||
|
function etherscanAddressUrl(address) {
|
||||||
|
return `${currentNetwork().explorerUrl}/address/${address}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function etherscanLinkHtml(url) {
|
||||||
|
return (
|
||||||
|
`<a href="${url}" target="_blank" rel="noopener" ` +
|
||||||
|
`class="inline-flex items-center">${EXT_ICON}</a>`
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Render a copyable text span with dashed underline affordance.
|
||||||
|
// The caller must attach click handlers via attachCopyHandlers() or
|
||||||
|
// manually wire up [data-copy] elements after inserting the HTML.
|
||||||
|
function copyableHtml(text, extraClass) {
|
||||||
|
const cls =
|
||||||
|
"underline decoration-dashed cursor-pointer" +
|
||||||
|
(extraClass ? " " + extraClass : "");
|
||||||
|
return `<span class="${cls}" data-copy="${escapeHtml(text)}">${escapeHtml(text)}</span>`;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Attach click-to-copy handlers to all [data-copy] elements within
|
||||||
|
// a container. Safe to call multiple times on the same container.
|
||||||
|
function attachCopyHandlers(container) {
|
||||||
|
const root =
|
||||||
|
typeof container === "string"
|
||||||
|
? document.getElementById(container)
|
||||||
|
: container;
|
||||||
|
if (!root) return;
|
||||||
|
root.querySelectorAll("[data-copy]").forEach((el) => {
|
||||||
|
el.onclick = () => {
|
||||||
|
navigator.clipboard.writeText(el.dataset.copy);
|
||||||
|
showFlash("Copied!");
|
||||||
|
flashCopyFeedback(el);
|
||||||
|
};
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Unified address rendering.
|
||||||
|
//
|
||||||
|
// Produces consistent HTML for any Ethereum address:
|
||||||
|
// • Color dot
|
||||||
|
// • Optional title (e.g. "Wallet 1 — Address 2") shown bold above address
|
||||||
|
// • Optional ENS name shown bold above address
|
||||||
|
// • Full address (or truncated via maxLen) with dashed-underline click-to-copy
|
||||||
|
// • Etherscan external link icon
|
||||||
|
//
|
||||||
|
// Options object:
|
||||||
|
// title — wallet title string (from addressTitle)
|
||||||
|
// ensName — ENS name string
|
||||||
|
// maxLen — if set, truncate address display (min 32 chars enforced)
|
||||||
|
// noLink — if true, omit etherscan link
|
||||||
|
//
|
||||||
|
// After inserting the returned HTML into the DOM, call
|
||||||
|
// attachCopyHandlers() on the parent to wire up click-to-copy.
|
||||||
|
function renderAddressHtml(address, opts) {
|
||||||
|
const { title, ensName, maxLen, noLink } = opts || {};
|
||||||
|
const dot = addressDotHtml(address);
|
||||||
|
const displayAddr = maxLen ? truncateMiddle(address, maxLen) : address;
|
||||||
|
const link = etherscanAddressUrl(address);
|
||||||
|
const extLink = noLink ? "" : etherscanLinkHtml(link);
|
||||||
|
|
||||||
|
let html = "";
|
||||||
|
if (title) {
|
||||||
|
html += `<div class="flex items-center font-bold">${dot}${escapeHtml(title)}</div>`;
|
||||||
|
}
|
||||||
|
if (ensName) {
|
||||||
|
html += `<div class="flex items-center font-bold">${title ? "" : dot}${escapeHtml(ensName)}</div>`;
|
||||||
|
}
|
||||||
|
if (title || ensName) {
|
||||||
|
html += `<div class="flex items-center">${copyableHtml(displayAddr, "break-all")}${extLink}</div>`;
|
||||||
|
} else {
|
||||||
|
html += `<div class="flex items-center">${dot}${copyableHtml(displayAddr, "break-all")}${extLink}</div>`;
|
||||||
|
}
|
||||||
|
return html;
|
||||||
|
}
|
||||||
|
|
||||||
|
function flashCopyFeedback(el) {
|
||||||
|
if (!el) return;
|
||||||
|
el.classList.remove("copy-flash-fade");
|
||||||
|
el.classList.add("copy-flash-active");
|
||||||
|
setTimeout(() => {
|
||||||
|
el.classList.remove("copy-flash-active");
|
||||||
|
el.classList.add("copy-flash-fade");
|
||||||
|
setTimeout(() => {
|
||||||
|
el.classList.remove("copy-flash-fade");
|
||||||
|
}, 275);
|
||||||
|
}, 75);
|
||||||
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
|
VIEWS,
|
||||||
$,
|
$,
|
||||||
showError,
|
showError,
|
||||||
hideError,
|
hideError,
|
||||||
showView,
|
showView,
|
||||||
|
onViewLeave,
|
||||||
|
updateDebugBanner,
|
||||||
|
setRenderMain,
|
||||||
|
pushCurrentView,
|
||||||
|
goBack,
|
||||||
|
clearViewStack,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
balanceLine,
|
balanceLine,
|
||||||
balanceLinesForAddress,
|
balanceLinesForAddress,
|
||||||
|
addressHoldsFunds,
|
||||||
addressColor,
|
addressColor,
|
||||||
addressDotHtml,
|
addressDotHtml,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
formatAddressHtml,
|
formatAddressHtml,
|
||||||
|
renderAddressHtml,
|
||||||
|
copyableHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
etherscanAddressUrl,
|
||||||
|
etherscanLinkHtml,
|
||||||
|
EXT_ICON,
|
||||||
truncateMiddle,
|
truncateMiddle,
|
||||||
isoDate,
|
isoDate,
|
||||||
timeAgo,
|
timeAgo,
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
balanceLinesForAddress,
|
balanceLinesForAddress,
|
||||||
isoDate,
|
isoDate,
|
||||||
timeAgo,
|
timeAgo,
|
||||||
@@ -9,6 +10,9 @@ const {
|
|||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
truncateMiddle,
|
truncateMiddle,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
pushCurrentView,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, saveState, currentAddress } = require("../../shared/state");
|
const { state, saveState, currentAddress } = require("../../shared/state");
|
||||||
const {
|
const {
|
||||||
@@ -17,6 +21,11 @@ const {
|
|||||||
resetSendValidation,
|
resetSendValidation,
|
||||||
} = require("./send");
|
} = require("./send");
|
||||||
const { deriveAddressFromXpub } = require("../../shared/wallet");
|
const { deriveAddressFromXpub } = require("../../shared/wallet");
|
||||||
|
const { canRemoveAddress } = require("../../shared/walletDelete");
|
||||||
|
const {
|
||||||
|
walletDefect,
|
||||||
|
walletDefectHtml,
|
||||||
|
} = require("../../shared/walletDefects");
|
||||||
const {
|
const {
|
||||||
formatUsd,
|
formatUsd,
|
||||||
getPrice,
|
getPrice,
|
||||||
@@ -68,27 +77,12 @@ function renderTotalValue() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
function renderActiveAddress() {
|
function renderActiveAddress() {
|
||||||
const el = $("active-address-display");
|
const el = $("active-address-display");
|
||||||
if (!el) return;
|
if (!el) return;
|
||||||
if (state.activeAddress) {
|
if (state.activeAddress) {
|
||||||
const addr = state.activeAddress;
|
el.innerHTML = renderAddressHtml(state.activeAddress);
|
||||||
const dot = addressDotHtml(addr);
|
attachCopyHandlers(el);
|
||||||
const link = `https://etherscan.io/address/${addr}`;
|
|
||||||
el.innerHTML =
|
|
||||||
`<span class="underline decoration-dashed cursor-pointer" id="active-addr-copy">${dot}${escapeHtml(addr)}</span>` +
|
|
||||||
`<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
|
||||||
$("active-addr-copy").addEventListener("click", () => {
|
|
||||||
navigator.clipboard.writeText(addr);
|
|
||||||
showFlash("Copied!");
|
|
||||||
});
|
|
||||||
} else {
|
} else {
|
||||||
el.textContent = "";
|
el.textContent = "";
|
||||||
}
|
}
|
||||||
@@ -174,6 +168,7 @@ async function loadHomeTxs(ctx) {
|
|||||||
if (allAddresses.length === 0) return;
|
if (allAddresses.length === 0) return;
|
||||||
|
|
||||||
const filters = {
|
const filters = {
|
||||||
|
hideSpoofedSymbols: state.hideSpoofedSymbols,
|
||||||
hideLowHolderTokens: state.hideLowHolderTokens,
|
hideLowHolderTokens: state.hideLowHolderTokens,
|
||||||
hideFraudContracts: state.hideFraudContracts,
|
hideFraudContracts: state.hideFraudContracts,
|
||||||
hideDustTransactions: state.hideDustTransactions,
|
hideDustTransactions: state.hideDustTransactions,
|
||||||
@@ -224,30 +219,34 @@ async function loadHomeTxs(ctx) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function render(ctx) {
|
// The wallet list markup. Pure: it reads state and returns a string, so the
|
||||||
const container = $("wallet-list");
|
// list can be asserted on without a DOM.
|
||||||
if (state.wallets.length === 0) {
|
function walletListHtml() {
|
||||||
container.innerHTML =
|
|
||||||
'<p class="text-muted py-2">No wallets yet. Add one to get started.</p>';
|
|
||||||
renderTotalValue();
|
|
||||||
renderActiveAddress();
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
let html = "";
|
let html = "";
|
||||||
state.wallets.forEach((wallet, wi) => {
|
state.wallets.forEach((wallet, wi) => {
|
||||||
|
const defect = walletDefect(wallet);
|
||||||
html += `<div>`;
|
html += `<div>`;
|
||||||
html += `<div class="flex justify-between items-center bg-section py-1 px-2" style="margin:0 -0.5rem">`;
|
html += `<div class="flex justify-between items-center bg-section py-1 px-2" style="margin:0 -0.5rem">`;
|
||||||
html += `<span class="font-bold cursor-pointer wallet-name underline decoration-dashed" data-wallet="${wi}">${wallet.name}</span>`;
|
html += `<span class="font-bold cursor-pointer wallet-name underline decoration-dashed" data-wallet="${wi}">${wallet.name}</span>`;
|
||||||
if (wallet.type === "hd") {
|
// No "+" on a defective wallet: deriving another address from that
|
||||||
|
// xpub would only add one more address the key does not produce
|
||||||
|
// under the standard path.
|
||||||
|
if (!defect && (wallet.type === "hd" || wallet.type === "xprv")) {
|
||||||
html += `<button class="btn-add-address border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer text-xs" data-wallet="${wi}" title="Add another address to this wallet">+</button>`;
|
html += `<button class="btn-add-address border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer text-xs" data-wallet="${wi}" title="Add another address to this wallet">+</button>`;
|
||||||
}
|
}
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
|
html += walletDefectHtml(wallet);
|
||||||
|
|
||||||
wallet.addresses.forEach((addr, ai) => {
|
wallet.addresses.forEach((addr, ai) => {
|
||||||
html += `<div class="address-row py-1 border-b border-border-light cursor-pointer hover:bg-hover" data-wallet="${wi}" data-address="${ai}">`;
|
html += `<div class="address-row py-1 border-b border-border-light cursor-pointer hover:bg-hover" data-wallet="${wi}" data-address="${ai}">`;
|
||||||
const isActive = state.activeAddress === addr.address;
|
const isActive = state.activeAddress === addr.address;
|
||||||
const infoBtn = `<span class="btn-addr-info text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg" style="padding:0" data-wallet="${wi}" data-address="${ai}">[info]</span>`;
|
const infoBtn = `<span class="btn-addr-info text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg" style="padding:0" data-wallet="${wi}" data-address="${ai}">[info]</span>`;
|
||||||
|
// Only where a wallet can spare the address: a wallet holding a
|
||||||
|
// single address has no remove control, because its last address
|
||||||
|
// is never removable.
|
||||||
|
const removeBtn = canRemoveAddress(wallet)
|
||||||
|
? `<span class="btn-remove-address text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg ml-1" style="padding:0" data-wallet="${wi}" data-address="${ai}" title="Remove this address from the wallet">[x]</span>`
|
||||||
|
: "";
|
||||||
const dot = addressDotHtml(addr.address);
|
const dot = addressDotHtml(addr.address);
|
||||||
const titleBold = isActive ? "font-bold" : "";
|
const titleBold = isActive ? "font-bold" : "";
|
||||||
html += `<div class="text-xs ${titleBold}">Address ${ai + 1}</div>`;
|
html += `<div class="text-xs ${titleBold}">Address ${ai + 1}</div>`;
|
||||||
@@ -256,7 +255,7 @@ function render(ctx) {
|
|||||||
}
|
}
|
||||||
html += `<div class="flex text-xs items-center justify-between">`;
|
html += `<div class="flex text-xs items-center justify-between">`;
|
||||||
html += `<span class="flex items-center break-all">${addr.ensName ? "" : dot}${addr.address}</span>`;
|
html += `<span class="flex items-center break-all">${addr.ensName ? "" : dot}${addr.address}</span>`;
|
||||||
html += `<span class="flex-shrink-0 ml-1">${infoBtn}</span>`;
|
html += `<span class="flex-shrink-0 ml-1">${infoBtn}${removeBtn}</span>`;
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
const addrUsd = formatUsd(getAddressValueUsd(addr));
|
const addrUsd = formatUsd(getAddressValueUsd(addr));
|
||||||
html += `<div class="text-xs text-muted text-right min-h-[1rem]">${addrUsd || " "}</div>`;
|
html += `<div class="text-xs text-muted text-right min-h-[1rem]">${addrUsd || " "}</div>`;
|
||||||
@@ -270,7 +269,20 @@ function render(ctx) {
|
|||||||
|
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
});
|
});
|
||||||
container.innerHTML = html;
|
return html;
|
||||||
|
}
|
||||||
|
|
||||||
|
function render(ctx) {
|
||||||
|
const container = $("wallet-list");
|
||||||
|
if (state.wallets.length === 0) {
|
||||||
|
container.innerHTML =
|
||||||
|
'<p class="text-muted py-2">No wallets yet. Add one to get started.</p>';
|
||||||
|
renderTotalValue();
|
||||||
|
renderActiveAddress();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
container.innerHTML = walletListHtml();
|
||||||
|
|
||||||
container.querySelectorAll(".address-row").forEach((row) => {
|
container.querySelectorAll(".address-row").forEach((row) => {
|
||||||
row.addEventListener("click", async () => {
|
row.addEventListener("click", async () => {
|
||||||
@@ -299,6 +311,16 @@ function render(ctx) {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
container.querySelectorAll(".btn-remove-address").forEach((btn) => {
|
||||||
|
btn.addEventListener("click", (e) => {
|
||||||
|
e.stopPropagation();
|
||||||
|
ctx.showDeleteAddress(
|
||||||
|
parseInt(btn.dataset.wallet, 10),
|
||||||
|
parseInt(btn.dataset.address, 10),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
container.querySelectorAll(".btn-add-address").forEach((btn) => {
|
container.querySelectorAll(".btn-add-address").forEach((btn) => {
|
||||||
btn.addEventListener("click", async (e) => {
|
btn.addEventListener("click", async (e) => {
|
||||||
e.stopPropagation();
|
e.stopPropagation();
|
||||||
@@ -358,6 +380,13 @@ function render(ctx) {
|
|||||||
loadHomeTxs(ctx);
|
loadHomeTxs(ctx);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The defect of the wallet the selected address belongs to, or null. Call
|
||||||
|
// after selectActiveAddress().
|
||||||
|
function selectedWalletDefect() {
|
||||||
|
if (state.selectedWallet === null) return null;
|
||||||
|
return walletDefect(state.wallets[state.selectedWallet]);
|
||||||
|
}
|
||||||
|
|
||||||
function selectActiveAddress() {
|
function selectActiveAddress() {
|
||||||
for (let wi = 0; wi < state.wallets.length; wi++) {
|
for (let wi = 0; wi < state.wallets.length; wi++) {
|
||||||
for (let ai = 0; ai < state.wallets[wi].addresses.length; ai++) {
|
for (let ai = 0; ai < state.wallets[wi].addresses.length; ai++) {
|
||||||
@@ -381,6 +410,13 @@ function init(ctx) {
|
|||||||
showFlash("No active address selected.");
|
showFlash("No active address selected.");
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
// Before the balance check and before any password is asked for: this
|
||||||
|
// wallet cannot sign at all, so the send screen is a dead end.
|
||||||
|
const defect = selectedWalletDefect();
|
||||||
|
if (defect) {
|
||||||
|
showFlash(defect.shortMessage);
|
||||||
|
return;
|
||||||
|
}
|
||||||
const addr = currentAddress();
|
const addr = currentAddress();
|
||||||
if (!addr.balance || parseFloat(addr.balance) === 0) {
|
if (!addr.balance || parseFloat(addr.balance) === 0) {
|
||||||
showFlash("Cannot send \u2014 zero balance.");
|
showFlash("Cannot send \u2014 zero balance.");
|
||||||
@@ -393,6 +429,7 @@ function init(ctx) {
|
|||||||
renderSendTokenSelect(addr);
|
renderSendTokenSelect(addr);
|
||||||
updateSendBalance();
|
updateSendBalance();
|
||||||
resetSendValidation();
|
resetSendValidation();
|
||||||
|
pushCurrentView();
|
||||||
showView("send");
|
showView("send");
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -405,4 +442,4 @@ function init(ctx) {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { init, render };
|
module.exports = { init, render, walletListHtml };
|
||||||
|
|||||||
@@ -1,69 +0,0 @@
|
|||||||
const { $, showView, showFlash } = require("./helpers");
|
|
||||||
const { addressFromPrivateKey } = require("../../shared/wallet");
|
|
||||||
const { encryptWithPassword } = require("../../shared/vault");
|
|
||||||
const { state, saveState } = require("../../shared/state");
|
|
||||||
|
|
||||||
function show() {
|
|
||||||
$("import-private-key").value = "";
|
|
||||||
$("import-key-password").value = "";
|
|
||||||
$("import-key-password-confirm").value = "";
|
|
||||||
showView("import-key");
|
|
||||||
}
|
|
||||||
|
|
||||||
function init(ctx) {
|
|
||||||
$("btn-import-key-confirm").addEventListener("click", async () => {
|
|
||||||
const key = $("import-private-key").value.trim();
|
|
||||||
if (!key) {
|
|
||||||
showFlash("Please enter your private key.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
let addr;
|
|
||||||
try {
|
|
||||||
addr = addressFromPrivateKey(key);
|
|
||||||
} catch (e) {
|
|
||||||
showFlash("Invalid private key.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const pw = $("import-key-password").value;
|
|
||||||
const pw2 = $("import-key-password-confirm").value;
|
|
||||||
if (!pw) {
|
|
||||||
showFlash("Please choose a password.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (pw.length < 12) {
|
|
||||||
showFlash("Password must be at least 12 characters.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
if (pw !== pw2) {
|
|
||||||
showFlash("Passwords do not match.");
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const encrypted = await encryptWithPassword(key, pw);
|
|
||||||
const walletNum = state.wallets.length + 1;
|
|
||||||
state.wallets.push({
|
|
||||||
type: "key",
|
|
||||||
name: "Wallet " + walletNum,
|
|
||||||
encryptedSecret: encrypted,
|
|
||||||
addresses: [
|
|
||||||
{ address: addr, balance: "0.0000", tokenBalances: [] },
|
|
||||||
],
|
|
||||||
});
|
|
||||||
state.hasWallet = true;
|
|
||||||
await saveState();
|
|
||||||
ctx.renderWalletList();
|
|
||||||
showView("main");
|
|
||||||
|
|
||||||
ctx.doRefreshAndRender();
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-import-key-back").addEventListener("click", () => {
|
|
||||||
if (!state.hasWallet) {
|
|
||||||
showView("welcome");
|
|
||||||
} else {
|
|
||||||
ctx.renderWalletList();
|
|
||||||
showView("main");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
module.exports = { init, show };
|
|
||||||
@@ -2,19 +2,15 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
formatAddressHtml,
|
formatAddressHtml,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
|
attachCopyHandlers,
|
||||||
|
goBack,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, currentAddress } = require("../../shared/state");
|
const { state, currentAddress, currentNetwork } = require("../../shared/state");
|
||||||
const QRCode = require("qrcode");
|
const QRCode = require("qrcode");
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
function show() {
|
function show() {
|
||||||
const addr = currentAddress();
|
const addr = currentAddress();
|
||||||
const address = addr ? addr.address : "";
|
const address = addr ? addr.address : "";
|
||||||
@@ -24,10 +20,8 @@ function show() {
|
|||||||
? formatAddressHtml(address, ensName, null, title)
|
? formatAddressHtml(address, ensName, null, title)
|
||||||
: "";
|
: "";
|
||||||
$("receive-address-block").dataset.full = address;
|
$("receive-address-block").dataset.full = address;
|
||||||
const link = address ? `https://etherscan.io/address/${address}` : "";
|
// Etherscan link is now included in formatAddressHtml via renderAddressHtml
|
||||||
$("receive-etherscan-link").innerHTML = link
|
$("receive-etherscan-link").innerHTML = "";
|
||||||
? `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`
|
|
||||||
: "";
|
|
||||||
if (address) {
|
if (address) {
|
||||||
QRCode.toCanvas($("receive-qr"), address, {
|
QRCode.toCanvas($("receive-qr"), address, {
|
||||||
width: 200,
|
width: 200,
|
||||||
@@ -51,37 +45,30 @@ function show() {
|
|||||||
warningEl.textContent =
|
warningEl.textContent =
|
||||||
"This is an ERC-20 token. Only send " +
|
"This is an ERC-20 token. Only send " +
|
||||||
symbol +
|
symbol +
|
||||||
" on the Ethereum network to this address. Sending tokens on other networks will result in permanent loss.";
|
" on " +
|
||||||
warningEl.classList.remove("hidden");
|
currentNetwork().name +
|
||||||
|
" to this address. Sending tokens on other networks will result in permanent loss.";
|
||||||
|
warningEl.style.visibility = "visible";
|
||||||
} else {
|
} else {
|
||||||
warningEl.classList.add("hidden");
|
warningEl.textContent = "";
|
||||||
|
warningEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
showView("receive");
|
showView("receive");
|
||||||
|
attachCopyHandlers("view-receive");
|
||||||
}
|
}
|
||||||
|
|
||||||
function init(ctx) {
|
function init(ctx) {
|
||||||
$("receive-address-block").addEventListener("click", () => {
|
|
||||||
const addr = $("receive-address-block").dataset.full;
|
|
||||||
if (addr) {
|
|
||||||
navigator.clipboard.writeText(addr);
|
|
||||||
showFlash("Copied!");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
$("btn-receive-copy").addEventListener("click", () => {
|
$("btn-receive-copy").addEventListener("click", () => {
|
||||||
const addr = $("receive-address-block").dataset.full;
|
const addr = $("receive-address-block").dataset.full;
|
||||||
if (addr) {
|
if (addr) {
|
||||||
navigator.clipboard.writeText(addr);
|
navigator.clipboard.writeText(addr);
|
||||||
showFlash("Copied!");
|
showFlash("Copied!");
|
||||||
|
flashCopyFeedback($("receive-address-block"));
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-receive-back").addEventListener("click", () => {
|
$("btn-receive-back").addEventListener("click", () => {
|
||||||
if (state.selectedToken) {
|
goBack();
|
||||||
ctx.showAddressToken();
|
|
||||||
} else {
|
|
||||||
ctx.showAddressDetail();
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -3,14 +3,18 @@
|
|||||||
const {
|
const {
|
||||||
$,
|
$,
|
||||||
showFlash,
|
showFlash,
|
||||||
addressDotHtml,
|
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
goBack,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state, currentAddress } = require("../../shared/state");
|
const { state, currentAddress } = require("../../shared/state");
|
||||||
let ctx;
|
let ctx;
|
||||||
const { getProvider } = require("../../shared/balances");
|
const { getProvider } = require("../../shared/balances");
|
||||||
const { KNOWN_SYMBOLS, resolveSymbol } = require("../../shared/tokenList");
|
const { resolveSymbol } = require("../../shared/tokenList");
|
||||||
|
const { isLowHolderCount } = require("../../shared/holders");
|
||||||
|
const { isSpoofedSymbol } = require("../../shared/symbolSpoof");
|
||||||
const { getAddress } = require("ethers");
|
const { getAddress } = require("ethers");
|
||||||
|
|
||||||
const ZERO_ADDRESS = "0x0000000000000000000000000000000000000000";
|
const ZERO_ADDRESS = "0x0000000000000000000000000000000000000000";
|
||||||
@@ -113,21 +117,6 @@ function updateToValidation() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
function isSpoofedToken(t) {
|
|
||||||
const upper = (t.symbol || "").toUpperCase();
|
|
||||||
if (!KNOWN_SYMBOLS.has(upper)) return false;
|
|
||||||
const legit = KNOWN_SYMBOLS.get(upper);
|
|
||||||
if (legit === null) return true;
|
|
||||||
return t.address.toLowerCase() !== legit;
|
|
||||||
}
|
|
||||||
|
|
||||||
function renderSendTokenSelect(addr) {
|
function renderSendTokenSelect(addr) {
|
||||||
const sel = $("send-token");
|
const sel = $("send-token");
|
||||||
sel.innerHTML = '<option value="ETH">ETH</option>';
|
sel.innerHTML = '<option value="ETH">ETH</option>';
|
||||||
@@ -135,9 +124,12 @@ function renderSendTokenSelect(addr) {
|
|||||||
(state.fraudContracts || []).map((a) => a.toLowerCase()),
|
(state.fraudContracts || []).map((a) => a.toLowerCase()),
|
||||||
);
|
);
|
||||||
for (const t of addr.tokenBalances || []) {
|
for (const t of addr.tokenBalances || []) {
|
||||||
if (isSpoofedToken(t)) continue;
|
if (isSpoofedSymbol(t.symbol, t.address)) continue;
|
||||||
if (fraudSet.has(t.address.toLowerCase())) continue;
|
if (fraudSet.has(t.address.toLowerCase())) continue;
|
||||||
if (state.hideLowHolderTokens && (t.holders || 0) < 1000) continue;
|
// An unknown holder count does not withhold a token the user holds:
|
||||||
|
// only a count the explorer actually reported as below the threshold
|
||||||
|
// does. Otherwise a missing field makes a real asset unspendable.
|
||||||
|
if (state.hideLowHolderTokens && isLowHolderCount(t.holders)) continue;
|
||||||
const opt = document.createElement("option");
|
const opt = document.createElement("option");
|
||||||
opt.value = t.address;
|
opt.value = t.address;
|
||||||
opt.textContent = t.symbol;
|
opt.textContent = t.symbol;
|
||||||
@@ -148,24 +140,12 @@ function renderSendTokenSelect(addr) {
|
|||||||
function updateSendBalance() {
|
function updateSendBalance() {
|
||||||
const addr = currentAddress();
|
const addr = currentAddress();
|
||||||
if (!addr) return;
|
if (!addr) return;
|
||||||
const dot = addressDotHtml(addr.address);
|
|
||||||
const link = `https://etherscan.io/address/${addr.address}`;
|
|
||||||
const extLink = `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
|
||||||
const title = addressTitle(addr.address, state.wallets);
|
const title = addressTitle(addr.address, state.wallets);
|
||||||
let fromHtml = "";
|
$("send-from").innerHTML = renderAddressHtml(addr.address, {
|
||||||
if (title) {
|
title,
|
||||||
fromHtml += `<div class="flex items-center font-bold">${dot}${escapeHtml(title)}</div>`;
|
ensName: addr.ensName,
|
||||||
if (addr.ensName) {
|
});
|
||||||
fromHtml += `<div>${escapeHtml(addr.ensName)}</div>`;
|
attachCopyHandlers($("send-from"));
|
||||||
}
|
|
||||||
fromHtml += `<div class="break-all">${escapeHtml(addr.address)}${extLink}</div>`;
|
|
||||||
} else if (addr.ensName) {
|
|
||||||
fromHtml += `<div class="flex items-center font-bold">${dot}${escapeHtml(addr.ensName)}</div>`;
|
|
||||||
fromHtml += `<div class="break-all">${escapeHtml(addr.address)}${extLink}</div>`;
|
|
||||||
} else {
|
|
||||||
fromHtml += `<div class="flex items-center">${dot}<span class="break-all">${escapeHtml(addr.address)}</span>${extLink}</div>`;
|
|
||||||
}
|
|
||||||
$("send-from").innerHTML = fromHtml;
|
|
||||||
const token = state.selectedToken || $("send-token").value;
|
const token = state.selectedToken || $("send-token").value;
|
||||||
if (token === "ETH") {
|
if (token === "ETH") {
|
||||||
$("send-balance").textContent =
|
$("send-balance").textContent =
|
||||||
@@ -268,11 +248,7 @@ function init(_ctx) {
|
|||||||
$("btn-send-back").addEventListener("click", () => {
|
$("btn-send-back").addEventListener("click", () => {
|
||||||
$("send-token").classList.remove("hidden");
|
$("send-token").classList.remove("hidden");
|
||||||
$("send-token-static").classList.add("hidden");
|
$("send-token-static").classList.add("hidden");
|
||||||
if (state.selectedToken) {
|
goBack();
|
||||||
ctx.showAddressToken();
|
|
||||||
} else {
|
|
||||||
ctx.showAddressDetail();
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,12 +1,40 @@
|
|||||||
const { $, showView, showFlash, escapeHtml } = require("./helpers");
|
const {
|
||||||
const { state, saveState } = require("../../shared/state");
|
$,
|
||||||
const { ETHEREUM_MAINNET_CHAIN_ID } = require("../../shared/constants");
|
showView,
|
||||||
const { log, debugFetch } = require("../../shared/log");
|
updateDebugBanner,
|
||||||
|
showFlash,
|
||||||
|
escapeHtml,
|
||||||
|
flashCopyFeedback,
|
||||||
|
goBack,
|
||||||
|
pushCurrentView,
|
||||||
|
} = require("./helpers");
|
||||||
|
const { applyTheme } = require("../theme");
|
||||||
|
const {
|
||||||
|
DUST_THRESHOLD_MESSAGE,
|
||||||
|
parseDustThresholdGwei,
|
||||||
|
} = require("../dustThreshold");
|
||||||
|
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||||
|
const { NETWORKS, SUPPORTED_CHAIN_IDS } = require("../../shared/networks");
|
||||||
|
const { onChainSwitch } = require("../../shared/chainSwitch");
|
||||||
|
const { log, debugFetch, setRuntimeDebug } = require("../../shared/log");
|
||||||
const deleteWallet = require("./deleteWallet");
|
const deleteWallet = require("./deleteWallet");
|
||||||
|
const showPhrase = require("./showPhrase");
|
||||||
|
const { walletHasRecoveryPhrase } = require("../../shared/wallet");
|
||||||
|
const {
|
||||||
|
BUILD_VERSION,
|
||||||
|
BUILD_LICENSE,
|
||||||
|
BUILD_AUTHOR,
|
||||||
|
BUILD_COMMIT,
|
||||||
|
BUILD_DATE,
|
||||||
|
GITEA_COMMIT_URL,
|
||||||
|
} = require("../../shared/buildInfo");
|
||||||
|
|
||||||
const runtime =
|
const runtime =
|
||||||
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
||||||
|
|
||||||
|
let versionClickCount = 0;
|
||||||
|
let versionClickTimer = null;
|
||||||
|
|
||||||
function renderSiteList(containerId, siteMap, stateKey) {
|
function renderSiteList(containerId, siteMap, stateKey) {
|
||||||
const container = $(containerId);
|
const container = $(containerId);
|
||||||
const hostnames = [...new Set(Object.values(siteMap).flat())];
|
const hostnames = [...new Set(Object.values(siteMap).flat())];
|
||||||
@@ -77,17 +105,34 @@ function renderWalletListSettings() {
|
|||||||
const name = escapeHtml(wallet.name || "Wallet " + (idx + 1));
|
const name = escapeHtml(wallet.name || "Wallet " + (idx + 1));
|
||||||
html += `<div class="flex justify-between items-center text-xs py-1 border-b border-border-light">`;
|
html += `<div class="flex justify-between items-center text-xs py-1 border-b border-border-light">`;
|
||||||
html += `<span class="settings-wallet-name cursor-pointer underline decoration-dashed" data-idx="${idx}">${name}</span>`;
|
html += `<span class="settings-wallet-name cursor-pointer underline decoration-dashed" data-idx="${idx}">${name}</span>`;
|
||||||
|
html += `<span class="flex items-center gap-1 flex-shrink-0">`;
|
||||||
|
// Key and xprv wallets have no recovery phrase, so they are never
|
||||||
|
// offered the action at all.
|
||||||
|
if (walletHasRecoveryPhrase(wallet)) {
|
||||||
|
html += `<button class="btn-show-phrase border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-idx="${idx}" title="Show recovery phrase">[recovery phrase]</button>`;
|
||||||
|
}
|
||||||
html += `<button class="btn-delete-wallet border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-idx="${idx}">[x]</button>`;
|
html += `<button class="btn-delete-wallet border border-border px-1 hover:bg-fg hover:text-bg cursor-pointer" data-idx="${idx}">[x]</button>`;
|
||||||
|
html += `</span>`;
|
||||||
html += `</div>`;
|
html += `</div>`;
|
||||||
});
|
});
|
||||||
container.innerHTML = html;
|
container.innerHTML = html;
|
||||||
container.querySelectorAll(".btn-delete-wallet").forEach((btn) => {
|
container.querySelectorAll(".btn-delete-wallet").forEach((btn) => {
|
||||||
btn.addEventListener("click", () => {
|
btn.addEventListener("click", () => {
|
||||||
const idx = parseInt(btn.dataset.idx, 10);
|
const idx = parseInt(btn.dataset.idx, 10);
|
||||||
|
pushCurrentView();
|
||||||
deleteWallet.show(idx);
|
deleteWallet.show(idx);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
container.querySelectorAll(".btn-show-phrase").forEach((btn) => {
|
||||||
|
btn.addEventListener("click", () => {
|
||||||
|
const idx = parseInt(btn.dataset.idx, 10);
|
||||||
|
// No pushCurrentView() here: showPhrase.show() refuses
|
||||||
|
// non-HD wallets and pushes only when it navigates.
|
||||||
|
showPhrase.show(idx);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
// Inline rename on click
|
// Inline rename on click
|
||||||
container.querySelectorAll(".settings-wallet-name").forEach((span) => {
|
container.querySelectorAll(".settings-wallet-name").forEach((span) => {
|
||||||
span.addEventListener("click", () => {
|
span.addEventListener("click", () => {
|
||||||
@@ -124,10 +169,36 @@ function renderWalletListSettings() {
|
|||||||
function show() {
|
function show() {
|
||||||
$("settings-rpc").value = state.rpcUrl;
|
$("settings-rpc").value = state.rpcUrl;
|
||||||
$("settings-blockscout").value = state.blockscoutUrl;
|
$("settings-blockscout").value = state.blockscoutUrl;
|
||||||
|
const networkSelect = $("settings-network");
|
||||||
|
if (networkSelect) {
|
||||||
|
networkSelect.value = state.networkId;
|
||||||
|
}
|
||||||
renderTrackedTokens();
|
renderTrackedTokens();
|
||||||
renderSiteLists();
|
renderSiteLists();
|
||||||
renderWalletListSettings();
|
renderWalletListSettings();
|
||||||
|
|
||||||
|
// Populate About well
|
||||||
|
$("about-license").textContent = BUILD_LICENSE;
|
||||||
|
// Show only the name part of the author field (strip email)
|
||||||
|
const authorName = BUILD_AUTHOR.replace(/\s*<[^>]+>/, "");
|
||||||
|
$("about-author").textContent = authorName;
|
||||||
|
$("about-version").textContent = BUILD_VERSION;
|
||||||
|
$("about-release-date").textContent = BUILD_DATE;
|
||||||
|
$("about-commit-link").textContent = BUILD_COMMIT;
|
||||||
|
$("about-commit-link").href = GITEA_COMMIT_URL;
|
||||||
|
|
||||||
|
// Reset version click counter each time settings opens
|
||||||
|
versionClickCount = 0;
|
||||||
|
|
||||||
|
// Show debug well if debug mode is already enabled
|
||||||
|
const debugWell = $("settings-debug-well");
|
||||||
|
if (state.debugMode) {
|
||||||
|
debugWell.style.display = "";
|
||||||
|
} else {
|
||||||
|
debugWell.style.display = "none";
|
||||||
|
}
|
||||||
|
$("settings-debug-mode").checked = state.debugMode;
|
||||||
|
|
||||||
showView("settings");
|
showView("settings");
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -142,6 +213,7 @@ function renderSiteLists() {
|
|||||||
|
|
||||||
function init(ctx) {
|
function init(ctx) {
|
||||||
deleteWallet.init(ctx);
|
deleteWallet.init(ctx);
|
||||||
|
showPhrase.init();
|
||||||
|
|
||||||
$("btn-save-rpc").addEventListener("click", async () => {
|
$("btn-save-rpc").addEventListener("click", async () => {
|
||||||
const url = $("settings-rpc").value.trim();
|
const url = $("settings-rpc").value.trim();
|
||||||
@@ -167,9 +239,12 @@ function init(ctx) {
|
|||||||
showFlash("Endpoint returned error: " + json.error.message);
|
showFlash("Endpoint returned error: " + json.error.message);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (json.result !== ETHEREUM_MAINNET_CHAIN_ID) {
|
const net = currentNetwork();
|
||||||
|
if (json.result !== net.chainId) {
|
||||||
showFlash(
|
showFlash(
|
||||||
"Wrong network (expected mainnet, got chain " +
|
"Wrong network (expected " +
|
||||||
|
net.name +
|
||||||
|
", got chain " +
|
||||||
json.result +
|
json.result +
|
||||||
").",
|
").",
|
||||||
);
|
);
|
||||||
@@ -208,12 +283,36 @@ function init(ctx) {
|
|||||||
showFlash("Saved.");
|
showFlash("Saved.");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
const networkSelect = $("settings-network");
|
||||||
|
if (networkSelect) {
|
||||||
|
networkSelect.addEventListener("change", async () => {
|
||||||
|
const newId = networkSelect.value;
|
||||||
|
const net = await onChainSwitch(newId);
|
||||||
|
$("settings-rpc").value = state.rpcUrl;
|
||||||
|
$("settings-blockscout").value = state.blockscoutUrl;
|
||||||
|
showFlash("Switched to " + net.name + ".");
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
$("settings-show-zero-balances").checked = state.showZeroBalanceTokens;
|
$("settings-show-zero-balances").checked = state.showZeroBalanceTokens;
|
||||||
$("settings-show-zero-balances").addEventListener("change", async () => {
|
$("settings-show-zero-balances").addEventListener("change", async () => {
|
||||||
state.showZeroBalanceTokens = $("settings-show-zero-balances").checked;
|
state.showZeroBalanceTokens = $("settings-show-zero-balances").checked;
|
||||||
await saveState();
|
await saveState();
|
||||||
});
|
});
|
||||||
|
|
||||||
|
$("settings-theme").value = state.theme;
|
||||||
|
$("settings-theme").addEventListener("change", async () => {
|
||||||
|
state.theme = $("settings-theme").value;
|
||||||
|
await saveState();
|
||||||
|
applyTheme(state.theme);
|
||||||
|
});
|
||||||
|
|
||||||
|
$("settings-hide-spoofed-symbols").checked = state.hideSpoofedSymbols;
|
||||||
|
$("settings-hide-spoofed-symbols").addEventListener("change", async () => {
|
||||||
|
state.hideSpoofedSymbols = $("settings-hide-spoofed-symbols").checked;
|
||||||
|
await saveState();
|
||||||
|
});
|
||||||
|
|
||||||
$("settings-hide-low-holders").checked = state.hideLowHolderTokens;
|
$("settings-hide-low-holders").checked = state.hideLowHolderTokens;
|
||||||
$("settings-hide-low-holders").addEventListener("change", async () => {
|
$("settings-hide-low-holders").addEventListener("change", async () => {
|
||||||
state.hideLowHolderTokens = $("settings-hide-low-holders").checked;
|
state.hideLowHolderTokens = $("settings-hide-low-holders").checked;
|
||||||
@@ -234,11 +333,24 @@ function init(ctx) {
|
|||||||
|
|
||||||
$("settings-dust-threshold").value = state.dustThresholdGwei;
|
$("settings-dust-threshold").value = state.dustThresholdGwei;
|
||||||
$("settings-dust-threshold").addEventListener("change", async () => {
|
$("settings-dust-threshold").addEventListener("change", async () => {
|
||||||
const val = parseInt($("settings-dust-threshold").value, 10);
|
const val = parseDustThresholdGwei($("settings-dust-threshold").value);
|
||||||
if (!isNaN(val) && val >= 0) {
|
// Rejected input is never coerced. The field is put back to the
|
||||||
|
// stored threshold so it never shows a value the wallet is not
|
||||||
|
// using, and the message says what the field wants so the snap-back
|
||||||
|
// is explained rather than silent.
|
||||||
|
if (val === null) {
|
||||||
|
showFlash(DUST_THRESHOLD_MESSAGE);
|
||||||
|
} else {
|
||||||
state.dustThresholdGwei = val;
|
state.dustThresholdGwei = val;
|
||||||
await saveState();
|
await saveState();
|
||||||
}
|
}
|
||||||
|
$("settings-dust-threshold").value = state.dustThresholdGwei;
|
||||||
|
});
|
||||||
|
|
||||||
|
$("settings-utc-timestamps").checked = state.utcTimestamps;
|
||||||
|
$("settings-utc-timestamps").addEventListener("change", async () => {
|
||||||
|
state.utcTimestamps = $("settings-utc-timestamps").checked;
|
||||||
|
await saveState();
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-main-add-wallet").addEventListener("click", ctx.showAddWalletView);
|
$("btn-main-add-wallet").addEventListener("click", ctx.showAddWalletView);
|
||||||
@@ -248,9 +360,68 @@ function init(ctx) {
|
|||||||
ctx.showSettingsAddTokenView,
|
ctx.showSettingsAddTokenView,
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Bright saturated colors for easter egg flashes (clicks 6–10)
|
||||||
|
const easterEggColors = [
|
||||||
|
"#ff0055", // hot pink
|
||||||
|
"#00cc44", // vivid green
|
||||||
|
"#3366ff", // electric blue
|
||||||
|
"#ff9900", // bright orange
|
||||||
|
"#aa00ff", // vivid purple
|
||||||
|
];
|
||||||
|
|
||||||
|
// Easter egg: click version 10 times to reveal the debug well.
|
||||||
|
// Each click does a copy-flash animation. After 5 clicks, each
|
||||||
|
// additional click flashes a different bright saturated color.
|
||||||
|
$("about-version").addEventListener("click", () => {
|
||||||
|
versionClickCount++;
|
||||||
|
clearTimeout(versionClickTimer);
|
||||||
|
// Reset counter if user stops clicking for 3 seconds
|
||||||
|
versionClickTimer = setTimeout(() => {
|
||||||
|
versionClickCount = 0;
|
||||||
|
}, 3000);
|
||||||
|
|
||||||
|
const el = $("about-version");
|
||||||
|
|
||||||
|
if (versionClickCount > 5) {
|
||||||
|
// Colored flash for clicks 6–10
|
||||||
|
const colorIdx = versionClickCount - 6;
|
||||||
|
const color = easterEggColors[colorIdx % easterEggColors.length];
|
||||||
|
el.classList.remove("copy-flash-fade");
|
||||||
|
el.style.backgroundColor = color;
|
||||||
|
el.style.color = "#ffffff";
|
||||||
|
setTimeout(() => {
|
||||||
|
el.style.backgroundColor = "";
|
||||||
|
el.style.color = "";
|
||||||
|
el.classList.add("copy-flash-fade");
|
||||||
|
setTimeout(() => {
|
||||||
|
el.classList.remove("copy-flash-fade");
|
||||||
|
}, 275);
|
||||||
|
}, 75);
|
||||||
|
} else {
|
||||||
|
// Standard copy-flash for clicks 1–5
|
||||||
|
flashCopyFeedback(el);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (versionClickCount >= 10) {
|
||||||
|
versionClickCount = 0;
|
||||||
|
clearTimeout(versionClickTimer);
|
||||||
|
$("settings-debug-well").style.display = "";
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// Debug mode toggle — update runtime flag, persist, and re-render banner
|
||||||
|
$("settings-debug-mode").addEventListener("change", async () => {
|
||||||
|
state.debugMode = $("settings-debug-mode").checked;
|
||||||
|
setRuntimeDebug(state.debugMode);
|
||||||
|
await saveState();
|
||||||
|
updateDebugBanner(state.currentView);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Sync runtime debug flag on init
|
||||||
|
setRuntimeDebug(state.debugMode);
|
||||||
|
|
||||||
$("btn-settings-back").addEventListener("click", () => {
|
$("btn-settings-back").addEventListener("click", () => {
|
||||||
ctx.renderWalletList();
|
goBack();
|
||||||
showView("main");
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
const { $, showView, showFlash } = require("./helpers");
|
const { $, showView, showFlash, goBack } = require("./helpers");
|
||||||
const { getTopTokens } = require("../../shared/tokenList");
|
const { getTopTokens } = require("../../shared/tokenList");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState } = require("../../shared/state");
|
||||||
const { lookupTokenInfo } = require("../../shared/balances");
|
const { lookupTokenInfo } = require("../../shared/balances");
|
||||||
@@ -73,7 +73,8 @@ function renderDropdown() {
|
|||||||
|
|
||||||
function show() {
|
function show() {
|
||||||
$("settings-addtoken-address").value = "";
|
$("settings-addtoken-address").value = "";
|
||||||
$("settings-addtoken-info").classList.add("hidden");
|
$("settings-addtoken-info").textContent = "";
|
||||||
|
$("settings-addtoken-info").style.visibility = "hidden";
|
||||||
renderTop10();
|
renderTop10();
|
||||||
renderDropdown();
|
renderDropdown();
|
||||||
showView("settings-addtoken");
|
showView("settings-addtoken");
|
||||||
@@ -83,7 +84,7 @@ function init(_ctx) {
|
|||||||
ctx = _ctx;
|
ctx = _ctx;
|
||||||
|
|
||||||
$("btn-settings-addtoken-back").addEventListener("click", () => {
|
$("btn-settings-addtoken-back").addEventListener("click", () => {
|
||||||
ctx.showSettingsView();
|
goBack();
|
||||||
});
|
});
|
||||||
|
|
||||||
$("btn-settings-addtoken-select").addEventListener("click", async () => {
|
$("btn-settings-addtoken-select").addEventListener("click", async () => {
|
||||||
@@ -129,7 +130,7 @@ function init(_ctx) {
|
|||||||
}
|
}
|
||||||
const infoEl = $("settings-addtoken-info");
|
const infoEl = $("settings-addtoken-info");
|
||||||
infoEl.textContent = "Looking up token...";
|
infoEl.textContent = "Looking up token...";
|
||||||
infoEl.classList.remove("hidden");
|
infoEl.style.visibility = "visible";
|
||||||
log.debugf("Looking up token contract", addr);
|
log.debugf("Looking up token contract", addr);
|
||||||
try {
|
try {
|
||||||
const info = await lookupTokenInfo(addr, state.rpcUrl);
|
const info = await lookupTokenInfo(addr, state.rpcUrl);
|
||||||
@@ -143,7 +144,8 @@ function init(_ctx) {
|
|||||||
await saveState();
|
await saveState();
|
||||||
showFlash("Added " + info.symbol);
|
showFlash("Added " + info.symbol);
|
||||||
$("settings-addtoken-address").value = "";
|
$("settings-addtoken-address").value = "";
|
||||||
infoEl.classList.add("hidden");
|
infoEl.textContent = "";
|
||||||
|
infoEl.style.visibility = "hidden";
|
||||||
renderTop10();
|
renderTop10();
|
||||||
renderDropdown();
|
renderDropdown();
|
||||||
ctx.doRefreshAndRender();
|
ctx.doRefreshAndRender();
|
||||||
@@ -151,7 +153,8 @@ function init(_ctx) {
|
|||||||
const detail = e.shortMessage || e.message || String(e);
|
const detail = e.shortMessage || e.message || String(e);
|
||||||
log.errorf("Token lookup failed for", addr, detail);
|
log.errorf("Token lookup failed for", addr, detail);
|
||||||
showFlash(detail);
|
showFlash(detail);
|
||||||
infoEl.classList.add("hidden");
|
infoEl.textContent = "";
|
||||||
|
infoEl.style.visibility = "hidden";
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
154
src/popup/views/showPhrase.js
Normal file
154
src/popup/views/showPhrase.js
Normal file
@@ -0,0 +1,154 @@
|
|||||||
|
// Recovery phrase display for HD wallets.
|
||||||
|
//
|
||||||
|
// The phrase is the secret that owns every address in the wallet, so it is
|
||||||
|
// handled under four rules:
|
||||||
|
//
|
||||||
|
// 1. Only an HD wallet reaches this screen (walletHasRecoveryPhrase).
|
||||||
|
// 2. Nothing is decrypted, and nothing is written into the DOM, until
|
||||||
|
// decryptWithPassword has accepted the password.
|
||||||
|
// 3. Leaving the screen by any path wipes it, via the onViewLeave hook,
|
||||||
|
// and a decrypt still in flight when that happens is discarded
|
||||||
|
// instead of written (revealGeneration).
|
||||||
|
// 4. The phrase never reaches the logger. This module deliberately does
|
||||||
|
// not import src/shared/log.js, and the failed-decrypt path reports a
|
||||||
|
// fixed sentence rather than the caught error.
|
||||||
|
//
|
||||||
|
// The phrase is also never assigned to `state`, so it cannot be persisted
|
||||||
|
// to extension storage, and "show-phrase" is excluded from RESTORABLE_VIEWS
|
||||||
|
// so the popup can never reopen onto it.
|
||||||
|
|
||||||
|
const {
|
||||||
|
$,
|
||||||
|
showView,
|
||||||
|
showFlash,
|
||||||
|
flashCopyFeedback,
|
||||||
|
goBack,
|
||||||
|
onViewLeave,
|
||||||
|
pushCurrentView,
|
||||||
|
} = require("./helpers");
|
||||||
|
const { state } = require("../../shared/state");
|
||||||
|
const { decryptWithPassword } = require("../../shared/vault");
|
||||||
|
const { walletHasRecoveryPhrase } = require("../../shared/wallet");
|
||||||
|
|
||||||
|
const VIEW = "show-phrase";
|
||||||
|
|
||||||
|
let walletIndex = null;
|
||||||
|
|
||||||
|
// Bumped by every clear(), which is what leaving the screen runs. reveal()
|
||||||
|
// captures it before awaiting the decrypt and refuses to touch the DOM if
|
||||||
|
// it has moved: a decrypt still in flight when the screen is left would
|
||||||
|
// otherwise write the phrase *after* the wipe, with nothing scheduled to
|
||||||
|
// wipe it again, leaving it in the hidden view for the life of the popup.
|
||||||
|
let revealGeneration = 0;
|
||||||
|
|
||||||
|
// True only if the reveal that captured `generation` is still the live one:
|
||||||
|
// the screen has not been left, cleared, or re-entered for another wallet
|
||||||
|
// since it started.
|
||||||
|
function isCurrentReveal(generation) {
|
||||||
|
return (
|
||||||
|
generation === revealGeneration &&
|
||||||
|
walletIndex !== null &&
|
||||||
|
state.currentView === VIEW
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function fail(message) {
|
||||||
|
$("show-phrase-flash").textContent = message;
|
||||||
|
$("show-phrase-flash").style.visibility = "visible";
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wipe every trace of the phrase and drop the wallet selection. Safe to
|
||||||
|
// call when nothing was ever revealed, and safe to call twice.
|
||||||
|
function clear() {
|
||||||
|
walletIndex = null;
|
||||||
|
revealGeneration += 1;
|
||||||
|
$("show-phrase-value").textContent = "";
|
||||||
|
$("show-phrase-password").value = "";
|
||||||
|
$("show-phrase-result").classList.add("hidden");
|
||||||
|
$("show-phrase-password-section").classList.remove("hidden");
|
||||||
|
$("show-phrase-flash").textContent = "";
|
||||||
|
$("show-phrase-flash").style.visibility = "hidden";
|
||||||
|
}
|
||||||
|
|
||||||
|
function show(walletIdx) {
|
||||||
|
const wallet = state.wallets[walletIdx];
|
||||||
|
if (!walletHasRecoveryPhrase(wallet)) {
|
||||||
|
showFlash("This wallet does not have a recovery phrase.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
clear();
|
||||||
|
walletIndex = walletIdx;
|
||||||
|
$("show-phrase-wallet-name").textContent =
|
||||||
|
wallet.name || "Wallet " + (walletIdx + 1);
|
||||||
|
// Pushed here rather than by the caller: this function can return
|
||||||
|
// without navigating, and a push that happened anyway would leave an
|
||||||
|
// entry on the stack that no screen transition matches.
|
||||||
|
pushCurrentView();
|
||||||
|
showView(VIEW);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function reveal() {
|
||||||
|
const password = $("show-phrase-password").value;
|
||||||
|
if (!password) {
|
||||||
|
fail("Please enter your password.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (walletIndex === null) {
|
||||||
|
fail("No wallet is selected.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const wallet = state.wallets[walletIndex];
|
||||||
|
if (!walletHasRecoveryPhrase(wallet)) {
|
||||||
|
fail("This wallet does not have a recovery phrase.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const btn = $("btn-show-phrase-reveal");
|
||||||
|
btn.disabled = true;
|
||||||
|
btn.classList.add("text-muted");
|
||||||
|
const generation = revealGeneration;
|
||||||
|
try {
|
||||||
|
const phrase = await decryptWithPassword(
|
||||||
|
wallet.encryptedSecret,
|
||||||
|
password,
|
||||||
|
);
|
||||||
|
// The only suspension point in this view, and the only place a
|
||||||
|
// secret is written: if the screen was left while the decrypt ran,
|
||||||
|
// the wipe has already happened and this write must not land.
|
||||||
|
if (!isCurrentReveal(generation)) return;
|
||||||
|
$("show-phrase-password").value = "";
|
||||||
|
$("show-phrase-password-section").classList.add("hidden");
|
||||||
|
$("show-phrase-value").textContent = phrase;
|
||||||
|
$("show-phrase-result").classList.remove("hidden");
|
||||||
|
$("show-phrase-flash").textContent = "";
|
||||||
|
$("show-phrase-flash").style.visibility = "hidden";
|
||||||
|
} catch {
|
||||||
|
if (!isCurrentReveal(generation)) return;
|
||||||
|
// Deliberately not the caught error: the message is fixed so that
|
||||||
|
// nothing derived from the ciphertext or the attempt can surface.
|
||||||
|
fail("That password is not correct. Please try again.");
|
||||||
|
} finally {
|
||||||
|
btn.disabled = false;
|
||||||
|
btn.classList.remove("text-muted");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function init() {
|
||||||
|
onViewLeave(VIEW, clear);
|
||||||
|
|
||||||
|
$("btn-show-phrase-back").addEventListener("click", () => {
|
||||||
|
goBack();
|
||||||
|
});
|
||||||
|
|
||||||
|
$("btn-show-phrase-reveal").addEventListener("click", reveal);
|
||||||
|
|
||||||
|
$("show-phrase-value").addEventListener("click", () => {
|
||||||
|
const phrase = $("show-phrase-value").textContent;
|
||||||
|
if (!phrase) return;
|
||||||
|
navigator.clipboard.writeText(phrase);
|
||||||
|
showFlash("Copied!");
|
||||||
|
flashCopyFeedback($("show-phrase-value"));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { init, show };
|
||||||
@@ -5,31 +5,43 @@ const {
|
|||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
showFlash,
|
||||||
addressDotHtml,
|
flashCopyFeedback,
|
||||||
addressTitle,
|
addressTitle,
|
||||||
|
addressDotHtml,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
isoDate,
|
isoDate,
|
||||||
timeAgo,
|
timeAgo,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
copyableHtml,
|
||||||
|
etherscanLinkHtml,
|
||||||
|
goBack,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { state } = require("../../shared/state");
|
const { state, currentNetwork } = require("../../shared/state");
|
||||||
|
const { formatEther, formatUnits } = require("ethers");
|
||||||
const makeBlockie = require("ethereum-blockies-base64");
|
const makeBlockie = require("ethereum-blockies-base64");
|
||||||
const { log, debugFetch } = require("../../shared/log");
|
const { log, debugFetch } = require("../../shared/log");
|
||||||
const { decodeCalldata } = require("./approval");
|
const { decodeCalldata } = require("./approval");
|
||||||
|
|
||||||
const EXT_ICON =
|
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
|
||||||
|
|
||||||
let ctx;
|
let ctx;
|
||||||
|
|
||||||
function copyableHtml(text, extraClass) {
|
/**
|
||||||
const cls =
|
* Determine a human-readable transaction type string from tx fields.
|
||||||
"underline decoration-dashed cursor-pointer" +
|
*/
|
||||||
(extraClass ? " " + extraClass : "");
|
function getTransactionType(tx) {
|
||||||
return `<span class="${cls}" data-copy="${escapeHtml(text)}">${escapeHtml(text)}</span>`;
|
if (!tx.to) return "Contract Creation";
|
||||||
|
if (tx.direction === "contract") {
|
||||||
|
if (tx.directionLabel === "Swap") return "Swap";
|
||||||
|
if (
|
||||||
|
tx.method === "approve" ||
|
||||||
|
tx.directionLabel === "Approve" ||
|
||||||
|
tx.method === "setApprovalForAll"
|
||||||
|
)
|
||||||
|
return "Token Approval";
|
||||||
|
return "Contract Call";
|
||||||
|
}
|
||||||
|
if (tx.symbol && tx.symbol !== "ETH") return "ERC-20 Token Transfer";
|
||||||
|
return "Native ETH Transfer";
|
||||||
}
|
}
|
||||||
|
|
||||||
function blockieHtml(address) {
|
function blockieHtml(address) {
|
||||||
@@ -37,44 +49,16 @@ function blockieHtml(address) {
|
|||||||
return `<img src="${src}" width="48" height="48" style="image-rendering:pixelated;border-radius:50%;display:inline-block">`;
|
return `<img src="${src}" width="48" height="48" style="image-rendering:pixelated;border-radius:50%;display:inline-block">`;
|
||||||
}
|
}
|
||||||
|
|
||||||
function etherscanLinkHtml(url) {
|
function txAddressHtml(address, ensName, title) {
|
||||||
|
const blockie = blockieHtml(address);
|
||||||
return (
|
return (
|
||||||
`<a href="${url}" target="_blank" rel="noopener" ` +
|
`<div class="mb-1">${blockie}</div>` +
|
||||||
`class="inline-flex items-center"` +
|
renderAddressHtml(address, { title, ensName })
|
||||||
`>${EXT_ICON}</a>`
|
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
function txAddressHtml(address, ensName, title) {
|
|
||||||
const blockie = blockieHtml(address);
|
|
||||||
const dot = addressDotHtml(address);
|
|
||||||
const link = `https://etherscan.io/address/${address}`;
|
|
||||||
const extLink = etherscanLinkHtml(link);
|
|
||||||
let html = `<div class="mb-1">${blockie}</div>`;
|
|
||||||
if (title) {
|
|
||||||
html += `<div class="font-bold">${escapeHtml(title)}</div>`;
|
|
||||||
}
|
|
||||||
if (ensName) {
|
|
||||||
html +=
|
|
||||||
`<div class="flex items-center">${dot}` +
|
|
||||||
copyableHtml(ensName, "") +
|
|
||||||
`</div>` +
|
|
||||||
`<div class="flex items-center">${dot}` +
|
|
||||||
copyableHtml(address, "break-all") +
|
|
||||||
extLink +
|
|
||||||
`</div>`;
|
|
||||||
} else {
|
|
||||||
html +=
|
|
||||||
`<div class="flex items-center">${dot}` +
|
|
||||||
copyableHtml(address, "break-all") +
|
|
||||||
extLink +
|
|
||||||
`</div>`;
|
|
||||||
}
|
|
||||||
return html;
|
|
||||||
}
|
|
||||||
|
|
||||||
function txHashHtml(hash) {
|
function txHashHtml(hash) {
|
||||||
const link = `https://etherscan.io/tx/${hash}`;
|
const link = `${currentNetwork().explorerUrl}/tx/${hash}`;
|
||||||
const extLink = etherscanLinkHtml(link);
|
const extLink = etherscanLinkHtml(link);
|
||||||
return copyableHtml(hash, "break-all") + extLink;
|
return copyableHtml(hash, "break-all") + extLink;
|
||||||
}
|
}
|
||||||
@@ -98,6 +82,7 @@ function show(tx) {
|
|||||||
direction: tx.direction || null,
|
direction: tx.direction || null,
|
||||||
isContractCall: tx.isContractCall || false,
|
isContractCall: tx.isContractCall || false,
|
||||||
method: tx.method || null,
|
method: tx.method || null,
|
||||||
|
contractAddress: tx.contractAddress || null,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
render();
|
render();
|
||||||
@@ -134,47 +119,162 @@ function render() {
|
|||||||
nativeEl.parentElement.classList.add("hidden");
|
nativeEl.parentElement.classList.add("hidden");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Show type label for contract interactions (Swap, Execute, etc.)
|
// Always show transaction type as the first field
|
||||||
const typeSection = $("tx-detail-type-section");
|
const typeSection = $("tx-detail-type-section");
|
||||||
const typeEl = $("tx-detail-type");
|
const typeEl = $("tx-detail-type");
|
||||||
const headingEl = $("tx-detail-heading");
|
const headingEl = $("tx-detail-heading");
|
||||||
if (tx.direction === "contract" && tx.directionLabel) {
|
if (typeSection && typeEl) {
|
||||||
if (typeSection) {
|
typeEl.textContent = getTransactionType(tx);
|
||||||
typeEl.textContent = tx.directionLabel;
|
typeSection.classList.remove("hidden");
|
||||||
typeSection.classList.remove("hidden");
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
if (typeSection) typeSection.classList.add("hidden");
|
|
||||||
}
|
}
|
||||||
if (headingEl) headingEl.textContent = "Transaction";
|
if (headingEl) headingEl.textContent = "Transaction";
|
||||||
|
|
||||||
// Hide calldata and raw data sections; re-fetch if this is a contract call
|
// Token contract address (for ERC-20 transfers)
|
||||||
|
const tokenContractSection = $("tx-detail-token-contract-section");
|
||||||
|
const tokenContractEl = $("tx-detail-token-contract");
|
||||||
|
if (tokenContractSection && tokenContractEl) {
|
||||||
|
if (tx.contractAddress) {
|
||||||
|
const dot = addressDotHtml(tx.contractAddress);
|
||||||
|
const link = `${currentNetwork().explorerUrl}/token/${tx.contractAddress}`;
|
||||||
|
tokenContractEl.innerHTML =
|
||||||
|
`<div class="flex items-center">${dot}` +
|
||||||
|
copyableHtml(tx.contractAddress, "break-all") +
|
||||||
|
etherscanLinkHtml(link) +
|
||||||
|
`</div>`;
|
||||||
|
tokenContractSection.classList.remove("hidden");
|
||||||
|
} else {
|
||||||
|
tokenContractSection.classList.add("hidden");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Hide calldata and raw data sections; always fetch full tx details
|
||||||
const calldataSection = $("tx-detail-calldata-section");
|
const calldataSection = $("tx-detail-calldata-section");
|
||||||
if (calldataSection) calldataSection.classList.add("hidden");
|
if (calldataSection) calldataSection.classList.add("hidden");
|
||||||
const rawDataSection = $("tx-detail-rawdata-section");
|
const rawDataSection = $("tx-detail-rawdata-section");
|
||||||
if (rawDataSection) rawDataSection.classList.add("hidden");
|
if (rawDataSection) rawDataSection.classList.add("hidden");
|
||||||
|
|
||||||
if (tx.isContractCall || tx.direction === "contract") {
|
// Hide on-chain detail sections until populated
|
||||||
loadCalldata(tx.hash, tx.to);
|
for (const id of [
|
||||||
|
"tx-detail-block-section",
|
||||||
|
"tx-detail-nonce-section",
|
||||||
|
"tx-detail-fee-section",
|
||||||
|
"tx-detail-gasprice-section",
|
||||||
|
"tx-detail-gasused-section",
|
||||||
|
"tx-detail-network-section",
|
||||||
|
]) {
|
||||||
|
const el = $(id);
|
||||||
|
if (el) el.classList.add("hidden");
|
||||||
}
|
}
|
||||||
|
|
||||||
$("tx-detail-time").textContent =
|
loadFullTxDetails(tx.hash, tx.to, tx.isContractCall);
|
||||||
isoDate(tx.timestamp) + " (" + timeAgo(tx.timestamp) + ")";
|
|
||||||
|
const isoStr = isoDate(tx.timestamp);
|
||||||
|
$("tx-detail-time").innerHTML =
|
||||||
|
copyableHtml(isoStr) + " (" + escapeHtml(timeAgo(tx.timestamp)) + ")";
|
||||||
$("tx-detail-status").textContent = tx.isError ? "Failed" : "Success";
|
$("tx-detail-status").textContent = tx.isError ? "Failed" : "Success";
|
||||||
showView("transaction");
|
showView("transaction");
|
||||||
|
attachCopyHandlers("view-transaction");
|
||||||
|
}
|
||||||
|
|
||||||
document
|
function showDetailField(sectionId, contentId, value) {
|
||||||
.getElementById("view-transaction")
|
const section = $(sectionId);
|
||||||
.querySelectorAll("[data-copy]")
|
const el = $(contentId);
|
||||||
.forEach((el) => {
|
if (!section || !el) return;
|
||||||
|
el.innerHTML = copyableHtml(value, "");
|
||||||
|
section.classList.remove("hidden");
|
||||||
|
}
|
||||||
|
|
||||||
|
function populateOnChainDetails(txData) {
|
||||||
|
// Block number
|
||||||
|
if (txData.block_number != null) {
|
||||||
|
const blockLink = `${currentNetwork().explorerUrl}/block/${txData.block_number}`;
|
||||||
|
const blockSection = $("tx-detail-block-section");
|
||||||
|
const blockEl = $("tx-detail-block");
|
||||||
|
if (blockSection && blockEl) {
|
||||||
|
blockEl.innerHTML =
|
||||||
|
copyableHtml(String(txData.block_number), "") +
|
||||||
|
etherscanLinkHtml(blockLink);
|
||||||
|
blockSection.classList.remove("hidden");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Nonce
|
||||||
|
if (txData.nonce != null) {
|
||||||
|
showDetailField(
|
||||||
|
"tx-detail-nonce-section",
|
||||||
|
"tx-detail-nonce",
|
||||||
|
String(txData.nonce),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Transaction fee
|
||||||
|
const feeWei = txData.fee?.value || txData.tx_fee;
|
||||||
|
if (feeWei) {
|
||||||
|
const feeEth = formatEther(String(feeWei));
|
||||||
|
showDetailField(
|
||||||
|
"tx-detail-fee-section",
|
||||||
|
"tx-detail-fee",
|
||||||
|
feeEth + " ETH",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Gas price
|
||||||
|
const gasPrice = txData.gas_price;
|
||||||
|
if (gasPrice) {
|
||||||
|
const gwei = formatUnits(String(gasPrice), "gwei");
|
||||||
|
showDetailField(
|
||||||
|
"tx-detail-gasprice-section",
|
||||||
|
"tx-detail-gasprice",
|
||||||
|
gwei + " Gwei",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Gas used
|
||||||
|
const gasUsed = txData.gas_used;
|
||||||
|
if (gasUsed) {
|
||||||
|
showDetailField(
|
||||||
|
"tx-detail-gasused-section",
|
||||||
|
"tx-detail-gasused",
|
||||||
|
String(gasUsed),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Show the network details wrapper if any child section is visible
|
||||||
|
const networkWrapper = $("tx-detail-network-section");
|
||||||
|
if (networkWrapper) {
|
||||||
|
const hasVisible = [
|
||||||
|
"tx-detail-nonce-section",
|
||||||
|
"tx-detail-fee-section",
|
||||||
|
"tx-detail-gasprice-section",
|
||||||
|
"tx-detail-gasused-section",
|
||||||
|
].some((id) => {
|
||||||
|
const el = $(id);
|
||||||
|
return el && !el.classList.contains("hidden");
|
||||||
|
});
|
||||||
|
if (hasVisible) networkWrapper.classList.remove("hidden");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Bind copy handlers for newly added elements
|
||||||
|
for (const id of [
|
||||||
|
"tx-detail-block-section",
|
||||||
|
"tx-detail-nonce-section",
|
||||||
|
"tx-detail-fee-section",
|
||||||
|
"tx-detail-gasprice-section",
|
||||||
|
"tx-detail-gasused-section",
|
||||||
|
]) {
|
||||||
|
const section = $(id);
|
||||||
|
if (!section) continue;
|
||||||
|
section.querySelectorAll("[data-copy]").forEach((el) => {
|
||||||
el.onclick = () => {
|
el.onclick = () => {
|
||||||
navigator.clipboard.writeText(el.dataset.copy);
|
navigator.clipboard.writeText(el.dataset.copy);
|
||||||
showFlash("Copied!");
|
showFlash("Copied!");
|
||||||
|
flashCopyFeedback(el);
|
||||||
};
|
};
|
||||||
});
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async function loadCalldata(txHash, toAddress) {
|
async function loadFullTxDetails(txHash, toAddress, isContractCall) {
|
||||||
const section = $("tx-detail-calldata-section");
|
const section = $("tx-detail-calldata-section");
|
||||||
const actionEl = $("tx-detail-calldata-action");
|
const actionEl = $("tx-detail-calldata-action");
|
||||||
const detailsEl = $("tx-detail-calldata-details");
|
const detailsEl = $("tx-detail-calldata-details");
|
||||||
@@ -189,6 +289,10 @@ async function loadCalldata(txHash, toAddress) {
|
|||||||
);
|
);
|
||||||
if (!resp.ok) return;
|
if (!resp.ok) return;
|
||||||
const txData = await resp.json();
|
const txData = await resp.json();
|
||||||
|
|
||||||
|
// Populate on-chain detail fields (block, nonce, gas, fee)
|
||||||
|
populateOnChainDetails(txData);
|
||||||
|
|
||||||
const inputData = txData.raw_input || txData.input || null;
|
const inputData = txData.raw_input || txData.input || null;
|
||||||
if (!inputData || inputData === "0x") return;
|
if (!inputData || inputData === "0x") return;
|
||||||
|
|
||||||
@@ -204,19 +308,14 @@ async function loadCalldata(txHash, toAddress) {
|
|||||||
detailsHtml += `<div class="mb-2">`;
|
detailsHtml += `<div class="mb-2">`;
|
||||||
detailsHtml += `<div class="text-muted">${escapeHtml(d.label)}</div>`;
|
detailsHtml += `<div class="text-muted">${escapeHtml(d.label)}</div>`;
|
||||||
if (d.address && d.isToken) {
|
if (d.address && d.isToken) {
|
||||||
// Token entry: show symbol on its own line, then dot + address + Etherscan link
|
// Token entry: show symbol on its own line, then address via shared renderer
|
||||||
const dot = addressDotHtml(d.address);
|
|
||||||
const tokenSymbol = d.value.match(/^(\S+)\s*\(/)?.[1];
|
const tokenSymbol = d.value.match(/^(\S+)\s*\(/)?.[1];
|
||||||
if (tokenSymbol) {
|
if (tokenSymbol) {
|
||||||
detailsHtml += `<div class="font-bold">${escapeHtml(tokenSymbol)}</div>`;
|
detailsHtml += `<div class="font-bold">${escapeHtml(tokenSymbol)}</div>`;
|
||||||
}
|
}
|
||||||
const etherscanUrl = `https://etherscan.io/token/${d.address}`;
|
detailsHtml += renderAddressHtml(d.address);
|
||||||
detailsHtml += `<div class="flex items-center">${dot}${copyableHtml(d.address, "break-all")}${etherscanLinkHtml(etherscanUrl)}</div>`;
|
|
||||||
} else if (d.address) {
|
} else if (d.address) {
|
||||||
// Protocol/contract entry: show name + Etherscan link
|
detailsHtml += renderAddressHtml(d.address);
|
||||||
const dot = addressDotHtml(d.address);
|
|
||||||
const etherscanUrl = `https://etherscan.io/address/${d.address}`;
|
|
||||||
detailsHtml += `<div class="flex items-center">${dot}${copyableHtml(d.value, "break-all")}${etherscanLinkHtml(etherscanUrl)}</div>`;
|
|
||||||
} else {
|
} else {
|
||||||
detailsHtml += `<div class="font-bold">${escapeHtml(d.value)}</div>`;
|
detailsHtml += `<div class="font-bold">${escapeHtml(d.value)}</div>`;
|
||||||
}
|
}
|
||||||
@@ -243,12 +342,7 @@ async function loadCalldata(txHash, toAddress) {
|
|||||||
// Bind copy handlers for new elements (including raw data now outside section)
|
// Bind copy handlers for new elements (including raw data now outside section)
|
||||||
const copyTargets = [section, rawSection].filter(Boolean);
|
const copyTargets = [section, rawSection].filter(Boolean);
|
||||||
for (const container of copyTargets) {
|
for (const container of copyTargets) {
|
||||||
container.querySelectorAll("[data-copy]").forEach((el) => {
|
attachCopyHandlers(container);
|
||||||
el.onclick = () => {
|
|
||||||
navigator.clipboard.writeText(el.dataset.copy);
|
|
||||||
showFlash("Copied!");
|
|
||||||
};
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.errorf("loadCalldata failed:", e.message);
|
log.errorf("loadCalldata failed:", e.message);
|
||||||
@@ -258,11 +352,7 @@ async function loadCalldata(txHash, toAddress) {
|
|||||||
function init(_ctx) {
|
function init(_ctx) {
|
||||||
ctx = _ctx;
|
ctx = _ctx;
|
||||||
$("btn-tx-back").addEventListener("click", () => {
|
$("btn-tx-back").addEventListener("click", () => {
|
||||||
if (state.selectedToken) {
|
goBack();
|
||||||
ctx.showAddressToken();
|
|
||||||
} else {
|
|
||||||
ctx.showAddressDetail();
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -3,28 +3,49 @@
|
|||||||
const {
|
const {
|
||||||
$,
|
$,
|
||||||
showView,
|
showView,
|
||||||
showFlash,
|
|
||||||
addressDotHtml,
|
|
||||||
addressTitle,
|
addressTitle,
|
||||||
escapeHtml,
|
escapeHtml,
|
||||||
|
renderAddressHtml,
|
||||||
|
attachCopyHandlers,
|
||||||
|
copyableHtml,
|
||||||
|
etherscanLinkHtml,
|
||||||
|
clearViewStack,
|
||||||
} = require("./helpers");
|
} = require("./helpers");
|
||||||
const { TOKEN_BY_ADDRESS } = require("../../shared/tokenList");
|
const { TOKEN_BY_ADDRESS } = require("../../shared/tokenList");
|
||||||
const { state, saveState } = require("../../shared/state");
|
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||||
const { getProvider } = require("../../shared/balances");
|
const { getProvider } = require("../../shared/balances");
|
||||||
const { log } = require("../../shared/log");
|
const { log } = require("../../shared/log");
|
||||||
|
|
||||||
const EXT_ICON =
|
// Receipt poll cadence and the deadline after which the wait is reported as
|
||||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
// a timeout. Both are documented in the WaitTx section of README.md.
|
||||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
const POLL_INTERVAL_MS = 10000;
|
||||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
const TIMEOUT_MS = 60000;
|
||||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
|
||||||
`</svg></span>`;
|
// How many receipt lookups may fail in a row before the wait is ended and
|
||||||
|
// the failure reported. A lookup that throws says nothing about the
|
||||||
|
// transaction, so one must not end the wait — but an RPC that never answers
|
||||||
|
// (a mistyped URL in settings is the ordinary case) must not leave the wait
|
||||||
|
// running forever either, least of all a persisted one that every popup
|
||||||
|
// open would resume. Six is 60 seconds at the poll cadence: the same
|
||||||
|
// patience the confirmation deadline gets. Any lookup that answers, with a
|
||||||
|
// receipt or with null, resets the count.
|
||||||
|
const MAX_CONSECUTIVE_LOOKUP_FAILURES = 6;
|
||||||
|
|
||||||
let ctx;
|
let ctx;
|
||||||
let elapsedTimer = null;
|
let elapsedTimer = null;
|
||||||
let pollTimer = null;
|
let pollTimer = null;
|
||||||
|
|
||||||
function clearTimers() {
|
// Identifies the wait currently on screen. Bumped by endWait(), so a timer
|
||||||
|
// callback or an in-flight receipt lookup that outlives its wait can tell
|
||||||
|
// that it is stale and leave the current view alone. Without it, a receipt
|
||||||
|
// resolving after the wait has ended renders over whatever view replaced it.
|
||||||
|
let waitId = 0;
|
||||||
|
|
||||||
|
// End the wait on screen: stop its timers and invalidate its pending async
|
||||||
|
// work. Called on receipt, on timeout, when a new wait starts, and when the
|
||||||
|
// user navigates away.
|
||||||
|
function endWait() {
|
||||||
|
waitId++;
|
||||||
if (elapsedTimer) {
|
if (elapsedTimer) {
|
||||||
clearInterval(elapsedTimer);
|
clearInterval(elapsedTimer);
|
||||||
elapsedTimer = null;
|
elapsedTimer = null;
|
||||||
@@ -36,43 +57,28 @@ function clearTimers() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function toAddressHtml(address) {
|
function toAddressHtml(address) {
|
||||||
const dot = addressDotHtml(address);
|
|
||||||
const link = `https://etherscan.io/address/${address}`;
|
|
||||||
const extLink = `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
|
||||||
const title = addressTitle(address, state.wallets);
|
const title = addressTitle(address, state.wallets);
|
||||||
if (title) {
|
return renderAddressHtml(address, { title });
|
||||||
return (
|
|
||||||
`<div class="flex items-center font-bold">${dot}${escapeHtml(title)}</div>` +
|
|
||||||
`<div class="break-all underline decoration-dashed cursor-pointer" data-copy="${escapeHtml(address)}">${escapeHtml(address)}</div>` +
|
|
||||||
extLink
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return `<div class="flex items-center">${dot}<span class="break-all underline decoration-dashed cursor-pointer" data-copy="${escapeHtml(address)}">${escapeHtml(address)}</span>${extLink}</div>`;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function txHashHtml(hash) {
|
function txHashHtml(hash) {
|
||||||
const link = `https://etherscan.io/tx/${hash}`;
|
const link = `${currentNetwork().explorerUrl}/tx/${hash}`;
|
||||||
const extLink = `<a href="${link}" target="_blank" rel="noopener" class="inline-flex items-center">${EXT_ICON}</a>`;
|
return copyableHtml(hash, "break-all") + etherscanLinkHtml(link);
|
||||||
return (
|
|
||||||
`<span class="underline decoration-dashed cursor-pointer break-all" data-copy="${escapeHtml(hash)}">${escapeHtml(hash)}</span>` +
|
|
||||||
extLink
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function attachCopyHandlers(viewId) {
|
function blockNumberHtml(blockNumber) {
|
||||||
document
|
const num = String(blockNumber);
|
||||||
.getElementById(viewId)
|
const link = `${currentNetwork().explorerUrl}/block/${num}`;
|
||||||
.querySelectorAll("[data-copy]")
|
return copyableHtml(num) + etherscanLinkHtml(link);
|
||||||
.forEach((el) => {
|
|
||||||
el.onclick = () => {
|
|
||||||
navigator.clipboard.writeText(el.dataset.copy);
|
|
||||||
showFlash("Copied!");
|
|
||||||
};
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function showWait(txInfo, txHash) {
|
// Render the wait view and start polling for the receipt. broadcastTime is
|
||||||
clearTimers();
|
// when the transaction was broadcast, which is what the elapsed counter and
|
||||||
|
// the timeout deadline are both measured from; pollNow runs one lookup
|
||||||
|
// immediately instead of waiting a full poll interval.
|
||||||
|
function startWait(txInfo, txHash, broadcastTime, pollNow) {
|
||||||
|
endWait();
|
||||||
|
const id = waitId;
|
||||||
|
|
||||||
const symbol = txInfo.token === "ETH" ? "ETH" : txInfo.tokenSymbol || "?";
|
const symbol = txInfo.token === "ETH" ? "ETH" : txInfo.tokenSymbol || "?";
|
||||||
$("wait-tx-summary").textContent = txInfo.amount + " " + symbol;
|
$("wait-tx-summary").textContent = txInfo.amount + " " + symbol;
|
||||||
@@ -80,41 +86,130 @@ function showWait(txInfo, txHash) {
|
|||||||
$("wait-tx-hash").innerHTML = txHashHtml(txHash);
|
$("wait-tx-hash").innerHTML = txHashHtml(txHash);
|
||||||
attachCopyHandlers("view-wait-tx");
|
attachCopyHandlers("view-wait-tx");
|
||||||
|
|
||||||
const broadcastTime = Date.now();
|
// Persisted so closing and reopening the popup resumes this wait
|
||||||
$("wait-tx-status").textContent = "Waiting for confirmation... 0s";
|
// instead of silently abandoning it.
|
||||||
|
state.viewData = {
|
||||||
|
pendingWait: {
|
||||||
|
txInfo: txInfo,
|
||||||
|
hash: txHash,
|
||||||
|
broadcastTime: broadcastTime,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
elapsedTimer = setInterval(() => {
|
function renderElapsed() {
|
||||||
const elapsed = Math.floor((Date.now() - broadcastTime) / 1000);
|
const elapsed = Math.floor((Date.now() - broadcastTime) / 1000);
|
||||||
$("wait-tx-status").textContent =
|
$("wait-tx-status").textContent =
|
||||||
"Waiting for confirmation... " + elapsed + "s";
|
"Waiting for confirmation... " + elapsed + "s";
|
||||||
|
}
|
||||||
|
renderElapsed();
|
||||||
|
|
||||||
|
elapsedTimer = setInterval(() => {
|
||||||
|
if (id !== waitId) return;
|
||||||
|
renderElapsed();
|
||||||
}, 1000);
|
}, 1000);
|
||||||
|
|
||||||
const provider = getProvider(state.rpcUrl);
|
const provider = getProvider(state.rpcUrl);
|
||||||
pollTimer = setInterval(async () => {
|
let consecutiveFailures = 0;
|
||||||
|
|
||||||
|
async function poll() {
|
||||||
|
if (id !== waitId) return;
|
||||||
|
let receipt = null;
|
||||||
|
let answered = true;
|
||||||
try {
|
try {
|
||||||
const receipt = await provider.getTransactionReceipt(txHash);
|
receipt = await provider.getTransactionReceipt(txHash);
|
||||||
if (receipt) {
|
|
||||||
showSuccess(txInfo, txHash, receipt.blockNumber);
|
|
||||||
}
|
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
|
// A thrown lookup means "no answer this tick", not "no
|
||||||
|
// receipt": the RPC failed, the chain said nothing. Declaring
|
||||||
|
// the timeout off it would report a confirmed transaction as
|
||||||
|
// failed — which matters most on a resumed wait, where the
|
||||||
|
// first poll is already past the deadline.
|
||||||
|
answered = false;
|
||||||
log.errorf("poll receipt failed:", e.message);
|
log.errorf("poll receipt failed:", e.message);
|
||||||
}
|
}
|
||||||
|
// The lookup is async: the wait may have ended while it was in
|
||||||
const elapsed = Math.floor((Date.now() - broadcastTime) / 1000);
|
// flight, in which case this result must not touch the view.
|
||||||
if (elapsed >= 60) {
|
if (id !== waitId) return;
|
||||||
|
// Exactly one outcome per wait. A receipt wins even on the tick
|
||||||
|
// that crosses the deadline, because the transaction did confirm.
|
||||||
|
if (receipt) {
|
||||||
|
showSuccess(txInfo, txHash, receipt.blockNumber);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (!answered) {
|
||||||
|
consecutiveFailures++;
|
||||||
|
// The failure is the user's news, and it is a different fact
|
||||||
|
// from "the transaction did not confirm" — the chain was never
|
||||||
|
// asked. Ending the wait here is what keeps it bounded and
|
||||||
|
// gives the user a Done button to leave by.
|
||||||
|
if (consecutiveFailures >= MAX_CONSECUTIVE_LOOKUP_FAILURES) {
|
||||||
|
showError(
|
||||||
|
txInfo,
|
||||||
|
txHash,
|
||||||
|
"The network could not be reached to check this transaction — " +
|
||||||
|
MAX_CONSECUTIVE_LOOKUP_FAILURES +
|
||||||
|
" lookups failed in a row. Check the RPC URL in Settings. The transaction may still have confirmed — check Etherscan.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
// Otherwise keep polling: the next tick may answer.
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
consecutiveFailures = 0;
|
||||||
|
if (Date.now() - broadcastTime >= TIMEOUT_MS) {
|
||||||
showError(
|
showError(
|
||||||
txInfo,
|
txInfo,
|
||||||
txHash,
|
txHash,
|
||||||
"Transaction was not confirmed within 60 seconds. It may still confirm later \u2014 check Etherscan.",
|
"Transaction was not confirmed within 60 seconds. It may still confirm later \u2014 check Etherscan.",
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}, 10000);
|
}
|
||||||
|
|
||||||
|
pollTimer = setInterval(poll, POLL_INTERVAL_MS);
|
||||||
|
|
||||||
showView("wait-tx");
|
showView("wait-tx");
|
||||||
|
|
||||||
|
if (pollNow) poll();
|
||||||
|
}
|
||||||
|
|
||||||
|
function showWait(txInfo, txHash) {
|
||||||
|
startWait(txInfo, txHash, Date.now(), false);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Resume a wait persisted by a previous popup session. The deadline still
|
||||||
|
// runs from the original broadcast, so a wait that has already outlived it
|
||||||
|
// resolves on the immediate first poll rather than restarting the clock.
|
||||||
|
// Returns false when there is nothing resumable to resume. Every field
|
||||||
|
// startWait() goes on to use is validated, not just the presence of the
|
||||||
|
// containers: txInfo.to reaches addressTitle(), which calls
|
||||||
|
// address.toLowerCase(), and txInfo.amount is rendered into the summary, so
|
||||||
|
// an object merely missing one of them throws a TypeError out of
|
||||||
|
// restoreView() — which init() does not guard, skipping the rest of popup
|
||||||
|
// init and leaving wait-tx on screen with no back control. A non-numeric
|
||||||
|
// broadcastTime leaves an unexitable wait counting "NaNs". txInfo.token and
|
||||||
|
// txInfo.tokenSymbol are deliberately unchecked: they are compared and
|
||||||
|
// coalesced rather than dereferenced, and tokenSymbol is null for ETH.
|
||||||
|
function restoreWait() {
|
||||||
|
const d = state.viewData;
|
||||||
|
if (!d || !d.pendingWait) return false;
|
||||||
|
const w = d.pendingWait;
|
||||||
|
if (!w.hash) return false;
|
||||||
|
// typeof [] is "object", so an array passes an object check.
|
||||||
|
const info = w.txInfo;
|
||||||
|
if (!info || typeof info !== "object" || Array.isArray(info)) return false;
|
||||||
|
// A string is the whole requirement: the empty string is what a
|
||||||
|
// contract-deployment approval persists (approval.js writes `to: toAddr
|
||||||
|
// || ""`), and both fields render harmlessly when empty, so refusing it
|
||||||
|
// would abandon a wait the live path itself created.
|
||||||
|
if (typeof info.to !== "string") return false;
|
||||||
|
if (typeof info.amount !== "string") return false;
|
||||||
|
if (typeof w.broadcastTime !== "number" || !isFinite(w.broadcastTime)) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
startWait(w.txInfo, w.hash, w.broadcastTime, true);
|
||||||
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
function showSuccess(txInfo, txHash, blockNumber) {
|
function showSuccess(txInfo, txHash, blockNumber) {
|
||||||
clearTimers();
|
endWait();
|
||||||
|
|
||||||
const symbol = txInfo.token === "ETH" ? "ETH" : txInfo.tokenSymbol || "?";
|
const symbol = txInfo.token === "ETH" ? "ETH" : txInfo.tokenSymbol || "?";
|
||||||
state.viewData = {
|
state.viewData = {
|
||||||
@@ -135,7 +230,7 @@ function tokenLabel(address) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function etherscanTokenLink(address) {
|
function etherscanTokenLink(address) {
|
||||||
return `https://etherscan.io/token/${address}`;
|
return `${currentNetwork().explorerUrl}/token/${address}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
function decodedDetailsHtml(decoded) {
|
function decodedDetailsHtml(decoded) {
|
||||||
@@ -189,7 +284,7 @@ function renderSuccess() {
|
|||||||
$("success-tx-to").innerHTML = toAddressHtml(d.to);
|
$("success-tx-to").innerHTML = toAddressHtml(d.to);
|
||||||
}
|
}
|
||||||
|
|
||||||
$("success-tx-block").textContent = String(d.blockNumber);
|
$("success-tx-block").innerHTML = blockNumberHtml(d.blockNumber);
|
||||||
$("success-tx-hash").innerHTML = txHashHtml(d.hash);
|
$("success-tx-hash").innerHTML = txHashHtml(d.hash);
|
||||||
|
|
||||||
// Show decoded calldata details if present
|
// Show decoded calldata details if present
|
||||||
@@ -206,7 +301,7 @@ function renderSuccess() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function showError(txInfo, txHash, message) {
|
function showError(txInfo, txHash, message) {
|
||||||
clearTimers();
|
endWait();
|
||||||
|
|
||||||
const symbol = txInfo.token === "ETH" ? "ETH" : txInfo.tokenSymbol || "?";
|
const symbol = txInfo.token === "ETH" ? "ETH" : txInfo.tokenSymbol || "?";
|
||||||
state.viewData = {
|
state.viewData = {
|
||||||
@@ -242,14 +337,23 @@ function isApprovalPopup() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function navigateBack() {
|
function navigateBack() {
|
||||||
|
// Nothing should still be polling by now, but leaving a view is the
|
||||||
|
// point at which its timers must be gone.
|
||||||
|
endWait();
|
||||||
if (isApprovalPopup()) {
|
if (isApprovalPopup()) {
|
||||||
window.close();
|
window.close();
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
// After a completed transaction, reset the navigation stack
|
||||||
|
// and go directly to the address view (token or detail).
|
||||||
|
// Use require() lazily to call show() without the ctx push wrapper.
|
||||||
|
clearViewStack();
|
||||||
|
state.viewStack.push("main");
|
||||||
if (state.selectedToken) {
|
if (state.selectedToken) {
|
||||||
ctx.showAddressToken();
|
state.viewStack.push("address");
|
||||||
|
require("./addressToken").show();
|
||||||
} else {
|
} else {
|
||||||
ctx.showAddressDetail();
|
require("./addressDetail").show();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -260,4 +364,12 @@ function init(_ctx) {
|
|||||||
$("btn-error-tx-done").addEventListener("click", navigateBack);
|
$("btn-error-tx-done").addEventListener("click", navigateBack);
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { init, showWait, showError, renderSuccess, renderError };
|
module.exports = {
|
||||||
|
init,
|
||||||
|
showWait,
|
||||||
|
restoreWait,
|
||||||
|
endWait,
|
||||||
|
showError,
|
||||||
|
renderSuccess,
|
||||||
|
renderError,
|
||||||
|
};
|
||||||
|
|||||||
114
src/shared/addressWarnings.js
Normal file
114
src/shared/addressWarnings.js
Normal file
@@ -0,0 +1,114 @@
|
|||||||
|
// Address warning module.
|
||||||
|
// Provides local and async (RPC-based) warning checks for Ethereum addresses.
|
||||||
|
// Returns arrays of {type, message, severity} objects.
|
||||||
|
|
||||||
|
const { isScamAddress } = require("./scamlist");
|
||||||
|
const { isBurnAddress } = require("./constants");
|
||||||
|
const { checkEtherscanLabel } = require("./etherscanLabels");
|
||||||
|
const { log } = require("./log");
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check an address against local-only lists (scam, burn, self-send).
|
||||||
|
* Synchronous — no network calls.
|
||||||
|
*
|
||||||
|
* @param {string} address - The target address to check.
|
||||||
|
* @param {object} [options] - Optional context.
|
||||||
|
* @param {string} [options.fromAddress] - Sender address (for self-send check).
|
||||||
|
* @returns {Array<{type: string, message: string, severity: string}>}
|
||||||
|
*/
|
||||||
|
function getLocalWarnings(address, options = {}) {
|
||||||
|
const warnings = [];
|
||||||
|
const addr = address.toLowerCase();
|
||||||
|
|
||||||
|
if (isScamAddress(addr)) {
|
||||||
|
warnings.push({
|
||||||
|
type: "scam",
|
||||||
|
message:
|
||||||
|
"This address is on a known scam/fraud list. Do not send funds to this address.",
|
||||||
|
severity: "critical",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (isBurnAddress(addr)) {
|
||||||
|
warnings.push({
|
||||||
|
type: "burn",
|
||||||
|
message:
|
||||||
|
"This is a known null/burn address. Funds sent here are permanently destroyed and cannot be recovered.",
|
||||||
|
severity: "critical",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (options.fromAddress && addr === options.fromAddress.toLowerCase()) {
|
||||||
|
warnings.push({
|
||||||
|
type: "self-send",
|
||||||
|
message: "You are sending to your own address.",
|
||||||
|
severity: "warning",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return warnings;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check an address against local lists AND via RPC queries.
|
||||||
|
* Async — performs network calls to check contract status and tx history.
|
||||||
|
*
|
||||||
|
* @param {string} address - The target address to check.
|
||||||
|
* @param {object} provider - An ethers.js provider instance.
|
||||||
|
* @param {object} [options] - Optional context.
|
||||||
|
* @param {string} [options.fromAddress] - Sender address (for self-send check).
|
||||||
|
* @returns {Promise<Array<{type: string, message: string, severity: string}>>}
|
||||||
|
*/
|
||||||
|
async function getFullWarnings(address, provider, options = {}) {
|
||||||
|
const warnings = getLocalWarnings(address, options);
|
||||||
|
|
||||||
|
let isContract = false;
|
||||||
|
try {
|
||||||
|
const code = await provider.getCode(address);
|
||||||
|
if (code && code !== "0x") {
|
||||||
|
isContract = true;
|
||||||
|
warnings.push({
|
||||||
|
type: "contract",
|
||||||
|
message:
|
||||||
|
"This address is a smart contract, not a regular wallet.",
|
||||||
|
severity: "warning",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
log.errorf("contract check failed:", e.message);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Skip tx count check for contracts — they may legitimately have
|
||||||
|
// zero inbound EOA transactions.
|
||||||
|
if (!isContract) {
|
||||||
|
try {
|
||||||
|
const txCount = await provider.getTransactionCount(address);
|
||||||
|
if (txCount === 0) {
|
||||||
|
warnings.push({
|
||||||
|
type: "new-address",
|
||||||
|
message:
|
||||||
|
"This address has never sent a transaction. Double-check it is correct.",
|
||||||
|
severity: "info",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
log.errorf("tx count check failed:", e.message);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Etherscan label check (best-effort async — network failures are silent).
|
||||||
|
// Runs for ALL addresses including contracts, since many dangerous
|
||||||
|
// flagged addresses on Etherscan (drainers, phishing contracts) are contracts.
|
||||||
|
try {
|
||||||
|
const etherscanWarning = await checkEtherscanLabel(address);
|
||||||
|
if (etherscanWarning) {
|
||||||
|
warnings.push(etherscanWarning);
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
log.errorf("etherscan label check failed:", e.message);
|
||||||
|
}
|
||||||
|
|
||||||
|
return warnings;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { getLocalWarnings, getFullWarnings };
|
||||||
114
src/shared/alarms.js
Normal file
114
src/shared/alarms.js
Normal file
@@ -0,0 +1,114 @@
|
|||||||
|
// Periodic scheduling for the background context.
|
||||||
|
//
|
||||||
|
// The Chrome MV3 service worker is terminated after roughly 30 seconds idle,
|
||||||
|
// which takes every setInterval/setTimeout with it. The extension alarms API
|
||||||
|
// is the mechanism that survives: the browser holds the schedule and wakes
|
||||||
|
// the worker to deliver onAlarm. Firefox MV2 runs a persistent background
|
||||||
|
// page where timers would survive, but alarms behave identically there, so
|
||||||
|
// both targets share this path and both manifests declare the "alarms"
|
||||||
|
// permission.
|
||||||
|
//
|
||||||
|
// Periods are whole minutes at or above the browser-enforced one-minute
|
||||||
|
// minimum, so nothing here is silently clamped to a slower cadence.
|
||||||
|
//
|
||||||
|
// Trap for anyone changing a period: each job also carries a freshness guard
|
||||||
|
// that can veto its own scheduled tick. A guard timed to the alarm period
|
||||||
|
// halves the real cadence, because the guard is measured from when the last
|
||||||
|
// run finished and the alarm fires one run-duration earlier than that. Every
|
||||||
|
// guard must therefore either be strictly shorter than the period it gates or
|
||||||
|
// be bypassed on the scheduled tick — see backgroundRefresh() in
|
||||||
|
// src/background/index.js and updatePhishingList() in shared/phishingDomains.js.
|
||||||
|
|
||||||
|
const BALANCE_REFRESH_ALARM = "autistmask-balance-refresh";
|
||||||
|
const PHISHING_REFRESH_ALARM = "autistmask-phishing-refresh";
|
||||||
|
|
||||||
|
const MIN_ALARM_PERIOD_MINUTES = 1;
|
||||||
|
const BALANCE_REFRESH_PERIOD_MINUTES = 1;
|
||||||
|
const PHISHING_REFRESH_PERIOD_MINUTES = 24 * 60;
|
||||||
|
|
||||||
|
// Resolved on use rather than captured at module load: the worker is torn
|
||||||
|
// down and re-evaluated repeatedly, and tests install a stub after requiring
|
||||||
|
// the module.
|
||||||
|
function alarmsApi() {
|
||||||
|
if (typeof browser !== "undefined" && browser.alarms) return browser.alarms;
|
||||||
|
if (typeof chrome !== "undefined" && chrome.alarms) return chrome.alarms;
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create an alarm unless one with the requested period already exists.
|
||||||
|
*
|
||||||
|
* The existence check is load-bearing: creating an alarm resets its schedule,
|
||||||
|
* and this runs on every worker wake. Creating unconditionally would push the
|
||||||
|
* next fire time out on every incoming message, so a busy extension would
|
||||||
|
* never see the alarm fire at all.
|
||||||
|
*
|
||||||
|
* The period comparison is equally load-bearing in the other direction: an
|
||||||
|
* alarm created by an older version keeps its old period forever unless a
|
||||||
|
* changed constant re-creates it, so a period edit would never reach an
|
||||||
|
* existing install. Re-creating on a period change happens once and then
|
||||||
|
* settles into the existence check above.
|
||||||
|
*
|
||||||
|
* @param {string} name
|
||||||
|
* @param {number} periodInMinutes
|
||||||
|
* @returns {Promise<boolean>} true if the alarm was created by this call.
|
||||||
|
*/
|
||||||
|
async function ensureAlarm(name, periodInMinutes) {
|
||||||
|
const api = alarmsApi();
|
||||||
|
if (!api) return false;
|
||||||
|
const period = Math.max(periodInMinutes, MIN_ALARM_PERIOD_MINUTES);
|
||||||
|
const existing = await api.get(name);
|
||||||
|
if (existing && existing.periodInMinutes === period) return false;
|
||||||
|
api.create(name, {
|
||||||
|
periodInMinutes: period,
|
||||||
|
delayInMinutes: period,
|
||||||
|
});
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Ensure both recurring background jobs are scheduled. Safe to call on every
|
||||||
|
* worker start, on onInstalled and on onStartup.
|
||||||
|
*
|
||||||
|
* @returns {Promise<{balance: boolean, phishing: boolean}>} which alarms this
|
||||||
|
* call had to create.
|
||||||
|
*/
|
||||||
|
async function ensureRecurringAlarms() {
|
||||||
|
const balance = await ensureAlarm(
|
||||||
|
BALANCE_REFRESH_ALARM,
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES,
|
||||||
|
);
|
||||||
|
const phishing = await ensureAlarm(
|
||||||
|
PHISHING_REFRESH_ALARM,
|
||||||
|
PHISHING_REFRESH_PERIOD_MINUTES,
|
||||||
|
);
|
||||||
|
return { balance, phishing };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Register per-alarm handlers. One listener dispatches by alarm name so the
|
||||||
|
* worker only ever installs a single onAlarm listener.
|
||||||
|
*
|
||||||
|
* @param {Object<string, function>} handlers
|
||||||
|
* @returns {boolean} true if the listener was installed.
|
||||||
|
*/
|
||||||
|
function registerAlarmHandlers(handlers) {
|
||||||
|
const api = alarmsApi();
|
||||||
|
if (!api || !api.onAlarm) return false;
|
||||||
|
api.onAlarm.addListener((alarm) => {
|
||||||
|
const handler = handlers[alarm && alarm.name];
|
||||||
|
if (handler) handler();
|
||||||
|
});
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
BALANCE_REFRESH_ALARM,
|
||||||
|
PHISHING_REFRESH_ALARM,
|
||||||
|
MIN_ALARM_PERIOD_MINUTES,
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES,
|
||||||
|
PHISHING_REFRESH_PERIOD_MINUTES,
|
||||||
|
ensureAlarm,
|
||||||
|
ensureRecurringAlarms,
|
||||||
|
registerAlarmHandlers,
|
||||||
|
};
|
||||||
570
src/shared/approvalVerify.js
Normal file
570
src/shared/approvalVerify.js
Normal file
@@ -0,0 +1,570 @@
|
|||||||
|
// Verification of the signed artifacts produced by the approval popup.
|
||||||
|
//
|
||||||
|
// Signing happens in the popup, where the password is entered; the background
|
||||||
|
// only broadcasts the raw transaction and resolves the pending approval back
|
||||||
|
// to the requesting page. So that moving the signing out of the background
|
||||||
|
// does not turn the background into a blind relay, the background re-derives
|
||||||
|
// the signer from the artifact and checks it against the approval it is
|
||||||
|
// holding before acting on it. All recovery is delegated to ethers.
|
||||||
|
//
|
||||||
|
// The check is an allowlist, in both directions, because a denylist cannot be
|
||||||
|
// correct against a transaction format that keeps gaining fields:
|
||||||
|
//
|
||||||
|
// - only transaction types 0, 1 and 2 are accepted. Every later EIP-2718 type
|
||||||
|
// adds a field with consequences of its own — EIP-7702's authorizationList
|
||||||
|
// rewrites the code at the signer's own account, EIP-4844's blob
|
||||||
|
// commitments carry a separate fee — and a check that enumerates the fields
|
||||||
|
// it refuses admits every one of them by default.
|
||||||
|
// - after the per-field comparisons, the artifact is rebuilt from those
|
||||||
|
// checked fields and nothing else, and the two are compared byte for byte.
|
||||||
|
// Anything the artifact carries that this module does not name is absent
|
||||||
|
// from the rebuild and changes the bytes, so the final assertion is that
|
||||||
|
// the artifact *is* the approved transaction, not merely that it is not one
|
||||||
|
// of the tampered shapes that were thought of.
|
||||||
|
// - every comparison runs against the decode, but the string handed to
|
||||||
|
// broadcastTransaction() is the artifact. So the artifact is also required
|
||||||
|
// to be the canonical re-encoding of its own decode, which is what makes
|
||||||
|
// the checked transaction and the broadcast bytes the same object rather
|
||||||
|
// than two things that merely decode alike.
|
||||||
|
//
|
||||||
|
// Every consequential field is compared, and a mismatch is a refusal to act,
|
||||||
|
// never a warning: what the user approved is what gets broadcast, or nothing
|
||||||
|
// does.
|
||||||
|
//
|
||||||
|
// Fields the approval does not carry are not treated as zero. The popup
|
||||||
|
// populates nonce, gas limit, fee and chain id through populateTransaction()
|
||||||
|
// when the requesting page did not fix them, so there is no approved value to
|
||||||
|
// compare against; treating absent as zero would refuse every legitimate
|
||||||
|
// transaction. Those fields are instead held to the absolute ceilings below,
|
||||||
|
// and the chain id is always checked against the selected network rather than
|
||||||
|
// against the approval alone, which is what makes a cross-chain replay
|
||||||
|
// impossible.
|
||||||
|
//
|
||||||
|
// Every failure message is a full sentence, because these strings are shown to
|
||||||
|
// the user and returned to the dApp.
|
||||||
|
|
||||||
|
const {
|
||||||
|
Transaction,
|
||||||
|
accessListify,
|
||||||
|
getAddress,
|
||||||
|
getBytes,
|
||||||
|
verifyMessage,
|
||||||
|
verifyTypedData,
|
||||||
|
} = require("ethers");
|
||||||
|
|
||||||
|
// The only transaction types this wallet signs: legacy, EIP-2930 and
|
||||||
|
// EIP-1559. populateTransaction() produces nothing else, so nothing else can
|
||||||
|
// be an artifact of an approval this wallet raised.
|
||||||
|
const ALLOWED_TX_TYPES = [0, 1, 2];
|
||||||
|
|
||||||
|
// The serialized fields of each allowed type, which is also the complete set
|
||||||
|
// of fields the checks below compare or bound. The artifact is rebuilt from
|
||||||
|
// exactly these at the end of verification and compared byte for byte, so a
|
||||||
|
// field outside this table cannot ride along unexamined.
|
||||||
|
const SERIALIZED_FIELDS = {
|
||||||
|
0: ["chainId", "nonce", "gasPrice", "gasLimit", "to", "value", "data"],
|
||||||
|
1: [
|
||||||
|
"chainId",
|
||||||
|
"nonce",
|
||||||
|
"gasPrice",
|
||||||
|
"gasLimit",
|
||||||
|
"to",
|
||||||
|
"value",
|
||||||
|
"data",
|
||||||
|
"accessList",
|
||||||
|
],
|
||||||
|
2: [
|
||||||
|
"chainId",
|
||||||
|
"nonce",
|
||||||
|
"maxPriorityFeePerGas",
|
||||||
|
"maxFeePerGas",
|
||||||
|
"gasLimit",
|
||||||
|
"to",
|
||||||
|
"value",
|
||||||
|
"data",
|
||||||
|
"accessList",
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
// Fields no allowed type may carry. The type allowlist already excludes every
|
||||||
|
// type that defines them, and the structural check at the end of verification
|
||||||
|
// would catch them anyway; they are named here so that an artifact carrying
|
||||||
|
// one is refused with a message that says what it was.
|
||||||
|
const FORBIDDEN_FIELDS = [
|
||||||
|
{
|
||||||
|
key: "authorizationList",
|
||||||
|
message:
|
||||||
|
"The signed transaction would hand the signing account over to another contract, which was not approved.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "blobVersionedHashes",
|
||||||
|
message:
|
||||||
|
"The signed transaction carries blob commitments, which were not approved.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "blobs",
|
||||||
|
message:
|
||||||
|
"The signed transaction carries blobs, which were not approved.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "maxFeePerBlobGas",
|
||||||
|
message:
|
||||||
|
"The signed transaction carries a blob gas fee, which was not approved.",
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
// Above the block gas limit of every supported network (see networks.js), so
|
||||||
|
// no transaction that could ever be included is refused by it.
|
||||||
|
const MAX_GAS_LIMIT = 100000000n;
|
||||||
|
|
||||||
|
// 100,000 gwei per gas: orders of magnitude above the highest fee either
|
||||||
|
// supported network has produced, and low enough to catch a fee that would
|
||||||
|
// hand the validator the balance.
|
||||||
|
const MAX_FEE_PER_GAS = 100000000000000n;
|
||||||
|
|
||||||
|
// A refusal to act on an artifact: it is not the thing that was approved, so
|
||||||
|
// the approval it was offered against is spent and must not be retried. Every
|
||||||
|
// throw in this module is one of these; the background distinguishes them from
|
||||||
|
// transient failures (a busy node, a failed broadcast), which leave the
|
||||||
|
// approval standing so the user can try again.
|
||||||
|
class ApprovalMismatchError extends Error {
|
||||||
|
constructor(message) {
|
||||||
|
super(message);
|
||||||
|
this.name = "ApprovalMismatchError";
|
||||||
|
this.approvalMismatch = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function refuse(message) {
|
||||||
|
return new ApprovalMismatchError(message);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Whether a signing failure leaves the approval usable. Anything that is not a
|
||||||
|
// mismatch is the user's to correct and retry.
|
||||||
|
function failureIsRetryable(err) {
|
||||||
|
return !(err && err.approvalMismatch === true);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Case-insensitive address comparison that tolerates absent values on either
|
||||||
|
// side. Two absent addresses compare equal (contract creation has no `to`).
|
||||||
|
function sameAddress(a, b) {
|
||||||
|
const aMissing = a === null || a === undefined || a === "";
|
||||||
|
const bMissing = b === null || b === undefined || b === "";
|
||||||
|
if (aMissing || bMissing) return aMissing && bMissing;
|
||||||
|
try {
|
||||||
|
return getAddress(a) === getAddress(b);
|
||||||
|
} catch {
|
||||||
|
return String(a).toLowerCase() === String(b).toLowerCase();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Whether the approval fixed a value for a field at all.
|
||||||
|
function present(v) {
|
||||||
|
return v !== null && v !== undefined && v !== "";
|
||||||
|
}
|
||||||
|
|
||||||
|
// Whether a field carries anything at all. An empty array is nothing: ethers
|
||||||
|
// reports an absent access list on a type 2 transaction as `[]`.
|
||||||
|
function carriesValue(v) {
|
||||||
|
if (!present(v)) return false;
|
||||||
|
if (Array.isArray(v)) return v.length > 0;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Normalize a quantity that must be present, refusing anything that is not a
|
||||||
|
// number: an approval carrying junk in a fee field cannot be compared, and an
|
||||||
|
// uncomparable field is a refusal rather than a pass.
|
||||||
|
function normalizeQuantity(v, label) {
|
||||||
|
try {
|
||||||
|
return BigInt(v);
|
||||||
|
} catch {
|
||||||
|
throw refuse(
|
||||||
|
"The approved " +
|
||||||
|
label +
|
||||||
|
" is not a number, so it cannot be" +
|
||||||
|
" compared with the signed transaction.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Normalize a transaction value (hex string, decimal string, number or
|
||||||
|
// bigint) to a bigint. An absent value is zero, matching ethers. The value is
|
||||||
|
// page-controlled, so it goes through the same refusal as every other
|
||||||
|
// quantity rather than throwing a raw BigInt conversion error.
|
||||||
|
function normalizeValue(v) {
|
||||||
|
if (!present(v)) return 0n;
|
||||||
|
return normalizeQuantity(v, "value");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Normalize an access list to a comparable string. An absent or empty list is
|
||||||
|
// the empty string, so absent and `[]` are the same thing.
|
||||||
|
function normalizeAccessList(v) {
|
||||||
|
if (!carriesValue(v)) return "";
|
||||||
|
let list;
|
||||||
|
try {
|
||||||
|
list = accessListify(v);
|
||||||
|
} catch {
|
||||||
|
throw refuse(
|
||||||
|
"The approved access list is not a valid access list, so it cannot be compared with the signed transaction.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return list
|
||||||
|
.map(
|
||||||
|
(entry) =>
|
||||||
|
String(entry.address).toLowerCase() +
|
||||||
|
":" +
|
||||||
|
entry.storageKeys.map((k) => String(k).toLowerCase()).join(","),
|
||||||
|
)
|
||||||
|
.join(";");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Normalize call data to a lowercase hex string. Absent data is "0x".
|
||||||
|
function normalizeData(v) {
|
||||||
|
if (v === null || v === undefined || v === "" || v === "0x") return "0x";
|
||||||
|
return String(v).toLowerCase();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Quantity fields the requesting page may fix in the approval. Each is
|
||||||
|
// compared exactly when the approval carries it, and left to the ceilings
|
||||||
|
// above when it does not.
|
||||||
|
const APPROVED_QUANTITIES = [
|
||||||
|
{
|
||||||
|
key: "nonce",
|
||||||
|
label: "nonce",
|
||||||
|
message: "The signed transaction does not carry the approved nonce.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "gasLimit",
|
||||||
|
label: "gas limit",
|
||||||
|
message:
|
||||||
|
"The signed transaction does not carry the approved gas limit.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "gasPrice",
|
||||||
|
label: "gas price",
|
||||||
|
message:
|
||||||
|
"The signed transaction does not carry the approved gas price.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "maxFeePerGas",
|
||||||
|
label: "maximum fee per gas",
|
||||||
|
message:
|
||||||
|
"The signed transaction does not carry the approved maximum fee per gas.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
key: "maxPriorityFeePerGas",
|
||||||
|
label: "maximum priority fee per gas",
|
||||||
|
message:
|
||||||
|
"The signed transaction does not carry the approved maximum priority fee per gas.",
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
// Refuse a field only a transaction type this wallet does not sign can carry.
|
||||||
|
// The type allowlist keeps these unreachable in production, which is exactly
|
||||||
|
// what they are for; it also means nothing else exercises them, so this is
|
||||||
|
// exported and tested on its own rather than left to be believed.
|
||||||
|
function assertNoForbiddenFields(parsed) {
|
||||||
|
for (const field of FORBIDDEN_FIELDS) {
|
||||||
|
if (carriesValue(parsed[field.key])) throw refuse(field.message);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Closing structural check. Rebuild the transaction from the fields the
|
||||||
|
// comparisons cover, and nothing else, then compare the unsigned bytes. Every
|
||||||
|
// field carried by the artifact but absent from the rebuild changes the
|
||||||
|
// serialization, so this refuses anything this module does not account for —
|
||||||
|
// including a field a future ethers learns to parse onto an allowed type —
|
||||||
|
// instead of waving it through by not naming it. Also exported for its own
|
||||||
|
// test: nothing reachable today can make the bytes differ.
|
||||||
|
function assertNothingUnchecked(parsed) {
|
||||||
|
let rebuilt;
|
||||||
|
try {
|
||||||
|
const fields = { type: parsed.type };
|
||||||
|
for (const key of SERIALIZED_FIELDS[parsed.type]) {
|
||||||
|
fields[key] = parsed[key];
|
||||||
|
}
|
||||||
|
rebuilt = Transaction.from(fields);
|
||||||
|
} catch {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction could not be rebuilt from the fields that were checked, so it cannot be shown to be the approved transaction.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (rebuilt.unsignedSerialized !== parsed.unsignedSerialized) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction carries data beyond the fields that were checked against the approval.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The other half of the closing check, and the one that makes it bind on the
|
||||||
|
// bytes that actually leave: every comparison above runs against the decode,
|
||||||
|
// so on its own the rebuild proves only that the transaction ethers understood
|
||||||
|
// is the approved one. What the background hands to broadcastTransaction() is
|
||||||
|
// the artifact string itself. Requiring the artifact to be exactly the
|
||||||
|
// canonical re-encoding of its own decode closes the gap between the two —
|
||||||
|
// no encoding the decoder normalizes away (a leading zero byte on an RLP
|
||||||
|
// quantity, say) can differ from what was checked. Hex case is not part of the
|
||||||
|
// encoding, so only that is normalized before comparing.
|
||||||
|
function assertCanonicalBytes(parsed, rawSignedTx) {
|
||||||
|
if (parsed.serialized !== String(rawSignedTx).toLowerCase()) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction is not encoded canonically, so the bytes that would be broadcast are not the bytes that were checked.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Assert that a raw signed transaction is the transaction the user approved,
|
||||||
|
// signed by the address the approval was raised for, on the network that is
|
||||||
|
// selected. Returns the parsed ethers Transaction on success, throws
|
||||||
|
// otherwise.
|
||||||
|
function verifySignedTx(rawSignedTx, txParams, expectedFrom, selectedChainId) {
|
||||||
|
if (typeof rawSignedTx !== "string" || !rawSignedTx.startsWith("0x")) {
|
||||||
|
throw refuse("The signed transaction is missing or malformed.");
|
||||||
|
}
|
||||||
|
|
||||||
|
let parsed;
|
||||||
|
try {
|
||||||
|
parsed = Transaction.from(rawSignedTx);
|
||||||
|
} catch {
|
||||||
|
throw refuse("The signed transaction could not be decoded.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!parsed.from) {
|
||||||
|
throw refuse("The signed transaction carries no valid signature.");
|
||||||
|
}
|
||||||
|
if (!sameAddress(parsed.from, expectedFrom)) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction was signed by a different address than the one that was approved.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Before any field is looked at: the type decides which fields exist at
|
||||||
|
// all, so an unrecognised type is refused outright rather than compared
|
||||||
|
// field by field against an approval that cannot describe it.
|
||||||
|
if (!ALLOWED_TX_TYPES.includes(parsed.type)) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction is of a type this wallet does not sign, so what it would do beyond the approved transfer cannot be checked.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
assertNoForbiddenFields(parsed);
|
||||||
|
|
||||||
|
// The selected network, not the artifact, is the authority on which chain
|
||||||
|
// this may be broadcast to; without it nothing can be verified.
|
||||||
|
if (!present(selectedChainId)) {
|
||||||
|
throw refuse(
|
||||||
|
"The selected network is unknown, so the signed transaction cannot be checked against it.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (parsed.chainId !== normalizeQuantity(selectedChainId, "network")) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction is for a different network than the one that is selected.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
present(txParams.chainId) &&
|
||||||
|
parsed.chainId !== normalizeQuantity(txParams.chainId, "network")
|
||||||
|
) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction is for a different network than the one that was approved.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!sameAddress(parsed.to, txParams.to)) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction does not go to the approved recipient.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (normalizeValue(parsed.value) !== normalizeValue(txParams.value)) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction does not carry the approved value.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (normalizeData(parsed.data) !== normalizeData(txParams.data)) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction does not carry the approved call data.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
normalizeAccessList(parsed.accessList) !==
|
||||||
|
normalizeAccessList(txParams.accessList)
|
||||||
|
) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction does not carry the approved access list.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// An approval that fixed EIP-1559 fees must not be signed as a legacy
|
||||||
|
// transaction, and vice versa: the fee the user agreed to is only
|
||||||
|
// meaningful under the mechanism it was quoted in.
|
||||||
|
const approvedEip1559 =
|
||||||
|
present(txParams.maxFeePerGas) ||
|
||||||
|
present(txParams.maxPriorityFeePerGas);
|
||||||
|
const approvedLegacy = present(txParams.gasPrice);
|
||||||
|
const signedEip1559 = parsed.type === 2;
|
||||||
|
if (
|
||||||
|
(approvedEip1559 && !signedEip1559) ||
|
||||||
|
(approvedLegacy && signedEip1559)
|
||||||
|
) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction does not use the approved fee mechanism.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const field of APPROVED_QUANTITIES) {
|
||||||
|
if (!present(txParams[field.key])) continue;
|
||||||
|
const approved = normalizeQuantity(txParams[field.key], field.label);
|
||||||
|
if (normalizeQuantity(parsed[field.key], field.label) !== approved) {
|
||||||
|
throw refuse(field.message);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (parsed.gasLimit > MAX_GAS_LIMIT) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction sets a gas limit no network this wallet supports can accept.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
for (const key of ["gasPrice", "maxFeePerGas", "maxPriorityFeePerGas"]) {
|
||||||
|
const fee = parsed[key];
|
||||||
|
if (fee !== null && fee !== undefined && fee > MAX_FEE_PER_GAS) {
|
||||||
|
throw refuse(
|
||||||
|
"The signed transaction sets a fee per gas far above any plausible value.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
assertNothingUnchecked(parsed);
|
||||||
|
assertCanonicalBytes(parsed, rawSignedTx);
|
||||||
|
|
||||||
|
return parsed;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Assert that a signature over the approved message or typed data was
|
||||||
|
// produced by the address the approval was raised for. Returns the recovered
|
||||||
|
// address on success, throws otherwise.
|
||||||
|
function verifySignature(signParams, signature, expectedFrom) {
|
||||||
|
if (typeof signature !== "string" || !signature.startsWith("0x")) {
|
||||||
|
throw refuse("The signature is missing or malformed.");
|
||||||
|
}
|
||||||
|
|
||||||
|
let recovered;
|
||||||
|
try {
|
||||||
|
if (
|
||||||
|
signParams.method === "personal_sign" ||
|
||||||
|
signParams.method === "eth_sign"
|
||||||
|
) {
|
||||||
|
recovered = verifyMessage(getBytes(signParams.message), signature);
|
||||||
|
} else {
|
||||||
|
const typedData = JSON.parse(signParams.typedData);
|
||||||
|
const { domain, types, message } = typedData;
|
||||||
|
// ethers derives EIP712Domain itself and rejects it as an input.
|
||||||
|
delete types.EIP712Domain;
|
||||||
|
recovered = verifyTypedData(domain, types, message, signature);
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
throw refuse("The signature could not be verified.");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!sameAddress(recovered, expectedFrom)) {
|
||||||
|
throw refuse(
|
||||||
|
"The signature was produced by a different address than the one that was approved.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return recovered;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The stage a transaction approval failed at. Which stage it is decides
|
||||||
|
// whether the approval survives the failure.
|
||||||
|
const TX_STAGE_SIGN = "sign";
|
||||||
|
const TX_STAGE_VERIFY = "verify";
|
||||||
|
const TX_STAGE_BROADCAST = "broadcast";
|
||||||
|
// Not a failure of this request at all: a second response arrived for an
|
||||||
|
// approval an attempt already holds. The first attempt is still running and
|
||||||
|
// may yet succeed, so the one thing the popup must not say is "start again
|
||||||
|
// from the site".
|
||||||
|
const TX_STAGE_INFLIGHT = "inflight";
|
||||||
|
|
||||||
|
function errorText(err) {
|
||||||
|
if (typeof err === "string" && err !== "") return err;
|
||||||
|
if (err && (err.shortMessage || err.message)) {
|
||||||
|
return err.shortMessage || err.message;
|
||||||
|
}
|
||||||
|
return "The transaction could not be sent.";
|
||||||
|
}
|
||||||
|
|
||||||
|
// What the background does with a pending transaction approval after a failed
|
||||||
|
// attempt: what it tells the popup, and whether the approval is spent
|
||||||
|
// (resolved to the requesting page as an error and deleted) or left standing
|
||||||
|
// so the user can try the transaction they already saw again.
|
||||||
|
//
|
||||||
|
// - sign: the popup could not produce an artifact, almost always a wrong
|
||||||
|
// password. Nothing left the extension, so the approval stands.
|
||||||
|
// - verify: a mismatch is a refusal and spends the approval — an artifact
|
||||||
|
// that is not the approved transaction must never be retried against that
|
||||||
|
// approval. Anything else failed before the check ran and is retryable.
|
||||||
|
// - broadcast: always terminal. A broadcast that throws after the node
|
||||||
|
// accepted the transaction is routine (a timeout, a dropped response, a
|
||||||
|
// node answering "already known"), and the popup's retry does not
|
||||||
|
// re-broadcast these bytes — it re-runs populateTransaction() and signs
|
||||||
|
// again at a freshly fetched pending-tag nonce. Retrying would therefore
|
||||||
|
// put a second transaction on the chain for one approval.
|
||||||
|
function describeTxFailure(stage, err) {
|
||||||
|
const error = errorText(err);
|
||||||
|
const retryable =
|
||||||
|
stage === TX_STAGE_SIGN ||
|
||||||
|
(stage === TX_STAGE_VERIFY && failureIsRetryable(err));
|
||||||
|
return { error, retryable, spendApproval: !retryable };
|
||||||
|
}
|
||||||
|
|
||||||
|
// What the popup shows and does after the background reports a failed signing
|
||||||
|
// attempt. A retryable failure leaves the approval pending in the background,
|
||||||
|
// so the button goes back to being usable; a refusal spent the approval, and
|
||||||
|
// the popup says so rather than offering a button that cannot succeed.
|
||||||
|
//
|
||||||
|
// A failed broadcast gets its own wording: the transaction may already be on
|
||||||
|
// the network, so telling the user to start again from the site is exactly the
|
||||||
|
// wrong instruction.
|
||||||
|
function describeSigningFailure(response, fallbackMessage) {
|
||||||
|
let message = (response && response.error) || fallbackMessage;
|
||||||
|
if (!/[.!?]$/.test(message)) message += ".";
|
||||||
|
const retryable = !!(response && response.retryable);
|
||||||
|
const stage = response && response.stage;
|
||||||
|
if (!retryable) {
|
||||||
|
if (stage === TX_STAGE_BROADCAST) {
|
||||||
|
message +=
|
||||||
|
" The transaction may still have reached the network." +
|
||||||
|
" Check the account before sending it again.";
|
||||||
|
} else if (stage === TX_STAGE_INFLIGHT) {
|
||||||
|
message +=
|
||||||
|
" The first attempt is still running and may still succeed." +
|
||||||
|
" Wait for it rather than starting again.";
|
||||||
|
} else {
|
||||||
|
message +=
|
||||||
|
" This request can no longer be signed. Please start it" +
|
||||||
|
" again from the site.";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return { message, retryable };
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
verifySignedTx,
|
||||||
|
verifySignature,
|
||||||
|
assertNoForbiddenFields,
|
||||||
|
assertNothingUnchecked,
|
||||||
|
assertCanonicalBytes,
|
||||||
|
sameAddress,
|
||||||
|
failureIsRetryable,
|
||||||
|
describeTxFailure,
|
||||||
|
describeSigningFailure,
|
||||||
|
ApprovalMismatchError,
|
||||||
|
ALLOWED_TX_TYPES,
|
||||||
|
SERIALIZED_FIELDS,
|
||||||
|
FORBIDDEN_FIELDS,
|
||||||
|
TX_STAGE_SIGN,
|
||||||
|
TX_STAGE_VERIFY,
|
||||||
|
TX_STAGE_BROADCAST,
|
||||||
|
TX_STAGE_INFLIGHT,
|
||||||
|
MAX_GAS_LIMIT,
|
||||||
|
MAX_FEE_PER_GAS,
|
||||||
|
};
|
||||||
@@ -11,14 +11,21 @@ const {
|
|||||||
const { ERC20_ABI } = require("./constants");
|
const { ERC20_ABI } = require("./constants");
|
||||||
const { log, debugFetch } = require("./log");
|
const { log, debugFetch } = require("./log");
|
||||||
const { deriveAddressFromXpub } = require("./wallet");
|
const { deriveAddressFromXpub } = require("./wallet");
|
||||||
const { KNOWN_SYMBOLS, TOKEN_BY_ADDRESS } = require("./tokenList");
|
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
||||||
|
const { LOW_HOLDER_THRESHOLD, parseHoldersCount } = require("./holders");
|
||||||
|
const { isSpoofedSymbol } = require("./symbolSpoof");
|
||||||
|
|
||||||
// Use a static network to skip auto-detection (which can fail and cause
|
// Use a static network to skip auto-detection (which can fail and cause
|
||||||
// "could not coalesce error" on some RPC endpoints like Cloudflare).
|
// "could not coalesce error" on some RPC endpoints like Cloudflare).
|
||||||
const mainnet = Network.from("mainnet");
|
// Accepts an optional networkName ("mainnet" or "sepolia") for the static
|
||||||
|
// network hint so ethers picks the right chain parameters. When omitted,
|
||||||
function getProvider(rpcUrl) {
|
// reads the currently selected network from extension state.
|
||||||
return new JsonRpcProvider(rpcUrl, mainnet, { staticNetwork: mainnet });
|
function getProvider(rpcUrl, networkName) {
|
||||||
|
// Lazy require to avoid circular dependency issues at module scope.
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
const name = networkName || currentNetwork().id;
|
||||||
|
const net = Network.from(name);
|
||||||
|
return new JsonRpcProvider(rpcUrl, net, { staticNetwork: net });
|
||||||
}
|
}
|
||||||
|
|
||||||
function formatBalance(wei) {
|
function formatBalance(wei) {
|
||||||
@@ -65,23 +72,29 @@ async function fetchTokenBalances(address, blockscoutUrl, trackedTokens) {
|
|||||||
if (bal === "0.0") continue;
|
if (bal === "0.0") continue;
|
||||||
|
|
||||||
const tokenAddr = (item.token.address_hash || "").toLowerCase();
|
const tokenAddr = (item.token.address_hash || "").toLowerCase();
|
||||||
const holders = parseInt(item.token.holders_count || "0", 10);
|
// null means the explorer reported no count, which is not the
|
||||||
|
// same as a count of zero. This gate is not the low-holder
|
||||||
|
// display filter: it has no user-facing off switch and governs
|
||||||
|
// the whole balance list, so it stays strict and admits a token
|
||||||
|
// only on a reported count — an unreported one is no evidence.
|
||||||
|
// A legitimate token still reaches the list through the known
|
||||||
|
// token list or by the user tracking it, and the null is carried
|
||||||
|
// through to the views, where the two low-holder filters treat
|
||||||
|
// an unknown count as "do not judge" rather than as zero.
|
||||||
|
const holders = parseHoldersCount(item.token.holders_count);
|
||||||
const isKnown = TOKEN_BY_ADDRESS.has(tokenAddr);
|
const isKnown = TOKEN_BY_ADDRESS.has(tokenAddr);
|
||||||
const isTracked = trackedSet.has(tokenAddr);
|
const isTracked = trackedSet.has(tokenAddr);
|
||||||
const hasEnoughHolders = holders >= 1000;
|
const hasEnoughHolders =
|
||||||
|
holders !== null && holders >= LOW_HOLDER_THRESHOLD;
|
||||||
|
|
||||||
// Skip spam tokens the user never asked to see
|
// Skip spam tokens the user never asked to see
|
||||||
if (!isKnown && !isTracked && !hasEnoughHolders) continue;
|
if (!isKnown && !isTracked && !hasEnoughHolders) continue;
|
||||||
|
|
||||||
// Skip tokens spoofing a known symbol from a different address
|
// Skip tokens spoofing a known symbol from a different address.
|
||||||
const sym = (item.token.symbol || "").toUpperCase();
|
// Every row here is an ERC-20 the explorer reported, so it has a
|
||||||
const legitAddr = KNOWN_SYMBOLS.get(sym);
|
// contract address; the native ETH balance is fetched over RPC in
|
||||||
if (
|
// refreshBalances and never passes through this loop.
|
||||||
legitAddr !== undefined &&
|
if (isSpoofedSymbol(item.token.symbol, tokenAddr)) continue;
|
||||||
legitAddr !== null &&
|
|
||||||
tokenAddr !== legitAddr
|
|
||||||
)
|
|
||||||
continue;
|
|
||||||
|
|
||||||
balances.push({
|
balances.push({
|
||||||
address: item.token.address_hash,
|
address: item.token.address_hash,
|
||||||
@@ -273,6 +286,7 @@ async function scanForAddresses(xpub, rpcUrl, gapLimit = 5) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
|
fetchTokenBalances,
|
||||||
refreshBalances,
|
refreshBalances,
|
||||||
lookupTokenInfo,
|
lookupTokenInfo,
|
||||||
getProvider,
|
getProvider,
|
||||||
|
|||||||
35
src/shared/buildInfo.js
Normal file
35
src/shared/buildInfo.js
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
// Build-time constants injected by esbuild define in build.js.
|
||||||
|
// These globals are replaced at bundle time with string literals.
|
||||||
|
|
||||||
|
/* global __BUILD_VERSION__, __BUILD_LICENSE__, __BUILD_AUTHOR__,
|
||||||
|
__BUILD_COMMIT__, __BUILD_COMMIT_FULL__, __BUILD_DATE__ */
|
||||||
|
|
||||||
|
const BUILD_VERSION =
|
||||||
|
typeof __BUILD_VERSION__ !== "undefined" ? __BUILD_VERSION__ : "dev";
|
||||||
|
const BUILD_LICENSE =
|
||||||
|
typeof __BUILD_LICENSE__ !== "undefined" ? __BUILD_LICENSE__ : "GPL-3.0";
|
||||||
|
const BUILD_AUTHOR =
|
||||||
|
typeof __BUILD_AUTHOR__ !== "undefined"
|
||||||
|
? __BUILD_AUTHOR__
|
||||||
|
: "sneak <sneak@sneak.berlin>";
|
||||||
|
const BUILD_COMMIT =
|
||||||
|
typeof __BUILD_COMMIT__ !== "undefined" ? __BUILD_COMMIT__ : "unknown";
|
||||||
|
const BUILD_COMMIT_FULL =
|
||||||
|
typeof __BUILD_COMMIT_FULL__ !== "undefined"
|
||||||
|
? __BUILD_COMMIT_FULL__
|
||||||
|
: "unknown";
|
||||||
|
const BUILD_DATE =
|
||||||
|
typeof __BUILD_DATE__ !== "undefined" ? __BUILD_DATE__ : "unknown";
|
||||||
|
|
||||||
|
const GITEA_COMMIT_URL =
|
||||||
|
"https://git.eeqj.de/sneak/AutistMask/commit/" + BUILD_COMMIT_FULL;
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
BUILD_VERSION,
|
||||||
|
BUILD_LICENSE,
|
||||||
|
BUILD_AUTHOR,
|
||||||
|
BUILD_COMMIT,
|
||||||
|
BUILD_COMMIT_FULL,
|
||||||
|
BUILD_DATE,
|
||||||
|
GITEA_COMMIT_URL,
|
||||||
|
};
|
||||||
57
src/shared/chainSwitch.js
Normal file
57
src/shared/chainSwitch.js
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
// Consolidated chain-switch handler.
|
||||||
|
//
|
||||||
|
// Every state change required when the active network changes is
|
||||||
|
// performed here so that callers (settings UI, background
|
||||||
|
// wallet_switchEthereumChain, future chain additions) all go
|
||||||
|
// through a single code path.
|
||||||
|
//
|
||||||
|
// Adding a new chain (e.g. ETC) requires only a new entry in
|
||||||
|
// networks.js — no per-caller wiring is needed.
|
||||||
|
|
||||||
|
const { networkById } = require("./networks");
|
||||||
|
const { clearPrices } = require("./prices");
|
||||||
|
|
||||||
|
// Switch the active chain and reset all chain-specific cached state.
|
||||||
|
// Returns the network configuration object for the new chain.
|
||||||
|
async function onChainSwitch(newNetworkId) {
|
||||||
|
const { state, saveState } = require("./state");
|
||||||
|
|
||||||
|
const net = networkById(newNetworkId);
|
||||||
|
|
||||||
|
// --- core identity ---
|
||||||
|
state.networkId = net.id;
|
||||||
|
state.rpcUrl = net.defaultRpcUrl;
|
||||||
|
state.blockscoutUrl = net.defaultBlockscoutUrl;
|
||||||
|
|
||||||
|
// --- price cache ---
|
||||||
|
// Prices are chain-specific (testnet tokens are worthless,
|
||||||
|
// ETC has different pricing, etc.).
|
||||||
|
clearPrices();
|
||||||
|
|
||||||
|
// --- balance / refresh state ---
|
||||||
|
// Reset last-refresh timestamp so the next polling cycle
|
||||||
|
// triggers an immediate balance refresh on the new chain.
|
||||||
|
state.lastBalanceRefresh = 0;
|
||||||
|
|
||||||
|
// Clear per-address balances and token balances so stale data
|
||||||
|
// from the previous chain is never displayed while the first
|
||||||
|
// refresh on the new chain is in flight.
|
||||||
|
for (const wallet of state.wallets) {
|
||||||
|
for (const addr of wallet.addresses) {
|
||||||
|
addr.balance = "0";
|
||||||
|
addr.tokenBalances = [];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- chain-specific caches ---
|
||||||
|
// Token holder counts and fraud contract lists are
|
||||||
|
// chain-specific and must not carry over.
|
||||||
|
state.tokenHolderCache = {};
|
||||||
|
state.fraudContracts = [];
|
||||||
|
|
||||||
|
await saveState();
|
||||||
|
|
||||||
|
return net;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { onChainSwitch };
|
||||||
@@ -1,8 +1,32 @@
|
|||||||
const DEBUG = true;
|
// DEBUG is a build-time constant injected by esbuild's define in build.js
|
||||||
|
// (see src/shared/buildInfo.js for the same pattern). It is false unless the
|
||||||
|
// bundle was produced with AUTISTMASK_DEBUG=1, and it is false whenever the
|
||||||
|
// module is loaded outside a bundle (tests, plain require). It must never be
|
||||||
|
// derived from anything the user can change at runtime: it is what gates the
|
||||||
|
// hardcoded test mnemonic below.
|
||||||
|
/* global __BUILD_DEBUG__ */
|
||||||
|
const DEBUG = typeof __BUILD_DEBUG__ !== "undefined" ? __BUILD_DEBUG__ : false;
|
||||||
|
|
||||||
|
// Machine-readable record of the compiled DEBUG state, read out of the emitted
|
||||||
|
// bundles by script/verify-build. It is derived from DEBUG itself so the two
|
||||||
|
// cannot disagree, and it is a plain string literal rather than a minifier
|
||||||
|
// artifact like `DEBUG:!1`, so the check does not depend on esbuild's output
|
||||||
|
// staying byte-stable across versions.
|
||||||
|
//
|
||||||
|
// The ambiguity is the point. When DEBUG is known at build time the bundler
|
||||||
|
// folds this to exactly one of the two literals. When it is not — which is
|
||||||
|
// exactly what happens if the __BUILD_DEBUG__ define goes missing from
|
||||||
|
// build.js — the ternary survives, both literals appear in the bundle, and
|
||||||
|
// verify-build fails rather than guessing.
|
||||||
|
const BUILD_DEBUG_MARKER = DEBUG
|
||||||
|
? "autistmask-build-debug=on"
|
||||||
|
: "autistmask-build-debug=off";
|
||||||
|
|
||||||
const DEBUG_MNEMONIC =
|
const DEBUG_MNEMONIC =
|
||||||
"cube evolve unfold result inch risk jealous skill hotel bulb night wreck";
|
"cube evolve unfold result inch risk jealous skill hotel bulb night wreck";
|
||||||
|
|
||||||
const ETHEREUM_MAINNET_CHAIN_ID = "0x1";
|
const ETHEREUM_MAINNET_CHAIN_ID = "0x1";
|
||||||
|
const ETHEREUM_SEPOLIA_CHAIN_ID = "0xaa36a7";
|
||||||
|
|
||||||
const DEFAULT_RPC_URL = "https://ethereum-rpc.publicnode.com";
|
const DEFAULT_RPC_URL = "https://ethereum-rpc.publicnode.com";
|
||||||
|
|
||||||
@@ -20,12 +44,29 @@ const ERC20_ABI = [
|
|||||||
"function approve(address spender, uint256 amount) returns (bool)",
|
"function approve(address spender, uint256 amount) returns (bool)",
|
||||||
];
|
];
|
||||||
|
|
||||||
|
// Known null/burn addresses that permanently destroy funds.
|
||||||
|
const BURN_ADDRESSES = new Set([
|
||||||
|
"0x0000000000000000000000000000000000000000",
|
||||||
|
"0x0000000000000000000000000000000000000001",
|
||||||
|
"0x000000000000000000000000000000000000dead",
|
||||||
|
"0xdead000000000000000000000000000000000000",
|
||||||
|
"0x00000000000000000000000000000000deadbeef",
|
||||||
|
]);
|
||||||
|
|
||||||
|
function isBurnAddress(address) {
|
||||||
|
return BURN_ADDRESSES.has(address.toLowerCase());
|
||||||
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
DEBUG,
|
DEBUG,
|
||||||
|
BUILD_DEBUG_MARKER,
|
||||||
DEBUG_MNEMONIC,
|
DEBUG_MNEMONIC,
|
||||||
ETHEREUM_MAINNET_CHAIN_ID,
|
ETHEREUM_MAINNET_CHAIN_ID,
|
||||||
|
ETHEREUM_SEPOLIA_CHAIN_ID,
|
||||||
DEFAULT_RPC_URL,
|
DEFAULT_RPC_URL,
|
||||||
DEFAULT_BLOCKSCOUT_URL,
|
DEFAULT_BLOCKSCOUT_URL,
|
||||||
BIP44_ETH_PATH,
|
BIP44_ETH_PATH,
|
||||||
ERC20_ABI,
|
ERC20_ABI,
|
||||||
|
BURN_ADDRESSES,
|
||||||
|
isBurnAddress,
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,6 +1,11 @@
|
|||||||
// Cached ENS reverse resolution.
|
// Cached ENS reverse resolution.
|
||||||
// Resolves addresses to ENS names via ethers provider.lookupAddress(),
|
// Resolves addresses to ENS names via ethers provider.lookupAddress(),
|
||||||
// caching results in localStorage with a 12-hour TTL.
|
// caching results in localStorage with a 12-hour TTL.
|
||||||
|
//
|
||||||
|
// POPUP ONLY. localStorage does not exist in the Chrome MV3 service worker,
|
||||||
|
// so this module must not be pulled into src/background/. Anything the
|
||||||
|
// background context needs to cache goes in extension storage instead (see
|
||||||
|
// shared/phishingDomains.js).
|
||||||
|
|
||||||
const { getProvider } = require("./balances");
|
const { getProvider } = require("./balances");
|
||||||
const { log } = require("./log");
|
const { log } = require("./log");
|
||||||
|
|||||||
107
src/shared/etherscanLabels.js
Normal file
107
src/shared/etherscanLabels.js
Normal file
@@ -0,0 +1,107 @@
|
|||||||
|
// Etherscan address label lookup via page scraping.
|
||||||
|
// Extension users make the requests directly to Etherscan — no proxy needed.
|
||||||
|
// This is a best-effort enrichment: network failures return null silently.
|
||||||
|
|
||||||
|
// Patterns in the page title that indicate a flagged address.
|
||||||
|
// Title format: "Fake_Phishing184810 | Address: 0x... | Etherscan"
|
||||||
|
const PHISHING_LABEL_PATTERNS = [/^Fake_Phishing/i, /^Phish:/i, /^Exploiter/i];
|
||||||
|
|
||||||
|
// Patterns in the page body that indicate a scam/phishing warning.
|
||||||
|
const SCAM_BODY_PATTERNS = [
|
||||||
|
/used in a\s+(?:\w+\s+)?phishing scam/i,
|
||||||
|
/used in a\s+(?:\w+\s+)?scam/i,
|
||||||
|
/wallet\s+drainer/i,
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Parse the Etherscan address page HTML to extract label info.
|
||||||
|
* Exported for unit testing (no fetch needed).
|
||||||
|
*
|
||||||
|
* @param {string} html - Raw HTML of the Etherscan address page.
|
||||||
|
* @returns {{ label: string|null, isPhishing: boolean, warning: string|null }}
|
||||||
|
*/
|
||||||
|
function parseEtherscanPage(html) {
|
||||||
|
// Extract <title> content
|
||||||
|
const titleMatch = html.match(/<title[^>]*>([^<]+)<\/title>/i);
|
||||||
|
let label = null;
|
||||||
|
let isPhishing = false;
|
||||||
|
let warning = null;
|
||||||
|
|
||||||
|
if (titleMatch) {
|
||||||
|
const title = titleMatch[1].trim();
|
||||||
|
// Title: "LABEL | Address: 0x... | Etherscan" or "Address: 0x... | Etherscan"
|
||||||
|
const labelMatch = title.match(/^(.+?)\s*\|\s*Address:/);
|
||||||
|
if (labelMatch) {
|
||||||
|
const candidate = labelMatch[1].trim();
|
||||||
|
// Only treat as a label if it's not just "Address" (unlabeled addresses)
|
||||||
|
if (candidate.toLowerCase() !== "address") {
|
||||||
|
label = candidate;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check label against phishing patterns
|
||||||
|
if (label) {
|
||||||
|
for (const pat of PHISHING_LABEL_PATTERNS) {
|
||||||
|
if (pat.test(label)) {
|
||||||
|
isPhishing = true;
|
||||||
|
warning = `Etherscan labels this address as "${label}" (Phish/Hack).`;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check page body for scam warning banners
|
||||||
|
if (!isPhishing) {
|
||||||
|
for (const pat of SCAM_BODY_PATTERNS) {
|
||||||
|
if (pat.test(html)) {
|
||||||
|
isPhishing = true;
|
||||||
|
warning = label
|
||||||
|
? `Etherscan labels this address as "${label}" and reports it was used in a scam.`
|
||||||
|
: "Etherscan reports this address was flagged for phishing/scam activity.";
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return { label, isPhishing, warning };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Fetch an address page from Etherscan and check for scam/phishing labels.
|
||||||
|
* Returns a warning object if the address is flagged, or null.
|
||||||
|
* Network failures return null silently (best-effort check).
|
||||||
|
*
|
||||||
|
* Uses the current network's explorer URL so the lookup works on both
|
||||||
|
* mainnet (etherscan.io) and Sepolia (sepolia.etherscan.io).
|
||||||
|
*
|
||||||
|
* @param {string} address - Ethereum address to check.
|
||||||
|
* @returns {Promise<{type: string, message: string, severity: string}|null>}
|
||||||
|
*/
|
||||||
|
async function checkEtherscanLabel(address) {
|
||||||
|
try {
|
||||||
|
// Lazy require to avoid pulling in chrome.storage at module scope
|
||||||
|
// (which breaks unit tests that only exercise parseEtherscanPage).
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
const etherscanBase = currentNetwork().explorerUrl + "/address/";
|
||||||
|
const resp = await fetch(etherscanBase + address, {
|
||||||
|
headers: { Accept: "text/html" },
|
||||||
|
});
|
||||||
|
if (!resp.ok) return null;
|
||||||
|
const html = await resp.text();
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
if (result.isPhishing) {
|
||||||
|
return {
|
||||||
|
type: "etherscan-phishing",
|
||||||
|
message: result.warning,
|
||||||
|
severity: "critical",
|
||||||
|
};
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
} catch {
|
||||||
|
// Network errors are expected — Etherscan may rate-limit or block.
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { parseEtherscanPage, checkEtherscanLabel };
|
||||||
32
src/shared/holders.js
Normal file
32
src/shared/holders.js
Normal file
@@ -0,0 +1,32 @@
|
|||||||
|
// Holder counts, and the one rule that decides whether a count is "low".
|
||||||
|
//
|
||||||
|
// The block explorer's holders_count is optional: it is absent on a token it
|
||||||
|
// has only just indexed, and it goes missing on a degraded or changed API.
|
||||||
|
// Absent means the count is unknown. It does not mean the token has no
|
||||||
|
// holders, and collapsing the two hides a token the user really holds as if
|
||||||
|
// it were spam. Every call site reads the count through here so the
|
||||||
|
// distinction cannot be lost again in one place while holding in the others.
|
||||||
|
|
||||||
|
const LOW_HOLDER_THRESHOLD = 1000;
|
||||||
|
|
||||||
|
// Parse an explorer-supplied holders_count into a number, or null when the
|
||||||
|
// explorer did not report one. Anything unparseable is unknown too: a count
|
||||||
|
// we cannot read is not a count of zero.
|
||||||
|
function parseHoldersCount(raw) {
|
||||||
|
if (raw === null || raw === undefined || raw === "") return null;
|
||||||
|
const n = parseInt(raw, 10);
|
||||||
|
return Number.isFinite(n) ? n : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// True only for a token the explorer reported as having fewer holders than
|
||||||
|
// the threshold. An unknown count is never low: showing a spam token the
|
||||||
|
// user can see is unusual costs less than hiding an asset they own.
|
||||||
|
function isLowHolderCount(holders) {
|
||||||
|
return holders != null && holders < LOW_HOLDER_THRESHOLD;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
LOW_HOLDER_THRESHOLD,
|
||||||
|
parseHoldersCount,
|
||||||
|
isLowHolderCount,
|
||||||
|
};
|
||||||
@@ -1,12 +1,27 @@
|
|||||||
// Leveled logger. Outputs to console with [AutistMask] prefix.
|
// Leveled logger. Outputs to console with [AutistMask] prefix.
|
||||||
// Level is DEBUG when the DEBUG constant is true, INFO otherwise.
|
// Level is DEBUG when the compile-time DEBUG constant is true or the runtime
|
||||||
|
// debugMode state flag is enabled. The runtime flag is checked lazily so it
|
||||||
|
// responds immediately when toggled in settings.
|
||||||
|
|
||||||
const { DEBUG } = require("./constants");
|
const { DEBUG } = require("./constants");
|
||||||
|
|
||||||
const LEVELS = { debug: 0, info: 1, warn: 2, error: 3 };
|
const LEVELS = { debug: 0, info: 1, warn: 2, error: 3 };
|
||||||
const threshold = DEBUG ? LEVELS.debug : LEVELS.info;
|
|
||||||
|
// Runtime debug mode flag — set by settings.js when the user toggles debug
|
||||||
|
// mode via the easter egg. Kept here as a simple mutable reference so it can
|
||||||
|
// be updated without circular dependency issues with state.js.
|
||||||
|
let _runtimeDebug = false;
|
||||||
|
|
||||||
|
function setRuntimeDebug(enabled) {
|
||||||
|
_runtimeDebug = enabled;
|
||||||
|
}
|
||||||
|
|
||||||
|
function isDebug() {
|
||||||
|
return DEBUG || _runtimeDebug;
|
||||||
|
}
|
||||||
|
|
||||||
function emit(level, method, args) {
|
function emit(level, method, args) {
|
||||||
|
const threshold = isDebug() ? LEVELS.debug : LEVELS.info;
|
||||||
if (LEVELS[level] >= threshold) {
|
if (LEVELS[level] >= threshold) {
|
||||||
console[method]("[AutistMask]", ...args);
|
console[method]("[AutistMask]", ...args);
|
||||||
}
|
}
|
||||||
@@ -37,4 +52,4 @@ async function debugFetch(url, opts) {
|
|||||||
return resp;
|
return resp;
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { log, debugFetch };
|
module.exports = { log, debugFetch, setRuntimeDebug, isDebug };
|
||||||
|
|||||||
57
src/shared/networks.js
Normal file
57
src/shared/networks.js
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
// Network definitions for supported Ethereum networks.
|
||||||
|
// Each network specifies its chain ID, default RPC and Blockscout endpoints,
|
||||||
|
// and the block explorer base URL used for address/tx/token/block links.
|
||||||
|
|
||||||
|
const NETWORKS = {
|
||||||
|
mainnet: {
|
||||||
|
id: "mainnet",
|
||||||
|
name: "Ethereum Mainnet",
|
||||||
|
chainId: "0x1",
|
||||||
|
networkVersion: "1",
|
||||||
|
nativeCurrency: "ETH",
|
||||||
|
defaultRpcUrl: "https://ethereum-rpc.publicnode.com",
|
||||||
|
defaultBlockscoutUrl: "https://eth.blockscout.com/api/v2",
|
||||||
|
explorerUrl: "https://etherscan.io",
|
||||||
|
isTestnet: false,
|
||||||
|
},
|
||||||
|
sepolia: {
|
||||||
|
id: "sepolia",
|
||||||
|
name: "Sepolia Testnet",
|
||||||
|
chainId: "0xaa36a7",
|
||||||
|
networkVersion: "11155111",
|
||||||
|
nativeCurrency: "SepoliaETH",
|
||||||
|
defaultRpcUrl: "https://ethereum-sepolia-rpc.publicnode.com",
|
||||||
|
defaultBlockscoutUrl: "https://eth-sepolia.blockscout.com/api/v2",
|
||||||
|
explorerUrl: "https://sepolia.etherscan.io",
|
||||||
|
isTestnet: true,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
const SUPPORTED_CHAIN_IDS = new Set(
|
||||||
|
Object.values(NETWORKS).map((n) => n.chainId),
|
||||||
|
);
|
||||||
|
|
||||||
|
function networkById(id) {
|
||||||
|
return NETWORKS[id] || NETWORKS.mainnet;
|
||||||
|
}
|
||||||
|
|
||||||
|
function networkByChainId(chainId) {
|
||||||
|
for (const net of Object.values(NETWORKS)) {
|
||||||
|
if (net.chainId === chainId) return net;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Build a block explorer link for the given path type and value.
|
||||||
|
// type: "address" | "tx" | "token" | "block"
|
||||||
|
function explorerLink(network, type, value) {
|
||||||
|
return `${network.explorerUrl}/${type}/${value}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
NETWORKS,
|
||||||
|
SUPPORTED_CHAIN_IDS,
|
||||||
|
networkById,
|
||||||
|
networkByChainId,
|
||||||
|
explorerLink,
|
||||||
|
};
|
||||||
231418
src/shared/phishingBlocklist.json
Normal file
231418
src/shared/phishingBlocklist.json
Normal file
File diff suppressed because it is too large
Load Diff
342
src/shared/phishingDomains.js
Normal file
342
src/shared/phishingDomains.js
Normal file
@@ -0,0 +1,342 @@
|
|||||||
|
// Domain-based phishing detection using a vendored blocklist with delta updates.
|
||||||
|
//
|
||||||
|
// A community-maintained phishing domain blocklist is vendored in
|
||||||
|
// phishingBlocklist.json and bundled at build time. At runtime, we fetch
|
||||||
|
// the live list periodically and keep only the delta (new entries not in
|
||||||
|
// the vendored list) in memory. This keeps runtime memory usage small.
|
||||||
|
//
|
||||||
|
// The domain-checker checks the in-memory delta first (fresh/recent scam
|
||||||
|
// sites), then falls back to the vendored list.
|
||||||
|
//
|
||||||
|
// If the delta and its fetch timestamp fit in 256 KiB they are persisted to
|
||||||
|
// extension storage, so they survive termination of the MV3 service worker.
|
||||||
|
// Extension storage, not localStorage: localStorage does not exist in a
|
||||||
|
// service worker, so the previous persistence never ran on Chrome at all.
|
||||||
|
// The stored timestamps are what keep a restarted worker from re-fetching on
|
||||||
|
// every wake while still noticing an overdue update. Those guards apply to the
|
||||||
|
// startup path only; the 24-hour alarm tick bypasses them, or it would veto
|
||||||
|
// its own refresh — see updatePhishingList().
|
||||||
|
|
||||||
|
const vendoredConfig = require("./phishingBlocklist.json");
|
||||||
|
|
||||||
|
const BLOCKLIST_URL =
|
||||||
|
"https://raw.githubusercontent.com/MetaMask/eth-phishing-detect/main/src/config.json";
|
||||||
|
|
||||||
|
const CACHE_TTL_MS = 24 * 60 * 60 * 1000; // 24 hours
|
||||||
|
|
||||||
|
// Floor on how often an unscheduled path may hit the network. The worker is
|
||||||
|
// revived every ~30 seconds while the browser is busy, and every revival runs
|
||||||
|
// the startup path; without a persisted record of the last attempt, any state
|
||||||
|
// that leaves lastFetchTime unset — a fetch that failed, or a delta too large
|
||||||
|
// to store — would download the full list on every single wake.
|
||||||
|
const MIN_FETCH_ATTEMPT_INTERVAL_MS = 60 * 60 * 1000; // 1 hour
|
||||||
|
|
||||||
|
const DELTA_STORAGE_KEY = "phishing-delta";
|
||||||
|
const MAX_DELTA_BYTES = 256 * 1024; // 256 KiB
|
||||||
|
|
||||||
|
// Vendored set — built once from the bundled JSON.
|
||||||
|
const vendoredBlacklist = new Set(
|
||||||
|
(vendoredConfig.blacklist || []).map((d) => d.toLowerCase()),
|
||||||
|
);
|
||||||
|
|
||||||
|
// Delta set — only entries from live list that are NOT in vendored.
|
||||||
|
let deltaBlacklist = new Set();
|
||||||
|
let lastFetchTime = 0;
|
||||||
|
let lastAttemptTime = 0;
|
||||||
|
let fetchPromise = null;
|
||||||
|
let loadPromise = null;
|
||||||
|
|
||||||
|
// Resolved on use rather than captured at module load, so a test can install
|
||||||
|
// a stub after requiring the module and so the popup — which has no reason to
|
||||||
|
// touch the delta — does not fail to load where the API is absent.
|
||||||
|
function storageApi() {
|
||||||
|
if (typeof browser !== "undefined" && browser.storage) {
|
||||||
|
return browser.storage.local;
|
||||||
|
}
|
||||||
|
if (typeof chrome !== "undefined" && chrome.storage) {
|
||||||
|
return chrome.storage.local;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Sanitise a timestamp read back from storage.
|
||||||
|
*
|
||||||
|
* A value in the future is permanent poison: every guard here measures elapsed
|
||||||
|
* time as `Date.now() - stamp` and tests only the lower bound, so a stamp a
|
||||||
|
* year ahead suppresses updates for a year with no path that ever clears it.
|
||||||
|
* Clock skew and a restored profile backup both produce one. Since these
|
||||||
|
* timestamps only ever gate work, discarding an impossible one is safe: it
|
||||||
|
* costs at most a single extra fetch and restores a sane value immediately.
|
||||||
|
*
|
||||||
|
* @param {unknown} value
|
||||||
|
* @returns {number} the timestamp, or 0 if it is unusable.
|
||||||
|
*/
|
||||||
|
function sanitizeTimestamp(value) {
|
||||||
|
if (typeof value !== "number" || !Number.isFinite(value)) return 0;
|
||||||
|
if (value <= 0 || value > Date.now()) return 0;
|
||||||
|
return value;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Load the persisted delta and its timestamps from extension storage.
|
||||||
|
* Runs once per worker lifetime; every entry point funnels through
|
||||||
|
* ensureDeltaLoaded() so a wake from termination restores state exactly once.
|
||||||
|
*
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async function loadDeltaFromStorage() {
|
||||||
|
const storage = storageApi();
|
||||||
|
if (!storage) return;
|
||||||
|
try {
|
||||||
|
const result = await storage.get(DELTA_STORAGE_KEY);
|
||||||
|
const data = result && result[DELTA_STORAGE_KEY];
|
||||||
|
if (!data) return;
|
||||||
|
if (Array.isArray(data.blacklist)) {
|
||||||
|
deltaBlacklist = new Set(
|
||||||
|
data.blacklist.map((d) => d.toLowerCase()),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
lastFetchTime = sanitizeTimestamp(data.lastFetchTime);
|
||||||
|
lastAttemptTime = sanitizeTimestamp(data.lastAttemptTime);
|
||||||
|
} catch {
|
||||||
|
// Storage unavailable or corrupt — start empty and re-fetch.
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function ensureDeltaLoaded() {
|
||||||
|
if (!loadPromise) loadPromise = loadDeltaFromStorage();
|
||||||
|
return loadPromise;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Persist the delta and its timestamps if they fit within MAX_DELTA_BYTES.
|
||||||
|
*
|
||||||
|
* The 256 KiB cap covers the delta and its freshness claim: when the delta is
|
||||||
|
* too large to keep, lastFetchTime goes with it, so the next start re-fetches
|
||||||
|
* rather than trusting a freshness claim for a delta it no longer holds.
|
||||||
|
* lastAttemptTime is written either way — it records that the network was
|
||||||
|
* contacted, which stays true whatever became of the response, and it is what
|
||||||
|
* stops a permanently oversized list from downloading on every worker wake.
|
||||||
|
*
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async function saveDeltaToStorage() {
|
||||||
|
const storage = storageApi();
|
||||||
|
if (!storage) return;
|
||||||
|
try {
|
||||||
|
const data = {
|
||||||
|
blacklist: Array.from(deltaBlacklist),
|
||||||
|
lastFetchTime,
|
||||||
|
lastAttemptTime,
|
||||||
|
};
|
||||||
|
const json = JSON.stringify(data);
|
||||||
|
if (json.length < MAX_DELTA_BYTES) {
|
||||||
|
await storage.set({ [DELTA_STORAGE_KEY]: data });
|
||||||
|
} else if (lastAttemptTime > 0) {
|
||||||
|
await storage.set({ [DELTA_STORAGE_KEY]: { lastAttemptTime } });
|
||||||
|
} else {
|
||||||
|
await storage.remove(DELTA_STORAGE_KEY);
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// Storage unavailable — skip silently
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Load a pre-parsed config and compute the delta against the vendored list.
|
||||||
|
* Used for both live fetches and testing.
|
||||||
|
*
|
||||||
|
* @param {{ blacklist?: string[] }} config
|
||||||
|
* @returns {Promise<void>} resolves once the delta has been persisted.
|
||||||
|
*/
|
||||||
|
function loadConfig(config) {
|
||||||
|
const liveBlacklist = (config.blacklist || []).map((d) => d.toLowerCase());
|
||||||
|
|
||||||
|
// Delta = entries in the live list that are NOT in the vendored list
|
||||||
|
deltaBlacklist = new Set(
|
||||||
|
liveBlacklist.filter((d) => !vendoredBlacklist.has(d)),
|
||||||
|
);
|
||||||
|
|
||||||
|
lastFetchTime = Date.now();
|
||||||
|
return saveDeltaToStorage();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Generate hostname variants for subdomain matching.
|
||||||
|
* "sub.evil.com" yields ["sub.evil.com", "evil.com"].
|
||||||
|
*
|
||||||
|
* @param {string} hostname
|
||||||
|
* @returns {string[]}
|
||||||
|
*/
|
||||||
|
function hostnameVariants(hostname) {
|
||||||
|
const h = hostname.toLowerCase();
|
||||||
|
const variants = [h];
|
||||||
|
const parts = h.split(".");
|
||||||
|
// Parent domains: a.b.c.d -> b.c.d, c.d
|
||||||
|
for (let i = 1; i < parts.length - 1; i++) {
|
||||||
|
variants.push(parts.slice(i).join("."));
|
||||||
|
}
|
||||||
|
return variants;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check if a hostname is on the phishing blocklist.
|
||||||
|
* Checks delta first (fresh/recent scam sites), then vendored list.
|
||||||
|
*
|
||||||
|
* Synchronous by design — callers answer an approval prompt with it. On a
|
||||||
|
* worker that has just woken, the persisted delta may still be loading; the
|
||||||
|
* vendored list, which is bundled and always present, carries the check until
|
||||||
|
* it lands.
|
||||||
|
*
|
||||||
|
* @param {string} hostname - The hostname to check.
|
||||||
|
* @returns {boolean}
|
||||||
|
*/
|
||||||
|
function isPhishingDomain(hostname) {
|
||||||
|
if (!hostname) return false;
|
||||||
|
const variants = hostnameVariants(hostname);
|
||||||
|
|
||||||
|
// Check delta blacklist first (fresh/recent scam sites), then vendored
|
||||||
|
for (const v of variants) {
|
||||||
|
if (deltaBlacklist.has(v) || vendoredBlacklist.has(v)) return true;
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Fetch the latest blocklist and compute delta against vendored data.
|
||||||
|
* De-duplicates concurrent fetches. Results are cached for CACHE_TTL_MS,
|
||||||
|
* counted from the persisted timestamp so the cache outlives the worker.
|
||||||
|
*
|
||||||
|
* `force` is what makes the 24-hour alarm actually refresh every 24 hours.
|
||||||
|
* The alarm fires one period after the previous alarm, but lastFetchTime is
|
||||||
|
* stamped when that fetch *completed*, so an unforced tick lands one fetch
|
||||||
|
* latency inside its own TTL, skips, and turns the real cadence into 48 hours.
|
||||||
|
* Shortening the TTL instead would not fix it: the worker wakes every ~30
|
||||||
|
* seconds and the startup path re-checks the TTL each time, so a shortened TTL
|
||||||
|
* simply becomes the real cadence. The TTL is there to stop redundant fetches
|
||||||
|
* on wake, and the scheduled tick is not redundant, so it bypasses it.
|
||||||
|
*
|
||||||
|
* @param {{force?: boolean}} [opts] force: fetch unless one is already in
|
||||||
|
* flight, ignoring both the freshness and the retry guard. For the scheduled
|
||||||
|
* alarm tick only.
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async function updatePhishingList({ force = false } = {}) {
|
||||||
|
// A worker that has just been revived knows nothing until the persisted
|
||||||
|
// record is back in memory; without this the freshness check below would
|
||||||
|
// always see 0 and re-fetch on every wake.
|
||||||
|
await ensureDeltaLoaded();
|
||||||
|
|
||||||
|
if (!force) {
|
||||||
|
const now = Date.now();
|
||||||
|
// Skip if recently fetched.
|
||||||
|
if (lastFetchTime > 0 && now - lastFetchTime < CACHE_TTL_MS) return;
|
||||||
|
// Skip if the network was contacted recently and the result was not
|
||||||
|
// usable — a failed fetch or an oversized delta leaves lastFetchTime
|
||||||
|
// unset, and without this every wake would retry.
|
||||||
|
if (
|
||||||
|
lastAttemptTime > 0 &&
|
||||||
|
now - lastAttemptTime < MIN_FETCH_ATTEMPT_INTERVAL_MS
|
||||||
|
) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// De-duplicate concurrent calls
|
||||||
|
if (fetchPromise) return fetchPromise;
|
||||||
|
|
||||||
|
fetchPromise = (async () => {
|
||||||
|
lastAttemptTime = Date.now();
|
||||||
|
try {
|
||||||
|
const resp = await fetch(BLOCKLIST_URL);
|
||||||
|
if (!resp.ok) throw new Error("HTTP " + resp.status);
|
||||||
|
const config = await resp.json();
|
||||||
|
await loadConfig(config);
|
||||||
|
} catch {
|
||||||
|
// Silently fail — vendored list still provides coverage. Persist
|
||||||
|
// the attempt so a persistently failing fetch is retried on the
|
||||||
|
// schedule rather than on every wake.
|
||||||
|
await saveDeltaToStorage();
|
||||||
|
} finally {
|
||||||
|
fetchPromise = null;
|
||||||
|
}
|
||||||
|
})();
|
||||||
|
|
||||||
|
return fetchPromise;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Restore persisted state and fetch if the list is overdue.
|
||||||
|
*
|
||||||
|
* Called from the background script every time it starts — a fresh install,
|
||||||
|
* a browser start, and every revival of a terminated service worker all land
|
||||||
|
* here. The recurring 24-hour schedule itself is an alarm (see
|
||||||
|
* shared/alarms.js), not a timer, because timers die with the worker.
|
||||||
|
*
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async function initPhishingList() {
|
||||||
|
await ensureDeltaLoaded();
|
||||||
|
return updatePhishingList();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The 24-hour alarm tick. Separate from initPhishingList() because this is the
|
||||||
|
* scheduled refresh and must not be vetoed by the guards that exist to keep
|
||||||
|
* the unscheduled startup path off the network.
|
||||||
|
*
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async function refreshPhishingListOnSchedule() {
|
||||||
|
return updatePhishingList({ force: true });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return the total blocklist size (vendored + delta) for diagnostics.
|
||||||
|
*
|
||||||
|
* @returns {number}
|
||||||
|
*/
|
||||||
|
function getBlocklistSize() {
|
||||||
|
return vendoredBlacklist.size + deltaBlacklist.size;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return the delta blocklist size for diagnostics.
|
||||||
|
*
|
||||||
|
* @returns {number}
|
||||||
|
*/
|
||||||
|
function getDeltaSize() {
|
||||||
|
return deltaBlacklist.size;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reset internal state (for testing).
|
||||||
|
*/
|
||||||
|
function _reset() {
|
||||||
|
deltaBlacklist = new Set();
|
||||||
|
lastFetchTime = 0;
|
||||||
|
lastAttemptTime = 0;
|
||||||
|
fetchPromise = null;
|
||||||
|
loadPromise = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
isPhishingDomain,
|
||||||
|
updatePhishingList,
|
||||||
|
refreshPhishingListOnSchedule,
|
||||||
|
initPhishingList,
|
||||||
|
loadDeltaFromStorage,
|
||||||
|
loadConfig,
|
||||||
|
CACHE_TTL_MS,
|
||||||
|
MIN_FETCH_ATTEMPT_INTERVAL_MS,
|
||||||
|
DELTA_STORAGE_KEY,
|
||||||
|
MAX_DELTA_BYTES,
|
||||||
|
getBlocklistSize,
|
||||||
|
getDeltaSize,
|
||||||
|
hostnameVariants,
|
||||||
|
_reset,
|
||||||
|
// Exposed for testing only
|
||||||
|
_getVendoredBlacklistSize: () => vendoredBlacklist.size,
|
||||||
|
_getDeltaBlacklist: () => deltaBlacklist,
|
||||||
|
};
|
||||||
@@ -8,6 +8,13 @@ const prices = {};
|
|||||||
let lastFetchedAt = 0;
|
let lastFetchedAt = 0;
|
||||||
|
|
||||||
async function refreshPrices() {
|
async function refreshPrices() {
|
||||||
|
// Testnet tokens have no real market value — skip price fetching
|
||||||
|
// and clear any stale mainnet prices so the UI shows no USD values.
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
if (currentNetwork().isTestnet) {
|
||||||
|
clearPrices();
|
||||||
|
return;
|
||||||
|
}
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
if (now - lastFetchedAt < PRICE_CACHE_TTL) return;
|
if (now - lastFetchedAt < PRICE_CACHE_TTL) return;
|
||||||
try {
|
try {
|
||||||
@@ -19,7 +26,19 @@ async function refreshPrices() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Clear all cached prices and reset the fetch timestamp so the
|
||||||
|
// next refreshPrices() call will fetch fresh data.
|
||||||
|
function clearPrices() {
|
||||||
|
for (const key of Object.keys(prices)) {
|
||||||
|
delete prices[key];
|
||||||
|
}
|
||||||
|
lastFetchedAt = 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Return the USD price for a symbol, or null on testnet / unknown.
|
||||||
function getPrice(symbol) {
|
function getPrice(symbol) {
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
if (currentNetwork().isTestnet) return null;
|
||||||
return prices[symbol] || null;
|
return prices[symbol] || null;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -37,6 +56,8 @@ function formatUsd(amount) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function getAddressValueUsd(addr) {
|
function getAddressValueUsd(addr) {
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
if (currentNetwork().isTestnet) return null;
|
||||||
if (!prices.ETH) return null;
|
if (!prices.ETH) return null;
|
||||||
let total = 0;
|
let total = 0;
|
||||||
const ethBal = parseFloat(addr.balance || "0");
|
const ethBal = parseFloat(addr.balance || "0");
|
||||||
@@ -51,6 +72,8 @@ function getAddressValueUsd(addr) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function getWalletValueUsd(wallet) {
|
function getWalletValueUsd(wallet) {
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
if (currentNetwork().isTestnet) return null;
|
||||||
if (!prices.ETH) return null;
|
if (!prices.ETH) return null;
|
||||||
let total = 0;
|
let total = 0;
|
||||||
for (const addr of wallet.addresses) {
|
for (const addr of wallet.addresses) {
|
||||||
@@ -60,6 +83,8 @@ function getWalletValueUsd(wallet) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function getTotalValueUsd(wallets) {
|
function getTotalValueUsd(wallets) {
|
||||||
|
const { currentNetwork } = require("./state");
|
||||||
|
if (currentNetwork().isTestnet) return null;
|
||||||
if (!prices.ETH) return null;
|
if (!prices.ETH) return null;
|
||||||
let total = 0;
|
let total = 0;
|
||||||
for (const wallet of wallets) {
|
for (const wallet of wallets) {
|
||||||
@@ -71,6 +96,7 @@ function getTotalValueUsd(wallets) {
|
|||||||
module.exports = {
|
module.exports = {
|
||||||
prices,
|
prices,
|
||||||
refreshPrices,
|
refreshPrices,
|
||||||
|
clearPrices,
|
||||||
getPrice,
|
getPrice,
|
||||||
formatUsd,
|
formatUsd,
|
||||||
getAddressValueUsd,
|
getAddressValueUsd,
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -1,6 +1,7 @@
|
|||||||
// State management and extension storage persistence.
|
// State management and extension storage persistence.
|
||||||
|
|
||||||
const { DEFAULT_RPC_URL, DEFAULT_BLOCKSCOUT_URL } = require("./constants");
|
const { DEFAULT_RPC_URL, DEFAULT_BLOCKSCOUT_URL } = require("./constants");
|
||||||
|
const { networkById } = require("./networks");
|
||||||
|
|
||||||
const storageApi =
|
const storageApi =
|
||||||
typeof browser !== "undefined"
|
typeof browser !== "undefined"
|
||||||
@@ -11,6 +12,7 @@ const DEFAULT_STATE = {
|
|||||||
hasWallet: false,
|
hasWallet: false,
|
||||||
wallets: [],
|
wallets: [],
|
||||||
trackedTokens: [],
|
trackedTokens: [],
|
||||||
|
networkId: "mainnet",
|
||||||
rpcUrl: DEFAULT_RPC_URL,
|
rpcUrl: DEFAULT_RPC_URL,
|
||||||
blockscoutUrl: DEFAULT_BLOCKSCOUT_URL,
|
blockscoutUrl: DEFAULT_BLOCKSCOUT_URL,
|
||||||
lastBalanceRefresh: 0,
|
lastBalanceRefresh: 0,
|
||||||
@@ -19,12 +21,16 @@ const DEFAULT_STATE = {
|
|||||||
deniedSites: {},
|
deniedSites: {},
|
||||||
rememberSiteChoice: true,
|
rememberSiteChoice: true,
|
||||||
showZeroBalanceTokens: true,
|
showZeroBalanceTokens: true,
|
||||||
|
hideSpoofedSymbols: true,
|
||||||
hideLowHolderTokens: true,
|
hideLowHolderTokens: true,
|
||||||
hideFraudContracts: true,
|
hideFraudContracts: true,
|
||||||
hideDustTransactions: true,
|
hideDustTransactions: true,
|
||||||
dustThresholdGwei: 100000,
|
dustThresholdGwei: 100000,
|
||||||
|
utcTimestamps: false,
|
||||||
fraudContracts: [],
|
fraudContracts: [],
|
||||||
tokenHolderCache: {},
|
tokenHolderCache: {},
|
||||||
|
theme: "system",
|
||||||
|
debugMode: false,
|
||||||
};
|
};
|
||||||
|
|
||||||
const state = {
|
const state = {
|
||||||
@@ -34,13 +40,20 @@ const state = {
|
|||||||
selectedAddress: null,
|
selectedAddress: null,
|
||||||
selectedToken: null,
|
selectedToken: null,
|
||||||
viewData: {},
|
viewData: {},
|
||||||
|
viewStack: [],
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// Return the network configuration for the currently selected network.
|
||||||
|
function currentNetwork() {
|
||||||
|
return networkById(state.networkId);
|
||||||
|
}
|
||||||
|
|
||||||
async function saveState() {
|
async function saveState() {
|
||||||
const persisted = {
|
const persisted = {
|
||||||
hasWallet: state.hasWallet,
|
hasWallet: state.hasWallet,
|
||||||
wallets: state.wallets,
|
wallets: state.wallets,
|
||||||
trackedTokens: state.trackedTokens,
|
trackedTokens: state.trackedTokens,
|
||||||
|
networkId: state.networkId,
|
||||||
rpcUrl: state.rpcUrl,
|
rpcUrl: state.rpcUrl,
|
||||||
blockscoutUrl: state.blockscoutUrl,
|
blockscoutUrl: state.blockscoutUrl,
|
||||||
lastBalanceRefresh: state.lastBalanceRefresh,
|
lastBalanceRefresh: state.lastBalanceRefresh,
|
||||||
@@ -49,17 +62,22 @@ async function saveState() {
|
|||||||
deniedSites: state.deniedSites,
|
deniedSites: state.deniedSites,
|
||||||
rememberSiteChoice: state.rememberSiteChoice,
|
rememberSiteChoice: state.rememberSiteChoice,
|
||||||
showZeroBalanceTokens: state.showZeroBalanceTokens,
|
showZeroBalanceTokens: state.showZeroBalanceTokens,
|
||||||
|
hideSpoofedSymbols: state.hideSpoofedSymbols,
|
||||||
hideLowHolderTokens: state.hideLowHolderTokens,
|
hideLowHolderTokens: state.hideLowHolderTokens,
|
||||||
hideFraudContracts: state.hideFraudContracts,
|
hideFraudContracts: state.hideFraudContracts,
|
||||||
hideDustTransactions: state.hideDustTransactions,
|
hideDustTransactions: state.hideDustTransactions,
|
||||||
dustThresholdGwei: state.dustThresholdGwei,
|
dustThresholdGwei: state.dustThresholdGwei,
|
||||||
|
utcTimestamps: state.utcTimestamps,
|
||||||
fraudContracts: state.fraudContracts,
|
fraudContracts: state.fraudContracts,
|
||||||
tokenHolderCache: state.tokenHolderCache,
|
tokenHolderCache: state.tokenHolderCache,
|
||||||
|
theme: state.theme,
|
||||||
|
debugMode: state.debugMode,
|
||||||
currentView: state.currentView,
|
currentView: state.currentView,
|
||||||
selectedWallet: state.selectedWallet,
|
selectedWallet: state.selectedWallet,
|
||||||
selectedAddress: state.selectedAddress,
|
selectedAddress: state.selectedAddress,
|
||||||
selectedToken: state.selectedToken,
|
selectedToken: state.selectedToken,
|
||||||
viewData: state.viewData,
|
viewData: state.viewData,
|
||||||
|
viewStack: state.viewStack,
|
||||||
};
|
};
|
||||||
await storageApi.set({ autistmask: persisted });
|
await storageApi.set({ autistmask: persisted });
|
||||||
}
|
}
|
||||||
@@ -68,9 +86,13 @@ async function loadState() {
|
|||||||
const result = await storageApi.get("autistmask");
|
const result = await storageApi.get("autistmask");
|
||||||
if (result.autistmask) {
|
if (result.autistmask) {
|
||||||
const saved = result.autistmask;
|
const saved = result.autistmask;
|
||||||
state.hasWallet = saved.hasWallet;
|
|
||||||
state.wallets = saved.wallets || [];
|
state.wallets = saved.wallets || [];
|
||||||
|
// Derived, never read from storage: a profile persisted with the flag
|
||||||
|
// out of step with the wallet list would otherwise stay broken on
|
||||||
|
// every load. Nothing depends on the two disagreeing.
|
||||||
|
state.hasWallet = state.wallets.length > 0;
|
||||||
state.trackedTokens = saved.trackedTokens || [];
|
state.trackedTokens = saved.trackedTokens || [];
|
||||||
|
state.networkId = saved.networkId || DEFAULT_STATE.networkId;
|
||||||
state.rpcUrl = saved.rpcUrl || DEFAULT_STATE.rpcUrl;
|
state.rpcUrl = saved.rpcUrl || DEFAULT_STATE.rpcUrl;
|
||||||
state.blockscoutUrl =
|
state.blockscoutUrl =
|
||||||
saved.blockscoutUrl || DEFAULT_STATE.blockscoutUrl;
|
saved.blockscoutUrl || DEFAULT_STATE.blockscoutUrl;
|
||||||
@@ -92,6 +114,12 @@ async function loadState() {
|
|||||||
saved.showZeroBalanceTokens !== undefined
|
saved.showZeroBalanceTokens !== undefined
|
||||||
? saved.showZeroBalanceTokens
|
? saved.showZeroBalanceTokens
|
||||||
: true;
|
: true;
|
||||||
|
// A profile written before this setting existed has no key for it.
|
||||||
|
// It is a safety filter, so absent must load as on, not as undefined.
|
||||||
|
state.hideSpoofedSymbols =
|
||||||
|
saved.hideSpoofedSymbols !== undefined
|
||||||
|
? saved.hideSpoofedSymbols
|
||||||
|
: true;
|
||||||
state.hideLowHolderTokens =
|
state.hideLowHolderTokens =
|
||||||
saved.hideLowHolderTokens !== undefined
|
saved.hideLowHolderTokens !== undefined
|
||||||
? saved.hideLowHolderTokens
|
? saved.hideLowHolderTokens
|
||||||
@@ -108,8 +136,13 @@ async function loadState() {
|
|||||||
saved.dustThresholdGwei !== undefined
|
saved.dustThresholdGwei !== undefined
|
||||||
? saved.dustThresholdGwei
|
? saved.dustThresholdGwei
|
||||||
: 100000;
|
: 100000;
|
||||||
|
state.utcTimestamps =
|
||||||
|
saved.utcTimestamps !== undefined ? saved.utcTimestamps : false;
|
||||||
state.fraudContracts = saved.fraudContracts || [];
|
state.fraudContracts = saved.fraudContracts || [];
|
||||||
state.tokenHolderCache = saved.tokenHolderCache || {};
|
state.tokenHolderCache = saved.tokenHolderCache || {};
|
||||||
|
state.theme = saved.theme || "system";
|
||||||
|
state.debugMode =
|
||||||
|
saved.debugMode !== undefined ? saved.debugMode : false;
|
||||||
state.currentView = saved.currentView || null;
|
state.currentView = saved.currentView || null;
|
||||||
state.selectedWallet =
|
state.selectedWallet =
|
||||||
saved.selectedWallet !== undefined ? saved.selectedWallet : null;
|
saved.selectedWallet !== undefined ? saved.selectedWallet : null;
|
||||||
@@ -117,6 +150,7 @@ async function loadState() {
|
|||||||
saved.selectedAddress !== undefined ? saved.selectedAddress : null;
|
saved.selectedAddress !== undefined ? saved.selectedAddress : null;
|
||||||
state.selectedToken = saved.selectedToken || null;
|
state.selectedToken = saved.selectedToken || null;
|
||||||
state.viewData = saved.viewData || {};
|
state.viewData = saved.viewData || {};
|
||||||
|
state.viewStack = Array.isArray(saved.viewStack) ? saved.viewStack : [];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -127,4 +161,10 @@ function currentAddress() {
|
|||||||
return state.wallets[state.selectedWallet].addresses[state.selectedAddress];
|
return state.wallets[state.selectedWallet].addresses[state.selectedAddress];
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { state, saveState, loadState, currentAddress };
|
module.exports = {
|
||||||
|
state,
|
||||||
|
saveState,
|
||||||
|
loadState,
|
||||||
|
currentAddress,
|
||||||
|
currentNetwork,
|
||||||
|
};
|
||||||
|
|||||||
43
src/shared/symbolSpoof.js
Normal file
43
src/shared/symbolSpoof.js
Normal file
@@ -0,0 +1,43 @@
|
|||||||
|
// The known-symbol spoof rule, in one place.
|
||||||
|
//
|
||||||
|
// A token that borrows a known symbol from a contract that is not the one
|
||||||
|
// that symbol belongs to is a spoof, and the wallet hides it. Three surfaces
|
||||||
|
// ask that question — the transaction history, the Send token selector and
|
||||||
|
// the balance list — and they must answer it identically: a token the history
|
||||||
|
// calls fake while the balance list lists it as a holding is worse than
|
||||||
|
// either verdict alone, because the balance list is where the user forms
|
||||||
|
// their belief about what they own (issue #235).
|
||||||
|
//
|
||||||
|
// KNOWN_SYMBOLS maps a symbol to the lowercased contract address that may
|
||||||
|
// bear it, or to null. Null means the symbol belongs to the native asset,
|
||||||
|
// which has no contract at all, so no contract may bear it and every one
|
||||||
|
// that does is a spoof. "ETH" is the only such entry today; the rule is
|
||||||
|
// written so that a second one needs no change here or at any call site.
|
||||||
|
|
||||||
|
const { KNOWN_SYMBOLS } = require("./tokenList");
|
||||||
|
|
||||||
|
// Ethereum addresses are case-insensitive: EIP-55 mixed case is a checksum
|
||||||
|
// over the address, not part of its identity.
|
||||||
|
function normalizeAddress(addr) {
|
||||||
|
return (addr || "").toLowerCase();
|
||||||
|
}
|
||||||
|
|
||||||
|
// True when a token bearing `symbol` from contract `contractAddress` is
|
||||||
|
// impersonating a known symbol.
|
||||||
|
//
|
||||||
|
// An empty contract address is the native asset, which is never a spoof:
|
||||||
|
// this is what keeps the user's real ETH out of the rule, and it holds for
|
||||||
|
// any symbol that becomes null-mapped later, not just for ETH.
|
||||||
|
function isSpoofedSymbol(symbol, contractAddress) {
|
||||||
|
const contract = normalizeAddress(contractAddress);
|
||||||
|
if (!contract) return false;
|
||||||
|
const sym = (symbol || "").toUpperCase();
|
||||||
|
if (!KNOWN_SYMBOLS.has(sym)) return false;
|
||||||
|
const legit = KNOWN_SYMBOLS.get(sym);
|
||||||
|
if (legit === null) return true;
|
||||||
|
return contract !== normalizeAddress(legit);
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
isSpoofedSymbol,
|
||||||
|
};
|
||||||
@@ -8,7 +8,17 @@
|
|||||||
|
|
||||||
const { formatEther, formatUnits } = require("ethers");
|
const { formatEther, formatUnits } = require("ethers");
|
||||||
const { log, debugFetch } = require("./log");
|
const { log, debugFetch } = require("./log");
|
||||||
const { KNOWN_SYMBOLS, TOKEN_BY_ADDRESS } = require("./tokenList");
|
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
||||||
|
const { parseHoldersCount, isLowHolderCount } = require("./holders");
|
||||||
|
const { isSpoofedSymbol } = require("./symbolSpoof");
|
||||||
|
|
||||||
|
// Ethereum addresses are case-insensitive: EIP-55 mixed case is a checksum
|
||||||
|
// over the address, not part of its identity. Every address comparison in
|
||||||
|
// this file goes through this helper, so an address arriving in checksummed
|
||||||
|
// or upper-case form can never be read as a different address.
|
||||||
|
function normalizeAddress(addr) {
|
||||||
|
return (addr || "").toLowerCase();
|
||||||
|
}
|
||||||
|
|
||||||
function formatTxValue(val) {
|
function formatTxValue(val) {
|
||||||
const parts = val.split(".");
|
const parts = val.split(".");
|
||||||
@@ -30,10 +40,10 @@ function parseTx(tx, addrLower) {
|
|||||||
let exactValue = formatEther(rawWei);
|
let exactValue = formatEther(rawWei);
|
||||||
let rawAmount = rawWei;
|
let rawAmount = rawWei;
|
||||||
let rawUnit = "wei";
|
let rawUnit = "wei";
|
||||||
let direction = from.toLowerCase() === addrLower ? "sent" : "received";
|
let direction = normalizeAddress(from) === addrLower ? "sent" : "received";
|
||||||
let directionLabel = direction === "sent" ? "Sent" : "Received";
|
let directionLabel = direction === "sent" ? "Sent" : "Received";
|
||||||
if (toIsContract && method && method !== "transfer") {
|
if (toIsContract && method && method !== "transfer") {
|
||||||
const token = TOKEN_BY_ADDRESS.get(to.toLowerCase());
|
const token = TOKEN_BY_ADDRESS.get(normalizeAddress(to));
|
||||||
if (token) {
|
if (token) {
|
||||||
symbol = token.symbol;
|
symbol = token.symbol;
|
||||||
}
|
}
|
||||||
@@ -87,7 +97,8 @@ function parseTokenTransfer(tt, addrLower) {
|
|||||||
const to = tt.to?.hash || "";
|
const to = tt.to?.hash || "";
|
||||||
const decimals = parseInt(tt.total?.decimals || "18", 10);
|
const decimals = parseInt(tt.total?.decimals || "18", 10);
|
||||||
const rawVal = tt.total?.value || "0";
|
const rawVal = tt.total?.value || "0";
|
||||||
const direction = from.toLowerCase() === addrLower ? "sent" : "received";
|
const direction =
|
||||||
|
normalizeAddress(from) === addrLower ? "sent" : "received";
|
||||||
const sym = tt.token?.symbol || "?";
|
const sym = tt.token?.symbol || "?";
|
||||||
return {
|
return {
|
||||||
hash: tt.transaction_hash,
|
hash: tt.transaction_hash,
|
||||||
@@ -104,18 +115,98 @@ function parseTokenTransfer(tt, addrLower) {
|
|||||||
direction: direction,
|
direction: direction,
|
||||||
directionLabel: direction === "sent" ? "Sent" : "Received",
|
directionLabel: direction === "sent" ? "Sent" : "Received",
|
||||||
isError: false,
|
isError: false,
|
||||||
contractAddress: (
|
contractAddress: normalizeAddress(
|
||||||
tt.token?.address_hash ||
|
tt.token?.address_hash || tt.token?.address || "",
|
||||||
tt.token?.address ||
|
),
|
||||||
""
|
// null when the explorer reported no count: unknown, not zero. The
|
||||||
).toLowerCase(),
|
// low-holder filter declines to judge a null, so a legitimate token
|
||||||
holders: parseInt(tt.token?.holders_count || "0", 10),
|
// is not hidden because a field went missing upstream.
|
||||||
|
holders: parseHoldersCount(tt.token?.holders_count),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// True when a parsed native entry moved no ETH. Contract-call entries have
|
||||||
|
// their amount fields blanked by parseTx, so they are never judged here.
|
||||||
|
function movedNoEther(tx) {
|
||||||
|
if (tx.direction === "contract") return false;
|
||||||
|
return BigInt(tx.rawAmount || "0") === BigInt(0);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Merge parsed normal transactions with parsed ERC-20 token transfers into
|
||||||
|
// one row per distinct value movement. Pure: it reads only its arguments
|
||||||
|
// and returns a new list sorted newest block first.
|
||||||
|
//
|
||||||
|
// The merge key is the transaction hash for the native entry and
|
||||||
|
// hash + token contract for each token transfer, so:
|
||||||
|
//
|
||||||
|
// - A display-level contract call (a swap and friends, direction
|
||||||
|
// "contract") absorbs every token leg of its hash into the single
|
||||||
|
// native entry, because the legs are hops of one operation rather
|
||||||
|
// than separate movements the user made.
|
||||||
|
// - Otherwise each distinct token contract in the transaction keeps its
|
||||||
|
// own row, so a hash carrying several genuine transfers stays several
|
||||||
|
// rows.
|
||||||
|
// - The native entry of such a transaction is dropped when it moved no
|
||||||
|
// ETH and at least one token transfer shares its hash: that entry is
|
||||||
|
// the ERC-20 call itself, already represented by the token row. A
|
||||||
|
// native entry that moved ETH survives alongside the token rows, since
|
||||||
|
// the ETH and the tokens are two real movements, and a zero-value
|
||||||
|
// native transaction with no token transfer on its hash survives too.
|
||||||
|
function mergeTransactions(txs, tokenTransfers) {
|
||||||
|
const byKey = new Map();
|
||||||
|
|
||||||
|
// Entries are copied so consolidation never writes through to the
|
||||||
|
// caller's objects.
|
||||||
|
for (const tx of txs) {
|
||||||
|
byKey.set(tx.hash, { ...tx });
|
||||||
|
}
|
||||||
|
|
||||||
|
const absorbedHashes = new Set();
|
||||||
|
|
||||||
|
for (const parsed of tokenTransfers) {
|
||||||
|
const existing = byKey.get(parsed.hash);
|
||||||
|
if (existing && existing.direction === "contract") {
|
||||||
|
// For contract calls (swaps), consolidate into the original
|
||||||
|
// tx entry. Prefer the "received" transfer (swap output)
|
||||||
|
// for the display amount. If no received transfer exists,
|
||||||
|
// fall back to the first "sent" transfer (swap input).
|
||||||
|
const isReceived = parsed.direction === "received";
|
||||||
|
const needsAmount = !existing.exactValue;
|
||||||
|
if (isReceived || needsAmount) {
|
||||||
|
existing.value = parsed.value;
|
||||||
|
existing.exactValue = parsed.exactValue;
|
||||||
|
existing.rawAmount = parsed.rawAmount;
|
||||||
|
existing.rawUnit = parsed.rawUnit;
|
||||||
|
existing.symbol = parsed.symbol;
|
||||||
|
existing.contractAddress = parsed.contractAddress;
|
||||||
|
existing.holders = parsed.holders;
|
||||||
|
}
|
||||||
|
// Keep the original tx's from/to (the user's address and the
|
||||||
|
// contract they called), not the token transfer's from/to
|
||||||
|
// which may be a router or Permit2 contract.
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (existing && movedNoEther(existing)) {
|
||||||
|
absorbedHashes.add(parsed.hash);
|
||||||
|
}
|
||||||
|
// Every other token transfer gets its own entry.
|
||||||
|
byKey.set(parsed.hash + ":" + (parsed.contractAddress || ""), {
|
||||||
|
...parsed,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const hash of absorbedHashes) {
|
||||||
|
byKey.delete(hash);
|
||||||
|
}
|
||||||
|
|
||||||
|
const merged = [...byKey.values()];
|
||||||
|
merged.sort((a, b) => b.blockNumber - a.blockNumber);
|
||||||
|
return merged;
|
||||||
|
}
|
||||||
|
|
||||||
async function fetchRecentTransactions(address, blockscoutUrl, count = 25) {
|
async function fetchRecentTransactions(address, blockscoutUrl, count = 25) {
|
||||||
log.debugf("fetchRecentTransactions", address);
|
log.debugf("fetchRecentTransactions", address);
|
||||||
const addrLower = address.toLowerCase();
|
const addrLower = normalizeAddress(address);
|
||||||
|
|
||||||
const [txResp, ttResp] = await Promise.all([
|
const [txResp, ttResp] = await Promise.all([
|
||||||
debugFetch(blockscoutUrl + "/addresses/" + address + "/transactions"),
|
debugFetch(blockscoutUrl + "/addresses/" + address + "/transactions"),
|
||||||
@@ -145,90 +236,62 @@ async function fetchRecentTransactions(address, blockscoutUrl, count = 25) {
|
|||||||
const txJson = txResp.ok ? await txResp.json() : {};
|
const txJson = txResp.ok ? await txResp.json() : {};
|
||||||
const ttJson = ttResp.ok ? await ttResp.json() : {};
|
const ttJson = ttResp.ok ? await ttResp.json() : {};
|
||||||
|
|
||||||
const txsByHash = new Map();
|
const txs = mergeTransactions(
|
||||||
|
(txJson.items || []).map((tx) => parseTx(tx, addrLower)),
|
||||||
|
(ttJson.items || []).map((tt) => parseTokenTransfer(tt, addrLower)),
|
||||||
|
);
|
||||||
|
|
||||||
for (const tx of txJson.items || []) {
|
|
||||||
txsByHash.set(tx.hash, parseTx(tx, addrLower));
|
|
||||||
}
|
|
||||||
|
|
||||||
// When a token transfer shares a hash with a normal tx, the normal tx
|
|
||||||
// is the contract call (0 ETH) and the token transfer has the real
|
|
||||||
// amount and symbol. A single transaction (e.g. a swap) can produce
|
|
||||||
// multiple token transfers (one per token involved), so we key token
|
|
||||||
// transfers by hash + contract address to keep all of them. We also
|
|
||||||
// preserve contract-call metadata (direction, label, method) from the
|
|
||||||
// matching normal tx so swaps display correctly.
|
|
||||||
for (const tt of ttJson.items || []) {
|
|
||||||
const parsed = parseTokenTransfer(tt, addrLower);
|
|
||||||
const existing = txsByHash.get(parsed.hash);
|
|
||||||
if (existing && existing.direction === "contract") {
|
|
||||||
parsed.direction = "contract";
|
|
||||||
parsed.directionLabel = existing.directionLabel;
|
|
||||||
parsed.isContractCall = true;
|
|
||||||
parsed.method = existing.method;
|
|
||||||
// Remove the bare-hash normal tx so it doesn't appear as a
|
|
||||||
// duplicate with empty value; token transfers replace it.
|
|
||||||
txsByHash.delete(parsed.hash);
|
|
||||||
}
|
|
||||||
// Use composite key so multiple token transfers per tx are kept.
|
|
||||||
const ttKey = parsed.hash + ":" + (parsed.contractAddress || "");
|
|
||||||
txsByHash.set(ttKey, parsed);
|
|
||||||
}
|
|
||||||
|
|
||||||
const txs = [...txsByHash.values()];
|
|
||||||
|
|
||||||
txs.sort((a, b) => b.blockNumber - a.blockNumber);
|
|
||||||
const result = txs.slice(0, count);
|
const result = txs.slice(0, count);
|
||||||
log.debugf("fetchRecentTransactions done, count:", result.length);
|
log.debugf("fetchRecentTransactions done, count:", result.length);
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check if a token transfer is spoofing a known symbol.
|
|
||||||
// Returns true if the symbol matches a known token but the contract
|
|
||||||
// address doesn't match the legitimate one.
|
|
||||||
function isSpoofedSymbol(tx) {
|
|
||||||
if (!tx.contractAddress) return false;
|
|
||||||
const symbol = (tx.symbol || "").toUpperCase();
|
|
||||||
if (!KNOWN_SYMBOLS.has(symbol)) return false;
|
|
||||||
const legit = KNOWN_SYMBOLS.get(symbol);
|
|
||||||
if (legit === null) return true; // "ETH" as ERC-20 is always fake
|
|
||||||
return tx.contractAddress !== legit;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Pure filter function. Takes raw transactions and filter settings,
|
// Pure filter function. Takes raw transactions and filter settings,
|
||||||
// returns { transactions, newFraudContracts }.
|
// returns { transactions, newFraudContracts }.
|
||||||
function filterTransactions(txs, filters = {}) {
|
function filterTransactions(txs, filters = {}) {
|
||||||
const fraudSet = new Set(
|
const fraudSet = new Set(
|
||||||
(filters.fraudContracts || []).map((a) => a.toLowerCase()),
|
(filters.fraudContracts || []).map(normalizeAddress),
|
||||||
);
|
);
|
||||||
|
// The dust threshold defaults only when it is unset (nullish): a
|
||||||
|
// threshold of 0 is a real value meaning "hide nothing", since no
|
||||||
|
// transaction has a value below 0 gwei. It is therefore equivalent to
|
||||||
|
// clearing the hide-dust checkbox, and the two controls cannot override
|
||||||
|
// each other in either direction.
|
||||||
|
const dustThresholdGwei = filters.dustThresholdGwei ?? 100000;
|
||||||
const newFraud = [];
|
const newFraud = [];
|
||||||
const filtered = [];
|
const filtered = [];
|
||||||
|
// Fail-safe, unlike the three flags below: this one is off only when the
|
||||||
|
// caller says so explicitly, so a caller that omits the key keeps the
|
||||||
|
// check rather than silently losing it. The setting also governs the
|
||||||
|
// blocklist learning below, which exists only to serve this check —
|
||||||
|
// leaving learning on while the check is off would re-hide the very rows
|
||||||
|
// the user asked to see, through the fraud-contract rule.
|
||||||
|
const hideSpoofed = filters.hideSpoofedSymbols !== false;
|
||||||
|
|
||||||
for (const tx of txs) {
|
for (const tx of txs) {
|
||||||
// Always filter spoofed known symbols and record the fraud contract
|
const contract = normalizeAddress(tx.contractAddress);
|
||||||
if (isSpoofedSymbol(tx)) {
|
|
||||||
if (tx.contractAddress && !fraudSet.has(tx.contractAddress)) {
|
// Filter spoofed known symbols and record the fraud contract
|
||||||
fraudSet.add(tx.contractAddress);
|
if (hideSpoofed && isSpoofedSymbol(tx.symbol, tx.contractAddress)) {
|
||||||
newFraud.push(tx.contractAddress);
|
if (contract && !fraudSet.has(contract)) {
|
||||||
|
fraudSet.add(contract);
|
||||||
|
newFraud.push(contract);
|
||||||
}
|
}
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Filter fraud contracts if setting is on
|
// Filter fraud contracts if setting is on
|
||||||
if (
|
if (filters.hideFraudContracts && contract && fraudSet.has(contract)) {
|
||||||
filters.hideFraudContracts &&
|
|
||||||
tx.contractAddress &&
|
|
||||||
fraudSet.has(tx.contractAddress)
|
|
||||||
) {
|
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Filter low-holder tokens (<1000) if setting is on
|
// Filter low-holder tokens (<1000) if setting is on. A token whose
|
||||||
|
// holder count the explorer did not report is kept: only a reported
|
||||||
|
// count below the threshold is "low".
|
||||||
if (
|
if (
|
||||||
filters.hideLowHolderTokens &&
|
filters.hideLowHolderTokens &&
|
||||||
tx.contractAddress &&
|
tx.contractAddress &&
|
||||||
tx.holders !== null &&
|
isLowHolderCount(tx.holders)
|
||||||
tx.holders < 1000
|
|
||||||
) {
|
) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
@@ -240,7 +303,7 @@ function filterTransactions(txs, filters = {}) {
|
|||||||
filters.hideDustTransactions &&
|
filters.hideDustTransactions &&
|
||||||
!tx.isContractCall &&
|
!tx.isContractCall &&
|
||||||
tx.valueGwei !== null &&
|
tx.valueGwei !== null &&
|
||||||
tx.valueGwei < (filters.dustThresholdGwei || 100000)
|
tx.valueGwei < dustThresholdGwei
|
||||||
) {
|
) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
@@ -251,4 +314,8 @@ function filterTransactions(txs, filters = {}) {
|
|||||||
return { transactions: filtered, newFraudContracts: newFraud };
|
return { transactions: filtered, newFraudContracts: newFraud };
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { fetchRecentTransactions, filterTransactions };
|
module.exports = {
|
||||||
|
fetchRecentTransactions,
|
||||||
|
filterTransactions,
|
||||||
|
mergeTransactions,
|
||||||
|
};
|
||||||
|
|||||||
171
src/shared/txValidation.js
Normal file
171
src/shared/txValidation.js
Normal file
@@ -0,0 +1,171 @@
|
|||||||
|
// Balance arithmetic for the transaction confirmation screen.
|
||||||
|
//
|
||||||
|
// Pure: no DOM, no network, no state. Everything is exact integer math on
|
||||||
|
// 18-decimal fixed point (wei for ETH), so it can be unit tested directly
|
||||||
|
// instead of through the confirmation view. The caller maps the returned
|
||||||
|
// codes to the reserved message elements on the screen.
|
||||||
|
//
|
||||||
|
// Human decimal strings ("1.25") are scaled to 18 decimals for comparison.
|
||||||
|
// That scale is independent of a token's own decimals: both the amount and
|
||||||
|
// the token balance arrive as human decimal strings, so comparing them at a
|
||||||
|
// common scale is exact.
|
||||||
|
|
||||||
|
const { parseUnits } = require("ethers");
|
||||||
|
|
||||||
|
const SCALE_DECIMALS = 18;
|
||||||
|
|
||||||
|
// Whether the asynchronous fee estimate has arrived yet.
|
||||||
|
const FEE_PENDING = "pending";
|
||||||
|
const FEE_KNOWN = "known";
|
||||||
|
const FEE_UNAVAILABLE = "unavailable";
|
||||||
|
|
||||||
|
const CODES = {
|
||||||
|
// The amount is not a non-negative number we can do exact arithmetic on.
|
||||||
|
AMOUNT_INVALID: "amount-invalid",
|
||||||
|
// ERC-20: the token amount exceeds the token balance.
|
||||||
|
INSUFFICIENT_TOKEN: "insufficient-token",
|
||||||
|
// ETH: the amount alone already exceeds the ETH balance.
|
||||||
|
INSUFFICIENT_ETH: "insufficient-eth",
|
||||||
|
// ETH: the amount fits, the amount plus the network fee does not.
|
||||||
|
INSUFFICIENT_ETH_WITH_FEE: "insufficient-eth-with-fee",
|
||||||
|
// ERC-20: the token balance covers the transfer, the ETH balance does
|
||||||
|
// not cover the network fee it costs.
|
||||||
|
INSUFFICIENT_ETH_FOR_FEE: "insufficient-eth-for-fee",
|
||||||
|
// The fee estimate has not arrived yet.
|
||||||
|
FEE_PENDING: "fee-pending",
|
||||||
|
// The fee estimate failed. Unknown is never treated as zero.
|
||||||
|
FEE_UNAVAILABLE: "fee-unavailable",
|
||||||
|
};
|
||||||
|
|
||||||
|
// The fee that must be reserved for a transaction, in wei: the amount the
|
||||||
|
// node will require, not the amount the transaction is expected to cost.
|
||||||
|
//
|
||||||
|
// A send that pins no fee fields is populated by ethers as a type-2
|
||||||
|
// (EIP-1559) transaction, and a node validates that against
|
||||||
|
// `value + gasLimit * maxFeePerGas`. ethers derives maxFeePerGas as
|
||||||
|
// `baseFeePerGas * 2 + maxPriorityFeePerGas`, so reserving `gasPrice`
|
||||||
|
// (roughly `baseFee + tip`) under-reserves by about `gasLimit * baseFee` and
|
||||||
|
// lets through a transaction the node then rejects with "insufficient funds
|
||||||
|
// for gas * price + value". gasPrice is the fallback only for a network that
|
||||||
|
// offers no type-2 pricing at all.
|
||||||
|
//
|
||||||
|
// Returns null when no usable price is available, which the caller must treat
|
||||||
|
// as a failed estimate rather than as a free transaction.
|
||||||
|
function feeReserveWei(gasLimit, feeData) {
|
||||||
|
if (typeof gasLimit !== "bigint" || gasLimit < 0n) return null;
|
||||||
|
const price = feeData?.maxFeePerGas ?? feeData?.gasPrice;
|
||||||
|
if (typeof price !== "bigint" || price < 0n) return null;
|
||||||
|
return gasLimit * price;
|
||||||
|
}
|
||||||
|
|
||||||
|
// What the transaction is expected to actually cost, in wei — not what must
|
||||||
|
// be reserved for it. A type-2 transaction is charged `baseFee + tip` per gas
|
||||||
|
// and refunded the rest of the cap, and `eth_gasPrice` reports roughly that,
|
||||||
|
// so gasPrice is the estimate and maxFeePerGas is the reserve. On a network
|
||||||
|
// with no type-2 pricing the two are the same number.
|
||||||
|
//
|
||||||
|
// Display only: nothing gates on this. Returns null on the same unusable
|
||||||
|
// inputs as feeReserveWei().
|
||||||
|
function feeEstimateWei(gasLimit, feeData) {
|
||||||
|
if (typeof gasLimit !== "bigint" || gasLimit < 0n) return null;
|
||||||
|
const price = feeData?.gasPrice ?? feeData?.maxFeePerGas;
|
||||||
|
if (typeof price !== "bigint" || price < 0n) return null;
|
||||||
|
return gasLimit * price;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Scale a human decimal string to 18-decimal fixed point. Returns null when
|
||||||
|
// the value is not a decimal number or carries more precision than the scale
|
||||||
|
// can hold, which the caller must treat as unusable rather than as zero.
|
||||||
|
function toFixedPoint(value) {
|
||||||
|
if (typeof value !== "string" && typeof value !== "number") return null;
|
||||||
|
const text = String(value).trim();
|
||||||
|
if (text === "") return null;
|
||||||
|
try {
|
||||||
|
return parseUnits(text, SCALE_DECIMALS);
|
||||||
|
} catch (e) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Validate a pending transfer against the balances that must cover it.
|
||||||
|
//
|
||||||
|
// isErc20 — token transfer rather than a native ETH transfer
|
||||||
|
// amount — human decimal string being sent, non-negative. Anything
|
||||||
|
// else, a negative value included, is an unusable amount
|
||||||
|
// rather than an amount that passes every comparison.
|
||||||
|
// ethBalance — human decimal string, the sender's ETH balance
|
||||||
|
// tokenBalance — human decimal string, the sender's token balance
|
||||||
|
// feeStatus — FEE_PENDING, FEE_KNOWN or FEE_UNAVAILABLE. Anything else
|
||||||
|
// is treated as FEE_UNAVAILABLE.
|
||||||
|
// feeWei — the fee reserve in wei from feeReserveWei(), as a
|
||||||
|
// non-negative bigint, when FEE_KNOWN. Any other value makes
|
||||||
|
// the fee unavailable rather than zero.
|
||||||
|
//
|
||||||
|
// Returns { canSend, codes }. Every code blocks sending: canSend is true
|
||||||
|
// only when nothing was found.
|
||||||
|
function validateTransfer({
|
||||||
|
isErc20 = false,
|
||||||
|
amount,
|
||||||
|
ethBalance,
|
||||||
|
tokenBalance,
|
||||||
|
feeStatus = FEE_PENDING,
|
||||||
|
feeWei = null,
|
||||||
|
} = {}) {
|
||||||
|
const codes = [];
|
||||||
|
|
||||||
|
const amountFp = toFixedPoint(amount);
|
||||||
|
const ethFp = toFixedPoint(ethBalance) ?? 0n;
|
||||||
|
|
||||||
|
// A negative amount parses to a valid bigint, so every comparison below
|
||||||
|
// is trivially false and the send clears the screen — then dies at encode
|
||||||
|
// time in parseEther(). Unusable, on the same footing as a malformed fee.
|
||||||
|
if (amountFp === null || amountFp < 0n) {
|
||||||
|
codes.push(CODES.AMOUNT_INVALID);
|
||||||
|
return { canSend: false, codes };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Fail closed. Anything that is not a usable fee under a recognised
|
||||||
|
// status — a malformed feeWei, or a status this module does not know —
|
||||||
|
// is an unavailable estimate, never a fee of zero. Every such input errs
|
||||||
|
// in the direction that lets money out, so none of them is trusted.
|
||||||
|
const known =
|
||||||
|
feeStatus === FEE_KNOWN && typeof feeWei === "bigint" && feeWei >= 0n;
|
||||||
|
let status = feeStatus;
|
||||||
|
if (feeStatus === FEE_KNOWN && !known) status = FEE_UNAVAILABLE;
|
||||||
|
if (status !== FEE_KNOWN && status !== FEE_PENDING) {
|
||||||
|
status = FEE_UNAVAILABLE;
|
||||||
|
}
|
||||||
|
|
||||||
|
const feeFp = known ? feeWei : null;
|
||||||
|
|
||||||
|
if (isErc20) {
|
||||||
|
const tokenFp = toFixedPoint(tokenBalance) ?? 0n;
|
||||||
|
if (amountFp > tokenFp) codes.push(CODES.INSUFFICIENT_TOKEN);
|
||||||
|
if (feeFp !== null && feeFp > ethFp) {
|
||||||
|
codes.push(CODES.INSUFFICIENT_ETH_FOR_FEE);
|
||||||
|
}
|
||||||
|
} else if (amountFp > ethFp) {
|
||||||
|
codes.push(CODES.INSUFFICIENT_ETH);
|
||||||
|
} else if (feeFp !== null && amountFp + feeFp > ethFp) {
|
||||||
|
codes.push(CODES.INSUFFICIENT_ETH_WITH_FEE);
|
||||||
|
}
|
||||||
|
|
||||||
|
// An unknown fee is never assumed to be zero: sending stays blocked
|
||||||
|
// until the estimate arrives, and stays blocked if it never does.
|
||||||
|
if (status === FEE_PENDING) codes.push(CODES.FEE_PENDING);
|
||||||
|
if (status === FEE_UNAVAILABLE) codes.push(CODES.FEE_UNAVAILABLE);
|
||||||
|
|
||||||
|
return { canSend: codes.length === 0, codes };
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
CODES,
|
||||||
|
FEE_PENDING,
|
||||||
|
FEE_KNOWN,
|
||||||
|
FEE_UNAVAILABLE,
|
||||||
|
SCALE_DECIMALS,
|
||||||
|
feeReserveWei,
|
||||||
|
feeEstimateWei,
|
||||||
|
toFixedPoint,
|
||||||
|
validateTransfer,
|
||||||
|
};
|
||||||
@@ -359,9 +359,12 @@ function decode(data, toAddress) {
|
|||||||
const s = decodeV3SwapExactIn(inputs[i]);
|
const s = decodeV3SwapExactIn(inputs[i]);
|
||||||
if (s) {
|
if (s) {
|
||||||
if (!inputToken) inputToken = s.tokenIn;
|
if (!inputToken) inputToken = s.tokenIn;
|
||||||
if (!outputToken) outputToken = s.tokenOut;
|
|
||||||
if (!inputAmount) inputAmount = s.amountIn;
|
if (!inputAmount) inputAmount = s.amountIn;
|
||||||
if (!minOutput) minOutput = s.amountOutMin;
|
// Always update output: in multi-step swaps (V3 → V4),
|
||||||
|
// the last swap step determines the final output token
|
||||||
|
// and minimum received amount.
|
||||||
|
outputToken = s.tokenOut;
|
||||||
|
minOutput = s.amountOutMin;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -369,9 +372,9 @@ function decode(data, toAddress) {
|
|||||||
const s = decodeV2SwapExactIn(inputs[i]);
|
const s = decodeV2SwapExactIn(inputs[i]);
|
||||||
if (s) {
|
if (s) {
|
||||||
if (!inputToken) inputToken = s.tokenIn;
|
if (!inputToken) inputToken = s.tokenIn;
|
||||||
if (!outputToken) outputToken = s.tokenOut;
|
|
||||||
if (!inputAmount) inputAmount = s.amountIn;
|
if (!inputAmount) inputAmount = s.amountIn;
|
||||||
if (!minOutput) minOutput = s.amountOutMin;
|
outputToken = s.tokenOut;
|
||||||
|
minOutput = s.amountOutMin;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -388,12 +391,11 @@ function decode(data, toAddress) {
|
|||||||
const v4 = decodeV4Swap(inputs[i]);
|
const v4 = decodeV4Swap(inputs[i]);
|
||||||
if (v4) {
|
if (v4) {
|
||||||
if (!inputToken && v4.tokenIn) inputToken = v4.tokenIn;
|
if (!inputToken && v4.tokenIn) inputToken = v4.tokenIn;
|
||||||
if (!outputToken && v4.tokenOut)
|
|
||||||
outputToken = v4.tokenOut;
|
|
||||||
if (!inputAmount && v4.amountIn)
|
if (!inputAmount && v4.amountIn)
|
||||||
inputAmount = v4.amountIn;
|
inputAmount = v4.amountIn;
|
||||||
if (!minOutput && v4.amountOutMin)
|
// Always update output: last swap step wins
|
||||||
minOutput = v4.amountOutMin;
|
if (v4.tokenOut) outputToken = v4.tokenOut;
|
||||||
|
if (v4.amountOutMin) minOutput = v4.amountOutMin;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +1,80 @@
|
|||||||
// Vault: password-based encryption of secrets using libsodium.
|
// Vault: password-based encryption of secrets using libsodium.
|
||||||
// Uses Argon2id for key derivation and XSalsa20-Poly1305 for encryption.
|
// Uses Argon2id for key derivation and XSalsa20-Poly1305 for encryption.
|
||||||
// All crypto operations are delegated to libsodium — no raw primitives.
|
// All crypto operations are delegated to libsodium — no raw primitives.
|
||||||
|
//
|
||||||
|
// Backend: WebAssembly, deliberately (#182).
|
||||||
|
//
|
||||||
|
// libsodium ships one file containing both a WebAssembly build and a
|
||||||
|
// wasm2js ("asm.js") translation of it. It tries WASM first and, if
|
||||||
|
// instantiation throws, silently swaps in the translation. An extension
|
||||||
|
// CSP of plain script-src 'self' refuses WASM, so every popup load used
|
||||||
|
// to take that fallback — announced by nothing but an uncaught
|
||||||
|
// CompileError in the console.
|
||||||
|
//
|
||||||
|
// Measured here, same Argon2id parameters (OPSLIMIT_INTERACTIVE,
|
||||||
|
// MEMLIMIT_INTERACTIVE = 2 passes over 64MiB), node 22 on this machine:
|
||||||
|
// WASM 141-198ms per derivation, wasm2js 3204-3660ms. The work factor is
|
||||||
|
// identical either way — it is set by the ops/mem parameters, not by wall
|
||||||
|
// time — so the fallback bought no security, it only made every password
|
||||||
|
// operation take three and a half seconds, and the wallet asks for the
|
||||||
|
// password on every signature.
|
||||||
|
//
|
||||||
|
// So both manifests declare 'wasm-unsafe-eval' for extension pages. That
|
||||||
|
// keyword permits compiling WebAssembly and nothing else: not eval() of
|
||||||
|
// strings, not inline script, not remote script. Reaching it requires
|
||||||
|
// already executing script in the extension page, which is total
|
||||||
|
// compromise on its own. 'unsafe-eval' would be a different matter and is
|
||||||
|
// not granted. tests/manifest.test.js pins both policies to exactly
|
||||||
|
// "'self' 'wasm-unsafe-eval'" so neither the grant nor the surrounding
|
||||||
|
// strictness can drift unnoticed.
|
||||||
|
//
|
||||||
|
// The fallback still exists, and a wallet that refuses to decrypt is
|
||||||
|
// worse than a slow one, so it is not disabled — it is made loud:
|
||||||
|
// cryptoBackend() reports which backend this realm can run, ensureReady()
|
||||||
|
// logs an error if it is not WASM, tests/vaultBackend.test.js asserts the
|
||||||
|
// unit tests exercise the WASM backend, and the end-to-end suite asserts
|
||||||
|
// it in the real popup under the real manifest.
|
||||||
|
|
||||||
const sodium = require("libsodium-wrappers-sumo");
|
const sodium = require("libsodium-wrappers-sumo");
|
||||||
|
const { log } = require("./log");
|
||||||
|
|
||||||
|
// An empty WebAssembly module: the 8-byte magic number and version header,
|
||||||
|
// no sections. Compiling it asks the cheapest possible form of the only
|
||||||
|
// question that matters here — may this realm compile WebAssembly at all —
|
||||||
|
// which is exactly what a CSP without 'wasm-unsafe-eval' refuses, and
|
||||||
|
// exactly what decides which backend libsodium ends up on.
|
||||||
|
const EMPTY_WASM_MODULE = new Uint8Array([
|
||||||
|
0x00, 0x61, 0x73, 0x6d, 0x01, 0x00, 0x00, 0x00,
|
||||||
|
]);
|
||||||
|
|
||||||
|
// "wasm" or "asmjs": whether this realm may compile WebAssembly, which is
|
||||||
|
// what decides libsodium's backend when the CSP is the reason it cannot —
|
||||||
|
// the case this codebase guards. It probes the realm, not libsodium, so a
|
||||||
|
// fallback taken for some other reason (allocation failure, corrupt module)
|
||||||
|
// would not be caught here; tests/vaultBackend.test.js checks libsodium's
|
||||||
|
// own marker directly.
|
||||||
|
async function cryptoBackend() {
|
||||||
|
try {
|
||||||
|
await WebAssembly.compile(EMPTY_WASM_MODULE);
|
||||||
|
return "wasm";
|
||||||
|
} catch (_) {
|
||||||
|
return "asmjs";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
let ready = false;
|
let ready = false;
|
||||||
|
|
||||||
async function ensureReady() {
|
async function ensureReady() {
|
||||||
if (!ready) {
|
if (!ready) {
|
||||||
await sodium.ready;
|
await sodium.ready;
|
||||||
|
if ((await cryptoBackend()) !== "wasm") {
|
||||||
|
log.errorf(
|
||||||
|
"libsodium is running on the wasm2js fallback: this realm " +
|
||||||
|
"refuses to compile WebAssembly, so every password " +
|
||||||
|
"derivation costs roughly 20x what it should. See the " +
|
||||||
|
"backend note in src/shared/vault.js.",
|
||||||
|
);
|
||||||
|
}
|
||||||
ready = true;
|
ready = true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -59,4 +125,4 @@ async function decryptWithPassword(encrypted, password) {
|
|||||||
return sodium.to_string(plaintext);
|
return sodium.to_string(plaintext);
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = { encryptWithPassword, decryptWithPassword };
|
module.exports = { cryptoBackend, decryptWithPassword, encryptWithPassword };
|
||||||
|
|||||||
@@ -5,6 +5,10 @@ const { Mnemonic, HDNodeWallet, Wallet } = require("ethers");
|
|||||||
const { DEBUG, DEBUG_MNEMONIC, BIP44_ETH_PATH } = require("./constants");
|
const { DEBUG, DEBUG_MNEMONIC, BIP44_ETH_PATH } = require("./constants");
|
||||||
|
|
||||||
function generateMnemonic() {
|
function generateMnemonic() {
|
||||||
|
// This must stay the compile-time DEBUG constant. Do NOT switch it to
|
||||||
|
// isDebug() from log.js: that also ORs in the runtime debugMode flag the
|
||||||
|
// settings toggle drives, which would let a user of a release build turn
|
||||||
|
// the hardcoded, publicly known test phrase back on for real wallets.
|
||||||
if (DEBUG) return DEBUG_MNEMONIC;
|
if (DEBUG) return DEBUG_MNEMONIC;
|
||||||
const m = Mnemonic.fromEntropy(
|
const m = Mnemonic.fromEntropy(
|
||||||
globalThis.crypto.getRandomValues(new Uint8Array(16)),
|
globalThis.crypto.getRandomValues(new Uint8Array(16)),
|
||||||
@@ -12,8 +16,60 @@ function generateMnemonic() {
|
|||||||
return m.phrase;
|
return m.phrase;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Every extended key (xprv or xpub) entering the app goes through this.
|
||||||
|
//
|
||||||
|
// ethers' HDNodeWallet.fromExtendedKey does NOT verify the base58 checksum
|
||||||
|
// when the decoded payload is the usual 82 bytes, which is exactly the case
|
||||||
|
// the checksum exists to catch: a key with a one-character typo parses into a
|
||||||
|
// *different* wallet instead of being rejected. Re-encoding the parsed node
|
||||||
|
// reproduces a well-formed key byte for byte, checksum included, so comparing
|
||||||
|
// the round trip against the input rejects any altered character. Measured by
|
||||||
|
// the sweep in tests/wallet.test.js over every single-character substitution
|
||||||
|
// of the BIP-32 vector 1 master key: 199 parse without the round-trip
|
||||||
|
// comparison, 0 with it.
|
||||||
|
//
|
||||||
|
// Returns the parsed node, or null if the key is not a well-formed extended
|
||||||
|
// key. Callers turn null into a user-facing error; none of them may fall back
|
||||||
|
// to fromExtendedKey directly.
|
||||||
|
function parseExtendedKey(key) {
|
||||||
|
if (typeof key !== "string") return null;
|
||||||
|
try {
|
||||||
|
const node = HDNodeWallet.fromExtendedKey(key);
|
||||||
|
return node.extendedKey === key ? node : null;
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A master key is at depth 0. Only from there is BIP44_ETH_PATH the absolute
|
||||||
|
// path it names; deriving it under an account-level or child key yields
|
||||||
|
// addresses that correspond to nothing the user holds.
|
||||||
|
const MASTER_DEPTH = 0;
|
||||||
|
|
||||||
|
// Parse an extended private key that the BIP-44 Ethereum account path can be
|
||||||
|
// derived from, or throw. Both callers derive BIP44_ETH_PATH from the result.
|
||||||
|
function masterXprvOrThrow(key) {
|
||||||
|
const node = parseExtendedKey(key);
|
||||||
|
if (!node) {
|
||||||
|
throw new Error("Not a valid extended private key (xprv).");
|
||||||
|
}
|
||||||
|
if (!node.privateKey) {
|
||||||
|
throw new Error("Not an extended private key (xprv).");
|
||||||
|
}
|
||||||
|
if (node.depth !== MASTER_DEPTH) {
|
||||||
|
throw new Error(
|
||||||
|
"Not a master extended private key (xprv): an account-level or " +
|
||||||
|
"child key cannot be imported.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return node;
|
||||||
|
}
|
||||||
|
|
||||||
function deriveAddressFromXpub(xpub, index) {
|
function deriveAddressFromXpub(xpub, index) {
|
||||||
const node = HDNodeWallet.fromExtendedKey(xpub);
|
const node = parseExtendedKey(xpub);
|
||||||
|
if (!node) {
|
||||||
|
throw new Error("Not a valid extended key.");
|
||||||
|
}
|
||||||
return node.deriveChild(index).address;
|
return node.deriveChild(index).address;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -24,6 +80,31 @@ function hdWalletFromMnemonic(mnemonic) {
|
|||||||
return { xpub, firstAddress };
|
return { xpub, firstAddress };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function hdWalletFromXprv(xprv) {
|
||||||
|
// BIP44_ETH_PATH is absolute ("m/..."), which ethers will only derive from
|
||||||
|
// a depth-0 node. The relative form this used to derive would have been
|
||||||
|
// applied *beneath* an account-level key instead of being refused.
|
||||||
|
const node = masterXprvOrThrow(xprv).derivePath(BIP44_ETH_PATH);
|
||||||
|
const xpub = node.neuter().extendedKey;
|
||||||
|
const firstAddress = node.deriveChild(0).address;
|
||||||
|
return { xpub, firstAddress };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Well-formed extended private key. Says nothing about depth: the import view
|
||||||
|
// reports a non-master key separately, since "check it for a typo" is the
|
||||||
|
// wrong advice for a key the user copied correctly.
|
||||||
|
function isValidXprv(key) {
|
||||||
|
const node = parseExtendedKey(key);
|
||||||
|
return !!(node && node.privateKey);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Whether an extended key is a master key, i.e. the one BIP44_ETH_PATH can be
|
||||||
|
// derived from. False for anything parseExtendedKey rejects.
|
||||||
|
function isMasterExtendedKey(key) {
|
||||||
|
const node = parseExtendedKey(key);
|
||||||
|
return !!node && node.depth === MASTER_DEPTH;
|
||||||
|
}
|
||||||
|
|
||||||
function addressFromPrivateKey(key) {
|
function addressFromPrivateKey(key) {
|
||||||
const w = new Wallet(key);
|
const w = new Wallet(key);
|
||||||
return w.address;
|
return w.address;
|
||||||
@@ -38,6 +119,26 @@ function getSignerForAddress(walletData, addrIndex, decryptedSecret) {
|
|||||||
);
|
);
|
||||||
return node.deriveChild(addrIndex);
|
return node.deriveChild(addrIndex);
|
||||||
}
|
}
|
||||||
|
if (walletData.type === "xprv") {
|
||||||
|
// Checked here rather than through masterXprvOrThrow so the message
|
||||||
|
// fits the situation: nobody is importing anything at signing time,
|
||||||
|
// and this wallet is already in storage. src/shared/walletDefects.js
|
||||||
|
// catches it at list-render time; this is the backstop behind that.
|
||||||
|
const node = parseExtendedKey(decryptedSecret);
|
||||||
|
if (!node || !node.privateKey) {
|
||||||
|
throw new Error(
|
||||||
|
"This wallet's stored key is not a valid extended private " +
|
||||||
|
"key, so it cannot sign.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (node.depth !== MASTER_DEPTH) {
|
||||||
|
throw new Error(
|
||||||
|
"This wallet was imported from an extended private key that " +
|
||||||
|
"is not a master key, so it cannot sign.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return node.derivePath(BIP44_ETH_PATH).deriveChild(addrIndex);
|
||||||
|
}
|
||||||
return new Wallet(decryptedSecret);
|
return new Wallet(decryptedSecret);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -45,11 +146,25 @@ function isValidMnemonic(mnemonic) {
|
|||||||
return Mnemonic.isValidMnemonic(mnemonic);
|
return Mnemonic.isValidMnemonic(mnemonic);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Only an HD wallet has a recovery phrase. A "key" wallet holds a bare
|
||||||
|
// private key and an "xprv" wallet an extended private key; neither can be
|
||||||
|
// turned back into words, so neither may ever be offered the phrase display.
|
||||||
|
// Written as an allowlist on purpose: a wallet type added later is excluded
|
||||||
|
// until someone decides otherwise.
|
||||||
|
function walletHasRecoveryPhrase(walletData) {
|
||||||
|
return !!walletData && walletData.type === "hd";
|
||||||
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
generateMnemonic,
|
generateMnemonic,
|
||||||
|
parseExtendedKey,
|
||||||
deriveAddressFromXpub,
|
deriveAddressFromXpub,
|
||||||
hdWalletFromMnemonic,
|
hdWalletFromMnemonic,
|
||||||
|
hdWalletFromXprv,
|
||||||
|
isValidXprv,
|
||||||
|
isMasterExtendedKey,
|
||||||
addressFromPrivateKey,
|
addressFromPrivateKey,
|
||||||
getSignerForAddress,
|
getSignerForAddress,
|
||||||
isValidMnemonic,
|
isValidMnemonic,
|
||||||
|
walletHasRecoveryPhrase,
|
||||||
};
|
};
|
||||||
|
|||||||
86
src/shared/walletDefects.js
Normal file
86
src/shared/walletDefects.js
Normal file
@@ -0,0 +1,86 @@
|
|||||||
|
// Wallets already in stored state whose key cannot be used, and the copy that
|
||||||
|
// explains them.
|
||||||
|
//
|
||||||
|
// Refusing a non-master extended private key at import time does nothing for a
|
||||||
|
// wallet imported before that refusal existed. Such a wallet is detected here,
|
||||||
|
// at wallet-list render time, so the user meets the explanation on the list
|
||||||
|
// screen rather than an exception on the send screen. Nothing here modifies or
|
||||||
|
// removes a wallet: the record is the user's data.
|
||||||
|
|
||||||
|
const { parseExtendedKey } = require("./wallet");
|
||||||
|
|
||||||
|
const NON_MASTER_XPRV = "non-master-xprv";
|
||||||
|
|
||||||
|
// An "xprv" wallet stores the neutered BIP-44 Ethereum node, four levels below
|
||||||
|
// the key that was imported: the current import path derives the absolute
|
||||||
|
// m/44'/60'/0'/0 from a depth-0 key, and the pre-#210 path derived the same
|
||||||
|
// four levels as a relative path beneath whatever depth it was given. A master
|
||||||
|
// import therefore stores a depth-4 xpub and a depth-d import stores depth
|
||||||
|
// d + 4, which makes the stored xpub an exact read on the imported key's
|
||||||
|
// depth — and it is readable without the password, unlike the key itself.
|
||||||
|
const BIP44_ETH_XPUB_DEPTH = 4;
|
||||||
|
|
||||||
|
const DEFECTS = {
|
||||||
|
[NON_MASTER_XPRV]: {
|
||||||
|
id: NON_MASTER_XPRV,
|
||||||
|
heading: "This wallet's addresses were derived incorrectly.",
|
||||||
|
paragraphs: [
|
||||||
|
"This wallet was imported from an extended private key that is " +
|
||||||
|
"not a master key. An earlier version applied the Ethereum " +
|
||||||
|
"derivation path beneath that key instead of from a master " +
|
||||||
|
"key, so the addresses listed here are not the ones that key " +
|
||||||
|
"produces under the standard path.",
|
||||||
|
"Signing and sending are disabled for this wallet. The addresses " +
|
||||||
|
"do descend from the extended private key you imported, so " +
|
||||||
|
"anything they hold is still reachable by software that " +
|
||||||
|
"repeats the same non-standard derivation. Check them in a " +
|
||||||
|
"block explorer before deciding what to do.",
|
||||||
|
"To see the addresses this key produces under the standard path, " +
|
||||||
|
"import the master extended private key, or the recovery " +
|
||||||
|
"phrase it came from, as a new wallet. Nothing here has been " +
|
||||||
|
"changed or removed, and this wallet stays until you delete " +
|
||||||
|
"it yourself.",
|
||||||
|
],
|
||||||
|
// One sentence for the places that have room for one: the flash on a
|
||||||
|
// blocked Send, the inline error on the approval screens.
|
||||||
|
shortMessage:
|
||||||
|
"This wallet cannot sign, because it was imported from an " +
|
||||||
|
"extended private key that is not a master key. The wallet list " +
|
||||||
|
"explains what happened.",
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
// The defect record for a wallet, or null if there is nothing wrong with it
|
||||||
|
// that this module can see. Read-only.
|
||||||
|
//
|
||||||
|
// A wallet whose xpub will not parse gets null rather than a defect: there is
|
||||||
|
// no basis in that case to tell the user their key was not a master key, and a
|
||||||
|
// wrong explanation is worse than none.
|
||||||
|
function walletDefect(walletData) {
|
||||||
|
if (!walletData || walletData.type !== "xprv") return null;
|
||||||
|
const node = parseExtendedKey(walletData.xpub);
|
||||||
|
if (!node) return null;
|
||||||
|
if (node.depth === BIP44_ETH_XPUB_DEPTH) return null;
|
||||||
|
return DEFECTS[NON_MASTER_XPRV];
|
||||||
|
}
|
||||||
|
|
||||||
|
// The notice block for the wallet list, or "" for a wallet with no defect.
|
||||||
|
// The copy is fixed text from this module, so it needs no escaping.
|
||||||
|
function walletDefectHtml(walletData) {
|
||||||
|
const defect = walletDefect(walletData);
|
||||||
|
if (!defect) return "";
|
||||||
|
let html =
|
||||||
|
'<div class="border border-red-500 border-dashed p-2 my-1 text-xs text-red-500">';
|
||||||
|
html += `<div class="font-bold mb-1">${defect.heading}</div>`;
|
||||||
|
for (const p of defect.paragraphs) {
|
||||||
|
html += `<p class="mb-1">${p}</p>`;
|
||||||
|
}
|
||||||
|
html += "</div>";
|
||||||
|
return html;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
NON_MASTER_XPRV,
|
||||||
|
walletDefect,
|
||||||
|
walletDefectHtml,
|
||||||
|
};
|
||||||
157
src/shared/walletDelete.js
Normal file
157
src/shared/walletDelete.js
Normal file
@@ -0,0 +1,157 @@
|
|||||||
|
// Wallet and address deletion state transitions, kept out of the views so the
|
||||||
|
// selection and broadcast rules are testable without a DOM.
|
||||||
|
|
||||||
|
// Two records of the same address can be stored in different cases, so
|
||||||
|
// address equality is never a literal string comparison.
|
||||||
|
function sameAddress(a, b) {
|
||||||
|
if (a === null || a === undefined || b === null || b === undefined) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
return String(a).toLowerCase() === String(b).toLowerCase();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Forget every site permission held against the given addresses.
|
||||||
|
function dropSitePermissions(state, addresses) {
|
||||||
|
for (const addr of addresses) {
|
||||||
|
delete state.allowedSites[addr];
|
||||||
|
delete state.deniedSites[addr];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Remove wallet `walletIdx` from `state` and repair the derived state.
|
||||||
|
//
|
||||||
|
// Rules:
|
||||||
|
// - `hasWallet` tracks whether any wallet remains.
|
||||||
|
// - Site permissions are dropped for every address of the deleted wallet.
|
||||||
|
// - `selectedWallet` follows the splice: it is decremented when a wallet
|
||||||
|
// before it was removed, and falls back to the first remaining wallet's
|
||||||
|
// first address only when the selection itself was deleted.
|
||||||
|
// - `activeAddress` is only moved when it belonged to the deleted wallet;
|
||||||
|
// the fallback is the first remaining wallet's first address, or null
|
||||||
|
// when no wallet remains.
|
||||||
|
//
|
||||||
|
// Returns whether `activeAddress` changed, so the caller can broadcast it.
|
||||||
|
function removeWalletFromState(state, walletIdx) {
|
||||||
|
const wallet = state.wallets[walletIdx];
|
||||||
|
const addresses = (wallet.addresses || []).map((a) => a.address);
|
||||||
|
const previousActive = state.activeAddress;
|
||||||
|
const activeWasDeleted = addresses.some((a) =>
|
||||||
|
sameAddress(a, previousActive),
|
||||||
|
);
|
||||||
|
|
||||||
|
state.wallets.splice(walletIdx, 1);
|
||||||
|
|
||||||
|
dropSitePermissions(state, addresses);
|
||||||
|
|
||||||
|
state.hasWallet = state.wallets.length > 0;
|
||||||
|
|
||||||
|
const fallbackAddress = state.hasWallet
|
||||||
|
? state.wallets[0].addresses[0]?.address || null
|
||||||
|
: null;
|
||||||
|
|
||||||
|
if (!state.hasWallet) {
|
||||||
|
state.selectedWallet = null;
|
||||||
|
state.selectedAddress = null;
|
||||||
|
} else if (state.selectedWallet === walletIdx) {
|
||||||
|
state.selectedWallet = 0;
|
||||||
|
state.selectedAddress = 0;
|
||||||
|
} else if (
|
||||||
|
typeof state.selectedWallet === "number" &&
|
||||||
|
state.selectedWallet > walletIdx
|
||||||
|
) {
|
||||||
|
state.selectedWallet -= 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (activeWasDeleted || !state.hasWallet) {
|
||||||
|
state.activeAddress = fallbackAddress;
|
||||||
|
}
|
||||||
|
|
||||||
|
return { activeAddressChanged: state.activeAddress !== previousActive };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Whether a wallet may be offered a per-address remove control, and the same
|
||||||
|
// gate the removal itself is held behind.
|
||||||
|
//
|
||||||
|
// Only a wallet that derives its addresses from an extended key can hold more
|
||||||
|
// than one, so only those get the control — a key wallet has exactly one
|
||||||
|
// address and no "+" button either. The last address of any wallet is never
|
||||||
|
// removable: a wallet with no addresses is what delete-wallet is for.
|
||||||
|
function canRemoveAddress(wallet) {
|
||||||
|
if (!wallet) return false;
|
||||||
|
if (wallet.type !== "hd" && wallet.type !== "xprv") return false;
|
||||||
|
return (wallet.addresses || []).length > 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Remove address `addrIdx` of wallet `walletIdx` and repair the derived state.
|
||||||
|
//
|
||||||
|
// Nothing is destroyed here. The address stays derivable from the wallet's own
|
||||||
|
// key material and any funds at it are untouched; this only stops the wallet
|
||||||
|
// tracking it. `nextIndex` is deliberately left alone — it is a derivation
|
||||||
|
// high-water mark, so "+" derives a fresh index rather than handing back the
|
||||||
|
// address just removed, and the gap it leaves is within what
|
||||||
|
// `scanForAddresses()` re-discovers on a later import.
|
||||||
|
//
|
||||||
|
// The rules mirror removeWalletFromState() one level down:
|
||||||
|
// - The call is refused unless canRemoveAddress() allows it, so the last
|
||||||
|
// address of a wallet always survives.
|
||||||
|
// - Site permissions are dropped for the removed address.
|
||||||
|
// - `selectedAddress` follows the splice, but only within the wallet that
|
||||||
|
// lost the address: it is decremented when an earlier address was
|
||||||
|
// removed, and falls back to that wallet's first address when the
|
||||||
|
// selection itself was removed. `selectedWallet` never moves, because the
|
||||||
|
// wallet list does not.
|
||||||
|
// - `activeAddress` moves only when it was the removed address, and then to
|
||||||
|
// the wallet's first remaining address.
|
||||||
|
//
|
||||||
|
// Returns whether the address was removed and whether `activeAddress`
|
||||||
|
// changed, so the caller can broadcast it.
|
||||||
|
function removeAddressFromState(state, walletIdx, addrIdx) {
|
||||||
|
const wallet = state.wallets[walletIdx];
|
||||||
|
const refused = { removed: false, activeAddressChanged: false };
|
||||||
|
if (!canRemoveAddress(wallet)) return refused;
|
||||||
|
if (!wallet.addresses[addrIdx]) return refused;
|
||||||
|
|
||||||
|
const address = wallet.addresses[addrIdx].address;
|
||||||
|
const previousActive = state.activeAddress;
|
||||||
|
const activeWasRemoved = sameAddress(address, previousActive);
|
||||||
|
|
||||||
|
wallet.addresses.splice(addrIdx, 1);
|
||||||
|
|
||||||
|
dropSitePermissions(state, [address]);
|
||||||
|
|
||||||
|
if (state.selectedWallet === walletIdx) {
|
||||||
|
if (state.selectedAddress === addrIdx) {
|
||||||
|
state.selectedAddress = 0;
|
||||||
|
} else if (
|
||||||
|
typeof state.selectedAddress === "number" &&
|
||||||
|
state.selectedAddress > addrIdx
|
||||||
|
) {
|
||||||
|
state.selectedAddress -= 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (activeWasRemoved) {
|
||||||
|
state.activeAddress = wallet.addresses[0].address;
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
removed: true,
|
||||||
|
activeAddressChanged: state.activeAddress !== previousActive,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Tell the background the active address changed, so it re-emits
|
||||||
|
// accountsChanged to connected sites. Same call shape as the address
|
||||||
|
// switch in the home view.
|
||||||
|
function broadcastActiveChanged() {
|
||||||
|
const runtime =
|
||||||
|
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
|
||||||
|
runtime.sendMessage({ type: "AUTISTMASK_ACTIVE_CHANGED" });
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
canRemoveAddress,
|
||||||
|
removeAddressFromState,
|
||||||
|
removeWalletFromState,
|
||||||
|
broadcastActiveChanged,
|
||||||
|
};
|
||||||
468
tests/alarms.test.js
Normal file
468
tests/alarms.test.js
Normal file
@@ -0,0 +1,468 @@
|
|||||||
|
// Scheduling for the background context.
|
||||||
|
//
|
||||||
|
// The Chrome MV3 service worker is terminated after roughly 30 seconds idle,
|
||||||
|
// so anything scheduled with setInterval/setTimeout dies with it. These tests
|
||||||
|
// pin the recurring jobs to the alarms API and to the re-registration path a
|
||||||
|
// revived worker runs.
|
||||||
|
|
||||||
|
// A controllable clock plus a stubbed balance refresh, so a cadence test can
|
||||||
|
// measure the interval between refreshes that actually happened rather than
|
||||||
|
// asserting the interval someone intended.
|
||||||
|
let mockNow = 0;
|
||||||
|
const mockBalanceRefreshAt = [];
|
||||||
|
|
||||||
|
// jest.resetModules() clears the call record of every jest.fn, and loading the
|
||||||
|
// worker is exactly that call — so anything that must be counted across a load
|
||||||
|
// is counted here rather than read off a mock.
|
||||||
|
let mockSetIntervalCalls = 0;
|
||||||
|
|
||||||
|
// Extension storage reads do not take a constant amount of time, and that is
|
||||||
|
// what makes a guard timed to the alarm period bite: backgroundRefresh()
|
||||||
|
// stamps its freshness marker after awaiting loadState(), so any read that is
|
||||||
|
// quicker than the previous one puts the next tick inside a guard of exactly
|
||||||
|
// one period and the tick is skipped. A simulation with a constant latency
|
||||||
|
// would sit exactly on the boundary and hide the bug.
|
||||||
|
const MOCK_STORAGE_LATENCIES_MS = [7, 3, 11, 2, 9, 4, 13, 1, 6, 5];
|
||||||
|
const MOCK_MAX_STORAGE_LATENCY_MS = Math.max(...MOCK_STORAGE_LATENCIES_MS);
|
||||||
|
let mockStorageJitter = false;
|
||||||
|
let mockStorageOpCount = 0;
|
||||||
|
|
||||||
|
function mockStorageTick() {
|
||||||
|
if (!mockStorageJitter) return;
|
||||||
|
mockNow +=
|
||||||
|
MOCK_STORAGE_LATENCIES_MS[
|
||||||
|
mockStorageOpCount++ % MOCK_STORAGE_LATENCIES_MS.length
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
jest.mock("../src/shared/balances", () => ({
|
||||||
|
refreshBalances: jest.fn(async () => {
|
||||||
|
mockBalanceRefreshAt.push(Date.now());
|
||||||
|
}),
|
||||||
|
getProvider: jest.fn(() => ({})),
|
||||||
|
}));
|
||||||
|
|
||||||
|
function makeAlarmsStub() {
|
||||||
|
const alarms = new Map();
|
||||||
|
const listeners = [];
|
||||||
|
const stub = {
|
||||||
|
created: [],
|
||||||
|
alarms,
|
||||||
|
create: jest.fn((name, info) => {
|
||||||
|
stub.created.push({ name, info });
|
||||||
|
alarms.set(name, { name, ...info });
|
||||||
|
}),
|
||||||
|
get: jest.fn(async (name) => alarms.get(name)),
|
||||||
|
clear: jest.fn(async (name) => alarms.delete(name)),
|
||||||
|
onAlarm: {
|
||||||
|
addListener: jest.fn((fn) => listeners.push(fn)),
|
||||||
|
},
|
||||||
|
fire: (name) => {
|
||||||
|
for (const fn of listeners) fn({ name });
|
||||||
|
},
|
||||||
|
listenerCount: () => listeners.length,
|
||||||
|
};
|
||||||
|
return stub;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("alarms module", () => {
|
||||||
|
let alarmsStub;
|
||||||
|
let alarmsMod;
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
jest.resetModules();
|
||||||
|
alarmsStub = makeAlarmsStub();
|
||||||
|
global.chrome = { alarms: alarmsStub };
|
||||||
|
alarmsMod = require("../src/shared/alarms");
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("ensureRecurringAlarms schedules both recurring jobs", async () => {
|
||||||
|
const created = await alarmsMod.ensureRecurringAlarms();
|
||||||
|
expect(created).toEqual({ balance: true, phishing: true });
|
||||||
|
|
||||||
|
const names = alarmsStub.created.map((c) => c.name).sort();
|
||||||
|
expect(names).toEqual(
|
||||||
|
[
|
||||||
|
alarmsMod.BALANCE_REFRESH_ALARM,
|
||||||
|
alarmsMod.PHISHING_REFRESH_ALARM,
|
||||||
|
].sort(),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the balance refresh keeps its 60-second cadence", async () => {
|
||||||
|
await alarmsMod.ensureRecurringAlarms();
|
||||||
|
const balance = alarmsStub.alarms.get(alarmsMod.BALANCE_REFRESH_ALARM);
|
||||||
|
expect(balance.periodInMinutes).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the phishing refresh keeps its 24-hour cadence", async () => {
|
||||||
|
await alarmsMod.ensureRecurringAlarms();
|
||||||
|
const phishing = alarmsStub.alarms.get(
|
||||||
|
alarmsMod.PHISHING_REFRESH_ALARM,
|
||||||
|
);
|
||||||
|
expect(phishing.periodInMinutes).toBe(24 * 60);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("no period is below the browser-enforced minimum", async () => {
|
||||||
|
// A period under one minute is silently clamped by the browser, so a
|
||||||
|
// request for one would mean the documented cadence is not the real
|
||||||
|
// one. Every period must be a whole minute at or above the minimum.
|
||||||
|
await alarmsMod.ensureRecurringAlarms();
|
||||||
|
for (const { info } of alarmsStub.created) {
|
||||||
|
expect(info.periodInMinutes).toBeGreaterThanOrEqual(
|
||||||
|
alarmsMod.MIN_ALARM_PERIOD_MINUTES,
|
||||||
|
);
|
||||||
|
expect(Number.isInteger(info.periodInMinutes)).toBe(true);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a revived worker does not reset an existing alarm's schedule", async () => {
|
||||||
|
await alarmsMod.ensureRecurringAlarms();
|
||||||
|
expect(alarmsStub.create).toHaveBeenCalledTimes(2);
|
||||||
|
|
||||||
|
// Every wake re-runs the startup path. Re-creating an alarm restarts
|
||||||
|
// its period, so a busy extension would push the next fire out
|
||||||
|
// forever and the job would never run.
|
||||||
|
const again = await alarmsMod.ensureRecurringAlarms();
|
||||||
|
expect(again).toEqual({ balance: false, phishing: false });
|
||||||
|
expect(alarmsStub.create).toHaveBeenCalledTimes(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a missing alarm is re-created on the next start", async () => {
|
||||||
|
await alarmsMod.ensureRecurringAlarms();
|
||||||
|
await alarmsStub.clear(alarmsMod.BALANCE_REFRESH_ALARM);
|
||||||
|
|
||||||
|
const again = await alarmsMod.ensureRecurringAlarms();
|
||||||
|
expect(again).toEqual({ balance: true, phishing: false });
|
||||||
|
expect(
|
||||||
|
alarmsStub.alarms.get(alarmsMod.BALANCE_REFRESH_ALARM),
|
||||||
|
).toBeDefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an alarm left over with a stale period is re-created", async () => {
|
||||||
|
// An install carries its alarms across an extension update, so a
|
||||||
|
// period changed in a new release only ever reaches users if the
|
||||||
|
// stale one is reconciled.
|
||||||
|
alarmsStub.create(alarmsMod.PHISHING_REFRESH_ALARM, {
|
||||||
|
periodInMinutes: 7 * 24 * 60,
|
||||||
|
});
|
||||||
|
alarmsStub.create.mockClear();
|
||||||
|
|
||||||
|
const created = await alarmsMod.ensureRecurringAlarms();
|
||||||
|
expect(created.phishing).toBe(true);
|
||||||
|
expect(
|
||||||
|
alarmsStub.alarms.get(alarmsMod.PHISHING_REFRESH_ALARM)
|
||||||
|
.periodInMinutes,
|
||||||
|
).toBe(alarmsMod.PHISHING_REFRESH_PERIOD_MINUTES);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("reconciling a period settles instead of re-creating forever", async () => {
|
||||||
|
alarmsStub.create(alarmsMod.BALANCE_REFRESH_ALARM, {
|
||||||
|
periodInMinutes: 30,
|
||||||
|
});
|
||||||
|
await alarmsMod.ensureRecurringAlarms();
|
||||||
|
alarmsStub.create.mockClear();
|
||||||
|
|
||||||
|
const again = await alarmsMod.ensureRecurringAlarms();
|
||||||
|
expect(again).toEqual({ balance: false, phishing: false });
|
||||||
|
expect(alarmsStub.create).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handlers are dispatched by alarm name from one listener", () => {
|
||||||
|
const balance = jest.fn();
|
||||||
|
const phishing = jest.fn();
|
||||||
|
expect(
|
||||||
|
alarmsMod.registerAlarmHandlers({
|
||||||
|
[alarmsMod.BALANCE_REFRESH_ALARM]: balance,
|
||||||
|
[alarmsMod.PHISHING_REFRESH_ALARM]: phishing,
|
||||||
|
}),
|
||||||
|
).toBe(true);
|
||||||
|
expect(alarmsStub.listenerCount()).toBe(1);
|
||||||
|
|
||||||
|
alarmsStub.fire(alarmsMod.BALANCE_REFRESH_ALARM);
|
||||||
|
expect(balance).toHaveBeenCalledTimes(1);
|
||||||
|
expect(phishing).not.toHaveBeenCalled();
|
||||||
|
|
||||||
|
alarmsStub.fire(alarmsMod.PHISHING_REFRESH_ALARM);
|
||||||
|
expect(phishing).toHaveBeenCalledTimes(1);
|
||||||
|
|
||||||
|
alarmsStub.fire("some-other-extension-alarm");
|
||||||
|
expect(balance).toHaveBeenCalledTimes(1);
|
||||||
|
expect(phishing).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("Firefox MV2 gets the same treatment via browser.alarms", async () => {
|
||||||
|
// Both targets are built from one bundle. MV2 has a persistent
|
||||||
|
// background page, but it takes the alarm path too, so the schedule
|
||||||
|
// is the same code on both browsers.
|
||||||
|
jest.resetModules();
|
||||||
|
const firefoxAlarms = makeAlarmsStub();
|
||||||
|
global.browser = { alarms: firefoxAlarms };
|
||||||
|
try {
|
||||||
|
const mod = require("../src/shared/alarms");
|
||||||
|
const created = await mod.ensureRecurringAlarms();
|
||||||
|
expect(created).toEqual({ balance: true, phishing: true });
|
||||||
|
expect(firefoxAlarms.created).toHaveLength(2);
|
||||||
|
// The Chrome stub must not have been touched.
|
||||||
|
expect(alarmsStub.create).not.toHaveBeenCalled();
|
||||||
|
} finally {
|
||||||
|
delete global.browser;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a context without the alarms API degrades instead of throwing", async () => {
|
||||||
|
jest.resetModules();
|
||||||
|
delete global.chrome;
|
||||||
|
const mod = require("../src/shared/alarms");
|
||||||
|
await expect(mod.ensureRecurringAlarms()).resolves.toEqual({
|
||||||
|
balance: false,
|
||||||
|
phishing: false,
|
||||||
|
});
|
||||||
|
expect(mod.registerAlarmHandlers({})).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// Loads the background worker against stubbed browser APIs. The returned
|
||||||
|
// store is the extension storage the worker sees, so a test can seed wallet
|
||||||
|
// state and read back what the worker persisted.
|
||||||
|
function loadBackground(initialStore = {}) {
|
||||||
|
const storageStore = initialStore;
|
||||||
|
const alarmsStub = makeAlarmsStub();
|
||||||
|
const listeners = { onInstalled: [], onStartup: [] };
|
||||||
|
global.chrome = {
|
||||||
|
alarms: alarmsStub,
|
||||||
|
storage: {
|
||||||
|
local: {
|
||||||
|
get: async (key) => {
|
||||||
|
mockStorageTick();
|
||||||
|
return Object.prototype.hasOwnProperty.call(
|
||||||
|
storageStore,
|
||||||
|
key,
|
||||||
|
)
|
||||||
|
? { [key]: storageStore[key] }
|
||||||
|
: {};
|
||||||
|
},
|
||||||
|
set: async (items) => {
|
||||||
|
mockStorageTick();
|
||||||
|
Object.assign(storageStore, items);
|
||||||
|
},
|
||||||
|
remove: async (key) => {
|
||||||
|
delete storageStore[key];
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
runtime: {
|
||||||
|
onMessage: { addListener: jest.fn() },
|
||||||
|
onConnect: { addListener: jest.fn() },
|
||||||
|
onInstalled: {
|
||||||
|
addListener: jest.fn((fn) => listeners.onInstalled.push(fn)),
|
||||||
|
},
|
||||||
|
onStartup: {
|
||||||
|
addListener: jest.fn((fn) => listeners.onStartup.push(fn)),
|
||||||
|
},
|
||||||
|
getURL: (p) => "chrome-extension://test/" + p,
|
||||||
|
lastError: null,
|
||||||
|
},
|
||||||
|
windows: {
|
||||||
|
onRemoved: { addListener: jest.fn() },
|
||||||
|
create: jest.fn(),
|
||||||
|
},
|
||||||
|
tabs: { query: jest.fn(), sendMessage: jest.fn() },
|
||||||
|
action: { setPopup: jest.fn() },
|
||||||
|
};
|
||||||
|
global.fetch = jest.fn(async () => ({
|
||||||
|
ok: true,
|
||||||
|
json: async () => ({ blacklist: [] }),
|
||||||
|
}));
|
||||||
|
jest.resetModules();
|
||||||
|
require("../src/background/index");
|
||||||
|
return { alarmsStub, listeners, store: storageStore };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Flush the promise chains the startup path and the alarm handlers run on.
|
||||||
|
async function settle() {
|
||||||
|
for (let i = 0; i < 3; i++) {
|
||||||
|
await new Promise((resolve) => setImmediate(resolve));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("background worker scheduling", () => {
|
||||||
|
let alarmsStub;
|
||||||
|
let timers;
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
mockSetIntervalCalls = 0;
|
||||||
|
timers = {
|
||||||
|
setInterval: jest
|
||||||
|
.spyOn(global, "setInterval")
|
||||||
|
.mockImplementation(() => {
|
||||||
|
mockSetIntervalCalls++;
|
||||||
|
return 0;
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
timers.setInterval.mockRestore();
|
||||||
|
delete global.chrome;
|
||||||
|
delete global.fetch;
|
||||||
|
jest.resetModules();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("startup schedules the recurring jobs as alarms, not timers", async () => {
|
||||||
|
alarmsStub = loadBackground().alarmsStub;
|
||||||
|
// Let the startup path's promises settle.
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
const names = alarmsStub.created.map((c) => c.name).sort();
|
||||||
|
const {
|
||||||
|
BALANCE_REFRESH_ALARM,
|
||||||
|
PHISHING_REFRESH_ALARM,
|
||||||
|
} = require("../src/shared/alarms");
|
||||||
|
expect(names).toEqual(
|
||||||
|
[BALANCE_REFRESH_ALARM, PHISHING_REFRESH_ALARM].sort(),
|
||||||
|
);
|
||||||
|
expect(mockSetIntervalCalls).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an onAlarm listener is installed on startup", async () => {
|
||||||
|
alarmsStub = loadBackground().alarmsStub;
|
||||||
|
await settle();
|
||||||
|
expect(alarmsStub.listenerCount()).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("onInstalled and onStartup both re-establish the schedule", async () => {
|
||||||
|
const loaded = loadBackground();
|
||||||
|
alarmsStub = loaded.alarmsStub;
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(loaded.listeners.onInstalled).toHaveLength(1);
|
||||||
|
expect(loaded.listeners.onStartup).toHaveLength(1);
|
||||||
|
|
||||||
|
// A browser start after the alarms were dropped must put them back.
|
||||||
|
alarmsStub.alarms.clear();
|
||||||
|
alarmsStub.created.length = 0;
|
||||||
|
loaded.listeners.onStartup[0]();
|
||||||
|
await settle();
|
||||||
|
expect(alarmsStub.created).toHaveLength(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the install-time listener and the top-level call share one run", async () => {
|
||||||
|
// On a fresh install both fire, close enough that both could observe
|
||||||
|
// an alarm missing and create it — and a second create restarts the
|
||||||
|
// period the first one just set.
|
||||||
|
const loaded = loadBackground();
|
||||||
|
alarmsStub = loaded.alarmsStub;
|
||||||
|
loaded.listeners.onInstalled[0]();
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(alarmsStub.created).toHaveLength(2);
|
||||||
|
expect(alarmsStub.created.map((c) => c.name).sort()).toEqual(
|
||||||
|
[
|
||||||
|
"autistmask-balance-refresh",
|
||||||
|
"autistmask-phishing-refresh",
|
||||||
|
].sort(),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The alarm period alone must set the cadence. A freshness guard timed to the
|
||||||
|
// period vetoes the very tick it gates, because the guard is measured from
|
||||||
|
// when the last run finished and the alarm fires one run-duration before that.
|
||||||
|
// These tests measure the interval between refreshes that actually ran.
|
||||||
|
describe("balance refresh steady-state cadence", () => {
|
||||||
|
const {
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES,
|
||||||
|
BALANCE_REFRESH_ALARM,
|
||||||
|
} = require("../src/shared/alarms");
|
||||||
|
const PERIOD_MS = BALANCE_REFRESH_PERIOD_MINUTES * 60 * 1000;
|
||||||
|
|
||||||
|
let clockSpy;
|
||||||
|
let timerSpy;
|
||||||
|
|
||||||
|
function seededStore() {
|
||||||
|
return {
|
||||||
|
autistmask: {
|
||||||
|
hasWallet: true,
|
||||||
|
wallets: [
|
||||||
|
{ address: "0x0000000000000000000000000000000000000001" },
|
||||||
|
],
|
||||||
|
lastBalanceRefresh: 0,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
mockNow = Date.UTC(2026, 0, 1, 0, 0, 0);
|
||||||
|
mockBalanceRefreshAt.length = 0;
|
||||||
|
mockSetIntervalCalls = 0;
|
||||||
|
mockStorageOpCount = 0;
|
||||||
|
mockStorageJitter = false;
|
||||||
|
clockSpy = jest.spyOn(Date, "now").mockImplementation(() => mockNow);
|
||||||
|
timerSpy = jest.spyOn(global, "setInterval").mockImplementation(() => {
|
||||||
|
mockSetIntervalCalls++;
|
||||||
|
return 0;
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
mockStorageJitter = false;
|
||||||
|
clockSpy.mockRestore();
|
||||||
|
timerSpy.mockRestore();
|
||||||
|
delete global.chrome;
|
||||||
|
delete global.fetch;
|
||||||
|
jest.resetModules();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("ten alarm ticks produce ten refreshes, one per period", async () => {
|
||||||
|
const { alarmsStub } = loadBackground(seededStore());
|
||||||
|
await settle();
|
||||||
|
mockStorageJitter = true;
|
||||||
|
|
||||||
|
const TICKS = 10;
|
||||||
|
let tickAt = mockNow + PERIOD_MS;
|
||||||
|
for (let i = 0; i < TICKS; i++) {
|
||||||
|
mockNow = tickAt;
|
||||||
|
tickAt += PERIOD_MS;
|
||||||
|
alarmsStub.fire(BALANCE_REFRESH_ALARM);
|
||||||
|
await settle();
|
||||||
|
}
|
||||||
|
|
||||||
|
// No tick was a no-op. This is the assertion that fails when the guard
|
||||||
|
// is timed to the alarm period.
|
||||||
|
expect(mockBalanceRefreshAt).toHaveLength(TICKS);
|
||||||
|
|
||||||
|
// And the observed cadence is one period, not two.
|
||||||
|
const intervals = mockBalanceRefreshAt
|
||||||
|
.slice(1)
|
||||||
|
.map((t, i) => t - mockBalanceRefreshAt[i]);
|
||||||
|
for (const interval of intervals) {
|
||||||
|
expect(interval).toBeGreaterThanOrEqual(
|
||||||
|
PERIOD_MS - MOCK_MAX_STORAGE_LATENCY_MS,
|
||||||
|
);
|
||||||
|
expect(interval).toBeLessThanOrEqual(
|
||||||
|
PERIOD_MS + MOCK_MAX_STORAGE_LATENCY_MS,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a refresh an open popup just did still suppresses the tick", async () => {
|
||||||
|
// The guard's actual job, and the reason it is shortened rather than
|
||||||
|
// removed: while the popup is open it refreshes every 10 seconds and
|
||||||
|
// stamps the same field, and the background job has nothing to add.
|
||||||
|
const store = seededStore();
|
||||||
|
const { alarmsStub } = loadBackground(store);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
mockNow += PERIOD_MS;
|
||||||
|
store.autistmask.lastBalanceRefresh = mockNow - 10 * 1000;
|
||||||
|
alarmsStub.fire(BALANCE_REFRESH_ALARM);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(mockBalanceRefreshAt).toHaveLength(0);
|
||||||
|
});
|
||||||
|
});
|
||||||
1147
tests/approvalVerify.test.js
Normal file
1147
tests/approvalVerify.test.js
Normal file
File diff suppressed because it is too large
Load Diff
679
tests/backgroundApproval.test.js
Normal file
679
tests/backgroundApproval.test.js
Normal file
@@ -0,0 +1,679 @@
|
|||||||
|
// The background's approval message wiring, driven end to end: a dApp
|
||||||
|
// eth_sendTransaction raises a pending approval, and the popup answers it with
|
||||||
|
// AUTISTMASK_TX_RESPONSE / AUTISTMASK_SIGN_RESPONSE.
|
||||||
|
//
|
||||||
|
// What this exists for is the duplicate response. The handler verifies and
|
||||||
|
// broadcasts asynchronously, and the approval deliberately survives a
|
||||||
|
// retryable failure so the user can try again with the transaction they
|
||||||
|
// already saw — which means the entry being present is not by itself proof
|
||||||
|
// that no attempt is running. A second response carrying the same id (a
|
||||||
|
// reloaded approval window re-rendering a live Approve button, a popup that
|
||||||
|
// emits the message twice) must not start a second verify and broadcast: with
|
||||||
|
// the ordinary dApp approval shape the page fixes no nonce, so two artifacts
|
||||||
|
// signed at different nonces both verify, and the approved transfer would go
|
||||||
|
// out twice.
|
||||||
|
|
||||||
|
const { Wallet } = require("ethers");
|
||||||
|
|
||||||
|
const SIGNER_KEY =
|
||||||
|
"0x59c6995e998f97a5a0044966f0945389dc9e86dae88c7a8412f4603b6b78690d";
|
||||||
|
const signer = new Wallet(SIGNER_KEY);
|
||||||
|
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
|
const ORIGIN = "https://dapp.example";
|
||||||
|
const HOSTNAME = "dapp.example";
|
||||||
|
const EXT_URL = "chrome-extension://autistmask/";
|
||||||
|
|
||||||
|
// What the dApp asks for: no nonce, no gas, no fees. This is the shape that
|
||||||
|
// makes a duplicate broadcast possible at all.
|
||||||
|
const TX_PARAMS = {
|
||||||
|
from: signer.address,
|
||||||
|
to: RECIPIENT,
|
||||||
|
value: "0x2386f26fc10000",
|
||||||
|
data: "0x",
|
||||||
|
};
|
||||||
|
|
||||||
|
// The fields the popup's populateTransaction() would fill in. The nonce is a
|
||||||
|
// parameter because the duplicate case turns on the two artifacts differing
|
||||||
|
// in exactly the field nothing constrains.
|
||||||
|
function populated(nonce) {
|
||||||
|
return {
|
||||||
|
type: 2,
|
||||||
|
chainId: 1,
|
||||||
|
nonce,
|
||||||
|
gasLimit: 100000n,
|
||||||
|
maxFeePerGas: 2000000000n,
|
||||||
|
maxPriorityFeePerGas: 1000000000n,
|
||||||
|
to: TX_PARAMS.to,
|
||||||
|
value: BigInt(TX_PARAMS.value),
|
||||||
|
data: TX_PARAMS.data,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function signedAtNonce(nonce) {
|
||||||
|
return signer.signTransaction(populated(nonce));
|
||||||
|
}
|
||||||
|
|
||||||
|
// A promise whose settlement the test controls, so a broadcast can be held in
|
||||||
|
// flight while the second response arrives.
|
||||||
|
function deferred() {
|
||||||
|
let resolve;
|
||||||
|
let reject;
|
||||||
|
const promise = new Promise((res, rej) => {
|
||||||
|
resolve = res;
|
||||||
|
reject = rej;
|
||||||
|
});
|
||||||
|
return { promise, resolve, reject };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Load the background worker against stubbed browser and network APIs and
|
||||||
|
// return the handles the tests drive it through. Everything that would touch
|
||||||
|
// the network or the browser's own schedulers is mocked; the approval
|
||||||
|
// verification is the real module, because that is what the handler under
|
||||||
|
// test is wired to.
|
||||||
|
function loadBackground(options) {
|
||||||
|
const opts = options || {};
|
||||||
|
jest.resetModules();
|
||||||
|
|
||||||
|
const broadcastTransaction = jest.fn();
|
||||||
|
const loadState = jest.fn(opts.loadState || (async () => {}));
|
||||||
|
|
||||||
|
jest.doMock("../src/shared/state", () => ({
|
||||||
|
state: { rpcUrl: "https://rpc.invalid", wallets: [] },
|
||||||
|
loadState,
|
||||||
|
saveState: jest.fn(async () => {}),
|
||||||
|
currentNetwork: () => ({ chainId: "0x1" }),
|
||||||
|
}));
|
||||||
|
jest.doMock("../src/shared/balances", () => ({
|
||||||
|
getProvider: () => ({ broadcastTransaction }),
|
||||||
|
refreshBalances: jest.fn(async () => {}),
|
||||||
|
}));
|
||||||
|
jest.doMock("../src/shared/phishingDomains", () => ({
|
||||||
|
isPhishingDomain: () => false,
|
||||||
|
refreshPhishingListOnSchedule: jest.fn(async () => {}),
|
||||||
|
initPhishingList: jest.fn(async () => {}),
|
||||||
|
}));
|
||||||
|
jest.doMock("../src/shared/alarms", () => ({
|
||||||
|
BALANCE_REFRESH_ALARM: "balance",
|
||||||
|
PHISHING_REFRESH_ALARM: "phishing",
|
||||||
|
BALANCE_REFRESH_PERIOD_MINUTES: 1,
|
||||||
|
ensureRecurringAlarms: jest.fn(async () => {}),
|
||||||
|
registerAlarmHandlers: jest.fn(),
|
||||||
|
}));
|
||||||
|
|
||||||
|
const persisted = {
|
||||||
|
wallets: [
|
||||||
|
{ name: "Wallet 1", type: "hd", addresses: [signer.address] },
|
||||||
|
],
|
||||||
|
rpcUrl: "https://rpc.invalid",
|
||||||
|
activeAddress: signer.address,
|
||||||
|
allowedSites: { [signer.address]: [HOSTNAME] },
|
||||||
|
deniedSites: {},
|
||||||
|
};
|
||||||
|
|
||||||
|
let messageListener = null;
|
||||||
|
let windowRemovedListener = null;
|
||||||
|
const created = [];
|
||||||
|
const removed = [];
|
||||||
|
|
||||||
|
global.chrome = {
|
||||||
|
storage: {
|
||||||
|
local: {
|
||||||
|
get: jest.fn(async () => ({ autistmask: persisted })),
|
||||||
|
set: jest.fn(async () => {}),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
runtime: {
|
||||||
|
getURL: (path) => EXT_URL + path,
|
||||||
|
onMessage: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
messageListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
onConnect: { addListener: () => {} },
|
||||||
|
lastError: null,
|
||||||
|
},
|
||||||
|
windows: {
|
||||||
|
getLastFocused: (cb) => cb(null),
|
||||||
|
create: (options2, cb) => {
|
||||||
|
created.push(options2);
|
||||||
|
cb({ id: created.length });
|
||||||
|
},
|
||||||
|
remove: (id, cb) => {
|
||||||
|
removed.push(id);
|
||||||
|
if (cb) cb();
|
||||||
|
},
|
||||||
|
// Captured, not swallowed: closing the approval window is the
|
||||||
|
// event that used to retire an approval out from under a live
|
||||||
|
// broadcast, and a no-op stub here hides exactly that.
|
||||||
|
onRemoved: {
|
||||||
|
addListener: (fn) => {
|
||||||
|
windowRemovedListener = fn;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
tabs: {
|
||||||
|
query: (q, cb) => cb([]),
|
||||||
|
sendMessage: () => {},
|
||||||
|
},
|
||||||
|
action: { setPopup: () => {} },
|
||||||
|
};
|
||||||
|
|
||||||
|
require("../src/background/index");
|
||||||
|
|
||||||
|
// Send a message the way the browser would, and hand back whatever the
|
||||||
|
// handler passed to sendResponse.
|
||||||
|
function send(msg, sender) {
|
||||||
|
const sendResponse = jest.fn();
|
||||||
|
const kept = messageListener(msg, sender || {}, sendResponse);
|
||||||
|
return { sendResponse, kept };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Raise a pending transaction approval the way a dApp does, and dig the
|
||||||
|
// approval id back out of the popup URL the background opened.
|
||||||
|
function requestTx() {
|
||||||
|
let rpcResult = null;
|
||||||
|
const sendResponse = jest.fn((r) => {
|
||||||
|
rpcResult = r;
|
||||||
|
});
|
||||||
|
messageListener(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_RPC",
|
||||||
|
method: "eth_sendTransaction",
|
||||||
|
params: [TX_PARAMS],
|
||||||
|
},
|
||||||
|
{ origin: ORIGIN },
|
||||||
|
sendResponse,
|
||||||
|
);
|
||||||
|
return {
|
||||||
|
id: () => new URL(created[0].url).searchParams.get("approval"),
|
||||||
|
result: () => rpcResult,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// The user closes the approval popup. `created` is index-aligned with the
|
||||||
|
// ids the window stub hands back, so window 1 is the first popup opened.
|
||||||
|
function closeWindow(windowId) {
|
||||||
|
windowRemovedListener(windowId);
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
send,
|
||||||
|
requestTx,
|
||||||
|
closeWindow,
|
||||||
|
broadcastTransaction,
|
||||||
|
loadState,
|
||||||
|
created,
|
||||||
|
removed,
|
||||||
|
fromPopup: { url: EXT_URL + "src/popup/index.html" },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Let the handler's promise chain run to the next suspension point.
|
||||||
|
async function settle() {
|
||||||
|
for (let i = 0; i < 10; i++) await Promise.resolve();
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.chrome;
|
||||||
|
jest.resetModules();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("one approval, one broadcast", () => {
|
||||||
|
test("a second AUTISTMASK_TX_RESPONSE for the same id does not broadcast again", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
expect(id).toBeTruthy();
|
||||||
|
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
|
||||||
|
// The popup answers. Verification passes and the broadcast is held
|
||||||
|
// open, which is the whole window the second message arrives in.
|
||||||
|
const first = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
|
||||||
|
// A reloaded approval window signs the same approval again. Nothing
|
||||||
|
// in the approval fixes a nonce, so this artifact verifies just as
|
||||||
|
// well as the first one.
|
||||||
|
const second = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(8),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
expect(second.sendResponse).toHaveBeenCalledWith(
|
||||||
|
expect.objectContaining({
|
||||||
|
error: expect.stringMatching(/already being sent/),
|
||||||
|
retryable: false,
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
expect(first.sendResponse).toHaveBeenCalledWith({ txHash: "0xfeed" });
|
||||||
|
expect(pending.result()).toEqual({ result: "0xfeed" });
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the same artifact sent twice broadcasts once", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
const raw = await signedAtNonce(7);
|
||||||
|
const msg = {
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: raw,
|
||||||
|
};
|
||||||
|
|
||||||
|
bg.send(msg, { url: bg.fromPopup.url });
|
||||||
|
bg.send(msg, { url: bg.fromPopup.url });
|
||||||
|
await settle();
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a response arriving after the broadcast finished finds nothing to send", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
bg.broadcastTransaction.mockResolvedValue({ hash: "0xfeed" });
|
||||||
|
bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
const late = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(8),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
expect(late.sendResponse).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a second AUTISTMASK_SIGN_RESPONSE for the same id is refused", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
// Hold the transaction approval in flight, then answer it a second
|
||||||
|
// time as if it were a sign approval: the sign handler must apply the
|
||||||
|
// same interlock rather than running its own verification.
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
const second = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_SIGN_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
signature: "0x00",
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(second.sendResponse).toHaveBeenCalledWith(
|
||||||
|
expect.objectContaining({
|
||||||
|
error: expect.stringMatching(/already being signed/),
|
||||||
|
retryable: false,
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The interlock must not cost the retry the approval exists to allow.
|
||||||
|
describe("the interlock releases a failed attempt", () => {
|
||||||
|
test("a retryable failure before the broadcast leaves the approval usable", async () => {
|
||||||
|
let failNext = true;
|
||||||
|
const bg = loadBackground({
|
||||||
|
loadState: async () => {
|
||||||
|
if (failNext) {
|
||||||
|
failNext = false;
|
||||||
|
throw new Error("storage unavailable");
|
||||||
|
}
|
||||||
|
},
|
||||||
|
});
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const first = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(bg.broadcastTransaction).not.toHaveBeenCalled();
|
||||||
|
expect(first.sendResponse).toHaveBeenCalledWith(
|
||||||
|
expect.objectContaining({ retryable: true }),
|
||||||
|
);
|
||||||
|
|
||||||
|
bg.broadcastTransaction.mockResolvedValue({ hash: "0xfeed" });
|
||||||
|
const retry = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
expect(retry.sendResponse).toHaveBeenCalledWith({ txHash: "0xfeed" });
|
||||||
|
expect(pending.result()).toEqual({ result: "0xfeed" });
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a mismatched artifact spends the approval outright", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
// Signed for a different recipient than the one that was approved.
|
||||||
|
const wrong = await signer.signTransaction({
|
||||||
|
...populated(7),
|
||||||
|
to: "0xdAC17F958D2ee523a2206206994597C13D831ec7",
|
||||||
|
});
|
||||||
|
const first = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: wrong,
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(first.sendResponse).toHaveBeenCalledWith(
|
||||||
|
expect.objectContaining({ retryable: false, stage: "verify" }),
|
||||||
|
);
|
||||||
|
|
||||||
|
const retry = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.broadcastTransaction).not.toHaveBeenCalled();
|
||||||
|
expect(retry.sendResponse).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The claim is what makes one approval one broadcast, so it has to hold
|
||||||
|
// against everything else that retires an approval, not just against a second
|
||||||
|
// AUTISTMASK_TX_RESPONSE. Each of these paths used to resolve the waiting
|
||||||
|
// promise 4001 while the attempt behind it ran to completion: the transaction
|
||||||
|
// reached the chain and the page was told the user rejected it, which invites
|
||||||
|
// the user to send it a second time at a fresh nonce.
|
||||||
|
describe("a claimed approval outlives every other retirement path", () => {
|
||||||
|
// The approval popup stays open across the broadcast it is waiting on, so
|
||||||
|
// a user closing an apparently-hung window needs no adversary at all.
|
||||||
|
test("closing the approval window mid-broadcast still reports the result", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
const first = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
|
||||||
|
// The user closes the window while the broadcast is still open.
|
||||||
|
bg.closeWindow(1);
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toBeNull();
|
||||||
|
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(pending.result()).toEqual({ result: "0xfeed" });
|
||||||
|
expect(first.sendResponse).toHaveBeenCalledWith({ txHash: "0xfeed" });
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("switching the active address mid-broadcast still reports the result", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
|
||||||
|
// The user switches account in the toolbar popup, which rejects and
|
||||||
|
// force-closes every pending approval.
|
||||||
|
bg.send(
|
||||||
|
{ type: "AUTISTMASK_ACTIVE_CHANGED" },
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toBeNull();
|
||||||
|
// The window an in-flight attempt reports into is left standing too.
|
||||||
|
expect(bg.removed).toEqual([]);
|
||||||
|
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(pending.result()).toEqual({ result: "0xfeed" });
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a reject arriving mid-broadcast is refused, not honoured", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
const reject = bg.send(
|
||||||
|
{ type: "AUTISTMASK_TX_RESPONSE", id, approved: false },
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toBeNull();
|
||||||
|
expect(reject.sendResponse).toHaveBeenCalledWith(
|
||||||
|
expect.objectContaining({
|
||||||
|
retryable: false,
|
||||||
|
stage: "broadcast",
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(pending.result()).toEqual({ result: "0xfeed" });
|
||||||
|
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The refusals above must not cost the rejection its ordinary meaning.
|
||||||
|
test("with no attempt running, closing the window still rejects", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
bg.closeWindow(1);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(pending.result()).toEqual({
|
||||||
|
error: { code: 4001, message: "User rejected the request." },
|
||||||
|
});
|
||||||
|
expect(bg.broadcastTransaction).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("with no attempt running, an active-address switch still rejects and closes", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
bg.send(
|
||||||
|
{ type: "AUTISTMASK_ACTIVE_CHANGED" },
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(pending.result()).toEqual({
|
||||||
|
error: { code: 4001, message: "User rejected the request." },
|
||||||
|
});
|
||||||
|
expect(bg.removed).toEqual([1]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// A sign approval held by a running verification is the same shape, and
|
||||||
|
// the refusal must not tell the user to start again from the site while
|
||||||
|
// the first attempt may still hand back a signature.
|
||||||
|
test("a reject during a sign attempt is refused with the in-flight stage", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const inFlight = deferred();
|
||||||
|
bg.broadcastTransaction.mockReturnValue(inFlight.promise);
|
||||||
|
bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
const reject = bg.send(
|
||||||
|
{ type: "AUTISTMASK_SIGN_RESPONSE", id, approved: false },
|
||||||
|
{ url: bg.fromPopup.url },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
expect(reject.sendResponse).toHaveBeenCalledWith(
|
||||||
|
expect.objectContaining({ retryable: false, stage: "inflight" }),
|
||||||
|
);
|
||||||
|
|
||||||
|
inFlight.resolve({ hash: "0xfeed" });
|
||||||
|
await settle();
|
||||||
|
expect(pending.result()).toEqual({ result: "0xfeed" });
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("popup-only messages", () => {
|
||||||
|
test("a page sender cannot answer an approval", async () => {
|
||||||
|
const bg = loadBackground();
|
||||||
|
const pending = bg.requestTx();
|
||||||
|
await settle();
|
||||||
|
const id = pending.id();
|
||||||
|
|
||||||
|
const spoof = bg.send(
|
||||||
|
{
|
||||||
|
type: "AUTISTMASK_TX_RESPONSE",
|
||||||
|
id,
|
||||||
|
approved: true,
|
||||||
|
rawSignedTx: await signedAtNonce(7),
|
||||||
|
},
|
||||||
|
{ url: ORIGIN + "/index.html" },
|
||||||
|
);
|
||||||
|
await settle();
|
||||||
|
|
||||||
|
expect(bg.broadcastTransaction).not.toHaveBeenCalled();
|
||||||
|
expect(spoof.sendResponse).toHaveBeenCalledWith({
|
||||||
|
error: "Unauthorized sender",
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,4 +1,6 @@
|
|||||||
const {
|
const {
|
||||||
|
DEBUG,
|
||||||
|
BUILD_DEBUG_MARKER,
|
||||||
ETHEREUM_MAINNET_CHAIN_ID,
|
ETHEREUM_MAINNET_CHAIN_ID,
|
||||||
DEFAULT_RPC_URL,
|
DEFAULT_RPC_URL,
|
||||||
BIP44_ETH_PATH,
|
BIP44_ETH_PATH,
|
||||||
@@ -19,6 +21,24 @@ describe("constants", () => {
|
|||||||
expect(BIP44_ETH_PATH).toBe("m/44'/60'/0'/0");
|
expect(BIP44_ETH_PATH).toBe("m/44'/60'/0'/0");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// This does not replace script/verify-build, which is the only thing that
|
||||||
|
// can see the compiled DEBUG state of a real bundle. It pins the source
|
||||||
|
// invariant that the marker tracks DEBUG, so the two cannot be edited
|
||||||
|
// apart and leave verify-build asserting something that is no longer the
|
||||||
|
// flag the code branches on.
|
||||||
|
test("build debug marker is derived from DEBUG", () => {
|
||||||
|
expect(BUILD_DEBUG_MARKER).toBe(
|
||||||
|
DEBUG ? "autistmask-build-debug=on" : "autistmask-build-debug=off",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Outside a bundle there is no __BUILD_DEBUG__ define, and the fallback
|
||||||
|
// must be the safe one.
|
||||||
|
test("DEBUG is off when loaded outside a bundle", () => {
|
||||||
|
expect(DEBUG).toBe(false);
|
||||||
|
expect(BUILD_DEBUG_MARKER).toBe("autistmask-build-debug=off");
|
||||||
|
});
|
||||||
|
|
||||||
test("exports ERC-20 ABI with expected functions", () => {
|
test("exports ERC-20 ABI with expected functions", () => {
|
||||||
expect(Array.isArray(ERC20_ABI)).toBe(true);
|
expect(Array.isArray(ERC20_ABI)).toBe(true);
|
||||||
expect(ERC20_ABI.length).toBeGreaterThan(0);
|
expect(ERC20_ABI.length).toBeGreaterThan(0);
|
||||||
|
|||||||
158
tests/deleteAddress.test.js
Normal file
158
tests/deleteAddress.test.js
Normal file
@@ -0,0 +1,158 @@
|
|||||||
|
// Tests for the copy on the address-removal confirmation (issue #162).
|
||||||
|
//
|
||||||
|
// The screen's whole job is to warn before a destructive-looking action, so
|
||||||
|
// the copy is the substance and is tested as such. Two things it must not
|
||||||
|
// get wrong: what it takes to get the address back — the app refuses both
|
||||||
|
// obvious routes — and what counts as holding something, which is any
|
||||||
|
// ERC-20 as well as ETH, at any size, including a balance that rounds to
|
||||||
|
// zero at the four decimals the balance lines render. The DOM behaviour
|
||||||
|
// around them is driven against the real popup by tests/e2e/run.js.
|
||||||
|
|
||||||
|
// helpers.js pulls in state.js, which reads chrome.storage.local at load.
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const { addressHoldsFunds } = require("../src/popup/views/helpers");
|
||||||
|
const {
|
||||||
|
recoveryPathText,
|
||||||
|
balanceWarningHtml,
|
||||||
|
} = require("../src/popup/views/deleteAddress");
|
||||||
|
const { prices, clearPrices } = require("../src/shared/prices");
|
||||||
|
|
||||||
|
const USDC = "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48";
|
||||||
|
|
||||||
|
const EMPTY = { address: "0x1", balance: "0.0000", tokenBalances: [] };
|
||||||
|
const ETH_ONLY = { address: "0x1", balance: "1.5", tokenBalances: [] };
|
||||||
|
const DUST = { address: "0x1", balance: "0.00001", tokenBalances: [] };
|
||||||
|
const TOKEN_ONLY = {
|
||||||
|
address: "0x1",
|
||||||
|
balance: "0.0000",
|
||||||
|
tokenBalances: [{ address: USDC, symbol: "USDC", balance: "2500.0" }],
|
||||||
|
};
|
||||||
|
const ZERO_TOKEN = {
|
||||||
|
address: "0x1",
|
||||||
|
balance: "0",
|
||||||
|
tokenBalances: [{ address: USDC, symbol: "USDC", balance: "0" }],
|
||||||
|
};
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
clearPrices();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("what the screen says it takes to get the address back", () => {
|
||||||
|
// The screen used to promise the address "can be brought back at any
|
||||||
|
// time by importing this wallet's recovery phrase again". That import is
|
||||||
|
// refused as a duplicate for as long as the wallet is present, which it
|
||||||
|
// always is here — a wallet never gives up its last address.
|
||||||
|
test("it does not promise a re-import while the wallet is here", () => {
|
||||||
|
const text = recoveryPathText({ type: "hd" });
|
||||||
|
expect(text).not.toMatch(/at any time/);
|
||||||
|
expect(text).toContain("is refused while this wallet is still here");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("it names deleting the whole wallet as the route back", () => {
|
||||||
|
expect(recoveryPathText({ type: "hd" })).toContain(
|
||||||
|
"delete the whole wallet in Settings",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The scan after a re-import finds used addresses only, so an address
|
||||||
|
// that never saw a transaction does not come back at all. Saying so is
|
||||||
|
// the difference between a warning and a false reassurance.
|
||||||
|
test("it states the limit: only on-chain activity is found", () => {
|
||||||
|
const text = recoveryPathText({ type: "hd" });
|
||||||
|
expect(text).toContain("only finds addresses that have on-chain");
|
||||||
|
expect(text).toContain("never been used is not found by it");
|
||||||
|
});
|
||||||
|
|
||||||
|
// The screen is offered on xprv wallets too, and an xprv wallet holds no
|
||||||
|
// recovery phrase — telling its owner to import one would send them
|
||||||
|
// looking for words that do not exist.
|
||||||
|
test("an xprv wallet is told about its extended private key", () => {
|
||||||
|
const text = recoveryPathText({ type: "xprv" });
|
||||||
|
expect(text).toContain("extended private key");
|
||||||
|
expect(text).not.toContain("recovery phrase");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an HD wallet is told about its recovery phrase", () => {
|
||||||
|
const text = recoveryPathText({ type: "hd" });
|
||||||
|
expect(text).toContain("recovery phrase");
|
||||||
|
expect(text).not.toContain("extended private key");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("whether an address holds anything", () => {
|
||||||
|
test("ETH counts", () => {
|
||||||
|
expect(addressHoldsFunds(ETH_ONLY)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The case that decides the screen: no ETH at all, and $2500 of a
|
||||||
|
// stablecoin sitting at the address.
|
||||||
|
test("an ERC-20 balance counts even with no ETH", () => {
|
||||||
|
expect(addressHoldsFunds(TOKEN_ONLY)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// 0.00001 ETH renders as "0.0000" at four decimals. It is still money.
|
||||||
|
test("an ETH balance below the displayed precision counts", () => {
|
||||||
|
expect(addressHoldsFunds(DUST)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an address holding nothing does not", () => {
|
||||||
|
expect(addressHoldsFunds(EMPTY)).toBe(false);
|
||||||
|
expect(addressHoldsFunds(ZERO_TOKEN)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a missing address or missing fields do not", () => {
|
||||||
|
expect(addressHoldsFunds(undefined)).toBe(false);
|
||||||
|
expect(addressHoldsFunds({ address: "0x1" })).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the balance warning on the removal confirmation", () => {
|
||||||
|
test("an address holding nothing gets a blank line, not a warning", () => {
|
||||||
|
expect(balanceWarningHtml(EMPTY)).toBe(" ");
|
||||||
|
expect(balanceWarningHtml(ZERO_TOKEN)).toBe(" ");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an ERC-20-only address is warned about, and its token listed", () => {
|
||||||
|
const html = balanceWarningHtml(TOKEN_ONLY);
|
||||||
|
expect(html).toContain("This address holds a balance.");
|
||||||
|
expect(html).toContain("does not move or spend anything");
|
||||||
|
expect(html).toContain("USDC");
|
||||||
|
expect(html).toContain("2500.0000");
|
||||||
|
});
|
||||||
|
|
||||||
|
// The rendered line says 0.0000 for this address — that is the display
|
||||||
|
// format, shared with Home and AddressDetail — and the warning is shown
|
||||||
|
// all the same, because the balance is not zero.
|
||||||
|
test("an ETH balance that renders as 0.0000 is warned about", () => {
|
||||||
|
const html = balanceWarningHtml(DUST);
|
||||||
|
expect(html).toContain("This address holds a balance.");
|
||||||
|
expect(html).toContain("<span>0.0000</span>");
|
||||||
|
});
|
||||||
|
|
||||||
|
// The sentence must not assert an amount, because any amount it could
|
||||||
|
// assert has been rounded: "This address holds 0.0000 ETH." is what the
|
||||||
|
// rounded form produces for an address that holds real money.
|
||||||
|
test("the warning sentence asserts no rounded amount", () => {
|
||||||
|
for (const addr of [DUST, ETH_ONLY, TOKEN_ONLY]) {
|
||||||
|
expect(balanceWarningHtml(addr)).not.toMatch(
|
||||||
|
/holds [\d.]+ (ETH|USDC)/,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the USD total is shown when prices are known", () => {
|
||||||
|
prices.ETH = 2000;
|
||||||
|
prices.USDC = 1;
|
||||||
|
expect(balanceWarningHtml(TOKEN_ONLY)).toContain("Total: $2,500.00");
|
||||||
|
expect(balanceWarningHtml(ETH_ONLY)).toContain("Total: $3,000.00");
|
||||||
|
});
|
||||||
|
|
||||||
|
// getAddressValueUsd() returns null on testnet and before the first
|
||||||
|
// price fetch. A "Total: $0.00" there would be a lie about the holdings.
|
||||||
|
test("no USD total is shown when prices are not known", () => {
|
||||||
|
expect(balanceWarningHtml(TOKEN_ONLY)).not.toContain("Total:");
|
||||||
|
});
|
||||||
|
});
|
||||||
243
tests/dustThreshold.test.js
Normal file
243
tests/dustThreshold.test.js
Normal file
@@ -0,0 +1,243 @@
|
|||||||
|
// Tests for the dust threshold field in Settings (issue #233).
|
||||||
|
//
|
||||||
|
// Two halves: what the parse accepts, and what the settings view does with a
|
||||||
|
// rejection. The view half runs against the real change handler with the DOM
|
||||||
|
// helpers stubbed out, because the bug was not in the parse — it was that a
|
||||||
|
// rejection said nothing.
|
||||||
|
|
||||||
|
const {
|
||||||
|
DUST_THRESHOLD_MESSAGE,
|
||||||
|
parseDustThresholdGwei,
|
||||||
|
} = require("../src/popup/dustThreshold");
|
||||||
|
|
||||||
|
describe("parsing the dust threshold", () => {
|
||||||
|
test("accepts a whole number of gwei", () => {
|
||||||
|
expect(parseDustThresholdGwei("100000")).toBe(100000);
|
||||||
|
expect(parseDustThresholdGwei("1")).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Zero is a real setting, not an empty field: it hides nothing.
|
||||||
|
test("accepts zero", () => {
|
||||||
|
expect(parseDustThresholdGwei("0")).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("accepts surrounding whitespace", () => {
|
||||||
|
expect(parseDustThresholdGwei(" 250 ")).toBe(250);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("rejects an empty field", () => {
|
||||||
|
expect(parseDustThresholdGwei("")).toBe(null);
|
||||||
|
expect(parseDustThresholdGwei(" ")).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("rejects a negative threshold", () => {
|
||||||
|
expect(parseDustThresholdGwei("-1")).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
// parseInt used to read this as 1, which is not what was typed.
|
||||||
|
test("rejects a fractional value", () => {
|
||||||
|
expect(parseDustThresholdGwei("1.5")).toBe(null);
|
||||||
|
expect(parseDustThresholdGwei("1.0")).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
// parseInt used to read this as 100. The unit is printed beside the
|
||||||
|
// field already.
|
||||||
|
test("rejects a value carrying its unit", () => {
|
||||||
|
expect(parseDustThresholdGwei("100 gwei")).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Number() reads this as 16. Storing 16 for a field that was told to
|
||||||
|
// want a whole number of gwei would be the same silent substitution the
|
||||||
|
// message exists to end.
|
||||||
|
test("rejects hex notation", () => {
|
||||||
|
expect(parseDustThresholdGwei("0x10")).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Number() reads this as 1000.
|
||||||
|
test("rejects exponent notation", () => {
|
||||||
|
expect(parseDustThresholdGwei("1e3")).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("rejects other non-numeric input", () => {
|
||||||
|
expect(parseDustThresholdGwei("lots")).toBe(null);
|
||||||
|
expect(parseDustThresholdGwei("+5")).toBe(null);
|
||||||
|
expect(parseDustThresholdGwei("Infinity")).toBe(null);
|
||||||
|
expect(parseDustThresholdGwei(undefined)).toBe(null);
|
||||||
|
expect(parseDustThresholdGwei(5)).toBe(null);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Beyond 2^53 the digits would round on the way in, so the stored
|
||||||
|
// threshold would not be the one typed.
|
||||||
|
test("rejects a value too large to hold exactly", () => {
|
||||||
|
expect(parseDustThresholdGwei("9007199254740993")).toBe(null);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the rejection message", () => {
|
||||||
|
// README, Language & Labeling: error messages are full sentences.
|
||||||
|
test("is a full sentence naming the constraint", () => {
|
||||||
|
expect(DUST_THRESHOLD_MESSAGE).toMatch(/^[A-Z].*\.$/);
|
||||||
|
expect(DUST_THRESHOLD_MESSAGE).toContain("whole number of gwei");
|
||||||
|
expect(DUST_THRESHOLD_MESSAGE).toContain("zero or greater");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the flash line the message is shown in", () => {
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
|
||||||
|
const POPUP_HTML = fs.readFileSync(
|
||||||
|
path.join(__dirname, "..", "src", "popup", "index.html"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
|
||||||
|
// This asserts only that the reservation exists in the markup. It does
|
||||||
|
// NOT and CANNOT assert that the message fits inside it: jest runs on
|
||||||
|
// the node environment here, with no layout engine, so every rendered
|
||||||
|
// height is zero. An earlier version of this block claimed to pin the
|
||||||
|
// No Layout Shift policy with this regex, and it passed at any message
|
||||||
|
// length, including one that wrapped to two lines and pushed the
|
||||||
|
// settings view down 12px.
|
||||||
|
//
|
||||||
|
// The assertion that actually measures — empty line vs. the message,
|
||||||
|
// real Chromium, documented 360x600 popup — is
|
||||||
|
// "a rejected dust threshold shifts no layout (#233)" in
|
||||||
|
// tests/e2e/run.js, run by make test-e2e. It is not in make check
|
||||||
|
// because REPO_POLICIES.md caps make test at 20 seconds and a browser
|
||||||
|
// suite does not fit; run it before changing the wording.
|
||||||
|
test("reserves its height in the markup", () => {
|
||||||
|
const flashLine = POPUP_HTML.match(
|
||||||
|
/<div\s+id="flash-msg"\s+class="([^"]*)"/,
|
||||||
|
);
|
||||||
|
expect(flashLine).not.toBeNull();
|
||||||
|
expect(flashLine[1]).toMatch(/min-h-\[/);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the settings view on a change to the field", () => {
|
||||||
|
let elements;
|
||||||
|
let flashes;
|
||||||
|
let saves;
|
||||||
|
let state;
|
||||||
|
|
||||||
|
// A stand-in for one DOM node: enough of an element for init() to set
|
||||||
|
// properties on it and hang listeners off it.
|
||||||
|
function fakeElement() {
|
||||||
|
return {
|
||||||
|
value: "",
|
||||||
|
checked: false,
|
||||||
|
textContent: "",
|
||||||
|
href: "",
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
classList: { add() {}, remove() {} },
|
||||||
|
listeners: {},
|
||||||
|
addEventListener(event, handler) {
|
||||||
|
this.listeners[event] = handler;
|
||||||
|
},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function loadSettingsView() {
|
||||||
|
elements = {};
|
||||||
|
flashes = [];
|
||||||
|
saves = 0;
|
||||||
|
|
||||||
|
jest.resetModules();
|
||||||
|
|
||||||
|
jest.doMock("../src/popup/views/helpers", () => ({
|
||||||
|
$: (id) => (elements[id] ||= fakeElement()),
|
||||||
|
showView: () => {},
|
||||||
|
updateDebugBanner: () => {},
|
||||||
|
showFlash: (msg) => flashes.push(msg),
|
||||||
|
escapeHtml: (s) => s,
|
||||||
|
flashCopyFeedback: () => {},
|
||||||
|
goBack: () => {},
|
||||||
|
pushCurrentView: () => {},
|
||||||
|
onViewLeave: () => {},
|
||||||
|
VIEWS: [],
|
||||||
|
}));
|
||||||
|
|
||||||
|
state = require("../src/shared/state").state;
|
||||||
|
state.dustThresholdGwei = 100000;
|
||||||
|
|
||||||
|
const settings = require("../src/popup/views/settings");
|
||||||
|
settings.init({});
|
||||||
|
return elements["settings-dust-threshold"];
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
globalThis.chrome = {
|
||||||
|
runtime: { sendMessage: () => {} },
|
||||||
|
storage: {
|
||||||
|
local: {
|
||||||
|
get: async () => ({}),
|
||||||
|
set: async () => {
|
||||||
|
saves++;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
jest.dontMock("../src/popup/views/helpers");
|
||||||
|
delete globalThis.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
async function change(field, typed) {
|
||||||
|
field.value = typed;
|
||||||
|
await field.listeners.change();
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a valid value is stored and says nothing", async () => {
|
||||||
|
const field = loadSettingsView();
|
||||||
|
|
||||||
|
await change(field, "250");
|
||||||
|
|
||||||
|
expect(state.dustThresholdGwei).toBe(250);
|
||||||
|
expect(field.value).toBe(250);
|
||||||
|
expect(flashes).toEqual([]);
|
||||||
|
expect(saves).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a rejected value shows the message and is not stored", async () => {
|
||||||
|
const field = loadSettingsView();
|
||||||
|
|
||||||
|
await change(field, "1.5");
|
||||||
|
|
||||||
|
expect(state.dustThresholdGwei).toBe(100000);
|
||||||
|
expect(flashes).toEqual([DUST_THRESHOLD_MESSAGE]);
|
||||||
|
expect(saves).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The snap-back is the behaviour the message explains, so it stays.
|
||||||
|
test("a rejected value still resyncs the field to what is stored", async () => {
|
||||||
|
const field = loadSettingsView();
|
||||||
|
|
||||||
|
await change(field, "100 gwei");
|
||||||
|
|
||||||
|
expect(field.value).toBe(100000);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("every rejected notation gets the same one message", async () => {
|
||||||
|
for (const typed of ["", "-1", "1.5", "100 gwei", "0x10", "1e3"]) {
|
||||||
|
const field = loadSettingsView();
|
||||||
|
|
||||||
|
await change(field, typed);
|
||||||
|
|
||||||
|
expect(flashes).toEqual([DUST_THRESHOLD_MESSAGE]);
|
||||||
|
expect(state.dustThresholdGwei).toBe(100000);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("zero is accepted, not treated as an empty field", async () => {
|
||||||
|
const field = loadSettingsView();
|
||||||
|
|
||||||
|
await change(field, "0");
|
||||||
|
|
||||||
|
expect(state.dustThresholdGwei).toBe(0);
|
||||||
|
expect(flashes).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
349
tests/e2e/harness.js
Normal file
349
tests/e2e/harness.js
Normal file
@@ -0,0 +1,349 @@
|
|||||||
|
// End-to-end harness: launches a real Chromium with the unpacked MV3
|
||||||
|
// build loaded, collects every uncaught page error and console.error, and
|
||||||
|
// exposes the popup flows the tests drive.
|
||||||
|
//
|
||||||
|
// This runs inside the pinned Playwright container; see script/test-e2e.
|
||||||
|
// It is deliberately NOT part of make check — REPO_POLICIES.md caps
|
||||||
|
// make test at 20 seconds and a browser suite does not fit.
|
||||||
|
|
||||||
|
"use strict";
|
||||||
|
|
||||||
|
const fs = require("fs");
|
||||||
|
const os = require("os");
|
||||||
|
const path = require("path");
|
||||||
|
|
||||||
|
const { chromium } = require("playwright-core");
|
||||||
|
const { installNetworkStubs } = require("./network");
|
||||||
|
|
||||||
|
const REPO_ROOT = path.resolve(__dirname, "..", "..");
|
||||||
|
const EXT_PATH = path.join(REPO_ROOT, "dist", "chrome");
|
||||||
|
|
||||||
|
// Page errors that are known, tracked, and deliberately tolerated. Every
|
||||||
|
// entry must name the issue that will remove it. This list is the one
|
||||||
|
// concession in an otherwise zero-tolerance policy: an uncaught error is
|
||||||
|
// how this harness caught issue #150 in the first place.
|
||||||
|
//
|
||||||
|
// Empty, and worth keeping that way. Its only entry was the WASM
|
||||||
|
// CompileError libsodium provoked on every popup load, deleted with #182
|
||||||
|
// when both manifests started allowing WASM; the run that used to need it
|
||||||
|
// is now the run that proves the fix.
|
||||||
|
const ALLOWED_ERRORS = [];
|
||||||
|
|
||||||
|
function isAllowed(text) {
|
||||||
|
return ALLOWED_ERRORS.some((a) => a.pattern.test(text));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Collects every uncaught page error, console.error and unstubbed
|
||||||
|
// request, and hands each one to exactly one reporter.
|
||||||
|
//
|
||||||
|
// This deliberately has NO window API. It used to expose mark()/since()
|
||||||
|
// so a test could ask for "the errors since I started", and that shape
|
||||||
|
// produced a green run that proved nothing twice over: first the mark
|
||||||
|
// started after test 1, so everything recorded during launch was
|
||||||
|
// discarded, then the tail after the final test was never read at all. In
|
||||||
|
// both cases a record fell outside somebody's window and vanished, which
|
||||||
|
// is the precise failure this harness exists to prevent.
|
||||||
|
//
|
||||||
|
// So there is no window left to fall outside of. take() is the only
|
||||||
|
// reader and it always takes everything outstanding, so successive takes
|
||||||
|
// partition the entire record stream with no gaps, and the runner turns
|
||||||
|
// every record it reads into a failure.
|
||||||
|
//
|
||||||
|
// Observation ends when the browser context is closed. Nothing records
|
||||||
|
// after that — the route handler and the console listeners are gone with
|
||||||
|
// the context — so there is no post-teardown phase to collect, and this
|
||||||
|
// class deliberately offers no mechanism pretending to cover one.
|
||||||
|
//
|
||||||
|
// One narrow exception exists, and it is not a mute: expect(). A test that
|
||||||
|
// drives a failure path on purpose — a refused gas estimate, say — provokes
|
||||||
|
// the console.error the code is supposed to emit, and that error is the
|
||||||
|
// behaviour under test rather than an escape. Declaring it consumes exactly
|
||||||
|
// one matching record and no more, and an expectation nothing matched fails
|
||||||
|
// its test just as an unexpected error does. So it cannot be used to
|
||||||
|
// silence anything: it can only assert that a specific error happened.
|
||||||
|
class ErrorCollector {
|
||||||
|
constructor() {
|
||||||
|
this.entries = [];
|
||||||
|
this.taken = 0;
|
||||||
|
this.expectations = [];
|
||||||
|
}
|
||||||
|
|
||||||
|
// Declare a console.error this test is about to cause deliberately.
|
||||||
|
// `label` names it in the failure message if it never arrives.
|
||||||
|
expect(label, pattern) {
|
||||||
|
this.expectations.push({ label, pattern, matched: false });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Declared expectations that nothing matched, clearing the list so each
|
||||||
|
// test starts with none outstanding.
|
||||||
|
unmatchedExpectations() {
|
||||||
|
const out = this.expectations
|
||||||
|
.filter((e) => !e.matched)
|
||||||
|
.map((e) => e.label);
|
||||||
|
this.expectations = [];
|
||||||
|
return out;
|
||||||
|
}
|
||||||
|
|
||||||
|
record(kind, text) {
|
||||||
|
const line = kind + ": " + String(text).split("\n")[0];
|
||||||
|
if (isAllowed(line)) return;
|
||||||
|
const expected = this.expectations.find(
|
||||||
|
(e) => !e.matched && e.pattern.test(line),
|
||||||
|
);
|
||||||
|
if (expected) {
|
||||||
|
expected.matched = true;
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
this.entries.push(line);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Everything recorded since the previous take(). Never yields a
|
||||||
|
// record twice and never skips one.
|
||||||
|
take() {
|
||||||
|
const out = this.entries.slice(this.taken);
|
||||||
|
this.taken = this.entries.length;
|
||||||
|
return out;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function attachErrorListeners(ctx, errors) {
|
||||||
|
const attachPage = (page) => {
|
||||||
|
page.on("pageerror", (err) => {
|
||||||
|
errors.record("pageerror", err.message || String(err));
|
||||||
|
});
|
||||||
|
page.on("console", (msg) => {
|
||||||
|
if (msg.type() === "error") {
|
||||||
|
errors.record("console.error", msg.text());
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
|
ctx.pages().forEach(attachPage);
|
||||||
|
ctx.on("page", attachPage);
|
||||||
|
// Per-page listeners only: the context-level "weberror" event covers
|
||||||
|
// the same page exceptions and would double-report them. Playwright
|
||||||
|
// exposes no error EVENT for service workers, so an uncaught
|
||||||
|
// exception in the background worker is not visible here — everything
|
||||||
|
// this suite drives lives in the popup page. That is an error-channel
|
||||||
|
// gap only: worker NETWORK traffic is intercepted and reported like
|
||||||
|
// any other, and assertWorkerTrafficIntercepted() below fails the run
|
||||||
|
// if it ever stops being.
|
||||||
|
}
|
||||||
|
|
||||||
|
async function serviceWorker(ctx) {
|
||||||
|
const [existing] = ctx.serviceWorkers();
|
||||||
|
if (existing) return existing;
|
||||||
|
return ctx.waitForEvent("serviceworker", { timeout: 30000 });
|
||||||
|
}
|
||||||
|
|
||||||
|
// How long to wait for the background worker's first outbound request.
|
||||||
|
//
|
||||||
|
// The margin that actually decides whether this check is sound is not
|
||||||
|
// this timeout — it is whether the route handler is installed before the
|
||||||
|
// worker fetches. Measured over several runs: route installation
|
||||||
|
// completes 11-23ms after the context comes up, and the worker's
|
||||||
|
// blocklist fetch arrives 525-883ms after that, so the route wins by
|
||||||
|
// roughly 25-50x. This 30s figure is only slack for a loaded machine on
|
||||||
|
// top of that; losing the race fails the run rather than passing it
|
||||||
|
// quietly, which was verified by forcing a 3s delay before route
|
||||||
|
// installation.
|
||||||
|
const WORKER_TRAFFIC_TIMEOUT_MS = 30000;
|
||||||
|
|
||||||
|
// ctx.route() only sees service-worker requests when Playwright runs with
|
||||||
|
// PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1, which script/test-e2e
|
||||||
|
// sets. Without it the worker's traffic — notably the phishing blocklist
|
||||||
|
// fetch src/background/index.js issues at startup — goes to the real
|
||||||
|
// internet, and nothing says so, because src/shared/phishingDomains.js
|
||||||
|
// swallows fetch failures. A harness whose isolation can lapse in silence
|
||||||
|
// is worthless, so this does not take the flag on trust: the background
|
||||||
|
// worker's own startup fetch has to show up in the route handler, or the
|
||||||
|
// suite refuses to run.
|
||||||
|
//
|
||||||
|
// Deliberately NOT a synthetic probe fetched through worker.evaluate():
|
||||||
|
// evaluating in an extension worker this early kills it (the call fails
|
||||||
|
// with "Target page, context or browser has been closed" and the worker
|
||||||
|
// disappears), which would break the very thing being measured. Observing
|
||||||
|
// traffic the extension already generates costs nothing and cannot
|
||||||
|
// perturb it.
|
||||||
|
async function assertWorkerTrafficIntercepted(stubs) {
|
||||||
|
const seen = await stubs.waitForServiceWorkerTraffic(
|
||||||
|
WORKER_TRAFFIC_TIMEOUT_MS,
|
||||||
|
);
|
||||||
|
if (seen) return seen;
|
||||||
|
|
||||||
|
// State the observation, not a conclusion. This fires for at least
|
||||||
|
// two quite different causes and the harness cannot tell them apart
|
||||||
|
// from here, so guessing one of them in the message sends the reader
|
||||||
|
// the wrong way.
|
||||||
|
throw new Error(
|
||||||
|
"observed no service-worker request in the route handler within " +
|
||||||
|
WORKER_TRAFFIC_TIMEOUT_MS +
|
||||||
|
"ms. Under working interception the background worker's " +
|
||||||
|
"startup blocklist fetch (src/background/index.js) reaches the " +
|
||||||
|
"handler about half a second after the route is installed. " +
|
||||||
|
"Two causes are plausible and this check cannot distinguish " +
|
||||||
|
"them: (1) service-worker interception is not in effect, so " +
|
||||||
|
"that traffic went to the real internet unobserved — the suite " +
|
||||||
|
"must be run through script/test-e2e, which sets " +
|
||||||
|
"PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1, and a " +
|
||||||
|
"Playwright upgrade may have dropped or renamed that flag; " +
|
||||||
|
"(2) no worker request was made in the first place — the route " +
|
||||||
|
"lost the startup race, or the worker no longer fetches at " +
|
||||||
|
"startup, in which case this check needs a new anchor because " +
|
||||||
|
"there is no longer any worker traffic to observe. Either way " +
|
||||||
|
"the fix is a replacement mechanism or an honest downgrade of " +
|
||||||
|
"the isolation claims in tests/e2e/network.js and README.md — " +
|
||||||
|
"not deleting this check",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function launch(routeOpts) {
|
||||||
|
if (!fs.existsSync(path.join(EXT_PATH, "manifest.json"))) {
|
||||||
|
throw new Error(
|
||||||
|
"no unpacked build at " +
|
||||||
|
EXT_PATH +
|
||||||
|
" — run make build before the e2e suite",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const userDir = fs.mkdtempSync(path.join(os.tmpdir(), "autistmask-e2e-"));
|
||||||
|
const ctx = await chromium.launchPersistentContext(userDir, {
|
||||||
|
// channel: "chromium" is load-bearing. The default headless mode
|
||||||
|
// uses the headless shell, which silently refuses to load
|
||||||
|
// extensions: there is no error at all, the service worker simply
|
||||||
|
// never appears. This cost real debugging time once already.
|
||||||
|
channel: "chromium",
|
||||||
|
headless: true,
|
||||||
|
args: [
|
||||||
|
"--disable-extensions-except=" + EXT_PATH,
|
||||||
|
"--load-extension=" + EXT_PATH,
|
||||||
|
// The container runs unprivileged; Chrome's sandbox needs
|
||||||
|
// capabilities the harness deliberately does not grant it.
|
||||||
|
"--no-sandbox",
|
||||||
|
// Belt to the interception braces: nothing that slips past
|
||||||
|
// the route handler can resolve a name, so a request that
|
||||||
|
// escapes cannot actually reach the internet. Detection is
|
||||||
|
// still assertWorkerTrafficIntercepted()'s job — this only
|
||||||
|
// bounds the damage while a gap goes unnoticed. Playwright
|
||||||
|
// fulfils routed requests without touching the resolver, and
|
||||||
|
// it drives the browser over a pipe, so neither is affected.
|
||||||
|
"--host-resolver-rules=MAP * ~NOTFOUND",
|
||||||
|
],
|
||||||
|
});
|
||||||
|
|
||||||
|
const cleanup = async () => {
|
||||||
|
await ctx.close().catch(() => {});
|
||||||
|
fs.rmSync(userDir, { recursive: true, force: true });
|
||||||
|
};
|
||||||
|
|
||||||
|
try {
|
||||||
|
const errors = new ErrorCollector();
|
||||||
|
attachErrorListeners(ctx, errors);
|
||||||
|
routeOpts.report = (text) => errors.record("network", text);
|
||||||
|
const stubs = await installNetworkStubs(ctx, routeOpts);
|
||||||
|
|
||||||
|
await assertWorkerTrafficIntercepted(stubs);
|
||||||
|
|
||||||
|
// The extension id is derived from the unpacked path, so it
|
||||||
|
// changes and must never be hardcoded. It is the host part of the
|
||||||
|
// service worker URL.
|
||||||
|
const sw = await serviceWorker(ctx);
|
||||||
|
const id = new URL(sw.url()).host;
|
||||||
|
|
||||||
|
return {
|
||||||
|
ctx,
|
||||||
|
errors,
|
||||||
|
extensionId: id,
|
||||||
|
popupUrl: "chrome-extension://" + id + "/src/popup/index.html",
|
||||||
|
close: cleanup,
|
||||||
|
};
|
||||||
|
} catch (e) {
|
||||||
|
// Anything that fails after the browser is up has to tear it down
|
||||||
|
// on the way out: an orphaned context keeps node alive forever,
|
||||||
|
// turning a clean failure into a hung run.
|
||||||
|
await cleanup();
|
||||||
|
throw e;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------- flows
|
||||||
|
|
||||||
|
const PASSWORD = "e2e-harness-password";
|
||||||
|
|
||||||
|
async function visible(page, selector, timeout = 15000) {
|
||||||
|
await page.waitForSelector(selector, { state: "visible", timeout });
|
||||||
|
}
|
||||||
|
|
||||||
|
// An empty WebAssembly module: magic number and version header, no
|
||||||
|
// sections. Compiling it in the popup asks the one question that decides
|
||||||
|
// libsodium's backend — may this realm compile WebAssembly — of the real
|
||||||
|
// page under the real shipped manifest, which is the only place the
|
||||||
|
// answer can be observed. Kept independent of src/shared/vault.js on
|
||||||
|
// purpose: a bundle asked to grade itself proves less than an outside
|
||||||
|
// observation of the same realm.
|
||||||
|
const EMPTY_WASM_MODULE = [0x00, 0x61, 0x73, 0x6d, 0x01, 0x00, 0x00, 0x00];
|
||||||
|
|
||||||
|
async function pageCompilesWasm(page) {
|
||||||
|
return page.evaluate(async (bytes) => {
|
||||||
|
try {
|
||||||
|
await WebAssembly.compile(new Uint8Array(bytes));
|
||||||
|
return true;
|
||||||
|
} catch (_) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}, EMPTY_WASM_MODULE);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function openPopup(ctx, popupUrl) {
|
||||||
|
const page = await ctx.newPage();
|
||||||
|
await page.goto(popupUrl);
|
||||||
|
return page;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Full wallet creation through the real UI: BIP-39 generation, libsodium
|
||||||
|
// vault encryption and extension storage persistence, for real.
|
||||||
|
//
|
||||||
|
// Returns the recovery phrase it generated. Tests that assert on a secret
|
||||||
|
// need the real value — checking for "some 12 words" would pass against the
|
||||||
|
// wrong wallet's phrase, and checking for nothing at all would pass against
|
||||||
|
// a screen that shows the phrase it was supposed to hide.
|
||||||
|
async function createWallet(page) {
|
||||||
|
await page.click("#btn-welcome-add");
|
||||||
|
await visible(page, "#view-add-wallet");
|
||||||
|
await page.click("#btn-generate-phrase");
|
||||||
|
await page.waitForFunction(() => {
|
||||||
|
const el = document.getElementById("wallet-mnemonic");
|
||||||
|
return el && el.value.trim().split(/\s+/).length >= 12;
|
||||||
|
});
|
||||||
|
const phrase = (await page.inputValue("#wallet-mnemonic")).trim();
|
||||||
|
await page.fill("#add-wallet-password", PASSWORD);
|
||||||
|
await page.fill("#add-wallet-password-confirm", PASSWORD);
|
||||||
|
await page.click("#btn-add-wallet-confirm");
|
||||||
|
await visible(page, "#view-main", 60000);
|
||||||
|
return phrase;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Reach the address detail screen of the FIRST address of the first wallet,
|
||||||
|
// from wherever the popup restored to. Clicking .address-row does not open
|
||||||
|
// it; the [info] button does.
|
||||||
|
//
|
||||||
|
// .first() rather than a bare selector because the suite adds a second
|
||||||
|
// wallet partway through, and every later test would otherwise die in
|
||||||
|
// Playwright's strict mode rather than on an assertion.
|
||||||
|
async function openAddressDetail(page) {
|
||||||
|
const onAddress = await page.isVisible("#view-address");
|
||||||
|
if (!onAddress) {
|
||||||
|
await visible(page, "#view-main");
|
||||||
|
await page.locator("#wallet-list .btn-addr-info").first().click();
|
||||||
|
}
|
||||||
|
await visible(page, "#view-address");
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
PASSWORD,
|
||||||
|
createWallet,
|
||||||
|
launch,
|
||||||
|
openAddressDetail,
|
||||||
|
openPopup,
|
||||||
|
pageCompilesWasm,
|
||||||
|
visible,
|
||||||
|
};
|
||||||
507
tests/e2e/network.js
Normal file
507
tests/e2e/network.js
Normal file
@@ -0,0 +1,507 @@
|
|||||||
|
// Browser-level network interception for the end-to-end suite.
|
||||||
|
//
|
||||||
|
// Every http(s) request the extension makes — from the popup page AND
|
||||||
|
// from the MV3 background service worker — is fulfilled from these
|
||||||
|
// fixtures, so the suite is deterministic and runs entirely offline. The
|
||||||
|
// probe that motivated this harness (see issue #181) observed live calls
|
||||||
|
// to Blockscout returning 401 inside the container, which would make any
|
||||||
|
// assertion about rendered transaction data worthless.
|
||||||
|
//
|
||||||
|
// Service-worker coverage is not free: ctx.route() only sees worker
|
||||||
|
// traffic when PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1 is set in
|
||||||
|
// the environment, which script/test-e2e does. Without it the phishing
|
||||||
|
// blocklist fetch that src/background/index.js issues at worker startup
|
||||||
|
// silently reaches raw.githubusercontent.com on the open internet, and
|
||||||
|
// src/shared/phishingDomains.js swallows the failure so nothing surfaces
|
||||||
|
// it. That is not left to trust: waitForServiceWorkerTraffic() below
|
||||||
|
// backs the launch-time canary in harness.js, which fails the entire
|
||||||
|
// suite if worker requests stop being visible here.
|
||||||
|
//
|
||||||
|
// Anything not explicitly stubbed here is aborted AND reported to the
|
||||||
|
// error collector, so a newly added outbound call shows up as a test
|
||||||
|
// failure rather than as intermittent flakiness.
|
||||||
|
|
||||||
|
"use strict";
|
||||||
|
|
||||||
|
// Fictional ERC-20 used to seed the transaction-detail test. The symbol
|
||||||
|
// must not collide with any entry in src/shared/tokenList.js, or
|
||||||
|
// isSpoofedSymbol() in src/shared/transactions.js drops the transfer as a
|
||||||
|
// symbol-spoofing attempt; holders_count must be >= 1000 or the default
|
||||||
|
// hideLowHolderTokens filter drops it. Either would make the test pass
|
||||||
|
// vacuously by never rendering a row at all.
|
||||||
|
const STUB_TOKEN = {
|
||||||
|
address: "0xe2e0000000000000000000000000000000000e2e",
|
||||||
|
symbol: "E2E",
|
||||||
|
name: "End To End Test Token",
|
||||||
|
decimals: "6",
|
||||||
|
holders: "12345",
|
||||||
|
};
|
||||||
|
|
||||||
|
const STUB_COUNTERPARTY = "0xc0ffee0000000000000000000000000000c0ffee";
|
||||||
|
|
||||||
|
const STUB_TX_HASH =
|
||||||
|
"0xe2e0000000000000000000000000000000000000000000000000000000000e2e";
|
||||||
|
|
||||||
|
const STUB_BLOCK_NUMBER = 21000000;
|
||||||
|
|
||||||
|
// Fixed instant so timeAgo() output is stable across runs.
|
||||||
|
const STUB_TX_TIMESTAMP = "2026-01-02T03:04:05.000000Z";
|
||||||
|
|
||||||
|
// A 32-byte zero word. Returned for every eth_call, which is what makes
|
||||||
|
// ethers' ENS reverse lookup resolve to "no resolver set" and return null
|
||||||
|
// instead of throwing. A throw would be logged by src/shared/ens.js via
|
||||||
|
// log.errorf(), i.e. console.error, which fails the run on its own.
|
||||||
|
const ZERO_WORD = "0x" + "0".repeat(64);
|
||||||
|
|
||||||
|
function hex(value) {
|
||||||
|
return "0x" + BigInt(value).toString(16);
|
||||||
|
}
|
||||||
|
|
||||||
|
// A bigint as a 32-byte ABI word.
|
||||||
|
function word(value) {
|
||||||
|
return "0x" + BigInt(value).toString(16).padStart(64, "0");
|
||||||
|
}
|
||||||
|
|
||||||
|
// ------------------------------------------------------------ fee fixture
|
||||||
|
//
|
||||||
|
// The confirmation screen carries two different numbers for the same
|
||||||
|
// transaction and may gate on only one of them:
|
||||||
|
//
|
||||||
|
// reserve = gasLimit * maxFeePerGas — what a node requires to be
|
||||||
|
// available for a type-2 transaction, and what the spend gate
|
||||||
|
// must use.
|
||||||
|
// estimate = gasLimit * gasPrice — what the transfer is expected to
|
||||||
|
// actually cost. Display only.
|
||||||
|
//
|
||||||
|
// Issue #154 was the gate reading the smaller of the two. ethers derives
|
||||||
|
// maxFeePerGas as baseFeePerGas * 2 + maxPriorityFeePerGas, so the numbers
|
||||||
|
// below put the reserve at very nearly twice the estimate. That gap is the
|
||||||
|
// entire point of these values: it leaves room for a send that an
|
||||||
|
// estimate-based gate accepts and a reserve-based gate refuses, which is
|
||||||
|
// what lets the ConfirmTx tests tell the two apart at all. Collapse the gap
|
||||||
|
// — by dropping baseFeePerGas from the block below, say — and those tests
|
||||||
|
// go on passing while asserting nothing.
|
||||||
|
const GAS_LIMIT = 21000n;
|
||||||
|
const BASE_FEE_WEI = 100000000000n; // 100 gwei
|
||||||
|
const PRIORITY_FEE_WEI = 1000000000n; // 1 gwei
|
||||||
|
const GAS_PRICE_WEI = BASE_FEE_WEI + PRIORITY_FEE_WEI; // 101 gwei
|
||||||
|
const MAX_FEE_WEI = BASE_FEE_WEI * 2n + PRIORITY_FEE_WEI; // 201 gwei
|
||||||
|
|
||||||
|
const FEE_ESTIMATE_WEI = GAS_LIMIT * GAS_PRICE_WEI; // 0.002121 ETH
|
||||||
|
const FEE_RESERVE_WEI = GAS_LIMIT * MAX_FEE_WEI; // 0.004221 ETH
|
||||||
|
|
||||||
|
const RPC_RESULTS = {
|
||||||
|
eth_chainId: "0x1",
|
||||||
|
net_version: "1",
|
||||||
|
eth_blockNumber: "0x1406f40",
|
||||||
|
eth_getBalance: "0x0",
|
||||||
|
eth_call: ZERO_WORD,
|
||||||
|
eth_getCode: "0x",
|
||||||
|
eth_gasPrice: hex(GAS_PRICE_WEI),
|
||||||
|
eth_estimateGas: hex(GAS_LIMIT),
|
||||||
|
eth_getTransactionCount: "0x0",
|
||||||
|
eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI),
|
||||||
|
};
|
||||||
|
|
||||||
|
// The "latest" block, which ethers' getFeeData() reads baseFeePerGas from
|
||||||
|
// to derive maxFeePerGas. Without it every fee is a legacy gasPrice, the
|
||||||
|
// reserve and the estimate collapse to the same number, and the gate tests
|
||||||
|
// stop being able to distinguish them.
|
||||||
|
function latestBlock() {
|
||||||
|
return {
|
||||||
|
hash: "0x" + "11".repeat(32),
|
||||||
|
parentHash: "0x" + "22".repeat(32),
|
||||||
|
number: hex(STUB_BLOCK_NUMBER),
|
||||||
|
timestamp: hex(1767326645),
|
||||||
|
nonce: "0x0000000000000000",
|
||||||
|
difficulty: "0x0",
|
||||||
|
gasLimit: "0x1c9c380",
|
||||||
|
gasUsed: "0xf4240",
|
||||||
|
miner: STUB_COUNTERPARTY,
|
||||||
|
extraData: "0x",
|
||||||
|
baseFeePerGas: hex(BASE_FEE_WEI),
|
||||||
|
transactions: [],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// keccak("decimals()")[0:4].
|
||||||
|
const SELECTOR_DECIMALS = "0x313ce567";
|
||||||
|
|
||||||
|
// Every eth_call still answers with a zero word except decimals() on the
|
||||||
|
// stub token. ethers reads that before it can encode an ERC-20 transfer,
|
||||||
|
// and a zero there makes parseUnits() reject any fractional amount — so the
|
||||||
|
// ERC-20 confirmation path would fail its gas estimate for a reason that
|
||||||
|
// has nothing to do with what is being tested.
|
||||||
|
function ethCallResult(req) {
|
||||||
|
const call = Array.isArray(req.params) ? req.params[0] : null;
|
||||||
|
if (!call || typeof call !== "object") return ZERO_WORD;
|
||||||
|
const data = String(call.data || call.input || "").toLowerCase();
|
||||||
|
const to = String(call.to || "").toLowerCase();
|
||||||
|
if (data.startsWith(SELECTOR_DECIMALS) && to === STUB_TOKEN.address) {
|
||||||
|
return word(STUB_TOKEN.decimals);
|
||||||
|
}
|
||||||
|
return ZERO_WORD;
|
||||||
|
}
|
||||||
|
|
||||||
|
function tokenObject() {
|
||||||
|
return {
|
||||||
|
address_hash: STUB_TOKEN.address,
|
||||||
|
address: STUB_TOKEN.address,
|
||||||
|
symbol: STUB_TOKEN.symbol,
|
||||||
|
name: STUB_TOKEN.name,
|
||||||
|
decimals: STUB_TOKEN.decimals,
|
||||||
|
holders_count: STUB_TOKEN.holders,
|
||||||
|
type: "ERC-20",
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// One received ERC-20 transfer of 1.5 E2E to the address under test.
|
||||||
|
function tokenTransferItems(address) {
|
||||||
|
return [
|
||||||
|
{
|
||||||
|
transaction_hash: STUB_TX_HASH,
|
||||||
|
block_number: STUB_BLOCK_NUMBER,
|
||||||
|
timestamp: STUB_TX_TIMESTAMP,
|
||||||
|
from: { hash: STUB_COUNTERPARTY },
|
||||||
|
to: { hash: address },
|
||||||
|
total: { decimals: STUB_TOKEN.decimals, value: "1500000" },
|
||||||
|
token: tokenObject(),
|
||||||
|
},
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
// A holding of 1.5 E2E, in the shape src/shared/balances.js parses. Serving
|
||||||
|
// this is what puts an ERC-20 in the send screen's token dropdown, which is
|
||||||
|
// the only way the confirmation screen's ERC-20 path can be reached.
|
||||||
|
function tokenBalanceItems() {
|
||||||
|
return [
|
||||||
|
{
|
||||||
|
value: "1500000",
|
||||||
|
token: tokenObject(),
|
||||||
|
},
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
// Full details for STUB_TX_HASH. raw_input is "0x" so the calldata
|
||||||
|
// decoder short-circuits; the on-chain detail fields still populate.
|
||||||
|
function transactionDetails() {
|
||||||
|
return {
|
||||||
|
hash: STUB_TX_HASH,
|
||||||
|
block_number: STUB_BLOCK_NUMBER,
|
||||||
|
nonce: 7,
|
||||||
|
gas_used: "51000",
|
||||||
|
gas_price: "1000000000",
|
||||||
|
fee: { value: "51000000000000" },
|
||||||
|
raw_input: "0x",
|
||||||
|
status: "ok",
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function jsonResponse(route, body) {
|
||||||
|
return route.fulfill({
|
||||||
|
status: 200,
|
||||||
|
contentType: "application/json",
|
||||||
|
body: JSON.stringify(body),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Extract the address from a Blockscout /addresses/<addr>/... path.
|
||||||
|
function blockscoutAddress(pathname) {
|
||||||
|
const m = pathname.match(/\/addresses\/(0x[0-9a-fA-F]{40})\//);
|
||||||
|
return m ? m[1] : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
function sleep(ms) {
|
||||||
|
return new Promise((resolve) => setTimeout(resolve, ms));
|
||||||
|
}
|
||||||
|
|
||||||
|
// How long a deliberately held reply is allowed to stay held, and how often
|
||||||
|
// the release flag is re-read while it is.
|
||||||
|
const HOLD_POLL_MS = 25;
|
||||||
|
const HOLD_MAX_MS = 30000;
|
||||||
|
|
||||||
|
// Hold a gas estimate open for as long as the test asks.
|
||||||
|
//
|
||||||
|
// opts.holdGasEstimate is read here rather than captured, so a test flips it
|
||||||
|
// on the same options object the route was registered with — the same
|
||||||
|
// pattern as seedTokenTransfer. This is the only way to observe the
|
||||||
|
// confirmation screen while its estimate is genuinely in flight; sampling
|
||||||
|
// the screen and hoping to win a race against the network would assert
|
||||||
|
// nothing on a slow machine.
|
||||||
|
//
|
||||||
|
// It never gives up quietly. A hold that outlives the bound is reported like
|
||||||
|
// any other harness fault, because a "pending" state that stopped being
|
||||||
|
// pending on its own is a green assertion about the wrong screen.
|
||||||
|
async function awaitRelease(opts, report) {
|
||||||
|
const started = Date.now();
|
||||||
|
while (opts.holdGasEstimate) {
|
||||||
|
if (Date.now() - started > HOLD_MAX_MS) {
|
||||||
|
report(
|
||||||
|
"held gas estimate was never released after " +
|
||||||
|
HOLD_MAX_MS +
|
||||||
|
"ms",
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
await sleep(HOLD_POLL_MS);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// One JSON-RPC reply. Methods whose answer depends on a fixture a test has
|
||||||
|
// set, or on the call itself, are resolved here; every other method is a
|
||||||
|
// constant in RPC_RESULTS.
|
||||||
|
function rpcReply(req, opts, report) {
|
||||||
|
const envelope = { jsonrpc: "2.0", id: req.id };
|
||||||
|
|
||||||
|
if (req.method === "eth_getBalance") {
|
||||||
|
return Object.assign(envelope, {
|
||||||
|
result: opts.ethBalanceWei || RPC_RESULTS.eth_getBalance,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
if (req.method === "eth_call") {
|
||||||
|
return Object.assign(envelope, { result: ethCallResult(req) });
|
||||||
|
}
|
||||||
|
if (req.method === "eth_getBlockByNumber") {
|
||||||
|
return Object.assign(envelope, { result: latestBlock() });
|
||||||
|
}
|
||||||
|
if (req.method === "eth_estimateGas" && opts.failGasEstimate) {
|
||||||
|
// A refusal the node itself would produce, not a transport error:
|
||||||
|
// this is the shape the confirmation screen has to turn into
|
||||||
|
// "Unable to estimate" rather than into a fee of zero.
|
||||||
|
return Object.assign(envelope, {
|
||||||
|
error: {
|
||||||
|
code: -32000,
|
||||||
|
message: "e2e fixture: gas required exceeds allowance",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const result = RPC_RESULTS[req.method];
|
||||||
|
if (result === undefined) {
|
||||||
|
report("unstubbed RPC method: " + req.method);
|
||||||
|
return Object.assign(envelope, {
|
||||||
|
error: { code: -32601, message: "unstubbed in e2e harness" },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return Object.assign(envelope, { result });
|
||||||
|
}
|
||||||
|
|
||||||
|
async function handleRpc(route, postData, opts, report) {
|
||||||
|
let payload;
|
||||||
|
try {
|
||||||
|
payload = JSON.parse(postData || "null");
|
||||||
|
} catch {
|
||||||
|
report("unstubbed RPC: unparseable body " + String(postData));
|
||||||
|
return route.abort();
|
||||||
|
}
|
||||||
|
// ethers batches by default, so the body may be an array.
|
||||||
|
const batch = Array.isArray(payload) ? payload : [payload];
|
||||||
|
|
||||||
|
// Anything that is not a JSON-RPC object, or a batch of them, is not
|
||||||
|
// RPC at all and must be reported like any other unrecognised
|
||||||
|
// outbound traffic rather than dereferenced. request.postData()
|
||||||
|
// returns null both for a bodyless POST and for a body Playwright
|
||||||
|
// cannot decode as UTF-8 (sendBeacon with a Blob, or any binary
|
||||||
|
// payload), so this is not an empty-string special case: it rejects
|
||||||
|
// every non-object payload, exactly as the catch above rejects every
|
||||||
|
// unparseable one.
|
||||||
|
if (
|
||||||
|
payload === null ||
|
||||||
|
typeof payload !== "object" ||
|
||||||
|
!batch.every((req) => req !== null && typeof req === "object")
|
||||||
|
) {
|
||||||
|
report("unstubbed request: POST " + route.request().url());
|
||||||
|
return route.abort();
|
||||||
|
}
|
||||||
|
if (batch.some((req) => req.method === "eth_estimateGas")) {
|
||||||
|
await awaitRelease(opts, report);
|
||||||
|
}
|
||||||
|
|
||||||
|
const replies = batch.map((req) => rpcReply(req, opts, report));
|
||||||
|
return jsonResponse(route, Array.isArray(payload) ? replies : replies[0]);
|
||||||
|
}
|
||||||
|
|
||||||
|
const TRACE_TRUE = ["1", "true", "yes", "on"];
|
||||||
|
const TRACE_FALSE = ["", "0", "false", "no", "off"];
|
||||||
|
|
||||||
|
// Whether E2E_TRACE_NETWORK asks for the request trace.
|
||||||
|
//
|
||||||
|
// A set-but-unrecognised value is a hard error rather than a quiet
|
||||||
|
// "off": E2E_TRACE_NETWORK=true asking for a trace and getting silence
|
||||||
|
// is the operator being lied to about what the harness is doing, which
|
||||||
|
// is the whole failure mode this suite exists to eliminate. Refusing to
|
||||||
|
// guess costs one line and one obvious error message.
|
||||||
|
function traceEnabled(raw) {
|
||||||
|
if (raw === undefined || raw === null) return false;
|
||||||
|
const v = String(raw).trim().toLowerCase();
|
||||||
|
if (TRACE_TRUE.includes(v)) return true;
|
||||||
|
if (TRACE_FALSE.includes(v)) return false;
|
||||||
|
throw new Error(
|
||||||
|
"E2E_TRACE_NETWORK is set to " +
|
||||||
|
JSON.stringify(String(raw)) +
|
||||||
|
", which is not a recognised on/off value. Use one of " +
|
||||||
|
TRACE_TRUE.join(", ") +
|
||||||
|
" to enable the request trace, or one of " +
|
||||||
|
TRACE_FALSE.slice(1).join(", ") +
|
||||||
|
" to disable it. Refusing to guess: a diagnostic that silently " +
|
||||||
|
"does nothing is worse than one that is not there",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Route every http(s) request through local fixtures.
|
||||||
|
*
|
||||||
|
* @param {import("playwright-core").BrowserContext} ctx
|
||||||
|
* @param {object} opts
|
||||||
|
* @param {(text: string) => void} opts.report called for unstubbed traffic
|
||||||
|
* @param {boolean} [opts.seedTokenTransfer] serve the stubbed ERC-20
|
||||||
|
* transfer. Read at request time, so a test can flip it on the same
|
||||||
|
* options object without re-registering the route.
|
||||||
|
* @param {boolean} [opts.seedTokenBalance] serve the stubbed ERC-20
|
||||||
|
* holding, which is what makes the token reachable from the send screen.
|
||||||
|
* @param {string} [opts.ethBalanceWei] hex wei answered to eth_getBalance;
|
||||||
|
* defaults to zero, which is what every test that predates the funded
|
||||||
|
* fixture expects.
|
||||||
|
* @param {boolean} [opts.failGasEstimate] answer eth_estimateGas with a
|
||||||
|
* node-side refusal.
|
||||||
|
* @param {boolean} [opts.holdGasEstimate] hold every batch containing an
|
||||||
|
* eth_estimateGas until this is cleared again.
|
||||||
|
* @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) =>
|
||||||
|
* Promise<string|null>}>}
|
||||||
|
*/
|
||||||
|
async function installNetworkStubs(ctx, opts) {
|
||||||
|
const report = opts.report;
|
||||||
|
|
||||||
|
// First request seen that originated in a service worker, and the
|
||||||
|
// resolver waiting for it. This is what proves worker interception is
|
||||||
|
// actually in force; see waitForServiceWorkerTraffic below.
|
||||||
|
let firstWorkerRequest = null;
|
||||||
|
let announceWorkerRequest = null;
|
||||||
|
|
||||||
|
// E2E_TRACE_NETWORK=1 prints every request that reaches this handler,
|
||||||
|
// tagged [sw] when it originated in the background service worker.
|
||||||
|
// It exists so the isolation claim above can be re-checked by anyone
|
||||||
|
// in one command, without editing files: the phishing blocklist fetch
|
||||||
|
// showing up with an [sw] tag is the proof that the worker really is
|
||||||
|
// intercepted and that the raw.githubusercontent.com stub below is
|
||||||
|
// live code rather than decoration.
|
||||||
|
const trace = traceEnabled(process.env.E2E_TRACE_NETWORK);
|
||||||
|
|
||||||
|
// Regex rather than a glob so chrome-extension:// resource loads are
|
||||||
|
// never touched — routing those would break the popup itself.
|
||||||
|
await ctx.route(/^https?:\/\//, async (route) => {
|
||||||
|
const req = route.request();
|
||||||
|
const url = new URL(req.url());
|
||||||
|
const p = url.pathname;
|
||||||
|
const fromWorker = !!req.serviceWorker();
|
||||||
|
|
||||||
|
if (fromWorker && !firstWorkerRequest) {
|
||||||
|
firstWorkerRequest = req.method() + " " + req.url();
|
||||||
|
if (announceWorkerRequest)
|
||||||
|
announceWorkerRequest(firstWorkerRequest);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (trace) {
|
||||||
|
const origin = fromWorker ? "[sw] " : "[page] ";
|
||||||
|
console.log("# routed " + origin + req.method() + " " + req.url());
|
||||||
|
}
|
||||||
|
|
||||||
|
// JSON-RPC endpoint (any host): a POST with a JSON-RPC body.
|
||||||
|
if (req.method() === "POST") {
|
||||||
|
return handleRpc(route, req.postData(), opts, report);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Blockscout v2
|
||||||
|
if (p.includes("/api/v2/")) {
|
||||||
|
if (/\/addresses\/0x[0-9a-fA-F]{40}\/transactions$/.test(p)) {
|
||||||
|
return jsonResponse(route, { items: [] });
|
||||||
|
}
|
||||||
|
if (/\/addresses\/0x[0-9a-fA-F]{40}\/token-transfers$/.test(p)) {
|
||||||
|
const addr = blockscoutAddress(p);
|
||||||
|
return jsonResponse(route, {
|
||||||
|
items:
|
||||||
|
opts.seedTokenTransfer && addr
|
||||||
|
? tokenTransferItems(addr)
|
||||||
|
: [],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
if (/\/addresses\/0x[0-9a-fA-F]{40}\/token-balances$/.test(p)) {
|
||||||
|
return jsonResponse(
|
||||||
|
route,
|
||||||
|
opts.seedTokenBalance ? tokenBalanceItems() : [],
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (p.endsWith("/transactions/" + STUB_TX_HASH)) {
|
||||||
|
return jsonResponse(route, transactionDetails());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// CoinDesk price tick
|
||||||
|
if (url.hostname.endsWith("coindesk.com")) {
|
||||||
|
return jsonResponse(route, { Data: {} });
|
||||||
|
}
|
||||||
|
|
||||||
|
// MetaMask phishing blocklist
|
||||||
|
if (
|
||||||
|
url.hostname === "raw.githubusercontent.com" ||
|
||||||
|
p.endsWith("/eth-phishing-detect/main/src/config.json")
|
||||||
|
) {
|
||||||
|
return jsonResponse(route, {
|
||||||
|
version: 2,
|
||||||
|
tolerance: 2,
|
||||||
|
fuzzylist: [],
|
||||||
|
whitelist: [],
|
||||||
|
blacklist: [],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Best-effort Etherscan address labels: served as an empty page.
|
||||||
|
if (url.hostname.endsWith("etherscan.io")) {
|
||||||
|
return route.fulfill({
|
||||||
|
status: 200,
|
||||||
|
contentType: "text/html",
|
||||||
|
body: "<html><body></body></html>",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
report("unstubbed request: " + req.method() + " " + req.url());
|
||||||
|
return route.abort();
|
||||||
|
});
|
||||||
|
|
||||||
|
return {
|
||||||
|
/**
|
||||||
|
* Resolve with the first service-worker-originated request this
|
||||||
|
* handler saw, or null if none arrives within `ms`.
|
||||||
|
*
|
||||||
|
* The background worker fetches the phishing blocklist at
|
||||||
|
* startup, unconditionally, within about a second of the context
|
||||||
|
* coming up — so under working interception this resolves almost
|
||||||
|
* immediately. Nothing arriving means worker traffic is bypassing
|
||||||
|
* the handler entirely and going to the real internet, which the
|
||||||
|
* caller turns into a hard failure of the whole suite.
|
||||||
|
*/
|
||||||
|
waitForServiceWorkerTraffic(ms) {
|
||||||
|
if (firstWorkerRequest) return Promise.resolve(firstWorkerRequest);
|
||||||
|
return new Promise((resolve) => {
|
||||||
|
const timer = setTimeout(() => {
|
||||||
|
announceWorkerRequest = null;
|
||||||
|
resolve(null);
|
||||||
|
}, ms);
|
||||||
|
announceWorkerRequest = (req) => {
|
||||||
|
clearTimeout(timer);
|
||||||
|
announceWorkerRequest = null;
|
||||||
|
resolve(req);
|
||||||
|
};
|
||||||
|
});
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
installNetworkStubs,
|
||||||
|
FEE_ESTIMATE_WEI,
|
||||||
|
FEE_RESERVE_WEI,
|
||||||
|
STUB_COUNTERPARTY,
|
||||||
|
STUB_TOKEN,
|
||||||
|
STUB_TX_HASH,
|
||||||
|
};
|
||||||
1372
tests/e2e/run.js
Normal file
1372
tests/e2e/run.js
Normal file
File diff suppressed because it is too large
Load Diff
100
tests/etherscanLabels.test.js
Normal file
100
tests/etherscanLabels.test.js
Normal file
@@ -0,0 +1,100 @@
|
|||||||
|
const { parseEtherscanPage } = require("../src/shared/etherscanLabels");
|
||||||
|
|
||||||
|
describe("etherscanLabels", () => {
|
||||||
|
describe("parseEtherscanPage", () => {
|
||||||
|
test("detects Fake_Phishing label in title", () => {
|
||||||
|
const html = `<html><head><title>Fake_Phishing184810 | Address: 0x00000c07...3ea470000 | Etherscan</title></head><body></body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("Fake_Phishing184810");
|
||||||
|
expect(result.isPhishing).toBe(true);
|
||||||
|
expect(result.warning).toContain("Fake_Phishing184810");
|
||||||
|
expect(result.warning).toContain("Phish/Hack");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects Fake_Phishing with different number", () => {
|
||||||
|
const html = `<html><head><title>Fake_Phishing5169 | Address: 0x3e0defb8...99a7a8a74 | Etherscan</title></head><body></body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("Fake_Phishing5169");
|
||||||
|
expect(result.isPhishing).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects Exploiter label", () => {
|
||||||
|
const html = `<html><head><title>Exploiter 42 | Address: 0xabcdef...1234 | Etherscan</title></head><body></body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("Exploiter 42");
|
||||||
|
expect(result.isPhishing).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects scam warning in body text", () => {
|
||||||
|
const html =
|
||||||
|
`<html><head><title>Address: 0xabcdef...1234 | Etherscan</title></head>` +
|
||||||
|
`<body>There are reports that this address was used in a Phishing scam.</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBeNull();
|
||||||
|
expect(result.isPhishing).toBe(true);
|
||||||
|
expect(result.warning).toContain("phishing/scam");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects scam warning with label in body", () => {
|
||||||
|
const html =
|
||||||
|
`<html><head><title>SomeScammer | Address: 0xabcdef...1234 | Etherscan</title></head>` +
|
||||||
|
`<body>There are reports that this address was used in a scam.</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("SomeScammer");
|
||||||
|
expect(result.isPhishing).toBe(true);
|
||||||
|
expect(result.warning).toContain("SomeScammer");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("returns clean result for legitimate address", () => {
|
||||||
|
const html = `<html><head><title>vitalik.eth | Address: 0xd8dA6BF2...37aA96045 | Etherscan</title></head><body>Overview</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("vitalik.eth");
|
||||||
|
expect(result.isPhishing).toBe(false);
|
||||||
|
expect(result.warning).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("returns clean result for unlabeled address", () => {
|
||||||
|
const html = `<html><head><title>Address: 0x1234567890...abcdef | Etherscan</title></head><body>Overview</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBeNull();
|
||||||
|
expect(result.isPhishing).toBe(false);
|
||||||
|
expect(result.warning).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handles exchange labels correctly (not phishing)", () => {
|
||||||
|
const html = `<html><head><title>Coinbase 10 | Address: 0xa9d1e08c...b81d3e43 | Etherscan</title></head><body>Overview</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("Coinbase 10");
|
||||||
|
expect(result.isPhishing).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handles contract names correctly (not phishing)", () => {
|
||||||
|
const html = `<html><head><title>Beacon Deposit Contract | Address: 0x00000000...03d7705Fa | Etherscan</title></head><body>Overview</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBe("Beacon Deposit Contract");
|
||||||
|
expect(result.isPhishing).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handles empty HTML gracefully", () => {
|
||||||
|
const result = parseEtherscanPage("");
|
||||||
|
expect(result.label).toBeNull();
|
||||||
|
expect(result.isPhishing).toBe(false);
|
||||||
|
expect(result.warning).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handles malformed title tag", () => {
|
||||||
|
const html = `<html><head><title></title></head><body></body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.label).toBeNull();
|
||||||
|
expect(result.isPhishing).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects wallet drainer warning", () => {
|
||||||
|
const html =
|
||||||
|
`<html><head><title>Address: 0xabc...def | Etherscan</title></head>` +
|
||||||
|
`<body>This is a known wallet drainer contract.</body></html>`;
|
||||||
|
const result = parseEtherscanPage(html);
|
||||||
|
expect(result.isPhishing).toBe(true);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
331
tests/exportPrivkey.test.js
Normal file
331
tests/exportPrivkey.test.js
Normal file
@@ -0,0 +1,331 @@
|
|||||||
|
// Tests for the private key export screen (issue #221).
|
||||||
|
//
|
||||||
|
// The screen holds the one secret that owns an address outright, so what is
|
||||||
|
// pinned here is disposal: the key is wiped from the DOM whenever the screen
|
||||||
|
// is left by any route, and a decrypt still in flight when the screen is
|
||||||
|
// left never writes at all. That last case is the one a per-button wipe and
|
||||||
|
// a naive leave hook both miss — the write lands after the wipe, with
|
||||||
|
// nothing scheduled to wipe it again.
|
||||||
|
//
|
||||||
|
// The view is driven against a minimal DOM stub rather than a real browser:
|
||||||
|
// the module is deliberately shaped like src/popup/views/showPhrase.js, with
|
||||||
|
// no dependency that needs a document beyond the nodes it reads and writes.
|
||||||
|
|
||||||
|
const mockPrivateKey = "0x" + "ab".repeat(32);
|
||||||
|
|
||||||
|
jest.mock("ethereum-blockies-base64", () => () => "data:image/png;base64,x");
|
||||||
|
jest.mock("../src/shared/vault", () => ({
|
||||||
|
decryptWithPassword: jest.fn(),
|
||||||
|
}));
|
||||||
|
jest.mock("../src/shared/wallet", () => ({
|
||||||
|
getSignerForAddress: jest.fn(() => ({ privateKey: mockPrivateKey })),
|
||||||
|
}));
|
||||||
|
|
||||||
|
const { RESTORABLE_VIEWS } = require("../src/popup/restorableViews");
|
||||||
|
|
||||||
|
const VIEW = "export-privkey";
|
||||||
|
const PASSWORD = "correct horse battery";
|
||||||
|
|
||||||
|
// ------------------------------------------------------------ DOM stub
|
||||||
|
|
||||||
|
function makeElement(id, withParent) {
|
||||||
|
const classes = new Set();
|
||||||
|
const el = {
|
||||||
|
id,
|
||||||
|
textContent: "",
|
||||||
|
value: "",
|
||||||
|
innerHTML: "",
|
||||||
|
disabled: false,
|
||||||
|
style: {},
|
||||||
|
dataset: {},
|
||||||
|
listeners: {},
|
||||||
|
classList: {
|
||||||
|
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||||
|
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||||
|
contains: (n) => classes.has(n),
|
||||||
|
toggle: (n, force) => {
|
||||||
|
const on = force === undefined ? !classes.has(n) : force;
|
||||||
|
if (on) classes.add(n);
|
||||||
|
else classes.delete(n);
|
||||||
|
return on;
|
||||||
|
},
|
||||||
|
},
|
||||||
|
addEventListener: (name, fn) => {
|
||||||
|
el.listeners[name] = el.listeners[name] || [];
|
||||||
|
el.listeners[name].push(fn);
|
||||||
|
},
|
||||||
|
appendChild: () => {},
|
||||||
|
remove: () => {},
|
||||||
|
querySelectorAll: () => [],
|
||||||
|
};
|
||||||
|
el.parentElement = withParent ? makeElement(id + "-parent", false) : null;
|
||||||
|
return el;
|
||||||
|
}
|
||||||
|
|
||||||
|
function makeDocument() {
|
||||||
|
const els = new Map();
|
||||||
|
return {
|
||||||
|
getElementById(id) {
|
||||||
|
// The debug banner is created on demand by helpers.js; absent
|
||||||
|
// is the state a non-debug, non-testnet popup is in.
|
||||||
|
if (id === "debug-banner") return null;
|
||||||
|
if (!els.has(id)) els.set(id, makeElement(id, true));
|
||||||
|
return els.get(id);
|
||||||
|
},
|
||||||
|
createElement: () => makeElement("created", false),
|
||||||
|
addEventListener: () => {},
|
||||||
|
body: { prepend: () => {} },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// ------------------------------------------------------------ harness
|
||||||
|
|
||||||
|
function load() {
|
||||||
|
jest.resetModules();
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
globalThis.document = makeDocument();
|
||||||
|
|
||||||
|
const helpers = require("../src/popup/views/helpers");
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const vault = require("../src/shared/vault");
|
||||||
|
const wallet = require("../src/shared/wallet");
|
||||||
|
const exportPrivkey = require("../src/popup/views/exportPrivkey");
|
||||||
|
|
||||||
|
state.wallets = [
|
||||||
|
{
|
||||||
|
name: "Wallet 1",
|
||||||
|
type: "key",
|
||||||
|
encryptedSecret: "ciphertext",
|
||||||
|
addresses: [
|
||||||
|
{
|
||||||
|
address: "0x" + "11".repeat(20),
|
||||||
|
balance: "0.0000",
|
||||||
|
tokenBalances: [],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
address: "0x" + "22".repeat(20),
|
||||||
|
balance: "0.0000",
|
||||||
|
tokenBalances: [],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
];
|
||||||
|
state.viewStack = [];
|
||||||
|
state.currentView = "address";
|
||||||
|
|
||||||
|
exportPrivkey.init();
|
||||||
|
return { helpers, state, vault, wallet, exportPrivkey };
|
||||||
|
}
|
||||||
|
|
||||||
|
function click(id) {
|
||||||
|
const el = globalThis.document.getElementById(id);
|
||||||
|
return Promise.all((el.listeners.click || []).map((fn) => fn()));
|
||||||
|
}
|
||||||
|
|
||||||
|
function node(id) {
|
||||||
|
return globalThis.document.getElementById(id);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Start a reveal and hand back both the promise it returns and the resolver
|
||||||
|
// for the decrypt it is waiting on, so a test can navigate away mid-flight.
|
||||||
|
function startReveal(vault) {
|
||||||
|
let resolveDecrypt;
|
||||||
|
let rejectDecrypt;
|
||||||
|
vault.decryptWithPassword.mockImplementation(
|
||||||
|
() =>
|
||||||
|
new Promise((resolve, reject) => {
|
||||||
|
resolveDecrypt = resolve;
|
||||||
|
rejectDecrypt = reject;
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
node("export-privkey-password").value = PASSWORD;
|
||||||
|
const pending = click("btn-export-privkey-confirm");
|
||||||
|
return {
|
||||||
|
pending,
|
||||||
|
resolve: (v) => resolveDecrypt(v),
|
||||||
|
reject: (e) => rejectDecrypt(e),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// ------------------------------------------------------------ tests
|
||||||
|
|
||||||
|
describe("a decrypt still running when the screen is left", () => {
|
||||||
|
// The load-bearing case. Without the liveness guard in reveal(), the
|
||||||
|
// write lands after the leave hook has already wiped, and the key sits
|
||||||
|
// in the hidden view for the life of the popup.
|
||||||
|
test("never writes the key into the DOM", async () => {
|
||||||
|
const { helpers, vault, wallet, exportPrivkey } = load();
|
||||||
|
exportPrivkey.show(0, 0);
|
||||||
|
|
||||||
|
const reveal = startReveal(vault);
|
||||||
|
// The settings gear, mid-decrypt.
|
||||||
|
helpers.showView("settings");
|
||||||
|
reveal.resolve("wallet secret");
|
||||||
|
await reveal.pending;
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
// Nothing was even derived: the guard sits in front of the
|
||||||
|
// derivation, not just in front of the write.
|
||||||
|
expect(wallet.getSignerForAddress).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
// The generation counter, not merely the current-view check: by the time
|
||||||
|
// the stale decrypt resolves the user is back on the screen, so a guard
|
||||||
|
// that only asked "is this view showing?" would let the write through.
|
||||||
|
test("never writes it after the screen is re-entered", async () => {
|
||||||
|
const { helpers, vault, exportPrivkey } = load();
|
||||||
|
exportPrivkey.show(0, 0);
|
||||||
|
|
||||||
|
const stale = startReveal(vault);
|
||||||
|
helpers.showView("settings");
|
||||||
|
exportPrivkey.show(0, 1);
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
|
||||||
|
stale.resolve("wallet secret");
|
||||||
|
await stale.pending;
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
expect(node("export-privkey-result").classList.contains("hidden")).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Same hole on the failure path: a wrong-password error written after
|
||||||
|
// the wipe would restore the flash line on a screen the user has left.
|
||||||
|
test("never writes the failure message either", async () => {
|
||||||
|
const { helpers, vault, exportPrivkey } = load();
|
||||||
|
exportPrivkey.show(0, 0);
|
||||||
|
|
||||||
|
const reveal = startReveal(vault);
|
||||||
|
helpers.showView("settings");
|
||||||
|
reveal.reject(new Error("decryption failed"));
|
||||||
|
await reveal.pending;
|
||||||
|
|
||||||
|
expect(node("export-privkey-flash").textContent).toBe("");
|
||||||
|
expect(node("export-privkey-flash").style.visibility).toBe("hidden");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("a reveal that is not interrupted", () => {
|
||||||
|
// Guards the guard: a liveness check that rejected every write would
|
||||||
|
// pass every test above and ship a screen that reveals nothing.
|
||||||
|
test("puts the key on screen", async () => {
|
||||||
|
const { vault, exportPrivkey } = load();
|
||||||
|
exportPrivkey.show(0, 0);
|
||||||
|
|
||||||
|
const reveal = startReveal(vault);
|
||||||
|
reveal.resolve("wallet secret");
|
||||||
|
await reveal.pending;
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe(mockPrivateKey);
|
||||||
|
expect(node("export-privkey-result").classList.contains("hidden")).toBe(
|
||||||
|
false,
|
||||||
|
);
|
||||||
|
// The password is dropped as soon as it has been spent.
|
||||||
|
expect(node("export-privkey-password").value).toBe("");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("writes nothing before the password is accepted", async () => {
|
||||||
|
const { vault, exportPrivkey } = load();
|
||||||
|
exportPrivkey.show(0, 0);
|
||||||
|
|
||||||
|
const reveal = startReveal(vault);
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
reveal.resolve("wallet secret");
|
||||||
|
await reveal.pending;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("reveals nothing when the password is wrong", async () => {
|
||||||
|
const { vault, exportPrivkey } = load();
|
||||||
|
exportPrivkey.show(0, 0);
|
||||||
|
|
||||||
|
const reveal = startReveal(vault);
|
||||||
|
reveal.reject(new Error("decryption failed"));
|
||||||
|
await reveal.pending;
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
expect(node("export-privkey-flash").textContent).toBe(
|
||||||
|
"That password is not correct. Please try again.",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("leaving the screen after the key is on it", () => {
|
||||||
|
async function revealed() {
|
||||||
|
const loaded = load();
|
||||||
|
loaded.exportPrivkey.show(0, 0);
|
||||||
|
const reveal = startReveal(loaded.vault);
|
||||||
|
reveal.resolve("wallet secret");
|
||||||
|
await reveal.pending;
|
||||||
|
expect(node("export-privkey-value").textContent).toBe(mockPrivateKey);
|
||||||
|
return loaded;
|
||||||
|
}
|
||||||
|
|
||||||
|
test("the Back button clears the key", async () => {
|
||||||
|
await revealed();
|
||||||
|
await click("btn-export-privkey-back");
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
expect(node("export-privkey-password").value).toBe("");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the settings gear clears the key", async () => {
|
||||||
|
const { helpers } = await revealed();
|
||||||
|
helpers.showView("settings");
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
expect(node("export-privkey-password").value).toBe("");
|
||||||
|
// And the screen is back to its password prompt, not to a result
|
||||||
|
// panel that would flash an empty well on the next visit.
|
||||||
|
expect(node("export-privkey-result").classList.contains("hidden")).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
expect(
|
||||||
|
node("export-privkey-password-section").classList.contains(
|
||||||
|
"hidden",
|
||||||
|
),
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Any other navigation: the same hook covers routes that do not exist
|
||||||
|
// yet, which is the point of registering it on the view rather than on
|
||||||
|
// the controls that leave it.
|
||||||
|
test("any other navigation clears the key", async () => {
|
||||||
|
const { helpers } = await revealed();
|
||||||
|
helpers.showView("main");
|
||||||
|
|
||||||
|
expect(node("export-privkey-value").textContent).toBe("");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("views the popup may reopen onto", () => {
|
||||||
|
// Restoring onto this screen would put a private key on display with no
|
||||||
|
// password prompt in front of it, on a popup reopened by accident.
|
||||||
|
test("the private key export screen is not restorable", () => {
|
||||||
|
expect(RESTORABLE_VIEWS.has(VIEW)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("it is still a registered view", () => {
|
||||||
|
const { helpers } = load();
|
||||||
|
expect(helpers.VIEWS).toContain(VIEW);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the key cannot reach the logger", () => {
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
const source = fs.readFileSync(
|
||||||
|
path.join(__dirname, "..", "src", "popup", "views", "exportPrivkey.js"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
|
||||||
|
test("the view does not import src/shared/log.js", () => {
|
||||||
|
expect(source).not.toMatch(/require\(["'][^"']*shared\/log["']\)/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the view calls no logger method", () => {
|
||||||
|
expect(source).not.toMatch(/\blog\.(debugf|infof|warnf|errorf)\b/);
|
||||||
|
});
|
||||||
|
});
|
||||||
166
tests/holders.test.js
Normal file
166
tests/holders.test.js
Normal file
@@ -0,0 +1,166 @@
|
|||||||
|
// Tests for src/shared/holders.js and the balance-list spam gate that reads
|
||||||
|
// it (issue #230).
|
||||||
|
//
|
||||||
|
// The rule these pin down: an explorer that reports no holders_count has told
|
||||||
|
// us nothing, and "nothing" must not be recorded as "zero holders". Zero is
|
||||||
|
// the strongest spam signal the wallet has, so handing it out for free turns
|
||||||
|
// a missing field into a hidden asset.
|
||||||
|
|
||||||
|
jest.mock("../src/shared/log", () => ({
|
||||||
|
log: {
|
||||||
|
debugf: () => {},
|
||||||
|
infof: () => {},
|
||||||
|
warnf: () => {},
|
||||||
|
errorf: () => {},
|
||||||
|
},
|
||||||
|
debugFetch: jest.fn(),
|
||||||
|
setRuntimeDebug: () => {},
|
||||||
|
isDebug: () => false,
|
||||||
|
}));
|
||||||
|
|
||||||
|
global.fetch = jest.fn(() => {
|
||||||
|
throw new Error("tests must not perform network requests");
|
||||||
|
});
|
||||||
|
global.chrome = { storage: { local: {} } };
|
||||||
|
|
||||||
|
const {
|
||||||
|
LOW_HOLDER_THRESHOLD,
|
||||||
|
parseHoldersCount,
|
||||||
|
isLowHolderCount,
|
||||||
|
} = require("../src/shared/holders");
|
||||||
|
const { fetchTokenBalances } = require("../src/shared/balances");
|
||||||
|
const { debugFetch } = require("../src/shared/log");
|
||||||
|
|
||||||
|
const BLOCKSCOUT = "https://eth.blockscout.com/api/v2";
|
||||||
|
const HOLDER = "0x66133e8ea0f5d1d612d2502a968757d1048c214a";
|
||||||
|
const USDC_CONTRACT = "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48";
|
||||||
|
const NOVEL_TOKEN = "0x1111111111111111111111111111111111111111";
|
||||||
|
|
||||||
|
describe("parseHoldersCount", () => {
|
||||||
|
test("a reported count parses to that number", () => {
|
||||||
|
expect(parseHoldersCount("3500000")).toBe(3500000);
|
||||||
|
expect(parseHoldersCount(3500000)).toBe(3500000);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a reported "0" parses to 0, which is not null', () => {
|
||||||
|
expect(parseHoldersCount("0")).toBe(0);
|
||||||
|
expect(parseHoldersCount(0)).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an omitted, null or empty count is unknown", () => {
|
||||||
|
expect(parseHoldersCount(undefined)).toBeNull();
|
||||||
|
expect(parseHoldersCount(null)).toBeNull();
|
||||||
|
expect(parseHoldersCount("")).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an unparseable count is unknown rather than zero", () => {
|
||||||
|
expect(parseHoldersCount("many")).toBeNull();
|
||||||
|
expect(parseHoldersCount(NaN)).toBeNull();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("isLowHolderCount", () => {
|
||||||
|
test("the threshold is the documented 1,000 holders", () => {
|
||||||
|
expect(LOW_HOLDER_THRESHOLD).toBe(1000);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a reported count below the threshold is low", () => {
|
||||||
|
expect(isLowHolderCount(0)).toBe(true);
|
||||||
|
expect(isLowHolderCount(999)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a reported count at or above the threshold is not low", () => {
|
||||||
|
expect(isLowHolderCount(1000)).toBe(false);
|
||||||
|
expect(isLowHolderCount(1001)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an unknown count is not low", () => {
|
||||||
|
expect(isLowHolderCount(null)).toBe(false);
|
||||||
|
expect(isLowHolderCount(undefined)).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// fetchTokenBalances applies its own spam gate, which is not the low-holder
|
||||||
|
// display filter: it has no setting behind it and decides what the balance
|
||||||
|
// list contains at all. It stays strict on an unknown count — see the
|
||||||
|
// comment at the gate — but must stop recording that unknown as zero.
|
||||||
|
describe("the balance-list spam gate", () => {
|
||||||
|
function respondWith(items) {
|
||||||
|
debugFetch.mockImplementation(async () => ({
|
||||||
|
ok: true,
|
||||||
|
status: 200,
|
||||||
|
statusText: "OK",
|
||||||
|
json: async () => items,
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
function item(overrides = {}) {
|
||||||
|
const { token, ...rest } = overrides;
|
||||||
|
return {
|
||||||
|
value: "12500000",
|
||||||
|
...rest,
|
||||||
|
token: {
|
||||||
|
type: "ERC-20",
|
||||||
|
address_hash: NOVEL_TOKEN,
|
||||||
|
symbol: "SPAMTKN",
|
||||||
|
name: "Spam Token",
|
||||||
|
decimals: "6",
|
||||||
|
holders_count: "50000",
|
||||||
|
...token,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
debugFetch.mockReset();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a token with plenty of reported holders is listed", async () => {
|
||||||
|
respondWith([item()]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, []);
|
||||||
|
expect(balances).toHaveLength(1);
|
||||||
|
expect(balances[0].holders).toBe(50000);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a token reporting zero holders is still excluded", async () => {
|
||||||
|
respondWith([item({ token: { holders_count: "0" } })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an unknown holder count does not admit an unvouched token", async () => {
|
||||||
|
respondWith([item({ token: { holders_count: null } })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The path that reaches the send selector and the history filter: a token
|
||||||
|
// the user vouched for by tracking it is listed whatever the explorer
|
||||||
|
// says, and it must carry the unknown count through as null, not as the
|
||||||
|
// zero that would then hide it downstream.
|
||||||
|
test("a tracked token with an unknown count is listed with holders null", async () => {
|
||||||
|
respondWith([item({ token: { holders_count: undefined } })]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, [
|
||||||
|
{ address: NOVEL_TOKEN.toUpperCase() },
|
||||||
|
]);
|
||||||
|
expect(balances).toHaveLength(1);
|
||||||
|
expect(balances[0].holders).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a known-list token with an unknown count is listed with holders null", async () => {
|
||||||
|
respondWith([
|
||||||
|
item({
|
||||||
|
token: {
|
||||||
|
address_hash: USDC_CONTRACT,
|
||||||
|
symbol: "USDC",
|
||||||
|
holders_count: null,
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, []);
|
||||||
|
expect(balances).toHaveLength(1);
|
||||||
|
expect(balances[0].holders).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("no test in this file performed a network request", () => {
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
});
|
||||||
105
tests/manifest.test.js
Normal file
105
tests/manifest.test.js
Normal file
@@ -0,0 +1,105 @@
|
|||||||
|
// The shipped Content Security Policy, pinned in both directions.
|
||||||
|
//
|
||||||
|
// This is the anti-regression check for #182. libsodium decides its
|
||||||
|
// backend by trying to compile WebAssembly and catching the failure, so a
|
||||||
|
// CSP that refuses WASM demotes the vault to the wasm2js translation —
|
||||||
|
// roughly 20x slower per Argon2id derivation — and says so only in a
|
||||||
|
// console message nobody reads. Dropping 'wasm-unsafe-eval' from either
|
||||||
|
// manifest therefore has to fail a check, not a log line.
|
||||||
|
//
|
||||||
|
// It is equally a check against loosening. 'wasm-unsafe-eval' is granted
|
||||||
|
// deliberately and narrowly (see the backend note in src/shared/vault.js);
|
||||||
|
// 'unsafe-eval', 'unsafe-inline' and any remote script source are not, and
|
||||||
|
// an exact match on the token set is what keeps the next edit from
|
||||||
|
// smuggling one in alongside.
|
||||||
|
//
|
||||||
|
// build.js copies these files to dist/<target>/manifest.json verbatim, so
|
||||||
|
// what is asserted here is what ships.
|
||||||
|
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
|
||||||
|
const MANIFEST_DIR = path.join(__dirname, "..", "manifest");
|
||||||
|
|
||||||
|
const EXPECTED_SCRIPT_SRC = ["'self'", "'wasm-unsafe-eval'"];
|
||||||
|
const EXPECTED_OBJECT_SRC = ["'self'"];
|
||||||
|
|
||||||
|
const FORBIDDEN_SOURCES = [
|
||||||
|
"'unsafe-eval'",
|
||||||
|
"'unsafe-inline'",
|
||||||
|
"http:",
|
||||||
|
"https:",
|
||||||
|
"data:",
|
||||||
|
"blob:",
|
||||||
|
"*",
|
||||||
|
];
|
||||||
|
|
||||||
|
function readManifest(name) {
|
||||||
|
return JSON.parse(
|
||||||
|
fs.readFileSync(path.join(MANIFEST_DIR, name + ".json"), "utf8"),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// "script-src 'self'; object-src 'self'" -> { "script-src": ["'self'"], ... }
|
||||||
|
function parseCsp(policy) {
|
||||||
|
const directives = {};
|
||||||
|
for (const part of policy.split(";")) {
|
||||||
|
const tokens = part.trim().split(/\s+/).filter(Boolean);
|
||||||
|
if (tokens.length === 0) continue;
|
||||||
|
directives[tokens[0]] = tokens.slice(1);
|
||||||
|
}
|
||||||
|
return directives;
|
||||||
|
}
|
||||||
|
|
||||||
|
function assertPolicy(policy) {
|
||||||
|
const directives = parseCsp(policy);
|
||||||
|
expect(Object.keys(directives).sort()).toEqual([
|
||||||
|
"object-src",
|
||||||
|
"script-src",
|
||||||
|
]);
|
||||||
|
expect(directives["script-src"].slice().sort()).toEqual(
|
||||||
|
EXPECTED_SCRIPT_SRC,
|
||||||
|
);
|
||||||
|
expect(directives["object-src"].slice().sort()).toEqual(
|
||||||
|
EXPECTED_OBJECT_SRC,
|
||||||
|
);
|
||||||
|
for (const source of FORBIDDEN_SOURCES) {
|
||||||
|
expect(directives["script-src"]).not.toContain(source);
|
||||||
|
expect(directives["object-src"]).not.toContain(source);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("shipped Content Security Policy", () => {
|
||||||
|
// MV3 takes an object and applies extension_pages to the popup and the
|
||||||
|
// background service worker, which is where libsodium runs.
|
||||||
|
test("chrome MV3 allows WASM and nothing else beyond 'self'", () => {
|
||||||
|
const csp = readManifest("chrome").content_security_policy;
|
||||||
|
expect(typeof csp).toBe("object");
|
||||||
|
expect(Object.keys(csp)).toEqual(["extension_pages"]);
|
||||||
|
assertPolicy(csp.extension_pages);
|
||||||
|
});
|
||||||
|
|
||||||
|
// MV2 takes the policy as a bare string. Firefox does not require
|
||||||
|
// 'wasm-unsafe-eval' for MV2 today — enforcement is report-only and
|
||||||
|
// Bugzilla 1770909 is still open — so that token is future-proofing
|
||||||
|
// for when it lands, not a mandate, and it stays inside Firefox's MV2
|
||||||
|
// base-CSP ceiling. object-src 'self' is the load-bearing half: a
|
||||||
|
// Firefox before 106 rejects an MV2 policy string that omits
|
||||||
|
// object-src and falls back to its own default, discarding everything
|
||||||
|
// declared here. Same policy as Chrome, different manifest shape.
|
||||||
|
test("firefox MV2 allows WASM and nothing else beyond 'self'", () => {
|
||||||
|
const csp = readManifest("firefox").content_security_policy;
|
||||||
|
expect(typeof csp).toBe("string");
|
||||||
|
assertPolicy(csp);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The two targets share one codebase and one crypto path; a policy
|
||||||
|
// that drifts apart between them means one of the two builds is
|
||||||
|
// running a backend nothing tests.
|
||||||
|
test("both targets ship the same policy", () => {
|
||||||
|
const chrome =
|
||||||
|
readManifest("chrome").content_security_policy.extension_pages;
|
||||||
|
const firefox = readManifest("firefox").content_security_policy;
|
||||||
|
expect(firefox).toBe(chrome);
|
||||||
|
});
|
||||||
|
});
|
||||||
573
tests/phishingDomains.test.js
Normal file
573
tests/phishingDomains.test.js
Normal file
@@ -0,0 +1,573 @@
|
|||||||
|
// Extension storage stub for the Node test environment. The module resolves
|
||||||
|
// the storage API on use, so this only has to exist before the first call.
|
||||||
|
// Values round-trip through JSON the way structured cloning would, so a test
|
||||||
|
// cannot pass by holding a live reference to the module's own array.
|
||||||
|
const storageStore = {};
|
||||||
|
global.chrome = {
|
||||||
|
storage: {
|
||||||
|
local: {
|
||||||
|
get: async (key) =>
|
||||||
|
Object.prototype.hasOwnProperty.call(storageStore, key)
|
||||||
|
? { [key]: JSON.parse(JSON.stringify(storageStore[key])) }
|
||||||
|
: {},
|
||||||
|
set: async (items) => {
|
||||||
|
for (const [key, value] of Object.entries(items)) {
|
||||||
|
storageStore[key] = JSON.parse(JSON.stringify(value));
|
||||||
|
}
|
||||||
|
},
|
||||||
|
remove: async (key) => {
|
||||||
|
delete storageStore[key];
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
const {
|
||||||
|
isPhishingDomain,
|
||||||
|
loadConfig,
|
||||||
|
getBlocklistSize,
|
||||||
|
getDeltaSize,
|
||||||
|
hostnameVariants,
|
||||||
|
DELTA_STORAGE_KEY,
|
||||||
|
_reset,
|
||||||
|
_getVendoredBlacklistSize,
|
||||||
|
_getDeltaBlacklist,
|
||||||
|
} = require("../src/shared/phishingDomains");
|
||||||
|
|
||||||
|
function clearStorage() {
|
||||||
|
for (const key of Object.keys(storageStore)) {
|
||||||
|
delete storageStore[key];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The MV3 service worker is torn down when idle and re-evaluated on the next
|
||||||
|
// event, which wipes every module-level variable. Re-requiring the module with
|
||||||
|
// the registry reset is exactly that: fresh in-memory state, same extension
|
||||||
|
// storage underneath.
|
||||||
|
function restartWorker() {
|
||||||
|
jest.resetModules();
|
||||||
|
return require("../src/shared/phishingDomains");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Reset delta state before each test to avoid cross-test contamination.
|
||||||
|
// Note: vendored sets are immutable and always present.
|
||||||
|
beforeEach(() => {
|
||||||
|
_reset();
|
||||||
|
clearStorage();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("phishingDomains", () => {
|
||||||
|
describe("vendored blocklist", () => {
|
||||||
|
test("vendored blacklist is loaded from bundled JSON", () => {
|
||||||
|
// The vendored blocklist should have a large number of entries
|
||||||
|
expect(_getVendoredBlacklistSize()).toBeGreaterThan(100000);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects domains from vendored blacklist", () => {
|
||||||
|
// These are well-known phishing domains in the vendored list
|
||||||
|
expect(isPhishingDomain("hopprotocol.pro")).toBe(true);
|
||||||
|
expect(isPhishingDomain("blast-pools.pages.dev")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("getBlocklistSize includes vendored entries", () => {
|
||||||
|
expect(getBlocklistSize()).toBeGreaterThan(100000);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("hostnameVariants", () => {
|
||||||
|
test("returns exact hostname plus parent domains", () => {
|
||||||
|
const variants = hostnameVariants("sub.evil.com");
|
||||||
|
expect(variants).toEqual(["sub.evil.com", "evil.com"]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("returns just the hostname for a bare domain", () => {
|
||||||
|
const variants = hostnameVariants("example.com");
|
||||||
|
expect(variants).toEqual(["example.com"]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handles deep subdomain chains", () => {
|
||||||
|
const variants = hostnameVariants("a.b.c.d.com");
|
||||||
|
expect(variants).toEqual([
|
||||||
|
"a.b.c.d.com",
|
||||||
|
"b.c.d.com",
|
||||||
|
"c.d.com",
|
||||||
|
"d.com",
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("lowercases hostnames", () => {
|
||||||
|
const variants = hostnameVariants("Evil.COM");
|
||||||
|
expect(variants).toEqual(["evil.com"]);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("delta computation via loadConfig", () => {
|
||||||
|
test("loadConfig computes delta of new entries not in vendored list", () => {
|
||||||
|
loadConfig({
|
||||||
|
blacklist: [
|
||||||
|
"brand-new-scam-site-xyz123.com",
|
||||||
|
"hopprotocol.pro", // already in vendored
|
||||||
|
],
|
||||||
|
});
|
||||||
|
// Only the new domain should be in the delta
|
||||||
|
expect(
|
||||||
|
_getDeltaBlacklist().has("brand-new-scam-site-xyz123.com"),
|
||||||
|
).toBe(true);
|
||||||
|
expect(_getDeltaBlacklist().has("hopprotocol.pro")).toBe(false);
|
||||||
|
expect(getDeltaSize()).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("re-loading config replaces previous delta", () => {
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["first-scam-xyz.com"],
|
||||||
|
});
|
||||||
|
expect(isPhishingDomain("first-scam-xyz.com")).toBe(true);
|
||||||
|
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["second-scam-xyz.com"],
|
||||||
|
});
|
||||||
|
expect(isPhishingDomain("first-scam-xyz.com")).toBe(false);
|
||||||
|
expect(isPhishingDomain("second-scam-xyz.com")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("getBlocklistSize includes both vendored and delta", () => {
|
||||||
|
const baseSize = getBlocklistSize();
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["delta-only-scam-xyz.com"],
|
||||||
|
});
|
||||||
|
expect(getBlocklistSize()).toBe(baseSize + 1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("isPhishingDomain with delta + vendored", () => {
|
||||||
|
test("detects domain from delta blacklist", () => {
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["fresh-scam-xyz.com"],
|
||||||
|
});
|
||||||
|
expect(isPhishingDomain("fresh-scam-xyz.com")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects domain from vendored blacklist", () => {
|
||||||
|
// No delta loaded — vendored still works
|
||||||
|
expect(isPhishingDomain("hopprotocol.pro")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("returns false for clean domains", () => {
|
||||||
|
expect(isPhishingDomain("etherscan.io")).toBe(false);
|
||||||
|
expect(isPhishingDomain("example.com")).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects subdomain of blacklisted domain (vendored)", () => {
|
||||||
|
expect(isPhishingDomain("app.hopprotocol.pro")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("detects subdomain of blacklisted domain (delta)", () => {
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["delta-phish-xyz.com"],
|
||||||
|
});
|
||||||
|
expect(isPhishingDomain("sub.delta-phish-xyz.com")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("case-insensitive matching", () => {
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["Delta-Scam-XYZ.COM"],
|
||||||
|
});
|
||||||
|
expect(isPhishingDomain("delta-scam-xyz.com")).toBe(true);
|
||||||
|
expect(isPhishingDomain("DELTA-SCAM-XYZ.COM")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("returns false for empty/null hostname", () => {
|
||||||
|
expect(isPhishingDomain("")).toBe(false);
|
||||||
|
expect(isPhishingDomain(null)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("handles config with no blacklist key", () => {
|
||||||
|
loadConfig({});
|
||||||
|
expect(getDeltaSize()).toBe(0);
|
||||||
|
// Vendored list still works
|
||||||
|
expect(isPhishingDomain("hopprotocol.pro")).toBe(true);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("extension storage persistence", () => {
|
||||||
|
test("delta is persisted to extension storage, not localStorage", async () => {
|
||||||
|
await loadConfig({
|
||||||
|
blacklist: ["persisted-scam-xyz.com"],
|
||||||
|
});
|
||||||
|
const stored = storageStore[DELTA_STORAGE_KEY];
|
||||||
|
expect(stored).toBeDefined();
|
||||||
|
expect(stored.blacklist).toContain("persisted-scam-xyz.com");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the fetch timestamp is persisted alongside the delta", async () => {
|
||||||
|
const before = Date.now();
|
||||||
|
await loadConfig({ blacklist: ["timestamped-scam-xyz.com"] });
|
||||||
|
const stored = storageStore[DELTA_STORAGE_KEY];
|
||||||
|
expect(typeof stored.lastFetchTime).toBe("number");
|
||||||
|
expect(stored.lastFetchTime).toBeGreaterThanOrEqual(before);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an oversized delta is dropped entirely, timestamp included", async () => {
|
||||||
|
// A record above the 256 KiB cap is not worth keeping; the
|
||||||
|
// timestamp goes with it so the next start re-fetches rather than
|
||||||
|
// claiming freshness for a delta that was never stored.
|
||||||
|
const huge = [];
|
||||||
|
for (let i = 0; i < 20000; i++) {
|
||||||
|
huge.push(`oversize-scam-${i}-xyzxyzxyzxyzxyz.com`);
|
||||||
|
}
|
||||||
|
await loadConfig({ blacklist: huge });
|
||||||
|
expect(storageStore[DELTA_STORAGE_KEY]).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("delta is cleared on _reset", () => {
|
||||||
|
loadConfig({
|
||||||
|
blacklist: ["temp-scam-xyz.com"],
|
||||||
|
});
|
||||||
|
expect(getDeltaSize()).toBe(1);
|
||||||
|
_reset();
|
||||||
|
expect(getDeltaSize()).toBe(0);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("real-world blocklist patterns", () => {
|
||||||
|
test("detects known phishing domains from vendored list", () => {
|
||||||
|
expect(isPhishingDomain("uniswap-trade.web.app")).toBe(true);
|
||||||
|
expect(isPhishingDomain("hopprotocol.pro")).toBe(true);
|
||||||
|
expect(isPhishingDomain("blast-pools.pages.dev")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("does not flag legitimate domains", () => {
|
||||||
|
expect(isPhishingDomain("opensea.io")).toBe(false);
|
||||||
|
expect(isPhishingDomain("etherscan.io")).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("phishing list across a service worker restart", () => {
|
||||||
|
beforeEach(() => {
|
||||||
|
clearStorage();
|
||||||
|
jest.resetModules();
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.fetch;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a revived worker restores the persisted delta without re-fetching", async () => {
|
||||||
|
const first = require("../src/shared/phishingDomains");
|
||||||
|
await first.loadConfig({ blacklist: ["restart-scam-xyz.com"] });
|
||||||
|
|
||||||
|
const revived = restartWorker();
|
||||||
|
// Nothing in memory yet — this is a brand new module instance.
|
||||||
|
expect(revived.getDeltaSize()).toBe(0);
|
||||||
|
|
||||||
|
global.fetch = jest.fn();
|
||||||
|
await revived.initPhishingList();
|
||||||
|
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
expect(revived.getDeltaSize()).toBe(1);
|
||||||
|
expect(revived.isPhishingDomain("restart-scam-xyz.com")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("repeated wakes inside the cache window never re-fetch", async () => {
|
||||||
|
const first = require("../src/shared/phishingDomains");
|
||||||
|
await first.loadConfig({ blacklist: ["no-storm-scam-xyz.com"] });
|
||||||
|
|
||||||
|
global.fetch = jest.fn();
|
||||||
|
for (let i = 0; i < 5; i++) {
|
||||||
|
const revived = restartWorker();
|
||||||
|
await revived.initPhishingList();
|
||||||
|
}
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a persisted timestamp older than the TTL causes a fetch on startup", async () => {
|
||||||
|
const first = require("../src/shared/phishingDomains");
|
||||||
|
await first.loadConfig({ blacklist: ["stale-scam-xyz.com"] });
|
||||||
|
|
||||||
|
// Age the persisted record past the 24-hour TTL.
|
||||||
|
storageStore[first.DELTA_STORAGE_KEY].lastFetchTime =
|
||||||
|
Date.now() - first.CACHE_TTL_MS - 1000;
|
||||||
|
|
||||||
|
const revived = restartWorker();
|
||||||
|
global.fetch = jest.fn(async () => ({
|
||||||
|
ok: true,
|
||||||
|
json: async () => ({ blacklist: ["refreshed-scam-xyz.com"] }),
|
||||||
|
}));
|
||||||
|
await revived.initPhishingList();
|
||||||
|
|
||||||
|
expect(global.fetch).toHaveBeenCalledTimes(1);
|
||||||
|
expect(revived.isPhishingDomain("refreshed-scam-xyz.com")).toBe(true);
|
||||||
|
expect(revived.isPhishingDomain("stale-scam-xyz.com")).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a first start with nothing persisted fetches immediately", async () => {
|
||||||
|
const fresh = restartWorker();
|
||||||
|
global.fetch = jest.fn(async () => ({
|
||||||
|
ok: true,
|
||||||
|
json: async () => ({ blacklist: ["first-run-scam-xyz.com"] }),
|
||||||
|
}));
|
||||||
|
await fresh.initPhishingList();
|
||||||
|
|
||||||
|
expect(global.fetch).toHaveBeenCalledTimes(1);
|
||||||
|
expect(fresh.isPhishingDomain("first-run-scam-xyz.com")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("updatePhishingList honours the persisted timestamp on its own", async () => {
|
||||||
|
// The startup path calls updatePhishingList() directly, so it must
|
||||||
|
// load persisted state itself rather than relying on anything else
|
||||||
|
// having finished first.
|
||||||
|
const first = require("../src/shared/phishingDomains");
|
||||||
|
await first.loadConfig({ blacklist: ["alarm-tick-scam-xyz.com"] });
|
||||||
|
|
||||||
|
const revived = restartWorker();
|
||||||
|
global.fetch = jest.fn();
|
||||||
|
await revived.updatePhishingList();
|
||||||
|
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
expect(revived.isPhishingDomain("alarm-tick-scam-xyz.com")).toBe(true);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The alarm period alone must set the cadence. lastFetchTime is stamped when
|
||||||
|
// the fetch completes, so it lands one fetch latency after the alarm that
|
||||||
|
// caused it; a freshness guard timed to the alarm period therefore vetoes
|
||||||
|
// every scheduled tick and halves the real refresh rate. These tests measure
|
||||||
|
// the interval between fetches that actually happened.
|
||||||
|
describe("phishing refresh steady-state cadence", () => {
|
||||||
|
const { PHISHING_REFRESH_PERIOD_MINUTES } = require("../src/shared/alarms");
|
||||||
|
const PERIOD_MS = PHISHING_REFRESH_PERIOD_MINUTES * 60 * 1000;
|
||||||
|
|
||||||
|
let clockSpy;
|
||||||
|
let now;
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
clearStorage();
|
||||||
|
jest.resetModules();
|
||||||
|
now = Date.UTC(2026, 0, 1, 0, 0, 0);
|
||||||
|
clockSpy = jest.spyOn(Date, "now").mockImplementation(() => now);
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
clockSpy.mockRestore();
|
||||||
|
delete global.fetch;
|
||||||
|
});
|
||||||
|
|
||||||
|
function fetchStub(latencyMs, seen) {
|
||||||
|
return jest.fn(async () => {
|
||||||
|
seen.push(now);
|
||||||
|
// A network fetch takes time, and lastFetchTime is stamped after
|
||||||
|
// it, not when the alarm fired.
|
||||||
|
now += latencyMs;
|
||||||
|
return { ok: true, json: async () => ({ blacklist: [] }) };
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
test("ten alarm ticks produce ten fetches, one per period", async () => {
|
||||||
|
const fetchedAt = [];
|
||||||
|
global.fetch = fetchStub(5000, fetchedAt);
|
||||||
|
|
||||||
|
const startup = require("../src/shared/phishingDomains");
|
||||||
|
const T0 = now;
|
||||||
|
await startup.initPhishingList();
|
||||||
|
expect(fetchedAt).toEqual([T0]);
|
||||||
|
|
||||||
|
const TICKS = 10;
|
||||||
|
let tickAt = T0 + PERIOD_MS;
|
||||||
|
for (let i = 0; i < TICKS; i++) {
|
||||||
|
now = tickAt;
|
||||||
|
tickAt += PERIOD_MS;
|
||||||
|
// The browser wakes a terminated worker to deliver the alarm, so
|
||||||
|
// every tick starts from cold memory and the persisted record.
|
||||||
|
const revived = restartWorker();
|
||||||
|
await revived.refreshPhishingListOnSchedule();
|
||||||
|
}
|
||||||
|
|
||||||
|
expect(fetchedAt).toHaveLength(TICKS + 1);
|
||||||
|
const intervals = fetchedAt.slice(1).map((t, i) => t - fetchedAt[i]);
|
||||||
|
expect(intervals).toEqual(new Array(TICKS).fill(PERIOD_MS));
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the scheduled tick fetches whatever the last fetch's latency was", async () => {
|
||||||
|
// The alarm fires one period after the previous alarm, which is
|
||||||
|
// `latency` short of one period since the fetch it caused completed.
|
||||||
|
for (const latency of [200, 1000, 5000]) {
|
||||||
|
clearStorage();
|
||||||
|
jest.resetModules();
|
||||||
|
storageStore[DELTA_STORAGE_KEY] = {
|
||||||
|
blacklist: [],
|
||||||
|
lastFetchTime: now - PERIOD_MS + latency,
|
||||||
|
lastAttemptTime: now - PERIOD_MS,
|
||||||
|
};
|
||||||
|
const mod = require("../src/shared/phishingDomains");
|
||||||
|
const fetchedAt = [];
|
||||||
|
global.fetch = fetchStub(latency, fetchedAt);
|
||||||
|
|
||||||
|
await mod.refreshPhishingListOnSchedule();
|
||||||
|
expect(fetchedAt).toHaveLength(1);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a worker wake inside the cache window still does not fetch", async () => {
|
||||||
|
// The TTL is not removed, only taken off the scheduled path. Chrome
|
||||||
|
// revives the worker every ~30 seconds and every revival runs the
|
||||||
|
// startup path, so the TTL still has to keep that off the network.
|
||||||
|
storageStore[DELTA_STORAGE_KEY] = {
|
||||||
|
blacklist: [],
|
||||||
|
lastFetchTime: now - PERIOD_MS + 5000,
|
||||||
|
lastAttemptTime: now - PERIOD_MS,
|
||||||
|
};
|
||||||
|
const mod = require("../src/shared/phishingDomains");
|
||||||
|
global.fetch = jest.fn();
|
||||||
|
|
||||||
|
await mod.initPhishingList();
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("phishing list timestamps that cannot be trusted", () => {
|
||||||
|
let clockSpy;
|
||||||
|
let now;
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
clearStorage();
|
||||||
|
jest.resetModules();
|
||||||
|
now = Date.UTC(2026, 0, 1, 0, 0, 0);
|
||||||
|
clockSpy = jest.spyOn(Date, "now").mockImplementation(() => now);
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
clockSpy.mockRestore();
|
||||||
|
delete global.fetch;
|
||||||
|
});
|
||||||
|
|
||||||
|
function okFetch() {
|
||||||
|
return jest.fn(async () => ({
|
||||||
|
ok: true,
|
||||||
|
json: async () => ({ blacklist: ["recovered-scam-xyz.com"] }),
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
// jest.resetModules() clears the call record of a jest.fn, and simulating
|
||||||
|
// a worker restart is exactly that call. Anything counted across restarts
|
||||||
|
// has to be counted outside the mock.
|
||||||
|
function countingFetch(counter, response) {
|
||||||
|
return async () => {
|
||||||
|
counter.calls++;
|
||||||
|
return response();
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a lastFetchTime in the future is discarded rather than trusted", async () => {
|
||||||
|
// Clock skew or a restored profile backup writes one. Every guard
|
||||||
|
// measures `Date.now() - stamp` and only tests the lower bound, so a
|
||||||
|
// stamp a year ahead would suppress updates for a year, and now that
|
||||||
|
// the value is persisted it would outlive every worker.
|
||||||
|
storageStore[DELTA_STORAGE_KEY] = {
|
||||||
|
blacklist: ["poisoned-scam-xyz.com"],
|
||||||
|
lastFetchTime: now + 365 * 24 * 60 * 60 * 1000,
|
||||||
|
lastAttemptTime: 0,
|
||||||
|
};
|
||||||
|
const mod = require("../src/shared/phishingDomains");
|
||||||
|
global.fetch = okFetch();
|
||||||
|
|
||||||
|
await mod.initPhishingList();
|
||||||
|
|
||||||
|
expect(global.fetch).toHaveBeenCalledTimes(1);
|
||||||
|
expect(mod.isPhishingDomain("recovered-scam-xyz.com")).toBe(true);
|
||||||
|
// And the record it leaves behind is sane, so recovery is permanent.
|
||||||
|
expect(
|
||||||
|
storageStore[DELTA_STORAGE_KEY].lastFetchTime,
|
||||||
|
).toBeLessThanOrEqual(now);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a lastAttemptTime in the future does not suppress the retry", async () => {
|
||||||
|
storageStore[DELTA_STORAGE_KEY] = {
|
||||||
|
lastAttemptTime: now + 365 * 24 * 60 * 60 * 1000,
|
||||||
|
};
|
||||||
|
const mod = require("../src/shared/phishingDomains");
|
||||||
|
global.fetch = okFetch();
|
||||||
|
|
||||||
|
await mod.initPhishingList();
|
||||||
|
expect(global.fetch).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an oversized delta does not re-download on every worker wake", async () => {
|
||||||
|
// The delta and its freshness claim are both dropped, which is right,
|
||||||
|
// but nothing then says a fetch just happened. Chrome cycles the
|
||||||
|
// worker roughly every 30 seconds idle, so without the attempt stamp
|
||||||
|
// this is a full blocklist download per wake, forever.
|
||||||
|
const huge = [];
|
||||||
|
for (let i = 0; i < 20000; i++) {
|
||||||
|
huge.push(`oversize-scam-${i}-xyzxyzxyzxyzxyz.com`);
|
||||||
|
}
|
||||||
|
const counter = { calls: 0 };
|
||||||
|
global.fetch = countingFetch(counter, () => ({
|
||||||
|
ok: true,
|
||||||
|
json: async () => ({ blacklist: huge }),
|
||||||
|
}));
|
||||||
|
|
||||||
|
for (let wake = 0; wake < 4; wake++) {
|
||||||
|
const revived = restartWorker();
|
||||||
|
await revived.initPhishingList();
|
||||||
|
now += 30 * 1000; // idle timeout, worker torn down and revived
|
||||||
|
}
|
||||||
|
|
||||||
|
expect(counter.calls).toBe(1);
|
||||||
|
expect(storageStore[DELTA_STORAGE_KEY].blacklist).toBeUndefined();
|
||||||
|
expect(typeof storageStore[DELTA_STORAGE_KEY].lastAttemptTime).toBe(
|
||||||
|
"number",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a failing fetch is not retried on every worker wake either", async () => {
|
||||||
|
const counter = { calls: 0 };
|
||||||
|
global.fetch = countingFetch(counter, () => ({
|
||||||
|
ok: false,
|
||||||
|
status: 503,
|
||||||
|
}));
|
||||||
|
|
||||||
|
for (let wake = 0; wake < 4; wake++) {
|
||||||
|
const revived = restartWorker();
|
||||||
|
await revived.initPhishingList();
|
||||||
|
now += 30 * 1000;
|
||||||
|
}
|
||||||
|
|
||||||
|
expect(counter.calls).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the retry floor expires, so a failure is not permanent", async () => {
|
||||||
|
const {
|
||||||
|
MIN_FETCH_ATTEMPT_INTERVAL_MS,
|
||||||
|
} = require("../src/shared/phishingDomains");
|
||||||
|
const counter = { calls: 0 };
|
||||||
|
global.fetch = countingFetch(counter, () => ({
|
||||||
|
ok: false,
|
||||||
|
status: 503,
|
||||||
|
}));
|
||||||
|
|
||||||
|
await restartWorker().initPhishingList();
|
||||||
|
expect(counter.calls).toBe(1);
|
||||||
|
|
||||||
|
// Still inside the floor: no retry.
|
||||||
|
now += MIN_FETCH_ATTEMPT_INTERVAL_MS - 1000;
|
||||||
|
await restartWorker().initPhishingList();
|
||||||
|
expect(counter.calls).toBe(1);
|
||||||
|
|
||||||
|
// Past it: the extension goes back to the network.
|
||||||
|
now += 2000;
|
||||||
|
await restartWorker().initPhishingList();
|
||||||
|
expect(counter.calls).toBe(2);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the scheduled tick ignores the retry floor", async () => {
|
||||||
|
// The alarm period is far above the floor, but the floor exists to
|
||||||
|
// throttle wakes, not the schedule.
|
||||||
|
storageStore[DELTA_STORAGE_KEY] = { lastAttemptTime: now - 1000 };
|
||||||
|
const mod = require("../src/shared/phishingDomains");
|
||||||
|
global.fetch = okFetch();
|
||||||
|
|
||||||
|
await mod.refreshPhishingListOnSchedule();
|
||||||
|
expect(global.fetch).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
123
tests/sendTokenSelect.test.js
Normal file
123
tests/sendTokenSelect.test.js
Normal file
@@ -0,0 +1,123 @@
|
|||||||
|
// Tests for the token filtering in the Send view's token selector
|
||||||
|
// (src/popup/views/send.js).
|
||||||
|
//
|
||||||
|
// The selector decides which of the user's tokens can be spent at all, so
|
||||||
|
// over-filtering here is worse than in the history list: the asset is not
|
||||||
|
// merely hidden, it becomes unspendable through the UI. Issue #230: an
|
||||||
|
// explorer that omits holders_count was read as "zero holders" and the token
|
||||||
|
// disappeared from this list.
|
||||||
|
//
|
||||||
|
// renderSendTokenSelect only ever touches getElementById, createElement,
|
||||||
|
// innerHTML, value, textContent and appendChild, so a small stub document is
|
||||||
|
// enough to drive it; the real DOM behaviour of the view is covered by
|
||||||
|
// tests/e2e/run.js.
|
||||||
|
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const { renderSendTokenSelect } = require("../src/popup/views/send");
|
||||||
|
|
||||||
|
const USDC_CONTRACT = "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48";
|
||||||
|
const NOVEL_TOKEN = "0x1111111111111111111111111111111111111111";
|
||||||
|
|
||||||
|
let select;
|
||||||
|
|
||||||
|
function installStubDocument() {
|
||||||
|
select = { innerHTML: "", children: [] };
|
||||||
|
select.appendChild = (child) => select.children.push(child);
|
||||||
|
globalThis.document = {
|
||||||
|
getElementById: (id) => (id === "send-token" ? select : null),
|
||||||
|
createElement: () => ({ value: "", textContent: "" }),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// The symbols offered for sending, excluding the hardcoded ETH option that
|
||||||
|
// renderSendTokenSelect writes straight into innerHTML.
|
||||||
|
function offeredTokens() {
|
||||||
|
return select.children.map((opt) => opt.value.toLowerCase());
|
||||||
|
}
|
||||||
|
|
||||||
|
function tokenBalance(overrides) {
|
||||||
|
return {
|
||||||
|
address: NOVEL_TOKEN,
|
||||||
|
symbol: "SPAMTKN",
|
||||||
|
decimals: 18,
|
||||||
|
balance: "12.5",
|
||||||
|
holders: 50000,
|
||||||
|
...overrides,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function render(tokenBalances) {
|
||||||
|
installStubDocument();
|
||||||
|
renderSendTokenSelect({ address: "0x" + "a".repeat(40), tokenBalances });
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
state.fraudContracts = [];
|
||||||
|
state.hideLowHolderTokens = true;
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the low-holder rule in the send token selector", () => {
|
||||||
|
test("ETH is always offered", () => {
|
||||||
|
render([]);
|
||||||
|
expect(select.innerHTML).toBe('<option value="ETH">ETH</option>');
|
||||||
|
expect(offeredTokens()).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a token with plenty of holders is offered", () => {
|
||||||
|
render([tokenBalance()]);
|
||||||
|
expect(offeredTokens()).toEqual([NOVEL_TOKEN]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a token reporting zero holders is withheld", () => {
|
||||||
|
render([tokenBalance({ holders: 0 })]);
|
||||||
|
expect(offeredTokens()).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("boundary: 999 holders is withheld, 1000 is offered", () => {
|
||||||
|
render([tokenBalance({ holders: 999 })]);
|
||||||
|
expect(offeredTokens()).toEqual([]);
|
||||||
|
render([tokenBalance({ holders: 1000 })]);
|
||||||
|
expect(offeredTokens()).toEqual([NOVEL_TOKEN]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Issue #230: an unknown holder count must not read as zero. A token the
|
||||||
|
// user demonstrably holds — it has a balance — cannot be made unspendable
|
||||||
|
// by a field the block explorer failed to report.
|
||||||
|
test("a token whose holder count is unknown is still offered", () => {
|
||||||
|
render([tokenBalance({ holders: null })]);
|
||||||
|
expect(offeredTokens()).toEqual([NOVEL_TOKEN]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a token balance carrying no holders field at all is offered", () => {
|
||||||
|
const t = tokenBalance();
|
||||||
|
delete t.holders;
|
||||||
|
render([t]);
|
||||||
|
expect(offeredTokens()).toEqual([NOVEL_TOKEN]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the rule is bypassed entirely when the setting is off", () => {
|
||||||
|
state.hideLowHolderTokens = false;
|
||||||
|
render([tokenBalance({ holders: 0 })]);
|
||||||
|
expect(offeredTokens()).toEqual([NOVEL_TOKEN]);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the other send-selector rules are unaffected", () => {
|
||||||
|
test("a token spoofing a known symbol from a wrong address is withheld", () => {
|
||||||
|
render([
|
||||||
|
tokenBalance({ symbol: "USDC", holders: null }),
|
||||||
|
tokenBalance({ address: USDC_CONTRACT, symbol: "USDC" }),
|
||||||
|
]);
|
||||||
|
expect(offeredTokens()).toEqual([USDC_CONTRACT.toLowerCase()]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a blocklisted fraud contract is withheld even with an unknown count", () => {
|
||||||
|
state.fraudContracts = [NOVEL_TOKEN.toUpperCase()];
|
||||||
|
render([tokenBalance({ holders: null })]);
|
||||||
|
expect(offeredTokens()).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
111
tests/settingsUtcTimestamps.test.js
Normal file
111
tests/settingsUtcTimestamps.test.js
Normal file
@@ -0,0 +1,111 @@
|
|||||||
|
// Tests for the UTC Timestamps setting.
|
||||||
|
//
|
||||||
|
// The checkbox was moved out of the Token Spam Protection well and into the
|
||||||
|
// Display well next to the theme selector. It is wired by id through the $()
|
||||||
|
// helper, so the move cannot break the handler — but nothing in the suite said
|
||||||
|
// so. These tests pin both halves down: the markup lives in Display and
|
||||||
|
// nowhere else, and the value still round-trips through storage.
|
||||||
|
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
|
||||||
|
const POPUP_HTML = fs.readFileSync(
|
||||||
|
path.join(__dirname, "..", "src", "popup", "index.html"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
|
||||||
|
// The body of one `<div class="bg-well ...">` well, selected by its heading.
|
||||||
|
function wellWithHeading(html, heading) {
|
||||||
|
const headingIndex = html.indexOf(
|
||||||
|
'<h3 class="font-bold mb-1">' + heading + "</h3>",
|
||||||
|
);
|
||||||
|
expect(headingIndex).toBeGreaterThan(-1);
|
||||||
|
const start = html.lastIndexOf('<div class="bg-well', headingIndex);
|
||||||
|
const end = html.indexOf('<div class="bg-well', headingIndex);
|
||||||
|
return html.slice(start, end === -1 ? html.length : end);
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("the UTC Timestamps checkbox placement", () => {
|
||||||
|
test("the checkbox appears exactly once in the popup markup", () => {
|
||||||
|
const matches = POPUP_HTML.match(/id="settings-utc-timestamps"/g);
|
||||||
|
expect(matches).toHaveLength(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("it renders in the Display well, alongside the theme selector", () => {
|
||||||
|
const display = wellWithHeading(POPUP_HTML, "Display");
|
||||||
|
|
||||||
|
expect(display).toContain('id="settings-utc-timestamps"');
|
||||||
|
expect(display).toContain('id="settings-theme"');
|
||||||
|
});
|
||||||
|
|
||||||
|
test("it does not render in the Token Spam Protection well", () => {
|
||||||
|
const spam = wellWithHeading(POPUP_HTML, "Token Spam Protection");
|
||||||
|
|
||||||
|
expect(spam).not.toContain('id="settings-utc-timestamps"');
|
||||||
|
// The filters that do belong there are untouched.
|
||||||
|
expect(spam).toContain('id="settings-hide-low-holders"');
|
||||||
|
expect(spam).toContain('id="settings-hide-fraud-contracts"');
|
||||||
|
expect(spam).toContain('id="settings-hide-dust"');
|
||||||
|
expect(spam).toContain('id="settings-dust-threshold"');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the UTC Timestamps setting round-trips through storage", () => {
|
||||||
|
let store;
|
||||||
|
|
||||||
|
function loadStateModule() {
|
||||||
|
store = {};
|
||||||
|
global.chrome = {
|
||||||
|
storage: {
|
||||||
|
local: {
|
||||||
|
get: async (key) =>
|
||||||
|
key in store ? { [key]: store[key] } : {},
|
||||||
|
set: async (obj) => Object.assign(store, obj),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
jest.resetModules();
|
||||||
|
return require("../src/shared/state");
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("defaults to off with nothing persisted", async () => {
|
||||||
|
const { state, loadState } = loadStateModule();
|
||||||
|
|
||||||
|
await loadState();
|
||||||
|
|
||||||
|
expect(state.utcTimestamps).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an enabled checkbox is persisted and read back", async () => {
|
||||||
|
const first = loadStateModule();
|
||||||
|
|
||||||
|
// What the change handler in views/settings.js does.
|
||||||
|
first.state.utcTimestamps = true;
|
||||||
|
await first.saveState();
|
||||||
|
expect(store.autistmask.utcTimestamps).toBe(true);
|
||||||
|
|
||||||
|
// A fresh popup load sees it.
|
||||||
|
jest.resetModules();
|
||||||
|
const second = require("../src/shared/state");
|
||||||
|
expect(second.state.utcTimestamps).toBe(false);
|
||||||
|
await second.loadState();
|
||||||
|
expect(second.state.utcTimestamps).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("turning it back off is persisted too", async () => {
|
||||||
|
const { state, saveState, loadState } = loadStateModule();
|
||||||
|
|
||||||
|
state.utcTimestamps = true;
|
||||||
|
await saveState();
|
||||||
|
state.utcTimestamps = false;
|
||||||
|
await saveState();
|
||||||
|
|
||||||
|
state.utcTimestamps = true;
|
||||||
|
await loadState();
|
||||||
|
expect(state.utcTimestamps).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
94
tests/showPhrase.test.js
Normal file
94
tests/showPhrase.test.js
Normal file
@@ -0,0 +1,94 @@
|
|||||||
|
// Tests for the recovery phrase display (issue #161).
|
||||||
|
//
|
||||||
|
// These cover the parts that do not need a DOM: which wallet types may be
|
||||||
|
// offered the action at all, the exclusion of the screen from the set of
|
||||||
|
// views the popup may reopen onto, and the absence of any path from this
|
||||||
|
// module to the logger. The DOM behaviour it guards — nothing rendered
|
||||||
|
// before the password is accepted, a wrong password revealing nothing, and
|
||||||
|
// the wipe on leaving — is driven against the real popup in a real browser
|
||||||
|
// by tests/e2e/run.js, which is where every other view behaviour is tested.
|
||||||
|
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
|
||||||
|
const { walletHasRecoveryPhrase } = require("../src/shared/wallet");
|
||||||
|
const { RESTORABLE_VIEWS } = require("../src/popup/restorableViews");
|
||||||
|
|
||||||
|
const SHOW_PHRASE_VIEW = "show-phrase";
|
||||||
|
|
||||||
|
// helpers.js pulls in state.js, which reads chrome.storage.local at load.
|
||||||
|
function loadHelpers() {
|
||||||
|
globalThis.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
return require("../src/popup/views/helpers");
|
||||||
|
}
|
||||||
|
|
||||||
|
describe("which wallets have a recovery phrase", () => {
|
||||||
|
test("an HD wallet does", () => {
|
||||||
|
expect(walletHasRecoveryPhrase({ type: "hd" })).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
// A key wallet holds a bare private key and an xprv wallet an extended
|
||||||
|
// private key. Neither can be turned back into words, so neither may be
|
||||||
|
// offered the action.
|
||||||
|
test("a key wallet does not", () => {
|
||||||
|
expect(walletHasRecoveryPhrase({ type: "key" })).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an xprv wallet does not", () => {
|
||||||
|
expect(walletHasRecoveryPhrase({ type: "xprv" })).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an unknown or missing wallet type does not", () => {
|
||||||
|
expect(walletHasRecoveryPhrase({ type: "something-new" })).toBe(false);
|
||||||
|
expect(walletHasRecoveryPhrase({})).toBe(false);
|
||||||
|
expect(walletHasRecoveryPhrase(undefined)).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("views the popup may reopen onto", () => {
|
||||||
|
// Restoring onto a secret screen would put the phrase on screen with no
|
||||||
|
// password prompt in front of it, on a popup the user may have reopened
|
||||||
|
// by accident.
|
||||||
|
test("the recovery phrase screen is not restorable", () => {
|
||||||
|
expect(RESTORABLE_VIEWS.has(SHOW_PHRASE_VIEW)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the private key export screen is not restorable either", () => {
|
||||||
|
expect(RESTORABLE_VIEWS.has("export-privkey")).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the recovery phrase screen is still a registered view", () => {
|
||||||
|
const { VIEWS } = loadHelpers();
|
||||||
|
expect(VIEWS).toContain(SHOW_PHRASE_VIEW);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Guards the other direction: a restorable name that is not a real view
|
||||||
|
// would leave restoreView() showing nothing at all.
|
||||||
|
test("every restorable view is a registered view", () => {
|
||||||
|
const { VIEWS } = loadHelpers();
|
||||||
|
for (const view of RESTORABLE_VIEWS) {
|
||||||
|
expect(VIEWS).toContain(view);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("the phrase cannot reach the logger", () => {
|
||||||
|
const source = fs.readFileSync(
|
||||||
|
path.join(__dirname, "..", "src", "popup", "views", "showPhrase.js"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
|
||||||
|
// The decrypted phrase only ever lives in a local and in the DOM node
|
||||||
|
// that displays it. The module has no logger to hand it to, and this
|
||||||
|
// pins that: src/shared/log.js writes to the console, and a console
|
||||||
|
// record of a recovery phrase outlives the popup.
|
||||||
|
test("the view does not import src/shared/log.js", () => {
|
||||||
|
expect(source).not.toMatch(/require\(["'][^"']*shared\/log["']\)/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the view calls no logger method", () => {
|
||||||
|
expect(source).not.toMatch(/\blog\.(debugf|infof|warnf|errorf)\b/);
|
||||||
|
});
|
||||||
|
});
|
||||||
161
tests/state.test.js
Normal file
161
tests/state.test.js
Normal file
@@ -0,0 +1,161 @@
|
|||||||
|
const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||||
|
|
||||||
|
function oneWallet() {
|
||||||
|
return [{ name: "Wallet 1", type: "hd", addresses: [ADDRESS] }];
|
||||||
|
}
|
||||||
|
|
||||||
|
// state.js resolves the storage API at require time, so the stub has to exist
|
||||||
|
// before the module is loaded, and the module registry has to be reset between
|
||||||
|
// cases because `state` is a module-level singleton.
|
||||||
|
function loadModuleWith(persisted) {
|
||||||
|
jest.resetModules();
|
||||||
|
const set = jest.fn(async () => {});
|
||||||
|
global.chrome = {
|
||||||
|
storage: {
|
||||||
|
local: {
|
||||||
|
get: jest.fn(async () =>
|
||||||
|
persisted ? { autistmask: persisted } : {},
|
||||||
|
),
|
||||||
|
set,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
return { mod: require("../src/shared/state"), set };
|
||||||
|
}
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
delete global.chrome;
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("loadState hasWallet reconciliation", () => {
|
||||||
|
// A profile that deleted its last wallet on a build predating the write
|
||||||
|
// path fix keeps hasWallet: true forever. It must load as no wallet, which
|
||||||
|
// is what sends the popup to the welcome view.
|
||||||
|
test("stored hasWallet true with zero wallets loads as no wallet", async () => {
|
||||||
|
const { mod } = loadModuleWith({ hasWallet: true, wallets: [] });
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hasWallet).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("stored hasWallet true with a missing wallets key loads as no wallet", async () => {
|
||||||
|
const { mod } = loadModuleWith({ hasWallet: true });
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.wallets).toEqual([]);
|
||||||
|
expect(mod.state.hasWallet).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("stored hasWallet false with one wallet loads as having a wallet", async () => {
|
||||||
|
const { mod } = loadModuleWith({
|
||||||
|
hasWallet: false,
|
||||||
|
wallets: oneWallet(),
|
||||||
|
});
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hasWallet).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("absent hasWallet with wallets present loads as having a wallet", async () => {
|
||||||
|
const { mod } = loadModuleWith({ wallets: oneWallet() });
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hasWallet).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("consistent stored states are preserved", async () => {
|
||||||
|
const withWallet = loadModuleWith({
|
||||||
|
hasWallet: true,
|
||||||
|
wallets: oneWallet(),
|
||||||
|
});
|
||||||
|
await withWallet.mod.loadState();
|
||||||
|
expect(withWallet.mod.state.hasWallet).toBe(true);
|
||||||
|
|
||||||
|
const without = loadModuleWith({ hasWallet: false, wallets: [] });
|
||||||
|
await without.mod.loadState();
|
||||||
|
expect(without.mod.state.hasWallet).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("empty storage leaves the default no-wallet state", async () => {
|
||||||
|
const { mod } = loadModuleWith(null);
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hasWallet).toBe(false);
|
||||||
|
expect(mod.state.wallets).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The correction is derived on every load rather than written back, so a
|
||||||
|
// load never has a storage side effect.
|
||||||
|
test("loadState does not write to storage", async () => {
|
||||||
|
const { mod, set } = loadModuleWith({ hasWallet: true, wallets: [] });
|
||||||
|
await mod.loadState();
|
||||||
|
expect(set).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
// Deriving must not disturb the rest of the load.
|
||||||
|
test("other persisted fields still load", async () => {
|
||||||
|
const { mod } = loadModuleWith({
|
||||||
|
hasWallet: false,
|
||||||
|
wallets: oneWallet(),
|
||||||
|
networkId: "sepolia",
|
||||||
|
theme: "dark",
|
||||||
|
activeAddress: ADDRESS,
|
||||||
|
});
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.networkId).toBe("sepolia");
|
||||||
|
expect(mod.state.theme).toBe("dark");
|
||||||
|
expect(mod.state.activeAddress).toBe(ADDRESS);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// The known-symbol spoof filter is a safety filter, so an existing profile
|
||||||
|
// stored before the setting existed must load with it on rather than with
|
||||||
|
// undefined, which would read as off.
|
||||||
|
describe("hideSpoofedSymbols persistence", () => {
|
||||||
|
test("defaults to on with empty storage", async () => {
|
||||||
|
const { mod } = loadModuleWith(null);
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hideSpoofedSymbols).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a profile stored without the key loads with it on", async () => {
|
||||||
|
const { mod } = loadModuleWith({ wallets: oneWallet() });
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hideSpoofedSymbols).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an explicit false survives the load", async () => {
|
||||||
|
const { mod } = loadModuleWith({
|
||||||
|
wallets: oneWallet(),
|
||||||
|
hideSpoofedSymbols: false,
|
||||||
|
});
|
||||||
|
await mod.loadState();
|
||||||
|
expect(mod.state.hideSpoofedSymbols).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("saveState persists the flag", async () => {
|
||||||
|
const { mod, set } = loadModuleWith(null);
|
||||||
|
mod.state.hideSpoofedSymbols = false;
|
||||||
|
await mod.saveState();
|
||||||
|
expect(set).toHaveBeenCalledWith({
|
||||||
|
autistmask: expect.objectContaining({ hideSpoofedSymbols: false }),
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the flag round-trips off through save and load", async () => {
|
||||||
|
const first = loadModuleWith(null);
|
||||||
|
first.mod.state.hideSpoofedSymbols = false;
|
||||||
|
await first.mod.saveState();
|
||||||
|
const persisted = first.set.mock.calls[0][0].autistmask;
|
||||||
|
|
||||||
|
const second = loadModuleWith(persisted);
|
||||||
|
await second.mod.loadState();
|
||||||
|
expect(second.mod.state.hideSpoofedSymbols).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the flag round-trips back on through save and load", async () => {
|
||||||
|
const first = loadModuleWith(null);
|
||||||
|
first.mod.state.hideSpoofedSymbols = true;
|
||||||
|
await first.mod.saveState();
|
||||||
|
const persisted = first.set.mock.calls[0][0].autistmask;
|
||||||
|
|
||||||
|
const second = loadModuleWith(persisted);
|
||||||
|
await second.mod.loadState();
|
||||||
|
expect(second.mod.state.hideSpoofedSymbols).toBe(true);
|
||||||
|
});
|
||||||
|
});
|
||||||
296
tests/symbolSpoof.test.js
Normal file
296
tests/symbolSpoof.test.js
Normal file
@@ -0,0 +1,296 @@
|
|||||||
|
// Tests for the known-symbol spoof rule (src/shared/symbolSpoof.js) and for
|
||||||
|
// its application on all three surfaces that show tokens: the transaction
|
||||||
|
// history, the Send token selector, and the balance list.
|
||||||
|
//
|
||||||
|
// Issue #235: the three surfaces disagreed about what a `null` entry in
|
||||||
|
// KNOWN_SYMBOLS means. The history and the selector read it as "no contract
|
||||||
|
// may bear this symbol" and filtered a fake `ETH` ERC-20; the balance list
|
||||||
|
// read it as "no comparison is possible" and listed the fake token next to
|
||||||
|
// the user's real ETH, which is where a user forms their belief about what
|
||||||
|
// they own. The rule now lives in one module, so a fourth surface cannot
|
||||||
|
// reintroduce a fourth reading, and these tests assert the same attack on
|
||||||
|
// each surface.
|
||||||
|
//
|
||||||
|
// Nothing here touches the network: global.fetch is a throwing stub and the
|
||||||
|
// only fetch path in the modules under test (debugFetch, from
|
||||||
|
// src/shared/log) is mocked at the module boundary.
|
||||||
|
|
||||||
|
// The RPC provider is replaced so that refreshBalances can be driven end to
|
||||||
|
// end: the native balance it reports must survive a balance list in which
|
||||||
|
// every ERC-20 row is a fake ETH. Everything else in ethers is the real
|
||||||
|
// module, including the formatters the assertions depend on.
|
||||||
|
jest.mock("ethers", () => {
|
||||||
|
const actual = jest.requireActual("ethers");
|
||||||
|
class StubProvider {
|
||||||
|
async getBalance() {
|
||||||
|
return 1234500000000000000n;
|
||||||
|
}
|
||||||
|
async lookupAddress() {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
...actual,
|
||||||
|
JsonRpcProvider: StubProvider,
|
||||||
|
Network: { from: () => ({}) },
|
||||||
|
};
|
||||||
|
});
|
||||||
|
|
||||||
|
jest.mock("../src/shared/log", () => ({
|
||||||
|
log: {
|
||||||
|
debugf: () => {},
|
||||||
|
infof: () => {},
|
||||||
|
warnf: () => {},
|
||||||
|
errorf: () => {},
|
||||||
|
},
|
||||||
|
debugFetch: jest.fn(),
|
||||||
|
setRuntimeDebug: () => {},
|
||||||
|
isDebug: () => false,
|
||||||
|
}));
|
||||||
|
|
||||||
|
global.fetch = jest.fn(() => {
|
||||||
|
throw new Error("tests must not perform network requests");
|
||||||
|
});
|
||||||
|
global.chrome = {
|
||||||
|
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||||
|
};
|
||||||
|
|
||||||
|
const { isSpoofedSymbol } = require("../src/shared/symbolSpoof");
|
||||||
|
const { KNOWN_SYMBOLS } = require("../src/shared/tokenList");
|
||||||
|
const { filterTransactions } = require("../src/shared/transactions");
|
||||||
|
const {
|
||||||
|
fetchTokenBalances,
|
||||||
|
refreshBalances,
|
||||||
|
} = require("../src/shared/balances");
|
||||||
|
const { renderSendTokenSelect } = require("../src/popup/views/send");
|
||||||
|
const { state } = require("../src/shared/state");
|
||||||
|
const { debugFetch } = require("../src/shared/log");
|
||||||
|
|
||||||
|
// The fake "Ethereum" token with symbol "ETH" from the attack documented in
|
||||||
|
// README.md, given a holder count high enough to clear every other filter so
|
||||||
|
// that only the known-symbol rule can catch it.
|
||||||
|
const FAKE_ETH_CONTRACT = "0xd05339f9ea5ab9d9f03b9d57f671d2abd1f55c82";
|
||||||
|
const HOLDER = "0x66133e8ea0f5d1d612d2502a968757d1048c214a";
|
||||||
|
const USDC_CONTRACT = "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48";
|
||||||
|
const WETH_CONTRACT = "0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2";
|
||||||
|
const BLOCKSCOUT = "https://eth.blockscout.com/api/v2";
|
||||||
|
|
||||||
|
describe("the shared rule", () => {
|
||||||
|
test('"ETH" is still the null-mapped symbol these tests assume', () => {
|
||||||
|
expect(KNOWN_SYMBOLS.get("ETH")).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a contract bearing a null-mapped symbol is a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol("ETH", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("even a genuine contract may not bear a null-mapped symbol", () => {
|
||||||
|
expect(isSpoofedSymbol("ETH", WETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the native asset carries no contract and is never a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol("ETH", null)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol("ETH", undefined)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol("ETH", "")).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The native exemption is "has no contract address", not "the symbol is
|
||||||
|
// ETH". A second null-mapped symbol added to the table later inherits
|
||||||
|
// both halves of the rule without any call site being revisited.
|
||||||
|
test("a newly null-mapped symbol behaves the same way", () => {
|
||||||
|
const added = !KNOWN_SYMBOLS.has("XTZTEST");
|
||||||
|
KNOWN_SYMBOLS.set("XTZTEST", null);
|
||||||
|
try {
|
||||||
|
expect(isSpoofedSymbol("XTZTEST", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
expect(isSpoofedSymbol("XTZTEST", null)).toBe(false);
|
||||||
|
} finally {
|
||||||
|
if (added) KNOWN_SYMBOLS.delete("XTZTEST");
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a known symbol from its own contract is not a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol("USDC", USDC_CONTRACT)).toBe(false);
|
||||||
|
expect(isSpoofedSymbol("usdc", USDC_CONTRACT.toUpperCase())).toBe(
|
||||||
|
false,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a known symbol from another contract is a spoof", () => {
|
||||||
|
expect(isSpoofedSymbol("USDC", FAKE_ETH_CONTRACT)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a symbol that is not in the table is not judged here", () => {
|
||||||
|
expect(isSpoofedSymbol("SPAMTKN", FAKE_ETH_CONTRACT)).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("surface 1: the transaction history", () => {
|
||||||
|
function fakeEthTransfer() {
|
||||||
|
return {
|
||||||
|
hash: "0x" + "1".repeat(64),
|
||||||
|
symbol: "ETH",
|
||||||
|
contractAddress: FAKE_ETH_CONTRACT,
|
||||||
|
holders: 900000,
|
||||||
|
valueGwei: null,
|
||||||
|
isContractCall: false,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
test("a fake ETH token transfer is filtered", () => {
|
||||||
|
const result = filterTransactions([fakeEthTransfer()], {
|
||||||
|
hideSpoofedSymbols: true,
|
||||||
|
hideFraudContracts: true,
|
||||||
|
hideLowHolderTokens: true,
|
||||||
|
hideDustTransactions: true,
|
||||||
|
dustThresholdGwei: 100000,
|
||||||
|
});
|
||||||
|
expect(result.transactions).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a real native ETH transfer survives", () => {
|
||||||
|
const native = {
|
||||||
|
hash: "0x" + "2".repeat(64),
|
||||||
|
symbol: "ETH",
|
||||||
|
contractAddress: null,
|
||||||
|
holders: null,
|
||||||
|
valueGwei: 5000000,
|
||||||
|
isContractCall: false,
|
||||||
|
};
|
||||||
|
const result = filterTransactions([native], {
|
||||||
|
hideSpoofedSymbols: true,
|
||||||
|
hideFraudContracts: true,
|
||||||
|
hideLowHolderTokens: true,
|
||||||
|
hideDustTransactions: true,
|
||||||
|
dustThresholdGwei: 100000,
|
||||||
|
});
|
||||||
|
expect(result.transactions).toEqual([native]);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("surface 2: the Send token selector", () => {
|
||||||
|
let select;
|
||||||
|
|
||||||
|
function render(tokenBalances) {
|
||||||
|
select = { innerHTML: "", children: [] };
|
||||||
|
select.appendChild = (child) => select.children.push(child);
|
||||||
|
globalThis.document = {
|
||||||
|
getElementById: (id) => (id === "send-token" ? select : null),
|
||||||
|
createElement: () => ({ value: "", textContent: "" }),
|
||||||
|
};
|
||||||
|
renderSendTokenSelect({
|
||||||
|
address: "0x" + "a".repeat(40),
|
||||||
|
tokenBalances,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
state.fraudContracts = [];
|
||||||
|
state.hideLowHolderTokens = true;
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a fake ETH token is not selectable", () => {
|
||||||
|
render([
|
||||||
|
{
|
||||||
|
address: FAKE_ETH_CONTRACT,
|
||||||
|
symbol: "ETH",
|
||||||
|
decimals: 18,
|
||||||
|
balance: "0.005",
|
||||||
|
holders: 900000,
|
||||||
|
},
|
||||||
|
]);
|
||||||
|
expect(select.children).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("native ETH remains the always-present option", () => {
|
||||||
|
render([]);
|
||||||
|
expect(select.innerHTML).toBe('<option value="ETH">ETH</option>');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("surface 3: the balance list", () => {
|
||||||
|
function respondWith(items) {
|
||||||
|
debugFetch.mockImplementation(async () => ({
|
||||||
|
ok: true,
|
||||||
|
status: 200,
|
||||||
|
statusText: "OK",
|
||||||
|
json: async () => items,
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
function fakeEthItem(overrides = {}) {
|
||||||
|
return {
|
||||||
|
value: "5000000000000000",
|
||||||
|
token: {
|
||||||
|
type: "ERC-20",
|
||||||
|
address_hash: FAKE_ETH_CONTRACT,
|
||||||
|
symbol: "ETH",
|
||||||
|
name: "Ethereum",
|
||||||
|
decimals: "18",
|
||||||
|
holders_count: "900000",
|
||||||
|
...overrides,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
debugFetch.mockReset();
|
||||||
|
});
|
||||||
|
|
||||||
|
// The bug in issue #235: this token cleared the balance list's own
|
||||||
|
// 1,000-holder floor and was listed as a holding named ETH.
|
||||||
|
test("a fake ETH token clearing the holder floor is filtered", async () => {
|
||||||
|
respondWith([fakeEthItem()]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("tracking the fake token manually does not admit it either", async () => {
|
||||||
|
respondWith([fakeEthItem({ holders_count: "0" })]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, [
|
||||||
|
{ address: FAKE_ETH_CONTRACT },
|
||||||
|
]);
|
||||||
|
expect(balances).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a genuine token keeps its place in the list", async () => {
|
||||||
|
respondWith([
|
||||||
|
fakeEthItem({
|
||||||
|
address_hash: USDC_CONTRACT,
|
||||||
|
symbol: "USDC",
|
||||||
|
name: "USD Coin",
|
||||||
|
decimals: "6",
|
||||||
|
}),
|
||||||
|
]);
|
||||||
|
const balances = await fetchTokenBalances(HOLDER, BLOCKSCOUT, []);
|
||||||
|
expect(balances).toHaveLength(1);
|
||||||
|
expect(balances[0].symbol).toBe("USDC");
|
||||||
|
});
|
||||||
|
|
||||||
|
// The trap in this change: the user's real ETH balance is not an ERC-20
|
||||||
|
// and is fetched over RPC in refreshBalances, so it never passes through
|
||||||
|
// this loop at all. An explorer row that is not an ERC-20 is dropped
|
||||||
|
// before the symbol rule is consulted.
|
||||||
|
test("a non-ERC-20 row claiming ETH never reaches the symbol rule", async () => {
|
||||||
|
respondWith([fakeEthItem({ type: "ERC-721" })]);
|
||||||
|
expect(await fetchTokenBalances(HOLDER, BLOCKSCOUT, [])).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// The money test: the user holds real ETH and has been airdropped a fake
|
||||||
|
// ETH ERC-20. The fake is gone from the list of tokens; the real balance
|
||||||
|
// is exactly what the node reported.
|
||||||
|
test("the real native ETH balance survives a fake ETH airdrop", async () => {
|
||||||
|
respondWith([fakeEthItem()]);
|
||||||
|
const addr = { address: HOLDER };
|
||||||
|
await refreshBalances(
|
||||||
|
[{ addresses: [addr] }],
|
||||||
|
"https://rpc.example.invalid",
|
||||||
|
BLOCKSCOUT,
|
||||||
|
[],
|
||||||
|
);
|
||||||
|
expect(addr.balance).toBe("1.2345");
|
||||||
|
expect(addr.tokenBalances).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("no test in this file performed a network request", () => {
|
||||||
|
expect(global.fetch).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
});
|
||||||
1552
tests/transactions.test.js
Normal file
1552
tests/transactions.test.js
Normal file
File diff suppressed because it is too large
Load Diff
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user