Compare commits

..

1 Commits

Author SHA1 Message Date
c8e193335d fix: a shared ticker no longer hides one of its two real tokens (closes #276)
All checks were successful
check / check (push) Successful in 33s
KNOWN_SYMBOLS maps a symbol to the set of contract addresses that bear
it, instead of to one of them.

A ticker is not unique, and the bundled list proves it: seven of its 512
tokens -- FRAX, REUSD, TON, EURE, MSUSD, MUSD and JPYC -- share a symbol
with another bundled entry at a different real contract.  The table is
built from that list first-wins, so it kept the earlier entry of each
pair and the later one was judged a spoof of its own symbol at its own
address.  A user holding any of the seven saw it filtered out of the
balance list, the transaction history and the send token selector, and
so could not spend it through the UI.

Both contracts of every pair come from the same source fetch (CoinGecko,
2026-02-27, decimals verified on-chain), so neither is stale relative to
the other and there is nothing to prefer between them.  The fix is
therefore in the shape of the table rather than in its contents: no
address was picked and none was dropped.  isSpoofedSymbol() asks set
membership where it asked equality, which does not loosen the rule --
every address in a set is one the wallet ships as a real token, and a
contract outside the set is still a spoof.  The native-asset entry stays
null and still means no contract may bear the symbol.

The suite walked KNOWN_SYMBOLS, which is derived from TOKENS, so it
could only assert that the table agreed with itself.  It now also walks
TOKENS asserting that no bundled token is filtered at its own address --
the walk that would have caught this -- pins both contracts of each of
the seven by address, asserts a third contract bearing a shared ticker
is still filtered, and asserts every address the table vouches for is a
bundled token reporting that symbol.
2026-08-12 11:14:29 +00:00
19 changed files with 262 additions and 3111 deletions

106
README.md
View File

@@ -169,34 +169,6 @@ reserve while sitting on the same side of the estimate, so swapping the two in
what [#154](https://git.eeqj.de/sneak/AutistMask/issues/154) was, and it was what [#154](https://git.eeqj.de/sneak/AutistMask/issues/154) was, and it was
previously correct by reading only. previously correct by reading only.
It also covers the **dApp approval round trips** — the one place where the
content script, the inpage provider, the background worker and the approval
popup all have to work together. A local test page is served by the route
handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
`MAIN`-world content script like any other page, and drives
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
`eth_sendTransaction` through the real prompts. Every signature is recovered in
the runner and compared against the active address, the transaction assertions
run against the raw signed transaction captured at `eth_sendRawTransaction`
rather than against anything the extension reported, rejecting each prompt is
required to return a rejection to the page rather than hang or resolve, and the
password is required to be absent from every message the approval window sends
to the background — with the message that would carry it required to be present,
so that check cannot pass by observing nothing. That last one is the standing
floor under [#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
Three limits of that coverage, none of them papered over. The RPC is stubbed
throughout, so this is **not** a real dApp against a real network with real
funds; that remains a human pass before 1.0.0. The site-connection prompt is
raised through `chrome.action.openPopup()`, and headless Chromium's
browser-action popup is not a page Playwright can see or click, so that one
prompt is driven at the URL the extension itself puts on the action — the same
page and the same approval id, but whether a real toolbar click shows it is not
observable here. And the EIP-1193 error code does not survive the last hop: the
rejection that crosses the boundary carries code 4001 and is asserted to, but
`src/content/inpage.js` rebuilds it as `new Error(message)`, so the calling page
catches an error with no `code` property.
Any test that drives a failure path on purpose declares the `console.error` it Any test that drives a failure path on purpose declares the `console.error` it
is about to provoke, via `errors.expect()`. That is not a mute: the declaration is about to provoke, via `errors.expect()`. That is not a mute: the declaration
consumes exactly one matching record, and a declaration nothing matched fails consumes exactly one matching record, and a declaration nothing matched fails
@@ -243,18 +215,10 @@ and this suite exists because exactly that class of bug shipped twice.
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a `make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver. real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
It covers popup load, wallet creation through the UI, the Add Token screen, and It covers popup load, wallet creation through the UI, and the Add Token screen.
the four dApp round trips — `eth_requestAccounts`, `personal_sign`, The suite lives in `tests/e2e/firefox/` and has **no npm dependencies at all**:
`eth_sendTransaction`, and a closed approval window rejecting with EIP-1193 4001 it is a small WebDriver client built on global `fetch` and `child_process`
— driven through the real content script, background page and approval windows. against geckodriver's HTTP API.
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
**no npm dependencies at all**: it is built on global `fetch` and
`child_process` against geckodriver's HTTP API. The dApp fixture (`dapp.js`) and
the assertions do use `ethers`, and have to — a signature is recovered in the
runner rather than believed from the extension, and the stub node has to answer
`eth_sendRawTransaction` with the hash `ethers` computes for the artifact it
sent, or `provider.broadcastTransaction()` refuses the answer.
Unlike the Chrome suite it builds its own container image rather than pulling a Unlike the Chrome suite it builds its own container image rather than pulling a
published one, because no published image carries both a pinned Firefox and a published one, because no published image carries both a pinned Firefox and a
@@ -276,30 +240,20 @@ because BiDi's `browsingContext.navigate` refuses `moz-extension://` outright.
**Any uncaught error from a `moz-extension://` source fails the run**, including **Any uncaught error from a `moz-extension://` source fails the run**, including
errors from the background page, which the suite never navigates to: a `throw` errors from the background page, which the suite never navigates to: a `throw`
at the top of `src/background/index.js` kills the background page and fails at the top of `src/background/index.js` kills the background page and fails
step 1. Content scripts **are** exercised now — the dApp steps drive a page step 1. Content-script errors should arrive by the same route, but this suite
served from loopback, which survives `--network none` — but the _capture_ of a does not exercise it and does not claim it — with `--network none` there is no
content-script error by this route is still unproven: no probe has forced a `http://` page for a content script to be injected into. Errors from add-on
throw inside one and watched it fail the run, so it remains an expectation install and background startup are folded into step 1 rather than discarded.
rather than a demonstrated fact. Errors from add-on install and background Errors are read from the privileged `nsIConsoleService` in Marionette's chrome
startup are folded into step 1 rather than discarded. context and filtered to non-warning entries whose `sourceName` is the extension
origin. That mechanism is not a stylistic choice. WebDriver BiDi's
One error is tolerated rather than fatal, listed in `ALLOWED_ERRORS` in `log.entryAdded` delivers **nothing** for extension pages: on a plain `http://`
`tests/e2e/firefox/run.js` with the issue that will delete it, and printed on page it reports uncaught errors with stack traces, and on the `moz-extension://`
every occurrence so the concession stays visible in the run output. It is popup it reports zero events, because Firefox's remote agent excludes extension
Firefox reporting the site-approval popup's unawaited `sendMessage` settling browsing contexts from BiDi observation. Any harness built on Playwright-BiDi or
after `window.close()` unloaded the context — the same teardown ordering as Puppeteer-BiDi would therefore see nothing and report success, which is exactly
[#275](https://git.eeqj.de/sneak/AutistMask/issues/275), and unsuppressable from the vacuous check this repo has already shipped twice. Do not migrate this suite
the calling code, because `BaseContext.wrapPromise` reports it whether or not a to BiDi.
handler is attached. Errors are read from the privileged `nsIConsoleService` in
Marionette's chrome context and filtered to non-warning entries whose
`sourceName` is the extension origin. That mechanism is not a stylistic choice.
WebDriver BiDi's `log.entryAdded` delivers **nothing** for extension pages: on a
plain `http://` page it reports uncaught errors with stack traces, and on the
`moz-extension://` popup it reports zero events, because Firefox's remote agent
excludes extension browsing contexts from BiDi observation. Any harness built on
Playwright-BiDi or Puppeteer-BiDi would therefore see nothing and report
success, which is exactly the vacuous check this repo has already shipped twice.
Do not migrate this suite to BiDi.
Two limits are worth knowing, both real differences from the Chrome suite: Two limits are worth knowing, both real differences from the Chrome suite:
@@ -323,19 +277,17 @@ Two limits are worth knowing, both real differences from the Chrome suite:
but a step that logs heavily could evict unread errors. What poll-based costs but a step that logs heavily could evict unread errors. What poll-based costs
is location, not coverage: an error cannot be placed within a step the way the is location, not coverage: an error cannot be placed within a step the way the
Chrome suite's `pageerror` events place it. Chrome suite's `pageerror` events place it.
- **Almost nothing is stubbed, which inverts the coverage of network-dependent - **Nothing is stubbed, which inverts the coverage of network-dependent code.**
code.** The container still runs with `--network none`, so the run is offline There is no fixture layer; the container runs with `--network none` instead,
and no request can escape. The one thing it can reach is the loopback fixture so the run is offline and deterministic and no request can escape. The
in `tests/e2e/firefox/dapp.js`, which serves the dApp page and a JSON-RPC node extension swallows its own fetch failures, so the flows are unaffected — but
and which the extension's `rpcUrl` is pointed at for the dApp steps; a every network call fails, so only the _failure_ branches of code that depends
JSON-RPC method that fixture does not model fails the run rather than on one are ever executed. A `ReferenceError` in the success path of
answering `null`. Everything else — Blockscout, the price feed, the phishing `renderTransactions`, or of price or balance rendering, passes this suite
blocklist — has no fixture and simply fails, and the extension swallows its green. The offline run is also weaker than the Chrome suite's interception: it
own fetch failures, so only the _failure_ branches of that code are ever proves nothing got out, but it cannot report which requests were attempted.
executed. A `ReferenceError` in the success path of `renderTransactions`, or Closing that gap needs a fixture layer, deliberately out of scope for this
of price rendering, passes this suite green. The offline run is also weaker harness.
than the Chrome suite's interception for those calls: it proves nothing got
out, but it cannot report which requests were attempted.
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
`make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser `make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser

38
TODO.md
View File

@@ -45,33 +45,6 @@ undefined identifiers, which is how
# Completed Steps # Completed Steps
- 2026-08-12: One shared extension-API module,
[`src/shared/browserApi.js`](src/shared/browserApi.js), is the only place in
the tree that names `browser` or `chrome`. Every call site returns a promise;
`runtime.lastError` is gone. The same commit gives the Firefox suite the four
dApp round trips — `eth_requestAccounts`, `personal_sign`,
`eth_sendTransaction` and a closed approval window rejecting with EIP-1193
4001 — against a page and a JSON-RPC node served from loopback, which survives
`--network none`. **The premise of
[#153](https://git.eeqj.de/sneak/AutistMask/issues/153) does not survive that
harness**: Firefox's `browser.*` honours a trailing Chrome-style callback and
populates `runtime.lastError`, both measured directly on Firefox 153.0.3, and
all four flows pass against the unconverted code. What landed is a uniformity
and coverage change, not a repair of a broken target.
- 2026-08-12: EIP-1193 error codes now reach the page. `src/content/inpage.js`
rebuilt every failure as `new Error(error.message)`, so the code the
background produced and the content script relayed intact was dropped in the
last hop and a dApp checking `err.code === 4001` saw `undefined` — a wallet
the user deliberately declined was indistinguishable from one that broke. The
provider now rejects with a `ProviderRpcError` carrying `code` and, where the
boundary sent one, `data`, passed through verbatim rather than matched against
a list, so 4001, 4100 and 4902 all arrive and a future code needs no edit
here. An error the background sent with no code stays a plain `Error` with no
`code` property, and `message` is unchanged in every case. All four request
entry points (`request`, `enable`, `send`, `sendAsync`) are covered by
`tests/inpageErrors.test.js`, and the e2e probe that printed the missing code
now requires it on the page's Error as well as on the wire, for all four
rejected flows ([#274](https://git.eeqj.de/sneak/AutistMask/issues/274)).
- 2026-08-12: `KNOWN_SYMBOLS` now maps a symbol to the set of contract addresses - 2026-08-12: `KNOWN_SYMBOLS` now maps a symbol to the set of contract addresses
that bear it, not to one of them. A ticker is not unique: seven of the 512 that bear it, not to one of them. A ticker is not unique: seven of the 512
bundled tokens — `FRAX`, `REUSD`, `TON`, `EURE`, `MSUSD`, `MUSD` and `JPYC` bundled tokens — `FRAX`, `REUSD`, `TON`, `EURE`, `MSUSD`, `MUSD` and `JPYC`
@@ -86,17 +59,6 @@ undefined identifiers, which is how
walks `TOKENS` asserting no bundled token is filtered at its own address, walks `TOKENS` asserting no bundled token is filtered at its own address,
which is the walk the suite lacked which is the walk the suite lacked
([#276](https://git.eeqj.de/sneak/AutistMask/issues/276)). ([#276](https://git.eeqj.de/sneak/AutistMask/issues/276)).
- 2026-08-12: The dApp approval round trips are driven end to end in the
browser. A test page served by the harness speaks EIP-1193 to the real inpage
provider through the real content script, background worker and approval popup
for `eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
`eth_sendTransaction`. Every signature is recovered and compared against the
active address, the transaction is checked against the bytes handed to the
stubbed RPC, each rejection must reach the page as a rejection, and the
password must appear in no message the approval window sends — the assertion
that gives [#157](https://git.eeqj.de/sneak/AutistMask/issues/157) a permanent
floor. This does not discharge a real dApp with real funds against mainnet
([#183](https://git.eeqj.de/sneak/AutistMask/issues/183)).
- 2026-08-12: The known-symbol spoof rule now judges the symbol a user actually - 2026-08-12: The known-symbol spoof rule now judges the symbol a user actually
sees. `isSpoofedSymbol()` normalizes before the lookup — NFKC, then every sees. `isSpoofedSymbol()` normalizes before the lookup — NFKC, then every
character that paints nothing removed (the format and default-ignorable character that paints nothing removed (the format and default-ignorable

View File

@@ -39,21 +39,17 @@ const {
registerAlarmHandlers, registerAlarmHandlers,
} = require("../shared/alarms"); } = require("../shared/alarms");
const { const storageApi =
actionApi, typeof browser !== "undefined"
runtimeApi, ? browser.storage.local
storageGet, : chrome.storage.local;
tabsQuery, const runtime =
tabsSendMessage, typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
windowsApi, const windowsApi =
windowsCreate, typeof browser !== "undefined" ? browser.windows : chrome.windows;
windowsGetLastFocused, const tabsApi = typeof browser !== "undefined" ? browser.tabs : chrome.tabs;
windowsRemove, const actionApi =
} = require("../shared/browserApi"); typeof browser !== "undefined" ? browser.browserAction : chrome.action;
const runtime = runtimeApi();
const windowsNs = windowsApi();
const actionNs = actionApi();
// Connected sites (in-memory, non-persisted): { "origin:address": true } // Connected sites (in-memory, non-persisted): { "origin:address": true }
const connectedSites = {}; const connectedSites = {};
@@ -62,7 +58,7 @@ const connectedSites = {};
const pendingApprovals = {}; const pendingApprovals = {};
async function getState() { async function getState() {
const result = await storageGet("autistmask"); const result = await storageApi.get("autistmask");
return ( return (
result.autistmask || { result.autistmask || {
wallets: [], wallets: [],
@@ -126,8 +122,8 @@ async function proxyRpc(method, params) {
} }
function resetPopupUrl() { function resetPopupUrl() {
if (actionNs && typeof actionNs.setPopup === "function") { if (actionApi && typeof actionApi.setPopup === "function") {
actionNs.setPopup({ popup: "src/popup/index.html" }); actionApi.setPopup({ popup: "src/popup/index.html" });
} }
} }
@@ -183,55 +179,32 @@ function releaseApproval(approval) {
// Open approval in a separate popup window. // Open approval in a separate popup window.
// This is the primary mechanism for tx/sign approvals (triggered programmatically, // This is the primary mechanism for tx/sign approvals (triggered programmatically,
// not from a user gesture) and the fallback for site-connection approvals. // not from a user gesture) and the fallback for site-connection approvals.
// Never rejects. Its callers raise it from inside a Promise executor and drop function openApprovalWindow(id) {
// the result on the floor, so a rejection here would be unhandled.
async function openApprovalWindow(id) {
const popupUrl = runtime.getURL("src/popup/index.html?approval=" + id); const popupUrl = runtime.getURL("src/popup/index.html?approval=" + id);
const popupWidth = 360; const popupWidth = 360;
const popupHeight = 600; const popupHeight = 600;
let currentWin = null; windowsApi.getLastFocused((currentWin) => {
try { const opts = {
currentWin = await windowsGetLastFocused(); url: popupUrl,
} catch { type: "popup",
// Nothing focused to centre on. The window still opens, at whatever width: popupWidth,
// position the browser picks. height: popupHeight,
} };
if (currentWin) {
const opts = { opts.left = Math.round(
url: popupUrl, currentWin.left + (currentWin.width - popupWidth) / 2,
type: "popup", );
width: popupWidth, opts.top = Math.round(
height: popupHeight, currentWin.top + (currentWin.height - popupHeight) / 2,
}; );
if (currentWin) { }
opts.left = Math.round( windowsApi.create(opts, (win) => {
currentWin.left + (currentWin.width - popupWidth) / 2, if (win) {
); pendingApprovals[id].windowId = win.id;
opts.top = Math.round( }
currentWin.top + (currentWin.height - popupHeight) / 2, });
); });
}
let win = null;
try {
win = await windowsCreate(opts);
} catch (e) {
// No window means no approval screen and no way for the user to
// answer. The request stays pending rather than being settled behind
// their back; say so rather than failing silently.
log.errorf("could not open the approval window:", e);
return;
}
// The id the onRemoved listener matches on to turn a closed window into a
// rejection. Guarded because the create() above is a real await now: an
// address switch can settle and remove the approval while the window is
// opening, and writing the id back would resurrect a bare entry that
// nothing would ever resolve.
if (win && pendingApprovals[id]) {
pendingApprovals[id].windowId = win.id;
}
} }
// Open an approval popup and return a promise that resolves with the user decision. // Open an approval popup and return a promise that resolves with the user decision.
@@ -241,12 +214,12 @@ function requestApproval(origin, hostname) {
const id = crypto.randomUUID(); const id = crypto.randomUUID();
pendingApprovals[id] = { origin, hostname, resolve }; pendingApprovals[id] = { origin, hostname, resolve };
if (actionNs && typeof actionNs.openPopup === "function") { if (actionApi && typeof actionApi.openPopup === "function") {
actionNs.setPopup({ actionApi.setPopup({
popup: "src/popup/index.html?approval=" + id, popup: "src/popup/index.html?approval=" + id,
}); });
try { try {
const result = actionNs.openPopup(); const result = actionApi.openPopup();
if (result && typeof result.catch === "function") { if (result && typeof result.catch === "function") {
result.catch(() => openApprovalWindow(id)); result.catch(() => openApprovalWindow(id));
} }
@@ -308,7 +281,7 @@ function requestSignApproval(origin, hostname, signParams, approvedFrom) {
// Detect when an approval popup (browser-action) closes without a response. // Detect when an approval popup (browser-action) closes without a response.
// TX and sign approvals now use windows.create() and are handled by the // TX and sign approvals now use windows.create() and are handled by the
// windows.onRemoved listener below, but we still handle site-connection // windowsApi.onRemoved listener below, but we still handle site-connection
// approval disconnects here. // approval disconnects here.
runtime.onConnect.addListener((port) => { runtime.onConnect.addListener((port) => {
if (port.name.startsWith("approval:")) { if (port.name.startsWith("approval:")) {
@@ -690,26 +663,24 @@ async function handleRpc(method, params, origin) {
} }
// Broadcast chainChanged to all tabs when the network is switched. // Broadcast chainChanged to all tabs when the network is switched.
// function broadcastChainChanged(chainId) {
// Never rejects: its caller is an RPC handler that must answer the page tabsApi.query({}, (tabs) => {
// whatever the browser made of the broadcast. for (const tab of tabs) {
async function broadcastChainChanged(chainId) { tabsApi.sendMessage(
let tabs; tab.id,
try { {
tabs = await tabsQuery({}); type: "AUTISTMASK_EVENT",
} catch { eventName: "chainChanged",
return; data: chainId,
} },
for (const tab of tabs) { () => {
// A tab with no content script has no receiver, and that is the if (runtime.lastError) {
// ordinary case rather than a fault. The rejection it produces is the // expected for tabs without our content script
// promise-shaped form of the runtime.lastError this used to read. }
tabsSendMessage(tab.id, { },
type: "AUTISTMASK_EVENT", );
eventName: "chainChanged", }
data: chainId, });
}).catch(() => {});
}
} }
// Broadcast accountsChanged to all tabs, respecting per-address permissions // Broadcast accountsChanged to all tabs, respecting per-address permissions
@@ -734,36 +705,41 @@ async function broadcastAccountsChanged() {
: { approved: false, remember: false }; : { approved: false, remember: false };
if (!settleApproval(id, rejection)) continue; if (!settleApproval(id, rejection)) continue;
if (approval.windowId) { if (approval.windowId) {
// Rejects when the window has already gone, which is a race the windowsApi.remove(approval.windowId, () => {
// user wins routinely by closing it themselves. if (runtime.lastError) {
windowsRemove(approval.windowId).catch(() => {}); // window already closed
}
});
} }
} }
resetPopupUrl(); resetPopupUrl();
const s = await getState(); const s = await getState();
const activeAddress = await getActiveAddress(); const activeAddress = await getActiveAddress();
const allowed = activeAddress ? s.allowedSites[activeAddress] || [] : []; const allowed = activeAddress ? s.allowedSites[activeAddress] || [] : [];
let tabs; tabsApi.query({}, (tabs) => {
try { for (const tab of tabs) {
tabs = await tabsQuery({}); const origin = tab.url ? new URL(tab.url).origin : "";
} catch { const hostname = extractHostname(origin);
return; const hasPermission =
} activeAddress &&
for (const tab of tabs) { (allowed.includes(hostname) ||
const origin = tab.url ? new URL(tab.url).origin : ""; connectedSites[origin + ":" + activeAddress]);
const hostname = extractHostname(origin); tabsApi.sendMessage(
const hasPermission = tab.id,
activeAddress && {
(allowed.includes(hostname) || type: "AUTISTMASK_EVENT",
connectedSites[origin + ":" + activeAddress]); eventName: "accountsChanged",
// Same as chainChanged above: a tab without our content script data: hasPermission ? [activeAddress] : [],
// rejects, and that is expected rather than a fault. },
tabsSendMessage(tab.id, { () => {
type: "AUTISTMASK_EVENT", // Ignore errors for tabs without content script
eventName: "accountsChanged", if (runtime.lastError) {
data: hasPermission ? [activeAddress] : [], // expected for tabs without our content script
}).catch(() => {}); }
} },
);
}
});
} }
// Background balance refresh: every 60 seconds when the popup isn't open. // Background balance refresh: every 60 seconds when the popup isn't open.
@@ -856,8 +832,8 @@ startBackgroundJobs();
// window is an ordinary event with an attempt already in flight behind it. // window is an ordinary event with an attempt already in flight behind it.
// settleApproval() refuses those, which leaves the attempt to report its real // settleApproval() refuses those, which leaves the attempt to report its real
// outcome to the page. // outcome to the page.
if (windowsNs && windowsNs.onRemoved) { if (windowsApi && windowsApi.onRemoved) {
windowsNs.onRemoved.addListener((windowId) => { windowsApi.onRemoved.addListener((windowId) => {
for (const [id, approval] of Object.entries(pendingApprovals)) { for (const [id, approval] of Object.entries(pendingApprovals)) {
if (approval.windowId !== windowId) continue; if (approval.windowId !== windowId) continue;
const rejection = const rejection =

View File

@@ -1,20 +1,12 @@
// AutistMask content script — bridges between inpage (window.ethereum) // AutistMask content script — bridges between inpage (window.ethereum)
// and the background service worker via extension messaging. // and the background service worker via extension messaging.
const {
hasBrowserNamespace,
runtimeApi,
sendMessage,
storageGet,
storageSet,
} = require("../shared/browserApi");
// In Chrome (MV3), inpage.js runs as a MAIN-world content script declared // In Chrome (MV3), inpage.js runs as a MAIN-world content script declared
// in the manifest, so no injection is needed here. In Firefox (MV2), the // in the manifest, so no injection is needed here. In Firefox (MV2), the
// "world" key is not supported, so we inject via a <script> tag. // "world" key is not supported, so we inject via a <script> tag.
if (hasBrowserNamespace()) { if (typeof browser !== "undefined") {
const script = document.createElement("script"); const script = document.createElement("script");
script.src = runtimeApi().getURL("src/content/inpage.js"); script.src = browser.runtime.getURL("src/content/inpage.js");
script.onload = function () { script.onload = function () {
this.remove(); this.remove();
}; };
@@ -22,27 +14,23 @@ if (hasBrowserNamespace()) {
} }
// Send the persisted EIP-6963 provider UUID to the inpage script. // Send the persisted EIP-6963 provider UUID to the inpage script.
// Generated once at install time and stored in extension storage. // Generated once at install time and stored in chrome.storage.local.
(async function sendProviderUuid() { (function sendProviderUuid() {
let uuid = null; const storage =
try { typeof browser !== "undefined"
const items = await storageGet("eip6963Uuid"); ? browser.storage.local
uuid = items?.eip6963Uuid; : chrome.storage.local;
storage.get("eip6963Uuid", (items) => {
let uuid = items?.eip6963Uuid;
if (!uuid) { if (!uuid) {
uuid = crypto.randomUUID(); uuid = crypto.randomUUID();
await storageSet({ eip6963Uuid: uuid }); storage.set({ eip6963Uuid: uuid });
} }
} catch { window.postMessage(
// Storage was unavailable or refused the write. The announcement { type: "AUTISTMASK_PROVIDER_UUID", uuid },
// still has to go out — a provider that never announces is invisible location.origin,
// to every EIP-6963 dApp — so it goes under a fresh uuid that this );
// page load will not outlive. });
if (!uuid) uuid = crypto.randomUUID();
}
window.postMessage(
{ type: "AUTISTMASK_PROVIDER_UUID", uuid },
location.origin,
);
})(); })();
// Relay requests from the page to the background script // Relay requests from the page to the background script
@@ -51,31 +39,27 @@ window.addEventListener("message", (event) => {
if (event.data?.type !== "AUTISTMASK_REQUEST") return; if (event.data?.type !== "AUTISTMASK_REQUEST") return;
const { id, method, params } = event.data; const { id, method, params } = event.data;
sendMessage({ const runtime =
type: "AUTISTMASK_RPC", typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
id,
method, runtime.sendMessage(
params, { type: "AUTISTMASK_RPC", id, method, params, origin: location.origin },
origin: location.origin, (response) => {
})
.then((response) => {
if (response) { if (response) {
window.postMessage( window.postMessage(
{ type: "AUTISTMASK_RESPONSE", id, ...response }, { type: "AUTISTMASK_RESPONSE", id, ...response },
"*", "*",
); );
} }
}) },
.catch(() => { );
// No receiver: the background context is gone. The page's promise
// stays pending, which is what it did before this was a promise
// at all; turning it into a rejection here is a change to what
// dApps see and belongs to its own issue.
});
}); });
// Listen for events pushed from the background (e.g. accountsChanged) // Listen for events pushed from the background (e.g. accountsChanged)
runtimeApi().onMessage.addListener((msg) => { const runtime =
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
runtime.onMessage.addListener((msg) => {
if (msg.type === "AUTISTMASK_EVENT") { if (msg.type === "AUTISTMASK_EVENT") {
window.postMessage( window.postMessage(
{ {

View File

@@ -11,39 +11,6 @@
let nextId = 1; let nextId = 1;
const pending = {}; const pending = {};
// EIP-1193 ProviderRpcError: `code`, `message`, optional `data`. A class
// rather than properties bolted onto an Error because this object crosses
// no boundary after construction — it is built in the page's own realm and
// handed straight to the caller's catch — so the prototype survives and
// `error.name` is a stable thing for a dApp to see.
class ProviderRpcError extends Error {
constructor(code, message, data) {
super(message);
this.name = "ProviderRpcError";
this.code = code;
if (data !== undefined) this.data = data;
}
}
// Rebuild a boundary error as the error the page catches, carrying the
// code (and data) the extension reported. Without this a dApp cannot tell
// a user's refusal (4001) from a wallet that broke, and retries or shows
// an error instead of accepting the refusal.
//
// Whatever code arrived is passed through verbatim rather than being
// matched against a list: the extension emits 4001, 4100 and 4902 today,
// and a code this file has never heard of is still the truth about what
// happened. An error reported with no code at all stays a plain Error —
// a ProviderRpcError whose `code` is undefined would advertise a
// conformance it does not have. `message` is untouched in every case.
function toPageError(error) {
const message = (error && error.message) || "Request failed";
if (error && error.code !== undefined && error.code !== null) {
return new ProviderRpcError(error.code, message, error.data);
}
return new Error(message);
}
// Listen for responses from the content script // Listen for responses from the content script
window.addEventListener("message", function onUuid(event) { window.addEventListener("message", function onUuid(event) {
if (event.source !== window) return; if (event.source !== window) return;
@@ -53,7 +20,7 @@
if (!p) return; if (!p) return;
delete pending[id]; delete pending[id];
if (error) { if (error) {
p.reject(toPageError(error)); p.reject(new Error(error.message || "Request failed"));
} else { } else {
p.resolve(result); p.resolve(result);
} }

View File

@@ -27,7 +27,8 @@ const { walletDefect } = require("../../shared/walletDefects");
const { describeSigningFailure } = require("../../shared/approvalVerify"); const { describeSigningFailure } = require("../../shared/approvalVerify");
const txStatus = require("./txStatus"); const txStatus = require("./txStatus");
const uniswap = require("../../shared/uniswap"); const uniswap = require("../../shared/uniswap");
const { notify, runtimeApi, sendMessage } = require("../../shared/browserApi"); const runtime =
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
const erc20Iface = new Interface(ERC20_ABI); const erc20Iface = new Interface(ERC20_ABI);
@@ -438,41 +439,34 @@ function showSignApproval(details) {
); );
} }
// Awaited by nobody: the popup entry point calls this and moves on. It function show(id) {
// therefore has to absorb its own failure, and a background that cannot
// describe the approval is the same outcome as an approval that is gone.
async function show(id) {
approvalId = id; approvalId = id;
runtimeApi().connect({ name: "approval:" + id }); runtime.connect({ name: "approval:" + id });
runtime.sendMessage({ type: "AUTISTMASK_GET_APPROVAL", id }, (details) => {
let details = null; if (!details) {
try { window.close();
details = await sendMessage({ type: "AUTISTMASK_GET_APPROVAL", id }); return;
} catch { }
details = null; if (details.type === "tx") {
} showTxApproval(details);
return;
if (!details) { }
window.close(); if (details.type === "sign") {
return; showSignApproval(details);
} return;
if (details.type === "tx") { }
showTxApproval(details); // Site connection approval
return; showPhishingWarning(
} "approve-site-phishing-warning",
if (details.type === "sign") { details.isPhishingDomain,
showSignApproval(details); );
return; $("approve-hostname").textContent = details.hostname;
} $("approve-address").innerHTML = approvalAddressHtml(
// Site connection approval state.activeAddress,
showPhishingWarning( );
"approve-site-phishing-warning", attachCopyHandlers("view-approve-site");
details.isPhishingDomain, $("approve-remember").checked = state.rememberSiteChoice;
); });
$("approve-hostname").textContent = details.hostname;
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
attachCopyHandlers("view-approve-site");
$("approve-remember").checked = state.rememberSiteChoice;
} }
let approvalId = null; let approvalId = null;
@@ -554,7 +548,7 @@ function init(ctx) {
$("btn-approve").addEventListener("click", () => { $("btn-approve").addEventListener("click", () => {
const remember = $("approve-remember").checked; const remember = $("approve-remember").checked;
notify({ runtime.sendMessage({
type: "AUTISTMASK_APPROVAL_RESPONSE", type: "AUTISTMASK_APPROVAL_RESPONSE",
id: approvalId, id: approvalId,
approved: true, approved: true,
@@ -565,7 +559,7 @@ function init(ctx) {
$("btn-reject").addEventListener("click", () => { $("btn-reject").addEventListener("click", () => {
const remember = $("approve-remember").checked; const remember = $("approve-remember").checked;
notify({ runtime.sendMessage({
type: "AUTISTMASK_APPROVAL_RESPONSE", type: "AUTISTMASK_APPROVAL_RESPONSE",
id: approvalId, id: approvalId,
approved: false, approved: false,
@@ -654,37 +648,29 @@ function init(ctx) {
decryptedSecret = null; decryptedSecret = null;
} }
// A send that never reaches the background is reported to the user runtime.sendMessage(payload, (response) => {
// the same way a background that refused it is: describeSigningFailure if (response && response.txHash) {
// turns a null response into the generic message below. txStatus.showWait(pendingTxDetails, response.txHash);
let response = null; return;
try { }
response = await sendMessage(payload); // A retryable failure leaves the approval pending in the
} catch { // background, so stay on this screen with a live button rather
response = null; // than sending the user to a dead end.
} const outcome = describeSigningFailure(
response,
if (response && response.txHash) { "The transaction could not be sent.",
txStatus.showWait(pendingTxDetails, response.txHash); );
return; if (outcome.retryable) {
} showError("approve-tx-error", outcome.message);
// A retryable failure leaves the approval pending in the setTxButtonBusy(false);
// background, so stay on this screen with a live button rather } else {
// than sending the user to a dead end. txStatus.showError(pendingTxDetails, null, outcome.message);
const outcome = describeSigningFailure( }
response, });
"The transaction could not be sent.",
);
if (outcome.retryable) {
showError("approve-tx-error", outcome.message);
setTxButtonBusy(false);
} else {
txStatus.showError(pendingTxDetails, null, outcome.message);
}
}); });
$("btn-reject-tx").addEventListener("click", () => { $("btn-reject-tx").addEventListener("click", () => {
notify({ runtime.sendMessage({
type: "AUTISTMASK_TX_RESPONSE", type: "AUTISTMASK_TX_RESPONSE",
id: approvalId, id: approvalId,
approved: false, approved: false,
@@ -778,31 +764,26 @@ function init(ctx) {
decryptedSecret = null; decryptedSecret = null;
} }
let response = null; runtime.sendMessage(payload, (response) => {
try { if (response && response.signature) {
response = await sendMessage(payload); window.close();
} catch { return;
response = null; }
} // The button comes back only when the approval is still pending in
// the background; otherwise it stays disabled and the message says
if (response && response.signature) { // why, because a control that cannot succeed must not look like it
window.close(); // can.
return; const outcome = describeSigningFailure(
} response,
// The button comes back only when the approval is still pending in "The message could not be signed.",
// the background; otherwise it stays disabled and the message says );
// why, because a control that cannot succeed must not look like it showError("approve-sign-error", outcome.message);
// can. if (outcome.retryable) setSignButtonBusy(false);
const outcome = describeSigningFailure( });
response,
"The message could not be signed.",
);
showError("approve-sign-error", outcome.message);
if (outcome.retryable) setSignButtonBusy(false);
}); });
$("btn-reject-sign").addEventListener("click", () => { $("btn-reject-sign").addEventListener("click", () => {
notify({ runtime.sendMessage({
type: "AUTISTMASK_SIGN_RESPONSE", type: "AUTISTMASK_SIGN_RESPONSE",
id: approvalId, id: approvalId,
approved: false, approved: false,

View File

@@ -15,7 +15,6 @@ const {
pushCurrentView, pushCurrentView,
} = require("./helpers"); } = require("./helpers");
const { state, saveState, currentAddress } = require("../../shared/state"); const { state, saveState, currentAddress } = require("../../shared/state");
const { notify } = require("../../shared/browserApi");
const { const {
updateSendBalance, updateSendBalance,
renderSendTokenSelect, renderSendTokenSelect,
@@ -294,7 +293,11 @@ function render(ctx) {
state.activeAddress = addr; state.activeAddress = addr;
await saveState(); await saveState();
render(ctx); render(ctx);
notify({ type: "AUTISTMASK_ACTIVE_CHANGED" }); const runtime =
typeof browser !== "undefined"
? browser.runtime
: chrome.runtime;
runtime.sendMessage({ type: "AUTISTMASK_ACTIVE_CHANGED" });
} }
}); });
}); });

View File

@@ -29,7 +29,8 @@ const {
GITEA_COMMIT_URL, GITEA_COMMIT_URL,
} = require("../../shared/buildInfo"); } = require("../../shared/buildInfo");
const { notify } = require("../../shared/browserApi"); const runtime =
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
let versionClickCount = 0; let versionClickCount = 0;
let versionClickTimer = null; let versionClickTimer = null;
@@ -60,7 +61,7 @@ function renderSiteList(containerId, siteMap, stateKey) {
} }
} }
await saveState(); await saveState();
notify({ type: "AUTISTMASK_REMOVE_SITE" }); runtime.sendMessage({ type: "AUTISTMASK_REMOVE_SITE" });
renderSiteList(containerId, state[key], key); renderSiteList(containerId, state[key], key);
}); });
}); });

View File

@@ -19,8 +19,6 @@
// be bypassed on the scheduled tick — see backgroundRefresh() in // be bypassed on the scheduled tick — see backgroundRefresh() in
// src/background/index.js and updatePhishingList() in shared/phishingDomains.js. // src/background/index.js and updatePhishingList() in shared/phishingDomains.js.
const { alarmsApi } = require("./browserApi");
const BALANCE_REFRESH_ALARM = "autistmask-balance-refresh"; const BALANCE_REFRESH_ALARM = "autistmask-balance-refresh";
const PHISHING_REFRESH_ALARM = "autistmask-phishing-refresh"; const PHISHING_REFRESH_ALARM = "autistmask-phishing-refresh";
@@ -28,10 +26,14 @@ const MIN_ALARM_PERIOD_MINUTES = 1;
const BALANCE_REFRESH_PERIOD_MINUTES = 1; const BALANCE_REFRESH_PERIOD_MINUTES = 1;
const PHISHING_REFRESH_PERIOD_MINUTES = 24 * 60; const PHISHING_REFRESH_PERIOD_MINUTES = 24 * 60;
// alarmsApi() resolves on use rather than at module load: the worker is torn // Resolved on use rather than captured at module load: the worker is torn
// down and re-evaluated repeatedly, and tests install a stub after requiring // down and re-evaluated repeatedly, and tests install a stub after requiring
// this module. It returns null where the API is absent, which is why every // the module.
// entry point below degrades instead of throwing. function alarmsApi() {
if (typeof browser !== "undefined" && browser.alarms) return browser.alarms;
if (typeof chrome !== "undefined" && chrome.alarms) return chrome.alarms;
return null;
}
/** /**
* Create an alarm unless one with the requested period already exists. * Create an alarm unless one with the requested period already exists.

View File

@@ -1,245 +0,0 @@
// The one place in this tree that names `browser` or `chrome`.
//
// The two targets do not agree on either the namespace or the call shape.
// Chrome MV3 exposes `chrome.*`, where tabs, windows and messaging take a
// trailing callback and report failure through the global
// `chrome.runtime.lastError`. Firefox MV2 exposes `browser.*`, where those
// same methods return promises and take no callback at all — a function
// passed where an options argument is expected is simply never invoked, so
// the call looks like it succeeded and silently never completes. Resolving
// the namespace with a ternary and then calling it Chrome-style, which is
// what this codebase used to do, is broken on Firefox in exactly that way:
// see https://git.eeqj.de/sneak/AutistMask/issues/153.
//
// The strategy is promises out, everywhere. Callers `await`; nothing outside
// this file has to know which browser it is running on.
//
// Two deliberate asymmetries, because they are what the browsers actually do
// rather than what a uniform-looking shim would pretend:
//
// - Storage is called in its PROMISE form on both namespaces.
// `chrome.storage.local.get()` returns a promise on MV3 and the popup
// already depends on that — src/shared/state.js has always awaited it, and
// that is precisely why the Firefox popup flows work today while
// everything in the issue above does not. Wrapping it in a callback here
// would be a change, not a fix.
// - notify() sends without a callback. It is for a message whose answer
// nobody reads; appending a callback would only manufacture a
// lastError/rejection for a receiver that was never expected to reply.
//
// Everything is resolved on use rather than captured at module load. The MV3
// service worker is torn down and re-evaluated repeatedly, and the unit
// suite installs its stubs on `global.chrome` around a require().
// The extension API namespace, preferring `browser.*` where it exists.
//
// Whole-namespace, never per-method: mixing `browser.tabs` with
// `chrome.windows` would also mix promise and callback semantics inside a
// single call path, which is the bug this module exists to remove.
function extensionApi() {
if (typeof browser !== "undefined" && browser) return browser;
if (typeof chrome !== "undefined" && chrome) return chrome;
return null;
}
// True when the resolved namespace is the promise-flavoured one.
//
// It doubles as "this is the Gecko/MV2 build", which is a second question
// with the same answer and one real caller: src/content/index.js has to
// inject the inpage provider itself there, because MV2 has no
// `"world": "MAIN"` for a manifest-declared content script.
function hasBrowserNamespace() {
return typeof browser !== "undefined" && !!browser;
}
function namespaceMember(name) {
const api = extensionApi();
return (api && api[name]) || null;
}
function runtimeApi() {
return namespaceMember("runtime");
}
function tabsApi() {
return namespaceMember("tabs");
}
function windowsApi() {
return namespaceMember("windows");
}
function alarmsApi() {
return namespaceMember("alarms");
}
// The toolbar button. MV3 calls it `action`, MV2 calls it `browserAction`.
function actionApi() {
const api = extensionApi();
if (!api) return null;
return api.action || api.browserAction || null;
}
// `storage.local`, or null in a context that has no storage permission. Null
// rather than a throw because two callers degrade rather than fail on it.
function storageLocal() {
const storage = namespaceMember("storage");
return (storage && storage.local) || null;
}
// The Chrome-only error channel. Never populated for a `browser.*` call,
// which is why the checks that used to guard callbacks in the background are
// gone: on this side it becomes a rejection, and on the other side there was
// never anything to read.
function lastError() {
const runtime = runtimeApi();
return (runtime && runtime.lastError) || null;
}
// Call `owner[method](...args)` and return a promise for its result.
//
// On the promise namespace the method already returns one. On the callback
// namespace the callback is appended here and lastError becomes a rejection,
// because a caller holding a promise has nowhere to check a global flag.
function invoke(owner, method, ...args) {
if (!owner || typeof owner[method] !== "function") {
return Promise.reject(
new Error(
"extension API " +
method +
"() is not available in this context",
),
);
}
if (hasBrowserNamespace()) {
try {
return Promise.resolve(owner[method](...args));
} catch (e) {
return Promise.reject(e);
}
}
return new Promise((resolve, reject) => {
owner[method](...args, (result) => {
const err = lastError();
if (err) reject(new Error(err.message || String(err)));
else resolve(result);
});
});
}
/**
* Send a message to the extension's own contexts and resolve with the reply.
*
* Rejects when nothing is listening, on both browsers. A caller that does not
* care must say so — see notify().
*
* @param {Object} message
* @returns {Promise<*>} the receiver's response.
*/
function sendMessage(message) {
return invoke(runtimeApi(), "sendMessage", message);
}
/**
* Send a message nobody is expected to answer, and swallow the fact that
* nobody did.
*
* @param {Object} message
* @returns {void}
*/
function notify(message) {
const runtime = runtimeApi();
if (!runtime || typeof runtime.sendMessage !== "function") return;
const result = runtime.sendMessage(message);
// MV3 hands back a promise for a one-argument send, and it rejects when
// the background is not listening. Unhandled, that surfaces as an error
// the e2e suites fail the run on.
if (result && typeof result.catch === "function") result.catch(() => {});
}
/**
* @param {string|string[]|Object} keys
* @returns {Promise<Object>} the stored items, or {} where storage is absent.
*/
function storageGet(keys) {
const storage = storageLocal();
if (!storage) return Promise.resolve({});
return Promise.resolve(storage.get(keys));
}
/**
* @param {Object} items
* @returns {Promise<void>}
*/
function storageSet(items) {
const storage = storageLocal();
if (!storage) return Promise.resolve();
return Promise.resolve(storage.set(items));
}
/**
* @param {Object} queryInfo
* @returns {Promise<Array>} the matching tabs.
*/
function tabsQuery(queryInfo) {
return invoke(tabsApi(), "query", queryInfo);
}
/**
* Send a message to one tab's content script.
*
* Rejects for a tab that has no receiver, which is most of them. That
* rejection is the promise-shaped replacement for the runtime.lastError
* checks the broadcast helpers used to make, and callers ignore it the same
* way.
*
* @param {number} tabId
* @param {Object} message
* @returns {Promise<*>}
*/
function tabsSendMessage(tabId, message) {
return invoke(tabsApi(), "sendMessage", tabId, message);
}
/**
* @param {Object} createData
* @returns {Promise<Object>} the created window.
*/
function windowsCreate(createData) {
return invoke(windowsApi(), "create", createData);
}
/**
* @returns {Promise<Object>} the last focused window.
*/
function windowsGetLastFocused() {
return invoke(windowsApi(), "getLastFocused");
}
/**
* @param {number} windowId
* @returns {Promise<void>}
*/
function windowsRemove(windowId) {
return invoke(windowsApi(), "remove", windowId);
}
module.exports = {
actionApi,
alarmsApi,
extensionApi,
hasBrowserNamespace,
notify,
runtimeApi,
sendMessage,
storageGet,
storageLocal,
storageSet,
tabsApi,
tabsQuery,
tabsSendMessage,
windowsApi,
windowsCreate,
windowsGetLastFocused,
windowsRemove,
};

View File

@@ -18,7 +18,6 @@
// its own refresh — see updatePhishingList(). // its own refresh — see updatePhishingList().
const vendoredConfig = require("./phishingBlocklist.json"); const vendoredConfig = require("./phishingBlocklist.json");
const { storageLocal } = require("./browserApi");
const BLOCKLIST_URL = const BLOCKLIST_URL =
"https://raw.githubusercontent.com/MetaMask/eth-phishing-detect/main/src/config.json"; "https://raw.githubusercontent.com/MetaMask/eth-phishing-detect/main/src/config.json";
@@ -47,10 +46,18 @@ let lastAttemptTime = 0;
let fetchPromise = null; let fetchPromise = null;
let loadPromise = null; let loadPromise = null;
// storageLocal() resolves on use rather than at module load, so a test can // Resolved on use rather than captured at module load, so a test can install
// install a stub after requiring this module, and it returns null where the // a stub after requiring the module and so the popup — which has no reason to
// API is absent — which is why the popup, with no reason to touch the delta, // touch the delta — does not fail to load where the API is absent.
// loads fine without it. function storageApi() {
if (typeof browser !== "undefined" && browser.storage) {
return browser.storage.local;
}
if (typeof chrome !== "undefined" && chrome.storage) {
return chrome.storage.local;
}
return null;
}
/** /**
* Sanitise a timestamp read back from storage. * Sanitise a timestamp read back from storage.
@@ -79,7 +86,7 @@ function sanitizeTimestamp(value) {
* @returns {Promise<void>} * @returns {Promise<void>}
*/ */
async function loadDeltaFromStorage() { async function loadDeltaFromStorage() {
const storage = storageLocal(); const storage = storageApi();
if (!storage) return; if (!storage) return;
try { try {
const result = await storage.get(DELTA_STORAGE_KEY); const result = await storage.get(DELTA_STORAGE_KEY);
@@ -115,7 +122,7 @@ function ensureDeltaLoaded() {
* @returns {Promise<void>} * @returns {Promise<void>}
*/ */
async function saveDeltaToStorage() { async function saveDeltaToStorage() {
const storage = storageLocal(); const storage = storageApi();
if (!storage) return; if (!storage) return;
try { try {
const data = { const data = {

View File

@@ -5,7 +5,10 @@ const { networkById } = require("./networks");
// Dependency-free constant module; safe to pull into a background bundle. // Dependency-free constant module; safe to pull into a background bundle.
const { RESTORABLE_VIEWS } = require("../popup/restorableViews"); const { RESTORABLE_VIEWS } = require("../popup/restorableViews");
const { storageGet, storageSet } = require("./browserApi"); const storageApi =
typeof browser !== "undefined"
? browser.storage.local
: chrome.storage.local;
const DEFAULT_STATE = { const DEFAULT_STATE = {
hasWallet: false, hasWallet: false,
@@ -111,11 +114,11 @@ async function saveState() {
viewData: state.viewData, viewData: state.viewData,
viewStack: state.viewStack, viewStack: state.viewStack,
}; };
await storageSet({ autistmask: persisted }); await storageApi.set({ autistmask: persisted });
} }
async function loadState() { async function loadState() {
const result = await storageGet("autistmask"); const result = await storageApi.get("autistmask");
if (result.autistmask) { if (result.autistmask) {
const saved = result.autistmask; const saved = result.autistmask;
state.wallets = saved.wallets || []; state.wallets = saved.wallets || [];

View File

@@ -1,8 +1,6 @@
// Wallet and address deletion state transitions, kept out of the views so the // Wallet and address deletion state transitions, kept out of the views so the
// selection and broadcast rules are testable without a DOM. // selection and broadcast rules are testable without a DOM.
const { notify } = require("./browserApi");
// Two records of the same address can be stored in different cases, so // Two records of the same address can be stored in different cases, so
// address equality is never a literal string comparison. // address equality is never a literal string comparison.
function sameAddress(a, b) { function sameAddress(a, b) {
@@ -146,7 +144,9 @@ function removeAddressFromState(state, walletIdx, addrIdx) {
// accountsChanged to connected sites. Same call shape as the address // accountsChanged to connected sites. Same call shape as the address
// switch in the home view. // switch in the home view.
function broadcastActiveChanged() { function broadcastActiveChanged() {
notify({ type: "AUTISTMASK_ACTIVE_CHANGED" }); const runtime =
typeof browser !== "undefined" ? browser.runtime : chrome.runtime;
runtime.sendMessage({ type: "AUTISTMASK_ACTIVE_CHANGED" });
} }
module.exports = { module.exports = {

View File

@@ -1,238 +0,0 @@
// A loopback dApp origin and stub Ethereum node for the Firefox suite.
//
// The Firefox container runs with --network none, and the harness note in
// driver.js records the consequence: with no http:// origin in reach, no
// content script was ever injected, so content-script behaviour was
// UNVERIFIED and the dApp flows could not be driven at all.
//
// --network none removes every interface except loopback, and loopback is
// enough. This serves the page and the JSON-RPC endpoint from 127.0.0.1
// inside the same container Firefox runs in, so the dApp round trips execute
// against a real http:// origin and the run stays as offline as it was: the
// only reachable peer is this process.
//
// The page itself is not written twice. DAPP_HTML comes from the Chrome
// suite's fixture, so both harnesses drive the same __dapp API and the same
// message log.
//
// Unlike driver.js this file does use ethers, and it has to: the node has to
// answer eth_sendRawTransaction with the hash ethers computes for the
// artifact it was handed, or provider.broadcastTransaction() refuses the
// answer, and the suite recovers signatures itself rather than believing the
// extension's own verdict.
"use strict";
const http = require("http");
const { Transaction } = require("ethers");
const { DAPP_HTML } = require("../network");
// The same fee shape the Chrome suite uses, for the same reason: it has to
// pass the ceilings in src/shared/approvalVerify.js and it has to leave the
// reserve and the estimate distinguishable.
const GAS_LIMIT = 21000n;
const BASE_FEE_WEI = 100000000000n; // 100 gwei
const PRIORITY_FEE_WEI = 1000000000n; // 1 gwei
const GAS_PRICE_WEI = BASE_FEE_WEI + PRIORITY_FEE_WEI;
const STUB_BLOCK_NUMBER = 21000000;
// A 32-byte zero word, returned for every eth_call. It is what makes ethers'
// ENS reverse lookup resolve to "no resolver set" instead of throwing, and a
// throw there reaches the console through src/shared/log.js, which fails the
// run on its own.
const ZERO_WORD = "0x" + "0".repeat(64);
// One ETH, so the popup's balance lines render something and the wallet does
// not look empty on the approval screen.
const STUB_BALANCE_WEI = 10n ** 18n;
function hex(value) {
return "0x" + BigInt(value).toString(16);
}
function latestBlock() {
return {
hash: "0x" + "11".repeat(32),
parentHash: "0x" + "22".repeat(32),
number: hex(STUB_BLOCK_NUMBER),
timestamp: hex(1767326645),
nonce: "0x0000000000000000",
difficulty: "0x0",
gasLimit: "0x1c9c380",
gasUsed: "0xf4240",
miner: "0xc0ffee0000000000000000000000000000c0ffee",
extraData: "0x",
baseFeePerGas: hex(BASE_FEE_WEI),
transactions: [],
};
}
const RPC_RESULTS = {
eth_chainId: "0x1",
net_version: "1",
eth_blockNumber: hex(STUB_BLOCK_NUMBER),
eth_getBalance: hex(STUB_BALANCE_WEI),
eth_call: ZERO_WORD,
eth_getCode: "0x",
eth_gasPrice: hex(GAS_PRICE_WEI),
eth_estimateGas: hex(GAS_LIMIT),
eth_getTransactionCount: "0x0",
eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI),
// "accepted but not mined", which is what a node says about a transaction
// it has only just taken. The wait screen the approval hands off to polls
// this for the rest of the run.
eth_getTransactionReceipt: null,
web3_clientVersion: "autistmask-e2e-firefox/0",
};
// Answer one JSON-RPC call. `broadcast` collects every raw transaction that
// reached this node, which is what the transaction assertions are made
// against — the artifact as the node saw it, never as the extension described
// it.
function rpcResult(req, state) {
const method = req.method;
if (method === "eth_sendRawTransaction") {
const raw = req.params && req.params[0];
state.broadcast.push(raw);
// ethers checks the hash it is given against the hash it computes for
// the artifact it sent, so this cannot be a fixed string.
return Transaction.from(raw).hash;
}
if (method === "eth_getBlockByNumber" || method === "eth_getBlockByHash") {
return latestBlock();
}
if (Object.prototype.hasOwnProperty.call(RPC_RESULTS, method)) {
return RPC_RESULTS[method];
}
// Never a silent default. An unstubbed method answered with null looks
// like a working node returning nothing, and the assertion downstream
// fails somewhere unrelated.
state.unstubbed.push(method);
throw new Error("no fixture for JSON-RPC method " + method);
}
function readBody(req) {
return new Promise((resolve, reject) => {
let body = "";
req.on("data", (chunk) => {
body += chunk;
});
req.on("end", () => resolve(body));
req.on("error", reject);
});
}
function handleRpcBody(body, state) {
const parsed = JSON.parse(body);
const answer = (req) => {
try {
return {
jsonrpc: "2.0",
id: req.id,
result: rpcResult(req, state),
};
} catch (e) {
return {
jsonrpc: "2.0",
id: req.id,
error: { code: -32601, message: e.message },
};
}
};
return Array.isArray(parsed) ? parsed.map(answer) : answer(parsed);
}
/**
* Serve the dApp page and the stub node on loopback.
*
* @returns {Promise<Object>} the running fixture: `url` and `origin` of the
* page, `rpcUrl` for the extension's rpcUrl setting, `broadcast` (the raw
* transactions the node received, in order), `unstubbed` (JSON-RPC methods
* nothing answered) and `close()`.
*/
async function startDappServer() {
const state = { broadcast: [], unstubbed: [], requests: [] };
const server = http.createServer((req, res) => {
const url = new URL(req.url, "http://127.0.0.1");
state.requests.push(req.method + " " + url.pathname);
if (url.pathname === "/rpc" && req.method === "POST") {
readBody(req)
.then((body) => {
const payload = JSON.stringify(handleRpcBody(body, state));
res.writeHead(200, {
"Content-Type": "application/json",
// The extension fetches this from its background
// page, whose origin is moz-extension://. Without CORS
// the fetch fails and every transaction assertion
// fails for a reason that has nothing to do with the
// wallet.
"Access-Control-Allow-Origin": "*",
});
res.end(payload);
})
.catch((e) => {
res.writeHead(500, { "Content-Type": "text/plain" });
res.end(String(e && e.message));
});
return;
}
if (url.pathname === "/") {
res.writeHead(200, { "Content-Type": "text/html; charset=utf-8" });
res.end(DAPP_HTML);
return;
}
// An empty favicon rather than a 404: a 404 is a page error in
// Firefox's console under some settings, and the suite fails the run
// on those.
if (url.pathname === "/favicon.ico") {
res.writeHead(200, { "Content-Type": "image/x-icon" });
res.end("");
return;
}
res.writeHead(404, { "Content-Type": "text/plain" });
res.end("not found");
});
await new Promise((resolve, reject) => {
server.on("error", reject);
// Port 0: this host runs many sessions at once, and a fixed port is a
// guaranteed collision rather than a possible one.
server.listen(0, "127.0.0.1", resolve);
});
const { port } = server.address();
const origin = "http://127.0.0.1:" + port;
return {
origin,
url: origin + "/",
rpcUrl: origin + "/rpc",
broadcast: state.broadcast,
unstubbed: state.unstubbed,
requests: state.requests,
close: () =>
new Promise((resolve) => {
server.closeAllConnections();
server.close(() => resolve());
}),
};
}
module.exports = {
GAS_LIMIT,
GAS_PRICE_WEI,
STUB_BALANCE_WEI,
startDappServer,
};

View File

@@ -110,26 +110,6 @@ class Driver {
"extensions.webextensions.uuids": JSON.stringify({ "extensions.webextensions.uuids": JSON.stringify({
[EXTENSION_ID]: EXTENSION_UUID, [EXTENSION_ID]: EXTENSION_UUID,
}), }),
// The container has loopback and nothing else. Firefox's own
// link-status detection can read that as "offline" and then
// refuse every request, including the ones to the loopback dApp
// origin the suite serves; this takes the decision away from it.
"network.manage-offline-status": false,
// Force the site-connection prompt down its windows.create()
// fallback.
//
// src/background/index.js prefers the toolbar-anchored popup for
// that one approval and opens a real window only when
// openPopup() refuses. A panel is not a top-level browsing
// context, so WebDriver cannot see it, list it or click in it —
// the same blind spot the Chrome harness documents. Leaving this
// at its default would make which path runs depend on whether a
// headless Firefox counts as having had a user gesture, which is
// not a thing to leave to chance in a suite that has to be able
// to fail. The window path is shipped code and the same approval
// id, so what is driven is real; what is NOT covered either way
// is the panel presentation itself.
"extensions.openPopupWithoutUserGesture.enabled": false,
}; };
const value = await this.send("POST", "/session", { const value = await this.send("POST", "/session", {
@@ -199,16 +179,6 @@ class Driver {
return this.session("POST", "/execute/sync", { script, args }); return this.session("POST", "/execute/sync", { script, args });
} }
// The asynchronous form: the script is handed a resolve callback as its
// last argument and the call settles when that is invoked. Everything
// interesting about an extension page is promise-shaped — storage reads,
// the provider's own request() — and /execute/sync cannot wait for any
// of it.
async executeAsync(script, args = []) {
await this.setContext("content");
return this.session("POST", "/execute/async", { script, args });
}
// Runs in the privileged chrome scope, where Services and Ci exist. // Runs in the privileged chrome scope, where Services and Ci exist.
async executeChrome(script, args = []) { async executeChrome(script, args = []) {
await this.setContext("chrome"); await this.setContext("chrome");
@@ -359,63 +329,6 @@ class Driver {
[selector], [selector],
); );
} }
// ------------------------------------------------------------ windows
//
// The approval prompts this suite drives are separate top-level windows
// the extension opens itself, so every one of them is a window handle
// here and the suite has to move between them explicitly.
async windowHandles() {
return this.session("GET", "/window/handles");
}
async currentWindow() {
return this.session("GET", "/window");
}
async switchToWindow(handle) {
await this.setContext("content");
await this.session("POST", "/window", { handle });
}
async newWindow(type = "window") {
await this.setContext("content");
const value = await this.session("POST", "/window/new", { type });
return value.handle;
}
// Closes the current window and leaves the session on `fallback`, because
// a session whose current window is gone fails every subsequent command
// with "no such window" rather than with anything diagnosable.
async closeWindow(fallback) {
await this.setContext("content");
await this.session("DELETE", "/window");
if (fallback) await this.switchToWindow(fallback);
}
async url() {
return this.session("GET", "/url");
}
// The handle of the first window whose URL matches, or null. Restores the
// window that was current before the search either way: a probe that
// silently relocates the session is a trap for the step after it.
async findWindow(predicate) {
const origin = await this.currentWindow();
try {
for (const handle of await this.windowHandles()) {
await this.switchToWindow(handle);
if (predicate(await this.url())) return handle;
}
return null;
} finally {
// Tolerated: the window the search started from may have been the
// one that just closed, and a throw in here would replace the
// real result with "no such window".
await this.switchToWindow(origin).catch(() => {});
}
}
} }
// ------------------------------------------------------- error capture // ------------------------------------------------------- error capture
@@ -436,15 +349,10 @@ class Driver {
// background page, which BiDi would not have covered even if it worked. // background page, which BiDi would not have covered even if it worked.
// Background-page capture is verified by probe — a throw at the top of // Background-page capture is verified by probe — a throw at the top of
// src/background/index.js, which kills the background page outright, fails // src/background/index.js, which kills the background page outright, fails
// the run. // the run. Content-script errors should arrive by the same route, but that
// // is UNVERIFIED here and must not be claimed: the container runs with
// Content scripts ARE now exercised: tests/e2e/firefox/dapp.js serves a page // --network none, so there is no http:// page for a content script to be
// from loopback, which survives --network none, and the suite drives the // injected into and this suite never exercises one.
// EIP-1193 round trips through the content script injected into it. What is
// still unproven is the CAPTURE, not the execution — no probe has forced a
// throw from inside a content script and watched it fail the run, so an
// uncaught content-script error arriving by this route remains an
// expectation rather than a demonstrated fact. Do not claim otherwise.
// //
// Warnings are excluded so the semantics match Playwright's pageerror: // Warnings are excluded so the semantics match Playwright's pageerror:
// uncaught errors only. // uncaught errors only.

View File

@@ -15,15 +15,8 @@
// UI steps below are written twice on purpose. Chrome runs on Playwright, // UI steps below are written twice on purpose. Chrome runs on Playwright,
// which cannot see extension-page errors in Firefox at all (see the BiDi // which cannot see extension-page errors in Firefox at all (see the BiDi
// note in driver.js), so the two backends have no common substrate to // note in driver.js), so the two backends have no common substrate to
// abstract over. Duplicated steps do not pay for a shim; revisit if this // abstract over. Three duplicated steps do not pay for a shim; revisit if
// suite grows to where they do. What IS shared is the dApp page fixture // this suite grows to where they do.
// itself — DAPP_HTML, served here from loopback by dapp.js — so an assertion
// about the __dapp API means the same thing on both browsers.
//
// The dApp steps need an http:// origin, which --network none was thought to
// rule out. It does not: loopback survives it, so the page and the stub node
// are served from 127.0.0.1 inside the container and the run reaches nothing
// but this process. See tests/e2e/firefox/dapp.js.
// //
// LIMITATION, and the difference from the Chrome suite worth knowing: error // LIMITATION, and the difference from the Chrome suite worth knowing: error
// capture here is POLL-BASED, not event-streamed. The console service is // capture here is POLL-BASED, not event-streamed. The console service is
@@ -47,21 +40,7 @@
const fs = require("fs"); const fs = require("fs");
const path = require("path"); const path = require("path");
const {
Transaction,
formatEther,
getAddress,
getBytes,
hexlify,
parseEther,
toQuantity,
toUtf8Bytes,
verifyMessage,
} = require("ethers");
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver"); const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
const { startDappServer } = require("./dapp");
const { STUB_COUNTERPARTY } = require("../network");
const REPO_ROOT = path.resolve(__dirname, "..", "..", ".."); const REPO_ROOT = path.resolve(__dirname, "..", "..", "..");
const POPUP_URL = EXTENSION_ORIGIN + "/src/popup/index.html"; const POPUP_URL = EXTENSION_ORIGIN + "/src/popup/index.html";
@@ -158,596 +137,8 @@ step("add token screen opens from address detail", async (env) => {
assert(picks > 0, "no common-token quick-pick buttons rendered"); assert(picks > 0, "no common-token quick-pick buttons rendered");
}); });
// ------------------------------------------------- the dApp round trips
//
// Everything above drives the popup on its own. From here the page, the
// content script, the inpage provider, the background page and the approval
// window all have to work together, which on Firefox is exactly the seam
// https://git.eeqj.de/sneak/AutistMask/issues/153 is about: every one of
// these paths used to hand a Chrome-style callback to the promise-only
// browser.* namespace and simply never complete.
//
// The shape is the Chrome suite's (tests/e2e/run.js, the #183 section) and
// the assertions mean the same things:
//
// - the signature is recovered here, in the runner, from the artifact the
// extension produced, and compared against the address read out of
// extension storage. The background verifies too; these assertions do not
// lean on that, because a test that trusted the wallet's own verdict would
// pass against a wallet that verified nothing.
// - the transaction is asserted against the raw signed transaction that
// reached the stub node, not against anything the extension reported.
//
// What this does NOT cover: a real dApp with real funds against a real
// network. The node is a fixture on loopback.
const SIGN_TEXT = "AutistMask e2e round trip: personal_sign";
const SIGN_HEX = hexlify(toUtf8Bytes(SIGN_TEXT));
const TX_VALUE_ETH = "0.0123";
const TX_VALUE_WEI = parseEther(TX_VALUE_ETH);
// Call data that decodes as nothing, so the screen assertion compares the
// calldata itself rather than a decoder's summary of it.
const TX_DATA = "0xdeadbeef" + "01".repeat(28);
const USER_REJECTION_MESSAGE = "User rejected the request.";
// Read the extension's persisted state, point its rpcUrl at the loopback stub
// node, and hand back the active address. Runs on the popup page, which is
// the one moz-extension:// document the suite has open and therefore the only
// place the storage API is reachable from.
async function pointAtStubNode(d, rpcUrl) {
const outcome = await d.executeAsync(
`const done = arguments[arguments.length - 1];
const rpcUrl = arguments[0];
const api = typeof browser !== "undefined" ? browser : chrome;
Promise.resolve(api.storage.local.get("autistmask"))
.then((r) => {
const s = r.autistmask;
if (!s) throw new Error("the extension has no persisted state");
s.rpcUrl = rpcUrl;
const w = s.wallets && s.wallets[0];
const first = w && w.addresses && w.addresses[0];
const address = s.activeAddress || (first && first.address);
if (!address) throw new Error("the extension holds no address");
return Promise.resolve(api.storage.local.set({ autistmask: s }))
.then(() => done({ address: address }));
})
.catch((e) => done({ error: String((e && e.message) || e) }));`,
[rpcUrl],
);
assert(
outcome && !outcome.error,
"could not point the extension at the stub node: " +
(outcome && outcome.error),
);
return getAddress(outcome.address);
}
// The approval window the background opened. Approvals are raised from an RPC
// call rather than from a user gesture, so the extension opens a real window
// for them, which is an ordinary window handle here.
async function waitForApprovalWindow(d, timeout = 30000) {
const deadline = Date.now() + timeout;
for (;;) {
const handle = await d.findWindow((u) => u.includes("?approval="));
if (handle) return handle;
if (Date.now() > deadline) {
throw new Error(
"the extension opened no approval window within " +
timeout +
"ms",
);
}
await sleep(100);
}
}
function startRequest(d, key, method, params) {
return d.execute(
"window.__dapp.start(arguments[0], arguments[1], arguments[2]);" +
" return true;",
[key, method, params],
);
}
// The settled outcome of a parked request, or {settled:"pending"} if it is
// still outstanding. A bounded wait rather than a bare await: "returns a
// rejection rather than hanging" is one of the things under test, and an
// await would report a hang as a step timeout with no indication of which
// call never settled.
function settleRequest(d, key, timeout = 45000) {
return d.executeAsync(
`const done = arguments[arguments.length - 1];
const key = arguments[0];
const timeout = arguments[1];
Promise.race([
window.__dapp.settle(key),
new Promise((r) => setTimeout(() => r({ settled: "pending" }), timeout)),
]).then(done, (e) => done({ settled: "error", message: String(e) }));`,
[key, timeout],
);
}
// Every AUTISTMASK_* message that has crossed between the page and the
// content script. This is the boundary half of the rejection assertion: the
// code has to be on the wire as well as on the Error the page catches, so a
// pass cannot come from the provider inventing one.
function dappMessages(d, type) {
return d.execute(
// `want` is bound outside the callback deliberately: inside it,
// arguments[0] is the message being tested, not the script argument,
// and the filter silently matches nothing.
"var want = arguments[0];" +
" return window.__dapp.messages.filter(function (m) {" +
" return !want || m.type === want; });",
[type || null],
);
}
async function lastResponseError(d) {
const responses = await dappMessages(d, "AUTISTMASK_RESPONSE");
const last = responses[responses.length - 1];
assert(last, "the page received no AUTISTMASK_RESPONSE at all");
return last.error || null;
}
// A rejected prompt, asserted at both ends: the page's promise rejected
// rather than hanging or resolving, and the response that crossed the
// boundary carried EIP-1193 code 4001.
async function assertUserRejection(d, key, label) {
const outcome = await settleRequest(d, key);
assert(
outcome.settled !== "pending",
label + " never settled: the rejected prompt left the page hanging",
);
assert(
outcome.settled === "rejected",
label + " resolved instead of rejecting: " + JSON.stringify(outcome),
);
assert(
outcome.message === USER_REJECTION_MESSAGE,
label + " rejected with the wrong message: " + outcome.message,
);
const error = await lastResponseError(d);
assert(
error && error.code === 4001,
label +
" did not carry EIP-1193 code 4001 across the boundary: " +
JSON.stringify(error),
);
assert(
outcome.hasCode,
label +
" reached the page as an error with no code property at all, so a " +
"dApp cannot tell the user's refusal from a failure: " +
JSON.stringify(outcome),
);
assert(
outcome.code === 4001,
label +
" reached the page with code " +
JSON.stringify(outcome.code) +
" rather than EIP-1193 4001",
);
assert(
outcome.name === "ProviderRpcError",
label +
" reached the page as " +
JSON.stringify(outcome.name) +
" rather than an EIP-1193 ProviderRpcError",
);
console.log(
"# " +
label +
": code 4001 on the wire and on the page's " +
outcome.name,
);
}
step("the loopback dApp page gets the real inpage provider", async (env) => {
const d = env.driver;
// The popup is still the current window; point the extension at the stub
// node from there, then reload it so its in-memory copy of the state
// carries the new rpcUrl and cannot save the old one back over it.
env.address = await pointAtStubNode(d, env.server.rpcUrl);
await d.navigate(POPUP_URL);
await d.waitVisible("#view-main", STEP_TIMEOUT_MS);
env.popupWindow = await d.currentWindow();
env.dappWindow = await d.newWindow("tab");
await d.switchToWindow(env.dappWindow);
await d.navigate(env.server.url);
// window.ethereum is not the fixture's doing — it is the shipped content
// script, injected into a real http:// origin. Waiting for it is waiting
// for the real provider to have installed itself.
await d.waitFor(
"the injected EIP-1193 provider and the test page API",
"return !!window.ethereum && !!window.__dapp;",
[],
STEP_TIMEOUT_MS,
);
// EIP-6963, asked of the provider itself. The announcement carries the
// uuid src/content/index.js reads out of extension storage — call site 1
// in the issue — and it has to name this extension and hand back the very
// object on window.ethereum.
const announced = await d.executeAsync(
`const done = arguments[arguments.length - 1];
const onAnnounce = (e) => {
window.removeEventListener("eip6963:announceProvider", onAnnounce);
done({
rdns: e.detail.info.rdns,
uuid: e.detail.info.uuid,
isWindowEthereum: e.detail.provider === window.ethereum,
});
};
window.addEventListener("eip6963:announceProvider", onAnnounce);
window.dispatchEvent(new Event("eip6963:requestProvider"));
setTimeout(() => done(null), 15000);`,
);
assert(announced, "the provider announced itself to no EIP-6963 request");
assert(
announced.rdns === "berlin.sneak.autistmask",
"the announced provider is not this extension: " +
JSON.stringify(announced),
);
assert(
announced.isWindowEthereum,
"the announced provider is not the object on window.ethereum",
);
assert(
typeof announced.uuid === "string" && announced.uuid.length === 36,
"the announcement carries no stored provider uuid: " +
JSON.stringify(announced.uuid),
);
// A full page -> content script -> background round trip that needs no
// approval, so the relay is proven before any prompt is driven. This is
// call site 2, the one that used to fail for every window.ethereum
// request a dApp made.
const chainId = await d.executeAsync(
`const done = arguments[arguments.length - 1];
window.ethereum.request({ method: "eth_chainId" }).then(
(r) => done({ ok: r }),
(e) => done({ err: String((e && e.message) || e) }),
);`,
);
assert(
chainId && chainId.ok === "0x1",
"eth_chainId did not round trip through the extension: " +
JSON.stringify(chainId),
);
console.log(
"# dapp origin " + env.server.origin + " active address " + env.address,
);
});
step(
"eth_requestAccounts approved returns the selected address",
async (env) => {
const d = env.driver;
await d.switchToWindow(env.dappWindow);
await startRequest(d, "accounts", "eth_requestAccounts", []);
const popup = await waitForApprovalWindow(d);
await d.switchToWindow(popup);
await d.waitVisible("#view-approve-site");
const hostname = await d.text("#approve-hostname");
assert(
hostname === "127.0.0.1",
"the site prompt names the wrong origin: " +
JSON.stringify(hostname),
);
const shown = await d.text("#approve-address");
assert(
shown.toLowerCase().includes(env.address.toLowerCase()),
"the site prompt shows the wrong address: " + JSON.stringify(shown),
);
// Remembered, so the origin stays authorized for the sign and transaction
// steps below.
const checked = await d.execute(
'return document.getElementById("approve-remember").checked;',
);
if (!checked) await d.click("#approve-remember");
await d.click("#btn-approve");
// The approve button closes its own window, so get off it before asking
// the page anything.
await d.switchToWindow(env.dappWindow);
const outcome = await settleRequest(d, "accounts");
assert(
outcome.settled === "resolved",
"eth_requestAccounts did not resolve: " + JSON.stringify(outcome),
);
assert(
Array.isArray(outcome.result) && outcome.result.length === 1,
"eth_requestAccounts returned no single account: " +
JSON.stringify(outcome.result),
);
assert(
getAddress(outcome.result[0]) === env.address,
"eth_requestAccounts returned " +
outcome.result[0] +
", not the selected address " +
env.address,
);
},
);
step(
"personal_sign returns a signature that recovers to the address",
async (env) => {
const d = env.driver;
await d.switchToWindow(env.dappWindow);
await startRequest(d, "sign", "personal_sign", [SIGN_HEX, env.address]);
const popup = await waitForApprovalWindow(d);
await d.switchToWindow(popup);
await d.waitVisible("#view-approve-sign");
const screen = await d.execute(
`return {
hostname: document.getElementById("approve-sign-hostname").textContent,
type: document.getElementById("approve-sign-type").textContent,
message: document.getElementById("approve-sign-message").textContent,
from: document.getElementById("approve-sign-from").textContent,
};`,
);
assert(
screen.hostname === "127.0.0.1",
"the sign prompt names the wrong origin: " +
JSON.stringify(screen.hostname),
);
assert(
screen.type === "Personal message",
"the sign prompt reports the wrong type: " +
JSON.stringify(screen.type),
);
assert(
screen.message === SIGN_TEXT,
"the sign prompt shows the wrong message: " +
JSON.stringify(screen.message),
);
assert(
screen.from.toLowerCase().includes(env.address.toLowerCase()),
"the sign prompt shows the wrong signing address: " +
JSON.stringify(screen.from),
);
await d.fill("#approve-sign-password", PASSWORD);
await d.click("#btn-approve-sign");
await d.switchToWindow(env.dappWindow);
const outcome = await settleRequest(d, "sign");
assert(
outcome.settled === "resolved",
"personal_sign did not resolve: " + JSON.stringify(outcome),
);
const recovered = getAddress(
verifyMessage(getBytes(SIGN_HEX), outcome.result),
);
console.log(
"# personal_sign: recovered=" +
recovered +
" expected=" +
env.address,
);
assert(
recovered === env.address,
"the personal_sign signature recovers to " +
recovered +
", not to the approved address " +
env.address,
);
},
);
step(
"eth_sendTransaction shows the transaction and returns its hash",
async (env) => {
const d = env.driver;
const before = env.server.broadcast.length;
await d.switchToWindow(env.dappWindow);
await startRequest(d, "tx", "eth_sendTransaction", [
{
from: env.address,
to: STUB_COUNTERPARTY,
value: toQuantity(TX_VALUE_WEI),
data: TX_DATA,
},
]);
const popup = await waitForApprovalWindow(d);
await d.switchToWindow(popup);
await d.waitVisible("#view-approve-tx");
const screen = await d.execute(
`return {
hostname: document.getElementById("approve-tx-hostname").textContent,
from: document.getElementById("approve-tx-from").textContent,
to: document.getElementById("approve-tx-to").textContent,
value: document.getElementById("approve-tx-value").textContent,
data: document.getElementById("approve-tx-data").textContent,
dataShown: !document
.getElementById("approve-tx-data-section")
.classList.contains("hidden"),
};`,
);
assert(
screen.hostname === "127.0.0.1",
"the transaction prompt names the wrong origin: " +
JSON.stringify(screen.hostname),
);
assert(
screen.from.toLowerCase().includes(env.address.toLowerCase()),
"the transaction prompt shows the wrong sender: " +
JSON.stringify(screen.from),
);
assert(
screen.to.toLowerCase().includes(STUB_COUNTERPARTY.toLowerCase()),
"the transaction prompt shows the wrong recipient: " +
JSON.stringify(screen.to),
);
assert(
screen.value.startsWith(TX_VALUE_ETH + " ETH"),
"the transaction prompt shows the wrong value: " +
JSON.stringify(screen.value),
);
assert(
screen.dataShown && screen.data === TX_DATA,
"the transaction prompt does not show the approved call data: " +
JSON.stringify(screen.data),
);
await d.fill("#approve-tx-password", PASSWORD);
await d.click("#btn-approve-tx");
// The approval window hands off to the wait screen rather than closing,
// and the hash it shows is asserted before it is retired: left open it
// polls the stub node for a receipt for the rest of the run.
await d.waitVisible("#view-wait-tx", STEP_TIMEOUT_MS);
const waitHash = await d.text("#wait-tx-hash");
await d.switchToWindow(env.dappWindow);
const outcome = await settleRequest(d, "tx");
assert(
outcome.settled === "resolved",
"eth_sendTransaction did not resolve: " + JSON.stringify(outcome),
);
// The artifact as the node saw it, not as the extension described it.
assert(
env.server.broadcast.length === before + 1,
"expected exactly one raw transaction to reach the node, got " +
(env.server.broadcast.length - before),
);
const signed = Transaction.from(
env.server.broadcast[env.server.broadcast.length - 1],
);
console.log(
"# eth_sendTransaction: signer=" +
getAddress(signed.from) +
" to=" +
getAddress(signed.to) +
" value=" +
formatEther(signed.value) +
" chainId=" +
signed.chainId,
);
assert(
getAddress(signed.from) === env.address,
"the broadcast transaction was signed by " +
getAddress(signed.from) +
", not by the approved address " +
env.address,
);
assert(
getAddress(signed.to) === getAddress(STUB_COUNTERPARTY),
"the broadcast transaction goes to " + signed.to,
);
assert(
signed.value === TX_VALUE_WEI,
"the broadcast transaction carries " +
formatEther(signed.value) +
" ETH, not the approved " +
TX_VALUE_ETH,
);
assert(
signed.data === TX_DATA,
"the broadcast transaction carries different call data: " +
signed.data,
);
assert(
signed.chainId === 1n,
"the broadcast transaction is for chain " + signed.chainId,
);
assert(
outcome.result === signed.hash,
"the page received " +
outcome.result +
", not the hash of the broadcast transaction " +
signed.hash,
);
assert(
waitHash.includes(signed.hash),
"the wait screen shows a different hash: " +
JSON.stringify(waitHash),
);
await d.switchToWindow(popup);
await d.closeWindow(env.dappWindow);
},
);
step(
"closing an approval window rejects the request with 4001",
async (env) => {
const d = env.driver;
const before = env.server.broadcast.length;
await d.switchToWindow(env.dappWindow);
await startRequest(d, "sign-closed", "personal_sign", [
SIGN_HEX,
env.address,
]);
const popup = await waitForApprovalWindow(d);
await d.switchToWindow(popup);
await d.waitVisible("#view-approve-sign");
// Closed, not rejected: this is the windows.onRemoved path, which can
// only fire if windows.create() handed back a window id for the approval
// to be matched against — call site 4 in the issue, where the id used to
// be assigned from a callback the browser.* namespace never invoked.
await d.closeWindow(env.dappWindow);
await assertUserRejection(d, "sign-closed", "a closed approval window");
assert(
env.server.broadcast.length === before,
"a closed approval window still put a transaction on the node",
);
},
);
// ------------------------------------------------------------- runner // ------------------------------------------------------------- runner
// Uncaught extension errors that are known, tracked and deliberately
// tolerated, in the same spirit as ALLOWED_ERRORS in tests/e2e/harness.js:
// every entry names the issue that will delete it, and every occurrence is
// still printed, so tolerating one is visible in the log rather than silent.
// This is the only concession in an otherwise zero-tolerance policy.
const ALLOWED_ERRORS = [
{
// The site-connection buttons in src/popup/views/approval.js send
// their decision and call window.close() on the next line. Firefox's
// BaseContext.wrapPromise reports, through Cu.reportError, any
// extension-API promise that settles after its context unloaded —
// whether or not the caller attached a handler, so notify()'s catch
// cannot suppress it.
//
// Pre-existing, and not introduced by the promise shim: the send was
// already unawaited, and this suite is merely the first thing to
// drive that window on Firefox. It is the same teardown ordering as
// the issue below, whose fix — making the outcome independent of when
// the popup closes — removes this entry with it.
pattern: /Promise (?:resolved|rejected) after context unloaded/,
source: /\/src\/popup\/index\.js$/,
issue: "https://git.eeqj.de/sneak/AutistMask/issues/275",
},
];
function allowedFor(e) {
return ALLOWED_ERRORS.find(
(a) => a.pattern.test(e.msg) && a.source.test(e.src),
);
}
function formatError(e) { function formatError(e) {
return ( return (
e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")" e.msg + " (" + e.src + ":" + e.line + (e.cat ? ", " + e.cat : "") + ")"
@@ -774,21 +165,6 @@ async function main() {
return; return;
} }
// Loopback survives --network none, so this is the http:// origin the
// dApp steps need and the node they talk to. Started before the browser
// so its url is available to the first step that asks for it.
let server;
try {
server = await startDappServer();
} catch (e) {
console.error(
"e2e-firefox: cannot serve the dApp fixture: " + e.message,
);
process.exitCode = 1;
return;
}
console.log("# dapp fixture: " + server.url + " rpc " + server.rpcUrl);
let driver; let driver;
try { try {
driver = await start(); driver = await start();
@@ -799,20 +175,12 @@ async function main() {
// absent suite. Never skip and report success. // absent suite. Never skip and report success.
console.error("e2e-firefox: cannot run the suite: " + e.message); console.error("e2e-firefox: cannot run the suite: " + e.message);
if (driver) await driver.quit().catch(() => {}); if (driver) await driver.quit().catch(() => {});
await server.close();
process.exitCode = 1; process.exitCode = 1;
return; return;
} }
const errors = new ConsoleErrors(driver, EXTENSION_ORIGIN); const errors = new ConsoleErrors(driver, EXTENSION_ORIGIN);
const env = { const env = { driver, phrase: null };
driver,
server,
phrase: null,
address: null,
dappWindow: null,
popupWindow: null,
};
console.log("# extension origin: " + EXTENSION_ORIGIN); console.log("# extension origin: " + EXTENSION_ORIGIN);
console.log("1.." + steps.length); console.log("1.." + steps.length);
@@ -864,20 +232,6 @@ async function main() {
installFailure = null; installFailure = null;
} }
// Tolerated errors are set aside, never dropped: each one is
// printed with the issue that keeps it on the list, so the
// concession stays in the run output.
const tolerated = found.filter((e) => allowedFor(e));
found = found.filter((e) => !allowedFor(e));
for (const e of tolerated) {
console.log(
"# tolerated (" +
allowedFor(e).issue +
"): " +
formatError(e),
);
}
// Any uncaught error from an extension source fails the step // Any uncaught error from an extension source fails the step
// that provoked it, whether or not its assertions passed. // that provoked it, whether or not its assertions passed.
if (!failure && found.length > 0) { if (!failure && found.length > 0) {
@@ -902,13 +256,7 @@ async function main() {
// blamed on any one step, but they are still reported and they // blamed on any one step, but they are still reported and they
// still fail the run. // still fail the run.
await sleep(1000); await sleep(1000);
const trailingAll = await errors.take(); const trailing = await errors.take();
for (const e of trailingAll.filter((x) => allowedFor(x))) {
console.log(
"# tolerated (" + allowedFor(e).issue + "): " + formatError(e),
);
}
const trailing = trailingAll.filter((e) => !allowedFor(e));
console.log( console.log(
"# " + "# " +
(steps.length - failed) + (steps.length - failed) +
@@ -925,25 +273,12 @@ async function main() {
); );
for (const e of trailing) console.log("# " + formatError(e)); for (const e of trailing) console.log("# " + formatError(e));
} }
// A JSON-RPC method nothing answered means the extension asked the
// node something this fixture does not model, and whatever depended
// on the answer took the error branch instead. That is a hole in the
// fixture, not a pass.
if (server.unstubbed.length > 0) {
console.log(
"# FAILED: no fixture for JSON-RPC method(s) " +
[...new Set(server.unstubbed)].join(", "),
);
process.exitCode = 1;
}
if (failed > 0 || trailing.length > 0) { if (failed > 0 || trailing.length > 0) {
console.log("# FAILED"); console.log("# FAILED");
process.exitCode = 1; process.exitCode = 1;
} }
} finally { } finally {
await driver.quit().catch(() => {}); await driver.quit().catch(() => {});
await server.close();
} }
} }

View File

@@ -23,8 +23,6 @@
"use strict"; "use strict";
const { Transaction } = require("ethers");
// Fictional ERC-20 used to seed the transaction-detail test. The symbol // Fictional ERC-20 used to seed the transaction-detail test. The symbol
// must not collide with any entry in src/shared/tokenList.js, or // must not collide with any entry in src/shared/tokenList.js, or
// isSpoofedSymbol() in src/shared/transactions.js drops the transfer as a // isSpoofedSymbol() in src/shared/transactions.js drops the transfer as a
@@ -64,94 +62,6 @@ function word(value) {
return "0x" + BigInt(value).toString(16).padStart(64, "0"); return "0x" + BigInt(value).toString(16).padStart(64, "0");
} }
// -------------------------------------------------------- dApp fixture
//
// The origin the EIP-1193 test page is served from, and the page itself.
//
// It is a fixture like every other one in this file: the route handler
// fulfils the navigation from the string below, so the page never comes
// from a remote origin and nothing about the dApp round trips leaves the
// container. `.test` is reserved by RFC 6761 and has no owner to reach in
// the first place; the launch arguments map every host to NOTFOUND anyway.
//
// What the page deliberately does NOT do is load a provider. window.ethereum
// is put there by the shipped manifest's MAIN-world content script, exactly
// as it is on any http(s) page a user visits, so what these tests speak to
// is the real inpage provider and not a copy the harness wired up.
//
// DAPP_HTML below is exported and served verbatim by the Firefox suite too
// (tests/e2e/firefox/dapp.js), from a loopback origin rather than through a
// route handler. The two suites drive different browsers over different
// protocols, but the page they drive — the __dapp API, the message log — is
// one fixture, so an assertion written against it means the same thing on
// both.
const DAPP_ORIGIN = "https://dapp.e2e.test";
const DAPP_URL = DAPP_ORIGIN + "/";
// Requests are parked rather than awaited. An approval prompt only exists
// while its call is in flight, so a test that awaited the promise could
// never drive the popup that has to settle it; start() files the promise
// under a key and settle() collects it once the prompt has been dealt with.
//
// The rejection branch records the whole observable shape of the error as it
// arrives — name, message, and whether a `code` is present at all as distinct
// from its value. EIP-1193 says a user rejection is a ProviderRpcError
// carrying code 4001; what the page can actually see is recorded here rather
// than assumed, and asserted in run.js.
//
// The message log is the page's half of the boundary observation: every
// AUTISTMASK_* message that crosses between this page and the content
// script, in both directions, verbatim.
const DAPP_HTML = [
"<!doctype html>",
'<html lang="en">',
"<head>",
'<meta charset="utf-8">',
"<title>AutistMask e2e dApp</title>",
// Inline and empty: without it Chromium asks for /favicon.ico, which
// the unstubbed-request guard would report as escaping traffic.
'<link rel="icon" href="data:,">',
"</head>",
"<body>",
"<h1>AutistMask e2e dApp</h1>",
"<script>",
"window.__dapp = {",
" messages: [],",
" calls: {},",
" start: function (key, method, params) {",
" window.__dapp.calls[key] = window.ethereum",
" .request({ method: method, params: params })",
" .then(",
" function (result) {",
" return { settled: 'resolved', result: result };",
" },",
" function (error) {",
" return {",
" settled: 'rejected',",
" message: String((error && error.message) || error),",
" name: error ? error.name : undefined,",
" hasCode: !!error && 'code' in Object(error),",
" code: error ? error.code : undefined,",
" };",
" },",
" );",
" },",
" settle: function (key) {",
" return window.__dapp.calls[key];",
" },",
"};",
"window.addEventListener('message', function (event) {",
" if (event.source !== window) return;",
" var d = event.data;",
" if (!d || typeof d.type !== 'string') return;",
" if (d.type.indexOf('AUTISTMASK') !== 0) return;",
" window.__dapp.messages.push(d);",
"});",
"</script>",
"</body>",
"</html>",
].join("\n");
// ------------------------------------------------------------ fee fixture // ------------------------------------------------------------ fee fixture
// //
// The confirmation screen carries two different numbers for the same // The confirmation screen carries two different numbers for the same
@@ -191,11 +101,6 @@ const RPC_RESULTS = {
eth_estimateGas: hex(GAS_LIMIT), eth_estimateGas: hex(GAS_LIMIT),
eth_getTransactionCount: "0x0", eth_getTransactionCount: "0x0",
eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI), eth_maxPriorityFeePerGas: hex(PRIORITY_FEE_WEI),
// "not mined yet", which is what a node answers for a transaction it has
// only just accepted. The wait screen the dApp transaction approval hands
// off to polls this every 10 seconds; leaving it unstubbed would report
// the poll as escaping traffic the moment a test outlived one tick.
eth_getTransactionReceipt: null,
}; };
// The "latest" block, which ethers' getFeeData() reads baseFeePerGas from // The "latest" block, which ethers' getFeeData() reads baseFeePerGas from
@@ -359,31 +264,6 @@ function rpcReply(req, opts, report) {
if (req.method === "eth_getBlockByNumber") { if (req.method === "eth_getBlockByNumber") {
return Object.assign(envelope, { result: latestBlock() }); return Object.assign(envelope, { result: latestBlock() });
} }
// The end of the dApp transaction round trip: the raw signed transaction
// the background hands to the node. It is recorded verbatim so a test can
// recover the signer from the exact bytes that were broadcast, rather than
// from anything the extension reported about them.
//
// The reply must be the transaction's real hash. ethers compares the hash
// the node returns against the one it computes itself and throws on a
// mismatch, so a constant here would fail the broadcast for a reason that
// has nothing to do with what is being tested.
if (req.method === "eth_sendRawTransaction") {
const raw = Array.isArray(req.params) ? req.params[0] : null;
let parsed;
try {
parsed = Transaction.from(raw);
} catch {
report("eth_sendRawTransaction with an undecodable transaction");
return Object.assign(envelope, {
error: { code: -32000, message: "undecodable transaction" },
});
}
if (Array.isArray(opts.broadcastTransactions)) {
opts.broadcastTransactions.push(raw);
}
return Object.assign(envelope, { result: parsed.hash });
}
if (req.method === "eth_estimateGas" && opts.failGasEstimate) { if (req.method === "eth_estimateGas" && opts.failGasEstimate) {
// A refusal the node itself would produce, not a transport error: // A refusal the node itself would produce, not a transport error:
// this is the shape the confirmation screen has to turn into // this is the shape the confirmation screen has to turn into
@@ -495,8 +375,6 @@ function traceEnabled(raw) {
* node-side refusal. * node-side refusal.
* @param {boolean} [opts.holdGasEstimate] hold every batch containing an * @param {boolean} [opts.holdGasEstimate] hold every batch containing an
* eth_estimateGas until this is cleared again. * eth_estimateGas until this is cleared again.
* @param {string[]} [opts.broadcastTransactions] every raw signed
* transaction handed to eth_sendRawTransaction, appended in order.
* @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) => * @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) =>
* Promise<string|null>}>} * Promise<string|null>}>}
*/ */
@@ -542,18 +420,6 @@ async function installNetworkStubs(ctx, opts) {
return handleRpc(route, req.postData(), opts, report); return handleRpc(route, req.postData(), opts, report);
} }
// The local EIP-1193 test page. Served from here so the dApp round
// trips run against a real http(s) origin — which is what makes the
// shipped content scripts inject at all — without any remote origin
// being involved.
if (url.origin === DAPP_ORIGIN && p === "/") {
return route.fulfill({
status: 200,
contentType: "text/html; charset=utf-8",
body: DAPP_HTML,
});
}
// Blockscout v2 // Blockscout v2
if (p.includes("/api/v2/")) { if (p.includes("/api/v2/")) {
if (/\/addresses\/0x[0-9a-fA-F]{40}\/transactions$/.test(p)) { if (/\/addresses\/0x[0-9a-fA-F]{40}\/transactions$/.test(p)) {
@@ -642,9 +508,6 @@ async function installNetworkStubs(ctx, opts) {
module.exports = { module.exports = {
installNetworkStubs, installNetworkStubs,
DAPP_HTML,
DAPP_ORIGIN,
DAPP_URL,
FEE_ESTIMATE_WEI, FEE_ESTIMATE_WEI,
FEE_RESERVE_WEI, FEE_RESERVE_WEI,
STUB_COUNTERPARTY, STUB_COUNTERPARTY,

File diff suppressed because it is too large Load Diff

View File

@@ -1,310 +0,0 @@
// The EIP-1193 error the page actually catches (src/content/inpage.js).
//
// The bug this pins down (issue #274): the provider rebuilt every failure as
// `new Error(error.message)`, so the `code` the background produced and the
// content script relayed intact was thrown away in the last hop. A dApp
// checking `err.code === 4001` — the standard way to tell "the user said no"
// from "the wallet broke" — saw undefined, and well-behaved sites showed an
// error or retried instead of accepting the refusal.
//
// inpage.js is a bare IIFE injected into the page's JS context, not a module:
// it takes no import and exports nothing, and reaches for `window` at load.
// So it is evaluated here the way the browser evaluates it, against a stub
// window, and the provider is collected from `window.ethereum`. The globals it
// touches are passed in as function parameters rather than assigned to
// globalThis: nothing leaks between tests, and the source is compiled in this
// realm, so the errors it constructs are comparable against this file's own
// `Error` — which a second realm's intrinsics would silently defeat.
//
// There is no jsdom in this repo; see tests/txStatus.test.js.
const fs = require("fs");
const path = require("path");
const { webcrypto } = require("crypto");
const SOURCE = fs.readFileSync(
path.join(__dirname, "..", "src", "content", "inpage.js"),
"utf8",
);
const loadInto = new Function(
"window",
"self",
"crypto",
"Event",
"CustomEvent",
SOURCE,
);
class StubEvent {
constructor(type) {
this.type = type;
}
}
class StubCustomEvent extends StubEvent {
constructor(type, init) {
super(type);
this.detail = init && init.detail;
}
}
// Every code the background emits on the RPC path today, read out of
// src/background/index.js. The provider must not know this list — it passes
// through whatever arrived — but the cases below are the real ones.
const REJECTED = 4001; // user rejected the request
const UNAUTHORIZED = 4100; // site not connected / wrong address
const UNRECOGNIZED_CHAIN = 4902; // switch/add to an unsupported chain
// A stub window with the four things inpage.js touches: message listeners,
// postMessage out to the content script, window.ethereum, and dispatchEvent
// for the EIP-6963 announcement.
function loadProvider() {
const messageListeners = [];
const posted = [];
const win = {
addEventListener(type, fn) {
if (type === "message") messageListeners.push(fn);
},
removeEventListener(type, fn) {
const i = messageListeners.indexOf(fn);
if (type === "message" && i !== -1) messageListeners.splice(i, 1);
},
postMessage(data) {
posted.push(data);
},
dispatchEvent() {
return true;
},
};
win.window = win;
loadInto(win, win, webcrypto, StubEvent, StubCustomEvent);
// Deliver the content script's answer to an outstanding request. The id is
// read back off the wire rather than assumed: inpage.js issues its own
// eth_chainId at load, so the first id a test sees is not 1.
function respond(response) {
const request = posted
.filter((m) => m.type === "AUTISTMASK_REQUEST")
.pop();
expect(request).toBeDefined();
const event = {
source: win,
data: { type: "AUTISTMASK_RESPONSE", id: request.id, ...response },
};
for (const fn of messageListeners.slice()) fn(event);
}
return { provider: win.ethereum, posted, respond };
}
// Start a request, answer it with `response`, and hand back the rejection.
// Fails the test if the call resolves instead.
async function rejectionFrom(start, response) {
const { provider, respond } = loadProvider();
const settled = start(provider).then(
(result) => ({ resolved: result }),
(error) => ({ error }),
);
// The provider posts synchronously, so the request is already on the wire.
respond(response);
const outcome = await settled;
expect(outcome).not.toHaveProperty("resolved");
return outcome.error;
}
describe("an EIP-1193 code reaches the page", () => {
test("a user rejection arrives as code 4001", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_requestAccounts" }),
{
error: {
code: REJECTED,
message: "User rejected the request.",
},
},
);
expect(err.code).toBe(REJECTED);
expect(err.message).toBe("User rejected the request.");
});
test("it is a ProviderRpcError, and an Error", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_requestAccounts" }),
{
error: {
code: REJECTED,
message: "User rejected the request.",
},
},
);
expect(err).toBeInstanceOf(Error);
expect(err.name).toBe("ProviderRpcError");
});
test("4100 unauthorized arrives intact", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "personal_sign", params: ["0x00"] }),
{ error: { code: UNAUTHORIZED, message: "Unauthorized" } },
);
expect(err.code).toBe(UNAUTHORIZED);
expect(err.message).toBe("Unauthorized");
});
test("4902 unrecognized chain arrives intact", async () => {
const message =
"AutistMask supports Ethereum Mainnet and Sepolia Testnet only.";
const err = await rejectionFrom(
(p) => p.request({ method: "wallet_switchEthereumChain" }),
{ error: { code: UNRECOGNIZED_CHAIN, message } },
);
expect(err.code).toBe(UNRECOGNIZED_CHAIN);
expect(err.message).toBe(message);
});
// The provider is not allowed to know the list above: a code added to the
// background later must reach the page without this file being edited.
test("a code the provider has never heard of is passed through", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_accounts" }),
{ error: { code: 4900, message: "Disconnected" } },
);
expect(err.code).toBe(4900);
});
test("data is carried when the boundary sent it", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_call" }),
{
error: {
code: -32000,
message: "execution reverted",
data: "0x08c379a0",
},
},
);
expect(err.code).toBe(-32000);
expect(err.data).toBe("0x08c379a0");
});
test("no data property is invented when the boundary sent none", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_requestAccounts" }),
{
error: {
code: REJECTED,
message: "User rejected the request.",
},
},
);
expect("data" in err).toBe(false);
});
});
describe("the message is untouched", () => {
test("a coded error keeps the message byte for byte", async () => {
const message =
"This site asked to sign as an address that is not " +
"the active one.";
const err = await rejectionFrom(
(p) => p.request({ method: "personal_sign" }),
{ error: { code: UNAUTHORIZED, message } },
);
expect(err.message).toBe(message);
});
test("an error the background sent with no code keeps its message", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_sendTransaction" }),
{ error: { message: "No accounts available" } },
);
expect(err.message).toBe("No accounts available");
});
// A ProviderRpcError whose code is undefined would claim a conformance it
// does not have, and `'code' in err` is exactly what a careful dApp asks.
test("an error with no code gets no code property at all", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_sendTransaction" }),
{ error: { message: "No accounts available" } },
);
expect(err).toBeInstanceOf(Error);
expect("code" in err).toBe(false);
});
test("an error with no message keeps the generic fallback", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_sendTransaction" }),
{ error: { code: REJECTED } },
);
expect(err.message).toBe("Request failed");
expect(err.code).toBe(REJECTED);
});
});
// Every entry point the provider exposes, not just eth_requestAccounts. They
// all funnel through the same response listener, and this is what says so.
describe("every request path carries the code", () => {
const rejection = {
error: { code: REJECTED, message: "User rejected the request." },
};
test("request()", async () => {
const err = await rejectionFrom(
(p) => p.request({ method: "eth_requestAccounts" }),
rejection,
);
expect(err.code).toBe(REJECTED);
});
test("enable()", async () => {
const err = await rejectionFrom((p) => p.enable(), rejection);
expect(err.code).toBe(REJECTED);
});
test("send(method, params)", async () => {
const err = await rejectionFrom(
(p) => p.send("eth_requestAccounts", []),
rejection,
);
expect(err.code).toBe(REJECTED);
});
test("send({ method, params })", async () => {
const err = await rejectionFrom(
(p) => p.send({ method: "personal_sign", params: ["0x00"] }),
rejection,
);
expect(err.code).toBe(REJECTED);
});
test("sendAsync() hands the code to its callback", async () => {
const { provider, respond } = loadProvider();
const called = new Promise((resolve) => {
provider.sendAsync({ id: 1, method: "eth_requestAccounts" }, (e) =>
resolve(e),
);
});
respond(rejection);
const err = await called;
expect(err.name).toBe("ProviderRpcError");
expect(err.code).toBe(REJECTED);
expect(err.message).toBe("User rejected the request.");
});
});
describe("the success path is unchanged", () => {
test("a result still resolves", async () => {
const { provider, respond } = loadProvider();
const settled = provider.request({ method: "eth_requestAccounts" });
respond({ result: ["0xb61264DEFB0c4B8afb3D73724be15310036743a5"] });
await expect(settled).resolves.toEqual([
"0xb61264DEFB0c4B8afb3D73724be15310036743a5",
]);
expect(provider.selectedAddress).toBe(
"0xb61264DEFB0c4B8afb3D73724be15310036743a5",
);
});
});