Compare commits
1 Commits
issue-259-
...
issue-271-
| Author | SHA1 | Date | |
|---|---|---|---|
| 73db8eee43 |
@@ -1,49 +0,0 @@
|
||||
name: e2e
|
||||
on: [push]
|
||||
|
||||
# The browser end-to-end suites, one job per browser, deliberately kept out
|
||||
# of the check workflow: REPO_POLICIES.md caps make test at 20 seconds and
|
||||
# script/cibuild is a plain `docker build .` whose Dockerfile runs
|
||||
# make check, so folding a browser suite into either would blow that cap
|
||||
# and slow the local fast path. Before this workflow every browser-level
|
||||
# guarantee in this repo held only when a human remembered to run it.
|
||||
#
|
||||
# One job per browser rather than two steps in one job, so a Chrome failure
|
||||
# does not hide the Firefox result.
|
||||
#
|
||||
# Each job is one script and nothing else. Both scripts need docker and
|
||||
# nothing else — they deliver the repo to the daemon as a build context and
|
||||
# build the extension inside the pinned image — which is what makes them
|
||||
# runnable here at all: the runner executes the job in a container against
|
||||
# the host's docker socket, so a `-v "$PWD:/work"` source path is resolved
|
||||
# by the host daemon and mounts an empty directory, and the runner image's
|
||||
# node is too old to install this repo's dependencies.
|
||||
#
|
||||
# These jobs REPORT, they do not gate. Whether a check blocks a merge is
|
||||
# Gitea branch protection, which this repo does not configure, so a failure
|
||||
# here is a red mark a reviewer has to account for rather than a hard
|
||||
# block. Making e2e-chrome a required check is blocked on the measured
|
||||
# flake in the dApp signing wait -- two of six runs of unmutated code on a
|
||||
# loaded machine -- tracked as
|
||||
# https://git.eeqj.de/sneak/AutistMask/issues/287. A gate that fails at
|
||||
# random teaches people to merge past red.
|
||||
#
|
||||
# Nothing here may pass vacuously. There is no continue-on-error and no
|
||||
# `|| true`. Both scripts exit non-zero when docker is missing, when the
|
||||
# image build fails, and when the browser fails to start; the Chrome
|
||||
# harness aborts the suite outright if its network interception is not in
|
||||
# effect.
|
||||
jobs:
|
||||
e2e-chrome:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# actions/checkout v4.2.2, 2026-02-22
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- run: script/test-e2e
|
||||
|
||||
e2e-firefox:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# actions/checkout v4.2.2, 2026-02-22
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- run: script/test-e2e-firefox
|
||||
84
README.md
84
README.md
@@ -83,11 +83,10 @@ provide:
|
||||
git pre-commit hook
|
||||
- `script/projectname` — print the project name (used for the Docker image tag)
|
||||
- `script/test` — run the test suite (jest)
|
||||
- `script/test-e2e` — run the Chrome browser end-to-end suite (docker is the
|
||||
only prerequisite: it builds a pinned image that carries the repo and a fresh
|
||||
extension build, see [End-to-End Tests](#end-to-end-tests))
|
||||
- `script/test-e2e-firefox` — run the Firefox browser end-to-end suite (same,
|
||||
against an image with a pinned Firefox and geckodriver, see
|
||||
- `script/test-e2e` — run the Chrome browser end-to-end suite (docker required;
|
||||
see [End-to-End Tests](#end-to-end-tests))
|
||||
- `script/test-e2e-firefox` — run the Firefox browser end-to-end suite (docker
|
||||
required; builds its own pinned image, see
|
||||
[End-to-End Tests](#end-to-end-tests))
|
||||
- `script/lint` — run the linter
|
||||
- `script/fmt` — format all files (writes)
|
||||
@@ -137,12 +136,11 @@ are outside `make check`.
|
||||
|
||||
`make test-e2e` builds `dist/chrome/` and drives the **real popup in a real
|
||||
Chrome**, loaded as an unpacked MV3 extension inside a pinned
|
||||
`mcr.microsoft.com/playwright` container (pinned by digest in
|
||||
`tests/e2e/Dockerfile`, which is also where the extension is built; docker is
|
||||
required and the suite fails loudly rather than skipping if it is unavailable).
|
||||
The suite lives in `tests/e2e/` and is driven by `playwright-core`, whose
|
||||
version must stay matched to the container's Playwright version — the browsers
|
||||
ship inside the image.
|
||||
`mcr.microsoft.com/playwright` container (pinned by digest in `script/test-e2e`;
|
||||
docker is required and the suite fails loudly rather than skipping if it is
|
||||
unavailable). The suite lives in `tests/e2e/` and is driven by
|
||||
`playwright-core`, whose version must stay matched to the container's Playwright
|
||||
version — the browsers ship inside the image.
|
||||
|
||||
It covers popup load, WebAssembly compilation under the shipped CSP (see
|
||||
[Content Security Policy](#content-security-policy)), wallet creation through
|
||||
@@ -322,46 +320,9 @@ Two limits are worth knowing, both real differences from the Chrome suite:
|
||||
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
||||
`make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser
|
||||
suite does not fit; nothing in `tests/e2e/` is named `*.test.js`, so jest cannot
|
||||
pick it up either. Run them locally before changing anything under
|
||||
`src/popup/views/`.
|
||||
|
||||
### In CI
|
||||
|
||||
`.gitea/workflows/e2e.yml` runs both suites on every push, as two jobs —
|
||||
`e2e-chrome` and `e2e-firefox` — separate from the `check` workflow, so the
|
||||
20-second `make test` cap and the local fast path are untouched. Each job is a
|
||||
checkout and the matching `script/` entrypoint, nothing else.
|
||||
|
||||
Docker is the only thing either job needs from the runner, and that is not an
|
||||
accident. The runner executes a job inside a container against the **host's**
|
||||
docker daemon, so a `docker run -v "$PWD:/work"` source path is resolved by the
|
||||
host and mounts an empty directory, and the runner image's node is too old to
|
||||
install this repo's dependencies. Both suites therefore ship the repo to the
|
||||
daemon as a build context and build the extension inside the image, which works
|
||||
identically on a laptop.
|
||||
|
||||
The jobs **report, they do not gate.** A failure is a red mark against the
|
||||
commit that a reviewer has to account for, not a hard block: whether a check
|
||||
blocks a merge is Gitea branch protection, which this repo does not configure.
|
||||
|
||||
That is not only a statement about configuration. The Chrome suite is
|
||||
**measurably flaky under load** — two of six runs of unmutated code on a busy
|
||||
machine lost the approval popup out from under the dApp signing wait, always in
|
||||
the `#183` section, tracked as
|
||||
[#287](https://git.eeqj.de/sneak/AutistMask/issues/287). So a red `e2e-chrome`
|
||||
has to be read before it is believed, and that flake is the blocker to ever
|
||||
making this a required check. Do not answer it with a retry wrapper: a suite
|
||||
that reruns until it is green stops being evidence.
|
||||
|
||||
Nothing in either job can pass vacuously. There is no `continue-on-error` and no
|
||||
`|| true`; both scripts exit non-zero when docker is missing, when the image
|
||||
build fails, and when the browser fails to start; the Chrome harness aborts the
|
||||
suite outright if its network interception is not in effect.
|
||||
|
||||
Measured on this repo's runner: `e2e-chrome` about 1m55s cold, almost all of it
|
||||
the one-time pull of the pinned ~800MB Playwright layer, and well under a minute
|
||||
once that layer is cached. `e2e-firefox` about 1m05s cold, and it caches its
|
||||
Firefox and geckodriver downloads the same way.
|
||||
pick it up either. Neither is wired into the Gitea workflow yet —
|
||||
docker-in-docker in CI is a separate question. Run them locally before changing
|
||||
anything under `src/popup/views/`.
|
||||
|
||||
## Rationale
|
||||
|
||||
@@ -677,21 +638,6 @@ ExportPrivKey and ShowRecoveryPhrase — are deliberately absent from that list,
|
||||
so the popup can never reopen onto one of them with no password prompt in front
|
||||
of it.
|
||||
|
||||
A reopened popup renders the wallet list and the one screen it restores onto,
|
||||
and nothing else, so every screen on the stack behind that one is still the
|
||||
blank template from `index.html`. "Back" therefore renders its target rather
|
||||
than only unhiding it, through the same dispatch and data guards as the restore
|
||||
(`src/popup/viewRouter.js`), and falls back to Home when the state the target
|
||||
would render is gone.
|
||||
|
||||
It renders only a screen this page load has not rendered yet. Forward navigation
|
||||
renders as it goes, and `viewRouter.js` records every screen that reaches
|
||||
`showView()`, so "Back" onto a screen already on the page unhides it and nothing
|
||||
more — rendering it a second time would re-fetch and overwrite what it holds,
|
||||
such as an edit typed into Settings and not yet saved. Home is the one screen
|
||||
"Back" always re-renders, so the wallet list reflects anything that changed
|
||||
while the user was away from it.
|
||||
|
||||
Every screen that holds secret material in the page registers a cleanup with
|
||||
`onViewLeave()` (`src/popup/views/helpers.js`), which `showView()` runs on every
|
||||
exit from that screen rather than only on its "Back" button, so nothing secret
|
||||
@@ -1217,7 +1163,11 @@ on ConfirmTx, DeleteWallet, ApproveTx and ApproveSign.
|
||||
opening the window, so the screen shows a complete transaction and the signed
|
||||
artifact can be compared with it field for field. A request that cannot be
|
||||
populated — unreachable node, reverting gas estimate — opens no window and is
|
||||
failed back to the site.
|
||||
failed back to the site. Only one transaction approval exists at a time:
|
||||
populating fixes the nonce, so a second `eth_sendTransaction` arriving while
|
||||
one is unanswered is refused with EIP-1193 code `-32002` rather than being
|
||||
populated at the same nonce. It opens no window and takes no nonce, and the
|
||||
site can send it again once the pending one is answered.
|
||||
- **Elements**:
|
||||
- "Transaction Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
|
||||
59
TODO.md
59
TODO.md
@@ -33,8 +33,7 @@ The backlog lives on the
|
||||
authoritative; this file does not duplicate it. Full policy file set present.
|
||||
Real-browser end-to-end suites (`make test-e2e` for Chrome,
|
||||
`make test-e2e-firefox` for Firefox) now sit alongside `make check`, which
|
||||
cannot see a runtime `ReferenceError` in a popup view, and
|
||||
`.gitea/workflows/e2e.yml` runs both of them on every push.
|
||||
cannot see a runtime `ReferenceError` in a popup view.
|
||||
|
||||
# Next Step
|
||||
|
||||
@@ -46,24 +45,23 @@ undefined identifiers, which is how
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-14: CI runs the browser end-to-end suites. `.gitea/workflows/e2e.yml`
|
||||
runs `script/test-e2e` and `script/test-e2e-firefox` as two jobs on every
|
||||
push, separate from `check`, so `make check` and its 20-second `make test` cap
|
||||
are untouched. Every browser-level guarantee in this repo — the WASM-under-CSP
|
||||
check, the recovery-phrase and private-key DOM wipes, the ConfirmTx spend
|
||||
gate, the dApp approval round trips — was enforced only when a human
|
||||
remembered to run it by hand. The suites could not run on the runner as they
|
||||
stood: the runner executes a job in a container against the host's docker
|
||||
daemon, so `docker run -v "$PWD:/work"` mounts an empty directory (measured),
|
||||
and the runner image's node cannot install this repo's dependencies. Both
|
||||
suites now ship the repo to the daemon as a build context and build the
|
||||
extension inside the pinned image, so docker is the only prerequisite on a
|
||||
runner or a laptop, and both run the image by ID rather than by tag so
|
||||
concurrent clones cannot swap it. The jobs report rather than gate — this repo
|
||||
configures no branch protection, and the Chrome suite is measurably flaky
|
||||
under load, filed as [#287](https://git.eeqj.de/sneak/AutistMask/issues/287)
|
||||
rather than papered over
|
||||
([#259](https://git.eeqj.de/sneak/AutistMask/issues/259)).
|
||||
- 2026-08-14: One transaction approval at a time. Populating in the background
|
||||
before the window opens is what makes the displayed object the verified
|
||||
object, and it also fixes the nonce: two `eth_sendTransaction` calls populated
|
||||
concurrently took the same nonce from a node that had seen neither broadcast,
|
||||
and the second could then never be sent, because the only way to give it a
|
||||
fresh nonce is to populate it again after the user has read the old one off
|
||||
the screen. A second request is now refused with EIP-1193 `-32002` while one
|
||||
is unanswered — before anything is populated, so no second nonce is allocated
|
||||
and no second window opens — and the slot is freed when the page has its
|
||||
answer. Signature approvals are not gated, consuming no nonce. A collision
|
||||
that does happen is also reported accurately now: a broadcast the node refused
|
||||
for the nonce, and an approval carrying a nonce this worker has already
|
||||
broadcast (caught before the node is asked at all), both say the transaction
|
||||
did not reach the network and to send it again, instead of warning that it may
|
||||
have sent. `already known` deliberately keeps the ambiguous wording, because a
|
||||
node that says it has the transaction has it
|
||||
([#271](https://git.eeqj.de/sneak/AutistMask/issues/271)).
|
||||
- 2026-08-12: EIP-1193 error codes now reach the page. `src/content/inpage.js`
|
||||
rebuilt every failure as `new Error(error.message)`, so the code the
|
||||
background produced and the content script relayed intact was dropped in the
|
||||
@@ -78,23 +76,6 @@ undefined identifiers, which is how
|
||||
`tests/inpageErrors.test.js`, and the e2e probe that printed the missing code
|
||||
now requires it on the page's Error as well as on the wire, for all four
|
||||
rejected flows ([#274](https://git.eeqj.de/sneak/AutistMask/issues/274)).
|
||||
- 2026-08-12: "Back" now renders the screen it lands on instead of only unhiding
|
||||
it. A reopened popup renders the wallet list and the one screen it restores
|
||||
onto, so every screen further down the stack was still the blank template from
|
||||
`index.html`, and Back walked straight onto it — an empty address, no
|
||||
balances, no QR code. The Back path now goes through the same per-view
|
||||
dispatch and data guards as the restore (`src/popup/viewRouter.js`, shared
|
||||
with `restoreView()`), falling back to Home when the state the target would
|
||||
render is gone. It renders only a view this page load has not rendered yet:
|
||||
`viewRouter.js` records every view that reaches `showView()`, which is where
|
||||
forward navigation and the restore both end, so Back onto a view already on
|
||||
the page unhides it and nothing more. That is what keeps a second render from
|
||||
re-fetching and overwriting what the view holds — an unsaved edit in Settings,
|
||||
a transaction list already loaded. Home is the exception and is always
|
||||
re-rendered, as it was before. Covered by unit tests on the real `goBack()`
|
||||
and by three end-to-end cases against the real popup, each demonstrated
|
||||
failing on the unfixed build
|
||||
([#268](https://git.eeqj.de/sneak/AutistMask/issues/268)).
|
||||
- 2026-08-12: `KNOWN_SYMBOLS` now maps a symbol to the set of contract addresses
|
||||
that bear it, not to one of them. A ticker is not unique: seven of the 512
|
||||
bundled tokens — `FRAX`, `REUSD`, `TON`, `EURE`, `MSUSD`, `MUSD` and `JPYC` —
|
||||
@@ -387,5 +368,9 @@ tracker.
|
||||
- Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
||||
input validation) before any 1.0rc tag. Individual filed issues are parts of
|
||||
it, but the review is broader than any of them.
|
||||
- Decide whether docker-in-docker makes `make test-e2e` and
|
||||
`make test-e2e-firefox` runnable in the Gitea workflow. Extending the Chrome
|
||||
suite itself is tracked as
|
||||
[#183](https://git.eeqj.de/sneak/AutistMask/issues/183).
|
||||
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
||||
land.
|
||||
|
||||
@@ -7,29 +7,17 @@
|
||||
# caps make test at 20 seconds and a browser suite does not fit. Run it
|
||||
# yourself before touching popup views; it is the only check that can see
|
||||
# a used-but-not-imported identifier blow up at runtime.
|
||||
# .gitea/workflows/e2e.yml also runs it on every push, in a job separate
|
||||
# from check so that cap and the local fast path both stay intact.
|
||||
#
|
||||
# Docker is the only prerequisite. The repo reaches the container as a
|
||||
# build context and the extension is built inside it (see
|
||||
# tests/e2e/Dockerfile), so nothing here depends on the node, yarn or make
|
||||
# on the machine that starts the run. That is not a convenience: a bind
|
||||
# mount cannot work under Gitea Actions, and the runner image's node is too
|
||||
# old to install this repo's dependencies.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
IMAGE="$("$SCRIPT_DIR/projectname")-e2e-chrome"
|
||||
|
||||
IIDFILE=""
|
||||
|
||||
cleanup() {
|
||||
if [ -n "$IIDFILE" ]; then
|
||||
rm -f "$IIDFILE"
|
||||
fi
|
||||
}
|
||||
# mcr.microsoft.com/playwright:v1.56.0-noble, 2026-08-09
|
||||
#
|
||||
# The playwright-core devDependency is pinned to the matching Playwright
|
||||
# version (1.56.0) and the two must be bumped together: the browsers ship
|
||||
# inside this image, and playwright-core looks for the exact browser
|
||||
# revision its own version expects. A mismatch fails at launch.
|
||||
IMAGE="mcr.microsoft.com/playwright@sha256:35246d87a7c88ea9b771c65d33171b2611b02a8253b4b12ce6f94376c55f99f2"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
@@ -39,23 +27,14 @@ main() {
|
||||
exit 1
|
||||
fi
|
||||
|
||||
IIDFILE="$(mktemp)"
|
||||
trap cleanup EXIT
|
||||
trap 'cleanup; exit 130' INT TERM
|
||||
|
||||
echo "Building the Chrome e2e image (extension included)..."
|
||||
docker build --iidfile "$IIDFILE" -t "$IMAGE" -f tests/e2e/Dockerfile .
|
||||
echo "Building extension for e2e..."
|
||||
yarn run build 2>&1
|
||||
|
||||
echo "Running e2e suite in the pinned Playwright container..."
|
||||
# The image is run by ID, not by tag: where two clones of this repo run
|
||||
# the suite at once, the other build can move the tag between this
|
||||
# build and this run, and the suite would then silently test the other
|
||||
# checkout.
|
||||
#
|
||||
# --ipc=host: Chromium's shared-memory needs more than the default
|
||||
# 64MB /dev/shm or renderers crash.
|
||||
# HOME=/tmp: the image's root home is not a reliable place for the
|
||||
# browser profile.
|
||||
# --user: keep files the suite touches owned by the caller, not root.
|
||||
# HOME=/tmp: the mapped uid has no home directory in the image.
|
||||
# PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1: without it,
|
||||
# ctx.route() intercepts page requests only, and every fetch made by
|
||||
# the MV3 background service worker — including the phishing
|
||||
@@ -72,10 +51,13 @@ main() {
|
||||
# on a deliberate bump.
|
||||
docker run --rm \
|
||||
--ipc=host \
|
||||
--user "$(id -u):$(id -g)" \
|
||||
-e HOME=/tmp \
|
||||
-e PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1 \
|
||||
-e "E2E_TRACE_NETWORK=${E2E_TRACE_NETWORK:-0}" \
|
||||
"$(cat "$IIDFILE")" \
|
||||
-v "$ROOT:/work" \
|
||||
-w /work \
|
||||
"$IMAGE" \
|
||||
node tests/e2e/run.js
|
||||
}
|
||||
|
||||
|
||||
@@ -5,17 +5,12 @@
|
||||
#
|
||||
# Deliberately NOT called by script/check or script/test, for the same
|
||||
# reason as the Chrome suite: REPO_POLICIES.md caps make test at 20 seconds
|
||||
# and a browser suite does not fit. .gitea/workflows/e2e.yml also runs it
|
||||
# on every push, in a job separate from check.
|
||||
# and a browser suite does not fit.
|
||||
#
|
||||
# Unlike script/test-e2e this builds its base image locally, because no
|
||||
# Unlike script/test-e2e this builds its image locally, because no
|
||||
# published image carries both a pinned Firefox and a matching geckodriver.
|
||||
# All three external artifacts are pinned by digest inside the Dockerfile;
|
||||
# see tests/e2e/firefox/Dockerfile, which also explains why the repo and
|
||||
# the extension build are baked into the image rather than mounted.
|
||||
#
|
||||
# Docker is the only prerequisite: nothing here depends on the node, yarn
|
||||
# or make on the machine that starts the run.
|
||||
# see tests/e2e/firefox/Dockerfile.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
@@ -23,14 +18,6 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
IMAGE="$("$SCRIPT_DIR/projectname")-e2e-firefox"
|
||||
|
||||
IIDFILE=""
|
||||
|
||||
cleanup() {
|
||||
if [ -n "$IIDFILE" ]; then
|
||||
rm -f "$IIDFILE"
|
||||
fi
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
|
||||
@@ -39,20 +26,16 @@ main() {
|
||||
exit 1
|
||||
fi
|
||||
|
||||
IIDFILE="$(mktemp)"
|
||||
trap cleanup EXIT
|
||||
trap 'cleanup; exit 130' INT TERM
|
||||
echo "Building extension for e2e..."
|
||||
yarn run build 2>&1
|
||||
|
||||
echo "Building the pinned Firefox e2e image (extension included)..."
|
||||
docker build --iidfile "$IIDFILE" -t "$IMAGE" \
|
||||
-f tests/e2e/firefox/Dockerfile .
|
||||
# The build context is tests/e2e/firefox/ and holds nothing but the
|
||||
# Dockerfile: the harness itself arrives over the bind mount below, so
|
||||
# editing it never invalidates an image layer.
|
||||
echo "Building the pinned Firefox e2e image..."
|
||||
docker build -t "$IMAGE" "$ROOT/tests/e2e/firefox"
|
||||
|
||||
echo "Running the Firefox e2e suite..."
|
||||
# The image is run by ID, not by tag: where two clones of this repo run
|
||||
# the suite at once, the other build can move the tag between this
|
||||
# build and this run, and the suite would then silently test the other
|
||||
# checkout.
|
||||
#
|
||||
# --shm-size=1g: Firefox needs more than the default 64MB /dev/shm.
|
||||
# --network none: the suite stubs nothing, so this is what keeps the
|
||||
# run offline and deterministic. The extension swallows its own
|
||||
@@ -60,8 +43,8 @@ main() {
|
||||
# network note in README.md. Weaker than the Chrome suite's
|
||||
# fixture interception, and honestly so — it proves no request
|
||||
# escaped, but it cannot report which ones were attempted.
|
||||
# HOME=/tmp: the image's root home is not a reliable place for the
|
||||
# browser profile.
|
||||
# --user: keep files the suite touches owned by the caller, not root.
|
||||
# HOME=/tmp: the mapped uid has no home directory in the image.
|
||||
#
|
||||
# No --privileged. Firefox's sandbox logs
|
||||
# "CanCreateUserNamespace() clone() failure: EPERM" on startup here;
|
||||
@@ -69,8 +52,11 @@ main() {
|
||||
docker run --rm \
|
||||
--shm-size=1g \
|
||||
--network none \
|
||||
--user "$(id -u):$(id -g)" \
|
||||
-e HOME=/tmp \
|
||||
"$(cat "$IIDFILE")" \
|
||||
-v "$ROOT:/work" \
|
||||
-w /work \
|
||||
"$IMAGE" \
|
||||
node tests/e2e/firefox/run.js dist/firefox
|
||||
}
|
||||
|
||||
|
||||
@@ -24,6 +24,7 @@ const {
|
||||
TX_STAGE_VERIFY,
|
||||
TX_STAGE_BROADCAST,
|
||||
TX_STAGE_INFLIGHT,
|
||||
TX_STAGE_NONCE,
|
||||
} = require("../shared/approvalVerify");
|
||||
const { prepareApprovalTx } = require("../shared/approvalTx");
|
||||
const {
|
||||
@@ -57,6 +58,81 @@ const connectedSites = {};
|
||||
// Pending approval requests: { id: { origin, hostname, resolve } }
|
||||
const pendingApprovals = {};
|
||||
|
||||
// One transaction approval at a time, wallet-wide.
|
||||
//
|
||||
// The transaction a site asks for is populated before its approval window
|
||||
// opens, so that the object the user is shown is the object the signed
|
||||
// artifact is verified against. Populating fixes the nonce. Two requests
|
||||
// populated concurrently therefore take the SAME nonce — the node reports the
|
||||
// same pending count to both, neither having been broadcast — and whichever is
|
||||
// broadcast second is refused by the network for a nonce it can never be
|
||||
// re-signed at, because re-signing it would mean signing something other than
|
||||
// what was displayed.
|
||||
//
|
||||
// So the second request is refused while the first is unanswered. It is
|
||||
// refused before anything is populated, so no second nonce is allocated at
|
||||
// all, and while the page is still waiting with nothing on screen. The
|
||||
// alternatives were considered and rejected in
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/271: populating again at Confirm
|
||||
// puts a nonce on screen that is not the nonce that gets signed, and
|
||||
// allocating around in-flight approvals makes the wallet's own bookkeeping the
|
||||
// authority on a nonce the network has not accepted, which an abandoned
|
||||
// approval then leaves a hole in.
|
||||
//
|
||||
// Sign approvals are not gated: a signature consumes no nonce.
|
||||
let txApprovalSlotHeld = false;
|
||||
|
||||
// EIP-1474 "resource unavailable": the standard code for a request that is
|
||||
// refused because another one is already pending.
|
||||
const TX_APPROVAL_PENDING_CODE = -32002;
|
||||
|
||||
const TX_APPROVAL_PENDING_MESSAGE =
|
||||
"Another transaction is already waiting to be approved in AutistMask," +
|
||||
" so this one was not sent. Please answer that request, then send this" +
|
||||
" one again.";
|
||||
|
||||
// Take the slot, or refuse. Called before the first await of the
|
||||
// eth_sendTransaction handler, so two requests arriving in the same tick
|
||||
// cannot both pass it.
|
||||
function reserveTxApprovalSlot() {
|
||||
if (txApprovalSlotHeld) return false;
|
||||
txApprovalSlotHeld = true;
|
||||
return true;
|
||||
}
|
||||
|
||||
function releaseTxApprovalSlot() {
|
||||
txApprovalSlotHeld = false;
|
||||
}
|
||||
|
||||
// Nonces this worker has already handed to the node, per address. This is the
|
||||
// wallet's own knowledge that a nonce is spent, and it is checked before a
|
||||
// broadcast rather than after: a node's pending count can lag a transaction it
|
||||
// has itself just accepted, and a request populated inside that window would
|
||||
// otherwise be signed and sent at a nonce this wallet has already used.
|
||||
//
|
||||
// The record dies with the worker, which is correct rather than merely
|
||||
// convenient: after a restart the node's count is the only answer available,
|
||||
// and a transaction of this wallet's that the node has forgotten is one the
|
||||
// user does want to be able to send again.
|
||||
const broadcastNonces = {};
|
||||
|
||||
function broadcastNoncesFor(address) {
|
||||
const key = String(address || "").toLowerCase();
|
||||
if (!broadcastNonces[key]) broadcastNonces[key] = new Set();
|
||||
return broadcastNonces[key];
|
||||
}
|
||||
|
||||
// An approved transaction's nonce as a decimal string, or null if it cannot be
|
||||
// read as a number. Verification refuses an unreadable nonce before this is
|
||||
// ever reached; null here only keeps the record from holding junk.
|
||||
function approvedNonce(approvedTx) {
|
||||
try {
|
||||
return BigInt(approvedTx.nonce).toString();
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function getState() {
|
||||
const result = await storageApi.get("autistmask");
|
||||
return (
|
||||
@@ -585,10 +661,46 @@ async function handleRpc(method, params, origin) {
|
||||
}
|
||||
|
||||
if (method === "eth_sendTransaction") {
|
||||
// Synchronous, before any await: two requests delivered in the same
|
||||
// tick must not both get past this.
|
||||
if (!reserveTxApprovalSlot()) {
|
||||
return {
|
||||
error: {
|
||||
code: TX_APPROVAL_PENDING_CODE,
|
||||
message: TX_APPROVAL_PENDING_MESSAGE,
|
||||
},
|
||||
};
|
||||
}
|
||||
try {
|
||||
return await handleSendTransaction(params, origin);
|
||||
} finally {
|
||||
// Held until the page has its answer — the approval was broadcast,
|
||||
// rejected, or retired by a closed window — because until then its
|
||||
// nonce is allocated and unspent.
|
||||
releaseTxApprovalSlot();
|
||||
}
|
||||
}
|
||||
|
||||
// Proxy safe read-only methods to the RPC node
|
||||
if (PROXY_METHODS.includes(method)) {
|
||||
try {
|
||||
const result = await proxyRpc(method, params);
|
||||
return { result };
|
||||
} catch (e) {
|
||||
return { error: { message: e.message } };
|
||||
}
|
||||
}
|
||||
|
||||
return { error: { message: "Unsupported method: " + method } };
|
||||
}
|
||||
|
||||
// The body of eth_sendTransaction, from the connection check through to the
|
||||
// user's decision. Its caller holds the single transaction-approval slot for
|
||||
// as long as this runs.
|
||||
async function handleSendTransaction(params, origin) {
|
||||
const s = await getState();
|
||||
const activeAddress = await getActiveAddress();
|
||||
if (!activeAddress)
|
||||
return { error: { message: "No accounts available" } };
|
||||
if (!activeAddress) return { error: { message: "No accounts available" } };
|
||||
|
||||
const hostname = extractHostname(origin);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
@@ -647,19 +759,6 @@ async function handleRpc(method, params, origin) {
|
||||
);
|
||||
if (decision.error) return { error: decision.error };
|
||||
return { result: decision.txHash };
|
||||
}
|
||||
|
||||
// Proxy safe read-only methods to the RPC node
|
||||
if (PROXY_METHODS.includes(method)) {
|
||||
try {
|
||||
const result = await proxyRpc(method, params);
|
||||
return { result };
|
||||
} catch (e) {
|
||||
return { error: { message: e.message } };
|
||||
}
|
||||
}
|
||||
|
||||
return { error: { message: "Unsupported method: " + method } };
|
||||
}
|
||||
|
||||
// Broadcast chainChanged to all tabs when the network is switched.
|
||||
@@ -959,7 +1058,7 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
sendResponse({
|
||||
error: outcome.error,
|
||||
retryable: outcome.retryable,
|
||||
stage: TX_STAGE_SIGN,
|
||||
stage: outcome.stage,
|
||||
});
|
||||
return false;
|
||||
}
|
||||
@@ -1019,7 +1118,28 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
sendResponse({
|
||||
error: outcome.error,
|
||||
retryable: outcome.retryable,
|
||||
stage: TX_STAGE_VERIFY,
|
||||
stage: outcome.stage,
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
// A nonce this worker has already broadcast for this address. The
|
||||
// node is not asked: it has answered once already, and the wallet
|
||||
// holding the receipt of that answer is what makes this failure
|
||||
// one the user can be told did not reach the network.
|
||||
const nonce = approvedNonce(approval.approvedTx);
|
||||
const spent = broadcastNoncesFor(approval.approvedFrom);
|
||||
if (nonce !== null && spent.has(nonce)) {
|
||||
const outcome = describeTxFailure(TX_STAGE_NONCE, null);
|
||||
settleApproval(
|
||||
msg.id,
|
||||
{ error: { message: outcome.error } },
|
||||
{ holdsClaim: true },
|
||||
);
|
||||
sendResponse({
|
||||
error: outcome.error,
|
||||
retryable: outcome.retryable,
|
||||
stage: outcome.stage,
|
||||
});
|
||||
return;
|
||||
}
|
||||
@@ -1027,6 +1147,7 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
try {
|
||||
const provider = getProvider(state.rpcUrl);
|
||||
const tx = await provider.broadcastTransaction(msg.rawSignedTx);
|
||||
if (nonce !== null) spent.add(nonce);
|
||||
settleApproval(
|
||||
msg.id,
|
||||
{ txHash: tx.hash },
|
||||
@@ -1039,6 +1160,11 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
// tell a transaction that never left from one already in the
|
||||
// mempool. The page has been given its outcome for this
|
||||
// request; a second attempt would report a second one.
|
||||
//
|
||||
// Unless the node blamed the nonce, which is the one answer
|
||||
// that says plainly it did not take the transaction:
|
||||
// describeTxFailure() reclassifies that, and the stage it
|
||||
// returns is the one reported.
|
||||
const outcome = describeTxFailure(TX_STAGE_BROADCAST, e);
|
||||
settleApproval(
|
||||
msg.id,
|
||||
@@ -1048,7 +1174,7 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
sendResponse({
|
||||
error: outcome.error,
|
||||
retryable: outcome.retryable,
|
||||
stage: TX_STAGE_BROADCAST,
|
||||
stage: outcome.stage,
|
||||
});
|
||||
}
|
||||
})();
|
||||
|
||||
@@ -9,17 +9,16 @@ const {
|
||||
$,
|
||||
showView,
|
||||
updateDebugBanner,
|
||||
setBackRenderer,
|
||||
setRenderMain,
|
||||
pushCurrentView,
|
||||
goBack,
|
||||
clearViewStack,
|
||||
} = require("./views/helpers");
|
||||
const { applyTheme } = require("./theme");
|
||||
// Renders a view the popup lands on without having navigated to it forward:
|
||||
// on restore here, and on Back. Only the views that can be fully re-rendered
|
||||
// from persisted state (RESTORABLE_VIEWS, src/popup/restorableViews.js) go
|
||||
// through it; anything else falls back to the nearest restorable parent.
|
||||
const { renderView, makeBackRenderer } = require("./viewRouter");
|
||||
// Views that can be fully re-rendered from persisted state. All others fall
|
||||
// back to the nearest restorable parent; see the module for why the
|
||||
// secret-bearing views are absent.
|
||||
const { RESTORABLE_VIEWS } = require("./restorableViews");
|
||||
|
||||
const home = require("./views/home");
|
||||
const welcome = require("./views/welcome");
|
||||
@@ -109,23 +108,92 @@ const ctx = {
|
||||
},
|
||||
};
|
||||
|
||||
// The view modules the router renders through, keyed as it expects them.
|
||||
const viewModules = {
|
||||
main: { show: () => fallbackView() },
|
||||
addressDetail,
|
||||
addressToken,
|
||||
receive,
|
||||
settings,
|
||||
settingsAddToken,
|
||||
confirmTx,
|
||||
transactionDetail,
|
||||
txStatus,
|
||||
};
|
||||
function needsAddress(view) {
|
||||
return (
|
||||
view === "address" ||
|
||||
view === "address-token" ||
|
||||
view === "receive" ||
|
||||
view === "transaction"
|
||||
);
|
||||
}
|
||||
|
||||
function hasValidAddress() {
|
||||
return (
|
||||
state.selectedWallet !== null &&
|
||||
state.selectedAddress !== null &&
|
||||
state.wallets[state.selectedWallet] &&
|
||||
state.wallets[state.selectedWallet].addresses[state.selectedAddress]
|
||||
);
|
||||
}
|
||||
|
||||
function restoreView() {
|
||||
if (!renderView(state.currentView, state, viewModules)) {
|
||||
const view = state.currentView;
|
||||
if (!view || !RESTORABLE_VIEWS.has(view)) {
|
||||
return fallbackView();
|
||||
}
|
||||
|
||||
if (needsAddress(view) && !hasValidAddress()) {
|
||||
return fallbackView();
|
||||
}
|
||||
|
||||
if (view === "address-token" && !state.selectedToken) {
|
||||
return fallbackView();
|
||||
}
|
||||
|
||||
switch (view) {
|
||||
case "address":
|
||||
addressDetail.show();
|
||||
break;
|
||||
case "address-token":
|
||||
addressToken.show();
|
||||
break;
|
||||
case "receive":
|
||||
receive.show();
|
||||
break;
|
||||
case "settings":
|
||||
settings.show();
|
||||
break;
|
||||
case "settings-addtoken":
|
||||
settingsAddToken.show();
|
||||
break;
|
||||
case "confirm-tx":
|
||||
if (state.viewData && state.viewData.pendingTx) {
|
||||
confirmTx.restore();
|
||||
} else {
|
||||
fallbackView();
|
||||
}
|
||||
break;
|
||||
case "transaction":
|
||||
if (state.viewData && state.viewData.tx) {
|
||||
transactionDetail.render();
|
||||
} else {
|
||||
fallbackView();
|
||||
}
|
||||
break;
|
||||
case "wait-tx":
|
||||
// Resumes the receipt poll from the persisted broadcast time.
|
||||
if (!txStatus.restoreWait()) {
|
||||
fallbackView();
|
||||
}
|
||||
break;
|
||||
case "success-tx":
|
||||
if (state.viewData && state.viewData.hash) {
|
||||
txStatus.renderSuccess();
|
||||
} else {
|
||||
fallbackView();
|
||||
}
|
||||
break;
|
||||
case "error-tx":
|
||||
if (state.viewData && state.viewData.message) {
|
||||
txStatus.renderError();
|
||||
} else {
|
||||
fallbackView();
|
||||
}
|
||||
break;
|
||||
default:
|
||||
fallbackView();
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
function fallbackView() {
|
||||
@@ -179,7 +247,7 @@ async function init() {
|
||||
settings.show();
|
||||
});
|
||||
|
||||
setBackRenderer(makeBackRenderer(state, viewModules));
|
||||
setRenderMain(renderWalletList);
|
||||
|
||||
welcome.init(ctx);
|
||||
addWallet.init(ctx);
|
||||
|
||||
@@ -1,167 +0,0 @@
|
||||
// Rendering a view the popup lands on without having navigated to it
|
||||
// forward: on restore, and on Back. In both cases the view may never have
|
||||
// been rendered in this page load — a reopened popup renders only the
|
||||
// wallet list and the view it restores onto, so every other view is still
|
||||
// the blank static template from index.html — so unhiding it is not enough.
|
||||
//
|
||||
// Forward navigation renders as it goes and must NOT come through here:
|
||||
// rendering a second time would re-fetch and clobber whatever the view has
|
||||
// in flight.
|
||||
//
|
||||
// The view modules are injected and nothing here touches the DOM, so the
|
||||
// dispatch and its data guards can be tested directly; src/popup/index.js
|
||||
// cannot be required outside a browser.
|
||||
|
||||
const { RESTORABLE_VIEWS } = require("./restorableViews");
|
||||
|
||||
// The views this page load has rendered.
|
||||
//
|
||||
// The Back path cannot otherwise tell its two cases apart. A view the popup
|
||||
// never rendered is still the blank template from index.html and has to be
|
||||
// rendered; a view already on the page must NOT be rendered again, because
|
||||
// a second render re-fetches and overwrites whatever the user has typed
|
||||
// into it and not yet saved.
|
||||
//
|
||||
// Registration is showView() in views/helpers.js, which is the last thing
|
||||
// every render path runs — restoreView()'s, the Back path's, and every
|
||||
// forward show(). That is the point of putting it there rather than in the
|
||||
// individual views: a view added later registers itself with no one having
|
||||
// to remember it, so this cannot decay.
|
||||
//
|
||||
// Module scope is page-load scope: the popup loads this module once per
|
||||
// page load, and a reopened popup gets a fresh, empty set — which is
|
||||
// exactly the state that makes the Back path render.
|
||||
const renderedViews = new Set();
|
||||
|
||||
function markViewRendered(view) {
|
||||
if (view) renderedViews.add(view);
|
||||
}
|
||||
|
||||
// Begin a fresh page-load scope. The popup gets one by being loaded; the
|
||||
// unit tests, which simulate several page loads against one module
|
||||
// instance, ask for one.
|
||||
function resetRenderedViews() {
|
||||
renderedViews.clear();
|
||||
}
|
||||
|
||||
// Home is the exception: Back re-renders it every time, which is what the
|
||||
// popup did before this router existed (index.js registered
|
||||
// renderWalletList() as setRenderMain(), and goBack() called it on every
|
||||
// Back onto "main"). It must stay that way — the wallet list has to reflect
|
||||
// what changed while the user was away from it, such as a wallet renamed or
|
||||
// an address removed in Settings — and Home holds no unsaved input to lose.
|
||||
const ALWAYS_RENDER_ON_BACK = new Set(["main"]);
|
||||
|
||||
// Views that render an address the user picked and cannot be rendered
|
||||
// without one.
|
||||
const ADDRESS_VIEWS = new Set([
|
||||
"address",
|
||||
"address-token",
|
||||
"receive",
|
||||
"transaction",
|
||||
]);
|
||||
|
||||
function needsAddress(view) {
|
||||
return ADDRESS_VIEWS.has(view);
|
||||
}
|
||||
|
||||
function hasValidAddress(state) {
|
||||
return Boolean(
|
||||
state.selectedWallet !== null &&
|
||||
state.selectedAddress !== null &&
|
||||
state.wallets[state.selectedWallet] &&
|
||||
state.wallets[state.selectedWallet].addresses[state.selectedAddress],
|
||||
);
|
||||
}
|
||||
|
||||
// Render `view` from persisted state. Each view module shows itself, so a
|
||||
// true return means the view is both rendered and on screen.
|
||||
//
|
||||
// Returns false when the view is not one the popup renders from state, or
|
||||
// when the state it would render is gone — a token no longer selected, a
|
||||
// transaction no longer persisted. The caller falls back rather than
|
||||
// putting an empty template on screen.
|
||||
function renderView(view, state, views) {
|
||||
if (!view || !RESTORABLE_VIEWS.has(view)) return false;
|
||||
if (needsAddress(view) && !hasValidAddress(state)) return false;
|
||||
if (view === "address-token" && !state.selectedToken) return false;
|
||||
|
||||
const data = state.viewData || {};
|
||||
switch (view) {
|
||||
case "main":
|
||||
views.main.show();
|
||||
return true;
|
||||
case "address":
|
||||
views.addressDetail.show();
|
||||
return true;
|
||||
case "address-token":
|
||||
views.addressToken.show();
|
||||
return true;
|
||||
case "receive":
|
||||
views.receive.show();
|
||||
return true;
|
||||
case "settings":
|
||||
views.settings.show();
|
||||
return true;
|
||||
case "settings-addtoken":
|
||||
views.settingsAddToken.show();
|
||||
return true;
|
||||
case "confirm-tx":
|
||||
if (!data.pendingTx) return false;
|
||||
views.confirmTx.restore();
|
||||
return true;
|
||||
case "transaction":
|
||||
if (!data.tx) return false;
|
||||
views.transactionDetail.render();
|
||||
return true;
|
||||
case "wait-tx":
|
||||
// Resumes the receipt poll from the persisted broadcast time,
|
||||
// and answers false when there is nothing resumable left.
|
||||
return Boolean(views.txStatus.restoreWait());
|
||||
case "success-tx":
|
||||
if (!data.hash) return false;
|
||||
views.txStatus.renderSuccess();
|
||||
return true;
|
||||
case "error-tx":
|
||||
if (!data.message) return false;
|
||||
views.txStatus.renderError();
|
||||
return true;
|
||||
default:
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
// The Back-path renderer, registered with setBackRenderer() in
|
||||
// views/helpers.js.
|
||||
//
|
||||
// Returns false — leaving goBack() to unhide the view, as it always did —
|
||||
// in the two cases where the view is known to be on the page already:
|
||||
//
|
||||
// - It is not one the popup renders from persisted state. The restored
|
||||
// stack is filtered against RESTORABLE_VIEWS, so such a view can only
|
||||
// be on the stack from this page load, where forward navigation
|
||||
// rendered it on the way in.
|
||||
// - This page load has rendered it. Re-rendering would re-fetch and
|
||||
// clobber what it holds; Home is rendered anyway, see above.
|
||||
//
|
||||
// What is left is the case the router exists for: a view on the stack that
|
||||
// this page load has never rendered, whose template is still blank.
|
||||
function makeBackRenderer(state, views) {
|
||||
return function renderBack(view) {
|
||||
if (!RESTORABLE_VIEWS.has(view)) return false;
|
||||
if (renderedViews.has(view) && !ALWAYS_RENDER_ON_BACK.has(view)) {
|
||||
return false;
|
||||
}
|
||||
if (!renderView(view, state, views)) {
|
||||
views.main.show();
|
||||
}
|
||||
return true;
|
||||
};
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
renderView,
|
||||
makeBackRenderer,
|
||||
markViewRendered,
|
||||
resetRenderedViews,
|
||||
};
|
||||
@@ -7,7 +7,6 @@ const {
|
||||
getAddressValueUsd,
|
||||
} = require("../../shared/prices");
|
||||
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||
const { markViewRendered } = require("../viewRouter");
|
||||
|
||||
// When views are added, removed, or transitions between them change,
|
||||
// update the view-navigation documentation in README.md to match.
|
||||
@@ -77,10 +76,6 @@ function showView(name) {
|
||||
}
|
||||
clearFlash();
|
||||
state.currentView = name;
|
||||
// A view's show() ends here, so this is where the Back path learns the
|
||||
// view is no longer the blank template from index.html and must not be
|
||||
// rendered a second time. See viewRouter.js.
|
||||
markViewRendered(name);
|
||||
saveState();
|
||||
updateDebugBanner(name);
|
||||
}
|
||||
@@ -116,19 +111,12 @@ function updateDebugBanner(viewName) {
|
||||
}
|
||||
}
|
||||
|
||||
// Callback that renders a view being navigated BACK onto. Set once by
|
||||
// index.js via setBackRenderer(), which routes the view through the same
|
||||
// per-view render and data guards restoreView() uses.
|
||||
//
|
||||
// It answers true when it took the navigation — the view is rendered and
|
||||
// shown, or its backing data was gone and it fell back — and false for a
|
||||
// view the popup does not render from persisted state. Those can only be
|
||||
// on the stack from this page load, because the stack is filtered on load,
|
||||
// so they have already been rendered and only need unhiding.
|
||||
let _renderBack = null;
|
||||
// Callback to re-render the main/home view when navigating back to it.
|
||||
// Set once by index.js via setRenderMain().
|
||||
let _renderMain = null;
|
||||
|
||||
function setBackRenderer(fn) {
|
||||
_renderBack = fn;
|
||||
function setRenderMain(fn) {
|
||||
_renderMain = fn;
|
||||
}
|
||||
|
||||
// Push the current view onto the navigation stack so goBack() can
|
||||
@@ -148,11 +136,9 @@ function goBack() {
|
||||
} else {
|
||||
target = "main";
|
||||
}
|
||||
// A popped view is landed on, not navigated to. If the popup has been
|
||||
// closed and reopened since the view was pushed, nothing has ever
|
||||
// rendered it in this page load and its template is still blank, so it
|
||||
// has to be rendered here rather than merely unhidden.
|
||||
if (_renderBack && _renderBack(target)) return;
|
||||
if (target === "main" && _renderMain) {
|
||||
_renderMain();
|
||||
}
|
||||
showView(target);
|
||||
}
|
||||
|
||||
@@ -484,7 +470,7 @@ module.exports = {
|
||||
showView,
|
||||
onViewLeave,
|
||||
updateDebugBanner,
|
||||
setBackRenderer,
|
||||
setRenderMain,
|
||||
pushCurrentView,
|
||||
goBack,
|
||||
clearViewStack,
|
||||
|
||||
@@ -602,6 +602,12 @@ const TX_STAGE_BROADCAST = "broadcast";
|
||||
// may yet succeed, so the one thing the popup must not say is "start again
|
||||
// from the site".
|
||||
const TX_STAGE_INFLIGHT = "inflight";
|
||||
// A transaction refused for a nonce that is already spoken for, either by the
|
||||
// node's own answer or by this wallet's record of what it has broadcast. It is
|
||||
// the one broadcast-stage failure that is not ambiguous: the transaction was
|
||||
// not taken, so the user is told it did not reach the network and to send it
|
||||
// again, rather than being warned that it might already be out there.
|
||||
const TX_STAGE_NONCE = "nonce";
|
||||
|
||||
function errorText(err) {
|
||||
if (typeof err === "string" && err !== "") return err;
|
||||
@@ -611,6 +617,59 @@ function errorText(err) {
|
||||
return "The transaction could not be sent.";
|
||||
}
|
||||
|
||||
// Every string a failure might carry its reason in. ethers reports the node's
|
||||
// own words in `shortMessage`, but a JSON-RPC error it could not classify is
|
||||
// nested under `error` or `info.error` with the node's message intact, and the
|
||||
// classification below has to see that too.
|
||||
function failureTexts(err) {
|
||||
if (typeof err === "string") return [err];
|
||||
if (!err || typeof err !== "object") return [];
|
||||
const texts = [];
|
||||
for (const text of [err.shortMessage, err.message, err.reason]) {
|
||||
if (text) texts.push(String(text));
|
||||
}
|
||||
const nested = err.error || (err.info && err.info.error);
|
||||
if (nested && nested.message) texts.push(String(nested.message));
|
||||
return texts;
|
||||
}
|
||||
|
||||
// What the Ethereum clients say when a transaction's nonce is already spoken
|
||||
// for: either it is below the account's next nonce, or another transaction is
|
||||
// sitting in the pool at that nonce and this one did not outbid it. Either way
|
||||
// the node answered, and its answer was that it did not take this transaction.
|
||||
//
|
||||
// "already known" is deliberately absent. A node that says it knows the
|
||||
// transaction has it, so that transaction did reach the network and the
|
||||
// ambiguous broadcast wording is the correct one for it.
|
||||
const NONCE_COLLISION_PATTERNS = [
|
||||
/nonce too low/i,
|
||||
/nonce has already been used/i,
|
||||
/invalid nonce/i,
|
||||
/oldnonce/i,
|
||||
/replacement transaction underpriced/i,
|
||||
/replacement fee too low/i,
|
||||
];
|
||||
|
||||
// ethers' own classification of the same two conditions.
|
||||
const NONCE_COLLISION_CODES = ["NONCE_EXPIRED", "REPLACEMENT_UNDERPRICED"];
|
||||
|
||||
// Whether a failed send is a nonce collision.
|
||||
function isNonceCollision(err) {
|
||||
if (!err) return false;
|
||||
if (err.code && NONCE_COLLISION_CODES.includes(err.code)) return true;
|
||||
return failureTexts(err).some((text) =>
|
||||
NONCE_COLLISION_PATTERNS.some((pattern) => pattern.test(text)),
|
||||
);
|
||||
}
|
||||
|
||||
// What both the requesting page and the popup are told about a nonce
|
||||
// collision. The node's own words ("nonce too low") are a fragment and are
|
||||
// replaced rather than passed through: they are not a sentence, and they say
|
||||
// less than the wallet knows.
|
||||
const NONCE_COLLISION_MESSAGE =
|
||||
"The transaction was not sent, because its nonce had already been used" +
|
||||
" by another transaction.";
|
||||
|
||||
// What the background does with a pending transaction approval after a failed
|
||||
// attempt: what it tells the popup, and whether the approval is spent
|
||||
// (resolved to the requesting page as an error and deleted) or left standing
|
||||
@@ -627,12 +686,31 @@ function errorText(err) {
|
||||
// that never left from one that is already in the mempool. The approval is
|
||||
// spent and the requesting page has been given its outcome; a second
|
||||
// attempt against it would report a second outcome for one request.
|
||||
// - nonce: terminal too, and the one case where the wallet does know the
|
||||
// transaction never left. The approval carries a nonce that is spent, so
|
||||
// the artifact signed against it can never be accepted and the user is told
|
||||
// to send it again from the site.
|
||||
//
|
||||
// The stage comes back out because a broadcast failure the node blamed on the
|
||||
// nonce is reclassified here; the caller reports the stage this returns rather
|
||||
// than the one it passed in.
|
||||
function describeTxFailure(stage, err) {
|
||||
if (
|
||||
stage === TX_STAGE_NONCE ||
|
||||
(stage === TX_STAGE_BROADCAST && isNonceCollision(err))
|
||||
) {
|
||||
return {
|
||||
error: NONCE_COLLISION_MESSAGE,
|
||||
retryable: false,
|
||||
spendApproval: true,
|
||||
stage: TX_STAGE_NONCE,
|
||||
};
|
||||
}
|
||||
const error = errorText(err);
|
||||
const retryable =
|
||||
stage === TX_STAGE_SIGN ||
|
||||
(stage === TX_STAGE_VERIFY && failureIsRetryable(err));
|
||||
return { error, retryable, spendApproval: !retryable };
|
||||
return { error, retryable, spendApproval: !retryable, stage };
|
||||
}
|
||||
|
||||
// What the popup shows and does after the background reports a failed signing
|
||||
@@ -642,14 +720,20 @@ function describeTxFailure(stage, err) {
|
||||
//
|
||||
// A failed broadcast gets its own wording: the transaction may already be on
|
||||
// the network, so telling the user to start again from the site is exactly the
|
||||
// wrong instruction.
|
||||
// wrong instruction. A nonce collision is the exception to that exception —
|
||||
// the transaction demonstrably did not go out, and saying it might have would
|
||||
// send the user hunting for a transaction that does not exist.
|
||||
function describeSigningFailure(response, fallbackMessage) {
|
||||
let message = (response && response.error) || fallbackMessage;
|
||||
if (!/[.!?]$/.test(message)) message += ".";
|
||||
const retryable = !!(response && response.retryable);
|
||||
const stage = response && response.stage;
|
||||
if (!retryable) {
|
||||
if (stage === TX_STAGE_BROADCAST) {
|
||||
if (stage === TX_STAGE_NONCE) {
|
||||
message +=
|
||||
" The transaction did not reach the network." +
|
||||
" Please send it again from the site.";
|
||||
} else if (stage === TX_STAGE_BROADCAST) {
|
||||
message +=
|
||||
" The transaction may still have reached the network." +
|
||||
" Check the account before sending it again.";
|
||||
@@ -675,9 +759,11 @@ module.exports = {
|
||||
assertWithinCeilings,
|
||||
sameAddress,
|
||||
failureIsRetryable,
|
||||
isNonceCollision,
|
||||
describeTxFailure,
|
||||
describeSigningFailure,
|
||||
ApprovalMismatchError,
|
||||
NONCE_COLLISION_MESSAGE,
|
||||
ALLOWED_TX_TYPES,
|
||||
SERIALIZED_FIELDS,
|
||||
FORBIDDEN_FIELDS,
|
||||
@@ -686,6 +772,7 @@ module.exports = {
|
||||
TX_STAGE_VERIFY,
|
||||
TX_STAGE_BROADCAST,
|
||||
TX_STAGE_INFLIGHT,
|
||||
TX_STAGE_NONCE,
|
||||
MAX_GAS_LIMIT,
|
||||
MAX_FEE_PER_GAS,
|
||||
};
|
||||
|
||||
@@ -14,8 +14,10 @@ const {
|
||||
assertWithinCeilings,
|
||||
sameAddress,
|
||||
failureIsRetryable,
|
||||
isNonceCollision,
|
||||
describeTxFailure,
|
||||
describeSigningFailure,
|
||||
NONCE_COLLISION_MESSAGE,
|
||||
ALLOWED_TX_TYPES,
|
||||
SERIALIZED_FIELDS,
|
||||
FORBIDDEN_FIELDS,
|
||||
@@ -23,6 +25,7 @@ const {
|
||||
TX_STAGE_SIGN,
|
||||
TX_STAGE_VERIFY,
|
||||
TX_STAGE_BROADCAST,
|
||||
TX_STAGE_NONCE,
|
||||
MAX_GAS_LIMIT,
|
||||
MAX_FEE_PER_GAS,
|
||||
} = require("../src/shared/approvalVerify");
|
||||
@@ -1191,7 +1194,6 @@ describe("signing failure and retry", () => {
|
||||
"already known",
|
||||
"timeout of 30000ms exceeded",
|
||||
"could not coalesce error",
|
||||
"replacement transaction underpriced",
|
||||
]) {
|
||||
const outcome = describeTxFailure(
|
||||
TX_STAGE_BROADCAST,
|
||||
@@ -1199,10 +1201,76 @@ describe("signing failure and retry", () => {
|
||||
);
|
||||
expect(outcome.retryable).toBe(false);
|
||||
expect(outcome.spendApproval).toBe(true);
|
||||
expect(outcome.stage).toBe(TX_STAGE_BROADCAST);
|
||||
expect(outcome.error).toBe(message);
|
||||
}
|
||||
});
|
||||
|
||||
// The one broadcast failure that is not ambiguous. The node answered, and
|
||||
// its answer was that the nonce was already spoken for, so this
|
||||
// transaction is not in a mempool anywhere.
|
||||
test("a nonce the node refused is classified however it was worded", () => {
|
||||
for (const err of [
|
||||
new Error("nonce too low"),
|
||||
new Error("replacement transaction underpriced"),
|
||||
Object.assign(new Error("could not coalesce error"), {
|
||||
code: "NONCE_EXPIRED",
|
||||
}),
|
||||
Object.assign(new Error("could not coalesce error"), {
|
||||
code: "REPLACEMENT_UNDERPRICED",
|
||||
}),
|
||||
// The shape ethers hands up when it could not classify the node's
|
||||
// error itself: the node's own words are nested underneath.
|
||||
Object.assign(new Error("could not coalesce error"), {
|
||||
info: { error: { code: -32000, message: "OldNonce" } },
|
||||
}),
|
||||
]) {
|
||||
const outcome = describeTxFailure(TX_STAGE_BROADCAST, err);
|
||||
expect(
|
||||
describeSigningFailure(
|
||||
outcome,
|
||||
"The transaction could not be sent.",
|
||||
).message,
|
||||
).toMatch(/did not reach the network/);
|
||||
expect(outcome.retryable).toBe(false);
|
||||
expect(outcome.spendApproval).toBe(true);
|
||||
expect(outcome.error).toBe(NONCE_COLLISION_MESSAGE);
|
||||
expect(outcome.stage).toBe(TX_STAGE_NONCE);
|
||||
expect(isNonceCollision(err)).toBe(true);
|
||||
}
|
||||
});
|
||||
|
||||
// A node that says it knows the transaction has it, so it did reach the
|
||||
// network and the ambiguous wording is the correct one.
|
||||
test("already known is not a nonce collision", () => {
|
||||
const err = new Error("already known");
|
||||
const outcome = describeTxFailure(TX_STAGE_BROADCAST, err);
|
||||
expect(
|
||||
describeSigningFailure(
|
||||
outcome,
|
||||
"The transaction could not be sent.",
|
||||
).message,
|
||||
).toMatch(/may still have reached the network/);
|
||||
expect(outcome.stage).toBe(TX_STAGE_BROADCAST);
|
||||
expect(isNonceCollision(err)).toBe(false);
|
||||
});
|
||||
|
||||
test("a nonce collision says the transaction did not reach the network", () => {
|
||||
const outcome = describeTxFailure(
|
||||
TX_STAGE_BROADCAST,
|
||||
new Error("nonce too low"),
|
||||
);
|
||||
const copy = describeSigningFailure(
|
||||
outcome,
|
||||
"The transaction could not be sent.",
|
||||
);
|
||||
expect(copy.retryable).toBe(false);
|
||||
expect(copy.message).toMatch(/did not reach the network/);
|
||||
expect(copy.message).not.toMatch(/may still have reached the network/);
|
||||
expect(copy.message).toMatch(/Please send it again from the site\.$/);
|
||||
expect(copy.message).toMatch(/^[A-Z].*\.$/);
|
||||
});
|
||||
|
||||
test("a failed broadcast does not tell the user to send it again", () => {
|
||||
const outcome = describeSigningFailure(
|
||||
{
|
||||
|
||||
@@ -1,329 +0,0 @@
|
||||
// Back after reopening the popup (#268).
|
||||
//
|
||||
// A reopened popup renders the wallet list and the one view it restores
|
||||
// onto; every other view is still the blank static template from
|
||||
// index.html. goBack() used to only unhide its target, so Back landed on
|
||||
// that blank template for any view the popup had not rendered in this page
|
||||
// load. These tests drive the real goBack() with the real router wired to
|
||||
// recording view modules, so what is asserted is which view render ran —
|
||||
// the thing that was missing.
|
||||
//
|
||||
// The rendering itself is asserted against the real popup in a real
|
||||
// browser by tests/e2e/run.js; here the DOM is a stub, because goBack()
|
||||
// only needs showView() to work.
|
||||
|
||||
const els = new Map();
|
||||
|
||||
function fakeEl() {
|
||||
return {
|
||||
textContent: "",
|
||||
innerHTML: "",
|
||||
classList: {
|
||||
toggle() {},
|
||||
add() {},
|
||||
remove() {},
|
||||
contains: () => false,
|
||||
},
|
||||
remove() {},
|
||||
};
|
||||
}
|
||||
|
||||
globalThis.document = {
|
||||
getElementById(id) {
|
||||
if (!els.has(id)) els.set(id, fakeEl());
|
||||
return els.get(id);
|
||||
},
|
||||
};
|
||||
|
||||
// helpers.js pulls in state.js, which reads chrome.storage.local at load.
|
||||
globalThis.chrome = {
|
||||
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||
};
|
||||
|
||||
const {
|
||||
showView,
|
||||
goBack,
|
||||
setBackRenderer,
|
||||
pushCurrentView,
|
||||
} = require("../src/popup/views/helpers");
|
||||
const {
|
||||
makeBackRenderer,
|
||||
markViewRendered,
|
||||
resetRenderedViews,
|
||||
} = require("../src/popup/viewRouter");
|
||||
const { state } = require("../src/shared/state");
|
||||
|
||||
const ADDRESS = "0x1111111111111111111111111111111111111111";
|
||||
const TOKEN = "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48";
|
||||
|
||||
let calls;
|
||||
|
||||
// Stand-ins for the view modules. Each records itself and then shows its
|
||||
// view, which is what every real view render ends with — so the assertions
|
||||
// can tell "rendered and shown" apart from "merely unhidden".
|
||||
function recorder(name, view) {
|
||||
return () => {
|
||||
calls.push(name);
|
||||
showView(view);
|
||||
};
|
||||
}
|
||||
|
||||
function makeViews() {
|
||||
return {
|
||||
main: { show: recorder("main", "main") },
|
||||
addressDetail: { show: recorder("addressDetail", "address") },
|
||||
addressToken: { show: recorder("addressToken", "address-token") },
|
||||
receive: { show: recorder("receive", "receive") },
|
||||
settings: { show: recorder("settings", "settings") },
|
||||
settingsAddToken: {
|
||||
show: recorder("settingsAddToken", "settings-addtoken"),
|
||||
},
|
||||
confirmTx: { restore: recorder("confirmTx", "confirm-tx") },
|
||||
transactionDetail: {
|
||||
render: recorder("transactionDetail", "transaction"),
|
||||
},
|
||||
txStatus: {
|
||||
restoreWait: () => {
|
||||
calls.push("waitTx");
|
||||
showView("wait-tx");
|
||||
return true;
|
||||
},
|
||||
renderSuccess: recorder("successTx", "success-tx"),
|
||||
renderError: recorder("errorTx", "error-tx"),
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
// The popup as it stands just after a reopen: one wallet with one address,
|
||||
// the view the popup restored onto, and the stack behind it.
|
||||
//
|
||||
// A reopen is a fresh page load, so the record of what has been rendered
|
||||
// starts empty — that emptiness is what makes the Back path render at all.
|
||||
// Returns the view modules so a test can drive forward navigation through
|
||||
// the same recorders the router renders through.
|
||||
function reopenedOn(view, stack, extra) {
|
||||
calls = [];
|
||||
resetRenderedViews();
|
||||
state.wallets = [
|
||||
{
|
||||
name: "Wallet 1",
|
||||
addresses: [{ address: ADDRESS, balance: "0", tokenBalances: [] }],
|
||||
},
|
||||
];
|
||||
state.selectedWallet = 0;
|
||||
state.selectedAddress = 0;
|
||||
state.selectedToken = null;
|
||||
state.viewData = null;
|
||||
state.currentView = view;
|
||||
state.viewStack = stack.slice();
|
||||
Object.assign(state, extra || {});
|
||||
// Restoring onto a view renders it, so the reopened popup has that one
|
||||
// view on the page and nothing else.
|
||||
markViewRendered(view);
|
||||
const views = makeViews();
|
||||
setBackRenderer(makeBackRenderer(state, views));
|
||||
return views;
|
||||
}
|
||||
|
||||
// The reproduction from the issue, step for step.
|
||||
describe("Back onto a view the reopened popup never rendered", () => {
|
||||
test("Back from settings renders the address detail underneath", () => {
|
||||
reopenedOn("settings", ["main", "address"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["addressDetail"]);
|
||||
expect(state.currentView).toBe("address");
|
||||
expect(state.viewStack).toEqual(["main"]);
|
||||
});
|
||||
|
||||
test("Back onto the token detail renders it", () => {
|
||||
reopenedOn("settings", ["main", "address", "address-token"], {
|
||||
selectedToken: TOKEN,
|
||||
});
|
||||
goBack();
|
||||
expect(calls).toEqual(["addressToken"]);
|
||||
expect(state.currentView).toBe("address-token");
|
||||
});
|
||||
|
||||
test("Back onto Receive renders it", () => {
|
||||
reopenedOn("settings", ["main", "address", "receive"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["receive"]);
|
||||
expect(state.currentView).toBe("receive");
|
||||
});
|
||||
|
||||
test("Back onto the transaction detail renders it", () => {
|
||||
reopenedOn("settings", ["main", "transaction"], {
|
||||
viewData: { tx: { hash: "0xdead" } },
|
||||
});
|
||||
goBack();
|
||||
expect(calls).toEqual(["transactionDetail"]);
|
||||
expect(state.currentView).toBe("transaction");
|
||||
});
|
||||
|
||||
test("Back onto the transaction confirmation restores it", () => {
|
||||
reopenedOn("settings", ["main", "confirm-tx"], {
|
||||
viewData: { pendingTx: { to: ADDRESS, amount: "1" } },
|
||||
});
|
||||
goBack();
|
||||
expect(calls).toEqual(["confirmTx"]);
|
||||
expect(state.currentView).toBe("confirm-tx");
|
||||
});
|
||||
|
||||
test("Back onto the success screen renders it", () => {
|
||||
reopenedOn("settings", ["main", "success-tx"], {
|
||||
viewData: { hash: "0xdead" },
|
||||
});
|
||||
goBack();
|
||||
expect(calls).toEqual(["successTx"]);
|
||||
expect(state.currentView).toBe("success-tx");
|
||||
});
|
||||
|
||||
test("Back onto the failure screen renders it", () => {
|
||||
reopenedOn("settings", ["main", "error-tx"], {
|
||||
viewData: { message: "execution reverted" },
|
||||
});
|
||||
goBack();
|
||||
expect(calls).toEqual(["errorTx"]);
|
||||
expect(state.currentView).toBe("error-tx");
|
||||
});
|
||||
|
||||
test("Back onto Home renders the wallet list", () => {
|
||||
reopenedOn("settings", ["main"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("Back with an empty stack renders Home", () => {
|
||||
reopenedOn("settings", []);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
});
|
||||
|
||||
// The guards are restoreView()'s, so a popped view whose backing data is
|
||||
// gone lands on Home rather than on an empty template.
|
||||
describe("Back onto a view whose backing data is gone", () => {
|
||||
test("the token detail with no token selected falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "address-token"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("the transaction detail with no transaction falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "transaction"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("the confirmation with no pending transaction falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "confirm-tx"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("an address view with no address selected falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "receive"], {
|
||||
selectedAddress: null,
|
||||
});
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("the success screen with no transaction hash falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "success-tx"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("the failure screen with no message falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "error-tx"]);
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("a wait that can no longer be resumed falls back to Home", () => {
|
||||
reopenedOn("settings", ["main", "wait-tx"]);
|
||||
const views = makeViews();
|
||||
views.txStatus.restoreWait = () => false;
|
||||
setBackRenderer(makeBackRenderer(state, views));
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
});
|
||||
|
||||
// Forward navigation renders as it goes, and a second render would re-fetch
|
||||
// and clobber whatever the view holds — an unsaved edit, a request in
|
||||
// flight. So the Back path renders only a view this page load has never
|
||||
// rendered, and merely unhides every other one: the views it does not
|
||||
// render from persisted state, and the views already on the page.
|
||||
describe("what the Back path leaves alone", () => {
|
||||
test("forward navigation renders nothing by itself", () => {
|
||||
reopenedOn("address", ["main"]);
|
||||
pushCurrentView();
|
||||
showView("send");
|
||||
expect(calls).toEqual([]);
|
||||
expect(state.viewStack).toEqual(["main", "address"]);
|
||||
});
|
||||
|
||||
test("Back onto a live-session view only unhides it", () => {
|
||||
reopenedOn("confirm-tx", ["main", "address", "send"]);
|
||||
goBack();
|
||||
expect(calls).toEqual([]);
|
||||
expect(state.currentView).toBe("send");
|
||||
});
|
||||
|
||||
test("Back renders its target exactly once", () => {
|
||||
reopenedOn("settings", ["main", "address"]);
|
||||
goBack();
|
||||
expect(calls.filter((c) => c === "addressDetail")).toHaveLength(1);
|
||||
});
|
||||
|
||||
test("Back onto a view this page load already rendered only unhides it", () => {
|
||||
const views = reopenedOn("main", []);
|
||||
pushCurrentView();
|
||||
views.addressDetail.show();
|
||||
pushCurrentView();
|
||||
views.settings.show();
|
||||
calls = [];
|
||||
goBack();
|
||||
expect(calls).toEqual([]);
|
||||
expect(state.currentView).toBe("address");
|
||||
});
|
||||
|
||||
// The unit mirror of the regression the browser suite pins: Settings
|
||||
// reassigns its fields from persisted state on every render, so a
|
||||
// re-render on the way back discards an edit the user has not saved.
|
||||
test("Back onto Settings visited earlier in this page load does not re-render it", () => {
|
||||
const views = reopenedOn("main", []);
|
||||
pushCurrentView();
|
||||
views.settings.show();
|
||||
pushCurrentView();
|
||||
views.settingsAddToken.show();
|
||||
calls = [];
|
||||
goBack();
|
||||
expect(calls).toEqual([]);
|
||||
expect(state.currentView).toBe("settings");
|
||||
});
|
||||
|
||||
// Home is the deliberate exception, unchanged from the popup's
|
||||
// behaviour before the router existed: it re-renders on every Back so
|
||||
// the wallet list reflects what changed while the user was away.
|
||||
test("Back onto Home renders it again even when it is already on the page", () => {
|
||||
const views = reopenedOn("main", []);
|
||||
pushCurrentView();
|
||||
views.addressDetail.show();
|
||||
calls = [];
|
||||
goBack();
|
||||
expect(calls).toEqual(["main"]);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
});
|
||||
@@ -206,6 +206,10 @@ function loadBackground(options) {
|
||||
// approval id back out of the popup URL the background opened.
|
||||
function requestTx(txParams) {
|
||||
let rpcResult = null;
|
||||
// The window this request opens, if it opens one. A request refused
|
||||
// before an approval is raised opens none, and the window belonging to
|
||||
// some other request must not be handed back as this one's.
|
||||
const windowIndex = created.length;
|
||||
const sendResponse = jest.fn((r) => {
|
||||
rpcResult = r;
|
||||
});
|
||||
@@ -219,7 +223,12 @@ function loadBackground(options) {
|
||||
sendResponse,
|
||||
);
|
||||
return {
|
||||
id: () => new URL(created[0].url).searchParams.get("approval"),
|
||||
id: () =>
|
||||
created.length > windowIndex
|
||||
? new URL(created[windowIndex].url).searchParams.get(
|
||||
"approval",
|
||||
)
|
||||
: null,
|
||||
result: () => rpcResult,
|
||||
};
|
||||
}
|
||||
@@ -444,6 +453,176 @@ describe("one approval, one broadcast", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// Populating the transaction before the approval window opens is what makes
|
||||
// the displayed object the verified object. It also fixes the nonce before the
|
||||
// user has answered anything: two requests populated concurrently take the
|
||||
// same nonce from a node that has seen neither of them broadcast, and the
|
||||
// second can then never be sent, because the only way to give it a fresh nonce
|
||||
// is to populate it again after the user has read the old one off the screen.
|
||||
// So the second request is refused while the first is unanswered.
|
||||
describe("one transaction approval at a time", () => {
|
||||
test("a second eth_sendTransaction while one is pending is refused before it takes a nonce", async () => {
|
||||
const getTransactionCount = jest.fn(async () => NONCE);
|
||||
const bg = loadBackground({ provider: { getTransactionCount } });
|
||||
|
||||
const first = bg.requestTx();
|
||||
await settle();
|
||||
expect(first.id()).toBeTruthy();
|
||||
expect(getTransactionCount).toHaveBeenCalledTimes(1);
|
||||
|
||||
const second = bg.requestTx();
|
||||
await settle();
|
||||
|
||||
expect(second.result()).toEqual({
|
||||
error: {
|
||||
code: -32002,
|
||||
message: expect.stringMatching(
|
||||
/already waiting to be approved/,
|
||||
),
|
||||
},
|
||||
});
|
||||
// Where the refusal happened matters as much as that it happened: no
|
||||
// second window, and the node was never asked for a second nonce.
|
||||
expect(bg.created).toHaveLength(1);
|
||||
expect(getTransactionCount).toHaveBeenCalledTimes(1);
|
||||
|
||||
// The refusal leaves the pending approval untouched, and it still
|
||||
// sends.
|
||||
bg.broadcastTransaction.mockResolvedValue({ hash: "0xfeed" });
|
||||
bg.send(
|
||||
{
|
||||
type: "AUTISTMASK_TX_RESPONSE",
|
||||
id: first.id(),
|
||||
approved: true,
|
||||
rawSignedTx: await signedAtNonce(NONCE),
|
||||
},
|
||||
{ url: bg.fromPopup.url },
|
||||
);
|
||||
await settle();
|
||||
expect(first.result()).toEqual({ result: "0xfeed" });
|
||||
});
|
||||
|
||||
test("an answered approval frees the next request", async () => {
|
||||
const bg = loadBackground();
|
||||
const first = bg.requestTx();
|
||||
await settle();
|
||||
|
||||
// The user closes the approval window, which rejects it.
|
||||
bg.closeWindow(1);
|
||||
await settle();
|
||||
expect(first.result()).toEqual({
|
||||
error: { code: 4001, message: "User rejected the request." },
|
||||
});
|
||||
|
||||
const second = bg.requestTx();
|
||||
await settle();
|
||||
expect(second.id()).toBeTruthy();
|
||||
expect(bg.created).toHaveLength(2);
|
||||
});
|
||||
|
||||
test("a signature request is not held up by a pending transaction", async () => {
|
||||
const bg = loadBackground();
|
||||
bg.requestTx();
|
||||
await settle();
|
||||
|
||||
// A signature consumes no nonce, so it has nothing to collide with.
|
||||
const signing = bg.requestSign();
|
||||
await settle();
|
||||
expect(signing.id()).toBeTruthy();
|
||||
expect(signing.result()).toBeNull();
|
||||
expect(bg.created).toHaveLength(2);
|
||||
});
|
||||
});
|
||||
|
||||
// A nonce collision found before the transaction reaches the network is the
|
||||
// one send failure the wallet can speak about with certainty. The user is told
|
||||
// it did not go out and to send it again, rather than being warned it might
|
||||
// already be on the chain — which would send them looking for a transaction
|
||||
// that does not exist, and stop them retrying the one that never went.
|
||||
describe("a nonce collision is reported as a transaction that did not go out", () => {
|
||||
test("a broadcast the node refused for the nonce is not reported as possibly sent", async () => {
|
||||
const bg = loadBackground();
|
||||
const pending = bg.requestTx();
|
||||
await settle();
|
||||
|
||||
bg.broadcastTransaction.mockRejectedValue(
|
||||
Object.assign(new Error("nonce too low"), {
|
||||
code: "NONCE_EXPIRED",
|
||||
}),
|
||||
);
|
||||
const answer = bg.send(
|
||||
{
|
||||
type: "AUTISTMASK_TX_RESPONSE",
|
||||
id: pending.id(),
|
||||
approved: true,
|
||||
rawSignedTx: await signedAtNonce(NONCE),
|
||||
},
|
||||
{ url: bg.fromPopup.url },
|
||||
);
|
||||
await settle();
|
||||
|
||||
expect(answer.sendResponse).toHaveBeenCalledWith({
|
||||
error: expect.stringMatching(/nonce had already been used/),
|
||||
retryable: false,
|
||||
stage: "nonce",
|
||||
});
|
||||
expect(pending.result()).toEqual({
|
||||
error: {
|
||||
message: expect.stringMatching(
|
||||
/transaction was not sent, because its nonce/,
|
||||
),
|
||||
},
|
||||
});
|
||||
});
|
||||
|
||||
test("a nonce this wallet already broadcast is refused without asking the node again", async () => {
|
||||
const bg = loadBackground();
|
||||
const first = bg.requestTx();
|
||||
await settle();
|
||||
|
||||
bg.broadcastTransaction.mockResolvedValue({ hash: "0xfeed" });
|
||||
bg.send(
|
||||
{
|
||||
type: "AUTISTMASK_TX_RESPONSE",
|
||||
id: first.id(),
|
||||
approved: true,
|
||||
rawSignedTx: await signedAtNonce(NONCE),
|
||||
},
|
||||
{ url: bg.fromPopup.url },
|
||||
);
|
||||
await settle();
|
||||
expect(first.result()).toEqual({ result: "0xfeed" });
|
||||
|
||||
// The stubbed node still reports NONCE as the next nonce — a pending
|
||||
// count that lags a broadcast the node has already taken — so this
|
||||
// second approval is populated at a nonce this worker has spent.
|
||||
const second = bg.requestTx();
|
||||
await settle();
|
||||
const answer = bg.send(
|
||||
{
|
||||
type: "AUTISTMASK_TX_RESPONSE",
|
||||
id: second.id(),
|
||||
approved: true,
|
||||
rawSignedTx: await signedAtNonce(NONCE),
|
||||
},
|
||||
{ url: bg.fromPopup.url },
|
||||
);
|
||||
await settle();
|
||||
|
||||
expect(bg.broadcastTransaction).toHaveBeenCalledTimes(1);
|
||||
expect(answer.sendResponse).toHaveBeenCalledWith({
|
||||
error: expect.stringMatching(/nonce had already been used/),
|
||||
retryable: false,
|
||||
stage: "nonce",
|
||||
});
|
||||
expect(second.result()).toEqual({
|
||||
error: {
|
||||
message: expect.stringMatching(/nonce had already been used/),
|
||||
},
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
// The approval carries the transaction the user was shown and the address it
|
||||
// was raised for, and the artifact is checked against both. Every case here is
|
||||
// one the old comparison — against the dApp's request, for the address that is
|
||||
|
||||
@@ -1,34 +0,0 @@
|
||||
# Chrome end-to-end image: the pinned Playwright image with this repo and a
|
||||
# freshly built extension inside it, built by script/test-e2e. The suite is
|
||||
# still started with `docker run`, so every runtime flag the harness needs
|
||||
# (--ipc=host in particular) applies as before.
|
||||
#
|
||||
# The repo is baked in rather than bind-mounted because a bind mount does
|
||||
# not resolve under Gitea Actions: the runner runs the job in a container
|
||||
# against the HOST's docker socket, so the source side of a -v is resolved
|
||||
# by the host daemon while the job's checkout lives on a docker volume that
|
||||
# is not a host path -- the mount silently succeeds and /work is empty. A
|
||||
# build context is streamed to the daemon and so works from anywhere.
|
||||
# Building the extension here too means the machine starting a run needs
|
||||
# docker and nothing else.
|
||||
|
||||
# mcr.microsoft.com/playwright:v1.56.0-noble, 2026-08-09
|
||||
#
|
||||
# The playwright-core devDependency is pinned to the matching Playwright
|
||||
# version (1.56.0) and the two must be bumped together: the browsers ship
|
||||
# inside this image, and playwright-core looks for the exact browser
|
||||
# revision its own version expects. A mismatch fails at launch.
|
||||
FROM mcr.microsoft.com/playwright@sha256:35246d87a7c88ea9b771c65d33171b2611b02a8253b4b12ce6f94376c55f99f2
|
||||
|
||||
WORKDIR /work
|
||||
|
||||
# Same layering as the root Dockerfile: script/bootstrap installs the
|
||||
# prerequisites and the dependencies, and the manifests are copied first so
|
||||
# that layer is cached until they change.
|
||||
COPY script/ script/
|
||||
COPY package.json yarn.lock ./
|
||||
RUN script/bootstrap
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN make build
|
||||
@@ -1,24 +1,10 @@
|
||||
# Firefox end-to-end image: stock Firefox plus geckodriver on a node base,
|
||||
# with this repo and a freshly built extension inside it, built by
|
||||
# script/test-e2e-firefox. The harness itself has no dependencies, so
|
||||
# nothing is installed for it.
|
||||
# built by script/test-e2e-firefox. The repo is bind-mounted at /work; the
|
||||
# harness itself has no dependencies, so nothing is installed for it.
|
||||
#
|
||||
# The build context is the repo root. The repo is baked in rather than
|
||||
# bind-mounted because a bind mount does not resolve under Gitea Actions:
|
||||
# the runner runs the job in a container against the HOST's docker socket,
|
||||
# so the source side of a -v is resolved by the host daemon while the job's
|
||||
# checkout lives on a docker volume that is not a host path -- the mount
|
||||
# silently succeeds and /work is empty. Baking the build in is also the
|
||||
# only way this suite can have both a built extension and the
|
||||
# `--network none` it runs under, since a container with no network cannot
|
||||
# install anything.
|
||||
#
|
||||
# All three external artifacts are pinned by digest, and are fetched in
|
||||
# layers above the repo copy, so editing the harness or any source file
|
||||
# re-runs only the two cheap layers at the bottom. The Firefox version in
|
||||
# particular must not float: -remote-allow-system-access is mandatory on
|
||||
# 153 and was not on 142, so the flag the harness passes is
|
||||
# version-coupled.
|
||||
# All three external artifacts are pinned by digest. The Firefox version in
|
||||
# particular must not float: -remote-allow-system-access is mandatory on 153
|
||||
# and was not on 142, so the flag the harness passes is version-coupled.
|
||||
|
||||
# node:22-bookworm-slim, 2026-08-12
|
||||
FROM node@sha256:d649c27dae7ba0137b3cef5dd75baa422c08dc3d9e3fc0c23dfb172dc3cc6436
|
||||
@@ -62,16 +48,4 @@ ENV FIREFOX_BIN=/opt/firefox/firefox
|
||||
ENV GECKODRIVER=/usr/local/bin/geckodriver
|
||||
|
||||
WORKDIR /work
|
||||
|
||||
# Same layering as the root Dockerfile: script/bootstrap installs the
|
||||
# prerequisites and the dependencies, and the manifests are copied first so
|
||||
# that layer is cached until they change.
|
||||
COPY script/ script/
|
||||
COPY package.json yarn.lock ./
|
||||
RUN script/bootstrap
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN make build
|
||||
|
||||
CMD ["node", "tests/e2e/firefox/run.js", "dist/firefox"]
|
||||
|
||||
166
tests/e2e/run.js
166
tests/e2e/run.js
@@ -419,172 +419,6 @@ test("reopening the popup never lands on the phrase screen (#161)", async (env)
|
||||
assertWiped(st, env.phrase, "after reopening the popup");
|
||||
});
|
||||
|
||||
// ------------------------------- Back after reopening the popup (#268)
|
||||
|
||||
// A reopened popup renders the wallet list and the view it restores onto,
|
||||
// and nothing else: every other screen is still the blank static template
|
||||
// from index.html. Back used to only unhide its target, which is why these
|
||||
// have to run against the real popup — the template is present and
|
||||
// well-formed, so only its emptiness distinguishes the defect, and only a
|
||||
// real reopen produces it.
|
||||
|
||||
// Everything the address screen must have on it, read out of the DOM.
|
||||
function addressScreenState(page) {
|
||||
return page.evaluate(() => {
|
||||
const line = document.getElementById("address-line");
|
||||
const balances = document.getElementById("address-balances");
|
||||
return {
|
||||
hidden: document
|
||||
.getElementById("view-address")
|
||||
.classList.contains("hidden"),
|
||||
line: line ? line.innerText.trim() : "",
|
||||
balances: balances ? balances.innerText.trim() : "",
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
// Close and reopen the page rather than reload it: that is what the toolbar
|
||||
// popup does, and it is the only thing that produces the unrendered views.
|
||||
async function reopenPopup(env, restoredView) {
|
||||
await env.page.close();
|
||||
env.page = await openPopup(env.ctx, env.popupUrl);
|
||||
await visible(env.page, restoredView);
|
||||
}
|
||||
|
||||
// The reproduction from the issue, step for step.
|
||||
test("Back after reopening the popup renders the address screen (#268)", async (env) => {
|
||||
await openAddressDetail(env.page);
|
||||
const before = await addressScreenState(env.page);
|
||||
assert(
|
||||
before.line.length > 0,
|
||||
"the address screen was blank to begin with",
|
||||
);
|
||||
|
||||
await env.page.click("#btn-settings");
|
||||
await visible(env.page, "#view-settings");
|
||||
|
||||
await reopenPopup(env, "#view-settings");
|
||||
|
||||
await env.page.click("#btn-settings-back");
|
||||
await visible(env.page, "#view-address");
|
||||
|
||||
const after = await addressScreenState(env.page);
|
||||
assert(
|
||||
after.line === before.line,
|
||||
"the address line reads " +
|
||||
JSON.stringify(after.line) +
|
||||
", expected " +
|
||||
JSON.stringify(before.line),
|
||||
);
|
||||
assert(
|
||||
after.balances.includes("ETH"),
|
||||
"the balances read " + JSON.stringify(after.balances),
|
||||
);
|
||||
});
|
||||
|
||||
// The same defect one screen further in. Receive holds the address twice
|
||||
// over — as text and as the QR code the sender scans — and a blank one is
|
||||
// worse than a missing screen.
|
||||
// Everything the Receive screen must have on it. The QR code is read as
|
||||
// pixels, not as an element: the blank template carries the canvas too, a
|
||||
// default 300x150 one with nothing drawn on it and every pixel fully
|
||||
// transparent. A drawn QR paints an opaque background across the whole
|
||||
// canvas, so a single opaque pixel is the whole question.
|
||||
function receiveScreenState(page) {
|
||||
return page.evaluate(() => {
|
||||
const block = document.getElementById("receive-address-block");
|
||||
const canvas = document.getElementById("receive-qr");
|
||||
const px = canvas
|
||||
.getContext("2d")
|
||||
.getImageData(0, 0, canvas.width, canvas.height).data;
|
||||
let opaque = 0;
|
||||
for (let i = 3; i < px.length; i += 4) {
|
||||
if (px[i] > 0) opaque += 1;
|
||||
}
|
||||
return {
|
||||
address: block.dataset.full || "",
|
||||
text: block.innerText.trim(),
|
||||
qrOpaquePixels: opaque,
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
test("Back after reopening the popup renders the Receive screen (#268)", async (env) => {
|
||||
await openAddressDetail(env.page);
|
||||
await env.page.click("#btn-receive");
|
||||
await visible(env.page, "#view-receive");
|
||||
const before = await receiveScreenState(env.page);
|
||||
assert(
|
||||
/^0x[0-9a-fA-F]{40}$/.test(before.address),
|
||||
"Receive showed no address to begin with: " +
|
||||
JSON.stringify(before.address),
|
||||
);
|
||||
|
||||
await env.page.click("#btn-settings");
|
||||
await visible(env.page, "#view-settings");
|
||||
|
||||
await reopenPopup(env, "#view-settings");
|
||||
|
||||
await env.page.click("#btn-settings-back");
|
||||
await visible(env.page, "#view-receive");
|
||||
|
||||
const shown = await receiveScreenState(env.page);
|
||||
assert(
|
||||
shown.address === before.address,
|
||||
"Receive shows " +
|
||||
JSON.stringify(shown.address) +
|
||||
", expected " +
|
||||
JSON.stringify(before.address),
|
||||
);
|
||||
assert(
|
||||
shown.text.includes(before.address),
|
||||
"the Receive address is not on screen: " + JSON.stringify(shown.text),
|
||||
);
|
||||
assert(shown.qrOpaquePixels > 0, "Receive shows an unpainted QR code");
|
||||
|
||||
// Leave the suite where it found it.
|
||||
await env.page.click("#btn-receive-back");
|
||||
await visible(env.page, "#view-address");
|
||||
await env.page.click("#btn-address-back");
|
||||
await visible(env.page, "#view-main");
|
||||
});
|
||||
|
||||
// The other half of the requirement: Back renders a screen this page load
|
||||
// never rendered, and must NOT re-render one it already has on screen.
|
||||
// settings.show() reassigns #settings-rpc from persisted state, so
|
||||
// re-rendering Settings on the way back would silently revert whatever the
|
||||
// user typed and had not saved yet — and they could then press Save and
|
||||
// store the value they believed they had replaced. No reopen here: this is
|
||||
// an ordinary in-session forward-and-back, which is exactly why the render
|
||||
// must not happen.
|
||||
test("Back onto Settings keeps unsaved input (#268)", async (env) => {
|
||||
await visible(env.page, "#view-main");
|
||||
await env.page.click("#btn-settings");
|
||||
await visible(env.page, "#view-settings");
|
||||
|
||||
const typed = "https://rpc.example.invalid/unsaved";
|
||||
await env.page.fill("#settings-rpc", typed);
|
||||
|
||||
await env.page.click("#btn-settings-add-token");
|
||||
await visible(env.page, "#view-settings-addtoken");
|
||||
await env.page.click("#btn-settings-addtoken-back");
|
||||
await visible(env.page, "#view-settings");
|
||||
|
||||
const kept = await env.page.inputValue("#settings-rpc");
|
||||
assert(
|
||||
kept === typed,
|
||||
"the unsaved RPC URL reads " +
|
||||
JSON.stringify(kept) +
|
||||
", expected " +
|
||||
JSON.stringify(typed),
|
||||
);
|
||||
|
||||
// Leave the suite where it found it. The typed value was never saved,
|
||||
// and Settings reloads the field from state next time it renders.
|
||||
await env.page.click("#btn-settings-back");
|
||||
await visible(env.page, "#view-main");
|
||||
});
|
||||
|
||||
// -------------------------------------------- address removal (#162)
|
||||
|
||||
// Number of address rows across every wallet in the list, counted in the DOM
|
||||
|
||||
Reference in New Issue
Block a user