Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8b68b3e681 |
@@ -414,16 +414,18 @@ content script, the inpage provider, the background worker and the approval
|
||||
popup all have to work together. A local test page is served by the route
|
||||
handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
|
||||
`MAIN`-world content script like any other page, and drives
|
||||
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
|
||||
`eth_sendTransaction` through the real prompts. Every signature is recovered in
|
||||
the runner and compared against the active address, the transaction assertions
|
||||
run against the raw signed transaction captured at `eth_sendRawTransaction`
|
||||
rather than against anything the extension reported, rejecting each prompt is
|
||||
required to return a rejection to the page rather than hang or resolve, a prompt
|
||||
raised while another approval window has focus is required to open a window of
|
||||
its own, and the password is required to be absent from every message the
|
||||
approval window sends to the background — with the message that would carry it
|
||||
required to be present, so that check cannot pass by observing nothing. That
|
||||
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4`,
|
||||
`eth_sendTransaction` and `wallet_switchEthereumChain` through the real prompts.
|
||||
Every signature is recovered in the runner and compared against the active
|
||||
address, the transaction assertions run against the raw signed transaction
|
||||
captured at `eth_sendRawTransaction` rather than against anything the extension
|
||||
reported, rejecting each prompt is required to return a rejection to the page
|
||||
rather than hang or resolve, a network switch request is required to leave the
|
||||
stored network unchanged and send no `chainChanged` until it is approved, a
|
||||
prompt raised while another approval window has focus is required to open a
|
||||
window of its own, and the password is required to be absent from every message
|
||||
the approval window sends to the background — with the message that would carry
|
||||
it required to be present, so that check cannot pass by observing nothing. That
|
||||
last one is the standing floor under
|
||||
[#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
||||
|
||||
@@ -525,10 +527,11 @@ Chrome that ever changes this fails the run instead of passing it.
|
||||
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
|
||||
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
|
||||
It covers popup load, the StateRecovery screen (the same cases as the Chrome
|
||||
suite), wallet creation through the UI, the Add Token screen, and the four dApp
|
||||
round trips — `eth_requestAccounts`, `personal_sign`, `eth_sendTransaction`, and
|
||||
a closed approval window rejecting with EIP-1193 4001 — driven through the real
|
||||
content script, background page and approval windows.
|
||||
suite), wallet creation through the UI, the Add Token screen, and the dApp round
|
||||
trips — `eth_requestAccounts`, `personal_sign`, `wallet_switchEthereumChain`
|
||||
rejected and then approved, `eth_sendTransaction`, and a closed approval window
|
||||
rejecting with EIP-1193 4001 — driven through the real content script,
|
||||
background page and approval windows.
|
||||
|
||||
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
|
||||
**no npm dependencies at all**: it is built on global `fetch` and
|
||||
@@ -1783,7 +1786,9 @@ view would leave a wallet one click from deletion.
|
||||
- Display: "Show tracked tokens with zero balance" checkbox, "UTC
|
||||
Timestamps" checkbox, and a Theme selector (System / Light / Dark)
|
||||
- Network: network selector (Ethereum Mainnet / Sepolia Testnet); switching
|
||||
resets the RPC and Blockscout endpoints to that network's defaults
|
||||
resets the RPC and Blockscout endpoints to that network's defaults. The
|
||||
network changes only here, or when the user approves a site's request on
|
||||
**NetworkApproval**
|
||||
- Ethereum RPC: endpoint URL input + "Save" button (validated against
|
||||
`eth_chainId` before being saved)
|
||||
- Blockscout API: endpoint URL input + "Save" button (validated against
|
||||
@@ -2071,7 +2076,10 @@ view would leave a wallet one click from deletion.
|
||||
no window and takes no nonce, and the site can send it again once the pending
|
||||
one is answered. The window is centred on the browser window the user was last
|
||||
in; if that was another approval window, or the browser refuses the centred
|
||||
position, the browser picks the position.
|
||||
position, the browser picks the position. The network shown is the one the
|
||||
transaction was populated on, and a site cannot switch it without the user:
|
||||
its `wallet_switchEthereumChain` request changes the network only when the
|
||||
user approves it on **NetworkApproval**.
|
||||
- **Elements**:
|
||||
- "Transaction Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
@@ -2162,6 +2170,39 @@ view would leave a wallet one click from deletion.
|
||||
- Popup window closed without answering → the request is rejected with
|
||||
EIP-1193 code 4001
|
||||
|
||||
#### NetworkApproval (`approve-network`)
|
||||
|
||||
- **When**: A connected website asks to switch the network with
|
||||
`wallet_switchEthereumChain`, naming a supported network other than the active
|
||||
one. Only the user switches the network: until the user approves the request
|
||||
here, it changes nothing — not the network, the RPC and Blockscout endpoints,
|
||||
the balances or the cached token data — and no page is sent `chainChanged`.
|
||||
Opened the same way as TxApproval, in a separate popup window. Only one exists
|
||||
per site at a time: a further switch request from a site whose switch request
|
||||
is still unanswered is refused with EIP-1193 code `-32002` and opens no
|
||||
window. A request naming the network already active is answered at once and
|
||||
opens nothing; one naming an unsupported chain is refused with code `4902`,
|
||||
and one from a site that is not connected with code `4100`.
|
||||
`wallet_addEthereumChain` never switches the network.
|
||||
- **Elements**:
|
||||
- "Network Switch Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
blocklist)
|
||||
- Site origin (bold, scheme and port included) + "wants to switch the
|
||||
wallet's network."
|
||||
- Current network: its name
|
||||
- Requested network: its name
|
||||
- A line saying that switching changes the network for the whole wallet and
|
||||
for every site
|
||||
- "Switch" / "Reject" buttons
|
||||
- **Transitions**:
|
||||
- "Switch" → closes popup; the background switches the network as
|
||||
**Settings** does, sends `chainChanged` to every open tab, and answers the
|
||||
site with success
|
||||
- "Reject" → closes popup; the site is answered with EIP-1193 code 4001 and
|
||||
nothing changes
|
||||
- Popup window closed without answering → the same as "Reject"
|
||||
|
||||
#### StateRecovery (`state-recovery`)
|
||||
|
||||
- **When**: the stored profile fails `assertStateUsable()`. At open, that is
|
||||
@@ -2456,6 +2497,8 @@ logged.
|
||||
- Sign transactions requested by connected sites (`eth_sendTransaction`)
|
||||
- Sign messages (`personal_sign`, `eth_sign`)
|
||||
- Sign typed data (`eth_signTypedData_v4`, `eth_signTypedData`)
|
||||
- Switch network at a connected site's request, once the user approves it
|
||||
(`wallet_switchEthereumChain`)
|
||||
- Human-readable transaction decoding (ERC-20, Uniswap Universal Router)
|
||||
- ETH/USD and token/USD price display
|
||||
- Configurable RPC endpoint and Blockscout API
|
||||
|
||||
@@ -44,6 +44,19 @@ then continue tagging as milestones land.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-07: A site can no longer switch the wallet's network by itself
|
||||
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)). A connected site's
|
||||
`wallet_switchEthereumChain` request for the other supported network opens a
|
||||
prompt in its own window, through the same approval machinery as the
|
||||
transaction and signature prompts, naming the site, the current network and
|
||||
the requested one. The network, its endpoints, the balances and the caches
|
||||
change, and `chainChanged` is sent, only when the user approves it; rejecting
|
||||
or closing the prompt answers 4001. One such prompt per site at a time. The
|
||||
approval window no longer shows the connection prompt while it waits for the
|
||||
background to describe the approval, because that prompt's "Allow" answers on
|
||||
the same port as the new one. `tests/chainSwitchGate.test.js` and both browser
|
||||
suites drive the prompt.
|
||||
|
||||
- 2026-10-07: Two holes in what `tests/persistedFieldContract.test.js` checks
|
||||
are closed ([#379](https://git.eeqj.de/sneak/AutistMask/issues/379)). The
|
||||
check that every swept field is driven both truthy and falsy counts only
|
||||
|
||||
+72
-19
@@ -137,11 +137,12 @@ function releaseTxApprovalSlotFor(approvalId) {
|
||||
}
|
||||
}
|
||||
|
||||
// One site-connection approval and one sign approval per site at a time: a
|
||||
// page that asks again before the user has answered is refused with the code
|
||||
// above instead of opening another window, so it cannot bury the user in
|
||||
// prompts. The pending approval itself holds the place, so a caller must test
|
||||
// this and raise its approval with nothing awaited in between.
|
||||
// One site-connection approval, one sign approval and one network-switch
|
||||
// approval per site at a time: a page that asks again before the user has
|
||||
// answered is refused with the code above instead of opening another window,
|
||||
// so it cannot bury the user in prompts. The pending approval itself holds the
|
||||
// place, so a caller must test this and raise its approval with nothing awaited
|
||||
// in between.
|
||||
function findPendingApproval(origin, type) {
|
||||
return Object.values(pendingApprovals).find(
|
||||
(approval) => approval.origin === origin && approval.type === type,
|
||||
@@ -348,8 +349,9 @@ function settleApproval(id, result, options) {
|
||||
|
||||
// What a pending approval resolves to when it is given up on rather than
|
||||
// answered: the window was closed, or could not be opened at all. A tx or sign
|
||||
// approval answers the requesting page in EIP-1193 shape; a site-connection
|
||||
// approval answers the connection handler in its own.
|
||||
// approval answers the requesting page in EIP-1193 shape; a site-connection or
|
||||
// network-switch approval answers its handler in the shape the popup's
|
||||
// decision has, as a refusal.
|
||||
function abandonedResult(approval, code, message) {
|
||||
if (approval.type === "tx" || approval.type === "sign") {
|
||||
return { error: { code, message } };
|
||||
@@ -588,6 +590,26 @@ function requestSignApproval(origin, signParams, approvedFrom) {
|
||||
});
|
||||
}
|
||||
|
||||
// Open a network-switch approval popup and return a promise that resolves with
|
||||
// { approved }. Opened in a window, as tx and sign approvals are, because a
|
||||
// site's request is not a user gesture. The popup answers on the approval port,
|
||||
// as a site-connection approval does.
|
||||
function requestNetworkApproval(origin, currentNetworkId, requestedNetworkId) {
|
||||
return new Promise((resolve) => {
|
||||
const id = crypto.randomUUID();
|
||||
pendingApprovals[id] = {
|
||||
id,
|
||||
origin,
|
||||
currentNetworkId,
|
||||
requestedNetworkId,
|
||||
resolve,
|
||||
type: "network",
|
||||
};
|
||||
|
||||
openApprovalWindow(id);
|
||||
});
|
||||
}
|
||||
|
||||
// Anything only the extension's own pages may say. A content script speaks
|
||||
// with the page's URL, so this is what separates the popup from the site the
|
||||
// popup is being asked about.
|
||||
@@ -597,8 +619,8 @@ function isExtensionSender(sender) {
|
||||
}
|
||||
|
||||
// The approval popup's port: it carries the user's decision on a
|
||||
// site-connection approval, and its disconnect is how that approval learns the
|
||||
// popup closed without one.
|
||||
// site-connection or network-switch approval, and its disconnect is how that
|
||||
// approval learns the popup closed without one.
|
||||
//
|
||||
// The decision travels this port rather than a one-off runtime.sendMessage()
|
||||
// for exactly one reason: the port is also what the popup's window.close()
|
||||
@@ -806,6 +828,10 @@ async function handleRpc(method, params, origin) {
|
||||
// tab is served from, so a page the user never connected to must
|
||||
// not be able to do it. Ungated, any page could clear the
|
||||
// [TESTNET] banner under a user who believed they were on Sepolia.
|
||||
//
|
||||
// A connected site does not switch it either: only the user does,
|
||||
// by approving the request on the prompt below
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||
const s = await getState();
|
||||
const activeAddress = activeAddressOf(s);
|
||||
const allowed = s.allowedSites[activeAddress] || [];
|
||||
@@ -827,6 +853,27 @@ async function handleRpc(method, params, origin) {
|
||||
}
|
||||
if (SUPPORTED_CHAIN_IDS.has(chainId)) {
|
||||
const target = networkByChainId(chainId);
|
||||
if (findPendingApproval(origin, "network")) {
|
||||
return {
|
||||
error: {
|
||||
code: APPROVAL_PENDING_CODE,
|
||||
message: APPROVAL_PENDING_MESSAGE,
|
||||
},
|
||||
};
|
||||
}
|
||||
const decision = await requestNetworkApproval(
|
||||
origin,
|
||||
s.networkId,
|
||||
target.id,
|
||||
);
|
||||
if (!decision.approved) {
|
||||
return {
|
||||
error: {
|
||||
code: APPROVAL_REJECTED_CODE,
|
||||
message: APPROVAL_REJECTED_MESSAGE,
|
||||
},
|
||||
};
|
||||
}
|
||||
// Read-modify-write against storage. The old path went through
|
||||
// onChainSwitch(), which mutates the singleton and then persists
|
||||
// every field of it — on an unloaded worker that wrote empty
|
||||
@@ -1345,20 +1392,21 @@ startBackgroundJobs();
|
||||
// which then fails retryably settles instead of waiting in a window that no
|
||||
// longer exists.
|
||||
//
|
||||
// A site-connection approval whose popup connected its port is not decided
|
||||
// here. That popup approves and closes in the same breath, and this event
|
||||
// races the decision on a channel of its own — the same race the port exists
|
||||
// to end. Its port disconnect says the same thing this event does, in an order
|
||||
// that is defined, so the disconnect is left to say it. The window closing
|
||||
// before any port connected is the one case with nothing else to speak for it,
|
||||
// and is rejected here so the dApp is not left waiting on a window that is
|
||||
// gone.
|
||||
// A site-connection or network-switch approval whose popup connected its port
|
||||
// is not decided here. That popup approves and closes in the same breath, and
|
||||
// this event races the decision on a channel of its own — the same race the
|
||||
// port exists to end. Its port disconnect says the same thing this event does,
|
||||
// in an order that is defined, so the disconnect is left to say it. The window
|
||||
// closing before any port connected is the one case with nothing else to speak
|
||||
// for it, and is rejected here so the dApp is not left waiting on a window that
|
||||
// is gone.
|
||||
if (windowsNs && windowsNs.onRemoved) {
|
||||
windowsNs.onRemoved.addListener((windowId) => {
|
||||
for (const [id, approval] of Object.entries(pendingApprovals)) {
|
||||
if (approval.windowId !== windowId) continue;
|
||||
const isSite = approval.type !== "tx" && approval.type !== "sign";
|
||||
if (isSite && approval.portConnected) continue;
|
||||
const decidedOnPort =
|
||||
approval.type !== "tx" && approval.type !== "sign";
|
||||
if (decidedOnPort && approval.portConnected) continue;
|
||||
const rejection = abandonedResult(
|
||||
approval,
|
||||
APPROVAL_REJECTED_CODE,
|
||||
@@ -1446,6 +1494,11 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
resp.signParams = approval.signParams;
|
||||
resp.approvedFrom = approval.approvedFrom;
|
||||
}
|
||||
if (approval.type === "network") {
|
||||
resp.type = "network";
|
||||
resp.currentNetworkId = approval.currentNetworkId;
|
||||
resp.requestedNetworkId = approval.requestedNetworkId;
|
||||
}
|
||||
// Flag if the requesting domain is on the phishing blocklist.
|
||||
resp.isPhishingDomain = isPhishingDomain(
|
||||
extractHostname(approval.origin),
|
||||
|
||||
@@ -1741,6 +1741,54 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ============ NETWORK SWITCH APPROVAL ============ -->
|
||||
<div id="view-approve-network" class="view hidden">
|
||||
<h2 class="font-bold mb-2">Network Switch Request</h2>
|
||||
<div
|
||||
id="approve-network-phishing-warning"
|
||||
class="mb-3 p-2 text-xs font-bold hidden bg-red-100 text-red-800 border-2 border-red-600 rounded-md"
|
||||
>
|
||||
⚠️ PHISHING WARNING: This site is on a known phishing
|
||||
blocklist. Proceed with extreme caution.
|
||||
</div>
|
||||
<p class="mb-2">
|
||||
<span id="approve-network-origin" class="font-bold"></span>
|
||||
wants to switch the wallet's network.
|
||||
</p>
|
||||
<div class="mb-3">
|
||||
<div class="text-xs text-muted mb-1">Current network</div>
|
||||
<div
|
||||
id="approve-network-current"
|
||||
class="text-xs font-bold"
|
||||
></div>
|
||||
</div>
|
||||
<div class="mb-3">
|
||||
<div class="text-xs text-muted mb-1">Requested network</div>
|
||||
<div
|
||||
id="approve-network-requested"
|
||||
class="text-xs font-bold"
|
||||
></div>
|
||||
</div>
|
||||
<p class="mb-3 text-xs">
|
||||
Switching changes the network for the whole wallet and for
|
||||
every site, not only for this one.
|
||||
</p>
|
||||
<div class="flex justify-between">
|
||||
<button
|
||||
id="btn-approve-network"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Switch
|
||||
</button>
|
||||
<button
|
||||
id="btn-reject-network"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Reject
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ============ STATE RECOVERY ============ -->
|
||||
<!--
|
||||
Shown when the stored profile cannot be read at all. Every
|
||||
|
||||
+2
-2
@@ -238,9 +238,9 @@ async function init() {
|
||||
// rejection rather than an uncaught error — measured as still failing
|
||||
// the run on both harnesses (Playwright `pageerror`, and the Firefox
|
||||
// driver's console-service drain), so nothing is lost by leaving it
|
||||
// on that path.
|
||||
// on that path. show() puts the approval's own screen up once the
|
||||
// background has described it.
|
||||
approval.show(approvalId);
|
||||
showView("approve-site");
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
+46
-11
@@ -14,6 +14,7 @@ const {
|
||||
} = require("./helpers");
|
||||
const { state, saveState } = require("../../shared/state");
|
||||
const {
|
||||
networkById,
|
||||
networkByChainId,
|
||||
nativeCurrencyByChainId,
|
||||
} = require("../../shared/networks");
|
||||
@@ -752,9 +753,29 @@ function showSignApproval(details) {
|
||||
);
|
||||
}
|
||||
|
||||
function showNetworkApproval(details) {
|
||||
showPhishingWarning(
|
||||
"approve-network-phishing-warning",
|
||||
details.isPhishingDomain,
|
||||
);
|
||||
$("approve-network-origin").textContent = details.origin;
|
||||
$("approve-network-current").textContent = networkById(
|
||||
details.currentNetworkId,
|
||||
).name;
|
||||
$("approve-network-requested").textContent = networkById(
|
||||
details.requestedNetworkId,
|
||||
).name;
|
||||
showView("approve-network");
|
||||
}
|
||||
|
||||
// Awaited by nobody: the popup entry point calls this and moves on. It
|
||||
// therefore has to absorb its own failure, and a background that cannot
|
||||
// describe the approval is the same outcome as an approval that is gone.
|
||||
//
|
||||
// Nothing is on screen until the background has described the approval, so
|
||||
// the screen shown is always the one for the approval this window answers:
|
||||
// the connection prompt's "Allow" and the network switch prompt's "Switch"
|
||||
// answer on the same port, and either would approve the other.
|
||||
async function show(id) {
|
||||
approvalId = id;
|
||||
approvalPort = runtimeApi().connect({ name: "approval:" + id });
|
||||
@@ -778,6 +799,10 @@ async function show(id) {
|
||||
showSignApproval(details);
|
||||
return;
|
||||
}
|
||||
if (details.type === "network") {
|
||||
showNetworkApproval(details);
|
||||
return;
|
||||
}
|
||||
// Site connection approval
|
||||
showPhishingWarning(
|
||||
"approve-site-phishing-warning",
|
||||
@@ -787,6 +812,7 @@ async function show(id) {
|
||||
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
|
||||
attachCopyHandlers("view-approve-site");
|
||||
$("approve-remember").checked = state.rememberSiteChoice;
|
||||
showView("approve-site");
|
||||
}
|
||||
|
||||
let approvalId = null;
|
||||
@@ -866,20 +892,21 @@ function clearSignPassword() {
|
||||
hideError("approve-sign-error");
|
||||
}
|
||||
|
||||
// Answer a site-connection approval and close. The decision goes out on the
|
||||
// approval port — see approvalPort above for why — and carries no approval id,
|
||||
// because the port name already names the approval the background will settle.
|
||||
// The post is guarded because a throw must not cost the close: posting on a
|
||||
// port whose background worker has been torn down throws, and the approval it
|
||||
// would have settled died with that worker, so the only thing left to do is
|
||||
// what the user asked for — go away.
|
||||
function decideSite(approved) {
|
||||
// Answer a site-connection or network-switch approval and close. The decision
|
||||
// goes out on the approval port — see approvalPort above for why — and carries
|
||||
// no approval id, because the port name already names the approval the
|
||||
// background will settle. `remember` means something only for a site
|
||||
// connection. The post is guarded because a throw must not cost the close:
|
||||
// posting on a port whose background worker has been torn down throws, and the
|
||||
// approval it would have settled died with that worker, so the only thing left
|
||||
// to do is what the user asked for — go away.
|
||||
function decide(approved, remember) {
|
||||
if (approvalPort) {
|
||||
try {
|
||||
approvalPort.postMessage({
|
||||
type: "AUTISTMASK_APPROVAL_DECISION",
|
||||
approved,
|
||||
remember: $("approve-remember").checked,
|
||||
remember,
|
||||
});
|
||||
} catch {
|
||||
// Nothing to report it to; the window closes either way.
|
||||
@@ -898,11 +925,19 @@ function init(_ctx) {
|
||||
});
|
||||
|
||||
$("btn-approve").addEventListener("click", () => {
|
||||
decideSite(true);
|
||||
decide(true, $("approve-remember").checked);
|
||||
});
|
||||
|
||||
$("btn-reject").addEventListener("click", () => {
|
||||
decideSite(false);
|
||||
decide(false, $("approve-remember").checked);
|
||||
});
|
||||
|
||||
$("btn-approve-network").addEventListener("click", () => {
|
||||
decide(true, false);
|
||||
});
|
||||
|
||||
$("btn-reject-network").addEventListener("click", () => {
|
||||
decide(false, false);
|
||||
});
|
||||
|
||||
$("btn-approve-tx").addEventListener("click", async () => {
|
||||
|
||||
@@ -51,6 +51,7 @@ const VIEWS = [
|
||||
"approve-site",
|
||||
"approve-tx",
|
||||
"approve-sign",
|
||||
"approve-network",
|
||||
"export-privkey",
|
||||
"show-phrase",
|
||||
// Shown by src/popup/views/stateRecovery.js when the stored profile
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
// The connection, transaction and signature prompts name the site by its full
|
||||
// origin, scheme and port included, not by its bare hostname
|
||||
// The connection, transaction, signature and network switch prompts name the
|
||||
// site by its full origin, scheme and port included, not by its bare hostname
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http,
|
||||
// or on another port, of a host the user trusts over https must not raise a
|
||||
// prompt that reads as that trusted site.
|
||||
@@ -104,6 +104,7 @@ beforeEach(() => {
|
||||
test("the connection prompt shows the origin", async () => {
|
||||
await openApproval({});
|
||||
expect(node("approve-origin").textContent).toBe(ORIGIN);
|
||||
expect(node("view-approve-site").classList.contains("hidden")).toBe(false);
|
||||
});
|
||||
|
||||
test("the transaction prompt shows the origin", async () => {
|
||||
@@ -138,3 +139,24 @@ test("the signature prompt shows the origin", async () => {
|
||||
});
|
||||
expect(node("approve-sign-origin").textContent).toBe(ORIGIN);
|
||||
});
|
||||
|
||||
test("the network switch prompt shows the origin and both networks", async () => {
|
||||
await openApproval({
|
||||
type: "network",
|
||||
currentNetworkId: "mainnet",
|
||||
requestedNetworkId: "sepolia",
|
||||
});
|
||||
expect(node("approve-network-origin").textContent).toBe(ORIGIN);
|
||||
expect(node("approve-network-current").textContent).toBe(
|
||||
"Ethereum Mainnet",
|
||||
);
|
||||
expect(node("approve-network-requested").textContent).toBe(
|
||||
"Sepolia Testnet",
|
||||
);
|
||||
// Its own screen, and not the connection prompt, whose "Allow" answers
|
||||
// on the same port.
|
||||
expect(node("view-approve-network").classList.contains("hidden")).toBe(
|
||||
false,
|
||||
);
|
||||
expect(node("view-approve-site").classList.contains("hidden")).toBe(true);
|
||||
});
|
||||
|
||||
@@ -25,6 +25,7 @@
|
||||
|
||||
const { Wallet } = require("ethers");
|
||||
const { networkById } = require("../src/shared/networks");
|
||||
const { applyChainSwitchFields } = require("../src/shared/chainSwitchFields");
|
||||
const { makeStorageStub } = require("./support/storageStub");
|
||||
|
||||
const SIGNER_KEY =
|
||||
@@ -240,8 +241,8 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
||||
// The artifact is verified against the chain read at the top of the
|
||||
// attempt. Whatever endpoint it is then broadcast to has to be that same
|
||||
// chain's — otherwise the wallet checks a transaction against Sepolia and
|
||||
// sends it to a mainnet node. A connected site can switch the chain at any
|
||||
// moment, including this one.
|
||||
// sends it to a mainnet node. The user can switch the network in Settings
|
||||
// at any moment, including this one.
|
||||
test("the artifact is broadcast to the endpoint of the chain it was verified against", async () => {
|
||||
const bg = loadWorker("sepolia");
|
||||
|
||||
@@ -264,9 +265,9 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
||||
populated(Number(SEPOLIA.networkVersion)),
|
||||
);
|
||||
|
||||
// A connected site switches the chain while the attempt is running,
|
||||
// and the switch is committed to storage in full before the attempt
|
||||
// goes any further.
|
||||
// The user switches the network in Settings while the attempt is
|
||||
// running: the popup writes the switched record to storage in full
|
||||
// before the attempt goes any further.
|
||||
//
|
||||
// It is fired from inside the attempt's SECOND state read, because
|
||||
// that is where the window used to be: the chain id was captured at
|
||||
@@ -277,18 +278,18 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
||||
// this to fire on, and the switch below runs after the attempt is
|
||||
// done instead — which is the point.
|
||||
let reads = 0;
|
||||
let switched = null;
|
||||
const doSwitch = async () => {
|
||||
switched = bg.rpc("wallet_switchEthereumChain", [
|
||||
{ chainId: MAINNET.chainId },
|
||||
]);
|
||||
await settle();
|
||||
let switched = false;
|
||||
const doSwitch = () => {
|
||||
const record = bg.persisted();
|
||||
applyChainSwitchFields(record, MAINNET.id);
|
||||
global.chrome.storage.write("autistmask", record);
|
||||
switched = true;
|
||||
};
|
||||
bg.setGetHook(async () => {
|
||||
reads++;
|
||||
if (reads !== 2) return;
|
||||
bg.setGetHook(null);
|
||||
await doSwitch();
|
||||
doSwitch();
|
||||
});
|
||||
|
||||
const attempt = bg.send(
|
||||
@@ -303,8 +304,7 @@ describe("a chain switch under a transaction already committed to a chain", () =
|
||||
await settle();
|
||||
|
||||
bg.setGetHook(null);
|
||||
if (!switched) await doSwitch();
|
||||
expect(switched.result()).toEqual({ result: null });
|
||||
if (!switched) doSwitch();
|
||||
expect(bg.persisted().networkId).toBe("mainnet");
|
||||
await settle();
|
||||
|
||||
|
||||
+208
-38
@@ -1,16 +1,22 @@
|
||||
// Who may move the active chain.
|
||||
// Who may move the active chain, and when.
|
||||
//
|
||||
// wallet_switchEthereumChain used to be answered for any origin at all, with
|
||||
// no connection check and no prompt, so a page the user had never connected
|
||||
// to could clear the [TESTNET] banner under someone who believed they were
|
||||
// on Sepolia (https://git.eeqj.de/sneak/AutistMask/issues/308). The refusal
|
||||
// is asserted as a refusal to ACT — the state unmoved and no chainChanged
|
||||
// broadcast — because an error code alone would not distinguish a gate from
|
||||
// a switch that happened and then reported a failure.
|
||||
// on Sepolia (https://git.eeqj.de/sneak/AutistMask/issues/308). Gated on the
|
||||
// connection, a connected site could still move the wallet between mainnet and
|
||||
// Sepolia without asking. Only the user switches the network: a connected
|
||||
// site's request opens a prompt, and nothing changes unless the user approves
|
||||
// it there (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||
//
|
||||
// The endpoint half of that issue lives in tests/networkEndpoints.test.js,
|
||||
// which covers the popup's chain switch; this file covers the background's,
|
||||
// which goes through storage rather than the shared state singleton.
|
||||
// Every refusal is asserted as a refusal to ACT — the stored record unmoved
|
||||
// and no chainChanged broadcast — because an error code alone would not
|
||||
// distinguish a refusal from a switch that happened and then reported a
|
||||
// failure.
|
||||
//
|
||||
// The endpoint half of #308 lives in tests/networkEndpoints.test.js, which
|
||||
// covers the popup's chain switch; this file covers the background's, which
|
||||
// goes through storage rather than the shared state singleton.
|
||||
|
||||
const { networkById } = require("../src/shared/networks");
|
||||
const { makeStorageStub } = require("./support/storageStub");
|
||||
@@ -21,18 +27,23 @@ const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
const CONNECTED_ORIGIN = "https://dapp.example";
|
||||
const STRANGER_ORIGIN = "https://stranger.example";
|
||||
|
||||
const EXT_URL = "chrome-extension://autistmask/";
|
||||
|
||||
const MAINNET = networkById("mainnet");
|
||||
const SEPOLIA = networkById("sepolia");
|
||||
|
||||
// The user's own node, so a switch that happens is visible as the loss of it.
|
||||
const CUSTOM_RPC = "http://127.0.0.1:8545";
|
||||
|
||||
// A balance a switch would clear, so a switch that happens is visible here too.
|
||||
function walletFixture() {
|
||||
return [
|
||||
{
|
||||
name: "Wallet 1",
|
||||
type: "hd",
|
||||
addresses: [{ address: ADDRESS, balance: "0", tokenBalances: [] }],
|
||||
addresses: [
|
||||
{ address: ADDRESS, balance: "1.5", tokenBalances: [] },
|
||||
],
|
||||
},
|
||||
];
|
||||
}
|
||||
@@ -47,10 +58,6 @@ afterEach(() => {
|
||||
delete global.chrome;
|
||||
});
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// The gate: which origins the background will switch the chain for.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
// Load the background worker against stubbed browser APIs, with the real
|
||||
// chain-switch and persistence modules behind it, and return the handles to
|
||||
// drive it.
|
||||
@@ -91,30 +98,46 @@ function loadBackground() {
|
||||
const storage = makeStorageStub({ autistmask: persisted });
|
||||
|
||||
let messageListener = null;
|
||||
let connectListener = null;
|
||||
let windowRemovedListener = null;
|
||||
// The URL of every approval window the background opened. The approval id
|
||||
// is in it, and that is how the popup learns which approval it answers.
|
||||
const opened = [];
|
||||
// Every message the background pushed at a content script. chainChanged
|
||||
// is what tells a page the wallet moved, so an ungated switch is visible
|
||||
// here as well as in the state.
|
||||
// is what tells a page the wallet moved, so a switch is visible here as
|
||||
// well as in the state.
|
||||
const toTabs = [];
|
||||
|
||||
global.chrome = {
|
||||
storage,
|
||||
runtime: {
|
||||
getURL: (path) => "chrome-extension://autistmask/" + path,
|
||||
getURL: (path) => EXT_URL + path,
|
||||
onMessage: {
|
||||
addListener: (fn) => {
|
||||
messageListener = fn;
|
||||
},
|
||||
},
|
||||
onConnect: { addListener: () => {} },
|
||||
onConnect: {
|
||||
addListener: (fn) => {
|
||||
connectListener = fn;
|
||||
},
|
||||
},
|
||||
lastError: null,
|
||||
},
|
||||
windows: {
|
||||
getLastFocused: (cb) => cb(null),
|
||||
create: (options, cb) => cb({ id: 1 }),
|
||||
create: (options, cb) => {
|
||||
opened.push(options.url);
|
||||
cb({ id: opened.length });
|
||||
},
|
||||
remove: (id, cb) => {
|
||||
if (cb) cb();
|
||||
},
|
||||
onRemoved: { addListener: () => {} },
|
||||
onRemoved: {
|
||||
addListener: (fn) => {
|
||||
windowRemovedListener = fn;
|
||||
},
|
||||
},
|
||||
},
|
||||
tabs: {
|
||||
query: (queryInfo, cb) => cb([{ id: 1 }]),
|
||||
@@ -128,6 +151,8 @@ function loadBackground() {
|
||||
|
||||
require("../src/background/index");
|
||||
|
||||
// A page's request. Its answer is read with result(), which is null for as
|
||||
// long as the request is waiting on the user.
|
||||
async function switchChain(chainId, origin) {
|
||||
let result = null;
|
||||
messageListener(
|
||||
@@ -142,56 +167,147 @@ function loadBackground() {
|
||||
},
|
||||
);
|
||||
await settle();
|
||||
return result;
|
||||
return { result: () => result };
|
||||
}
|
||||
|
||||
function promptId() {
|
||||
return new URL(opened[opened.length - 1]).searchParams.get("approval");
|
||||
}
|
||||
|
||||
// What the popup is told to show for the prompt.
|
||||
function describePrompt() {
|
||||
let reply = null;
|
||||
messageListener(
|
||||
{ type: "AUTISTMASK_GET_APPROVAL", id: promptId() },
|
||||
{ url: EXT_URL + "src/popup/index.html" },
|
||||
(r) => {
|
||||
reply = r;
|
||||
},
|
||||
);
|
||||
return reply;
|
||||
}
|
||||
|
||||
// The user's answer, as the popup sends it: on the port named for the
|
||||
// approval, from the extension's own page, and then the window closes.
|
||||
async function answerPrompt(approved) {
|
||||
const onMessage = [];
|
||||
const onDisconnect = [];
|
||||
const port = {
|
||||
name: "approval:" + promptId(),
|
||||
sender: { url: EXT_URL + "src/popup/index.html" },
|
||||
onMessage: { addListener: (fn) => onMessage.push(fn) },
|
||||
onDisconnect: { addListener: (fn) => onDisconnect.push(fn) },
|
||||
};
|
||||
connectListener(port);
|
||||
for (const fn of onMessage) {
|
||||
fn(
|
||||
{
|
||||
type: "AUTISTMASK_APPROVAL_DECISION",
|
||||
approved,
|
||||
remember: false,
|
||||
},
|
||||
port,
|
||||
);
|
||||
}
|
||||
for (const fn of onDisconnect) fn(port);
|
||||
await settle();
|
||||
}
|
||||
|
||||
// The user closes the prompt window without answering it.
|
||||
async function closePrompt() {
|
||||
windowRemovedListener(opened.length);
|
||||
await settle();
|
||||
}
|
||||
|
||||
return {
|
||||
switchChain,
|
||||
describePrompt,
|
||||
answerPrompt,
|
||||
closePrompt,
|
||||
opened,
|
||||
walletState: () => storage.read("autistmask"),
|
||||
chainChangedEvents: () =>
|
||||
toTabs.filter((m) => m.eventName === "chainChanged"),
|
||||
};
|
||||
}
|
||||
|
||||
const USER_REJECTED = { code: 4001, message: "User rejected the request." };
|
||||
|
||||
describe("wallet_switchEthereumChain is gated on the connection", () => {
|
||||
test("an origin the wallet was never connected to is refused with 4100", async () => {
|
||||
const bg = loadBackground();
|
||||
const before = bg.walletState();
|
||||
|
||||
const result = await bg.switchChain(SEPOLIA.chainId, STRANGER_ORIGIN);
|
||||
const request = await bg.switchChain(SEPOLIA.chainId, STRANGER_ORIGIN);
|
||||
|
||||
expect(result.error).toEqual({ code: 4100, message: "Unauthorized" });
|
||||
expect(result.result).toBeUndefined();
|
||||
expect(request.result().error).toEqual({
|
||||
code: 4100,
|
||||
message: "Unauthorized",
|
||||
});
|
||||
expect(request.result().result).toBeUndefined();
|
||||
// The refusal has to be a refusal to ACT, not just an error string:
|
||||
// the wallet is still on mainnet, still on the user's own node, and
|
||||
// no page was told the chain moved.
|
||||
expect(bg.walletState().networkId).toBe("mainnet");
|
||||
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
|
||||
// no page was told the chain moved. Nor was the user asked.
|
||||
expect(bg.walletState()).toEqual(before);
|
||||
expect(bg.chainChangedEvents()).toEqual([]);
|
||||
expect(bg.opened).toEqual([]);
|
||||
});
|
||||
|
||||
test("an unconnected origin is refused even for the chain already active", async () => {
|
||||
const bg = loadBackground();
|
||||
|
||||
const result = await bg.switchChain(MAINNET.chainId, STRANGER_ORIGIN);
|
||||
const request = await bg.switchChain(MAINNET.chainId, STRANGER_ORIGIN);
|
||||
|
||||
expect(result.error).toEqual({ code: 4100, message: "Unauthorized" });
|
||||
expect(request.result().error).toEqual({
|
||||
code: 4100,
|
||||
message: "Unauthorized",
|
||||
});
|
||||
});
|
||||
|
||||
test("an unconnected origin is refused before the unsupported-chain answer", async () => {
|
||||
const bg = loadBackground();
|
||||
|
||||
const result = await bg.switchChain("0x89", STRANGER_ORIGIN);
|
||||
const request = await bg.switchChain("0x89", STRANGER_ORIGIN);
|
||||
|
||||
expect(result.error.code).toBe(4100);
|
||||
expect(request.result().error.code).toBe(4100);
|
||||
});
|
||||
});
|
||||
|
||||
describe("only the user switches the network", () => {
|
||||
test("a connected site's request changes nothing while the prompt is open", async () => {
|
||||
const bg = loadBackground();
|
||||
const before = bg.walletState();
|
||||
|
||||
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
|
||||
// Waiting on the user, with one prompt on screen naming the site and
|
||||
// both networks.
|
||||
expect(request.result()).toBeNull();
|
||||
expect(bg.opened).toHaveLength(1);
|
||||
expect(bg.describePrompt()).toMatchObject({
|
||||
origin: CONNECTED_ORIGIN,
|
||||
type: "network",
|
||||
currentNetworkId: "mainnet",
|
||||
requestedNetworkId: "sepolia",
|
||||
});
|
||||
|
||||
// The network, the endpoints and the balances are as they were, and
|
||||
// no page was told otherwise.
|
||||
expect(bg.walletState()).toEqual(before);
|
||||
expect(bg.chainChangedEvents()).toEqual([]);
|
||||
});
|
||||
|
||||
test("a connected origin switches the chain", async () => {
|
||||
test("approving the prompt switches the network", async () => {
|
||||
const bg = loadBackground();
|
||||
|
||||
const result = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
await bg.answerPrompt(true);
|
||||
|
||||
expect(result).toEqual({ result: null });
|
||||
expect(bg.walletState().networkId).toBe("sepolia");
|
||||
expect(request.result()).toEqual({ result: null });
|
||||
const after = bg.walletState();
|
||||
expect(after.networkId).toBe("sepolia");
|
||||
expect(after.rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
|
||||
expect(after.wallets[0].addresses[0].balance).toBe("0");
|
||||
expect(bg.chainChangedEvents()).toEqual([
|
||||
{
|
||||
type: "AUTISTMASK_EVENT",
|
||||
@@ -201,22 +317,76 @@ describe("wallet_switchEthereumChain is gated on the connection", () => {
|
||||
]);
|
||||
});
|
||||
|
||||
test("a connected origin asking for an unsupported chain still gets 4902", async () => {
|
||||
test("rejecting the prompt changes nothing and answers 4001", async () => {
|
||||
const bg = loadBackground();
|
||||
const before = bg.walletState();
|
||||
|
||||
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
await bg.answerPrompt(false);
|
||||
|
||||
expect(request.result()).toEqual({ error: USER_REJECTED });
|
||||
expect(bg.walletState()).toEqual(before);
|
||||
expect(bg.chainChangedEvents()).toEqual([]);
|
||||
});
|
||||
|
||||
test("closing the prompt without answering changes nothing and answers 4001", async () => {
|
||||
const bg = loadBackground();
|
||||
const before = bg.walletState();
|
||||
|
||||
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
await bg.closePrompt();
|
||||
|
||||
expect(request.result()).toEqual({ error: USER_REJECTED });
|
||||
expect(bg.walletState()).toEqual(before);
|
||||
expect(bg.chainChangedEvents()).toEqual([]);
|
||||
});
|
||||
|
||||
test("a request for the chain already active opens no prompt", async () => {
|
||||
const bg = loadBackground();
|
||||
const before = bg.walletState();
|
||||
|
||||
const request = await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
|
||||
|
||||
expect(request.result()).toEqual({ result: null });
|
||||
expect(bg.opened).toEqual([]);
|
||||
expect(bg.walletState()).toEqual(before);
|
||||
expect(bg.chainChangedEvents()).toEqual([]);
|
||||
});
|
||||
|
||||
test("a second request while the prompt is open is refused with -32002", async () => {
|
||||
const bg = loadBackground();
|
||||
|
||||
const result = await bg.switchChain("0x89", CONNECTED_ORIGIN);
|
||||
const first = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
const second = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
|
||||
expect(result.error.code).toBe(4902);
|
||||
expect(second.result().error.code).toBe(-32002);
|
||||
expect(bg.opened).toHaveLength(1);
|
||||
|
||||
// The first prompt still decides.
|
||||
await bg.answerPrompt(true);
|
||||
expect(first.result()).toEqual({ result: null });
|
||||
expect(bg.walletState().networkId).toBe("sepolia");
|
||||
});
|
||||
|
||||
test("a request for an unsupported chain still gets 4902 and no prompt", async () => {
|
||||
const bg = loadBackground();
|
||||
|
||||
const request = await bg.switchChain("0x89", CONNECTED_ORIGIN);
|
||||
|
||||
expect(request.result().error.code).toBe(4902);
|
||||
expect(bg.opened).toEqual([]);
|
||||
expect(bg.walletState().networkId).toBe("mainnet");
|
||||
});
|
||||
|
||||
test("a switch by a connected origin keeps the user's endpoint", async () => {
|
||||
test("an approved switch keeps the user's endpoint", async () => {
|
||||
const bg = loadBackground();
|
||||
|
||||
await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
|
||||
await bg.answerPrompt(true);
|
||||
expect(bg.walletState().rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
|
||||
|
||||
await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
|
||||
await bg.answerPrompt(true);
|
||||
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -14,6 +14,10 @@
|
||||
// itself: the handler has to do it. tests/chainSwitchGate.test.js mocks the
|
||||
// state module wholesale and tests/networkEndpoints.test.js always loads
|
||||
// first, so neither can see this.
|
||||
//
|
||||
// A site's switch happens only once the user approves it on a prompt
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/408), so every switch here is
|
||||
// approved the way the popup approves one.
|
||||
|
||||
const { networkById } = require("../src/shared/networks");
|
||||
const { makeStorageStub } = require("./support/storageStub");
|
||||
@@ -90,6 +94,9 @@ function loadColdWorker(networkId) {
|
||||
const storage = makeStorageStub({ autistmask: storedProfile(networkId) });
|
||||
|
||||
let messageListener = null;
|
||||
let connectListener = null;
|
||||
// The URL of every approval window opened; the approval id is in it.
|
||||
const opened = [];
|
||||
const toTabs = [];
|
||||
|
||||
global.chrome = {
|
||||
@@ -101,12 +108,19 @@ function loadColdWorker(networkId) {
|
||||
messageListener = fn;
|
||||
},
|
||||
},
|
||||
onConnect: { addListener: () => {} },
|
||||
onConnect: {
|
||||
addListener: (fn) => {
|
||||
connectListener = fn;
|
||||
},
|
||||
},
|
||||
lastError: null,
|
||||
},
|
||||
windows: {
|
||||
getLastFocused: (cb) => cb(null),
|
||||
create: (options, cb) => cb({ id: 1 }),
|
||||
create: (options, cb) => {
|
||||
opened.push(options.url);
|
||||
cb({ id: opened.length });
|
||||
},
|
||||
remove: (id, cb) => {
|
||||
if (cb) cb();
|
||||
},
|
||||
@@ -124,6 +138,32 @@ function loadColdWorker(networkId) {
|
||||
|
||||
require("../src/background/index");
|
||||
|
||||
// The user approves the prompt the request opened, as the popup does: a
|
||||
// decision on the port named for the approval, from the extension's own
|
||||
// page.
|
||||
function approvePrompt() {
|
||||
const id = new URL(opened[opened.length - 1]).searchParams.get(
|
||||
"approval",
|
||||
);
|
||||
let onDecision = null;
|
||||
const port = {
|
||||
name: "approval:" + id,
|
||||
sender: { url: "chrome-extension://autistmask/src/popup/" },
|
||||
onMessage: {
|
||||
addListener: (fn) => {
|
||||
onDecision = fn;
|
||||
},
|
||||
},
|
||||
onDisconnect: { addListener: () => {} },
|
||||
};
|
||||
connectListener(port);
|
||||
onDecision(
|
||||
{ type: "AUTISTMASK_APPROVAL_DECISION", approved: true },
|
||||
port,
|
||||
);
|
||||
}
|
||||
|
||||
// A connected site asks for `chainId`, and the user approves it.
|
||||
async function switchChain(chainId) {
|
||||
let result = null;
|
||||
messageListener(
|
||||
@@ -138,6 +178,8 @@ function loadColdWorker(networkId) {
|
||||
},
|
||||
);
|
||||
await settle();
|
||||
approvePrompt();
|
||||
await settle();
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -63,6 +63,7 @@ const {
|
||||
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
|
||||
const { startDappServer } = require("./dapp");
|
||||
const { STUB_COUNTERPARTY } = require("../network");
|
||||
const { NETWORKS } = require("../../../src/shared/networks");
|
||||
const {
|
||||
STATE_SCHEMA_VERSION,
|
||||
stateProblem,
|
||||
@@ -684,6 +685,159 @@ step(
|
||||
},
|
||||
);
|
||||
|
||||
// The network fields of the stored record, read on the popup page, the one
|
||||
// moz-extension:// document the suite has open.
|
||||
async function storedNetwork(env) {
|
||||
const d = env.driver;
|
||||
await d.switchToWindow(env.popupWindow);
|
||||
const stored = await d.executeAsync(
|
||||
`const done = arguments[arguments.length - 1];
|
||||
const api = typeof browser !== "undefined" ? browser : chrome;
|
||||
Promise.resolve(api.storage.local.get("autistmask")).then(
|
||||
(r) => done({
|
||||
networkId: r.autistmask.networkId,
|
||||
rpcUrl: r.autistmask.rpcUrl,
|
||||
blockscoutUrl: r.autistmask.blockscoutUrl,
|
||||
}),
|
||||
(e) => done({ error: String((e && e.message) || e) }),
|
||||
);`,
|
||||
);
|
||||
assert(
|
||||
stored && !stored.error,
|
||||
"could not read the stored network: " + (stored && stored.error),
|
||||
);
|
||||
return stored;
|
||||
}
|
||||
|
||||
// Every chainChanged event the test page has been sent, waiting up to
|
||||
// `timeout` for there to be `count` of them: the background sends the event
|
||||
// alongside its answer to the request, so it can arrive just after it. Leaves
|
||||
// the driver on the page.
|
||||
async function chainChangedEvents(env, count = 0, timeout = 5000) {
|
||||
const d = env.driver;
|
||||
await d.switchToWindow(env.dappWindow);
|
||||
const deadline = Date.now() + timeout;
|
||||
for (;;) {
|
||||
const events = (await dappMessages(d, "AUTISTMASK_EVENT")).filter(
|
||||
(m) => m.eventName === "chainChanged",
|
||||
);
|
||||
if (events.length >= count || Date.now() > deadline) return events;
|
||||
await sleep(100);
|
||||
}
|
||||
}
|
||||
|
||||
// Ask, from the page, to switch from network `from` to network `to`, and
|
||||
// return the prompt that opens, checked to name the site and both networks.
|
||||
// Leaves the driver on the prompt.
|
||||
async function openNetworkPrompt(env, key, from, to) {
|
||||
const d = env.driver;
|
||||
await d.switchToWindow(env.dappWindow);
|
||||
await startRequest(d, key, "wallet_switchEthereumChain", [
|
||||
{ chainId: to.chainId },
|
||||
]);
|
||||
const popup = await waitForApprovalWindow(d);
|
||||
await d.switchToWindow(popup);
|
||||
await d.waitVisible("#view-approve-network");
|
||||
const screen = {
|
||||
origin: await d.text("#approve-network-origin"),
|
||||
current: await d.text("#approve-network-current"),
|
||||
requested: await d.text("#approve-network-requested"),
|
||||
};
|
||||
assert(
|
||||
isDeepStrictEqual(screen, {
|
||||
origin: env.server.origin,
|
||||
current: from.name,
|
||||
requested: to.name,
|
||||
}),
|
||||
"the network switch prompt shows " + JSON.stringify(screen),
|
||||
);
|
||||
return popup;
|
||||
}
|
||||
|
||||
// Only the user switches the network. A connected site's request opens a
|
||||
// prompt, and until the user approves it the stored network does not move and
|
||||
// no page is told it did (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||
// The wallet goes back to mainnet the same way at the end, for the transaction
|
||||
// step after this one.
|
||||
step(
|
||||
"a site's network switch changes nothing until the user approves it",
|
||||
async (env) => {
|
||||
const d = env.driver;
|
||||
const { mainnet, sepolia } = NETWORKS;
|
||||
const before = await storedNetwork(env);
|
||||
assert(
|
||||
before.networkId === "mainnet",
|
||||
"this step starts on mainnet, not on " + before.networkId,
|
||||
);
|
||||
const eventsBefore = (await chainChangedEvents(env)).length;
|
||||
|
||||
const rejected = await openNetworkPrompt(
|
||||
env,
|
||||
"switch-reject",
|
||||
mainnet,
|
||||
sepolia,
|
||||
);
|
||||
assert(
|
||||
isDeepStrictEqual(await storedNetwork(env), before),
|
||||
"the network moved while its prompt was still open",
|
||||
);
|
||||
// Nothing else closes this window, so a click that did not land
|
||||
// leaves the request unanswered and the assertion below fails.
|
||||
await d.switchToWindow(rejected);
|
||||
await d.click("#btn-reject-network");
|
||||
await d.switchToWindow(env.dappWindow);
|
||||
await assertUserRejection(
|
||||
d,
|
||||
"switch-reject",
|
||||
"the network switch rejection",
|
||||
);
|
||||
assert(
|
||||
isDeepStrictEqual(await storedNetwork(env), before),
|
||||
"a rejected network switch moved the network",
|
||||
);
|
||||
assert(
|
||||
(await chainChangedEvents(env)).length === eventsBefore,
|
||||
"a rejected network switch told the page the chain changed",
|
||||
);
|
||||
|
||||
await openNetworkPrompt(env, "switch-approve", mainnet, sepolia);
|
||||
await d.click("#btn-approve-network");
|
||||
await d.switchToWindow(env.dappWindow);
|
||||
let outcome = await settleRequest(d, "switch-approve");
|
||||
assert(
|
||||
outcome.settled === "resolved" && outcome.result === null,
|
||||
"the approved network switch did not resolve: " +
|
||||
JSON.stringify(outcome),
|
||||
);
|
||||
assert(
|
||||
(await storedNetwork(env)).networkId === "sepolia",
|
||||
"the approved network switch did not move the network",
|
||||
);
|
||||
const events = await chainChangedEvents(env, eventsBefore + 1);
|
||||
assert(
|
||||
events.length === eventsBefore + 1 &&
|
||||
events[events.length - 1].data === sepolia.chainId,
|
||||
"the page was not told of the approved switch: " +
|
||||
JSON.stringify(events),
|
||||
);
|
||||
|
||||
await openNetworkPrompt(env, "switch-restore", sepolia, mainnet);
|
||||
await d.click("#btn-approve-network");
|
||||
await d.switchToWindow(env.dappWindow);
|
||||
outcome = await settleRequest(d, "switch-restore");
|
||||
assert(
|
||||
outcome.settled === "resolved",
|
||||
"switching back to mainnet did not resolve: " +
|
||||
JSON.stringify(outcome),
|
||||
);
|
||||
assert(
|
||||
isDeepStrictEqual(await storedNetwork(env), before),
|
||||
"switching back did not restore the mainnet network and endpoints",
|
||||
);
|
||||
await d.switchToWindow(env.dappWindow);
|
||||
},
|
||||
);
|
||||
|
||||
step(
|
||||
"eth_sendTransaction shows the transaction and returns its hash",
|
||||
async (env) => {
|
||||
|
||||
+156
-7
@@ -3499,7 +3499,7 @@ async function closeApprovalPages(ctx) {
|
||||
}
|
||||
|
||||
// Click a button whose own handler closes the window it lives in — every
|
||||
// Reject, and Allow on the site prompt.
|
||||
// Reject, Allow on the site prompt, and Switch on the network switch prompt.
|
||||
//
|
||||
// page.click() dispatches the click and then waits for the renderer to
|
||||
// acknowledge it, and a page torn down by the handler never gets to. The
|
||||
@@ -3514,12 +3514,13 @@ async function closeApprovalPages(ctx) {
|
||||
// #btn-reject-sign, #btn-reject-tx — their disconnect leaves the approval
|
||||
// pending, so a click that never landed leaves the dApp promise unsettled
|
||||
// and the assertion after the call fails on its own.
|
||||
// #btn-approve — only a decision resolves the promise, and a swallowed click
|
||||
// cannot produce settled === "resolved".
|
||||
// #btn-reject on the site prompt — NOT self-proving. A page that went away
|
||||
// without the click landing disconnects the approval port, the background
|
||||
// settles that as 4001, and 4001 is exactly what assertUserRejection
|
||||
// accepts. Both call sites arm the click trace below and assert it.
|
||||
// #btn-approve, #btn-approve-network — only a decision resolves the promise,
|
||||
// and a swallowed click cannot produce settled === "resolved".
|
||||
// #btn-reject on the site prompt, #btn-reject-network — NOT self-proving. A
|
||||
// page that went away without the click landing disconnects the approval
|
||||
// port, the background settles that as 4001, and 4001 is exactly what
|
||||
// assertUserRejection accepts. Every call site arms the click trace below
|
||||
// and asserts it.
|
||||
//
|
||||
// A button that is missing or unclickable raises a different error, which is
|
||||
// rethrown.
|
||||
@@ -4389,6 +4390,154 @@ test("a prompt raised while another approval window has focus opens its own (#29
|
||||
await assertUserRejection(env.dapp, "focus-sign", "the sign prompt");
|
||||
});
|
||||
|
||||
// The network fields of the stored record.
|
||||
async function storedNetwork(page) {
|
||||
const s = await storedRecord(page);
|
||||
return {
|
||||
networkId: s.networkId,
|
||||
rpcUrl: s.rpcUrl,
|
||||
blockscoutUrl: s.blockscoutUrl,
|
||||
};
|
||||
}
|
||||
|
||||
// Every chainChanged event the test page has been sent, waiting up to
|
||||
// `timeout` for there to be `count` of them: the background sends the event
|
||||
// alongside its answer to the request, so it can arrive just after it.
|
||||
async function chainChangedEvents(page, count = 0, timeout = 5000) {
|
||||
const deadline = Date.now() + timeout;
|
||||
for (;;) {
|
||||
const events = (await dappMessages(page, "AUTISTMASK_EVENT")).filter(
|
||||
(m) => m.eventName === "chainChanged",
|
||||
);
|
||||
if (events.length >= count || Date.now() > deadline) return events;
|
||||
await sleep(50);
|
||||
}
|
||||
}
|
||||
|
||||
// Ask, from the test page, to switch from network `from` to network `to`, and
|
||||
// return the prompt that opens, checked to name the site and both networks.
|
||||
async function openNetworkPrompt(env, key, from, to) {
|
||||
await startRequest(env.dapp, key, "wallet_switchEthereumChain", [
|
||||
{ chainId: to.chainId },
|
||||
]);
|
||||
const popup = await waitForApprovalWindow(env.ctx);
|
||||
await visible(popup, "#view-approve-network");
|
||||
const screen = await popup.evaluate(() => ({
|
||||
origin: document.getElementById("approve-network-origin").textContent,
|
||||
current: document.getElementById("approve-network-current").textContent,
|
||||
requested: document.getElementById("approve-network-requested")
|
||||
.textContent,
|
||||
}));
|
||||
assert(
|
||||
isDeepStrictEqual(screen, {
|
||||
origin: DAPP_ORIGIN,
|
||||
current: from.name,
|
||||
requested: to.name,
|
||||
}),
|
||||
"the network switch prompt shows " + JSON.stringify(screen),
|
||||
);
|
||||
return popup;
|
||||
}
|
||||
|
||||
// Only the user switches the network. A connected site's request opens a
|
||||
// prompt, and until the user approves it the stored network does not move and
|
||||
// no page is told it did (https://git.eeqj.de/sneak/AutistMask/issues/408).
|
||||
// The wallet goes back to mainnet the same way at the end, for the tests after
|
||||
// this one.
|
||||
test("a site's network switch changes nothing until the user approves it (#408)", async (env) => {
|
||||
const { mainnet, sepolia } = NETWORKS;
|
||||
const before = await storedNetwork(env.page);
|
||||
assert(
|
||||
before.networkId === "mainnet",
|
||||
"this test starts on mainnet, not on " + before.networkId,
|
||||
);
|
||||
const eventsBefore = (await chainChangedEvents(env.dapp)).length;
|
||||
|
||||
const rejected = await openNetworkPrompt(
|
||||
env,
|
||||
"switch-reject",
|
||||
mainnet,
|
||||
sepolia,
|
||||
);
|
||||
try {
|
||||
assert(
|
||||
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||
"the network moved while its prompt was still open",
|
||||
);
|
||||
// Closing the prompt unanswered is also a rejection, so the click
|
||||
// itself is witnessed.
|
||||
await armClickTrace(env, rejected, "#btn-reject-network");
|
||||
await clickAndClose(rejected, "#btn-reject-network");
|
||||
await assertClickLanded(env, "#btn-reject-network");
|
||||
await assertUserRejection(
|
||||
env.dapp,
|
||||
"switch-reject",
|
||||
"the network switch rejection",
|
||||
);
|
||||
} finally {
|
||||
await closeApprovalPages(env.ctx);
|
||||
}
|
||||
assert(
|
||||
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||
"a rejected network switch moved the network",
|
||||
);
|
||||
assert(
|
||||
(await chainChangedEvents(env.dapp)).length === eventsBefore,
|
||||
"a rejected network switch told the page the chain changed",
|
||||
);
|
||||
|
||||
const approved = await openNetworkPrompt(
|
||||
env,
|
||||
"switch-approve",
|
||||
mainnet,
|
||||
sepolia,
|
||||
);
|
||||
let outcome;
|
||||
try {
|
||||
await clickAndClose(approved, "#btn-approve-network");
|
||||
outcome = await settleRequest(env.dapp, "switch-approve");
|
||||
} finally {
|
||||
await closeApprovalPages(env.ctx);
|
||||
}
|
||||
assert(
|
||||
outcome.settled === "resolved" && outcome.result === null,
|
||||
"the approved network switch did not resolve: " +
|
||||
JSON.stringify(outcome),
|
||||
);
|
||||
assert(
|
||||
(await storedNetwork(env.page)).networkId === "sepolia",
|
||||
"the approved network switch did not move the network",
|
||||
);
|
||||
const events = await chainChangedEvents(env.dapp, eventsBefore + 1);
|
||||
assert(
|
||||
events.length === eventsBefore + 1 &&
|
||||
events[events.length - 1].data === sepolia.chainId,
|
||||
"the page was not told of the approved switch: " +
|
||||
JSON.stringify(events),
|
||||
);
|
||||
|
||||
const restored = await openNetworkPrompt(
|
||||
env,
|
||||
"switch-restore",
|
||||
sepolia,
|
||||
mainnet,
|
||||
);
|
||||
try {
|
||||
await clickAndClose(restored, "#btn-approve-network");
|
||||
outcome = await settleRequest(env.dapp, "switch-restore");
|
||||
} finally {
|
||||
await closeApprovalPages(env.ctx);
|
||||
}
|
||||
assert(
|
||||
outcome.settled === "resolved",
|
||||
"switching back to mainnet did not resolve: " + JSON.stringify(outcome),
|
||||
);
|
||||
assert(
|
||||
isDeepStrictEqual(await storedNetwork(env.page), before),
|
||||
"switching back did not restore the mainnet network and endpoints",
|
||||
);
|
||||
});
|
||||
|
||||
// The closing pass over both boundaries at once. Every message the section
|
||||
// put on either channel is re-read here and required to be free of the
|
||||
// password — and required to be there at all, method by method, so the
|
||||
|
||||
Reference in New Issue
Block a user