Compare commits
1
Commits
next
..
f47d17a98f
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f47d17a98f |
+7
-77
@@ -1,77 +1,7 @@
|
||||
# .dockerignore does NOT use .gitignore semantics. Docker matches with
|
||||
# moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross
|
||||
# `/` and an unprefixed pattern is anchored at the context root. Every
|
||||
# depth-independent pattern therefore needs `**/`, or `config/.env` and
|
||||
# `certs/server.key` still ship while this file reads as solved. Only
|
||||
# genuinely root-anchored entries go unprefixed. Never transplant these
|
||||
# into .gitignore, where `**/` is wrong.
|
||||
#
|
||||
# Matching is case-sensitive, so secrets use character ranges rather
|
||||
# than an ALL-CAPS twin, which would still miss `Server.Key`.
|
||||
#
|
||||
# Extend with this repo's own host-built artifacts, written anchored:
|
||||
# `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and
|
||||
# deletes the package directory from the context.
|
||||
|
||||
# .git is sent without its config. Without a VERSION build argument the
|
||||
# stage that compiles runs `git describe --tags --always` on .git, which
|
||||
# does not need .git/config; that file can hold a credential, such as a
|
||||
# password in a remote URL or the token the CI checkout step stores there.
|
||||
# Each submodule keeps a config with the same exposure in its git directory
|
||||
# under .git/modules/, nested again for a submodule's own submodules, or in
|
||||
# its own .git directory when it keeps one.
|
||||
# KNOWN GAP: a submodule whose name has a `config` segment (`config`,
|
||||
# `deploy/config`, `config/lib`) loses its whole git directory, because
|
||||
# `**/.git/modules/**/config` also matches that segment's directory
|
||||
# under .git/modules/. Go's version stamping then fails the build;
|
||||
# nothing leaks. Name such a submodule without that segment:
|
||||
# `git submodule add --name`.
|
||||
**/.git/config
|
||||
**/.git/modules/**/config
|
||||
|
||||
# Agent scratch: one full checkout of the repo per in-flight agent.
|
||||
# Anchored because it occurs once where agents run at the repo root.
|
||||
# KNOWN GAP: a repo running agents in subdirectories still ships
|
||||
# `services/api/.claude/` and must add its own anchored entry.
|
||||
.claude
|
||||
|
||||
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
||||
# convention. Re-include a committed template with a negation if the
|
||||
# build needs one: `!docs/example.env`.
|
||||
**/*.[eE][nN][vV]
|
||||
**/.[eE][nN][vV].*
|
||||
**/.[eE][nN][vV][rR][cC]
|
||||
|
||||
# Private keys and the bundles carrying them. Public certificates
|
||||
# (*.crt, *.cer) are deliberately absent: they are legitimate inputs.
|
||||
**/*.[pP][eE][mM]
|
||||
**/*.[kK][eE][yY]
|
||||
**/*.[pP]12
|
||||
**/*.[pP][fF][xX]
|
||||
**/[iI][dD]_[rR][sS][aA]
|
||||
**/[iI][dD]_[dD][sS][aA]
|
||||
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
||||
**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
||||
**/[iI][dD]_[eE][dD]25519
|
||||
**/[iI][dD]_[eE][dD]25519_[sS][kK]
|
||||
|
||||
# Dependencies: restored inside the image, never copied in.
|
||||
**/node_modules
|
||||
|
||||
# OS metadata.
|
||||
**/.DS_Store
|
||||
**/Thumbs.db
|
||||
|
||||
# Editor state: never a build input, and it churns COPY.
|
||||
**/*.swp
|
||||
**/*.swo
|
||||
**/*~
|
||||
**/*.bak
|
||||
**/.idea
|
||||
**/.vscode
|
||||
**/*.sublime-*
|
||||
|
||||
# This repo's host-built artifacts: make build writes dist/ and make package
|
||||
# writes release/. The image builds its own.
|
||||
/dist
|
||||
/release
|
||||
# .git is deliberately NOT excluded: build.js shells out to `git rev-parse` for
|
||||
# build-info stamping and the Dockerfile runs `make build`, so excluding it
|
||||
# would make every built extension report commitHash "unknown".
|
||||
node_modules
|
||||
.DS_Store
|
||||
dist
|
||||
release
|
||||
|
||||
+10
-17
@@ -2,11 +2,11 @@ name: e2e
|
||||
on: [push]
|
||||
|
||||
# The browser end-to-end suites, one job per browser, deliberately kept out
|
||||
# of the check workflow: REPO_POLICIES.md caps make test at 60 seconds and
|
||||
# script/cibuild runs script/check, so folding a browser suite into either
|
||||
# would blow that cap and slow the local fast path. Before this workflow
|
||||
# every browser-level guarantee in this repo held only when a human
|
||||
# remembered to run it.
|
||||
# of the check workflow: REPO_POLICIES.md caps make test at 20 seconds and
|
||||
# script/cibuild is a plain `docker build .` whose Dockerfile runs
|
||||
# make check, so folding a browser suite into either would blow that cap
|
||||
# and slow the local fast path. Before this workflow every browser-level
|
||||
# guarantee in this repo held only when a human remembered to run it.
|
||||
#
|
||||
# One job per browser rather than two steps in one job, so a Chrome failure
|
||||
# does not hide the Firefox result.
|
||||
@@ -22,10 +22,11 @@ on: [push]
|
||||
# These jobs REPORT, they do not gate. Whether a check blocks a merge is
|
||||
# Gitea branch protection, which this repo does not configure, so a failure
|
||||
# here is a red mark a reviewer has to account for rather than a hard
|
||||
# block. Making e2e-chrome a required check is blocked while reports of the
|
||||
# Chrome suite failing under load are still open; the "In CI" section of
|
||||
# README.md names them. A gate that fails at random teaches people to merge
|
||||
# past red.
|
||||
# block. Making e2e-chrome a required check is blocked on the measured
|
||||
# flake in the dApp signing wait -- two of six runs of unmutated code on a
|
||||
# loaded machine -- tracked as
|
||||
# https://git.eeqj.de/sneak/AutistMask/issues/287. A gate that fails at
|
||||
# random teaches people to merge past red.
|
||||
#
|
||||
# Nothing here may pass vacuously. There is no continue-on-error and no
|
||||
# `|| true`. Both scripts exit non-zero when docker is missing, when the
|
||||
@@ -35,10 +36,6 @@ on: [push]
|
||||
jobs:
|
||||
e2e-chrome:
|
||||
runs-on: ubuntu-latest
|
||||
# Bounds the image build, a cold cache included, and both Chrome
|
||||
# programs, so a hung browser frees the shared runner. README.md
|
||||
# "In CI" has the measured times.
|
||||
timeout-minutes: 20
|
||||
steps:
|
||||
# actions/checkout v4.2.2, 2026-02-22
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
@@ -46,10 +43,6 @@ jobs:
|
||||
|
||||
e2e-firefox:
|
||||
runs-on: ubuntu-latest
|
||||
# Bounds the image build, a cold cache included, and both Firefox
|
||||
# programs, so a hung browser frees the shared runner. README.md
|
||||
# "In CI" has the measured times.
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
# actions/checkout v4.2.2, 2026-02-22
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
+5
-31
@@ -11,40 +11,14 @@ Thumbs.db
|
||||
.vscode/
|
||||
*.sublime-*
|
||||
|
||||
# Agent scratch (worktrees of this repo, created and destroyed by
|
||||
# in-flight tooling). Unanchored: .gitignore patterns already match at
|
||||
# every depth, so no prefix is wanted here. This is not a .dockerignore
|
||||
# entry and must not be given a `**/` prefix on the way into one.
|
||||
.claude/
|
||||
|
||||
# Node
|
||||
node_modules/
|
||||
|
||||
# Secrets. Unanchored like every entry above, so each matches at every
|
||||
# depth. Matching is case-sensitive on Linux, so names use character
|
||||
# ranges rather than a lowercase form that misses `Server.Key`.
|
||||
|
||||
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
||||
# convention. Only the templates `example.env` and `sample.env` are
|
||||
# re-included below. A repository that commits any other template adds
|
||||
# its own negation after these lines, for example `!.env.example`.
|
||||
*.[eE][nN][vV]
|
||||
.[eE][nN][vV].*
|
||||
.[eE][nN][vV][rR][cC]
|
||||
!example.env
|
||||
!sample.env
|
||||
|
||||
# Private keys and the bundles carrying them.
|
||||
*.[pP][eE][mM]
|
||||
*.[kK][eE][yY]
|
||||
*.[pP]12
|
||||
*.[pP][fF][xX]
|
||||
[iI][dD]_[rR][sS][aA]
|
||||
[iI][dD]_[dD][sS][aA]
|
||||
[iI][dD]_[eE][cC][dD][sS][aA]
|
||||
[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
||||
[iI][dD]_[eE][dD]25519
|
||||
[iI][dD]_[eE][dD]25519_[sS][kK]
|
||||
# Environment / secrets
|
||||
.env
|
||||
.env.*
|
||||
*.pem
|
||||
*.key
|
||||
|
||||
# Build output
|
||||
dist/
|
||||
|
||||
@@ -1,2 +1,5 @@
|
||||
node_modules/
|
||||
yarn.lock
|
||||
dist/
|
||||
release/
|
||||
.claude/
|
||||
|
||||
+28
-67
@@ -1,80 +1,41 @@
|
||||
# Lint phase: ESLint, prettier --check, and script/check-censored. The tools
|
||||
# are invoked directly rather than through `make lint` or `script/lint`, which
|
||||
# are themselves a docker build and would recurse into a daemon that does not
|
||||
# exist in a build step.
|
||||
#
|
||||
# node:22-slim (22.x LTS), 2026-02-24
|
||||
FROM node@sha256:5373f1906319b3a1f291da5d102f4ce5c77ccbe29eb637f072b6c7b70443fc36 AS lint
|
||||
FROM node@sha256:5373f1906319b3a1f291da5d102f4ce5c77ccbe29eb637f072b6c7b70443fc36 AS base
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Marks "already inside the lint container" for script/lint, which otherwise
|
||||
# shells out to docker to build the lint stage below. Nothing outside this
|
||||
# image sets it.
|
||||
ENV AUTISTMASK_LINT_NATIVE=1
|
||||
|
||||
# script/test's default 30s bound is the host figure. In here the same suite
|
||||
# starts on a cold jest cache and shares the runner with the rest of the build,
|
||||
# so 30s is too tight — it killed a healthy suite at 30.6s on a cold CI cache.
|
||||
# 180s still catches a hang in three minutes and cannot be tripped by a suite
|
||||
# that is merely running on contended hardware.
|
||||
ENV AUTISTMASK_TEST_TIMEOUT=180
|
||||
|
||||
# script/bootstrap installs all prerequisites (make via apt here; node
|
||||
# is already in the base image, yarn comes via corepack) and runs
|
||||
# yarn install --frozen-lockfile. Dependency manifests are copied first
|
||||
# so the bootstrap layer is cached until they change.
|
||||
COPY script/ script/
|
||||
COPY package.json yarn.lock ./
|
||||
RUN script/bootstrap
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN yarn run lint
|
||||
RUN script/check-censored
|
||||
|
||||
# Test phase, same shape and for the same reason: the jest suite (its worker
|
||||
# cap is in package.json), rerun verbose on failure, then
|
||||
# script/test-verify-build.
|
||||
#
|
||||
# node:22-slim (22.x LTS), 2026-02-24
|
||||
FROM node@sha256:5373f1906319b3a1f291da5d102f4ce5c77ccbe29eb637f072b6c7b70443fc36 AS test
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY script/ script/
|
||||
COPY package.json yarn.lock ./
|
||||
RUN script/bootstrap
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN timeout 90 yarn run test || \
|
||||
{ echo "--- Rerunning with --verbose for details ---"; \
|
||||
timeout 90 yarn run test:verbose; exit 1; }
|
||||
RUN script/test-verify-build
|
||||
|
||||
# Development environment with the extension built, and the last stage: a
|
||||
# plain `docker build .` names no target and so builds this one. Nothing is
|
||||
# wanted from the two phases above; the copies are what make BuildKit build
|
||||
# them first, so this image cannot be produced unless lint and test passed. A
|
||||
# stage appended after this one would drop all three out of a plain build.
|
||||
#
|
||||
# node:22-slim (22.x LTS), 2026-02-24
|
||||
FROM node@sha256:5373f1906319b3a1f291da5d102f4ce5c77ccbe29eb637f072b6c7b70443fc36
|
||||
|
||||
WORKDIR /app
|
||||
# Lint stage — fail fast on static analysis and formatting, before the tests
|
||||
# and the build. This is also the stage script/lint builds from a host, which
|
||||
# is how linting stays on the pinned ESLint rather than the host's.
|
||||
FROM base AS lint
|
||||
RUN make lint
|
||||
|
||||
# Full check and build. The COPY --from is a no-op file copy whose only job is
|
||||
# to make BuildKit finish the lint stage before this one starts; without it the
|
||||
# stages run in parallel and a lint failure would not fail the build early.
|
||||
FROM base AS check
|
||||
COPY --from=lint /app/package.json /dev/null
|
||||
COPY --from=test /app/package.json /dev/null
|
||||
|
||||
# script/bootstrap installs all prerequisites, git included. Manifests are
|
||||
# copied first so that layer stays cached until dependencies change.
|
||||
COPY script/ script/
|
||||
COPY package.json yarn.lock ./
|
||||
RUN script/bootstrap
|
||||
# A tar-stream context keeps the sender's file owners, which git refuses.
|
||||
RUN git config --system --add safe.directory /app
|
||||
|
||||
COPY . .
|
||||
|
||||
# The VERSION build arg when one is given, otherwise
|
||||
# `git describe --tags --always` on the .git in the build context. With .git
|
||||
# present, a version that is still empty, dev or unknown fails the build: git
|
||||
# is missing or could not read the checkout, and build.js, which stamps the
|
||||
# extension with the commit it was built from, would stamp "unknown".
|
||||
ARG VERSION
|
||||
RUN VERSION="${VERSION:-$(git describe --tags --always)}"; \
|
||||
if [ -e .git ]; then \
|
||||
case "$VERSION" in ""|dev|unknown) \
|
||||
echo "version is '$VERSION' although .git is present" >&2; \
|
||||
exit 1 ;; \
|
||||
esac; \
|
||||
fi; \
|
||||
make build
|
||||
# A LABEL cannot run git, so it carries the build argument alone; a plain
|
||||
# `docker build .` leaves it empty.
|
||||
LABEL org.opencontainers.image.version="${VERSION}"
|
||||
RUN make check
|
||||
RUN make build
|
||||
|
||||
@@ -107,14 +107,6 @@ vendor-blocklist:
|
||||
clean:
|
||||
@rm -rf dist/ release/
|
||||
|
||||
# Run the build make build runs, without the checks that follow it, then run it
|
||||
# again after every change to a file under src/, manifest/ or icons/, until
|
||||
# interrupted. A failed build is reported, may leave dist/ partly written, and
|
||||
# watching carries on. It writes no build receipt, so nothing can verify what it
|
||||
# leaves in dist/: anything handed on comes from make build. A release build
|
||||
# unless AUTISTMASK_DEBUG=1 is exported. A change anywhere else, package.json
|
||||
# and build.js included, starts no build, and a directory created while it runs
|
||||
# is not watched; restart it after either.
|
||||
dev:
|
||||
@echo "Building in watch mode..."
|
||||
@yarn run build --watch 2>&1
|
||||
|
||||
@@ -222,32 +222,31 @@ provide:
|
||||
- `script/setup` — make a fresh clone ready for development: bootstrap plus the
|
||||
git pre-commit hook
|
||||
- `script/projectname` — print the project name (used for the Docker image tag)
|
||||
- `script/test` — build the Dockerfile's `test` phase, uncached: the jest suite,
|
||||
stopped after 90 seconds and rerun verbose if it fails, then
|
||||
`script/test-verify-build`
|
||||
- `script/test` — run the test suite (jest)
|
||||
- `script/test-e2e` — run the Chrome browser end-to-end suite (docker is the
|
||||
only prerequisite: it builds a pinned image that carries the repo and a fresh
|
||||
extension build, see [End-to-End Tests](#end-to-end-tests))
|
||||
- `script/test-e2e-firefox` — run the Firefox browser end-to-end suite (same,
|
||||
against an image with a pinned Firefox and geckodriver, see
|
||||
[End-to-End Tests](#end-to-end-tests))
|
||||
- `script/lint` — build the Dockerfile's `lint` phase, uncached: ESLint
|
||||
(`eslint.config.js`), `prettier --check`, then `script/check-censored`,
|
||||
failing on any of them. It never writes: `--fix` is not in this path, so
|
||||
`make check` stays non-mutating. Linting runs only in the container, because
|
||||
an ESLint result that depends on whichever ESLint the host happens to have is
|
||||
not a result, so docker is required to lint.
|
||||
- `script/fmt` — format all files (writes), on the host
|
||||
- `script/fmt-check` — check formatting (read-only), on the host
|
||||
- `script/check` — run `script/test`, `script/lint` and `script/fmt-check`
|
||||
- `script/lint` — run ESLint (`eslint.config.js`) and then `prettier --check`,
|
||||
failing on either. It never writes: `--fix` is not in this path, so
|
||||
`make check` stays non-mutating. Linting runs in the container — the script
|
||||
builds the Dockerfile's `lint` stage — because an ESLint result that depends
|
||||
on whichever ESLint the host happens to have is not a result. Docker is
|
||||
therefore required to lint; inside that image `AUTISTMASK_LINT_NATIVE=1` makes
|
||||
the same script lint in place instead of recursing.
|
||||
- `script/fmt` — format all files (writes)
|
||||
- `script/fmt-check` — check formatting (read-only)
|
||||
- `script/check` — run test, test-verify-build, check-censored, lint, and
|
||||
fmt-check
|
||||
- `script/check-censored` — assert the competitor name RULES.md bars appears
|
||||
nowhere in the working tree or under `dist/` outside its documented
|
||||
exceptions: the pinned source reference in `script/vendor-blocklist`, the two
|
||||
provider-shim identifiers in `src/content/inpage.js`, and one ERC-20's
|
||||
on-chain name in `src/shared/tokenList.js`. Each is scoped to that path and
|
||||
fails anywhere else. Run by the `lint` phase, so part of `make check`; it
|
||||
inspects `dist/` when there is one and says loudly when there is not, and the
|
||||
build context of that phase never has one. `make build` re-runs it with
|
||||
fails anywhere else. Part of `make check`, which inspects `dist/` when there
|
||||
is one and says loudly when there is not; `make build` re-runs it with
|
||||
`--require-dist`, so a build artifact is always covered
|
||||
- `script/package` — produce the release artifacts: `make build` first, so the
|
||||
archives can only ever be made from a `dist/` that has been verified against
|
||||
@@ -282,23 +281,14 @@ provide:
|
||||
failing and a succeeding release build step, and read the `make build` and
|
||||
`make build-debug` recipes back out of `make -n` to check that they pass the
|
||||
mode as an argument on a scrubbed environment and wrap only the release path.
|
||||
Run by the `test` phase, so part of `make check`; it reads no build artifacts
|
||||
and writes nothing under `dist/`. The cases that depend on file permissions
|
||||
cannot mean anything for a process that is not subject to them, so the harness
|
||||
proves its runner against a mode-000 file before counting them, dropping to an
|
||||
unprivileged user when run as root; if it cannot, it skips those cases and
|
||||
says so in a banner rather than passing them.
|
||||
- `script/docker` — build the Docker image, uncached and tagged via
|
||||
`script/projectname`: the `lint` and `test` phases, then `make build` in the
|
||||
last stage. It passes what `git describe --tags --always --dirty` prints on
|
||||
the host as the `VERSION` build argument, or `unknown` when that prints
|
||||
nothing, and the last stage fails on `unknown` whenever the build context
|
||||
carries `.git`. Only a build given no `VERSION` at all, such as a plain
|
||||
`docker build .`, runs `git describe` on the `.git` in the build context,
|
||||
which `.dockerignore` sends without its `config`, and fails if git cannot read
|
||||
it
|
||||
- `script/cibuild` — CI entrypoint: `script/bootstrap`, `script/check`, then the
|
||||
same image build as `script/docker`
|
||||
Part of `make check`; it reads no build artifacts and writes nothing under
|
||||
`dist/`. The cases that depend on file permissions cannot mean anything for a
|
||||
process that is not subject to them, so the harness proves its runner against
|
||||
a mode-000 file before counting them, dropping to an unprivileged user when
|
||||
run as root; if it cannot, it skips those cases and says so in a banner rather
|
||||
than passing them.
|
||||
- `script/docker` — build the Docker image tagged via `script/projectname`
|
||||
- `script/cibuild` — CI entrypoint: plain `docker build .`
|
||||
- `script/precommit` — run by the git pre-commit hook; runs `script/check`
|
||||
- `script/install-precommit` — install the git pre-commit hook
|
||||
|
||||
@@ -316,15 +306,7 @@ The Makefile shims to those. It also carries a few targets that have no
|
||||
debug build, and keeping its `dist/` on failure (see
|
||||
[Debug Builds](#debug-builds))
|
||||
- `make clean` — remove `dist/` and `release/`
|
||||
- `make dev` — run the build `make build` runs, without the checks that follow
|
||||
it, then run it again after every change to a file under `src/`, `manifest/`
|
||||
or `icons/`, until interrupted. A failed build is reported, may leave `dist/`
|
||||
partly written, and watching carries on. It writes no build receipt, so
|
||||
nothing can verify what it leaves in `dist/` (see
|
||||
[Build Receipts](#build-receipts)): anything handed on comes from
|
||||
`make build`. A release build unless `AUTISTMASK_DEBUG=1` is exported. A
|
||||
change anywhere else, `package.json` and `build.js` included, starts no build,
|
||||
and a directory created while it runs is not watched; restart it after either
|
||||
- `make dev` — build in watch mode
|
||||
|
||||
## End-to-End Tests
|
||||
|
||||
@@ -360,11 +342,6 @@ fixtures in `tests/e2e/network.js`, so the run is deterministic and fully
|
||||
offline; unrecognised outbound requests are reported as failures rather than
|
||||
silently allowed.
|
||||
|
||||
It also covers the StateRecovery screen, under the shipped CSP: a stored record
|
||||
this build cannot read opens the popup on it, its export text box holds that
|
||||
record exactly as stored, a near-miss confirmation phrase erases nothing, and
|
||||
the exact one erases the record and reloads into Welcome.
|
||||
|
||||
It also covers the **Settings screen**, which holds the densest run of element
|
||||
id lookups in the codebase and where one wrong id leaves the whole popup blank
|
||||
rather than only degrading Settings: that the screen renders populated — the
|
||||
@@ -394,12 +371,6 @@ reserve while sitting on the same side of the estimate, so swapping the two in
|
||||
what [#154](https://git.eeqj.de/sneak/AutistMask/issues/154) was, and it was
|
||||
previously correct by reading only.
|
||||
|
||||
It also covers both ways the wait for a sent transaction's receipt ends on the
|
||||
error screen: lookups that still find no receipt 60 seconds after the broadcast,
|
||||
and six lookups in a row that fail. Each must show its own message, and Done
|
||||
must lead back to the address screen. Both wait in real time, about a minute
|
||||
each.
|
||||
|
||||
It also covers the **dApp approval round trips** — the one place where the
|
||||
content script, the inpage provider, the background worker and the approval
|
||||
popup all have to work together. A local test page is served by the route
|
||||
@@ -410,13 +381,11 @@ handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
|
||||
the runner and compared against the active address, the transaction assertions
|
||||
run against the raw signed transaction captured at `eth_sendRawTransaction`
|
||||
rather than against anything the extension reported, rejecting each prompt is
|
||||
required to return a rejection to the page rather than hang or resolve, a prompt
|
||||
raised while another approval window has focus is required to open a window of
|
||||
its own, and the password is required to be absent from every message the
|
||||
approval window sends to the background — with the message that would carry it
|
||||
required to be present, so that check cannot pass by observing nothing. That
|
||||
last one is the standing floor under
|
||||
[#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
||||
required to return a rejection to the page rather than hang or resolve, and the
|
||||
password is required to be absent from every message the approval window sends
|
||||
to the background — with the message that would carry it required to be present,
|
||||
so that check cannot pass by observing nothing. That last one is the standing
|
||||
floor under [#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
|
||||
|
||||
Two limits of that coverage, neither of them papered over. The RPC is stubbed
|
||||
throughout, so this is **not** a real dApp against a real network with real
|
||||
@@ -493,11 +462,10 @@ Chrome that ever changes this fails the run instead of passing it.
|
||||
|
||||
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
|
||||
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
|
||||
It covers popup load, the StateRecovery screen (the same cases as the Chrome
|
||||
suite), wallet creation through the UI, the Add Token screen, and the four dApp
|
||||
round trips — `eth_requestAccounts`, `personal_sign`, `eth_sendTransaction`, and
|
||||
a closed approval window rejecting with EIP-1193 4001 — driven through the real
|
||||
content script, background page and approval windows.
|
||||
It covers popup load, wallet creation through the UI, the Add Token screen, and
|
||||
the four dApp round trips — `eth_requestAccounts`, `personal_sign`,
|
||||
`eth_sendTransaction`, and a closed approval window rejecting with EIP-1193 4001
|
||||
— driven through the real content script, background page and approval windows.
|
||||
|
||||
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
|
||||
**no npm dependencies at all**: it is built on global `fetch` and
|
||||
@@ -627,7 +595,7 @@ Two limits are worth knowing, both real differences from the Chrome suite:
|
||||
out, but it cannot report which requests were attempted.
|
||||
|
||||
Neither `make test-e2e` nor `make test-e2e-firefox` is part of `make check` or
|
||||
`make test`. `REPO_POLICIES.md` caps `make test` at 60 seconds and a browser
|
||||
`make test`. `REPO_POLICIES.md` caps `make test` at 20 seconds and a browser
|
||||
suite does not fit; nothing in `tests/e2e/` is named `*.test.js`, so jest cannot
|
||||
pick it up either. Run them locally before changing anything under
|
||||
`src/popup/views/`.
|
||||
@@ -636,7 +604,7 @@ pick it up either. Run them locally before changing anything under
|
||||
|
||||
`.gitea/workflows/e2e.yml` runs both suites on every push, as two jobs —
|
||||
`e2e-chrome` and `e2e-firefox` — separate from the `check` workflow, so the
|
||||
60-second `make test` cap and the local fast path are untouched. Each job is a
|
||||
20-second `make test` cap and the local fast path are untouched. Each job is a
|
||||
checkout and the matching `script/` entrypoint, nothing else.
|
||||
|
||||
Docker is the only thing either job needs from the runner, and that is not an
|
||||
@@ -651,32 +619,24 @@ The jobs **report, they do not gate.** A failure is a red mark against the
|
||||
commit that a reviewer has to account for, not a hard block: whether a check
|
||||
blocks a merge is Gitea branch protection, which this repo does not configure.
|
||||
|
||||
That is not only a statement about configuration. No report of the Chrome suite
|
||||
**failing under load** is open now, but it has failed that way before, so a red
|
||||
`e2e-chrome` is read before it is believed. Do not answer one with a retry
|
||||
wrapper: a suite that reruns until it is green stops being evidence.
|
||||
That is not only a statement about configuration. The Chrome suite is
|
||||
**measurably flaky under load** — two of six runs of unmutated code on a busy
|
||||
machine lost the approval popup out from under the dApp signing wait, always in
|
||||
the `#183` section, tracked as
|
||||
[#287](https://git.eeqj.de/sneak/AutistMask/issues/287). So a red `e2e-chrome`
|
||||
has to be read before it is believed, and that flake is the blocker to ever
|
||||
making this a required check. Do not answer it with a retry wrapper: a suite
|
||||
that reruns until it is green stops being evidence.
|
||||
|
||||
Nothing in either job can pass vacuously. There is no `continue-on-error` and no
|
||||
`|| true`; both scripts exit non-zero when docker is missing, when the image
|
||||
build fails, and when the browser fails to start; the Chrome harness aborts the
|
||||
suite outright if its network interception is not in effect.
|
||||
|
||||
Measured on this repo's runner in the green runs of early October 2026, from a
|
||||
warm docker cache to a cold one: `e2e-chrome` 1m44s to 4m48s, and `e2e-firefox`
|
||||
31s to 4m07s. A cold cache adds three to four minutes to each job, spent
|
||||
rebuilding its image: reinstalling dependencies and, for `e2e-firefox`,
|
||||
installing Firefox, geckodriver and their system libraries. Both scripts now
|
||||
build their image with `--no-cache`, so every run pays the cold figure. Those
|
||||
`e2e-chrome` runs predate the cases that wait in real time for a receipt to end
|
||||
in error. `make test-e2e` took 3m51s locally with its image cached, so with the
|
||||
image rebuilt every run, an `e2e-chrome` run comes to about seven minutes.
|
||||
|
||||
Each e2e job has a `timeout-minutes` cap, so a hung build or browser ends the
|
||||
job instead of holding the shared runner: `e2e-firefox` 15 minutes and
|
||||
`e2e-chrome` 20, each over two and a half times the job's slowest cold run. A
|
||||
job that reaches its cap has hung; read it as a hang, not as a slow run to
|
||||
retry. The `check` job has no cap: `.gitea/workflows/check.yml` is the canonical
|
||||
copy from `sneak/prompts`, kept byte-identical.
|
||||
Measured on this repo's runner: `e2e-chrome` about 1m55s cold, almost all of it
|
||||
the one-time pull of the pinned ~800MB Playwright layer, and well under a minute
|
||||
once that layer is cached. `e2e-firefox` about 1m05s cold, and it caches its
|
||||
Firefox and geckodriver downloads the same way.
|
||||
|
||||
### Element id guard (part of `make check`)
|
||||
|
||||
@@ -735,7 +695,6 @@ src/
|
||||
balances.js — ETH + ERC-20 balance fetching via RPC + Blockscout
|
||||
constants.js — chain IDs, default RPC endpoint, ERC-20 ABI
|
||||
ens.js — ENS forward/reverse resolution (popup only)
|
||||
holders.js — holder-count parsing and the low-holder rule
|
||||
prices.js — ETH/USD and token/USD via CoinDesk API
|
||||
scamlist.js — known fraud contract addresses
|
||||
state.js — persisted state (extension storage)
|
||||
@@ -842,15 +801,13 @@ discoverable.
|
||||
on critical screens and when space is available to allow users to disambiguate
|
||||
addresses visually, as a security feature.
|
||||
- **Tailwind CSS**: Utility-first CSS via Tailwind. No custom CSS classes for
|
||||
styling, and no `style="..."` attributes, which the
|
||||
[Content Security Policy](#content-security-policy) refuses. Tailwind is
|
||||
configured with a minimal monochrome palette. This keeps the styling
|
||||
co-located with the markup and eliminates CSS file management. The handful of
|
||||
classes in `styles/main.css` are not styling: `.copy-flash-*` carries the copy
|
||||
feedback animation, and `.am-address` carries the rule that an address never
|
||||
wraps. Both are invariants that hold in every place they appear, and spelling
|
||||
either out as repeated utilities is how one of those places drifts away from
|
||||
the rest.
|
||||
styling. Tailwind is configured with a minimal monochrome palette. This keeps
|
||||
the styling co-located with the markup and eliminates CSS file management. The
|
||||
handful of classes in `styles/main.css` are not styling: `.copy-flash-*`
|
||||
carries the copy feedback animation, and `.am-address` carries the rule that
|
||||
an address never wraps. Both are invariants that hold in every place they
|
||||
appear, and spelling either out as repeated utilities is how one of those
|
||||
places drifts away from the rest.
|
||||
- **Vanilla JS**: No framework (React, Vue, Svelte, etc.). The popup UI is small
|
||||
enough that vanilla JS with simple view switching is sufficient. A framework
|
||||
would add bundle size, build complexity, and attack surface for no benefit at
|
||||
@@ -884,26 +841,18 @@ something when you click it.
|
||||
The same data must be formatted identically everywhere it appears. Token and ETH
|
||||
amounts are displayed with exactly 4 decimal places (e.g. "1.0500 ETH", "17.1900
|
||||
USDT") in balance lists, transaction lists, send confirmations, and approval
|
||||
screens. A transaction's time includes both an ISO datetime and a humanized
|
||||
relative age, written by `isoDate()` and `timeAgo()` in
|
||||
`src/popup/views/helpers.js` on every screen that shows one; the ISO datetime is
|
||||
in UTC when the UTC Timestamps setting is on. If a formatting rule applies in
|
||||
one place, it applies in every place. Users should never see the same value
|
||||
rendered differently on two screens.
|
||||
screens. Timestamps include both an ISO datetime and a humanized relative age
|
||||
wherever shown. If a formatting rule applies in one place, it applies in every
|
||||
place. Users should never see the same value rendered differently on two
|
||||
screens.
|
||||
|
||||
The native token's label is a network's `nativeCurrency` in
|
||||
`src/shared/networks.js`: `ETH` on mainnet, `SepoliaETH` on Sepolia. The
|
||||
wallet's balances and the Send and confirmation screens, which send on the
|
||||
active network, use the active network's. A transaction's figures use the one of
|
||||
the network its chain id names, whichever network is active: the value and fee
|
||||
on the approval screen, the amount on the wait, success and error screens, the
|
||||
transaction history and the transaction detail screen, and the refusal of a fee
|
||||
above 1 ETH. A chain id that names no network reads `ETH`. Wherever this
|
||||
document shows ETH as the label of a native balance, value or fee, in a "Native
|
||||
ETH transfer" type line, in the contract-recipient warning or in that refusal,
|
||||
Sepolia shows `SepoliaETH`. The swap lines keep `ETH`, the router's own name for
|
||||
the native currency, and the ETH/USD price line, shown on mainnet only, keeps
|
||||
its fixed wording.
|
||||
The native token's label is the active network's `nativeCurrency` in
|
||||
`src/shared/networks.js`: `ETH` on mainnet, `SepoliaETH` on Sepolia. Wherever
|
||||
this document shows ETH as the label of a native balance, value or fee, or in a
|
||||
"Native ETH transfer" type line, Sepolia shows `SepoliaETH`. The swap lines keep
|
||||
`ETH`, the router's own name for the native currency, and the ETH/USD price
|
||||
line, the contract-recipient warning and the refusal of a fee above 1 ETH keep
|
||||
their fixed wording.
|
||||
|
||||
**Specific Exception — Truncation:** On some non-critical display locations, we
|
||||
may truncate _a small number_ of characters from the middle of an address solely
|
||||
@@ -1165,21 +1114,15 @@ balance is nonzero and it is in the bundled known-token list, is tracked by the
|
||||
user, or has 1,000 or more holders; a token claiming a symbol from the bundled
|
||||
list from any other contract address is always dropped, and so is any token
|
||||
claiming a symbol that belongs to the native asset and therefore has no
|
||||
legitimate contract at all (`"ETH"`, and every network's `nativeCurrency`, such
|
||||
as `"SepoliaETH"`, on every network). That filter is unconditional — the "Hide
|
||||
legitimate contract at all (`"ETH"`). That filter is unconditional — the "Hide
|
||||
tokens with fewer than 1,000 holders" setting governs the transaction history
|
||||
and the send-screen token selector, not this list. A token's holder count is
|
||||
unknown when the explorer reports none, or reports anything other than a whole
|
||||
number written in digits alone, such as `1,000` or `1e3` (`parseHoldersCount()`
|
||||
in `src/shared/holders.js`). This list does not take an unknown count as 1,000
|
||||
or more, so such a token is shown only when it is on the bundled list or
|
||||
tracked. `fetchTokenBalances()` stores every nonzero holding of a token it
|
||||
admits, however small, but a holding below 0.000001 is left out of the balance
|
||||
lists, the send-screen token selector, the address total and the remove-address
|
||||
warning (`isBelowOneMillionth()` in `src/shared/amountDisplay.js`). The Send and
|
||||
confirmation screens show it when its token is the one being sent. Tracked
|
||||
tokens with a zero balance are listed as well while "Show tracked tokens with
|
||||
zero balance" is on.
|
||||
and the send-screen token selector, not this list. `fetchTokenBalances()` stores
|
||||
every nonzero holding of a token it admits, however small, but a holding below
|
||||
0.000001 is left out of the balance lists, the send-screen token selector, the
|
||||
address total and the remove-address warning (`isBelowOneMillionth()` in
|
||||
`src/shared/amountDisplay.js`). The Send and confirmation screens show it when
|
||||
its token is the one being sent. Tracked tokens with a zero balance are listed
|
||||
as well while "Show tracked tokens with zero balance" is on.
|
||||
|
||||
#### Stored state and its version
|
||||
|
||||
@@ -1199,18 +1142,16 @@ because bumping for one would send every older install to StateRecovery for
|
||||
nothing.
|
||||
|
||||
Every read of the record goes through `assertStateUsable()` first, on the raw
|
||||
bytes, before normalization: `loadState()` and every `saveState()` for the
|
||||
popup, and `getState()` for the background. It refuses a record that is not an
|
||||
object, a `schemaVersion` this build does not understand (a newer one included),
|
||||
a `wallets` that is not a list of wallet records with address records in them,
|
||||
and a `networkId` that is not a network in `src/shared/networks.js`. Refusing is
|
||||
the whole point — a record the wallet cannot vouch for is never normalized,
|
||||
never written back, and never half-loaded. The popup shows StateRecovery,
|
||||
whether it finds the record unreadable when it opens or at a save while it is
|
||||
open; a dApp gets a specific error (`-32007`, an EIP-1474 server-error code the
|
||||
spec leaves unassigned) saying the saved data cannot be read and that nothing
|
||||
was signed or sent, rather than the generic `-32603` every request used to
|
||||
answer.
|
||||
bytes, before normalization: `loadState()` for the popup and `getState()` for
|
||||
the background. It refuses a record that is not an object, a `schemaVersion`
|
||||
this build does not understand (a newer one included), a `wallets` that is not a
|
||||
list of wallet records with address records in them, and a `networkId` that is
|
||||
not a network in `src/shared/networks.js`. Refusing is the whole point — a
|
||||
record the wallet cannot vouch for is never normalized, never written back, and
|
||||
never half-loaded. The popup shows StateRecovery; a dApp gets a specific error
|
||||
(`-32007`, an EIP-1474 server-error code the spec leaves unassigned) saying the
|
||||
saved data cannot be read and that nothing was signed or sent, rather than the
|
||||
generic `-32603` every request used to answer.
|
||||
|
||||
Every other field of the record is floored in `normalizePersisted()` rather than
|
||||
gated, and the floor is not the same for every field. Some are type-checked as a
|
||||
@@ -1254,9 +1195,8 @@ now also reported rather than swallowed: `onSaveFailure()` in
|
||||
`src/shared/state.js` is called for every failed save, awaited or not, and the
|
||||
popup puts up a persistent "NOT SAVED" banner (`showSaveFailureBanner()` in
|
||||
`src/popup/views/helpers.js`). Storage can still fail for reasons no floor
|
||||
covers — a quota, a revoked permission — and the wallet must never look healthy
|
||||
while that is true. A save that fails because the stored record fails the gate,
|
||||
such as one a newer build wrote, gets StateRecovery instead of the banner.
|
||||
covers — a quota, a revoked permission, a record a newer build wrote — and the
|
||||
wallet must never look healthy while that is true.
|
||||
|
||||
The `networkId` check is not cosmetic: that value is an object KEY into
|
||||
`state.networkEndpoints`, so an unvalidated `"__proto__"` would set the map's
|
||||
@@ -1488,9 +1428,7 @@ view would leave a wallet one click from deletion.
|
||||
- Send / Receive buttons
|
||||
- Token contract well (ERC-20 only): full contract address (tap to copy,
|
||||
etherscan link) plus name, symbol, decimals, holder count and project
|
||||
website where known. The "Holders:" row is left out, not shown as 0, when
|
||||
the token's balance-list entry has no holder count: the explorer did not
|
||||
report a readable one, or the token is not in the balance list
|
||||
website where known
|
||||
- Token-filtered transaction list (only this token's transfers)
|
||||
- **Transitions**:
|
||||
- "Send" → **Send** (token locked: the dropdown is replaced by a static
|
||||
@@ -1512,17 +1450,6 @@ view would leave a wallet one click from deletion.
|
||||
- Amount input with current balance display, which reads
|
||||
`Current balance: unknown (SYMBOL)` for a token whose scale is unknown, as
|
||||
ConfirmTx's balance line does (see Unknown token scale)
|
||||
- "Max" button beside the amount input, always in place. It fills in a
|
||||
token's balance, cut down to the 18 decimal places ConfirmTx accepts for a
|
||||
token that has more, or for ETH the exact balance minus the network fee
|
||||
reserve that ConfirmTx's balance check gates on, never the rounded balance
|
||||
shown above it. The ETH fee is estimated for the recipient entered, so it
|
||||
asks for a recipient first; an estimate that finishes after the screen was
|
||||
left or the address, holding or recipient changed fills nothing in. Where
|
||||
there is nothing to fill in, a flash message says why: the balance does
|
||||
not cover the fee, the fee could not be estimated, or the token's balance
|
||||
is unknown or zero. Typing in the amount makes it an ordinary amount;
|
||||
changing what to send clears an amount Max filled in
|
||||
- "Review" button, disabled until the recipient validates
|
||||
- **Transitions**:
|
||||
- "Review" (valid inputs, ENS resolved) → **ConfirmTx**
|
||||
@@ -1539,14 +1466,7 @@ view would leave a wallet one click from deletion.
|
||||
- Token contract: full address + etherscan link (ERC-20 only)
|
||||
- From: blockie + color dot + full address + etherscan link + wallet title
|
||||
- To: blockie + color dot + full address + etherscan link + ENS name
|
||||
- Amount: value + symbol (USD in parentheses). An ETH amount Send's "Max"
|
||||
filled in is worked out again from this screen's own fee estimate when it
|
||||
arrives, as the balance minus the reserve, and the transaction is signed
|
||||
with that estimate's fee fields, so a fee fetched again at signing cannot
|
||||
exceed what the amount leaves behind. The address keeps whatever part of
|
||||
the reserve the transaction does not use. If the balance no longer covers
|
||||
the fee, the amount is left as it was and the amount-plus-fee error below
|
||||
blocks the send
|
||||
- Amount: value + symbol (USD in parentheses)
|
||||
- Your balance: value + symbol (USD in parentheses), or `unknown (SYMBOL)`
|
||||
for a token whose scale is unknown
|
||||
- Network fee: "Estimating..." then two lines, or "Unable to estimate",
|
||||
@@ -1674,9 +1594,7 @@ view would leave a wallet one click from deletion.
|
||||
- "Transaction" heading, "Back" button
|
||||
- Transaction hash: full hash (tap to copy) + etherscan link
|
||||
- Type: transaction classification — one of: Native ETH Transfer, ERC-20
|
||||
Token Transfer, Swap, Token Approval, Contract Call, Contract Creation. A
|
||||
transfer with a token contract is an ERC-20 Token Transfer whatever symbol
|
||||
the token reports.
|
||||
Token Transfer, Swap, Token Approval, Contract Call, Contract Creation
|
||||
- Status: "Success" or "Failed"
|
||||
- From: blockie + color dot + full address (tap to copy) + etherscan link;
|
||||
ENS name if available
|
||||
@@ -1850,10 +1768,7 @@ view would leave a wallet one click from deletion.
|
||||
new password — and, in bold, that without that phrase written down the
|
||||
deletion loses everything the wallet holds, forever
|
||||
- That the other wallets are not touched
|
||||
- The wallet's name, and a text input asking for it to be typed back. A name
|
||||
that shows nothing at all (only spaces, or only characters that paint
|
||||
nothing) is shown as "Wallet N", its position in the list, and that is
|
||||
what is typed back.
|
||||
- The wallet's name, and a text input asking for it to be typed back
|
||||
- Error line
|
||||
- "Delete This Wallet Forever" button
|
||||
- **Transitions**:
|
||||
@@ -1861,9 +1776,9 @@ view would leave a wallet one click from deletion.
|
||||
outcomes as "Confirm Delete" above, through the same `finishDelete()`, so
|
||||
the selection repair, permission cleanup and `AUTISTMASK_ACTIVE_CHANGED`
|
||||
broadcast are identical on both routes
|
||||
- "Delete This Wallet Forever" (name does not match, or the field is empty)
|
||||
→ "That is not the name of this wallet. Type <name> to confirm." on
|
||||
the error line, nothing deleted
|
||||
- "Delete This Wallet Forever" (name does not match) → "That is not the name
|
||||
of this wallet. Type <name> to confirm." on the error line, nothing
|
||||
deleted
|
||||
- "Back" → **DeleteWallet**, re-entered through its `show()` so the wallet
|
||||
selection comes back with it. The two delete screens are siblings rather
|
||||
than parent and child: nothing is pushed on the way here, so both have
|
||||
@@ -1872,13 +1787,8 @@ view would leave a wallet one click from deletion.
|
||||
secret protects nobody: an attacker at the popup who wants the wallet gone can
|
||||
uninstall the extension, so the only person such a gate stops is the owner who
|
||||
forgot it. The typed name is a check that the user knows which wallet they are
|
||||
on, not a secret, so it is matched as the user can see it: letter case,
|
||||
surrounding spaces and repeated inner spaces are ignored, and characters that
|
||||
paint nothing (format characters such as the zero-width space,
|
||||
default-ignorable characters, and DELETE — the same set
|
||||
`src/shared/symbolSpoof.js` strips) are removed from both sides before
|
||||
comparing. An empty field, or one holding only spaces or such characters, is
|
||||
refused whatever the wallet is called.
|
||||
on, not a secret, so it is matched with surrounding spaces and letter case
|
||||
ignored.
|
||||
- Not in `RESTORABLE_VIEWS`, alongside `delete-wallet-confirm`: a popup reopened
|
||||
by accident must not land on a screen whose button erases key material.
|
||||
|
||||
@@ -2003,9 +1913,7 @@ view would leave a wallet one click from deletion.
|
||||
`eth_sendTransaction` arriving while one is unanswered is refused with
|
||||
EIP-1193 code `-32002` rather than being populated at the same nonce. It opens
|
||||
no window and takes no nonce, and the site can send it again once the pending
|
||||
one is answered. The window is centred on the browser window the user was last
|
||||
in; if that was another approval window, or the browser refuses the centred
|
||||
position, the browser picks the position.
|
||||
one is answered.
|
||||
- **Elements**:
|
||||
- "Transaction Request" heading
|
||||
- Phishing warning banner (shown when the hostname is on the phishing
|
||||
@@ -2098,19 +2006,9 @@ view would leave a wallet one click from deletion.
|
||||
|
||||
#### StateRecovery (`state-recovery`)
|
||||
|
||||
- **When**: the stored profile fails `assertStateUsable()`. At open, that is
|
||||
`loadState()` refusing it, so the popup has no profile at all. While the popup
|
||||
is open, on any screen, it is a save refusing it: every `saveState()` reads
|
||||
the stored record and runs the same check before writing, so the popup finds
|
||||
it at the next navigation or ten-second refresh, whether or not the network
|
||||
answers ([#373](https://git.eeqj.de/sneak/AutistMask/issues/373)). A save that
|
||||
fails for any other reason, such as a storage read or write that errors, gets
|
||||
the "NOT SAVED" banner instead and leaves the screen as it is. The screen it
|
||||
replaces is left as any navigation leaves it, so a revealed phrase or key, or
|
||||
a typed password, is wiped. Once up, the screen stays until the popup closes
|
||||
or reloads: work still running in the popup, such as a transaction wait,
|
||||
cannot replace it, even after the record is erased in another window. It is
|
||||
the only screen that never appears during ordinary use.
|
||||
- **When**: `loadState()` refused the stored profile, so the popup has no
|
||||
profile at all. It is the only screen reached without one, and the only one
|
||||
that never appears during ordinary use.
|
||||
- **Why it exists**: a record the wallet cannot read used to render nothing — no
|
||||
view, no message, no control — while every dApp call answered a generic
|
||||
internal error, and no reset or wipe control existed anywhere in the product.
|
||||
@@ -2137,20 +2035,16 @@ view would leave a wallet one click from deletion.
|
||||
Nothing was erased." on the error line
|
||||
- **No other control is reachable.** The Settings gear is hidden while this
|
||||
screen is up, because every screen behind it renders from the profile that
|
||||
could not be read. `showView()` is not used to raise it, for the same reason:
|
||||
it reads and writes the state singleton. Under an open popup the screen is
|
||||
passed to `showView()` only to run the replaced screen's cleanup; from then on
|
||||
`showView()` shows nothing else in that popup.
|
||||
could not be read, and `showView()` is not used to raise it for the same
|
||||
reason — it reads and writes the state singleton.
|
||||
- **Both controls are required.** An export with no reset leaves the user
|
||||
looking at a broken profile with no way to use the wallet again; a reset with
|
||||
no export destroys the only copy of a record that may hold recoverable key
|
||||
material. The typed phrase is the same barrier DeleteWalletLostPassword uses,
|
||||
and for the same reason: there is no password to gate this with, since there
|
||||
is no profile to check one against.
|
||||
- Not in `RESTORABLE_VIEWS`, and never recorded as the current view: the record
|
||||
can become readable again under an open popup, erased in another window, and
|
||||
the next save from that popup then succeeds. A popup opened after that opens
|
||||
normally.
|
||||
- Not in `RESTORABLE_VIEWS`: it is never persisted as the current view, because
|
||||
nothing on this path writes state at all.
|
||||
|
||||
### External Services
|
||||
|
||||
@@ -2218,8 +2112,8 @@ Dev dependencies (not shipped in extension):
|
||||
| Package | Version | License | Purpose |
|
||||
| ------------------ | ------- | ------- | ------------------------- |
|
||||
| `esbuild` | 0.27.3 | MIT | JS bundler (inlines deps) |
|
||||
| `tailwindcss` | 4.3.1 | MIT | CSS compilation |
|
||||
| `@tailwindcss/cli` | 4.3.1 | MIT | Tailwind CLI |
|
||||
| `tailwindcss` | 4.2.1 | MIT | CSS compilation |
|
||||
| `@tailwindcss/cli` | 4.2.1 | MIT | Tailwind CLI |
|
||||
| `jest` | 30.2.0 | MIT | Test runner |
|
||||
| `prettier` | 3.8.1 | MIT | Code formatter |
|
||||
|
||||
@@ -2243,7 +2137,7 @@ a bare string in `manifest/firefox.json` (MV2):
|
||||
|
||||
```
|
||||
default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; object-src 'self';
|
||||
style-src 'self'; img-src 'self' data:;
|
||||
style-src 'self' 'unsafe-inline'; img-src 'self' data:;
|
||||
connect-src 'self' https: http:; frame-src 'none'; form-action 'none';
|
||||
base-uri 'none'
|
||||
```
|
||||
@@ -2255,17 +2149,15 @@ wallet's own UI. Escaping is the primary fix for that (see
|
||||
`src/shared/html.js`); this is the second line, so an escape that does slip
|
||||
cannot reach the network.
|
||||
|
||||
`style-src 'self'` admits the stylesheet and nothing inline: both browsers
|
||||
refuse a `style="..."` attribute and a `<style>` block. So the popup's markup,
|
||||
in `src/popup/index.html` and in the HTML the view helpers build, carries
|
||||
Tailwind classes and never a `style` attribute. Script that sets `element.style`
|
||||
is not affected; that is how the views show and hide their error lines. An
|
||||
inline style that slips in anyway is refused with a console error, which fails
|
||||
both end-to-end suites.
|
||||
|
||||
These directives differ from a plain `'self'`, each for a reason that does not
|
||||
Four directives are looser than `'self'`, each for a reason that does not
|
||||
generalise:
|
||||
|
||||
- `style-src 'unsafe-inline'` — `src/popup/index.html` and the view helpers set
|
||||
presentation through `style="..."` attributes, which CSP blocks without this.
|
||||
Chrome enforces `style-src` on attributes, not only on `<style>` blocks, and
|
||||
Firefox has never implemented `style-src-attr`, so there is no narrower
|
||||
spelling that works on both targets. It permits inline **style**; script stays
|
||||
under `script-src`, which does not allow `'unsafe-inline'`.
|
||||
- `img-src data:` — identicons are generated in the popup by
|
||||
`ethereum-blockies-base64` and assigned to `img.src` as `data:` PNGs.
|
||||
- `connect-src https: http:` — the RPC endpoint is user-configurable and a local
|
||||
@@ -2461,8 +2353,7 @@ indexes it as a real token transfer.
|
||||
act on and what the user believes they own rather than what the history
|
||||
displays. All three surfaces read the rule from `src/shared/symbolSpoof.js`,
|
||||
so they cannot answer the question differently. A symbol the list maps to no
|
||||
contract at all — the native asset's labels: `"ETH"` and every network's
|
||||
`nativeCurrency`, such as `"SepoliaETH"`, on every network — may be borne by
|
||||
contract at all — `"ETH"`, the native asset, is the only one — may be borne by
|
||||
no contract, so every ERC-20 claiming it is a spoof on all three. The user's
|
||||
real ETH balance is not an ERC-20 and is read over RPC, so the rule never sees
|
||||
it.
|
||||
@@ -2471,8 +2362,7 @@ indexes it as a real token transfer.
|
||||
fewer than 1,000 holders are hidden from transaction history by default.
|
||||
Legitimate tokens have substantial holder counts; poisoning tokens typically
|
||||
have zero. This catches new poisoning contracts that use novel symbols not in
|
||||
the known token list. A transfer whose token's holder count is unknown (see
|
||||
Data Model) is kept: only a reported count below 1,000 hides it.
|
||||
the known token list.
|
||||
|
||||
- **Fraud contract blocklist**: AutistMask maintains a local list of known fraud
|
||||
contract addresses. Token transfers involving these contracts are filtered
|
||||
@@ -2482,9 +2372,7 @@ indexes it as a real token transfer.
|
||||
- **Send-side token filtering**: Tokens with fewer than 1,000 holders are
|
||||
excluded from the token selector on the send screen. This prevents users from
|
||||
accidentally interacting with a spoofed token that appeared in their balance
|
||||
via a fake Transfer event. A token whose holder count is unknown is kept in
|
||||
the selector. The selector offers only tokens in the balance list, so such a
|
||||
token is one on the bundled list or one the user tracks.
|
||||
via a fake Transfer event.
|
||||
|
||||
- **Dust transaction filtering**: A second wave of the same attack used real
|
||||
native ETH transfers instead of fake tokens. Transaction
|
||||
@@ -2508,9 +2396,8 @@ indexes it as a real token transfer.
|
||||
both cases identically to the history. The fraud contract blocklist is applied
|
||||
unconditionally on that selector and is not consulted by the balance list at
|
||||
all. The low-holder setting also gates the send selector, while the balance
|
||||
list's own 1,000-holder floor is unconditional (see Data Model). An unknown
|
||||
holder count passes the history and send-selector filters but not that floor.
|
||||
The dust threshold applies to the transaction history alone.
|
||||
list's own 1,000-holder floor is unconditional (see Data Model). The dust
|
||||
threshold applies to the transaction history alone.
|
||||
|
||||
#### Phishing Domain Protection
|
||||
|
||||
|
||||
+82
-353
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Repository Policies
|
||||
last_modified: 2026-10-04
|
||||
last_modified: 2026-07-06
|
||||
---
|
||||
|
||||
This document covers repository structure, tooling, and workflow standards. Code
|
||||
@@ -60,28 +60,17 @@ style conventions are in separate documents:
|
||||
prerequisite since nvm requires bash. yarn is then pinned via
|
||||
`corepack prepare yarn@<version> --activate`. Never install "latest" or "lts";
|
||||
always exact versions. `script/cibuild` runs the CI build: it changes to the
|
||||
repo root, runs `script/bootstrap`, runs `script/check`, and builds the image
|
||||
with the version; the Gitea workflow calls it. **`script/cibuild` runs
|
||||
`script/bootstrap` first**, because the workflow checks out the repo and runs
|
||||
nothing else, while `script/fmt-check` runs the formatter on the host: on a
|
||||
pristine checkout with nothing installed the run dies there, after the
|
||||
containerised gates have passed. **The bootstrap alone is not enough**:
|
||||
`script/bootstrap` installs node and yarn under nvm and leaves neither on the
|
||||
`PATH` of the shell that called it, so a bare `yarn` still exits 127. The host
|
||||
entrypoints that need yarn — `script/fmt` and `script/fmt-check` — therefore
|
||||
source nvm for the pinned node version before invoking it, exactly as
|
||||
`script/bootstrap`'s own install step does. A runner carrying nothing but
|
||||
docker and git then gets through `script/check`. Four further scripts are our
|
||||
own extensions to the standard: `script/check` runs `script/test`,
|
||||
`script/lint` and `script/fmt-check`; `script/precommit` is what the git
|
||||
pre-commit hook runs, and it calls `script/check`; `script/install-precommit`
|
||||
installs the git pre-commit hook (the `make hooks` target shims to it); and
|
||||
`script/projectname` (literally that filename) simply outputs the project's
|
||||
name. Scripts that need the name call `script/projectname` — e.g.
|
||||
`script/docker` assembles its image tag from it — so those scripts stay
|
||||
byte-identical across all repos. Repo-type-specific pre-commit extras (e.g.
|
||||
`go mod tidy` verification in Go repos) belong in `script/precommit`, not in
|
||||
the hook itself. Model scripts are at
|
||||
repo root and runs `docker build .`; the Gitea workflow calls it. Four further
|
||||
scripts are our own extensions to the standard: `script/check` runs
|
||||
`script/test`, `script/lint`, and `script/fmt-check`; `script/precommit` is
|
||||
what the git pre-commit hook runs, and it calls `script/check`;
|
||||
`script/install-precommit` installs the git pre-commit hook (the `make hooks`
|
||||
target shims to it); and `script/projectname` (literally that filename) simply
|
||||
outputs the project's name. Scripts that need the name call
|
||||
`script/projectname` — e.g. `script/docker` assembles its image tag from it —
|
||||
so those scripts stay byte-identical across all repos. Repo-type-specific
|
||||
pre-commit extras (e.g. `go mod tidy` verification in Go repos) belong in
|
||||
`script/precommit`, not in the hook itself. Model scripts are at
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/script/<name>`. The README
|
||||
must document the provided scripts in an **Entrypoints** section (see the
|
||||
README requirements below).
|
||||
@@ -100,198 +89,87 @@ style conventions are in separate documents:
|
||||
contributor should be able to understand the entire development workflow by
|
||||
reading the Makefile.
|
||||
|
||||
- Every repo should have a `Dockerfile`, and it carries the repo's gates: a
|
||||
`lint` phase and a `test` phase, with the final stage depending on both so the
|
||||
image cannot be built unless they pass. For non-server repos the final stage
|
||||
brings up a development environment; for server repos it is the runtime image.
|
||||
The gate phases and the build stage start from their pinned base images and
|
||||
install what those images lack either inline, as the canonical Go `Dockerfile`
|
||||
below does for `git`, or by running `script/bootstrap`, as the `prompts`
|
||||
repo's own `Dockerfile` does for its yarn packages. The development
|
||||
environment stage installs development prerequisites by running
|
||||
`script/bootstrap` rather than duplicating its installs inline. A stage that
|
||||
runs `script/bootstrap` COPYs `script/` and the dependency manifests
|
||||
(`package.json` + `yarn.lock`, `go.mod` + `go.sum`, etc.) before running it.
|
||||
- Every repo should have a `Dockerfile`. All Dockerfiles must run `make check`
|
||||
as a build step so the build fails if the branch is not green. For non-server
|
||||
repos, the Dockerfile should bring up a development environment and run
|
||||
`make check`. For server repos, `make check` should run as an early build
|
||||
stage before the final image is assembled. Dockerfiles install development
|
||||
prerequisites by running `script/bootstrap` rather than duplicating installs
|
||||
inline; COPY `script/` and the dependency manifests (`package.json` +
|
||||
`yarn.lock`, `go.mod` + `go.sum`, etc.) before running it so the bootstrap
|
||||
layer stays cached until dependencies change.
|
||||
|
||||
- **Linting and testing run in Docker, as phases of the `Dockerfile`.** There is
|
||||
no separate lint file. `script/lint` and `script/test` each build one phase
|
||||
and nothing else:
|
||||
- **Dockerfiles must use a separate lint stage for fail-fast feedback.** Go
|
||||
repos use a multistage build where linting runs in an independent stage based
|
||||
on the `golangci/golangci-lint` image (pinned by hash). This stage runs
|
||||
`make fmt-check` and `make lint` before the full build begins. The build stage
|
||||
then declares an explicit dependency on the lint stage via
|
||||
`COPY --from=lint /src/go.sum /dev/null`, which forces BuildKit to complete
|
||||
linting before proceeding to compilation and tests. This ensures lint failures
|
||||
surface in seconds rather than minutes, without blocking on dependency
|
||||
download or compilation in the build stage.
|
||||
|
||||
```sh
|
||||
docker build --no-cache --target lint -t "$(script/projectname)-lint" .
|
||||
docker build --no-cache --target test -t "$(script/projectname)-test" .
|
||||
```
|
||||
|
||||
**A stage that is not the last one in the file is built only when the final
|
||||
stage's chain depends on it, or when `--target` names it.** That is why the
|
||||
two gates are always invoked by name here, and why the final stage carries a
|
||||
`COPY --from=` of a harmless file from each of them: without that edge a
|
||||
plain `docker build .` builds the last stage alone and exits 0 having linted
|
||||
and tested nothing.
|
||||
|
||||
**Every `docker build` in `script/` is tagged**, here and in
|
||||
`script/cibuild` and `script/docker`. An untagged build leaves a dangling
|
||||
image behind on every invocation, on every developer host and every CI
|
||||
runner; a tagged one replaces the previous image.
|
||||
|
||||
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
||||
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
||||
themselves a `docker build` and would recurse into a daemon that does not
|
||||
exist in a build step. Formatting is the exception and stays on the host:
|
||||
`script/fmt` writes the working tree, and `script/fmt-check` is its
|
||||
read-only twin.
|
||||
|
||||
**No lint verdict may come from a host invocation of the linter.** On a
|
||||
shared host golangci-lint reads a result cache keyed on file content rather
|
||||
than location, so a second checkout of the same content is served the first
|
||||
one's findings, and a host-global lock in `$TMPDIR` makes concurrent runs
|
||||
exit non-zero with `parallel golangci-lint is running` — a status a caller
|
||||
cannot tell from real findings. Both have produced wrong verdicts in this
|
||||
org, in both directions. A container has its own cache, its own `TMPDIR` and
|
||||
a digest-pinned binary, so neither is reachable.
|
||||
|
||||
- **Any build that runs checks is built with `--no-cache`.** Docker invalidates
|
||||
a `COPY` layer only when the copied content changes, so on an unchanged tree
|
||||
the check `RUN` is served from cache, nothing executes, and the build still
|
||||
exits 0. Every `docker build` in `script/` therefore passes `--no-cache`:
|
||||
`script/lint`, `script/test`, `script/cibuild` and `script/docker` are the
|
||||
four, and there is no fifth — `script/check` runs the two gate phases and
|
||||
`script/fmt-check`, and builds no image of its own. A bare `docker build .` is
|
||||
not evidence that anything ran: a sub-second build reporting success is a
|
||||
cache hit, not a result. Never invalidate by pruning — `docker builder prune`
|
||||
and friends destroy a build cache shared with every other build on the host.
|
||||
When a check is added or changed, prove it works by planting a defect it must
|
||||
catch and watching the run fail on it, then revert the defect. A green run
|
||||
alone shows neither that the check ran nor that it covers what it should.
|
||||
|
||||
- **The gate phases are separate stages, and the build stage depends on both.**
|
||||
The lint phase is based on the `golangci/golangci-lint` image (pinned by
|
||||
hash), so lint failures surface in seconds rather than after a full compile,
|
||||
and the test phase is based on the Debian Go image. The canonical Go repo
|
||||
`Dockerfile`:
|
||||
The standard pattern for a Go repo Dockerfile is:
|
||||
|
||||
```dockerfile
|
||||
# Lint phase
|
||||
# Lint stage — fast feedback on formatting and lint issues
|
||||
# golangci/golangci-lint:v2.x.x, YYYY-MM-DD
|
||||
FROM golangci/golangci-lint@sha256:... AS lint
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
RUN golangci-lint run --config .golangci.yml ./...
|
||||
RUN make fmt-check
|
||||
RUN make lint
|
||||
|
||||
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
|
||||
# image ships and the alpine one does not.
|
||||
# golang:1.x, YYYY-MM-DD
|
||||
FROM golang@sha256:... AS test
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
RUN go test -timeout 90s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -timeout 90s -race -v ./...; exit 1; }
|
||||
|
||||
# Build stage. Nothing is wanted from either phase above; the copies
|
||||
# are what make BuildKit build them first, so this stage cannot run
|
||||
# unless lint and test passed.
|
||||
# Build stage
|
||||
# golang:1.x-alpine, YYYY-MM-DD
|
||||
FROM golang@sha256:... AS builder
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=test /src/go.sum /dev/null
|
||||
RUN apk add --no-cache git
|
||||
# A tar-stream context keeps the sender's file owners, which git refuses.
|
||||
RUN git config --system --add safe.directory /src
|
||||
WORKDIR /src
|
||||
|
||||
# Force BuildKit to run the lint stage before proceeding
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
RUN make test
|
||||
|
||||
# The VERSION build arg when one is given, otherwise
|
||||
# `git describe --tags --always` on the .git in the build context. With
|
||||
# .git present, a version that is still empty, dev or unknown fails the
|
||||
# build: git is missing or could not read the checkout.
|
||||
ARG VERSION
|
||||
RUN VERSION="${VERSION:-$(git describe --tags --always)}"; \
|
||||
if [ -e .git ]; then \
|
||||
case "$VERSION" in ""|dev|unknown) \
|
||||
echo "version is '$VERSION' although .git is present" >&2; \
|
||||
exit 1 ;; \
|
||||
esac; \
|
||||
fi; \
|
||||
CGO_ENABLED=0 go build -trimpath \
|
||||
ARG VERSION=dev
|
||||
RUN CGO_ENABLED=0 go build -trimpath \
|
||||
-ldflags="-s -w -X main.Version=${VERSION}" \
|
||||
-o /app ./cmd/app/
|
||||
|
||||
# Runtime stage, and the last one
|
||||
# Runtime stage
|
||||
FROM alpine@sha256:...
|
||||
COPY --from=builder /app /usr/local/bin/app
|
||||
ENTRYPOINT ["app"]
|
||||
```
|
||||
|
||||
Key points:
|
||||
- The lint phase uses the `golangci/golangci-lint` image directly (it has
|
||||
both Go and the linter), so nothing needs installing.
|
||||
- `COPY --from=<phase> /src/go.sum /dev/null` is a no-op copy whose only
|
||||
purpose is the ordering edge. BuildKit runs stages in parallel by default,
|
||||
and a stage nothing depends on is not built at all, so without these two
|
||||
lines a red gate would not fail the build.
|
||||
- Keep the runtime stage last, and if you add a stage after it, give it the
|
||||
same two copies. A plain `docker build .` builds the last stage's chain
|
||||
and nothing else.
|
||||
- The lint stage uses the `golangci/golangci-lint` image directly (it
|
||||
includes both Go and the linter), so there is no need to install the
|
||||
linter separately.
|
||||
- `COPY --from=lint /src/go.sum /dev/null` is a no-op file copy that creates
|
||||
a stage dependency. BuildKit runs stages in parallel by default; without
|
||||
this line, the build stage would not wait for lint to finish and a lint
|
||||
failure might not fail the overall build.
|
||||
- If the project uses `//go:embed` directives that reference build artifacts
|
||||
(e.g. a web frontend compiled in a separate stage), the lint phase must
|
||||
(e.g. a web frontend compiled in a separate stage), the lint stage must
|
||||
create placeholder files so the embed directives resolve. Example:
|
||||
`RUN mkdir -p web/dist && touch web/dist/index.html web/dist/style.css`.
|
||||
- If the project requires CGO or system libraries for linting, install them
|
||||
in the lint phase. The `golangci/golangci-lint` image is Debian-based and
|
||||
has no `apk`, so install with `apt-get` under the Debian package name
|
||||
(`libvips-dev`, where alpine says `vips-dev`), and delete the package
|
||||
lists in the same `RUN`, so the layer does not keep them:
|
||||
|
||||
```dockerfile
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends libvips-dev \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
```
|
||||
|
||||
- `.dockerignore` lets `.git` into the build context. It keeps out every git
|
||||
`config` at any depth (`**/.git/config`, `**/.git/modules/**/config`): the
|
||||
repository's own, each submodule's under `.git/modules/`, and that of a
|
||||
submodule keeping its own `.git` directory. `git describe` does not need
|
||||
them, and each can hold a credential: a password in a remote URL, or the
|
||||
token the CI checkout step stores there. A submodule whose name has a
|
||||
`config` segment (`config`, `deploy/config`, `config/lib`) loses its whole
|
||||
git directory to `**/.git/modules/**/config`, and Go's version stamping
|
||||
then fails the build: give it a name without that segment
|
||||
(`git submodule add --name`). The stage that compiles has `git` (the
|
||||
Debian Go image has it; an alpine one needs `apk add --no-cache git`) and
|
||||
takes the version from the `VERSION` build argument when one is given,
|
||||
otherwise from `git describe --tags --always`. That gives the tag on a
|
||||
tagged commit; on a later commit, the tag, the number of commits since it
|
||||
and the short commit (`v1.2.3-4-gabc1234`); and the short commit when no
|
||||
tag is reachable. The stage that compiles also marks its working directory
|
||||
safe for git (`git config --system --add safe.directory /src`): a context
|
||||
sent as a tar stream keeps the sender's file owners, and git refuses a
|
||||
checkout owned by another user, so the version would come out empty.
|
||||
`ARG VERSION` has no default, and the build fails if the context carries
|
||||
`.git` and the version still comes out empty, `dev` or `unknown`. A plain
|
||||
`docker build .` with no build arguments must succeed; a Dockerfile that
|
||||
refuses an empty build argument drops that refusal and keeps the argument.
|
||||
The lint stage should not depend on the actual build output — it exists to
|
||||
fail fast.
|
||||
- If the project requires CGO or system libraries for linting (e.g.
|
||||
`vips-dev`), install them in the lint stage with `apk add`.
|
||||
- The build stage runs `make test` after compilation setup. Tests run in the
|
||||
build stage, not the lint stage, because they may require compiled
|
||||
artifacts or heavier dependencies.
|
||||
|
||||
- Every repo should have a Gitea Actions workflow (`.gitea/workflows/`) that
|
||||
runs `script/cibuild` on push, and checks out the repo as its only other step.
|
||||
That script bootstraps, runs the gate phases, and then builds the image, so a
|
||||
successful run means every check passed; a bare `docker build .` does not
|
||||
carry the same guarantee, because its gate phases may come from the cache. The
|
||||
image build is uncached and so runs the gate phases a second time. That is the
|
||||
price of the rule above, and it is worth paying: the image that ships is built
|
||||
from a run of its own gates rather than from a cache entry. A separate
|
||||
workflow limited to `main` by a `branches` list under `on: push` cannot be
|
||||
checked by review: to try a change to it, add the feature branch to that list
|
||||
and push, then remove the branch from the list again before merging. Keep any
|
||||
job in it that publishes behind `if: github.ref_name == 'main'`, so the run
|
||||
from the feature branch publishes nothing.
|
||||
runs `script/cibuild` (which runs `docker build .`) on push. Since the
|
||||
Dockerfile already runs `make check`, a successful build implies all checks
|
||||
pass.
|
||||
|
||||
- Use platform-standard formatters: `black` for Python, `prettier` for
|
||||
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
|
||||
@@ -311,21 +189,14 @@ style conventions are in separate documents:
|
||||
module under test to verify it compiles/parses. There is no excuse for
|
||||
`make test` to be a no-op.
|
||||
|
||||
- `make test` must complete in under 60 seconds. That is the hard cap, and a
|
||||
suite that exceeds it fails. Under 20 seconds is the target. A suite between
|
||||
20 and 60 seconds is still green, but the overage must be filed as an
|
||||
improvement bug against that repo. Add a 90-second timeout to the test
|
||||
invocation (`go test -timeout 90s`). The backstop deliberately sits above the
|
||||
hard cap so that it catches a genuinely hung test rather than a merely slow
|
||||
one.
|
||||
- `make test` must complete in under 20 seconds. Add a 30-second timeout in the
|
||||
Makefile.
|
||||
|
||||
- **The test command should use the conditional verbose rerun pattern.** Run
|
||||
tests without `-v` (verbose) first. If tests fail, automatically rerun with
|
||||
`-v` to show full output. This keeps CI logs and `docker build` output clean
|
||||
on success (just package/suite summaries) while providing full diagnostic
|
||||
detail on failure (every test case, every assertion). The command lives in the
|
||||
`test` phase of the `Dockerfile`, since `script/test` builds that phase; the
|
||||
Makefile form below is the same pattern for any repo-local invocation:
|
||||
- **`make test` should use the conditional verbose rerun pattern.** Run tests
|
||||
without `-v` (verbose) first. If tests fail, automatically rerun with `-v` to
|
||||
show full output. This keeps CI logs and `docker build` output clean on
|
||||
success (just package/suite summaries) while providing full diagnostic detail
|
||||
on failure (every test case, every assertion). The general shell pattern:
|
||||
|
||||
```makefile
|
||||
test:
|
||||
@@ -338,26 +209,11 @@ style conventions are in separate documents:
|
||||
|
||||
```makefile
|
||||
test:
|
||||
@go test -count=1 -timeout 90s -race -cover ./... || \
|
||||
@go test -timeout 30s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -count=1 -timeout 90s -race -v ./...; exit 1; }
|
||||
go test -timeout 30s -race -v ./...; exit 1; }
|
||||
```
|
||||
|
||||
`-count=1` is required on both invocations: it defeats Go's test _result_
|
||||
cache, so neither run can report a stored pass in place of running the
|
||||
tests. It leaves the build cache alone, so it costs the runtime of the suite
|
||||
and no recompilation.
|
||||
|
||||
That cache is Go's own, separate from Docker's layer cache. Go stores a
|
||||
passing result in its cache directory (`GOCACHE`), and when the same tests
|
||||
run again on unchanged code it prints that result, marked `(cached)`,
|
||||
without running them. That matters on a developer's machine, where this
|
||||
target runs and the directory lasts from one run to the next. The `test`
|
||||
phase of the `Dockerfile` needs no `-count=1`: its base image holds no
|
||||
result for this repo's tests and nothing before its `go test` step runs a
|
||||
test, so there is nothing to replay. `--no-cache` (above) is what makes that
|
||||
step run on an unchanged tree.
|
||||
|
||||
Python example:
|
||||
|
||||
```makefile
|
||||
@@ -383,84 +239,10 @@ style conventions are in separate documents:
|
||||
must be in `.gitignore`. No exceptions.
|
||||
|
||||
- `.gitignore` should be comprehensive from the start: OS files (`.DS_Store`),
|
||||
editor files (`.swp`, `*~`), in-repo agent scratch directories (`.claude/`),
|
||||
language build artifacts, and `node_modules/`. Fetch the standard `.gitignore`
|
||||
from `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` when
|
||||
setting up a new repo. These patterns are written to `.gitignore`'s own
|
||||
semantics, in which an unanchored pattern already matches at every depth; they
|
||||
are not a `.dockerignore` and must not be transplanted into one unmodified.
|
||||
|
||||
- **`.dockerignore` does not use `.gitignore` semantics, and copying patterns
|
||||
across unmodified leaves secrets in the build context.** Docker matches with
|
||||
`moby/patternmatcher`: `filepath.Match` semantics plus a `**` extension, so
|
||||
`*` does not cross `/` and a pattern without a leading `**/` is anchored at
|
||||
the build-context root. A `.dockerignore` listing `.env`, `*.pem` and `*.key`
|
||||
therefore excludes only the copies at the repository root, while `config/.env`
|
||||
and `certs/server.key` still reach the context and can land in an image layer
|
||||
— which is more dangerous than a short file with no secret patterns at all,
|
||||
because it reads as solved and stops anyone looking. Give every
|
||||
depth-independent pattern the `**/` prefix and leave only genuinely
|
||||
root-anchored entries unprefixed: `.claude`, and the repo's own host-built
|
||||
binary, written `/myapp` and never `**/myapp`, which would also match
|
||||
`cmd/myapp/` and delete the package directory from the context. Matching is
|
||||
case-sensitive, and an ALL-CAPS twin per pattern still misses `Server.Key`, so
|
||||
secret names use character ranges — `**/*.[kK][eE][yY]`, `**/*.[pP][eE][mM]`,
|
||||
and likewise for `.envrc` and the extensionless SSH keys. Where such a pattern
|
||||
also catches something the build needs, re-include it with a negation
|
||||
(`!docs/example.env`); deleting the pattern reopens the exposure for every
|
||||
other file it covers. Fetch the standard `.dockerignore` from
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore` and extend
|
||||
it with the repo's own artifacts.
|
||||
|
||||
- **In-repo agent scratch belongs in both files, written to each file's own
|
||||
semantics.** `.claude/` holds one worktree per in-flight agent — an entire
|
||||
additional checkout of the repo — so under `COPY . .` the build context
|
||||
inflates by a multiple of the repo and another session's unreviewed work can
|
||||
be copied into an image layer. In `.gitignore` the entry is `.claude/`,
|
||||
unanchored. In `.dockerignore` it is `.claude`, anchored and with **no** `**/`
|
||||
prefix, because the prefixed form would also delete any nested directory of
|
||||
that name from the build. Anchoring carries a known gap that the canonical
|
||||
`.dockerignore` states in its own comment, since consuming repos receive the
|
||||
file and not the tracker: the directory is created in the agent's working
|
||||
directory, so a repo running agents in subdirectories still ships
|
||||
`services/api/.claude/` and must add its own anchored entry there.
|
||||
|
||||
- **A plain `docker build .` of a clone stamps the version that
|
||||
`git describe --tags --always` gives**, derived from the `.git` in the build
|
||||
context as the canonical `Dockerfile` above shows. Without its failure check,
|
||||
a missing `git` or an unreadable checkout would leave `-X main.Version=` empty
|
||||
and the build would still exit 0. `script/docker` and `script/cibuild` pass
|
||||
the version they compute on the host; it takes precedence. They do this
|
||||
byte-identically across repos:
|
||||
|
||||
```sh
|
||||
# Own line: a failing command substitution inside an argument does not
|
||||
# trip `set -e`, so the inline form degrades to an empty constant.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache \
|
||||
--build-arg VERSION="$version" \
|
||||
-t "$(script/projectname)" .
|
||||
```
|
||||
|
||||
`--always` makes an untagged repo yield an abbreviated commit hash rather
|
||||
than failing, and the `[ -n "$version" ]` line is the single place the
|
||||
fallback is applied — a live check that fires on a build from an export with
|
||||
no `.git` and on a repository with no commits yet. Do not fold it into the
|
||||
substitution as `|| echo unknown`, which makes the guard unreachable. The
|
||||
Dockerfile's side is `ARG VERSION` in the stage that compiles, declared
|
||||
there because `ARG` is stage-scoped; passing `VERSION` to a repo whose
|
||||
Dockerfile declares no such `ARG` is ignored and costs nothing, which is why
|
||||
the scripts stay byte-identical. One consequence for CI: the standard
|
||||
checkout action clones shallow and fetches no tags, so a repo that embeds a
|
||||
tag-derived version must set `fetch-depth: 0` on its checkout step.
|
||||
|
||||
- **Verify `.dockerignore` by enumerating the image, not by reading the
|
||||
patterns.** Plant files at the root _and_ at least two directories deep, build
|
||||
a probe image that does `COPY . .`, and list what actually landed
|
||||
(`docker run --rm --entrypoint find IMAGE /app`). The `transferring context`
|
||||
size is not a substitute: a nested secret is a few bytes, and BuildKit
|
||||
transfers only the delta from the previous build.
|
||||
editor files (`.swp`, `*~`), language build artifacts, and `node_modules/`.
|
||||
Fetch the standard `.gitignore` from
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` when setting up
|
||||
a new repo.
|
||||
|
||||
- **No build artifacts in version control.** Code-derived data (compiled
|
||||
bundles, minified output, generated assets) must never be committed to the
|
||||
@@ -476,56 +258,9 @@ style conventions are in separate documents:
|
||||
- Make all changes on a feature branch. You can do whatever you want on a
|
||||
feature branch.
|
||||
|
||||
- `.golangci.yml` is standardized. The vendored copy in a consuming repo must
|
||||
_NEVER_ be modified by an agent: fetch it from
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml` and keep it
|
||||
byte-identical, so that no repo can quietly loosen its own linting. Linter
|
||||
configuration changes are made to the canonical copy in the `prompts` repo and
|
||||
reach consuming repos by re-vendoring; an agent may open a PR against
|
||||
canonical, which only the user merges. One list is exempt from byte-identity,
|
||||
because it cannot be written once for every repo: the `deny` list of the
|
||||
`test-support` depguard rule, where a repo names its own test-support packages
|
||||
by full import path. A repo adds entries there and changes nothing else, and a
|
||||
re-vendor carries its entries forward. The canonical golangci-lint version is
|
||||
v2.14.0 (released 2026-09-24), pinned as the digest of the lint phase's base
|
||||
image
|
||||
(`golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f`,
|
||||
which reports `2.14.0 built with go1.27.0 from 114493f9`). A module's `go`
|
||||
directive must not name a newer Go minor version than the one golangci-lint
|
||||
was built with, or golangci-lint refuses to lint it: this release lints
|
||||
`go 1.27.1` but not `go 1.28`. That digest is the only pin, since no repo
|
||||
installs golangci-lint on the host. A repo sets the lint phase digest to the
|
||||
one named here and re-vendors `.golangci.yml` in the same commit, whichever of
|
||||
the two prompted the change: the canonical copy can name linters that an older
|
||||
golangci-lint rejects, and a newer golangci-lint can add linters that
|
||||
`default: all` switches on until the canonical copy disables them.
|
||||
|
||||
- **`script/bootstrap` installs a pinned tool by comparing versions, never by
|
||||
testing presence.** An `if ! command -v <tool>; then install; fi` guard tests
|
||||
`PATH` only, so on an already-provisioned machine the pin is inert and a
|
||||
version bump is a silent no-op — while the Dockerfile, installing into a clean
|
||||
image, gets the pinned version, so a local `make check` and `make docker` can
|
||||
disagree about what the tool even is. The canonical form:
|
||||
- compares the installed version against the pin over the **whole** version
|
||||
token; a parser that stops at the first `-` reports `2.12.2` for a host
|
||||
running `2.12.2-rc1` and skips the install;
|
||||
- treats absent, non-zero, empty or unrecognised `--version` output as a
|
||||
mismatch, so the failure direction is a redundant install and never a
|
||||
skipped one;
|
||||
- after installing, re-resolves the binary the way callers do — `hash -r`,
|
||||
then through `PATH`, not through the directory the installer wrote to —
|
||||
and fails naming the resolved path, since an install that a shadowing
|
||||
binary hides succeeds while changing nothing any caller sees;
|
||||
- is actually called, and prints the version on both success paths: a
|
||||
function defined and never invoked has the same exit status and the same
|
||||
empty output as one that worked.
|
||||
|
||||
Keep it POSIX sh: no arrays, no `[[`, no `grep -P`.
|
||||
|
||||
A Go tool a repo needs on the host is installed with `go install` pinned to
|
||||
a commit hash (`go install <package>@<commit hash>`). It is never tracked as
|
||||
a `go.mod` tool dependency or through a `tools.go` file, either of which
|
||||
pulls the tool's own dependencies into the repo's `go.mod` and `go.sum`.
|
||||
- `.golangci.yml` is standardized and must _NEVER_ be modified by an agent, only
|
||||
manually by the user. Fetch from
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.golangci.yml`.
|
||||
|
||||
- When pinning images or packages by hash, add a comment above the reference
|
||||
with the version and date (YYYY-MM-DD).
|
||||
@@ -639,14 +374,12 @@ style conventions are in separate documents:
|
||||
settings.
|
||||
|
||||
- Avoid putting files in the repo root unless necessary. Root should contain
|
||||
only project-level config files (`README.md`, `AGENTS.md`, `Makefile`,
|
||||
`Dockerfile`, `LICENSE`, `.gitignore`, `.editorconfig`, `REPO_POLICIES.md`,
|
||||
and language-specific config). Everything else goes in a subdirectory.
|
||||
Canonical subdirectory names:
|
||||
only project-level config files (`README.md`, `Makefile`, `Dockerfile`,
|
||||
`LICENSE`, `.gitignore`, `.editorconfig`, `REPO_POLICIES.md`, and
|
||||
language-specific config). Everything else goes in a subdirectory. Canonical
|
||||
subdirectory names:
|
||||
- `bin/` — executable scripts and tools
|
||||
- `cmd/` — Go command entrypoints; thin only: one `main.go` per binary whose
|
||||
body is a single call into `internal/` or `pkg/`, no project logic in
|
||||
`cmd/`
|
||||
- `cmd/` — Go command entrypoints
|
||||
- `configs/` — configuration templates and examples
|
||||
- `deploy/` — deployment manifests (k8s, compose, terraform)
|
||||
- `docs/` — documentation and markdown (README.md stays in root)
|
||||
@@ -673,7 +406,3 @@ style conventions are in separate documents:
|
||||
- Go: `go.mod`, `go.sum`, `.golangci.yml`
|
||||
- JS: `package.json`, `yarn.lock`, `.prettierrc`, `.prettierignore`
|
||||
- Python: `pyproject.toml`
|
||||
|
||||
- Guidance for coding agents lives in one `AGENTS.md` at the repository root. It
|
||||
is never committed under a file or directory named after one agent tool, such
|
||||
as `CLAUDE.md` or `.claude/`, and never split into separate memory files.
|
||||
|
||||
@@ -45,323 +45,13 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-06: The private key export screen opens again in the same popup
|
||||
session ([#460](https://git.eeqj.de/sneak/AutistMask/issues/460)). `show()`
|
||||
found the address line through the element inside it, which its own rendering
|
||||
replaced, so the second open threw before it navigated. The line now carries
|
||||
the `export-privkey-address` id itself. `tests/exportPrivkey.test.js` opens
|
||||
the screen twice, its DOM stub now takes an element out of the document when
|
||||
its parent's contents are replaced, and the `#253` e2e case no longer reopens
|
||||
the popup before its second open.
|
||||
|
||||
- 2026-10-06: The canonical files are re-vendored from `sneak/prompts` at
|
||||
`dd4027b` ([#472](https://git.eeqj.de/sneak/AutistMask/issues/472)). The
|
||||
`Dockerfile` has separate `lint` and `test` phases, and its last stage depends
|
||||
on both before it runs `make build`. `script/lint` and `script/test` each
|
||||
build one phase, uncached. `script/check-censored` runs in the `lint` phase
|
||||
and `script/test-verify-build` in the `test` phase. `script/check` runs the
|
||||
two phases and `script/fmt-check`. `script/cibuild` bootstraps, runs
|
||||
`script/check`, then builds the image uncached. Given no `VERSION` build
|
||||
argument, as in a plain `docker build .`, the image build takes one from
|
||||
`git describe` on the `.git` in the build context, which `.dockerignore` now
|
||||
sends without its `config`. The vendored `check.yml` has no `timeout-minutes`,
|
||||
so the `check` job's cap is gone.
|
||||
|
||||
- 2026-10-06: Reloading or closing the popup mid-refresh no longer logs the
|
||||
requests that cancels as failures
|
||||
([#218](https://git.eeqj.de/sneak/AutistMask/issues/218)). Chrome cancels a
|
||||
closing page's open requests just after `pagehide`, and in the page a
|
||||
cancelled `fetch()` fails with the same "Failed to fetch" as a server that
|
||||
cannot be reached, so the home screen's transaction list and the balance
|
||||
refresh logged an error for each, and the e2e suite failed on them. The popup
|
||||
now aborts an `AbortController` on `pagehide`, and those two check its signal
|
||||
before reporting a failure. New e2e tests reload the popup with Blockscout
|
||||
held and require nothing logged, and fail the transaction list for real and
|
||||
require the failure reported; `tests/balanceRefreshCancelled.test.js` covers
|
||||
the balance refresh. The address and token screens and the address scan after
|
||||
a new wallet still log a cancelled request
|
||||
([#475](https://git.eeqj.de/sneak/AutistMask/issues/475)).
|
||||
|
||||
- 2026-10-05: `make build` no longer prints the Node `DEP0205`
|
||||
`module.register()` deprecation warning
|
||||
([#355](https://git.eeqj.de/sneak/AutistMask/issues/355)). The call came from
|
||||
`@tailwindcss/node`, which the Tailwind CLI loads; `tailwindcss` and
|
||||
`@tailwindcss/cli` are now pinned at 4.3.1, the first release that uses
|
||||
`module.registerHooks()` where Node has it. The compiled CSS computes to the
|
||||
same values; it drops the unused `.start` and `.end` rules and writes
|
||||
`calc(var(--spacing) * 1)` as `var(--spacing)` and `calc(var(--spacing) * 0)`
|
||||
as `0`.
|
||||
|
||||
- 2026-10-05: `make dev` watches
|
||||
([#332](https://git.eeqj.de/sneak/AutistMask/issues/332)). It used to pass
|
||||
`--watch` to a `build.js` that read no arguments, so it built once and exited.
|
||||
`build.js --watch` now builds, then builds again after every change to a file
|
||||
under `src/`, `manifest/` or `icons/`; any other argument fails. It watches
|
||||
each directory rather than using Node's recursive watch, which on Linux stops
|
||||
seeing a file an editor saves by renaming a new copy over it. It writes no
|
||||
build receipt, so nothing can verify what it builds; `make build` remains the
|
||||
way to produce a `dist/` to hand on. `tests/buildWatch.test.js` covers the
|
||||
watch loop against a temp directory.
|
||||
|
||||
- 2026-10-05: Every CI job has a `timeout-minutes` cap
|
||||
([#294](https://git.eeqj.de/sneak/AutistMask/issues/294)): `check` 10 minutes,
|
||||
`e2e-firefox` 15 and `e2e-chrome` 20, each over two and a half times the job's
|
||||
slowest cold-cache run. A hung build or browser now ends its job instead of
|
||||
holding the shared runner for hours.
|
||||
|
||||
- 2026-10-05: `PROXY_METHODS` in `src/background/index.js` no longer lists
|
||||
`eth_chainId` and `net_version`
|
||||
([#326](https://git.eeqj.de/sneak/AutistMask/issues/326)). `handleRpc` answers
|
||||
both itself before its proxy branch, so the list named two methods that are
|
||||
never sent to the RPC endpoint. No other entry is answered earlier.
|
||||
`tests/proxyMethods.test.js` sends every listed method from a page and fails
|
||||
on any that does not reach the RPC endpoint.
|
||||
|
||||
- 2026-10-05: The popup's Content Security Policy no longer allows inline style
|
||||
([#328](https://git.eeqj.de/sneak/AutistMask/issues/328)): `style-src` is
|
||||
`'self'` in both manifests, pinned in `tests/manifest.test.js`. The 42
|
||||
`style="..."` attributes in `src/popup/index.html` and in the markup the view
|
||||
helpers build are now Tailwind classes, each computing to the value it
|
||||
replaced. The 16 address dot colours are written out as whole classes, because
|
||||
Tailwind builds only the classes it finds in the source. The Settings debug
|
||||
well is shown and hidden with the `hidden` class, since clearing an inline
|
||||
`display` no longer uncovers it. Script that sets `element.style` is
|
||||
unaffected.
|
||||
|
||||
- 2026-10-05: `.prettierignore` no longer lists an AI vendor's tool directory
|
||||
([#363](https://git.eeqj.de/sneak/AutistMask/issues/363)). The directory is
|
||||
not tracked, so the line ignored nothing.
|
||||
|
||||
- 2026-10-05: The Chrome end-to-end suite drives both ways the wait for a
|
||||
transaction's receipt ends on the error screen
|
||||
([#315](https://git.eeqj.de/sneak/AutistMask/issues/315)): lookups that still
|
||||
find no receipt 60 seconds after the broadcast end it with the timeout
|
||||
message, and six lookups that fail in a row end it with the message naming the
|
||||
unreachable network. Done then returns to the address screen. Both cases wait
|
||||
in real time, about a minute each. Playwright's clock would apply to every
|
||||
later test in the run and cannot be removed, and moving the stored broadcast
|
||||
time back can be undone by the save the popup makes every ten seconds.
|
||||
|
||||
- 2026-10-05: The Chrome end-to-end suite covers the last of the
|
||||
[#150](https://git.eeqj.de/sneak/AutistMask/issues/150) and
|
||||
[#151](https://git.eeqj.de/sneak/AutistMask/issues/151) items
|
||||
([#295](https://git.eeqj.de/sneak/AutistMask/issues/295)): a token added on
|
||||
Add Token by its contract address is listed on the address screen;
|
||||
TransactionDetail opened from the token screen leaves that screen on the
|
||||
persisted navigation stack, and Back returns to it; and the token contract row
|
||||
links to the explorer's token page, read off the link rather than followed.
|
||||
The network stub answers `symbol()` and `name()` for the stub token, which
|
||||
adding it reads.
|
||||
|
||||
- 2026-10-05: Each control that leads to a signature or to the private key has a
|
||||
test that it refuses a defective wallet before asking for a password
|
||||
([#254](https://git.eeqj.de/sneak/AutistMask/issues/254)): Send on the main,
|
||||
address and token screens, Export Private Key, and both approval screens, as
|
||||
drawn and as clicked. Send on the confirmation screen refuses it too now,
|
||||
because the popup reopens onto that screen from a saved view. The comments
|
||||
that said the wallet's key cannot be derived now say that
|
||||
`getSignerForAddress` refuses it, and the module comment in
|
||||
`src/shared/walletDefects.js` names both earlier import paths.
|
||||
|
||||
- 2026-10-05: The Chrome end-to-end suite drives the private key export screen
|
||||
as it drives the recovery phrase screen
|
||||
([#253](https://git.eeqj.de/sneak/AutistMask/issues/253)): the correct
|
||||
password shows the key, leaving by the settings gear empties the screen, and
|
||||
leaving while the password is still being checked never puts the key on it.
|
||||
The cases use the imported key wallet rather than the HD one. Leaving drops
|
||||
the address the screen was showing, and an HD wallet's key cannot be derived
|
||||
without it, so on an HD wallet a late decrypt fails by itself and would never
|
||||
exercise the check that discards it. The screen cannot yet be opened twice in
|
||||
one popup session ([#460](https://git.eeqj.de/sneak/AutistMask/issues/460)),
|
||||
so the cases reopen the popup before the second open.
|
||||
|
||||
- 2026-10-05: The StateRecovery screen is driven in a real browser under the
|
||||
shipped CSP, in both end-to-end suites
|
||||
([#361](https://git.eeqj.de/sneak/AutistMask/issues/361)). A stored record
|
||||
this build cannot read opens the popup on it; its export text box holds the
|
||||
record exactly as stored; a near-miss confirmation phrase erases nothing; and
|
||||
the exact phrase erases the record and reloads into Welcome. The cases run
|
||||
before any wallet exists: with no wallet nothing saves on a timer, so no save
|
||||
can write a good record over the unreadable one, and the erase leaves the
|
||||
popup on Welcome for wallet creation.
|
||||
|
||||
- 2026-10-05: Escaping in the popup's views follows its own rule with no
|
||||
exceptions ([#329](https://git.eeqj.de/sneak/AutistMask/issues/329)). The
|
||||
decimals and holder count on a token's screen, and every USD figure (the ETH
|
||||
price, each total and each balance row's value), went into `innerHTML`
|
||||
unescaped; they are escaped now. None could carry markup, but `formatUsd()`
|
||||
writes a value under a cent as `< $0.01`. `displaySymbol()` counts a symbol in
|
||||
code points rather than UTF-16 units, so a cut never splits an emoji into a
|
||||
half that renders as U+FFFD. `explorerLink()`, also named in the issue, was
|
||||
already removed by [#168](https://git.eeqj.de/sneak/AutistMask/issues/168).
|
||||
|
||||
- 2026-10-05: A Chrome end-to-end test that fails no longer takes later tests
|
||||
down with it ([#318](https://git.eeqj.de/sneak/AutistMask/issues/318)). Each
|
||||
test that turns a fixture switch on for itself alone (a held or failing gas
|
||||
estimate, a seeded native transfer or receipt, a token's lying `decimals()` or
|
||||
markup symbol) turns it off again in a `finally`, and the two tests that drive
|
||||
the popup's own send end on the address screen whether they pass or not,
|
||||
reopening the popup to leave a wait for a receipt. The lying-`decimals()` test
|
||||
checks that nothing was broadcast as soon as the send ends, before it waits
|
||||
for the failure screen, so a broadcast fails it in seconds rather than after a
|
||||
60-second wait. The fixture's `decimals()` override tells 0 from no override,
|
||||
so a token with no decimal places can be fixtured.
|
||||
|
||||
- 2026-10-05: Chrome draws the popup in its monospace font
|
||||
([#418](https://git.eeqj.de/sneak/AutistMask/issues/418)), as Firefox does.
|
||||
Chrome adds a stylesheet of its own to extension pages that sets the font on
|
||||
`body`, and it beat Tailwind's `font-mono`: Tailwind 4 puts its classes in a
|
||||
cascade layer, and a rule outside any layer wins over them. `body` now carries
|
||||
`font-mono!`, which marks the class important. Both end-to-end suites check
|
||||
the popup's font. The same stylesheet also makes Chrome draw the popup's text
|
||||
at 12px rather than the 14px `text-sm` asks for; that is unchanged, and filed
|
||||
as [#456](https://git.eeqj.de/sneak/AutistMask/issues/456).
|
||||
|
||||
- 2026-10-05: Dead code removed and copied view helpers shared
|
||||
([#168](https://git.eeqj.de/sneak/AutistMask/issues/168)). AddressDetail and
|
||||
AddressToken each defined their own `isoDate()` and `timeAgo()` in place of
|
||||
the ones in `src/popup/views/helpers.js`, so a fix to the shared pair would
|
||||
not have reached them. The copies were identical; every screen now uses the
|
||||
shared pair. `blockieHtml()` and `tokenLabel()`, each defined twice, live in
|
||||
`helpers.js` too. Removed as never called: `explorerLink()` (the views build
|
||||
explorer links with `explorerUrl()`), `ETHEREUM_SEPOLIA_CHAIN_ID` (the chain
|
||||
id lives in `src/shared/networks.js`), and `getWalletValue()` and
|
||||
`getTotalValue()`: Home's "Total:" is the active address's total, as
|
||||
`README.md` says. `addressColor()` and `etherscanAddressUrl()` are no longer
|
||||
exported. Nothing the user sees changed.
|
||||
|
||||
- 2026-10-05: A prompt raised while another approval window has focus opens a
|
||||
window of its own ([#290](https://git.eeqj.de/sneak/AutistMask/issues/290)).
|
||||
The background centred each approval window on the last focused window, which
|
||||
could be an earlier approval window still open; headless Chrome reports one as
|
||||
1280x720, so the new window came out where the browser refused to create it,
|
||||
and the request failed with no window at all. It now centres only on a browser
|
||||
window, and when the browser refuses the position it asks again without one
|
||||
and lets the browser place the window. In the Chrome end-to-end suite a test
|
||||
could raise its prompt while the previous test's window was still closing, and
|
||||
then either hit that refusal or take the closing window for its own. After a
|
||||
test that passed, the runner now waits a few seconds for approval windows to
|
||||
close and fails the test if one is still open; after a test that failed, it
|
||||
closes them.
|
||||
|
||||
- 2026-10-05: The Send screen has a "Max" button
|
||||
([#198](https://git.eeqj.de/sneak/AutistMask/issues/198)). Emptying an ETH
|
||||
address took guessing an amount and being refused by the confirmation screen's
|
||||
balance check. Max fills in a token's whole balance, cut to the 18 decimal
|
||||
places the confirmation screen accepts, or for ETH the exact balance minus the
|
||||
fee reserve that check gates on, never the four-decimal balance shown; a fee
|
||||
estimate that finishes after the Send screen was left, or its address, holding
|
||||
or recipient changed, fills nothing in. The confirmation screen works a max
|
||||
ETH amount out again from its own fee estimate and signs it with that
|
||||
estimate's fee fields: fetched again at signing, a fee that had risen since
|
||||
would leave amount plus fee above the balance, and the node would refuse the
|
||||
send. A token's maximum is still refused when ETH cannot pay the fee. Where
|
||||
there is nothing to fill in, a flash message says why.
|
||||
|
||||
- 2026-10-05: A token scale of zero decimals is tested
|
||||
([#325](https://git.eeqj.de/sneak/AutistMask/issues/325)).
|
||||
`resolveTokenDecimals()` already used a scale of 0 from the bundled list or
|
||||
from a tracked token, but no test said so: turning either of its `d !== null`
|
||||
checks into a plain truthiness check left every test green while a
|
||||
zero-decimal token fell through to the next source, or to "decimals unknown".
|
||||
The approval tests now assert a scale of 0 from each of those two sources,
|
||||
both where it is resolved and on the approval screen's Amount line. The second
|
||||
half of the issue, one shared `toDecimals()`, had already landed with
|
||||
[#349](https://git.eeqj.de/sneak/AutistMask/issues/349).
|
||||
|
||||
- 2026-10-05: The e2e suite waits for a save to land before it closes the popup
|
||||
([#446](https://git.eeqj.de/sneak/AutistMask/issues/446)). The Settings round
|
||||
trip switched the theme and the network and closed the popup at once, and a
|
||||
close before the save lands loses the switch; with the network left on
|
||||
Sepolia, a dozen later tests failed too. Each Settings switch and spam-filter
|
||||
toggle is now waited for in storage before the close, and `reopenPopup()`
|
||||
waits until the view it expects to reopen on is the saved one. The restore
|
||||
half of the round trip and the second filter toggle change a setting right
|
||||
after a reopen, while the reopened popup's own saves may still be running;
|
||||
they rely on the fix for
|
||||
[#448](https://git.eeqj.de/sneak/AutistMask/issues/448).
|
||||
|
||||
- 2026-10-05: A change made while an earlier save from the same page is still
|
||||
running is stored ([#448](https://git.eeqj.de/sneak/AutistMask/issues/448)).
|
||||
`saveStateOnce()` took its baseline from the page's state after the write, so
|
||||
a change made while the save waited on storage counted as already stored and
|
||||
the save queued after it wrote nothing. A setting changed during the read was
|
||||
lost; so was a wallet added, a site revoked or an endpoint changed during the
|
||||
write, and a wallet deleted then stayed in storage. The save now copies the
|
||||
page's fields when it starts, writes from that copy, and keeps the copy as the
|
||||
baseline.
|
||||
|
||||
- 2026-10-05: The extension no longer opens a window for a site-connection
|
||||
prompt already answered
|
||||
([#287](https://git.eeqj.de/sneak/AutistMask/issues/287)). When the prompt was
|
||||
decided before the toolbar popup raised for it had loaded, that popup was torn
|
||||
down, `chrome.action.openPopup()` rejected, and the background opened its
|
||||
fallback window for the answered approval and then removed it. In the Chrome
|
||||
end-to-end suite the next test could take that window for its own prompt and
|
||||
lose it under its wait. `openApprovalWindow()` now opens nothing for an
|
||||
approval that is no longer pending. The blocklist test's Reject, whose window
|
||||
closes itself, is clicked as the other site Reject is, with the click
|
||||
witnessed. Making `e2e-chrome` a required check is still blocked: other
|
||||
reports of the Chrome suite failing under load are open, among them
|
||||
[#290](https://git.eeqj.de/sneak/AutistMask/issues/290) and
|
||||
[#446](https://git.eeqj.de/sneak/AutistMask/issues/446), as `README.md` says.
|
||||
|
||||
- 2026-10-05: The lost-password delete confirmation refuses an empty field and
|
||||
ignores characters that paint nothing
|
||||
([#336](https://git.eeqj.de/sneak/AutistMask/issues/336)). A wallet named only
|
||||
with spaces compared equal to an empty field, so typing nothing would have
|
||||
deleted it, and a zero-width space in a name made the name impossible to type
|
||||
back. An empty field is now refused whatever the name is, the same invisible
|
||||
characters `src/shared/symbolSpoof.js` strips are removed from both sides, and
|
||||
a name that shows nothing is shown and typed back as "Wallet N".
|
||||
|
||||
- 2026-10-05: A `holders_count` that is not a whole number in plain digits is
|
||||
unknown, not read in part
|
||||
([#251](https://git.eeqj.de/sneak/AutistMask/issues/251)). `parseInt` read
|
||||
`1,000` as 1, `0x10` as 0 and `1e3` as 1, a reported low count that hides the
|
||||
token in the transaction history and the send-screen token selector. A count
|
||||
above `Number.MAX_SAFE_INTEGER` is unknown too, not rounded or `Infinity`. The
|
||||
balance list's `holders !== null` check, which did nothing, is dropped.
|
||||
`README.md` and `docs/README.md` now say how each filter treats an unknown
|
||||
count and that the token screen leaves out its "Holders:" row then, and
|
||||
`README.md` lists `src/shared/holders.js`.
|
||||
|
||||
- 2026-10-04: A popup boot in the tests loads transactions without failing
|
||||
([#429](https://git.eeqj.de/sneak/AutistMask/issues/429)). The stand-in for
|
||||
`filterTransactions` in `tests/support/popupBoot.js` returned a bare list,
|
||||
while the real one returns `{ transactions, newFraudContracts }`, so every
|
||||
boot onto Home, AddressDetail or AddressToken failed inside its transaction
|
||||
loading and logged `loadHomeTxs failed` or `loadTransactions failed`; the rest
|
||||
of that code never ran. The stand-in now returns the real shape, and
|
||||
`tests/persistedFieldContract.test.js` boots onto each of the three and
|
||||
asserts neither message is logged. `make test` time did not change measurably.
|
||||
|
||||
- 2026-10-04: The native token's label follows the network
|
||||
- 2026-10-04: The native token's label follows the active network
|
||||
([#372](https://git.eeqj.de/sneak/AutistMask/issues/372)). `networks.js` gives
|
||||
each network a `nativeCurrency` and nothing read it: every screen wrote `ETH`,
|
||||
so on Sepolia the balance, the value and the fee all read `ETH`. Every native
|
||||
figure now reads `nativeCurrency`, which is `ETH` on mainnet and `SepoliaETH`
|
||||
on Sepolia: the balance lists, Send and confirmation screens and the
|
||||
contract-recipient warning the active network's; the approval, wait, success,
|
||||
error and transaction detail screens, the transaction history and the refusal
|
||||
of a fee above the limit that of the network the transaction's chain id names.
|
||||
A token claiming any network's `nativeCurrency` is dropped as a fake, as one
|
||||
claiming `ETH` already was, and the transaction detail screen calls an entry a
|
||||
token transfer when it has a token contract, not by its symbol.
|
||||
- 2026-10-04: A popup that is already open when the stored profile becomes
|
||||
unreadable moves to the recovery screen
|
||||
([#373](https://git.eeqj.de/sneak/AutistMask/issues/373)). It used to stay on
|
||||
the last good profile, with the "NOT SAVED" banner at most, until reopened.
|
||||
Every save already ran the check the popup runs at open, so the popup finds
|
||||
the record at the next navigation or ten-second refresh, whether or not the
|
||||
network answers; a save that fails that check now raises the recovery screen
|
||||
and stops the refresh. The screen it replaces is left as any navigation leaves
|
||||
it, so a revealed phrase or key or a typed password is wiped. Once up, nothing
|
||||
else in that popup can replace it, and a later save or a transaction wait that
|
||||
ends does not clear an export or a typed confirmation. It is never saved as
|
||||
the current view, so a popup opened after the record is erased in another
|
||||
window opens normally. Any other failed save still gets the banner and leaves
|
||||
the screen alone.
|
||||
so on Sepolia the balance, the value and the fee all read `ETH`. The balance
|
||||
lists, Send, confirmation, approval, wait, success and error screens, and the
|
||||
transaction history now read `nativeCurrency`, which is `ETH` on mainnet and
|
||||
`SepoliaETH` on Sepolia.
|
||||
- 2026-10-04: A swap whose deadline is later than a JavaScript date can hold is
|
||||
decoded ([#437](https://git.eeqj.de/sneak/AutistMask/issues/437)). A date
|
||||
reaches only to 275760-09-13, so a later deadline, such as the `uint256`
|
||||
|
||||
@@ -15,15 +15,6 @@ const DIST_CHROME = path.join(DIST, "chrome");
|
||||
const DIST_FIREFOX = path.join(DIST, "firefox");
|
||||
const SRC = path.join(__dirname, "src");
|
||||
|
||||
// What `make dev` watches: the directories whose files build() bundles,
|
||||
// compiles or copies. A change anywhere else, package.json and build.js
|
||||
// included, starts no build; restart make dev after one.
|
||||
const WATCHED_DIRS = [
|
||||
SRC,
|
||||
path.join(__dirname, "manifest"),
|
||||
path.join(__dirname, "icons"),
|
||||
];
|
||||
|
||||
// The module whose compiled DEBUG state script/verify-build asserts. Which
|
||||
// bundles contain it is derived from esbuild's own dependency graph rather
|
||||
// than from a hardcoded list, so it tracks the bundle layout instead of
|
||||
@@ -40,7 +31,7 @@ const AUDITED_MODULE = "src/shared/constants.js";
|
||||
// the build, whether or not a text matcher would have recognized it. A
|
||||
// background entry point the table does not name fails as well, so a second
|
||||
// worker is protected by default rather than by someone remembering this file.
|
||||
// The Dockerfile's last stage runs `make build`, so it is enforced in CI.
|
||||
// Dockerfile:42 runs `make build`, so it is enforced in CI.
|
||||
|
||||
// The build receipt: every file this build emits, with its sha256 and whether
|
||||
// it is one of the audited bundles. script/verify-build is handed this and
|
||||
@@ -450,10 +441,6 @@ function getBuildInfo() {
|
||||
async function build() {
|
||||
console.log("Building AutistMask extension...");
|
||||
|
||||
// Under make dev this runs once per rebuild in the same process, and each
|
||||
// build accounts only for what it emits itself.
|
||||
emittedFiles.length = 0;
|
||||
|
||||
const receiptPath = receiptTarget();
|
||||
if (!receiptPath) {
|
||||
console.warn(
|
||||
@@ -610,74 +597,10 @@ async function build() {
|
||||
console.log("Build complete: dist/chrome/ and dist/firefox/");
|
||||
}
|
||||
|
||||
// make dev: build, then build again after every change under `dirs`, until
|
||||
// interrupted. A failed build is reported and watching carries on, so a
|
||||
// half-finished edit does not end it. A change that arrives while a build is
|
||||
// running is not lost: it causes one more build as soon as that one finishes.
|
||||
// A directory created after this starts is not watched until a restart.
|
||||
//
|
||||
// make dev sets no AUTISTMASK_BUILD_RECEIPT, so these builds write no receipt
|
||||
// and nothing can verify what they leave in dist/.
|
||||
//
|
||||
// `rebuild` is build() everywhere but tests/buildWatch.test.js, which also
|
||||
// closes the returned watchers.
|
||||
function watch(dirs, rebuild) {
|
||||
let building = false;
|
||||
let changedAgain = false;
|
||||
|
||||
async function run() {
|
||||
if (building) {
|
||||
changedAgain = true;
|
||||
return;
|
||||
}
|
||||
building = true;
|
||||
do {
|
||||
// Let the rest of one save's events arrive first, so that one
|
||||
// save is one build.
|
||||
await new Promise((resolve) => setTimeout(resolve, 100));
|
||||
changedAgain = false;
|
||||
try {
|
||||
await rebuild();
|
||||
} catch (err) {
|
||||
console.error(
|
||||
`Build failed: ${err && err.message ? err.message : err}`,
|
||||
);
|
||||
}
|
||||
} while (changedAgain);
|
||||
building = false;
|
||||
console.log("Watching for changes (Ctrl-C to stop)...");
|
||||
}
|
||||
|
||||
// One watcher per directory rather than fs.watch's recursive option: on
|
||||
// Linux, Node's recursive watch watches each file, and stops seeing one
|
||||
// that an editor saves by renaming a new copy over it. A directory's
|
||||
// watcher reports every change to the files in it, however they are saved.
|
||||
const subdirectories = dirs.flatMap((dir) =>
|
||||
fs
|
||||
.readdirSync(dir, { recursive: true, withFileTypes: true })
|
||||
.filter((entry) => entry.isDirectory())
|
||||
.map((entry) => path.join(entry.parentPath, entry.name)),
|
||||
);
|
||||
const watchers = [...dirs, ...subdirectories].map((dir) =>
|
||||
fs.watch(dir, run),
|
||||
);
|
||||
run();
|
||||
return watchers;
|
||||
}
|
||||
|
||||
// Run only as a program. Required as a module — which is how
|
||||
// tests/buildForbiddenInputs.test.js and tests/buildWatch.test.js reach the
|
||||
// functions below — this file builds nothing and writes nothing.
|
||||
// tests/buildForbiddenInputs.test.js reaches the checks below — this file
|
||||
// builds nothing and writes nothing.
|
||||
if (require.main === module) {
|
||||
const args = process.argv.slice(2);
|
||||
// An argument this file does not know fails rather than being ignored.
|
||||
if (args.length > 1 || (args.length === 1 && args[0] !== "--watch")) {
|
||||
console.error("usage: node build.js [--watch]");
|
||||
process.exit(2);
|
||||
}
|
||||
if (args[0] === "--watch") {
|
||||
watch(WATCHED_DIRS, build);
|
||||
} else {
|
||||
build().catch((err) => {
|
||||
console.error(
|
||||
`Build failed: ${err && err.message ? err.message : err}`,
|
||||
@@ -685,19 +608,16 @@ if (require.main === module) {
|
||||
process.exit(1);
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
// Exported for tests only: watch() for tests/buildWatch.test.js, the rest for
|
||||
// tests/buildForbiddenInputs.test.js. The prohibition those enforce is the
|
||||
// guarantee behind https://git.eeqj.de/sneak/AutistMask/issues/324, and
|
||||
// `make check` does not run `make build` — so they are unit tested against
|
||||
// synthetic metafiles rather than being exercised only by CI, where "it ran"
|
||||
// is not "it works".
|
||||
// Exported for tests/buildForbiddenInputs.test.js only. The prohibition these
|
||||
// three functions enforce is the guarantee behind
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/324, and `make check` does not
|
||||
// run `make build` — so they are unit tested against synthetic metafiles
|
||||
// rather than being exercised only by CI, where "it ran" is not "it works".
|
||||
module.exports = {
|
||||
importChain,
|
||||
newForbiddenRecord,
|
||||
recordBundledInputs,
|
||||
assertNoForbiddenInputs,
|
||||
assertForbiddenTableCovered,
|
||||
watch,
|
||||
};
|
||||
|
||||
+2
-10
@@ -240,9 +240,7 @@ screen. Tokens can also be added from Settings, under "Tracked Tokens".
|
||||
2. Select what to send (ETH, or any ERC-20 token with a balance on this address
|
||||
that survives the spam filters).
|
||||
3. Enter the recipient address or ENS name (e.g. `vitalik.eth`).
|
||||
4. Enter the amount, or click "Max" to fill it in: a token's balance, cut to 18
|
||||
decimal places, or your ETH balance minus the amount reserved for the network
|
||||
fee.
|
||||
4. Enter the amount.
|
||||
5. Click "Review" to see the confirmation screen.
|
||||
|
||||
The confirmation screen shows:
|
||||
@@ -335,13 +333,7 @@ it is hidden from your transaction history and from the send token list.
|
||||
from transaction history and the send token list, and are left out of your
|
||||
balances unless they are on the bundled known-token list or you added them
|
||||
yourself. Legitimate tokens have substantial holder counts; scam tokens deployed
|
||||
for address poisoning typically have zero. When the explorer reports no holder
|
||||
count for a token, or reports something other than a whole number in plain
|
||||
digits (such as "1,000"), the count is unknown. An unknown count does not hide a
|
||||
token from your transaction history or the send token list, and it does not get
|
||||
a token into your balances either: such a token is listed only if it is on the
|
||||
bundled known-token list or you added it yourself. The screen you reach by
|
||||
clicking a token balance shows a "Holders:" line only when the count is known.
|
||||
for address poisoning typically have zero.
|
||||
|
||||
**Fraud contract blocklist.** When AutistMask detects a fraudulent transfer, it
|
||||
adds the contract address to a local blocklist. Future transactions from that
|
||||
|
||||
+3
-3
@@ -16,9 +16,9 @@ so the "release commit" throughout is the `main` commit the milestone PR merged.
|
||||
## Procedure
|
||||
|
||||
1. **Confirm `main` is green in CI.** The `check` workflow
|
||||
(`.gitea/workflows/check.yml`) runs `script/cibuild`, which runs
|
||||
`script/check` and then builds the image uncached, so a green `check` run is
|
||||
a green `make check`. Find the run for the exact release commit on the
|
||||
(`.gitea/workflows/check.yml`) runs `script/cibuild`, i.e. `docker build .`,
|
||||
and the `Dockerfile` runs `make check` as a build step, so a green `check`
|
||||
run is a green `make check`. Find the run for the exact release commit on the
|
||||
tracker's Actions view. _Check:_ that commit's `check` run succeeded; running
|
||||
`make check` on a clean checkout of the commit reproduces it and exits 0.
|
||||
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
"permissions": ["storage", "activeTab", "alarms"],
|
||||
"host_permissions": ["<all_urls>"],
|
||||
"content_security_policy": {
|
||||
"extension_pages": "default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; object-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https: http:; frame-src 'none'; form-action 'none'; base-uri 'none'"
|
||||
"extension_pages": "default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; object-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self' https: http:; frame-src 'none'; form-action 'none'; base-uri 'none'"
|
||||
},
|
||||
"icons": {
|
||||
"16": "icons/icon16.png",
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
"version": "0.1.0",
|
||||
"description": "Minimal Ethereum wallet for Firefox",
|
||||
"permissions": ["storage", "activeTab", "alarms", "<all_urls>"],
|
||||
"content_security_policy": "default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; object-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https: http:; frame-src 'none'; form-action 'none'; base-uri 'none'",
|
||||
"content_security_policy": "default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; object-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self' https: http:; frame-src 'none'; form-action 'none'; base-uri 'none'",
|
||||
"icons": {
|
||||
"16": "icons/icon16.png",
|
||||
"32": "icons/icon32.png",
|
||||
|
||||
+2
-2
@@ -15,14 +15,14 @@
|
||||
},
|
||||
"devDependencies": {
|
||||
"@eslint/js": "10.0.1",
|
||||
"@tailwindcss/cli": "4.3.1",
|
||||
"@tailwindcss/cli": "^4.2.1",
|
||||
"esbuild": "^0.27.3",
|
||||
"eslint": "10.8.1",
|
||||
"globals": "17.11.0",
|
||||
"jest": "^30.2.0",
|
||||
"playwright-core": "1.56.0",
|
||||
"prettier": "^3.8.1",
|
||||
"tailwindcss": "4.3.1"
|
||||
"tailwindcss": "^4.2.1"
|
||||
},
|
||||
"dependencies": {
|
||||
"ethereum-blockies-base64": "^1.0.2",
|
||||
|
||||
+4
-4
@@ -1,14 +1,14 @@
|
||||
#!/bin/sh
|
||||
# script/check: run all checks (test, lint, fmt-check). Our own
|
||||
# extension to scripts-to-rule-them-all. test and lint are Docker
|
||||
# phases; fmt-check is native, because a formatter writes the working
|
||||
# tree. Must not modify any files.
|
||||
# script/check: run all checks (test, test-verify-build, lint, fmt-check).
|
||||
# Our own extension to scripts-to-rule-them-all. Must not modify any files.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
|
||||
main() {
|
||||
"$SCRIPT_DIR/test"
|
||||
"$SCRIPT_DIR/test-verify-build"
|
||||
"$SCRIPT_DIR/check-censored"
|
||||
"$SCRIPT_DIR/lint"
|
||||
"$SCRIPT_DIR/fmt-check"
|
||||
}
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
#!/bin/sh
|
||||
# script/check-censored: assert that the competitor name RULES.md bars appears
|
||||
# nowhere in this repo, and nowhere in the built extension, except where it is
|
||||
# deliberate. Our own extension to scripts-to-rule-them-all, run by the
|
||||
# Dockerfile's lint phase and by make build.
|
||||
# deliberate. Our own extension to scripts-to-rule-them-all, run from
|
||||
# script/check and from make build.
|
||||
#
|
||||
# Where the name is allowed, and why each one is not negotiable away:
|
||||
#
|
||||
|
||||
+4
-19
@@ -1,28 +1,13 @@
|
||||
#!/bin/sh
|
||||
# script/cibuild: run the CI build. It bootstraps first: a CI runner
|
||||
# checks out and runs this and nothing else, and script/fmt-check runs
|
||||
# the formatter on the host, which a pristine checkout cannot do.
|
||||
# --no-cache for the same reason as script/docker: the gate phases the
|
||||
# final stage depends on are RUN steps, and a cached one is a check that
|
||||
# did not run.
|
||||
# script/cibuild: run the CI build. The Dockerfile runs make check, so
|
||||
# a successful build implies all checks pass.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
"$SCRIPT_DIR/bootstrap"
|
||||
"$SCRIPT_DIR/check"
|
||||
# Own line: a failing command substitution inside an argument does
|
||||
# not trip `set -e`, so the inline form degrades silently to an
|
||||
# empty constant. The VERSION build argument takes precedence over
|
||||
# the version a build stage derives from the .git in the context.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache \
|
||||
--build-arg VERSION="$version" \
|
||||
-t "$("$SCRIPT_DIR/projectname")" .
|
||||
docker build .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+1
-11
@@ -1,8 +1,6 @@
|
||||
#!/bin/sh
|
||||
# script/docker: build the Docker image tagged with the project name.
|
||||
# Identical in all repos; the tag comes from script/projectname.
|
||||
# --no-cache because the gate phases the final stage depends on are RUN
|
||||
# steps, and a cached one is a check that did not run.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
@@ -10,15 +8,7 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
# Own line: a failing command substitution inside an argument does
|
||||
# not trip `set -e`, so the inline form degrades silently to an
|
||||
# empty constant. The VERSION build argument takes precedence over
|
||||
# the version a build stage derives from the .git in the context.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache \
|
||||
--build-arg VERSION="$version" \
|
||||
-t "$("$SCRIPT_DIR/projectname")" .
|
||||
docker build -t "$("$SCRIPT_DIR/projectname")" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+1
-20
@@ -4,29 +4,10 @@ set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
# Must match the pin in script/bootstrap.
|
||||
NODE_VERSION="22.17.0"
|
||||
|
||||
# script/bootstrap installs node and yarn under nvm and leaves neither
|
||||
# on the PATH of the shell that called it, so resolve the pinned
|
||||
# toolchain here the way bootstrap's own install step does. nvm is a
|
||||
# bash script, hence the subshell.
|
||||
run_yarn() {
|
||||
if command -v yarn >/dev/null 2>&1; then
|
||||
exec yarn "$@"
|
||||
fi
|
||||
if [ ! -s "$HOME/.nvm/nvm.sh" ]; then
|
||||
echo "fmt: no yarn; run script/bootstrap first" >&2
|
||||
exit 1
|
||||
fi
|
||||
exec bash -c '. "$HOME/.nvm/nvm.sh" && nvm use "$1" >/dev/null &&
|
||||
shift && exec yarn "$@"' bash "$NODE_VERSION" "$@"
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
echo "Formatting..."
|
||||
run_yarn run fmt
|
||||
yarn run fmt 2>&1
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+1
-20
@@ -5,29 +5,10 @@ set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
# Must match the pin in script/bootstrap.
|
||||
NODE_VERSION="22.17.0"
|
||||
|
||||
# script/bootstrap installs node and yarn under nvm and leaves neither
|
||||
# on the PATH of the shell that called it, so resolve the pinned
|
||||
# toolchain here the way bootstrap's own install step does. nvm is a
|
||||
# bash script, hence the subshell.
|
||||
run_yarn() {
|
||||
if command -v yarn >/dev/null 2>&1; then
|
||||
exec yarn "$@"
|
||||
fi
|
||||
if [ ! -s "$HOME/.nvm/nvm.sh" ]; then
|
||||
echo "fmt-check: no yarn; run script/bootstrap first" >&2
|
||||
exit 1
|
||||
fi
|
||||
exec bash -c '. "$HOME/.nvm/nvm.sh" && nvm use "$1" >/dev/null &&
|
||||
shift && exec yarn "$@"' bash "$NODE_VERSION" "$@"
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
echo "Checking formatting..."
|
||||
run_yarn run fmt-check
|
||||
yarn run fmt-check 2>&1
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
// the build when esbuild's own metafile reports src/shared/state.js as an input
|
||||
// of a background bundle. That consults the resolution esbuild actually
|
||||
// performed, so no specifier syntax and no resolution rule can slip past it,
|
||||
// and the Dockerfile's last stage runs `make build` in CI.
|
||||
// and Dockerfile:42 runs `make build` in CI.
|
||||
//
|
||||
// What this rule is: fast local feedback, in the editor and in `make lint`,
|
||||
// before a full bundle. It reads sources from disk and matches import
|
||||
|
||||
+41
-13
@@ -1,23 +1,51 @@
|
||||
#!/bin/sh
|
||||
# script/lint: run the linter. Linting is a phase of the Dockerfile and
|
||||
# this builds that phase alone; the linter is never installed or run on
|
||||
# a developer host, where a shared result cache and a host-global lock
|
||||
# make its answer untrustworthy.
|
||||
# script/lint: run the linter (eslint, then prettier --check).
|
||||
#
|
||||
# The phase is not the last stage in the file, so it is built only when
|
||||
# --target names it. --no-cache because a cached lint layer is a lint
|
||||
# that did not run. The tag makes each build replace the previous image
|
||||
# instead of leaving a dangling one behind.
|
||||
# Linting is containerized. ESLint results depend on the ESLint version, and
|
||||
# the pinned one is the one in the image; a host's own install must not be
|
||||
# able to decide whether this repo is green. From a host this therefore builds
|
||||
# the Dockerfile's `lint` stage, which runs this same script inside the image.
|
||||
#
|
||||
# AUTISTMASK_LINT_NATIVE is set only in that image (see the Dockerfile) and is
|
||||
# what stops the recursion, so `make check` inside the CI build lints in place
|
||||
# instead of trying to reach a docker daemon it does not have.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
docker build --no-cache \
|
||||
--target lint \
|
||||
-t "$("$SCRIPT_DIR/projectname")-lint" .
|
||||
|
||||
case "${AUTISTMASK_LINT_NATIVE:-}" in
|
||||
1)
|
||||
echo "Linting..."
|
||||
yarn run lint 2>&1
|
||||
return 0
|
||||
;;
|
||||
"") ;;
|
||||
*)
|
||||
# Set but not recognized: say so rather than silently taking the
|
||||
# docker path, which would look like the variable had no effect.
|
||||
echo "lint: AUTISTMASK_LINT_NATIVE is set to" \
|
||||
"'${AUTISTMASK_LINT_NATIVE}'; the only recognized value is 1" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
if ! command -v docker >/dev/null 2>&1; then
|
||||
echo "lint: docker is required; linting does not run on the host" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Linting in the pinned container..."
|
||||
# --progress=plain: the default progress renderer collapses the lint
|
||||
# output on success, and a lint run whose output cannot be seen is not
|
||||
# evidence that it ran.
|
||||
#
|
||||
# --output=type=cacheonly: the exit status is the whole result; exporting
|
||||
# an image afterwards costs about ten times the lint itself.
|
||||
docker build --progress=plain --target lint \
|
||||
--output=type=cacheonly . 2>&1
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+43
-10
@@ -1,19 +1,52 @@
|
||||
#!/bin/sh
|
||||
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
||||
# and this builds that phase alone, on the same terms as script/lint:
|
||||
# --target because a phase that is not the last stage is built only when
|
||||
# named, --no-cache because a cached test layer is a test that did not
|
||||
# run, and a tag so each build replaces the previous image.
|
||||
# script/test: run the test suite.
|
||||
#
|
||||
# jest runs three worker processes (package.json), not one per CPU core: on a
|
||||
# many-core shared host one per core took gigabytes of RAM per run.
|
||||
#
|
||||
# The timeout bounds a hung suite; it is not a performance budget. On the busy
|
||||
# shared build host the suite takes 8-13s with three workers, inside
|
||||
# REPO_POLICIES' 20s budget. Inside the image the same suite also pays a cold
|
||||
# jest cache and shares the runner with the rest of the build, which is not what
|
||||
# that budget describes, so the Dockerfile raises the bound through
|
||||
# AUTISTMASK_TEST_TIMEOUT. A cap a healthy suite can trip on a cold cache
|
||||
# produces a red that means nothing, and teaches "just run it again".
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
TIMEOUT="${AUTISTMASK_TEST_TIMEOUT:-30}"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
docker build --no-cache \
|
||||
--target test \
|
||||
-t "$("$SCRIPT_DIR/projectname")-test" .
|
||||
echo "Running tests (timeout ${TIMEOUT}s)..."
|
||||
|
||||
status=0
|
||||
timeout "$TIMEOUT" yarn run test 2>&1 || status=$?
|
||||
[ "$status" -eq 0 ] && return 0
|
||||
|
||||
# 124 is timeout(1) killing the suite. Say so: a kill is not a failed
|
||||
# assertion, and the verbose rerun would only spend the same wall clock
|
||||
# to be killed again.
|
||||
if [ "$status" -eq 124 ]; then
|
||||
echo "tests: TIMED OUT after ${TIMEOUT}s (no assertion failed)" >&2
|
||||
echo "tests: raise AUTISTMASK_TEST_TIMEOUT if the suite is healthy" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# 125 is timeout(1) itself failing, which here means AUTISTMASK_TEST_TIMEOUT
|
||||
# is not a duration it accepts. The suite never ran, so it neither timed out
|
||||
# nor failed, and the verbose rerun would only reprint the same complaint.
|
||||
if [ "$status" -eq 125 ]; then
|
||||
echo "tests: DID NOT RUN: timeout(1) rejected AUTISTMASK_TEST_TIMEOUT=\"${TIMEOUT}\"" >&2
|
||||
echo "tests: set it to a duration such as 30 or 180 (see timeout(1))" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "--- Rerunning with --verbose for details ---"
|
||||
timeout "$TIMEOUT" yarn run test:verbose 2>&1 || true
|
||||
# Always fail: the first run already proved the tests are broken, so a
|
||||
# flaky pass on the rerun must not turn the build green.
|
||||
exit 1
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+2
-5
@@ -4,7 +4,7 @@
|
||||
# scripts-to-rule-them-all.
|
||||
#
|
||||
# Deliberately NOT called by script/check or script/test: REPO_POLICIES.md
|
||||
# caps make test at 60 seconds and a browser suite does not fit. Run it
|
||||
# caps make test at 20 seconds and a browser suite does not fit. Run it
|
||||
# yourself before touching popup views. ESLint's no-undef now catches a
|
||||
# used-but-not-imported identifier in make check, but only this suite sees
|
||||
# what a view actually does when it runs.
|
||||
@@ -45,10 +45,7 @@ main() {
|
||||
trap 'cleanup; exit 130' INT TERM
|
||||
|
||||
echo "Building the Chrome e2e image (extension included)..."
|
||||
# --no-cache: the image build runs make build and its checks, and a
|
||||
# cached layer is a check that did not run.
|
||||
docker build --no-cache --iidfile "$IIDFILE" -t "$IMAGE" \
|
||||
-f tests/e2e/Dockerfile .
|
||||
docker build --iidfile "$IIDFILE" -t "$IMAGE" -f tests/e2e/Dockerfile .
|
||||
|
||||
echo "Running e2e suite in the pinned Playwright container..."
|
||||
# The image is run by ID, not by tag: where two clones of this repo run
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
# script/test-e2e. Our own extension to scripts-to-rule-them-all.
|
||||
#
|
||||
# Deliberately NOT called by script/check or script/test, for the same
|
||||
# reason as the Chrome suite: REPO_POLICIES.md caps make test at 60 seconds
|
||||
# reason as the Chrome suite: REPO_POLICIES.md caps make test at 20 seconds
|
||||
# and a browser suite does not fit. .gitea/workflows/e2e.yml also runs it
|
||||
# on every push, in a job separate from check.
|
||||
#
|
||||
@@ -44,9 +44,7 @@ main() {
|
||||
trap 'cleanup; exit 130' INT TERM
|
||||
|
||||
echo "Building the pinned Firefox e2e image (extension included)..."
|
||||
# --no-cache: the image build runs make build and its checks, and a
|
||||
# cached layer is a check that did not run.
|
||||
docker build --no-cache --iidfile "$IIDFILE" -t "$IMAGE" \
|
||||
docker build --iidfile "$IIDFILE" -t "$IMAGE" \
|
||||
-f tests/e2e/firefox/Dockerfile .
|
||||
|
||||
echo "Running the Firefox e2e suite..."
|
||||
|
||||
@@ -2,8 +2,7 @@
|
||||
# script/test-verify-build: exercise every failure mode of
|
||||
# script/verify-build, and what make build does with dist/ after one of them
|
||||
# (script/discard-dist-on-failure). Our own extension to
|
||||
# scripts-to-rule-them-all, run by the Dockerfile's test phase so make check
|
||||
# covers it.
|
||||
# scripts-to-rule-them-all, run from script/check so make check covers it.
|
||||
#
|
||||
# Why this exists: verify-build is the build-integrity guard, and four separate
|
||||
# reviews of it each found a fresh vacuous pass — the grep exit-2 conflation,
|
||||
|
||||
+7
-32
@@ -413,7 +413,7 @@ function releaseApproval(approval) {
|
||||
}
|
||||
}
|
||||
|
||||
// Open approval in a separate popup window, unless it is no longer pending.
|
||||
// Open approval in a separate popup window.
|
||||
// This is the primary mechanism for tx/sign approvals (triggered programmatically,
|
||||
// not from a user gesture) and the fallback for site-connection approvals.
|
||||
// Never rejects. Its callers raise it from inside a Promise executor and drop
|
||||
@@ -437,13 +437,7 @@ async function openApprovalWindow(id) {
|
||||
width: popupWidth,
|
||||
height: popupHeight,
|
||||
};
|
||||
// Centred on a browser window only. The last focused window can be
|
||||
// another approval window still open, and centring on one can give a
|
||||
// position the browser refuses ("Bounds must be at least 50% within
|
||||
// visible screen space"): headless Chrome reports this 360x600 popup as
|
||||
// 1280x720. The request then failed with no window at all. Over a popup,
|
||||
// the browser picks the position.
|
||||
if (currentWin && currentWin.type === "normal") {
|
||||
if (currentWin) {
|
||||
opts.left = Math.round(
|
||||
currentWin.left + (currentWin.width - popupWidth) / 2,
|
||||
);
|
||||
@@ -452,32 +446,15 @@ async function openApprovalWindow(id) {
|
||||
);
|
||||
}
|
||||
|
||||
// Already answered: a site-connection prompt decided before the toolbar
|
||||
// popup raised for it had loaded, whose openPopup() rejects only now.
|
||||
if (!pendingApprovals[id]) return;
|
||||
|
||||
let win = null;
|
||||
try {
|
||||
win = await windowsCreate(opts);
|
||||
} catch (e) {
|
||||
// The promise namespace reports the failure by rejecting where the
|
||||
// callback namespace reported it by handing back no window; both
|
||||
// leave win null.
|
||||
// callback namespace reported it by handing back no window; both land
|
||||
// on the !win branch below, which settles the approval.
|
||||
log.errorf("could not open the approval window:", e);
|
||||
}
|
||||
// The browser also refuses a centred position that is too far off screen,
|
||||
// as it is over a browser window near the screen edge. Asked again
|
||||
// without a position, it places the window itself. If that fails too,
|
||||
// the !win branch below settles the approval.
|
||||
if (!win && opts.left !== undefined) {
|
||||
delete opts.left;
|
||||
delete opts.top;
|
||||
try {
|
||||
win = await windowsCreate(opts);
|
||||
} catch (e) {
|
||||
log.errorf("could not open the approval window:", e);
|
||||
}
|
||||
}
|
||||
|
||||
const approval = pendingApprovals[id];
|
||||
if (!approval) {
|
||||
@@ -741,12 +718,11 @@ async function handleConnectionRequest(origin) {
|
||||
}
|
||||
}
|
||||
|
||||
// Methods that are safe to proxy directly to the RPC node. A method handleRpc
|
||||
// answers before its proxy branch does not belong here: it would never reach
|
||||
// the node. tests/proxyMethods.test.js sends every one of these.
|
||||
// Methods that are safe to proxy directly to the RPC node
|
||||
const PROXY_METHODS = [
|
||||
"eth_blockNumber",
|
||||
"eth_call",
|
||||
"eth_chainId",
|
||||
"eth_estimateGas",
|
||||
"eth_gasPrice",
|
||||
"eth_getBalance",
|
||||
@@ -760,6 +736,7 @@ const PROXY_METHODS = [
|
||||
"eth_getTransactionReceipt",
|
||||
"eth_maxPriorityFeePerGas",
|
||||
"eth_sendRawTransaction",
|
||||
"net_version",
|
||||
"web3_clientVersion",
|
||||
"eth_feeHistory",
|
||||
"eth_getBlockTransactionCountByHash",
|
||||
@@ -1802,5 +1779,3 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
|
||||
return false;
|
||||
}
|
||||
});
|
||||
|
||||
module.exports = { PROXY_METHODS };
|
||||
|
||||
+102
-49
@@ -6,10 +6,7 @@
|
||||
<title>AutistMask</title>
|
||||
<link rel="stylesheet" href="styles.css" />
|
||||
</head>
|
||||
<!-- Chrome gives extension pages a stylesheet of its own that sets the
|
||||
font on body, and a Tailwind class beats it only when marked
|
||||
important: hence font-mono! rather than font-mono. -->
|
||||
<body class="bg-bg text-fg font-mono! text-sm">
|
||||
<body class="bg-bg text-fg font-mono text-sm">
|
||||
<div id="app" class="p-2 pr-5 overflow-x-hidden">
|
||||
<!-- ============ GLOBAL TITLE BAR ============ -->
|
||||
<div
|
||||
@@ -110,7 +107,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="add-wallet-phrase-warning"
|
||||
class="text-xs mb-2 border border-border border-dashed p-2 invisible"
|
||||
class="text-xs mb-2 border border-border border-dashed p-2"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
Write these words down and keep them safe. Anyone with
|
||||
them can take your funds; if you lose them, your wallet
|
||||
@@ -261,7 +259,10 @@
|
||||
|
||||
<!-- recent transactions across all addresses -->
|
||||
<div>
|
||||
<div class="font-bold bg-section py-1 px-2 -mx-2">
|
||||
<div
|
||||
class="font-bold bg-section py-1 px-2"
|
||||
style="margin-left: -0.5rem; margin-right: -0.5rem"
|
||||
>
|
||||
Recent Transactions
|
||||
</div>
|
||||
<div id="home-tx-list">
|
||||
@@ -269,7 +270,7 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="py-1 -mx-2"> </div>
|
||||
<div class="py-1" style="margin: 0 -0.5rem"> </div>
|
||||
|
||||
<div class="text-xs text-muted">
|
||||
<span
|
||||
@@ -391,14 +392,22 @@
|
||||
></div>
|
||||
<h2 class="font-bold mb-1">Export Private Key</h2>
|
||||
<p class="text-xs mb-1" id="export-privkey-title"></p>
|
||||
<div id="export-privkey-address" class="text-xs mb-3"></div>
|
||||
<div class="text-xs mb-3">
|
||||
<span id="export-privkey-dot"></span>
|
||||
<span
|
||||
id="export-privkey-address"
|
||||
class="cursor-pointer"
|
||||
title="Click to copy"
|
||||
></span>
|
||||
</div>
|
||||
<p class="text-xs mb-3 text-muted">
|
||||
Warning: anyone with this private key can access and
|
||||
transfer all funds from this address. Never share it.
|
||||
</p>
|
||||
<div
|
||||
id="export-privkey-flash"
|
||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div id="export-privkey-password-section" class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
@@ -530,7 +539,8 @@
|
||||
/>
|
||||
<div
|
||||
id="send-to-error"
|
||||
class="text-xs min-h-[1.25rem] text-[#cc0000]"
|
||||
class="text-xs"
|
||||
style="min-height: 1.25rem; color: #cc0000"
|
||||
></div>
|
||||
</div>
|
||||
<div class="mb-2">
|
||||
@@ -541,20 +551,12 @@
|
||||
class="text-xs text-muted"
|
||||
></span>
|
||||
</div>
|
||||
<div class="flex gap-1">
|
||||
<input
|
||||
type="text"
|
||||
id="send-amount"
|
||||
class="border border-border p-1 flex-1 min-w-0 font-mono text-sm bg-bg text-fg"
|
||||
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
|
||||
placeholder="0.0"
|
||||
/>
|
||||
<button
|
||||
id="btn-send-max"
|
||||
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
|
||||
>
|
||||
Max
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
<button
|
||||
id="btn-send-review"
|
||||
@@ -606,7 +608,7 @@
|
||||
<div class="text-xs text-muted mb-1">Your balance</div>
|
||||
<div id="confirm-balance" class="text-xs"></div>
|
||||
</div>
|
||||
<div id="confirm-fee" class="mb-3 invisible">
|
||||
<div id="confirm-fee" class="mb-3" style="visibility: hidden">
|
||||
<div class="text-xs text-muted mb-1">Network fee</div>
|
||||
<div id="confirm-fee-amount" class="text-xs"></div>
|
||||
<!-- Holds its one line of space from the first paint, so
|
||||
@@ -614,13 +616,22 @@
|
||||
nothing. The placeholder is never seen. -->
|
||||
<div
|
||||
id="confirm-fee-reserve"
|
||||
class="text-xs text-muted invisible"
|
||||
class="text-xs text-muted"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
reserve pending
|
||||
</div>
|
||||
</div>
|
||||
<div id="confirm-warnings" class="mb-2 invisible"></div>
|
||||
<div id="confirm-recipient-warning" class="mb-2 invisible">
|
||||
<div
|
||||
id="confirm-warnings"
|
||||
class="mb-2"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div
|
||||
id="confirm-recipient-warning"
|
||||
class="mb-2"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
<div
|
||||
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||
>
|
||||
@@ -629,13 +640,24 @@
|
||||
Double-check the address before sending.
|
||||
</div>
|
||||
</div>
|
||||
<!-- Its sentence names the network's native token, so show()
|
||||
in confirmTx.js sets it. -->
|
||||
<div
|
||||
id="confirm-contract-warning"
|
||||
class="mb-2 border border-red-500 border-dashed p-2 text-xs font-bold text-red-500 invisible"
|
||||
></div>
|
||||
<div id="confirm-burn-warning" class="mb-2 invisible">
|
||||
class="mb-2"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
<div
|
||||
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||
>
|
||||
WARNING: The recipient is a smart contract. Sending ETH
|
||||
or tokens directly to a contract may result in permanent
|
||||
loss of funds.
|
||||
</div>
|
||||
</div>
|
||||
<div
|
||||
id="confirm-burn-warning"
|
||||
class="mb-2"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
<div
|
||||
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||
>
|
||||
@@ -643,7 +665,11 @@
|
||||
here are permanently destroyed and cannot be recovered.
|
||||
</div>
|
||||
</div>
|
||||
<div id="confirm-etherscan-warning" class="mb-2 invisible">
|
||||
<div
|
||||
id="confirm-etherscan-warning"
|
||||
class="mb-2"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
<div
|
||||
class="border border-red-500 border-dashed p-2 text-xs font-bold text-red-500"
|
||||
>
|
||||
@@ -653,11 +679,13 @@
|
||||
</div>
|
||||
<div
|
||||
id="confirm-errors"
|
||||
class="mb-2 border border-border border-dashed p-2 invisible min-h-[1.25rem]"
|
||||
class="mb-2 border border-border border-dashed p-2"
|
||||
style="visibility: hidden; min-height: 1.25rem"
|
||||
></div>
|
||||
<div
|
||||
id="confirm-amount-fee-error"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs invisible"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||
style="visibility: hidden"
|
||||
>
|
||||
Your balance does not cover this amount plus the network
|
||||
fee. Please go back and send a smaller amount.
|
||||
@@ -666,13 +694,15 @@
|
||||
in confirmTx.js sets it. -->
|
||||
<div
|
||||
id="confirm-gas-error"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs invisible"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<!-- Its sentence names why the fee could not be estimated,
|
||||
so show() in confirmTx.js sets it. -->
|
||||
<div
|
||||
id="confirm-fee-unknown-error"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs invisible"
|
||||
class="mb-2 border border-border border-dashed p-2 text-xs"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1 text-xs">Password</label>
|
||||
@@ -684,7 +714,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="confirm-tx-password-error"
|
||||
class="text-xs mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<button
|
||||
id="btn-confirm-send"
|
||||
@@ -799,7 +830,8 @@
|
||||
</button>
|
||||
<div
|
||||
id="receive-erc20-warning"
|
||||
class="text-xs border border-border border-dashed p-2 mt-3 invisible"
|
||||
class="text-xs border border-border border-dashed p-2 mt-3"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
</div>
|
||||
|
||||
@@ -827,7 +859,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="add-token-info"
|
||||
class="text-xs text-muted mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-muted mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1 text-xs text-muted"
|
||||
@@ -1013,7 +1046,8 @@
|
||||
type="text"
|
||||
inputmode="numeric"
|
||||
id="settings-dust-threshold"
|
||||
class="border border-border p-1 text-xs bg-bg text-fg w-[10ch]"
|
||||
class="border border-border p-1 text-xs bg-bg text-fg"
|
||||
style="width: 10ch"
|
||||
/>
|
||||
<span class="text-xs text-muted">gwei</span>
|
||||
</div>
|
||||
@@ -1090,7 +1124,8 @@
|
||||
|
||||
<div
|
||||
id="settings-debug-well"
|
||||
class="bg-well p-3 mx-1 mb-3 hidden"
|
||||
class="bg-well p-3 mx-1 mb-3"
|
||||
style="display: none"
|
||||
>
|
||||
<h3 class="font-bold mb-1">Debug</h3>
|
||||
<label
|
||||
@@ -1118,7 +1153,8 @@
|
||||
</p>
|
||||
<div
|
||||
id="delete-wallet-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
@@ -1191,7 +1227,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="delete-wallet-lost-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<button
|
||||
id="btn-delete-wallet-lost-confirm"
|
||||
@@ -1246,7 +1283,8 @@
|
||||
</p>
|
||||
<div
|
||||
id="delete-address-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<button
|
||||
id="btn-delete-address-confirm"
|
||||
@@ -1275,7 +1313,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="show-phrase-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div id="show-phrase-password-section" class="mb-2">
|
||||
<label class="block mb-1">Password</label>
|
||||
@@ -1357,7 +1396,8 @@
|
||||
/>
|
||||
<div
|
||||
id="settings-addtoken-info"
|
||||
class="text-xs text-muted mt-1 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-muted mt-1 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<button
|
||||
id="btn-settings-addtoken-manual"
|
||||
@@ -1590,7 +1630,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="approve-tx-error"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem] invisible"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="flex justify-between">
|
||||
<button
|
||||
@@ -1626,7 +1667,15 @@
|
||||
|
||||
<div
|
||||
id="approve-sign-danger-warning"
|
||||
class="mb-3 p-2 text-xs font-bold invisible min-h-[1.25rem] bg-[#fee2e2] text-[#991b1b] border-2 border-[#dc2626] rounded-[6px]"
|
||||
class="mb-3 p-2 text-xs font-bold"
|
||||
style="
|
||||
visibility: hidden;
|
||||
min-height: 1.25rem;
|
||||
background: #fee2e2;
|
||||
color: #991b1b;
|
||||
border: 2px solid #dc2626;
|
||||
border-radius: 6px;
|
||||
"
|
||||
></div>
|
||||
|
||||
<div class="mb-3">
|
||||
@@ -1643,7 +1692,8 @@
|
||||
<div class="text-xs text-muted mb-1">Message</div>
|
||||
<div
|
||||
id="approve-sign-message"
|
||||
class="text-xs break-all max-h-48 overflow-y-auto"
|
||||
class="text-xs break-all"
|
||||
style="max-height: 12rem; overflow-y: auto"
|
||||
></div>
|
||||
</div>
|
||||
|
||||
@@ -1651,7 +1701,8 @@
|
||||
<div class="text-xs text-muted mb-1">Raw data</div>
|
||||
<div
|
||||
id="approve-sign-hex"
|
||||
class="text-xs break-all max-h-24 overflow-y-auto"
|
||||
class="text-xs break-all"
|
||||
style="max-height: 6rem; overflow-y: auto"
|
||||
></div>
|
||||
</div>
|
||||
|
||||
@@ -1665,7 +1716,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="approve-sign-error"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem] invisible"
|
||||
class="text-xs mb-2 border border-border border-dashed p-1 min-h-[1.875rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<div class="flex justify-between">
|
||||
<button
|
||||
@@ -1789,7 +1841,8 @@
|
||||
</div>
|
||||
<div
|
||||
id="state-recovery-flash"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
|
||||
class="text-xs text-red-500 mb-2 min-h-[1.25rem]"
|
||||
style="visibility: hidden"
|
||||
></div>
|
||||
<button
|
||||
id="btn-state-recovery-reset"
|
||||
|
||||
+2
-37
@@ -48,20 +48,8 @@ function renderWalletList() {
|
||||
home.render(ctx);
|
||||
}
|
||||
|
||||
// Aborted when the popup page goes away, closed or reloaded. Chrome then
|
||||
// cancels the requests the page still has open, and a cancelled fetch() fails
|
||||
// with the same "Failed to fetch" as a server that cannot be reached. pagehide
|
||||
// fires first, so code that reports a failed request checks this and stays
|
||||
// silent about one the page's own closing cancelled.
|
||||
const pageClosed = new AbortController();
|
||||
window.addEventListener("pagehide", () => pageClosed.abort());
|
||||
|
||||
let refreshInFlight = false;
|
||||
|
||||
// The ten-second refresh init() starts, stopped when the popup moves to the
|
||||
// recovery screen: there is no profile left to refresh.
|
||||
let refreshTimer = null;
|
||||
|
||||
async function doRefreshAndRender() {
|
||||
if (refreshInFlight) return;
|
||||
refreshInFlight = true;
|
||||
@@ -74,7 +62,6 @@ async function doRefreshAndRender() {
|
||||
state.blockscoutUrl,
|
||||
state.trackedTokens,
|
||||
state.networkId,
|
||||
pageClosed.signal,
|
||||
),
|
||||
]);
|
||||
state.lastBalanceRefresh = Date.now();
|
||||
@@ -96,7 +83,6 @@ async function doRefreshAndRender() {
|
||||
const ctx = {
|
||||
renderWalletList,
|
||||
doRefreshAndRender,
|
||||
pageClosed: pageClosed.signal,
|
||||
showAddWalletView: () => {
|
||||
pushCurrentView();
|
||||
addWallet.show();
|
||||
@@ -169,28 +155,7 @@ async function init() {
|
||||
// reported rather than being swallowed by the save queue
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/362). Registered ahead of
|
||||
// the approval-window branch below too, since that window saves as well.
|
||||
//
|
||||
// Every save first reads the stored record and refuses it with the same
|
||||
// check loadState() runs below. So a record that becomes unreadable while
|
||||
// the popup is open is found by the next save, a navigation or the
|
||||
// ten-second refresh, and gets the screen it would get at open
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/373). Passing the recovery
|
||||
// screen to showView() first leaves the current screen as any navigation
|
||||
// does, so a phrase, key or password on it is wiped, and from then on
|
||||
// showView() shows nothing else. A later save that fails the same way,
|
||||
// such as a refresh already in flight, comes back here, where both calls
|
||||
// see the screen already up and do nothing. Any other failed save is a
|
||||
// read or write that failed, and gets the banner without changing the
|
||||
// screen.
|
||||
onSaveFailure((e) => {
|
||||
if (e instanceof StateUnusableError) {
|
||||
clearInterval(refreshTimer);
|
||||
showView("state-recovery");
|
||||
stateRecovery.show(e);
|
||||
} else {
|
||||
showSaveFailureBanner(e);
|
||||
}
|
||||
});
|
||||
onSaveFailure(showSaveFailureBanner);
|
||||
try {
|
||||
await loadState();
|
||||
} catch (e) {
|
||||
@@ -279,7 +244,7 @@ async function init() {
|
||||
renderWalletList();
|
||||
restoreView();
|
||||
doRefreshAndRender();
|
||||
refreshTimer = setInterval(doRefreshAndRender, 10000);
|
||||
setInterval(doRefreshAndRender, 10000);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -7,14 +7,13 @@ const {
|
||||
addressTitle,
|
||||
escapeHtml,
|
||||
displaySymbol,
|
||||
nativeCurrency,
|
||||
renderAddressHtml,
|
||||
attachCopyHandlers,
|
||||
goBack,
|
||||
pushCurrentView,
|
||||
isoDate,
|
||||
timeAgo,
|
||||
} = require("./helpers");
|
||||
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||
const { state, saveState } = require("../../shared/state");
|
||||
const { formatAddressTotal, getAddressValue } = require("../../shared/prices");
|
||||
const {
|
||||
fetchRecentTransactions,
|
||||
@@ -33,8 +32,8 @@ const { walletDefect } = require("../../shared/walletDefects");
|
||||
|
||||
// The defect of the wallet the selected address belongs to, or null. Both the
|
||||
// send and the private-key export path check it before asking for a password,
|
||||
// so a wallet whose key getSignerForAddress refuses says so instead of failing
|
||||
// after the user has typed one in.
|
||||
// so a wallet that cannot derive its keys says so instead of failing after the
|
||||
// user has typed one in.
|
||||
function selectedWalletDefect() {
|
||||
if (state.selectedWallet === null) return null;
|
||||
return walletDefect(state.wallets[state.selectedWallet]);
|
||||
@@ -66,7 +65,7 @@ function show() {
|
||||
$("address-line").dataset.full = addr.address;
|
||||
attachCopyHandlers($("address-line"));
|
||||
const usdTotal = formatAddressTotal(getAddressValue(addr));
|
||||
$("address-usd-total").innerHTML = escapeHtml(usdTotal) || " ";
|
||||
$("address-usd-total").innerHTML = usdTotal || " ";
|
||||
const ensEl = $("address-ens");
|
||||
// ENS is now shown inside renderAddressHtml, hide the separate element
|
||||
ensEl.classList.add("hidden");
|
||||
@@ -90,6 +89,62 @@ function show() {
|
||||
loadTransactions(addr.address);
|
||||
}
|
||||
|
||||
function isoDate(timestamp) {
|
||||
const d = new Date(timestamp * 1000);
|
||||
const pad = (n) => String(n).padStart(2, "0");
|
||||
if (state.utcTimestamps) {
|
||||
return (
|
||||
d.getUTCFullYear() +
|
||||
"-" +
|
||||
pad(d.getUTCMonth() + 1) +
|
||||
"-" +
|
||||
pad(d.getUTCDate()) +
|
||||
"T" +
|
||||
pad(d.getUTCHours()) +
|
||||
":" +
|
||||
pad(d.getUTCMinutes()) +
|
||||
":" +
|
||||
pad(d.getUTCSeconds()) +
|
||||
"Z"
|
||||
);
|
||||
}
|
||||
const offsetMin = -d.getTimezoneOffset();
|
||||
const sign = offsetMin >= 0 ? "+" : "-";
|
||||
const absOff = Math.abs(offsetMin);
|
||||
const tzStr = sign + pad(Math.floor(absOff / 60)) + ":" + pad(absOff % 60);
|
||||
return (
|
||||
d.getFullYear() +
|
||||
"-" +
|
||||
pad(d.getMonth() + 1) +
|
||||
"-" +
|
||||
pad(d.getDate()) +
|
||||
"T" +
|
||||
pad(d.getHours()) +
|
||||
":" +
|
||||
pad(d.getMinutes()) +
|
||||
":" +
|
||||
pad(d.getSeconds()) +
|
||||
tzStr
|
||||
);
|
||||
}
|
||||
|
||||
function timeAgo(timestamp) {
|
||||
const seconds = Math.floor(Date.now() / 1000 - timestamp);
|
||||
if (seconds < 60) return seconds + " seconds ago";
|
||||
const minutes = Math.floor(seconds / 60);
|
||||
if (minutes < 60)
|
||||
return minutes + " minute" + (minutes !== 1 ? "s" : "") + " ago";
|
||||
const hours = Math.floor(minutes / 60);
|
||||
if (hours < 24) return hours + " hour" + (hours !== 1 ? "s" : "") + " ago";
|
||||
const days = Math.floor(hours / 24);
|
||||
if (days < 30) return days + " day" + (days !== 1 ? "s" : "") + " ago";
|
||||
const months = Math.floor(days / 30);
|
||||
if (months < 12)
|
||||
return months + " month" + (months !== 1 ? "s" : "") + " ago";
|
||||
const years = Math.floor(days / 365);
|
||||
return years + " year" + (years !== 1 ? "s" : "") + " ago";
|
||||
}
|
||||
|
||||
let loadedTxs = [];
|
||||
|
||||
let ensNameMap = new Map();
|
||||
@@ -99,7 +154,7 @@ async function loadTransactions(address) {
|
||||
const rawTxs = await fetchRecentTransactions(
|
||||
address,
|
||||
state.blockscoutUrl,
|
||||
currentNetwork().chainId,
|
||||
nativeCurrency(),
|
||||
);
|
||||
const result = filterTransactions(rawTxs, {
|
||||
hideSpoofedSymbols: state.hideSpoofedSymbols,
|
||||
@@ -181,10 +236,10 @@ function renderTransactions(txs) {
|
||||
// it on the line above rather than replacing it.
|
||||
const nameStr = escapeHtml(title || ensName || "");
|
||||
const err = tx.isError ? " (failed)" : "";
|
||||
const opacity = tx.isError ? " opacity-50" : "";
|
||||
const opacity = tx.isError ? " opacity:0.5;" : "";
|
||||
const ago = escapeHtml(timeAgo(tx.timestamp));
|
||||
const iso = escapeHtml(isoDate(tx.timestamp));
|
||||
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover${opacity}" data-tx="${i}">`;
|
||||
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
||||
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
||||
html += txCounterpartyHtml(counterparty, nameStr, amountStr);
|
||||
html += `</div>`;
|
||||
@@ -259,10 +314,9 @@ function init(_ctx) {
|
||||
$("btn-export-privkey").addEventListener("click", () => {
|
||||
moreDropdown.classList.add("hidden");
|
||||
moreBtn.classList.remove("bg-fg", "text-bg");
|
||||
// This address's private key can be derived from the stored key,
|
||||
// but export goes through getSignerForAddress, which refuses a key
|
||||
// that is not a master key. Without this the export screen would
|
||||
// take a password and then report that refusal as a wrong password.
|
||||
// There is no private key to export for an address this wallet
|
||||
// cannot derive. Without this the export screen would take a
|
||||
// password and then report it as wrong.
|
||||
const defect = selectedWalletDefect();
|
||||
if (defect) {
|
||||
showFlash(defect.shortMessage);
|
||||
|
||||
@@ -17,10 +17,8 @@ const {
|
||||
attachCopyHandlers,
|
||||
goBack,
|
||||
pushCurrentView,
|
||||
isoDate,
|
||||
timeAgo,
|
||||
} = require("./helpers");
|
||||
const { state, saveState, currentNetwork } = require("../../shared/state");
|
||||
const { state, saveState } = require("../../shared/state");
|
||||
const { TOKEN_BY_ADDRESS, resolveSymbol } = require("../../shared/tokenList");
|
||||
const { formatUsd, getPrice } = require("../../shared/prices");
|
||||
const {
|
||||
@@ -39,6 +37,62 @@ const { walletDefect } = require("../../shared/walletDefects");
|
||||
|
||||
let ctx;
|
||||
|
||||
function isoDate(timestamp) {
|
||||
const d = new Date(timestamp * 1000);
|
||||
const pad = (n) => String(n).padStart(2, "0");
|
||||
if (state.utcTimestamps) {
|
||||
return (
|
||||
d.getUTCFullYear() +
|
||||
"-" +
|
||||
pad(d.getUTCMonth() + 1) +
|
||||
"-" +
|
||||
pad(d.getUTCDate()) +
|
||||
"T" +
|
||||
pad(d.getUTCHours()) +
|
||||
":" +
|
||||
pad(d.getUTCMinutes()) +
|
||||
":" +
|
||||
pad(d.getUTCSeconds()) +
|
||||
"Z"
|
||||
);
|
||||
}
|
||||
const offsetMin = -d.getTimezoneOffset();
|
||||
const sign = offsetMin >= 0 ? "+" : "-";
|
||||
const absOff = Math.abs(offsetMin);
|
||||
const tzStr = sign + pad(Math.floor(absOff / 60)) + ":" + pad(absOff % 60);
|
||||
return (
|
||||
d.getFullYear() +
|
||||
"-" +
|
||||
pad(d.getMonth() + 1) +
|
||||
"-" +
|
||||
pad(d.getDate()) +
|
||||
"T" +
|
||||
pad(d.getHours()) +
|
||||
":" +
|
||||
pad(d.getMinutes()) +
|
||||
":" +
|
||||
pad(d.getSeconds()) +
|
||||
tzStr
|
||||
);
|
||||
}
|
||||
|
||||
function timeAgo(timestamp) {
|
||||
const seconds = Math.floor(Date.now() / 1000 - timestamp);
|
||||
if (seconds < 60) return seconds + " seconds ago";
|
||||
const minutes = Math.floor(seconds / 60);
|
||||
if (minutes < 60)
|
||||
return minutes + " minute" + (minutes !== 1 ? "s" : "") + " ago";
|
||||
const hours = Math.floor(minutes / 60);
|
||||
if (hours < 24) return hours + " hour" + (hours !== 1 ? "s" : "") + " ago";
|
||||
const days = Math.floor(hours / 24);
|
||||
if (days < 30) return days + " day" + (days !== 1 ? "s" : "") + " ago";
|
||||
const months = Math.floor(days / 30);
|
||||
if (months < 12)
|
||||
return months + " month" + (months !== 1 ? "s" : "") + " ago";
|
||||
const years = Math.floor(days / 365);
|
||||
return years + " year" + (years !== 1 ? "s" : "") + " ago";
|
||||
}
|
||||
|
||||
let loadedTxs = [];
|
||||
let ensNameMap = new Map();
|
||||
let currentSymbol = null;
|
||||
@@ -103,7 +157,7 @@ function show() {
|
||||
// USD total for this token only
|
||||
const usdVal = price && amount !== null ? amount * price : null;
|
||||
const usdStr = formatUsd(usdVal);
|
||||
$("address-token-usd-total").innerHTML = escapeHtml(usdStr) || " ";
|
||||
$("address-token-usd-total").innerHTML = usdStr || " ";
|
||||
|
||||
// Single token balance line (no tokenId — not clickable here)
|
||||
$("address-token-balance").innerHTML = balanceLine(symbol, amount, price);
|
||||
@@ -148,9 +202,9 @@ function show() {
|
||||
if (tokenSymbol)
|
||||
infoHtml += `<div class="mb-1"><span class="text-muted">Symbol:</span> ${tokenSymbol}</div>`;
|
||||
if (tokenDecimals != null)
|
||||
infoHtml += `<div class="mb-1"><span class="text-muted">Decimals:</span> ${escapeHtml(tokenDecimals)}</div>`;
|
||||
infoHtml += `<div class="mb-1"><span class="text-muted">Decimals:</span> ${tokenDecimals}</div>`;
|
||||
if (tokenHolders != null)
|
||||
infoHtml += `<div class="mb-1"><span class="text-muted">Holders:</span> ${escapeHtml(Number(tokenHolders).toLocaleString())}</div>`;
|
||||
infoHtml += `<div class="mb-1"><span class="text-muted">Holders:</span> ${Number(tokenHolders).toLocaleString()}</div>`;
|
||||
if (projectUrl)
|
||||
infoHtml += `<div class="mb-1"><span class="text-muted">Website:</span> <a href="${escapeHtml(projectUrl)}" target="_blank" rel="noopener" class="underline decoration-dashed">${escapeHtml(projectUrl)}</a></div>`;
|
||||
contractInfo.innerHTML = infoHtml;
|
||||
@@ -173,7 +227,7 @@ async function loadTransactions(address, tokenId) {
|
||||
const rawTxs = await fetchRecentTransactions(
|
||||
address,
|
||||
state.blockscoutUrl,
|
||||
currentNetwork().chainId,
|
||||
nativeCurrency(),
|
||||
);
|
||||
const result = filterTransactions(rawTxs, {
|
||||
hideSpoofedSymbols: state.hideSpoofedSymbols,
|
||||
@@ -258,10 +312,10 @@ function renderTransactions(txs) {
|
||||
// it on the line above rather than replacing it.
|
||||
const nameStr = escapeHtml(title || ensName || "");
|
||||
const err = tx.isError ? " (failed)" : "";
|
||||
const opacity = tx.isError ? " opacity-50" : "";
|
||||
const opacity = tx.isError ? " opacity:0.5;" : "";
|
||||
const ago = escapeHtml(timeAgo(tx.timestamp));
|
||||
const iso = escapeHtml(isoDate(tx.timestamp));
|
||||
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover${opacity}" data-tx="${i}">`;
|
||||
html += `<div class="tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
||||
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
||||
html += txCounterpartyHtml(counterparty, nameStr, amountStr);
|
||||
html += `</div>`;
|
||||
|
||||
+19
-21
@@ -10,13 +10,10 @@ const {
|
||||
attachCopyHandlers,
|
||||
onViewLeave,
|
||||
formatFee,
|
||||
tokenLabel,
|
||||
nativeCurrency,
|
||||
} = require("./helpers");
|
||||
const { state, saveState } = require("../../shared/state");
|
||||
const {
|
||||
networkByChainId,
|
||||
nativeCurrencyByChainId,
|
||||
} = require("../../shared/networks");
|
||||
const { networkByChainId } = require("../../shared/networks");
|
||||
const {
|
||||
formatEther,
|
||||
formatUnits,
|
||||
@@ -74,6 +71,17 @@ function tokenAmountText(rawAmount, decimals, symbol) {
|
||||
};
|
||||
}
|
||||
|
||||
// The symbol shown for a token line, resolved from the bundled list, the
|
||||
// tokens the user tracks, and the explorer's report — the same chain the
|
||||
// amount line's scale comes from. Null when no source names one, so the token
|
||||
// lines keep saying `Unknown token` for a token nothing knows.
|
||||
function tokenLabel(address) {
|
||||
return resolveTokenSymbol(address, {
|
||||
trackedTokens: state.trackedTokens,
|
||||
wallets: state.wallets,
|
||||
});
|
||||
}
|
||||
|
||||
// Try to decode calldata using known ABIs.
|
||||
// Returns { name, description, details } or null.
|
||||
function decodeCalldata(data, toAddress) {
|
||||
@@ -212,12 +220,8 @@ function showTxFee(approvedTx) {
|
||||
const gasLimit = BigInt(approvedTx.gasLimit);
|
||||
const feePerGas = BigInt(approvedTx.maxFeePerGas || approvedTx.gasPrice);
|
||||
// Through formatFee(), as the confirmation screen's fee is, so the same
|
||||
// fee reads the same on both. In the native currency of the network shown
|
||||
// above, as the value is.
|
||||
$("approve-tx-fee").textContent = formatFee(
|
||||
gasLimit * feePerGas,
|
||||
nativeCurrencyByChainId(approvedTx.chainId),
|
||||
);
|
||||
// fee reads the same on both.
|
||||
$("approve-tx-fee").textContent = formatFee(gasLimit * feePerGas);
|
||||
|
||||
let detail =
|
||||
gasLimit.toString() +
|
||||
@@ -261,7 +265,6 @@ function showTxApproval(details) {
|
||||
amount: formatTxValue(ethValue),
|
||||
token: "ETH",
|
||||
tokenSymbol: null,
|
||||
chainId: approvedTx.chainId,
|
||||
};
|
||||
|
||||
// If this is an ERC-20 call, try to extract the real recipient and amount
|
||||
@@ -327,14 +330,10 @@ function showTxApproval(details) {
|
||||
const ethPrice = getPrice("ETH");
|
||||
const ethUsd = ethPrice ? parseFloat(ethValueFormatted) * ethPrice : null;
|
||||
const usdStr = formatUsd(ethUsd);
|
||||
// In the native currency of the network the transaction is for, which the
|
||||
// Network line names, not the active network's: a site can switch the
|
||||
// active network after this transaction is prepared and back before it is
|
||||
// signed.
|
||||
$("approve-tx-value").textContent =
|
||||
ethValueFormatted +
|
||||
" " +
|
||||
nativeCurrencyByChainId(approvedTx.chainId) +
|
||||
nativeCurrency() +
|
||||
(usdStr ? " (" + usdStr + ")" : "");
|
||||
|
||||
showTxFee(approvedTx);
|
||||
@@ -822,10 +821,9 @@ function setSignButtonBusy(busy) {
|
||||
}
|
||||
|
||||
// Say so on the approval screen itself, and disable the approve button, when
|
||||
// the address the approval was raised for belongs to a wallet whose key
|
||||
// getSignerForAddress refuses. Without this the screen would take a password
|
||||
// and fail after deriving it. Reject stays available; the wallet is not
|
||||
// touched.
|
||||
// the address the approval was raised for belongs to a wallet whose keys
|
||||
// cannot be derived. Without this the screen would take a password and fail
|
||||
// after deriving it. Reject stays available; the wallet is not touched.
|
||||
// Returns true when it gated.
|
||||
function gateOnWalletDefect(errorId, buttonId, address) {
|
||||
const owner = findWalletFor(address);
|
||||
|
||||
@@ -13,15 +13,13 @@ const {
|
||||
displaySymbol,
|
||||
nativeCurrency,
|
||||
renderAddressHtml,
|
||||
blockieHtml,
|
||||
attachCopyHandlers,
|
||||
goBack,
|
||||
onViewLeave,
|
||||
formatFee,
|
||||
} = require("./helpers");
|
||||
const { state, currentNetwork } = require("../../shared/state");
|
||||
const { state } = require("../../shared/state");
|
||||
const { getSignerForAddress } = require("../../shared/wallet");
|
||||
const { walletDefect } = require("../../shared/walletDefects");
|
||||
const { decryptWithPassword } = require("../../shared/vault");
|
||||
const { formatUsd, getPrice } = require("../../shared/prices");
|
||||
const { getProvider } = require("../../shared/balances");
|
||||
@@ -45,10 +43,10 @@ const {
|
||||
FEE_UNAVAILABLE,
|
||||
feeReserveWei,
|
||||
feeEstimateWei,
|
||||
maxEthAmount,
|
||||
validateTransfer,
|
||||
} = require("../../shared/txValidation");
|
||||
const { log } = require("../../shared/log");
|
||||
const makeBlockie = require("ethereum-blockies-base64");
|
||||
const txStatus = require("./txStatus");
|
||||
|
||||
let pendingTx = null;
|
||||
@@ -56,10 +54,6 @@ let pendingTx = null;
|
||||
// filled in by estimateGas() when the estimate resolves or fails.
|
||||
let feeStatus = FEE_PENDING;
|
||||
let feeWei = null;
|
||||
// The fee fields a max ETH send is signed with: those of the estimate its
|
||||
// amount was derived from. Null for any other send, which ethers prices from
|
||||
// the node at signing time.
|
||||
let maxSendFees = null;
|
||||
|
||||
function restore() {
|
||||
const d = state.viewData;
|
||||
@@ -68,6 +62,11 @@ function restore() {
|
||||
}
|
||||
}
|
||||
|
||||
function blockieHtml(address) {
|
||||
const src = makeBlockie(address);
|
||||
return `<img src="${escapeHtml(src)}" width="48" height="48" style="image-rendering:pixelated;border-radius:50%;display:inline-block">`;
|
||||
}
|
||||
|
||||
function confirmAddressHtml(address, ensName, title) {
|
||||
const blockie = blockieHtml(address);
|
||||
return (
|
||||
@@ -83,24 +82,10 @@ function valueWithUsd(text, usdAmount) {
|
||||
return text;
|
||||
}
|
||||
|
||||
// The Amount line, with its USD value. A max ETH send's line is drawn again
|
||||
// once its amount is re-derived from the fee estimate.
|
||||
function renderAmount(txInfo) {
|
||||
const isErc20 = txInfo.token !== "ETH";
|
||||
const rawSymbol = isErc20 ? txInfo.tokenSymbol || "?" : nativeCurrency();
|
||||
const price = isErc20 ? getPrice(rawSymbol) : getPrice("ETH");
|
||||
const amountUsd = price ? parseFloat(txInfo.amount) * price : null;
|
||||
$("confirm-amount").textContent = valueWithUsd(
|
||||
txInfo.amount + " " + displaySymbol(rawSymbol),
|
||||
amountUsd,
|
||||
);
|
||||
}
|
||||
|
||||
function show(txInfo) {
|
||||
pendingTx = txInfo;
|
||||
feeStatus = FEE_PENDING;
|
||||
feeWei = null;
|
||||
maxSendFees = null;
|
||||
|
||||
const isErc20 = txInfo.token !== "ETH";
|
||||
// The raw symbol is the price-table key; the capped one is what the
|
||||
@@ -147,11 +132,18 @@ function show(txInfo) {
|
||||
);
|
||||
$("confirm-to-ens").classList.add("hidden");
|
||||
|
||||
renderAmount(txInfo);
|
||||
|
||||
// Balance (with inline USD)
|
||||
// Amount (with inline USD)
|
||||
const ethPrice = getPrice("ETH");
|
||||
const tokenPrice = getPrice(rawSymbol);
|
||||
const amountNum = parseFloat(txInfo.amount);
|
||||
const price = isErc20 ? tokenPrice : ethPrice;
|
||||
const amountUsd = price ? amountNum * price : null;
|
||||
$("confirm-amount").textContent = valueWithUsd(
|
||||
txInfo.amount + " " + symbol,
|
||||
amountUsd,
|
||||
);
|
||||
|
||||
// Balance (with inline USD)
|
||||
if (isErc20) {
|
||||
// null is a balance whose scale nothing knows, not a balance of zero
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/349). The send is
|
||||
@@ -213,13 +205,6 @@ function show(txInfo) {
|
||||
nativeCurrency() +
|
||||
" to this address and try again.";
|
||||
|
||||
// Shown later, once checkRecipientHistory() finds a contract.
|
||||
$("confirm-contract-warning").textContent =
|
||||
"WARNING: The recipient is a smart contract. Sending " +
|
||||
nativeCurrency() +
|
||||
" or tokens directly to a contract may result in permanent loss of" +
|
||||
" funds.";
|
||||
|
||||
// The fee-unknown message names its cause, which is also known here.
|
||||
// Without the token's scale estimateGas() cannot encode the transfer, so
|
||||
// the estimate fails every time and going back cannot help; any other
|
||||
@@ -388,8 +373,8 @@ async function estimateGas(txInfo) {
|
||||
}
|
||||
|
||||
// What the node will require to be reserved, which is what the gate
|
||||
// must be: the send is broadcast as a type-2 transaction priced at
|
||||
// maxFeePerGas, which only a max ETH send pins (see below).
|
||||
// must be: the send pins no fee fields, so it is broadcast as a
|
||||
// type-2 transaction priced at maxFeePerGas.
|
||||
const gasCostWei = feeReserveWei(gasLimit, feeData);
|
||||
if (gasCostWei === null) {
|
||||
throw new Error("no usable gas price from the provider");
|
||||
@@ -406,8 +391,7 @@ async function estimateGas(txInfo) {
|
||||
// The fee line goes through formatFee(), as the approval screen's
|
||||
// does, so the same fee reads the same on both.
|
||||
if (estimateWei !== null && estimateWei < gasCostWei) {
|
||||
$("confirm-fee-amount").textContent =
|
||||
"~" + formatFee(estimateWei, nativeCurrency());
|
||||
$("confirm-fee-amount").textContent = "~" + formatFee(estimateWei);
|
||||
$("confirm-fee-reserve").textContent =
|
||||
"up to " +
|
||||
truncateAmountNeverZero(formatEther(gasCostWei)) +
|
||||
@@ -419,38 +403,11 @@ async function estimateGas(txInfo) {
|
||||
// No spread to report: either there is no estimate, or the node
|
||||
// quotes a gas price at or above maxFeePerGas, so the expected
|
||||
// cost is not below the reserve. Show the reserve alone.
|
||||
$("confirm-fee-amount").textContent = formatFee(
|
||||
gasCostWei,
|
||||
nativeCurrency(),
|
||||
);
|
||||
$("confirm-fee-amount").textContent = formatFee(gasCostWei);
|
||||
setVisible("confirm-fee-reserve", false);
|
||||
}
|
||||
feeStatus = FEE_KNOWN;
|
||||
feeWei = gasCostWei;
|
||||
// A max ETH send is the balance minus this estimate's reserve, not the
|
||||
// Send screen's, and is signed with this estimate's fee fields: fees
|
||||
// fetched again at signing could exceed the reserve it leaves, and the
|
||||
// node would refuse it for want of funds. Where the balance no longer
|
||||
// covers the fee, the amount is left as it is and the balance check
|
||||
// below says so.
|
||||
if (txInfo.max && txInfo.token === "ETH") {
|
||||
const amount = maxEthAmount(txInfo.balance, gasCostWei);
|
||||
if (amount !== null) {
|
||||
txInfo.amount = amount;
|
||||
renderAmount(txInfo);
|
||||
// Priced as feeReserveWei() priced the reserve: maxFeePerGas,
|
||||
// or gasPrice on a network with no type-2 pricing.
|
||||
if (feeData.maxFeePerGas != null) {
|
||||
maxSendFees = {
|
||||
gasLimit,
|
||||
maxFeePerGas: feeData.maxFeePerGas,
|
||||
maxPriorityFeePerGas: feeData.maxPriorityFeePerGas,
|
||||
};
|
||||
} else {
|
||||
maxSendFees = { gasLimit, gasPrice: feeData.gasPrice };
|
||||
}
|
||||
}
|
||||
}
|
||||
renderValidation(txInfo);
|
||||
} catch (e) {
|
||||
log.errorf("gas estimation failed:", e.shortMessage || e.message);
|
||||
@@ -464,19 +421,18 @@ async function estimateGas(txInfo) {
|
||||
}
|
||||
|
||||
// Populate the transaction this send describes, enforce the fee bound against
|
||||
// the fees that were actually filled in, then sign and broadcast it. Apart
|
||||
// from a max ETH send, which passes its estimate's fee fields as `fees`, the
|
||||
// send pins no fee fields, so ethers fills maxFeePerGas and the gas limit from
|
||||
// what the configured RPC node answers, with nothing otherwise bounding what a
|
||||
// the fees that were actually filled in, then sign and broadcast it. The send
|
||||
// pins no fee fields, so ethers fills maxFeePerGas and the gas limit from what
|
||||
// the configured RPC node answers, with nothing otherwise bounding what a
|
||||
// hostile node can set — the dApp path's ceilings never reached this one.
|
||||
// Populating before the check is what makes assertWithinCeilings() see the
|
||||
// same numbers that would be signed; it throws an ApprovalMismatchError when
|
||||
// the product gasLimit × maxFeePerGas is over the bound, which the caller
|
||||
// shows in the reserved error area rather than sending.
|
||||
async function populateVerifyAndSend(connectedSigner, tx, fees = null) {
|
||||
async function populateVerifyAndSend(connectedSigner, tx) {
|
||||
let request;
|
||||
if (tx.token === "ETH") {
|
||||
request = { to: tx.to, value: parseEther(tx.amount), ...fees };
|
||||
request = { to: tx.to, value: parseEther(tx.amount) };
|
||||
} else {
|
||||
const contract = new Contract(tx.token, ERC20_ABI, connectedSigner);
|
||||
// The contract's decimals() is read to be COMPARED with the scale the
|
||||
@@ -538,15 +494,6 @@ function init(_ctx) {
|
||||
onViewLeave("confirm-tx", clearPassword);
|
||||
|
||||
$("btn-confirm-send").addEventListener("click", async () => {
|
||||
const wallet = state.wallets[state.selectedWallet];
|
||||
// Every Send button refuses a defective wallet before this screen,
|
||||
// but the popup also reopens onto it from a saved view.
|
||||
const defect = walletDefect(wallet);
|
||||
if (defect) {
|
||||
showError("confirm-tx-password-error", defect.shortMessage);
|
||||
return;
|
||||
}
|
||||
|
||||
const password = $("confirm-tx-password").value;
|
||||
if (!password) {
|
||||
showError(
|
||||
@@ -556,6 +503,7 @@ function init(_ctx) {
|
||||
return;
|
||||
}
|
||||
|
||||
const wallet = state.wallets[state.selectedWallet];
|
||||
let decryptedSecret;
|
||||
hideError("confirm-tx-password-error");
|
||||
|
||||
@@ -575,10 +523,6 @@ function init(_ctx) {
|
||||
$("btn-confirm-send").disabled = true;
|
||||
$("btn-confirm-send").classList.add("text-muted");
|
||||
|
||||
// The network it is sent on. The wait, success and error screens
|
||||
// label its amount by this, not by the network active when they draw.
|
||||
pendingTx.chainId = currentNetwork().chainId;
|
||||
|
||||
let tx;
|
||||
try {
|
||||
const signer = getSignerForAddress(
|
||||
@@ -589,11 +533,7 @@ function init(_ctx) {
|
||||
const provider = getProvider(state.rpcUrl, state.networkId);
|
||||
const connectedSigner = signer.connect(provider);
|
||||
|
||||
tx = await populateVerifyAndSend(
|
||||
connectedSigner,
|
||||
pendingTx,
|
||||
maxSendFees,
|
||||
);
|
||||
tx = await populateVerifyAndSend(connectedSigner, pendingTx);
|
||||
|
||||
// Best-effort: clear decrypted secret after use.
|
||||
// Note: JS strings are immutable; this nulls the reference but
|
||||
|
||||
@@ -12,7 +12,6 @@ const {
|
||||
removeWalletFromState,
|
||||
broadcastActiveChanged,
|
||||
} = require("../../shared/walletDelete");
|
||||
const { INVISIBLE_CHARACTERS } = require("../../shared/symbolSpoof");
|
||||
|
||||
let deleteWalletIndex = null;
|
||||
let lostPasswordIndex = null;
|
||||
@@ -21,31 +20,21 @@ let ctx = null;
|
||||
// The name shown for a wallet, and on the lost-password screen the string
|
||||
// the user has to type back. One function so the two cannot disagree: a
|
||||
// confirmation that asks for a name other than the one on screen is
|
||||
// unusable. A name that shows nothing at all (only spaces, or only
|
||||
// zero-width characters) is replaced by "Wallet N" for the same reason:
|
||||
// there would be nothing on screen to type back.
|
||||
// unusable.
|
||||
function displayName(walletIdx) {
|
||||
const wallet = state.wallets[walletIdx];
|
||||
const name = wallet && wallet.name;
|
||||
if (name && confirmKey(name)) return name;
|
||||
return "Wallet " + (walletIdx + 1);
|
||||
return (wallet && wallet.name) || "Wallet " + (walletIdx + 1);
|
||||
}
|
||||
|
||||
// What the typed confirmation and the wallet name are compared as. HTML
|
||||
// collapses runs of whitespace when it renders the name, so a wallet named
|
||||
// "My Wallet" with two spaces DISPLAYS as "My Wallet": the user cannot
|
||||
// see the second space and cannot type a string that matches the stored
|
||||
// name. Characters that paint nothing, such as a zero-width space, are
|
||||
// invisible the same way and are removed first. Comparing this form on
|
||||
// both sides is what keeps the confirmation satisfiable, on the one screen
|
||||
// whose whole purpose is unwedging a user who is already stuck. Case and
|
||||
// surrounding space go the same way.
|
||||
// name. Comparing collapsed on both sides is what keeps the confirmation
|
||||
// satisfiable, on the one screen whose whole purpose is unwedging a user
|
||||
// who is already stuck. Case and surrounding space go the same way.
|
||||
function confirmKey(name) {
|
||||
return name
|
||||
.replace(INVISIBLE_CHARACTERS, "")
|
||||
.trim()
|
||||
.replace(/\s+/g, " ")
|
||||
.toLowerCase();
|
||||
return name.trim().replace(/\s+/g, " ").toLowerCase();
|
||||
}
|
||||
|
||||
// Drop the password from the DOM and the wallet selection from the
|
||||
@@ -185,16 +174,14 @@ function init(_ctx) {
|
||||
return;
|
||||
}
|
||||
|
||||
// Case, surrounding spaces, repeated inner spaces and invisible
|
||||
// characters are not part of the confirmation; see confirmKey().
|
||||
// This asks whether the user knows which wallet they are on; it is
|
||||
// not a secret, and refusing "wallet 2" for "Wallet 2" would only
|
||||
// teach the user to distrust the control. An empty field is
|
||||
// refused whatever the wallet is called, so no stored name can
|
||||
// ever be confirmed by typing nothing.
|
||||
const typed = confirmKey($("delete-wallet-lost-name-input").value);
|
||||
// Case, surrounding spaces and repeated inner spaces are not part
|
||||
// of the confirmation; see confirmKey(). This asks whether the
|
||||
// user knows which wallet they are on; it is not a secret, and
|
||||
// refusing "wallet 2" for "Wallet 2" would only teach the user to
|
||||
// distrust the control.
|
||||
const typed = $("delete-wallet-lost-name-input").value;
|
||||
const expected = displayName(lostPasswordIndex);
|
||||
if (typed === "" || typed !== confirmKey(expected)) {
|
||||
if (confirmKey(typed) !== confirmKey(expected)) {
|
||||
$("delete-wallet-lost-flash").textContent =
|
||||
"That is not the name of this wallet. Type " +
|
||||
expected +
|
||||
|
||||
@@ -98,7 +98,7 @@ function show(walletIdx, addrIdx) {
|
||||
|
||||
$("export-privkey-title").textContent =
|
||||
wallet.name + " — Address " + (addrIdx + 1);
|
||||
const addrContainer = $("export-privkey-address");
|
||||
const addrContainer = $("export-privkey-dot").parentElement;
|
||||
addrContainer.innerHTML = renderAddressHtml(addr.address);
|
||||
attachCopyHandlers(addrContainer);
|
||||
|
||||
|
||||
+33
-76
@@ -13,12 +13,10 @@
|
||||
// reasoning behind it are; it is re-exported below so views keep importing
|
||||
// it from here.
|
||||
const { formatEther } = require("ethers");
|
||||
const makeBlockie = require("ethereum-blockies-base64");
|
||||
const {
|
||||
truncateAmountNeverZero,
|
||||
isBelowOneMillionth,
|
||||
} = require("../../shared/amountDisplay");
|
||||
const { resolveTokenSymbol } = require("../../shared/approvalAmount");
|
||||
const { DEBUG } = require("../../shared/constants");
|
||||
const { escapeHtml } = require("../../shared/html");
|
||||
const { isDebug } = require("../../shared/log");
|
||||
@@ -54,8 +52,9 @@ const VIEWS = [
|
||||
"export-privkey",
|
||||
"show-phrase",
|
||||
// Shown by src/popup/views/stateRecovery.js when the stored profile
|
||||
// cannot be read, never by showView() (see there), but listed so that
|
||||
// every view-hiding loop covers it.
|
||||
// cannot be read. It is never reached through showView() — by then the
|
||||
// state singleton this file writes on every navigation refuses to be read
|
||||
// — but it is listed so that every view-hiding loop covers it.
|
||||
"state-recovery",
|
||||
];
|
||||
|
||||
@@ -86,28 +85,12 @@ function hideError(id) {
|
||||
el.style.visibility = "hidden";
|
||||
}
|
||||
|
||||
// Set when src/popup/index.js passes the recovery screen to showView(), and
|
||||
// never cleared. Kept in memory for this popup's life, never in
|
||||
// state.currentView, which is saved: a popup opened later must not inherit it.
|
||||
let stateRecoveryShown = false;
|
||||
|
||||
function showView(name) {
|
||||
// The recovery screen, once up, is never replaced: work still running
|
||||
// when it went up, such as a transaction wait, must not take the user off
|
||||
// it or clear what they exported or typed there
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/373).
|
||||
if (stateRecoveryShown) return;
|
||||
const leaving = state.currentView;
|
||||
if (leaving && leaving !== name) {
|
||||
const onLeave = viewLeaveHandlers.get(leaving);
|
||||
if (onLeave) onLeave();
|
||||
}
|
||||
// Passed here only so the screen it replaces is left like any other;
|
||||
// stateRecovery.show() raises it, and it is never the current view.
|
||||
if (name === "state-recovery") {
|
||||
stateRecoveryShown = true;
|
||||
return;
|
||||
}
|
||||
for (const v of VIEWS) {
|
||||
const el = document.getElementById(`view-${v}`);
|
||||
if (el) {
|
||||
@@ -270,40 +253,25 @@ function unknownableAmount(balance) {
|
||||
}
|
||||
|
||||
// The active network's native token symbol, `ETH` on mainnet and `SepoliaETH`
|
||||
// on Sepolia, as src/shared/networks.js names it. The wallet's balances and
|
||||
// the Send and confirmation screens, which send on the active network, label a
|
||||
// native amount with this; a transaction already made or requested is labelled
|
||||
// by its own chain id, through nativeCurrencyByChainId() in networks.js. The
|
||||
// "ETH" that state.selectedToken and txInfo.token hold is the native token's
|
||||
// id, not its label, and stays "ETH" on every network.
|
||||
// on Sepolia, as src/shared/networks.js names it. Every screen labels a native
|
||||
// amount with this. The "ETH" that state.selectedToken and txInfo.token hold
|
||||
// is the native token's id, not its label, and stays "ETH" on every network.
|
||||
function nativeCurrency() {
|
||||
return currentNetwork().nativeCurrency;
|
||||
}
|
||||
|
||||
// The symbol shown for a token line, resolved from the bundled list, the
|
||||
// tokens the user tracks, and the explorer's report — the same chain the
|
||||
// amount line's scale comes from. Null when no source names one, so the token
|
||||
// lines keep saying `Unknown token` for a token nothing knows.
|
||||
function tokenLabel(address) {
|
||||
return resolveTokenSymbol(address, {
|
||||
trackedTokens: state.trackedTokens,
|
||||
wallets: state.wallets,
|
||||
});
|
||||
}
|
||||
|
||||
// A network fee in wei as the confirmation and approval screens both show it:
|
||||
// the ETH figure through truncateAmountNeverZero() and labelled `symbol`, the
|
||||
// native currency of the network the fee is paid on, then its USD value when
|
||||
// the ETH price is known. The USD value is of the exact fee, not of the
|
||||
// truncated figure.
|
||||
function formatFee(wei, symbol) {
|
||||
// the ETH figure through truncateAmountNeverZero(), then its USD value when the
|
||||
// ETH price is known. The USD value is of the exact fee, not of the truncated
|
||||
// figure.
|
||||
function formatFee(wei) {
|
||||
const eth = formatEther(wei);
|
||||
const ethPrice = getPrice("ETH");
|
||||
const usd = ethPrice ? formatUsd(parseFloat(eth) * ethPrice) : "";
|
||||
return (
|
||||
truncateAmountNeverZero(eth) +
|
||||
" " +
|
||||
symbol +
|
||||
nativeCurrency() +
|
||||
(usd ? " (" + usd + ")" : "")
|
||||
);
|
||||
}
|
||||
@@ -325,7 +293,7 @@ function balanceLine(symbol, amount, price, tokenId) {
|
||||
const qty = amount === null ? "quantity unknown" : amount.toFixed(4);
|
||||
const usd =
|
||||
price && amount !== null
|
||||
? escapeHtml(formatUsd(amount * price)) || " "
|
||||
? formatUsd(amount * price) || " "
|
||||
: " ";
|
||||
// tokenId is a contract address out of the same explorer JSON, and it
|
||||
// lands inside a quoted attribute.
|
||||
@@ -335,7 +303,7 @@ function balanceLine(symbol, amount, price, tokenId) {
|
||||
: "";
|
||||
return (
|
||||
`<div class="flex text-xs${clickClass}"${tokenAttr}>` +
|
||||
`<span class="flex justify-between w-[42ch] max-w-full">` +
|
||||
`<span class="flex justify-between" style="width:42ch;max-width:100%">` +
|
||||
`<span>${escapeHtml(displaySymbol(symbol))}</span>` +
|
||||
`<span>${qty}</span>` +
|
||||
`</span>` +
|
||||
@@ -430,26 +398,23 @@ function truncateMiddle(str, maxLen) {
|
||||
|
||||
// 16 colors evenly spaced around the hue wheel (22.5° apart),
|
||||
// all at HSL saturation 70%, lightness 50% for uniform vibrancy.
|
||||
// Each is a whole Tailwind class: Tailwind builds only the classes it finds
|
||||
// written out in the source, so the class name cannot be put together at
|
||||
// runtime.
|
||||
const ADDRESS_COLORS = [
|
||||
"bg-[#d92626]",
|
||||
"bg-[#d96926]",
|
||||
"bg-[#d9ac26]",
|
||||
"bg-[#c2d926]",
|
||||
"bg-[#80d926]",
|
||||
"bg-[#3dd926]",
|
||||
"bg-[#26d953]",
|
||||
"bg-[#26d996]",
|
||||
"bg-[#26d9d9]",
|
||||
"bg-[#2696d9]",
|
||||
"bg-[#2653d9]",
|
||||
"bg-[#3d26d9]",
|
||||
"bg-[#8026d9]",
|
||||
"bg-[#c226d9]",
|
||||
"bg-[#d926ac]",
|
||||
"bg-[#d92669]",
|
||||
"#d92626",
|
||||
"#d96926",
|
||||
"#d9ac26",
|
||||
"#c2d926",
|
||||
"#80d926",
|
||||
"#3dd926",
|
||||
"#26d953",
|
||||
"#26d996",
|
||||
"#26d9d9",
|
||||
"#2696d9",
|
||||
"#2653d9",
|
||||
"#3d26d9",
|
||||
"#8026d9",
|
||||
"#c226d9",
|
||||
"#d926ac",
|
||||
"#d92669",
|
||||
];
|
||||
|
||||
function addressColor(address) {
|
||||
@@ -459,12 +424,7 @@ function addressColor(address) {
|
||||
|
||||
function addressDotHtml(address) {
|
||||
const color = addressColor(address);
|
||||
return `<span class="inline-block w-[8px] h-[8px] rounded-[50%] ${color} mr-[4px] align-middle shrink-0"></span>`;
|
||||
}
|
||||
|
||||
function blockieHtml(address) {
|
||||
const src = makeBlockie(address);
|
||||
return `<img src="${escapeHtml(src)}" width="48" height="48" class="inline-block rounded-[50%] [image-rendering:pixelated]">`;
|
||||
return `<span style="width:8px;height:8px;border-radius:50%;display:inline-block;background:${color};margin-right:4px;vertical-align:middle;flex-shrink:0;"></span>`;
|
||||
}
|
||||
|
||||
// Look up an address across all wallets and return its title
|
||||
@@ -513,9 +473,6 @@ function formatAddressHtml(address, ensName, maxLen, title) {
|
||||
return renderAddressHtml(address, { title, ensName, maxLen });
|
||||
}
|
||||
|
||||
// A transaction's time as every screen shows it (README, Display
|
||||
// Consistency): the ISO datetime, in UTC when the UTC Timestamps setting is
|
||||
// on, and the relative age. Views import these two; they keep no copies.
|
||||
function isoDate(timestamp) {
|
||||
const d = new Date(timestamp * 1000);
|
||||
const pad = (n) => String(n).padStart(2, "0");
|
||||
@@ -574,7 +531,7 @@ function timeAgo(timestamp) {
|
||||
|
||||
// Shared external-link icon SVG used across all views.
|
||||
const EXT_ICON =
|
||||
`<span class="inline-block w-[10px] h-[10px] ml-[4px] align-middle">` +
|
||||
`<span style="display:inline-block;width:10px;height:10px;margin-left:4px;vertical-align:middle">` +
|
||||
`<svg viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5">` +
|
||||
`<path d="M4.5 1.5H2a.5.5 0 00-.5.5v8a.5.5 0 00.5.5h8a.5.5 0 00.5-.5V7.5"/>` +
|
||||
`<path d="M7 1.5h3.5V5M7 5.5L10.5 1.5"/>` +
|
||||
@@ -715,10 +672,9 @@ module.exports = {
|
||||
addressHoldsFunds,
|
||||
unknownableAmount,
|
||||
nativeCurrency,
|
||||
tokenLabel,
|
||||
formatFee,
|
||||
addressColor,
|
||||
addressDotHtml,
|
||||
blockieHtml,
|
||||
escapeHtml,
|
||||
displaySymbol,
|
||||
addressTitle,
|
||||
@@ -728,6 +684,7 @@ module.exports = {
|
||||
renderAddressHtml,
|
||||
copyableHtml,
|
||||
attachCopyHandlers,
|
||||
etherscanAddressUrl,
|
||||
etherscanLinkHtml,
|
||||
explorerUrl,
|
||||
EXT_ICON,
|
||||
|
||||
+10
-19
@@ -15,12 +15,7 @@ const {
|
||||
attachCopyHandlers,
|
||||
pushCurrentView,
|
||||
} = require("./helpers");
|
||||
const {
|
||||
state,
|
||||
saveState,
|
||||
currentAddress,
|
||||
currentNetwork,
|
||||
} = require("../../shared/state");
|
||||
const { state, saveState, currentAddress } = require("../../shared/state");
|
||||
const { notify } = require("../../shared/browserApi");
|
||||
const {
|
||||
updateSendBalance,
|
||||
@@ -63,7 +58,7 @@ function renderTotalValue() {
|
||||
const ethPrice = getPrice("ETH");
|
||||
if (priceEl) {
|
||||
priceEl.innerHTML = ethPrice
|
||||
? escapeHtml(formatUsd(ethPrice) + " USD/ETH")
|
||||
? formatUsd(ethPrice) + " USD/ETH"
|
||||
: " ";
|
||||
}
|
||||
|
||||
@@ -79,8 +74,7 @@ function renderTotalValue() {
|
||||
el.textContent = ethStr + ethUsd;
|
||||
|
||||
if (subEl) {
|
||||
subEl.innerHTML =
|
||||
escapeHtml(formatAddressTotal(getAddressValue(addr))) || " ";
|
||||
subEl.innerHTML = formatAddressTotal(getAddressValue(addr)) || " ";
|
||||
}
|
||||
}
|
||||
|
||||
@@ -131,10 +125,10 @@ function renderHomeTxList(ctx) {
|
||||
const title = addressTitle(counterparty, state.wallets);
|
||||
const titleStr = title ? escapeHtml(title) : "";
|
||||
const err = tx.isError ? " (failed)" : "";
|
||||
const opacity = tx.isError ? " opacity-50" : "";
|
||||
const opacity = tx.isError ? " opacity:0.5;" : "";
|
||||
const ago = escapeHtml(timeAgo(tx.timestamp));
|
||||
const iso = escapeHtml(isoDate(tx.timestamp));
|
||||
html += `<div class="home-tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover${opacity}" data-tx="${i}">`;
|
||||
html += `<div class="home-tx-row py-2 border-b border-border-light text-xs cursor-pointer hover:bg-hover" data-tx="${i}" style="${opacity}">`;
|
||||
html += `<div class="flex justify-between"><span class="text-muted" title="${iso}">${ago}</span><span>${dirLabel}${err}</span></div>`;
|
||||
html += txCounterpartyHtml(counterparty, titleStr, amountStr);
|
||||
html += `</div>`;
|
||||
@@ -192,7 +186,7 @@ async function loadHomeTxs(ctx) {
|
||||
fetchRecentTransactions(
|
||||
addr,
|
||||
state.blockscoutUrl,
|
||||
currentNetwork().chainId,
|
||||
nativeCurrency(),
|
||||
),
|
||||
);
|
||||
const results = await Promise.all(fetches);
|
||||
@@ -225,9 +219,6 @@ async function loadHomeTxs(ctx) {
|
||||
homeTxs = merged.slice(0, 25);
|
||||
renderHomeTxList(ctx);
|
||||
} catch (e) {
|
||||
// Cancelled by the popup closing, not failed: see pageClosed in
|
||||
// src/popup/index.js.
|
||||
if (ctx.pageClosed.aborted) return;
|
||||
log.errorf("loadHomeTxs failed:", e.message);
|
||||
const list = $("home-tx-list");
|
||||
if (list) {
|
||||
@@ -244,7 +235,7 @@ function walletListHtml() {
|
||||
state.wallets.forEach((wallet, wi) => {
|
||||
const defect = walletDefect(wallet);
|
||||
html += `<div>`;
|
||||
html += `<div class="flex justify-between items-center bg-section py-1 px-2 -mx-2">`;
|
||||
html += `<div class="flex justify-between items-center bg-section py-1 px-2" style="margin:0 -0.5rem">`;
|
||||
html += `<span class="font-bold cursor-pointer wallet-name underline decoration-dashed" data-wallet="${wi}">${escapeHtml(wallet.name)}</span>`;
|
||||
// No "+" on a defective wallet: deriving another address from that
|
||||
// xpub would only add one more address the key does not produce
|
||||
@@ -258,12 +249,12 @@ function walletListHtml() {
|
||||
wallet.addresses.forEach((addr, ai) => {
|
||||
html += `<div class="address-row py-1 border-b border-border-light cursor-pointer hover:bg-hover" data-wallet="${wi}" data-address="${ai}">`;
|
||||
const isActive = state.activeAddress === addr.address;
|
||||
const infoBtn = `<span class="btn-addr-info text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg p-0" data-wallet="${wi}" data-address="${ai}">[info]</span>`;
|
||||
const infoBtn = `<span class="btn-addr-info text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg" style="padding:0" data-wallet="${wi}" data-address="${ai}">[info]</span>`;
|
||||
// Only where a wallet can spare the address: a wallet holding a
|
||||
// single address has no remove control, because its last address
|
||||
// is never removable.
|
||||
const removeBtn = canRemoveAddress(wallet)
|
||||
? `<span class="btn-remove-address text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg ml-1 p-0" data-wallet="${wi}" data-address="${ai}" title="Remove this address from the wallet">[x]</span>`
|
||||
? `<span class="btn-remove-address text-xs cursor-pointer border border-border hover:bg-fg hover:text-bg ml-1" style="padding:0" data-wallet="${wi}" data-address="${ai}" title="Remove this address from the wallet">[x]</span>`
|
||||
: "";
|
||||
const dot = addressDotHtml(addr.address);
|
||||
const titleBold = isActive ? "font-bold" : "";
|
||||
@@ -284,7 +275,7 @@ function walletListHtml() {
|
||||
}
|
||||
html += `<div class="am-address text-xs">${escapeHtml(addr.address)}</div>`;
|
||||
const addrTotal = formatAddressTotal(getAddressValue(addr));
|
||||
html += `<div class="text-xs text-muted text-right min-h-[1rem]">${escapeHtml(addrTotal) || " "}</div>`;
|
||||
html += `<div class="text-xs text-muted text-right min-h-[1rem]">${addrTotal || " "}</div>`;
|
||||
html += balanceLinesForAddress(
|
||||
addr,
|
||||
state.trackedTokens,
|
||||
|
||||
+2
-114
@@ -22,25 +22,10 @@ const {
|
||||
truncateAmountNeverZero,
|
||||
isBelowOneMillionth,
|
||||
} = require("../../shared/amountDisplay");
|
||||
const {
|
||||
feeReserveWei,
|
||||
maxEthAmount,
|
||||
maxTokenAmount,
|
||||
} = require("../../shared/txValidation");
|
||||
const { log } = require("../../shared/log");
|
||||
const { getAddress, parseEther } = require("ethers");
|
||||
const { getAddress } = require("ethers");
|
||||
|
||||
const ZERO_ADDRESS = "0x0000000000000000000000000000000000000000";
|
||||
|
||||
// Whether the amount field holds what Max filled in. The confirmation screen
|
||||
// re-derives a max ETH amount from its own fee estimate; typing in the field
|
||||
// makes it an ordinary amount again.
|
||||
let amountIsMax = false;
|
||||
|
||||
// Counts the times the Send screen has opened, so a Max fee estimate started
|
||||
// before it was last opened fills nothing in.
|
||||
let sendScreenOpenings = 0;
|
||||
|
||||
/**
|
||||
* Validate a destination address string.
|
||||
* Returns { valid: true } or { valid: false, error: "..." }.
|
||||
@@ -244,102 +229,9 @@ function updateSendBalance() {
|
||||
}
|
||||
}
|
||||
|
||||
// Fill the amount field with the most the selected holding can send: a
|
||||
// token's whole balance (cut to 18 decimal places), or for ETH the exact
|
||||
// balance minus the fee reserve the confirmation screen checks against, never
|
||||
// the rounded balance the screen shows. Where there is nothing to fill in, a
|
||||
// flash message says why.
|
||||
async function fillMaxAmount() {
|
||||
const addr = currentAddress();
|
||||
if (!addr) return;
|
||||
const token = state.selectedToken || $("send-token").value;
|
||||
|
||||
if (token !== "ETH") {
|
||||
const bal = tokenBalanceAndDecimals(addr, token).tokenBalance;
|
||||
if (bal == null) {
|
||||
showFlash("This token's balance is unknown.");
|
||||
return;
|
||||
}
|
||||
const amount = maxTokenAmount(bal);
|
||||
if (!(parseFloat(amount) > 0)) {
|
||||
showFlash("This token's balance is zero.");
|
||||
return;
|
||||
}
|
||||
$("send-amount").value = amount;
|
||||
amountIsMax = true;
|
||||
return;
|
||||
}
|
||||
|
||||
// The fee is estimated for this recipient, as the confirmation screen
|
||||
// estimates it: sending to a contract can cost more gas.
|
||||
const to = $("send-to").value.trim();
|
||||
if (!validateToAddress(to).valid) {
|
||||
showFlash("Please enter a recipient address first.");
|
||||
return;
|
||||
}
|
||||
const typed = $("send-amount").value;
|
||||
const opening = sendScreenOpenings;
|
||||
let feeWei = null;
|
||||
try {
|
||||
const provider = getProvider(state.rpcUrl, state.networkId);
|
||||
const [feeData, gasLimit] = await Promise.all([
|
||||
provider.getFeeData(),
|
||||
provider.estimateGas({
|
||||
from: addr.address,
|
||||
to,
|
||||
value: parseEther(addr.balance || "0"),
|
||||
}),
|
||||
]);
|
||||
feeWei = feeReserveWei(gasLimit, feeData);
|
||||
} catch (e) {
|
||||
log.errorf(
|
||||
"max amount fee estimate failed:",
|
||||
e.shortMessage || e.message,
|
||||
);
|
||||
}
|
||||
// While the estimate was in flight the user left the screen (and perhaps
|
||||
// opened it again), typed an amount, or changed the address, the holding
|
||||
// or the recipient: what they did wins.
|
||||
if (
|
||||
state.currentView !== "send" ||
|
||||
sendScreenOpenings !== opening ||
|
||||
currentAddress()?.address !== addr.address ||
|
||||
(state.selectedToken || $("send-token").value) !== token ||
|
||||
$("send-to").value.trim() !== to ||
|
||||
$("send-amount").value !== typed
|
||||
) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (feeWei === null) {
|
||||
showFlash("The network fee could not be estimated.");
|
||||
return;
|
||||
}
|
||||
const amount = maxEthAmount(addr.balance, feeWei);
|
||||
if (amount === null) {
|
||||
showFlash("Your balance does not cover the network fee.");
|
||||
return;
|
||||
}
|
||||
$("send-amount").value = amount;
|
||||
amountIsMax = true;
|
||||
}
|
||||
|
||||
function init(_ctx) {
|
||||
ctx = _ctx;
|
||||
$("send-token").addEventListener("change", () => {
|
||||
// A filled-in maximum is the maximum of the holding it was filled in
|
||||
// for.
|
||||
if (amountIsMax) {
|
||||
$("send-amount").value = "";
|
||||
amountIsMax = false;
|
||||
}
|
||||
updateSendBalance();
|
||||
});
|
||||
|
||||
$("btn-send-max").addEventListener("click", fillMaxAmount);
|
||||
$("send-amount").addEventListener("input", () => {
|
||||
amountIsMax = false;
|
||||
});
|
||||
$("send-token").addEventListener("change", updateSendBalance);
|
||||
|
||||
// Initial state: disable review button until address is entered
|
||||
$("btn-send-review").disabled = true;
|
||||
@@ -416,7 +308,6 @@ function init(_ctx) {
|
||||
tokenSymbol: tokenSymbol,
|
||||
tokenBalance: tokenBalance,
|
||||
tokenDecimals: tokenDecimals,
|
||||
max: amountIsMax,
|
||||
});
|
||||
});
|
||||
|
||||
@@ -427,10 +318,7 @@ function init(_ctx) {
|
||||
});
|
||||
}
|
||||
|
||||
// Called each time the Send screen opens, with its fields cleared.
|
||||
function resetSendValidation() {
|
||||
sendScreenOpenings++;
|
||||
amountIsMax = false;
|
||||
const errorEl = $("send-to-error");
|
||||
const btn = $("btn-send-review");
|
||||
if (errorEl) errorEl.textContent = "";
|
||||
|
||||
@@ -213,7 +213,12 @@ function show() {
|
||||
versionClickCount = 0;
|
||||
|
||||
// Show debug well if debug mode is already enabled
|
||||
$("settings-debug-well").classList.toggle("hidden", !state.debugMode);
|
||||
const debugWell = $("settings-debug-well");
|
||||
if (state.debugMode) {
|
||||
debugWell.style.display = "";
|
||||
} else {
|
||||
debugWell.style.display = "none";
|
||||
}
|
||||
$("settings-debug-mode").checked = state.debugMode;
|
||||
|
||||
showView("settings");
|
||||
@@ -429,7 +434,7 @@ function init(ctx) {
|
||||
if (versionClickCount >= 10) {
|
||||
versionClickCount = 0;
|
||||
clearTimeout(versionClickTimer);
|
||||
$("settings-debug-well").classList.remove("hidden");
|
||||
$("settings-debug-well").style.display = "";
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@ function isTracked(address) {
|
||||
return state.trackedTokens.some((t) => t.address.toLowerCase() === lower);
|
||||
}
|
||||
|
||||
function nameAndSymbol(t) {
|
||||
function tokenLabel(t) {
|
||||
return t.name ? t.name + " (" + t.symbol + ")" : t.symbol;
|
||||
}
|
||||
|
||||
@@ -60,7 +60,7 @@ function renderDropdown() {
|
||||
let html = '<option value="">-- select --</option>';
|
||||
for (const t of tokens) {
|
||||
const tracked = isTracked(t.address);
|
||||
const label = nameAndSymbol(t) + (tracked ? " (tracked)" : "");
|
||||
const label = tokenLabel(t) + (tracked ? " (tracked)" : "");
|
||||
html +=
|
||||
`<option value="${escapeHtml(t.address)}"` +
|
||||
` data-symbol="${escapeHtml(t.symbol)}"` +
|
||||
|
||||
@@ -3,10 +3,8 @@
|
||||
// Everything else in the popup assumes a loaded profile: showView() reads and
|
||||
// writes the state singleton, every view renders from it, and the Settings
|
||||
// gear leads to a screen that does both. None of that is available here — by
|
||||
// the time this runs, the stored record has been REFUSED, deliberately: at
|
||||
// open loadState() refused it and reading the singleton throws
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/311), and under an open popup
|
||||
// a save refused it (https://git.eeqj.de/sneak/AutistMask/issues/373).
|
||||
// the time this runs, loadState() has REFUSED, deliberately, and reading the
|
||||
// singleton throws (https://git.eeqj.de/sneak/AutistMask/issues/311).
|
||||
//
|
||||
// So this module talks to the DOM directly and touches no state at all. It is
|
||||
// the one screen that must work when nothing else can, which is also why it
|
||||
@@ -172,11 +170,6 @@ function wire() {
|
||||
* refused, or its sentence.
|
||||
*/
|
||||
function show(problem) {
|
||||
// Already up: a later save that trips over the same record, such as a
|
||||
// refresh that was in flight when the screen went up, must not clear what
|
||||
// the user has exported or typed here.
|
||||
if (!$("view-state-recovery").classList.contains("hidden")) return;
|
||||
|
||||
const sentence =
|
||||
(problem && (problem.problem || problem.message)) || String(problem);
|
||||
|
||||
|
||||
@@ -13,17 +13,17 @@ const {
|
||||
isoDate,
|
||||
timeAgo,
|
||||
renderAddressHtml,
|
||||
blockieHtml,
|
||||
attachCopyHandlers,
|
||||
copyableHtml,
|
||||
etherscanLinkHtml,
|
||||
explorerUrl,
|
||||
displaySymbol,
|
||||
nativeCurrency,
|
||||
goBack,
|
||||
} = require("./helpers");
|
||||
const { state } = require("../../shared/state");
|
||||
const { nativeCurrencyByChainId } = require("../../shared/networks");
|
||||
const { formatEther, formatUnits } = require("ethers");
|
||||
const makeBlockie = require("ethereum-blockies-base64");
|
||||
const { log, debugFetch } = require("../../shared/log");
|
||||
const { decodeCalldata } = require("./approval");
|
||||
|
||||
@@ -42,10 +42,15 @@ function getTransactionType(tx) {
|
||||
return "Token Approval";
|
||||
return "Contract Call";
|
||||
}
|
||||
// By the token contract, not the symbol: a token chooses its own symbol
|
||||
// and can report the native token's, but only a token transfer has one.
|
||||
if (tx.contractAddress) return "ERC-20 Token Transfer";
|
||||
return "Native " + nativeCurrencyByChainId(tx.chainId) + " Transfer";
|
||||
if (tx.symbol && tx.symbol !== nativeCurrency()) {
|
||||
return "ERC-20 Token Transfer";
|
||||
}
|
||||
return "Native " + nativeCurrency() + " Transfer";
|
||||
}
|
||||
|
||||
function blockieHtml(address) {
|
||||
const src = makeBlockie(address);
|
||||
return `<img src="${escapeHtml(src)}" width="48" height="48" style="image-rendering:pixelated;border-radius:50%;display:inline-block">`;
|
||||
}
|
||||
|
||||
function txAddressHtml(address, ensName, title) {
|
||||
@@ -82,11 +87,6 @@ function show(tx) {
|
||||
isContractCall: tx.isContractCall || false,
|
||||
method: tx.method || null,
|
||||
contractAddress: tx.contractAddress || null,
|
||||
// The network the history entry was read from. The type line and
|
||||
// the fee are in its native currency, not the active network's:
|
||||
// a site can switch the active network before a later popup
|
||||
// shows this screen again.
|
||||
chainId: tx.chainId,
|
||||
},
|
||||
};
|
||||
render();
|
||||
@@ -182,7 +182,7 @@ function render() {
|
||||
if (el) el.classList.add("hidden");
|
||||
}
|
||||
|
||||
loadFullTxDetails(tx.hash, tx.to, tx.chainId);
|
||||
loadFullTxDetails(tx.hash, tx.to);
|
||||
|
||||
const isoStr = isoDate(tx.timestamp);
|
||||
$("tx-detail-time").innerHTML =
|
||||
@@ -200,7 +200,7 @@ function showDetailField(sectionId, contentId, value) {
|
||||
section.classList.remove("hidden");
|
||||
}
|
||||
|
||||
function populateOnChainDetails(txData, chainId) {
|
||||
function populateOnChainDetails(txData) {
|
||||
// Block number
|
||||
if (txData.block_number != null) {
|
||||
const blockLink = explorerUrl("block", String(txData.block_number));
|
||||
@@ -230,7 +230,7 @@ function populateOnChainDetails(txData, chainId) {
|
||||
showDetailField(
|
||||
"tx-detail-fee-section",
|
||||
"tx-detail-fee",
|
||||
feeEth + " " + nativeCurrencyByChainId(chainId),
|
||||
feeEth + " " + nativeCurrency(),
|
||||
);
|
||||
}
|
||||
|
||||
@@ -290,7 +290,7 @@ function populateOnChainDetails(txData, chainId) {
|
||||
}
|
||||
}
|
||||
|
||||
async function loadFullTxDetails(txHash, toAddress, chainId) {
|
||||
async function loadFullTxDetails(txHash, toAddress) {
|
||||
const section = $("tx-detail-calldata-section");
|
||||
const actionEl = $("tx-detail-calldata-action");
|
||||
const detailsEl = $("tx-detail-calldata-details");
|
||||
@@ -307,7 +307,7 @@ async function loadFullTxDetails(txHash, toAddress, chainId) {
|
||||
const txData = await resp.json();
|
||||
|
||||
// Populate on-chain detail fields (block, nonce, gas, fee)
|
||||
populateOnChainDetails(txData, chainId);
|
||||
populateOnChainDetails(txData);
|
||||
|
||||
const inputData = txData.raw_input || txData.input || null;
|
||||
if (!inputData || inputData === "0x") return;
|
||||
|
||||
+19
-13
@@ -12,11 +12,11 @@ const {
|
||||
etherscanLinkHtml,
|
||||
explorerUrl,
|
||||
displaySymbol,
|
||||
nativeCurrency,
|
||||
clearViewStack,
|
||||
tokenLabel,
|
||||
} = require("./helpers");
|
||||
const { resolveTokenSymbol } = require("../../shared/approvalAmount");
|
||||
const { state } = require("../../shared/state");
|
||||
const { nativeCurrencyByChainId } = require("../../shared/networks");
|
||||
const { getProvider } = require("../../shared/balances");
|
||||
const { log } = require("../../shared/log");
|
||||
|
||||
@@ -87,13 +87,9 @@ function startWait(txInfo, txHash, broadcastTime, pollNow) {
|
||||
endWait();
|
||||
const id = waitId;
|
||||
|
||||
// A native amount, here and on the success and error screens, is in the
|
||||
// native currency of txInfo.chainId, the network the transaction was sent
|
||||
// on, not the active network's: a site can switch the active network
|
||||
// while this screen is open or before a later popup resumes it.
|
||||
const symbol =
|
||||
txInfo.token === "ETH"
|
||||
? nativeCurrencyByChainId(txInfo.chainId)
|
||||
? nativeCurrency()
|
||||
: displaySymbol(txInfo.tokenSymbol || "?");
|
||||
$("wait-tx-summary").textContent = txInfo.amount + " " + symbol;
|
||||
$("wait-tx-to").innerHTML = toAddressHtml(txInfo.to);
|
||||
@@ -198,10 +194,9 @@ function showWait(txInfo, txHash) {
|
||||
// an object merely missing one of them throws a TypeError out of
|
||||
// restoreView() — which init() does not guard, skipping the rest of popup
|
||||
// init and leaving wait-tx on screen with no back control. A non-numeric
|
||||
// broadcastTime leaves an unexitable wait counting "NaNs". txInfo.token,
|
||||
// txInfo.tokenSymbol and txInfo.chainId are deliberately unchecked: they are
|
||||
// compared and coalesced rather than dereferenced, and tokenSymbol is null for
|
||||
// ETH.
|
||||
// broadcastTime leaves an unexitable wait counting "NaNs". txInfo.token and
|
||||
// txInfo.tokenSymbol are deliberately unchecked: they are compared and
|
||||
// coalesced rather than dereferenced, and tokenSymbol is null for ETH.
|
||||
function restoreWait() {
|
||||
const d = state.viewData;
|
||||
if (!d || !d.pendingWait) return false;
|
||||
@@ -229,7 +224,7 @@ function showSuccess(txInfo, txHash, blockNumber) {
|
||||
|
||||
const symbol =
|
||||
txInfo.token === "ETH"
|
||||
? nativeCurrencyByChainId(txInfo.chainId)
|
||||
? nativeCurrency()
|
||||
: displaySymbol(txInfo.tokenSymbol || "?");
|
||||
state.viewData = {
|
||||
amount: txInfo.amount,
|
||||
@@ -243,6 +238,17 @@ function showSuccess(txInfo, txHash, blockNumber) {
|
||||
ctx.doRefreshAndRender();
|
||||
}
|
||||
|
||||
// The symbol shown for a decoded token line, resolved from the bundled list,
|
||||
// the tokens the user tracks, and the explorer's report — the same chain the
|
||||
// approval screen uses. Null when no source names one, so the line keeps
|
||||
// saying `Unknown token`.
|
||||
function tokenLabel(address) {
|
||||
return resolveTokenSymbol(address, {
|
||||
trackedTokens: state.trackedTokens,
|
||||
wallets: state.wallets,
|
||||
});
|
||||
}
|
||||
|
||||
function decodedDetailsHtml(decoded) {
|
||||
if (!decoded || !decoded.details) return "";
|
||||
let html = `<div class="border border-border border-dashed p-2 mb-3">`;
|
||||
@@ -315,7 +321,7 @@ function showError(txInfo, txHash, message) {
|
||||
|
||||
const symbol =
|
||||
txInfo.token === "ETH"
|
||||
? nativeCurrencyByChainId(txInfo.chainId)
|
||||
? nativeCurrency()
|
||||
: displaySymbol(txInfo.tokenSymbol || "?");
|
||||
state.viewData = {
|
||||
amount: txInfo.amount,
|
||||
|
||||
@@ -54,11 +54,9 @@ const {
|
||||
formatEther,
|
||||
getAddress,
|
||||
getBytes,
|
||||
toQuantity,
|
||||
verifyMessage,
|
||||
verifyTypedData,
|
||||
} = require("ethers");
|
||||
const { nativeCurrencyByChainId } = require("./networks");
|
||||
|
||||
// The only transaction types this wallet signs: legacy, EIP-2930 and
|
||||
// EIP-1559. populateTransaction() produces nothing else, so nothing else can
|
||||
@@ -409,21 +407,12 @@ function assertWithinCeilings(tx) {
|
||||
price = normalizeQuantity(tx.gasPrice, "gas price");
|
||||
}
|
||||
if (price !== null && gasLimit * price > MAX_TOTAL_FEE) {
|
||||
// The fee is paid in the native currency of the network the
|
||||
// transaction is for. Every caller's transaction names it.
|
||||
const nativeCurrency = nativeCurrencyByChainId(
|
||||
present(tx.chainId) ? toQuantity(tx.chainId) : null,
|
||||
);
|
||||
throw refuse(
|
||||
"This transaction would allow a network fee of up to " +
|
||||
formatEther(gasLimit * price) +
|
||||
" " +
|
||||
nativeCurrency +
|
||||
", which is more than the " +
|
||||
" ETH, which is more than the " +
|
||||
formatEther(MAX_TOTAL_FEE) +
|
||||
" " +
|
||||
nativeCurrency +
|
||||
" this wallet will sign for.",
|
||||
" ETH this wallet will sign for.",
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
+9
-24
@@ -87,15 +87,7 @@ function rawUnits(value) {
|
||||
// way `holders` already is. Absence is never filled in here: this is the
|
||||
// upstream of every screen that displays a token amount, so a value invented
|
||||
// at this point is indistinguishable from a real one everywhere below it.
|
||||
//
|
||||
// `signal`, passed by the popup, is aborted when the popup closes; a request
|
||||
// that fails after that was cancelled by the closing and is not logged.
|
||||
async function fetchTokenBalances(
|
||||
address,
|
||||
blockscoutUrl,
|
||||
trackedTokens,
|
||||
signal,
|
||||
) {
|
||||
async function fetchTokenBalances(address, blockscoutUrl, trackedTokens) {
|
||||
try {
|
||||
const resp = await debugFetch(
|
||||
blockscoutUrl + "/addresses/" + address + "/token-balances",
|
||||
@@ -155,20 +147,20 @@ async function fetchTokenBalances(
|
||||
// null is a holding of an amount that cannot be stated, which is
|
||||
// not the same as a holding of zero, and must never render as one.
|
||||
const bal = scale === null ? null : formatTokenBalance(raw, scale);
|
||||
// null means the explorer reported no readable count, which is
|
||||
// not the same as a count of zero. This gate is not the
|
||||
// low-holder display filter: it has no user-facing off switch and
|
||||
// governs the whole balance list, so it stays strict and admits a
|
||||
// token only on a reported count — an unreported one is no
|
||||
// evidence, and `null >= LOW_HOLDER_THRESHOLD` is false. A
|
||||
// legitimate token still reaches the list through the known
|
||||
// null means the explorer reported no count, which is not the
|
||||
// same as a count of zero. This gate is not the low-holder
|
||||
// display filter: it has no user-facing off switch and governs
|
||||
// the whole balance list, so it stays strict and admits a token
|
||||
// only on a reported count — an unreported one is no evidence.
|
||||
// A legitimate token still reaches the list through the known
|
||||
// token list or by the user tracking it, and the null is carried
|
||||
// through to the views, where the two low-holder filters treat
|
||||
// an unknown count as "do not judge" rather than as zero.
|
||||
const holders = parseHoldersCount(item.token.holders_count);
|
||||
const isKnown = TOKEN_BY_ADDRESS.has(tokenAddr);
|
||||
const isTracked = trackedSet.has(tokenAddr);
|
||||
const hasEnoughHolders = holders >= LOW_HOLDER_THRESHOLD;
|
||||
const hasEnoughHolders =
|
||||
holders !== null && holders >= LOW_HOLDER_THRESHOLD;
|
||||
|
||||
// Skip spam tokens the user never asked to see
|
||||
if (!isKnown && !isTracked && !hasEnoughHolders) continue;
|
||||
@@ -198,22 +190,18 @@ async function fetchTokenBalances(
|
||||
}
|
||||
return balances;
|
||||
} catch (e) {
|
||||
if (!signal?.aborted) {
|
||||
log.errorf("fetchTokenBalances failed:", e.message);
|
||||
}
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
// Fetch ETH balances, ENS names, and ERC-20 token balances for all addresses.
|
||||
// `signal` is as for fetchTokenBalances().
|
||||
async function refreshBalances(
|
||||
wallets,
|
||||
rpcUrl,
|
||||
blockscoutUrl,
|
||||
trackedTokens,
|
||||
networkId,
|
||||
signal,
|
||||
) {
|
||||
log.debugf("refreshBalances start, rpc:", urlOrigin(rpcUrl));
|
||||
const provider = getProvider(rpcUrl, networkId);
|
||||
@@ -232,7 +220,6 @@ async function refreshBalances(
|
||||
log.debugf("ETH balance", addr.address, addr.balance);
|
||||
})
|
||||
.catch((e) => {
|
||||
if (signal?.aborted) return;
|
||||
log.errorf(
|
||||
"ETH balance failed",
|
||||
addr.address,
|
||||
@@ -256,7 +243,6 @@ async function refreshBalances(
|
||||
);
|
||||
})
|
||||
.catch((e) => {
|
||||
if (signal?.aborted) return;
|
||||
log.errorf(
|
||||
"ENS reverse failed",
|
||||
addr.address,
|
||||
@@ -272,7 +258,6 @@ async function refreshBalances(
|
||||
addr.address,
|
||||
blockscoutUrl,
|
||||
trackedTokens,
|
||||
signal,
|
||||
).then((balances) => {
|
||||
if (balances !== null) {
|
||||
addr.tokenBalances = balances;
|
||||
|
||||
@@ -33,6 +33,7 @@ const DEBUG_MNEMONIC = DEBUG
|
||||
: null;
|
||||
|
||||
const ETHEREUM_MAINNET_CHAIN_ID = "0x1";
|
||||
const ETHEREUM_SEPOLIA_CHAIN_ID = "0xaa36a7";
|
||||
|
||||
const DEFAULT_RPC_URL = "https://ethereum-rpc.publicnode.com";
|
||||
|
||||
@@ -68,6 +69,7 @@ module.exports = {
|
||||
BUILD_DEBUG_MARKER,
|
||||
DEBUG_MNEMONIC,
|
||||
ETHEREUM_MAINNET_CHAIN_ID,
|
||||
ETHEREUM_SEPOLIA_CHAIN_ID,
|
||||
DEFAULT_RPC_URL,
|
||||
DEFAULT_BLOCKSCOUT_URL,
|
||||
BIP44_ETH_PATH,
|
||||
|
||||
+6
-15
@@ -9,22 +9,13 @@
|
||||
|
||||
const LOW_HOLDER_THRESHOLD = 1000;
|
||||
|
||||
// Parse an explorer-supplied holders_count into a number, or null when it is
|
||||
// not one. Only a whole number of zero or more, or a string made of nothing
|
||||
// but the digits 0-9, is a count. Anything else is null, never read in part:
|
||||
// "1,000", "0x10" and "1e3" are unknown, not 1, 0 and 1, because a count we
|
||||
// cannot read is not a low count. A count above Number.MAX_SAFE_INTEGER is
|
||||
// null too: a number cannot hold it exactly, so it would come back rounded,
|
||||
// or as Infinity.
|
||||
// Parse an explorer-supplied holders_count into a number, or null when the
|
||||
// explorer did not report one. Anything unparseable is unknown too: a count
|
||||
// we cannot read is not a count of zero.
|
||||
function parseHoldersCount(raw) {
|
||||
if (typeof raw === "number") {
|
||||
return Number.isSafeInteger(raw) && raw >= 0 ? raw : null;
|
||||
}
|
||||
if (typeof raw === "string" && /^[0-9]+$/.test(raw)) {
|
||||
const count = Number(raw);
|
||||
return Number.isSafeInteger(count) ? count : null;
|
||||
}
|
||||
return null;
|
||||
if (raw === null || raw === undefined || raw === "") return null;
|
||||
const n = parseInt(raw, 10);
|
||||
return Number.isFinite(n) ? n : null;
|
||||
}
|
||||
|
||||
// True only for a token the explorer reported as having fewer holders than
|
||||
|
||||
@@ -76,13 +76,10 @@ function networkByChainId(chainId) {
|
||||
return null;
|
||||
}
|
||||
|
||||
// The native currency of the network with this chain id. A transaction's
|
||||
// value and fee are labelled with the one of the chain the transaction is on,
|
||||
// which need not be the active network. `ETH` when the chain id is missing or
|
||||
// no network here has it.
|
||||
function nativeCurrencyByChainId(chainId) {
|
||||
const network = networkByChainId(chainId);
|
||||
return network ? network.nativeCurrency : "ETH";
|
||||
// Build a block explorer link for the given path type and value.
|
||||
// type: "address" | "tx" | "token" | "block"
|
||||
function explorerLink(network, type, value) {
|
||||
return `${network.explorerUrl}/${type}/${value}`;
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
@@ -92,5 +89,5 @@ module.exports = {
|
||||
isKnownNetworkId,
|
||||
networkById,
|
||||
networkByChainId,
|
||||
nativeCurrencyByChainId,
|
||||
explorerLink,
|
||||
};
|
||||
|
||||
@@ -104,6 +104,27 @@ function getAddressValue(addr) {
|
||||
return { usd, partial };
|
||||
}
|
||||
|
||||
// The same pair for a whole wallet, and for every wallet at once. One
|
||||
// unpriced holding anywhere makes the sum a floor, so partial carries up.
|
||||
function getWalletValue(wallet) {
|
||||
return sumValues(wallet.addresses.map(getAddressValue));
|
||||
}
|
||||
|
||||
function getTotalValue(wallets) {
|
||||
return sumValues(wallets.map(getWalletValue));
|
||||
}
|
||||
|
||||
function sumValues(values) {
|
||||
let usd = null;
|
||||
let partial = false;
|
||||
for (const value of values) {
|
||||
if (value.usd === null) continue;
|
||||
usd = (usd === null ? 0 : usd) + value.usd;
|
||||
partial = partial || value.partial;
|
||||
}
|
||||
return { usd, partial };
|
||||
}
|
||||
|
||||
// The one rendering of an address total, so no screen says it differently.
|
||||
//
|
||||
// A partial total is shown and named as partial: the figure is the ETH and
|
||||
@@ -128,4 +149,6 @@ module.exports = {
|
||||
formatUsd,
|
||||
formatAddressTotal,
|
||||
getAddressValue,
|
||||
getWalletValue,
|
||||
getTotalValue,
|
||||
};
|
||||
|
||||
+5
-12
@@ -122,9 +122,9 @@ function currentNetwork() {
|
||||
return networkById(state.networkId);
|
||||
}
|
||||
|
||||
// The persisted fields as this page held them when its last loadState()
|
||||
// finished, or when its last successful saveState() began. saveState() diffs
|
||||
// the live state against this to find only the fields THIS page changed since.
|
||||
// The persisted fields as they stood at the end of this page's last
|
||||
// loadState() or saveState(). saveState() diffs the live state against this
|
||||
// to find only the fields THIS page actually changed.
|
||||
//
|
||||
// Deep-cloned, not a reference: callers mutate persisted objects and arrays
|
||||
// in place (state.wallets.push(...)), and a reference baseline would mutate
|
||||
@@ -464,10 +464,7 @@ function mergeNetworkEndpoints(base, ours, theirs) {
|
||||
// does not own goes on being whatever its last loadState() saw, same as
|
||||
// before this fix; only the persisted record is guaranteed current.
|
||||
async function saveStateOnce() {
|
||||
// A copy, so what this save compares and writes is the page's state as it
|
||||
// stood when the save began. A change made while it waits on storage is
|
||||
// left for the next save, which compares against this copy.
|
||||
const current = structuredClone(snapshotPersisted());
|
||||
const current = snapshotPersisted();
|
||||
const result = await storageGet("autistmask");
|
||||
// The record in storage right now is about to be merged into and written
|
||||
// back, so it is validated exactly like a load validates it. Without this,
|
||||
@@ -524,11 +521,7 @@ async function saveStateOnce() {
|
||||
// exactly as it stood; see the note above.
|
||||
rawState.hasWallet = rawState.wallets.length > 0;
|
||||
|
||||
// What this save compared and wrote, not the page's state now: a change
|
||||
// made during the save must still differ from the baseline, or the save
|
||||
// queued after it finds nothing to store
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/448).
|
||||
baseline = current;
|
||||
baseline = structuredClone(snapshotPersisted());
|
||||
}
|
||||
|
||||
// showView() calls saveState() on every navigation without awaiting it, so
|
||||
|
||||
@@ -20,10 +20,6 @@
|
||||
// (MSYRUPUSDP), so nothing the wallet ships as a real token is ever
|
||||
// truncated. The ellipsis is what tells the user the name they are looking
|
||||
// at is not the whole name — worth knowing before they send to it.
|
||||
//
|
||||
// Characters are counted as code points, not UTF-16 units, so an emoji is
|
||||
// one character and the cut never falls between the two halves of one: a
|
||||
// half on its own renders as U+FFFD.
|
||||
|
||||
const MAX_SYMBOL_LENGTH = 12;
|
||||
|
||||
@@ -36,9 +32,8 @@ const UNKNOWN_SYMBOL = "???";
|
||||
function displaySymbol(symbol) {
|
||||
const s = symbol === null || symbol === undefined ? "" : String(symbol);
|
||||
if (s.length === 0) return UNKNOWN_SYMBOL;
|
||||
const chars = Array.from(s);
|
||||
if (chars.length <= MAX_SYMBOL_LENGTH) return s;
|
||||
return chars.slice(0, MAX_SYMBOL_LENGTH - 1).join("") + "…";
|
||||
if (s.length <= MAX_SYMBOL_LENGTH) return s;
|
||||
return s.slice(0, MAX_SYMBOL_LENGTH - 1) + "…";
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
|
||||
@@ -11,8 +11,8 @@
|
||||
// KNOWN_SYMBOLS maps a symbol to the set of lowercased contract addresses
|
||||
// that may bear it, or to null. Null means the symbol belongs to the native
|
||||
// asset, which has no contract at all, so no contract may bear it and every
|
||||
// one that does is a spoof. "ETH" is one such entry, and every network's
|
||||
// `nativeCurrency` in networks.js (`SepoliaETH`) is another, on every network.
|
||||
// one that does is a spoof. "ETH" is the only such entry today; the rule is
|
||||
// written so that a second one needs no change here or at any call site.
|
||||
//
|
||||
// The value is a set because a ticker is not unique: seven symbols in the
|
||||
// bundled list belong to two real contracts each, and answering with one of
|
||||
|
||||
@@ -6,7 +6,6 @@
|
||||
// 511 tokens.
|
||||
|
||||
const { debugFetch } = require("./log");
|
||||
const { NETWORKS } = require("./networks");
|
||||
|
||||
const COINDESK_API = "https://data-api.coindesk.com/index/cc/v1/latest/tick";
|
||||
|
||||
@@ -3611,9 +3610,7 @@ for (const t of TOKENS) {
|
||||
// Build a map of symbol (uppercased) -> the set of contract addresses
|
||||
// (lowercased) that legitimately bear it. Used for spoofed-symbol detection.
|
||||
// "ETH" maps to null: the native asset has no contract, so no contract may
|
||||
// bear its symbol. So does every network's `nativeCurrency` in networks.js
|
||||
// (`SepoliaETH`), on every network, since that is the label the wallet shows
|
||||
// its native asset under on that network.
|
||||
// bear its symbol.
|
||||
//
|
||||
// The value is a set and not a single address because tickers are not unique
|
||||
// and the list above proves it: seven of these 512 tokens share a symbol with
|
||||
@@ -3627,9 +3624,6 @@ for (const t of TOKENS) {
|
||||
// loosen the rule, because a contract outside the set is still a spoof.
|
||||
const KNOWN_SYMBOLS = new Map();
|
||||
KNOWN_SYMBOLS.set("ETH", null);
|
||||
for (const network of Object.values(NETWORKS)) {
|
||||
KNOWN_SYMBOLS.set(network.nativeCurrency.toUpperCase(), null);
|
||||
}
|
||||
for (const t of TOKENS) {
|
||||
const upper = t.symbol.toUpperCase();
|
||||
if (!KNOWN_SYMBOLS.has(upper)) {
|
||||
|
||||
+12
-17
@@ -11,7 +11,6 @@ const { log, debugFetch } = require("./log");
|
||||
const { TOKEN_BY_ADDRESS } = require("./tokenList");
|
||||
const { parseHoldersCount, isLowHolderCount } = require("./holders");
|
||||
const { isSpoofedSymbol } = require("./symbolSpoof");
|
||||
const { nativeCurrencyByChainId } = require("./networks");
|
||||
// The uint8 test every scale in this wallet goes through. Shared, not copied:
|
||||
// a scale is either reported or it is unknown, and "unknown" must mean the
|
||||
// same thing here as it does on the screens that refuse to format one.
|
||||
@@ -29,7 +28,7 @@ function normalizeAddress(addr) {
|
||||
return (addr || "").toLowerCase();
|
||||
}
|
||||
|
||||
function parseTx(tx, addrLower, chainId) {
|
||||
function parseTx(tx, addrLower, nativeCurrency) {
|
||||
const from = tx.from?.hash || "";
|
||||
const to = tx.to?.hash || "";
|
||||
const rawWei = tx.value || "0";
|
||||
@@ -37,7 +36,7 @@ function parseTx(tx, addrLower, chainId) {
|
||||
const method = tx.method || null;
|
||||
|
||||
// For contract calls, produce a meaningful label instead of "0.0000 ETH"
|
||||
let symbol = nativeCurrencyByChainId(chainId);
|
||||
let symbol = nativeCurrency;
|
||||
let value = formatTxValue(formatEther(rawWei));
|
||||
let exactValue = formatEther(rawWei);
|
||||
let rawAmount = rawWei;
|
||||
@@ -91,11 +90,10 @@ function parseTx(tx, addrLower, chainId) {
|
||||
holders: null,
|
||||
isContractCall: toIsContract,
|
||||
method: method,
|
||||
chainId: chainId,
|
||||
};
|
||||
}
|
||||
|
||||
function parseTokenTransfer(tt, addrLower, chainId) {
|
||||
function parseTokenTransfer(tt, addrLower) {
|
||||
const from = tt.from?.hash || "";
|
||||
const to = tt.to?.hash || "";
|
||||
// The explorer's own answer, or null. Never a default: a transfer of
|
||||
@@ -137,12 +135,10 @@ function parseTokenTransfer(tt, addrLower, chainId) {
|
||||
contractAddress: normalizeAddress(
|
||||
tt.token?.address_hash || tt.token?.address || "",
|
||||
),
|
||||
// null when the explorer reported no readable count: unknown, not
|
||||
// zero. The low-holder filter declines to judge a null, so a
|
||||
// legitimate token is not hidden because a field went missing
|
||||
// upstream.
|
||||
// null when the explorer reported no count: unknown, not zero. The
|
||||
// low-holder filter declines to judge a null, so a legitimate token
|
||||
// is not hidden because a field went missing upstream.
|
||||
holders: parseHoldersCount(tt.token?.holders_count),
|
||||
chainId: chainId,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -225,13 +221,12 @@ function mergeTransactions(txs, tokenTransfers) {
|
||||
return merged;
|
||||
}
|
||||
|
||||
// `chainId` is the chain id of the network `blockscoutUrl` serves. Every entry
|
||||
// carries it, and a native entry is labelled with that network's
|
||||
// `nativeCurrency` from networks.js (`ETH`, `SepoliaETH`).
|
||||
// `nativeCurrency` is the active network's native token symbol from
|
||||
// networks.js (`ETH`, `SepoliaETH`), which a native entry is labelled with.
|
||||
async function fetchRecentTransactions(
|
||||
address,
|
||||
blockscoutUrl,
|
||||
chainId,
|
||||
nativeCurrency,
|
||||
count = 25,
|
||||
) {
|
||||
log.debugf("fetchRecentTransactions", address);
|
||||
@@ -266,10 +261,10 @@ async function fetchRecentTransactions(
|
||||
const ttJson = ttResp.ok ? await ttResp.json() : {};
|
||||
|
||||
const txs = mergeTransactions(
|
||||
(txJson.items || []).map((tx) => parseTx(tx, addrLower, chainId)),
|
||||
(ttJson.items || []).map((tt) =>
|
||||
parseTokenTransfer(tt, addrLower, chainId),
|
||||
(txJson.items || []).map((tx) =>
|
||||
parseTx(tx, addrLower, nativeCurrency),
|
||||
),
|
||||
(ttJson.items || []).map((tt) => parseTokenTransfer(tt, addrLower)),
|
||||
);
|
||||
|
||||
const result = txs.slice(0, count);
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
// Balance arithmetic for the Send and transaction confirmation screens.
|
||||
// Balance arithmetic for the transaction confirmation screen.
|
||||
//
|
||||
// Pure: no DOM, no network, no state. Everything is exact integer math on
|
||||
// 18-decimal fixed point (wei for ETH), so it can be unit tested directly
|
||||
@@ -10,7 +10,7 @@
|
||||
// the token balance arrive as human decimal strings, so comparing them at a
|
||||
// common scale is exact.
|
||||
|
||||
const { parseUnits, formatEther } = require("ethers");
|
||||
const { parseUnits } = require("ethers");
|
||||
|
||||
const SCALE_DECIMALS = 18;
|
||||
|
||||
@@ -87,28 +87,6 @@ function toFixedPoint(value) {
|
||||
}
|
||||
}
|
||||
|
||||
// The most ETH a send can carry: the exact balance minus the fee reserve from
|
||||
// feeReserveWei(), as a decimal string, so validateTransfer() passes it with
|
||||
// exactly that reserve left behind. `ethBalance` is the exact decimal string
|
||||
// balances.js stores, never a rounded one. Null when the balance does not
|
||||
// leave anything to send once the fee is paid, or when either input is
|
||||
// unusable.
|
||||
function maxEthAmount(ethBalance, feeWei) {
|
||||
const balanceWei = toFixedPoint(ethBalance);
|
||||
if (balanceWei === null) return null;
|
||||
if (typeof feeWei !== "bigint" || feeWei < 0n) return null;
|
||||
const amountWei = balanceWei - feeWei;
|
||||
if (amountWei <= 0n) return null;
|
||||
return formatEther(amountWei);
|
||||
}
|
||||
|
||||
// The most of a token a send can carry: its balance cut down, never rounded
|
||||
// up, to the 18 places (SCALE_DECIMALS) an amount may have. A token can
|
||||
// declare more than 18 decimals, and its balance is stored with all of them.
|
||||
function maxTokenAmount(tokenBalance) {
|
||||
return tokenBalance.replace(/(\.\d{18})\d+$/, "$1");
|
||||
}
|
||||
|
||||
// Validate a pending transfer against the balances that must cover it.
|
||||
//
|
||||
// isErc20 — token transfer rather than a native ETH transfer
|
||||
@@ -161,12 +139,13 @@ function validateTransfer({
|
||||
const feeFp = known ? feeWei : null;
|
||||
|
||||
if (isErc20) {
|
||||
// Only the first 18 places of the balance are read: an amount with
|
||||
// more was refused above, so the places after them cannot decide
|
||||
// whether the amount fits.
|
||||
// A token can declare more than 18 decimals, and its balance is
|
||||
// stored with all of them. Only the first 18 places (SCALE_DECIMALS)
|
||||
// are read: an amount with more was refused above, so the places
|
||||
// after them cannot decide whether the amount fits.
|
||||
const tokenText =
|
||||
typeof tokenBalance === "string"
|
||||
? maxTokenAmount(tokenBalance)
|
||||
? tokenBalance.replace(/(\.\d{18})\d+$/, "$1")
|
||||
: tokenBalance;
|
||||
const tokenFp = toFixedPoint(tokenText) ?? 0n;
|
||||
if (amountFp > tokenFp) codes.push(CODES.INSUFFICIENT_TOKEN);
|
||||
@@ -195,8 +174,6 @@ module.exports = {
|
||||
SCALE_DECIMALS,
|
||||
feeReserveWei,
|
||||
feeEstimateWei,
|
||||
maxEthAmount,
|
||||
maxTokenAmount,
|
||||
toFixedPoint,
|
||||
validateTransfer,
|
||||
};
|
||||
|
||||
@@ -13,17 +13,11 @@ const NON_MASTER_XPRV = "non-master-xprv";
|
||||
|
||||
// An "xprv" wallet stores the neutered BIP-44 Ethereum node, four levels below
|
||||
// the key that was imported: the current import path derives the absolute
|
||||
// m/44'/60'/0'/0 from a depth-0 key, and the path before #210 (57959b7)
|
||||
// derived the same four levels as a relative path beneath whatever depth it
|
||||
// was given. A master import therefore stores a depth-4 xpub and a depth-d
|
||||
// import stores depth d + 4, which makes the stored xpub an exact read on the
|
||||
// imported key's depth — and it is readable without the password, unlike the
|
||||
// key itself.
|
||||
//
|
||||
// The first import path (7a7f9c5) does not fit: it stored the imported key's
|
||||
// own xpub with no derivation, so a wallet it wrote is judged wrongly here (a
|
||||
// master import as defective, a depth-4 import as sound). 57959b7 replaced it
|
||||
// in the same push, and no tag contains it.
|
||||
// m/44'/60'/0'/0 from a depth-0 key, and the pre-#210 path derived the same
|
||||
// four levels as a relative path beneath whatever depth it was given. A master
|
||||
// import therefore stores a depth-4 xpub and a depth-d import stores depth
|
||||
// d + 4, which makes the stored xpub an exact read on the imported key's
|
||||
// depth — and it is readable without the password, unlike the key itself.
|
||||
const BIP44_ETH_XPUB_DEPTH = 4;
|
||||
|
||||
const DEFECTS = {
|
||||
|
||||
@@ -22,6 +22,8 @@ const {
|
||||
prices,
|
||||
clearPrices,
|
||||
getAddressValue,
|
||||
getWalletValue,
|
||||
getTotalValue,
|
||||
formatAddressTotal,
|
||||
} = require("../src/shared/prices");
|
||||
const { state } = require("../src/shared/state");
|
||||
@@ -134,6 +136,17 @@ describe("the value of an address, and whether it is the whole value", () => {
|
||||
partial: false,
|
||||
});
|
||||
});
|
||||
|
||||
test("one unpriced holding makes a wallet and the grand total partial", () => {
|
||||
const wallet = { addresses: [FULLY_PRICED, UNPRICED_ONLY] };
|
||||
expect(getWalletValue(wallet)).toEqual({ usd: 5500, partial: true });
|
||||
expect(getTotalValue([wallet])).toEqual({ usd: 5500, partial: true });
|
||||
});
|
||||
|
||||
test("a wallet of fully priced addresses stays complete", () => {
|
||||
const wallet = { addresses: [FULLY_PRICED, EMPTY] };
|
||||
expect(getWalletValue(wallet)).toEqual({ usd: 5500, partial: false });
|
||||
});
|
||||
});
|
||||
|
||||
describe("how that value is written on screen", () => {
|
||||
@@ -194,14 +207,6 @@ describe("the wallet list on Home", () => {
|
||||
clearPrices();
|
||||
expect(walletListTotal(FULLY_PRICED)).toBe(" ");
|
||||
});
|
||||
|
||||
// A total under a cent is written "< $0.01", and the "<" is escaped
|
||||
// here as the removal warning escapes it.
|
||||
test("a total under a cent is escaped, as on the removal warning", () => {
|
||||
const tiny = { ...EMPTY, balance: "0.000001" };
|
||||
expect(walletListTotal(tiny)).toBe("Total: < $0.01");
|
||||
expect(removalWarningTotal(tiny)).toBe("Total: < $0.01");
|
||||
});
|
||||
});
|
||||
|
||||
describe("the balance warning on the address-removal confirmation", () => {
|
||||
|
||||
@@ -31,15 +31,11 @@ const iface = new Interface(ERC20_ABI);
|
||||
const NOVEL_TOKEN = "0xE2E0000000000000000000000000000000000E2e";
|
||||
// In the bundled list, at 6 decimals.
|
||||
const USDC = "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48";
|
||||
// In the bundled list, at 0 decimals.
|
||||
const SLP = "0xCC8Fa225D80b9c7D42F96e9570156c65D6cAAa25";
|
||||
const RECIPIENT = "0xC0FfEE0000000000000000000000000000c0fFEe";
|
||||
const SPENDER = "0x1111111111111111111111111111111111111111";
|
||||
|
||||
// 5,000 units of a 6-decimal token, the amount from the issue.
|
||||
const FIVE_THOUSAND_AT_SIX = 5000000000n;
|
||||
// 5,000 units of a 0-decimal token, which are 5,000 tokens.
|
||||
const FIVE_THOUSAND_AT_ZERO = 5000n;
|
||||
const MAX_UINT256 = (1n << 256n) - 1n;
|
||||
|
||||
function transferData(amount) {
|
||||
@@ -117,21 +113,6 @@ describe("resolveTokenDecimals", () => {
|
||||
expect(resolveTokenDecimals(NOVEL_TOKEN, state)).toBe(6);
|
||||
});
|
||||
|
||||
// Zero decimals is a real scale, not a missing one, so a source that
|
||||
// answers 0 is used rather than fallen past like the unusable entry above.
|
||||
test("uses a bundled scale of zero", () => {
|
||||
state.trackedTokens = [{ address: SLP, symbol: "SLP", decimals: 18 }];
|
||||
expect(resolveTokenDecimals(SLP, state)).toBe(0);
|
||||
});
|
||||
|
||||
test("uses a tracked scale of zero", () => {
|
||||
state.trackedTokens = [
|
||||
{ address: NOVEL_TOKEN, symbol: "NOVEL", decimals: 0 },
|
||||
];
|
||||
state.wallets = walletsHolding(NOVEL_TOKEN, 18);
|
||||
expect(resolveTokenDecimals(NOVEL_TOKEN, state)).toBe(0);
|
||||
});
|
||||
|
||||
test("refuses a scale the explorer's own entries disagree about", () => {
|
||||
const wallets = walletsHolding(NOVEL_TOKEN, 6);
|
||||
wallets[0].addresses.push({
|
||||
@@ -232,21 +213,6 @@ describe("decodeCalldata amount", () => {
|
||||
);
|
||||
});
|
||||
|
||||
test("a bundled token with zero decimals shows the true quantity", () => {
|
||||
expect(amountLine(transferData(FIVE_THOUSAND_AT_ZERO), SLP)).toBe(
|
||||
"5000.0000 SLP",
|
||||
);
|
||||
});
|
||||
|
||||
test("a tracked token with zero decimals shows the true quantity", () => {
|
||||
state.trackedTokens = [
|
||||
{ address: NOVEL_TOKEN, symbol: "NOVEL", decimals: 0 },
|
||||
];
|
||||
expect(
|
||||
amountLine(transferData(FIVE_THOUSAND_AT_ZERO), NOVEL_TOKEN),
|
||||
).toBe("5000.0000 NOVEL");
|
||||
});
|
||||
|
||||
test("the amount carried to the status screens is the same string", () => {
|
||||
const decoded = decodeCalldata(
|
||||
transferData(FIVE_THOUSAND_AT_SIX),
|
||||
|
||||
@@ -599,24 +599,6 @@ describe("verifySignedTx field comparison", () => {
|
||||
expect(e.message).toContain("1.0 ETH");
|
||||
}
|
||||
});
|
||||
|
||||
// The fee is in the native currency of the network the transaction is
|
||||
// for, whether its chain id is the hex string the background prepares
|
||||
// or the number ethers parses from a signed transaction.
|
||||
test.each([
|
||||
["0x1", "ETH"],
|
||||
[1n, "ETH"],
|
||||
["0xaa36a7", "SepoliaETH"],
|
||||
[11155111n, "SepoliaETH"],
|
||||
])("the refusal on chain %p names %s", (chainId, nativeCurrency) => {
|
||||
expect(() => assertWithinCeilings({ ...OVER, chainId })).toThrow(
|
||||
"up to 3000.0 " +
|
||||
nativeCurrency +
|
||||
", which is more than the 1.0 " +
|
||||
nativeCurrency +
|
||||
" this wallet",
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
test("every field mismatch is a refusal, not a warning", async () => {
|
||||
|
||||
@@ -267,22 +267,9 @@ function loadBackground(options) {
|
||||
lastError: null,
|
||||
},
|
||||
windows: {
|
||||
getLastFocused: (cb) => cb(opts.lastFocused || null),
|
||||
getLastFocused: (cb) => cb(null),
|
||||
create: (options2, cb) => {
|
||||
// A copy, as the browser takes it at the call: the background
|
||||
// reuses the object when it asks a second time.
|
||||
created.push({ ...options2 });
|
||||
// A browser that refuses any position it is given, as Chrome
|
||||
// does for one it judges too far off screen.
|
||||
if (opts.refusePosition && options2.left !== undefined) {
|
||||
global.chrome.runtime.lastError = {
|
||||
message:
|
||||
"Invalid value for bounds. Bounds must be at least 50% within visible screen space.",
|
||||
};
|
||||
cb(undefined);
|
||||
global.chrome.runtime.lastError = null;
|
||||
return;
|
||||
}
|
||||
created.push(options2);
|
||||
// A browser that answers with no window at all. The approval
|
||||
// then has no window it can ever be answered in.
|
||||
cb(opts.noWindow ? undefined : { id: created.length });
|
||||
@@ -2248,27 +2235,6 @@ describe("a site connection decided as the popup closes", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// The prompt is decided before the toolbar popup raised for it has
|
||||
// loaded; that popup is torn down and openPopup() rejects only after.
|
||||
test("a toolbar prompt already decided opens no window when openPopup() rejects", async () => {
|
||||
const bg = loadBackground({ actionPopup: true });
|
||||
const opening = deferred();
|
||||
bg.openPopup.mockImplementation(() => opening.promise);
|
||||
const pending = bg.requestSite();
|
||||
await settle();
|
||||
|
||||
const port = bg.connectApproval(pending.id());
|
||||
port.decide(true, false);
|
||||
port.disconnect();
|
||||
await settle();
|
||||
expect(pending.result()).toEqual({ result: [signer.address] });
|
||||
|
||||
opening.reject(new Error("the toolbar popup closed before it loaded"));
|
||||
await settle();
|
||||
|
||||
expect(bg.created).toHaveLength(0);
|
||||
});
|
||||
|
||||
// The port carries a decision now, so it carries the sender check the
|
||||
// one-off message used to carry. A content script that guessed an
|
||||
// approval id must not be able to connect the site it is running on.
|
||||
@@ -2729,77 +2695,3 @@ describe("removing a site in Settings disconnects it", () => {
|
||||
expect(await siteAccounts(bg)).toEqual({ result: [signer.address] });
|
||||
});
|
||||
});
|
||||
|
||||
// An approval window still open is often the last focused window, and headless
|
||||
// Chrome reports one as 1280x720. Centred on that, the next approval window
|
||||
// lands where the browser refuses to create it, and its request failed with no
|
||||
// window at all (https://git.eeqj.de/sneak/AutistMask/issues/290).
|
||||
describe("where an approval window opens", () => {
|
||||
test("centred on the browser window the user was last in", async () => {
|
||||
const bg = loadBackground({
|
||||
lastFocused: {
|
||||
type: "normal",
|
||||
left: 0,
|
||||
top: 0,
|
||||
width: 1280,
|
||||
height: 720,
|
||||
},
|
||||
});
|
||||
|
||||
bg.requestSign();
|
||||
await settle();
|
||||
|
||||
expect(bg.created).toHaveLength(1);
|
||||
expect(bg.created[0]).toMatchObject({ left: 460, top: 60 });
|
||||
});
|
||||
|
||||
test("not centred on an approval window the user was last in", async () => {
|
||||
const bg = loadBackground({
|
||||
lastFocused: {
|
||||
type: "popup",
|
||||
left: 440,
|
||||
top: 0,
|
||||
width: 1280,
|
||||
height: 720,
|
||||
},
|
||||
});
|
||||
|
||||
bg.requestSign();
|
||||
await settle();
|
||||
|
||||
// Centred, it would be at left 900, the position the browser refused.
|
||||
expect(bg.created).toHaveLength(1);
|
||||
expect(bg.created[0].left).toBeUndefined();
|
||||
expect(bg.created[0].top).toBeUndefined();
|
||||
});
|
||||
|
||||
test("placed by the browser when it refuses the centred position", async () => {
|
||||
const bg = loadBackground({
|
||||
refusePosition: true,
|
||||
lastFocused: {
|
||||
type: "normal",
|
||||
left: 1500,
|
||||
top: 900,
|
||||
width: 400,
|
||||
height: 300,
|
||||
},
|
||||
});
|
||||
|
||||
const sign = bg.requestSign();
|
||||
await settle();
|
||||
|
||||
expect(bg.created).toHaveLength(2);
|
||||
expect(bg.created[0]).toMatchObject({ left: 1520, top: 750 });
|
||||
expect(bg.created[1].left).toBeUndefined();
|
||||
expect(bg.created[1].top).toBeUndefined();
|
||||
|
||||
// The request waits on the second window rather than failing:
|
||||
// closing that window is refusing the prompt.
|
||||
expect(sign.result()).toBeNull();
|
||||
bg.closeWindow(2);
|
||||
await settle();
|
||||
expect(sign.result()).toEqual({
|
||||
error: { code: 4001, message: "User rejected the request." },
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
//
|
||||
// The browser half of the same claim — that a real Chrome renders that
|
||||
// string as text and puts no iframe in the popup DOM — is in
|
||||
// tests/e2e/run.js. This half runs inside the 60-second make test cap.
|
||||
// tests/e2e/run.js. This half runs inside the 20-second make test cap.
|
||||
|
||||
"use strict";
|
||||
|
||||
@@ -66,11 +66,4 @@ describe("balanceLine", () => {
|
||||
expect(html).toContain("<span>1.5000</span>");
|
||||
expect(html).toContain('data-token="0xabc"');
|
||||
});
|
||||
|
||||
// formatUsd() writes a value under a cent as "< $0.01".
|
||||
test("escapes the USD value along with the symbol", () => {
|
||||
const html = balanceLine("USDC", 0.001, 1, null);
|
||||
expect(html).toContain("< $0.01");
|
||||
expect(html).not.toContain("< $0.01");
|
||||
});
|
||||
});
|
||||
|
||||
@@ -1,67 +0,0 @@
|
||||
// The balance refresh does not report a request the popup's own closing
|
||||
// cancelled, and still reports one that failed while the popup was open
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/218).
|
||||
//
|
||||
// In the popup a cancelled fetch() fails with the same "Failed to fetch" as a
|
||||
// server that cannot be reached, so every request here fails that way, and
|
||||
// only the signal the popup aborts on pagehide tells the two cases apart.
|
||||
|
||||
const { FetchRequest } = require("ethers");
|
||||
const { refreshBalances } = require("../src/shared/balances");
|
||||
|
||||
const RPC_URL = "https://rpc.example.invalid";
|
||||
const EXPLORER_URL = "https://explorer.example.invalid/api/v2";
|
||||
const ADDRESS = "0x1111111111111111111111111111111111111111";
|
||||
|
||||
const realFetch = globalThis.fetch;
|
||||
let logged;
|
||||
|
||||
beforeEach(() => {
|
||||
logged = [];
|
||||
jest.spyOn(console, "error").mockImplementation((...args) => {
|
||||
logged.push(args.map(String).join(" "));
|
||||
});
|
||||
const failedToFetch = async () => {
|
||||
throw new TypeError("Failed to fetch");
|
||||
};
|
||||
// The RPC calls (ETH balance, ENS name) and the explorer request (token
|
||||
// balances) all fail the same way.
|
||||
FetchRequest.registerGetUrl(failedToFetch);
|
||||
globalThis.fetch = jest.fn(failedToFetch);
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
FetchRequest.registerGetUrl(FetchRequest.createGetUrlFunc());
|
||||
globalThis.fetch = realFetch;
|
||||
jest.restoreAllMocks();
|
||||
});
|
||||
|
||||
function refresh(signal) {
|
||||
const wallets = [{ addresses: [{ address: ADDRESS }] }];
|
||||
return refreshBalances(
|
||||
wallets,
|
||||
RPC_URL,
|
||||
EXPLORER_URL,
|
||||
[],
|
||||
"mainnet",
|
||||
signal,
|
||||
);
|
||||
}
|
||||
|
||||
test("a failure while the popup is open is reported", async () => {
|
||||
await refresh(new AbortController().signal);
|
||||
for (const label of [
|
||||
"ETH balance failed",
|
||||
"ENS reverse failed",
|
||||
"fetchTokenBalances failed: Failed to fetch",
|
||||
]) {
|
||||
expect(logged.some((line) => line.includes(label))).toBe(true);
|
||||
}
|
||||
});
|
||||
|
||||
test("a failure once the popup has closed is not", async () => {
|
||||
const pageClosed = new AbortController();
|
||||
pageClosed.abort();
|
||||
await refresh(pageClosed.signal);
|
||||
expect(logged).toEqual([]);
|
||||
});
|
||||
@@ -1,104 +0,0 @@
|
||||
// `make dev` runs `node build.js --watch`
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/332). These drive build.js's
|
||||
// watch() over a temp directory with a stand-in for build(), so nothing here
|
||||
// builds or writes dist/.
|
||||
|
||||
const fs = require("fs");
|
||||
const os = require("os");
|
||||
const path = require("path");
|
||||
|
||||
const { watch } = require("../build");
|
||||
|
||||
let dir;
|
||||
let watchers = [];
|
||||
|
||||
beforeEach(() => {
|
||||
dir = fs.mkdtempSync(path.join(os.tmpdir(), "autistmask-watch-"));
|
||||
fs.mkdirSync(path.join(dir, "nested"));
|
||||
jest.spyOn(console, "log").mockImplementation(() => {});
|
||||
jest.spyOn(console, "error").mockImplementation(() => {});
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
for (const watcher of watchers) watcher.close();
|
||||
watchers = [];
|
||||
fs.rmSync(dir, { recursive: true, force: true });
|
||||
jest.restoreAllMocks();
|
||||
});
|
||||
|
||||
const sleep = (ms) => new Promise((resolve) => setTimeout(resolve, ms));
|
||||
|
||||
// Wait until `condition()` holds; fail the test if it has not within 3s.
|
||||
async function until(condition) {
|
||||
const deadline = Date.now() + 3000;
|
||||
while (!condition()) {
|
||||
if (Date.now() > deadline) throw new Error("timed out waiting");
|
||||
await sleep(10);
|
||||
}
|
||||
}
|
||||
|
||||
// Save the way many editors do: write a new copy, then rename it over the
|
||||
// original, so the file at that path is a different one afterwards.
|
||||
function saveByRename(file, contents) {
|
||||
fs.writeFileSync(`${file}.tmp`, contents);
|
||||
fs.renameSync(`${file}.tmp`, file);
|
||||
}
|
||||
|
||||
test("builds at start, then once per change to a file in a subdirectory", async () => {
|
||||
const file = path.join(dir, "nested", "a.js");
|
||||
fs.writeFileSync(file, "1");
|
||||
let builds = 0;
|
||||
watchers = watch([dir], async () => {
|
||||
builds++;
|
||||
});
|
||||
await until(() => builds === 1);
|
||||
|
||||
fs.writeFileSync(file, "2");
|
||||
await until(() => builds === 2);
|
||||
await sleep(300);
|
||||
expect(builds).toBe(2);
|
||||
});
|
||||
|
||||
test("keeps seeing a file that is saved by renaming a new copy over it", async () => {
|
||||
const file = path.join(dir, "nested", "a.js");
|
||||
fs.writeFileSync(file, "1");
|
||||
let builds = 0;
|
||||
watchers = watch([dir], async () => {
|
||||
builds++;
|
||||
});
|
||||
await until(() => builds === 1);
|
||||
|
||||
saveByRename(file, "2");
|
||||
await until(() => builds === 2);
|
||||
saveByRename(file, "3");
|
||||
await until(() => builds === 3);
|
||||
});
|
||||
|
||||
test("a failed build is reported and watching carries on", async () => {
|
||||
let builds = 0;
|
||||
watchers = watch([dir], async () => {
|
||||
builds++;
|
||||
if (builds === 1) throw new Error("unexpected token");
|
||||
});
|
||||
await until(() => console.error.mock.calls.length === 1);
|
||||
expect(console.error).toHaveBeenCalledWith(
|
||||
"Build failed: unexpected token",
|
||||
);
|
||||
|
||||
fs.writeFileSync(path.join(dir, "a.js"), "1");
|
||||
await until(() => builds === 2);
|
||||
});
|
||||
|
||||
test("a change made while a build runs causes one more build after it", async () => {
|
||||
let builds = 0;
|
||||
watchers = watch([dir], async () => {
|
||||
builds++;
|
||||
if (builds === 1) {
|
||||
fs.writeFileSync(path.join(dir, "a.js"), "1");
|
||||
await sleep(200);
|
||||
}
|
||||
});
|
||||
await until(() => builds === 2);
|
||||
await sleep(300);
|
||||
expect(builds).toBe(2);
|
||||
});
|
||||
@@ -301,7 +301,7 @@ describe.each([
|
||||
test("a contract creation's row says so, with no colour dot and no address line", async () => {
|
||||
const html = await rowsFor(historyTx(""));
|
||||
expect(html).toContain(SENTENCE);
|
||||
expect(html).not.toContain("bg-[#");
|
||||
expect(html).not.toContain("background:");
|
||||
expect(html).not.toContain("am-address");
|
||||
expect(html).not.toContain("undefined");
|
||||
});
|
||||
@@ -309,7 +309,7 @@ describe.each([
|
||||
test("a transaction with a recipient shows its colour dot and address", async () => {
|
||||
const html = await rowsFor(historyTx(RECIPIENT));
|
||||
expectAddressLine(html);
|
||||
expect(html).toContain("bg-[#");
|
||||
expect(html).toContain("background:#");
|
||||
expect(html).toContain(`<div class="am-address">${RECIPIENT}</div>`);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -46,9 +46,6 @@ const A1 = "0xdAC17F958D2ee523a2206206994597C13D831ec7";
|
||||
const B0 = "0x2260FAC5E5542a773Aa44fBCfeDf7C193bc2C599";
|
||||
const C0 = "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48";
|
||||
|
||||
// U+200B, built from its code point so that it can be seen in this file.
|
||||
const ZERO_WIDTH_SPACE = String.fromCodePoint(0x200b);
|
||||
|
||||
// ------------------------------------------------------------ DOM stub
|
||||
|
||||
function makeElement(id) {
|
||||
@@ -345,72 +342,6 @@ describe("the typed confirmation", () => {
|
||||
"secret-three",
|
||||
]);
|
||||
});
|
||||
|
||||
// A name of only spaces compares as nothing, and so does an empty
|
||||
// field. Typing nothing must still delete nothing.
|
||||
test.each(["", " "])(
|
||||
"typing %j deletes nothing when the name is only spaces",
|
||||
async (typedValue) => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets[1].name = " ";
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
|
||||
node("delete-wallet-lost-name-input").value = typedValue;
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
expect(node("delete-wallet-lost-flash").style.visibility).toBe(
|
||||
"visible",
|
||||
);
|
||||
expect(state.wallets).toHaveLength(3);
|
||||
expect(await persistedWallets(storage)).toHaveLength(3);
|
||||
},
|
||||
);
|
||||
|
||||
// A name that shows nothing would leave nothing on screen to type
|
||||
// back, so the screen names the wallet by its position instead, and
|
||||
// that is what the user types.
|
||||
test.each([
|
||||
["spaces", " "],
|
||||
["a zero-width space", ZERO_WIDTH_SPACE],
|
||||
])(
|
||||
"a name of only %s is shown and typed back as Wallet 2",
|
||||
async (_label, storedName) => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets[1].name = storedName;
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
|
||||
expect(node("delete-wallet-lost-name").textContent).toBe(
|
||||
"Wallet 2",
|
||||
);
|
||||
node("delete-wallet-lost-name-input").value = "Wallet 2";
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
const persisted = await persistedWallets(storage);
|
||||
expect(persisted.map((w) => w.encryptedSecret)).toEqual([
|
||||
"secret-one",
|
||||
"secret-three",
|
||||
]);
|
||||
},
|
||||
);
|
||||
|
||||
// A zero-width space paints nothing, so "My", a zero-width space and
|
||||
// "Wallet" reads as "MyWallet", and that is all the user can type. HTML
|
||||
// does not collapse it the way it collapses spaces, so it has to be
|
||||
// removed explicitly.
|
||||
test("a zero-width space inside the name is not part of it", async () => {
|
||||
const { deleteWallet, state, storage } = load();
|
||||
state.wallets[1].name = "My" + ZERO_WIDTH_SPACE + "Wallet";
|
||||
await openLostPassword(deleteWallet, 1);
|
||||
|
||||
node("delete-wallet-lost-name-input").value = "MyWallet";
|
||||
await click("btn-delete-wallet-lost-confirm");
|
||||
|
||||
const persisted = await persistedWallets(storage);
|
||||
expect(persisted.map((w) => w.encryptedSecret)).toEqual([
|
||||
"secret-one",
|
||||
"secret-three",
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("deleting without the password", () => {
|
||||
|
||||
@@ -105,7 +105,7 @@ describe("the flash line the message is shown in", () => {
|
||||
// "a rejected dust threshold shifts no layout (#233)" and "an over-long
|
||||
// flash message keeps to one line (#252)" in tests/e2e/run.js, run by
|
||||
// make test-e2e. They are not in make check because REPO_POLICIES.md
|
||||
// caps make test at 60 seconds and a browser suite does not fit.
|
||||
// caps make test at 20 seconds and a browser suite does not fit.
|
||||
test("reserves its height in the markup", () => {
|
||||
const flashLine = POPUP_HTML.match(
|
||||
/<div\s+id="flash-msg"\s+class="([^"]*)"/,
|
||||
|
||||
+1
-137
@@ -8,7 +8,7 @@
|
||||
// node tests/e2e/firefox/run.js [dist/firefox]
|
||||
//
|
||||
// Deliberately not part of script/check, and deliberately not named
|
||||
// *.test.js: REPO_POLICIES.md caps make test at 60 seconds and a browser
|
||||
// *.test.js: REPO_POLICIES.md caps make test at 20 seconds and a browser
|
||||
// suite does not fit.
|
||||
//
|
||||
// This shares no driver layer with the Chrome suite in tests/e2e/, and the
|
||||
@@ -46,7 +46,6 @@
|
||||
|
||||
const fs = require("fs");
|
||||
const path = require("path");
|
||||
const { isDeepStrictEqual } = require("util");
|
||||
|
||||
const {
|
||||
Transaction,
|
||||
@@ -63,10 +62,6 @@ const {
|
||||
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
|
||||
const { startDappServer } = require("./dapp");
|
||||
const { STUB_COUNTERPARTY } = require("../network");
|
||||
const {
|
||||
STATE_SCHEMA_VERSION,
|
||||
stateProblem,
|
||||
} = require("../../../src/shared/stateSchema");
|
||||
|
||||
const REPO_ROOT = path.resolve(__dirname, "..", "..", "..");
|
||||
const POPUP_URL = EXTENSION_ORIGIN + "/src/popup/index.html";
|
||||
@@ -113,137 +108,6 @@ step("popup loads and reaches the welcome view", async (env) => {
|
||||
assert(title === "AutistMask", "unexpected popup title: " + title);
|
||||
});
|
||||
|
||||
// The same check as the Chrome suite's (#418), so both browsers are held to
|
||||
// the same font.
|
||||
step("the popup is drawn in the monospace font it declares", async (env) => {
|
||||
const font = await env.driver.execute(
|
||||
"return getComputedStyle(document.body).fontFamily;",
|
||||
);
|
||||
// --font-mono in src/popup/styles/main.css, as the browser writes it out.
|
||||
assert(
|
||||
font ===
|
||||
'ui-monospace, SFMono-Regular, "SF Mono", Menlo, Consolas, "Liberation Mono", monospace',
|
||||
"the popup is drawn in " + font + ", not in --font-mono",
|
||||
);
|
||||
});
|
||||
|
||||
// The recovery screen (#361): the Chrome suite's four cases, run before any
|
||||
// wallet exists for the same reason. With no wallet nothing saves on a timer,
|
||||
// so no save can write a good record over the unreadable one. The last of them
|
||||
// erases it, which leaves the popup on Welcome for wallet creation.
|
||||
|
||||
// A profile a newer build wrote: a wallet with its encrypted secret, under a
|
||||
// schema version this build refuses to read.
|
||||
const UNREADABLE_RECORD = {
|
||||
schemaVersion: STATE_SCHEMA_VERSION + 1,
|
||||
wallets: [
|
||||
{
|
||||
type: "hd",
|
||||
name: "Main",
|
||||
xpub: "xpub-written-by-a-newer-build",
|
||||
encryptedSecret: "ciphertext-written-by-a-newer-build",
|
||||
nextIndex: 1,
|
||||
addresses: [{ address: STUB_COUNTERPARTY }],
|
||||
},
|
||||
],
|
||||
};
|
||||
|
||||
// The whole stored record, read on the popup page.
|
||||
function storedRecord(d) {
|
||||
return d.executeAsync(
|
||||
`const done = arguments[arguments.length - 1];
|
||||
browser.storage.local.get("autistmask").then((r) => done(r.autistmask));`,
|
||||
);
|
||||
}
|
||||
|
||||
step(
|
||||
"an unreadable stored record opens the popup on the recovery screen",
|
||||
async (env) => {
|
||||
const d = env.driver;
|
||||
// The popup the first step opened saves once, as it shows Welcome.
|
||||
// Stored before that save lands, the record would be written over.
|
||||
const deadline = Date.now() + 15000;
|
||||
for (;;) {
|
||||
const stored = await storedRecord(d);
|
||||
if (stored && stored.currentView === "welcome") break;
|
||||
assert(
|
||||
Date.now() < deadline,
|
||||
"the Welcome screen's save never landed: " +
|
||||
JSON.stringify(stored),
|
||||
);
|
||||
await sleep(100);
|
||||
}
|
||||
await d.executeAsync(
|
||||
`const done = arguments[arguments.length - 1];
|
||||
browser.storage.local.set({ autistmask: arguments[0] }).then(() => done());`,
|
||||
[UNREADABLE_RECORD],
|
||||
);
|
||||
|
||||
await d.navigate(POPUP_URL);
|
||||
await d.waitVisible("#view-state-recovery");
|
||||
const problem = await d.text("#state-recovery-problem");
|
||||
assert(
|
||||
problem === stateProblem(UNREADABLE_RECORD),
|
||||
"the recovery screen names the problem as " +
|
||||
JSON.stringify(problem),
|
||||
);
|
||||
},
|
||||
);
|
||||
|
||||
step("Export Saved Data shows the stored record verbatim", async (env) => {
|
||||
const d = env.driver;
|
||||
await d.click("#btn-state-recovery-export");
|
||||
await d.waitVisible("#state-recovery-blob");
|
||||
const exported = await d.value("#state-recovery-blob");
|
||||
assert(exported !== "", "Export Saved Data left the text box empty");
|
||||
assert(
|
||||
isDeepStrictEqual(JSON.parse(exported), UNREADABLE_RECORD),
|
||||
"the text box does not hold the stored record: " + exported,
|
||||
);
|
||||
});
|
||||
|
||||
step("a near-miss confirmation phrase erases nothing", async (env) => {
|
||||
const d = env.driver;
|
||||
await d.fill("#state-recovery-reset-input", "ERASE MY WALLETS");
|
||||
await d.click("#btn-state-recovery-reset");
|
||||
await d.waitFor(
|
||||
"the refusal on the error line",
|
||||
`return document.getElementById("state-recovery-flash").textContent ===
|
||||
"Type ERASE MY WALLET to confirm. Nothing was erased.";`,
|
||||
);
|
||||
const stored = await storedRecord(d);
|
||||
assert(
|
||||
isDeepStrictEqual(stored, UNREADABLE_RECORD),
|
||||
"the stored record changed: " + JSON.stringify(stored),
|
||||
);
|
||||
});
|
||||
|
||||
step(
|
||||
"the exact confirmation phrase erases the record and reloads into Welcome",
|
||||
async (env) => {
|
||||
const d = env.driver;
|
||||
try {
|
||||
await d.fill("#state-recovery-reset-input", "ERASE MY WALLET");
|
||||
await d.click("#btn-state-recovery-reset");
|
||||
// Welcome is the proof of the erase: the record still stored
|
||||
// would put the recovery screen up again, and its wallet would
|
||||
// open Home.
|
||||
await d.waitVisible("#view-welcome");
|
||||
} finally {
|
||||
// Whatever failed in these four steps, wallet creation starts
|
||||
// from Welcome. The record left stored would fail every step
|
||||
// after this.
|
||||
if (!(await d.isVisible("#view-welcome"))) {
|
||||
await d.executeAsync(
|
||||
`const done = arguments[arguments.length - 1];
|
||||
browser.storage.local.remove("autistmask").then(() => done());`,
|
||||
);
|
||||
await d.navigate(POPUP_URL);
|
||||
}
|
||||
}
|
||||
},
|
||||
);
|
||||
|
||||
step("wallet creation through the UI reaches the main view", async (env) => {
|
||||
const d = env.driver;
|
||||
await d.click("#btn-welcome-add");
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
//
|
||||
// This runs inside the pinned Playwright container; see script/test-e2e.
|
||||
// It is deliberately NOT part of make check — REPO_POLICIES.md caps
|
||||
// make test at 60 seconds and a browser suite does not fit.
|
||||
// make test at 20 seconds and a browser suite does not fit.
|
||||
|
||||
"use strict";
|
||||
|
||||
|
||||
+26
-57
@@ -22,7 +22,7 @@
|
||||
|
||||
"use strict";
|
||||
|
||||
const { AbiCoder, Transaction } = require("ethers");
|
||||
const { Transaction } = require("ethers");
|
||||
|
||||
// Fictional ERC-20 used to seed the transaction-detail test. The symbol
|
||||
// must not collide with any entry in src/shared/tokenList.js, or
|
||||
@@ -244,39 +244,26 @@ function latestBlock() {
|
||||
};
|
||||
}
|
||||
|
||||
// keccak("decimals()")[0:4], and the same for symbol() and name().
|
||||
// keccak("decimals()")[0:4].
|
||||
const SELECTOR_DECIMALS = "0x313ce567";
|
||||
const SELECTOR_SYMBOL = "0x95d89b41";
|
||||
const SELECTOR_NAME = "0x06fdde03";
|
||||
|
||||
// Every eth_call still answers with a zero word except decimals(), symbol()
|
||||
// and name() on the stub token. The wallet reads decimals() back at signing
|
||||
// time to compare with the scale the confirmation screen rendered (issue
|
||||
// #305). Adding the token by its contract address reads all three (issue
|
||||
// #295); symbol() and name() answer what the explorer reports for it.
|
||||
// Every eth_call still answers with a zero word except decimals() on the
|
||||
// stub token, which the wallet reads back at signing time to compare with
|
||||
// the scale the confirmation screen rendered (issue #305).
|
||||
//
|
||||
// opts.tokenDecimalsOverride is the lying contract: set it and decimals()
|
||||
// answers something other than the value this same fixture reports through
|
||||
// Blockscout, which is exactly the disagreement the wallet must refuse to
|
||||
// sign over. It is read at request time, so a test flips it on the options
|
||||
// object the route was registered with — after the confirmation screen has
|
||||
// been built — without re-registering anything. Only null or undefined means
|
||||
// no override: 0 is a token with no decimal places, and is answered as one.
|
||||
// been built — without re-registering anything.
|
||||
function ethCallResult(req, opts) {
|
||||
const call = Array.isArray(req.params) ? req.params[0] : null;
|
||||
if (!call || typeof call !== "object") return ZERO_WORD;
|
||||
const data = String(call.data || call.input || "").toLowerCase();
|
||||
const to = String(call.to || "").toLowerCase();
|
||||
if (to !== STUB_TOKEN.address) return ZERO_WORD;
|
||||
if (data.startsWith(SELECTOR_DECIMALS)) {
|
||||
return word(opts.tokenDecimalsOverride ?? STUB_TOKEN.decimals);
|
||||
}
|
||||
const abi = AbiCoder.defaultAbiCoder();
|
||||
if (data.startsWith(SELECTOR_SYMBOL)) {
|
||||
return abi.encode(["string"], [tokenObject(opts).symbol]);
|
||||
}
|
||||
if (data.startsWith(SELECTOR_NAME)) {
|
||||
return abi.encode(["string"], [tokenObject(opts).name]);
|
||||
if (data.startsWith(SELECTOR_DECIMALS) && to === STUB_TOKEN.address) {
|
||||
return word(opts.tokenDecimalsOverride || STUB_TOKEN.decimals);
|
||||
}
|
||||
return ZERO_WORD;
|
||||
}
|
||||
@@ -418,23 +405,27 @@ function sleep(ms) {
|
||||
const HOLD_POLL_MS = 25;
|
||||
const HOLD_MAX_MS = 30000;
|
||||
|
||||
// Hold a reply open for as long as the test asks: until opts[name] is false.
|
||||
// Hold a gas estimate open for as long as the test asks.
|
||||
//
|
||||
// The switch (holdGasEstimate or holdBlockscout) is read here rather than
|
||||
// captured, so a test flips it on the same options object the route was
|
||||
// registered with — the same pattern as seedTokenTransfer. This is the only way
|
||||
// to observe a screen while its request is genuinely in flight; sampling the
|
||||
// screen and hoping to win a race against the network would assert nothing on
|
||||
// a slow machine.
|
||||
// opts.holdGasEstimate is read here rather than captured, so a test flips it
|
||||
// on the same options object the route was registered with — the same
|
||||
// pattern as seedTokenTransfer. This is the only way to observe the
|
||||
// confirmation screen while its estimate is genuinely in flight; sampling
|
||||
// the screen and hoping to win a race against the network would assert
|
||||
// nothing on a slow machine.
|
||||
//
|
||||
// It never gives up quietly. A hold that outlives the bound is reported like
|
||||
// any other harness fault, because a "pending" state that stopped being
|
||||
// pending on its own is a green assertion about the wrong screen.
|
||||
async function awaitRelease(opts, name, report) {
|
||||
async function awaitRelease(opts, report) {
|
||||
const started = Date.now();
|
||||
while (opts[name]) {
|
||||
while (opts.holdGasEstimate) {
|
||||
if (Date.now() - started > HOLD_MAX_MS) {
|
||||
report(name + " was never released after " + HOLD_MAX_MS + "ms");
|
||||
report(
|
||||
"held gas estimate was never released after " +
|
||||
HOLD_MAX_MS +
|
||||
"ms",
|
||||
);
|
||||
return;
|
||||
}
|
||||
await sleep(HOLD_POLL_MS);
|
||||
@@ -456,16 +447,6 @@ function rpcReply(req, opts, report) {
|
||||
return Object.assign(envelope, { result: ethCallResult(req, opts) });
|
||||
}
|
||||
if (req.method === "eth_getTransactionReceipt") {
|
||||
// A lookup that fails, which the wait screen counts differently from
|
||||
// one that answers "not mined yet" (README.md, WaitTx).
|
||||
if (opts.failReceiptLookup) {
|
||||
return Object.assign(envelope, {
|
||||
error: {
|
||||
code: -32000,
|
||||
message: "e2e fixture: receipt lookup failed",
|
||||
},
|
||||
});
|
||||
}
|
||||
const hash = Array.isArray(req.params) ? req.params[0] : null;
|
||||
return Object.assign(envelope, {
|
||||
result: opts.seedReceipt && hash ? transactionReceipt(hash) : null,
|
||||
@@ -558,7 +539,7 @@ async function handleRpc(route, postData, opts, report) {
|
||||
return route.abort();
|
||||
}
|
||||
if (batch.some((req) => req.method === "eth_estimateGas")) {
|
||||
await awaitRelease(opts, "holdGasEstimate", report);
|
||||
await awaitRelease(opts, report);
|
||||
}
|
||||
|
||||
const replies = batch.map((req) => rpcReply(req, opts, report));
|
||||
@@ -614,23 +595,16 @@ function traceEnabled(raw) {
|
||||
* node-side refusal.
|
||||
* @param {boolean} [opts.holdGasEstimate] hold every batch containing an
|
||||
* eth_estimateGas until this is cleared again.
|
||||
* @param {boolean} [opts.holdBlockscout] hold every Blockscout request until
|
||||
* this is cleared again.
|
||||
* @param {boolean} [opts.failTransactionList] fail every request for an
|
||||
* address's transaction list as a network error; read at request time.
|
||||
* @param {string[]} [opts.broadcastTransactions] every raw signed
|
||||
* transaction handed to eth_sendRawTransaction, appended in order.
|
||||
* @param {number|string|null} [opts.tokenDecimalsOverride] the scale
|
||||
* decimals() answers for the stub token, in place of the value Blockscout
|
||||
* reports for it; null for none, while 0 is a scale like any other. This
|
||||
* is the token that lies about its scale; read at request time.
|
||||
* @param {string} [opts.tokenDecimalsOverride] what decimals() answers for
|
||||
* the stub token, in place of the value Blockscout reports for it. This is
|
||||
* the token that lies about its scale; read at request time.
|
||||
* @param {string} [opts.tokenSymbolOverride] what the explorer reports as
|
||||
* the stub token's symbol, in place of "E2E". This is the token whose
|
||||
* symbol is markup; read at request time.
|
||||
* @param {boolean} [opts.seedReceipt] answer eth_getTransactionReceipt with a
|
||||
* confirmed receipt instead of null, so a wait screen resolves.
|
||||
* @param {boolean} [opts.failReceiptLookup] answer eth_getTransactionReceipt
|
||||
* with an error, so every receipt lookup fails; read at request time.
|
||||
* @returns {Promise<{waitForServiceWorkerTraffic: (ms: number) =>
|
||||
* Promise<string|null>}>}
|
||||
*/
|
||||
@@ -693,12 +667,7 @@ async function installNetworkStubs(ctx, opts) {
|
||||
|
||||
// Blockscout v2
|
||||
if (p.includes("/api/v2/")) {
|
||||
await awaitRelease(opts, "holdBlockscout", report);
|
||||
if (/\/addresses\/0x[0-9a-fA-F]{40}\/transactions$/.test(p)) {
|
||||
// Aborted rather than answered with an error status: to the
|
||||
// page this is a server that cannot be reached, and fetch()
|
||||
// rejects with "Failed to fetch".
|
||||
if (opts.failTransactionList) return route.abort();
|
||||
const addr = blockscoutAddress(p);
|
||||
return jsonResponse(route, {
|
||||
items:
|
||||
|
||||
+99
-831
File diff suppressed because it is too large
Load Diff
@@ -58,20 +58,7 @@ function makeElement(id, withParent) {
|
||||
remove: () => {},
|
||||
querySelectorAll: () => [],
|
||||
};
|
||||
el.parentElement = null;
|
||||
if (withParent) {
|
||||
// As in a browser, replacing the parent's contents takes this
|
||||
// element out of the document: getElementById no longer finds it.
|
||||
el.parentElement = makeElement(id + "-parent", false);
|
||||
let html = "";
|
||||
Object.defineProperty(el.parentElement, "innerHTML", {
|
||||
get: () => html,
|
||||
set: (value) => {
|
||||
html = value;
|
||||
el.removed = true;
|
||||
},
|
||||
});
|
||||
}
|
||||
el.parentElement = withParent ? makeElement(id + "-parent", false) : null;
|
||||
return el;
|
||||
}
|
||||
|
||||
@@ -83,8 +70,7 @@ function makeDocument() {
|
||||
// is the state a non-debug, non-testnet popup is in.
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement(id, true));
|
||||
const el = els.get(id);
|
||||
return el.removed ? null : el;
|
||||
return els.get(id);
|
||||
},
|
||||
createElement: () => makeElement("created", false),
|
||||
addEventListener: () => {},
|
||||
@@ -314,28 +300,6 @@ describe("leaving the screen after the key is on it", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("opening the screen again in the same popup session", () => {
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/460: show() found the
|
||||
// address line through an element inside it, which its own rendering
|
||||
// deleted, so the second open threw before it navigated.
|
||||
test("shows it for the address chosen the second time", async () => {
|
||||
const { state, exportPrivkey } = load();
|
||||
exportPrivkey.show(0, 0);
|
||||
await click("btn-export-privkey-back");
|
||||
expect(state.currentView).toBe("address");
|
||||
|
||||
exportPrivkey.show(0, 1);
|
||||
|
||||
expect(state.currentView).toBe(VIEW);
|
||||
expect(node("export-privkey-title").textContent).toBe(
|
||||
"Wallet 1 — Address 2",
|
||||
);
|
||||
expect(node("export-privkey-address").innerHTML).toContain(
|
||||
"0x" + "22".repeat(20),
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
describe("views the popup may reopen onto", () => {
|
||||
// Restoring onto this screen would put a private key on display with no
|
||||
// password prompt in front of it, on a popup reopened by accident.
|
||||
|
||||
@@ -57,39 +57,6 @@ describe("parseHoldersCount", () => {
|
||||
expect(parseHoldersCount("many")).toBeNull();
|
||||
expect(parseHoldersCount(NaN)).toBeNull();
|
||||
});
|
||||
|
||||
// Each of these starts with a digit, so reading only the leading digits
|
||||
// would turn it into a small reported count, and a small count is
|
||||
// exactly what hides a token as spam (issue #251).
|
||||
test.each(["1,000", "0x10", "1e3", "12 holders"])(
|
||||
"%p is not read in part: it is unknown",
|
||||
(raw) => {
|
||||
expect(parseHoldersCount(raw)).toBeNull();
|
||||
},
|
||||
);
|
||||
|
||||
test("a negative count is unknown", () => {
|
||||
expect(parseHoldersCount("-5")).toBeNull();
|
||||
expect(parseHoldersCount(-5)).toBeNull();
|
||||
});
|
||||
|
||||
// A number holds a whole number exactly only up to 2^53 - 1. Past that a
|
||||
// string of digits would come back rounded, and a long enough one as
|
||||
// Infinity, which would pass every holder-count floor.
|
||||
test("a count too large for a number to hold exactly is unknown", () => {
|
||||
expect(parseHoldersCount("9007199254740993")).toBeNull();
|
||||
expect(parseHoldersCount("9".repeat(400))).toBeNull();
|
||||
expect(parseHoldersCount(2 ** 53)).toBeNull();
|
||||
});
|
||||
|
||||
test("the largest count a number holds exactly still parses", () => {
|
||||
expect(parseHoldersCount("9007199254740991")).toBe(
|
||||
Number.MAX_SAFE_INTEGER,
|
||||
);
|
||||
expect(parseHoldersCount(Number.MAX_SAFE_INTEGER)).toBe(
|
||||
Number.MAX_SAFE_INTEGER,
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
describe("isLowHolderCount", () => {
|
||||
|
||||
@@ -91,17 +91,6 @@ describe("displaySymbol", () => {
|
||||
expect(displaySymbol(exact)).toBe(exact);
|
||||
});
|
||||
|
||||
// An emoji outside the Basic Multilingual Plane is two UTF-16 units.
|
||||
// Cutting between them leaves half of one, which renders as U+FFFD.
|
||||
test("counts an emoji as one character and never cuts one in half", () => {
|
||||
expect(displaySymbol("🚀".repeat(MAX_SYMBOL_LENGTH))).toBe(
|
||||
"🚀".repeat(MAX_SYMBOL_LENGTH),
|
||||
);
|
||||
expect(displaySymbol("🚀".repeat(20))).toBe(
|
||||
"🚀".repeat(MAX_SYMBOL_LENGTH - 1) + "…",
|
||||
);
|
||||
});
|
||||
|
||||
test("substitutes a placeholder for an absent symbol", () => {
|
||||
expect(displaySymbol("")).toBe(UNKNOWN_SYMBOL);
|
||||
expect(displaySymbol(null)).toBe(UNKNOWN_SYMBOL);
|
||||
|
||||
@@ -21,14 +21,15 @@
|
||||
// escaping in src/shared/html.js is the primary fix; default-src is what
|
||||
// stops the next escape that slips from reaching the network.
|
||||
//
|
||||
// And for #328: style-src is 'self' alone, so the browser refuses every
|
||||
// style="..." attribute in the popup's markup, including one an escape lets
|
||||
// through. The popup styles with classes; script setting element.style is
|
||||
// not affected.
|
||||
//
|
||||
// Every directive below is pinned exactly, because each of the three
|
||||
// Every directive below is pinned exactly, because each of the four
|
||||
// loosenings is load-bearing and none of them may grow:
|
||||
//
|
||||
// style-src 'unsafe-inline' src/popup/index.html and the view helpers
|
||||
// use style="..." attributes throughout, which
|
||||
// CSP blocks without it. Chrome enforces this
|
||||
// on attributes, not just <style> blocks, and
|
||||
// Firefox has never implemented style-src-attr,
|
||||
// so there is no narrower spelling available.
|
||||
// img-src data: blockies are data: PNGs assigned to img.src.
|
||||
// connect-src https: http: the RPC endpoint is user-configurable, and a
|
||||
// local node over http://127.0.0.1 is a
|
||||
@@ -57,7 +58,7 @@ const EXPECTED_DIRECTIVES = {
|
||||
"default-src": ["'self'"],
|
||||
"script-src": ["'self'", "'wasm-unsafe-eval'"],
|
||||
"object-src": ["'self'"],
|
||||
"style-src": ["'self'"],
|
||||
"style-src": ["'self'", "'unsafe-inline'"],
|
||||
"img-src": ["'self'", "data:"],
|
||||
"connect-src": ["'self'", "http:", "https:"],
|
||||
"frame-src": ["'none'"],
|
||||
|
||||
@@ -5,9 +5,7 @@
|
||||
// hardcoded "ETH", so on Sepolia the balance, the value and the fee all read
|
||||
// ETH (https://git.eeqj.de/sneak/AutistMask/issues/372). Each line is asserted
|
||||
// on both networks, through the real Send, confirmation and approval screens,
|
||||
// with only the node and the DOM stubbed. So is that a token cannot pass for
|
||||
// the native token by reporting its label, and that a transaction's figures
|
||||
// carry its own network's label when another network is active.
|
||||
// with only the node and the DOM stubbed.
|
||||
|
||||
"use strict";
|
||||
|
||||
@@ -30,9 +28,6 @@ jest.mock("ethers", () => {
|
||||
async getTransactionCount() {
|
||||
return 1;
|
||||
}
|
||||
async getTransactionReceipt() {
|
||||
return { blockNumber: 21000000 };
|
||||
}
|
||||
}
|
||||
return {
|
||||
...actual,
|
||||
@@ -58,21 +53,6 @@ jest.mock("../src/shared/log", () => ({
|
||||
isDebug: () => false,
|
||||
}));
|
||||
|
||||
// Signing a send succeeds without a key, and sending answers with a hash.
|
||||
jest.mock("../src/shared/vault", () => ({
|
||||
...jest.requireActual("../src/shared/vault"),
|
||||
decryptWithPassword: async () => "secret",
|
||||
}));
|
||||
jest.mock("../src/shared/wallet", () => ({
|
||||
...jest.requireActual("../src/shared/wallet"),
|
||||
getSignerForAddress: () => ({
|
||||
connect: () => ({
|
||||
populateTransaction: async (request) => request,
|
||||
sendTransaction: async () => ({ hash: "0x" + "3".repeat(64) }),
|
||||
}),
|
||||
}),
|
||||
}));
|
||||
|
||||
global.fetch = jest.fn(() => {
|
||||
throw new Error("tests must not perform network requests");
|
||||
});
|
||||
@@ -131,10 +111,6 @@ function makeEl(id) {
|
||||
querySelector: () => null,
|
||||
remove() {},
|
||||
focus() {},
|
||||
// Views reach for .parentElement to hide whole sections.
|
||||
get parentElement() {
|
||||
return global.document.getElementById(id + "-parent");
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
@@ -155,16 +131,10 @@ const { clearPrices } = require("../src/shared/prices");
|
||||
const send = require("../src/popup/views/send");
|
||||
const confirmTx = require("../src/popup/views/confirmTx");
|
||||
const approval = require("../src/popup/views/approval");
|
||||
const transactionDetail = require("../src/popup/views/transactionDetail");
|
||||
const txStatus = require("../src/popup/views/txStatus");
|
||||
const { balanceLinesForAddress } = require("../src/popup/views/helpers");
|
||||
const { filterTransactions } = require("../src/shared/transactions");
|
||||
const { debugFetch } = require("../src/shared/log");
|
||||
|
||||
const HOLDER = "0x" + "a".repeat(40);
|
||||
const RECIPIENT = "0xC0FfEE0000000000000000000000000000c0fFEe";
|
||||
// A token contract that is not in the bundled token list.
|
||||
const TOKEN_CONTRACT = "0xd05339f9ea5ab9d9f03b9d57f671d2abd1f55c82";
|
||||
|
||||
function text(id) {
|
||||
return global.document.getElementById(id).textContent;
|
||||
@@ -186,8 +156,8 @@ async function confirmSend(amount) {
|
||||
}
|
||||
|
||||
// The approval screen for a dApp transaction sending 0.01 of the native token
|
||||
// with 21000 gas at up to 20 gwei, on the network with `chainId`.
|
||||
async function approveTx(chainId) {
|
||||
// with 21000 gas at up to 20 gwei, on the active network.
|
||||
async function approveTx() {
|
||||
approvalDetails = {
|
||||
type: "tx",
|
||||
origin: "https://dapp.example",
|
||||
@@ -196,7 +166,7 @@ async function approveTx(chainId) {
|
||||
to: RECIPIENT,
|
||||
value: "10000000000000000",
|
||||
data: "0x",
|
||||
chainId,
|
||||
chainId: NETWORKS[state.networkId].chainId,
|
||||
gasLimit: "21000",
|
||||
maxFeePerGas: "20000000000",
|
||||
nonce: 0,
|
||||
@@ -242,7 +212,7 @@ describe.each([
|
||||
await confirmSend("0.1");
|
||||
expect(text("confirm-type")).toBe("Native " + symbol + " transfer");
|
||||
expect(text("confirm-amount")).toBe("0.1 " + symbol);
|
||||
await approveTx(NETWORKS[networkId].chainId);
|
||||
await approveTx();
|
||||
expect(text("approve-tx-value")).toBe("0.0100 " + symbol);
|
||||
});
|
||||
|
||||
@@ -256,80 +226,10 @@ describe.each([
|
||||
expect(text("confirm-gas-error")).toContain(
|
||||
"You do not have enough " + symbol + " to pay the network fee",
|
||||
);
|
||||
await approveTx(NETWORKS[networkId].chainId);
|
||||
await approveTx();
|
||||
expect(text("approve-tx-fee")).toBe("0.0004 " + symbol);
|
||||
});
|
||||
|
||||
test("the contract-recipient warning", async () => {
|
||||
await confirmSend("0.1");
|
||||
expect(text("confirm-contract-warning")).toContain(
|
||||
"Sending " + symbol + " or tokens directly to a contract",
|
||||
);
|
||||
});
|
||||
|
||||
// A token reports whatever symbol it likes. One reporting the label the
|
||||
// wallet shows its native token under, on this network or any other, is
|
||||
// a fake, exactly as one reporting `ETH` always was.
|
||||
test.each(["ETH", symbol])(
|
||||
"a token claiming %s is dropped from the history and the Send selector",
|
||||
(claim) => {
|
||||
const result = filterTransactions(
|
||||
[
|
||||
{
|
||||
hash: "0x" + "1".repeat(64),
|
||||
symbol: claim,
|
||||
contractAddress: TOKEN_CONTRACT,
|
||||
holders: 900000,
|
||||
valueGwei: null,
|
||||
isContractCall: false,
|
||||
},
|
||||
],
|
||||
{ hideSpoofedSymbols: true },
|
||||
);
|
||||
expect(result.transactions).toEqual([]);
|
||||
expect(result.newFraudContracts).toEqual([TOKEN_CONTRACT]);
|
||||
|
||||
send.renderSendTokenSelect({
|
||||
address: HOLDER,
|
||||
tokenBalances: [
|
||||
{
|
||||
address: TOKEN_CONTRACT,
|
||||
symbol: claim,
|
||||
decimals: 18,
|
||||
balance: "5",
|
||||
holders: 900000,
|
||||
},
|
||||
],
|
||||
});
|
||||
expect(
|
||||
global.document.getElementById("send-token").children,
|
||||
).toEqual([]);
|
||||
},
|
||||
);
|
||||
|
||||
// The detail screen tells the two apart by the token contract, which only
|
||||
// a token transfer has, so a token reporting the native label still reads
|
||||
// as a token transfer.
|
||||
test("the transaction detail screen's type line", () => {
|
||||
const entry = {
|
||||
hash: "0x" + "2".repeat(64),
|
||||
from: RECIPIENT,
|
||||
to: HOLDER,
|
||||
value: "1.0000",
|
||||
exactValue: "1.0",
|
||||
symbol,
|
||||
timestamp: 1790000000,
|
||||
isError: false,
|
||||
direction: "received",
|
||||
directionLabel: "Received",
|
||||
chainId: NETWORKS[networkId].chainId,
|
||||
};
|
||||
transactionDetail.show({ ...entry, contractAddress: null });
|
||||
expect(text("tx-detail-type")).toBe("Native " + symbol + " Transfer");
|
||||
transactionDetail.show({ ...entry, contractAddress: TOKEN_CONTRACT });
|
||||
expect(text("tx-detail-type")).toBe("ERC-20 Token Transfer");
|
||||
});
|
||||
|
||||
test("the insufficient-balance error", async () => {
|
||||
await confirmSend("2");
|
||||
expect(
|
||||
@@ -343,119 +243,3 @@ describe.each([
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
// A transaction's value and fee are in the native currency of the network the
|
||||
// transaction is on, which need not be the active one. A site can switch the
|
||||
// active network after its transaction is prepared and back before it is
|
||||
// signed, and a popup opened after a switch shows a sent or listed transaction
|
||||
// again. The wallet's balances follow the active network; these do not.
|
||||
describe.each([
|
||||
["mainnet", "sepolia", "ETH"],
|
||||
["sepolia", "mainnet", "SepoliaETH"],
|
||||
])(
|
||||
"a %s transaction shown with %s active reads %s",
|
||||
(txNetworkId, activeNetworkId, symbol) => {
|
||||
const chainId = NETWORKS[txNetworkId].chainId;
|
||||
const hash = "0x" + "3".repeat(64);
|
||||
|
||||
beforeEach(() => {
|
||||
elements.clear();
|
||||
clearPrices();
|
||||
state.networkId = activeNetworkId;
|
||||
state.wallets = [
|
||||
{
|
||||
name: "Wallet 1",
|
||||
addresses: [{ address: HOLDER, balance: "1.5" }],
|
||||
},
|
||||
];
|
||||
state.selectedWallet = 0;
|
||||
state.selectedAddress = 0;
|
||||
state.trackedTokens = [];
|
||||
state.fraudContracts = [];
|
||||
state.currentView = null;
|
||||
txStatus.init({ doRefreshAndRender() {} });
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
txStatus.endWait();
|
||||
});
|
||||
|
||||
test("the approval screen's value and fee", async () => {
|
||||
await approveTx(chainId);
|
||||
expect(text("approve-tx-network")).toBe(NETWORKS[txNetworkId].name);
|
||||
expect(text("approve-tx-value")).toBe("0.0100 " + symbol);
|
||||
expect(text("approve-tx-fee")).toBe("0.0004 " + symbol);
|
||||
});
|
||||
|
||||
test("the wait, success and error screens", async () => {
|
||||
const txInfo = {
|
||||
from: HOLDER,
|
||||
to: RECIPIENT,
|
||||
amount: "0.0100",
|
||||
token: "ETH",
|
||||
tokenSymbol: null,
|
||||
chainId,
|
||||
};
|
||||
txStatus.showWait(txInfo, hash);
|
||||
expect(text("wait-tx-summary")).toBe("0.0100 " + symbol);
|
||||
txStatus.showError(txInfo, hash, "Failed.");
|
||||
expect(text("error-tx-summary")).toBe("0.0100 " + symbol);
|
||||
// A later popup resumes the wait, and the receipt is there.
|
||||
state.viewData = {
|
||||
pendingWait: { txInfo, hash, broadcastTime: Date.now() },
|
||||
};
|
||||
txStatus.restoreWait();
|
||||
for (let i = 0; i < 10; i++) {
|
||||
await new Promise((r) => setTimeout(r, 0));
|
||||
}
|
||||
expect(text("success-tx-summary")).toBe("0.0100 " + symbol);
|
||||
});
|
||||
|
||||
// Sent from the Send screen on the transaction's network, then
|
||||
// resumed by a popup that opens after the active network changed.
|
||||
test("the wait screen after a send", async () => {
|
||||
state.networkId = txNetworkId;
|
||||
await confirmSend("0.1");
|
||||
confirmTx.init({});
|
||||
global.document.getElementById("confirm-tx-password").value = "pw";
|
||||
await global.document
|
||||
.getElementById("btn-confirm-send")
|
||||
.handlers.get("click")();
|
||||
expect(text("wait-tx-summary")).toBe("0.1 " + symbol);
|
||||
state.networkId = activeNetworkId;
|
||||
txStatus.restoreWait();
|
||||
expect(text("wait-tx-summary")).toBe("0.1 " + symbol);
|
||||
});
|
||||
|
||||
test("the transaction detail screen's type line and fee", async () => {
|
||||
debugFetch.mockImplementationOnce(async () => ({
|
||||
ok: true,
|
||||
status: 200,
|
||||
json: async () => ({ fee: { value: "21000000000000" } }),
|
||||
}));
|
||||
transactionDetail.show({
|
||||
hash,
|
||||
from: RECIPIENT,
|
||||
to: HOLDER,
|
||||
value: "1.0000",
|
||||
exactValue: "1.0",
|
||||
symbol,
|
||||
timestamp: 1790000000,
|
||||
isError: false,
|
||||
direction: "received",
|
||||
directionLabel: "Received",
|
||||
contractAddress: null,
|
||||
chainId,
|
||||
});
|
||||
expect(text("tx-detail-type")).toBe(
|
||||
"Native " + symbol + " Transfer",
|
||||
);
|
||||
for (let i = 0; i < 10; i++) {
|
||||
await new Promise((r) => setTimeout(r, 0));
|
||||
}
|
||||
expect(
|
||||
global.document.getElementById("tx-detail-fee").innerHTML,
|
||||
).toContain("0.000021 " + symbol);
|
||||
});
|
||||
},
|
||||
);
|
||||
|
||||
@@ -722,28 +722,6 @@ describe("the base profile the sweep corrupts", () => {
|
||||
}
|
||||
});
|
||||
|
||||
// Home, AddressDetail and AddressToken load their transactions inside a catch
|
||||
// that only logs, so a boot that fails there still renders the view and passes
|
||||
// the tests above while none of that code runs.
|
||||
describe("the base profile loads transactions", () => {
|
||||
for (const view of ["main", "address", "address-token"]) {
|
||||
test(`on ${view} without logging a failure`, async () => {
|
||||
const consoleError = jest.spyOn(console, "error");
|
||||
try {
|
||||
await bootPopup(restoringOnto(view));
|
||||
const failures = consoleError.mock.calls
|
||||
.map((args) => args.join(" "))
|
||||
.filter((line) =>
|
||||
/loadHomeTxs failed|loadTransactions failed/.test(line),
|
||||
);
|
||||
expect(failures).toEqual([]);
|
||||
} finally {
|
||||
consoleError.mockRestore();
|
||||
}
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
// A field the ROUTER itself reads — the two it gates on and the two
|
||||
// hasValidAddress() indexes with. A hostile value in one of these legitimately
|
||||
// changes which view renders, so each gets its own boot per view and is held
|
||||
|
||||
@@ -45,9 +45,9 @@ describe("vendored blocklist", () => {
|
||||
// than loudly, so the ordering the search depends on is asserted here
|
||||
// against the committed file rather than assumed of the generator.
|
||||
// One assertion at the end rather than one per entry: 100k+ expect()
|
||||
// calls cost seconds, and make test is capped at 60 seconds for the
|
||||
// whole suite. The index of the first offender is reported, so a
|
||||
// failure still says where.
|
||||
// calls cost seconds, and make test is capped at 30 for the whole
|
||||
// suite. The index of the first offender is reported, so a failure
|
||||
// still says where.
|
||||
let previous = "";
|
||||
let outOfOrderAt = -1;
|
||||
for (let i = 0; i < vendored.count; i++) {
|
||||
|
||||
@@ -1,89 +0,0 @@
|
||||
// Every method in PROXY_METHODS is sent to the RPC node.
|
||||
//
|
||||
// handleRpc answers some methods itself before it reaches its proxy branch. A
|
||||
// method listed in PROXY_METHODS but answered earlier never reaches the node,
|
||||
// so the list would name a method that is not proxied
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/326). Each method is sent from
|
||||
// a page here and must come back with what the node answered.
|
||||
|
||||
const { makeStorageStub } = require("./support/storageStub");
|
||||
|
||||
async function settle() {
|
||||
for (let i = 0; i < 50; i++) await Promise.resolve();
|
||||
}
|
||||
|
||||
afterEach(() => {
|
||||
delete global.chrome;
|
||||
delete global.fetch;
|
||||
});
|
||||
|
||||
test("every method in PROXY_METHODS reaches the RPC node", async () => {
|
||||
jest.resetModules();
|
||||
|
||||
jest.doMock("../src/shared/balances", () => ({
|
||||
getProvider: () => ({}),
|
||||
refreshBalances: jest.fn(async () => {}),
|
||||
}));
|
||||
jest.doMock("../src/shared/phishingDomains", () => ({
|
||||
isPhishingDomain: () => false,
|
||||
}));
|
||||
jest.doMock("../src/shared/alarms", () => ({
|
||||
BALANCE_REFRESH_ALARM: "balance",
|
||||
BALANCE_REFRESH_PERIOD_MINUTES: 1,
|
||||
ensureRecurringAlarms: jest.fn(async () => {}),
|
||||
registerAlarmHandlers: jest.fn(),
|
||||
}));
|
||||
|
||||
// The node answers each method with a value naming that method.
|
||||
global.fetch = jest.fn(async (url, opts) => ({
|
||||
status: 200,
|
||||
json: async () => ({
|
||||
jsonrpc: "2.0",
|
||||
id: 1,
|
||||
result: "node answered " + JSON.parse(opts.body).method,
|
||||
}),
|
||||
}));
|
||||
|
||||
let messageListener = null;
|
||||
global.chrome = {
|
||||
storage: makeStorageStub({
|
||||
autistmask: {
|
||||
networkId: "mainnet",
|
||||
wallets: [],
|
||||
allowedSites: {},
|
||||
deniedSites: {},
|
||||
},
|
||||
}),
|
||||
runtime: {
|
||||
getURL: (path) => "chrome-extension://autistmask/" + path,
|
||||
onMessage: {
|
||||
addListener: (fn) => {
|
||||
messageListener = fn;
|
||||
},
|
||||
},
|
||||
onConnect: { addListener: () => {} },
|
||||
lastError: null,
|
||||
},
|
||||
windows: { onRemoved: { addListener: () => {} } },
|
||||
action: { setPopup: () => {} },
|
||||
};
|
||||
|
||||
const { PROXY_METHODS } = require("../src/background/index");
|
||||
|
||||
const answers = {};
|
||||
const expected = {};
|
||||
for (const method of PROXY_METHODS) {
|
||||
messageListener(
|
||||
{ type: "AUTISTMASK_RPC", method, params: [] },
|
||||
{ origin: "https://dapp.example" },
|
||||
(r) => {
|
||||
answers[method] = r;
|
||||
},
|
||||
);
|
||||
await settle();
|
||||
expected[method] = { result: "node answered " + method };
|
||||
}
|
||||
|
||||
expect(PROXY_METHODS.length).toBeGreaterThan(0);
|
||||
expect(answers).toEqual(expected);
|
||||
});
|
||||
@@ -1,530 +0,0 @@
|
||||
// The Send screen's "Max" control
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/198).
|
||||
//
|
||||
// For ETH it fills in the exact balance minus the fee reserve the
|
||||
// confirmation screen's balance check gates on, never the four-decimal balance
|
||||
// the Send screen shows; the confirmation screen re-derives that amount from
|
||||
// its own estimate, and signs with that estimate's fee fields. For a token it
|
||||
// fills in the whole balance, and the check that ETH covers the fee still
|
||||
// applies.
|
||||
//
|
||||
// Driven through the real refreshBalances(), Send screen and confirmation
|
||||
// screen, Sign & Send included, with only the node, the explorer and the DOM
|
||||
// stubbed.
|
||||
|
||||
"use strict";
|
||||
|
||||
// What the stub node answers, and the signed transactions it was handed.
|
||||
const mockNode = {
|
||||
balanceWei: 0n,
|
||||
feeData: null,
|
||||
broadcast: [],
|
||||
};
|
||||
|
||||
// The token rows the stub explorer reports for the address.
|
||||
const mockExplorer = { items: [] };
|
||||
|
||||
jest.mock("ethers", () => {
|
||||
const actual = jest.requireActual("ethers");
|
||||
class StubProvider {
|
||||
async getBalance() {
|
||||
return mockNode.balanceWei;
|
||||
}
|
||||
async lookupAddress() {
|
||||
return null;
|
||||
}
|
||||
async getFeeData() {
|
||||
return mockNode.feeData;
|
||||
}
|
||||
async estimateGas() {
|
||||
return 21000n;
|
||||
}
|
||||
async getCode() {
|
||||
return "0x";
|
||||
}
|
||||
async getTransactionCount() {
|
||||
return 1;
|
||||
}
|
||||
async getNetwork() {
|
||||
return { chainId: 1n };
|
||||
}
|
||||
async broadcastTransaction(signed) {
|
||||
mockNode.broadcast.push(signed);
|
||||
return { hash: "0x" + "ab".repeat(32) };
|
||||
}
|
||||
}
|
||||
return {
|
||||
...actual,
|
||||
JsonRpcProvider: StubProvider,
|
||||
Network: { from: () => ({}) },
|
||||
};
|
||||
});
|
||||
|
||||
jest.mock("../src/shared/log", () => ({
|
||||
log: {
|
||||
debugf: () => {},
|
||||
infof: () => {},
|
||||
warnf: () => {},
|
||||
errorf: () => {},
|
||||
},
|
||||
// The explorer's token list, which refreshBalances() also fetches.
|
||||
debugFetch: jest.fn(async () => ({
|
||||
ok: true,
|
||||
status: 200,
|
||||
json: async () => mockExplorer.items,
|
||||
})),
|
||||
urlOrigin: () => "",
|
||||
setRuntimeDebug: () => {},
|
||||
isDebug: () => false,
|
||||
}));
|
||||
|
||||
// The wait screen polls for a receipt; these tests stop at the broadcast.
|
||||
jest.mock("../src/popup/views/txStatus", () => ({
|
||||
showWait: jest.fn(),
|
||||
showError: jest.fn(),
|
||||
}));
|
||||
|
||||
// The confirmation screen's Etherscan label lookup is the only fetch() these
|
||||
// screens make; it fails, as it does offline.
|
||||
global.fetch = jest.fn(() => {
|
||||
throw new Error("tests must not perform network requests");
|
||||
});
|
||||
|
||||
const { makeStorageStub } = require("./support/storageStub");
|
||||
global.chrome = { storage: makeStorageStub(), runtime: { sendMessage() {} } };
|
||||
|
||||
// A stub DOM: every id resolves to a recording element.
|
||||
const elements = new Map();
|
||||
|
||||
function makeEl(id) {
|
||||
const handlers = new Map();
|
||||
return {
|
||||
id,
|
||||
textContent: "",
|
||||
innerHTML: "",
|
||||
value: "",
|
||||
disabled: false,
|
||||
style: {},
|
||||
dataset: {},
|
||||
classList: {
|
||||
add() {},
|
||||
remove() {},
|
||||
toggle() {},
|
||||
contains: () => false,
|
||||
},
|
||||
handlers,
|
||||
children: [],
|
||||
addEventListener(name, fn) {
|
||||
handlers.set(name, fn);
|
||||
},
|
||||
appendChild(child) {
|
||||
this.children.push(child);
|
||||
return child;
|
||||
},
|
||||
querySelectorAll: () => [],
|
||||
querySelector: () => null,
|
||||
remove() {},
|
||||
focus() {},
|
||||
};
|
||||
}
|
||||
|
||||
global.document = {
|
||||
getElementById(id) {
|
||||
if (!elements.has(id)) elements.set(id, makeEl(id));
|
||||
return elements.get(id);
|
||||
},
|
||||
createElement: (tag) => makeEl(tag),
|
||||
body: { prepend() {}, appendChild() {} },
|
||||
addEventListener() {},
|
||||
};
|
||||
global.navigator = { clipboard: { writeText() {} } };
|
||||
|
||||
const { Transaction, Wallet, formatEther } = require("ethers");
|
||||
const { refreshBalances } = require("../src/shared/balances");
|
||||
const { encryptWithPassword } = require("../src/shared/vault");
|
||||
const { state } = require("../src/shared/state");
|
||||
const send = require("../src/popup/views/send");
|
||||
const confirmTx = require("../src/popup/views/confirmTx");
|
||||
|
||||
const PRIVATE_KEY = "0x" + "11".repeat(32);
|
||||
const HOLDER = new Wallet(PRIVATE_KEY).address;
|
||||
const RECIPIENT = "0xC0FfEE0000000000000000000000000000c0fFEe";
|
||||
// A second address of the wallet, and a second recipient.
|
||||
const OTHER = "0x" + "e".repeat(40);
|
||||
const PASSWORD = "correct horse battery staple";
|
||||
|
||||
const GWEI = 1000000000n;
|
||||
const GAS = 21000n;
|
||||
|
||||
// The Send screen shows this balance as 1.2345 ETH.
|
||||
const BALANCE_WEI = 1234567890123456789n;
|
||||
|
||||
// A token the bundled list does not know, with enough holders to be listed.
|
||||
const TOKEN = "0x" + "d".repeat(40);
|
||||
|
||||
// Fee data whose reserve is 21000 gas at `maxFeePerGas`. The expected cost,
|
||||
// at gasPrice, is lower, as it is on mainnet.
|
||||
function fees(maxFeePerGas) {
|
||||
return {
|
||||
maxFeePerGas,
|
||||
maxPriorityFeePerGas: GWEI,
|
||||
gasPrice: maxFeePerGas / 2n,
|
||||
};
|
||||
}
|
||||
|
||||
// The balance minus a reserve of 21000 gas at `maxFeePerGas`.
|
||||
function maxAfter(maxFeePerGas) {
|
||||
return formatEther(BALANCE_WEI - GAS * maxFeePerGas);
|
||||
}
|
||||
|
||||
function el(id) {
|
||||
return global.document.getElementById(id);
|
||||
}
|
||||
|
||||
function text(id) {
|
||||
return el(id).textContent;
|
||||
}
|
||||
|
||||
// The ETH balance the node reports and the token rows the explorer reports,
|
||||
// fetched and stored exactly where the popup stores them.
|
||||
async function refreshWith(balanceWei, tokenItems = []) {
|
||||
mockNode.balanceWei = balanceWei;
|
||||
mockExplorer.items = tokenItems;
|
||||
state.wallets = [
|
||||
{
|
||||
type: "key",
|
||||
name: "Wallet 1",
|
||||
encryptedSecret: await encryptWithPassword(PRIVATE_KEY, PASSWORD),
|
||||
addresses: [{ address: HOLDER }],
|
||||
},
|
||||
];
|
||||
state.selectedWallet = 0;
|
||||
state.selectedAddress = 0;
|
||||
await refreshBalances(
|
||||
state.wallets,
|
||||
"https://rpc.example.invalid",
|
||||
"https://blockscout.example/api/v2",
|
||||
state.trackedTokens,
|
||||
"mainnet",
|
||||
);
|
||||
}
|
||||
|
||||
function tokenRow(value, decimals = "18") {
|
||||
return {
|
||||
value: String(value),
|
||||
token: {
|
||||
type: "ERC-20",
|
||||
address_hash: TOKEN,
|
||||
symbol: "TOK",
|
||||
name: "Token",
|
||||
decimals,
|
||||
holders_count: "50000",
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
// The confirmation screen Review leads to, once shown.
|
||||
let confirmed = null;
|
||||
|
||||
// Open the Send screen for `token` ("ETH" or a token address), with the
|
||||
// recipient entered.
|
||||
function openSend(token = "ETH") {
|
||||
send.init({ showConfirmTx: (info) => (confirmed = info) });
|
||||
confirmTx.init({});
|
||||
send.resetSendValidation();
|
||||
state.currentView = "send";
|
||||
state.selectedToken = token;
|
||||
el("send-to").value = RECIPIENT;
|
||||
el("send-amount").value = "";
|
||||
}
|
||||
|
||||
async function pressMax() {
|
||||
await el("btn-send-max").handlers.get("click")();
|
||||
}
|
||||
|
||||
// Press Review and show the confirmation screen with its fee estimate settled.
|
||||
async function review() {
|
||||
await el("btn-send-review").handlers.get("click")();
|
||||
confirmTx.show(confirmed);
|
||||
await settle();
|
||||
}
|
||||
|
||||
// show() starts the fee estimate without awaiting it; this lets it settle.
|
||||
async function settle() {
|
||||
for (let i = 0; i < 10; i++) await new Promise((r) => setTimeout(r, 0));
|
||||
}
|
||||
|
||||
function canSend() {
|
||||
return !el("btn-confirm-send").disabled;
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
elements.clear();
|
||||
confirmed = null;
|
||||
state.selectedToken = null;
|
||||
state.trackedTokens = [];
|
||||
state.fraudContracts = [];
|
||||
state.currentView = null;
|
||||
mockNode.feeData = fees(20n * GWEI);
|
||||
mockNode.broadcast = [];
|
||||
});
|
||||
|
||||
describe("Max on an ETH send", () => {
|
||||
test("fills in the exact balance minus the fee reserve", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
send.updateSendBalance();
|
||||
expect(text("send-balance")).toBe("Current balance: 1.2345 ETH");
|
||||
await pressMax();
|
||||
// 1.234567890123456789 - 21000 * 20 gwei.
|
||||
expect(el("send-amount").value).toBe("1.234147890123456789");
|
||||
});
|
||||
|
||||
test("leaves exactly the fee reserve behind, and the confirmation screen enables Send", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
await pressMax();
|
||||
await review();
|
||||
expect(text("confirm-amount")).toBe(maxAfter(20n * GWEI) + " ETH");
|
||||
expect(el("confirm-errors").innerHTML).toBe("");
|
||||
expect(el("confirm-amount-fee-error").style.visibility).toBe("hidden");
|
||||
expect(canSend()).toBe(true);
|
||||
});
|
||||
|
||||
test("re-derives the amount when the fee estimate changes", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe(maxAfter(20n * GWEI));
|
||||
|
||||
// The fee rises between Max and the confirmation screen's estimate.
|
||||
// Kept, the Send screen's amount would be refused for want of funds.
|
||||
mockNode.feeData = fees(30n * GWEI);
|
||||
await review();
|
||||
expect(text("confirm-amount")).toBe(maxAfter(30n * GWEI) + " ETH");
|
||||
expect(canSend()).toBe(true);
|
||||
|
||||
// And falls when the screen is shown again, as on reopening the popup.
|
||||
mockNode.feeData = fees(10n * GWEI);
|
||||
confirmTx.restore();
|
||||
await settle();
|
||||
expect(text("confirm-amount")).toBe(maxAfter(10n * GWEI) + " ETH");
|
||||
expect(canSend()).toBe(true);
|
||||
});
|
||||
|
||||
test("is signed with the fee its amount leaves behind", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
await pressMax();
|
||||
await review();
|
||||
// The fee the node quotes rises after the estimate. Fetched afresh
|
||||
// at signing, it would make amount plus fee more than the balance.
|
||||
mockNode.feeData = fees(25n * GWEI);
|
||||
el("confirm-tx-password").value = PASSWORD;
|
||||
await el("btn-confirm-send").handlers.get("click")();
|
||||
|
||||
expect(mockNode.broadcast).toHaveLength(1);
|
||||
const tx = Transaction.from(mockNode.broadcast[0]);
|
||||
expect(tx.to).toBe(RECIPIENT);
|
||||
expect(tx.maxFeePerGas).toBe(20n * GWEI);
|
||||
expect(tx.value + tx.gasLimit * tx.maxFeePerGas).toBe(BALANCE_WEI);
|
||||
});
|
||||
|
||||
test("says so instead of filling in an amount when the balance does not cover the fee", async () => {
|
||||
// 0.0001 ETH against a reserve of 0.00042 ETH.
|
||||
await refreshWith(100000000000000n);
|
||||
openSend();
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe(
|
||||
"Your balance does not cover the network fee.",
|
||||
);
|
||||
});
|
||||
|
||||
test("asks for the recipient first, since the fee depends on it", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
el("send-to").value = "";
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe(
|
||||
"Please enter a recipient address first.",
|
||||
);
|
||||
});
|
||||
|
||||
// Holds the node's fee answer, so Max's estimate is still running, until
|
||||
// the returned function is called.
|
||||
function holdFeeEstimate() {
|
||||
let release;
|
||||
mockNode.feeData = new Promise((resolve) => {
|
||||
release = () => resolve(fees(20n * GWEI));
|
||||
});
|
||||
return release;
|
||||
}
|
||||
|
||||
test.each([
|
||||
["the same address", 0],
|
||||
["another address", 1],
|
||||
])(
|
||||
"fills nothing in once Send was left and opened again for %s while the fee was estimated",
|
||||
async (_, addressIndex) => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
state.wallets[0].addresses.push({
|
||||
address: OTHER,
|
||||
balance: "2.0",
|
||||
tokenBalances: [],
|
||||
});
|
||||
openSend();
|
||||
const release = holdFeeEstimate();
|
||||
const pressed = pressMax();
|
||||
|
||||
// Back, then Send again as home.js opens it, with the same
|
||||
// recipient typed in again.
|
||||
state.selectedAddress = addressIndex;
|
||||
el("send-to").value = "";
|
||||
el("send-amount").value = "";
|
||||
send.resetSendValidation();
|
||||
el("send-to").value = RECIPIENT;
|
||||
|
||||
release();
|
||||
await pressed;
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe("");
|
||||
},
|
||||
);
|
||||
|
||||
test("fills nothing in and says nothing once Send was left while the fee was estimated", async () => {
|
||||
// 0.0001 ETH, which does not cover the fee: a result that landed
|
||||
// would say so on whichever screen is shown.
|
||||
await refreshWith(100000000000000n);
|
||||
openSend();
|
||||
const release = holdFeeEstimate();
|
||||
const pressed = pressMax();
|
||||
state.currentView = "home";
|
||||
release();
|
||||
await pressed;
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe("");
|
||||
});
|
||||
|
||||
test("fills nothing in when the recipient changed while the fee was estimated", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
const release = holdFeeEstimate();
|
||||
const pressed = pressMax();
|
||||
el("send-to").value = OTHER;
|
||||
release();
|
||||
await pressed;
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe("");
|
||||
});
|
||||
|
||||
test("fills nothing in when the holding was changed while the fee was estimated", async () => {
|
||||
await refreshWith(BALANCE_WEI, [tokenRow(10n ** 18n)]);
|
||||
// Opened from the home screen, where the dropdown picks the holding.
|
||||
openSend(null);
|
||||
el("send-token").value = "ETH";
|
||||
const release = holdFeeEstimate();
|
||||
const pressed = pressMax();
|
||||
el("send-token").value = TOKEN;
|
||||
el("send-token").handlers.get("change")();
|
||||
release();
|
||||
await pressed;
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe("");
|
||||
});
|
||||
|
||||
test("keeps an amount typed while the fee was estimated", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
const release = holdFeeEstimate();
|
||||
const pressed = pressMax();
|
||||
el("send-amount").value = "0.5";
|
||||
el("send-amount").handlers.get("input")();
|
||||
release();
|
||||
await pressed;
|
||||
expect(el("send-amount").value).toBe("0.5");
|
||||
expect(text("flash-msg")).toBe("");
|
||||
});
|
||||
|
||||
test("fills in once the held fee estimate arrives with nothing changed", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
const release = holdFeeEstimate();
|
||||
const pressed = pressMax();
|
||||
release();
|
||||
await pressed;
|
||||
expect(el("send-amount").value).toBe(maxAfter(20n * GWEI));
|
||||
});
|
||||
|
||||
test("typed over, is an ordinary amount the confirmation screen keeps", async () => {
|
||||
await refreshWith(BALANCE_WEI);
|
||||
openSend();
|
||||
await pressMax();
|
||||
el("send-amount").value = "0.5";
|
||||
el("send-amount").handlers.get("input")();
|
||||
mockNode.feeData = fees(30n * GWEI);
|
||||
await review();
|
||||
expect(text("confirm-amount")).toBe("0.5 ETH");
|
||||
});
|
||||
});
|
||||
|
||||
describe("Max on a token send", () => {
|
||||
// 1234.567890123456789012 TOK; the Send screen shows 1234.5678.
|
||||
const TOKEN_UNITS = 1234567890123456789012n;
|
||||
|
||||
test("fills in the whole token balance", async () => {
|
||||
await refreshWith(BALANCE_WEI, [tokenRow(TOKEN_UNITS)]);
|
||||
openSend(TOKEN);
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("1234.567890123456789012");
|
||||
await review();
|
||||
expect(text("confirm-amount")).toBe("1234.567890123456789012 TOK");
|
||||
expect(canSend()).toBe(true);
|
||||
});
|
||||
|
||||
test("of a token with more than 18 decimal places, fills in the balance cut down to the 18 the confirmation screen accepts", async () => {
|
||||
// 1234.567890123456789012999999 TOK at 24 decimal places.
|
||||
await refreshWith(BALANCE_WEI, [
|
||||
tokenRow(1234567890123456789012999999n, "24"),
|
||||
]);
|
||||
openSend(TOKEN);
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("1234.567890123456789012");
|
||||
await review();
|
||||
expect(text("confirm-amount")).toBe("1234.567890123456789012 TOK");
|
||||
expect(canSend()).toBe(true);
|
||||
});
|
||||
|
||||
test("is still refused when ETH cannot cover the fee", async () => {
|
||||
await refreshWith(0n, [tokenRow(TOKEN_UNITS)]);
|
||||
openSend(TOKEN);
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("1234.567890123456789012");
|
||||
await review();
|
||||
expect(el("confirm-gas-error").style.visibility).toBe("visible");
|
||||
expect(canSend()).toBe(false);
|
||||
});
|
||||
|
||||
test("says so when the token balance is unknown", async () => {
|
||||
// No scale from the explorer, the bundled list or a tracked token.
|
||||
const row = tokenRow(TOKEN_UNITS);
|
||||
delete row.token.decimals;
|
||||
await refreshWith(BALANCE_WEI, [row]);
|
||||
openSend(TOKEN);
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe("This token's balance is unknown.");
|
||||
});
|
||||
|
||||
test("says so when the token balance is zero", async () => {
|
||||
state.trackedTokens = [
|
||||
{ address: TOKEN, symbol: "TOK", name: "Token", decimals: 18 },
|
||||
];
|
||||
await refreshWith(BALANCE_WEI, [tokenRow(0n)]);
|
||||
openSend(TOKEN);
|
||||
await pressMax();
|
||||
expect(el("send-amount").value).toBe("");
|
||||
expect(text("flash-msg")).toBe("This token's balance is zero.");
|
||||
});
|
||||
});
|
||||
@@ -423,80 +423,3 @@ describe("two wallets independently created with a colliding identity", () => {
|
||||
expect(secrets).toContain("secret-b");
|
||||
});
|
||||
});
|
||||
|
||||
// showView() saves on every navigation without waiting, so the user can change
|
||||
// something while that save is still waiting on storage. The change is followed
|
||||
// by its own saveState(), which runs after the first save; it must be stored
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/448).
|
||||
describe("a change made while an earlier save from the same page is running", () => {
|
||||
// Runs `change` inside the next call to `op` (the stub's get or set),
|
||||
// before that call does its work.
|
||||
function runInside(op, change) {
|
||||
const real = op.getMockImplementation();
|
||||
op.mockImplementationOnce(async (arg) => {
|
||||
change();
|
||||
return real(arg);
|
||||
});
|
||||
}
|
||||
|
||||
test("a network switched during the earlier save's read is stored", async () => {
|
||||
const storage = makeStorageStub({
|
||||
autistmask: { wallets: [W1], networkId: "sepolia" },
|
||||
});
|
||||
const { state, saveState, loadState } = loadPage(storage).state;
|
||||
await loadState();
|
||||
|
||||
let queued;
|
||||
runInside(storage.get, () => {
|
||||
state.networkId = "mainnet";
|
||||
queued = saveState();
|
||||
});
|
||||
state.theme = "dark";
|
||||
await saveState();
|
||||
await queued;
|
||||
|
||||
const stored = storage.read("autistmask");
|
||||
expect(stored.theme).toBe("dark");
|
||||
expect(stored.networkId).toBe("mainnet");
|
||||
});
|
||||
|
||||
test("a wallet added during the earlier save's read is stored", async () => {
|
||||
const storage = makeStorageStub({ autistmask: { wallets: [W1] } });
|
||||
const { state, saveState, loadState } = loadPage(storage).state;
|
||||
await loadState();
|
||||
|
||||
let queued;
|
||||
runInside(storage.get, () => {
|
||||
state.wallets.push(W2);
|
||||
queued = saveState();
|
||||
});
|
||||
await saveState();
|
||||
await queued;
|
||||
|
||||
const stored = storage.read("autistmask");
|
||||
expect(stored.wallets.map((w) => w.encryptedSecret)).toEqual([
|
||||
"secret-one",
|
||||
"secret-two",
|
||||
]);
|
||||
});
|
||||
|
||||
test("a wallet added during the earlier save's write is stored", async () => {
|
||||
const storage = makeStorageStub({ autistmask: { wallets: [W1] } });
|
||||
const { state, saveState, loadState } = loadPage(storage).state;
|
||||
await loadState();
|
||||
|
||||
let queued;
|
||||
runInside(storage.set, () => {
|
||||
state.wallets.push(W2);
|
||||
queued = saveState();
|
||||
});
|
||||
await saveState();
|
||||
await queued;
|
||||
|
||||
const stored = storage.read("autistmask");
|
||||
expect(stored.wallets.map((w) => w.encryptedSecret)).toEqual([
|
||||
"secret-one",
|
||||
"secret-two",
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -148,173 +148,6 @@ describe("the destructive reset on the recovery screen", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("a popup already open when the stored profile becomes unreadable", () => {
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/373. The popup used to stay
|
||||
// on the wallet list with the last good balances, and only a reopen
|
||||
// reached the recovery screen.
|
||||
test("moves to the recovery screen at its next refresh", async () => {
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
expect(env.visibleViews()).toEqual(["main"]);
|
||||
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[0].blob);
|
||||
await env.tick();
|
||||
|
||||
expect(env.visibleViews()).toEqual(["state-recovery"]);
|
||||
expect(env.text("state-recovery-problem").length).toBeGreaterThan(10);
|
||||
expect(env.hidden("btn-settings")).toBe(true);
|
||||
expect(env.storage.read("autistmask")).toEqual(CORRUPT_BLOBS[0].blob);
|
||||
});
|
||||
|
||||
test("stops the ten-second refresh", async () => {
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[0].blob);
|
||||
await env.tick();
|
||||
const { refreshBalances } = require("../src/shared/balances");
|
||||
const calls = refreshBalances.mock.calls.length;
|
||||
|
||||
await env.tick();
|
||||
|
||||
expect(refreshBalances).toHaveBeenCalledTimes(calls);
|
||||
});
|
||||
|
||||
test("a later save does not clear what the user exported or typed", async () => {
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[2].blob);
|
||||
await env.tick();
|
||||
|
||||
await env.click("btn-state-recovery-export");
|
||||
env.node("state-recovery-reset-input").value = "erase my";
|
||||
// Such as the save of a refresh already in flight when the screen
|
||||
// went up.
|
||||
const { saveState } = require("../src/shared/state");
|
||||
await expect(saveState()).rejects.toThrow();
|
||||
await env.settle();
|
||||
|
||||
expect(env.visibleViews()).toEqual(["state-recovery"]);
|
||||
expect(env.hidden("state-recovery-blob")).toBe(false);
|
||||
expect(env.value("state-recovery-reset-input")).toBe("erase my");
|
||||
});
|
||||
|
||||
// The record can become readable again under this popup, erased from the
|
||||
// recovery screen of another window, so a save from this one can succeed.
|
||||
test("a popup opened after the record is erased elsewhere shows a screen", async () => {
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[0].blob);
|
||||
await env.tick();
|
||||
expect(env.visibleViews()).toEqual(["state-recovery"]);
|
||||
|
||||
await env.storage.remove("autistmask");
|
||||
const { saveState } = require("../src/shared/state");
|
||||
await saveState();
|
||||
|
||||
const reopened = await bootPopup(env.storage.read("autistmask"));
|
||||
expect(reopened.visibleViews()).toEqual(["welcome"]);
|
||||
});
|
||||
|
||||
test("a stored current view of the recovery screen does not blank the popup", async () => {
|
||||
const env = await bootPopup(
|
||||
unversionedValidProfile({ currentView: "state-recovery" }),
|
||||
);
|
||||
expect(env.visibleViews()).toEqual(["main"]);
|
||||
});
|
||||
|
||||
test("a transaction wait that ends under it does not replace it", async () => {
|
||||
const env = await bootPopup(
|
||||
unversionedValidProfile({
|
||||
currentView: "wait-tx",
|
||||
viewData: {
|
||||
pendingWait: {
|
||||
hash: "0x1",
|
||||
txInfo: { to: ADDRESS, amount: "1", token: "ETH" },
|
||||
broadcastTime: Date.now(),
|
||||
},
|
||||
},
|
||||
}),
|
||||
);
|
||||
expect(env.visibleViews()).toEqual(["wait-tx"]);
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[2].blob);
|
||||
await env.tick();
|
||||
await env.click("btn-state-recovery-export");
|
||||
env.node("state-recovery-reset-input").value = "erase my";
|
||||
|
||||
// The test provider answers no receipt lookup, and six that fail in
|
||||
// a row end the wait with an error.
|
||||
for (let i = 0; i < 6; i++) await env.tick();
|
||||
|
||||
expect(env.text("error-tx-message")).toMatch(/could not be reached/);
|
||||
expect(env.visibleViews()).toEqual(["state-recovery"]);
|
||||
expect(env.hidden("state-recovery-blob")).toBe(false);
|
||||
expect(env.value("state-recovery-reset-input")).toBe("erase my");
|
||||
});
|
||||
|
||||
test("a storage read that fails once leaves the wallet list up", async () => {
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
|
||||
env.storage.local.get.mockRejectedValueOnce(
|
||||
new Error("IO error: storage busy"),
|
||||
);
|
||||
await env.tick();
|
||||
|
||||
// Reported as a failed save, not mistaken for an unreadable profile.
|
||||
expect(env.visibleViews()).toEqual(["main"]);
|
||||
expect(env.node("save-failure-banner")).not.toBeNull();
|
||||
|
||||
await env.tick();
|
||||
expect(env.visibleViews()).toEqual(["main"]);
|
||||
});
|
||||
|
||||
// The screen it replaces is left as any navigation leaves it: the rules
|
||||
// at the top of src/popup/views/showPhrase.js and exportPrivkey.js hold
|
||||
// for this way off them too.
|
||||
describe("from a screen holding a secret", () => {
|
||||
const PHRASE =
|
||||
"abandon abandon abandon abandon abandon abandon abandon" +
|
||||
" abandon abandon abandon abandon about";
|
||||
|
||||
afterEach(() => jest.dontMock("../src/shared/vault"));
|
||||
|
||||
test("a recovery phrase on screen is wiped", async () => {
|
||||
jest.doMock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: async () => PHRASE,
|
||||
}));
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
require("../src/popup/views/showPhrase").show(0);
|
||||
env.node("show-phrase-password").value = "password";
|
||||
await env.click("btn-show-phrase-reveal");
|
||||
expect(env.text("show-phrase-value")).toBe(PHRASE);
|
||||
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[0].blob);
|
||||
await env.tick();
|
||||
|
||||
expect(env.visibleViews()).toEqual(["state-recovery"]);
|
||||
expect(env.text("show-phrase-value")).toBe("");
|
||||
});
|
||||
|
||||
test("a private key still being decrypted is never written", async () => {
|
||||
let answer;
|
||||
jest.doMock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: () =>
|
||||
new Promise((resolve) => {
|
||||
answer = resolve;
|
||||
}),
|
||||
}));
|
||||
const env = await bootPopup(unversionedValidProfile());
|
||||
require("../src/popup/views/exportPrivkey").show(0, 0);
|
||||
env.node("export-privkey-password").value = "password";
|
||||
const revealing = env.click("btn-export-privkey-confirm");
|
||||
|
||||
env.storage.write("autistmask", CORRUPT_BLOBS[0].blob);
|
||||
await env.tick();
|
||||
expect(env.visibleViews()).toEqual(["state-recovery"]);
|
||||
expect(env.value("export-privkey-password")).toBe("");
|
||||
|
||||
answer(PHRASE);
|
||||
await revealing;
|
||||
expect(env.text("export-privkey-value")).toBe("");
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("an unversioned profile that is perfectly valid", () => {
|
||||
// The upgrade case. Every install in the field is in this state, and the
|
||||
// popup must load it, not offer to wipe it.
|
||||
|
||||
@@ -40,10 +40,6 @@ jest.doMock("libsodium-wrappers-sumo", () => sodium);
|
||||
jest.doMock("qrcode", () => QRCode);
|
||||
jest.doMock("ethereum-blockies-base64", () => makeBlockie);
|
||||
|
||||
// Taken before any boot replaces them; see bootPopup().
|
||||
const realSetInterval = globalThis.setInterval;
|
||||
const realClearInterval = globalThis.clearInterval;
|
||||
|
||||
const POPUP_HTML = fs.readFileSync(
|
||||
path.join(__dirname, "..", "..", "src", "popup", "index.html"),
|
||||
"utf8",
|
||||
@@ -253,6 +249,8 @@ async function bootPopup(stored, options) {
|
||||
formatUsd: () => "",
|
||||
formatAddressTotal: () => "",
|
||||
getAddressValue: () => ({ usd: null, partial: false }),
|
||||
getWalletValue: () => ({ usd: null, partial: false }),
|
||||
getTotalValue: () => ({ usd: null, partial: false }),
|
||||
}));
|
||||
jest.doMock("../../src/shared/balances", () => ({
|
||||
fetchTokenBalances: jest.fn(async () => []),
|
||||
@@ -261,12 +259,9 @@ async function bootPopup(stored, options) {
|
||||
getProvider: () => ({}),
|
||||
scanForAddresses: jest.fn(async () => []),
|
||||
}));
|
||||
// filterTransactions() answers in the real one's shape: Home,
|
||||
// AddressDetail and AddressToken read both fields, and a bare list makes
|
||||
// their transaction loading throw into a catch that only logs.
|
||||
jest.doMock("../../src/shared/transactions", () => ({
|
||||
fetchRecentTransactions: jest.fn(async () => []),
|
||||
filterTransactions: () => ({ transactions: [], newFraudContracts: [] }),
|
||||
filterTransactions: () => [],
|
||||
}));
|
||||
|
||||
const storage =
|
||||
@@ -297,20 +292,9 @@ async function bootPopup(stored, options) {
|
||||
}),
|
||||
addEventListener: () => {},
|
||||
};
|
||||
// The ten-second refresh init() starts, and a transaction wait's timers,
|
||||
// would outlive the test. So every interval is recorded rather than
|
||||
// started, clearInterval() removes it as a browser would, and tick() below
|
||||
// runs the ones still set. Put back by cleanupPopup().
|
||||
const intervals = new Map();
|
||||
let lastId = 0;
|
||||
globalThis.setInterval = (fn) => {
|
||||
lastId += 1;
|
||||
intervals.set(lastId, fn);
|
||||
return lastId;
|
||||
};
|
||||
globalThis.clearInterval = (id) => {
|
||||
intervals.delete(id);
|
||||
};
|
||||
// The 10s refresh loop init() starts would outlive the test.
|
||||
const realSetInterval = globalThis.setInterval;
|
||||
globalThis.setInterval = () => 0;
|
||||
|
||||
require("../../src/popup/index");
|
||||
|
||||
@@ -332,6 +316,8 @@ async function bootPopup(stored, options) {
|
||||
}
|
||||
await settle();
|
||||
|
||||
globalThis.setInterval = realSetInterval;
|
||||
|
||||
return {
|
||||
storage,
|
||||
document,
|
||||
@@ -351,12 +337,6 @@ async function bootPopup(stored, options) {
|
||||
for (const fn of fns) await fn();
|
||||
await settle();
|
||||
},
|
||||
// Every interval still set runs once: the ten-second refresh, and a
|
||||
// transaction wait's receipt poll and elapsed counter while one runs.
|
||||
tick: async () => {
|
||||
for (const fn of intervals.values()) await fn();
|
||||
await settle();
|
||||
},
|
||||
settle,
|
||||
// The view ids whose section is not hidden, as the audit measured them.
|
||||
visibleViews: () => {
|
||||
@@ -374,8 +354,6 @@ function cleanupPopup() {
|
||||
delete globalThis.chrome;
|
||||
delete globalThis.document;
|
||||
delete globalThis.window;
|
||||
globalThis.setInterval = realSetInterval;
|
||||
globalThis.clearInterval = realClearInterval;
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
|
||||
@@ -1,159 +0,0 @@
|
||||
// A transaction's time is written by isoDate() and timeAgo() in
|
||||
// src/popup/views/helpers.js on every screen that shows one (README, Display
|
||||
// Consistency; https://git.eeqj.de/sneak/AutistMask/issues/168). AddressDetail
|
||||
// and AddressToken used to define their own copies, so a fix to the shared pair
|
||||
// would not have reached them.
|
||||
//
|
||||
// The pair is replaced before the views are loaded, because a view takes it
|
||||
// when it loads. A view that writes the time with a copy of its own shows the
|
||||
// real time instead of the replacement.
|
||||
//
|
||||
// Driven against a minimal DOM stub in the shape
|
||||
// tests/contractCreation.test.js uses.
|
||||
|
||||
jest.mock("../src/shared/log", () => ({
|
||||
log: {
|
||||
debugf: () => {},
|
||||
infof: () => {},
|
||||
warnf: () => {},
|
||||
errorf: () => {},
|
||||
},
|
||||
// The transaction detail view fetches on-chain details after drawing; an
|
||||
// answer that is not ok leaves the drawn lines as they are.
|
||||
debugFetch: async () => ({ ok: false }),
|
||||
setRuntimeDebug: () => {},
|
||||
isDebug: () => false,
|
||||
}));
|
||||
|
||||
// The history lists ask the explorer for their transactions and resolve ENS
|
||||
// names for them; here the explorer answers with mockHistory and no name
|
||||
// resolves.
|
||||
let mockHistory = [];
|
||||
jest.mock("../src/shared/transactions", () => ({
|
||||
...jest.requireActual("../src/shared/transactions"),
|
||||
fetchRecentTransactions: async () => mockHistory,
|
||||
}));
|
||||
jest.mock("../src/shared/ens", () => ({
|
||||
...jest.requireActual("../src/shared/ens"),
|
||||
resolveEnsNames: async () => new Map(),
|
||||
}));
|
||||
|
||||
globalThis.chrome = {
|
||||
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||
};
|
||||
|
||||
const helpers = require("../src/popup/views/helpers");
|
||||
jest.spyOn(helpers, "isoDate").mockReturnValue("SHARED-ISO-DATE");
|
||||
jest.spyOn(helpers, "timeAgo").mockReturnValue("SHARED-TIME-AGO");
|
||||
|
||||
const { state } = require("../src/shared/state");
|
||||
const addressDetail = require("../src/popup/views/addressDetail");
|
||||
const addressToken = require("../src/popup/views/addressToken");
|
||||
const transactionDetail = require("../src/popup/views/transactionDetail");
|
||||
|
||||
const FROM = "0x0000000000000000000000000000000000000a11";
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
function makeElement(id) {
|
||||
const el = {
|
||||
id,
|
||||
textContent: "",
|
||||
value: "",
|
||||
innerHTML: "",
|
||||
style: {},
|
||||
dataset: {},
|
||||
classList: {
|
||||
add: () => {},
|
||||
remove: () => {},
|
||||
contains: () => false,
|
||||
toggle: () => false,
|
||||
},
|
||||
addEventListener: () => {},
|
||||
querySelectorAll: () => [],
|
||||
appendChild: () => {},
|
||||
};
|
||||
// Views reach for .parentElement to hide whole sections.
|
||||
Object.defineProperty(el, "parentElement", {
|
||||
get: () => node(id + "-parent"),
|
||||
});
|
||||
return el;
|
||||
}
|
||||
|
||||
function makeDocument() {
|
||||
const els = new Map();
|
||||
return {
|
||||
getElementById(id) {
|
||||
// The debug banner is created on demand by helpers.js; absent
|
||||
// is the state a non-debug, non-testnet popup is in.
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement(id));
|
||||
return els.get(id);
|
||||
},
|
||||
createElement: () => makeElement("created"),
|
||||
body: { prepend: () => {} },
|
||||
};
|
||||
}
|
||||
|
||||
function node(id) {
|
||||
return globalThis.document.getElementById(id);
|
||||
}
|
||||
|
||||
// A transaction FROM sent, as the history lists hold it.
|
||||
function historyTx() {
|
||||
return {
|
||||
hash: "0x85215772ed26ea8b39c2b3b18779030487efbe0b5fd7e882592b2f62b837be84",
|
||||
from: FROM,
|
||||
to: RECIPIENT,
|
||||
value: "0.0000",
|
||||
exactValue: "0.0",
|
||||
rawAmount: "0",
|
||||
rawUnit: "wei",
|
||||
symbol: "ETH",
|
||||
timestamp: 1790000000,
|
||||
isError: false,
|
||||
directionLabel: "Sent",
|
||||
direction: "sent",
|
||||
contractAddress: null,
|
||||
};
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
globalThis.document = makeDocument();
|
||||
globalThis.window = { location: { search: "" } };
|
||||
state.wallets = [
|
||||
{
|
||||
name: "Main",
|
||||
type: "key",
|
||||
addresses: [{ address: FROM, balance: "0.0000" }],
|
||||
},
|
||||
];
|
||||
state.trackedTokens = [];
|
||||
state.viewData = {};
|
||||
state.viewStack = [];
|
||||
state.currentView = null;
|
||||
state.selectedWallet = 0;
|
||||
state.selectedAddress = 0;
|
||||
state.selectedToken = "ETH";
|
||||
});
|
||||
|
||||
describe.each([
|
||||
["AddressDetail", "tx-list", () => addressDetail.show()],
|
||||
["AddressToken", "address-token-tx-list", () => addressToken.show()],
|
||||
])("a transaction history row on %s", (_name, listId, open) => {
|
||||
test("shows the time written by the shared isoDate() and timeAgo()", async () => {
|
||||
mockHistory = [historyTx()];
|
||||
open();
|
||||
// The list is drawn once the history has been fetched.
|
||||
await new Promise((resolve) => setTimeout(resolve, 0));
|
||||
const html = node(listId).innerHTML;
|
||||
expect(html).toContain('title="SHARED-ISO-DATE"');
|
||||
expect(html).toContain(">SHARED-TIME-AGO<");
|
||||
});
|
||||
});
|
||||
|
||||
test("the transaction detail view shows the time written by the shared isoDate() and timeAgo()", () => {
|
||||
transactionDetail.show(historyTx());
|
||||
const html = node("tx-detail-time").innerHTML;
|
||||
expect(html).toContain("SHARED-ISO-DATE");
|
||||
expect(html).toContain("(SHARED-TIME-AGO)");
|
||||
});
|
||||
+17
-21
@@ -1219,7 +1219,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
|
||||
test("queries only the two Blockscout endpoints for the address", async () => {
|
||||
respondWith([], []);
|
||||
await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(debugFetch).toHaveBeenCalledTimes(2);
|
||||
const urls = debugFetch.mock.calls.map((c) => c[0]);
|
||||
expect(urls).toContain(
|
||||
@@ -1283,7 +1283,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
],
|
||||
);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(txs).toHaveLength(1);
|
||||
const merged = txs[0];
|
||||
// The received leg (the swap output) supplies the display amount.
|
||||
@@ -1320,7 +1320,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
],
|
||||
);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(txs).toHaveLength(1);
|
||||
expect(txs[0].symbol).toBe("USDC");
|
||||
expect(txs[0].value).toBe("1500.5000");
|
||||
@@ -1346,7 +1346,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
});
|
||||
respondWith([], [leg("1000000"), leg("2000000")]);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(txs).toHaveLength(1);
|
||||
// Keyed by hash plus contract, so the later leg wins.
|
||||
expect(txs[0].exactValue).toBe("2.0");
|
||||
@@ -1386,7 +1386,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
],
|
||||
);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(txs.map((t) => t.symbol).sort()).toEqual(["USDC", "WETH"]);
|
||||
});
|
||||
|
||||
@@ -1427,13 +1427,12 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
],
|
||||
);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(txs).toHaveLength(1);
|
||||
expect(txs[0].symbol).toBe("USDC");
|
||||
expect(txs[0].exactValue).toBe("1.0");
|
||||
expect(txs[0].direction).toBe("sent");
|
||||
expect(txs[0].contractAddress).toBe(USDC_CONTRACT);
|
||||
expect(txs[0].chainId).toBe("0x1");
|
||||
// The surviving row is the token row, and the filters keep it.
|
||||
const kept = filterTransactions(txs, filters()).transactions;
|
||||
expect(kept).toHaveLength(1);
|
||||
@@ -1453,14 +1452,13 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
});
|
||||
respondWith([item(6), item(8), item(7)], []);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1", 2);
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH", 2);
|
||||
expect(txs.map((t) => t.blockNumber)).toEqual([21000008, 21000007]);
|
||||
});
|
||||
|
||||
// https://git.eeqj.de/sneak/AutistMask/issues/372: the caller hands in
|
||||
// the chain id of the network the explorer serves. Every entry carries
|
||||
// it, and a native entry is labelled with that network's nativeCurrency.
|
||||
test("a native entry is labelled by the chain id handed in", async () => {
|
||||
// the active network's nativeCurrency, and a native entry carries it.
|
||||
test("a native entry is labelled with the native token symbol handed in", async () => {
|
||||
respondWith(
|
||||
[
|
||||
{
|
||||
@@ -1479,18 +1477,16 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
const sepolia = await fetchRecentTransactions(
|
||||
VICTIM,
|
||||
BLOCKSCOUT,
|
||||
"0xaa36a7",
|
||||
"SepoliaETH",
|
||||
);
|
||||
expect(sepolia[0].symbol).toBe("SepoliaETH");
|
||||
expect(sepolia[0].value).toBe("0.0100");
|
||||
expect(sepolia[0].chainId).toBe("0xaa36a7");
|
||||
const mainnet = await fetchRecentTransactions(
|
||||
VICTIM,
|
||||
BLOCKSCOUT,
|
||||
"0x1",
|
||||
"ETH",
|
||||
);
|
||||
expect(mainnet[0].symbol).toBe("ETH");
|
||||
expect(mainnet[0].chainId).toBe("0x1");
|
||||
});
|
||||
|
||||
test("the fake token transfer survives fetching and is then filtered", async () => {
|
||||
@@ -1513,7 +1509,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
],
|
||||
);
|
||||
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1");
|
||||
const txs = await fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH");
|
||||
expect(txs).toHaveLength(1);
|
||||
expect(txs[0].contractAddress).toBe(FAKE_ETH_CONTRACT);
|
||||
expect(txs[0].holders).toBe(0);
|
||||
@@ -1555,7 +1551,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
const txs = await fetchRecentTransactions(
|
||||
VICTIM,
|
||||
BLOCKSCOUT,
|
||||
"0x1",
|
||||
"ETH",
|
||||
);
|
||||
expect(txs[0].holders).toBeNull();
|
||||
});
|
||||
@@ -1565,7 +1561,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
const txs = await fetchRecentTransactions(
|
||||
VICTIM,
|
||||
BLOCKSCOUT,
|
||||
"0x1",
|
||||
"ETH",
|
||||
);
|
||||
expect(txs[0].holders).toBeNull();
|
||||
});
|
||||
@@ -1575,7 +1571,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
const txs = await fetchRecentTransactions(
|
||||
VICTIM,
|
||||
BLOCKSCOUT,
|
||||
"0x1",
|
||||
"ETH",
|
||||
);
|
||||
expect(filterTransactions(txs, filters()).transactions).toEqual(
|
||||
txs,
|
||||
@@ -1591,7 +1587,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
const txs = await fetchRecentTransactions(
|
||||
VICTIM,
|
||||
BLOCKSCOUT,
|
||||
"0x1",
|
||||
"ETH",
|
||||
);
|
||||
expect(txs[0].holders).toBe(0);
|
||||
expect(filterTransactions(txs, filters()).transactions).toEqual([]);
|
||||
@@ -1608,7 +1604,7 @@ describe("fetchRecentTransactions merge and dedup", () => {
|
||||
},
|
||||
}));
|
||||
await expect(
|
||||
fetchRecentTransactions(VICTIM, BLOCKSCOUT, "0x1"),
|
||||
fetchRecentTransactions(VICTIM, BLOCKSCOUT, "ETH"),
|
||||
).resolves.toEqual([]);
|
||||
});
|
||||
|
||||
|
||||
@@ -6,8 +6,6 @@ const {
|
||||
FEE_UNAVAILABLE,
|
||||
feeReserveWei,
|
||||
feeEstimateWei,
|
||||
maxEthAmount,
|
||||
maxTokenAmount,
|
||||
toFixedPoint,
|
||||
validateTransfer,
|
||||
} = require("../src/shared/txValidation");
|
||||
@@ -308,72 +306,6 @@ describe("feeEstimateWei", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// The amount the Send screen's Max fills in for ETH: the exact balance, as
|
||||
// balances.js stores it, minus the fee reserve. Never the four-decimal balance
|
||||
// the Send screen shows.
|
||||
describe("maxEthAmount", () => {
|
||||
// The Send screen shows this balance as 1.2345.
|
||||
const BALANCE = "1.234567890123456789";
|
||||
|
||||
test("is the exact balance minus the fee, to the wei", () => {
|
||||
expect(maxEthAmount(BALANCE, FEE)).toBe("1.234147890123456789");
|
||||
expect(
|
||||
parseEther(BALANCE) - parseEther(maxEthAmount(BALANCE, FEE)),
|
||||
).toBe(FEE);
|
||||
});
|
||||
|
||||
test("passes validateTransfer with exactly the fee left behind", () => {
|
||||
const r = validateTransfer({
|
||||
isErc20: false,
|
||||
amount: maxEthAmount(BALANCE, FEE),
|
||||
ethBalance: BALANCE,
|
||||
feeStatus: FEE_KNOWN,
|
||||
feeWei: FEE,
|
||||
});
|
||||
expect(r).toEqual({ canSend: true, codes: [] });
|
||||
});
|
||||
|
||||
test("is one wei when the balance is one wei more than the fee", () => {
|
||||
expect(maxEthAmount("0.000420000000000001", FEE)).toBe(
|
||||
"0.000000000000000001",
|
||||
);
|
||||
});
|
||||
|
||||
test("is null when the balance does not cover the fee", () => {
|
||||
expect(maxEthAmount("0.0001", FEE)).toBe(null);
|
||||
expect(maxEthAmount("0.0", FEE)).toBe(null);
|
||||
});
|
||||
|
||||
test("is null when the balance covers the fee and nothing more", () => {
|
||||
expect(maxEthAmount("0.00042", FEE)).toBe(null);
|
||||
});
|
||||
|
||||
test("is null on a balance or fee it cannot do exact arithmetic on", () => {
|
||||
expect(maxEthAmount(undefined, FEE)).toBe(null);
|
||||
expect(maxEthAmount("not a number", FEE)).toBe(null);
|
||||
expect(maxEthAmount(BALANCE, null)).toBe(null);
|
||||
expect(maxEthAmount(BALANCE, -1n)).toBe(null);
|
||||
expect(maxEthAmount(BALANCE, 420000000000000)).toBe(null);
|
||||
});
|
||||
});
|
||||
|
||||
// The amount the Send screen's Max fills in for a token.
|
||||
describe("maxTokenAmount", () => {
|
||||
test("cuts a balance with more than 18 places down, never up", () => {
|
||||
const amount = maxTokenAmount("1234.567890123456789012999999");
|
||||
expect(amount).toBe("1234.567890123456789012");
|
||||
expect(toFixedPoint(amount)).not.toBe(null);
|
||||
});
|
||||
|
||||
test("leaves a balance with 18 places or fewer as it is", () => {
|
||||
expect(maxTokenAmount("0.123456789012345678")).toBe(
|
||||
"0.123456789012345678",
|
||||
);
|
||||
expect(maxTokenAmount("1.5")).toBe("1.5");
|
||||
expect(maxTokenAmount("100")).toBe("100");
|
||||
});
|
||||
});
|
||||
|
||||
// Everything that is not a usable fee blocks exactly as FEE_UNAVAILABLE does.
|
||||
// Each of these previously returned { canSend: true, codes: [] } — counting no
|
||||
// fee at all, on a full-balance send, in the direction that lets money out.
|
||||
|
||||
+2
-2
@@ -12,8 +12,8 @@
|
||||
// interactive parameters, which the module hardcodes. The parameters are not
|
||||
// weakened or overridden anywhere in this file — they are pinned by the "key
|
||||
// derivation cost" tests, since they are the vault's only defence against an
|
||||
// offline attack on a stolen blob. The suite is kept inside the 60-second
|
||||
// make test cap by sharing one encrypted fixture across the tamper cases
|
||||
// offline attack on a stolen blob. The suite is kept inside script/test's
|
||||
// 30-second budget by sharing one encrypted fixture across the tamper cases
|
||||
// instead of re-encrypting per test.
|
||||
|
||||
const sodium = require("libsodium-wrappers-sumo");
|
||||
|
||||
+2
-294
@@ -4,16 +4,8 @@
|
||||
// already in storage: the import that created it ran before the refusal
|
||||
// existed. Such a wallet used to sign for the wrong tree and now throws on the
|
||||
// send screen instead. These tests pin down that it is named and explained in
|
||||
// the wallet list, that every control leading to a signature or to the private
|
||||
// key refuses it before asking for a password, that nothing on the way there
|
||||
// throws, and that a wallet imported from a real master key is untouched by
|
||||
// any of it.
|
||||
|
||||
// Mocked so that no password has to be hashed: the controls below are checked
|
||||
// for whether they decrypt at all.
|
||||
jest.mock("../src/shared/vault", () => ({
|
||||
decryptWithPassword: jest.fn(),
|
||||
}));
|
||||
// the wallet list, that nothing on the way there throws, and that a wallet
|
||||
// imported from a real master key is untouched by any of it.
|
||||
|
||||
const { HDNodeWallet, Mnemonic } = require("ethers");
|
||||
|
||||
@@ -245,290 +237,6 @@ describe("the wallet list", () => {
|
||||
});
|
||||
});
|
||||
|
||||
// A minimal DOM for driving the popup views: any element exists on first
|
||||
// lookup, and click() runs the listeners a view attached to it.
|
||||
function makeElement(id) {
|
||||
const classes = new Set();
|
||||
const el = {
|
||||
id,
|
||||
textContent: "",
|
||||
title: "",
|
||||
value: "",
|
||||
innerHTML: "",
|
||||
disabled: false,
|
||||
style: {},
|
||||
dataset: {},
|
||||
listeners: {},
|
||||
classList: {
|
||||
add: (...names) => names.forEach((n) => classes.add(n)),
|
||||
remove: (...names) => names.forEach((n) => classes.delete(n)),
|
||||
contains: (n) => classes.has(n),
|
||||
toggle: (n, force) => {
|
||||
const on = force === undefined ? !classes.has(n) : force;
|
||||
if (on) classes.add(n);
|
||||
else classes.delete(n);
|
||||
return on;
|
||||
},
|
||||
},
|
||||
addEventListener: (name, fn) => {
|
||||
el.listeners[name] = el.listeners[name] || [];
|
||||
el.listeners[name].push(fn);
|
||||
},
|
||||
querySelectorAll: () => [],
|
||||
appendChild: () => {},
|
||||
};
|
||||
// Views reach for .parentElement to hide whole sections.
|
||||
Object.defineProperty(el, "parentElement", {
|
||||
get: () => node(id + "-parent"),
|
||||
});
|
||||
return el;
|
||||
}
|
||||
|
||||
function makeDocument() {
|
||||
const els = new Map();
|
||||
return {
|
||||
getElementById(id) {
|
||||
// The debug banner is created on demand by helpers.js; absent
|
||||
// is the state a non-debug, non-testnet popup is in.
|
||||
if (id === "debug-banner") return null;
|
||||
if (!els.has(id)) els.set(id, makeElement(id));
|
||||
return els.get(id);
|
||||
},
|
||||
createElement: () => makeElement("created"),
|
||||
addEventListener: () => {},
|
||||
body: { prepend: () => {} },
|
||||
};
|
||||
}
|
||||
|
||||
function node(id) {
|
||||
return globalThis.document.getElementById(id);
|
||||
}
|
||||
|
||||
function click(id) {
|
||||
return Promise.all((node(id).listeners.click || []).map((fn) => fn()));
|
||||
}
|
||||
|
||||
// getSignerForAddress refuses this wallet's key, but only once the password
|
||||
// has been typed and spent, and the screens report that refusal as a wrong
|
||||
// password or a failed send. So every control that leads to it refuses first.
|
||||
describe("every way to a signature or the private key refuses a defective wallet first", () => {
|
||||
const RECIPIENT = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
|
||||
|
||||
let state;
|
||||
let decryptWithPassword;
|
||||
let home;
|
||||
let addressDetail;
|
||||
let addressToken;
|
||||
let approval;
|
||||
let confirmTx;
|
||||
|
||||
let address;
|
||||
let shortMessage;
|
||||
// What the background answers when the approval window asks which
|
||||
// approval it was opened for, and every message the popup sent it.
|
||||
let approvalDetails;
|
||||
let sent;
|
||||
|
||||
beforeAll(() => {
|
||||
state = require("../src/shared/state").state;
|
||||
decryptWithPassword =
|
||||
require("../src/shared/vault").decryptWithPassword;
|
||||
home = require("../src/popup/views/home");
|
||||
addressDetail = require("../src/popup/views/addressDetail");
|
||||
addressToken = require("../src/popup/views/addressToken");
|
||||
approval = require("../src/popup/views/approval");
|
||||
confirmTx = require("../src/popup/views/confirmTx");
|
||||
});
|
||||
|
||||
beforeEach(() => {
|
||||
const broken = brokenXprvWallet();
|
||||
// A balance, so that no Send button's zero-balance refusal can stand
|
||||
// in for the defect check.
|
||||
broken.addresses[0].balance = "1.0000";
|
||||
broken.addresses[0].tokenBalances = [];
|
||||
address = broken.addresses[0].address;
|
||||
shortMessage = walletDefect(broken).shortMessage;
|
||||
|
||||
approvalDetails = null;
|
||||
sent = [];
|
||||
globalThis.document = makeDocument();
|
||||
globalThis.window = { close: () => {} };
|
||||
globalThis.chrome = {
|
||||
storage: { local: { get: async () => ({}), set: async () => {} } },
|
||||
runtime: {
|
||||
connect: () => ({ postMessage: () => {} }),
|
||||
sendMessage: (msg, reply) => {
|
||||
sent.push(msg);
|
||||
if (!reply) return;
|
||||
reply(
|
||||
msg.type === "AUTISTMASK_GET_APPROVAL"
|
||||
? approvalDetails
|
||||
: null,
|
||||
);
|
||||
},
|
||||
},
|
||||
};
|
||||
// What the wallet's stored secret decrypts to: the account-level key
|
||||
// it was imported from.
|
||||
decryptWithPassword.mockReset();
|
||||
decryptWithPassword.mockResolvedValue(accountXprv(VECTOR_PHRASE));
|
||||
|
||||
state.wallets = [broken];
|
||||
state.activeAddress = address;
|
||||
state.selectedWallet = 0;
|
||||
state.selectedAddress = 0;
|
||||
state.selectedToken = "ETH";
|
||||
state.viewStack = [];
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
state.wallets = [];
|
||||
state.activeAddress = null;
|
||||
state.selectedWallet = null;
|
||||
state.selectedAddress = null;
|
||||
state.selectedToken = null;
|
||||
});
|
||||
|
||||
test("Send on the main screen", async () => {
|
||||
state.currentView = "main";
|
||||
home.init({});
|
||||
|
||||
await click("btn-main-send");
|
||||
|
||||
expect(node("flash-msg").textContent).toBe(shortMessage);
|
||||
expect(state.currentView).toBe("main");
|
||||
});
|
||||
|
||||
test("Send on the address screen", async () => {
|
||||
state.currentView = "address";
|
||||
addressDetail.init({});
|
||||
|
||||
await click("btn-send");
|
||||
|
||||
expect(node("flash-msg").textContent).toBe(shortMessage);
|
||||
expect(state.currentView).toBe("address");
|
||||
});
|
||||
|
||||
test("Export Private Key on the address screen", async () => {
|
||||
state.currentView = "address";
|
||||
addressDetail.init({});
|
||||
|
||||
await click("btn-export-privkey");
|
||||
|
||||
expect(node("flash-msg").textContent).toBe(shortMessage);
|
||||
expect(state.currentView).toBe("address");
|
||||
});
|
||||
|
||||
test("Send on a token's screen", async () => {
|
||||
state.currentView = "address-token";
|
||||
addressToken.init({});
|
||||
|
||||
await click("btn-address-token-send");
|
||||
|
||||
expect(node("flash-msg").textContent).toBe(shortMessage);
|
||||
expect(state.currentView).toBe("address-token");
|
||||
});
|
||||
|
||||
// The popup reopens onto this screen from a saved view, so the Send
|
||||
// buttons above are not the only way onto it. The screen is not drawn,
|
||||
// because drawing it starts a fee estimate against the network; with a
|
||||
// decrypt that fails, a handler without the check stops at the password
|
||||
// instead of going on to a transaction that was never set up.
|
||||
test("Send on the confirmation screen", async () => {
|
||||
decryptWithPassword.mockRejectedValue(new Error("wrong password"));
|
||||
state.currentView = "confirm-tx";
|
||||
confirmTx.init({});
|
||||
node("confirm-tx-password").value = "any password";
|
||||
|
||||
await click("btn-confirm-send");
|
||||
|
||||
expect(decryptWithPassword).not.toHaveBeenCalled();
|
||||
expect(node("confirm-tx-password-error").textContent).toBe(
|
||||
shortMessage,
|
||||
);
|
||||
});
|
||||
|
||||
async function openTxApproval() {
|
||||
approvalDetails = {
|
||||
type: "tx",
|
||||
origin: "https://dapp.example",
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: address,
|
||||
approvedTx: {
|
||||
from: address,
|
||||
to: RECIPIENT,
|
||||
value: "0x0",
|
||||
data: "0x",
|
||||
chainId: 1,
|
||||
nonce: 0,
|
||||
gasLimit: "21000",
|
||||
maxFeePerGas: "1000000000",
|
||||
},
|
||||
};
|
||||
approval.init({});
|
||||
await approval.show(1);
|
||||
}
|
||||
|
||||
async function openSignApproval() {
|
||||
approvalDetails = {
|
||||
type: "sign",
|
||||
origin: "https://dapp.example",
|
||||
isPhishingDomain: false,
|
||||
approvedFrom: address,
|
||||
// "Hello", as the hex a page sends.
|
||||
signParams: {
|
||||
method: "personal_sign",
|
||||
message: "0x48656c6c6f",
|
||||
from: address,
|
||||
},
|
||||
};
|
||||
approval.init({});
|
||||
await approval.show(1);
|
||||
}
|
||||
|
||||
test("the transaction approval screen says so and disables Approve", async () => {
|
||||
await openTxApproval();
|
||||
|
||||
expect(node("approve-tx-error").textContent).toBe(shortMessage);
|
||||
expect(node("btn-approve-tx").disabled).toBe(true);
|
||||
});
|
||||
|
||||
// The stub runs a disabled button's listener, which a browser would not:
|
||||
// what is asked here is whether the handler refuses on its own.
|
||||
test("Approve on the transaction approval screen does not decrypt", async () => {
|
||||
await openTxApproval();
|
||||
node("approve-tx-password").value = "any password";
|
||||
|
||||
await click("btn-approve-tx");
|
||||
|
||||
expect(decryptWithPassword).not.toHaveBeenCalled();
|
||||
expect(sent.map((msg) => msg.type)).not.toContain(
|
||||
"AUTISTMASK_TX_RESPONSE",
|
||||
);
|
||||
expect(node("approve-tx-error").textContent).toBe(shortMessage);
|
||||
});
|
||||
|
||||
test("the signature approval screen says so and disables Approve", async () => {
|
||||
await openSignApproval();
|
||||
|
||||
expect(node("approve-sign-error").textContent).toBe(shortMessage);
|
||||
expect(node("btn-approve-sign").disabled).toBe(true);
|
||||
});
|
||||
|
||||
test("Approve on the signature approval screen does not decrypt", async () => {
|
||||
await openSignApproval();
|
||||
node("approve-sign-password").value = "any password";
|
||||
|
||||
await click("btn-approve-sign");
|
||||
|
||||
expect(decryptWithPassword).not.toHaveBeenCalled();
|
||||
expect(sent.map((msg) => msg.type)).not.toContain(
|
||||
"AUTISTMASK_SIGN_RESPONSE",
|
||||
);
|
||||
expect(node("approve-sign-error").textContent).toBe(shortMessage);
|
||||
});
|
||||
});
|
||||
|
||||
describe("no path throws an unhandled error for a defective wallet", () => {
|
||||
test("address derivation from the stored xpub still works", () => {
|
||||
// The stored xpub is at a non-standard depth but is a valid extended
|
||||
|
||||
@@ -275,15 +275,7 @@
|
||||
resolved "https://registry.npmjs.org/@bcoe/v8-coverage/-/v8-coverage-0.2.3.tgz"
|
||||
integrity sha512-0hYQ8SB4Db5zvZB4axdMHGwEaQjkZzFjQiN9LVYvIFB2nSUHW9tYpxWriPrWDASIxiaXax83REcLxuSdnGPZtw==
|
||||
|
||||
"@emnapi/core@^1.10.0":
|
||||
version "1.11.3"
|
||||
resolved "https://registry.yarnpkg.com/@emnapi/core/-/core-1.11.3.tgz#5e95348a42cd1e06f0b9aa380cd74091daa4d520"
|
||||
integrity sha512-zLpS5asjEb7lq8jYLq37N6XKaE41DIexlY1rF/z4/tIl3wo13Sqm28fRyfIsKZD+NZ8mM5RoKkpW/rBcuoSZSg==
|
||||
dependencies:
|
||||
"@emnapi/wasi-threads" "1.2.3"
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@emnapi/core@^1.4.3":
|
||||
"@emnapi/core@^1.4.3", "@emnapi/core@^1.7.1", "@emnapi/core@^1.8.1":
|
||||
version "1.8.1"
|
||||
resolved "https://registry.yarnpkg.com/@emnapi/core/-/core-1.8.1.tgz#fd9efe721a616288345ffee17a1f26ac5dd01349"
|
||||
integrity sha512-AvT9QFpxK0Zd8J0jopedNm+w/2fIzvtPKPjqyw9jwvBaReTTqPBk9Hixaz7KbjimP+QNz605/XnjFcDAL2pqBg==
|
||||
@@ -291,34 +283,20 @@
|
||||
"@emnapi/wasi-threads" "1.1.0"
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@emnapi/runtime@^1.10.0":
|
||||
version "1.11.3"
|
||||
resolved "https://registry.yarnpkg.com/@emnapi/runtime/-/runtime-1.11.3.tgz#84257ae3b0531eb2aec1ffa23d70700da007ba95"
|
||||
integrity sha512-Xz4Tpyki7XyrpbUK1jR1AhdAdaXyhhY4lZ3neLodmhpuWfy2PAQN5B46sAiU4liOXGLkHypn/qU+jvfWSCYYLA==
|
||||
dependencies:
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@emnapi/runtime@^1.4.3":
|
||||
"@emnapi/runtime@^1.4.3", "@emnapi/runtime@^1.7.1", "@emnapi/runtime@^1.8.1":
|
||||
version "1.8.1"
|
||||
resolved "https://registry.yarnpkg.com/@emnapi/runtime/-/runtime-1.8.1.tgz#550fa7e3c0d49c5fb175a116e8cd70614f9a22a5"
|
||||
integrity sha512-mehfKSMWjjNol8659Z8KxEMrdSJDDot5SXMq00dM8BN4o+CLNXQ0xH2V7EchNHV4RmbZLmmPdEaXZc5H2FXmDg==
|
||||
dependencies:
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@emnapi/wasi-threads@1.1.0":
|
||||
"@emnapi/wasi-threads@1.1.0", "@emnapi/wasi-threads@^1.1.0":
|
||||
version "1.1.0"
|
||||
resolved "https://registry.npmjs.org/@emnapi/wasi-threads/-/wasi-threads-1.1.0.tgz"
|
||||
integrity sha512-WI0DdZ8xFSbgMjR1sFsKABJ/C5OnRrjT06JXbZKexJGrDuPTzZdDYfFlsgcCXCyf+suG5QU2e/y1Wo2V/OapLQ==
|
||||
dependencies:
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@emnapi/wasi-threads@1.2.3", "@emnapi/wasi-threads@^1.2.1":
|
||||
version "1.2.3"
|
||||
resolved "https://registry.yarnpkg.com/@emnapi/wasi-threads/-/wasi-threads-1.2.3.tgz#c9bf72fd4be5b928aee894820e8d814ed73916e9"
|
||||
integrity sha512-ELEBe8PsLvvJ6QMr0zLt8ffvOHW/dc1m3CEzNMg7aJUv3bMaoDtw2TXyDAwkYBuroxxuHEwhRTLJSe5sya547g==
|
||||
dependencies:
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@esbuild/aix-ppc64@0.27.3":
|
||||
version "0.27.3"
|
||||
resolved "https://registry.yarnpkg.com/@esbuild/aix-ppc64/-/aix-ppc64-0.27.3.tgz#815b39267f9bffd3407ea6c376ac32946e24f8d2"
|
||||
@@ -824,12 +802,14 @@
|
||||
"@emnapi/runtime" "^1.4.3"
|
||||
"@tybys/wasm-util" "^0.10.0"
|
||||
|
||||
"@napi-rs/wasm-runtime@^1.1.4":
|
||||
version "1.2.5"
|
||||
resolved "https://registry.yarnpkg.com/@napi-rs/wasm-runtime/-/wasm-runtime-1.2.5.tgz#8c728c07e2543d80e55ccb34158c4ae9d6bd13e8"
|
||||
integrity sha512-HshSvXzmBxNzqejd3k/KemgQ3hdREUYFRRrgxOZ+gPljDIsO2SDZrVZMd4Z/HsxudQbE62OVyVFE8z9BCurfjA==
|
||||
"@napi-rs/wasm-runtime@^1.1.1":
|
||||
version "1.1.1"
|
||||
resolved "https://registry.yarnpkg.com/@napi-rs/wasm-runtime/-/wasm-runtime-1.1.1.tgz#c3705ab549d176b8dc5172723d6156c3dc426af2"
|
||||
integrity sha512-p64ah1M1ld8xjWv3qbvFwHiFVWrq1yFvV4f7w+mzaqiR4IlSgkqhcRdHwsGgomwzBH51sRY4NEowLxnaBjcW/A==
|
||||
dependencies:
|
||||
"@tybys/wasm-util" "^0.10.3"
|
||||
"@emnapi/core" "^1.7.1"
|
||||
"@emnapi/runtime" "^1.7.1"
|
||||
"@tybys/wasm-util" "^0.10.1"
|
||||
|
||||
"@noble/curves@1.2.0":
|
||||
version "1.2.0"
|
||||
@@ -843,94 +823,94 @@
|
||||
resolved "https://registry.npmjs.org/@noble/hashes/-/hashes-1.3.2.tgz"
|
||||
integrity sha512-MVC8EAQp7MvEcm30KWENFjgR+Mkmf+D189XJTkFIlwohU5hcBbn1ZkKq7KVTi2Hme3PMGF390DaL52beVrIihQ==
|
||||
|
||||
"@parcel/watcher-android-arm64@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-android-arm64/-/watcher-android-arm64-2.5.1.tgz#507f836d7e2042f798c7d07ad19c3546f9848ac1"
|
||||
integrity sha512-KF8+j9nNbUN8vzOFDpRMsaKBHZ/mcjEjMToVMJOhTozkDonQFFrRcfdLWn6yWKCmJKmdVxSgHiYvTCef4/qcBA==
|
||||
"@parcel/watcher-android-arm64@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-android-arm64/-/watcher-android-arm64-2.5.6.tgz#5f32e0dba356f4ac9a11068d2a5c134ca3ba6564"
|
||||
integrity sha512-YQxSS34tPF/6ZG7r/Ih9xy+kP/WwediEUsqmtf0cuCV5TPPKw/PQHRhueUo6JdeFJaqV3pyjm0GdYjZotbRt/A==
|
||||
|
||||
"@parcel/watcher-darwin-arm64@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-darwin-arm64/-/watcher-darwin-arm64-2.5.1.tgz#3d26dce38de6590ef79c47ec2c55793c06ad4f67"
|
||||
integrity sha512-eAzPv5osDmZyBhou8PoF4i6RQXAfeKL9tjb3QzYuccXFMQU0ruIc/POh30ePnaOyD1UXdlKguHBmsTs53tVoPw==
|
||||
"@parcel/watcher-darwin-arm64@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.npmjs.org/@parcel/watcher-darwin-arm64/-/watcher-darwin-arm64-2.5.6.tgz"
|
||||
integrity sha512-Z2ZdrnwyXvvvdtRHLmM4knydIdU9adO3D4n/0cVipF3rRiwP+3/sfzpAwA/qKFL6i1ModaabkU7IbpeMBgiVEA==
|
||||
|
||||
"@parcel/watcher-darwin-x64@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-darwin-x64/-/watcher-darwin-x64-2.5.1.tgz#99f3af3869069ccf774e4ddfccf7e64fd2311ef8"
|
||||
integrity sha512-1ZXDthrnNmwv10A0/3AJNZ9JGlzrF82i3gNQcWOzd7nJ8aj+ILyW1MTxVk35Db0u91oD5Nlk9MBiujMlwmeXZg==
|
||||
"@parcel/watcher-darwin-x64@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-darwin-x64/-/watcher-darwin-x64-2.5.6.tgz#bf05d76a78bc15974f15ec3671848698b0838063"
|
||||
integrity sha512-HgvOf3W9dhithcwOWX9uDZyn1lW9R+7tPZ4sug+NGrGIo4Rk1hAXLEbcH1TQSqxts0NYXXlOWqVpvS1SFS4fRg==
|
||||
|
||||
"@parcel/watcher-freebsd-x64@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-freebsd-x64/-/watcher-freebsd-x64-2.5.1.tgz#14d6857741a9f51dfe51d5b08b7c8afdbc73ad9b"
|
||||
integrity sha512-SI4eljM7Flp9yPuKi8W0ird8TI/JK6CSxju3NojVI6BjHsTyK7zxA9urjVjEKJ5MBYC+bLmMcbAWlZ+rFkLpJQ==
|
||||
"@parcel/watcher-freebsd-x64@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-freebsd-x64/-/watcher-freebsd-x64-2.5.6.tgz#8bc26e9848e7303ac82922a5ae1b1ef1bdb48a53"
|
||||
integrity sha512-vJVi8yd/qzJxEKHkeemh7w3YAn6RJCtYlE4HPMoVnCpIXEzSrxErBW5SJBgKLbXU3WdIpkjBTeUNtyBVn8TRng==
|
||||
|
||||
"@parcel/watcher-linux-arm-glibc@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm-glibc/-/watcher-linux-arm-glibc-2.5.1.tgz#43c3246d6892381db473bb4f663229ad20b609a1"
|
||||
integrity sha512-RCdZlEyTs8geyBkkcnPWvtXLY44BCeZKmGYRtSgtwwnHR4dxfHRG3gR99XdMEdQ7KeiDdasJwwvNSF5jKtDwdA==
|
||||
"@parcel/watcher-linux-arm-glibc@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm-glibc/-/watcher-linux-arm-glibc-2.5.6.tgz#1328fee1deb0c2d7865079ef53a2ba4cc2f8b40a"
|
||||
integrity sha512-9JiYfB6h6BgV50CCfasfLf/uvOcJskMSwcdH1PHH9rvS1IrNy8zad6IUVPVUfmXr+u+Km9IxcfMLzgdOudz9EQ==
|
||||
|
||||
"@parcel/watcher-linux-arm-musl@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm-musl/-/watcher-linux-arm-musl-2.5.1.tgz#663750f7090bb6278d2210de643eb8a3f780d08e"
|
||||
integrity sha512-6E+m/Mm1t1yhB8X412stiKFG3XykmgdIOqhjWj+VL8oHkKABfu/gjFj8DvLrYVHSBNC+/u5PeNrujiSQ1zwd1Q==
|
||||
"@parcel/watcher-linux-arm-musl@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm-musl/-/watcher-linux-arm-musl-2.5.6.tgz#bad0f45cb3e2157746db8b9d22db6a125711f152"
|
||||
integrity sha512-Ve3gUCG57nuUUSyjBq/MAM0CzArtuIOxsBdQ+ftz6ho8n7s1i9E1Nmk/xmP323r2YL0SONs1EuwqBp2u1k5fxg==
|
||||
|
||||
"@parcel/watcher-linux-arm64-glibc@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm64-glibc/-/watcher-linux-arm64-glibc-2.5.1.tgz#ba60e1f56977f7e47cd7e31ad65d15fdcbd07e30"
|
||||
integrity sha512-LrGp+f02yU3BN9A+DGuY3v3bmnFUggAITBGriZHUREfNEzZh/GO06FF5u2kx8x+GBEUYfyTGamol4j3m9ANe8w==
|
||||
"@parcel/watcher-linux-arm64-glibc@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm64-glibc/-/watcher-linux-arm64-glibc-2.5.6.tgz#b75913fbd501d9523c5f35d420957bf7d0204809"
|
||||
integrity sha512-f2g/DT3NhGPdBmMWYoxixqYr3v/UXcmLOYy16Bx0TM20Tchduwr4EaCbmxh1321TABqPGDpS8D/ggOTaljijOA==
|
||||
|
||||
"@parcel/watcher-linux-arm64-musl@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm64-musl/-/watcher-linux-arm64-musl-2.5.1.tgz#f7fbcdff2f04c526f96eac01f97419a6a99855d2"
|
||||
integrity sha512-cFOjABi92pMYRXS7AcQv9/M1YuKRw8SZniCDw0ssQb/noPkRzA+HBDkwmyOJYp5wXcsTrhxO0zq1U11cK9jsFg==
|
||||
"@parcel/watcher-linux-arm64-musl@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-arm64-musl/-/watcher-linux-arm64-musl-2.5.6.tgz#da5621a6a576070c8c0de60dea8b46dc9c3827d4"
|
||||
integrity sha512-qb6naMDGlbCwdhLj6hgoVKJl2odL34z2sqkC7Z6kzir8b5W65WYDpLB6R06KabvZdgoHI/zxke4b3zR0wAbDTA==
|
||||
|
||||
"@parcel/watcher-linux-x64-glibc@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-x64-glibc/-/watcher-linux-x64-glibc-2.5.1.tgz#4d2ea0f633eb1917d83d483392ce6181b6a92e4e"
|
||||
integrity sha512-GcESn8NZySmfwlTsIur+49yDqSny2IhPeZfXunQi48DMugKeZ7uy1FX83pO0X22sHntJ4Ub+9k34XQCX+oHt2A==
|
||||
"@parcel/watcher-linux-x64-glibc@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-x64-glibc/-/watcher-linux-x64-glibc-2.5.6.tgz#ce437accdc4b30f93a090b4a221fd95cd9b89639"
|
||||
integrity sha512-kbT5wvNQlx7NaGjzPFu8nVIW1rWqV780O7ZtkjuWaPUgpv2NMFpjYERVi0UYj1msZNyCzGlaCWEtzc+exjMGbQ==
|
||||
|
||||
"@parcel/watcher-linux-x64-musl@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-x64-musl/-/watcher-linux-x64-musl-2.5.1.tgz#277b346b05db54f55657301dd77bdf99d63606ee"
|
||||
integrity sha512-n0E2EQbatQ3bXhcH2D1XIAANAcTZkQICBPVaxMeaCVBtOpBZpWJuf7LwyWPSBDITb7In8mqQgJ7gH8CILCURXg==
|
||||
"@parcel/watcher-linux-x64-musl@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-linux-x64-musl/-/watcher-linux-x64-musl-2.5.6.tgz#02400c54b4a67efcc7e2327b249711920ac969e2"
|
||||
integrity sha512-1JRFeC+h7RdXwldHzTsmdtYR/Ku8SylLgTU/reMuqdVD7CtLwf0VR1FqeprZ0eHQkO0vqsbvFLXUmYm/uNKJBg==
|
||||
|
||||
"@parcel/watcher-win32-arm64@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-win32-arm64/-/watcher-win32-arm64-2.5.1.tgz#7e9e02a26784d47503de1d10e8eab6cceb524243"
|
||||
integrity sha512-RFzklRvmc3PkjKjry3hLF9wD7ppR4AKcWNzH7kXR7GUe0Igb3Nz8fyPwtZCSquGrhU5HhUNDr/mKBqj7tqA2Vw==
|
||||
"@parcel/watcher-win32-arm64@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-win32-arm64/-/watcher-win32-arm64-2.5.6.tgz#caae3d3c7583ca0a7171e6bd142c34d20ea1691e"
|
||||
integrity sha512-3ukyebjc6eGlw9yRt678DxVF7rjXatWiHvTXqphZLvo7aC5NdEgFufVwjFfY51ijYEWpXbqF5jtrK275z52D4Q==
|
||||
|
||||
"@parcel/watcher-win32-ia32@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-win32-ia32/-/watcher-win32-ia32-2.5.1.tgz#2d0f94fa59a873cdc584bf7f6b1dc628ddf976e6"
|
||||
integrity sha512-c2KkcVN+NJmuA7CGlaGD1qJh1cLfDnQsHjE89E60vUEMlqduHGCdCLJCID5geFVM0dOtA3ZiIO8BoEQmzQVfpQ==
|
||||
"@parcel/watcher-win32-ia32@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-win32-ia32/-/watcher-win32-ia32-2.5.6.tgz#9ac922550896dfe47bfc5ae3be4f1bcaf8155d6d"
|
||||
integrity sha512-k35yLp1ZMwwee3Ez/pxBi5cf4AoBKYXj00CZ80jUz5h8prpiaQsiRPKQMxoLstNuqe2vR4RNPEAEcjEFzhEz/g==
|
||||
|
||||
"@parcel/watcher-win32-x64@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-win32-x64/-/watcher-win32-x64-2.5.1.tgz#ae52693259664ba6f2228fa61d7ee44b64ea0947"
|
||||
integrity sha512-9lHBdJITeNR++EvSQVUcaZoWupyHfXe1jZvGZ06O/5MflPcuPLtEphScIBL+AiCWBO46tDSHzWyD0uDmmZqsgA==
|
||||
"@parcel/watcher-win32-x64@2.5.6":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher-win32-x64/-/watcher-win32-x64-2.5.6.tgz#73fdafba2e21c448f0e456bbe13178d8fe11739d"
|
||||
integrity sha512-hbQlYcCq5dlAX9Qx+kFb0FHue6vbjlf0FrNzSKdYK2APUf7tGfGxQCk2ihEREmbR6ZMc0MVAD5RIX/41gpUzTw==
|
||||
|
||||
"@parcel/watcher@2.5.1":
|
||||
version "2.5.1"
|
||||
resolved "https://registry.yarnpkg.com/@parcel/watcher/-/watcher-2.5.1.tgz#342507a9cfaaf172479a882309def1e991fb1200"
|
||||
integrity sha512-dfUnCxiN9H4ap84DvD2ubjw+3vUNpstxa0TneY/Paat8a3R4uQZDLSvWjmznAY/DoahqTHl9V46HF/Zs3F29pg==
|
||||
"@parcel/watcher@^2.5.1":
|
||||
version "2.5.6"
|
||||
resolved "https://registry.npmjs.org/@parcel/watcher/-/watcher-2.5.6.tgz"
|
||||
integrity sha512-tmmZ3lQxAe/k/+rNnXQRawJ4NjxO2hqiOLTHvWchtGZULp4RyFeh6aU4XdOYBFe2KE1oShQTv4AblOs2iOrNnQ==
|
||||
dependencies:
|
||||
detect-libc "^1.0.3"
|
||||
detect-libc "^2.0.3"
|
||||
is-glob "^4.0.3"
|
||||
micromatch "^4.0.5"
|
||||
node-addon-api "^7.0.0"
|
||||
picomatch "^4.0.3"
|
||||
optionalDependencies:
|
||||
"@parcel/watcher-android-arm64" "2.5.1"
|
||||
"@parcel/watcher-darwin-arm64" "2.5.1"
|
||||
"@parcel/watcher-darwin-x64" "2.5.1"
|
||||
"@parcel/watcher-freebsd-x64" "2.5.1"
|
||||
"@parcel/watcher-linux-arm-glibc" "2.5.1"
|
||||
"@parcel/watcher-linux-arm-musl" "2.5.1"
|
||||
"@parcel/watcher-linux-arm64-glibc" "2.5.1"
|
||||
"@parcel/watcher-linux-arm64-musl" "2.5.1"
|
||||
"@parcel/watcher-linux-x64-glibc" "2.5.1"
|
||||
"@parcel/watcher-linux-x64-musl" "2.5.1"
|
||||
"@parcel/watcher-win32-arm64" "2.5.1"
|
||||
"@parcel/watcher-win32-ia32" "2.5.1"
|
||||
"@parcel/watcher-win32-x64" "2.5.1"
|
||||
"@parcel/watcher-android-arm64" "2.5.6"
|
||||
"@parcel/watcher-darwin-arm64" "2.5.6"
|
||||
"@parcel/watcher-darwin-x64" "2.5.6"
|
||||
"@parcel/watcher-freebsd-x64" "2.5.6"
|
||||
"@parcel/watcher-linux-arm-glibc" "2.5.6"
|
||||
"@parcel/watcher-linux-arm-musl" "2.5.6"
|
||||
"@parcel/watcher-linux-arm64-glibc" "2.5.6"
|
||||
"@parcel/watcher-linux-arm64-musl" "2.5.6"
|
||||
"@parcel/watcher-linux-x64-glibc" "2.5.6"
|
||||
"@parcel/watcher-linux-x64-musl" "2.5.6"
|
||||
"@parcel/watcher-win32-arm64" "2.5.6"
|
||||
"@parcel/watcher-win32-ia32" "2.5.6"
|
||||
"@parcel/watcher-win32-x64" "2.5.6"
|
||||
|
||||
"@pkgjs/parseargs@^0.11.0":
|
||||
version "0.11.0"
|
||||
@@ -961,131 +941,124 @@
|
||||
dependencies:
|
||||
"@sinonjs/commons" "^3.0.1"
|
||||
|
||||
"@tailwindcss/cli@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/cli/-/cli-4.3.1.tgz#bc00e49e2b70baad223969071e4e380da7123afe"
|
||||
integrity sha512-ZWPy20rF+TBfTImxDMG3Wr75Y3RpaPlo9lc+oJbInlMyjT+XPkTVKVIL5RZ7JirXuIahcfHoLNFRmDorKi+JQQ==
|
||||
"@tailwindcss/cli@^4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.npmjs.org/@tailwindcss/cli/-/cli-4.2.1.tgz"
|
||||
integrity sha512-b7MGn51IA80oSG+7fuAgzfQ+7pZBgjzbqwmiv6NO7/+a1sev32cGqnwhscT7h0EcAvMa9r7gjRylqOH8Xhc4DA==
|
||||
dependencies:
|
||||
"@parcel/watcher" "2.5.1"
|
||||
"@tailwindcss/node" "4.3.1"
|
||||
"@tailwindcss/oxide" "4.3.1"
|
||||
enhanced-resolve "5.21.6"
|
||||
"@parcel/watcher" "^2.5.1"
|
||||
"@tailwindcss/node" "4.2.1"
|
||||
"@tailwindcss/oxide" "4.2.1"
|
||||
enhanced-resolve "^5.19.0"
|
||||
mri "^1.2.0"
|
||||
picocolors "^1.1.1"
|
||||
tailwindcss "4.3.1"
|
||||
tailwindcss "4.2.1"
|
||||
|
||||
"@tailwindcss/node@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/node/-/node-4.3.1.tgz#77402afcfa29c4b48b8494d0edfc4428d0a504ba"
|
||||
integrity sha512-6NDaqRoAMSXD1mr/RXu0HBvNE9a2n5tHPsxu9XHLws8o4Twes5rBM2205SUUiJ9goAtadrN6xTGX0UDEwp/N4A==
|
||||
"@tailwindcss/node@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.npmjs.org/@tailwindcss/node/-/node-4.2.1.tgz"
|
||||
integrity sha512-jlx6sLk4EOwO6hHe1oCGm1Q4AN/s0rSrTTPBGPM0/RQ6Uylwq17FuU8IeJJKEjtc6K6O07zsvP+gDO6MMWo7pg==
|
||||
dependencies:
|
||||
"@jridgewell/remapping" "^2.3.5"
|
||||
enhanced-resolve "5.21.6"
|
||||
jiti "^2.7.0"
|
||||
lightningcss "1.32.0"
|
||||
enhanced-resolve "^5.19.0"
|
||||
jiti "^2.6.1"
|
||||
lightningcss "1.31.1"
|
||||
magic-string "^0.30.21"
|
||||
source-map-js "^1.2.1"
|
||||
tailwindcss "4.3.1"
|
||||
tailwindcss "4.2.1"
|
||||
|
||||
"@tailwindcss/oxide-android-arm64@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-android-arm64/-/oxide-android-arm64-4.3.1.tgz#83c6762cd383a2ebc6e01897b0f35f19225e6653"
|
||||
integrity sha512-SVlyf61g374l5cHyg8x9kf5xmLcOaxvOTsbsqDnSsDJaKOEFZ7GCvi84VAVGpxojYOs1+3K6M0UjXfqPU8vmOQ==
|
||||
"@tailwindcss/oxide-android-arm64@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-android-arm64/-/oxide-android-arm64-4.2.1.tgz#a7c24919b607e7f884e6ab97799d12c7fb5b47bd"
|
||||
integrity sha512-eZ7G1Zm5EC8OOKaesIKuw77jw++QJ2lL9N+dDpdQiAB/c/B2wDh0QPFHbkBVrXnwNugvrbJFk1gK2SsVjwWReg==
|
||||
|
||||
"@tailwindcss/oxide-darwin-arm64@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-darwin-arm64/-/oxide-darwin-arm64-4.3.1.tgz#2558b7e835889ad721823e4dcb50dd5071d747d8"
|
||||
integrity sha512-hVnWLwv+e/l7c4WKyVtHVrIPvYdqWHjRB3MDIqARynzFtnQg85kmQEFCbV9Ja0VVx4xXTIiDWY60Y7iz/iNoDA==
|
||||
"@tailwindcss/oxide-darwin-arm64@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.npmjs.org/@tailwindcss/oxide-darwin-arm64/-/oxide-darwin-arm64-4.2.1.tgz"
|
||||
integrity sha512-q/LHkOstoJ7pI1J0q6djesLzRvQSIfEto148ppAd+BVQK0JYjQIFSK3JgYZJa+Yzi0DDa52ZsQx2rqytBnf8Hw==
|
||||
|
||||
"@tailwindcss/oxide-darwin-x64@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-darwin-x64/-/oxide-darwin-x64-4.3.1.tgz#d987957b87a26668b6d0117ccd4a8a4d1a318a2b"
|
||||
integrity sha512-Cf7abu0WVgbhU7ANgPUnSAvm7nCvMweusHb8FnaHlLfv/Caq4GYaEZg7ZImzzmjx4lIAfuS8q+eLIS7A7IzxIg==
|
||||
"@tailwindcss/oxide-darwin-x64@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-darwin-x64/-/oxide-darwin-x64-4.2.1.tgz#1e59ef0665f6cb9e658bf0ebcb3cb50f21b2c175"
|
||||
integrity sha512-/f/ozlaXGY6QLbpvd/kFTro2l18f7dHKpB+ieXz+Cijl4Mt9AI2rTrpq7V+t04nK+j9XBQHnSMdeQRhbGyt6fw==
|
||||
|
||||
"@tailwindcss/oxide-freebsd-x64@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-freebsd-x64/-/oxide-freebsd-x64-4.3.1.tgz#75b342c81a07b1afa437976ec82f86d372431da7"
|
||||
integrity sha512-ZZqzX2Y+GXtXXfqSfpJhDm60OoZfvLHLCgm+J7NVqgHHJjG/m9ugZI77RwTsVd4fnBJuCFP6Ae6kTJb71UdS8g==
|
||||
"@tailwindcss/oxide-freebsd-x64@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-freebsd-x64/-/oxide-freebsd-x64-4.2.1.tgz#6b0c75e9dac7f1a241cb9a5eaa89f0d9664835b6"
|
||||
integrity sha512-5e/AkgYJT/cpbkys/OU2Ei2jdETCLlifwm7ogMC7/hksI2fC3iiq6OcXwjibcIjPung0kRtR3TxEITkqgn0TcA==
|
||||
|
||||
"@tailwindcss/oxide-linux-arm-gnueabihf@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-arm-gnueabihf/-/oxide-linux-arm-gnueabihf-4.3.1.tgz#6730adc6d17187eeeff2f14f6a914d009749cb97"
|
||||
integrity sha512-/Ah/xik0LaMYfv9DZ0S/t4pBlBNYOcqtRwusjgovHkvT8ixueWCLyJjsaF5kQIckjb4IT8Q6K6p/iPmZMixYgg==
|
||||
"@tailwindcss/oxide-linux-arm-gnueabihf@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-arm-gnueabihf/-/oxide-linux-arm-gnueabihf-4.2.1.tgz#717044d8fe746b1f0760485946c0c9a900174f7b"
|
||||
integrity sha512-Uny1EcVTTmerCKt/1ZuKTkb0x8ZaiuYucg2/kImO5A5Y/kBz41/+j0gxUZl+hTF3xkWpDmHX+TaWhOtba2Fyuw==
|
||||
|
||||
"@tailwindcss/oxide-linux-arm64-gnu@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-arm64-gnu/-/oxide-linux-arm64-gnu-4.3.1.tgz#869d16b3d9bd8097b797a3dd876db0368c07eae3"
|
||||
integrity sha512-gqdFoVJlw444GvpnheZLHmvTzSxI/cOUUh2KSNejQjTcYkW062SVD+En0rUgD+QV91bz1XGIGtt1HJd48xUGbQ==
|
||||
"@tailwindcss/oxide-linux-arm64-gnu@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-arm64-gnu/-/oxide-linux-arm64-gnu-4.2.1.tgz#f544b0faf166d80791347911b2dd4372a893129d"
|
||||
integrity sha512-CTrwomI+c7n6aSSQlsPL0roRiNMDQ/YzMD9EjcR+H4f0I1SQ8QqIuPnsVp7QgMkC1Qi8rtkekLkOFjo7OlEFRQ==
|
||||
|
||||
"@tailwindcss/oxide-linux-arm64-musl@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-arm64-musl/-/oxide-linux-arm64-musl-4.3.1.tgz#ab110680ce3c7a2a135656db4402dffc1fb9c1d7"
|
||||
integrity sha512-Bwv9KwOvE0VKa86xPFif9b9c3Y1NxOV1P0gLti/IYaWEsQYZXDlxfGEtA8mdDZ7SG3wyNXAWYT5SIn3giL57oA==
|
||||
"@tailwindcss/oxide-linux-arm64-musl@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-arm64-musl/-/oxide-linux-arm64-musl-4.2.1.tgz#9fbaf8dc00b858a2b955526abb15d88f5678d1ef"
|
||||
integrity sha512-WZA0CHRL/SP1TRbA5mp9htsppSEkWuQ4KsSUumYQnyl8ZdT39ntwqmz4IUHGN6p4XdSlYfJwM4rRzZLShHsGAQ==
|
||||
|
||||
"@tailwindcss/oxide-linux-x64-gnu@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-x64-gnu/-/oxide-linux-x64-gnu-4.3.1.tgz#422a4175a76ae60dd9d17946eec3584cb636352f"
|
||||
integrity sha512-Ymi8O8T15HYQdOUWUtTI6ldN0neHP85FC+Qz32xTcZ7iJXtem/x8ITev0o1e9e5rkqj4lONZfTRLvkmin1+tKg==
|
||||
"@tailwindcss/oxide-linux-x64-gnu@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-x64-gnu/-/oxide-linux-x64-gnu-4.2.1.tgz#6ab4e6b8d308d037a1155b8443df5941dbfa6aa1"
|
||||
integrity sha512-qMFzxI2YlBOLW5PhblzuSWlWfwLHaneBE0xHzLrBgNtqN6mWfs+qYbhryGSXQjFYB1Dzf5w+LN5qbUTPhW7Y5g==
|
||||
|
||||
"@tailwindcss/oxide-linux-x64-musl@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-x64-musl/-/oxide-linux-x64-musl-4.3.1.tgz#f4c714a653a0e742955d2af2c53d0064b4c500d1"
|
||||
integrity sha512-M+P/91qJ6uILLw4k2G93GMDRAXj61SMvFQYt39AqvUqYgExXpLL5aepfns7sj4HiAQeolirQF9E0lzRvdf4zPQ==
|
||||
"@tailwindcss/oxide-linux-x64-musl@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-linux-x64-musl/-/oxide-linux-x64-musl-4.2.1.tgz#52c55593394dff85f1fa88172f69f8fdcde182b6"
|
||||
integrity sha512-5r1X2FKnCMUPlXTWRYpHdPYUY6a1Ar/t7P24OuiEdEOmms5lyqjDRvVY1yy9Rmioh+AunQ0rWiOTPE8F9A3v5g==
|
||||
|
||||
"@tailwindcss/oxide-wasm32-wasi@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-wasm32-wasi/-/oxide-wasm32-wasi-4.3.1.tgz#32172ca8b2427b9c2bb09c97756960185b7d4fc0"
|
||||
integrity sha512-zsM8uOeqvVGHsAXsJxsT28ttosFahLJKCLOTUBqRAtKnVgGSRitds9T432QiT8b77Yga7JIBkulIRRlJPtYhRA==
|
||||
"@tailwindcss/oxide-wasm32-wasi@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-wasm32-wasi/-/oxide-wasm32-wasi-4.2.1.tgz#7401e35f881d3654b6180badd1243d75a2702ea5"
|
||||
integrity sha512-MGFB5cVPvshR85MTJkEvqDUnuNoysrsRxd6vnk1Lf2tbiqNlXpHYZqkqOQalydienEWOHHFyyuTSYRsLfxFJ2Q==
|
||||
dependencies:
|
||||
"@emnapi/core" "^1.10.0"
|
||||
"@emnapi/runtime" "^1.10.0"
|
||||
"@emnapi/wasi-threads" "^1.2.1"
|
||||
"@napi-rs/wasm-runtime" "^1.1.4"
|
||||
"@tybys/wasm-util" "^0.10.2"
|
||||
"@emnapi/core" "^1.8.1"
|
||||
"@emnapi/runtime" "^1.8.1"
|
||||
"@emnapi/wasi-threads" "^1.1.0"
|
||||
"@napi-rs/wasm-runtime" "^1.1.1"
|
||||
"@tybys/wasm-util" "^0.10.1"
|
||||
tslib "^2.8.1"
|
||||
|
||||
"@tailwindcss/oxide-win32-arm64-msvc@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-win32-arm64-msvc/-/oxide-win32-arm64-msvc-4.3.1.tgz#07a11b6eb1f578d012460e6ad6f2352a28d32514"
|
||||
integrity sha512-aiNvSq9BsVk8V513lDKlrCFAgf8qBMPZTpgEhInL+NwQqs97mYmupVMrPrgBBSL8Pv/0zXu9MrMF9rMun1ZeNg==
|
||||
"@tailwindcss/oxide-win32-arm64-msvc@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-win32-arm64-msvc/-/oxide-win32-arm64-msvc-4.2.1.tgz#63a502e7b696dcd976aa356b94ce0f4f8f832c44"
|
||||
integrity sha512-YlUEHRHBGnCMh4Nj4GnqQyBtsshUPdiNroZj8VPkvTZSoHsilRCwXcVKnG9kyi0ZFAS/3u+qKHBdDc81SADTRA==
|
||||
|
||||
"@tailwindcss/oxide-win32-x64-msvc@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-win32-x64-msvc/-/oxide-win32-x64-msvc-4.3.1.tgz#60c6095d97b141c02de36bb52a16c358d9bdaa98"
|
||||
integrity sha512-xDEyu1rg290472FEGaKHnzyDyh5QH+AlWvsU5hMoMtPpzmKlRI0jaYKCgSHDYtaQWZOYbMaduSyCwFwY4n1HmA==
|
||||
"@tailwindcss/oxide-win32-x64-msvc@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide-win32-x64-msvc/-/oxide-win32-x64-msvc-4.2.1.tgz#8cc59b28ebc4dc866c0c14d7057f07f0ed04c4a8"
|
||||
integrity sha512-rbO34G5sMWWyrN/idLeVxAZgAKWrn5LiR3/I90Q9MkA67s6T1oB0xtTe+0heoBvHSpbU9Mk7i6uwJnpo4u21XQ==
|
||||
|
||||
"@tailwindcss/oxide@4.3.1":
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/@tailwindcss/oxide/-/oxide-4.3.1.tgz#6fdd28b3abf785e2c2cac31f52c4755875826828"
|
||||
integrity sha512-yVPyo8RNkabVr3O2EhHEE0Rewu7YKzc1DhIqfL46LKveFrmu9XbDazNOJY7/GRuvw1h6u3utWnR29H/p5JPlgA==
|
||||
"@tailwindcss/oxide@4.2.1":
|
||||
version "4.2.1"
|
||||
resolved "https://registry.npmjs.org/@tailwindcss/oxide/-/oxide-4.2.1.tgz"
|
||||
integrity sha512-yv9jeEFWnjKCI6/T3Oq50yQEOqmpmpfzG1hcZsAOaXFQPfzWprWrlHSdGPEF3WQTi8zu8ohC9Mh9J470nT5pUw==
|
||||
optionalDependencies:
|
||||
"@tailwindcss/oxide-android-arm64" "4.3.1"
|
||||
"@tailwindcss/oxide-darwin-arm64" "4.3.1"
|
||||
"@tailwindcss/oxide-darwin-x64" "4.3.1"
|
||||
"@tailwindcss/oxide-freebsd-x64" "4.3.1"
|
||||
"@tailwindcss/oxide-linux-arm-gnueabihf" "4.3.1"
|
||||
"@tailwindcss/oxide-linux-arm64-gnu" "4.3.1"
|
||||
"@tailwindcss/oxide-linux-arm64-musl" "4.3.1"
|
||||
"@tailwindcss/oxide-linux-x64-gnu" "4.3.1"
|
||||
"@tailwindcss/oxide-linux-x64-musl" "4.3.1"
|
||||
"@tailwindcss/oxide-wasm32-wasi" "4.3.1"
|
||||
"@tailwindcss/oxide-win32-arm64-msvc" "4.3.1"
|
||||
"@tailwindcss/oxide-win32-x64-msvc" "4.3.1"
|
||||
"@tailwindcss/oxide-android-arm64" "4.2.1"
|
||||
"@tailwindcss/oxide-darwin-arm64" "4.2.1"
|
||||
"@tailwindcss/oxide-darwin-x64" "4.2.1"
|
||||
"@tailwindcss/oxide-freebsd-x64" "4.2.1"
|
||||
"@tailwindcss/oxide-linux-arm-gnueabihf" "4.2.1"
|
||||
"@tailwindcss/oxide-linux-arm64-gnu" "4.2.1"
|
||||
"@tailwindcss/oxide-linux-arm64-musl" "4.2.1"
|
||||
"@tailwindcss/oxide-linux-x64-gnu" "4.2.1"
|
||||
"@tailwindcss/oxide-linux-x64-musl" "4.2.1"
|
||||
"@tailwindcss/oxide-wasm32-wasi" "4.2.1"
|
||||
"@tailwindcss/oxide-win32-arm64-msvc" "4.2.1"
|
||||
"@tailwindcss/oxide-win32-x64-msvc" "4.2.1"
|
||||
|
||||
"@tybys/wasm-util@^0.10.0":
|
||||
"@tybys/wasm-util@^0.10.0", "@tybys/wasm-util@^0.10.1":
|
||||
version "0.10.1"
|
||||
resolved "https://registry.yarnpkg.com/@tybys/wasm-util/-/wasm-util-0.10.1.tgz#ecddd3205cf1e2d5274649ff0eedd2991ed7f414"
|
||||
integrity sha512-9tTaPJLSiejZKx+Bmog4uSubteqTvFrVrURwkmHixBo0G4seD0zUxp98E1DzUBJxLQ3NPwXrGKDiVjwx/DpPsg==
|
||||
dependencies:
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@tybys/wasm-util@^0.10.2", "@tybys/wasm-util@^0.10.3":
|
||||
version "0.10.4"
|
||||
resolved "https://registry.yarnpkg.com/@tybys/wasm-util/-/wasm-util-0.10.4.tgz#3e85ecb266f9d1722250e89bc69528615720b154"
|
||||
integrity sha512-W3c4gRigFS0T/Ma4qIYF3GDAc5AQdHb1yL5znJT1Zv1YaD9Kitx656wBjvr19qbiosmZT8lWDM5BEMynUqX65A==
|
||||
dependencies:
|
||||
tslib "^2.4.0"
|
||||
|
||||
"@types/babel__core@^7.20.5":
|
||||
version "7.20.5"
|
||||
resolved "https://registry.npmjs.org/@types/babel__core/-/babel__core-7.20.5.tgz"
|
||||
@@ -1609,11 +1582,6 @@ deepmerge@^4.3.1:
|
||||
resolved "https://registry.npmjs.org/deepmerge/-/deepmerge-4.3.1.tgz"
|
||||
integrity sha512-3sUqbMEc77XqpdNO7FRyRog+eW3ph+GYCbj+rK+uYyRMuwsVy0rMiVtPn+QJlKFvWP/1PYpapqYn0Me2knFn+A==
|
||||
|
||||
detect-libc@^1.0.3:
|
||||
version "1.0.3"
|
||||
resolved "https://registry.yarnpkg.com/detect-libc/-/detect-libc-1.0.3.tgz#fa137c4bd698edf55cd5cd02ac559f91a4c4ba9b"
|
||||
integrity sha512-pGjwhsmsp4kL2RTz08wcOlGN83otlqHeD/Z5T8GXZB+/YcpQ/dgo+lbU8ZsGxV0HIvqqxo9l7mqYwyYMD9bKDg==
|
||||
|
||||
detect-libc@^2.0.3:
|
||||
version "2.1.2"
|
||||
resolved "https://registry.npmjs.org/detect-libc/-/detect-libc-2.1.2.tgz"
|
||||
@@ -1654,13 +1622,13 @@ emoji-regex@^9.2.2:
|
||||
resolved "https://registry.npmjs.org/emoji-regex/-/emoji-regex-9.2.2.tgz"
|
||||
integrity sha512-L18DaJsXSUk2+42pv8mLs5jJT2hqFkFE4j21wOmgbUqsZ2hL72NsUU785g9RXgo3s0ZNgVl42TiHp3ZtOv/Vyg==
|
||||
|
||||
enhanced-resolve@5.21.6:
|
||||
version "5.21.6"
|
||||
resolved "https://registry.yarnpkg.com/enhanced-resolve/-/enhanced-resolve-5.21.6.tgz#aa207b43cf658e6ab3ba06896edc00c13c3127c6"
|
||||
integrity sha512-aNnGCvbJ/RIyWo1IuhNdVjnNF+EjH9wpzpNHt+ci/m9He9LJvUN8wrCcXjp9cWsGNAuvSpVFTx/vraAFQ8qGjQ==
|
||||
enhanced-resolve@^5.19.0:
|
||||
version "5.19.0"
|
||||
resolved "https://registry.npmjs.org/enhanced-resolve/-/enhanced-resolve-5.19.0.tgz"
|
||||
integrity sha512-phv3E1Xl4tQOShqSte26C7Fl84EwUdZsyOuSSk9qtAGyyQs2s3jJzComh+Abf4g187lUUAvH+H26omrqia2aGg==
|
||||
dependencies:
|
||||
graceful-fs "^4.2.4"
|
||||
tapable "^2.3.3"
|
||||
tapable "^2.3.0"
|
||||
|
||||
error-ex@^1.3.1:
|
||||
version "1.3.4"
|
||||
@@ -2501,10 +2469,10 @@ jest@^30.2.0:
|
||||
import-local "^3.2.0"
|
||||
jest-cli "30.2.0"
|
||||
|
||||
jiti@^2.7.0:
|
||||
version "2.7.0"
|
||||
resolved "https://registry.yarnpkg.com/jiti/-/jiti-2.7.0.tgz#974228f2f4ca2bc21885a1797b45fea68e950c64"
|
||||
integrity sha512-AC/7JofJvZGrrneWNaEnJeOLUx+JlGt7tNa0wZiRPT4MY1wmfKjt2+6O2p2uz2+skll8OZZmJMNqeke7kKbNgQ==
|
||||
jiti@^2.6.1:
|
||||
version "2.6.1"
|
||||
resolved "https://registry.npmjs.org/jiti/-/jiti-2.6.1.tgz"
|
||||
integrity sha512-ekilCSN1jwRvIbgeg/57YFh8qQDNbwDb9xT/qu2DAHbFFZUicIl4ygVaAvzveMhMVr3LnpSKTNnwt8PoOfmKhQ==
|
||||
|
||||
js-tokens@^4.0.0:
|
||||
version "4.0.0"
|
||||
@@ -2581,79 +2549,79 @@ libsodium-wrappers-sumo@^0.8.2:
|
||||
dependencies:
|
||||
libsodium-sumo "^0.8.0"
|
||||
|
||||
lightningcss-android-arm64@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-android-arm64/-/lightningcss-android-arm64-1.32.0.tgz#f033885116dfefd9c6f54787523e3514b61e1968"
|
||||
integrity sha512-YK7/ClTt4kAK0vo6w3X+Pnm0D2cf2vPHbhOXdoNti1Ga0al1P4TBZhwjATvjNwLEBCnKvjJc2jQgHXH0NEwlAg==
|
||||
lightningcss-android-arm64@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-android-arm64/-/lightningcss-android-arm64-1.31.1.tgz#609ff48332adff452a8157a7c2842fd692a8eac4"
|
||||
integrity sha512-HXJF3x8w9nQ4jbXRiNppBCqeZPIAfUo8zE/kOEGbW5NZvGc/K7nMxbhIr+YlFlHW5mpbg/YFPdbnCh1wAXCKFg==
|
||||
|
||||
lightningcss-darwin-arm64@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-darwin-arm64/-/lightningcss-darwin-arm64-1.32.0.tgz#50b71871b01c8199584b649e292547faea7af9b5"
|
||||
integrity sha512-RzeG9Ju5bag2Bv1/lwlVJvBE3q6TtXskdZLLCyfg5pt+HLz9BqlICO7LZM7VHNTTn/5PRhHFBSjk5lc4cmscPQ==
|
||||
lightningcss-darwin-arm64@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.npmjs.org/lightningcss-darwin-arm64/-/lightningcss-darwin-arm64-1.31.1.tgz"
|
||||
integrity sha512-02uTEqf3vIfNMq3h/z2cJfcOXnQ0GRwQrkmPafhueLb2h7mqEidiCzkE4gBMEH65abHRiQvhdcQ+aP0D0g67sg==
|
||||
|
||||
lightningcss-darwin-x64@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-darwin-x64/-/lightningcss-darwin-x64-1.32.0.tgz#35f3e97332d130b9ca181e11b568ded6aebc6d5e"
|
||||
integrity sha512-U+QsBp2m/s2wqpUYT/6wnlagdZbtZdndSmut/NJqlCcMLTWp5muCrID+K5UJ6jqD2BFshejCYXniPDbNh73V8w==
|
||||
lightningcss-darwin-x64@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-darwin-x64/-/lightningcss-darwin-x64-1.31.1.tgz#f7482c311273571ec0c2bd8277c1f5f6e90e03a4"
|
||||
integrity sha512-1ObhyoCY+tGxtsz1lSx5NXCj3nirk0Y0kB/g8B8DT+sSx4G9djitg9ejFnjb3gJNWo7qXH4DIy2SUHvpoFwfTA==
|
||||
|
||||
lightningcss-freebsd-x64@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-freebsd-x64/-/lightningcss-freebsd-x64-1.32.0.tgz#9777a76472b64ed6ff94342ad64c7bafd794a575"
|
||||
integrity sha512-JCTigedEksZk3tHTTthnMdVfGf61Fky8Ji2E4YjUTEQX14xiy/lTzXnu1vwiZe3bYe0q+SpsSH/CTeDXK6WHig==
|
||||
lightningcss-freebsd-x64@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-freebsd-x64/-/lightningcss-freebsd-x64-1.31.1.tgz#91df1bb290f1cb7bb2af832d7d0d8809225e0124"
|
||||
integrity sha512-1RINmQKAItO6ISxYgPwszQE1BrsVU5aB45ho6O42mu96UiZBxEXsuQ7cJW4zs4CEodPUioj/QrXW1r9pLUM74A==
|
||||
|
||||
lightningcss-linux-arm-gnueabihf@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-arm-gnueabihf/-/lightningcss-linux-arm-gnueabihf-1.32.0.tgz#13ae652e1ab73b9135d7b7da172f666c410ad53d"
|
||||
integrity sha512-x6rnnpRa2GL0zQOkt6rts3YDPzduLpWvwAF6EMhXFVZXD4tPrBkEFqzGowzCsIWsPjqSK+tyNEODUBXeeVHSkw==
|
||||
lightningcss-linux-arm-gnueabihf@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-arm-gnueabihf/-/lightningcss-linux-arm-gnueabihf-1.31.1.tgz#c3cad5ae8b70045f21600dc95295ab6166acf57e"
|
||||
integrity sha512-OOCm2//MZJ87CdDK62rZIu+aw9gBv4azMJuA8/KB74wmfS3lnC4yoPHm0uXZ/dvNNHmnZnB8XLAZzObeG0nS1g==
|
||||
|
||||
lightningcss-linux-arm64-gnu@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-arm64-gnu/-/lightningcss-linux-arm64-gnu-1.32.0.tgz#417858795a94592f680123a1b1f9da8a0e1ef335"
|
||||
integrity sha512-0nnMyoyOLRJXfbMOilaSRcLH3Jw5z9HDNGfT/gwCPgaDjnx0i8w7vBzFLFR1f6CMLKF8gVbebmkUN3fa/kQJpQ==
|
||||
lightningcss-linux-arm64-gnu@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-arm64-gnu/-/lightningcss-linux-arm64-gnu-1.31.1.tgz#a5c4f6a5ac77447093f61b209c0bd7fef1f0a3e3"
|
||||
integrity sha512-WKyLWztD71rTnou4xAD5kQT+982wvca7E6QoLpoawZ1gP9JM0GJj4Tp5jMUh9B3AitHbRZ2/H3W5xQmdEOUlLg==
|
||||
|
||||
lightningcss-linux-arm64-musl@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-arm64-musl/-/lightningcss-linux-arm64-musl-1.32.0.tgz#6be36692e810b718040802fd809623cffe732133"
|
||||
integrity sha512-UpQkoenr4UJEzgVIYpI80lDFvRmPVg6oqboNHfoH4CQIfNA+HOrZ7Mo7KZP02dC6LjghPQJeBsvXhJod/wnIBg==
|
||||
lightningcss-linux-arm64-musl@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-arm64-musl/-/lightningcss-linux-arm64-musl-1.31.1.tgz#af26ab8f829b727ada0a200938a6c8796ff36900"
|
||||
integrity sha512-mVZ7Pg2zIbe3XlNbZJdjs86YViQFoJSpc41CbVmKBPiGmC4YrfeOyz65ms2qpAobVd7WQsbW4PdsSJEMymyIMg==
|
||||
|
||||
lightningcss-linux-x64-gnu@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-x64-gnu/-/lightningcss-linux-x64-gnu-1.32.0.tgz#0b7803af4eb21cfd38dd39fe2abbb53c7dd091f6"
|
||||
integrity sha512-V7Qr52IhZmdKPVr+Vtw8o+WLsQJYCTd8loIfpDaMRWGUZfBOYEJeyJIkqGIDMZPwPx24pUMfwSxxI8phr/MbOA==
|
||||
lightningcss-linux-x64-gnu@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-x64-gnu/-/lightningcss-linux-x64-gnu-1.31.1.tgz#a891d44e84b71c0d88959feb9a7522bbf61450ee"
|
||||
integrity sha512-xGlFWRMl+0KvUhgySdIaReQdB4FNudfUTARn7q0hh/V67PVGCs3ADFjw+6++kG1RNd0zdGRlEKa+T13/tQjPMA==
|
||||
|
||||
lightningcss-linux-x64-musl@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-x64-musl/-/lightningcss-linux-x64-musl-1.32.0.tgz#88dc8ba865ddddb1ac5ef04b0f161804418c163b"
|
||||
integrity sha512-bYcLp+Vb0awsiXg/80uCRezCYHNg1/l3mt0gzHnWV9XP1W5sKa5/TCdGWaR/zBM2PeF/HbsQv/j2URNOiVuxWg==
|
||||
lightningcss-linux-x64-musl@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-linux-x64-musl/-/lightningcss-linux-x64-musl-1.31.1.tgz#8c8b21def851f4d477fa897b80cb3db2b650bc6e"
|
||||
integrity sha512-eowF8PrKHw9LpoZii5tdZwnBcYDxRw2rRCyvAXLi34iyeYfqCQNA9rmUM0ce62NlPhCvof1+9ivRaTY6pSKDaA==
|
||||
|
||||
lightningcss-win32-arm64-msvc@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-win32-arm64-msvc/-/lightningcss-win32-arm64-msvc-1.32.0.tgz#4f30ba3fa5e925f5b79f945e8cc0d176c3b1ab38"
|
||||
integrity sha512-8SbC8BR40pS6baCM8sbtYDSwEVQd4JlFTOlaD3gWGHfThTcABnNDBda6eTZeqbofalIJhFx0qKzgHJmcPTnGdw==
|
||||
lightningcss-win32-arm64-msvc@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-win32-arm64-msvc/-/lightningcss-win32-arm64-msvc-1.31.1.tgz#79000fb8c57e94a91b8fc643e74d5a54407d7080"
|
||||
integrity sha512-aJReEbSEQzx1uBlQizAOBSjcmr9dCdL3XuC/6HLXAxmtErsj2ICo5yYggg1qOODQMtnjNQv2UHb9NpOuFtYe4w==
|
||||
|
||||
lightningcss-win32-x64-msvc@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-win32-x64-msvc/-/lightningcss-win32-x64-msvc-1.32.0.tgz#141aa5605645064928902bb4af045fa7d9f4220a"
|
||||
integrity sha512-Amq9B/SoZYdDi1kFrojnoqPLxYhQ4Wo5XiL8EVJrVsB8ARoC1PWW6VGtT0WKCemjy8aC+louJnjS7U18x3b06Q==
|
||||
lightningcss-win32-x64-msvc@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss-win32-x64-msvc/-/lightningcss-win32-x64-msvc-1.31.1.tgz#7f025274c81c7d659829731e09c8b6f442209837"
|
||||
integrity sha512-I9aiFrbd7oYHwlnQDqr1Roz+fTz61oDDJX7n9tYF9FJymH1cIN1DtKw3iYt6b8WZgEjoNwVSncwF4wx/ZedMhw==
|
||||
|
||||
lightningcss@1.32.0:
|
||||
version "1.32.0"
|
||||
resolved "https://registry.yarnpkg.com/lightningcss/-/lightningcss-1.32.0.tgz#b85aae96486dcb1bf49a7c8571221273f4f1e4a9"
|
||||
integrity sha512-NXYBzinNrblfraPGyrbPoD19C1h9lfI/1mzgWYvXUTe414Gz/X1FD2XBZSZM7rRTrMA8JL3OtAaGifrIKhQ5yQ==
|
||||
lightningcss@1.31.1:
|
||||
version "1.31.1"
|
||||
resolved "https://registry.npmjs.org/lightningcss/-/lightningcss-1.31.1.tgz"
|
||||
integrity sha512-l51N2r93WmGUye3WuFoN5k10zyvrVs0qfKBhyC5ogUQ6Ew6JUSswh78mbSO+IU3nTWsyOArqPCcShdQSadghBQ==
|
||||
dependencies:
|
||||
detect-libc "^2.0.3"
|
||||
optionalDependencies:
|
||||
lightningcss-android-arm64 "1.32.0"
|
||||
lightningcss-darwin-arm64 "1.32.0"
|
||||
lightningcss-darwin-x64 "1.32.0"
|
||||
lightningcss-freebsd-x64 "1.32.0"
|
||||
lightningcss-linux-arm-gnueabihf "1.32.0"
|
||||
lightningcss-linux-arm64-gnu "1.32.0"
|
||||
lightningcss-linux-arm64-musl "1.32.0"
|
||||
lightningcss-linux-x64-gnu "1.32.0"
|
||||
lightningcss-linux-x64-musl "1.32.0"
|
||||
lightningcss-win32-arm64-msvc "1.32.0"
|
||||
lightningcss-win32-x64-msvc "1.32.0"
|
||||
lightningcss-android-arm64 "1.31.1"
|
||||
lightningcss-darwin-arm64 "1.31.1"
|
||||
lightningcss-darwin-x64 "1.31.1"
|
||||
lightningcss-freebsd-x64 "1.31.1"
|
||||
lightningcss-linux-arm-gnueabihf "1.31.1"
|
||||
lightningcss-linux-arm64-gnu "1.31.1"
|
||||
lightningcss-linux-arm64-musl "1.31.1"
|
||||
lightningcss-linux-x64-gnu "1.31.1"
|
||||
lightningcss-linux-x64-musl "1.31.1"
|
||||
lightningcss-win32-arm64-msvc "1.31.1"
|
||||
lightningcss-win32-x64-msvc "1.31.1"
|
||||
|
||||
lines-and-columns@^1.1.6:
|
||||
version "1.2.4"
|
||||
@@ -2712,9 +2680,9 @@ merge-stream@^2.0.0:
|
||||
resolved "https://registry.npmjs.org/merge-stream/-/merge-stream-2.0.0.tgz"
|
||||
integrity sha512-abv/qOcuPfk3URPfDzmZU1LKmuw8kT+0nIHvKrKgFrwifol/doWcdA4ZqsWQ8ENrFKkd67Mfpo/LovbIUsbt3w==
|
||||
|
||||
micromatch@^4.0.5, micromatch@^4.0.8:
|
||||
micromatch@^4.0.8:
|
||||
version "4.0.8"
|
||||
resolved "https://registry.yarnpkg.com/micromatch/-/micromatch-4.0.8.tgz#d66fa18f3a47076789320b9b1af32bd86d9fa202"
|
||||
resolved "https://registry.npmjs.org/micromatch/-/micromatch-4.0.8.tgz"
|
||||
integrity sha512-PXwfBhYu0hBCPw8Dn0E+WDYb7af3dSLVWKi3HGv84IdF4TyFoC0ysxFd0Goxw7nSv4T/PzEJQxsYsEiFCKo2BA==
|
||||
dependencies:
|
||||
braces "^3.0.3"
|
||||
@@ -2905,7 +2873,7 @@ picomatch@^2.0.4, picomatch@^2.3.1:
|
||||
resolved "https://registry.npmjs.org/picomatch/-/picomatch-2.3.1.tgz"
|
||||
integrity sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==
|
||||
|
||||
picomatch@^4.0.2:
|
||||
picomatch@^4.0.2, picomatch@^4.0.3:
|
||||
version "4.0.3"
|
||||
resolved "https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz"
|
||||
integrity sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==
|
||||
@@ -3166,15 +3134,15 @@ synckit@^0.11.8:
|
||||
dependencies:
|
||||
"@pkgr/core" "^0.2.9"
|
||||
|
||||
tailwindcss@4.3.1:
|
||||
version "4.3.1"
|
||||
resolved "https://registry.yarnpkg.com/tailwindcss/-/tailwindcss-4.3.1.tgz#78ee06f6186bc8fb9603f8083eb703dc7dd96a10"
|
||||
integrity sha512-hk+TB1m+K8CYNrP6rjQaq/Y+4Zylwpa87mLYBKCunwnnQ9p+fHb7kmSfGqyEJoxF/O6CDyABWVFEafNSYKll+Q==
|
||||
tailwindcss@4.2.1, tailwindcss@^4.2.1:
|
||||
version "4.2.1"
|
||||
resolved "https://registry.npmjs.org/tailwindcss/-/tailwindcss-4.2.1.tgz"
|
||||
integrity sha512-/tBrSQ36vCleJkAOsy9kbNTgaxvGbyOamC30PRePTQe/o1MFwEKHQk4Cn7BNGaPtjp+PuUrByJehM1hgxfq4sw==
|
||||
|
||||
tapable@^2.3.3:
|
||||
version "2.3.3"
|
||||
resolved "https://registry.yarnpkg.com/tapable/-/tapable-2.3.3.tgz#5da7c9992c46038221267985ab28421a8879f160"
|
||||
integrity sha512-uxc/zpqFg6x7C8vOE7lh6Lbda8eEL9zmVm/PLeTPBRhh1xCgdWaQ+J1CUieGpIfm2HdtsUpRv+HshiasBMcc6A==
|
||||
tapable@^2.3.0:
|
||||
version "2.3.0"
|
||||
resolved "https://registry.npmjs.org/tapable/-/tapable-2.3.0.tgz"
|
||||
integrity sha512-g9ljZiwki/LfxmQADO3dEY1CbpmXT5Hm2fJ+QaGKwSXUylMybePR7/67YW7jOrrvjEgL1Fmz5kzyAjWVWLlucg==
|
||||
|
||||
test-exclude@^6.0.0:
|
||||
version "6.0.0"
|
||||
|
||||
Reference in New Issue
Block a user