1 Commits
Author SHA1 Message Date
sneak facaed7967 chore: prune landed remote branches (closes #167)
check / check (push) Canceled after 0s
e2e / e2e-chrome (push) Canceled after 0s
e2e / e2e-firefox (push) Canceled after 0s
Eighteen branches on origin that the issue classifies as landed, or
superseded by merged pull requests, were deleted; the evidence for each
is on the issue. Four whose work is not in next are kept: the three
issue 87 error-display branches, reference for issue 493, and
chore/token-list-enrichment, re-created at f7a2437, pending issue 495.
TODO.md records this.

The branch-pruning Future Step had already left TODO.md in the issue 191
rewrite, so only the Completed Steps entry is added.

Model: opus-5-5
2026-10-07 06:44:52 +00:00
32 changed files with 281 additions and 1744 deletions
+36 -96
View File
@@ -414,20 +414,17 @@ content script, the inpage provider, the background worker and the approval
popup all have to work together. A local test page is served by the route popup all have to work together. A local test page is served by the route
handler on a reserved-TLD origin, gets `window.ethereum` from the shipped handler on a reserved-TLD origin, gets `window.ethereum` from the shipped
`MAIN`-world content script like any other page, and drives `MAIN`-world content script like any other page, and drives
`eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4`, `eth_requestAccounts`, `personal_sign`, `eth_signTypedData_v4` and
`eth_sendTransaction` and `wallet_switchEthereumChain` through the real prompts. `eth_sendTransaction` through the real prompts. Every signature is recovered in
Every signature is recovered in the runner and compared against the active the runner and compared against the active address, the transaction assertions
address, the transaction assertions run against the raw signed transaction run against the raw signed transaction captured at `eth_sendRawTransaction`
captured at `eth_sendRawTransaction` rather than against anything the extension rather than against anything the extension reported, rejecting each prompt is
reported, rejecting each prompt is required to return a rejection to the page required to return a rejection to the page rather than hang or resolve, a prompt
rather than hang or resolve, a network switch request is required to leave the raised while another approval window has focus is required to open a window of
stored network unchanged and send no `chainChanged` until it is approved, a its own, and the password is required to be absent from every message the
network switch in Settings is required to send the page `chainChanged` with the approval window sends to the background — with the message that would carry it
new chain id, a prompt raised while another approval window has focus is required to be present, so that check cannot pass by observing nothing. That
required to open a window of its own, and the password is required to be absent last one is the standing floor under
from every message the approval window sends to the background — with the
message that would carry it required to be present, so that check cannot pass by
observing nothing. That last one is the standing floor under
[#157](https://git.eeqj.de/sneak/AutistMask/issues/157). [#157](https://git.eeqj.de/sneak/AutistMask/issues/157).
The limits of that coverage and of the rest of the Chrome suite, none of them The limits of that coverage and of the rest of the Chrome suite, none of them
@@ -528,11 +525,10 @@ Chrome that ever changes this fails the run instead of passing it.
`make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a `make test-e2e-firefox` builds `dist/firefox/` and drives the **real popup in a
real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver. real Firefox**, installed as an unpacked MV2 temporary add-on via geckodriver.
It covers popup load, the StateRecovery screen (the same cases as the Chrome It covers popup load, the StateRecovery screen (the same cases as the Chrome
suite), wallet creation through the UI, the Add Token screen, and the dApp round suite), wallet creation through the UI, the Add Token screen, and the four dApp
trips — `eth_requestAccounts`, `personal_sign`, `wallet_switchEthereumChain` round trips — `eth_requestAccounts`, `personal_sign`, `eth_sendTransaction`, and
rejected and then approved, `eth_sendTransaction`, and a closed approval window a closed approval window rejecting with EIP-1193 4001 — driven through the real
rejecting with EIP-1193 4001 — driven through the real content script, content script, background page and approval windows.
background page and approval windows.
The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has The suite lives in `tests/e2e/firefox/`. Its WebDriver client (`driver.js`) has
**no npm dependencies at all**: it is built on global `fetch` and **no npm dependencies at all**: it is built on global `fetch` and
@@ -1267,21 +1263,14 @@ path rather than on the home screen. Read the claim narrowly, as that file
states it: what those boots prove is no structural dereference on the code paths states it: what those boots prove is no structural dereference on the code paths
a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes. a WHOLLY-CORRUPTED PROFILE takes, which is not every path a stored record takes.
Not driven: any pairing of values the four slots do not produce, a view only Not driven: any pairing of values the four slots do not produce, a view only
forward navigation opens, anything behind a click or a timer, and, of what a forward navigation opens, anything behind a click, and everything a healthy
healthy profile reaches, anything beyond its boot onto each view the popup can profile reaches. Within that boundary the verdict is unconditional — if one of
reopen onto. The fields the router does not read share a slot on each boot, so those boots leaves the popup unhealthy or off the view it stored, `make check`
one of them truthy while another is falsy is reached only where the falsy slot fails, including when it takes two corrupted fields at once, because the verdict
pairs a field that cannot be falsy with one that is. Within that boundary the is the combined boot and the per-field re-boot that names a culprit can only
verdict is unconditional — if one of those boots leaves the popup unhealthy, decorate the message. So does a field that gains a floor while its row still
`make check` fails, including when it takes two corrupted fields at once, claims it has none, and so does a field added to `PERSISTED_FIELDS` with no row
because the verdict is the combined boot and the per-field re-boot that names a at all. The per-field justification that used to live in the header of
culprit can only decorate the message. The combined boot must also land on the
view it stored, and each value driven only onto the restore path must land on
its view, or fall back to Home, as its row declares; a field the router reads
can legitimately change which view renders, so its own sweep is held to health
alone. `make check` also fails on a field that gains a floor while its row still
claims it has none, and on a field added to `PERSISTED_FIELDS` with no row at
all. The per-field justification that used to live in the header of
`src/shared/stateSchema.js` shipped a false claim in three consecutive changes, `src/shared/stateSchema.js` shipped a false claim in three consecutive changes,
each caught only by a reviewer re-deriving thirty fields by hand. each caught only by a reviewer re-deriving thirty fields by hand.
@@ -1455,17 +1444,14 @@ view would leave a wallet one click from deletion.
without it, the lost-password route on DeleteWallet is the first they without it, the lost-password route on DeleteWallet is the first they
would hear of it. The hint line reserves its height, so switching tabs would hear of it. The hint line reserves its height, so switching tabs
cannot move the password fields under the pointer. cannot move the password fields under the pointer.
- "Import" button, with the error line beside it so that it adds no height - "Import" button
to a screen whose button already starts near the bottom of the popup
- **Transitions**: - **Transitions**:
- "Import" with a valid entry and a matching password of at least 12 - "Import" with a valid entry and a matching password of at least 12
characters → creates the wallet, clears the navigation stack, and → characters → creates the wallet, clears the navigation stack, and →
**Home**. The phrase and xprv modes then scan for further used addresses **Home**. The phrase and xprv modes then scan for further used addresses
and report the count as a flash message. and report the count as a flash message.
- "Import" with a missing, short or mismatched password → full-sentence - "Import" with an invalid entry, a duplicate wallet or address, or a short
error on the error line, no screen change or mismatched password → flash message, no screen change
- "Import" with an invalid entry or a duplicate wallet or address → flash
message, no screen change
- "Back" → previous screen (Welcome, Home, or Settings) - "Back" → previous screen (Welcome, Home, or Settings)
#### AddressDetail (`address`) #### AddressDetail (`address`)
@@ -1504,8 +1490,8 @@ view would leave a wallet one click from deletion.
copy) copy)
- Warning that anyone holding the private key can transfer all funds from - Warning that anyone holding the private key can transfer all funds from
the address the address
- Password input, error line and "Reveal" button, shown until the key is - Error line
revealed - Password input and "Reveal" button, shown until the key is revealed
- The private key on a highlighted background, tap to copy, shown only after - The private key on a highlighted background, tap to copy, shown only after
the password has been accepted the password has been accepted
- **Transitions**: - **Transitions**:
@@ -1786,12 +1772,8 @@ view would leave a wallet one click from deletion.
plus a "+ Add token" button plus a "+ Add token" button
- Display: "Show tracked tokens with zero balance" checkbox, "UTC - Display: "Show tracked tokens with zero balance" checkbox, "UTC
Timestamps" checkbox, and a Theme selector (System / Light / Dark) Timestamps" checkbox, and a Theme selector (System / Light / Dark)
- Network: network selector (Ethereum Mainnet / Sepolia Testnet). The - Network: network selector (Ethereum Mainnet / Sepolia Testnet); switching
network changes only here, or when the user approves a site's request on resets the RPC and Blockscout endpoints to that network's defaults
**NetworkApproval**; either way, switching restores the RPC and Blockscout
endpoints last used on that network, or that network's defaults if it has
none, and sends `chainChanged` with the new chain id to every open tab.
Choosing the network already active changes nothing and sends nothing
- Ethereum RPC: endpoint URL input + "Save" button (validated against - Ethereum RPC: endpoint URL input + "Save" button (validated against
`eth_chainId` before being saved) `eth_chainId` before being saved)
- Blockscout API: endpoint URL input + "Save" button (validated against - Blockscout API: endpoint URL input + "Save" button (validated against
@@ -1847,8 +1829,8 @@ view would leave a wallet one click from deletion.
- Wallet name - Wallet name
- Warning box stating that anyone holding these words can take everything in - Warning box stating that anyone holding these words can take everything in
the wallet, from any device, without the password the wallet, from any device, without the password
- Password input, error line and "Reveal" button, shown until the password - Error line
is accepted - Password input + "Reveal" button, shown until the password is accepted
- The recovery phrase itself, in full and click-to-copy, shown only after a - The recovery phrase itself, in full and click-to-copy, shown only after a
correct password and in place of the password prompt correct password and in place of the password prompt
- **Transitions**: - **Transitions**:
@@ -1877,8 +1859,8 @@ view would leave a wallet one click from deletion.
- "Back" button, "Delete Wallet" heading - "Back" button, "Delete Wallet" heading
- Warning naming the wallet and stating that deletion is permanent and any - Warning naming the wallet and stating that deletion is permanent and any
funds are unrecoverable without the recovery phrase funds are unrecoverable without the recovery phrase
- Password input
- Error line - Error line
- Password input
- "Confirm Delete" button - "Confirm Delete" button
- An underlined "I have lost my password" control - An underlined "I have lost my password" control
- **Transitions**: - **Transitions**:
@@ -2079,10 +2061,7 @@ view would leave a wallet one click from deletion.
no window and takes no nonce, and the site can send it again once the pending no window and takes no nonce, and the site can send it again once the pending
one is answered. The window is centred on the browser window the user was last one is answered. The window is centred on the browser window the user was last
in; if that was another approval window, or the browser refuses the centred in; if that was another approval window, or the browser refuses the centred
position, the browser picks the position. The network shown is the one the position, the browser picks the position.
transaction was populated on, and a site cannot switch it without the user:
its `wallet_switchEthereumChain` request changes the network only when the
user approves it on **NetworkApproval**.
- **Elements**: - **Elements**:
- "Transaction Request" heading - "Transaction Request" heading
- Phishing warning banner (shown when the hostname is on the phishing - Phishing warning banner (shown when the hostname is on the phishing
@@ -2173,40 +2152,6 @@ view would leave a wallet one click from deletion.
- Popup window closed without answering → the request is rejected with - Popup window closed without answering → the request is rejected with
EIP-1193 code 4001 EIP-1193 code 4001
#### NetworkApproval (`approve-network`)
- **When**: A connected website asks to switch the network with
`wallet_switchEthereumChain`, naming a supported network other than the active
one. Only the user switches the network: until the user approves the request
here, it changes nothing — not the network, the RPC and Blockscout endpoints,
the balances or the cached token data — and no page is sent `chainChanged`.
Opened the same way as TxApproval, in a separate popup window. Only one exists
per site at a time: a further switch request from a site whose switch request
is still unanswered is refused with EIP-1193 code `-32002` and opens no
window. A request naming the network already active is answered at once and
opens nothing; one naming an unsupported chain is refused with code `4902`,
and one from a site that is not connected with code `4100`.
`wallet_addEthereumChain` never switches the network.
- **Elements**:
- "Network Switch Request" heading
- Phishing warning banner (shown when the hostname is on the phishing
blocklist)
- Site origin (bold, scheme and port included) + "wants to switch the
wallet's network."
- Current network: its name
- Requested network: its name
- A line saying that switching changes the network for the whole wallet and
for every site
- "Switch" / "Reject" buttons
- **Transitions**:
- "Switch" → closes popup; the background switches the network as
**Settings** does, restoring the RPC and Blockscout endpoints last used on
that network (or that network's defaults if it has none), sends
`chainChanged` to every open tab, and answers the site with success
- "Reject" → closes popup; the site is answered with EIP-1193 code 4001 and
nothing changes
- Popup window closed without answering → the same as "Reject"
#### StateRecovery (`state-recovery`) #### StateRecovery (`state-recovery`)
- **When**: the stored profile fails `assertStateUsable()`. At open, that is - **When**: the stored profile fails `assertStateUsable()`. At open, that is
@@ -2501,8 +2446,6 @@ logged.
- Sign transactions requested by connected sites (`eth_sendTransaction`) - Sign transactions requested by connected sites (`eth_sendTransaction`)
- Sign messages (`personal_sign`, `eth_sign`) - Sign messages (`personal_sign`, `eth_sign`)
- Sign typed data (`eth_signTypedData_v4`, `eth_signTypedData`) - Sign typed data (`eth_signTypedData_v4`, `eth_signTypedData`)
- Switch network at a connected site's request, once the user approves it
(`wallet_switchEthereumChain`)
- Human-readable transaction decoding (ERC-20, Uniswap Universal Router) - Human-readable transaction decoding (ERC-20, Uniswap Universal Router)
- ETH/USD and token/USD price display - ETH/USD and token/USD price display
- Configurable RPC endpoint and Blockscout API - Configurable RPC endpoint and Blockscout API
@@ -2695,7 +2638,7 @@ Currently supported:
### Non-Goals for 1.0 ### Non-Goals for 1.0
- Chains other than Ethereum mainnet and the Sepolia testnet - Multi-chain support (Ethereum mainnet only)
- Hardware wallet support - Hardware wallet support
## TODO ## TODO
@@ -2729,10 +2672,7 @@ Currently supported:
## Policies ## Policies
- We don't mention "the other wallet" by name in code or documentation. We're - We don't mention "the other wallet" by name in code or documentation. We're
our own thing. Written exception: the injected provider in our own thing.
`src/content/inpage.js` sets the flag named after the other wallet to `true`.
It is an interface-compatibility flag many dApps check, and without it the
wallet stops working on their sites.
- The README is the complete authoritative technical documentation. It's ok if - The README is the complete authoritative technical documentation. It's ok if
it gets big. it gets big.
+1 -4
View File
@@ -118,7 +118,4 @@ contradicts either, the originals govern.
- [ ] "Address" not "account" or "derived key" - [ ] "Address" not "account" or "derived key"
- [ ] "Password" not "encryption key" or "vault passphrase" - [ ] "Password" not "encryption key" or "vault passphrase"
- [ ] Error messages are full sentences - [ ] Error messages are full sentences
- [ ] No competitor mentioned by name in code or documentation. Written - [ ] No competitor mentioned by name in code or documentation
exception: the injected provider in `src/content/inpage.js` sets the flag
named after the other wallet to `true`, an interface-compatibility flag
many dApps check (README.md, Policies)
+14 -101
View File
@@ -23,118 +23,28 @@
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. The
milestone is in flight on `next`; its `next` -> `main` PR is milestone is in flight on `next`; its `next` -> `main` PR is
[#388](https://git.eeqj.de/sneak/AutistMask/pulls/388). `make build` produces [#190](https://git.eeqj.de/sneak/AutistMask/pulls/190). `make check` verified
`dist/chrome/` and `dist/firefox/` with `DEBUG` compiled off, and checks them green on `next` at `e9fa8be` on 2026-08-10, and `make build` produces
against the build's own receipt to hold exactly the regular files and symlinks `dist/chrome/` and `dist/firefox/`, verified against the build's own receipt to
that build emitted. hold exactly the regular files and symlinks that build emitted, with `DEBUG`
compiled off.
The backlog lives on the The backlog lives on the
[Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is [Gitea tracker](https://git.eeqj.de/sneak/AutistMask/issues), which is
authoritative; this file does not duplicate it. Full policy file set present. authoritative; this file does not duplicate it. Full policy file set present.
Real-browser end-to-end suites (`make test-e2e` for Chrome, Real-browser end-to-end suites (`make test-e2e` for Chrome,
`make test-e2e-firefox` for Firefox) sit alongside `make check`, which runs the `make test-e2e-firefox` for Firefox) sit alongside `make check`, which now does
tests, static analysis and the formatting check, and `.gitea/workflows/e2e.yml` static analysis as well as formatting, and `.gitea/workflows/e2e.yml` runs both
runs both of them on every push. of them on every push.
# Next Step # Next Step
Cut 1.0.0 once the Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
[1.0.0 milestone](https://git.eeqj.de/sneak/AutistMask/milestone/6) is empty, input validation) before any 1.0rc tag. Individual filed issues are parts of it,
then continue tagging as milestones land. but the review is broader than any of them.
# Completed Steps # Completed Steps
- 2026-10-08: The browser suites no longer read a screen before the page has
shown it ([#502](https://git.eeqj.de/sneak/AutistMask/issues/502)). Their wait
for a screen used to pass as soon as the element laid out, which every view
does until the page's stylesheet has applied, so an approval test could read
the prompt's fields before the page's script had filled them. `visible()` in
`tests/e2e/harness.js` and `waitVisible()` in `tests/e2e/firefox/driver.js`
now also wait for the page to finish loading and for neither the element nor
anything around it to carry the `hidden` class that `showView()` puts on every
view but the current one. No caller changed.
- 2026-10-08: Switching the network in Settings now tells open pages
([#500](https://git.eeqj.de/sneak/AutistMask/issues/500)). Once the switch is
saved, Settings asks the background to send `chainChanged` with the new chain
id to every open tab, through the same function an approved site request uses.
Choosing the network already active changes nothing and sends nothing. Only
the extension's own pages can ask for this. `tests/chainSwitchGate.test.js`
drives the real Settings view against the background, and the Chrome suite
checks that the test page hears both switches.
- 2026-10-07: A site can no longer switch the wallet's network by itself
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)). A connected site's
`wallet_switchEthereumChain` request for the other supported network opens a
prompt in its own window, through the same approval machinery as the
transaction and signature prompts, naming the site, the current network and
the requested one. The network, its endpoints, the balances and the caches
change, and `chainChanged` is sent, only when the user approves it; rejecting
or closing the prompt answers 4001. One such prompt per site at a time. The
approval window no longer shows the connection prompt while it waits for the
background to describe the approval, because that prompt's "Allow" answers on
the same port as the new one; `tests/approvalWindow.test.js` checks that it
shows no screen until then. `tests/chainSwitchGate.test.js` and both browser
suites drive the prompt.
- 2026-10-07: Two contradictions between the documents and the code are resolved
as ruled on [#165](https://git.eeqj.de/sneak/AutistMask/issues/165). The
README's 1.0 non-goal now puts Ethereum mainnet and the Sepolia testnet in
scope and other chains out of it. The injected provider's flag named after the
other wallet stays, as an interface-compatibility flag many dApps check, and
is written down as an exception to the rule against naming competitors in the
README's Policies section, in `RULES.md` and in a comment beside it in
`src/content/inpage.js`. `script/check-censored` already allows that flag only
in that file and its built copies, so it is unchanged.
- 2026-10-07: Two holes in what `tests/persistedFieldContract.test.js` checks
are closed ([#379](https://git.eeqj.de/sneak/AutistMask/issues/379)). The
check that every swept field is driven both truthy and falsy counts only
`hostile` and `falsy` values, which the sweep drives onto every restorable
view, and no longer a `hostileRestore` value, which reaches only the views its
entry names; the stale index 5 moves into `hostile` for `selectedWallet` and
`selectedAddress`, as the one value of either still truthy after the floor.
Each `hostileRestore` entry declares whether its boot lands on its view or
falls back to Home, and is held to it. The limits that remain, fields that
share a slot on one boot and anything no stored record reaches by itself, are
restated as built in the file's header and the README, which now also say
which boots are held to where the popup lands and that a healthy profile is
booted onto every restorable view.
- 2026-10-07: Every password error in the popup is shown the same way
([#493](https://git.eeqj.de/sneak/AutistMask/issues/493)): with `showError()`
and `hideError()` in a fixed-height error line below the password field, as
the send confirmation and approval screens already did. The add wallet screen
showed a missing, short or mismatched password in the flash line, and the
private key export, recovery phrase and delete wallet screens each had a line
of their own above the field. On the add wallet screen the line sits beside
the Import button, so the button stays where it was at 360x600. Each line
clears when the screen is shown again and when the password is tried again.
The add wallet screen's other messages, such as an invalid recovery phrase, a
duplicate wallet and the address scan, stay in the flash line.
`tests/passwordErrorLines.test.js` drives all four screens in the popup.
- 2026-10-07: Pre-1.0 security review of the extension
([#383](https://git.eeqj.de/sneak/AutistMask/issues/383)), reading the tree at
`99292b9` for key handling, the DEBUG mode policy, and what the background
accepts from pages, the configured RPC endpoint and the explorer, with what
the approval screens show from it; the site permission model and storage were
read as well. Its summary on that issue lists ten findings, each filed as its
own issue, and all ten are fixed on `next`; one,
[#399](https://git.eeqj.de/sneak/AutistMask/issues/399), put funds at risk.
Three decisions it raised are still open with the owner: the Argon2id cost for
the vault key ([#401](https://git.eeqj.de/sneak/AutistMask/issues/401)), a
connected site switching the network with no prompt
([#408](https://git.eeqj.de/sneak/AutistMask/issues/408)), and `eth_sign`
signing as a personal message
([#409](https://git.eeqj.de/sneak/AutistMask/issues/409)). Not covered: the
end-to-end suites were not run, the bundled phishing blocklist and token list
were not checked entry by entry, `ethers` and `libsodium-wrappers-sumo` were
taken as audited, and nothing was tried against a real network with real funds
([#385](https://git.eeqj.de/sneak/AutistMask/issues/385)). The planned
independent second check of each finding did not run; the findings rest on the
reviewer's own reading of the code.
- 2026-10-07: Stale branches pruned from `origin` - 2026-10-07: Stale branches pruned from `origin`
([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue ([#167](https://git.eeqj.de/sneak/AutistMask/issues/167)). The issue
classifies each branch it lists, with the evidence. The eighteen still on classifies each branch it lists, with the evidence. The eighteen still on
@@ -1977,3 +1887,6 @@ then continue tagging as milestones land.
Only work that has no issue of its own belongs here; everything else is on the Only work that has no issue of its own belongs here; everything else is on the
tracker. tracker.
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
land.
+19 -80
View File
@@ -137,12 +137,11 @@ function releaseTxApprovalSlotFor(approvalId) {
} }
} }
// One site-connection approval, one sign approval and one network-switch // One site-connection approval and one sign approval per site at a time: a
// approval per site at a time: a page that asks again before the user has // page that asks again before the user has answered is refused with the code
// answered is refused with the code above instead of opening another window, // above instead of opening another window, so it cannot bury the user in
// so it cannot bury the user in prompts. The pending approval itself holds the // prompts. The pending approval itself holds the place, so a caller must test
// place, so a caller must test this and raise its approval with nothing awaited // this and raise its approval with nothing awaited in between.
// in between.
function findPendingApproval(origin, type) { function findPendingApproval(origin, type) {
return Object.values(pendingApprovals).find( return Object.values(pendingApprovals).find(
(approval) => approval.origin === origin && approval.type === type, (approval) => approval.origin === origin && approval.type === type,
@@ -349,9 +348,8 @@ function settleApproval(id, result, options) {
// What a pending approval resolves to when it is given up on rather than // What a pending approval resolves to when it is given up on rather than
// answered: the window was closed, or could not be opened at all. A tx or sign // answered: the window was closed, or could not be opened at all. A tx or sign
// approval answers the requesting page in EIP-1193 shape; a site-connection or // approval answers the requesting page in EIP-1193 shape; a site-connection
// network-switch approval answers its handler in the shape the popup's // approval answers the connection handler in its own.
// decision has, as a refusal.
function abandonedResult(approval, code, message) { function abandonedResult(approval, code, message) {
if (approval.type === "tx" || approval.type === "sign") { if (approval.type === "tx" || approval.type === "sign") {
return { error: { code, message } }; return { error: { code, message } };
@@ -590,26 +588,6 @@ function requestSignApproval(origin, signParams, approvedFrom) {
}); });
} }
// Open a network-switch approval popup and return a promise that resolves with
// { approved }. Opened in a window, as tx and sign approvals are, because a
// site's request is not a user gesture. The popup answers on the approval port,
// as a site-connection approval does.
function requestNetworkApproval(origin, currentNetworkId, requestedNetworkId) {
return new Promise((resolve) => {
const id = crypto.randomUUID();
pendingApprovals[id] = {
id,
origin,
currentNetworkId,
requestedNetworkId,
resolve,
type: "network",
};
openApprovalWindow(id);
});
}
// Anything only the extension's own pages may say. A content script speaks // Anything only the extension's own pages may say. A content script speaks
// with the page's URL, so this is what separates the popup from the site the // with the page's URL, so this is what separates the popup from the site the
// popup is being asked about. // popup is being asked about.
@@ -619,8 +597,8 @@ function isExtensionSender(sender) {
} }
// The approval popup's port: it carries the user's decision on a // The approval popup's port: it carries the user's decision on a
// site-connection or network-switch approval, and its disconnect is how that // site-connection approval, and its disconnect is how that approval learns the
// approval learns the popup closed without one. // popup closed without one.
// //
// The decision travels this port rather than a one-off runtime.sendMessage() // The decision travels this port rather than a one-off runtime.sendMessage()
// for exactly one reason: the port is also what the popup's window.close() // for exactly one reason: the port is also what the popup's window.close()
@@ -828,10 +806,6 @@ async function handleRpc(method, params, origin) {
// tab is served from, so a page the user never connected to must // tab is served from, so a page the user never connected to must
// not be able to do it. Ungated, any page could clear the // not be able to do it. Ungated, any page could clear the
// [TESTNET] banner under a user who believed they were on Sepolia. // [TESTNET] banner under a user who believed they were on Sepolia.
//
// A connected site does not switch it either: only the user does,
// by approving the request on the prompt below
// (https://git.eeqj.de/sneak/AutistMask/issues/408).
const s = await getState(); const s = await getState();
const activeAddress = activeAddressOf(s); const activeAddress = activeAddressOf(s);
const allowed = s.allowedSites[activeAddress] || []; const allowed = s.allowedSites[activeAddress] || [];
@@ -853,27 +827,6 @@ async function handleRpc(method, params, origin) {
} }
if (SUPPORTED_CHAIN_IDS.has(chainId)) { if (SUPPORTED_CHAIN_IDS.has(chainId)) {
const target = networkByChainId(chainId); const target = networkByChainId(chainId);
if (findPendingApproval(origin, "network")) {
return {
error: {
code: APPROVAL_PENDING_CODE,
message: APPROVAL_PENDING_MESSAGE,
},
};
}
const decision = await requestNetworkApproval(
origin,
s.networkId,
target.id,
);
if (!decision.approved) {
return {
error: {
code: APPROVAL_REJECTED_CODE,
message: APPROVAL_REJECTED_MESSAGE,
},
};
}
// Read-modify-write against storage. The old path went through // Read-modify-write against storage. The old path went through
// onChainSwitch(), which mutates the singleton and then persists // onChainSwitch(), which mutates the singleton and then persists
// every field of it — on an unloaded worker that wrote empty // every field of it — on an unloaded worker that wrote empty
@@ -1392,21 +1345,20 @@ startBackgroundJobs();
// which then fails retryably settles instead of waiting in a window that no // which then fails retryably settles instead of waiting in a window that no
// longer exists. // longer exists.
// //
// A site-connection or network-switch approval whose popup connected its port // A site-connection approval whose popup connected its port is not decided
// is not decided here. That popup approves and closes in the same breath, and // here. That popup approves and closes in the same breath, and this event
// this event races the decision on a channel of its own — the same race the // races the decision on a channel of its own — the same race the port exists
// port exists to end. Its port disconnect says the same thing this event does, // to end. Its port disconnect says the same thing this event does, in an order
// in an order that is defined, so the disconnect is left to say it. The window // that is defined, so the disconnect is left to say it. The window closing
// closing before any port connected is the one case with nothing else to speak // before any port connected is the one case with nothing else to speak for it,
// for it, and is rejected here so the dApp is not left waiting on a window that // and is rejected here so the dApp is not left waiting on a window that is
// is gone. // gone.
if (windowsNs && windowsNs.onRemoved) { if (windowsNs && windowsNs.onRemoved) {
windowsNs.onRemoved.addListener((windowId) => { windowsNs.onRemoved.addListener((windowId) => {
for (const [id, approval] of Object.entries(pendingApprovals)) { for (const [id, approval] of Object.entries(pendingApprovals)) {
if (approval.windowId !== windowId) continue; if (approval.windowId !== windowId) continue;
const decidedOnPort = const isSite = approval.type !== "tx" && approval.type !== "sign";
approval.type !== "tx" && approval.type !== "sign"; if (isSite && approval.portConnected) continue;
if (decidedOnPort && approval.portConnected) continue;
const rejection = abandonedResult( const rejection = abandonedResult(
approval, approval,
APPROVAL_REJECTED_CODE, APPROVAL_REJECTED_CODE,
@@ -1471,7 +1423,6 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
"AUTISTMASK_ADDRESSES_REMOVED", "AUTISTMASK_ADDRESSES_REMOVED",
"AUTISTMASK_GET_CONNECTED_SITES", "AUTISTMASK_GET_CONNECTED_SITES",
"AUTISTMASK_REMOVE_SITE", "AUTISTMASK_REMOVE_SITE",
"AUTISTMASK_NETWORK_CHANGED",
]; ];
if (POPUP_ONLY_TYPES.includes(msg.type) && !isExtensionSender(sender)) { if (POPUP_ONLY_TYPES.includes(msg.type) && !isExtensionSender(sender)) {
sendResponse({ error: "Unauthorized sender" }); sendResponse({ error: "Unauthorized sender" });
@@ -1495,11 +1446,6 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
resp.signParams = approval.signParams; resp.signParams = approval.signParams;
resp.approvedFrom = approval.approvedFrom; resp.approvedFrom = approval.approvedFrom;
} }
if (approval.type === "network") {
resp.type = "network";
resp.currentNetworkId = approval.currentNetworkId;
resp.requestedNetworkId = approval.requestedNetworkId;
}
// Flag if the requesting domain is on the phishing blocklist. // Flag if the requesting domain is on the phishing blocklist.
resp.isPhishingDomain = isPhishingDomain( resp.isPhishingDomain = isPhishingDomain(
extractHostname(approval.origin), extractHostname(approval.origin),
@@ -1855,13 +1801,6 @@ runtime.onMessage.addListener((msg, sender, sendResponse) => {
broadcastSiteRemoved(msg.origin); broadcastSiteRemoved(msg.origin);
return false; return false;
} }
// Settings switched the network and has saved it. Open tabs are told the
// new chain id the same way as after a site's approved switch request.
if (msg.type === "AUTISTMASK_NETWORK_CHANGED") {
broadcastChainChanged(msg.chainId);
return false;
}
}); });
module.exports = { PROXY_METHODS }; module.exports = { PROXY_METHODS };
+1 -4
View File
@@ -99,10 +99,7 @@
const provider = { const provider = {
isAutistMask: true, isAutistMask: true,
// An interface-compatibility flag many dApps check. Kept as a written isMetaMask: true, // compatibility — many dApps check this
// exception to the rule that no competitor is named in code: see
// Policies in README.md, and RULES.md.
isMetaMask: true,
chainId: currentChainId, chainId: currentChainId,
networkVersion: currentNetworkVersion, networkVersion: currentNetworkVersion,
selectedAddress: null, selectedAddress: null,
+14 -72
View File
@@ -207,22 +207,12 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg" class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
/> />
</div> </div>
<!-- The error line sits beside Import, not above it: at
360x600 the button already starts near the bottom of
the popup, and a line of its own would push it below
the fold. The longest error fits on one line here. -->
<div class="flex items-center gap-2">
<button <button
id="btn-add-wallet-confirm" id="btn-add-wallet-confirm"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer" class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
> >
Import Import
</button> </button>
<div
id="add-wallet-password-error"
class="text-xs min-h-[1.25rem] invisible"
></div>
</div>
</div> </div>
<!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ --> <!-- ============ MAIN VIEW: ALL WALLETS & ADDRESSES ============ -->
@@ -406,6 +396,10 @@
Warning: anyone with this private key can access and Warning: anyone with this private key can access and
transfer all funds from this address. Never share it. transfer all funds from this address. Never share it.
</p> </p>
<div
id="export-privkey-flash"
class="text-xs mb-2 min-h-[1.25rem] invisible"
></div>
<div id="export-privkey-password-section" class="mb-2"> <div id="export-privkey-password-section" class="mb-2">
<label class="block mb-1">Password</label> <label class="block mb-1">Password</label>
<input <input
@@ -414,13 +408,9 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg" class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
placeholder="Enter your password to continue" placeholder="Enter your password to continue"
/> />
<div
id="export-privkey-password-error"
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
></div>
<button <button
id="btn-export-privkey-confirm" id="btn-export-privkey-confirm"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer" class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
> >
Reveal Reveal
</button> </button>
@@ -1126,6 +1116,10 @@
<strong id="delete-wallet-name"></strong> is permanent. Any <strong id="delete-wallet-name"></strong> is permanent. Any
funds will be unrecoverable without your recovery phrase. funds will be unrecoverable without your recovery phrase.
</p> </p>
<div
id="delete-wallet-flash"
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
></div>
<div class="mb-2"> <div class="mb-2">
<label class="block mb-1">Password</label> <label class="block mb-1">Password</label>
<input <input
@@ -1135,10 +1129,6 @@
placeholder="Enter your password to confirm" placeholder="Enter your password to confirm"
/> />
</div> </div>
<div
id="delete-wallet-password-error"
class="text-xs mb-2 min-h-[1.25rem] invisible"
></div>
<button <button
id="btn-delete-wallet-confirm" id="btn-delete-wallet-confirm"
class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer" class="border border-border text-red-500 px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
@@ -1283,6 +1273,10 @@
this wallet, from any device, without your password. Never this wallet, from any device, without your password. Never
type them into a website and never show them to anyone. type them into a website and never show them to anyone.
</div> </div>
<div
id="show-phrase-flash"
class="text-xs text-red-500 mb-2 min-h-[1.25rem] invisible"
></div>
<div id="show-phrase-password-section" class="mb-2"> <div id="show-phrase-password-section" class="mb-2">
<label class="block mb-1">Password</label> <label class="block mb-1">Password</label>
<input <input
@@ -1291,13 +1285,9 @@
class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg" class="border border-border p-1 w-full font-mono text-sm bg-bg text-fg"
placeholder="Enter your password to continue" placeholder="Enter your password to continue"
/> />
<div
id="show-phrase-password-error"
class="text-xs mt-2 mb-2 min-h-[1.25rem] invisible"
></div>
<button <button
id="btn-show-phrase-reveal" id="btn-show-phrase-reveal"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer" class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer mt-2"
> >
Reveal Reveal
</button> </button>
@@ -1741,54 +1731,6 @@
</div> </div>
</div> </div>
<!-- ============ NETWORK SWITCH APPROVAL ============ -->
<div id="view-approve-network" class="view hidden">
<h2 class="font-bold mb-2">Network Switch Request</h2>
<div
id="approve-network-phishing-warning"
class="mb-3 p-2 text-xs font-bold hidden bg-red-100 text-red-800 border-2 border-red-600 rounded-md"
>
⚠️ PHISHING WARNING: This site is on a known phishing
blocklist. Proceed with extreme caution.
</div>
<p class="mb-2">
<span id="approve-network-origin" class="font-bold"></span>
wants to switch the wallet's network.
</p>
<div class="mb-3">
<div class="text-xs text-muted mb-1">Current network</div>
<div
id="approve-network-current"
class="text-xs font-bold"
></div>
</div>
<div class="mb-3">
<div class="text-xs text-muted mb-1">Requested network</div>
<div
id="approve-network-requested"
class="text-xs font-bold"
></div>
</div>
<p class="mb-3 text-xs">
Switching changes the network for the whole wallet and for
every site, not only for this one.
</p>
<div class="flex justify-between">
<button
id="btn-approve-network"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
>
Switch
</button>
<button
id="btn-reject-network"
class="border border-border px-2 py-1 hover:bg-fg hover:text-bg cursor-pointer"
>
Reject
</button>
</div>
</div>
<!-- ============ STATE RECOVERY ============ --> <!-- ============ STATE RECOVERY ============ -->
<!-- <!--
Shown when the stored profile cannot be read at all. Every Shown when the stored profile cannot be read at all. Every
+2 -2
View File
@@ -238,9 +238,9 @@ async function init() {
// rejection rather than an uncaught error — measured as still failing // rejection rather than an uncaught error — measured as still failing
// the run on both harnesses (Playwright `pageerror`, and the Firefox // the run on both harnesses (Playwright `pageerror`, and the Firefox
// driver's console-service drain), so nothing is lost by leaving it // driver's console-service drain), so nothing is lost by leaving it
// on that path. show() puts the approval's own screen up once the // on that path.
// background has described it.
approval.show(approvalId); approval.show(approvalId);
showView("approve-site");
return; return;
} }
+4 -12
View File
@@ -2,8 +2,6 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
goBack, goBack,
clearViewStack, clearViewStack,
onViewLeave, onViewLeave,
@@ -100,7 +98,6 @@ function clear() {
$("add-wallet-password").value = ""; $("add-wallet-password").value = "";
$("add-wallet-password-confirm").value = ""; $("add-wallet-password-confirm").value = "";
$("add-wallet-phrase-warning").style.visibility = "hidden"; $("add-wallet-phrase-warning").style.visibility = "hidden";
hideError("add-wallet-password-error");
} }
// Each wallet has its own password (its own encryptedSecret), so adding a // Each wallet has its own password (its own encryptedSecret), so adding a
@@ -128,18 +125,15 @@ function validatePassword() {
const pw = $("add-wallet-password").value; const pw = $("add-wallet-password").value;
const pw2 = $("add-wallet-password-confirm").value; const pw2 = $("add-wallet-password-confirm").value;
if (!pw) { if (!pw) {
showError("add-wallet-password-error", "Please choose a password."); showFlash("Please choose a password.");
return null; return null;
} }
if (pw.length < 12) { if (pw.length < 12) {
showError( showFlash("Password must be at least 12 characters.");
"add-wallet-password-error",
"Password must be at least 12 characters.",
);
return null; return null;
} }
if (pw !== pw2) { if (pw !== pw2) {
showError("add-wallet-password-error", "Passwords do not match."); showFlash("Passwords do not match.");
return null; return null;
} }
return pw; return pw;
@@ -348,10 +342,8 @@ function init(ctx) {
$("add-wallet-phrase-warning").style.visibility = "visible"; $("add-wallet-phrase-warning").style.visibility = "visible";
}); });
// Import / confirm. Each press starts with no password error on screen: // Import / confirm
// validatePassword() puts it back if the password is still wrong.
$("btn-add-wallet-confirm").addEventListener("click", async () => { $("btn-add-wallet-confirm").addEventListener("click", async () => {
hideError("add-wallet-password-error");
if (currentMode === "mnemonic") { if (currentMode === "mnemonic") {
await importMnemonic(ctx); await importMnemonic(ctx);
} else if (currentMode === "privkey") { } else if (currentMode === "privkey") {
+14 -49
View File
@@ -14,7 +14,6 @@ const {
} = require("./helpers"); } = require("./helpers");
const { state, saveState } = require("../../shared/state"); const { state, saveState } = require("../../shared/state");
const { const {
networkById,
networkByChainId, networkByChainId,
nativeCurrencyByChainId, nativeCurrencyByChainId,
} = require("../../shared/networks"); } = require("../../shared/networks");
@@ -329,9 +328,9 @@ function showTxApproval(details) {
const ethUsd = ethPrice ? parseFloat(ethValueFormatted) * ethPrice : null; const ethUsd = ethPrice ? parseFloat(ethValueFormatted) * ethPrice : null;
const usdStr = formatUsd(ethUsd); const usdStr = formatUsd(ethUsd);
// In the native currency of the network the transaction is for, which the // In the native currency of the network the transaction is for, which the
// Network line names, not the active network's: the active network can // Network line names, not the active network's: a site can switch the
// change, in Settings or when the user approves a site's request, after // active network after this transaction is prepared and back before it is
// this transaction is prepared and change back before it is signed. // signed.
$("approve-tx-value").textContent = $("approve-tx-value").textContent =
ethValueFormatted + ethValueFormatted +
" " + " " +
@@ -753,29 +752,9 @@ function showSignApproval(details) {
); );
} }
function showNetworkApproval(details) {
showPhishingWarning(
"approve-network-phishing-warning",
details.isPhishingDomain,
);
$("approve-network-origin").textContent = details.origin;
$("approve-network-current").textContent = networkById(
details.currentNetworkId,
).name;
$("approve-network-requested").textContent = networkById(
details.requestedNetworkId,
).name;
showView("approve-network");
}
// Awaited by nobody: the popup entry point calls this and moves on. It // Awaited by nobody: the popup entry point calls this and moves on. It
// therefore has to absorb its own failure, and a background that cannot // therefore has to absorb its own failure, and a background that cannot
// describe the approval is the same outcome as an approval that is gone. // describe the approval is the same outcome as an approval that is gone.
//
// Nothing is on screen until the background has described the approval, so
// the screen shown is always the one for the approval this window answers:
// the connection prompt's "Allow" and the network switch prompt's "Switch"
// answer on the same port, and either would approve the other.
async function show(id) { async function show(id) {
approvalId = id; approvalId = id;
approvalPort = runtimeApi().connect({ name: "approval:" + id }); approvalPort = runtimeApi().connect({ name: "approval:" + id });
@@ -799,10 +778,6 @@ async function show(id) {
showSignApproval(details); showSignApproval(details);
return; return;
} }
if (details.type === "network") {
showNetworkApproval(details);
return;
}
// Site connection approval // Site connection approval
showPhishingWarning( showPhishingWarning(
"approve-site-phishing-warning", "approve-site-phishing-warning",
@@ -812,7 +787,6 @@ async function show(id) {
$("approve-address").innerHTML = approvalAddressHtml(state.activeAddress); $("approve-address").innerHTML = approvalAddressHtml(state.activeAddress);
attachCopyHandlers("view-approve-site"); attachCopyHandlers("view-approve-site");
$("approve-remember").checked = state.rememberSiteChoice; $("approve-remember").checked = state.rememberSiteChoice;
showView("approve-site");
} }
let approvalId = null; let approvalId = null;
@@ -892,21 +866,20 @@ function clearSignPassword() {
hideError("approve-sign-error"); hideError("approve-sign-error");
} }
// Answer a site-connection or network-switch approval and close. The decision // Answer a site-connection approval and close. The decision goes out on the
// goes out on the approval port — see approvalPort above for why — and carries // approval port — see approvalPort above for why — and carries no approval id,
// no approval id, because the port name already names the approval the // because the port name already names the approval the background will settle.
// background will settle. `remember` means something only for a site // The post is guarded because a throw must not cost the close: posting on a
// connection. The post is guarded because a throw must not cost the close: // port whose background worker has been torn down throws, and the approval it
// posting on a port whose background worker has been torn down throws, and the // would have settled died with that worker, so the only thing left to do is
// approval it would have settled died with that worker, so the only thing left // what the user asked for — go away.
// to do is what the user asked for — go away. function decideSite(approved) {
function decide(approved, remember) {
if (approvalPort) { if (approvalPort) {
try { try {
approvalPort.postMessage({ approvalPort.postMessage({
type: "AUTISTMASK_APPROVAL_DECISION", type: "AUTISTMASK_APPROVAL_DECISION",
approved, approved,
remember, remember: $("approve-remember").checked,
}); });
} catch { } catch {
// Nothing to report it to; the window closes either way. // Nothing to report it to; the window closes either way.
@@ -925,19 +898,11 @@ function init(_ctx) {
}); });
$("btn-approve").addEventListener("click", () => { $("btn-approve").addEventListener("click", () => {
decide(true, $("approve-remember").checked); decideSite(true);
}); });
$("btn-reject").addEventListener("click", () => { $("btn-reject").addEventListener("click", () => {
decide(false, $("approve-remember").checked); decideSite(false);
});
$("btn-approve-network").addEventListener("click", () => {
decide(true, false);
});
$("btn-reject-network").addEventListener("click", () => {
decide(false, false);
}); });
$("btn-approve-tx").addEventListener("click", async () => { $("btn-approve-tx").addEventListener("click", async () => {
+11 -16
View File
@@ -2,8 +2,6 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
goBack, goBack,
clearViewStack, clearViewStack,
onViewLeave, onViewLeave,
@@ -57,7 +55,8 @@ function confirmKey(name) {
function clear() { function clear() {
deleteWalletIndex = null; deleteWalletIndex = null;
$("delete-wallet-password").value = ""; $("delete-wallet-password").value = "";
hideError("delete-wallet-password-error"); $("delete-wallet-flash").textContent = "";
$("delete-wallet-flash").style.visibility = "hidden";
} }
// The lost-password screen holds no secret — a wallet name is not one — // The lost-password screen holds no secret — a wallet name is not one —
@@ -233,22 +232,19 @@ function init(_ctx) {
$("btn-delete-wallet-confirm").addEventListener("click", async () => { $("btn-delete-wallet-confirm").addEventListener("click", async () => {
const pw = $("delete-wallet-password").value; const pw = $("delete-wallet-password").value;
if (!pw) { if (!pw) {
showError( $("delete-wallet-flash").textContent =
"delete-wallet-password-error", "Please enter your password.";
"Please enter your password.", $("delete-wallet-flash").style.visibility = "visible";
);
return; return;
} }
if (deleteWalletIndex === null) { if (deleteWalletIndex === null) {
showError( $("delete-wallet-flash").textContent =
"delete-wallet-password-error", "No wallet selected for deletion.";
"No wallet selected for deletion.", $("delete-wallet-flash").style.visibility = "visible";
);
return; return;
} }
hideError("delete-wallet-password-error");
const btn = $("btn-delete-wallet-confirm"); const btn = $("btn-delete-wallet-confirm");
btn.disabled = true; btn.disabled = true;
btn.classList.add("text-muted"); btn.classList.add("text-muted");
@@ -260,10 +256,9 @@ function init(_ctx) {
try { try {
await decryptWithPassword(wallet.encryptedSecret, pw); await decryptWithPassword(wallet.encryptedSecret, pw);
} catch { } catch {
showError( $("delete-wallet-flash").textContent =
"delete-wallet-password-error", "That password is incorrect. Please try again.";
"That password is incorrect. Please try again.", $("delete-wallet-flash").style.visibility = "visible";
);
btn.disabled = false; btn.disabled = false;
btn.classList.remove("text-muted"); btn.classList.remove("text-muted");
return; return;
+12 -13
View File
@@ -20,8 +20,6 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
flashCopyFeedback, flashCopyFeedback,
goBack, goBack,
onViewLeave, onViewLeave,
@@ -58,6 +56,11 @@ function isCurrentReveal(generation) {
); );
} }
function fail(message) {
$("export-privkey-flash").textContent = message;
$("export-privkey-flash").style.visibility = "visible";
}
// Wipe every trace of the key and drop the address selection. Safe to call // Wipe every trace of the key and drop the address selection. Safe to call
// when nothing was ever revealed, and safe to call twice. // when nothing was ever revealed, and safe to call twice.
function clear() { function clear() {
@@ -68,7 +71,8 @@ function clear() {
$("export-privkey-password").value = ""; $("export-privkey-password").value = "";
$("export-privkey-result").classList.add("hidden"); $("export-privkey-result").classList.add("hidden");
$("export-privkey-password-section").classList.remove("hidden"); $("export-privkey-password-section").classList.remove("hidden");
hideError("export-privkey-password-error"); $("export-privkey-flash").textContent = "";
$("export-privkey-flash").style.visibility = "hidden";
} }
function show(walletIdx, addrIdx) { function show(walletIdx, addrIdx) {
@@ -108,19 +112,15 @@ function show(walletIdx, addrIdx) {
async function reveal() { async function reveal() {
const password = $("export-privkey-password").value; const password = $("export-privkey-password").value;
if (!password) { if (!password) {
showError( fail("Please enter your password.");
"export-privkey-password-error",
"Please enter your password.",
);
return; return;
} }
if (walletIndex === null) { if (walletIndex === null) {
showError("export-privkey-password-error", "No address is selected."); fail("No address is selected.");
return; return;
} }
const wallet = state.wallets[walletIndex]; const wallet = state.wallets[walletIndex];
hideError("export-privkey-password-error");
const btn = $("btn-export-privkey-confirm"); const btn = $("btn-export-privkey-confirm");
btn.disabled = true; btn.disabled = true;
btn.classList.add("text-muted"); btn.classList.add("text-muted");
@@ -140,12 +140,11 @@ async function reveal() {
$("export-privkey-password-section").classList.add("hidden"); $("export-privkey-password-section").classList.add("hidden");
$("export-privkey-value").textContent = signer.privateKey; $("export-privkey-value").textContent = signer.privateKey;
$("export-privkey-result").classList.remove("hidden"); $("export-privkey-result").classList.remove("hidden");
$("export-privkey-flash").textContent = "";
$("export-privkey-flash").style.visibility = "hidden";
} catch { } catch {
if (!isCurrentReveal(generation)) return; if (!isCurrentReveal(generation)) return;
showError( fail("That password is incorrect. Please try again.");
"export-privkey-password-error",
"That password is incorrect. Please try again.",
);
} finally { } finally {
btn.disabled = false; btn.disabled = false;
btn.classList.remove("text-muted"); btn.classList.remove("text-muted");
-1
View File
@@ -51,7 +51,6 @@ const VIEWS = [
"approve-site", "approve-site",
"approve-tx", "approve-tx",
"approve-sign", "approve-sign",
"approve-network",
"export-privkey", "export-privkey",
"show-phrase", "show-phrase",
// Shown by src/popup/views/stateRecovery.js when the stored profile // Shown by src/popup/views/stateRecovery.js when the stored profile
-4
View File
@@ -316,11 +316,7 @@ function init(ctx) {
const networkSelect = $("settings-network"); const networkSelect = $("settings-network");
networkSelect.addEventListener("change", async () => { networkSelect.addEventListener("change", async () => {
const newId = networkSelect.value; const newId = networkSelect.value;
if (newId === state.networkId) return;
const net = await onChainSwitch(newId); const net = await onChainSwitch(newId);
// Open pages are told by the background, as after a site's approved
// switch request.
notify({ type: "AUTISTMASK_NETWORK_CHANGED", chainId: net.chainId });
$("settings-rpc").value = state.rpcUrl; $("settings-rpc").value = state.rpcUrl;
$("settings-blockscout").value = state.blockscoutUrl; $("settings-blockscout").value = state.blockscoutUrl;
showFlash("Switched to " + net.name + "."); showFlash("Switched to " + net.name + ".");
+13 -14
View File
@@ -21,8 +21,6 @@ const {
$, $,
showView, showView,
showFlash, showFlash,
showError,
hideError,
flashCopyFeedback, flashCopyFeedback,
goBack, goBack,
onViewLeave, onViewLeave,
@@ -54,6 +52,11 @@ function isCurrentReveal(generation) {
); );
} }
function fail(message) {
$("show-phrase-flash").textContent = message;
$("show-phrase-flash").style.visibility = "visible";
}
// Wipe every trace of the phrase and drop the wallet selection. Safe to // Wipe every trace of the phrase and drop the wallet selection. Safe to
// call when nothing was ever revealed, and safe to call twice. // call when nothing was ever revealed, and safe to call twice.
function clear() { function clear() {
@@ -63,7 +66,8 @@ function clear() {
$("show-phrase-password").value = ""; $("show-phrase-password").value = "";
$("show-phrase-result").classList.add("hidden"); $("show-phrase-result").classList.add("hidden");
$("show-phrase-password-section").classList.remove("hidden"); $("show-phrase-password-section").classList.remove("hidden");
hideError("show-phrase-password-error"); $("show-phrase-flash").textContent = "";
$("show-phrase-flash").style.visibility = "hidden";
} }
function show(walletIdx) { function show(walletIdx) {
@@ -86,23 +90,19 @@ function show(walletIdx) {
async function reveal() { async function reveal() {
const password = $("show-phrase-password").value; const password = $("show-phrase-password").value;
if (!password) { if (!password) {
showError("show-phrase-password-error", "Please enter your password."); fail("Please enter your password.");
return; return;
} }
if (walletIndex === null) { if (walletIndex === null) {
showError("show-phrase-password-error", "No wallet is selected."); fail("No wallet is selected.");
return; return;
} }
const wallet = state.wallets[walletIndex]; const wallet = state.wallets[walletIndex];
if (!walletHasRecoveryPhrase(wallet)) { if (!walletHasRecoveryPhrase(wallet)) {
showError( fail("This wallet does not have a recovery phrase.");
"show-phrase-password-error",
"This wallet does not have a recovery phrase.",
);
return; return;
} }
hideError("show-phrase-password-error");
const btn = $("btn-show-phrase-reveal"); const btn = $("btn-show-phrase-reveal");
btn.disabled = true; btn.disabled = true;
btn.classList.add("text-muted"); btn.classList.add("text-muted");
@@ -120,14 +120,13 @@ async function reveal() {
$("show-phrase-password-section").classList.add("hidden"); $("show-phrase-password-section").classList.add("hidden");
$("show-phrase-value").textContent = phrase; $("show-phrase-value").textContent = phrase;
$("show-phrase-result").classList.remove("hidden"); $("show-phrase-result").classList.remove("hidden");
$("show-phrase-flash").textContent = "";
$("show-phrase-flash").style.visibility = "hidden";
} catch { } catch {
if (!isCurrentReveal(generation)) return; if (!isCurrentReveal(generation)) return;
// Deliberately not the caught error: the message is fixed so that // Deliberately not the caught error: the message is fixed so that
// nothing derived from the ciphertext or the attempt can surface. // nothing derived from the ciphertext or the attempt can surface.
showError( fail("That password is incorrect. Please try again.");
"show-phrase-password-error",
"That password is incorrect. Please try again.",
);
} finally { } finally {
btn.disabled = false; btn.disabled = false;
btn.classList.remove("text-muted"); btn.classList.remove("text-muted");
+2 -3
View File
@@ -84,9 +84,8 @@ function show(tx) {
contractAddress: tx.contractAddress || null, contractAddress: tx.contractAddress || null,
// The network the history entry was read from. The type line and // The network the history entry was read from. The type line and
// the fee are in its native currency, not the active network's: // the fee are in its native currency, not the active network's:
// the active network can change, in Settings or when the user // a site can switch the active network before a later popup
// approves a site's request, before a later popup shows this // shows this screen again.
// screen again.
chainId: tx.chainId, chainId: tx.chainId,
}, },
}; };
+2 -3
View File
@@ -89,9 +89,8 @@ function startWait(txInfo, txHash, broadcastTime, pollNow) {
// A native amount, here and on the success and error screens, is in the // A native amount, here and on the success and error screens, is in the
// native currency of txInfo.chainId, the network the transaction was sent // native currency of txInfo.chainId, the network the transaction was sent
// on, not the active network's: the active network can change, in // on, not the active network's: a site can switch the active network
// Settings or when the user approves a site's request, while this screen // while this screen is open or before a later popup resumes it.
// is open or before a later popup resumes it.
const symbol = const symbol =
txInfo.token === "ETH" txInfo.token === "ETH"
? nativeCurrencyByChainId(txInfo.chainId) ? nativeCurrencyByChainId(txInfo.chainId)
-2
View File
@@ -39,8 +39,6 @@ jest.doMock("../src/popup/views/helpers", () => ({
$: element, $: element,
showView: () => {}, showView: () => {},
showFlash: () => {}, showFlash: () => {},
showError: () => {},
hideError: () => {},
goBack: () => {}, goBack: () => {},
clearViewStack: () => {}, clearViewStack: () => {},
onViewLeave: () => {}, onViewLeave: () => {},
+2 -24
View File
@@ -1,5 +1,5 @@
// The connection, transaction, signature and network switch prompts name the // The connection, transaction and signature prompts name the site by its full
// site by its full origin, scheme and port included, not by its bare hostname // origin, scheme and port included, not by its bare hostname
// (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http, // (https://git.eeqj.de/sneak/AutistMask/issues/402). A page served over http,
// or on another port, of a host the user trusts over https must not raise a // or on another port, of a host the user trusts over https must not raise a
// prompt that reads as that trusted site. // prompt that reads as that trusted site.
@@ -104,7 +104,6 @@ beforeEach(() => {
test("the connection prompt shows the origin", async () => { test("the connection prompt shows the origin", async () => {
await openApproval({}); await openApproval({});
expect(node("approve-origin").textContent).toBe(ORIGIN); expect(node("approve-origin").textContent).toBe(ORIGIN);
expect(node("view-approve-site").classList.contains("hidden")).toBe(false);
}); });
test("the transaction prompt shows the origin", async () => { test("the transaction prompt shows the origin", async () => {
@@ -139,24 +138,3 @@ test("the signature prompt shows the origin", async () => {
}); });
expect(node("approve-sign-origin").textContent).toBe(ORIGIN); expect(node("approve-sign-origin").textContent).toBe(ORIGIN);
}); });
test("the network switch prompt shows the origin and both networks", async () => {
await openApproval({
type: "network",
currentNetworkId: "mainnet",
requestedNetworkId: "sepolia",
});
expect(node("approve-network-origin").textContent).toBe(ORIGIN);
expect(node("approve-network-current").textContent).toBe(
"Ethereum Mainnet",
);
expect(node("approve-network-requested").textContent).toBe(
"Sepolia Testnet",
);
// Its own screen, and not the connection prompt, whose "Allow" answers
// on the same port.
expect(node("view-approve-network").classList.contains("hidden")).toBe(
false,
);
expect(node("view-approve-site").classList.contains("hidden")).toBe(true);
});
-47
View File
@@ -1,47 +0,0 @@
// The approval window shows no screen until the background has described the
// approval it answers (https://git.eeqj.de/sneak/AutistMask/issues/408). The
// connection prompt's "Allow" and the network switch prompt's "Switch" answer
// on the same port, so a window that showed the connection prompt while it
// waited could approve a network switch.
//
// Booted through the real popup entry point, which is where the connection
// prompt used to be put up before the background had answered.
const {
bootPopup,
cleanupPopup,
settle,
unversionedValidProfile,
} = require("./support/popupBoot");
afterEach(cleanupPopup);
test("the approval window shows no screen until the background describes the approval", async () => {
// The background's answer, held until the test gives it.
let answer = null;
const env = await bootPopup(unversionedValidProfile(), {
search: "?approval=approval-1",
runtime: {
connect: () => ({ postMessage: () => {} }),
sendMessage: (msg, reply) => {
if (msg.type === "AUTISTMASK_GET_APPROVAL") answer = reply;
},
},
});
expect(answer).not.toBeNull();
// No screen at all, the connection prompt included.
expect(env.visibleViews()).toEqual([]);
answer({
type: "network",
origin: "https://dapp.example",
currentNetworkId: "mainnet",
requestedNetworkId: "sepolia",
isPhishingDomain: false,
});
await settle();
expect(env.visibleViews()).toEqual(["approve-network"]);
expect(env.pageErrors).toEqual([]);
});
+14 -14
View File
@@ -25,7 +25,6 @@
const { Wallet } = require("ethers"); const { Wallet } = require("ethers");
const { networkById } = require("../src/shared/networks"); const { networkById } = require("../src/shared/networks");
const { applyChainSwitchFields } = require("../src/shared/chainSwitchFields");
const { makeStorageStub } = require("./support/storageStub"); const { makeStorageStub } = require("./support/storageStub");
const SIGNER_KEY = const SIGNER_KEY =
@@ -241,8 +240,8 @@ describe("a chain switch under a transaction already committed to a chain", () =
// The artifact is verified against the chain read at the top of the // The artifact is verified against the chain read at the top of the
// attempt. Whatever endpoint it is then broadcast to has to be that same // attempt. Whatever endpoint it is then broadcast to has to be that same
// chain's — otherwise the wallet checks a transaction against Sepolia and // chain's — otherwise the wallet checks a transaction against Sepolia and
// sends it to a mainnet node. The user can switch the network in Settings // sends it to a mainnet node. A connected site can switch the chain at any
// at any moment, including this one. // moment, including this one.
test("the artifact is broadcast to the endpoint of the chain it was verified against", async () => { test("the artifact is broadcast to the endpoint of the chain it was verified against", async () => {
const bg = loadWorker("sepolia"); const bg = loadWorker("sepolia");
@@ -265,9 +264,9 @@ describe("a chain switch under a transaction already committed to a chain", () =
populated(Number(SEPOLIA.networkVersion)), populated(Number(SEPOLIA.networkVersion)),
); );
// The user switches the network in Settings while the attempt is // A connected site switches the chain while the attempt is running,
// running: the popup writes the switched record to storage in full // and the switch is committed to storage in full before the attempt
// before the attempt goes any further. // goes any further.
// //
// It is fired from inside the attempt's SECOND state read, because // It is fired from inside the attempt's SECOND state read, because
// that is where the window used to be: the chain id was captured at // that is where the window used to be: the chain id was captured at
@@ -278,18 +277,18 @@ describe("a chain switch under a transaction already committed to a chain", () =
// this to fire on, and the switch below runs after the attempt is // this to fire on, and the switch below runs after the attempt is
// done instead — which is the point. // done instead — which is the point.
let reads = 0; let reads = 0;
let switched = false; let switched = null;
const doSwitch = () => { const doSwitch = async () => {
const record = bg.persisted(); switched = bg.rpc("wallet_switchEthereumChain", [
applyChainSwitchFields(record, MAINNET.id); { chainId: MAINNET.chainId },
global.chrome.storage.write("autistmask", record); ]);
switched = true; await settle();
}; };
bg.setGetHook(async () => { bg.setGetHook(async () => {
reads++; reads++;
if (reads !== 2) return; if (reads !== 2) return;
bg.setGetHook(null); bg.setGetHook(null);
doSwitch(); await doSwitch();
}); });
const attempt = bg.send( const attempt = bg.send(
@@ -304,7 +303,8 @@ describe("a chain switch under a transaction already committed to a chain", () =
await settle(); await settle();
bg.setGetHook(null); bg.setGetHook(null);
if (!switched) doSwitch(); if (!switched) await doSwitch();
expect(switched.result()).toEqual({ result: null });
expect(bg.persisted().networkId).toBe("mainnet"); expect(bg.persisted().networkId).toBe("mainnet");
await settle(); await settle();
+38 -324
View File
@@ -1,24 +1,16 @@
// Who may move the active chain, and when. // Who may move the active chain.
// //
// wallet_switchEthereumChain used to be answered for any origin at all, with // wallet_switchEthereumChain used to be answered for any origin at all, with
// no connection check and no prompt, so a page the user had never connected // no connection check and no prompt, so a page the user had never connected
// to could clear the [TESTNET] banner under someone who believed they were // to could clear the [TESTNET] banner under someone who believed they were
// on Sepolia (https://git.eeqj.de/sneak/AutistMask/issues/308). Gated on the // on Sepolia (https://git.eeqj.de/sneak/AutistMask/issues/308). The refusal
// connection, a connected site could still move the wallet between mainnet and // is asserted as a refusal to ACT — the state unmoved and no chainChanged
// Sepolia without asking. Only the user switches the network: a connected // broadcast — because an error code alone would not distinguish a gate from
// site's request opens a prompt, and nothing changes unless the user approves // a switch that happened and then reported a failure.
// it there (https://git.eeqj.de/sneak/AutistMask/issues/408).
// //
// Every refusal is asserted as a refusal to ACT — the stored record unmoved // The endpoint half of that issue lives in tests/networkEndpoints.test.js,
// and no chainChanged broadcast — because an error code alone would not // which covers the popup's chain switch; this file covers the background's,
// distinguish a refusal from a switch that happened and then reported a // which goes through storage rather than the shared state singleton.
// failure.
//
// The endpoint half of #308 lives in tests/networkEndpoints.test.js, which
// covers the popup's chain switch; this file covers the background's, which
// goes through storage rather than the shared state singleton. The last block
// covers what the background tells open tabs when the user switches the
// network in Settings.
const { networkById } = require("../src/shared/networks"); const { networkById } = require("../src/shared/networks");
const { makeStorageStub } = require("./support/storageStub"); const { makeStorageStub } = require("./support/storageStub");
@@ -29,23 +21,18 @@ const ADDRESS = "0x66133E8ea0f5D1d612D2502a968757D1048c214a";
const CONNECTED_ORIGIN = "https://dapp.example"; const CONNECTED_ORIGIN = "https://dapp.example";
const STRANGER_ORIGIN = "https://stranger.example"; const STRANGER_ORIGIN = "https://stranger.example";
const EXT_URL = "chrome-extension://autistmask/";
const MAINNET = networkById("mainnet"); const MAINNET = networkById("mainnet");
const SEPOLIA = networkById("sepolia"); const SEPOLIA = networkById("sepolia");
// The user's own node, so a switch that happens is visible as the loss of it. // The user's own node, so a switch that happens is visible as the loss of it.
const CUSTOM_RPC = "http://127.0.0.1:8545"; const CUSTOM_RPC = "http://127.0.0.1:8545";
// A balance a switch would clear, so a switch that happens is visible here too.
function walletFixture() { function walletFixture() {
return [ return [
{ {
name: "Wallet 1", name: "Wallet 1",
type: "hd", type: "hd",
addresses: [ addresses: [{ address: ADDRESS, balance: "0", tokenBalances: [] }],
{ address: ADDRESS, balance: "1.5", tokenBalances: [] },
],
}, },
]; ];
} }
@@ -60,6 +47,10 @@ afterEach(() => {
delete global.chrome; delete global.chrome;
}); });
// ---------------------------------------------------------------------------
// The gate: which origins the background will switch the chain for.
// ---------------------------------------------------------------------------
// Load the background worker against stubbed browser APIs, with the real // Load the background worker against stubbed browser APIs, with the real
// chain-switch and persistence modules behind it, and return the handles to // chain-switch and persistence modules behind it, and return the handles to
// drive it. // drive it.
@@ -100,46 +91,30 @@ function loadBackground() {
const storage = makeStorageStub({ autistmask: persisted }); const storage = makeStorageStub({ autistmask: persisted });
let messageListener = null; let messageListener = null;
let connectListener = null;
let windowRemovedListener = null;
// The URL of every approval window the background opened. The approval id
// is in it, and that is how the popup learns which approval it answers.
const opened = [];
// Every message the background pushed at a content script. chainChanged // Every message the background pushed at a content script. chainChanged
// is what tells a page the wallet moved, so a switch is visible here as // is what tells a page the wallet moved, so an ungated switch is visible
// well as in the state. // here as well as in the state.
const toTabs = []; const toTabs = [];
global.chrome = { global.chrome = {
storage, storage,
runtime: { runtime: {
getURL: (path) => EXT_URL + path, getURL: (path) => "chrome-extension://autistmask/" + path,
onMessage: { onMessage: {
addListener: (fn) => { addListener: (fn) => {
messageListener = fn; messageListener = fn;
}, },
}, },
onConnect: { onConnect: { addListener: () => {} },
addListener: (fn) => {
connectListener = fn;
},
},
lastError: null, lastError: null,
}, },
windows: { windows: {
getLastFocused: (cb) => cb(null), getLastFocused: (cb) => cb(null),
create: (options, cb) => { create: (options, cb) => cb({ id: 1 }),
opened.push(options.url);
cb({ id: opened.length });
},
remove: (id, cb) => { remove: (id, cb) => {
if (cb) cb(); if (cb) cb();
}, },
onRemoved: { onRemoved: { addListener: () => {} },
addListener: (fn) => {
windowRemovedListener = fn;
},
},
}, },
tabs: { tabs: {
query: (queryInfo, cb) => cb([{ id: 1 }]), query: (queryInfo, cb) => cb([{ id: 1 }]),
@@ -153,8 +128,6 @@ function loadBackground() {
require("../src/background/index"); require("../src/background/index");
// A page's request. Its answer is read with result(), which is null for as
// long as the request is waiting on the user.
async function switchChain(chainId, origin) { async function switchChain(chainId, origin) {
let result = null; let result = null;
messageListener( messageListener(
@@ -169,155 +142,56 @@ function loadBackground() {
}, },
); );
await settle(); await settle();
return { result: () => result }; return result;
}
function promptId() {
return new URL(opened[opened.length - 1]).searchParams.get("approval");
}
// What the popup is told to show for the prompt.
function describePrompt() {
let reply = null;
messageListener(
{ type: "AUTISTMASK_GET_APPROVAL", id: promptId() },
{ url: EXT_URL + "src/popup/index.html" },
(r) => {
reply = r;
},
);
return reply;
}
// The user's answer, as the popup sends it: on the port named for the
// approval, from the extension's own page, and then the window closes.
async function answerPrompt(approved) {
const onMessage = [];
const onDisconnect = [];
const port = {
name: "approval:" + promptId(),
sender: { url: EXT_URL + "src/popup/index.html" },
onMessage: { addListener: (fn) => onMessage.push(fn) },
onDisconnect: { addListener: (fn) => onDisconnect.push(fn) },
};
connectListener(port);
for (const fn of onMessage) {
fn(
{
type: "AUTISTMASK_APPROVAL_DECISION",
approved,
remember: false,
},
port,
);
}
for (const fn of onDisconnect) fn(port);
await settle();
}
// The user closes the prompt window without answering it.
async function closePrompt() {
windowRemovedListener(opened.length);
await settle();
} }
return { return {
switchChain, switchChain,
describePrompt,
answerPrompt,
closePrompt,
opened,
// A message to the background from `sender`, and its answer.
send: (msg, sender) => {
let reply = null;
messageListener(msg, sender, (r) => {
reply = r;
});
return reply;
},
walletState: () => storage.read("autistmask"), walletState: () => storage.read("autistmask"),
chainChangedEvents: () => chainChangedEvents: () =>
toTabs.filter((m) => m.eventName === "chainChanged"), toTabs.filter((m) => m.eventName === "chainChanged"),
}; };
} }
const USER_REJECTED = { code: 4001, message: "User rejected the request." };
describe("wallet_switchEthereumChain is gated on the connection", () => { describe("wallet_switchEthereumChain is gated on the connection", () => {
test("an origin the wallet was never connected to is refused with 4100", async () => { test("an origin the wallet was never connected to is refused with 4100", async () => {
const bg = loadBackground(); const bg = loadBackground();
const before = bg.walletState();
const request = await bg.switchChain(SEPOLIA.chainId, STRANGER_ORIGIN); const result = await bg.switchChain(SEPOLIA.chainId, STRANGER_ORIGIN);
expect(request.result().error).toEqual({ expect(result.error).toEqual({ code: 4100, message: "Unauthorized" });
code: 4100, expect(result.result).toBeUndefined();
message: "Unauthorized",
});
expect(request.result().result).toBeUndefined();
// The refusal has to be a refusal to ACT, not just an error string: // The refusal has to be a refusal to ACT, not just an error string:
// the wallet is still on mainnet, still on the user's own node, and // the wallet is still on mainnet, still on the user's own node, and
// no page was told the chain moved. Nor was the user asked. // no page was told the chain moved.
expect(bg.walletState()).toEqual(before); expect(bg.walletState().networkId).toBe("mainnet");
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
expect(bg.chainChangedEvents()).toEqual([]); expect(bg.chainChangedEvents()).toEqual([]);
expect(bg.opened).toEqual([]);
}); });
test("an unconnected origin is refused even for the chain already active", async () => { test("an unconnected origin is refused even for the chain already active", async () => {
const bg = loadBackground(); const bg = loadBackground();
const request = await bg.switchChain(MAINNET.chainId, STRANGER_ORIGIN); const result = await bg.switchChain(MAINNET.chainId, STRANGER_ORIGIN);
expect(request.result().error).toEqual({ expect(result.error).toEqual({ code: 4100, message: "Unauthorized" });
code: 4100,
message: "Unauthorized",
});
}); });
test("an unconnected origin is refused before the unsupported-chain answer", async () => { test("an unconnected origin is refused before the unsupported-chain answer", async () => {
const bg = loadBackground(); const bg = loadBackground();
const request = await bg.switchChain("0x89", STRANGER_ORIGIN); const result = await bg.switchChain("0x89", STRANGER_ORIGIN);
expect(request.result().error.code).toBe(4100); expect(result.error.code).toBe(4100);
});
});
describe("only the user switches the network", () => {
test("a connected site's request changes nothing while the prompt is open", async () => {
const bg = loadBackground();
const before = bg.walletState();
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
// Waiting on the user, with one prompt on screen naming the site and
// both networks.
expect(request.result()).toBeNull();
expect(bg.opened).toHaveLength(1);
expect(bg.describePrompt()).toMatchObject({
origin: CONNECTED_ORIGIN,
type: "network",
currentNetworkId: "mainnet",
requestedNetworkId: "sepolia",
}); });
// The network, the endpoints and the balances are as they were, and test("a connected origin switches the chain", async () => {
// no page was told otherwise.
expect(bg.walletState()).toEqual(before);
expect(bg.chainChangedEvents()).toEqual([]);
});
test("approving the prompt switches the network", async () => {
const bg = loadBackground(); const bg = loadBackground();
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN); const result = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
await bg.answerPrompt(true);
expect(request.result()).toEqual({ result: null }); expect(result).toEqual({ result: null });
const after = bg.walletState(); expect(bg.walletState().networkId).toBe("sepolia");
expect(after.networkId).toBe("sepolia");
expect(after.rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
expect(after.wallets[0].addresses[0].balance).toBe("0");
expect(bg.chainChangedEvents()).toEqual([ expect(bg.chainChangedEvents()).toEqual([
{ {
type: "AUTISTMASK_EVENT", type: "AUTISTMASK_EVENT",
@@ -327,182 +201,22 @@ describe("only the user switches the network", () => {
]); ]);
}); });
test("rejecting the prompt changes nothing and answers 4001", async () => { test("a connected origin asking for an unsupported chain still gets 4902", async () => {
const bg = loadBackground();
const before = bg.walletState();
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
await bg.answerPrompt(false);
expect(request.result()).toEqual({ error: USER_REJECTED });
expect(bg.walletState()).toEqual(before);
expect(bg.chainChangedEvents()).toEqual([]);
});
test("closing the prompt without answering changes nothing and answers 4001", async () => {
const bg = loadBackground();
const before = bg.walletState();
const request = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
await bg.closePrompt();
expect(request.result()).toEqual({ error: USER_REJECTED });
expect(bg.walletState()).toEqual(before);
expect(bg.chainChangedEvents()).toEqual([]);
});
test("a request for the chain already active opens no prompt", async () => {
const bg = loadBackground();
const before = bg.walletState();
const request = await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
expect(request.result()).toEqual({ result: null });
expect(bg.opened).toEqual([]);
expect(bg.walletState()).toEqual(before);
expect(bg.chainChangedEvents()).toEqual([]);
});
test("a second request while the prompt is open is refused with -32002", async () => {
const bg = loadBackground(); const bg = loadBackground();
const first = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN); const result = await bg.switchChain("0x89", CONNECTED_ORIGIN);
const second = await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
expect(second.result().error.code).toBe(-32002); expect(result.error.code).toBe(4902);
expect(bg.opened).toHaveLength(1);
// The first prompt still decides.
await bg.answerPrompt(true);
expect(first.result()).toEqual({ result: null });
expect(bg.walletState().networkId).toBe("sepolia");
});
test("a request for an unsupported chain still gets 4902 and no prompt", async () => {
const bg = loadBackground();
const request = await bg.switchChain("0x89", CONNECTED_ORIGIN);
expect(request.result().error.code).toBe(4902);
expect(bg.opened).toEqual([]);
expect(bg.walletState().networkId).toBe("mainnet"); expect(bg.walletState().networkId).toBe("mainnet");
}); });
test("an approved switch keeps the user's endpoint", async () => { test("a switch by a connected origin keeps the user's endpoint", async () => {
const bg = loadBackground(); const bg = loadBackground();
await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN); await bg.switchChain(SEPOLIA.chainId, CONNECTED_ORIGIN);
await bg.answerPrompt(true);
expect(bg.walletState().rpcUrl).toBe(SEPOLIA.defaultRpcUrl); expect(bg.walletState().rpcUrl).toBe(SEPOLIA.defaultRpcUrl);
await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN); await bg.switchChain(MAINNET.chainId, CONNECTED_ORIGIN);
await bg.answerPrompt(true);
expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC); expect(bg.walletState().rpcUrl).toBe(CUSTOM_RPC);
}); });
}); });
// Switching the network in Settings tells open pages, as an approved site
// request does (https://git.eeqj.de/sneak/AutistMask/issues/500). These drive
// the real Settings view over the background's storage, with what it sends
// delivered to the background from the extension's own page.
describe("switching the network in Settings tells every open tab", () => {
const POPUP = { url: EXT_URL + "src/popup/index.html" };
// A stand-in for one DOM node: enough of an element for init() to set
// properties on it and hang listeners off it.
function fakeElement() {
return {
value: "",
checked: false,
textContent: "",
style: {},
dataset: {},
classList: { add() {}, remove() {} },
listeners: {},
addEventListener(event, handler) {
this.listeners[event] = handler;
},
querySelectorAll: () => [],
};
}
// Settings, opened the way the popup opens it. Returns its network
// selector.
async function openSettings(bg) {
const elements = {};
const element = (id) => (elements[id] ||= fakeElement());
jest.doMock("../src/popup/views/helpers", () => ({
$: element,
showView: () => {},
updateDebugBanner: () => {},
showFlash: () => {},
escapeHtml: (s) => s,
flashCopyFeedback: () => {},
goBack: () => {},
pushCurrentView: () => {},
onViewLeave: () => {},
VIEWS: [],
}));
global.chrome.runtime.sendMessage = (msg) => {
bg.send(msg, POPUP);
};
await require("../src/shared/state").loadState();
require("../src/popup/views/settings").init({
pageClosed: new AbortController().signal,
});
const select = element("settings-network");
select.value = "mainnet";
return select;
}
// The user picks `networkId` in the selector.
async function choose(select, networkId) {
select.value = networkId;
await select.listeners.change();
await settle();
}
afterEach(() => {
jest.dontMock("../src/popup/views/helpers");
});
test("switching to the other network sends chainChanged once, with its chain id", async () => {
const bg = loadBackground();
const select = await openSettings(bg);
await choose(select, "sepolia");
expect(bg.walletState().networkId).toBe("sepolia");
expect(bg.chainChangedEvents()).toEqual([
{
type: "AUTISTMASK_EVENT",
eventName: "chainChanged",
data: SEPOLIA.chainId,
},
]);
});
test("choosing the network already active changes nothing and sends nothing", async () => {
const bg = loadBackground();
const select = await openSettings(bg);
const before = bg.walletState();
await choose(select, "mainnet");
expect(bg.walletState()).toEqual(before);
expect(bg.chainChangedEvents()).toEqual([]);
});
test("a page cannot make the background send chainChanged", async () => {
const bg = loadBackground();
const reply = bg.send(
{ type: "AUTISTMASK_NETWORK_CHANGED", chainId: SEPOLIA.chainId },
{ url: CONNECTED_ORIGIN + "/" },
);
await settle();
expect(reply).toEqual({ error: "Unauthorized sender" });
expect(bg.chainChangedEvents()).toEqual([]);
});
});
+2 -44
View File
@@ -14,10 +14,6 @@
// itself: the handler has to do it. tests/chainSwitchGate.test.js mocks the // itself: the handler has to do it. tests/chainSwitchGate.test.js mocks the
// state module wholesale and tests/networkEndpoints.test.js always loads // state module wholesale and tests/networkEndpoints.test.js always loads
// first, so neither can see this. // first, so neither can see this.
//
// A site's switch happens only once the user approves it on a prompt
// (https://git.eeqj.de/sneak/AutistMask/issues/408), so every switch here is
// approved the way the popup approves one.
const { networkById } = require("../src/shared/networks"); const { networkById } = require("../src/shared/networks");
const { makeStorageStub } = require("./support/storageStub"); const { makeStorageStub } = require("./support/storageStub");
@@ -94,9 +90,6 @@ function loadColdWorker(networkId) {
const storage = makeStorageStub({ autistmask: storedProfile(networkId) }); const storage = makeStorageStub({ autistmask: storedProfile(networkId) });
let messageListener = null; let messageListener = null;
let connectListener = null;
// The URL of every approval window opened; the approval id is in it.
const opened = [];
const toTabs = []; const toTabs = [];
global.chrome = { global.chrome = {
@@ -108,19 +101,12 @@ function loadColdWorker(networkId) {
messageListener = fn; messageListener = fn;
}, },
}, },
onConnect: { onConnect: { addListener: () => {} },
addListener: (fn) => {
connectListener = fn;
},
},
lastError: null, lastError: null,
}, },
windows: { windows: {
getLastFocused: (cb) => cb(null), getLastFocused: (cb) => cb(null),
create: (options, cb) => { create: (options, cb) => cb({ id: 1 }),
opened.push(options.url);
cb({ id: opened.length });
},
remove: (id, cb) => { remove: (id, cb) => {
if (cb) cb(); if (cb) cb();
}, },
@@ -138,32 +124,6 @@ function loadColdWorker(networkId) {
require("../src/background/index"); require("../src/background/index");
// The user approves the prompt the request opened, as the popup does: a
// decision on the port named for the approval, from the extension's own
// page.
function approvePrompt() {
const id = new URL(opened[opened.length - 1]).searchParams.get(
"approval",
);
let onDecision = null;
const port = {
name: "approval:" + id,
sender: { url: "chrome-extension://autistmask/src/popup/" },
onMessage: {
addListener: (fn) => {
onDecision = fn;
},
},
onDisconnect: { addListener: () => {} },
};
connectListener(port);
onDecision(
{ type: "AUTISTMASK_APPROVAL_DECISION", approved: true },
port,
);
}
// A connected site asks for `chainId`, and the user approves it.
async function switchChain(chainId) { async function switchChain(chainId) {
let result = null; let result = null;
messageListener( messageListener(
@@ -178,8 +138,6 @@ function loadColdWorker(networkId) {
}, },
); );
await settle(); await settle();
approvePrompt();
await settle();
return result; return result;
} }
+1 -1
View File
@@ -253,7 +253,7 @@ describe("reaching the screen", () => {
const { decryptWithPassword } = require("../src/shared/vault"); const { decryptWithPassword } = require("../src/shared/vault");
decryptWithPassword.mockRejectedValue(new Error("nope")); decryptWithPassword.mockRejectedValue(new Error("nope"));
await click("btn-delete-wallet-confirm"); await click("btn-delete-wallet-confirm");
expect(node("delete-wallet-password-error").textContent).toBe( expect(node("delete-wallet-flash").textContent).toBe(
"That password is incorrect. Please try again.", "That password is incorrect. Please try again.",
); );
}); });
+2 -8
View File
@@ -279,18 +279,12 @@ class Driver {
// Shown means shown: in the popup a view is switched by toggling a // Shown means shown: in the popup a view is switched by toggling a
// "hidden" class, and an element that is present but collapsed is not // "hidden" class, and an element that is present but collapsed is not
// the thing a test means by visible. Until the page's stylesheet has // the thing a test means by visible.
// applied that class hides nothing and every view lays out, so the page
// must also have finished loading, which it does only after its
// stylesheet, and neither the element nor anything enclosing it may
// carry the class (https://git.eeqj.de/sneak/AutistMask/issues/502).
async waitVisible(selector, timeout = DEFAULT_WAIT_MS) { async waitVisible(selector, timeout = DEFAULT_WAIT_MS) {
return this.waitFor( return this.waitFor(
"selector " + selector + " to be visible", "selector " + selector + " to be visible",
`const el = document.querySelector(arguments[0]); `const el = document.querySelector(arguments[0]);
if (document.readyState !== "complete" || !el) return false; if (!el) return false;
if (el.closest(".hidden")) return false;
if (getComputedStyle(el).visibility !== "visible") return false;
const r = el.getBoundingClientRect(); const r = el.getBoundingClientRect();
return r.width > 0 && r.height > 0;`, return r.width > 0 && r.height > 0;`,
[selector], [selector],
-154
View File
@@ -63,7 +63,6 @@ const {
const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver"); const { ConsoleErrors, EXTENSION_ORIGIN, start, sleep } = require("./driver");
const { startDappServer } = require("./dapp"); const { startDappServer } = require("./dapp");
const { STUB_COUNTERPARTY } = require("../network"); const { STUB_COUNTERPARTY } = require("../network");
const { NETWORKS } = require("../../../src/shared/networks");
const { const {
STATE_SCHEMA_VERSION, STATE_SCHEMA_VERSION,
stateProblem, stateProblem,
@@ -685,159 +684,6 @@ step(
}, },
); );
// The network fields of the stored record, read on the popup page, the one
// moz-extension:// document the suite has open.
async function storedNetwork(env) {
const d = env.driver;
await d.switchToWindow(env.popupWindow);
const stored = await d.executeAsync(
`const done = arguments[arguments.length - 1];
const api = typeof browser !== "undefined" ? browser : chrome;
Promise.resolve(api.storage.local.get("autistmask")).then(
(r) => done({
networkId: r.autistmask.networkId,
rpcUrl: r.autistmask.rpcUrl,
blockscoutUrl: r.autistmask.blockscoutUrl,
}),
(e) => done({ error: String((e && e.message) || e) }),
);`,
);
assert(
stored && !stored.error,
"could not read the stored network: " + (stored && stored.error),
);
return stored;
}
// Every chainChanged event the test page has been sent, waiting up to
// `timeout` for there to be `count` of them: the background sends the event
// alongside its answer to the request, so it can arrive just after it. Leaves
// the driver on the page.
async function chainChangedEvents(env, count = 0, timeout = 5000) {
const d = env.driver;
await d.switchToWindow(env.dappWindow);
const deadline = Date.now() + timeout;
for (;;) {
const events = (await dappMessages(d, "AUTISTMASK_EVENT")).filter(
(m) => m.eventName === "chainChanged",
);
if (events.length >= count || Date.now() > deadline) return events;
await sleep(100);
}
}
// Ask, from the page, to switch from network `from` to network `to`, and
// return the prompt that opens, checked to name the site and both networks.
// Leaves the driver on the prompt.
async function openNetworkPrompt(env, key, from, to) {
const d = env.driver;
await d.switchToWindow(env.dappWindow);
await startRequest(d, key, "wallet_switchEthereumChain", [
{ chainId: to.chainId },
]);
const popup = await waitForApprovalWindow(d);
await d.switchToWindow(popup);
await d.waitVisible("#view-approve-network");
const screen = {
origin: await d.text("#approve-network-origin"),
current: await d.text("#approve-network-current"),
requested: await d.text("#approve-network-requested"),
};
assert(
isDeepStrictEqual(screen, {
origin: env.server.origin,
current: from.name,
requested: to.name,
}),
"the network switch prompt shows " + JSON.stringify(screen),
);
return popup;
}
// Only the user switches the network. A connected site's request opens a
// prompt, and until the user approves it the stored network does not move and
// no page is told it did (https://git.eeqj.de/sneak/AutistMask/issues/408).
// The wallet goes back to mainnet the same way at the end, for the transaction
// step after this one.
step(
"a site's network switch changes nothing until the user approves it",
async (env) => {
const d = env.driver;
const { mainnet, sepolia } = NETWORKS;
const before = await storedNetwork(env);
assert(
before.networkId === "mainnet",
"this step starts on mainnet, not on " + before.networkId,
);
const eventsBefore = (await chainChangedEvents(env)).length;
const rejected = await openNetworkPrompt(
env,
"switch-reject",
mainnet,
sepolia,
);
assert(
isDeepStrictEqual(await storedNetwork(env), before),
"the network moved while its prompt was still open",
);
// Nothing else closes this window, so a click that did not land
// leaves the request unanswered and the assertion below fails.
await d.switchToWindow(rejected);
await d.click("#btn-reject-network");
await d.switchToWindow(env.dappWindow);
await assertUserRejection(
d,
"switch-reject",
"the network switch rejection",
);
assert(
isDeepStrictEqual(await storedNetwork(env), before),
"a rejected network switch moved the network",
);
assert(
(await chainChangedEvents(env)).length === eventsBefore,
"a rejected network switch told the page the chain changed",
);
await openNetworkPrompt(env, "switch-approve", mainnet, sepolia);
await d.click("#btn-approve-network");
await d.switchToWindow(env.dappWindow);
let outcome = await settleRequest(d, "switch-approve");
assert(
outcome.settled === "resolved" && outcome.result === null,
"the approved network switch did not resolve: " +
JSON.stringify(outcome),
);
assert(
(await storedNetwork(env)).networkId === "sepolia",
"the approved network switch did not move the network",
);
const events = await chainChangedEvents(env, eventsBefore + 1);
assert(
events.length === eventsBefore + 1 &&
events[events.length - 1].data === sepolia.chainId,
"the page was not told of the approved switch: " +
JSON.stringify(events),
);
await openNetworkPrompt(env, "switch-restore", sepolia, mainnet);
await d.click("#btn-approve-network");
await d.switchToWindow(env.dappWindow);
outcome = await settleRequest(d, "switch-restore");
assert(
outcome.settled === "resolved",
"switching back to mainnet did not resolve: " +
JSON.stringify(outcome),
);
assert(
isDeepStrictEqual(await storedNetwork(env), before),
"switching back did not restore the mainnet network and endpoints",
);
await d.switchToWindow(env.dappWindow);
},
);
step( step(
"eth_sendTransaction shows the transaction and returns its hash", "eth_sendTransaction shows the transaction and returns its hash",
async (env) => { async (env) => {
+1 -26
View File
@@ -333,33 +333,8 @@ async function launch(routeOpts) {
const PASSWORD = "e2e-harness-password"; const PASSWORD = "e2e-harness-password";
// Waits until the page shows `selector`, not only until it lays out. Until the
// page's stylesheet has applied, the `hidden` class that showView() keeps on
// every view but the current one hides nothing and every view lays out, so a
// test could read a screen before the page's script had filled it
// (https://git.eeqj.de/sneak/AutistMask/issues/502). So the page must also
// have finished loading, which it does only after its stylesheet, and neither
// the element nor anything enclosing it may carry `hidden`. Polled on a timer:
// animation frames are not guaranteed to a window that is not in front.
async function visible(page, selector, timeout = 15000) { async function visible(page, selector, timeout = 15000) {
await page await page.waitForSelector(selector, { state: "visible", timeout });
.waitForFunction(
(sel) => {
const el = document.querySelector(sel);
if (document.readyState !== "complete" || !el) return false;
if (el.closest(".hidden")) return false;
if (getComputedStyle(el).visibility !== "visible") return false;
const r = el.getBoundingClientRect();
return r.width > 0 && r.height > 0;
},
selector,
{ polling: 50, timeout },
)
.catch((e) => {
throw new Error(
"the page did not show " + selector + ": " + e.message,
);
});
} }
// An empty WebAssembly module: magic number and version header, no // An empty WebAssembly module: magic number and version header, no
+13 -301
View File
@@ -809,7 +809,7 @@ async function secretScreenState(page, view) {
return page.evaluate( return page.evaluate(
(v) => ({ (v) => ({
value: document.getElementById(v + "-value").textContent, value: document.getElementById(v + "-value").textContent,
error: document.getElementById(v + "-password-error").textContent, error: document.getElementById(v + "-flash").textContent,
html: document.getElementById("view-" + v).innerHTML, html: document.getElementById("view-" + v).innerHTML,
resultHidden: document resultHidden: document
.getElementById(v + "-result") .getElementById(v + "-result")
@@ -906,8 +906,7 @@ test("a wrong password reveals nothing (#161)", async (env) => {
await env.page.click("#btn-show-phrase-reveal"); await env.page.click("#btn-show-phrase-reveal");
await env.page.waitForFunction( await env.page.waitForFunction(
() => () =>
document.getElementById("show-phrase-password-error").textContent document.getElementById("show-phrase-flash").textContent.length > 0,
.length > 0,
null, null,
{ timeout: 60000 }, { timeout: 60000 },
); );
@@ -1994,14 +1993,13 @@ test("an over-long flash message keeps to one line (#252)", async (env) => {
// Every screen that asks for a password reserves room for one line of error. // Every screen that asks for a password reserves room for one line of error.
// The two on the dApp approval screens also have a border and padding, which // The two on the dApp approval screens also have a border and padding, which
// that reserved height has to cover too. The add wallet screen's line sits // that reserved height has to cover too.
// beside its button rather than above it, and has its own test below.
const PASSWORD_ERROR_CONTAINERS = [ const PASSWORD_ERROR_CONTAINERS = [
"approve-tx-error", "approve-tx-error",
"approve-sign-error", "approve-sign-error",
"export-privkey-password-error", "export-privkey-flash",
"show-phrase-password-error", "show-phrase-flash",
"delete-wallet-password-error", "delete-wallet-flash",
"confirm-tx-password-error", "confirm-tx-password-error",
]; ];
@@ -2066,107 +2064,6 @@ test("a password error moves nothing on any screen (#297)", async (env) => {
} }
}); });
// ------------------------------------------ add wallet Import button (#493)
// At 360x600 the add wallet screen's Import button already starts near the
// bottom of the popup, so its password error line sits beside the button
// rather than above it. Measures the button and the line empty and again
// filled with the longest error addWallet.js puts there. Runs in the page.
function measureImportButton() {
const button = document.getElementById("btn-add-wallet-confirm");
const line = document.getElementById("add-wallet-password-error");
const measure = () => {
const b = button.getBoundingClientRect();
const l = line.getBoundingClientRect();
return {
buttonTop: b.top + window.scrollY,
buttonBottom: b.bottom + window.scrollY,
lineTop: l.top + window.scrollY,
lineBottom: l.bottom + window.scrollY,
};
};
const empty = measure();
line.textContent = "Password must be at least 12 characters.";
line.style.visibility = "visible";
const filled = measure();
line.textContent = "";
line.style.visibility = "hidden";
return { empty, filled };
}
test("the add wallet password error leaves Import where it was (#493)", async (env) => {
const page = await openPopup(env.ctx, env.popupUrl);
try {
await page.setViewportSize(POPUP_VIEWPORT);
// Brought up by toggling classes, as in the test above. The note
// addWallet.js shows once a wallet exists is the only part of the
// screen that differs between the first wallet and a later one.
await page.evaluate(() => {
const screen = document.getElementById("view-add-wallet");
for (const view of document.querySelectorAll(".view")) {
view.classList.toggle("hidden", view !== screen);
}
});
for (const walletExists of [false, true]) {
await page.evaluate(
(shown) =>
document
.getElementById("add-wallet-separate-password-note")
.classList.toggle("hidden", !shown),
walletExists,
);
for (const tab of ["tab-mnemonic", "tab-privkey", "tab-xprv"]) {
await page.click("#" + tab);
const { empty, filled } =
await page.evaluate(measureImportButton);
const where =
"#" +
tab +
(walletExists
? " with a wallet already added"
: " for the first wallet");
// Printed pass or fail, as the dust threshold test does.
console.log(
"# add wallet Import top, " +
where +
": " +
empty.buttonTop +
"px",
);
for (const m of [empty, filled]) {
assert(
m.lineTop >= m.buttonTop &&
m.lineBottom <= m.buttonBottom,
"the error line on " +
where +
" does not fit beside Import, so it adds height: " +
JSON.stringify(m),
);
}
assert(
filled.buttonTop === empty.buttonTop,
"Import moved " +
(filled.buttonTop - empty.buttonTop) +
"px when the error appeared on " +
where,
);
if (!walletExists) {
assert(
empty.buttonTop < POPUP_VIEWPORT.height,
"Import starts at " +
empty.buttonTop +
"px on " +
where +
", below the fold",
);
}
}
}
} finally {
await page.close();
}
});
// --------------------------------------------- confirmation screen (#238) // --------------------------------------------- confirmation screen (#238)
// //
// The screen that decides what gets signed. The arithmetic underneath it // The screen that decides what gets signed. The arithmetic underneath it
@@ -3499,7 +3396,7 @@ async function closeApprovalPages(ctx) {
} }
// Click a button whose own handler closes the window it lives in — every // Click a button whose own handler closes the window it lives in — every
// Reject, Allow on the site prompt, and Switch on the network switch prompt. // Reject, and Allow on the site prompt.
// //
// page.click() dispatches the click and then waits for the renderer to // page.click() dispatches the click and then waits for the renderer to
// acknowledge it, and a page torn down by the handler never gets to. The // acknowledge it, and a page torn down by the handler never gets to. The
@@ -3514,13 +3411,12 @@ async function closeApprovalPages(ctx) {
// #btn-reject-sign, #btn-reject-tx — their disconnect leaves the approval // #btn-reject-sign, #btn-reject-tx — their disconnect leaves the approval
// pending, so a click that never landed leaves the dApp promise unsettled // pending, so a click that never landed leaves the dApp promise unsettled
// and the assertion after the call fails on its own. // and the assertion after the call fails on its own.
// #btn-approve, #btn-approve-network — only a decision resolves the promise, // #btn-approve — only a decision resolves the promise, and a swallowed click
// and a swallowed click cannot produce settled === "resolved". // cannot produce settled === "resolved".
// #btn-reject on the site prompt, #btn-reject-network — NOT self-proving. A // #btn-reject on the site prompt — NOT self-proving. A page that went away
// page that went away without the click landing disconnects the approval // without the click landing disconnects the approval port, the background
// port, the background settles that as 4001, and 4001 is exactly what // settles that as 4001, and 4001 is exactly what assertUserRejection
// assertUserRejection accepts. Every call site arms the click trace below // accepts. Both call sites arm the click trace below and assert it.
// and asserts it.
// //
// A button that is missing or unclickable raises a different error, which is // A button that is missing or unclickable raises a different error, which is
// rethrown. // rethrown.
@@ -4390,190 +4286,6 @@ test("a prompt raised while another approval window has focus opens its own (#29
await assertUserRejection(env.dapp, "focus-sign", "the sign prompt"); await assertUserRejection(env.dapp, "focus-sign", "the sign prompt");
}); });
// The network fields of the stored record.
async function storedNetwork(page) {
const s = await storedRecord(page);
return {
networkId: s.networkId,
rpcUrl: s.rpcUrl,
blockscoutUrl: s.blockscoutUrl,
};
}
// Every chainChanged event the test page has been sent, waiting up to
// `timeout` for there to be `count` of them: the background sends the event
// alongside its answer to the request, so it can arrive just after it.
async function chainChangedEvents(page, count = 0, timeout = 5000) {
const deadline = Date.now() + timeout;
for (;;) {
const events = (await dappMessages(page, "AUTISTMASK_EVENT")).filter(
(m) => m.eventName === "chainChanged",
);
if (events.length >= count || Date.now() > deadline) return events;
await sleep(50);
}
}
// Ask, from the test page, to switch from network `from` to network `to`, and
// return the prompt that opens, checked to name the site and both networks.
async function openNetworkPrompt(env, key, from, to) {
await startRequest(env.dapp, key, "wallet_switchEthereumChain", [
{ chainId: to.chainId },
]);
const popup = await waitForApprovalWindow(env.ctx);
await visible(popup, "#view-approve-network");
const screen = await popup.evaluate(() => ({
origin: document.getElementById("approve-network-origin").textContent,
current: document.getElementById("approve-network-current").textContent,
requested: document.getElementById("approve-network-requested")
.textContent,
}));
assert(
isDeepStrictEqual(screen, {
origin: DAPP_ORIGIN,
current: from.name,
requested: to.name,
}),
"the network switch prompt shows " + JSON.stringify(screen),
);
return popup;
}
// Only the user switches the network. A connected site's request opens a
// prompt, and until the user approves it the stored network does not move and
// no page is told it did (https://git.eeqj.de/sneak/AutistMask/issues/408).
// The wallet goes back to mainnet the same way at the end, for the tests after
// this one.
test("a site's network switch changes nothing until the user approves it (#408)", async (env) => {
const { mainnet, sepolia } = NETWORKS;
const before = await storedNetwork(env.page);
assert(
before.networkId === "mainnet",
"this test starts on mainnet, not on " + before.networkId,
);
const eventsBefore = (await chainChangedEvents(env.dapp)).length;
const rejected = await openNetworkPrompt(
env,
"switch-reject",
mainnet,
sepolia,
);
try {
assert(
isDeepStrictEqual(await storedNetwork(env.page), before),
"the network moved while its prompt was still open",
);
// Closing the prompt unanswered is also a rejection, so the click
// itself is witnessed.
await armClickTrace(env, rejected, "#btn-reject-network");
await clickAndClose(rejected, "#btn-reject-network");
await assertClickLanded(env, "#btn-reject-network");
await assertUserRejection(
env.dapp,
"switch-reject",
"the network switch rejection",
);
} finally {
await closeApprovalPages(env.ctx);
}
assert(
isDeepStrictEqual(await storedNetwork(env.page), before),
"a rejected network switch moved the network",
);
assert(
(await chainChangedEvents(env.dapp)).length === eventsBefore,
"a rejected network switch told the page the chain changed",
);
const approved = await openNetworkPrompt(
env,
"switch-approve",
mainnet,
sepolia,
);
let outcome;
try {
await clickAndClose(approved, "#btn-approve-network");
outcome = await settleRequest(env.dapp, "switch-approve");
} finally {
await closeApprovalPages(env.ctx);
}
assert(
outcome.settled === "resolved" && outcome.result === null,
"the approved network switch did not resolve: " +
JSON.stringify(outcome),
);
assert(
(await storedNetwork(env.page)).networkId === "sepolia",
"the approved network switch did not move the network",
);
const events = await chainChangedEvents(env.dapp, eventsBefore + 1);
assert(
events.length === eventsBefore + 1 &&
events[events.length - 1].data === sepolia.chainId,
"the page was not told of the approved switch: " +
JSON.stringify(events),
);
const restored = await openNetworkPrompt(
env,
"switch-restore",
sepolia,
mainnet,
);
try {
await clickAndClose(restored, "#btn-approve-network");
outcome = await settleRequest(env.dapp, "switch-restore");
} finally {
await closeApprovalPages(env.ctx);
}
assert(
outcome.settled === "resolved",
"switching back to mainnet did not resolve: " + JSON.stringify(outcome),
);
assert(
isDeepStrictEqual(await storedNetwork(env.page), before),
"switching back did not restore the mainnet network and endpoints",
);
});
// Switching the network in Settings tells the page too, as an approved site
// request does (https://git.eeqj.de/sneak/AutistMask/issues/500). The wallet
// goes back to mainnet the same way at the end.
test("a network switch in Settings tells the page (#500)", async (env) => {
const { mainnet, sepolia } = NETWORKS;
const before = await storedNetwork(env.page);
assert(
before.networkId === "mainnet",
"this test starts on mainnet, not on " + before.networkId,
);
const eventsBefore = (await chainChangedEvents(env.dapp)).length;
await openSettings(env.page);
await env.page.selectOption("#settings-network", "sepolia");
let events = await chainChangedEvents(env.dapp, eventsBefore + 1);
assert(
events.length === eventsBefore + 1 &&
events[events.length - 1].data === sepolia.chainId,
"the page was not told of the switch to Sepolia: " +
JSON.stringify(events),
);
await env.page.selectOption("#settings-network", "mainnet");
events = await chainChangedEvents(env.dapp, eventsBefore + 2);
assert(
events.length === eventsBefore + 2 &&
events[events.length - 1].data === mainnet.chainId,
"the page was not told of the switch back to mainnet: " +
JSON.stringify(events),
);
assert(
isDeepStrictEqual(await storedNetwork(env.page), before),
"switching back did not restore the mainnet network and endpoints",
);
});
// The closing pass over both boundaries at once. Every message the section // The closing pass over both boundaries at once. Every message the section
// put on either channel is re-read here and required to be free of the // put on either channel is re-read here and required to be free of the
// password — and required to be there at all, method by method, so the // password — and required to be there at all, method by method, so the
+4 -6
View File
@@ -207,7 +207,7 @@ describe("a decrypt still running when the screen is left", () => {
}); });
// Same hole on the failure path: a wrong-password error written after // Same hole on the failure path: a wrong-password error written after
// the wipe would restore the error line on a screen the user has left. // the wipe would restore the flash line on a screen the user has left.
test("never writes the failure message either", async () => { test("never writes the failure message either", async () => {
const { helpers, vault, exportPrivkey } = load(); const { helpers, vault, exportPrivkey } = load();
exportPrivkey.show(0, 0); exportPrivkey.show(0, 0);
@@ -217,10 +217,8 @@ describe("a decrypt still running when the screen is left", () => {
reveal.reject(new Error("decryption failed")); reveal.reject(new Error("decryption failed"));
await reveal.pending; await reveal.pending;
expect(node("export-privkey-password-error").textContent).toBe(""); expect(node("export-privkey-flash").textContent).toBe("");
expect(node("export-privkey-password-error").style.visibility).toBe( expect(node("export-privkey-flash").style.visibility).toBe("hidden");
"hidden",
);
}); });
}); });
@@ -262,7 +260,7 @@ describe("a reveal that is not interrupted", () => {
await reveal.pending; await reveal.pending;
expect(node("export-privkey-value").textContent).toBe(""); expect(node("export-privkey-value").textContent).toBe("");
expect(node("export-privkey-password-error").textContent).toBe( expect(node("export-privkey-flash").textContent).toBe(
"That password is incorrect. Please try again.", "That password is incorrect. Please try again.",
); );
}); });
+4 -4
View File
@@ -345,10 +345,10 @@ describe.each([
}); });
// A transaction's value and fee are in the native currency of the network the // A transaction's value and fee are in the native currency of the network the
// transaction is on, which need not be the active one. The active network can // transaction is on, which need not be the active one. A site can switch the
// change, in Settings or when the user approves a site's request, after a // active network after its transaction is prepared and back before it is
// transaction is prepared and change back before it is signed, and a popup // signed, and a popup opened after a switch shows a sent or listed transaction
// opened after a switch shows a sent or listed transaction again. The wallet's balances follow the active network; these do not. // again. The wallet's balances follow the active network; these do not.
describe.each([ describe.each([
["mainnet", "sepolia", "ETH"], ["mainnet", "sepolia", "ETH"],
["sepolia", "mainnet", "SepoliaETH"], ["sepolia", "mainnet", "SepoliaETH"],
-159
View File
@@ -1,159 +0,0 @@
// Every screen that asks for a password shows a password error the same way:
// through showError() and hideError() in src/popup/views/helpers.js, in a
// fixed-height error line below the password field, and never in the flash
// line at the top of the popup
// (https://git.eeqj.de/sneak/AutistMask/issues/493). These boot the real popup
// over src/popup/index.html, so each error line has to exist in the markup,
// and check that the error appears in it and clears again.
jest.mock("../src/shared/vault", () => ({
decryptWithPassword: jest.fn(),
encryptWithPassword: jest.fn(),
}));
const {
bootPopup,
cleanupPopup,
unversionedValidProfile,
} = require("./support/popupBoot");
const PASSWORD = "correct horse battery staple";
const WRONG_PASSWORD = "That password is incorrect. Please try again.";
afterEach(() => {
cleanupPopup();
});
// The error line as the user sees it.
function errorLine(page, id) {
return {
inMarkup: page.document.authoredIds.has(id),
text: page.text(id),
visibility: page.node(id).style.visibility,
};
}
function shown(text) {
return { inMarkup: true, text, visibility: "visible" };
}
const cleared = { inMarkup: true, text: "", visibility: "hidden" };
describe("the add wallet screen", () => {
const ERROR = "add-wallet-password-error";
// First run: Welcome, "Add wallet", then the die for a valid phrase.
async function openAddWallet() {
const page = await bootPopup(undefined);
await page.click("btn-welcome-add");
await page.click("btn-generate-phrase");
return page;
}
function setPasswords(page, password, confirm) {
page.node("add-wallet-password").value = password;
page.node("add-wallet-password-confirm").value = confirm;
}
test("shows a password problem below the password fields, and clears it on the next press", async () => {
const page = await openAddWallet();
setPasswords(page, "short", "short");
await page.click("btn-add-wallet-confirm");
expect(errorLine(page, ERROR)).toEqual(
shown("Password must be at least 12 characters."),
);
expect(page.text("flash-msg")).toBe("");
// The password is fixed and the phrase emptied: the password error
// goes, and the phrase problem is still reported in the flash line.
setPasswords(page, PASSWORD, PASSWORD);
page.node("wallet-mnemonic").value = "";
await page.click("btn-add-wallet-confirm");
expect(errorLine(page, ERROR)).toEqual(cleared);
expect(page.text("flash-msg")).toBe(
"Enter a recovery phrase, or press the die.",
);
// Leaving clears the flash line and stops its timer, which would
// otherwise fire after this page is gone.
await page.click("btn-add-wallet-back");
});
test("clears the error when the screen is shown again", async () => {
const page = await openAddWallet();
setPasswords(page, PASSWORD, PASSWORD + " typo");
await page.click("btn-add-wallet-confirm");
expect(errorLine(page, ERROR)).toEqual(
shown("Passwords do not match."),
);
await page.click("btn-add-wallet-back");
await page.click("btn-welcome-add");
expect(errorLine(page, ERROR)).toEqual(cleared);
});
});
describe.each([
{
screen: "the private key export screen",
open: () => require("../src/popup/views/exportPrivkey").show(0, 0),
field: "export-privkey-password",
button: "btn-export-privkey-confirm",
error: "export-privkey-password-error",
},
{
screen: "the recovery phrase screen",
open: () => require("../src/popup/views/showPhrase").show(0),
field: "show-phrase-password",
button: "btn-show-phrase-reveal",
error: "show-phrase-password-error",
},
{
screen: "the delete wallet screen",
open: () => require("../src/popup/views/deleteWallet").show(0),
field: "delete-wallet-password",
button: "btn-delete-wallet-confirm",
error: "delete-wallet-password-error",
},
])("$screen", ({ open, field, button, error }) => {
// Opens the screen and enters a password the vault rejects.
async function failedAttempt() {
const page = await bootPopup(unversionedValidProfile());
open();
const { decryptWithPassword } = require("../src/shared/vault");
decryptWithPassword.mockRejectedValue(new Error("wrong password"));
page.node(field).value = "not the password";
await page.click(button);
return { page, decryptWithPassword };
}
test("shows a wrong password below the password field", async () => {
const { page } = await failedAttempt();
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
});
test("clears the error while the next password is checked", async () => {
const { page, decryptWithPassword } = await failedAttempt();
let rejectDecrypt;
decryptWithPassword.mockReturnValue(
new Promise((resolve, reject) => {
rejectDecrypt = reject;
}),
);
page.node(field).value = "another guess";
const pressed = page.click(button);
await page.settle();
expect(errorLine(page, error)).toEqual(cleared);
rejectDecrypt(new Error("wrong password"));
await pressed;
expect(errorLine(page, error)).toEqual(shown(WRONG_PASSWORD));
});
test("clears the error when the screen is shown again", async () => {
const { page } = await failedAttempt();
open();
expect(errorLine(page, error)).toEqual(cleared);
});
});
+46 -142
View File
@@ -49,37 +49,22 @@
// every path a stored record takes, and the difference is the whole of what // every path a stored record takes, and the difference is the whole of what
// this file does not cover: // this file does not cover:
// //
// - Only the values in the table, in the SLOT arrangement below. On the // - Only the values in the table, in the SLOT arrangement below: four value
// restore path the twelve fields the router does not read are corrupted // combinations per view, not the product of twelve fields. A dereference
// together, every field on the same slot, so a view gets four value // reached only under a pairing no slot produces is not driven at all.
// combinations of them, not their product. A branch entered only when one // - Only what a stored record reaches by ITSELF. A view only forward
// of them is truthy and another falsy is reached only where the falsy // navigation opens, and anything behind a click, is not driven.
// slot happens to pair a field that cannot be falsy with one that is. // - Nothing about the paths a HEALTHY profile takes, which is most of the
// Each field the router reads is corrupted alone, over an otherwise // popup. This file is a floor under one defect class, not a proof about
// well-formed record. // the renderers.
// - Only what a stored record reaches by ITSELF, as the boot renders it. A
// view only forward navigation opens, anything behind a click, and
// anything behind a timer (bootPopup() records every interval, and this
// file never runs one) is not driven.
// - Of the paths a HEALTHY profile takes, only its boot onto each
// restorable view ("the base profile the sweep corrupts" below). The rest
// of the popup is not covered: this file is a floor under one defect
// class, not a proof about the renderers.
// //
// Within that boundary it is unconditional: if a boot that corrupts a field // Within that boundary it is unconditional: if one of these boots leaves the
// leaves the popup unhealthy, this file goes red — including when it takes // popup unhealthy or off the view it stored, this file goes red — including
// two corrupted fields at once, because the verdict is the combined boot // when it takes two corrupted fields at once, because the verdict is the
// itself and the per-field re-boot below can only decorate the message. That // combined boot itself and the per-field re-boot below can only decorate the
// last part is the one thing an earlier version got wrong: it asserted on the // message. That last part is the one thing an earlier version got wrong: it
// per-field list, so an observed dead popup that no single field reproduced // asserted on the per-field list, so an observed dead popup that no single
// was reported green. // field reproduced was reported green.
//
// Where the popup lands is held for some of those boots and not others. The
// combined boot must land on the view it stored, and each `hostileRestore`
// value must land on its view, or fall back to Home, as its entry declares.
// The boots in "a hostile routing value restoring onto" are held to health
// alone, because a value in a field the router reads legitimately changes
// which view renders; so are the boots onto Home, which store no view.
// //
// Booting every field separately at every value would be several hundred boots // Booting every field separately at every value would be several hundred boots
// and most of the suite's budget; this is forty-four. Widening it further is // and most of the suite's budget; this is forty-four. Widening it further is
@@ -143,11 +128,7 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
// list short and pointed. `floorOnly` is extra values checked against the // list short and pointed. `floorOnly` is extra values checked against the
// floor alone, which is pure and free. `hostileRestore` is extra values driven // floor alone, which is pure and free. `hostileRestore` is extra values driven
// through the restore path only, for a value that means nothing until a // through the restore path only, for a value that means nothing until a
// particular branch's gate has let it past. Each of its entries names the // particular branch's gate has let it past.
// `views` it is driven onto and declares whether the boot lands on them
// (`restored: true`) or falls back to Home (`restored: false`), so a value
// written for one renderer cannot stop reaching it unnoticed. A value driven
// onto every restorable view is written with everyRestorableView() below.
// //
// `falsy` is the other POLARITY of a swept field, driven for the same reason. // `falsy` is the other POLARITY of a swept field, driven for the same reason.
// It is not a value src/ never writes — for three of these fields it is the // It is not a value src/ never writes — for three of these fields it is the
@@ -158,23 +139,6 @@ const sweptValues = (row) => [...row.hostile, ...(row.falsy || [])];
// falsy value stored under that field comes back TRUTHY from the floor, so no // falsy value stored under that field comes back TRUTHY from the floor, so no
// `!state.x` branch is reachable from a stored record at all. // `!state.x` branch is reachable from a stored record at all.
// The `hostileRestore` entries for a value driven onto every restorable view:
// it falls back to Home on the views listed in `fallsBackOn` and lands on every
// other one, so a view added to RESTORABLE_VIEWS is driven, and expected to
// land, without editing the row.
function everyRestorableView(value, fallsBackOn) {
return [
{ value, views: fallsBackOn, restored: false },
{
value,
views: [...RESTORABLE_VIEWS].filter(
(view) => !fallsBackOn.includes(view),
),
restored: true,
},
];
}
const CONTRACT = [ const CONTRACT = [
{ {
field: "wallets", field: "wallets",
@@ -316,38 +280,28 @@ const CONTRACT = [
kind: KIND.SCALAR, kind: KIND.SCALAR,
// The prototype members are the whole point: `wallets["map"]` is // The prototype members are the whole point: `wallets["map"]` is
// TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and // TRUTHY, so hasValidAddress()'s `&&` does not short-circuit and
// `.addresses[…]` throws. A stale INTEGER is the safe case and has to // `.addresses[…]` throws. A stale INTEGER is the safe case.
// stay so. 5 is one, out of range for the one wallet in the profile, hostile: ["map", "__proto__", { a: 1 }],
// and it is also this field's truthy polarity: every other value here
// comes back from the floor as null.
hostile: ["map", "__proto__", { a: 1 }, 5],
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true], floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
holds: isIndexOrNull, holds: isIndexOrNull,
// SCALAR, and swept anyway: the restore path is precisely why this // SCALAR, and swept anyway: the restore path is precisely why this
// field gained a floor, so the sweep is the regression guard on it. // field gained a floor, so the sweep is the regression guard on it.
alsoSweep: true, alsoSweep: true,
routes: true, routes: true,
// Comes back from the floor as null, which hasValidAddress() reads as // A stale INTEGER index, which reaches the restore path by a different
// nothing selected: the popup falls back to Home on the five views // route from the prototype members above — falsy or out of range
// that need an address, and lands on every other one. // rather than truthy — and has to keep being the safe case.
hostileRestore: everyRestorableView("length", [ hostileRestore: [{ value: "length" }, { value: 5 }],
"address",
"address-token",
"receive",
"transaction",
"confirm-tx",
]),
}, },
{ {
field: "selectedAddress", field: "selectedAddress",
kind: KIND.SCALAR, kind: KIND.SCALAR,
// 5 for the same reason as in selectedWallet: a stale index, and the hostile: ["map", "__proto__", { a: 1 }],
// one value here still truthy after the floor.
hostile: ["map", "__proto__", { a: 1 }, 5],
floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true], floorOnly: ["length", "constructor", "toString", "0", -1, 1.5, true],
holds: isIndexOrNull, holds: isIndexOrNull,
alsoSweep: true, alsoSweep: true,
routes: true, routes: true,
hostileRestore: [{ value: 5 }],
}, },
{ {
field: "currentView", field: "currentView",
@@ -371,9 +325,7 @@ const CONTRACT = [
// container shapes below onto every restorable view; hostileRestore // container shapes below onto every restorable view; hostileRestore
// adds the records that PASS a branch's gate and then hand its // adds the records that PASS a branch's gate and then hand its
// renderer something it dereferences, which is where the entries are // renderer something it dereferences, which is where the entries are
// actually decided. The guard refuses each single-view record below, // actually decided.
// so each is declared to fall back to Home: one that started landing
// would be reaching the renderer it was written against.
hostile: [42, "notarecord", { a: 1 }, [1, 2]], hostile: [42, "notarecord", { a: 1 }, [1, 2]],
// `structuredClone(saved.viewData || {})`: the container is never falsy // `structuredClone(saved.viewData || {})`: the container is never falsy
// in state whatever was stored, so no `!state.viewData` branch exists to // in state whatever was stored, so no `!state.viewData` branch exists to
@@ -382,20 +334,11 @@ const CONTRACT = [
hostileRestore: [ hostileRestore: [
// success-tx passes on `data.hash`, and renderSuccess() then calls // success-tx passes on `data.hash`, and renderSuccess() then calls
// toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase(). // toAddressHtml(d.to) -> addressTitle() -> address.toLowerCase().
{ { value: { hash: "0x1" }, views: ["success-tx"] },
value: { hash: "0x1" }, { value: { hash: "0x1", to: 42 }, views: ["success-tx"] },
views: ["success-tx"],
restored: false,
},
{
value: { hash: "0x1", to: 42 },
views: ["success-tx"],
restored: false,
},
{ {
value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } }, value: { hash: "0x1", to: ADDRESS, decoded: { details: 7 } },
views: ["success-tx"], views: ["success-tx"],
restored: false,
}, },
{ {
value: { value: {
@@ -404,25 +347,12 @@ const CONTRACT = [
decoded: { details: [{ address: 42 }] }, decoded: { details: [{ address: 42 }] },
}, },
views: ["success-tx"], views: ["success-tx"],
restored: false,
}, },
// error-tx passes on `data.message`, same dereference. // error-tx passes on `data.message`, same dereference.
{ { value: { message: "boom" }, views: ["error-tx"] },
value: { message: "boom" }, { value: { message: "boom", to: 42 }, views: ["error-tx"] },
views: ["error-tx"],
restored: false,
},
{
value: { message: "boom", to: 42 },
views: ["error-tx"],
restored: false,
},
// transaction passes on `data.tx`. // transaction passes on `data.tx`.
{ { value: { tx: { hash: "0x1" } }, views: ["transaction"] },
value: { tx: { hash: "0x1" } },
views: ["transaction"],
restored: false,
},
{ {
value: { value: {
tx: { tx: {
@@ -433,14 +363,9 @@ const CONTRACT = [
}, },
}, },
views: ["transaction"], views: ["transaction"],
restored: false,
}, },
// confirm-tx passes on `data.pendingTx`. // confirm-tx passes on `data.pendingTx`.
{ { value: { pendingTx: { amount: "1" } }, views: ["confirm-tx"] },
value: { pendingTx: { amount: "1" } },
views: ["confirm-tx"],
restored: false,
},
{ {
value: { value: {
pendingTx: { pendingTx: {
@@ -451,7 +376,6 @@ const CONTRACT = [
}, },
}, },
views: ["confirm-tx"], views: ["confirm-tx"],
restored: false,
}, },
// wait-tx passes on `pendingWait.hash`; restoreWait() has checked // wait-tx passes on `pendingWait.hash`; restoreWait() has checked
// the fields below it since it was written, and this is the // the fields below it since it was written, and this is the
@@ -464,29 +388,20 @@ const CONTRACT = [
}, },
}, },
views: ["wait-tx"], views: ["wait-tx"],
restored: false,
}, },
// A record that passes EVERY branch's gate at once, driven onto // A record that passes EVERY branch's gate at once, driven onto
// every restorable view: a branch a view does not read must stay // every restorable view: a branch a view does not read must stay
// one it does not read. The five views with a viewData branch // one it does not read, and each renderer must survive the fields
// refuse it; every other one renders it, and must survive the // another branch left behind.
// fields every branch left behind.
...everyRestorableView(
{ {
value: {
hash: "0x1", hash: "0x1",
message: "boom", message: "boom",
tx: { hash: "0x1" }, tx: { hash: "0x1" },
pendingTx: { amount: "1" }, pendingTx: { amount: "1" },
pendingWait: { hash: "0x1" }, pendingWait: { hash: "0x1" },
}, },
[ },
"confirm-tx",
"transaction",
"wait-tx",
"success-tx",
"error-tx",
],
),
], ],
}, },
{ {
@@ -668,11 +583,6 @@ const HEALTHY = { errors: [], blank: false };
// set is all-truthy by construction, so without a falsy slot a dereference // set is all-truthy by construction, so without a falsy slot a dereference
// behind `if (!state.x)` is never reached on the boot that corrupts x — the // behind `if (!state.x)` is never reached on the boot that corrupts x — the
// same falsy-collapse blind spot the fields below were floored for. // same falsy-collapse blind spot the fields below were floored for.
//
// Only `hostile` and `falsy` values count. Those go through the sweep below,
// which covers every restorable view; a `hostileRestore` entry is driven onto
// only the views it names, so a polarity it alone supplied might reach a single
// renderer.
describe("both polarities of every swept field are driven", () => { describe("both polarities of every swept field are driven", () => {
const FALSY_STORED = [0, "", false, null]; const FALSY_STORED = [0, "", false, null];
const floored = (field, value) => const floored = (field, value) =>
@@ -696,9 +606,10 @@ describe("both polarities of every swept field are driven", () => {
test(`${row.field}: truthy and falsy`, () => { test(`${row.field}: truthy and falsy`, () => {
// What the boots below actually drive, floored the way a renderer // What the boots below actually drive, floored the way a renderer
// sees it — not what the row says it drives. // sees it — not what the row says it drives.
const driven = sweptValues(row).map((value) => const driven = [
floored(row.field, value), ...sweptValues(row),
); ...(row.hostileRestore || []).map((entry) => entry.value),
].map((value) => floored(row.field, value));
expect({ expect({
truthy: driven.some((value) => Boolean(value)), truthy: driven.some((value) => Boolean(value)),
@@ -954,27 +865,20 @@ describe("every field the router does not read, corrupted at once, onto", () =>
// The values that only mean something on the restore path: a viewData that // The values that only mean something on the restore path: a viewData that
// PASSES a branch's gate and then hands its renderer something dereferenced, // PASSES a branch's gate and then hands its renderer something dereferenced,
// and a selectedWallet the floor turns into nothing selected. Each boot must // and the index values whose route through hasValidAddress() differs from the
// throw nothing and show exactly the view its entry says it lands on: its own, // row's own hostile set.
// or Home, so a value written for one renderer cannot stop reaching it and
// still pass.
describe("a restore-only hostile value onto", () => { describe("a restore-only hostile value onto", () => {
for (const row of CONTRACT) { for (const row of CONTRACT) {
for (const entry of row.hostileRestore || []) { for (const entry of row.hostileRestore || []) {
for (const view of entry.views) { for (const view of entry.views || RESTORABLE_VIEWS) {
test(`${view}: ${row.field} = ${JSON.stringify( test(`${view}: ${row.field} = ${JSON.stringify(
entry.value, entry.value,
)}`, async () => { )}`, async () => {
const env = await bootPopup( await expect(
bootHealth(
restoringOnto(view, { [row.field]: entry.value }), restoringOnto(view, { [row.field]: entry.value }),
); ),
expect({ ).resolves.toEqual(HEALTHY);
errors: env.pageErrors,
visible: env.visibleViews(),
}).toEqual({
errors: [],
visible: [entry.restored ? view : "main"],
});
}); });
} }
} }
+1 -6
View File
@@ -238,10 +238,6 @@ async function settle() {
* @param {object} [options] * @param {object} [options]
* @param {object} [options.storage] a storage stub from makeStorageStub(), for * @param {object} [options.storage] a storage stub from makeStorageStub(), for
* a test that needs to make writes fail or to watch the round trips. * a test that needs to make writes fail or to watch the round trips.
* @param {string} [options.search] the page URL's query string, such as
* "?approval=" and an id for the popup opened as an approval window.
* @param {object} [options.runtime] members of chrome.runtime that replace the
* stub's own, for a test that has to answer the background's messages.
* @returns {Promise<object>} handles onto the booted page. * @returns {Promise<object>} handles onto the booted page.
*/ */
async function bootPopup(stored, options) { async function bootPopup(stored, options) {
@@ -285,13 +281,12 @@ async function bootPopup(stored, options) {
sendMessage: jest.fn(async () => ({})), sendMessage: jest.fn(async () => ({})),
getURL: (p) => "chrome-extension://autistmask/" + p, getURL: (p) => "chrome-extension://autistmask/" + p,
onMessage: { addListener: () => {} }, onMessage: { addListener: () => {} },
...(options && options.runtime),
}, },
}; };
globalThis.document = document; globalThis.document = document;
globalThis.window = { globalThis.window = {
location: { location: {
search: (options && options.search) || "", search: "",
href: "chrome-extension://autistmask/src/popup/index.html", href: "chrome-extension://autistmask/src/popup/index.html",
reload: () => reloads.push(Date.now()), reload: () => reloads.push(Date.now()),
}, },