What changed. A site could fix the nonce of the transaction it asked the user to sign. The same nonce as a pending transaction, at a higher fee, replaces that transaction; a nonce above the account's next one leaves the new transaction stuck behind a gap. nonce is removed from the fields src/shared/approvalTx.js takes from the page's request, so the transaction always gets the account's next nonce from the network.
Why nothing else changed. The approval screen, the popup's signing and the background's check of the signed transaction (src/shared/approvalVerify.js) all read the transaction the background prepared, never the page's request, so once the nonce is no longer taken from the page they all carry the network's nonce. A gas limit the page supplies is still honoured; that is the owner's question in #207.
Tests. New tests/approvalNonce.test.js: a page asks for nonce 2 while the network's next nonce is 7; the approval screen shows 7, and the transaction its real Confirm button signs carries 7. It fails against current next, as does the updated case in tests/approvalTx.test.js, which used to assert that the page's nonce was kept.
Docs.README.md (TxApproval) now says a nonce the site supplies is ignored; TODO.md entry added.
Judgement call: README.md has no list of the fields taken from a page, so the sentence went into the TxApproval description of what the background populates.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/AutistMask/issues/404.
**What changed.** A site could fix the nonce of the transaction it asked the user to sign. The same nonce as a pending transaction, at a higher fee, replaces that transaction; a nonce above the account's next one leaves the new transaction stuck behind a gap. `nonce` is removed from the fields `src/shared/approvalTx.js` takes from the page's request, so the transaction always gets the account's next nonce from the network.
**Why nothing else changed.** The approval screen, the popup's signing and the background's check of the signed transaction (`src/shared/approvalVerify.js`) all read the transaction the background prepared, never the page's request, so once the nonce is no longer taken from the page they all carry the network's nonce. A gas limit the page supplies is still honoured; that is the owner's question in https://git.eeqj.de/sneak/AutistMask/issues/207.
**Tests.** New `tests/approvalNonce.test.js`: a page asks for nonce 2 while the network's next nonce is 7; the approval screen shows 7, and the transaction its real Confirm button signs carries 7. It fails against current `next`, as does the updated case in `tests/approvalTx.test.js`, which used to assert that the page's nonce was kept.
**Docs.** `README.md` (TxApproval) now says a nonce the site supplies is ignored; `TODO.md` entry added.
Judgement call: `README.md` has no list of the fields taken from a page, so the sentence went into the TxApproval description of what the background populates.
Model: opus-5-5
A site could fix the nonce of the transaction the user was asked to
sign: the same nonce as a pending transaction, at a higher fee,
replaces it, and a nonce above the account's next one leaves the new
transaction stuck behind a gap. `nonce` is no longer one of the fields
taken from the request, so the transaction always gets the account's
next nonce from the network, and that is the nonce the approval screen
shows and the popup signs.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #404.
What changed. A site could fix the nonce of the transaction it asked the user to sign. The same nonce as a pending transaction, at a higher fee, replaces that transaction; a nonce above the account's next one leaves the new transaction stuck behind a gap.
nonceis removed from the fieldssrc/shared/approvalTx.jstakes from the page's request, so the transaction always gets the account's next nonce from the network.Why nothing else changed. The approval screen, the popup's signing and the background's check of the signed transaction (
src/shared/approvalVerify.js) all read the transaction the background prepared, never the page's request, so once the nonce is no longer taken from the page they all carry the network's nonce. A gas limit the page supplies is still honoured; that is the owner's question in #207.Tests. New
tests/approvalNonce.test.js: a page asks for nonce 2 while the network's next nonce is 7; the approval screen shows 7, and the transaction its real Confirm button signs carries 7. It fails against currentnext, as does the updated case intests/approvalTx.test.js, which used to assert that the page's nonce was kept.Docs.
README.md(TxApproval) now says a nonce the site supplies is ignored;TODO.mdentry added.Judgement call:
README.mdhas no list of the fields taken from a page, so the sentence went into the TxApproval description of what the background populates.Model: opus-5-5
PASS
Model: opus-5-5