All checks were successful
check / check (push) Successful in 20s
src/shared/transactions.js had zero test coverage despite owning the four anti-poisoning filters that README.md:730-814 documents as a core security property: known token symbol verification, the 1,000-holder rule, the fraud contract blocklist, and the dust threshold. A regression in any of them does not crash, it just silently stops filtering, so the behaviour needs pinning down in both directions. Adds tests/transactions.test.js with fixtures built from the two real attacks cited in the README: the fake "Ethereum"/"ETH" token at 0xD05339f9 with zero holders, and the 1 gwei native dust transfer 0x2708ebdd from the look-alike sender 0xC3c6B3b4. Every filter is proven to work when on and to be bypassed when off, both thresholds are asserted at, just below, and just above their boundary, and legitimate traffic (a plain ETH transfer and genuine USDC and WETH transfers) is proven to survive all four rules. Also covers the per-address merge and dedup that fetchRecentTransactions owns, with debugFetch mocked at the module boundary. No test performs a network request: global.fetch is a throwing stub and is asserted never to have been called. Several tests are named as documenting current behaviour where it diverges from the README; no source file is modified here.
2.5 KiB
2.5 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0. Tagged v0.1.0 on 2026-02-27. Active development on branch feat/issue-144-settings-about (another agent working as of 2026-07-06). Full policy file set present; make check on main not verified.
Next Step
Land feat/issue-144-settings-about: finish the settings About well (build info, app name and repo link, release date, version click easter egg, git info derived inside Docker), resolve the untracked scripts/ directory (commit or gitignore), get review, merge to main.
Completed Steps
- 2026-08-09: Test coverage for the address-poisoning defense in
src/shared/transactions.js(#160) - 2026-07-07 Adopted scripts-to-rule-them-all:
script/entrypoints, Makefile shims, README Entrypoints section - 2026-03-01: About well in settings with build info and easter egg (in flight on feature branch); USD display suppressed on testnets (#142); estimated USD for ETH in approve-tx view (#141).
- Sepolia testnet support (#137); etherscan links go to token-specific URLs (#136).
- Transaction detail improvements: Type field and on-chain details (#130), txid-first reordering (#133), swap display corrections (#128), expanded confirm-tx warnings (#118).
- Dark mode theme setting (Light/Dark/System) with contrast fixes (#126); timestamps include timezone offset (#120); layout shift audit, reserved space for error messages (#124).
- Copy-flash visual feedback with timing tune (#113, #121); cross-wallet-type duplicate detection (#115).
- 2026-02-27: v0.1.0 tagged.
- 2026-02-24: Initial scaffolding: popup UI, BIP-39 wallet creation via ethers.js, wallet persistence, real ETH balances over RPC, ENS forward and reverse resolution.
Future Steps
- Verify main passes make check after the feature branch merges (not verified 2026-07-06 because an agent was active in the tree); fix anything red. main must always be green.
- Prune stale branches: dozens of merged local and remote feature branches remain (fix/, feature/, tx-*); delete merged ones locally and on origin.
- Continue the issue backlog toward a feature-complete wallet, then cut further tags as milestones land.
- Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC input validation) before any 1.0rc tag.