The 12-word BIP-39 test phrase survived in every release bundle as dead text: module.exports keeps DEBUG_MNEMONIC live even though wallet.js's only use of it folds away in a release build, so it could not be tree-shaken. Putting the value itself behind the __BUILD_DEBUG__ define makes esbuild fold it to null, so no distributed bundle carries it. script/verify-build now fails a release build if the phrase appears in any emitted file, so the fold cannot silently regress; test-verify-build covers both the release failure and the debug allowance. tests/extensionId.test.js now scans the content of every tracked file for a PEM private-key header instead of matching filename extensions alone, so a key committed under an unexpected name is caught. Model: opus-4-8
80 lines
3.3 KiB
JavaScript
80 lines
3.3 KiB
JavaScript
// DEBUG is a build-time constant injected by esbuild's define in build.js
|
|
// (see src/shared/buildInfo.js for the same pattern). It is false unless the
|
|
// bundle was produced with AUTISTMASK_DEBUG=1, and it is false whenever the
|
|
// module is loaded outside a bundle (tests, plain require). It must never be
|
|
// derived from anything the user can change at runtime: it is what gates the
|
|
// hardcoded test mnemonic below.
|
|
/* global __BUILD_DEBUG__ */
|
|
const DEBUG = typeof __BUILD_DEBUG__ !== "undefined" ? __BUILD_DEBUG__ : false;
|
|
|
|
// Machine-readable record of the compiled DEBUG state, read out of the emitted
|
|
// bundles by script/verify-build. It is derived from DEBUG itself so the two
|
|
// cannot disagree, and it is a plain string literal rather than a minifier
|
|
// artifact like `DEBUG:!1`, so the check does not depend on esbuild's output
|
|
// staying byte-stable across versions.
|
|
//
|
|
// The ambiguity is the point. When DEBUG is known at build time the bundler
|
|
// folds this to exactly one of the two literals. When it is not — which is
|
|
// exactly what happens if the __BUILD_DEBUG__ define goes missing from
|
|
// build.js — the ternary survives, both literals appear in the bundle, and
|
|
// verify-build fails rather than guessing.
|
|
const BUILD_DEBUG_MARKER = DEBUG
|
|
? "autistmask-build-debug=on"
|
|
: "autistmask-build-debug=off";
|
|
|
|
// Behind DEBUG for the same reason BUILD_DEBUG_MARKER is above: in a release
|
|
// build __BUILD_DEBUG__ is a compile-time false, esbuild drops this branch, and
|
|
// the phrase never reaches a distributed bundle. The literal used to survive as
|
|
// dead text because module.exports keeps this const live even though wallet.js's
|
|
// only use of it is folded away; making the value itself fold to null removes
|
|
// it. script/verify-build fails a release build if the phrase appears anyway.
|
|
const DEBUG_MNEMONIC = DEBUG
|
|
? "cube evolve unfold result inch risk jealous skill hotel bulb night wreck"
|
|
: null;
|
|
|
|
const ETHEREUM_MAINNET_CHAIN_ID = "0x1";
|
|
const ETHEREUM_SEPOLIA_CHAIN_ID = "0xaa36a7";
|
|
|
|
const DEFAULT_RPC_URL = "https://ethereum-rpc.publicnode.com";
|
|
|
|
const DEFAULT_BLOCKSCOUT_URL = "https://eth.blockscout.com/api/v2";
|
|
|
|
const BIP44_ETH_PATH = "m/44'/60'/0'/0";
|
|
|
|
const ERC20_ABI = [
|
|
"function name() view returns (string)",
|
|
"function symbol() view returns (string)",
|
|
"function decimals() view returns (uint8)",
|
|
"function balanceOf(address) view returns (uint256)",
|
|
"function transfer(address to, uint256 amount) returns (bool)",
|
|
"function allowance(address owner, address spender) view returns (uint256)",
|
|
"function approve(address spender, uint256 amount) returns (bool)",
|
|
];
|
|
|
|
// Known null/burn addresses that permanently destroy funds.
|
|
const BURN_ADDRESSES = new Set([
|
|
"0x0000000000000000000000000000000000000000",
|
|
"0x0000000000000000000000000000000000000001",
|
|
"0x000000000000000000000000000000000000dead",
|
|
"0xdead000000000000000000000000000000000000",
|
|
"0x00000000000000000000000000000000deadbeef",
|
|
]);
|
|
|
|
function isBurnAddress(address) {
|
|
return BURN_ADDRESSES.has(address.toLowerCase());
|
|
}
|
|
|
|
module.exports = {
|
|
DEBUG,
|
|
BUILD_DEBUG_MARKER,
|
|
DEBUG_MNEMONIC,
|
|
ETHEREUM_MAINNET_CHAIN_ID,
|
|
ETHEREUM_SEPOLIA_CHAIN_ID,
|
|
DEFAULT_RPC_URL,
|
|
DEFAULT_BLOCKSCOUT_URL,
|
|
BIP44_ETH_PATH,
|
|
ERC20_ABI,
|
|
BURN_ADDRESSES,
|
|
isBurnAddress,
|
|
};
|