All checks were successful
check / check (push) Successful in 55s
`make check` was green while the AddToken screen crashed on every open. `script/lint` is only `prettier --check`, so a used-but-not-imported identifier is invisible until a browser evaluates it. This adds a suite that runs the real popup in a real Chrome and treats any uncaught page error or console.error as a failure. - `script/test-e2e` (with `make test-e2e` as a thin shim) builds `dist/chrome/` and runs `tests/e2e/run.js` inside the Playwright image, pinned by digest. `playwright-core` is pinned to the matching 1.56.0 through `yarn.lock`; the two must be bumped together because the browsers ship inside the image. - Deliberately outside `script/test` and `script/check`: REPO_POLICIES caps `make test` at 20 seconds. Nothing under `tests/e2e/` is named `*.test.js`, so jest cannot pick it up either. - Launches with `channel: "chromium"`; the default headless shell silently refuses to load extensions with no error at all. The extension id is read from the service worker URL, never hardcoded. - All http(s) traffic is intercepted at the browser level and served from fixtures, so the run is deterministic and offline. Unrecognised outbound requests are reported as failures rather than allowed. - A missing build or an unavailable container fails loudly; a skip that looks like a pass is the failure mode this is meant to prevent. - One allowlisted page error, for the libsodium WASM CSP fallback tracked as #182, which is otherwise untouched here. The suite was demonstrated failing against the unfixed tree with `pageerror: showView is not defined` and `pageerror: addressDotHtml is not defined`, so it carries the two one-line import fixes it caught: closes #150 — `showView` restored to the destructure in `src/popup/views/addToken.js`, dropped bya22f33d, which made the AddToken screen unreachable and corrupted the navigation stack. closes #151 — `addressDotHtml` restored in `src/popup/views/transactionDetail.js`, dropped bydf031fd, which threw before `showView("transaction")` for every ERC-20 transfer. The shared `renderAddressHtml` helper is not used here on purpose: it hardcodes the `/address/` explorer URL, and this row needs the token-specific `/token/` link.
94 lines
4.9 KiB
Markdown
94 lines
4.9 KiB
Markdown
# Workflow
|
|
|
|
- branch (from `main`)
|
|
- do the work in Next Step
|
|
- move Next Step to the top of Completed Steps
|
|
- move the top item of Future Steps into Next Step
|
|
- commit (`TODO.md` changes in the same commit as the work)
|
|
- merge to `main` if the branch is not protected, otherwise open a PR
|
|
- push
|
|
|
|
# Status
|
|
|
|
pre-1.0, working towards the 1.0.0 milestone. Tagged v0.1.0 on 2026-02-27. No
|
|
other branch is in flight: the settings About well landed as #145 on 2026-07-26
|
|
and scripts-to-rule-them-all landed as #148, so the `scripts/` directory
|
|
question is resolved. Full policy file set present. `make check` verified
|
|
passing on `main` at `23aeae4` on 2026-08-09. The 1.0.0 backlog is filed as
|
|
#149-#168. A real-browser end-to-end suite (`make test-e2e`) now sits alongside
|
|
`make check`, which cannot see a runtime `ReferenceError` in a popup view.
|
|
|
|
# Next Step
|
|
|
|
Land #149: make `DEBUG` a build-time constant that defaults to off, injected as
|
|
the `__BUILD_DEBUG__` esbuild define from `AUTISTMASK_DEBUG=1`, so a plain
|
|
`make build` stops handing every newly created wallet the publicly committed
|
|
test recovery phrase. Branch `fix/issue-149-debug-build-flag`; PR open, awaiting
|
|
review.
|
|
|
|
# Completed Steps
|
|
|
|
- 2026-08-09: Containerized Chrome end-to-end harness (`make test-e2e` /
|
|
`script/test-e2e`) driving the real popup with all network intercepted, plus
|
|
the two used-but-not-imported crashes it caught: AddToken unreachable (#150)
|
|
and TransactionDetail broken for every ERC-20 transfer (#151). Harness
|
|
demonstrated failing before the fixes and passing after (#181).
|
|
- 2026-08-09: Reviewed the repo end to end and filed the 1.0.0 backlog
|
|
(#149-#168).
|
|
- 2026-07-26: About well in settings with build info, repo link and the version
|
|
click easter egg (#145); proper view navigation stack (#146).
|
|
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
|
|
shims, README Entrypoints section (#148)
|
|
- 2026-03-01: USD display suppressed on testnets (#142); estimated USD for ETH
|
|
in approve-tx view (#141).
|
|
- Sepolia testnet support (#137); etherscan links go to token-specific URLs
|
|
(#136).
|
|
- Transaction detail improvements: Type field and on-chain details (#130),
|
|
txid-first reordering (#133), swap display corrections (#128), expanded
|
|
confirm-tx warnings (#118).
|
|
- Dark mode theme setting (Light/Dark/System) with contrast fixes (#126);
|
|
timestamps include timezone offset (#120); layout shift audit, reserved space
|
|
for error messages (#124).
|
|
- Copy-flash visual feedback with timing tune (#113, #121); cross-wallet-type
|
|
duplicate detection (#115).
|
|
- 2026-02-27: v0.1.0 tagged.
|
|
- 2026-02-24: Initial scaffolding: popup UI, BIP-39 wallet creation via
|
|
ethers.js, wallet persistence, real ETH balances over RPC, ENS forward and
|
|
reverse resolution.
|
|
|
|
# Future Steps
|
|
|
|
- Add ESLint to `script/lint` (#152). `make check` is `prettier --check` only
|
|
and cannot catch undefined identifiers, which is how #150 and #151 shipped.
|
|
- Decide the libsodium backend that actually ships (#182) and delete the single
|
|
allowlist entry it owns in `tests/e2e/harness.js`.
|
|
- Extend the end-to-end suite to the dApp approval signing path (EIP-1193
|
|
through the real content script, background worker and approval popup), and
|
|
decide separately whether docker-in-docker makes `make test-e2e` runnable in
|
|
the Gitea workflow.
|
|
- Make the Firefox target functional: Chrome callback APIs are used against the
|
|
promise-only `browser` namespace (#153).
|
|
- Send and transaction-flow correctness: gas fee excluded from the
|
|
insufficient-balance check (#154), WaitTx 60s timeout overwriting a rendered
|
|
success screen (#155), last-wallet deletion leaving inconsistent state (#156).
|
|
- Security: plaintext password crossing the extension messaging boundary during
|
|
dApp approvals (#157); MV3 service worker termination killing the background
|
|
refresh and the 24h phishing list update (#158).
|
|
- Test the crypto core — `wallet.js` derivation and `vault.js` encryption (#159)
|
|
— and the address-poisoning defense in `transactions.js` (#160).
|
|
- Wallet features for 1.0: show a wallet's recovery phrase behind the password
|
|
(#161), delete an address from an HD wallet (#162).
|
|
- Docs: `docs/README.md` contradicts the code on external services and names
|
|
competitors (#163); README Screen Map omits three shipped screens (#164).
|
|
- Owner decisions: Sepolia support versus "Non-Goals for 1.0", and `isMetaMask`
|
|
naming a competitor in shipped code (#165).
|
|
- Repo policy compliance sweep: test rerun pattern, `yarn`/`npx`, frozen
|
|
lockfile, undocumented Makefile targets (#166).
|
|
- Prune the 24 stale remote feature branches (#167).
|
|
- Remove dead exports and de-duplicate copy-pasted view helpers (#168).
|
|
- Pre-1.0 security review of the extension (key handling, DEBUG mode policy, RPC
|
|
input validation) before any 1.0rc tag; #149 and #157 are parts of it, but the
|
|
review is broader than either.
|
|
- Cut 1.0.0 once the milestone is empty, then continue tagging as milestones
|
|
land.
|