Conversation
fix: harden crypto, extension privacy, and relayer validation
- Fix ancore-org#1393: Replace hardcoded balance in router with real HomeScreen component - Fix ancore-org#1396: Replace hardcoded permissions in AddSessionKeyDialog with PermissionSelector - Fix ancore-org#1394: Remove dead SessionKeysFlow.tsx file - Fix ancore-org#1397: Update signAuthEntry to return full signed entry XDR instead of bare signature Closes ancore-org#1393 Closes ancore-org#1394 Closes ancore-org#1396 Closes ancore-org#1397
|
@Hahfyeex Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🐛 Issues Fixed
#1393 - Live
/homeroute displays hardcoded fake balanceProblem: The router's inline
HomeScreen()component rendered a hardcoded1,245.80 XLMbalance, while the realHomeScreen.tsxwith proper balance fetching viauseAccountBalance(fixed in #1228/#1286) was never imported or used.Solution: Imported and used the real
HomeScreencomponent that properly fetches live balances from the network.Files changed:
apps/extension-wallet/src/router/index.tsx#1396 - PermissionSelector.tsx is unused duplicate code
Problem: A reusable
PermissionSelectorcomponent built on@ancore/account-abstraction's bitmask helpers existed but was never imported. Instead,AddSessionKeyDialog.tsxhand-rolled its own hardcoded permission array with duplicate logic.Solution: Refactored
AddSessionKeyDialogto use the existingPermissionSelectorcomponent, eliminating code duplication and ensuring consistency with the canonical permission system.Files changed:
apps/extension-wallet/src/screens/SessionKeys/AddSessionKeyDialog.tsx#1394 - SessionKeysFlow.tsx is fully dead code
Problem: A 133-line component file (
SessionKeysFlow.tsx) with its own local types had zero importers across the entire codebase. The router uses the separateSessionKeysScreen.tsxinstead.Solution: Deleted the unused file to reduce maintenance burden and codebase complexity.
Files changed:
apps/extension-wallet/src/screens/SessionKeys/SessionKeysFlow.tsx(deleted)#1397 - signAuthEntry returns bare signature, not full signed entry XDR
Problem: The
signAuthEntryfunction's JSDoc promised to return "the full signed entry XDR" but the implementation discarded the decoded entry and returned only raw signature bytes as base64. This violated SEP-43 expectations and had a TODO(#770) acknowledging the gap.Solution: Implemented proper XDR construction:
SorobanAddressCredentialswith the signatureSorobanAuthorizationEntrywith embedded credentialsFiles changed:
apps/extension-wallet/src/background/handlers/sign-auth-entry.ts📊 Impact
✅ Testing
/homeroute displays real account balance (not hardcoded 1,245.80 XLM)signAuthEntryreturns validSorobanAuthorizationEntryXDRCloses #1393
Closes #1394
Closes #1396
Closes #1397