fix(solana): decode a dApp transaction before asking the user to approve it - #152
Open
BitHighlander wants to merge 1 commit into
Open
BitHighlander wants to merge 1 commit into
BitHighlander wants to merge 1 commit into
Conversation
…ove it The approval card read unsignedTx.payment, and buildEvent() never set unsignedTx for a dApp-supplied Solana transaction, so a real transfer rendered as TO: N/A / AMOUNT: N/A. Worse, approval was collected BEFORE the vault's decode ran inside its signing gate, so the user approved a blind screen before any readable review existed anywhere. - vault: POST /solana/decode-transaction (separate PR) runs the same decoder as the signing gate, with no device and no signing - solana_signTransaction and solana_signAndSendTransaction now decode first and attach the result to the event, then ask for approval - the card gets a Solana branch: instruction list, blind-signing warning, unresolved-ALT warning, and a red refusal banner on a decode failure — never a friendly summary from a partial parse - the generic To/Amount table is never used for Solana again - Raw tab falls back to the request when unsignedTx is absent Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found while driving SoltoshiDICE with a funded mainnet wallet: approving a
solana_signTransactionshowed TO: N/A / AMOUNT: N/A over a real transfer. Diagnosis inHANDOFF_solana_tx_unreviewable_in_client.md; I verified its three load-bearing claims against the code before writing this.Two bugs
buildEvent()never setunsignedTx, andRequestDetailsCardreadsunsignedTx.paymentfor its To and Amount rows, so both printed the literal "N/A".solanaHandler.ts:880, and the vault's decode, risk bar and blind-signing policy all run later, inside the signing gate. The user approved a blind screen before any readable review existed anywhere in the system.This PR
solana_signTransactionandsolana_signAndSendTransactiondecode first, attach the result to the event, and then ask for approval. Sign-and-send matters most, since the dApp broadcasts right after.transaction.requestwhenunsignedTxis absent, so a blind event still shows its bytes.Requires the vault PR
Decoding goes through a new
POST /solana/decode-transaction(keepkey/keepkey-vault, separate PR), which runs the samebuildSolanaDecodedInfothe signing gate runs — one decoder, so the two screens cannot drift. No device, no signing, not a signing route.Verified live against a patched vault:
SolanaTxParseError: …withrequiresBlindSigningConsent: true, not a summaryraw_txgives a 400 validation errorpnpm type-checkpasses (15/15),pnpm buildsucceeds, and the built background bundle contains the decode callNot covered: no automated test asserts the decode-before-approval ordering. The handler imports too much to unit test as it stands. It needs the browser check below.
Please test
dist/.🤖 Generated with Claude Code