fix: throw instead of return in sendRequestToSubAccountSigner and harden spend-permission production guard#346
Open
erhnysr wants to merge 1 commit into
Conversation
…den production guard
Collaborator
🟡 Heimdall Review Status
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #326. Fixes #325.
Changes
1. sendRequestToSubAccountSigner: return → throw (#326)
Signer.ts:795usedreturn standardErrors.provider.unauthorized()inside a catch block. SincestandardErrors.provider.unauthorized()is a factory that returns anEthereumProviderErrorobject, the async function's Promise resolved successfully with the error object as its value instead of rejecting. The caller's catch block never fired, so the error was silently swallowed and returned to the dApp as if it were a valid RPC result.Changed to
throwso the Promise rejects and the caller handles the error correctly.2. createSpendPermissionTypedDataWithSeconds: console.warn → throw (#325)
The production guard in
utils.ts:126usedconsole.warn, which is invisible in production logging pipelines and does not prevent the function from returning valid typed data. A developer who accidentally ships a call to this test-only function in production receives a fully-formedSpendPermissionTypedDatathat can be signed and submitted on-chain.Changed to
throw new Error()so production callers fail fast and loudly.