fix(tron): report the MetaMask origin as lowercase - #392
Conversation
MetaMask-initiated operations reported their origin as `MetaMask`, while the keyring methods are granted to `metamask` and the other non-EVM snaps use the lowercase value. Because `TransactionScanService` only maps `metamask` to `https://metamask.io`, Tron transaction scan requests were sent with the literal `MetaMask` origin instead. - Add a `METAMASK_ORIGIN` constant and use it for every MetaMask-initiated origin (unified send, confirmations, submitted/finalized tracking). - Reuse the constant in `TransactionScanService` so the normalization applies. - Keep displaying `MetaMask` in the confirmation UI via `formatOrigin`.
e95b77b to
5669b46
Compare
Reformat the files touched by the previous commit so `yarn lint:misc:check` passes: reorder the `formatOrigin` import and unwrap two `expect` calls.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The confirmation handler converts the lowercase origin back to MetaMask before the security scan, leaving the reported scan origin incorrect.
Review effort: Balanced
Findings: 1
What changed in this PR
Canonicalizes MetaMask-initiated Tron operations to the lowercase metamask origin.
Changes:
- Adds and applies a shared
METAMASK_ORIGINconstant. - Preserves the user-facing
MetaMasklabel viaformatOrigin. - Adds normalization tests and updates the changelog and bundle checksum.
| File | Description |
|---|---|
packages/tron-wallet-snap/src/constants/index.ts |
Defines the canonical origin. |
packages/tron-wallet-snap/src/handlers/clientRequest/clientRequest.ts |
Updates unified-send origins. |
packages/tron-wallet-snap/src/handlers/clientRequest/clientRequest.test.ts |
Updates unified-send expectations. |
packages/tron-wallet-snap/src/handlers/cronjob/cronjob.tsx |
Updates finalized-event origin. |
packages/tron-wallet-snap/src/handlers/cronjob/cronjob.test.tsx |
Updates cron expectations. |
packages/tron-wallet-snap/src/services/confirmation/ConfirmationHandler.ts |
Updates claim confirmation origin. |
packages/tron-wallet-snap/src/services/confirmation/ConfirmationHandler.test.ts |
Updates confirmation expectations. |
packages/tron-wallet-snap/src/services/send/SendService.ts |
Changes the default send origin. |
packages/tron-wallet-snap/src/services/send/SendService.test.ts |
Updates send analytics expectations. |
packages/tron-wallet-snap/src/services/transaction-scan/TransactionScanService.ts |
Reuses the shared origin constant. |
packages/tron-wallet-snap/src/services/transaction-scan/TransactionScanService.test.ts |
Tests origin normalization. |
packages/tron-wallet-snap/src/ui/confirmation/views/ConfirmTransactionRequest/render.tsx |
Updates default confirmation context. |
packages/tron-wallet-snap/src/ui/confirmation/views/ConfirmTransactionRequest/render.test.tsx |
Updates render expectations. |
packages/tron-wallet-snap/src/ui/confirmation/views/ConfirmTransactionRequest/ConfirmTransactionRequest.tsx |
Formats the displayed origin. |
packages/tron-wallet-snap/src/ui/confirmation/views/ConfirmTransactionRequest/ConfirmTransactionRequest.test.tsx |
Uses the canonical test origin. |
packages/tron-wallet-snap/snap.manifest.json |
Updates the bundle checksum. |
packages/tron-wallet-snap/CHANGELOG.md |
Documents the fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
`confirmTransactionRequest` formatted the origin before handing it to the confirmation view, and the view passes the stored origin straight to the transaction scan. The scan normalizes only the lowercase `metamask` to `https://metamask.io`, so every MetaMask-initiated scan was sent the literal `MetaMask` and never resolved to the MetaMask URL, both on the initial scan and on each background refresh. Keep the raw origin in the interface context and format it only at the display leaf, matching `ConfirmSignTransaction` and `ConfirmSignMessage`. `ConfirmTransactionRequest` already renders `formatOrigin(origin)`, so the user-facing label is unchanged.
|
@metamaskbot publish-preview |
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
taran-a
left a comment
There was a problem hiding this comment.
LGTM, GG. just couple tiny comments/questions.
`mm-snap build` regenerates `source.shasum`, and CI already ignores shasum-only drift: require-clean-working-directory skips it and require-correct-shasum only enforces it on release PRs. Drop the restamped value so this fix does not carry a build artifact. Ratchet the coverage thresholds.
|




Explanation
MetaMask-initiated operations in the Tron snap reported their origin as the literal string
MetaMask. That value is wrong in two ways. First, the keyring methods are actually granted tometamask(viaDEFAULT_METAMASK_ORIGIN), soonKeyringRequestalways receives the lowercase origin, and the other non-EVM snaps (Bitcoin, Solana, Stellar) consistently usemetamaskas well. Second,TransactionScanServiceonly maps the lowercasemetamasktohttps://metamask.iobefore calling the security alerts API, so Tron'sMetaMaskfell through that normalization and was sent verbatim, misattributing every MetaMask-initiated Tron scan.The fix introduces a single
METAMASK_ORIGIN = 'metamask'constant and uses it for every MetaMask-initiated origin: the unified send flow'sTransaction Submittedtracking, the confirmation context passed toconfirmTransactionRequest, theconfirmSignTransactioncontext, and theTransaction Finalizedevent emitted by the background tracker.SendService.signAndSendTransaction's default parameter now uses the same constant.TransactionScanServiceimports the constant instead of declaring its own private copy, so the normalization it already performed now actually applies to these call sites.The confirmation UI keeps displaying
MetaMaskto the user:ConfirmTransactionRequestnow renders the origin through the existing case-insensitiveformatOriginhelper, so the stored and reported value is the lowercase canonical origin while the displayed label is unchanged.ConfirmSignTransactionalready usedformatOrigin.The result is that MetaMask-initiated Tron scans are correctly attributed to
https://metamask.io, the analytics origin matches the value used by the other non-EVM snaps, and the user-facing confirmation is unaffected.References
Checklist