refactor(tron-wallet-snap): assert supported networks at handler boundaries instead of casting - #394
ulissesferreira wants to merge 7 commits into
Conversation
0ddf3d2 to
995dd3d
Compare
995dd3d to
08849c2
Compare
090e695 to
7a86d64
Compare
…daries instead of casting
- Assert supported networks where data enters the snap: manifest scopes, AssetsController assets, Token API filtering and TrackTransaction background event params. - Carry the validated `Network` type instead of re-casting: sign renderers take `TronWalletKeyringRequest`, send uses `asset.network`, staking and zero-balance assets use `getAssetNetwork`. - Add `TronKeyringAccount` with `scopes: Network[]` for stored accounts; it remains assignable to the emitted `KeyringAccount`. - Build CAIP asset types from `Network` instead of `TrxScope`. - Add a lint rule banning casts to `Network` or `TrxScope` in the Tron snap.
Per review, keep the root ESLint config untouched: the no-tron-network-casts rule block and the shared no-enums selector extraction are dropped.
…ues(Network) The config structs validate the clients' baseUrls as record(NetworkStruct, UrlStruct), so keys are guaranteed to be supported networks. Iterating Object.values(Network) keeps that typing end to end, removing the Object.entries key-widening that previously forced a runtime isSupportedNetwork guard (and, before this PR, an 'as Network' cast).
7a86d64 to
33731fa
Compare
|
There was a problem hiding this comment.
When working locally on each Snap we should have narrowed types for certain locally stored things that we know are chain specific. Keyring accounts are a good example.
There was a problem hiding this comment.
The previous code's direct access to baseUrl was nice but doesn't play well with typescript because network always gets casted as string.
There was a problem hiding this comment.
The previous code's direct access to baseUrl was nice but doesn't play well with typescript because network always gets casted as string.
98a9bbe to
746f36f
Compare
|
Superseded by #402 — the branch was renamed to |



Explanation
The Tron Snap handled scopes and networks coming from untrusted boundaries (RPC request params, the Keyring API) with forced casts (
chainId as Network,scope as Network), silently accepting values the Snap does not control and indexingNetworks[...]with them.This PR replaces those casts with runtime assertions at the handler boundary, matching how other request fields are validated:
isNetwork(type guard) andassertNetwork(throwsInvalidParamsError) next toNetworkinconstants.ClientRequestHandler: the fourchainId as Networkcasts (onAmountInput,confirmSend,claimUnstakedTrx,claimTrxStakingRewards) now useassertNetwork(chainId).KeyringHandler.resolveAccountAddress: the extension-providedscopeis asserted instead of cast.Follow-up work (out of scope): collapse the remaining internally-consistent casts (
SendService,StakingService, asset mappers) and the config/manifest-derived casts by flowingNetworkdown from these boundaries.Ticket: WPN-2217
References
Based on the review thread in #388. This PR is intended to serve as the base that #388 builds on.
Checklist