Skip to content

[Security] SendTokensScreen sends an irreversible Stellar payment on a single button tap — no confirmation step #149

Description

@cybermax4200

Why this matters now

Token sending is a shipped feature powering real ECO / XLM payments. There is no confirmation dialog before signAndSubmitPayment or openLobstrForPayment is called. A single accidental tap, a mis-pasted address, or a wrong amount results in an irreversible on-chain transaction with no recourse. This is a UX-level security issue — the severity is higher than it first appears because in-app wallet users have no hardware confirmation step (unlike Ledger), and Lobstr's own confirmation dialog may be dismissed without reading.

Problem / What

src/screens/SendTokensScreen.tsx — handleSend:

const handleSend = useCallback(async () => {
  // validates inputs...
  setIsSending(true);
  try {
    // ... directly calls signAndSubmitPayment or openLobstrForPayment
    // No Alert.confirm or confirmation screen shown first
  }
}, [...]);

The fix is to show a confirmation Alert (React Native's Alert.alert with "Cancel" and "Confirm" buttons) after validation passes, displaying the destination, amount, and asset, before setIsSending(true) is called. For in-app wallets, the confirmation must appear before signPaymentXDR is called (signing is also irreversible in the sense that signed XDRs should not be left floating).

Key Challenges

Acceptance Criteria

  • A confirmation Alert appears after input validation with: truncated destination, full amount, asset name.
  • "Cancel" dismisses the alert and resets isSending to false.
  • "Confirm" proceeds to signing and submission.
  • Both the in-app wallet path and the Lobstr path show the confirmation.
  • Tests (can be added to the existing [Testing] Zero test coverage for SendTokensScreen — payment signing and Lobstr delegation #82 test file once that issue is worked): confirm dialog is shown, cancel aborts the send, confirm proceeds.

Relevant files / functions

  • src/screens/SendTokensScreen.tsx — handleSend
  • src/services/stellar.ts — signAndSubmitPayment
  • src/services/lobstr.ts — openLobstrForPayment

Out of scope

  • Implementing a dedicated "Review Transaction" screen (the Alert is sufficient for v0.3).
  • Fee estimation display.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions