-
Notifications
You must be signed in to change notification settings - Fork 29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Initial work to implement Sapphire snap connection #431
base: main
Are you sure you want to change the base?
Changes from 1 commit
2969bc0
6e05c03
b34dcfc
a4fd09d
367cd7f
6f05b4c
8844dbe
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,8 +1,9 @@ | ||
// SPDX-License-Identifier: Apache-2.0 | ||
|
||
import { BytesLike } from './ethersutils.js'; | ||
import { BytesLike, hexlify } from './ethersutils.js'; | ||
import { KeyFetcher } from './calldatapublickey.js'; | ||
import { SUBCALL_ADDR, CALLDATAPUBLICKEY_CALLDATA } from './constants.js'; | ||
import { Cipher } from './cipher.js'; | ||
|
||
// ----------------------------------------------------------------------------- | ||
// https://eips.ethereum.org/EIPS/eip-2696#interface | ||
|
@@ -43,6 +44,7 @@ export function isLegacyProvider<T extends object>( | |
|
||
export interface SapphireWrapOptions { | ||
fetcher: KeyFetcher; | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Options object is optional. When provided, TS requires fetcher, but we should be able just to set |
||
enableSapphireSnap: boolean | undefined | ||
} | ||
|
||
export function fillOptions( | ||
|
@@ -80,10 +82,10 @@ export function isWrappedEthereumProvider<P extends EIP2696_EthereumProvider>( | |
* @param options (optional) Re-use parameters from other providers | ||
* @returns Sapphire wrapped provider | ||
*/ | ||
export function wrapEthereumProvider<P extends EIP2696_EthereumProvider>( | ||
export async function wrapEthereumProvider<P extends EIP2696_EthereumProvider>( | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Does it affect all integrations? For example I don't see ether-v6 is relying on |
||
upstream: P, | ||
options?: SapphireWrapOptions, | ||
): P { | ||
): Promise<P> { | ||
if (isWrappedEthereumProvider(upstream)) { | ||
return upstream; | ||
} | ||
|
@@ -99,7 +101,7 @@ export function wrapEthereumProvider<P extends EIP2696_EthereumProvider>( | |
// if we do this, don't then re-wrap the send() function | ||
// only wrap the send() function if there was a request() function | ||
|
||
const request = makeSapphireRequestFn(upstream, filled_options); | ||
const request = await makeSapphireRequestFn(upstream, filled_options); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I have reverted a change of making it all async, because async part can be handled in proxy |
||
const hooks: Record<string, unknown> = { request }; | ||
|
||
// We prefer a request() method, but a provider may expose a send() method | ||
|
@@ -124,6 +126,61 @@ export function wrapEthereumProvider<P extends EIP2696_EthereumProvider>( | |
); | ||
} | ||
|
||
// ----------------------------------------------------------------------------- | ||
// Interact with the Sapphire MetaMask Snap to provide transaction insights | ||
// This sends the encryption key on a per-transaction basis | ||
|
||
interface SnapInfoT { | ||
version: string; | ||
id: string; | ||
enabled: boolean; | ||
blocked: boolean; | ||
} | ||
|
||
const SAPPHIRE_SNAP_PNPM_ID = 'npm:@oasisprotocol/sapphire-snap'; | ||
|
||
async function detectSapphireSnap (provider: EIP2696_EthereumProvider) { | ||
try { | ||
const installedSnaps = await provider.request({method: 'wallet_getSnaps'}) as Record<string,SnapInfoT>; | ||
for( const snap of Object.values(installedSnaps) ) { | ||
if( snap.id == SAPPHIRE_SNAP_PNPM_ID ) { | ||
return snap.id; | ||
} | ||
} | ||
} | ||
catch( e:any ) { | ||
return undefined; | ||
} | ||
} | ||
|
||
async function notifySapphireSnap( | ||
snapId:string, | ||
cipher:Cipher, | ||
transactionData: BytesLike, | ||
options:SapphireWrapOptions, | ||
provider: EIP2696_EthereumProvider | ||
) { | ||
const secretKey = (cipher as any).secretKey as Uint8Array | undefined; | ||
if( secretKey ) { | ||
const peerPublicKey = await options.fetcher.fetch(provider); | ||
await provider.request({ | ||
method: 'wallet_invokeSnap', | ||
params: { | ||
snapId: snapId, | ||
request: { | ||
method: 'setTransactionDecryptKeys', | ||
params: { | ||
id: transactionData, | ||
ephemeralSecretKey: hexlify(secretKey), | ||
peerPublicKey: peerPublicKey.key, | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. hexlify |
||
peerPublicKeyEpoch: peerPublicKey.epoch | ||
} | ||
} | ||
} | ||
}); | ||
} | ||
} | ||
|
||
const SAPPHIRE_EIP1193_REQUESTFN = '#SAPPHIRE_EIP1193_REQUESTFN' as const; | ||
|
||
export function isWrappedRequestFn< | ||
|
@@ -148,35 +205,43 @@ export function isCallDataPublicKeyQuery(params?: object | readonly unknown[]) { | |
* @param options | ||
* @returns | ||
*/ | ||
export function makeSapphireRequestFn( | ||
export async function makeSapphireRequestFn( | ||
provider: EIP2696_EthereumProvider, | ||
options?: SapphireWrapOptions, | ||
): EIP2696_EthereumProvider['request'] { | ||
): Promise<EIP2696_EthereumProvider['request']> { | ||
if (isWrappedRequestFn(provider.request)) { | ||
return provider.request; | ||
} | ||
|
||
const filled_options = fillOptions(options); | ||
|
||
const snapId = filled_options.enableSapphireSnap ? await detectSapphireSnap(provider) : undefined; | ||
|
||
const f = async (args: EIP1193_RequestArguments) => { | ||
const cipher = await filled_options.fetcher.cipher(provider); | ||
const { method, params } = args; | ||
|
||
let transactionData : BytesLike | undefined = undefined; | ||
// Encrypt requests which can be encrypted | ||
if ( | ||
params && | ||
Array.isArray(params) && | ||
/^eth_((send|sign)Transaction|call|estimateGas)$/.test(method) && | ||
params[0].data // Ignore balance transfers without calldata | ||
) { | ||
params[0].data = cipher.encryptCall(params[0].data); | ||
transactionData = params[0].data = cipher.encryptCall(params[0].data); | ||
} | ||
|
||
const res = await provider.request({ | ||
method, | ||
params: params ?? [], | ||
}); | ||
|
||
if( snapId !== undefined && transactionData !== undefined ) { | ||
// Run in background so as to not delay results | ||
notifySapphireSnap(snapId, cipher, transactionData, filled_options, provider); | ||
} | ||
|
||
// Decrypt responses which return encrypted data | ||
if (method === 'eth_call') { | ||
// If it's an unencrypted core.CallDataPublicKey query, don't attempt to decrypt the response | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That's not a key we need, added
ephemeralkey
.