Skip to content

Transaction inputs that are commands should also be confirmed #29

Description

@ImplOfAnImpl

Currently only transaction outputs are shown to the user, so basically every tx containing a command looks like a simple transfer to the user. This is exploitable by a compromised host, e.g.:

  • The user can be tricked into signing a token-related command that they didn't intend to sign.
  • FillOrder inputs, which don't require signatures, are exploitable too - the user can be tricked into filling a wrong order, with a bad ask/give ratio.
  • Etc.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions