Repository navigation
fix: align paykit auth sheet with figma #880
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
e1695d3
1ee9d64
301f2c5
12e44e9
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -621,4 +621,10 @@ private func XCTAssertThrowsErrorAsync( | |
| _ = try await expression() | ||
| XCTFail("Expected expression to throw", file: file, line: line) | ||
| } catch {} | ||
|
|
||
| func testRequestTextLosesAccentMarkupEvenWhenTagsAreNested() { | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [LOW] Accent-tag test is nested where XCTest will not run it Trigger: Mechanism: Consequence: a regression in Expected behavior: declare the test as a method on Evidence basis: source analysis of |
||
| XCTAssertEqual(pubkyAuthLiteralText("<accent>evil</accent>.app"), "evil.app") | ||
| XCTAssertEqual(pubkyAuthLiteralText("<acc<accent>ent>evil</acc</accent>ent>.app"), "evil.app") | ||
| XCTAssertEqual(pubkyAuthLiteralText("app.paykit.server"), "app.paykit.server") | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| Pubky authorization dialogs now name the requesting service, group permissions and details under clear headings, and show a compact profile card. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[MEDIUM] Consent sentence rewrites requester ids that contain placeholders
Trigger: a Paykit auth URL whose client id or service path contains another consent placeholder, such as
cid={service}withcaps=/pub/paykit/:rw, orcid=bank.comwithcaps=/pub/{clientId}/:rw.ClientId::newin pubky-common 0.15.0 (paykit-rs2ea4b2b) accepts any non-empty string up to 253 characters, and storage paths allow{in a segment.Mechanism:
descriptionTextandsuccessDescriptionTextpass those values throught(), which replaces{clientId},{service}, and{pubky}withreplacingOccurrencesand then keeps scanning the result for the remaining keys. Dictionary order is not fixed.pubkyAuthLiteralTextonly removes<accent>tags, so a value such as{service}is inserted and can be replaced by the service name. The same pass can turn a service name of{clientId}into the client id, and on the success sentence a client id containing{pubky}can include the truncated pubky.Consequence: this path would name a different requester or service than the grant. The lead sentence is now the only client-id display, so a
cidof{service}can read aspaykitwhile the authorized client id remains{service}. The permission row still shows the raw path, but not the client id.Expected behavior: show the requester id and service name literally, including
{service},{clientId}, and{pubky}. Substitute each template placeholder from the original string only, without scanning inserted values. Android already does that with positional%sarguments.Evidence basis: source analysis of
t()and the two call sites at12e44e9, plus the same replacement sequence checked outside the app. The iOS UI was not run. Run Tests does not cover this input.