Permission System 2.0 (#12243)
# Permission System 2.0
## Background
This PR migrates the extension permission system to [the new `PermissionController`](https://github.com/MetaMask/snaps-skunkworks/tree/main/packages/controllers/src/permissions).
The original permission system, based on [`rpc-cap`](https://github.com/MetaMask/rpc-cap), introduced [`ZCAP-LD`](https://w3c-ccg.github.io/zcap-ld/)-like permissions to our JSON-RPC stack.
We used it to [implement](https://github.com/MetaMask/metamask-extension/pull/7004) what we called "LoginPerSite" in [version 7.7.0](https://github.com/MetaMask/metamask-extension/releases/tag/v7.7.0) of the extension, which enabled the user to choose which accounts, if any, should be exposed to each dapp.
While that was a worthwhile feature in and of itself, we wanted a permission _system_ in order to enable everything we are going to with Snaps.
Unfortunately, the original permission system was difficult to use, and necessitated the creation of the original `PermissionsController` (note the "s"), which was more or less a wrapper for `rpc-cap`.
With this PR, we shake off the yoke of the original permission system, in favor of the modular, self-contained, ergonomic, and more mature permission system 2.0.
Note that [the `PermissionController` readme](https://github.com/MetaMask/snaps-skunkworks/tree/main/packages/controllers/src/permissions/README.md) explains how the new permission system works.
The `PermissionController` and `SubjectMetadataController` are currently shipped via `@metamask/snap-controllers`. This is a temporary state of affairs, and we'll move them to `@metamask/controllers` once they've landed in prod.
## Changes in Detail
First, the changes in this PR are not as big as they seem. Roughly half of the additions in this PR are fixtures in the test for the new migration (number 68), and a significant portion of the remaining ~2500 lines are due to find-and-replace changes in other test fixtures and UI files.
- The extension `PermissionsController` has been deleted, and completely replaced with the new `PermissionController` from [`@metamask/snap-controllers`](https://www.npmjs.com/package/@metamask/snap-controllers).
- The original `PermissionsController` "domain metadata" functionality is now managed by the new `SubjectMetadataController`, also from [`@metamask/snap-controllers`](https://www.npmjs.com/package/@metamask/snap-controllers).
- The permission activity and history log controller has been renamed `PermissionLogController` and has its own top-level state key, but is otherwise functionally equivalent to the existing implementation.
- Migration number 68 has been added to account for the new state changes.
- The tests in `app/scripts/controllers/permissions` have been migrated from `mocha` to `jest`.
Reviewers should focus their attention on the following files:
- `app/scripts/`
- `metamask-controller.js`
- This is where most of the integration work for the new `PermissionController` occurs.
Some functions that were internal to the original controller were moved here.
- `controllers/permissions/`
- `selectors.js`
- These selectors are for `ControllerMessenger` selector subscriptions. The actual subscriptions occur in `metamask-controller.js`. See the `ControllerMessenger` implementation for details.
- `specifications.js`
- The caveat and permission specifications are required by the new `PermissionController`, and are used to specify the `eth_accounts` permission and its JSON-RPC method implementation.
See the `PermissionController` readme for details.
- `migrations/068.js`
- The new state should be cross-referenced with the controllers that manage it.
The accompanying tests should also be thoroughly reviewed.
Some files may appear new but have just moved and/or been renamed:
- `app/scripts/lib/rpc-method-middleware/handlers/request-accounts.js`
- This was previously implemented in `controllers/permissions/permissionsMethodMiddleware.js`.
- `test/mocks/permissions.js`
- A truncated version of `test/mocks/permission-controller.js`.
Co-authored-by: Mark Stacey <markjstacey@gmail.com>
3 years ago
|
|
|
import { ethErrors } from 'eth-rpc-errors';
|
|
|
|
import { MESSAGE_TYPE } from '../../../../../shared/constants/app';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* This method attempts to retrieve the Ethereum accounts available to the
|
|
|
|
* requester, or initiate a request for account access if none are currently
|
|
|
|
* available. It is essentially a wrapper of wallet_requestPermissions that
|
|
|
|
* only errors if the user rejects the request. We maintain the method for
|
|
|
|
* backwards compatibility reasons.
|
|
|
|
*/
|
|
|
|
|
|
|
|
const requestEthereumAccounts = {
|
|
|
|
methodNames: [MESSAGE_TYPE.ETH_REQUEST_ACCOUNTS],
|
|
|
|
implementation: requestEthereumAccountsHandler,
|
|
|
|
hookNames: {
|
|
|
|
origin: true,
|
|
|
|
getAccounts: true,
|
|
|
|
getUnlockPromise: true,
|
|
|
|
hasPermission: true,
|
|
|
|
requestAccountsPermission: true,
|
|
|
|
},
|
|
|
|
};
|
|
|
|
export default requestEthereumAccounts;
|
|
|
|
|
|
|
|
// Used to rate-limit pending requests to one per origin
|
|
|
|
const locks = new Set();
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @typedef {Record<string, string | Function>} RequestEthereumAccountsOptions
|
|
|
|
* @property {string} origin - The requesting origin.
|
|
|
|
* @property {Function} getAccounts - Gets the accounts for the requesting
|
|
|
|
* origin.
|
|
|
|
* @property {Function} getUnlockPromise - Gets a promise that resolves when
|
|
|
|
* the extension unlocks.
|
|
|
|
* @property {Function} hasPermission - Returns whether the requesting origin
|
|
|
|
* has the specified permission.
|
|
|
|
* @property {Function} requestAccountsPermission - Requests the `eth_accounts`
|
|
|
|
* permission for the requesting origin.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
*
|
|
|
|
* @param {import('json-rpc-engine').JsonRpcRequest<unknown>} _req - The JSON-RPC request object.
|
|
|
|
* @param {import('json-rpc-engine').JsonRpcResponse<true>} res - The JSON-RPC response object.
|
|
|
|
* @param {Function} _next - The json-rpc-engine 'next' callback.
|
|
|
|
* @param {Function} end - The json-rpc-engine 'end' callback.
|
|
|
|
* @param {RequestEthereumAccountsOptions} options - The RPC method hooks.
|
|
|
|
*/
|
|
|
|
async function requestEthereumAccountsHandler(
|
|
|
|
_req,
|
|
|
|
res,
|
|
|
|
_next,
|
|
|
|
end,
|
|
|
|
{
|
|
|
|
origin,
|
|
|
|
getAccounts,
|
|
|
|
getUnlockPromise,
|
|
|
|
hasPermission,
|
|
|
|
requestAccountsPermission,
|
|
|
|
},
|
|
|
|
) {
|
|
|
|
if (locks.has(origin)) {
|
|
|
|
res.error = ethErrors.rpc.resourceUnavailable(
|
|
|
|
`Already processing ${MESSAGE_TYPE.ETH_REQUEST_ACCOUNTS}. Please wait.`,
|
|
|
|
);
|
|
|
|
return end();
|
|
|
|
}
|
|
|
|
|
|
|
|
if (hasPermission(MESSAGE_TYPE.ETH_ACCOUNTS)) {
|
|
|
|
// We wait for the extension to unlock in this case only, because permission
|
|
|
|
// requests are handled when the extension is unlocked, regardless of the
|
|
|
|
// lock state when they were received.
|
|
|
|
try {
|
|
|
|
locks.add(origin);
|
|
|
|
await getUnlockPromise(true);
|
Permission System 2.0 (#12243)
# Permission System 2.0
## Background
This PR migrates the extension permission system to [the new `PermissionController`](https://github.com/MetaMask/snaps-skunkworks/tree/main/packages/controllers/src/permissions).
The original permission system, based on [`rpc-cap`](https://github.com/MetaMask/rpc-cap), introduced [`ZCAP-LD`](https://w3c-ccg.github.io/zcap-ld/)-like permissions to our JSON-RPC stack.
We used it to [implement](https://github.com/MetaMask/metamask-extension/pull/7004) what we called "LoginPerSite" in [version 7.7.0](https://github.com/MetaMask/metamask-extension/releases/tag/v7.7.0) of the extension, which enabled the user to choose which accounts, if any, should be exposed to each dapp.
While that was a worthwhile feature in and of itself, we wanted a permission _system_ in order to enable everything we are going to with Snaps.
Unfortunately, the original permission system was difficult to use, and necessitated the creation of the original `PermissionsController` (note the "s"), which was more or less a wrapper for `rpc-cap`.
With this PR, we shake off the yoke of the original permission system, in favor of the modular, self-contained, ergonomic, and more mature permission system 2.0.
Note that [the `PermissionController` readme](https://github.com/MetaMask/snaps-skunkworks/tree/main/packages/controllers/src/permissions/README.md) explains how the new permission system works.
The `PermissionController` and `SubjectMetadataController` are currently shipped via `@metamask/snap-controllers`. This is a temporary state of affairs, and we'll move them to `@metamask/controllers` once they've landed in prod.
## Changes in Detail
First, the changes in this PR are not as big as they seem. Roughly half of the additions in this PR are fixtures in the test for the new migration (number 68), and a significant portion of the remaining ~2500 lines are due to find-and-replace changes in other test fixtures and UI files.
- The extension `PermissionsController` has been deleted, and completely replaced with the new `PermissionController` from [`@metamask/snap-controllers`](https://www.npmjs.com/package/@metamask/snap-controllers).
- The original `PermissionsController` "domain metadata" functionality is now managed by the new `SubjectMetadataController`, also from [`@metamask/snap-controllers`](https://www.npmjs.com/package/@metamask/snap-controllers).
- The permission activity and history log controller has been renamed `PermissionLogController` and has its own top-level state key, but is otherwise functionally equivalent to the existing implementation.
- Migration number 68 has been added to account for the new state changes.
- The tests in `app/scripts/controllers/permissions` have been migrated from `mocha` to `jest`.
Reviewers should focus their attention on the following files:
- `app/scripts/`
- `metamask-controller.js`
- This is where most of the integration work for the new `PermissionController` occurs.
Some functions that were internal to the original controller were moved here.
- `controllers/permissions/`
- `selectors.js`
- These selectors are for `ControllerMessenger` selector subscriptions. The actual subscriptions occur in `metamask-controller.js`. See the `ControllerMessenger` implementation for details.
- `specifications.js`
- The caveat and permission specifications are required by the new `PermissionController`, and are used to specify the `eth_accounts` permission and its JSON-RPC method implementation.
See the `PermissionController` readme for details.
- `migrations/068.js`
- The new state should be cross-referenced with the controllers that manage it.
The accompanying tests should also be thoroughly reviewed.
Some files may appear new but have just moved and/or been renamed:
- `app/scripts/lib/rpc-method-middleware/handlers/request-accounts.js`
- This was previously implemented in `controllers/permissions/permissionsMethodMiddleware.js`.
- `test/mocks/permissions.js`
- A truncated version of `test/mocks/permission-controller.js`.
Co-authored-by: Mark Stacey <markjstacey@gmail.com>
3 years ago
|
|
|
res.result = await getAccounts();
|
|
|
|
end();
|
|
|
|
} catch (error) {
|
|
|
|
end(error);
|
|
|
|
} finally {
|
|
|
|
locks.delete(origin);
|
|
|
|
}
|
|
|
|
return undefined;
|
|
|
|
}
|
|
|
|
|
|
|
|
// If no accounts, request the accounts permission
|
|
|
|
try {
|
|
|
|
await requestAccountsPermission();
|
|
|
|
} catch (err) {
|
|
|
|
res.error = err;
|
|
|
|
return end();
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get the approved accounts
|
|
|
|
const accounts = await getAccounts();
|
|
|
|
/* istanbul ignore else: too hard to induce, see below comment */
|
|
|
|
if (accounts.length > 0) {
|
|
|
|
res.result = accounts;
|
|
|
|
} else {
|
|
|
|
// This should never happen, because it should be caught in the
|
|
|
|
// above catch clause
|
|
|
|
res.error = ethErrors.rpc.internal(
|
|
|
|
'Accounts unexpectedly unavailable. Please report this bug.',
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
return end();
|
|
|
|
}
|