MetaMask / MetaMask/metamask-extension
feat: warn users when `personal_sign` message contains the string "wants you to sign in with your Ethereum account"
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
### What is this about?
Complete the following requirement of https://github.com/MetaMask/MetaMask-planning/issues/2278:
[ ] Ensure we warn the user when a personal_sign message contains the string "wants you to sign in with your Ethereum account". (see first recommendation here: https://eips.ethereum.org/EIPS/eip-4361#wallet-implementer-steps)
### Scenario
_No response_
### Design
We can use a warning banner alert for this. Copy and details should be discussed with design
### Technical Details
_No response_
### Threat Modeling Framework
_No response_
### Acceptance Criteria
_No response_
### Stakeholder review needed before the work gets merged
- [ ] Engineering (needed in most cases)
- [ ] Design
- [ ] Product
- [ ] QA (automation tests are required to pass before merging PRs but not all changes are covered by automation tests - please review if QA is needed beyond automation tests)
- [ ] Security
- [ ] Legal
- [ ] Marketing
- [ ] Management (please specify)
- [ ] Other (please specify)
### References
_No response_
Contributor guide
Research direction
No file, test, or entry point is named. Locate the personal_sign handling and existing warning-banner components, then review the EIP-4361 wallet implementer steps and the design discussion. Done means the specified message string triggers a user warning with agreed copy and appropriate automated coverage.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100