You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A device-code approval with expiry: 0 could return a valid non-expiring authorization but leave zero in local metadata, causing Accounts to discard it as expired. Normalize zero when preparing, importing, updating, and hydrating grants, and recognize legacy zero metadata during selection.
Omitted limits/scopes remain unrestricted; explicit empty lists remain restrictive. Finite expiries and on-chain missing/revoked-key checks retain their semantics. No new permissions or admin authority are introduced.
The base dependency tree subsequently failed the required audit with 11 active advisories. Update vulnerable transitive packages to published fixes, and replace the @istanbuljs/load-nyc-config YAML dependency with API-compatible js-yaml v4 to remove unpatched sprintf-js. Audit exclusions, trust policy, and CI gates are unchanged.
Validation:
Original implementation passed all 1,267 runtime tests across 49 files in CI, plus TypeScript and focused local tests.
The device-code fixture checks root signatures, canonical RPC expiry, reload/future selection, chain isolation, omitted/empty permissions, denial/timeout, and failed/successful revocation forwarding.
Updated dependency tree: frozen install succeeds and pnpm audit exits 0 with no active advisories (four previously ignored high findings remain).
Compatibility smoke checks pass for NYC YAML config loading with extends/arrays/scalars and KaTeX rendering with untrusted URL restrictions.
Updated-head pnpm -w check, pnpm -w build, and full pnpm check:types pass. Pure suite passes 641 tests in 40 files.
Full hosted runtime/localnet and required Checks must pass before merge.
The HTTP fixture uses a synthetic root and keystore. CI uses localnet; no real funds or user credentials are used by the tests.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A device-code approval with
expiry: 0could return a valid non-expiring authorization but leave zero in local metadata, causing Accounts to discard it as expired. Normalize zero when preparing, importing, updating, and hydrating grants, and recognize legacy zero metadata during selection.Omitted limits/scopes remain unrestricted; explicit empty lists remain restrictive. Finite expiries and on-chain missing/revoked-key checks retain their semantics. No new permissions or admin authority are introduced.
The base dependency tree subsequently failed the required audit with 11 active advisories. Update vulnerable transitive packages to published fixes, and replace the
@istanbuljs/load-nyc-configYAML dependency with API-compatible js-yaml v4 to remove unpatched sprintf-js. Audit exclusions, trust policy, and CI gates are unchanged.Validation:
pnpm auditexits 0 with no active advisories (four previously ignored high findings remain).pnpm -w check,pnpm -w build, and fullpnpm check:typespass. Pure suite passes 641 tests in 40 files.The HTTP fixture uses a synthetic root and keystore. CI uses localnet; no real funds or user credentials are used by the tests.