Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Add Multichain API to @metamask/multichain #4813

Open
wants to merge 202 commits into
base: main
Choose a base branch
from

Conversation

jiexi
Copy link
Contributor

@jiexi jiexi commented Oct 17, 2024

Explanation

This PR updates @metamask/multichain to add method handlers and middleware specific to the new Multichain API and which can be shared across the extension & mobile clients. The package includes implementations for managing multichain sessions, handling multichain RPC methods, and integrating multichain functionalities into the MetaMask extension. Key features of this package include:

  • Method Handlers: Implementations of the new RPC method handlers like wallet_createSession, wallet_invokeMethod, wallet_revokeSession, and wallet_getSession.
  • ScopesObject Transforms: Adds helpers that transform between NormalizedScopesObject and InternalScopesObject
  • Concurrent Eth Subscriptions: Adds helpers that orchestrate eth_subscriptions to numerous chains concurrently

These tools and utilities will be used in both clients (mobile + extension)'s multichain API implementations.

File Overview

  • packages/multichain/src/adapters/caip-permission-adapter-middleware.ts: Middleware for the EIP-1193 API that enforces a CAIP-25 permission for each request if that CAIP-25 permission was granted via wallet_createSession
  • packages/multichain/src/handlers/wallet-getSession.ts: Handlers for CAIP Multichain lifecycle methods except for wallet_createSession which seemed a little too platform specific to belong in a shared package currently
  • packages/multichain/src/middlewares/: Middleware for the Multichain API that helps facilitate concurrent eth subscriptions and for using @metamask/api-specs for method param validation for new CAIP Multichain methods
  • packages/multichain/src/scope/authorization.ts: Adds helpers that sort scopes based on if they are currently supported by the wallet (i.e. a network already exists the eip155 scope), if they could be supported by the wallet (i.e. the network does not already exist for the eip155 scope, but the dapp has provided EIP-3085 details for adding the network in the scopedProperties property of the wallet_createSession request), or if they cannot be served.
  • packages/multichain/src/scope/filter.ts: provides helpers used for the bucketing above in authorization.ts
  • types/@metamask/eth-json-rpc-filters.d.ts: Typedef for missing types in @metamask/eth-json-rpc-filters/subscriptionManager

References

Upstream: #4784
Downstream: None. This is the end.

Key Multichain API Standards implemented here:

Open PR that uses this new package for exposing the multichain API in the extension: MetaMask/metamask-extension#27782

Changelog

@metamask/multichain

  • ADDED: Adds getInternalScopesObject and getSessionScopes helpers for transforming between NormalizedScopesObject and InternalScopesObject.
  • ADDED: Adds caipPermissionAdapterMiddleware for enforcing CAIP-25 permission on the EIP-1193 API.
  • ADDED: Adds walletGetSession, walletInvokeMethod, and walletRevokeSession handlers.
  • ADDED: Adds multichainMethodCallValidatorMiddleware for validating Multichain API method params as defined in @metamask/api-specs.
  • ADDED: Adds MultichainMiddlewareManager to multiplex a request to other middleware based on requested scope.
  • ADDED: Adds MultichainSubscriptionManager to handle concurrent subscriptions across multiple scopes.
  • ADDED: Adds bucketScopes which groups the scopes in a NormalizedScopesObject based on if the scopes are already supported, could be supported, or are not supportable.
  • ADDED: Adds getSupportedScopeObjects helper for getting only the supported methods and notifications from each NormalizedScopeObject in a NormalizedScopesObject.

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've highlighted breaking changes using the "BREAKING" category above as appropriate
  • I've prepared draft pull requests for clients and consumer packages to resolve any breaking changes

jiexi and others added 30 commits October 10, 2024 14:02
## Explanation
This PR fixes a lot of the linting and typescript errors. still some
left but this covers a lot of it.


<!--
Thanks for your contribution! Take a moment to answer these questions so
that reviewers have the information they need to properly understand
your changes:

* What is the current state of things and why does it need to change?
* What is the solution your changes offer and how does it work?
* Are there any changes whose purpose might not obvious to those
unfamiliar with the domain?
* If your primary goal was to update one package but you found you had
to update another one along the way, why did you do so?
* If you had to upgrade a dependency, why did you do so?
-->

## References

<!--
Are there any issues that this pull request is tied to?
Are there other links that reviewers should consult to understand these
changes better?
Are there client or consumer pull requests to adopt any breaking
changes?

For example:

* Fixes #12345
* Related to #67890
-->

## Changelog

<!--
If you're making any consumer-facing changes, list those changes here as
if you were updating a changelog, using the template below as a guide.

(CATEGORY is one of BREAKING, ADDED, CHANGED, DEPRECATED, REMOVED, or
FIXED. For security-related issues, follow the Security Advisory
process.)

Please take care to name the exact pieces of the API you've added or
changed (e.g. types, interfaces, functions, or methods).

If there are any breaking changes, make sure to offer a solution for
consumers to follow once they upgrade to the changes.

Finally, if you're only making changes to development scripts or tests,
you may replace the template below with "None".
-->

### `@metamask/package-a`

- **<CATEGORY>**: Your change here
- **<CATEGORY>**: Your change here

### `@metamask/package-b`

- **<CATEGORY>**: Your change here
- **<CATEGORY>**: Your change here

## Checklist

- [ ] I've updated the test suite for new or updated code as appropriate
- [ ] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [ ] I've highlighted breaking changes using the "BREAKING" category
above as appropriate
- [ ] I've prepared draft pull requests for clients and consumer
packages to resolve any breaking changes

---------

Co-authored-by: Jiexi Luan <[email protected]>
## Explanation

<!--
Thanks for your contribution! Take a moment to answer these questions so
that reviewers have the information they need to properly understand
your changes:

* What is the current state of things and why does it need to change?
* What is the solution your changes offer and how does it work?
* Are there any changes whose purpose might not obvious to those
unfamiliar with the domain?
* If your primary goal was to update one package but you found you had
to update another one along the way, why did you do so?
* If you had to upgrade a dependency, why did you do so?
-->
Added ESM exports for multichain package

## References

<!--
Are there any issues that this pull request is tied to?
Are there other links that reviewers should consult to understand these
changes better?
Are there client or consumer pull requests to adopt any breaking
changes?

For example:

* Fixes #12345
* Related to #67890
-->

## Changelog

<!--
If you're making any consumer-facing changes, list those changes here as
if you were updating a changelog, using the template below as a guide.

(CATEGORY is one of BREAKING, ADDED, CHANGED, DEPRECATED, REMOVED, or
FIXED. For security-related issues, follow the Security Advisory
process.)

Please take care to name the exact pieces of the API you've added or
changed (e.g. types, interfaces, functions, or methods).

If there are any breaking changes, make sure to offer a solution for
consumers to follow once they upgrade to the changes.

Finally, if you're only making changes to development scripts or tests,
you may replace the template below with "None".
-->

### `@metamask/package-a`

- **<CATEGORY>**: Your change here
- **<CATEGORY>**: Your change here

### `@metamask/package-b`

- **<CATEGORY>**: Your change here
- **<CATEGORY>**: Your change here

## Checklist

- [ ] I've updated the test suite for new or updated code as appropriate
- [ ] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [ ] I've highlighted breaking changes using the "BREAKING" category
above as appropriate
- [ ] I've prepared draft pull requests for clients and consumer
packages to resolve any breaking changes
@jiexi
Copy link
Contributor Author

jiexi commented Jan 14, 2025

@metamaskbot publish-preview

Copy link
Contributor

Preview builds have been published. See these instructions for more information about preview builds.

Expand for full list of packages and versions.
{
  "@metamask-previews/accounts-controller": "21.0.0-preview-f3715655",
  "@metamask-previews/address-book-controller": "6.0.2-preview-f3715655",
  "@metamask-previews/announcement-controller": "7.0.2-preview-f3715655",
  "@metamask-previews/approval-controller": "7.1.2-preview-f3715655",
  "@metamask-previews/assets-controllers": "46.0.0-preview-f3715655",
  "@metamask-previews/base-controller": "7.1.1-preview-f3715655",
  "@metamask-previews/build-utils": "3.0.2-preview-f3715655",
  "@metamask-previews/composable-controller": "10.0.0-preview-f3715655",
  "@metamask-previews/controller-utils": "11.4.5-preview-f3715655",
  "@metamask-previews/ens-controller": "15.0.1-preview-f3715655",
  "@metamask-previews/eth-json-rpc-provider": "4.1.7-preview-f3715655",
  "@metamask-previews/gas-fee-controller": "22.0.2-preview-f3715655",
  "@metamask-previews/json-rpc-engine": "10.0.2-preview-f3715655",
  "@metamask-previews/json-rpc-middleware-stream": "8.0.6-preview-f3715655",
  "@metamask-previews/keyring-controller": "19.0.3-preview-f3715655",
  "@metamask-previews/logging-controller": "6.0.3-preview-f3715655",
  "@metamask-previews/message-manager": "11.0.3-preview-f3715655",
  "@metamask-previews/multichain": "2.0.0-preview-f3715655",
  "@metamask-previews/name-controller": "8.0.2-preview-f3715655",
  "@metamask-previews/network-controller": "22.1.1-preview-f3715655",
  "@metamask-previews/notification-services-controller": "0.16.0-preview-f3715655",
  "@metamask-previews/permission-controller": "11.0.5-preview-f3715655",
  "@metamask-previews/permission-log-controller": "3.0.2-preview-f3715655",
  "@metamask-previews/phishing-controller": "12.3.1-preview-f3715655",
  "@metamask-previews/polling-controller": "12.0.2-preview-f3715655",
  "@metamask-previews/preferences-controller": "15.0.1-preview-f3715655",
  "@metamask-previews/profile-sync-controller": "4.1.0-preview-f3715655",
  "@metamask-previews/queued-request-controller": "8.0.2-preview-f3715655",
  "@metamask-previews/rate-limit-controller": "6.0.2-preview-f3715655",
  "@metamask-previews/remote-feature-flag-controller": "1.3.0-preview-f3715655",
  "@metamask-previews/selected-network-controller": "20.0.2-preview-f3715655",
  "@metamask-previews/signature-controller": "23.2.0-preview-f3715655",
  "@metamask-previews/transaction-controller": "43.0.0-preview-f3715655",
  "@metamask-previews/user-operation-controller": "22.0.0-preview-f3715655"
}

@jiexi
Copy link
Contributor Author

jiexi commented Jan 14, 2025

@metamaskbot publish-preview

Copy link
Contributor

Preview builds have been published. See these instructions for more information about preview builds.

Expand for full list of packages and versions.
{
  "@metamask-previews/accounts-controller": "21.0.0-preview-6244b7be",
  "@metamask-previews/address-book-controller": "6.0.2-preview-6244b7be",
  "@metamask-previews/announcement-controller": "7.0.2-preview-6244b7be",
  "@metamask-previews/approval-controller": "7.1.2-preview-6244b7be",
  "@metamask-previews/assets-controllers": "46.0.0-preview-6244b7be",
  "@metamask-previews/base-controller": "7.1.1-preview-6244b7be",
  "@metamask-previews/build-utils": "3.0.2-preview-6244b7be",
  "@metamask-previews/composable-controller": "10.0.0-preview-6244b7be",
  "@metamask-previews/controller-utils": "11.4.5-preview-6244b7be",
  "@metamask-previews/ens-controller": "15.0.1-preview-6244b7be",
  "@metamask-previews/eth-json-rpc-provider": "4.1.7-preview-6244b7be",
  "@metamask-previews/gas-fee-controller": "22.0.2-preview-6244b7be",
  "@metamask-previews/json-rpc-engine": "10.0.2-preview-6244b7be",
  "@metamask-previews/json-rpc-middleware-stream": "8.0.6-preview-6244b7be",
  "@metamask-previews/keyring-controller": "19.0.3-preview-6244b7be",
  "@metamask-previews/logging-controller": "6.0.3-preview-6244b7be",
  "@metamask-previews/message-manager": "11.0.3-preview-6244b7be",
  "@metamask-previews/multichain": "2.0.0-preview-6244b7be",
  "@metamask-previews/name-controller": "8.0.2-preview-6244b7be",
  "@metamask-previews/network-controller": "22.1.1-preview-6244b7be",
  "@metamask-previews/notification-services-controller": "0.16.0-preview-6244b7be",
  "@metamask-previews/permission-controller": "11.0.5-preview-6244b7be",
  "@metamask-previews/permission-log-controller": "3.0.2-preview-6244b7be",
  "@metamask-previews/phishing-controller": "12.3.1-preview-6244b7be",
  "@metamask-previews/polling-controller": "12.0.2-preview-6244b7be",
  "@metamask-previews/preferences-controller": "15.0.1-preview-6244b7be",
  "@metamask-previews/profile-sync-controller": "4.1.0-preview-6244b7be",
  "@metamask-previews/queued-request-controller": "8.0.2-preview-6244b7be",
  "@metamask-previews/rate-limit-controller": "6.0.2-preview-6244b7be",
  "@metamask-previews/remote-feature-flag-controller": "1.3.0-preview-6244b7be",
  "@metamask-previews/selected-network-controller": "20.0.2-preview-6244b7be",
  "@metamask-previews/signature-controller": "23.2.0-preview-6244b7be",
  "@metamask-previews/transaction-controller": "43.0.0-preview-6244b7be",
  "@metamask-previews/user-operation-controller": "22.0.0-preview-6244b7be"
}

yarn.lock Outdated
@@ -3825,8 +3872,8 @@ __metadata:
linkType: hard

"@metamask/snaps-controllers@npm:^9.10.0":
version: 9.13.0
resolution: "@metamask/snaps-controllers@npm:9.13.0"
version: 9.12.0
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems like a rebase gone wrong potentially?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i've tried yarn and yarn dedupe and removing my node_modules. My yarn lock doesn't change

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

deleting my yarn.lock and running yarn and deduping again gives me this 20588ef

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this package resolves to 9.17.0 on this line now

'failed to resolve namespace for wallet_invokeMethod',
request,
);
return end(rpcErrors.internal());
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems like this should be some kind of "unsupported" error instead?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have unsupported method, unauthorized, resourceUnavailable, resourceNotFound.

I think it's an internal error because we do a check above to see that the requested scope and method are even permitted in the first place. If they aren't supported, then the dapp shouldn't have that scope in the sessionScope value we return to them

'failed to resolve network client for wallet_invokeMethod',
request,
);
return end(rpcErrors.internal());
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems like this should be some kind of "unsupported" error instead?

Copy link
Contributor

@adonesky1 adonesky1 Jan 15, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe this is an internal error because if it were unsupported it would have been caught in validation middleware (that verifies that its an authorized scope, meaning it should definitely be resolvable) that would run before it reached this handler, but correct me if I'm wrong on this @jiexi

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

almost. If there isn't a networkClient that can serve the chainId, then the chainId/scope should not be in the sessionScopes for the dapp, i.e. this should fail on the scopeObject?.methods?.includes(wrappedRequest.method) check above all this

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/[email protected]

new author seems to be bot that is on numerous other popular npm packages

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/@npmcli/[email protected]

new author seems to be bot that is on numerous other popular npm packages

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/[email protected]

new author seems to be bot that is on numerous other popular npm packages

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/[email protected]

author contributes to other repos with several thousand stars

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/[email protected]

new author seems to be involved in node and typescript development. His two changes to this package are a removal of a file and bumping the node engine version

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/[email protected]

New authors changes seem just to be fixes. Author is also part of the Netflix open source org
https://github.com/jshttp/negotiator/commits?author=wesleytodd

@jiexi
Copy link
Contributor Author

jiexi commented Jan 15, 2025

@SocketSecurity ignore npm/[email protected]

makes sense for this package to have network access

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants