feat: align with updated 7715 standard - #39176
Conversation
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
✨ Files requiring CODEOWNER review ✨✅ @MetaMask/confirmations (1 files, +4 -16)
👨🔧 @MetaMask/core-extension-ux (8 files, +220 -296)
📜 @MetaMask/policy-reviewers (12 files, +36 -228)
Tip Follow the policy review process outlined in the LavaMoat Policy Review Process doc before expecting an approval from Policy Reviewers. 👨🔧 @MetaMask/wallet-integrations (1 files, +4 -0)
|
Builds ready [e24c689]
UI Startup Metrics (1272 ± 107 ms)
📊 Page Load Benchmark ResultsCurrent Commit: 📄 Localhost MetaMask Test DappSamples: 100 Summary
📈 Detailed Results
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
## Explanation
### What is the current state of things and why does it need to change?
The `@metamask/eth-json-rpc-middleware` package currently supports two
EIP-7715 methods:
- `wallet_requestExecutionPermissions` — for requesting new execution
permissions
- `wallet_revokeExecutionPermission` — for revoking existing execution
permissions
However, the EIP-7715 specification also defines two additional
"discoverability" methods that allow dApps to query the wallet about its
execution permission capabilities. Without these methods, dApps have no
way to:
1. Discover which permission types the wallet supports and on which
chains
2. Retrieve the list of currently granted (non-revoked) permissions for
the user
### What is the solution your changes offer and how does it work?
This PR adds support for the two missing EIP-7715 discoverability
methods:
- **`wallet_getSupportedExecutionPermissions`** — Returns an object
keyed by permission type (e.g., `native-token-allowance`,
`erc20-token-allowance`) with their supported chain IDs and rule types.
This allows dApps to understand what the wallet can handle before making
permission requests.
- **`wallet_getGrantedExecutionPermissions`** — Returns an array of all
currently active (non-revoked) execution permissions. Each permission
includes chain ID, addresses, permission details, context, dependencies,
and delegation manager information.
The implementation follows the established patterns in this package:
- Each method has a dedicated handler file with a factory function
(`createWallet*Handler`)
- Hook-based architecture allows consumers to provide their own
processing logic
- Superstruct schemas are defined for result types, enabling runtime
validation
- Types and structs are exported from the package index for consumer use
#### EIP-7715 spec alignment for `wallet_requestExecutionPermissions`
The request/response schema has been updated to align with the latest
EIP-7715 specification:
- **Simplified address fields**: Replaced the nested `address` +
`signer: { type, data: { address } }` structure with flat `from`
(optional) and `to` (required) fields
- **Removed `isAdjustmentAllowed` from rules**: This property is only
relevant at the permission level, not individual rules
- **Extended result type**: Added `dependencies` (array of `{ factory,
factoryData }`) and `delegationManager` to the response
- **New export**: Added `PermissionDependency` type export for consumers
- **Consistent address validation**: Updated
`GrantedExecutionPermissionStruct` to use `HexChecksumAddressStruct` for
address fields
### Are there any changes whose purpose might not obvious to those
unfamiliar with the domain?
The handlers don't perform parameter validation since these methods
don't accept parameters (they're pure query methods). This is
intentional and differs from `wallet_requestExecutionPermissions` and
`wallet_revokeExecutionPermission` which validate their params using
Superstruct schemas.
## References
<!--
Are there any issues that this pull request is tied to?
Are there other links that reviewers should consult to understand these
changes better?
Are there client or consumer pull requests to adopt any breaking
changes?
For example:
* Fixes #12345
* Related to #67890
-->
- Needed for: MetaMask/metamask-extension#39176
- Related to: MetaMask/snap-7715-permissions#249
## Checklist
- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/contributing.md#updating-changelogs)
- [x] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> Implements EIP-7715 discoverability methods and integrates them into
the wallet middleware.
>
> - New handlers: `createWalletGetSupportedExecutionPermissionsHandler`
and `createWalletGetGrantedExecutionPermissionsHandler` using hook-based
processing and `NoParamsStruct` validation
> - Exports new types and structs from `index.ts`
(`SupportedExecutionPermissionConfig*`, `GrantedExecutionPermission*`,
results)
> - Adds `EmptyArrayStruct`/`NoParamsStruct` in `utils/structs` for "no
params" validation
> - Wires methods into `createWalletMiddleware` via optional
`processGet*` hooks
> - Unit tests for both methods: hook invocation, result passthrough,
missing-hook error, and params validation
> - Changelog updated to note new RPC support
>
> <sup>Written by [Cursor
Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit
8e94f86. This will update automatically
on new commits. Configure
[here](https://cursor.com/dashboard?tab=bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
…into feat--support-7715-discoverability-methods
Builds ready [164f5be]
UI Startup Metrics (1286 ± 110 ms)
📊 Page Load Benchmark ResultsCurrent Commit: 📄 Localhost MetaMask Test DappSamples: 100 Summary
📈 Detailed Results
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
## Explanation Releases: - `@metamask/gator-permissions-controller@1.0.0` - `@metamask/eth-json-rpc-middleware@23.0.0` - `@metamask/signature-controller@38.1.0` Both `gator-permissions-controller` and `eth-json-rpc-middleware` produce breaking changes to align with latest eip 7715 specs. ## References <!-- Are there any issues that this pull request is tied to? Are there other links that reviewers should consult to understand these changes better? Are there client or consumer pull requests to adopt any breaking changes? For example: * Fixes #12345 * Related to #67890 --> Required by: MetaMask/metamask-extension#39176 ## Checklist - [ ] I've updated the test suite for new or updated code as appropriate - [ ] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [ ] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > Releases coordinated majors with EIP‑7715 updates and dependency alignments. > > - **BREAKING:** `@metamask/eth-json-rpc-middleware@23.0.0` updates `wallet_requestExecutionPermissions` to 7715 spec; adds `wallet_getSupportedExecutionPermissions` and `wallet_getGrantedExecutionPermissions` > - **BREAKING:** `@metamask/gator-permissions-controller@1.0.0` updates core types to 7715 revisions > - **BREAKING:** `@metamask/shield-controller@5.0.0` now depends on `@metamask/signature-controller@39.0.0`; `decodedPermission` shape in signature requests changes > - `@metamask/signature-controller@39.0.0` bumps to use `gator-permissions-controller@1.0.0` > - `@metamask/network-controller` bumps dependency to `eth-json-rpc-middleware@^23.0.0` and updates changelog (notes new `ConnectivityController:getState` requirement) > - Bumps monorepo `version` to `751.0.0` and updates lockfile > > <sup>Written by [Cursor Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit e0a1409. This will update automatically on new commits. Configure [here](https://cursor.com/dashboard?tab=bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: Idris Bowman <34751375+V00D00-child@users.noreply.github.com>
…into feat--support-7715-discoverability-methods
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
Builds ready [509370a]
UI Startup Metrics (1332 ± 107 ms)
📊 Page Load Benchmark ResultsCurrent Commit: 📄 Localhost MetaMask Test DappSamples: 100 Summary
📈 Detailed Results
Bundle size diffs [🚀 Bundle size reduced!]
|
|
Policies updated. 🧠 Learn how: https://lavamoat.github.io/guides/policy-diff/#what-to-look-for-when-reviewing-a-policy-diff |
Builds ready [fb72537]
UI Startup Metrics (1343 ± 114 ms)
📊 Page Load Benchmark ResultsCurrent Commit: 📄 Localhost MetaMask Test DappSamples: 100 Summary
📈 Detailed Results
Bundle size diffs [🚀 Bundle size reduced!]
|
…into feat--support-7715-discoverability-methods
…github.com/MetaMask/metamask-extension into feat--support-7715-discoverability-methods
|
@metamaskbot update-policies |
|
No policy changes |
Builds ready [a522169]
UI Startup Metrics (1318 ± 94 ms)
📊 Page Load Benchmark ResultsCurrent Commit: 📄 Localhost MetaMask Test DappSamples: 100 Summary
📈 Detailed Results
Bundle size diffs [🚀 Bundle size reduced!]
|
Description
This PR updates the codebase to align with API changes in the
@metamask/gator-permissions-controllerpackage.Reason for the change:
The upstream
@metamask/gator-permissions-controllerpackage has updated its type definitions and data structures. This PR ensures compatibility with those changes.Changes included:
Type simplification: Removed the
Signergeneric parameter fromStoredGatorPermissionSanitized<Signer, PermissionTypesWithCustom>→StoredGatorPermissionSanitized<PermissionTypesWithCustom>across all files (selectors, hooks, components, and tests).Data structure updates:
permissionResponse.address→permissionResponse.from(delegator address)decodedPermission.signer.data.address→decodedPermission.to(delegate/recipient address)permissionResponse.signerMeta.delegationManager→permissionResponse.delegationManager(flattened structure)permission.rules→permissionResponse.rules(rules array location change)New RPC methods: Added support for two new unrestricted methods:
wallet_getSupportedExecutionPermissions- Returns supported permission types (filtered by enabled advanced permissions)wallet_getGrantedExecutionPermissions- Returns granted execution permissionsChangelog
CHANGELOG entry: Added support for
wallet_getSupportedExecutionPermissionsandwallet_getGrantedExecutionPermissionsRPC methods.CHANGELOG entry: Updated to latest 7715 standart.
Related issues
Depends on: MetaMask/core#7603
Relates to: MetaMask/snap-7715-permissions#249
Requires: MetaMask/core#7634
Requires: MetaMask/snap-7715-permissions#254
Manual testing steps
For manual testing check: MetaMask/snap-7715-permissions#249
Pre-merge author checklist
Pre-merge reviewer checklist
Note
Updates codebase to the 7715/gator-permissions v1 API and introduces execution-permissions query RPCs.
@metamask/gator-permissions-controller@^1.0.0: removeSignergeneric, movepermission.rulestopermissionResponse.rules, renamepermissionResponse.address→from,signerMeta.delegationManager→delegationManager, and decoded permissionsigner...address→to; applies across hooks, selectors, components, and testswallet_getSupportedExecutionPermissions(filters by enabled advanced types) andwallet_getGrantedExecutionPermissions; wires throughcreateMetamaskMiddlewareand forwards to the permissions kernel snapeth-json-rpc-middleware@^23,permissions-kernel-snap@^1.0.0,signature-controller@^39,shield-controller@^5, etc.) and adjusts LavaMoat policies to use the updated middleware pathingWritten by Cursor Bugbot for commit a522169. This will update automatically on new commits. Configure here.