Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Prevent addresses from being added to the URLs

Open
#90 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Stale
Tech stack
typescript
Domain
security, web-dev

Research direction

Start by reproducing the analytics.page payload shown in the issue from the playground, then trace how input parameters become URL search data. Review the privacy concern alongside the proposed Copy button and define the desired behavior before implementation. Done means addresses are not exposed through URLs or analytics while developers can still preserve their input.

Written by the indexing model from the issue text.

Description

Though the playground isn't intended for use with sensitive information, we should still avoid including addresses in URLs to avoid any privacy risks.

The recent addition of analytics that are including URLs in the event parameters exacerbates this risk so it should be prioritized.

Here's an example of what's being passed when there are params included in the URL (there is some masking but that is from a third-party UI and doesn't mean they don't have the full address in their system):

analytics.page({
  path: '/wallet/reference/wallet_requestpermissions/',
  referrer: '',
  search: '?requestPermissionsObject[eth_accounts][account]=0***',
  title: 'MetaMask developer documentation',
  url: 'https://docs.metamask.io/wallet/reference/wallet_requestpermissions/?requestPermissionsObject[eth_accounts][account]=0***'
});

At the same time, we want to balance privacy against the developer experience.
@BelfordZ recommends adding a "Copy" button to allow developers to save their input data from the playground in case they need it again later.

Dominant language
TypeScript
Stars
7
Forks
8
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from MetaMask/api-playground

All issues in MetaMask/api-playground

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.