Prevent addresses from being added to the URLs
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- typescript
Research direction
Start by reproducing the analytics.page payload shown in the issue from the playground, then trace how input parameters become URL search data. Review the privacy concern alongside the proposed Copy button and define the desired behavior before implementation. Done means addresses are not exposed through URLs or analytics while developers can still preserve their input.
Written by the indexing model from the issue text.
Description
Though the playground isn't intended for use with sensitive information, we should still avoid including addresses in URLs to avoid any privacy risks.
The recent addition of analytics that are including URLs in the event parameters exacerbates this risk so it should be prioritized.
Here's an example of what's being passed when there are params included in the URL (there is some masking but that is from a third-party UI and doesn't mean they don't have the full address in their system):
analytics.page({
path: '/wallet/reference/wallet_requestpermissions/',
referrer: '',
search: '?requestPermissionsObject[eth_accounts][account]=0***',
title: 'MetaMask developer documentation',
url: 'https://docs.metamask.io/wallet/reference/wallet_requestpermissions/?requestPermissionsObject[eth_accounts][account]=0***'
});
At the same time, we want to balance privacy against the developer experience.
@BelfordZ recommends adding a "Copy" button to allow developers to save their input data from the playground in case they need it again later.
- Dominant language
- TypeScript
- Stars
- 7
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from MetaMask/api-playground
-
Difficulty 2/5 1-3 hours Newbie friendliness 52/100
MetaMask/api-playground#73 · 2 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
MetaMask/api-playground#44 ·
All issues in MetaMask/api-playground
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
external-issue to-triage
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
diegosouzapw/OmniRoute#15401 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
code-yeongyu/oh-my-openagent#9454 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
smart-village-solutions/sva-studio#1654 ·
Maintainers usually reply within 1 day