brave/brave-talk

Warning message is not shown when domain is different

Closed this issue · 6 comments

Description

Warning message is not shown when domain is different

Steps

  1. Create Web3 Talk room
  2. Click on join the call to initiate sign message
  3. No warning shown to user when the request URI is different

Actual Result

image

Expected Result

image

Additional Information

cc: @mrose17

@srirambv - i can't seem to reproduce. can you make a video? thanks!

The warning message only seems to be showing up on MM and not on Brave Wallet.

826.mp4

@johnhalbert - my thinking is that we need to fill-in the actual domain (in this case talk.brave.software instead of hardcoding talk.brave.com for both the text <domain> wants you to sign in... and the URI: <domain> field.

The warning message only seems to be showing up on MM and not on Brave Wallet.

826.mp4

The fix is simple: use the wallet in the Brave browser...

@mrose17 I've update this as you mentioned above - we now use the host value from the browser as the domain in the SIWE message.

@srirambv this is ready for re-test.

Verified no warning message is shown when trying to sign messages

MetaMask Brave Wallet
MM-.826.mov
BW-.826.mp4