Fix: relay tx receipts through the server (CSP blocked direct RPC polls)

After a wallet sent a transaction, waitTx polled the public RPC straight
from the browser, which connect-src 'self' blocks (Firefox NetworkError,
reported by Marty on Activate; the activation itself landed on-chain).
New /api/tx/<hash> relays eth_getTransactionReceipt via the server's RPC
pool, so the browser only ever talks to us and the mainnet flip needs no
CSP changes. Assets v=20260905a.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
martbost
2026-09-05 05:40:56 -05:00
parent f848112e2d
commit 013a88b7d0
6 changed files with 29 additions and 22 deletions
+3 -4
View File
@@ -49,11 +49,10 @@ window.IAPWallet = (function () {
return eth().request({ method: 'eth_sendTransaction', params: [tx] });
}
async function waitTx(hash) {
const c = await IAP.getConfig();
// poll our own server (CSP-friendly); it relays the receipt from the RPC
for (let i = 0; i < 60; i++) {
const r = await (await fetch(c.rpc, { method: 'POST', headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ jsonrpc: '2.0', id: 1, method: 'eth_getTransactionReceipt', params: [hash] }) })).json();
if (r.result) return r.result;
const r = await (await fetch('/api/tx/' + hash)).json();
if (r.found) return { status: r.status, blockNumber: r.blockNumber };
await new Promise(res => setTimeout(res, 2500));
}
throw new Error('Timed out waiting for the transaction. Check the explorer.');