Commit 66a6dcf
fix(developers): address swap widget QA findings (#108)
* fix(csp): allow the swap widget's RPC, mempool and Solana endpoints on /developers
The widget polls EVM transaction status through viem clients pointed at
ShapeShift's per-chain RPC proxies (api.<chain>.shapeshift.com) and at
viem's default RPCs for Monad, MegaETH, HyperEVM, Plasma and Katana. It
reads Bitcoin balances and tx status from mempool.space, and falls back to
api.mainnet-beta.solana.com for Solana when AppKit has no connection.
None of those origins were in connect-src, so every status poll failed
and was retried forever (the widget maps RPC errors to 'pending'), leaving
a swap that had already confirmed on-chain stuck on 'Confirming
Transaction'. BTC and SOL balances failed the same way and rendered as
nothing.
Allow *.shapeshift.com so new chain proxies don't need a CSP change each
time, and list the remaining third-party RPCs explicitly.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(csp): restore the Onramper iframe on /trade
The Buy Crypto card on /trade embeds buy.onramper.com. Its frame-src
allowance lived in a route-level Content-Security-Policy header in
next.config.ts, which only ever took effect because the middleware's own
CSP header was being dropped on the /trade -> /en/trade rewrite. #104
fixed that header loss, so the middleware CSP (chatwoot-only frame-src)
now reaches /trade and replaces the next.config one, and the iframe is
blocked with a broken-page glyph on develop.
Move the Onramper origins into the middleware CSP, scoped to /trade with
or without a locale prefix, and drop the now-dead CSP entries from
next.config.ts (the COOP header there still does its job).
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat(developers): initialise AppKit host-side with chain icons and ShapeShift RPCs
Let the page own the Reown AppKit instance instead of the swap widget's
self-init. The widget documents this mode (it detects the singleton and
reuses its wagmi config), and it gives us two knobs the widget doesn't
expose:
- chainImages: AppKit has no preset icons for MegaETH, HyperEVM, Plasma
or Katana, so its network picker showed a generic globe for them. Feed
it the same icon set the widget draws in its own chain sidebar so both
surfaces match.
- customRpcUrls: route wallet balance reads and the Solana connection
through ShapeShift's RPC proxies (api.<chain>.shapeshift.com), the same
endpoints the widget already uses for status polling, with Reown's
Blockchain API kept as the fallback.
The network list, adapters and features mirror the widget's own
config/appkit.ts so wallet support is unchanged.
Co-authored-by: Cursor <cursoragent@cursor.com>
* docs(developers): spell out the Reown allowed-origins requirement
The blank WalletConnect QR on staging is the relay rejecting the origin:
the Reown project's allowlist only contains the *-widget.shapeshift.com
demo hosts, and the same project ID is baked into the website bundle.
Nothing in this repo can fix that; document exactly what to add and how
to check the current list, and note the new host-owned AppKit init.
Co-authored-by: Cursor <cursoragent@cursor.com>
* docs(developers): note the website origins are now on the Reown allowlist
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(developers): let the widget own AppKit and unblock WalletConnect signing
Host-side AppKit plus a pinned WC CSP dropped echo/secure-mobile hosts, so
session requests never reached the wallet. Match the stock embed path and
allow WalletConnect/Reown wildcards on /developers.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>1 parent b2e08ff commit 66a6dcf
4 files changed
Lines changed: 48 additions & 32 deletions
File tree
- app/[lang]/developers
- _components
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
28 | 30 | | |
29 | 31 | | |
30 | 32 | | |
| |||
Lines changed: 3 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | | - | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
| 8 | + | |
| 9 | + | |
15 | 10 | | |
16 | 11 | | |
17 | 12 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | | - | |
42 | | - | |
| 41 | + | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
46 | 53 | | |
47 | 54 | | |
48 | 55 | | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
49 | 63 | | |
50 | 64 | | |
51 | 65 | | |
| |||
185 | 199 | | |
186 | 200 | | |
187 | 201 | | |
188 | | - | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
189 | 212 | | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
190 | 217 | | |
191 | | - | |
| 218 | + | |
192 | 219 | | |
193 | 220 | | |
194 | | - | |
| 221 | + | |
195 | 222 | | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
196 | 226 | | |
197 | 227 | | |
198 | 228 | | |
| |||
201 | 231 | | |
202 | 232 | | |
203 | 233 | | |
204 | | - | |
| 234 | + | |
205 | 235 | | |
206 | 236 | | |
207 | 237 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| 50 | + | |
| 51 | + | |
50 | 52 | | |
51 | | - | |
52 | 53 | | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
58 | | - | |
59 | | - | |
| 54 | + | |
60 | 55 | | |
61 | 56 | | |
62 | | - | |
| 57 | + | |
63 | 58 | | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
70 | | - | |
| 59 | + | |
71 | 60 | | |
72 | 61 | | |
73 | 62 | | |
| |||
0 commit comments