mirror of
https://github.com/simplex-chat/simplex-chat.git
synced 2026-10-06 05:37:47 +00:00
core: don't reveal another profile when delivering a store purchase; bound store checks and restrict Play ids
This commit is contained in:
@@ -871,6 +871,7 @@ data ChatResponse
|
||||
| CRServiceResponse {user :: User, responseData :: J.Object}
|
||||
| CRServiceReplyAccepted {user :: User, connectionId :: AgentConnId}
|
||||
| CRBadgeRedeemed {user :: User, redeemedBadge :: LocalBadge, newBadge :: Bool, badgeState :: Maybe BadgeState}
|
||||
| CRBadgePurchaseDelivered {user :: User} -- delivered to the profile it was first presented under, which may be hidden
|
||||
| CRBadgeState {user :: User, badgeState :: Maybe BadgeState}
|
||||
| CRBadgeLedger {user :: User, badgeLedger :: [StatementEntry]}
|
||||
| CRUserAcceptedGroupSent {user :: User, groupInfo :: GroupInfo, hostContact :: Maybe Contact}
|
||||
|
||||
@@ -5257,8 +5257,10 @@ purchaseBadge nm presentingUser payment = do
|
||||
requestStashedBadge nm user sendTarget stash BSCPurchaseBadge {masterKey, payment, upgrade = Nothing} terminalReceiptError
|
||||
-- outside the badge lock: the chat lock must not be taken under it
|
||||
mapM_ presentUserBadgeToContacts present_
|
||||
pure purchased
|
||||
-- the owner may be hidden, so the answer is the same whether it is or not, and names only the presenter
|
||||
pure $ if userId == presentingUserId then purchased else CRBadgePurchaseDelivered presentingUser
|
||||
where
|
||||
User {userId = presentingUserId} = presentingUser
|
||||
-- the receipt will never be credited to this key; any other refusal may pass on a retry
|
||||
terminalReceiptError = \case
|
||||
BSEReceiptInvalid -> True
|
||||
|
||||
@@ -193,6 +193,7 @@ chatResponseToView hu cfg@ChatConfig {logLevel, showReactions, showFullLinks, te
|
||||
CRServiceReplyAccepted u (AgentConnId cId) -> ttyUser u [plain $ "service reply accepted, connection id: " <> safeDecodeUtf8 (strEncode cId)]
|
||||
-- the badge is only shown when it is the one now on the profile; a replayed code's badge may not be
|
||||
CRBadgeRedeemed u badge newBadge _ -> ttyUser u $ if newBadge then "badge redeemed" : viewContactBadge (Just badge) else ["badge already redeemed"]
|
||||
CRBadgePurchaseDelivered u -> ttyUser u ["badge purchase delivered to another profile"]
|
||||
CRBadgeState u st -> ttyUser u $ viewUserBadgeState st
|
||||
CRBadgeLedger u entries -> ttyUser u $ viewBadgeLedger entries
|
||||
CRGroupCreated u g -> ttyUser u $ viewGroupCreated g testView
|
||||
|
||||
Reference in New Issue
Block a user