Integration engineering

Invalidate approvals and quotes after an account switch

Bind quote, allowance and signature state to the connected account and protect it from late results after a wallet switch.

An account switch changes who owns the input funds, who grants permission and who may be eligible to execute a quote. Clear account-dependent state before asking the replacement account to sign anything.

The wallet's accountsChanged event supplies the newly available accounts. An empty array means the application no longer has an exposed account; it is not a zero-address wallet. Stop pending signing work and return to a disconnected-account state.

Key cached state by its owner

An allowance lookup belongs to a tuple of chain, token, owner and spender. A balance belongs to chain, asset and owner. A quote may additionally include taker and recipient. Reusing one account's sufficient allowance for another account can make the screen skip a required approval.

Signatures need stricter treatment. Discard an unsigned request prepared for the old account. Keep an already submitted order in history, but never relabel it as belonging to the newly selected account. If the old account signed an order that remains fillable, changing accounts in the interface does not revoke it.

A focused race fixture

  1. Start a quote and allowance read for account A.
  2. Emit accountsChanged with account B.
  3. Resolve A's allowance as sufficient.
  4. Resolve A's quote after B's balance has loaded.
  5. Verify that neither old result enables B's submit button.

Tag asynchronous work with an account-context generation, as well as its address. This handles a quick A-to-B-to-A sequence: the last A session may have different inputs from the first. Finally, verify the selected account when constructing the wallet request. A review screen tied only to a mutable global address invites inconsistencies between its visible terms and the actual sender.

Sources & verification (1)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. EIP-1193: Ethereum Provider JavaScript API

    Account/chain events and user rejection error

    https://eips.ethereum.org/EIPS/eip-1193

Continue reading

Swap API integration: quote, approve, simulate, submit