The overlay for tronWeb-built transactions was built from the dapp's raw_data JSON, which need not match raw_data_hex: a site could show "1 TRX to X" and get a signature over anything. lib/tron-decode.js decodes Transaction.raw from raw_data_hex (contract type, owner, to, amount, TRC-20 transfer/approve calldata, fee limit, memo); the txID must match the bytes, every contract's owner must be this wallet, and unlimited approvals or permission/resource delegation get a danger action. sendRawTransaction relayed any signed transaction a site handed it; it now broadcasts only txids Aegis itself signed. |
||
|---|---|---|
| .. | ||
| aegis | ||
| blocker | ||
| consent | ||
| docx-editor | ||
| notepad | ||
| pdf-editor | ||
| pithos | ||
| screenshot | ||
| translate | ||
| vpn | ||