Browser Extension
Supported Transactions
What the Joey browser extension will sign for a dApp, and what it always refuses.
Joey signs any transaction type it recognises, except the cases below. These refusals protect users from requests that would hand control of their account to someone else. They are applied:
- before the user is asked, and again at the moment of signing;
- at every level, including each inner transaction of an XLS-56
Batch.
The user is never asked to approve a refused request. Users can still perform these operations from Joey's own interface.
Refused transaction types
Requests for these fail with 4100 ("transaction type not permitted").
| Type | Why |
|---|---|
SetRegularKey |
Grants permanent signing authority to another key |
SignerListSet |
Grants signing authority through multisign |
DelegateSet |
Grants authority through delegation |
AccountDelete |
Irreversible |
SetHook |
Installs code that runs on every future transaction |
EnableAmendment, SetFee, UNLModify |
Pseudo-transactions that no account signs |
AccountSet with a dangerous flag |
See below |
AccountSet flags
Refused when set (SetFlag):
asfRequireAuthasfDisallowXRPasfDisableMasterasfNoFreezeasfAuthorizedNFTokenMinterasfAllowTrustLineClawbackasfGlobalFreezeasfDepositAuth
Refused when cleared (ClearFlag):
asfRequireAuthasfDisallowXRPasfDepositAuth
Other flags, such as asfDefaultRipple, asfRequireDest, asfAccountTxnID and the asfDisallowIncoming* flags, are allowed.
Future sequence numbers
A transaction that sets its own Sequence ahead of the account's current sequence, and has no LastLedgerSequence (or one too far away), is refused. Such a signature could be held and submitted much later. Add a LastLedgerSequence.
Field rules
Requests that break these rules fail with -32602 before the user is asked.
| Rule | Detail |
|---|---|
| Fee cap | Fee is a string of drops. With autofill: false, a fee above 2 XRP (2,000,000 drops) is refused. Autofilled fees are capped at the same amount. |
No NetworkID |
Any NetworkID field is refused. Mainnet, Testnet and Devnet don't use it. |
| No X-addresses | Use a classic r… address and a separate DestinationTag. |
| Valid integers | Integer fields must be whole numbers within the field's range. |
| Known types only | TransactionType must be a type Joey recognises. |
| Matching account | tx_json.Account must be the signing account (except for signTransactionFor). |
| Batch rules | A Batch must be alone in its request and pass the checks in Batch and bulk. |
Account types
- Ledger hardware accounts can sign ordinary transactions, confirmed on the device. They can't sign a
Batch, and they sign in with a challenge transaction. - Watch-only accounts can be connected but can't sign.