• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

safe-global / safe-cli / 9698628578

27 Jun 2024 02:38PM CUT coverage: 88.571% (+0.07%) from 88.505%
9698628578

push

github

web-flow
Add hw wallet sign message (#420)

* Add support for sign_message HwWallet

* Add Hw wallet support on SafeOperator tx-service mode

830 of 951 branches covered (87.28%)

Branch coverage included in aggregate %.

53 of 66 new or added lines in 7 files covered. (80.3%)

1 existing line in 1 file now uncovered.

2859 of 3214 relevant lines covered (88.95%)

3.56 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

68.83
/src/safe_cli/operators/safe_tx_service_operator.py
1
import json
4✔
2
from itertools import chain
4✔
3
from typing import Any, Dict, Optional, Sequence, Set, Union
4✔
4

5
from colorama import Fore, Style
4✔
6
from eth_account.messages import defunct_hash_message
4✔
7
from eth_account.signers.local import LocalAccount
4✔
8
from eth_typing import ChecksumAddress
4✔
9
from hexbytes import HexBytes
4✔
10
from prompt_toolkit import HTML, print_formatted_text
4✔
11
from tabulate import tabulate
4✔
12

13
from gnosis.eth.contracts import get_erc20_contract
4✔
14
from gnosis.eth.eip712 import eip712_encode_hash
4✔
15
from gnosis.safe import SafeOperationEnum, SafeTx
4✔
16
from gnosis.safe.api import SafeAPIException
4✔
17
from gnosis.safe.api.transaction_service_api.transaction_service_messages import (
4✔
18
    get_remove_transaction_message,
19
)
20
from gnosis.safe.multi_send import MultiSend, MultiSendOperation, MultiSendTx
4✔
21
from gnosis.safe.safe_signature import SafeSignature
4✔
22
from gnosis.safe.signatures import signature_to_bytes
4✔
23

24
from ..utils import get_input, yes_or_no_question
4✔
25
from . import SafeServiceNotAvailable
4✔
26
from .exceptions import AccountNotLoadedException, NonExistingOwnerException
4✔
27
from .hw_wallets.hw_wallet import HwWallet
4✔
28
from .safe_operator import SafeOperator
4✔
29

30

31
class SafeTxServiceOperator(SafeOperator):
4✔
32
    def __init__(self, address: str, node_url: str):
4✔
33
        super().__init__(address, node_url)
4✔
34
        if not self.safe_tx_service:
4✔
35
            raise SafeServiceNotAvailable(
4✔
36
                f"Cannot configure tx service for network {self.network.name}"
37
            )
38
        self.require_all_signatures = (
4✔
39
            False  # It doesn't require all signatures to be present to send a tx
40
        )
41

42
    def approve_hash(self, hash_to_approve: HexBytes, sender: str) -> bool:
4✔
43
        raise NotImplementedError("Not supported when using tx service")
44

45
    def sign_message(
4✔
46
        self,
47
        eip712_message_path: Optional[str] = None,
48
    ) -> bool:
49
        if eip712_message_path:
×
50
            try:
×
51
                message = json.load(open(eip712_message_path, "r"))
×
52
                message_hash = eip712_encode_hash(message)
×
53
            except ValueError:
×
54
                raise ValueError
×
55
        else:
56
            print_formatted_text("EIP191 message to sign:")
×
57
            message = get_input()
×
58
            message_hash = defunct_hash_message(text=message)
×
59

60
        safe_message_hash = self.safe.get_message_hash(message_hash)
×
61
        eoa_signers, hw_wallet_signers = self.get_signers()
×
62
        # Safe transaction service just accept one signer to create a message
NEW
63
        signature = b""
×
NEW
64
        if eoa_signers:
×
NEW
65
            signature_dict = eoa_signers[0].signHash(safe_message_hash)
×
UNCOV
66
            signature = signature_to_bytes(
×
67
                signature_dict["v"], signature_dict["r"], signature_dict["s"]
68
            )
69

NEW
70
        elif hw_wallet_signers:
×
NEW
71
            signature = SafeSignature.export_signatures(
×
72
                self.hw_wallet_manager.sign_message(
73
                    safe_message_hash, [hw_wallet_signers[0]]
74
                )
75
            )
76
        else:
NEW
77
            print_formatted_text(
×
78
                HTML("<ansired>At least one owner must be loaded</ansired>")
79
            )
80

NEW
81
        if self.safe_tx_service.post_message(self.address, message, signature):
×
82
            print_formatted_text(
×
83
                HTML(
84
                    f"<ansigreen>Message  with safe-message-hash {safe_message_hash.hex()} was correctly created on Safe Transaction Service</ansigreen>"
85
                )
86
            )
87
            return True
×
88
        else:
89
            print_formatted_text(
×
90
                HTML(
91
                    "<ansired>Something went wrong creating message on Safe Transaction Service</ansired>"
92
                )
93
            )
94
            return False
×
95

96
    def confirm_message(self, safe_message_hash: bytes, sender: ChecksumAddress):
4✔
97
        # GET message
98
        try:
4✔
99
            safe_message = self.safe_tx_service.get_message(safe_message_hash)
4✔
100
        except SafeAPIException:
×
101
            print_formatted_text(
×
102
                HTML(
103
                    f"<ansired>Message with hash {safe_message_hash.hex()} does not exist</ansired>"
104
                )
105
            )
106
        if not yes_or_no_question(
4✔
107
            f"Message: {safe_message['message']} \n Do you want to sign the following message?:"
108
        ):
109
            return False
×
110

111
        signer = self.search_account(sender)
4✔
112
        if not signer:
4✔
113
            print_formatted_text(
×
114
                HTML(f"<ansired>Owner with address {sender} was not loaded</ansired>")
115
            )
116

117
        if isinstance(signer, LocalAccount):
4✔
118
            signature = signer.signHash(safe_message_hash).signature
4✔
119
        else:
NEW
120
            signature = SafeSignature.export_signatures(
×
121
                self.hw_wallet_manager.sign_message(safe_message_hash, [signer])
122
            )
123

124
        try:
4✔
125
            self.safe_tx_service.post_message_signature(safe_message_hash, signature)
4✔
126
        except SafeAPIException as e:
4✔
127
            print_formatted_text(
4✔
128
                HTML(f"<ansired>Message wasn't confirmed due an error: {e}</ansired>")
129
            )
130
            return False
4✔
131
        print_formatted_text(
4✔
132
            HTML(
133
                f"<ansigreen>Message with safe-message-hash {safe_message_hash.hex()} was correctly confirmed on Safe Transaction Service</ansigreen>"
134
            )
135
        )
136
        return True
4✔
137

138
    def get_delegates(self):
4✔
139
        delegates = self.safe_tx_service.get_delegates(self.address)
4✔
140
        headers = ["delegate", "delegator", "label"]
4✔
141
        rows = []
4✔
142
        for delegate in delegates:
4✔
143
            row = [delegate["delegate"], delegate["delegator"], delegate["label"]]
4✔
144
            rows.append(row)
4✔
145
        print(tabulate(rows, headers=headers))
4✔
146
        return rows
4✔
147

148
    def add_delegate(self, delegate_address: str, label: str, signer_address: str):
4✔
149
        signer_account = [
4✔
150
            account for account in self.accounts if account.address == signer_address
151
        ]
152
        if not signer_account:
4✔
153
            raise AccountNotLoadedException(signer_address)
×
154
        elif signer_address not in self.safe_cli_info.owners:
4✔
155
            raise NonExistingOwnerException(signer_address)
×
156
        else:
157
            signer_account = signer_account[0]
4✔
158
            try:
4✔
159
                self.safe_tx_service.add_delegate(
4✔
160
                    self.address, delegate_address, label, signer_account
161
                )
162
                return True
4✔
163
            except SafeAPIException:
×
164
                return False
×
165

166
    def remove_delegate(self, delegate_address: str, signer_address: str):
4✔
167
        signer_account = [
4✔
168
            account for account in self.accounts if account.address == signer_address
169
        ]
170
        if not signer_account:
4✔
171
            raise AccountNotLoadedException(signer_address)
×
172
        elif signer_address not in self.safe_cli_info.owners:
4✔
173
            raise NonExistingOwnerException(signer_address)
×
174
        else:
175
            signer_account = signer_account[0]
4✔
176
            try:
4✔
177
                self.safe_tx_service.remove_delegate(
4✔
178
                    self.address, delegate_address, signer_account
179
                )
180
                return True
4✔
181
            except SafeAPIException:
×
182
                return False
×
183

184
    def submit_signatures(self, safe_tx_hash: bytes) -> bool:
4✔
185
        """
186
        Submit signatures to the tx service
187

188
        :return:
189
        """
190

191
        safe_tx, tx_hash = self.safe_tx_service.get_safe_transaction(safe_tx_hash)
4✔
192
        safe_tx.signatures = b""  # Don't post again existing signatures
4✔
193
        if tx_hash:
4✔
194
            print_formatted_text(
4✔
195
                HTML(
196
                    f"<ansired>Tx with safe-tx-hash {safe_tx_hash.hex()} "
197
                    f"has already been executed on {tx_hash.hex()}</ansired>"
198
                )
199
            )
200
        else:
201
            safe_tx = self.sign_transaction(safe_tx)
4✔
202
            if safe_tx.signers:
4✔
203
                self.safe_tx_service.post_signatures(safe_tx_hash, safe_tx.signatures)
4✔
204
                print_formatted_text(
4✔
205
                    HTML(
206
                        f"<ansigreen>{len(safe_tx.signers)} signatures were submitted to the tx service</ansigreen>"
207
                    )
208
                )
209
                return True
4✔
210
            else:
211
                print_formatted_text(
4✔
212
                    HTML(
213
                        "<ansired>Cannot generate signatures as there were no suitable signers</ansired>"
214
                    )
215
                )
216
        return False
4✔
217

218
    def batch_txs(self, safe_nonce: int, safe_tx_hashes: Sequence[bytes]) -> bool:
4✔
219
        """
220
        Submit signatures to the tx service. It's recommended to be on Safe v1.3.0 to prevent issues
221
        with `safeTxGas` and gas estimation.
222

223
        :return:
224
        """
225

226
        try:
4✔
227
            multisend = MultiSend(ethereum_client=self.ethereum_client)
4✔
228
        except ValueError:
×
229
            print_formatted_text(
×
230
                HTML(
231
                    "<ansired>Multisend contract is not deployed on this network and it's required for "
232
                    "batching txs</ansired>"
233
                )
234
            )
235

236
        multisend_txs = []
4✔
237
        for safe_tx_hash in safe_tx_hashes:
4✔
238
            safe_tx, _ = self.safe_tx_service.get_safe_transaction(safe_tx_hash)
4✔
239
            # Check if call is already a Multisend call
240
            inner_txs = MultiSend.from_transaction_data(safe_tx.data)
4✔
241
            if inner_txs:
4✔
242
                multisend_txs.extend(inner_txs)
×
243
            else:
244
                multisend_txs.append(
4✔
245
                    MultiSendTx(
246
                        MultiSendOperation.CALL, safe_tx.to, safe_tx.value, safe_tx.data
247
                    )
248
                )
249

250
        if len(multisend_txs) > 1:
4✔
251
            safe_tx = SafeTx(
×
252
                self.ethereum_client,
253
                self.address,
254
                multisend.address,
255
                0,
256
                multisend.build_tx_data(multisend_txs),
257
                SafeOperationEnum.DELEGATE_CALL.value,
258
                0,
259
                0,
260
                0,
261
                None,
262
                None,
263
                safe_nonce=safe_nonce,
264
            )
265
        else:
266
            safe_tx.safe_tx_gas = 0
4✔
267
            safe_tx.base_gas = 0
4✔
268
            safe_tx.gas_price = 0
4✔
269
            safe_tx.signatures = b""
4✔
270
            safe_tx.safe_nonce = safe_nonce  # Resend single transaction
4✔
271
        safe_tx = self.sign_transaction(safe_tx)
4✔
272
        if not safe_tx.signatures:
4✔
273
            print_formatted_text(
×
274
                HTML("<ansired>At least one owner must be loaded</ansired>")
275
            )
276
            return False
×
277
        else:
278
            return self.post_transaction_to_tx_service(safe_tx)
4✔
279

280
    def execute_tx(self, safe_tx_hash: Sequence[bytes]) -> bool:
4✔
281
        """
282
        Submit transaction on the tx-service to blockchain
283

284
        :return:
285
        """
286
        safe_tx, tx_hash = self.safe_tx_service.get_safe_transaction(safe_tx_hash)
×
287
        if tx_hash:
×
288
            print_formatted_text(
×
289
                HTML(
290
                    f"<ansired>Tx with safe-tx-hash {safe_tx_hash.hex()} "
291
                    f"has already been executed on {tx_hash.hex()}</ansired>"
292
                )
293
            )
294
        elif len(safe_tx.signers) < self.safe_cli_info.threshold:
×
295
            print_formatted_text(
×
296
                HTML(
297
                    f"<ansired>Number of signatures {len(safe_tx.signers)} "
298
                    f"must reach the threshold {self.safe_cli_info.threshold}</ansired>"
299
                )
300
            )
301
        else:
302
            if executed := self.execute_safe_transaction(safe_tx):
×
303
                self.refresh_safe_cli_info()
×
304
            return executed
×
305

306
    def get_balances(self):
4✔
307
        balances = self.safe_tx_service.get_balances(self.address)
4✔
308
        headers = ["name", "balance", "symbol", "decimals", "tokenAddress"]
4✔
309
        rows = []
4✔
310
        for balance in balances:
4✔
311
            if balance["tokenAddress"]:  # Token
4✔
312
                row = [
4✔
313
                    balance["token"]["name"],
314
                    f"{int(balance['balance']) / 10 ** int(balance['token']['decimals']):.5f}",
315
                    balance["token"]["symbol"],
316
                    balance["token"]["decimals"],
317
                    balance["tokenAddress"],
318
                ]
319
            else:  # Ether
320
                row = [
4✔
321
                    "ETHER",
322
                    f"{int(balance['balance']) / 10 ** 18:.5f}",
323
                    "Ξ",
324
                    18,
325
                    "",
326
                ]
327
            rows.append(row)
4✔
328
        print(tabulate(rows, headers=headers))
4✔
329
        return rows
4✔
330

331
    def get_transaction_history(self):
4✔
332
        transactions = self.safe_tx_service.get_transactions(self.address)
4✔
333
        headers = ["nonce", "to", "value", "transactionHash", "safeTxHash"]
4✔
334
        rows = []
4✔
335
        last_executed_tx = False
4✔
336
        for transaction in transactions:
4✔
337
            row = [transaction[header] for header in headers]
4✔
338
            data_decoded: Dict[str, Any] = transaction.get("dataDecoded")
4✔
339
            if data_decoded:
4✔
340
                row.append(self.safe_tx_service.data_decoded_to_text(data_decoded))
4✔
341
            if transaction["transactionHash"]:
4✔
342
                if not transaction["isSuccessful"]:
4✔
343
                    # Transaction failed
344
                    row[0] = Fore.RED + str(row[0])
×
345
                else:
346
                    row[0] = Fore.GREEN + str(
4✔
347
                        row[0]
348
                    )  # For executed transactions we use green
349
                    if not last_executed_tx:
4✔
350
                        row[0] = Style.BRIGHT + row[0]
4✔
351
                        last_executed_tx = True
4✔
352
            else:
353
                row[0] = Fore.YELLOW + str(
×
354
                    row[0]
355
                )  # For non executed transactions we use yellow
356

357
            row[0] = Style.RESET_ALL + row[0]  # Reset all just in case
4✔
358
            rows.append(row)
4✔
359

360
        headers.append("dataDecoded")
4✔
361
        headers[0] = Style.BRIGHT + headers[0]
4✔
362
        print(tabulate(rows, headers=headers))
4✔
363
        return rows
4✔
364

365
    def prepare_and_execute_safe_transaction(
4✔
366
        self,
367
        to: str,
368
        value: int,
369
        data: bytes,
370
        operation: SafeOperationEnum = SafeOperationEnum.CALL,
371
        safe_nonce: Optional[int] = None,
372
    ) -> bool:
373
        safe_tx = self.prepare_safe_transaction(
×
374
            to, value, data, operation, safe_nonce=safe_nonce
375
        )
376
        return self.post_transaction_to_tx_service(safe_tx)
×
377

378
    def post_transaction_to_tx_service(self, safe_tx: SafeTx) -> bool:
4✔
379
        if not yes_or_no_question(
4✔
380
            f"Do you want to send the tx with safe-tx-hash={safe_tx.safe_tx_hash.hex()} to Safe Transaction Service (it will not be executed) "
381
            + str(safe_tx)
382
        ):
383
            return False
×
384

385
        self.safe_tx_service.post_transaction(safe_tx)
4✔
386
        print_formatted_text(
4✔
387
            HTML(
388
                f"<ansigreen>Tx with safe-tx-hash={safe_tx.safe_tx_hash.hex()} was sent to Safe Transaction service</ansigreen>"
389
            )
390
        )
391
        return True
4✔
392

393
    def get_permitted_signers(self) -> Set[ChecksumAddress]:
4✔
394
        """
395
        :return: Owners and delegates, as they also can sign a transaction for the tx service
396
        """
397
        owners = super().get_permitted_signers()
4✔
398
        owners.update(
4✔
399
            [
400
                row["delegate"]
401
                for row in self.safe_tx_service.get_delegates(self.address)
402
            ]
403
        )
404
        return owners
4✔
405

406
    # Function that sends all assets to an account (to)
407
    def drain(self, to: ChecksumAddress):
4✔
408
        balances = self.safe_tx_service.get_balances(self.address)
×
409
        safe_txs = []
×
410
        safe_tx = None
×
411
        for balance in balances:
×
412
            amount = int(balance["balance"])
×
413
            if balance["tokenAddress"] is None:  # Then is ether
×
414
                if amount != 0:
×
415
                    safe_tx = self.prepare_safe_transaction(
×
416
                        to,
417
                        amount,
418
                        b"",
419
                        SafeOperationEnum.CALL,
420
                        safe_nonce=None,
421
                    )
422
            else:
423
                transaction = (
×
424
                    get_erc20_contract(self.ethereum_client.w3, balance["tokenAddress"])
425
                    .functions.transfer(to, amount)
426
                    .build_transaction({"from": self.address, "gas": 0, "gasPrice": 0})
427
                )
428
                safe_tx = self.prepare_safe_transaction(
×
429
                    balance["tokenAddress"],
430
                    0,
431
                    HexBytes(transaction["data"]),
432
                    SafeOperationEnum.CALL,
433
                    safe_nonce=None,
434
                )
435
            if safe_tx:
×
436
                safe_txs.append(safe_tx)
×
437
        if len(safe_txs) > 0:
×
438
            multisend_tx = self.batch_safe_txs(safe_tx.safe_nonce, safe_txs)
×
439
            if multisend_tx is not None:
×
440
                self.post_transaction_to_tx_service(multisend_tx)
×
441
                print_formatted_text(
×
442
                    HTML(
443
                        "<ansigreen>Transaction to drain account correctly created</ansigreen>"
444
                    )
445
                )
446
        else:
447
            print_formatted_text(
×
448
                HTML("<ansigreen>Safe account is currently empty</ansigreen>")
449
            )
450

451
    def search_account(
4✔
452
        self, address: ChecksumAddress
453
    ) -> Optional[Union[LocalAccount, HwWallet]]:
454
        """
455
        Search the provided address between loaded owners
456

457
        :param address:
458
        :return: LocalAccount or HwWallet of the provided address
459
        """
460
        for account in chain(self.accounts, self.hw_wallet_manager.wallets):
4✔
461
            if account.address == address:
4✔
462
                return account
4✔
463

464
    def remove_proposed_transaction(self, safe_tx_hash: bytes):
4✔
465
        eip712_message = get_remove_transaction_message(
4✔
466
            self.address, safe_tx_hash, self.ethereum_client.get_chain_id()
467
        )
468
        message_hash = eip712_encode_hash(eip712_message)
4✔
469
        try:
4✔
470
            safe_tx, _ = self.safe_tx_service.get_safe_transaction(safe_tx_hash)
4✔
471
            signer = self.search_account(safe_tx.proposer)
4✔
472
            if not signer:
4✔
473
                print_formatted_text(
4✔
474
                    HTML(
475
                        f"<ansired>The proposer with address: {safe_tx.proposer} was not loaded</ansired>"
476
                    )
477
                )
478
                return False
4✔
479

480
            if isinstance(signer, LocalAccount):
4✔
481
                signature = signer.signHash(message_hash).signature
4✔
482
            else:
483
                signature = self.hw_wallet_manager.sign_eip712(
×
484
                    eip712_message, [signer]
485
                )[0].signature
486

487
            if len(safe_tx.signers) >= self.safe.retrieve_threshold():
4✔
488
                print_formatted_text(
×
489
                    HTML(
490
                        "<ansired>The transaction has all the required signatures to be executed!!!\n"
491
                        "This means that the transaction can be executed by a 3rd party monitoring your Safe even after removal!\n"
492
                        f"Make sure you execute a transaction with nonce {safe_tx.safe_nonce} to void the current transaction"
493
                        "</ansired>"
494
                    )
495
                )
496

497
            if not yes_or_no_question(
4✔
498
                f"Do you want to remove the tx with safe-tx-hash={safe_tx.safe_tx_hash.hex()}"
499
            ):
500
                return False
×
501

502
            self.safe_tx_service.delete_transaction(safe_tx_hash.hex(), signature.hex())
4✔
503
            print_formatted_text(
4✔
504
                HTML(
505
                    f"<ansigreen>Transaction {safe_tx_hash.hex()} was removed correctly</ansigreen>"
506
                )
507
            )
508
            return True
4✔
509
        except SafeAPIException as e:
×
510
            print_formatted_text(
×
511
                HTML(f"<ansired>Transaction wasn't removed due an error: {e}</ansired>")
512
            )
513
            return False
×
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2025 Coveralls, Inc