Summary
extractDestination correctly unwraps FeeBumpTransaction.innerTransaction to find the payment destination (decodeTransaction.ts:39), but never considers the fee-bump's own fee-source account, which is a distinct trust signal.
Current Behavior / Relevant Code
- src/decode/decodeTransaction.ts:39 -- tx.innerTransaction extraction discards parsed.feeSource entirely.
Why This Matters
Fee-bump sponsorship is an underused but real signal -- a dApp or third party silently sponsoring your transaction fee is exactly the kind of 'unusual signal' the 'Elevated' tier (README.md:43) is meant to catch, and today it's invisible.
Proposed Solution
- When the parsed transaction is a FeeBumpTransaction, additionally capture parsed.feeSource and pass it through as supplementary context (surfaced in the popup at minimum, not necessarily scored the same way as a payment destination).
- Add fixtures/tests for fee-bumped transactions with a fee source distinct from the transaction's own source account.
Acceptance Criteria
Definition of Done
How to Claim This Issue (Application Process)
- Comment first. Post a short implementation plan on this issue — your proposed approach, the files you expect to touch, and any open questions — before writing code. This prevents duplicate effort and lets a maintainer flag concerns early, which matters especially for an issue at this complexity level.
- Wait for assignment. A maintainer will review your plan and assign the issue to you, typically within 48 hours. Please do not open a draft PR before you're assigned.
- Stay active. If there's no visible activity (commits or comments) for 10 days after assignment, the issue may be unassigned and reopened to other contributors.
- Submit a scoped PR. Reference this issue (
Closes #<issue-number>), keep the diff scoped to the acceptance criteria above, and ensure all CI gates pass before requesting review.
- Engage with review. Respond to review feedback within a reasonable timeframe; PRs with no response after 7 days may be closed pending resubmission when you're ready to pick it back up.
Category: Transaction Decoding Coverage
Estimated effort: S (small, ~1-2 days)
Difficulty: Advanced — this issue assumes familiarity with the codebase's MV3 service-worker architecture, the Freighter interception protocol, and/or the Stellar SDK.
Summary
extractDestination correctly unwraps FeeBumpTransaction.innerTransaction to find the payment destination (decodeTransaction.ts:39), but never considers the fee-bump's own fee-source account, which is a distinct trust signal.
Current Behavior / Relevant Code
Why This Matters
Fee-bump sponsorship is an underused but real signal -- a dApp or third party silently sponsoring your transaction fee is exactly the kind of 'unusual signal' the 'Elevated' tier (README.md:43) is meant to catch, and today it's invisible.
Proposed Solution
Acceptance Criteria
Definition of Done
npm run lint,npm run typecheck,npm test, andnpm run buildall pass locally and in CIREADME.mdHow to Claim This Issue (Application Process)
Closes #<issue-number>), keep the diff scoped to the acceptance criteria above, and ensure all CI gates pass before requesting review.Category: Transaction Decoding Coverage
Estimated effort: S (small, ~1-2 days)
Difficulty: Advanced — this issue assumes familiarity with the codebase's MV3 service-worker architecture, the Freighter interception protocol, and/or the Stellar SDK.