Security News
JSR Working Group Kicks Off with Ambitious Roadmap and Plans for Open Governance
At its inaugural meeting, the JSR Working Group outlined plans for an open governance model and a roadmap to enhance JavaScript package management.
@metamask/detect-provider
Advanced tools
A tiny utility for detecting the MetaMask Ethereum provider, or any EIP 1193-compliant provider.
A tiny utility for detecting the MetaMask Ethereum provider, or any provider injected at window.ethereum
.
It has 0 dependencies and works out of the box in any modern browser, for synchronously and asynchronously injected providers.
Keep in mind that the providers detected by this package may or may not support the Ethereum JavaScript Provider API. Please consult the MetaMask documentation to learn how to use our provider.
import detectEthereumProvider from '@metamask/detect-provider'
const provider = await detectEthereumProvider()
if (provider) {
console.log('Ethereum successfully detected!')
// From now on, this should always be true:
// provider === window.ethereum
// Access the decentralized web!
// Legacy providers may only have ethereum.sendAsync
const chainId = await provider.request({
method: 'eth_chainId'
})
} else {
// if the provider is not detected, detectEthereumProvider resolves to null
console.error('Please install MetaMask!', error)
}
<script src="https://unpkg.com/@metamask/detect-provider/dist/detect-provider.min.js"></script>
<script type="text/javascript">
const provider = await detectEthereumProvider()
if (provider) {
// handle provider
} else {
// handle no provider
}
</script>
The exported function takes an optional options
object.
In most cases, you won't need to specify anything, but read on for details.
options.mustBeMetaMask
Whether window.ethereum.isMetaMask === true
is required for the returned Promise to resolve.
Default: false
options.timeout
How many milliseconds to wait for asynchronously injected providers.
Default: 3000
Providers can be either synchronously or asynchronously injected:
The MetaMask extension provider is synchronously injected, while the MetaMask mobile provider is asynchronously injected.
To notify sites of asynchronous injection, MetaMask dispatches the ethereum#initialized
event on window
immediately after the provider has been set as window.ethereum
.
This package relies on that event to detect asynchronous injection.
window.ethereum
The detected provider object returned by this package will strictly equal (===
) window.ethereum
for the entire page lifecycle, unless window.ethereum
is overwritten.
In general, consumers should never overwrite window.ethereum
or attempt to modify the provider object.
If, as a dapp developer, you notice that the provider returned by this package does not strictly equal window.ethereum
, something is wrong.
This may happen, for example, if the user has multiple wallets installed.
After confirming that your code and dependencies are not modifying or overwriting window.ethereum
, you should ask the user to ensure that they only have a single provider-injecting wallet enabled at any one time.
[1.0.1] - 2020-06-24
FAQs
A tiny utility for detecting the MetaMask Ethereum provider, or any EIP 1193-compliant provider.
The npm package @metamask/detect-provider receives a total of 40,134 weekly downloads. As such, @metamask/detect-provider popularity was classified as popular.
We found that @metamask/detect-provider demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
At its inaugural meeting, the JSR Working Group outlined plans for an open governance model and a roadmap to enhance JavaScript package management.
Security News
Research
An advanced npm supply chain attack is leveraging Ethereum smart contracts for decentralized, persistent malware control, evading traditional defenses.
Security News
Research
Attackers are impersonating Sindre Sorhus on npm with a fake 'chalk-node' package containing a malicious backdoor to compromise developers' projects.