What changed, and why it matters
This commit contains three small, unrelated fixes. One adds a safety catch around a Lightning wallet disconnect call so the app doesn't crash if disconnect fails. Another trims spaces and trailing currency text from amount inputs before converting them to numbers, which could prevent user input errors or unexpected parsing. The third is an Italian translation correction for the word 'change'. There is no clear security vulnerability being patched.
No immediate security action required. Review the parseFixed input handling change for correctness (e.g., behavior with leading/trailing spaces, multiple spaces, or locale-specific formats) and consider moving the sanitization to the UI layer as the commit comment suggests.
Security signals we found
No explicit security relevance stated in commit title or message
No CVE, advisory, or researcher attribution present in commit
Changes are defensive/robustness improvements rather than vulnerability fixes
parse_fixed change handles user input sanitization but does not prevent a known exploit
Evidence from the diff
The diff modifies three files: (1) cw_bitcoin/lib/lightning/lightning_wallet.dart wraps _sdk?.disconnect() in a try/catch to swallow exceptions during wallet close; (2) cw_core/lib/parse_fixed.dart strips everything after the first space in parseFixed() to handle inputs like ‘1.23 USD’; (3) res/values/strings_it.arb changes the Italian translation of ‘change’ from ‘Resto’ (change output) to ‘Cambia’ (verb). None of these changes address an obvious security bug. The parse_fixed change is a robustness improvement for malformed input, not a fix for an injection or overflow. The Lightning change is cleanup for shutdown error handling.
Changed components
cw_bitcoin/lib/lightning/lightning_wallet.dartcw_core/lib/parse_fixed.dartres/values/strings_it.arbInspect captured patch +11 / −2
diff --git a/cw_bitcoin/lib/lightning/lightning_wallet.dart b/cw_bitcoin/lib/lightning/lightning_wallet.dart
index d78c88d1..d93a84b5 100644
--- a/cw_bitcoin/lib/lightning/lightning_wallet.dart
+++ b/cw_bitcoin/lib/lightning/lightning_wallet.dart
@@ -123,7 +123,9 @@ class LightningWallet {
Future<void> close() async {
_eventSubscription?.cancel();
- await _sdk?.disconnect();
+ try {
+ await _sdk?.disconnect();
+ } catch (_) {}
_logSubscription?.cancel();
}
diff --git a/cw_core/lib/parse_fixed.dart b/cw_core/lib/parse_fixed.dart
index fede4df0..51a6a7a5 100644
--- a/cw_core/lib/parse_fixed.dart
+++ b/cw_core/lib/parse_fixed.dart
@@ -29,6 +29,13 @@ BigInt? tryParseFixed(String value, int decimals) {
BigInt parseFixed(String value, int decimals) {
final multiplier = getMultiplier(decimals);
+ /// handle weird cases where users enter spaces and currency after the amount
+ /// This should be handled from UI field to prevent non numerical values
+ /// but will be in the refactoring
+ if (value.contains(" ")) {
+ value = value.split(" ").first;
+ }
+
final negative = value.startsWith("-");
if (negative) value = value.substring(1);
diff --git a/res/values/strings_it.arb b/res/values/strings_it.arb
index 03da71fc..2bd22854 100644
--- a/res/values/strings_it.arb
+++ b/res/values/strings_it.arb
@@ -166,7 +166,7 @@
"centralized": "Centralizzato",
"chain_id": "ID catena",
"chains": "Chain",
- "change": "Resto",
+ "change": "Cambia",
"change_backup_password_alert": "I tuoi file di backup precedenti non potranno essere importati con la nuova password di backup. La nuova password di backup verrà usata solo per i nuovi file di backup. Sei sicuro di voler cambiare la password di backup?",
"change_currency": "Cambia valuta",
"change_current_node": "Sei sicuro di voler cambiare il nodo corrente in ${node}?",
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.