What changed, and why it matters
This commit changes how the app converts a user's entered fiat amount into a cryptocurrency amount when getting a price quote. Previously, if the user's input couldn't be parsed as a number, the app would crash. Now it treats invalid input as zero instead. This is a defensive fix that prevents a crash but may silently produce a zero quote for bad input, which could confuse users. It is not obviously a security vulnerability on its own.
Treat as a routine robustness fix. If reviewing for security, verify that downstream quote logic handles a zero amount safely and that invalid input is surfaced to the user rather than silently producing a zero quote. No urgent security action is indicated by this diff alone.
Security signals we found
Change from throwing parse to non-throwing parse with default fallback
Potential silent degradation: invalid user input now yields zero amount instead of error
No input validation or user feedback added for malformed fiatAmount
No explicit security framing in commit title/message
Evidence from the diff
In lib/view_model/buy/buy_sell_view_model.dart, the amountForQuote method changed from double.parse(fiatAmount) to double.tryParse(fiatAmount) ?? 0. The original code would throw a FormatException if fiatAmount was empty, non-numeric, or malformed, likely causing an unhandled exception/crash in the UI flow. The patch replaces the throwing parse with a fallible parse that defaults to 0.0 on failure. There is no evidence in the commit message or diff that this was disclosed or acknowledged as a security issue.
Changed components
lib/view_model/buy/buy_sell_view_model.dartBuy/sell quote amount calculation flowInspect captured patch +1 / −1
diff --git a/lib/view_model/buy/buy_sell_view_model.dart b/lib/view_model/buy/buy_sell_view_model.dart
index 75b31d82..65fb89c5 100644
--- a/lib/view_model/buy/buy_sell_view_model.dart
+++ b/lib/view_model/buy/buy_sell_view_model.dart
@@ -172,7 +172,7 @@ abstract class BuySellViewModelBase extends WalletChangeListenerViewModel with S
}
Money? amountForQuote(Quote quote) => Money.trySafeParse(
- (double.parse(fiatAmount) / quote.rate).toStringAsFixed(min(20, cryptoCurrency.decimals)),
+ (double.tryParse(fiatAmount) ?? 0 / quote.rate).toStringAsFixed(min(20, cryptoCurrency.decimals)),
cryptoCurrency);
Money? fiatAmountForQuote(Quote quote) {
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.