What changed, and why it matters
This commit makes two small hardening changes in a cryptocurrency wallet app. It switches log writes to a synchronous (blocking) mode, which helps avoid file corruption if multiple log lines arrive quickly. It also replaces a strict number parser with a safer one that falls back to zero when the amount text is invalid, preventing the app from crashing if a user enters a non-numeric value in a fiat conversion field.
No urgent action required. The changes are minor hardening fixes. Reviewers may want to confirm that synchronous log writes do not block the UI thread in production, and verify that defaulting invalid amounts to 0 is the desired UX rather than showing an error message.
Security signals we found
Crash avoidance via safer parsing of user-controlled numeric input
Log integrity improvement via synchronous file writes
No explicit security framing by the vendor
Evidence from the diff
The diff contains two unrelated fixes. In cw_bitcoin/lib/lightning/lightning_wallet.dart, writeAsString is replaced with writeAsStringSync for log entries. The async version returns a Future whose completion is not awaited, so rapid successive writes could interleave or fail silently; the synchronous version blocks until each write completes. In lib/view_model/wallet_address_list/wallet_address_list_view_model.dart, double.parse(_amount) is replaced with double.tryParse(_amount) ?? 0 in two MobX computed getters (fiatAmount and selectedCurrencyFiatAmount). This prevents FormatException crashes when _amount is empty, malformed, or null-ish.
Changed components
cw_bitcoin/lib/lightning/lightning_wallet.dartlib/view_model/wallet_address_list/wallet_address_list_view_model.dartInspect captured patch +6 / −4
diff --git a/cw_bitcoin/lib/lightning/lightning_wallet.dart b/cw_bitcoin/lib/lightning/lightning_wallet.dart
index da926467..8f713b21 100644
--- a/cw_bitcoin/lib/lightning/lightning_wallet.dart
+++ b/cw_bitcoin/lib/lightning/lightning_wallet.dart
@@ -43,9 +43,9 @@ class LightningWallet {
void _subscribeToLogStream(File logFile) {
_logSubscription = _logStream?.listen((logEntry) {
- logFile.writeAsString("[${logEntry.level}] ${logEntry.line}\n", mode: FileMode.append);
+ logFile.writeAsStringSync("[${logEntry.level}] ${logEntry.line}\n", mode: FileMode.append);
}, onError: (e) {
- logFile.writeAsString("[ERROR] $e\n", mode: FileMode.append);
+ logFile.writeAsStringSync("[ERROR] $e\n", mode: FileMode.append);
});
}
diff --git a/lib/view_model/wallet_address_list/wallet_address_list_view_model.dart b/lib/view_model/wallet_address_list/wallet_address_list_view_model.dart
index 3620b138..8d2d2df3 100644
--- a/lib/view_model/wallet_address_list/wallet_address_list_view_model.dart
+++ b/lib/view_model/wallet_address_list/wallet_address_list_view_model.dart
@@ -146,13 +146,15 @@ abstract class WalletAddressListViewModelBase extends WalletChangeListenerViewMo
}
if (!fiatConversionStore.prices.containsKey(cryptoCurrency)) return "";
- return (double.parse(_amount) * fiatConversionStore.prices[cryptoCurrency]!).toStringAsFixed(2);
+ final amount = double.tryParse(_amount) ?? 0;
+ return (amount * fiatConversionStore.prices[cryptoCurrency]!).toStringAsFixed(2);
}
@computed
String get selectedCurrencyFiatAmount {
if (_fiatRate == null) return "";
- return (double.parse(_amount) * _fiatRate!).toStringAsFixed(2);
+ final amount = double.tryParse(_amount) ?? 0;
+ return (amount * _fiatRate!).toStringAsFixed(2);
}
@action
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.