What changed, and why it matters
This commit fixes a simple but meaningful math bug caused by missing parentheses. In the original code, the conversion from fiat to crypto amount was calculated incorrectly because division happened before the fallback to zero. Depending on the value of quote.rate, this could produce wrong crypto amounts when a user buys or sells cryptocurrency through the app. The fix makes sure the fiat amount is determined first, then divided by the exchange rate.
Review related buy/sell amount calculations for similar precedence issues, add unit tests covering null/empty/malformed fiatAmount inputs, and verify that quote.rate is validated (non-zero, finite) before division. Consider logging or rejecting invalid fiat inputs rather than silently defaulting to zero.
Security signals we found
Operator-precedence bug in financial amount calculation
Potential incorrect cryptocurrency purchase/sale amount
Null value passed to money parsing helper
No explicit input validation on fiatAmount before parsing
Evidence from the diff
The Dart expression (double.tryParse(fiatAmount) ?? 0 / quote.rate) was parsed as double.tryParse(fiatAmount) ?? (0 / quote.rate) due to operator precedence: division binds tighter than the null-coalescing operator ??. As a result, when fiatAmount could not be parsed, the expression evaluated to null rather than 0, and Money.trySafeParse received the string 'null' (or a division-by-null/zero edge case depending on quote.rate). The fix adds parentheses so the expression becomes ((double.tryParse(fiatAmount) ?? 0) / quote.rate), ensuring the parsed or default fiat value is divided by the rate. This is a correctness fix in the buy/sell quote calculation path.
Changed components
lib/view_model/buy/buy_sell_view_model.dartBuy/sell quote amount calculationMoney.trySafeParse integrationInspect captured patch +1 / −1
diff --git a/lib/view_model/buy/buy_sell_view_model.dart b/lib/view_model/buy/buy_sell_view_model.dart
index 65fb89c5..7122be97 100644
--- a/lib/view_model/buy/buy_sell_view_model.dart
+++ b/lib/view_model/buy/buy_sell_view_model.dart
@@ -172,7 +172,7 @@ abstract class BuySellViewModelBase extends WalletChangeListenerViewModel with S
}
Money? amountForQuote(Quote quote) => Money.trySafeParse(
- (double.tryParse(fiatAmount) ?? 0 / quote.rate).toStringAsFixed(min(20, cryptoCurrency.decimals)),
+ ((double.tryParse(fiatAmount) ?? 0) / quote.rate).toStringAsFixed(min(20, cryptoCurrency.decimals)),
cryptoCurrency);
Money? fiatAmountForQuote(Quote quote) {
Why this scored 48/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.