Disable Jupiter limits for non-solana swaps (#2880)
What changed, and why it matters
This update makes three small fixes in the Cake Wallet app: it stops using a hidden note field when decoding Zcash payment addresses, removes Jupiter swap limits for non-Solana trades, and adds missing Zcash QR-code restore labels. The Zcash memo change is the most security-relevant because it prevents a payment request from silently carrying an unexpected message, but the commit itself does not describe this as a security fix and no exploit is demonstrated.
Treat as a routine bug-fix release. Review the Zcash memo change for correctness, since it alters payment-request behavior. No urgent security response is indicated from the diff alone.
Security signals we found
Zcash payment URI memo now defaults to empty instead of inheriting output.note, reducing risk of unintended memo injection
Jupiter fetchLimits now validates currency support before returning null limits
QR restore mapping now includes zcash/zcash-wallet/zcash_wallet, closing a restore-gap
Evidence from the diff
The commit modifies six files. The key change in cw_zcash/lib/src/zcash_wallet.dart replaces String memo = output.note ?? ''; with String memo = '';, so decoded payment URIs no longer inherit any memo from the wallet output. The Jupiter provider now only returns open limits when both currencies are in _supportedCurrencies; otherwise it throws. Wallet restore and key export gain Zcash type strings. Version/build numbers are bumped. There is no explicit security framing by the vendor.
Changed components
cw_zcash/lib/src/zcash_wallet.dartlib/exchange/provider/jupiter_exchange_provider.dartlib/view_model/restore/wallet_restore_from_qr_code.dartlib/view_model/wallet_keys_view_model.dartscripts/android/app_env.shscripts/ios/app_env.shInspect captured patch +19 / −14
diff --git a/cw_zcash/lib/src/zcash_wallet.dart b/cw_zcash/lib/src/zcash_wallet.dart
index e9a44adb..386e69f4 100644
--- a/cw_zcash/lib/src/zcash_wallet.dart
+++ b/cw_zcash/lib/src/zcash_wallet.dart
@@ -175,7 +175,8 @@ abstract class ZcashWalletBase
}
final paymentUri = WarpApi.decodePaymentURI(coin, address);
- String memo = output.note ?? '';
+ // String memo = output.note ?? '';
+ String memo = '';
if (paymentUri != null && paymentUri.address != null) {
address = paymentUri.address!;
if (memo.isEmpty && paymentUri.memo != null) {
diff --git a/lib/exchange/provider/jupiter_exchange_provider.dart b/lib/exchange/provider/jupiter_exchange_provider.dart
index a10920b1..2bd5708e 100644
--- a/lib/exchange/provider/jupiter_exchange_provider.dart
+++ b/lib/exchange/provider/jupiter_exchange_provider.dart
@@ -81,16 +81,17 @@ class JupiterExchangeProvider extends ExchangeProvider {
required CryptoCurrency to,
required bool isFixedRateMode,
}) async {
- try {
- // The Ultra Swap API doesn't have a dedicated limits endpoint
- // The /order endpoint validates amounts and returns error codes:
- // - errorCode 1: Insufficient funds
- // - errorCode 2: Top up SOL for gas
- // - errorCode 3: Minimum amount for gasless
+ // The Ultra Swap API doesn't have a dedicated limits endpoint
+ // The /order endpoint validates amounts and returns error codes:
+ // - errorCode 1: Insufficient funds
+ // - errorCode 2: Top up SOL for gas
+ // - errorCode 3: Minimum amount for gasless
+
+ // only return null for supported currencies
+ if (_supportedCurrencies.contains(from) && _supportedCurrencies.contains(to)) {
return Limits(min: null, max: null);
- } catch (e) {
- printV('fetchLimits error: $e');
- throw Exception('Error fetching limits: $e');
+ } else {
+ throw Exception('not supported');
}
}
diff --git a/lib/view_model/restore/wallet_restore_from_qr_code.dart b/lib/view_model/restore/wallet_restore_from_qr_code.dart
index 5548d29e..4217aab5 100644
--- a/lib/view_model/restore/wallet_restore_from_qr_code.dart
+++ b/lib/view_model/restore/wallet_restore_from_qr_code.dart
@@ -54,7 +54,10 @@ class WalletRestoreFromQRCode {
'decred_wallet': WalletType.decred,
'dogecoin': WalletType.dogecoin,
'dogecoin-wallet': WalletType.dogecoin,
- 'dogecoin_wallet': WalletType.dogecoin
+ 'dogecoin_wallet': WalletType.dogecoin,
+ 'zcash': WalletType.zcash,
+ 'zcash-wallet': WalletType.zcash,
+ 'zcash_wallet': WalletType.zcash,
};
static WalletType? _extractWalletType(String code) {
diff --git a/lib/view_model/wallet_keys_view_model.dart b/lib/view_model/wallet_keys_view_model.dart
index a1f68a4c..e6f51d9a 100644
--- a/lib/view_model/wallet_keys_view_model.dart
+++ b/lib/view_model/wallet_keys_view_model.dart
@@ -308,7 +308,7 @@ abstract class WalletKeysViewModelBase with Store {
return 'dogecoin-wallet';
case WalletType.zcash:
return 'zcash-wallet';
- default:
+ case WalletType.none:
throw Exception('Unexpected wallet type: ${_wallet.type.toString()} for wallet keys');
}
}
diff --git a/scripts/android/app_env.sh b/scripts/android/app_env.sh
index 8e19bd1d..5c8cc8a1 100644
--- a/scripts/android/app_env.sh
+++ b/scripts/android/app_env.sh
@@ -22,7 +22,7 @@ MONERO_COM_SCHEME="monero.com"
CAKEWALLET_NAME="Cake Wallet"
CAKEWALLET_VERSION="5.9.0"
-CAKEWALLET_BUILD_NUMBER=4302
+CAKEWALLET_BUILD_NUMBER=4304
CAKEWALLET_BUNDLE_ID="com.cakewallet.cake_wallet"
CAKEWALLET_PACKAGE="com.cakewallet.cake_wallet"
CAKEWALLET_SCHEME="cakewallet"
diff --git a/scripts/ios/app_env.sh b/scripts/ios/app_env.sh
index e2049b3f..088924bf 100644
--- a/scripts/ios/app_env.sh
+++ b/scripts/ios/app_env.sh
@@ -18,7 +18,7 @@ MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
CAKEWALLET_VERSION="5.9.0"
-CAKEWALLET_BUILD_NUMBER=369
+CAKEWALLET_BUILD_NUMBER=372
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.