remove old ln hack in scan parsing logic
What changed, and why it matters
This commit removes some old, disabled code paths for handling Lightning Network and OpenCryptoPay QR code scans. The removed logic is commented out with 'false &&' guards, so it was already inactive. The practical effect is that scanning certain QR codes will now fall through to the remaining handler (WalletConnect 'wc:' scheme) instead of being processed by the old Lightning-specific logic. There is no clear security fix here; it appears to be cleanup of dead code.
Treat as routine cleanup. If the old Lightning parsing logic is being permanently retired, ensure related helper functions (getBolt11Amount, LNURL.getPayRequestAmount, isNonZeroAmountLightningInvoice, isLnurlInvoice, OpenCryptoPayService.isOpenCryptoPayQR) are also removed or marked deprecated to avoid future confusion. No immediate security action required.
Security signals we found
Removal of legacy Lightning/Bolt11/LNURL parsing paths
Old code relied on external parsing helpers (getBolt11Amount, LNURL.getPayRequestAmount) that are no longer invoked
No explicit security claim in commit title or message
Evidence from the diff
The change comments out four conditional branches in CoinActionRow’s QR scan parsing: isNonZeroAmountLightningInvoice, isLnurlInvoice, isOpenCryptoPayQR, and the fallback now only checks for WalletConnect ‘wc:’ scheme. The branches were already disabled by prepending ‘false &&’. This removes a ‘hack’ for Lightning invoice parsing. No active vulnerability is visible in the diff; the old code called getBolt11Amount and LNURL.getPayRequestAmount on scanned codes, which could have been a parsing/validation concern, but it is no longer reachable.
Changed components
lib/new-ui/widgets/coins_page/action_row/coin_action_row.dartInspect captured patch +12 / −11
diff --git a/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart b/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart
index 7ac50523..db877e1e 100644
--- a/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart
+++ b/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart
@@ -163,17 +163,18 @@ class CoinActionRow extends StatelessWidget {
late final PaymentRequest req;
var unspentCoinType = UnspentCoinType.any;
- if (SendViewModelBase.isNonZeroAmountLightningInvoice(code)) {
- unspentCoinType = UnspentCoinType.lightning;
- final amount = CryptoCurrency.btcln.formatAmount(BigInt.from(getBolt11Amount(code) ?? 0));
- req = PaymentRequest(code, amount, "", "", "");
- } else if (SendViewModelBase.isLnurlInvoice(code)) {
- unspentCoinType = UnspentCoinType.lightning;
- final amount = CryptoCurrency.btcln.formatAmount(BigInt.from(await LNURL.getPayRequestAmount(code) ?? 0));
- req = PaymentRequest(code, amount, "", "", "");
- } else if (OpenCryptoPayService.isOpenCryptoPayQR(code)) {
- req = PaymentRequest(code, "", "", "", "");
- } else if (Uri.tryParse(code)?.scheme == "wc") {
+ // if (false && SendViewModelBase.isNonZeroAmountLightningInvoice(code)) {
+ // unspentCoinType = UnspentCoinType.lightning;
+ // final amount = CryptoCurrency.btcln.formatAmount(BigInt.from(getBolt11Amount(code) ?? 0));
+ // req = PaymentRequest(code, amount, "", "", "");
+ // } else if (false && SendViewModelBase.isLnurlInvoice(code)) {
+ // unspentCoinType = UnspentCoinType.lightning;
+ // final amount = CryptoCurrency.btcln.formatAmount(BigInt.from(await LNURL.getPayRequestAmount(code) ?? 0));
+ // req = PaymentRequest(code, amount, "", "", "");
+ // } else if (false &&OpenCryptoPayService.isOpenCryptoPayQR(code)) {
+ // req = PaymentRequest(code, "", "", "", "");
+ // } else
+ if (Uri.tryParse(code)?.scheme == "wc") {
if (!isWalletConnectCompatibleChain(walletType)) {
showPopUp<void>(
context: context,
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.