fix: sorting of transactions (#3494)
What changed, and why it matters
This update fixes how Cake Wallet displays Zcash transactions. Previously, outgoing transaction fees were shown as zero and transaction timestamps could be wrong or missing. The patch makes fees show the real network fee and improves date/time handling for transactions. There is no direct evidence in the commit of a security vulnerability being exploited, but incorrect fee and time data could mislead users or cause accounting problems.
Treat as a routine bug-fix update. Users relying on accurate Zcash transaction history and fees should update. No immediate security response is indicated by the diff alone. Review the zkool2 dependency changelog for any related security fixes, as the bump may include additional changes not shown.
Security signals we found
Incorrect fee display could lead to user misrepresentation of transaction cost
Incorrect or missing transaction timestamps could affect transaction ordering/auditing
Dependency bump to newer zkool2 commit without disclosed security relevance
Evidence from the diff
The commit modifies cw_zcash Zcash wallet code. In zcash_wallet.dart, outgoing transaction fees now use tx.fee instead of Money.zero. In zkooltx.dart, the time getter is reordered to prefer the transaction timestamp, fall back to now() for unconfirmed (height==0) transactions, and only estimate from block height when no timestamp exists. The fee getter now returns BigInt.from(_tx.fee) rather than value - _calcValue. A fee field is added to JSON serialization/deserialization. The pubspec.yaml updates the zkool2 dependency to a newer commit. These are correctness/display fixes, not memory-safety or cryptographic fixes.
Changed components
cw_zcash/lib/src/zcash_wallet.dartcw_zcash/lib/src/zkooltx.dartcw_zcash/pubspec.yamlZcash transaction display and fee calculationInspect captured patch +15 / −6
diff --git a/cw_zcash/lib/src/zcash_wallet.dart b/cw_zcash/lib/src/zcash_wallet.dart
index 34ae0f1e..14cdf8f6 100644
--- a/cw_zcash/lib/src/zcash_wallet.dart
+++ b/cw_zcash/lib/src/zcash_wallet.dart
@@ -622,7 +622,10 @@ abstract class ZcashWalletBase
final info = ZcashTransactionInfo(
id: tx.txHash,
amount: Money(amount, currency),
- fee: Money.zero(currency),
+ fee: Money(
+ direction == TransactionDirection.outgoing ? tx.fee : BigInt.zero,
+ currency,
+ ),
direction: direction,
isPending: tx.height == 0,
date: tx.time,
diff --git a/cw_zcash/lib/src/zkooltx.dart b/cw_zcash/lib/src/zkooltx.dart
index 6c7c64b3..c70e8847 100644
--- a/cw_zcash/lib/src/zkooltx.dart
+++ b/cw_zcash/lib/src/zkooltx.dart
@@ -33,10 +33,13 @@ class ZkoolTx {
DateTime get time {
final ts = max(_tx.time, _txAccount.time) * 1000;
- if (ts == 0) {
- return ZcashHeight.getTimeByBlockHeight(height);
+ if (ts != 0) {
+ return DateTime.fromMillisecondsSinceEpoch(ts);
}
- return DateTime.fromMillisecondsSinceEpoch(ts);
+ if (height == 0) {
+ return DateTime.now();
+ }
+ return ZcashHeight.getTimeByBlockHeight(height);
}
String? get to => _txAccount.outputs.firstOrNull?.address;
@@ -96,7 +99,8 @@ class ZkoolTx {
BigInt get value => _value.abs();
- BigInt get fee => value - _calcValue;
+ BigInt get fee => BigInt.from(_tx.fee);
+
BigInt get _value {
if (_tx.value != 0) {
@@ -166,6 +170,7 @@ class ZkoolTx {
"height": _tx.height,
"time": _tx.time,
"value": value.toInt(),
+
"tpe": _tx.tpe,
"zsaValue": _tx.zsaValue,
"assetDisplay": _tx.assetDisplay,
@@ -277,6 +282,7 @@ class ZkoolTx {
height: _asInt(txJson["height"]),
time: _asInt(txJson["time"]),
value: _asInt(txJson["value"]),
+ fee: _asInt(txJson["fee"]),
tpe: txJson["tpe"] == null ? null : _asInt(txJson["tpe"]),
zsaValue: _asInt(txJson["zsaValue"]),
assetDisplay: txJson["assetDisplay"] as String? ?? "",
diff --git a/cw_zcash/pubspec.yaml b/cw_zcash/pubspec.yaml
index 3ae75fbd..06754026 100644
--- a/cw_zcash/pubspec.yaml
+++ b/cw_zcash/pubspec.yaml
@@ -21,7 +21,7 @@ dependencies:
# path: ../../zkool2
git:
url: https://github.com/cake-tech/zkool2.git
- ref: 16fd3d11575f850939f498c3ea75d391915456d1
+ ref: 36e72b530c274c4a54a6127aadb94886e84d67bf
path_provider: any
sqflite_common_ffi: any
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.