What changed, and why it matters
This commit is titled 'minor fixes' and mostly contains routine maintenance: pinning a shared library (on_chain) to a specific commit hash, a small UI spacing tweak, a test update, and a few app-logic hardening changes. The most notable security-relevant change is in the Jupiter exchange provider, where the code now explicitly checks that both the 'from' and 'to' currencies are Solana-based tokens before fetching prices or creating trades. Previously, the provider relied on a pre-generated list of supported pairs, which could be bypassed or become stale. Another change hides the recipient address after exchanges involving Zcash, matching the privacy behavior already used for Monero and Wownero. A Solana client cleanup removes an unused HTTP client field, and a send-sheet popup check adds a guard to avoid calling Navigator.pop when the dialog cannot be popped. None of these changes are described by the vendor as security fixes, and no external references or CVEs are supplied.
Treat as a routine maintenance commit. Review the pinned on_chain commit for any relevant upstream changes, verify the Jupiter provider's new currency checks cover all unsupported edge cases, and regression-test exchange flows and Zcash address display. No urgent security patch is indicated by the diff alone.
Security signals we found
Runtime currency-pair validation added to Jupiter exchange provider (prevention of unsupported trade paths)
Zcash receive address hidden post-exchange, consistent with Monero/Wownero privacy behavior
Dependency on on_chain pinned from branch to explicit commit hash (supply-chain/reproducibility)
Navigator.pop guarded with canPop to avoid potential exception/state inconsistency
No vendor description of security relevance, CVE, or researcher attribution present
Evidence from the diff
The diff updates pubspec files across multiple packages to pin the cake-tech/on_chain dependency from the floating branch ‘cake-update-v2’ to a concrete commit (096865a8c6b89c260beadfec04f7e184c40a3273). In cw_solana, an unused httpClient field is removed and the Solana wallet’s balance map is initialized eagerly rather than lazily. In lib/exchange/provider/jupiter_exchange_provider.dart, the constructor no longer pre-computes supported pairs; instead, two runtime checks reject unsupported currency combinations in estimateExchangeAmount and createTrade. In exchange_view_model.dart, WalletType.zcash is added to the list of wallets whose receive address is hidden after a trade. In send_card.dart, a Navigator.canPop guard is added before popping a loading bottom sheet. A UI padding change and a widget test update are also included.
Changed components
lib/exchange/provider/jupiter_exchange_provider.dartlib/view_model/exchange/exchange_view_model.dartlib/src/screens/send/widgets/send_card.dartcw_solana/lib/solana_client.dartcw_solana/lib/solana_wallet.dartpubspec_base.yamlcw_core/pubspec.yamlcw_solana/pubspec.yamlcw_tron/pubspec.yamlmultiple pubspec.lock filesInspect captured patch +39 / −36
diff --git a/cw_bitcoin/pubspec.lock b/cw_bitcoin/pubspec.lock
index 90dbdf60..31b74aeb 100644
--- a/cw_bitcoin/pubspec.lock
+++ b/cw_bitcoin/pubspec.lock
@@ -718,7 +718,7 @@ packages:
dependency: transitive
description:
path: "."
- ref: cake-update-v2
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
diff --git a/cw_core/pubspec.lock b/cw_core/pubspec.lock
index dd5dbaac..3f74f77d 100644
--- a/cw_core/pubspec.lock
+++ b/cw_core/pubspec.lock
@@ -478,7 +478,7 @@ packages:
dependency: "direct main"
description:
path: "."
- ref: cake-update-v2
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
diff --git a/cw_core/pubspec.yaml b/cw_core/pubspec.yaml
index 4dc27a06..949791eb 100644
--- a/cw_core/pubspec.yaml
+++ b/cw_core/pubspec.yaml
@@ -33,7 +33,7 @@ dependencies:
on_chain:
git:
url: https://github.com/cake-tech/on_chain.git
- ref: cake-update-v2
+ ref: 096865a8c6b89c260beadfec04f7e184c40a3273
socks_socket:
git:
url: https://github.com/sneurlax/socks_socket
diff --git a/cw_decred/pubspec.lock b/cw_decred/pubspec.lock
index ab2826fa..035874d9 100644
--- a/cw_decred/pubspec.lock
+++ b/cw_decred/pubspec.lock
@@ -501,8 +501,8 @@ packages:
dependency: transitive
description:
path: "."
- ref: cake-update-v2
- resolved-ref: "93440dc5126369b873ca1fccc13c3c1240b1c5c2"
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
+ resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
version: "3.7.0"
diff --git a/cw_monero/pubspec.lock b/cw_monero/pubspec.lock
index f9ef7a82..9de3df0b 100644
--- a/cw_monero/pubspec.lock
+++ b/cw_monero/pubspec.lock
@@ -598,7 +598,7 @@ packages:
dependency: transitive
description:
path: "."
- ref: cake-update-v2
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
diff --git a/cw_nano/pubspec.lock b/cw_nano/pubspec.lock
index 42df7b8d..f139a4f1 100644
--- a/cw_nano/pubspec.lock
+++ b/cw_nano/pubspec.lock
@@ -563,8 +563,8 @@ packages:
dependency: transitive
description:
path: "."
- ref: cake-update-v2
- resolved-ref: "01cbbacbb05d2113aafa8b7c4a2bb766f749d8d8"
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
+ resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
version: "3.7.0"
diff --git a/cw_solana/lib/solana_client.dart b/cw_solana/lib/solana_client.dart
index 31e9c3ab..bd83a4cb 100644
--- a/cw_solana/lib/solana_client.dart
+++ b/cw_solana/lib/solana_client.dart
@@ -33,7 +33,6 @@ class TransactionFetchResult {
class SolanaWalletClient {
// Minimum amount in SOL to consider a transaction valid (to filter spam)
static const double minValidAmount = 0.00000003;
- final httpClient = ProxyWrapper().getHttpClient();
late final client = ProxyWrapper().getHttpIOClient();
SolanaRPC? _provider;
diff --git a/cw_solana/lib/solana_wallet.dart b/cw_solana/lib/solana_wallet.dart
index 7a7c2ccb..8e78fd42 100644
--- a/cw_solana/lib/solana_wallet.dart
+++ b/cw_solana/lib/solana_wallet.dart
@@ -98,7 +98,8 @@ abstract class SolanaWalletBase
@override
@observable
- late ObservableMap<CryptoCurrency, SolanaBalance> balance;
+ ObservableMap<CryptoCurrency, SolanaBalance> balance =
+ ObservableMap<CryptoCurrency, SolanaBalance>();
final Completer<SharedPreferences> _sharedPrefs = Completer();
diff --git a/cw_solana/pubspec.yaml b/cw_solana/pubspec.yaml
index c91ca6ef..fdc946c0 100644
--- a/cw_solana/pubspec.yaml
+++ b/cw_solana/pubspec.yaml
@@ -23,7 +23,7 @@ dependencies:
on_chain:
git:
url: https://github.com/cake-tech/on_chain.git
- ref: cake-update-v2
+ ref: 096865a8c6b89c260beadfec04f7e184c40a3273
blockchain_utils:
git:
url: https://github.com/cake-tech/blockchain_utils
diff --git a/cw_tron/pubspec.yaml b/cw_tron/pubspec.yaml
index 57c99286..f406f3ac 100644
--- a/cw_tron/pubspec.yaml
+++ b/cw_tron/pubspec.yaml
@@ -18,7 +18,7 @@ dependencies:
on_chain:
git:
url: https://github.com/cake-tech/on_chain.git
- ref: cake-update-v2
+ ref: 096865a8c6b89c260beadfec04f7e184c40a3273
blockchain_utils:
git:
url: https://github.com/cake-tech/blockchain_utils
diff --git a/cw_wownero/pubspec.lock b/cw_wownero/pubspec.lock
index ce8192f8..fdc254a1 100644
--- a/cw_wownero/pubspec.lock
+++ b/cw_wownero/pubspec.lock
@@ -518,8 +518,8 @@ packages:
dependency: transitive
description:
path: "."
- ref: cake-update-v2
- resolved-ref: "93440dc5126369b873ca1fccc13c3c1240b1c5c2"
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
+ resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
version: "3.7.0"
diff --git a/cw_zano/pubspec.lock b/cw_zano/pubspec.lock
index 826e385b..15245131 100644
--- a/cw_zano/pubspec.lock
+++ b/cw_zano/pubspec.lock
@@ -515,8 +515,8 @@ packages:
dependency: transitive
description:
path: "."
- ref: cake-update-v2
- resolved-ref: "93440dc5126369b873ca1fccc13c3c1240b1c5c2"
+ ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
+ resolved-ref: "096865a8c6b89c260beadfec04f7e184c40a3273"
url: "https://github.com/cake-tech/on_chain.git"
source: git
version: "3.7.0"
diff --git a/lib/exchange/provider/jupiter_exchange_provider.dart b/lib/exchange/provider/jupiter_exchange_provider.dart
index 3a91a1b5..a2bb6909 100644
--- a/lib/exchange/provider/jupiter_exchange_provider.dart
+++ b/lib/exchange/provider/jupiter_exchange_provider.dart
@@ -17,29 +17,16 @@ import 'package:cw_core/utils/print_verbose.dart';
import 'package:cw_core/utils/proxy_wrapper.dart';
class JupiterExchangeProvider extends ExchangeProvider {
- JupiterExchangeProvider() : super(pairList: _getSupportedPairs());
+ JupiterExchangeProvider();
// Jupiter only supports Solana tokens
static const List<CryptoCurrency> _notSupported = [];
- static List<ExchangePair> _getSupportedPairs() {
- // Only support Solana and Solana tokens
- final solanaCurrencies = CryptoCurrency.all
+ static final List<CryptoCurrency> _supportedCurrencies = CryptoCurrency.all
.where((c) => c.tag == 'SOL' || c == CryptoCurrency.sol)
.where((c) => !_notSupported.contains(c))
.toList();
- final pairs = <ExchangePair>[];
- for (final from in solanaCurrencies) {
- for (final to in solanaCurrencies) {
- if (from != to) {
- pairs.add(ExchangePair(from: from, to: to, reverse: true));
- }
- }
- }
- return pairs;
- }
-
static const _baseUrl = 'api.jup.ag';
static const _orderPath = '/ultra/v1/order';
static const _executePath = '/ultra/v1/execute';
@@ -148,6 +135,10 @@ class JupiterExchangeProvider extends ExchangeProvider {
required bool isReceiveAmount,
}) async {
try {
+ // must support both
+ if (!_supportedCurrencies.contains(from) || !_supportedCurrencies.contains(to)) {
+ return 0.0;
+ }
final inputMint = _getTokenMint(from);
final outputMint = _getTokenMint(to);
@@ -235,6 +226,12 @@ class JupiterExchangeProvider extends ExchangeProvider {
required bool isSendAll,
}) async {
try {
+ // must support both
+ if (!_supportedCurrencies.contains(request.fromCurrency) ||
+ !_supportedCurrencies.contains(request.toCurrency)) {
+ throw "not supported currencies";
+ }
+
final inputMint = _getTokenMint(request.fromCurrency);
final outputMint = _getTokenMint(request.toCurrency);
diff --git a/lib/src/screens/new_wallet/advanced_privacy_settings_page.dart b/lib/src/screens/new_wallet/advanced_privacy_settings_page.dart
index 7f2c6587..bfdb65ae 100644
--- a/lib/src/screens/new_wallet/advanced_privacy_settings_page.dart
+++ b/lib/src/screens/new_wallet/advanced_privacy_settings_page.dart
@@ -300,7 +300,7 @@ class _AdvancedPrivacySettingsBodyState extends State<_AdvancedPrivacySettingsBo
bottomSectionPadding: EdgeInsets.all(24),
bottomSection: Column(
children: [
- const SizedBox(height: 24),
+ const SizedBox(height: 4),
LayoutBuilder(
builder: (_, constraints) => SizedBox(
width: constraints.maxWidth * 0.8,
diff --git a/lib/src/screens/send/widgets/send_card.dart b/lib/src/screens/send/widgets/send_card.dart
index 3cc1d50f..a27adea4 100644
--- a/lib/src/screens/send/widgets/send_card.dart
+++ b/lib/src/screens/send/widgets/send_card.dart
@@ -361,7 +361,9 @@ class SendCardState extends State<SendCard> with AutomaticKeepAliveClientMixin<S
}
await Future.delayed(const Duration(seconds: 2));
- if (loadingBottomSheetContext != null && loadingBottomSheetContext!.mounted) {
+ if (loadingBottomSheetContext != null &&
+ loadingBottomSheetContext!.mounted &&
+ Navigator.canPop(loadingBottomSheetContext!)) {
Navigator.of(loadingBottomSheetContext!).pop();
}
diff --git a/lib/view_model/exchange/exchange_view_model.dart b/lib/view_model/exchange/exchange_view_model.dart
index d487b328..c023f91b 100644
--- a/lib/view_model/exchange/exchange_view_model.dart
+++ b/lib/view_model/exchange/exchange_view_model.dart
@@ -213,7 +213,7 @@ abstract class ExchangeViewModelBase extends WalletChangeListenerViewModel with
].contains(wallet.type);
bool get hideAddressAfterExchange =>
- [WalletType.monero, WalletType.wownero].contains(wallet.type);
+ [WalletType.monero, WalletType.wownero, WalletType.zcash].contains(wallet.type);
bool _useTorOnly;
final Box<Trade> trades;
diff --git a/pubspec_base.yaml b/pubspec_base.yaml
index d0c6090f..4c119500 100644
--- a/pubspec_base.yaml
+++ b/pubspec_base.yaml
@@ -126,7 +126,7 @@ dependencies:
on_chain:
git:
url: https://github.com/cake-tech/on_chain.git
- ref: cake-update-v2
+ ref: 096865a8c6b89c260beadfec04f7e184c40a3273
reown_walletkit:
path: ./scripts/reown_flutter/packages/reown_walletkit
blockchain_utils:
diff --git a/test/widget_test.dart b/test/widget_test.dart
index 2c7ba24a..c79ce99a 100644
--- a/test/widget_test.dart
+++ b/test/widget_test.dart
@@ -5,15 +5,19 @@
// gestures. You can also use WidgetTester to find child widgets in the widget
// tree, read text, and verify that the values of widget properties are correct.
+import 'dart:async';
+
import 'package:flutter/material.dart';
import 'package:flutter_test/flutter_test.dart';
import 'package:cake_wallet/main.dart';
+final quickActionsStream = StreamController<Uri?>.broadcast();
+
void main() {
testWidgets('Counter increments smoke test', (WidgetTester tester) async {
// Build our app and trigger a frame.
- await tester.pumpWidget(App());
+ await tester.pumpWidget(App(quickActionsStream: quickActionsStream.stream));
// Verify that our counter starts at 0.
expect(find.text('0'), findsOneWidget);
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.