What changed, and why it matters
This commit makes two small UI/logic fixes in the buy/sell flow of the Cake Wallet app. It disables the Continue button when the amount field is empty, and it avoids a crash when converting an empty fiat amount to crypto or when no exchange rate is available. These are defensive hardening changes rather than a fix for an active security vulnerability.
No urgent action required. Treat as routine hardening. If the app has crash telemetry, verify that related `FormatException` or divide-by-zero reports in the buy/sell flow are resolved. Consider adding unit tests for empty/null fiat amounts and missing rates.
Security signals we found
Input validation added before parsing numeric string
Missing-data guard added before arithmetic operation
UI button disabled when required input is absent
Evidence from the diff
The patch hardens BuySellAmountPage and BuySellViewModel. In the UI, NewPrimaryButton now receives disabled: controller.text.isEmpty, preventing submission with an empty amount. In the view model, setCryptoAmountFromFiat now checks for an empty fiatAmount string and for a missing price entry before calling double.parse and division. Previously, an empty string or missing rate could trigger a FormatException or a divide-by-zero (double.parse('') or division by 0 when the price map returned 0).
Changed components
lib/new-ui/pages/buy_sell/buy_sell_amount_page.dartlib/view_model/buy/buy_sell_view_model.dartInspect captured patch +14 / −2
diff --git a/lib/new-ui/pages/buy_sell/buy_sell_amount_page.dart b/lib/new-ui/pages/buy_sell/buy_sell_amount_page.dart
index c7031c8d..951e2467 100644
--- a/lib/new-ui/pages/buy_sell/buy_sell_amount_page.dart
+++ b/lib/new-ui/pages/buy_sell/buy_sell_amount_page.dart
@@ -290,6 +290,7 @@ class BuySellCustomAmountInput extends StatelessWidget {
Padding(
padding: const EdgeInsets.all(18),
child: NewPrimaryButton(
+ disabled: controller.text.isEmpty,
onPressed: onContinuePressed,
isLoading: isLoading,
text: S.of(context).continue_text,
diff --git a/lib/view_model/buy/buy_sell_view_model.dart b/lib/view_model/buy/buy_sell_view_model.dart
index 048e6162..e936ca4b 100644
--- a/lib/view_model/buy/buy_sell_view_model.dart
+++ b/lib/view_model/buy/buy_sell_view_model.dart
@@ -96,10 +96,21 @@ abstract class BuySellViewModelBase extends WalletChangeListenerViewModel with S
// sets based on the absolute amout (from the fiat/charts api)
// works even if you have no rates
- Future<void> setCryptoAmountFromFiat(String fiatAmount) async => changeCryptoAmount(
- amount: (double.parse(fiatAmount) / (fiatConversionStore.prices[cryptoCurrency] ?? 0))
+ Future<void> setCryptoAmountFromFiat(String fiatAmount) async {
+ if(fiatAmount.isEmpty) {
+ await changeCryptoAmount(amount: "");
+ return;
+ }
+
+ if(fiatConversionStore.prices[cryptoCurrency] == null) {
+ return;
+ }
+
+ await changeCryptoAmount(
+ amount: (double.parse(fiatAmount) / (fiatConversionStore.prices[cryptoCurrency]!))
.toString(),
);
+ }
final AppStore _appStore;
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.