make walletconnect work from the scan button
What changed, and why it matters
This commit lets users scan a WalletConnect QR code from the main scan button. It adds a check that the current wallet supports EVM-compatible chains before allowing the connection, and routes the scanned 'wc:' URI into the existing WalletConnect pairing flow. It also bumps a Lightning SDK dependency version in the iOS lockfile. There is no obvious security fix or vulnerability being patched; it reads like a feature/UX improvement.
Treat as a routine feature commit. If reviewing for security, verify that walletKitService.pairWithUri handles malformed or malicious 'wc:' URIs safely, that the EVM-compatibility check cannot be bypassed, and review the breez_sdk_spark_flutter 0.11.0 changelog for any security fixes. No immediate incident response is indicated by the diff alone.
Security signals we found
New URI scheme handling ('wc:') added to a scan/deep-link path
User-facing guard added to restrict WalletConnect to EVM-compatible wallets
Third-party SDK version bump without disclosed security relevance
No input sanitization beyond Uri.tryParse and scheme check
Evidence from the diff
The change wires the home-page scan button to recognize ‘wc:’ URIs and pass them to WalletConnectConnectionsView, which now calls walletKitService.pairWithUri directly for ‘wc:’ schemes. A guard is added in CoinActionRow to show a popup if the active wallet is not EVM-compatible. The iOS Podfile.lock updates breez_sdk_spark_flutter from 0.9.1 to 0.11.0, but no release notes or security advisory for that bump is supplied.
Changed components
lib/new-ui/widgets/coins_page/action_row/coin_action_row.dartlib/src/screens/wallet_connect/wc_connections_listing_view.dartlib/new-ui/pages/home_page.dartios/Podfile.lock (breez_sdk_spark_flutter 0.9.1 -> 0.11.0)Inspect captured patch +38 / −8
diff --git a/ios/Podfile.lock b/ios/Podfile.lock
index 071f654b..bb969861 100644
--- a/ios/Podfile.lock
+++ b/ios/Podfile.lock
@@ -1,7 +1,7 @@
PODS:
- bitbox_flutter (0.0.1):
- Flutter
- - breez_sdk_spark_flutter (0.9.1):
+ - breez_sdk_spark_flutter (0.11.0):
- Flutter
- connectivity_plus (0.0.1):
- Flutter
@@ -303,7 +303,7 @@ EXTERNAL SOURCES:
SPEC CHECKSUMS:
bitbox_flutter: 506f80b961ddf646b0d80cef9f6eadaab96d91b0
- breez_sdk_spark_flutter: e96b24d1c0ca1ef7dec122dd7bbf63eb921f97f4
+ breez_sdk_spark_flutter: e7d0201b7001ff16f85a7c4820592db5728d4c27
connectivity_plus: 2a701ffec2c0ae28a48cf7540e279787e77c447d
CryptoSwift: e64e11850ede528a02a0f3e768cec8e9d92ecb90
cw_decred: 9c0e1df74745b51a1289ec5e91fb9e24b68fa14a
diff --git a/lib/new-ui/pages/home_page.dart b/lib/new-ui/pages/home_page.dart
index be30e72b..0fd2b958 100644
--- a/lib/new-ui/pages/home_page.dart
+++ b/lib/new-ui/pages/home_page.dart
@@ -159,11 +159,15 @@ class _NewHomePageState extends State<NewHomePage> {
builder: (_) {
return Column(
children: [
- CoinActionRow(
- lightningMode: _lightningMode,
- showSwap: widget.dashboardViewModel.isEnabledSwapAction,),
- MwebAd(dashboardViewModel: widget.dashboardViewModel,),
- ],
+ CoinActionRow(
+ lightningMode: _lightningMode,
+ showSwap: widget.dashboardViewModel.isEnabledSwapAction,
+ walletType: widget.dashboardViewModel.wallet.type,
+ ),
+ MwebAd(
+ dashboardViewModel: widget.dashboardViewModel,
+ ),
+ ],
);
},
),
diff --git a/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart b/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart
index 7732f92a..10a411c2 100644
--- a/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart
+++ b/lib/new-ui/widgets/coins_page/action_row/coin_action_row.dart
@@ -6,15 +6,19 @@ import 'package:cake_wallet/generated/i18n.dart';
import 'package:cake_wallet/new-ui/modal_navigator.dart';
import 'package:cake_wallet/new-ui/pages/send_page.dart';
import 'package:cake_wallet/new-ui/pages/swap_page.dart';
+import 'package:cake_wallet/reactions/wallet_connect.dart';
import 'package:cake_wallet/routes.dart';
+import 'package:cake_wallet/src/widgets/alert_with_one_action.dart';
import 'package:cake_wallet/src/widgets/cake_image_widget.dart';
import 'package:cake_wallet/utils/feature_flag.dart';
import 'package:cake_wallet/utils/payment_request.dart';
+import 'package:cake_wallet/utils/show_pop_up.dart';
import 'package:cake_wallet/view_model/send/send_view_model.dart';
import 'package:cake_wallet/view_model/wallet_address_list/wallet_address_list_view_model.dart';
import 'package:cw_core/crypto_currency.dart';
import 'package:cw_core/lnurl.dart';
import 'package:cw_core/unspent_coin_type.dart';
+import 'package:cw_core/wallet_type.dart';
import 'package:flutter/material.dart';
import 'package:flutter_svg/svg.dart';
import 'package:modal_bottom_sheet/modal_bottom_sheet.dart';
@@ -24,10 +28,11 @@ import '../../../pages/scan_page.dart';
import 'coin_action_button.dart';
class CoinActionRow extends StatelessWidget {
- const CoinActionRow({super.key, this.lightningMode = false, this.showSwap = true});
+ const CoinActionRow({super.key, this.lightningMode = false, this.showSwap = true, required this.walletType});
final bool lightningMode;
final bool showSwap;
+ final WalletType walletType;
@override
Widget build(BuildContext context) {
@@ -178,6 +183,21 @@ class CoinActionRow extends StatelessWidget {
req = PaymentRequest(code, amount, "", "", "");
} else if (OpenCryptoPayService.isOpenCryptoPayQR(code)) {
req = PaymentRequest(code, "", "", "", "");
+ } else if (Uri.tryParse(code)?.scheme == "wc") {
+ if (!isEVMCompatibleChain(walletType)) {
+ showPopUp<void>(
+ context: context,
+ builder: (context) => AlertWithOneAction(
+ alertTitle: "WalletConnect",
+ alertContent: S.of(context).switchToEVMCompatibleWallet,
+ buttonText: "OK",
+ buttonAction: Navigator.of(context).pop));
+ return;
+ }
+
+ Navigator.of(context)
+ .pushNamed(Routes.walletConnectConnectionsListing, arguments: Uri.parse(code));
+ return;
} else {
final uri = Uri.tryParse(code);
if (uri == null) return;
diff --git a/lib/src/screens/wallet_connect/wc_connections_listing_view.dart b/lib/src/screens/wallet_connect/wc_connections_listing_view.dart
index 46618a6e..5bc60cfd 100644
--- a/lib/src/screens/wallet_connect/wc_connections_listing_view.dart
+++ b/lib/src/screens/wallet_connect/wc_connections_listing_view.dart
@@ -12,6 +12,7 @@ import 'package:cake_wallet/entities/qr_scanner.dart';
import 'package:cake_wallet/src/widgets/primary_button.dart';
import 'package:cake_wallet/utils/show_pop_up.dart';
import 'package:cake_wallet/utils/permission_handler.dart';
+import 'package:url_launcher/url_launcher.dart';
import 'widgets/wc_pairing_item_widget.dart';
import 'wc_pairing_detail_page.dart';
@@ -27,6 +28,11 @@ class WalletConnectConnectionsView extends StatelessWidget {
void _triggerPairingFromDeeplink(Uri? launchUri) async {
if (launchUri == null) return;
+ if(launchUri.scheme == "wc") {
+ await walletKitService.pairWithUri(launchUri);
+ return;
+ }
+
final actualLinkList = launchUri.query.split("uri=");
if (actualLinkList.length <= 1) return;
Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.