What changed, and why it matters
This commit changes how the app handles fiat amounts typed by users. In some countries, people use a comma (,) as the decimal separator instead of a period (.). The app now converts any commas to periods before processing the amount. This is likely a bug-fix for incorrect amounts, payment failures, or wrong quotes when buying or selling cryptocurrency. It is not clearly a security fix, but bad number parsing in a buy/sell flow can cause real money errors.
Treat as a functional bug fix unless additional vendor guidance says otherwise. Review the full buy/sell flow to confirm downstream parsing uses the normalized value consistently and that validation rejects malformed input (e.g., multiple decimal separators).
Security signals we found
Input normalization in a financial transaction flow
Potential locale-dependent decimal parsing issue that could alter order/payment amounts
No explicit security claim, CVE, or advisory in commit or supplied references
Evidence from the diff
In lib/view_model/buy/buy_sell_view_model.dart, the changeFiatAmount setter now runs amount.replaceAll(‘,’, ‘.’) before assigning to fiatAmount. Previously the raw string was stored. This normalizes European-style decimal separators to the dot format expected by downstream parsing/formatting. The patch is one line and only addresses the input side; it does not show whether parsing, validation, or arithmetic elsewhere is also locale-aware. The commit message gives no security context.
Changed components
lib/view_model/buy/buy_sell_view_model.dartBuy/sell fiat amount input handlingInspect captured patch +1 / −1
diff --git a/lib/view_model/buy/buy_sell_view_model.dart b/lib/view_model/buy/buy_sell_view_model.dart
index 66e5c431..75b31d82 100644
--- a/lib/view_model/buy/buy_sell_view_model.dart
+++ b/lib/view_model/buy/buy_sell_view_model.dart
@@ -294,7 +294,7 @@ abstract class BuySellViewModelBase extends WalletChangeListenerViewModel with S
@action
Future<void> changeFiatAmount({required String amount}) async {
- fiatAmount = amount;
+ fiatAmount = amount.replaceAll(",", ".");
if (amount.isEmpty) {
fiatAmount = '';
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.