What changed, and why it matters
This commit fixes a small but potentially important bug in how the app looks up saved Monero node/server records by their ID. Previously, the code searched for a column literally named 'id', but the actual stored column name is held in a variable called selfIdColumn. If those names differ, lookups by ID would fail or behave unexpectedly. The change makes the lookup use the correct column name. There is no direct evidence this is a security vulnerability, but incorrect database lookups can sometimes cause app crashes, missing data, or in rare cases be chained into other issues.
Treat as a routine correctness fix. Review whether the old literal 'id' column caused any runtime failures, data loss, or unexpected behavior in production. No immediate security response is indicated by the diff alone, but include the fix in the next release.
Security signals we found
Database query column-name mismatch corrected
Potential lookup failure or data-retrieval bug fixed
No explicit security context in commit message or diff
Evidence from the diff
In cw_core/lib/node.dart, the Node.get(int id) static method previously constructed a SQL WHERE clause using the literal string ‘id = ?’. The patch changes this to ‘${selfIdColumn} = ?’, referencing the class-defined column name variable. This is a correctness fix for a database query. The diff alone does not show whether selfIdColumn differs from ‘id’, nor does it demonstrate any security consequence. It is a one-line bugfix with possible reliability implications.
Changed components
cw_core/lib/node.dartNode.get() static methodMonero node/server record retrievalInspect captured patch +1 / −1
diff --git a/cw_core/lib/node.dart b/cw_core/lib/node.dart
index f4307637..818286a2 100644
--- a/cw_core/lib/node.dart
+++ b/cw_core/lib/node.dart
@@ -205,7 +205,7 @@ class Node {
}
static Future<Node?> get(int id) async {
- return select("id = ?", [id]);
+ return select("${selfIdColumn} = ?", [id]);
}
Why this scored 27/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.