refactor: remove double `_nextIndex` increment in `wallet_hardware_restore_view_model` (#2703)
What changed, and why it matters
This commit removes an extra counter advance in the hardware-wallet account discovery screen. Previously, after loading a batch of accounts from a hardware wallet, the app advanced its internal index twice, which could cause some accounts to be skipped when the user scrolled to load more. The fix makes account listing more complete and predictable, but it is a UI/logic bug rather than a direct security vulnerability.
Treat as a routine bug fix. Verify that hardware-wallet account discovery now lists accounts sequentially without gaps across pagination. No immediate security response is indicated from the diff alone.
Security signals we found
Logic error causing skipped account ranges in hardware wallet account discovery
No input validation, cryptographic, or authorization changes observed
No memory safety, injection, or secret-handling changes observed
Evidence from the diff
In wallet_hardware_restore_view_model.dart, getNextAvailableAccounts(int limit) previously called service.getAvailableAccounts(index: _nextIndex, limit: limit), added the returned accounts to availableAccounts, and then incremented _nextIndex by limit. The underlying service or caller was also advancing _nextIndex, so the index advanced twice per batch, skipping account ranges on subsequent loads. The patch removes the explicit _nextIndex += limit and two unused imports. This is a correctness/refactoring fix for account enumeration during hardware-wallet restore.
Changed components
lib/view_model/wallet_hardware_restore_view_model.dartHardware wallet restore / account discovery UI flowInspect captured patch +1 / −4
diff --git a/lib/view_model/wallet_hardware_restore_view_model.dart b/lib/view_model/wallet_hardware_restore_view_model.dart
index 58585a66..16491d43 100644
--- a/lib/view_model/wallet_hardware_restore_view_model.dart
+++ b/lib/view_model/wallet_hardware_restore_view_model.dart
@@ -14,9 +14,7 @@ import 'package:cw_core/hardware/hardware_account_data.dart';
import 'package:cw_core/utils/print_verbose.dart';
import 'package:cw_core/wallet_base.dart';
import 'package:cw_core/wallet_credentials.dart';
-import 'package:cw_core/wallet_info.dart';
import 'package:cw_core/wallet_type.dart';
-import 'package:hive/hive.dart';
import 'package:mobx/mobx.dart';
part 'wallet_hardware_restore_view_model.g.dart';
@@ -57,7 +55,7 @@ abstract class WalletHardwareRestoreViewModelBase extends WalletCreationVM with
Future<void> getNextAvailableAccounts(int limit) async {
try {
final service = await hardwareWalletVM.getHardwareWalletService(type);
- List<HardwareAccountData> accounts = await service
+ final accounts = await service
.getAvailableAccounts(index: _nextIndex, limit: limit);
availableAccounts.addAll(accounts);
@@ -69,7 +67,6 @@ abstract class WalletHardwareRestoreViewModelBase extends WalletCreationVM with
}
isLoadingMoreAccounts = false;
- _nextIndex += limit;
}
@override
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.