ignore sources field from wallet rpc transfer (#148)
What changed, and why it matters
This is a tiny one-line change in a Java library that talks to the Monero cryptocurrency wallet. The library now explicitly ignores a new 'sources' field returned by the Monero wallet RPC when parsing transfer data. It prevents the parser from falling through to an 'unknown field' error or warning, but does not by itself fix a security vulnerability. It is best characterized as a compatibility/robustness update.
Treat as a routine compatibility fix. Reviewers may verify that ignoring 'sources' does not omit data needed by downstream callers, but no immediate security action is required.
Security signals we found
No security-relevant keywords in commit title or message
Change is a single no-op else-if branch for field filtering
No input validation, serialization, or cryptographic code modified
No references to CVEs, advisories, researchers, or security issues
Evidence from the diff
In MoneroWalletRpc.java, a new else-if branch was added to the JSON-to-object deserialization logic so that the ‘sources’ key returned by the wallet RPC’s transfer response is silently ignored. The field is already handled elsewhere or is not needed for the outgoing transfer object built by this method. The change avoids an unintended fall-through to the default/unknown-key handling path. There is no evidence in the commit of memory corruption, injection, authentication bypass, or cryptographic weakness.
Changed components
src/main/java/monero/wallet/MoneroWalletRpc.javaInspect captured patch +1 / −0
diff --git a/src/main/java/monero/wallet/MoneroWalletRpc.java b/src/main/java/monero/wallet/MoneroWalletRpc.java
index 041dfa1..4294796 100644
--- a/src/main/java/monero/wallet/MoneroWalletRpc.java
+++ b/src/main/java/monero/wallet/MoneroWalletRpc.java
@@ -3035,6 +3035,7 @@ public class MoneroWalletRpc extends MoneroWalletDefault {
if (transfer == null) transfer = new MoneroOutgoingTransfer().setTx(tx);
((MoneroOutgoingTransfer) transfer).setDestinations(destinations);
}
+ else if (key.equals("sources")) {} // ignoring
else if (key.equals("multisig_txset") && val != null) {} // handled elsewhere; this method only builds a tx wallet
else if (key.equals("unsigned_txset") && val != null) {} // handled elsewhere; this method only builds a tx wallet
else if (key.equals("amount_in")) tx.setInputSum((BigInteger) val);
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.