What changed, and why it matters
This commit fixes a minor resource cleanup issue in the QR code scanner screen. The app now properly stops and disposes the camera scanner controller when the user leaves the screen or after a successful scan. Without this fix, the camera could keep running briefly in the background, wasting battery and possibly keeping the camera active longer than intended. There is no direct evidence this is a security vulnerability.
Treat as a routine quality/resource-management fix. No urgent security action is indicated. If a security advisory is later published, re-evaluate.
Security signals we found
Resource lifecycle cleanup (camera controller disposal)
Potential camera remaining active after leaving scan screen
No input validation, cryptographic, or authentication changes
Evidence from the diff
The change in lib/screens/scan_qr.dart creates an explicit MobileScannerController, passes it to the MobileScanner widget, stops the controller in _onScannerDetect after a successful scan, and disposes it in the State’s dispose() lifecycle method. Previously the scanner was created implicitly and not explicitly cleaned up. This is a resource-leak/hygiene fix rather than a security boundary fix.
Changed components
lib/screens/scan_qr.dartMobileScanner widget integrationInspect captured patch +9 / −1
diff --git a/lib/screens/scan_qr.dart b/lib/screens/scan_qr.dart
index 004d520..a3158ec 100644
--- a/lib/screens/scan_qr.dart
+++ b/lib/screens/scan_qr.dart
@@ -10,8 +10,15 @@ class ScanQrScreen extends StatefulWidget {
}
class _ScanQrScreenState extends State<ScanQrScreen> {
+ final MobileScannerController _controller = MobileScannerController();
bool _hasScanned = false;
+ @override
+ void dispose() {
+ _controller.dispose();
+ super.dispose();
+ }
+
void _onScannerDetect(BarcodeCapture result) {
if (_hasScanned) return;
@@ -19,6 +26,7 @@ class _ScanQrScreenState extends State<ScanQrScreen> {
if (scanResult == null) return;
_hasScanned = true;
+ _controller.stop();
Navigator.pop(context, scanResult);
}
@@ -28,7 +36,7 @@ class _ScanQrScreenState extends State<ScanQrScreen> {
return Scaffold(
appBar: AppBar(title: Text(i18n.scanQrTitle)),
- body: SafeArea(child: MobileScanner(onDetect: _onScannerDetect)),
+ body: SafeArea(child: MobileScanner(controller: _controller, onDetect: _onScannerDetect)),
);
}
}
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.