ignore a paynym search result that arrives after the search has changed, and stop enter replacing a pasted payment code search with its abbreviated display
What changed, and why it matters
This commit fixes two minor user-interface timing glitches in Sparrow Wallet's PayNym (payment-code alias) search feature. First, it ignores a search result that arrives after the user has already typed something different. Second, it prevents pressing Enter from replacing a pasted full payment code with its shortened on-screen display. These are correctness/UX bugs, not direct theft-of-funds vulnerabilities, but in a wallet they could theoretically contribute to a user sending to the wrong recipient if the screen shows stale or truncated information.
Treat as a routine bug-fix commit. Reviewers may want to confirm that the abbreviated payment code cannot be confused with a full code elsewhere in the send workflow, and that stale async responses are handled consistently across other controllers. No immediate security response is indicated by the diff alone.
Security signals we found
UI state desynchronization between async search request and response
User input potentially replaced by abbreviated display string on Enter
Possible stale search result being rendered after user changed query
No input validation, cryptography, or network trust boundary changes visible
Evidence from the diff
In PayNymController.java, the KeyEvent filter for Enter now skips calling findNymProperty.set() when the search field text contains an ellipsis (‘…’), which is the abbreviated display form of a payment code. Separately, the async PayNymService.getPayNym() callback now checks whether the returned result’s nymIdentifier still equals the current findNymProperty before updating the followingList. This prevents a stale async response from overwriting the results of a newer search. The patch is partial/defensive and does not show an exploitable code path by itself.
Changed components
src/main/java/com/sparrowwallet/sparrow/paynym/PayNymController.javaPayNym search/following UIfindNymProperty / followingList stateInspect captured patch +10 / −5
### src/main/java/com/sparrowwallet/sparrow/paynym/PayNymController.java
@@ -142,7 +142,10 @@ public void initializeView(String walletId) {
searchPayNyms.setTextFormatter(new TextFormatter<>(paymentCodeFilter));
searchPayNyms.addEventFilter(KeyEvent.ANY, event -> {
if(event.getCode() == KeyCode.ENTER) {
- findNymProperty.set(searchPayNyms.getText());
+ //An abbreviated payment code is only the display of the one already being searched for
+ if(!searchPayNyms.getText().contains("...")) {
+ findNymProperty.set(searchPayNyms.getText());
+ }
event.consume();
}
});
@@ -231,10 +234,12 @@ private void searchFollowing(String nymIdentifier) {
PayNymService.getPayNym(nymIdentifier, true).subscribe(searchedPayNym -> {
findPayNym.setVisible(false);
- List<PayNym> searchList = new ArrayList<>();
- searchList.add(searchedPayNym);
- followingList.setUserData(Boolean.TRUE);
- followingList.setItems(FXCollections.observableList(searchList));
+ if(nymIdentifier.equals(findNymProperty.get())) {
+ List<PayNym> searchList = new ArrayList<>();
+ searchList.add(searchedPayNym);
+ followingList.setUserData(Boolean.TRUE);
+ followingList.setItems(FXCollections.observableList(searchList));
+ }
}, error -> {
findPayNym.setVisible(false);
});Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.