revalidate the send amount when payments are set from a uri opened externally or a spend event so insufficient and dust warnings show
What changed, and why it matters
This commit fixes a UI bug in Sparrow Wallet's send form. When a payment amount was filled in automatically—such as when opening a Bitcoin payment link from another app or when triggered by a 'spend' event—the wallet did not re-run its amount checks. That meant warnings about sending too small an amount ('dust') or not having enough funds ('insufficient balance') might not appear. The fix adds a single call to revalidate the amount after auto-filling it, so the correct warnings are shown.
Treat as a low-severity UI/validation fix. Review whether other auto-populated fields in the send flow (e.g., address, label) are similarly revalidated, and consider adding automated tests for URI/spend-event triggered payments to ensure warnings are consistently displayed.
Security signals we found
Missing input validation for programmatically populated field
UI warning suppression for dust and insufficient-balance checks
External URI/spend event triggers automatic form population
Evidence from the diff
In PaymentController.setPayment(), after setRecipientValueSats(payment.getAmount()) populates the send amount field from an external URI or spend event, the code now calls revalidateAmount(). This ensures field-level validation (dust threshold, available balance, etc.) fires for programmatically set values, not just user-typed ones. The change is one line and is defensive/UI-correctness in nature.
Changed components
src/main/java/com/sparrowwallet/sparrow/wallet/PaymentController.javaSend payment amount validation flowBitcoin URI handling / spend-event handlingInspect captured patch +1 / −0
### src/main/java/com/sparrowwallet/sparrow/wallet/PaymentController.java
@@ -749,6 +749,7 @@ public void setPayment(Payment payment) {
}
if(payment.getAmount() >= 0) {
setRecipientValueSats(payment.getAmount());
+ revalidateAmount();
}
setFiatAmount(AppServices.getFiatCurrencyExchangeRate(), payment.getAmount());
}Why this scored 27/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.