show an error when a scanned ur of type bytes is not a psbt, transaction or utf-8 text
What changed, and why it matters
This commit fixes a small bug in Sparrow Wallet's QR code scanner. Previously, when a scanned QR code contained raw bytes that could not be recognized as a PSBT, transaction, or readable text, the scanner would create an error message but accidentally continue processing and eventually return nothing (null). Now it immediately returns the error message to the user. This is a minor user-experience and error-handling improvement, not a serious security flaw.
No urgent action required. Treat as routine bug fix. Users may benefit from knowing that previously unrecognized UR byte QR scans could silently fail; the fix makes failures explicit.
Security signals we found
Error-handling path failed to return error result, leading to silent null return
Fix changes assignment to immediate return of URException result
No cryptographic, parsing-safety, or trust-boundary changes observed
Evidence from the diff
In QRScanDialog.java’s extractResultFromUR(), the code for handling UR type BYTES assigned a Result containing a URException to the local variable ‘result’ but did not return it. Execution continued through subsequent if/else branches and fell through to a final ‘return null’. The patch changes the assignment to an immediate return, and removes the now-unreachable ‘return null’. This ensures unrecognized byte payloads produce a visible error instead of silent failure.
Changed components
src/main/java/com/sparrowwallet/sparrow/control/QRScanDialog.javaQR/UR scanning dialogBYTES registry type handlingInspect captured patch +1 / −3
### src/main/java/com/sparrowwallet/sparrow/control/QRScanDialog.java
@@ -464,7 +464,7 @@ private Result extractResultFromUR(UR ur) {
//ignore, bytes not parsable as utf-8
}
- result = new Result(new URException("Parsed UR of type " + urRegistryType + " was not a PSBT, transaction or UTF-8 text"));
+ return new Result(new URException("Parsed UR of type " + urRegistryType + " was not a PSBT, transaction or UTF-8 text"));
} else if(urRegistryType.equals(RegistryType.CRYPTO_PSBT)) {
CryptoPSBT cryptoPSBT = (CryptoPSBT)ur.decodeFromRegistry();
try {
@@ -549,8 +549,6 @@ private Result extractResultFromUR(UR ur) {
log.error("Error parsing UR CBOR", e);
return new Result(new URException("Error parsing UR CBOR", e));
}
-
- return null;
}
private Address getAddress(CryptoAddress cryptoAddress) {Why this scored 30/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.