fix non firo view only new wallet creation bug
What changed, and why it matters
This commit fixes a bug in the Stack Wallet app where creating a new non-Firo wallet with the 'view only' option could incorrectly trigger Firo-specific Spark view-only conversion logic. The fix adds a check that the selected coin is actually Firo before enabling the Spark view-only path. It appears to be a functional bug fix rather than a security vulnerability, but the incorrect flag could lead to unexpected wallet behavior or creation failure.
Treat as a routine bug fix. Review whether _firoFlag is still necessary given the coin-type check, and verify that downstream wallet creation logic handles convertToViewOnlySpark consistently. No immediate security response appears warranted based on the diff alone.
Security signals we found
UI state used as security boundary (feature flag gated wallet creation parameter)
Incorrect coin-type branching in wallet creation logic
Potential cross-coin wallet misconfiguration
Evidence from the diff
In new_wallet_options_view.dart, the convertToViewOnlySpark parameter was previously set to _convertToViewOnly && _firoFlag. The _firoFlag variable appears to be a UI/feature flag that could be true even when the selected coin is not Firo. The patch adds widget.coin is Firo to the condition, ensuring Spark view-only conversion is only requested for Firo wallets. This prevents non-Firo wallets from being created with Firo Spark-specific view-only settings.
Changed components
lib/pages/add_wallet_views/new_wallet_options/new_wallet_options_view.dartNew wallet creation flowView-only wallet creationFiro Spark view-only conversionInspect captured patch +2 / −1
diff --git a/lib/pages/add_wallet_views/new_wallet_options/new_wallet_options_view.dart b/lib/pages/add_wallet_views/new_wallet_options/new_wallet_options_view.dart
index 1e7e9b9..e3a874a 100644
--- a/lib/pages/add_wallet_views/new_wallet_options/new_wallet_options_view.dart
+++ b/lib/pages/add_wallet_views/new_wallet_options/new_wallet_options_view.dart
@@ -421,7 +421,8 @@ class _NewWalletOptionsViewState extends ConsumerState<NewWalletOptionsView> {
.state,
mnemonicPassphrase: passwordController.text,
convertToViewOnly: _convertToViewOnly,
- convertToViewOnlySpark: _convertToViewOnly && _firoFlag,
+ convertToViewOnlySpark:
+ widget.coin is Firo && _convertToViewOnly && _firoFlag,
);
} else {
ref.read(pNewWalletOptions.notifier).state = null;
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.