fix(shopinbit): treat an empty 2xx body as an error
What changed, and why it matters
This commit fixes a bug in the Stack Wallet app's integration with ShopInBit. Previously, if the server returned a successful HTTP response with an empty body, the app would pretend it received valid data and create fake placeholder objects (for example, a support ticket with ID 0). Now the app correctly treats an empty successful response as an error instead. This is a defensive fix that prevents the app from acting on fabricated data, which could confuse users or lead to incorrect app behavior.
Review other API clients in the codebase for the same pattern (returning parse({}) or equivalent on empty 2xx bodies). Confirm that callers of ShopInBitClient handle ApiResponse.exception correctly and do not fall back to placeholder values. Consider adding unit tests for empty 2xx responses to prevent regression.
Security signals we found
Empty 2xx response body previously parsed as empty JSON object, producing placeholder objects
Fix surfaces empty-body success responses as explicit errors
Potential for downstream logic to act on fabricated default values (e.g., id 0) before fix
No explicit security claim, CVE, or attacker-controlled input path described in commit
Evidence from the diff
In lib/services/shopinbit/src/client.dart, the ShopInBitClient previously returned ApiResponse(value: parse({})) when a 2xx response had an empty body. Because downstream object parsers turn an empty JSON object into a default/placeholder instance (e.g., a ticket with id 0), this caused the client to silently synthesize bogus entities. The patch changes that path to return an ApiResponse containing an ApiException with message ‘Empty response body for $method $resolved’. This is a correctness/reliability fix; it does not by itself indicate an active vulnerability, but it removes a class of logic errors that could arise from empty API responses.
Changed components
lib/services/shopinbit/src/client.dartShopInBitClient API response handlingShopInBit object parsers consuming empty JSON objectsInspect captured patch +7 / −1
diff --git a/lib/services/shopinbit/src/client.dart b/lib/services/shopinbit/src/client.dart
index 9bda1bc..9d817db 100644
--- a/lib/services/shopinbit/src/client.dart
+++ b/lib/services/shopinbit/src/client.dart
@@ -764,7 +764,13 @@ class ShopInBitClient {
if (response.code >= 200 && response.code < 300) {
Logging.instance.t("$_kTag $method $resolved HTTP:${response.code}");
if (response.body.isEmpty) {
- return ApiResponse(value: parse({}));
+ // An empty 2xx body would make object parsers fabricate placeholder
+ // objects (e.g. a ticket with id 0); surface it as an error instead.
+ return ApiResponse(
+ exception: ApiException(
+ "Empty response body for $method $resolved",
+ ),
+ );
}
final json = jsonDecode(response.body) as Map<String, dynamic>;
return ApiResponse(value: parse(json), customerKey: customerKey);
Why this scored 44/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.