feat: use stored epicbox config when available
What changed, and why it matters
This commit changes how the Epic Cash wallet picks its Epicbox server configuration. Previously it always used a hardcoded default server. Now it first tries to read a user-stored configuration from secure device storage and only falls back to the default if none exists or it cannot be parsed. The change is a feature improvement, not a direct security fix, but it reduces reliance on a single hardcoded server.
Treat as a routine feature commit. If reviewing for security, verify that `EpicBoxConfigModel.fromString` validates the server identity (TLS certificate pinning, allowed host list, or similar) so a malicious stored config cannot redirect transaction metadata to an attacker-controlled Epicbox server. Also confirm secure storage is encrypted and scoped to the wallet.
Security signals we found
Hardcoded default server dependency reduced
User-supplied configuration now loaded from secure storage
Parsing failure is caught and logged, with safe fallback
No visible validation of the stored Epicbox server host/port/identity
Evidence from the diff
The getEpicBoxConfig() method in epiccash_wallet.dart was rewritten to read ${walletId}_epicboxConfig from secureStorageInterface before returning DefaultEpicBoxes.defaultEpicBoxServer. If a stored config exists and parses successfully it is returned; otherwise the method logs a warning and falls back to the default. The previous commented-out server-selection logic was removed. No input validation beyond JSON/parsing is visible in the diff.
Changed components
lib/wallets/wallet/impl/epiccash_wallet.dartEpic Cash wallet Epicbox configuration resolutionInspect captured patch +12 / −26
diff --git a/lib/wallets/wallet/impl/epiccash_wallet.dart b/lib/wallets/wallet/impl/epiccash_wallet.dart
index 66d9294..2a6be2f 100644
--- a/lib/wallets/wallet/impl/epiccash_wallet.dart
+++ b/lib/wallets/wallet/impl/epiccash_wallet.dart
@@ -148,34 +148,20 @@ class EpiccashWallet extends Bip39Wallet {
}
Future<EpicBoxConfigModel> getEpicBoxConfig() async {
- final EpicBoxConfigModel _epicBoxConfig = EpicBoxConfigModel.fromServer(
- DefaultEpicBoxes.defaultEpicBoxServer,
+ // check for user-configured epicbox first
+ final storedConfig = await secureStorageInterface.read(
+ key: '${walletId}_epicboxConfig',
);
+ if (storedConfig != null && storedConfig.isNotEmpty) {
+ try {
+ return EpicBoxConfigModel.fromString(storedConfig);
+ } catch (e) {
+ Logging.instance.w("Failed to parse stored epicbox config: $e");
+ }
+ }
- //Get the default Epicbox server and check if it's conected
- // bool isEpicboxConnected = await _testEpicboxServer(
- // DefaultEpicBoxes.defaultEpicBoxServer.host,
- // DefaultEpicBoxes.defaultEpicBoxServer.port ?? 443);
-
- // if (isEpicboxConnected) {
- //Use default server for as Epicbox config
-
- // }
- // else {
- // //Use Europe config
- // _epicBoxConfig = EpicBoxConfigModel.fromServer(DefaultEpicBoxes.europe);
- // }
- // // example of selecting another random server from the default list
- // // alternative servers: copy list of all default EB servers but remove the default default
- // // List<EpicBoxServerModel> alternativeServers = DefaultEpicBoxes.all;
- // // alternativeServers.removeWhere((opt) => opt.name == DefaultEpicBoxes.defaultEpicBoxServer.name);
- // // alternativeServers.shuffle(); // randomize which server is used
- // // _epicBoxConfig = EpicBoxConfigModel.fromServer(alternativeServers.first);
- //
- // // TODO test this connection before returning it
- // }
-
- return _epicBoxConfig;
+ // fall back to default
+ return EpicBoxConfigModel.fromServer(DefaultEpicBoxes.defaultEpicBoxServer);
}
Future<void> updateRestoreHeight(int height) async {
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.