What changed, and why it matters
This commit updates a status-checking helper in the Stack Wallet app so that two additional order/ticket states ('pendingClose' and 'refunded') are treated as 'terminal' or final states. Previously, only 'closed', 'closedCancelled', and 'merged' were considered finished. The change is a small bug fix in business logic and does not, by itself, appear to introduce a security vulnerability. The main security-relevant concern is whether treating these states as terminal could hide or prematurely stop handling of orders that still need user action or refunds, but the diff alone does not show that such mishandling actually occurs or is exploitable.
Review all call sites of TicketState.isTerminal to confirm that treating pendingClose and refunded as terminal does not prematurely halt required user notifications, refund flows, or dispute windows. No immediate security patch appears necessary from this diff alone.
Security signals we found
Business-logic state-machine change
Possible downstream effect on order lifecycle handling if isTerminal is used to stop processing or refunds
No direct security-sensitive code modified in the diff
Evidence from the diff
In lib/services/shopinbit/src/models/ticket.dart, the TicketState.isTerminal getter is expanded to include TicketState.pendingClose and TicketState.refunded alongside the existing .closed, .closedCancelled, and .merged. This is a Dart enum helper used by the ShopinBit integration. The change is purely additive to the set of states considered terminal. No parsing, serialization, authentication, cryptography, network, or input-validation code is modified. Any security implications would depend entirely on how downstream callers use isTerminal (e.g., stopping polling, disabling UI actions, releasing funds), which is not visible in this diff.
Changed components
lib/services/shopinbit/src/models/ticket.dartShopinBit ticket/order state machineInspect captured patch +8 / −4
diff --git a/lib/services/shopinbit/src/models/ticket.dart b/lib/services/shopinbit/src/models/ticket.dart
index 237ed1c..ca67826 100644
--- a/lib/services/shopinbit/src/models/ticket.dart
+++ b/lib/services/shopinbit/src/models/ticket.dart
@@ -34,10 +34,14 @@ enum TicketState {
return TicketState.unknown;
}
- bool get isTerminal => switch(this) {
- .closed || .closedCancelled || .merged => true,
- _ => false,
- } ;
+ bool get isTerminal => switch (this) {
+ .closed ||
+ .closedCancelled ||
+ .merged ||
+ .pendingClose ||
+ .refunded => true,
+ _ => false,
+ };
}
class TicketRef {
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.