add synchronous address validate call
What changed, and why it matters
This commit replaces a very weak Epic Cash address check with a proper synchronous validation call. Previously, the app considered any string containing an '@' symbol to be a valid Epicbox address, and any non-empty string longer than 10 characters to be valid otherwise. That could have allowed users to send funds to malformed or attacker-controlled addresses. The patch now delegates validation to the underlying Epic Cash library, which should reject invalid addresses correctly.
Verify that `epc.validateSendAddress` correctly validates Epicbox, HTTP, and slatepack addresses and rejects malformed or malicious inputs. Confirm the generated interface is regenerated and the new synchronous method is used consistently across the wallet UI. Consider adding unit tests for invalid address rejection.
Security signals we found
Weak address validation heuristic replaced with library validation
Any string containing '@' was previously accepted as a valid Epicbox address
Any non-empty string longer than 10 characters was previously accepted as valid
New synchronous FFI-style validation call added to generated interface
Evidence from the diff
The change removes a trivial length/character heuristic in epiccash.dart and instead calls libEpic.validateSendAddressSync(address:). A new synchronous method is added to the generated LibEpicCashInterface and implemented in the template, wrapping epc.validateSendAddress(address) == "1". This is a hardening/correctness fix rather than a memory-safety bug, but it closes a real validation bypass where malformed addresses could be accepted.
Changed components
lib/wallets/crypto_currency/coins/epiccash.dartlib/wl_gen/interfaces/libepiccash_interface.darttool/wl_templates/EPIC_libepiccash_interface_impl.template.dartInspect captured patch +13 / −8
diff --git a/lib/wallets/crypto_currency/coins/epiccash.dart b/lib/wallets/crypto_currency/coins/epiccash.dart
index 4411469..97c1b18 100644
--- a/lib/wallets/crypto_currency/coins/epiccash.dart
+++ b/lib/wallets/crypto_currency/coins/epiccash.dart
@@ -65,12 +65,7 @@ class Epiccash extends Bip39Currency {
}
}
- if (address.contains("@")) {
- return true; // Epicbox address format
- }
-
- // Very very basic (bad) check
- return address.isNotEmpty && address.length > 10;
+ return libEpic.validateSendAddressSync(address: address);
}
@override
@@ -143,7 +138,8 @@ class Epiccash extends Bip39Currency {
// Check for common slate fields.
return parsed is Map &&
(parsed.containsKey('id') || parsed.containsKey('slate_id')) &&
- (parsed.containsKey('amount') || parsed.containsKey('participant_data'));
+ (parsed.containsKey('amount') ||
+ parsed.containsKey('participant_data'));
} catch (e) {
return false;
}
@@ -163,7 +159,8 @@ class Epiccash extends Bip39Currency {
EpicTransactionMethod getTransactionMethod(String addressOrData) {
if (isSlateJson(addressOrData)) {
return EpicTransactionMethod.slatepack;
- } else if (isEpicboxAddress(addressOrData) || isHttpAddress(addressOrData)) {
+ } else if (isEpicboxAddress(addressOrData) ||
+ isHttpAddress(addressOrData)) {
return EpicTransactionMethod.epicbox;
} else {
throw Exception("Unknown EpicTransactionMethod found!");
diff --git a/lib/wl_gen/interfaces/libepiccash_interface.dart b/lib/wl_gen/interfaces/libepiccash_interface.dart
index 02ece22..cdbbb19 100644
--- a/lib/wl_gen/interfaces/libepiccash_interface.dart
+++ b/lib/wl_gen/interfaces/libepiccash_interface.dart
@@ -81,6 +81,8 @@ abstract class LibEpicCashInterface {
Future<bool> validateSendAddress({required String address});
+ bool validateSendAddressSync({required String address});
+
Future<({int fee, bool strategyUseAll, int total})> getTransactionFees({
required DynamicObject wallet,
required int amount,
diff --git a/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart b/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart
index ecfdf4a..4e78631 100644
--- a/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart
+++ b/tool/wl_templates/EPIC_libepiccash_interface_impl.template.dart
@@ -1,4 +1,5 @@
//ON
+import 'package:flutter_libepiccash/epic_cash.dart' as epc;
import 'package:flutter_libepiccash/git_versions.dart' as epic_versions;
import 'package:flutter_libepiccash/lib.dart';
import 'package:flutter_libepiccash/models/transaction.dart';
@@ -300,6 +301,11 @@ final class _LibEpicCashInterfaceImpl extends LibEpicCashInterface {
return EpicWallet.validateSendAddress(address: address);
}
+ @override
+ bool validateSendAddressSync({required String address}) {
+ return epc.validateSendAddress(address) == "1"; //lol
+ }
+
@override
Future<void> close({required DynamicObject wallet}) {
return wallet.get<EpicWallet>().close();
Why this scored 41/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.