fix(shopinbit): dumb hacked check for first and last name
What changed, and why it matters
This commit tightens the shipping/billing name validation in the ShopInBit feature of Stack Wallet. Previously, any non-empty name was accepted; now the name must contain at least two whitespace-separated words (e.g., a first and last name). The change is a client-side form check and does not appear to fix a security vulnerability. It is more likely a business-rule or partner-compliance fix to prevent incomplete names from being submitted to the ShopInBit service. There is no evidence in the commit or supplied references of a security issue, exploit, or disclosure.
No security action required. Treat as a normal functional/business-rule change. If ShopInBit requires verified first and last names, consider also enforcing the rule server-side and documenting the requirement for users.
Security signals we found
No security-relevant keywords in commit title or message
Change is client-side input validation only
No evidence of injection, authorization, cryptographic, or data-leak issues in diff
Commit language ('dumb hacked check') indicates low-severity workaround, not security fix
Evidence from the diff
The patch adds a check that _nameController.text and _billingNameController.text, after splitting on spaces, trimming, and filtering empty tokens, produce more than one token. This enforces a ‘first and last name’ requirement. It is implemented as a UI validation guard before form submission. The commit title’s wording (‘dumb hacked check’) suggests the developer considered it a quick, non-robust fix rather than a security measure. No server-side validation, sanitization, or cryptographic changes are present.
Changed components
lib/pages/shopinbit/shopinbit_shipping_view.dartShopInBit shipping/billing name validationInspect captured patch +12 / −0
diff --git a/lib/pages/shopinbit/shopinbit_shipping_view.dart b/lib/pages/shopinbit/shopinbit_shipping_view.dart
index e025bad..ed15da3 100644
--- a/lib/pages/shopinbit/shopinbit_shipping_view.dart
+++ b/lib/pages/shopinbit/shopinbit_shipping_view.dart
@@ -79,12 +79,24 @@ class _ShopInBitShippingViewState extends ConsumerState<ShopInBitShippingView> {
if (_submitting) return false;
final shippingValid =
_nameController.text.trim().isNotEmpty &&
+ _nameController.text
+ .split(" ")
+ .map((e) => e.trim())
+ .where((e) => e.isNotEmpty)
+ .length >
+ 1 &&
_streetController.text.trim().isNotEmpty &&
_cityController.text.trim().isNotEmpty &&
_postalCodeController.text.trim().isNotEmpty;
if (!shippingValid) return false;
if (_differentBilling) {
return _billingNameController.text.trim().isNotEmpty &&
+ _billingNameController.text
+ .split(" ")
+ .map((e) => e.trim())
+ .where((e) => e.isNotEmpty)
+ .length >
+ 1 &&
_billingStreetController.text.trim().isNotEmpty &&
_billingCityController.text.trim().isNotEmpty &&
_billingPostalCodeController.text.trim().isNotEmpty &&
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.