feat(spl): add custom token mint addresses storage to WalletInfo
What changed, and why it matters
This commit adds a new storage field to the wallet's metadata for remembering custom Solana token mint addresses. It is a straightforward feature addition with no visible security implications in the code changed.
No security action required. As a general hardening suggestion, ensure callers validate mint addresses before persisting them, but this commit itself does not create a vulnerability.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch extends the WalletInfo Isar model with a getter (solanaCustomTokenMintAddresses) and an update method (updateSolanaCustomTokenMintAddresses) that persists a list of user-defined Solana SPL token mint addresses in the wallet’s otherData map. No input validation, cryptographic, network, or authorization logic is introduced or altered.
Changed components
lib/wallets/isar/models/wallet_info.dartInspect captured patch +26 / −0
diff --git a/lib/wallets/isar/models/wallet_info.dart b/lib/wallets/isar/models/wallet_info.dart
index f4dbab5..8cb0f6a 100644
--- a/lib/wallets/isar/models/wallet_info.dart
+++ b/lib/wallets/isar/models/wallet_info.dart
@@ -86,6 +86,17 @@ class WalletInfo implements IsarId {
}
}
+ @ignore
+ List<String> get solanaCustomTokenMintAddresses {
+ if (otherData[WalletInfoKeys.solanaCustomTokenMintAddresses] is List) {
+ return List<String>.from(
+ otherData[WalletInfoKeys.solanaCustomTokenMintAddresses] as List,
+ );
+ } else {
+ return [];
+ }
+ }
+
/// Special case for coins such as firo lelantus
@ignore
Balance get cachedBalanceSecondary {
@@ -420,6 +431,19 @@ class WalletInfo implements IsarId {
);
}
+ /// Update custom Solana token mint addresses and update the db.
+ Future<void> updateSolanaCustomTokenMintAddresses({
+ required Set<String> newMintAddresses,
+ required Isar isar,
+ }) async {
+ await updateOtherData(
+ newEntries: {
+ WalletInfoKeys.solanaCustomTokenMintAddresses: newMintAddresses.toList(),
+ },
+ isar: isar,
+ );
+ }
+
Future<void> setMwebEnabled({
required bool newValue,
required Isar isar,
@@ -549,4 +573,6 @@ abstract class WalletInfoKeys {
static const String firoSparkUsedTagsCacheResetVersion =
"firoSparkUsedTagsCacheResetVersionKey";
static const String solanaTokenMintAddresses = "solanaTokenMintAddressesKey";
+ static const String solanaCustomTokenMintAddresses =
+ "solanaCustomTokenMintAddressesKey";
}
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.