Revert "feat(shopinbit): backfill remote tickets into the local db on refresh"
What changed, and why it matters
This commit undoes a recent feature that copied remote customer support tickets into the app's local database during refresh. The revert removes the backfill step, so tickets created on another device or the web dashboard will no longer automatically appear in the local database. The change is described as a routine revert, not a security fix, and no public references explain why it was reverted.
Treat this as a normal feature revert unless the project later discloses a security reason. If reviewing for security, verify whether the reverted backfill logic had issues such as writing unvalidated remote data, leaking tickets across customer keys, or race conditions, and confirm the revert fully removes the problematic code path.
Security signals we found
Revert of a feature commit with no stated security rationale
Removed local database write path fed by remote API data
No input validation, sanitization, or authorization changes visible in the diff
Evidence from the diff
The patch reverts commit 91dc8229, which added a backfill routine in ShopInBitOrdersService.refreshAll(). That routine fetched all ticket companions for the customer key and performed insertOnConflictUpdate into the local Drift database before calling getTicketsByCustomer. The revert deletes this try/catch backfill block and moves the SharedDrift.get() call back to after the API response check. The diff itself does not show a vulnerability being fixed; it simply removes cross-device ticket synchronization behavior.
Changed components
lib/services/shopinbit/shopinbit_orders_service.dartShopInBitOrdersService.refreshAll()shopInBitTickets local Drift tableInspect captured patch +1 / −16
diff --git a/lib/services/shopinbit/shopinbit_orders_service.dart b/lib/services/shopinbit/shopinbit_orders_service.dart
index 4594d1c..204bb25 100644
--- a/lib/services/shopinbit/shopinbit_orders_service.dart
+++ b/lib/services/shopinbit/shopinbit_orders_service.dart
@@ -158,27 +158,12 @@ class ShopInBitOrdersService extends ChangeNotifier {
Future<void> refreshAll() async {
try {
final customerKey = await shopInBitService.ensureCustomerKey();
- final db = SharedDrift.get();
-
- // Backfill rows for tickets that exist on the API but not locally
- // (created on another device, web dashboard, etc.). A failure here
- // shouldn't stop the refresh of tickets we already know about.
- try {
- final newCompanions = await shopInBitService.fetchAllForCustomerKey(
- customerKey,
- );
- for (final companion in newCompanions) {
- await db.into(db.shopInBitTickets).insertOnConflictUpdate(companion);
- }
- } catch (_) {
- // Fall through to the refresh-existing path.
- }
-
final resp = await shopInBitService.client.getTicketsByCustomer(
customerKey,
);
if (resp.hasError || resp.value == null) return;
+ final db = SharedDrift.get();
final localRows = await db.select(db.shopInBitTickets).get();
final byApiId = {for (final r in localRows) r.apiTicketId: r};
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.