vat rate can actually be a decimal which was not what the docs specified
What changed, and why it matters
This commit fixes a data-type mismatch in how the app reads VAT (sales tax) rates from a partner service. The code previously expected whole-number percentages like 19, but the service can actually send decimal values like 19.5. The change lets the app store and handle those decimal rates correctly. There is no direct evidence this is a security fix; it reads as a routine bug fix for incorrect parsing that could cause display or calculation errors.
Treat as a normal bug fix. If VAT rate values are used in downstream price calculations, verify that switching to Decimal prevents rounding/floating-point issues and that the values are validated before use. No urgent security action is indicated by the diff.
Security signals we found
No security framing in commit title or message
No input validation or sanitization added
No bounds checks or error handling changes beyond type parsing
Change is purely a type widening from int to Decimal
Evidence from the diff
In lib/services/shopinbit/src/models/payment.dart and lib/services/shopinbit/src/models/ticket.dart, the vatRate field is changed from int? to Decimal? (using the decimal package) and parsing is switched from int.tryParse to Decimal.tryParse. This accommodates API responses where vat_rate is a decimal rather than an integer. The commit message frames it as a documentation/API expectation mismatch, not a security issue. No bounds checking, input validation, or other security-hardening changes are present.
Changed components
lib/services/shopinbit/src/models/payment.dartlib/services/shopinbit/src/models/ticket.dartShopinBit payment/ticket model parsingInspect captured patch +8 / −4
diff --git a/lib/services/shopinbit/src/models/payment.dart b/lib/services/shopinbit/src/models/payment.dart
index 05c8648..cdc397a 100644
--- a/lib/services/shopinbit/src/models/payment.dart
+++ b/lib/services/shopinbit/src/models/payment.dart
@@ -1,8 +1,10 @@
+import 'package:decimal/decimal.dart';
+
class PaymentInfo {
final String status;
final String customerPrice;
final String partnerPrice;
- final int? vatRate;
+ final Decimal? vatRate;
final String currency;
final DateTime? rateLockedUntil;
final Map<String, String> paymentLinks;
@@ -25,7 +27,7 @@ class PaymentInfo {
status: json['status'] as String,
customerPrice: json['customer_price'] as String,
partnerPrice: json['partner_price'] as String,
- vatRate: int.tryParse(json['vat_rate'].toString()),
+ vatRate: Decimal.tryParse(json['vat_rate'].toString()),
currency: json['currency'] as String,
rateLockedUntil: DateTime.tryParse(
json['rate_locked_until']?.toString() ?? '',
diff --git a/lib/services/shopinbit/src/models/ticket.dart b/lib/services/shopinbit/src/models/ticket.dart
index 4736823..1e42367 100644
--- a/lib/services/shopinbit/src/models/ticket.dart
+++ b/lib/services/shopinbit/src/models/ticket.dart
@@ -1,3 +1,5 @@
+import 'package:decimal/decimal.dart';
+
import '../../../../utilities/logger.dart';
/// Splits a raw `tracking_link` value into individual tracking URLs.
@@ -159,7 +161,7 @@ class TicketFull {
final String? netPurchasePrice;
final String? netShippingCosts;
final String deliveryCountry;
- final int? vatRate;
+ final Decimal? vatRate;
TicketFull({
required this.id,
@@ -186,7 +188,7 @@ class TicketFull {
netShippingCosts: json['net_shipping_costs'] as String?,
deliveryCountry:
(json['delivery_country'] ?? json['deliverycountry']) as String,
- vatRate: int.tryParse(json['vat_rate'].toString()),
+ vatRate: Decimal.tryParse(json['vat_rate'].toString()),
);
}
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.