Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo
What changed, and why it matters
This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app now correctly copies that message into the Spark memo field. Previously, the message was apparently ignored for Spark addresses. There is no indication this is a security vulnerability; it is a feature-completion/fix for wallet behavior matching the official Firo wallet (firo-qt).
No security action required. Treat as a normal functional improvement. If reviewing for quality, ensure the `paymentData.message` length is bounded by Spark memo limits and that the validation call handles null/empty addresses safely, though the diff itself does not introduce unsafe behavior.
Security signals we found
No security-relevant signals detected in the diff.
Change is a UI autofill feature for Firo Spark memos from payment URI messages.
No input sanitization changes beyond existing address validation.
No privilege, authentication, or cryptographic code modified.
Evidence from the diff
The change adds identical logic in two UI send pages (mobile send_view.dart and desktop desktop_send.dart). After parsing a BIP21-style payment URI, if the coin is Firo, the URI contains a message field, and the destination address validates as a Spark address via SparkInterface.validateSparkAddress, the code sets the Spark memo controller text to the URI message. This aligns with firo-qt behavior. No cryptographic, input-validation, or authorization changes are present. The validation call uses the already-parsed address and network flag.
Changed components
lib/pages/send_view/send_view.dartlib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_send.dartFiro Spark payment flowPayment URI parsing / autofillInspect captured patch +20 / −0
### lib/pages/send_view/send_view.dart
@@ -169,6 +169,16 @@ class _SendViewState extends ConsumerState<SendView> {
noteController.text = paymentData.label!;
}
+ // firo-qt treats message as the spark memo when paying a spark address
+ if (coin is Firo &&
+ paymentData.message != null &&
+ SparkInterface.validateSparkAddress(
+ address: _address!,
+ isTestNet: coin.network.isTestNet,
+ )) {
+ memoController.text = paymentData.message!;
+ }
+
// autofill amount field
if (paymentData.amount != null) {
final amount = Amount.tryParseCanonicalAmount(
### lib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_send.dart
@@ -1010,6 +1010,16 @@ class _DesktopSendState extends ConsumerState<DesktopSend> {
_note = paymentData.label;
}
+ // firo-qt treats message as the spark memo when paying a spark address
+ if (coin is Firo &&
+ paymentData.message != null &&
+ SparkInterface.validateSparkAddress(
+ address: _address!,
+ isTestNet: coin.network.isTestNet,
+ )) {
+ memoController.text = paymentData.message!;
+ }
+
// autofill amount field
if (paymentData.amount != null) {
final amount = Amount.tryParseCanonicalAmount(Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.