What changed, and why it matters
This commit changes how custom Solana token addresses are stored internally from a 'Set' (which automatically removes duplicates and ignores order) to a 'List' (which preserves order and allows duplicates) to match how Ethereum tokens are handled. There is no direct evidence in the commit that this fixes an active security vulnerability; it appears to be a consistency or data-type alignment change.
Treat as a routine code-quality/data-model alignment change unless additional context emerges. Review whether List<String> introduces duplicate mint addresses or ordering issues that could affect token display, balance calculation, or transaction construction. If duplicates are a concern, consider adding explicit deduplication before persistence.
Security signals we found
Type change from Set<String> to List<String> for Solana custom token mint addresses
Removal of .toSet() deduplication in edit_wallet_tokens_view.dart
Stated goal is to match Ethereum implementation pattern
No explicit security context, CVE reference, or vulnerability description in commit message
Evidence from the diff
The patch modifies three Dart files in the Stack Wallet codebase. It changes the solanaCustomTokenMintAddresses parameter type from Set<String> to List<String> in WalletInfo.updateSolanaCustomTokenMintAddresses() and SolanaWallet.updateSolanaTokens(), and removes a .toSet() conversion in the UI edit view. The stated rationale is to match Ethereum’s implementation. The diff does not show any validation, sanitization, or access-control changes that would clearly address a security flaw.
Changed components
lib/pages/add_wallet_views/add_token_view/edit_wallet_tokens_view.dartlib/wallets/isar/models/wallet_info.dartlib/wallets/wallet/impl/solana_wallet.dartInspect captured patch +3 / −3
diff --git a/lib/pages/add_wallet_views/add_token_view/edit_wallet_tokens_view.dart b/lib/pages/add_wallet_views/add_token_view/edit_wallet_tokens_view.dart
index 2d4f869..bace01e 100644
--- a/lib/pages/add_wallet_views/add_token_view/edit_wallet_tokens_view.dart
+++ b/lib/pages/add_wallet_views/add_token_view/edit_wallet_tokens_view.dart
@@ -316,7 +316,7 @@ class _EditWalletTokensViewState extends ConsumerState<EditWalletTokensView> {
// Also add the custom token mint address to the wallet's custom token list.
final wallet = ref.read(pWallets).getWallet(widget.walletId);
if (wallet is SolanaWallet) {
- final currentCustomTokens = wallet.info.solanaCustomTokenMintAddresses.toSet();
+ final currentCustomTokens = wallet.info.solanaCustomTokenMintAddresses;
currentCustomTokens.add(token.address);
await wallet.info.updateSolanaCustomTokenMintAddresses(
newMintAddresses: currentCustomTokens,
diff --git a/lib/wallets/isar/models/wallet_info.dart b/lib/wallets/isar/models/wallet_info.dart
index a6747b5..db0a65c 100644
--- a/lib/wallets/isar/models/wallet_info.dart
+++ b/lib/wallets/isar/models/wallet_info.dart
@@ -437,7 +437,7 @@ class WalletInfo implements IsarId {
/// Update custom Solana token mint addresses and update the db.
Future<void> updateSolanaCustomTokenMintAddresses({
- required Set<String> newMintAddresses,
+ required List<String> newMintAddresses,
required Isar isar,
}) async {
await updateOtherData(
diff --git a/lib/wallets/wallet/impl/solana_wallet.dart b/lib/wallets/wallet/impl/solana_wallet.dart
index 01969e1..e9b9fcc 100644
--- a/lib/wallets/wallet/impl/solana_wallet.dart
+++ b/lib/wallets/wallet/impl/solana_wallet.dart
@@ -645,7 +645,7 @@ class SolanaWallet extends Bip39Wallet<Solana> {
return false;
}
- Future<void> updateSolanaTokens(Set<String> mintAddresses) async {
+ Future<void> updateSolanaTokens(List<String> mintAddresses) async {
await info.updateSolanaCustomTokenMintAddresses(
newMintAddresses: mintAddresses,
isar: mainDB.isar,
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.