Revert "chore: disable shopinbit sandbox"
What changed, and why it matters
This commit flips a single setting in the Stack Wallet app so that its built-in ShopInBit shopping feature talks to a test/sandbox environment instead of the real production service. The change is explicitly marked with a TODO saying it must be set to false for production. Using sandbox mode in a production release could mean users see fake/test data, make payments that don't result in real orders, or interact with a less secure/test server. However, the diff alone does not prove this change was ever shipped to users, and the commit message only says it is reverting an earlier change that disabled the sandbox.
Verify whether this commit was included in any release build. If it was, ensure the `sandbox` flag is set to `false` for production, remove the TODO, and audit any ShopInBit orders or payments processed while sandbox mode was active. Treat this as a configuration hygiene issue rather than a confirmed vulnerability.
Security signals we found
Re-enables sandbox/test mode for a third-party commerce integration
TODO comment explicitly flags the setting should be false in production
Change is a one-line configuration toggle with no hardening or validation added
Reversal of a prior commit that intentionally disabled sandbox mode
Evidence from the diff
The commit reverts d00a101a and changes the sandbox boolean in ShopInBitClient from false to true in lib/providers/global/shopin_bit_service_provider.dart. The accompanying comment // TODO set to false in prod indicates this is intended as a temporary development/testing configuration. The security relevance depends entirely on whether this commit reaches a production build: if it does, the app would point ShopInBit API traffic to a sandbox endpoint using real access credentials (kShopInBitAccessKey, kShopInBitPartnerSecret). That could affect integrity of orders/payments and potentially expose credentials to a different trust boundary, but the diff provides no evidence of credential leakage, endpoint details, or actual production shipment.
Changed components
lib/providers/global/shopin_bit_service_provider.dartShopInBitClient integrationShopInBit commerce/payment featureInspect captured patch +1 / −1
diff --git a/lib/providers/global/shopin_bit_service_provider.dart b/lib/providers/global/shopin_bit_service_provider.dart
index 102a59f..d2e5a49 100644
--- a/lib/providers/global/shopin_bit_service_provider.dart
+++ b/lib/providers/global/shopin_bit_service_provider.dart
@@ -11,7 +11,7 @@ final pShopinBitService = Provider(
client: ShopInBitClient(
accessKey: kShopInBitAccessKey,
partnerSecret: kShopInBitPartnerSecret,
- sandbox: false,
+ sandbox: true, // TODO set to false in prod
),
db: ref.watch(pSharedDrift),
),
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.