fix(ui): provider access after widget disposed
What changed, and why it matters
This is a small UI bug fix in a Flutter settings screen. It moves an asynchronous key-loading call so it only happens while the screen widget is still active, preventing a harmless 'provider accessed after widget disposed' warning. There is no direct evidence this is a security vulnerability.
Treat as a routine UI stability fix. No security response required unless additional context shows the disposed-widget state can be exploited to leak the customer key or corrupt state.
Security signals we found
No security-relevant keywords in commit title or message
No cryptographic logic changes
No input validation changes
No privilege boundary changes
No network or storage changes
Fix addresses a Flutter widget lifecycle warning, not a confidentiality/integrity/availability issue
Evidence from the diff
The change in lib/pages/shopinbit/shopinbit_settings_view.dart wraps the await ref.read(pShopinBitService).loadCustomerKey() call inside an additional if (mounted) guard. Previously the key was loaded before the mounted check, meaning a setState could be attempted after the widget was disposed. This is a standard Flutter lifecycle correctness fix; it does not alter how the customer key is loaded, stored, or validated.
Changed components
lib/pages/shopinbit/shopinbit_settings_view.dartInspect captured patch +7 / −5
diff --git a/lib/pages/shopinbit/shopinbit_settings_view.dart b/lib/pages/shopinbit/shopinbit_settings_view.dart
index 51fb674..a4b36b2 100644
--- a/lib/pages/shopinbit/shopinbit_settings_view.dart
+++ b/lib/pages/shopinbit/shopinbit_settings_view.dart
@@ -54,12 +54,14 @@ class _ShopInBitSettingsViewState extends ConsumerState<ShopInBitSettingsView> {
.read(pSharedDrift)
.shopinBitSettingsDao
.getSettings();
- final key = await ref.read(pShopinBitService).loadCustomerKey();
if (mounted) {
- setState(() {
- _currentKey = key;
- _displayNameController.text = settings.displayName ?? "";
- });
+ final key = await ref.read(pShopinBitService).loadCustomerKey();
+ if (mounted) {
+ setState(() {
+ _currentKey = key;
+ _displayNameController.text = settings.displayName ?? "";
+ });
+ }
}
}();
}
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.