AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 61 Monero

Standardize localized input:

Public commit record

What the developer wrote

Authored by Julian

58/100 · Thin
Standardize localized input:

- Explicit editable and canonical parsers, strict ASCII amount formatting, locale relocalization, and isolated IME recovery

- Wire existing formatters to their controllers
✓ Descriptive subject✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit rewrites how the Stack Wallet app handles typed-in money amounts. It makes the rules for what counts as a valid amount much stricter: only digits and the user's locale-specific decimal separator are allowed, grouping characters (like commas in 1,000) are rejected, and the code now keeps a separate 'canonical' parser for trusted sources like QR codes. The change also adds recovery logic for on-screen keyboards that compose characters in unusual ways, so the app doesn't get stuck with an unparseable amount. The main risk is that a user could previously enter an amount that the app misread by a factor of 1,000 (for example, treating '1.000' as one thousand instead of one), which could lead to sending far more cryptocurrency than intended.

Recommended action

Treat this as a security-hardening change that likely fixes real-world mis-send risk. Review the new Amount.tryParseEditable* and tryParseCanonical* boundaries to ensure no caller still feeds display-formatted or grouped strings into editable parsers. Verify that the IME recovery cache is keyed safely per controller/configuration and cannot leak state between fields. Run the updated test suite and add additional locale matrix tests for any supported locales not yet covered. Consider whether externally supplied amounts (QR/URI) correctly use the canonical parser with truncateOverprecision where appropriate.

Security signals we found

01

Locale-based decimal/grouping separator confusion (1.000 vs 1,000) is removed from editable parsing

02

Display-formatted strings are no longer re-parsed as input, closing a class of format-string confusion bugs

03

Strict ASCII canonical parser added for externally supplied amounts (QR/URI) with optional overprecision truncation

04

IME composition recovery added to prevent the input field from becoming trapped in an unparseable state

05

AmountInputFormatter now bound to TextEditingController to survive widget rebuilds during composition

06

Tests explicitly reject grouping characters, signs, whitespace, and ambiguous dot-group forms

Risk score

Why this scored 61/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.