Merge branch 'staging' into desktop_fee_form_refetch
What changed, and why it matters
This commit merges a feature branch into another work-in-progress branch. It adds QR-code scanning buttons to two desktop token send screens and resets an internal address-validation state variable when the send form is cleared. There is no direct evidence in the commit that these changes fix a security vulnerability; they appear to be normal UI/UX improvements and state cleanup.
No immediate security action required. Treat as routine UI merge. If the _setValidAddressProviders reset was added in response to a bug report, review the related issue or PR discussion for security context before release.
Security signals we found
State reset added to clearForm() to avoid stale validation data
New QR scan entry points in token send flows (UI feature, not a vulnerability signal)
Evidence from the diff
The diff adds a QR-code icon import and a conditional ‘Scan QR’ button to DesktopSolTokenSend and DesktopTokenSend, shown only when the recipient text field is empty. It also calls _setValidAddressProviders(‘’) inside the clearForm() methods of SendView and DesktopSend. The latter change likely prevents stale address-provider validation state from persisting after a user clears the form, which could reduce UI confusion but is not shown to be exploitable.
Changed components
lib/pages/send_view/send_view.dartlib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_send.dartlib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_sol_token_send.dartlib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_token_send.dartInspect captured patch +18 / −0
### lib/pages/send_view/send_view.dart
@@ -1218,6 +1218,7 @@ class _SendViewState extends ConsumerState<SendView> {
_address = "";
_addressToggleFlag = false;
_setOpReturnData(null);
+ _setValidAddressProviders("");
setState(() {});
}
### lib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_send.dart
@@ -871,6 +871,7 @@ class _DesktopSendState extends ConsumerState<DesktopSend> {
_addressToggleFlag = false;
_syncFeeAmount(null);
_setOpReturnData(null);
+ _setValidAddressProviders("");
setState(() {});
}
### lib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_sol_token_send.dart
@@ -46,6 +46,7 @@ import '../../../../widgets/desktop/qr_code_scanner_dialog.dart';
import '../../../../widgets/desktop/secondary_button.dart';
import '../../../../widgets/icon_widgets/addressbook_icon.dart';
import '../../../../widgets/icon_widgets/clipboard_icon.dart';
+import '../../../../widgets/icon_widgets/qrcode_icon.dart';
import '../../../../widgets/icon_widgets/x_icon.dart';
import '../../../../widgets/stack_text_field.dart';
import '../../../../widgets/textfield_icon_button.dart';
@@ -1044,6 +1045,13 @@ class _DesktopSolTokenSendState extends ConsumerState<DesktopSolTokenSend> {
},
child: const AddressBookIcon(),
),
+ if (sendToController.text.isEmpty)
+ TextFieldIconButton(
+ semanticsLabel: "Scan QR Button. Opens Camera For Scanning QR Code.",
+ key: const Key("sendViewScanQrButtonKey"),
+ onTap: scanQr,
+ child: const QrCodeIcon(),
+ ),
],
),
),
### lib/pages_desktop_specific/my_stack_view/wallet_view/sub_widgets/desktop_token_send.dart
@@ -51,6 +51,7 @@ import '../../../../widgets/desktop/secondary_button.dart';
import '../../../../widgets/eth_fee_form.dart';
import '../../../../widgets/icon_widgets/addressbook_icon.dart';
import '../../../../widgets/icon_widgets/clipboard_icon.dart';
+import '../../../../widgets/icon_widgets/qrcode_icon.dart';
import '../../../../widgets/icon_widgets/x_icon.dart';
import '../../../../widgets/stack_text_field.dart';
import '../../../../widgets/textfield_icon_button.dart';
@@ -1042,6 +1043,13 @@ class _DesktopTokenSendState extends ConsumerState<DesktopTokenSend> {
},
child: const AddressBookIcon(),
),
+ if (sendToController.text.isEmpty)
+ TextFieldIconButton(
+ semanticsLabel: "Scan QR Button. Opens Camera For Scanning QR Code.",
+ key: const Key("sendViewScanQrButtonKey"),
+ onTap: scanQr,
+ child: const QrCodeIcon(),
+ ),
],
),
),Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.