feat(shopinbit): backfill remote tickets into the local db on refresh
What changed, and why it matters
This commit adds a feature that downloads a user's complete order/ticket list from a remote service and saves any missing entries into the local database when the app refreshes. It is a routine data-synchronization improvement, not a security fix.
No security action required. Treat as a normal feature commit.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The change introduces a backfill step in ShopInBitOrdersService.refreshAll(). Before refreshing known tickets, it calls shopInBitService.fetchAllForCustomerKey(customerKey), iterates the returned companions, and inserts/updates them via insertOnConflictUpdate. Errors in this backfill are swallowed so the existing refresh path still runs. The SharedDrift.get() call is moved earlier to support both paths. No input validation, authentication, authorization, or cryptographic logic is changed.
Changed components
lib/services/shopinbit/shopinbit_orders_service.dartInspect captured patch +16 / −1
diff --git a/lib/services/shopinbit/shopinbit_orders_service.dart b/lib/services/shopinbit/shopinbit_orders_service.dart
index 204bb25..4594d1c 100644
--- a/lib/services/shopinbit/shopinbit_orders_service.dart
+++ b/lib/services/shopinbit/shopinbit_orders_service.dart
@@ -158,12 +158,27 @@ class ShopInBitOrdersService extends ChangeNotifier {
Future<void> refreshAll() async {
try {
final customerKey = await shopInBitService.ensureCustomerKey();
+ final db = SharedDrift.get();
+
+ // Backfill rows for tickets that exist on the API but not locally
+ // (created on another device, web dashboard, etc.). A failure here
+ // shouldn't stop the refresh of tickets we already know about.
+ try {
+ final newCompanions = await shopInBitService.fetchAllForCustomerKey(
+ customerKey,
+ );
+ for (final companion in newCompanions) {
+ await db.into(db.shopInBitTickets).insertOnConflictUpdate(companion);
+ }
+ } catch (_) {
+ // Fall through to the refresh-existing path.
+ }
+
final resp = await shopInBitService.client.getTicketsByCustomer(
customerKey,
);
if (resp.hasError || resp.value == null) return;
- final db = SharedDrift.get();
final localRows = await db.select(db.shopInBitTickets).get();
final byApiId = {for (final r in localRows) r.apiTicketId: r};
Why this scored 12/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.