What changed, and why it matters
A single-line change flips a third-party shopping integration from sandbox/test mode to live/production mode. This is a configuration change rather than a traditional code vulnerability, but it moves real user transactions and partner secrets from a safe test environment to the live service. If the rest of the app is not ready for production, this could expose real payment or order data, charge real money, or leak the partner secret through production traffic.
Treat this as a release-readiness checkpoint, not just a routine commit. Verify that the partner secret and access key are stored securely (e.g., encrypted at rest, not in source control or logs), that network traffic uses certificate pinning or strong TLS validation, that order/payment flows have been tested end-to-end in sandbox, and that production error handling does not leak secrets or user data. Review whether the commit should have been accompanied by a version bump, changelog note, or security review sign-off.
Security signals we found
Production environment toggle enabled without visible accompanying hardening
Removal of explicit TODO comment that marked this as a planned production change
Third-party API credentials (access key + partner secret) now used against live endpoint
Potential for real financial transactions, real PII, and real partner-billing if integration logic is immature
Evidence from the diff
The commit changes the sandbox parameter of ShopInBitClient from true to false in lib/providers/global/shopin_bit_service_provider.dart. The removed comment explicitly says ‘TODO set to false in prod’, indicating this was a known staging toggle. With sandbox: false, the client now talks to the production ShopInBit endpoint using kShopInBitAccessKey and kShopInBitPartnerSecret. There is no diff evidence of additional hardening, input validation, logging, or secret-handling changes accompanying the switch.
Changed components
lib/providers/global/shopin_bit_service_provider.dartShopInBitClient integrationShopInBit partner API credentials handlingInspect captured patch +1 / −1
diff --git a/lib/providers/global/shopin_bit_service_provider.dart b/lib/providers/global/shopin_bit_service_provider.dart
index d2e5a49..102a59f 100644
--- a/lib/providers/global/shopin_bit_service_provider.dart
+++ b/lib/providers/global/shopin_bit_service_provider.dart
@@ -11,7 +11,7 @@ final pShopinBitService = Provider(
client: ShopInBitClient(
accessKey: kShopInBitAccessKey,
partnerSecret: kShopInBitPartnerSecret,
- sandbox: true, // TODO set to false in prod
+ sandbox: false,
),
db: ref.watch(pSharedDrift),
),
Why this scored 44/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.