fix: This does not actually return a 403 when testing and is required to get a status update. Commenting out for now as otherwise the request will stay pending for ever in the UI
What changed, and why it matters
A developer commented out a special-case skip that prevented 'car research' support tickets from having their status checked. The change makes the app try to fetch status for those tickets too, fixing a UI hang where the request appeared to stay pending forever. There is no clear security problem in the diff itself; it is a functional bug fix.
Treat as a routine functional/UI fix. No security action required based on the commit alone. If the 403 behavior was originally a server-side access-control decision, verify server-side authorization is still enforced independently of the client skip.
Security signals we found
No direct security signal in diff
Change is a one-line functional comment-out for UI status refresh behavior
No authentication, authorization, cryptographic, or input-validation changes observed
Evidence from the diff
In lib/pages/shopinbit/shopinbit_tickets_view.dart, the line if (_tickets[localIdx].category == ShopInBitCategory.car) continue; was commented out. That guard had skipped status updates for car-research tickets because the /tickets/:id/* endpoints were believed to return HTTP 403 for them. The commit says the endpoint does not actually return 403 during testing and the skip is needed to get a status update, otherwise the UI request remains pending. The change simply removes the skip so the app calls service.client.getTicketStatus(ref.id) for car tickets as well.
Changed components
lib/pages/shopinbit/shopinbit_tickets_view.dartShopInBit ticket status refresh logicInspect captured patch +1 / −1
diff --git a/lib/pages/shopinbit/shopinbit_tickets_view.dart b/lib/pages/shopinbit/shopinbit_tickets_view.dart
index d600a00..32b65ce 100644
--- a/lib/pages/shopinbit/shopinbit_tickets_view.dart
+++ b/lib/pages/shopinbit/shopinbit_tickets_view.dart
@@ -123,7 +123,7 @@ class _ShopInBitTicketsViewState extends State<ShopInBitTicketsView> {
if (localIdx < 0) continue;
// Car research tickets return 403 on /tickets/:id/* endpoints.
- if (_tickets[localIdx].category == ShopInBitCategory.car) continue;
+ // if (_tickets[localIdx].category == ShopInBitCategory.car) continue;
final statusResp = await service.client.getTicketStatus(ref.id);
if (statusResp.hasError || statusResp.value == null) continue;
Why this scored 11/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.