What changed, and why it matters
A single-line fix changes which app feature flag controls whether a 'Gift cards' button appears in the wallet screen. The old code checked a flag named 'shopinBit' but should have checked 'cakePay'. This is almost certainly a UI/functional bug rather than a security vulnerability, but it could affect whether users see or can access a third-party gift-card service integration.
Treat as a routine functional bug fix. If the gift-card integration involves payments or external service calls, review the CakePay integration's security posture separately, but this commit does not introduce or fix a known security defect.
Security signals we found
Feature-flag mismatch could expose or hide a third-party service integration
No input handling, crypto, or privilege logic changed
No security-relevant keywords in commit title or message
Evidence from the diff
In lib/pages/wallet_view/wallet_view.dart, the condition guarding a WalletNavigationBarItemData for ‘Gift cards’ was corrected from AppConfig.hasFeature(Feature.shopinBit) to AppConfig.hasFeature(Feature.cakePay). The diff shows no other logic changes. There is no evidence of memory corruption, injection, authentication bypass, cryptographic mishandling, or data leakage in the change itself.
Changed components
lib/pages/wallet_view/wallet_view.dartWallet navigation bar UICakePay / ShopinBit gift-card feature flagInspect captured patch +1 / −1
diff --git a/lib/pages/wallet_view/wallet_view.dart b/lib/pages/wallet_view/wallet_view.dart
index 5d15365..b6619f9 100644
--- a/lib/pages/wallet_view/wallet_view.dart
+++ b/lib/pages/wallet_view/wallet_view.dart
@@ -1364,7 +1364,7 @@ class _WalletViewState extends ConsumerState<WalletView> {
).pushNamed(ServicesView.routeName);
},
),
- if (AppConfig.hasFeature(.shopinBit))
+ if (AppConfig.hasFeature(.cakePay))
WalletNavigationBarItemData(
label: "Gift cards",
icon: CreditCardIcon(
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.