What changed, and why it matters
This commit is routine build and continuous-integration housekeeping. It adds missing placeholder API key entries for several exchange partners (including Trocador) to test and prebuild scripts, removes some stale gitignore entries, and fixes a minor string formatting issue in an error message. There is no indication of a security vulnerability being fixed.
No security action required. Treat as normal maintenance.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff updates CI/prebuild templates to include newly required API key constants (kTrocadorApiKey, kTrocadorRefCode, kLetsExchangeId, kLetsExchangeToken, kCypherGoatApiKey, kCypherGoatAffiliate) in external_api_keys.dart generation. It also cleans up .gitignore (removes cs_monero build output ignores) and reformats a single error string in lib/services/exchange/trocador/trocador_api.dart. No functional code changes to cryptographic, authentication, or network logic are present.
Changed components
.github/workflows/test.yamlscripts/prebuild.ps1scripts/prebuild.sh.gitignorelib/services/exchange/trocador/trocador_api.dartInspect captured patch +43 / −7
### .github/workflows/test.yaml
@@ -60,6 +60,12 @@ jobs:
const kShopInBitPartnerSecret = "";
const kCakePayApiToken = "";
const kExolixApiKey = "";
+ const kLetsExchangeId = "";
+ const kLetsExchangeToken = "";
+ const kCypherGoatApiKey = "";
+ const kCypherGoatAffiliate = "";
+ const kTrocadorApiKey = "";
+ const kTrocadorRefCode = "";
EOF
fi
### .gitignore
@@ -106,9 +106,6 @@ pubspec.yaml
scripts/linux/build/libsecret/subprojects/gi-docgen/.meson-subproject-wrap-hash.txt
-crypto_plugins/cs_monero/built_outputs
-crypto_plugins/cs_monero/build
-crypto_plugins/*.diff
/devtools_options.yaml
# generated interfaces
### .gitmodules
[binary or diff unavailable]
### lib/services/exchange/trocador/trocador_api.dart
@@ -318,8 +318,7 @@ abstract class TrocadorAPI {
String error = map["error"] as String? ?? json.toString();
if (error ==
"trade could not be generated, some unknown error happened") {
- error =
- "This trade couldn't be completed. Please select another provider.";
+ error = "This trade couldn't be completed. Please select another provider.";
}
Logging.instance.e(
### scripts/prebuild.ps1
@@ -2,9 +2,27 @@
$KEYS = "..\lib\external_api_keys.dart"
if (-not (Test-Path $KEYS)) {
Write-Host "prebuild.ps1: creating template lib/external_api_keys.dart file"
- "const kChangeNowApiKey = '';" + "`nconst kSimpleSwapApiKey = '';" + "`nconst kNanswapApiKey = '';" + "`nconst kNanoSwapRpcApiKey = '';" + "`nconst kWizSwapApiKey = '';" + "`nconst kShopInBitAccessKey = '';" + "`nconst kShopInBitPartnerSecret = '';" + "`nconst kCakePayApiToken = '';" + "`nconst kExolixApiKey = '';" + "`nconst kLetsExchangeId = '';" + "`nconst kLetsExchangeToken = '';" + "`nconst kCypherGoatApiKey = '';" + "`nconst kCypherGoatAffiliate = '';" | Out-File $KEYS -Encoding UTF8
+
+ @'
+const String kChangeNowApiKey = "";
+const String kSimpleSwapApiKey = "";
+const String kNanswapApiKey = "";
+const String kNanoSwapRpcApiKey = "";
+const String kWizSwapApiKey = "";
+const kShopInBitAccessKey = "";
+const kShopInBitPartnerSecret = "";
+const kCakePayApiToken = "";
+const kExolixApiKey = "";
+const kLetsExchangeId = "";
+const kLetsExchangeToken = "";
+const kCypherGoatApiKey = "";
+const kCypherGoatAffiliate = "";
+const kTrocadorApiKey = "";
+const kTrocadorRefCode = "";
+'@ | Out-File $KEYS -Encoding UTF8
}
+
# Create template wallet test parameter files if they don't already exist
$coins = @("bitcoin", "bitcoincash", "dogecoin", "namecoin", "firo", "particl") # TODO add monero and wownero when those tests are updated to use the .gitignored test wallet setup: when doing that, make sure to update the test vectors for a new, private development seed
### scripts/prebuild.sh
@@ -4,7 +4,23 @@
KEYS=../lib/external_api_keys.dart
if ! test -f "$KEYS"; then
echo 'prebuild.sh: creating template lib/external_api_keys.dart file'
- printf 'const kChangeNowApiKey = "";\nconst kSimpleSwapApiKey = "";\nconst kNanswapApiKey = "";\nconst kNanoSwapRpcApiKey = "";\nconst kWizSwapApiKey = "";\nconst kShopInBitAccessKey = "";\nconst kShopInBitPartnerSecret = "";\nconst kCakePayApiToken = "";\nconst kExolixApiKey = "";\nconst kLetsExchangeId = "";\nconst kLetsExchangeToken = "";\nconst kCypherGoatApiKey = "";\nconst kCypherGoatAffiliate = "";\n' > $KEYS
+ cat << 'EOF' > "$KEYS"
+const kChangeNowApiKey = "";
+const kSimpleSwapApiKey = "";
+const kNanswapApiKey = "";
+const kNanoSwapRpcApiKey = "";
+const kWizSwapApiKey = "";
+const kShopInBitAccessKey = "";
+const kShopInBitPartnerSecret = "";
+const kCakePayApiToken = "";
+const kExolixApiKey = "";
+const kLetsExchangeId = "";
+const kLetsExchangeToken = "";
+const kCypherGoatApiKey = "";
+const kCypherGoatAffiliate = "";
+const kTrocadorApiKey = "";
+const kTrocadorRefCode = "";
+EOF
fi
# Create template wallet test parameter files if they don't already existWhy this scored 13/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.