What changed, and why it matters
This commit updates a database migration in the Stack Wallet app. It bumps the database version from 2 to 3 and changes the upgrade logic so that, when upgrading from any version below 3, two tables related to a 'Shop in Bit' feature are deleted and recreated, plus an app notifications table is created. The commit message and code comment state this is needed to 'recreate sib tables correctly.' There is no explicit mention of a security issue in the commit or supplied references. The main risk is that deleting and recreating tables during migration could cause data loss if the tables already contained user data, but the developer comment claims the feature was not used before this point. No independent security disclosure or vendor security advisory was provided.
Treat as a routine schema migration unless additional vendor or independent security context emerges. Review whether any production app builds with schema version 1 or 2 could have populated shopInBitSettings or shopInBitTickets, since deleteTable would drop that data. Verify the migration is idempotent and handles failures gracefully. No immediate security patch urgency is indicated by the diff alone.
Security signals we found
Destructive database migration: deleteTable followed by createTable for two tables
Schema version bump with broadened upgrade condition (from < 3)
Developer comment claiming deleted tables were unused prior to this change
No explicit security language, CVE, advisory, or researcher attribution in commit
Evidence from the diff
The patch modifies lib/db/drift/shared_db/shared_database.dart. It increments schemaVersion from 2 to 3 and broadens the migration condition from if (from < 2) to if (from < 3). Inside that branch it now calls m.deleteTable for shopInBitSettings and shopInBitTickets, then creates those two tables plus appNotifications. The comment asserts deletion is safe because ‘sib was not used before this.’ This is a corrective schema migration, not an obvious vulnerability fix. Without additional context, security relevance is speculative: potential concerns include destructive migration causing data loss, migration running on every upgrade from schema < 3, and possible migration failures leaving the database in an inconsistent state, but no exploit path is visible from the diff alone.
Changed components
lib/db/drift/shared_db/shared_database.dartShop in Bit settings table (shopInBitSettings)Shop in Bit tickets table (shopInBitTickets)App notifications table (appNotifications)Inspect captured patch +6 / −2
diff --git a/lib/db/drift/shared_db/shared_database.dart b/lib/db/drift/shared_db/shared_database.dart
index 456b4f6..df07f9f 100644
--- a/lib/db/drift/shared_db/shared_database.dart
+++ b/lib/db/drift/shared_db/shared_database.dart
@@ -41,12 +41,16 @@ final class SharedDatabase extends _$SharedDatabase {
: super(executor ?? _openConnection());
@override
- int get schemaVersion => 2;
+ int get schemaVersion => 3;
@override
MigrationStrategy get migration => MigrationStrategy(
onUpgrade: (m, from, to) async {
- if (from < 2) {
+ if (from < 3) {
+ // deletion is fine here because sib was not used before this
+ await m.deleteTable(shopInBitSettings.actualTableName);
+ await m.deleteTable(shopInBitTickets.actualTableName);
+
await m.createTable(shopInBitSettings);
await m.createTable(shopInBitTickets);
await m.createTable(appNotifications);
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.