AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 45 Monero

serialize external amounts with locale-independent decimals and use standard monero family query parameters

Public commit record

What the developer wrote

Authored by Julian

50/100 · Thin
serialize external amounts with locale-independent decimals and use standard monero family query parameters
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes how the wallet builds payment QR codes and web links so that the amount is written in a standard, locale-independent decimal format and uses the correct parameter names for Monero-family coins. Before, a user in a country that uses a comma as the decimal separator could generate a QR code with an amount another wallet might misread, and Monero-style URIs used non-standard fields. The change also adds input formatting and parsing helpers to keep the user's typed amount consistent with their locale while exporting a canonical decimal string.

Recommended action

Review the new Amount.tryParseCanonicalAmount, Amount.tryParseEditableAmount, and AmountInputFormatter implementations to confirm they reject malformed input and always serialize with a dot decimal separator. Verify that buildPaymentUriString is used everywhere payment URIs are constructed, and that downstream parsers handle tx_amount/tx_description correctly for Monero-family coins.

Security signals we found

01

Locale-dependent amount serialization in payment URIs

02

Monero-family URI parameter standardization (tx_amount/tx_description)

03

Amount parsing hardening with canonical format and overprecision truncation

04

New input formatter and relocalization listener for amount fields

Risk score

Why this scored 45/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 7/15
Affected reach 9/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.