misc: update to locked Xelis deps, adopt unified FFI lib API
What changed, and why it matters
This commit updates the Xelis cryptocurrency integration in Stack Wallet. It switches from a development Git dependency to a pinned published package version, adds support for a new 'stage' test network, fixes a block explorer URL path, and makes address validation aware of which network an address belongs to. There is no direct evidence in the commit of a security vulnerability being fixed; it reads as a routine dependency and API alignment update.
Treat as a normal maintenance/dependency update. Review the Xelis SDK and FFI changelog for any security fixes included in the version bumps, since the commit itself does not disclose security relevance. Verify that the new network-aware address validation correctly maps each Stack Wallet network enum to the corresponding Xelis network constant.
Security signals we found
Dependency source changed from floating Git refs to pinned versions (supply-chain hygiene)
Address validation now network-aware, which can prevent cross-network address misuse
Block explorer URL path corrected from /txs/ to /tx/
Evidence from the diff
The diff updates pubspec.lock and the pubspec template to pin xelis_dart_sdk to hosted version 0.30.9 and xelis_flutter to git ref v0.2.0, replacing earlier floating Git refs. It adds CryptoCurrencyNetwork.stage handling in xelis.dart, supplies a stagenet node, and corrects the mainnet explorer URL from /txs/ to /tx/. The isAddressValid method now requires a network parameter and passes it to the underlying FFI utility, and NewAsset.maxSupply changes type from int? to MaxSupplyMode? to match the updated SDK. No security bug or CVE is mentioned.
Changed components
lib/wallets/crypto_currency/coins/xelis.dartlib/wl_gen/interfaces/lib_xelis_interface.dartpubspec.lockscripts/app_config/templates/pubspec.template.yamltool/wl_templates/XEL_lib_xelis_interface_impl.template.dartInspect captured patch +60 / −22
diff --git a/lib/wallets/crypto_currency/coins/xelis.dart b/lib/wallets/crypto_currency/coins/xelis.dart
index e036c24..d022082 100644
--- a/lib/wallets/crypto_currency/coins/xelis.dart
+++ b/lib/wallets/crypto_currency/coins/xelis.dart
@@ -19,6 +19,10 @@ class Xelis extends ElectrumCurrency {
_id = "xelisTestNet";
_name = "tXelis";
_ticker = "XET";
+ case CryptoCurrencyNetwork.stage:
+ _id = "xelisStageNet";
+ _name = "sXelis";
+ _ticker = "XET";
default:
throw Exception("Unsupported network: $network");
}
@@ -79,6 +83,22 @@ class Xelis extends ElectrumCurrency {
isPrimary: isPrimary,
);
+ case CryptoCurrencyNetwork.test:
+ return NodeModel(
+ host: "stagenet-node.xelis.io",
+ port: 443,
+ name: DefaultNodes.defaultName,
+ id: DefaultNodes.buildId(this),
+ useSSL: true,
+ enabled: true,
+ coinName: identifier,
+ isFailover: true,
+ isDown: false,
+ torEnabled: false,
+ clearnetEnabled: true,
+ isPrimary: isPrimary,
+ );
+
default:
throw Exception("Unsupported network: $network");
}
@@ -93,7 +113,7 @@ class Xelis extends ElectrumCurrency {
@override
bool validateAddress(String address) {
try {
- return libXelis.isAddressValid(address: address);
+ return libXelis.isAddressValid(address: address, network: network);
} catch (_) {
return false;
}
@@ -133,7 +153,11 @@ class Xelis extends ElectrumCurrency {
Uri defaultBlockExplorer(String txid) {
switch (network) {
case CryptoCurrencyNetwork.main:
- return Uri.parse("https://explorer.xelis.io/txs/$txid");
+ return Uri.parse("https://explorer.xelis.io/tx/$txid");
+ case CryptoCurrencyNetwork.test:
+ return Uri.parse("https://testnet-explorer.xelis.io/tx/$txid");
+ case CryptoCurrencyNetwork.stage:
+ return Uri.parse("https://stagenet-explorer.xelis.io/tx/$txid");
default:
throw Exception(
"Unsupported network for defaultBlockExplorer(): $network",
diff --git a/lib/wl_gen/interfaces/lib_xelis_interface.dart b/lib/wl_gen/interfaces/lib_xelis_interface.dart
index 494b698..52d9079 100644
--- a/lib/wl_gen/interfaces/lib_xelis_interface.dart
+++ b/lib/wl_gen/interfaces/lib_xelis_interface.dart
@@ -1,4 +1,5 @@
import 'package:flutter/foundation.dart';
+import 'package:xelis_dart_sdk/src/data_transfer_objects/get_asset/max_supply_mode.dart';
import '../../providers/progress_report/xelis_table_progress_provider.dart';
import '../../wallets/crypto_currency/crypto_currency.dart';
@@ -18,7 +19,7 @@ abstract class LibXelisInterface {
Stream<XelisTableProgressState> createProgressReportStream();
- bool isAddressValid({required String address});
+ bool isAddressValid({required String address, required CryptoCurrencyNetwork network});
bool validateSeedWord(String word);
@@ -296,7 +297,7 @@ final class NewAsset extends Event {
// final xelis_sdk.AssetData asset;
final String name;
final int decimals;
- final int? maxSupply;
+ final MaxSupplyMode? maxSupply;
NewAsset(this.name, this.decimals, this.maxSupply);
}
diff --git a/pubspec.lock b/pubspec.lock
index 823d59c..4cbc870 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -1163,14 +1163,22 @@ packages:
description: flutter
source: sdk
version: "0.0.0"
+ freezed:
+ dependency: "direct overridden"
+ description:
+ name: freezed
+ sha256: "03dd9b7423ff0e31b7e01b2204593e5e1ac5ee553b6ea9d8184dff4a26b9fb07"
+ url: "https://pub.dev"
+ source: hosted
+ version: "3.2.4"
freezed_annotation:
- dependency: transitive
+ dependency: "direct overridden"
description:
name: freezed_annotation
- sha256: c2e2d632dd9b8a2b7751117abcfc2b4888ecfe181bd9fca7170d9ef02e595fe2
+ sha256: "7294967ff0a6d98638e7acb774aac3af2550777accd8149c90af5b014e6d44d8"
url: "https://pub.dev"
source: hosted
- version: "2.4.4"
+ version: "3.1.0"
frontend_server_client:
dependency: transitive
description:
@@ -2462,10 +2470,10 @@ packages:
dependency: transitive
description:
name: very_good_analysis
- sha256: e479fbc0941009262343db308133e121bf8660c2c81d48dd8e952df7b7e1e382
+ sha256: "96245839dbcc45dfab1af5fa551603b5c7a282028a64746c19c547d21a7f1e3a"
url: "https://pub.dev"
source: hosted
- version: "9.0.0"
+ version: "10.0.0"
vm_service:
dependency: transitive
description:
@@ -2613,23 +2621,22 @@ packages:
source: hosted
version: "1.1.0"
xelis_dart_sdk:
- dependency: transitive
+ dependency: "direct main"
description:
- path: "."
- ref: HEAD
- resolved-ref: "62f1c16a2762b9d4e9db24d101035b28a2dcc69e"
- url: "https://github.com/Tritonn204/xelis-dart-sdk"
- source: git
- version: "0.29.0"
+ name: xelis_dart_sdk
+ sha256: "2393fcd3dfe9175e34ed60e1a1f8821fb63d6a99d66894b9a24cdfc8cb4a6a4b"
+ url: "https://pub.dev"
+ source: hosted
+ version: "0.30.9"
xelis_flutter:
dependency: "direct main"
description:
path: "."
- ref: b09b3ffd89bc6390f6d565b967c2ae1052a4bdd2
- resolved-ref: b09b3ffd89bc6390f6d565b967c2ae1052a4bdd2
+ ref: "v0.2.0"
+ resolved-ref: "4aeeebc80a1b364b2105799cd1b08d159725bfac"
url: "https://github.com/xelis-project/xelis-flutter-ffi.git"
source: git
- version: "0.1.1"
+ version: "0.2.0"
xml:
dependency: transitive
description:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 1c84290..86d7040 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -30,10 +30,14 @@ dependencies:
# %%END_ENABLE_FROST%%
# %%ENABLE_XEL%%
+# xelis_dart_sdk: 0.30.9
+## git:
+## url: https://github.com/xelis-project/xelis-dart-sdk.git
+## ref: f1da98f8bad8b9ad3645661a23f9efb83e44b0c9
# xelis_flutter:
# git:
# url: https://github.com/xelis-project/xelis-flutter-ffi.git
-# ref: b09b3ffd89bc6390f6d565b967c2ae1052a4bdd2
+# ref: v0.2.0
# %%END_ENABLE_XEL%%
# %%ENABLE_FIRO%%
@@ -341,6 +345,8 @@ dependency_overrides:
# xelis override
json_rpc_2: ^4.0.0
+ freezed: ^3.1.0
+ freezed_annotation: ^3.1.0
# %%ENABLE_ISAR%%
# isar_community:
diff --git a/tool/wl_templates/XEL_lib_xelis_interface_impl.template.dart b/tool/wl_templates/XEL_lib_xelis_interface_impl.template.dart
index 9db4f3e..faccfbb 100644
--- a/tool/wl_templates/XEL_lib_xelis_interface_impl.template.dart
+++ b/tool/wl_templates/XEL_lib_xelis_interface_impl.template.dart
@@ -116,8 +116,8 @@ final class _LibXelisInterfaceImpl extends LibXelisInterface {
}
@override
- bool isAddressValid({required String address}) =>
- x_utils.isAddressValid(strAddress: address);
+ bool isAddressValid({required String address, required CryptoCurrencyNetwork network}) =>
+ x_utils.isAddressValid(strAddress: address, network: network.xelisNetwork);
@override
bool validateSeedWord(String word) {
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.