What changed, and why it matters
This commit changes a third-party shopping integration from 'sandbox' (test) mode to live mode. The developer left a note earlier saying it should be set to false in production. The change itself is a normal production toggle, but because it involves real money/purchases and secret API credentials, it is worth reviewing whether this was released safely and whether any test-only behavior or weaker security settings were carried over accidentally.
Verify that the production ShopInBit endpoint is used, TLS/certificate pinning is enforced, secrets are not logged or exposed in release builds, and that sandbox-only logic (if any) is gated by the same flag or removed. Treat this as a release-readiness check rather than a confirmed vulnerability.
Security signals we found
Production API mode enabled for an e-commerce integration
Hardcoded API secrets (`kShopInBitAccessKey`, `kShopInBitPartnerSecret`) are passed to the client
Prior TODO comment explicitly warned this must be disabled in production
No accompanying changes to endpoints, TLS pinning, or credential storage are visible in the diff
Evidence from the diff
The diff flips the sandbox boolean from true to false in ShopInBitClient initialization within lib/providers/global/shopin_bit_service_provider.dart. The constructor also receives accessKey and partnerSecret. Sandbox APIs often use different endpoints, relaxed validation, or no real billing; moving to production means real transactions and real credentials are now in scope. The patch is minimal and does not show credential handling, endpoint selection, certificate pinning, or error-handling changes, so we cannot confirm whether those were reviewed at the same time.
Changed components
lib/providers/global/shopin_bit_service_provider.dartShopInBitClient integrationIn-app shopping/purchasing flowInspect captured patch +1 / −1
diff --git a/lib/providers/global/shopin_bit_service_provider.dart b/lib/providers/global/shopin_bit_service_provider.dart
index d2e5a49..102a59f 100644
--- a/lib/providers/global/shopin_bit_service_provider.dart
+++ b/lib/providers/global/shopin_bit_service_provider.dart
@@ -11,7 +11,7 @@ final pShopinBitService = Provider(
client: ShopInBitClient(
accessKey: kShopInBitAccessKey,
partnerSecret: kShopInBitPartnerSecret,
- sandbox: true, // TODO set to false in prod
+ sandbox: false,
),
db: ref.watch(pSharedDrift),
),
Why this scored 45/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.