What changed, and why it matters
This commit updates the Stack Wallet app's integration with the ShopInBit service. It mainly adds a new 'delivery state/province' field to order requests, normalizes how US states and Canadian provinces are displayed, and fixes a small UI spacing issue. There is no clear security problem here; it looks like routine feature cleanup to make address information more complete and consistent.
No security action required. Treat as a normal functional/UI review. If desired, verify that the new deliveryState value is validated or sanitized server-side, since the client only sends it when non-null.
Security signals we found
No security-relevant signals detected in the diff
Change is functional/cosmetic: adding a deliveryState field and normalizing state names
No changes to authentication, encryption, network trust, or sensitive data handling
Evidence from the diff
The diff propagates a new optional deliveryState parameter through the ShopInBit request flow: UI view models → service layer → HTTP client → JSON payload. It also removes state/province abbreviations from hard-coded picker lists and makes the shipping view tolerate both ‘Delivery state:’ and ‘State:’ prefixes when parsing a prior ticket message. A missing UI spacer widget is added. No cryptographic, authentication, or input-sanitization changes are visible.
Changed components
lib/pages/shopinbit/shopinbit_car_fee_view.dartlib/pages/shopinbit/shopinbit_shipping_view.dartlib/pages/shopinbit/step_4_components/shopinbit_state_picker.dartlib/pages/shopinbit/step_4_components/shopinbit_step4_submit.dartlib/services/shopinbit/shopinbit_service.dartlib/services/shopinbit/src/client.dartlib/services/shopinbit/src/models/car_research.dartInspect captured patch +76 / −63
diff --git a/lib/pages/shopinbit/shopinbit_car_fee_view.dart b/lib/pages/shopinbit/shopinbit_car_fee_view.dart
index 044c862..d2a9475 100644
--- a/lib/pages/shopinbit/shopinbit_car_fee_view.dart
+++ b/lib/pages/shopinbit/shopinbit_car_fee_view.dart
@@ -122,6 +122,7 @@ class _ShopInBitCarFeeViewState extends ConsumerState<ShopInBitCarFeeView> {
customerPseudonym: kShopInBitCustomerPseudonym,
comment: widget.draft.requestDescription,
deliveryCountry: widget.draft.deliveryCountryCode,
+ deliveryState: billing.state,
);
final resp = await ref
diff --git a/lib/pages/shopinbit/shopinbit_shipping_view.dart b/lib/pages/shopinbit/shopinbit_shipping_view.dart
index 9dee2da..03e1220 100644
--- a/lib/pages/shopinbit/shopinbit_shipping_view.dart
+++ b/lib/pages/shopinbit/shopinbit_shipping_view.dart
@@ -148,7 +148,10 @@ class _ShopInBitShippingViewState extends ConsumerState<ShopInBitShippingView> {
throw ArgumentError("Missing state/province in first ticket message");
}
- _selectedState = line.replaceFirst("Delivery state:", "").trim();
+ _selectedState = line
+ .replaceFirst("Delivery state:", "")
+ .replaceFirst("State:", "")
+ .trim();
} else {
_selectedState = null;
}
@@ -451,6 +454,7 @@ class _ShopInBitShippingViewState extends ConsumerState<ShopInBitShippingView> {
enableSuggestions: false,
onChanged: (_) => setState(() {}),
),
+ spacing,
AdaptiveTextField(
controller: _billingLastNameController,
labelText: "Last name",
diff --git a/lib/pages/shopinbit/step_4_components/shopinbit_state_picker.dart b/lib/pages/shopinbit/step_4_components/shopinbit_state_picker.dart
index 84ace39..fb20d9c 100644
--- a/lib/pages/shopinbit/step_4_components/shopinbit_state_picker.dart
+++ b/lib/pages/shopinbit/step_4_components/shopinbit_state_picker.dart
@@ -9,74 +9,74 @@ import "../../../utilities/text_styles.dart";
import "../../../utilities/util.dart";
const List<String> _usStates = [
- "Alabama (AL)",
- "Alaska (AK)",
- "Arizona (AZ)",
- "Arkansas (AR)",
- "California (CA)",
- "Colorado (CO)",
- "Connecticut (CT)",
- "Delaware (DE)",
- "Florida (FL)",
- "Georgia (GA)",
- "Hawaii (HI)",
- "Idaho (ID)",
- "Illinois (IL)",
- "Indiana (IN)",
- "Iowa (IA)",
- "Kansas (KS)",
- "Kentucky (KY)",
- "Louisiana (LA)",
- "Maine (ME)",
- "Maryland (MD)",
- "Massachusetts (MA)",
- "Michigan (MI)",
- "Minnesota (MN)",
- "Mississippi (MS)",
- "Missouri (MO)",
- "Montana (MT)",
- "Nebraska (NE)",
- "Nevada (NV)",
- "New Hampshire (NH)",
- "New Jersey (NJ)",
- "New Mexico (NM)",
- "New York (NY)",
- "North Carolina (NC)",
- "North Dakota (ND)",
- "Ohio (OH)",
- "Oklahoma (OK)",
- "Oregon (OR)",
- "Pennsylvania (PA)",
- "Rhode Island (RI)",
- "South Carolina (SC)",
- "South Dakota (SD)",
- "Tennessee (TN)",
- "Texas (TX)",
- "Utah (UT)",
- "Vermont (VT)",
- "Virginia (VA)",
- "Washington (WA)",
- "West Virginia (WV)",
- "Wisconsin (WI)",
+ "Alabama",
+ "Alaska",
+ "Arizona",
+ "Arkansas",
+ "California",
+ "Colorado",
+ "Connecticut",
+ "Delaware",
+ "Florida",
+ "Georgia",
+ "Hawaii",
+ "Idaho",
+ "Illinois",
+ "Indiana",
+ "Iowa",
+ "Kansas",
+ "Kentucky",
+ "Louisiana",
+ "Maine",
+ "Maryland",
+ "Massachusetts",
+ "Michigan",
+ "Minnesota",
+ "Mississippi",
+ "Missouri",
+ "Montana",
+ "Nebraska",
+ "Nevada",
+ "New Hampshire",
+ "New Jersey",
+ "New Mexico",
+ "New York",
+ "North Carolina",
+ "North Dakota",
+ "Ohio",
+ "Oklahoma",
+ "Oregon",
+ "Pennsylvania",
+ "Rhode Island",
+ "South Carolina",
+ "South Dakota",
+ "Tennessee",
+ "Texas",
+ "Utah",
+ "Vermont",
+ "Virginia",
+ "Washington",
+ "West Virginia",
+ "Wisconsin",
// Wyoming is now allowed as per chat with shopinbit
// "Wyoming (WY)",
];
const List<String> _canadaProvinces = [
- "Alberta (AB)",
- "British Columbia (BC)",
- "Manitoba (MB)",
- "New Brunswick (NB)",
- "Newfoundland and Labrador (NL)",
- "Northwest Territories (NT)",
- "Nova Scotia (NS)",
- "Nunavut (NU)",
- "Ontario (ON)",
- "Prince Edward Island (PE)",
- "Quebec (QC)",
- "Saskatchewan (SK)",
- "Yukon (YT)",
+ "Alberta",
+ "British Columbia",
+ "Manitoba",
+ "New Brunswick",
+ "Newfoundland and Labrador",
+ "Northwest Territories",
+ "Nova Scotia",
+ "Nunavut",
+ "Ontario",
+ "Prince Edward Island",
+ "Quebec",
+ "Saskatchewan",
+ "Yukon",
];
List<String> _statesForCountry(String countryIso) => switch (countryIso) {
diff --git a/lib/pages/shopinbit/step_4_components/shopinbit_step4_submit.dart b/lib/pages/shopinbit/step_4_components/shopinbit_step4_submit.dart
index b432644..9bafa78 100644
--- a/lib/pages/shopinbit/step_4_components/shopinbit_step4_submit.dart
+++ b/lib/pages/shopinbit/step_4_components/shopinbit_step4_submit.dart
@@ -29,6 +29,7 @@ Future<void> submitShopInBitRequest(
category: draft.category,
comment: draft.requestDescription,
deliveryCountry: draft.deliveryCountryCode,
+ deliveryState: draft.deliveryState,
voucherCode: draft.voucherCode,
);
diff --git a/lib/services/shopinbit/shopinbit_service.dart b/lib/services/shopinbit/shopinbit_service.dart
index b11ae39..d8e49e0 100644
--- a/lib/services/shopinbit/shopinbit_service.dart
+++ b/lib/services/shopinbit/shopinbit_service.dart
@@ -121,6 +121,7 @@ class ShopInBitService {
required ShopInBitCategory category,
required String comment,
required String deliveryCountry,
+ required String? deliveryState,
String? voucherCode,
}) async {
final String key = await ensureCustomerKey();
@@ -130,6 +131,7 @@ class ShopInBitService {
serviceType: category.apiValue,
comment: comment,
deliveryCountry: deliveryCountry,
+ deliveryState: deliveryState,
voucherCode: voucherCode,
);
if (resp.hasError || resp.value == null) return null;
diff --git a/lib/services/shopinbit/src/client.dart b/lib/services/shopinbit/src/client.dart
index fa46fdd..d6c20d0 100644
--- a/lib/services/shopinbit/src/client.dart
+++ b/lib/services/shopinbit/src/client.dart
@@ -114,6 +114,7 @@ class ShopInBitClient {
required String serviceType,
required String comment,
required String deliveryCountry,
+ required String? deliveryState,
String? voucherCode,
}) async {
return _request(
@@ -125,6 +126,7 @@ class ShopInBitClient {
'service_type': serviceType,
'comment': comment,
'delivery_country': deliveryCountry,
+ if (deliveryState != null) 'delivery_state': deliveryState,
if (voucherCode != null) 'voucher_code': voucherCode,
},
parse: (json) {
diff --git a/lib/services/shopinbit/src/models/car_research.dart b/lib/services/shopinbit/src/models/car_research.dart
index 99501ef..b770fc2 100644
--- a/lib/services/shopinbit/src/models/car_research.dart
+++ b/lib/services/shopinbit/src/models/car_research.dart
@@ -5,17 +5,20 @@ class CarResearchRequest {
final String customerPseudonym;
final String comment;
final String deliveryCountry;
+ final String? deliveryState;
CarResearchRequest({
required this.customerPseudonym,
required this.comment,
required this.deliveryCountry,
+ required this.deliveryState,
});
Map<String, dynamic> toJson() => {
'customer_pseudonym': customerPseudonym,
'comment': comment,
'delivery_country': deliveryCountry,
+ if (deliveryState != null) 'delivery_state': deliveryState,
};
}
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.