fix(shopinbit): clear isPendingPayment before retry write
What changed, and why it matters
This commit fixes a small logic bug in a cryptocurrency wallet's car-research payment screen. Before saving a payment ticket to the local database, the code now clears a 'resume/retry' flag (isPendingPayment). Without the fix, the app might incorrectly think a payment was still pending after it had already completed, which could confuse the user or allow an unintended retry/refund flow. There is no direct evidence of a security vulnerability such as theft of funds.
Review all consumers of isPendingPayment to confirm the flag is cleared consistently at every terminal state (success, failure, cancellation). Add automated tests covering retry/resume paths and consider adding a guard in the persistence layer or state machine to reject inconsistent flag combinations.
Security signals we found
State-flag not cleared before persistence
Potential inconsistent local state leading to duplicate/retry actions
UI/payment-flow state machine bug
Evidence from the diff
In lib/pages/shopinbit/shopinbit_car_research_payment_view.dart, after a ShopInBit car-research payment request is created and the ticket status is set to pending, the patch now sets widget.model.isPendingPayment = false before persisting the ticket via MainDB.instance.putShopInBitTicket(). The flag appears to control whether the app should resume or retry an unfinished payment. The change prevents the persisted ticket from retaining a stale ‘pending payment’ state once the flow is complete. The diff is two lines (one comment, one assignment) and is a partial/local fix; no broader context about how isPendingPayment is consumed elsewhere is provided.
Changed components
lib/pages/shopinbit/shopinbit_car_research_payment_view.dartShopInBit car research payment flowlocal Isar ticket persistenceInspect captured patch +2 / −0
diff --git a/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart b/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart
index c66ef5e..2365814 100644
--- a/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart
+++ b/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart
@@ -560,6 +560,8 @@ class _ShopInBitCarResearchPaymentViewState
widget.model.apiTicketId = requestRef.id;
widget.model.ticketId = requestRef.number;
widget.model.status = ShopInBitOrderStatus.pending;
+ // Flow complete: clear the resume flag before saving.
+ widget.model.isPendingPayment = false;
await MainDB.instance.putShopInBitTicket(widget.model.toIsarTicket());
// Update fee receipt ticket
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.