chore(shopinbit): address review on car-research finalize
What changed, and why it matters
This commit makes two small code cleanups in a car-research payment flow. One change removes a manual timer cancellation and relies on the caller to cancel it, which could in theory lead to a timer continuing to run briefly if the caller doesn't always do so. The other change replaces a safe integer parser (which throws a clear error on bad input) with a stricter parser that throws a less informative error. Neither change is obviously a security fix, and the commit message frames them as routine review follow-up rather than a security issue.
No immediate security action is warranted based on the diff alone. Reviewers may want to verify that `_pollStatus` always cancels the timer before invoking `finalize()` and that removing the `mounted` guard does not introduce UI exceptions. Consider whether the less descriptive parse error affects debugging or logging.
Security signals we found
Timer lifecycle moved from callee to caller (potential consistency issue if caller behavior changes)
Removal of `mounted` guard before `setState` (could cause widget-state exceptions, not a security flaw)
Error message made less descriptive in `_toInt` parsing helper
Evidence from the diff
In shopinbit_car_research_payment_view.dart, the patch removes _pollTimer?.cancel() from finalize() and adds a comment that the caller (_pollStatus) cancels the timer. It also removes a mounted guard before setState. In ticket.dart, _toInt() is changed from int.tryParse() with a descriptive FormatException to int.parse(), which throws a FormatException with a generic message on invalid input. The diff is small and appears to be a refactor/cleanup; there is no direct evidence of a vulnerability being fixed.
Changed components
lib/pages/shopinbit/shopinbit_car_research_payment_view.dartlib/services/shopinbit/src/models/ticket.dartInspect captured patch +2 / −7
diff --git a/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart b/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart
index 808884f..0e77518 100644
--- a/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart
+++ b/lib/pages/shopinbit/shopinbit_car_research_payment_view.dart
@@ -388,14 +388,13 @@ class _ShopInBitCarResearchPaymentViewState
}
setState(() => _flowState = _PaymentFlowState.finalizing);
- _pollTimer?.cancel();
try {
// The finalized status carries the real car ticket id (the customer
// chat), so open that. The BTCPay webhook creates the ticket regardless.
+ // The caller (_pollStatus) cancels the poll timer before calling this.
final int? realId = _realTicketId;
- if (!mounted) return;
setState(() => _flowState = _PaymentFlowState.complete);
if (realId != null) {
diff --git a/lib/services/shopinbit/src/models/ticket.dart b/lib/services/shopinbit/src/models/ticket.dart
index 174b6ac..0a3a386 100644
--- a/lib/services/shopinbit/src/models/ticket.dart
+++ b/lib/services/shopinbit/src/models/ticket.dart
@@ -169,9 +169,5 @@ class TicketFull {
int _toInt(dynamic value) {
if (value is int) return value;
- final parsed = int.tryParse(value.toString());
- if (parsed == null) {
- throw FormatException("ShopInBit: expected an integer, got '$value'");
- }
- return parsed;
+ return int.parse(value.toString());
}
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.