What changed, and why it matters
This commit changes how the app handles package tracking links from a shopping partner API. Previously, the app took whatever text the API returned and treated it as a link. Now, if the text doesn't already start with 'http://' or 'https://', the app automatically adds 'https://' in front. This is a quick fix to prevent broken or unsafe links, but it doesn't fully validate that the resulting string is a real, safe URL.
Treat this as a temporary fix. Replace it with proper URL validation using a vetted URI parser, enforce an https-only allow-list for tracking providers, and sanitize or reject URLs that do not match expected patterns before presenting them to users or launching them in an external browser.
Security signals we found
URL scheme normalization added to API-derived tracking links
Prepend-only logic could upgrade http:// to https:// only when scheme is missing, not when http:// is explicitly supplied
No allow-list, domain validation, or URL parsing library used
Commit title describes change as a 'hack fix'
Untrusted API input is used to construct URLs that may be opened by the user
Evidence from the diff
The patch modifies splitTrackingLinks() in lib/services/shopinbit/src/models/ticket.dart. The original code simply trimmed each comma-or-pipe-separated token from the API and returned it as a tracking link. The new code checks whether each token begins with ‘http://’ or ‘https://’; if not, it prepends ‘https://’. This addresses cases where the upstream API returns bare hostnames or malformed URLs. However, the fix does not perform full URL parsing, scheme enforcement, allow-listing, or validation, so it remains a defensive ‘hack’ rather than a robust security control.
Changed components
lib/services/shopinbit/src/models/ticket.dartStack Wallet ShopinBit integrationTracking link display/handlingInspect captured patch +8 / −1
diff --git a/lib/services/shopinbit/src/models/ticket.dart b/lib/services/shopinbit/src/models/ticket.dart
index e42fb3d..4736823 100644
--- a/lib/services/shopinbit/src/models/ticket.dart
+++ b/lib/services/shopinbit/src/models/ticket.dart
@@ -9,7 +9,14 @@ List<String> splitTrackingLinks(String? raw) {
if (raw == null) return const [];
return raw
.split(RegExp(r'[,|;]'))
- .map((s) => s.trim())
+ .map((s) {
+ final url = s.trim();
+ if (url.startsWith("http://") || url.startsWith("https://")) {
+ return url;
+ } else {
+ return "https://$url";
+ }
+ })
.where((s) => s.isNotEmpty)
.toList();
}
Why this scored 38/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.