feat(shopinbit): cache car request payload when creating the fee invoice
What changed, and why it matters
This commit changes a car-research fee invoice screen so that, when requesting an invoice, the app now also sends the customer's car request details (a pseudonym, comment, and delivery country) to the backend. The stated goal is to let the backend create the real research ticket automatically once the fee is paid. There is no direct security bug visible in the diff, but it increases the amount of personal/order data transmitted and stored server-side, which could matter for privacy if the backend does not protect it properly.
Review the corresponding backend change that receives and caches the CarResearchRequest to verify the payload is authenticated, stored encrypted, access-controlled, and flushed appropriately. Also confirm that customerPseudonym and comment do not expose PII beyond what the user consented to share.
Security signals we found
New customer data fields sent to backend (customerPseudonym, comment, deliveryCountry)
Backend caching/failsafe logic mentioned but not reviewed in this commit
No visible input sanitization, encryption, or access-control changes
No security-relevant keywords in commit title or message
Evidence from the diff
The patch adds a CarResearchRequest object containing customerPseudonym, comment, and deliveryCountry and passes it to createCarResearchInvoice alongside existing billing data. The comment says this is a ‘failsafe’ cache so the backend can create the real car research ticket after fee payment. The diff itself only changes client-side data packaging; it does not show how the backend stores, authenticates, encrypts, or authorizes access to this cached payload. No input validation, encryption, or access-control changes are visible.
Changed components
lib/pages/shopinbit/shopinbit_car_fee_view.dartShopInBit car research invoice creation flowInspect captured patch +9 / −1
diff --git a/lib/pages/shopinbit/shopinbit_car_fee_view.dart b/lib/pages/shopinbit/shopinbit_car_fee_view.dart
index d6741e3..1606d4a 100644
--- a/lib/pages/shopinbit/shopinbit_car_fee_view.dart
+++ b/lib/pages/shopinbit/shopinbit_car_fee_view.dart
@@ -248,10 +248,18 @@ class _ShopInBitCarFeeViewState extends ConsumerState<ShopInBitCarFeeView> {
);
}
+ // Cache the car request alongside billing so the backend failsafe can
+ // create the real car research ticket once the fee is paid.
+ final request = CarResearchRequest(
+ customerPseudonym: widget.model.displayName,
+ comment: widget.model.requestDescription,
+ deliveryCountry: widget.model.deliveryCountry,
+ );
+
final resp = await ref
.read(pShopinBitService)
.client
- .createCarResearchInvoice(billing: billing);
+ .createCarResearchInvoice(billing: billing, request: request);
if (resp.hasError || resp.value == null) {
Logging.instance.e(
Why this scored 11/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.