Log.print used developer.log with no kDebugMode guard, so release builds emitted wallet JWTs, the HMAC secret, phone numbers and full API responses to os_log/logcat on the user's device. Both the rider and driver apps were affected. Also removes a hardcoded test-account condition in the rider login flow that skipped the entire FCM-token/fingerprint comparison — and therefore the device-change OTP — for one email address. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
21 lines
755 B
Dart
21 lines
755 B
Dart
import 'dart:developer' as developer;
|
|
|
|
import 'package:flutter/foundation.dart' show kDebugMode;
|
|
|
|
class Log {
|
|
Log._();
|
|
|
|
/// ⚠️ يُطبع في وضع التطوير فقط.
|
|
/// `developer.log` لا يُحذف في نسخة الإصدار — يذهب إلى os_log على iOS
|
|
/// و logcat على أندرويد، وكان يسرّب الـ JWT وسر الـ HMAC وأرقام الهواتف
|
|
/// وردود الـ API كاملة إلى سجلّ النظام على جهاز المستخدم.
|
|
static void print(String value, {StackTrace? stackTrace}) {
|
|
if (!kDebugMode) return;
|
|
developer.log(value, name: 'LOG', stackTrace: stackTrace);
|
|
}
|
|
|
|
static Object? inspect(Object? object) {
|
|
// return developer.inspect(object);
|
|
}
|
|
}
|