Skip to content

Conversation

@runway-github
Copy link
Contributor

@runway-github runway-github bot commented Oct 29, 2025

Description

This PR improves the Onboarding flow by adding coverage for several edge
cases and refining the token management strategy for the onboarding
token. These updates ensure more reliable handling of onboarding
sessions and reduce potential authentication inconsistencies.

Changelog

CHANGELOG entry: Added coverage for edge cases in the Onboarding flow
CHANGELOG entry: Improved onboarding token management strategy
CHANGELOG entry: Enhanced session reliability and authentication
consistency

Related issues

Fixes:

Manual testing steps

Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Note

Improves card onboarding/login flows, adds robust auth error handling and access-token storage, and introduces utilities/tests for onboarding token management.

  • Card Onboarding/Auth (UI + Flow):
    • Redirect login to onboarding when verification is pending; store onboardingId in Redux.
    • Confirm Email: navigates to auth when account exists and shows toast; resend cooldown; stricter validation.
    • Physical/Mailing Address: on success store short-lived access token, set authenticated state/location, then continue; improved field handling and validation; minor UI tweak to area code selector width.
  • Card Home (Error Handling):
    • Detect authentication errors, clear stored tokens and Redux auth state, and redirect to welcome; hide "Try again" on auth errors.
  • Auth/Session Management:
    • cardTokenVault: support access-only tokens (optional refresh token), validate accordingly.
    • handleLocalAuthentication: handle access-only tokens (5‑min buffer), clear on expiry, refresh and persist full tokens; clearer logs.
  • SDK/Hook Updates:
    • CardSDK.getCardDetails throws INVALID_CREDENTIALS on 401; email/phone verification endpoints and auth flow refinements.
    • useCardProviderAuthentication: treat OTP/pending/phase states as intermediate; proceed only after token exchange; set auth state/location.
    • useRegisterPersonalDetails: cleanup and naming consistency.
  • Utilities:
    • Add extractTokenExpiration (default 5 hours) and mapCountryToLocation helpers.
    • Add isAuthenticationError helper to classify auth failures.
  • Tests & i18n:
    • Comprehensive tests for Confirm Email, Mailing Address, auth handling, and token expiration/auth flows.
    • Add/update locale strings for onboarding and KYC states.

Written by Cursor Bugbot for commit e94d8c1. This will update automatically on new commits. Configure here.


Co-authored-by: sophieqgu [email protected] a172652

… Onboarding token management (#21594)

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

This PR improves the Onboarding flow by adding coverage for several edge
cases and refining the token management strategy for the onboarding
token. These updates ensure more reliable handling of onboarding
sessions and reduce potential authentication inconsistencies.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Added coverage for edge cases in the Onboarding flow
CHANGELOG entry: Improved onboarding token management strategy
CHANGELOG entry: Enhanced session reliability and authentication
consistency

## **Related issues**

Fixes:

## **Manual testing steps**

```gherkin
Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]
```

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [x] I’ve followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> Enhances card onboarding and authentication with access-only token
storage, onboarding redirects, robust auth-error handling/cleanup, and
extensive test coverage and i18n updates.
> 
> - **Onboarding/Auth flows**:
> - `CardAuthentication`: Redirects to `Routes.CARD.ONBOARDING.ROOT` and
sets `onboardingId` when `verificationState === 'PENDING'` or `phase`
exists; keeps OTP step handling.
> - `ConfirmEmail`: Adds resend cooldown, validation, Redux updates for
IDs, navigates to `CARD.AUTHENTICATION` for existing accounts, and shows
toast.
>   - `SetPhoneNumber`: Adjusts area code selector width.
> - **Session/Auth handling in Home**:
> - `CardHome`: Detects auth errors via `isAuthenticationError`, clears
keychain (`removeCardBaanxToken`), resets Redux auth
state/location/token fields, and navigates to `Routes.CARD.WELCOME`;
disables retry on auth errors.
> - **Token management**:
> - Support access-only onboarding tokens: make `refreshToken*` optional
in `CardTokenData`, update `cardTokenVault` validation/storage.
> - Store access token post address registration in
`PhysicalAddress`/`MailingAddress` using `mapCountryToLocation` +
`extractTokenExpiration`; set Redux auth state and location.
> - `handleLocalAuthentication`: Handle access-only tokens with 5‑min
buffer, improved cleanup/logging.
> - **SDK/Auth**:
>   - `CardSDK.getCardDetails`: Throw `INVALID_CREDENTIALS` on 401.
> - `useCardProviderAuthentication`: Treat OTP/PENDING/phase as
early-return states.
> - **Utilities**:
> - New `isAuthenticationError`, `mapCountryToLocation`,
`extractTokenExpiration` (with tests).
> - **Redux**:
> - Add/consume actions: `setOnboardingId`, `setContactVerificationId`,
`setIsAuthenticatedCard`, `setAuthenticatedPriorityToken*`,
`setUserCardLocation`.
> - **Tests**:
> - Major additions/overhauls for `ConfirmEmail`, `MailingAddress`,
`handleLocalAuthentication`, and `extractTokenExpiration`.
> - **i18n**:
> - Update onboarding strings (confirm email messaging, KYC
text/buttons).
> 
> <sup>Written by [Cursor
Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit
3c81f92. This will update automatically
on new commits. Configure
[here](https://cursor.com/dashboard?tab=bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: sophieqgu <[email protected]>
@runway-github runway-github bot requested a review from a team as a code owner October 29, 2025 00:04
@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamaskbot metamaskbot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label Oct 29, 2025
@sonarqubecloud
Copy link

Quality Gate Failed Quality Gate failed

Failed conditions
77.9% Coverage on New Code (required ≥ 80%)
14.0% Duplication on New Code (required ≤ 10%)

See analysis details on SonarQube Cloud

Copy link
Contributor

@Cal-L Cal-L left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Cal-L Cal-L merged commit f21cd1f into release/7.58.0 Oct 29, 2025
81 of 87 checks passed
@Cal-L Cal-L deleted the runway-cherry-pick-7.58.0-1761696252 branch October 29, 2025 04:08
@github-actions github-actions bot locked and limited conversation to collaborators Oct 29, 2025
@metamaskbot metamaskbot added the release-7.58.0 Issue or pull request that will be included in release 7.58.0 label Oct 29, 2025
@metamaskbot
Copy link
Collaborator

No release label on PR. Adding release label release-7.58.0 on PR, as PR was cherry-picked in branch 7.58.0.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-7.58.0 Issue or pull request that will be included in release 7.58.0 size-XL team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants