Skip to content

chore: back-merge main into dev before Sprint 159 release - #3073

Merged
jjramirezn merged 15 commits into
devfrom
codex/backmerge-main-20260909
Sep 9, 2026
Merged

jjramirezn merged 15 commits into
devfrom
codex/backmerge-main-20260909

Conversation

@jjramirezn

Copy link
Copy Markdown
Contributor

Bring the production desktop download QR behavior into staging before the Sprint 159 release. Resolve main-to-dev conflicts while preserving the newer staging bank-flow modules and residence-aware Mexico routing.

Tracking: https://app.notion.com/p/3d68381175798149887ff4085840c232

The saved-account tests retain CLABE inference and unknown-account country protection. Keep staging's real App Store/review URLs. Restore the Mexico enrollment regression against the new verify step. The src/content pointer matches production c49e663, avoiding a release rollback to staging's August 27 mirror; no content files are edited.

Validation: targeted bank-flow tests pass (79 tests); full local suite passes (560 suites, 6,916 tests; 5 skipped), typecheck and Prettier pass. Local production build passes (1,106 static pages; local Sentry upload reported 401 warnings but build exited zero). CI must pass before merge. Visual reference: production hotfix #3024 contains desktop flag-on, QR modal, and flag-off screenshots. This back-merge carries that same behavior; no fresh local screenshot is claimed. TASK-20600 and TASK-22333 are retained by this sync.

kushagrasarathe and others added 14 commits September 7, 2026 20:21
During the pwa-sunset window the desktop hero showed only two store web
links — the one desktop download surface without the QR path every other
surface (home, setup, guest CTAs) follows, and a store web page is a dead
end for someone sitting at a laptop. Add the Download now primary that
opens ScanToDownloadModal, keep the store pair. Flag-off renders are
untouched: every changed line lives inside the migrationOn && isDesktop
branch.
…the modal

Kush's review: three CTAs on the hero is noise; the modal already carries
the store links under the QR.
prod still carried the placeholder apps.apple.com/app/peanut in STORE_URL
and REVIEW_URL — flag-on would send every iOS user to a wrong listing.
ports the real id6786373552 URLs already on dev (no back-merge debt).
fix: real iOS App Store URLs before pwa-sunset flag-on (hotfix)
…esktop-qr

fix(landing): TASK-20600 desktop hero Download now opens the scan-to-download QR
…0908-054749

content: publish latest to production (src/content → peanut-content@c49e663)
…333)

Mexico is tagged region 'latam' for the region picker, but its bank rail
(SPEI) is a Bridge rail. Every bank-flow unlock CTA derived the KYC intent
from that picker region and sent LATAM + targetCountry=MX; the BE rejects
MX for the Manteca path and the UI collapsed the typed rejection into the
'contact support' dead-end. 8 approved Mexico users have no SPEI rail.

Add getBankRegionIntent (MX -> NA, else the region intent) and route all
six bank-flow call sites through it — add-money bank, withdraw bank, the
countries list and the bank claim — so the fix lives in one place instead
of the one page the report named (regression of hotfix #2163 coverage).
The region picker keeps getRegionIntent: it works off the clicked region,
not a country.
Reuse the existing 'Bridge serves this country' predicate instead of a
fifth hard-coded MX literal — the rule is 'latam picker country whose bank
rail is Bridge', and the predicate is already the withdraw page's routing
guard.
…ver the saved-account claim path

Review fixes (/code-review medium on #3036):
- getBankRegionIntent now reads RAIL_COUNTRY_TO_REGION_PATH — the table the
  pending-rail badges already use — instead of a Bridge-membership predicate
  that would flip AR/BR/CO to NA the day BRA/COL land in the Bridge alpha3
  map. One source of truth for 'which region tile does this rail belong to'.
- BankFlowManager: only the country list set selectedCountry, so a saved
  account (CLABE) reached the unlock CTA with a rest-of-world intent. Set it
  from the account — the account is the destination.
- withdraw page: one country lookup for intent and target country.
- page test asserts intent + crossRegion only; the country arg is dropped
  by useSumsubKycFlow for non-Manteca countries, so it must not be pinned.
… picked country

Third-reviewer finding on #3036: setSelectedCountry(getCountryFromAccount(account) ?? null)
overwrote a country the user already chose when the saved account's metadata
has no resolvable country (empty countryCode/countryName — a known prod state),
turning an EU uplift into a rest-of-world dead end. Guard the write, and add
the first BankFlowManager test: saved MX CLABE → selectedCountry = Mexico;
unresolvable account → no write; unlock CTA → NA intent.
…tent-na

fix(kyc): route Mexico bank enrollment through the NA intent (TASK-22333)
@vercel

vercel Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
peanut-wallet Ready Ready Preview Sep 9, 2026 1:29pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 78b8dd2c-9759-47b3-8591-33abc72174be

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jjramirezn
jjramirezn marked this pull request as ready for review September 9, 2026 13:21
@github-actions

github-actions Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Code-analysis diff

Painscore total: 8913.88 → 8914.96 (+1.08)
Findings: 0 net (+13 new, -13 resolved)

🆕 New findings (13)

  • critical complexity — src/components/LandingPage/LandingPageClient.tsx — CC 55, MI 57.46, SLOC 219
  • high hotspot — src/app/(mobile-ui)/add-money/[country]/bank/page.tsx — 79 commits, +725/-1088 lines since 6 months ago
  • high hotspot — src/app/(mobile-ui)/withdraw/[country]/bank/page.tsx — 74 commits, +670/-870 lines since 6 months ago
  • high hotspot — src/components/AddWithdraw/AddWithdrawCountriesList.tsx — 60 commits, +803/-533 lines since 6 months ago
  • high hotspot — src/components/Claim/Link/views/BankFlowManager.view.tsx — 43 commits, +503/-246 lines since 6 months ago
  • medium high-mdd — src/components/LandingPage/LandingPageClient.tsx:55 — LandingPageClient: MDD 65.9 (uses across many lines from declarations)
  • medium high-dlt — src/components/LandingPage/LandingPageClient.tsx:55 — LandingPageClient: DLT 31 (calls 31 distinct functions — high context load)
  • medium method-complexity — src/components/LandingPage/LandingPageClient.tsx:158 — CC 17 SLOC 39
  • medium react-direct-dom — src/components/LandingPage/LandingPageClient.tsx:160 — direct DOM: document.getElementById
  • low high-mdd — src/components/LandingPage/LandingPageClient.tsx:157 — : MDD 18.6 (uses across many lines from declarations)
  • low high-dlt — src/components/LandingPage/LandingPageClient.tsx:157 — : DLT 15 (calls 15 distinct functions — high context load)
  • low high-mdd — src/components/LandingPage/LandingPageClient.tsx:243 — : MDD 13.0 (uses across many lines from declarations)
  • low missing-return-type — src/components/LandingPage/LandingPageClient.tsx:55 — LandingPageClient: exported fn missing return type annotation

✅ Resolved (13)

  • src/components/LandingPage/LandingPageClient.tsx — CC 51, MI 56.24, SLOC 205
  • src/app/(mobile-ui)/add-money/[country]/bank/page.tsx — 78 commits, +723/-1086 lines since 6 months ago
  • src/app/(mobile-ui)/withdraw/[country]/bank/page.tsx — 72 commits, +667/-867 lines since 6 months ago
  • src/components/AddWithdraw/AddWithdrawCountriesList.tsx — 59 commits, +800/-530 lines since 6 months ago
  • src/components/Claim/Link/views/BankFlowManager.view.tsx — 40 commits, +488/-240 lines since 6 months ago
  • src/components/LandingPage/LandingPageClient.tsx:52 — LandingPageClient: MDD 62.3 (uses across many lines from declarations)
  • src/components/LandingPage/LandingPageClient.tsx:52 — LandingPageClient: DLT 30 (calls 30 distinct functions — high context load)
  • src/components/LandingPage/LandingPageClient.tsx:153 — CC 17 SLOC 39
  • src/components/LandingPage/LandingPageClient.tsx:155 — direct DOM: document.getElementById
  • src/components/LandingPage/LandingPageClient.tsx:152 — : MDD 18.6 (uses across many lines from declarations)
  • src/components/LandingPage/LandingPageClient.tsx:152 — : DLT 15 (calls 15 distinct functions — high context load)
  • src/components/LandingPage/LandingPageClient.tsx:238 — : MDD 13.0 (uses across many lines from declarations)
  • src/components/LandingPage/LandingPageClient.tsx:52 — LandingPageClient: exported fn missing return type annotation

@github-actions

github-actions Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

🧪 UI test report — ✅ all green

Suites

  • ✅ unit: 6926 ran, 0 failed, 0 skipped, 2.4m

📊 Coverage (unit)

metric %
statements 76.7%
branches 63.0%
functions 70.8%
lines 77.7%
⏱ 10 slowest test cases
time test
🐢 9.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Network failure keeps loading while retries remain, then shows the generic error
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_RECENT_REFUND fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › routes the KYC rejection on its wire code, and does not retry it
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_VOLUME_NEAR_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › User KYC not approved fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_SOURCE_OVER_MONTHLY_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › a refused idempotency key tells the user to scan again, not to contact support
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_USER_NOT_PROVISIONED fails fast with copy that names the real cause
3.2s src/components/Card/share-asset/__tests__/shareAssetLayout.test.ts › never places two stickers in heavy overlap (broad seed sweep)
3.1s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Going offline blames the connection, and reconnecting clears it for the recovered scan
📍 Inline annotations are in the **Unit test report** check above. Coverage artifact: `coverage-unit`. Generated by `.github/workflows/tests.yml`.

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

Clean exact-head review. The back-merge preserves the production desktop QR download behavior and staging's Mexico enrollment flow; no actionable correctness, security, adversarial, or maintainability defect was found.

Checked clean

  • Verified the detached worktree at the supplied head, trusted author and dev base metadata, merge base, effective three-file diff, and both-parent conflict resolution.
  • Checked the desktop migration CTA against the production hotfix and the existing Button, Hero, ScanToDownloadModal, DownloadQR, device-detection, close-state, and LANDING_HERO attribution contracts.
  • Checked the Mexico needs-enrollment regression against the preserved verify-step flow and NA intent assertion; the detached worktree has no installed Jest binary, so the focused local rerun was unavailable.
  • Confirmed src/content is a gitlink-only update from f5990317950a71a7cdea8f15d0a8fda20d13213f to the production parent's c49e663855da992ab54b1fa488fecb00abaf3cd4, with no content-file edits in this PR.
  • Checked exact-head automation: Deploy-Preview, Vercel, analyze, and bot-approval passed; no test-suite check was reported for this head.
  • Ran security and slop passes over the effective diff; it adds no authorization, credential, sensitive-data, money, workflow-secret, or process-execution surface.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: 853396235c7c · Context: repo · Took 9m

@jjramirezn
jjramirezn merged commit 07e08d1 into dev Sep 9, 2026
23 checks passed

This branch was successfully deployed

1 active deployment
Preview — 85339623 Deployed Sep 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants