Skip to content

fix(auth): prevent setup module cycle on home - #3155

Merged
innolope-dev merged 2 commits into
devfrom
innolope/fix-home-setup-tdz
Sep 14, 2026
Merged

innolope-dev merged 2 commits into
devfrom
innolope/fix-home-setup-tdz

Conversation

@innolope-dev

@innolope-dev innolope-dev commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Production setup recovery could fail while loading /home with ReferenceError: Cannot access 'v' before initialization (Sentry PEANUT-UI-T4Q, with related web reports in PEANUT-UI-T53). The failure could leave a logged-out user stuck in the home/setup recovery path.

Root cause and history

The URL-stepper refactor introduced this runtime dependency cycle in commit fcd12df / PR #2949, and PR #3062 carried it into dev:

Setup.consts -> Setup/Views -> useSetupFlow -> Setup.consts

The separate PR #3078 revert branch was closed without merging and is not an ancestor of dev. The cycle therefore remained present continuously; this is an introduced regression, not a previously fixed bug that later returned.

Fix

  • Keep setupSteps as the single owner of setup screen order and derive setupScreenIds from it.
  • Inject that registry-derived order through SetupFlowProvider; useSetupFlow now depends only on the flow context and setup types, never the component-backed registry.
  • Add an ESLint boundary that forbids useSetupFlow from importing Setup.consts or setup views, because the repository's generic cycle rule is intentionally disabled under the current resolver.
  • Add a production-mode Playwright regression for the reported /home -> /setup path. It captures uncaught page errors and console errors and rejects module-initialization failures.
  • Preserve the existing pre-filter placeholder behavior, native/web history contracts, runtime step filtering, and no-back guards.

The resulting dependency direction is acyclic and enforced:

registry -> views -> hook -> context
     |                         ^
     +-- derived screen IDs ---+

Validation

  • Focused Jest: 15/15 setup-flow tests passed.
  • Production Playwright: /home -> /setup initialization regression passed; stale-session setup regression passed.
  • TypeScript typecheck passed.
  • Focused ESLint passed, including the new import boundary.
  • Prettier check passed.
  • Optimized Next.js production build passed and generated all 1,108 static pages.
  • Vercel preview deployed successfully.
  • Required exact-head CI passed: ci-success, unit, typecheck, ESLint, format, native export, screen tests, and report.
  • Current-head Chip review found no blocking findings, and the PR has no review threads.

Advisory CI exception

ds-shots remains red after one rerun because its Next.js build exits inside webpack after compilation, before any screenshot or regression assertion runs. The exact dev base SHA (589d5f8) fails in the same job at the same webpack build point. This job is deliberately excluded from ci-success; the independent CI native-export build, the local optimized production build, and the Vercel preview all succeeded. No visual-diff result was produced.

No backend, database, migration, localization, or user-visible UI change.

Sentry:

@innolope-dev innolope-dev self-assigned this Sep 14, 2026
@vercel

vercel Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
peanut-wallet Ready Ready Preview Sep 14, 2026 10:32am UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 44426e3e-8be3-4865-95ce-11bff598dabe

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Code-analysis diff

Painscore total: 8348.63 → 8348.93 (+0.3)
Findings: 0 net (+8 new, -8 resolved)

🆕 New findings (8)

  • high complexity — src/components/Setup/Setup.consts.tsx — CC 2, MI 47.33, SLOC 73
  • medium high-mdd — src/features/setup/SetupFlowContext.tsx:46 — SetupFlowProvider: MDD 31.8 (uses across many lines from declarations)
  • medium high-mdd — src/hooks/useSetupFlow.ts:42 — useSetupFlow: MDD 29.2 (uses across many lines from declarations)
  • medium complexity — src/hooks/useSetupFlow.ts — CC 21, MI 56.89, SLOC 97
  • medium complexity — src/features/setup/SetupFlowContext.tsx — CC 7, MI 61.15, SLOC 60
  • low missing-return-type — src/features/setup/SetupFlowContext.tsx:46 — SetupFlowProvider: exported fn missing return type annotation
  • low unused-export — src/hooks/useSetupFlow.ts:12 — unused export: SETUP_SCREEN_PARAM
  • low missing-return-type — src/hooks/useSetupFlow.ts:42 — useSetupFlow: exported fn missing return type annotation

✅ Resolved (8)

  • src/components/Setup/Setup.consts.tsx — CC 1, MI 40.5, SLOC 69
  • src/features/setup/SetupFlowContext.tsx:44 — SetupFlowProvider: MDD 30.0 (uses across many lines from declarations)
  • src/hooks/useSetupFlow.ts:43 — useSetupFlow: MDD 29.2 (uses across many lines from declarations)
  • src/hooks/useSetupFlow.ts — CC 22, MI 58.15, SLOC 99
  • src/features/setup/SetupFlowContext.tsx — CC 7, MI 61.47, SLOC 59
  • src/features/setup/SetupFlowContext.tsx:44 — SetupFlowProvider: exported fn missing return type annotation
  • src/hooks/useSetupFlow.ts:13 — unused export: SETUP_SCREEN_PARAM
  • src/hooks/useSetupFlow.ts:43 — useSetupFlow: exported fn missing return type annotation

@innolope-dev
innolope-dev marked this pull request as ready for review September 14, 2026 08:56
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

🧪 UI test report — ✅ all green

Suites

  • ✅ unit: 7434 ran, 0 failed, 0 skipped, 2.8m

📊 Coverage (unit)

metric %
statements 77.8%
branches 64.5%
functions 71.9%
lines 78.9%
⏱ 10 slowest test cases
time test
🐢 9.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Network failure keeps loading while retries remain, then shows the generic error
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_VOLUME_NEAR_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_SOURCE_OVER_MONTHLY_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › a refused idempotency key tells the user to scan again, not to contact support
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_RECENT_REFUND fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_USER_NOT_PROVISIONED fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › User KYC not approved fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › routes the KYC rejection on its wire code, and does not retry it
3.2s src/components/Card/share-asset/__tests__/shareAssetLayout.test.ts › never places two stickers in heavy overlap (broad seed sweep)
3.1s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Scan that recovers on the retry lands on the payment screen, not an error
📍 Inline annotations are in the **Unit test report** check above. Coverage artifact: `coverage-unit`. Generated by `.github/workflows/tests.yml`.

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

No findings. The dependency-free screen ID list breaks the setup runtime cycle while preserving the fallback order, with parity guarded by a focused test.

Checked clean

  • Confirmed the exact head and merge base, then traced the changed runtime import graph through Setup.consts, the setup Views barrel, and useSetupFlow.
  • Verified SETUP_SCREEN_IDS matches setupSteps in membership and order and remains dependency-free at runtime through its type-only import.
  • Checked fallback cursor, filtered-step, and no-back guard behavior around the changed initialization path; behavior is unchanged after steps populate.
  • Reviewed exact-head CI: ci-success, unit, typecheck, eslint, format, native-export, and screen-tests passed.
  • Confirmed the advisory ds-shots build failure also occurs at the supplied base SHA and is not introduced by this pull request.
  • A local focused Jest rerun was unavailable because the detached worktree has no installed dependencies; the corresponding exact-head unit check passed in CI.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion: did not run — claude-api_error. This review is one reviewer short.

Exact head: 047b6e76a6c7 · Context: repo · Took 7m

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

No findings. The registry-derived screen order is injected through the provider, leaving the setup hook dependent only on context and types while preserving the pre-filter fallback behavior.

Checked clean

  • Verified the detached HEAD, trusted author, dev base ref, supplied base SHA, and merge base exactly match the review request.
  • Traced the setup registry, views, hook, and context imports and checked every SetupFlowProvider call site; the runtime dependency cycle is removed and the registry remains the single owner of screen order.
  • Checked initial URL parsing, runtime step filtering, transition direction, no-back guards, and default-screen fallback against the setup-flow implementation and regression tests.
  • Exact-head unit, typecheck, ESLint, format, screen-tests, and native-export checks succeeded. The advisory ds-shots build hit the same webpack WasmHash failure present on the supplied base SHA; Deploy Preview was still in progress when checked.
  • Local focused Jest and ESLint commands were unavailable because their binaries are not installed in the detached worktree; the corresponding exact-head CI checks succeeded.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion: did not run — claude-api_error. This review is one reviewer short.

Exact head: f497fda77534 · Context: repo · Took 7m

@innolope-dev
innolope-dev merged commit b2fe53b into dev Sep 14, 2026
45 of 48 checks passed

This branch was successfully deployed

1 active deployment
Preview — f497fda7 Deployed Sep 14, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant