Skip to content

feat: TASK-22452 rework receipts and processing screens - #3225

Merged
kushagrasarathe merged 21 commits into
devfrom
codex/TASK-22452-ds-wave2-receipts
Sep 17, 2026
Merged

kushagrasarathe merged 21 commits into
devfrom
codex/TASK-22452-ds-wave2-receipts

Conversation

@kushagrasarathe

@kushagrasarathe kushagrasarathe commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Receipt screens now use one primary action and a More actions drawer. The selected centered layout keeps Split this bill primary where eligible, with Share, PDF, Invite friends, and support in the drawer. Public receipts make Download primary.

  • Move the dark Peanut wordmark and issuer details to the top of public receipts and PDFs. Remove the duplicate company footer. Use DataRow copy fields with raw copy values, Reference and Issued on, and DS spacing that reserves the support link's full touch target.
  • Replace full-screen CyclingLoading on five payment/deposit rails with the selected ProcessingScreen and customer-facing confirmation copy. Respect reduced motion. Keep all-kind authenticated PDFs from Add official receipts for every transaction #3159 and add representative card, P2P, and claim coverage.
  • Complete the DS fixes: 24px trailing icon stacks in three action lists; controlled network Tabs; semantic attention/setup-hero tokens; one bank leading element; and legal re-consent priority over the download prompt.

Absorbs the current logo/DataRow work from #3171. Its PDF-link change was superseded by #3159.

Task

TASK-22452

Risks and design notes

  • Receipt action placement changes across completed, pending, failed, refunded, private, and public states. Pending payment/cancel behavior is preserved. Public PDF capability boundaries remain unchanged.
  • Share/PDF hooks serve both existing buttons and drawer rows. Cached native sharing keeps the user gesture; stale requests cannot populate another receipt's cache. Public-capability downloads retain their existing URL/native external-browser path.
  • The legal gate tracks the account that produced each result. Regression tests observe committed modal visibility during cold login and account changes.
  • Referral eligibility remains private, activated, completed outbound receipts. Impressions now mean the drawer row was visible; analytics use drawer_row rather than the retired placements.
  • No new architectural smell found. Shared hooks and the issuance helper prevent duplicated behavior. No backend deploy order or API contract change.

Flagged, not changed

  • Yellow size-s IconBubble rows and the receipt overflow composition are user-approved choices without a dedicated board definition. Vlad's board needs the action-color convention.
  • Network Tabs follow the user's ruling. All preserves the existing popular-network set; it does not expand to every supported network. Mono's SegmentedControl guidance needs a separate update.
  • Add board entries for foreground-attention and background-setup-hero. Existing AppShell blue surfaces remain a separate audit.
  • The bank avatar now uses one flag or bank fallback. A composite bank/flag vocabulary still needs a design ruling.
  • The existing PDF wordmark remains a vector twin; the DS has no shared Logo component spanning web and PDF.
  • Loading's global reduced-motion support remains separate DS work. This PR scopes the motion fix to ProcessingScreen.

Validation

  • Prettier, typecheck, DS lint: pass.
  • Full unit suite with TZ=UTC: 622 suites, 7,646 passed, 7 skipped. UTC avoids the two acknowledged local timezone failures.
  • Changed-file ESLint: zero errors, one existing UserCard dependency warning; not worsened.
  • Production build: pass.
  • Browser fixtures: 8 receipt states at 375px; 18 receipt combinations across English 375px and Spanish/Portuguese 320px; standalone and nested action drawers; raw reference copying; download/support hit targeting; referral eligibility; processing rails and reduced motion; network Tabs; action lists, warning states, setup hero, and bank leading.
  • PDF: actual mapper, PDF model, and renderer with synthetic QR data; one page, top issuer once, correct reference/date rows.
  • These are production-component, read-only fixture checks. They are surface verification, not backend payment end-to-end tests.
  • Required CI, DS screenshots, all locale captures, and Vercel: pass. The optional screen-library publish failed during external Cloudflare token verification; this PR does not change that workflow or its storage scripts.
  • Exact-head Chip review: no findings on d47208a83db0; Kimi security and Claude product/contract passes also found none.
  • Native: ⚠️ needs a device pass for Capacitor, iOS Safari, safe areas, keyboard, and file/share UX.

Docs and legal

No customer-facing product/help/legal fact changes. The audit read the applicable privacy, terms, and card agreements.

Separate mono DS follow-up: design/components.md network Tabs guidance and controlled API; design/design.md and design/components.md CyclingLoading rows. No content edits are bundled here.

Visual evidence

These 375px mobile captures render production components with synthetic, read-only fixtures. They verify the UI surface, not backend payment or rail behavior. The generated PDF uses the same synthetic receipt model. The pr-assets-3225 branch will be deleted after merge.

Receipt states, actions, issuer, and PDF
Public receipt and issuer Completed QR Settled card
Inbound P2P Pending link Pending request
Failed Refunded Unavailable
More actions Nested transaction + actions Rendered PDF

Download the generated synthetic receipt PDF

Processing screens across all five rails
Payment Deposit Deposit preparing
Crypto deposit Rhino deposit Manteca PIX
Action lists, network Tabs, warning tokens, setup hero, and bank leading
Send link actions Request pot actions Payment method actions
Network Tabs User card warning Passkey warning
Setup hero Bank flag Bank fallback

the bank row jumped its IconStack to 80px, which breaks the ListItem
trailing vocabulary and the 16/20/24 icon scale. the invited-by note also
forced a 24px top margin with !important over the list's own 8px gap;
the container spacing owns it now. TASK-22452
two warning texts painted themselves from the raw ramp: yellow-900 on the
recipient card and orange-400 on the passkey preflight, and orange-400
(#f69855) is not readable as type. one semantic token now carries the
attention tone for text, at the readable value the recipient card already
used. names follow the badge/surface attention family, not a second
'warning' word. no board defines a foreground tone past error — flagged
for vlad. TASK-22452
the onboarding hero and its bottom-inset fill painted the blue-300
primitive straight from the ramp, so the surface had no name and every new
setup screen had to re-find the right index. same resolved color, now a
semantic token. the native status-bar call still takes a hex literal.
no board defines it — flagged for vlad. TASK-22452
the bank branches drew a flag image with a mini bank bubble overlaid on
it — a hand-composed leading, which the leading vocabulary does not have.
the flag/logo now rides the DS avatar with the bank icon as its fallback,
the same shape the transaction rows already use. the bank cue only shows
when no flag or logo loads; flagged as a lost cue. TASK-22452
the light logo is white glyphs on the white receipt page — invisible.
absorbs the still-valid logo half of #3171 onto current dev (TASK-22452).
five hand-rolled flex+CopyToClipboard rows collapse into DataRow
allowCopy/copyValue: To, TxID (non-explorer), bank account (full unmasked
identifier on copy), transfer id, and the public reference (raw
case-sensitive id on copy, middle-ellipsis display). the shared copy
glyph gains shrink-0 print:hidden so long values cannot squash it and
print output stays clean. absorbs the DataRow half of #3171 (TASK-22452).
…only

hugo: 'we can't have 4 CTAs in a single page!' — the receipt now carries
one state-aware primary (Split when splittable, Share otherwise, Download
on the public page) and demotes share/download/support into a nested
More-actions drawer (ListItem rows, yellow size-s bubbles — the user's
explicit pick for receipt actions, flagged for the board).

the issuer facts appear once, at the top, on the web receipt AND the pdf:
dark wordmark left, issued-by + address + site right; the bottom company
footer is gone and the pdf wordmark drops its mascot glyph to match the
text-only dark asset. the details card gains Reference (raw id copyable,
middle-ellipsis display) and Issued-on rows from real source fields, and
the pdf's leading date row is relabelled Issued on — same status-branched
source timestamp, never the download time.

share/download logic is reused, not duplicated: ShareButton's behavior
moved to a useShareAction hook (button unchanged), PrivateReceiptPdfActions
became the useReceiptPdfFile hook (auth, native http, prefetch and retry
semantics identical). the #3159 public/private boundary is untouched
(TASK-22452).
the user ruled KEEP for the referral nudge, moved into the overflow. the
dead ReceiptReferralNudge component (no consumer since the linkbutton
sweep) becomes useReceiptReferralAction: the pre-#3159 eligibility gate
unchanged (own completed outbound payment, activated account with a
username, never public/pending/failed/refunded/inbound), the invite link
from generateInviteCodeLink as before. the impression fires only while
the drawer is open with the row visible, once per transaction; outcome
events keep firing from share success only. analytics note: the
button/text_link variants collapse into one 'drawer_row' variant — the
row now has exactly one placement (TASK-22452).
the authenticated all-kinds pdf landed in #3159; the model suite only
exercised bank rails. pin a card spend (fx row, no transfer id), a p2p
transfer (counterparty + memo) and a send-link claim (From + claim date)
so the wider coverage has representative fixtures. no access-boundary
changes — hasReceiptPage still classifies the public capability urls
(TASK-22452 item 4).
…lingLoading

CyclingLoading is inline-only by the rulebook, but five rails used it as
a full-screen state. they now share Global/ProcessingScreen — the one
mascot loader over a TitleBlock (the user's processing-C pick), centered
by each rail's own shell. copy is truthful and localized (en/es/pt): the
qr rail says we're confirming your payment, settling deposits say we're
confirming your deposit, and the two qr-generation waits carry the title
only — no confirming claim before money moved, no invented timings.

the rollout orphaned CyclingLoading itself (these five were its only
importers) — deleted; its word pool and css keyframes stay with the dev
loading-words page (TASK-22452).
the user explicitly ruled Tabs for the network row (over the docs' old
value-toggle guidance — flagged for the board). the tile grid becomes
controlled DS Tabs: an explicit All tab replaces clear-by-reselect (''
keeps its popular-set meaning), each popular chain gets a tab with its
icon, a chain picked from the More-networks list gets its own tab so the
selection stays visible, and More networks is a separate header action.
tab selection keeps the picked token exactly like the old tiles; the
list path still clears it; search still spans every allowed chain.

Tabs gains an optional controlled mode (value/onValueChange) and a
ReactNode label — string labels and the marketing MDX adapter are
untouched. NetworkButton and the clear-selection X are orphaned and
removed. first behavioral tests for both Tabs and TokenSelector
(TASK-22452 item 8).
the ToS re-consent modal and the migration download prompt could stack —
they mount in different trees (layout vs HomeModals) with no shared
priority. ModalsContext now carries a legal-consent gate that ReConsentModal
owns: 'checking' from before the status request until every terminal path
(nothing to show, snoozed, accepted, postponed, failed check, logged out,
unmount), 'prompting' while the modal shows. the download prompt defers
while the gate is not clear FOR ITS OWN account — the gate carries the
userId it resolved for, so one account's clear can never release another
mid-switch — and a legal prompt actually shown defers the download prompt
to the next visit, per account. a failed check or a consent-surface
unmount fails open: legal can gate, never brick. covered by a
both-mounted suite driving the real provider (in-flight window, dismissal,
error, unmount, A→B switch, per-account latch).
…antees

review follow-ups on the hook extraction. a prefetched file reaches
navigator.share synchronously from the click again — the unconditional
async boundary had broken the user-activation guarantee native share
sheets need. a receipt/locale switch now drops the cached file and
discards an in-flight fetch, so the drawer can never deliver the previous
transaction's document. repeated taps while an action is pending are a
no-op (ref-guarded, and both drawer file rows disable on busy — the old
buttons did). public-capability kinds keep their pre-existing url
download inside the drawer (anchor on web, system browser on native, no
bearer, no wait) via a helper shared with the visible download button;
only private kinds use the authenticated file hook. the public action
group also gains the support link with its own reserved hit area.
…nk target

receiptIssuedAt is now the pdf's status-branched rule (cancellation date
for cancelled/closed, refund date for refunded, settlement/claim for
completed, creation for pending) and the pdf model consumes the same
helper — page and pdf can never disagree, and no receipt ever invents a
time. its stale public-header comment is gone. the receipt's main
sections move to the approved xl/24 rhythm, and the support link sits in
a 44px flex-centered wrapper so its extended hit area (::after reaches
14px past the text row) can never overlap the button grouped above —
root reproduced that exact bottom-edge misfire on the public receipt.
the impression dedup becomes a set keyed per viewer+transaction — the
single last-id ref re-fired on an A→B→A bounce and its claim ignored who
was looking. the doc comment stops saying a cancelled share captures
nothing: the shared hook deliberately counts a completed clipboard copy
as success even when the sheet is then dismissed.
…reduced motion

root's rail qa: crypto and rhino kept their send-instructions / network
toggle above the processing state, inviting a second deposit while the
first confirmed. both rails now early-return a NavHeader + ProcessingScreen
shell once the deposit is settling (address preparation keeps the bare
mascot); navigation and polling are untouched, and the centered block
inherits shell height instead of a fixed h-screen box. ProcessingScreen
also halts the loader's descendant spin under prefers-reduced-motion,
scoped to this composition — the shared Loading has no rule of its own
and changing it is separate ds debt.
typescript narrows status after the new early return, so the old
'not loading' comparisons stopped compiling (crypto) or went dead
(rhino) — my own orphans, removed.
the tabs migration had grown a ~200-line iife inside the drawer's
ternary just to declare the token block and tab list — lifted to plain
consts above the return so the new diff reads top-down. the More-networks
link also gains a 44px flex-centered wrapper: its extended hit area
reaches 14px past the text row, straight into the tab row below without
the reservation. no behavior change; the tabs suite pins it.
root measured the wcag ratio at 5.93:1 on white and 5.44:1 on the page
tint — the 6.4:1 claim was wrong (still readable, just misstated). the
new comments from the mechanical pass drop their sentence-case starts.
…rn it

root's committed-state probe caught two intermediate frames the dom-final
assertions missed: on A→B the download modal committed visible under B
twice before B's consent check published. two owners were wrong. the
consent modal's publish effect labelled the PREVIOUS account's resolved
state with the new account's id for one render — resolution now carries
resolvedFor, and a state/account mismatch always publishes 'checking'.
the download prompt rendered its stored visible state under whichever
account happened to be current — the render now gates synchronously on
the current account and gate (visibleFor ownership + legal blocking +
per-account latch), and onVisibilityChange reports that same committed
visibility so HomeModals' sibling suppression cannot flash either.
one-visit deferral, fail-open on error/unmount, and the dev forceVariant
bypass are unchanged. the suite now records every committed visible
state with its account (useLayoutEffect recorder) and pins cold login,
A→B with A visible, and B's unresolved/failing/no-change results.
the full-suite gate caught send-states crashing at import: the module
read REFERRAL_SOURCES eagerly while that suite mocks the analytics
constants partially. the old component built the props lazily — restored
as a function, call sites unchanged in shape.
@vercel

vercel Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
peanut-wallet Ready Ready Preview Sep 17, 2026 9:16am UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: e70a3336-a772-42b8-bd33-5f532728fc8f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@notion-workspace

Copy link
Copy Markdown

ds smells

@github-actions

Copy link
Copy Markdown
Contributor

Code-analysis diff

Painscore total: 7997.19 → 8007.93 (+10.74)
Findings: +7 net (+107 new, -100 resolved)

🆕 New findings (107)

  • critical complexity — src/components/Global/TokenSelector/TokenSelector.tsx — CC 129, MI 59.85, SLOC 370
  • critical complexity — src/components/TransactionDetails/ReceiptActions.tsx — CC 96, MI 57.68, SLOC 208
  • critical complexity — src/components/Global/PeanutActionDetailsCard/index.tsx — CC 86, MI 54.45, SLOC 121
  • critical complexity — src/components/TransactionDetails/useReceiptViewModel.ts — CC 86, MI 59.64, SLOC 138
  • critical complexity — src/components/Claim/Link/SendLinkActionList.tsx — CC 68, MI 55.33, SLOC 214
  • critical method-complexity — src/components/TransactionDetails/ReceiptActions.tsx:47 — ReceiptActions CC 64 SLOC 125
  • critical complexity — src/components/AddMoney/components/MantecaAddMoney.tsx — CC 61, MI 57.09, SLOC 234
  • critical complexity — src/app/(mobile-ui)/dev/ds/foundations/tokens.generated.ts — CC 1, MI 11.76, SLOC 805
  • high hotspot — src/components/TransactionDetails/TransactionDetailsReceipt.tsx — 69 commits, +918/-2151 lines since 6 months ago
  • high complexity — src/components/TransactionDetails/TransactionDetailsReceipt.tsx — CC 49, MI 48.97, SLOC 109
  • high complexity — src/components/TransactionDetails/ReceiptDetailsCard.tsx — CC 47, MI 52.1, SLOC 85
  • high complexity — src/app/receipt/[entryId]/pdf/receipt-pdf-model.ts — CC 46, MI 49.59, SLOC 132
  • high complexity — src/features/payments/flows/contribute-pot/components/RequestPotActionList.tsx — CC 45, MI 58.23, SLOC 144
  • high method-complexity — src/components/TransactionDetails/ReceiptDetailsCard.tsx:48 — ReceiptDetailsCard CC 40 SLOC 64
  • high method-complexity — src/components/TransactionDetails/useReceiptViewModel.ts:150 — CC 40 SLOC 39
  • high complexity — src/components/Global/ReConsentModal/index.tsx — CC 39, MI 59.37, SLOC 172
  • high complexity — src/components/TransactionDetails/transaction-details.utils.ts — CC 39, MI 62.94, SLOC 71
  • high complexity — src/components/Migration/MigrationDownloadModal.tsx — CC 36, MI 53.93, SLOC 90
  • high complexity — src/components/TransactionDetails/useReceiptPdfFile.ts — CC 35, MI 56.26, SLOC 178
  • high method-complexity — src/components/Global/TokenSelector/TokenSelector.tsx:79 — CC 32 SLOC 127

…and 87 more.

✅ Resolved (100)

  • src/components/Global/TokenSelector/TokenSelector.tsx — CC 127, MI 60.42, SLOC 354
  • src/components/Global/PeanutActionDetailsCard/index.tsx — CC 89, MI 54.71, SLOC 118
  • src/components/TransactionDetails/useReceiptViewModel.ts — CC 86, MI 59.87, SLOC 135
  • src/components/Claim/Link/SendLinkActionList.tsx — CC 69, MI 55.3, SLOC 214
  • src/components/AddMoney/components/MantecaAddMoney.tsx — CC 61, MI 57.13, SLOC 233
  • src/app/receipt/[entryId]/pdf/receipt-pdf-model.ts — CC 60, MI 49.13, SLOC 132
  • src/components/TransactionDetails/ReceiptActions.tsx — CC 58, MI 58.73, SLOC 113
  • src/components/TransactionDetails/TransactionDetailsReceipt.tsx — CC 51, MI 48.07, SLOC 117
  • src/app/(mobile-ui)/dev/ds/foundations/tokens.generated.ts — CC 1, MI 11.88, SLOC 797
  • src/components/TransactionDetails/TransactionDetailsReceipt.tsx — 65 commits, +895/-2101 lines since 6 months ago
  • src/components/TransactionDetails/ReceiptDetailsCard.tsx — CC 46, MI 52.9, SLOC 79
  • src/features/payments/flows/contribute-pot/components/RequestPotActionList.tsx — CC 46, MI 58.18, SLOC 144
  • src/app/receipt/[entryId]/pdf/receipt-pdf-model.ts:98 — buildReceiptPdfModel CC 43 SLOC 82
  • src/components/TransactionDetails/useReceiptViewModel.ts:149 — CC 40 SLOC 36
  • src/components/TransactionDetails/ReceiptDetailsCard.tsx:44 — ReceiptDetailsCard CC 39 SLOC 58
  • src/components/TransactionDetails/ReceiptActions.tsx:39 — ReceiptActions CC 36 SLOC 52
  • src/components/TransactionDetails/PrivateReceiptPdfActions.tsx — CC 34, MI 52.65, SLOC 183
  • src/components/TransactionDetails/TransactionDetailsReceipt.tsx:38 — CC 34 SLOC 82
  • src/components/Global/TokenSelector/TokenSelector.tsx:75 — CC 32 SLOC 111
  • src/components/Global/ReConsentModal/index.tsx — CC 31, MI 60.09, SLOC 137

…and 80 more.

📈 Painscore deltas (top movers)

File Before After Δ
src/components/Global/ShareButton/useShareAction.ts 0.0 12.1 +12.1
src/components/TransactionDetails/useReceiptPdfFile.ts 0.0 7.9 +7.9
src/components/TransactionDetails/useReceiptReferralAction.ts 0.0 5.8 +5.8
src/components/TransactionDetails/receipt-pdf-link.utils.ts 0.0 4.4 +4.4
src/components/TransactionDetails/ReceiptMoreActionsDrawer.tsx 0.0 3.0 +3.0
src/components/Global/ProcessingScreen.tsx 0.0 2.2 +2.2
src/components/TransactionDetails/ReceiptActions.tsx 9.5 11.5 +2.0
src/components/Migration/MigrationDownloadModal.tsx 8.4 9.7 +1.3
src/components/Global/ReConsentModal/index.tsx 8.3 9.6 +1.3
src/components/TransactionDetails/transaction-details.utils.ts 5.9 6.9 +1.0
src/components/TransactionDetails/ReceiptDetailsCard.tsx 10.1 10.6 +0.5
src/app/receipt/[entryId]/pdf/receipt-pdf-model.ts 10.8 10.3 -0.6
src/components/TransactionDetails/ReceiptReferralNudge.tsx 4.2 0.0 -4.2
src/components/Global/Loading/CyclingLoading.tsx 4.8 0.0 -4.8
src/components/Global/TokenSelector/Components/NetworkButton.tsx 6.3 0.0 -6.3
src/components/Global/ShareButton/index.tsx 13.4 5.4 -8.0
src/components/TransactionDetails/PrivateReceiptPdfActions.tsx 8.5 0.0 -8.5

@github-actions

Copy link
Copy Markdown
Contributor

🧪 UI test report — ✅ all green

Suites

  • ✅ unit: 7653 ran, 0 failed, 0 skipped, 2.8m

📊 Coverage (unit)

metric %
statements 79.1%
branches 66.6%
functions 73.6%
lines 80.3%
⏱ 10 slowest test cases
time test
🐢 9.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Network failure keeps loading while retries remain, then shows the generic error
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_VOLUME_NEAR_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_RECENT_REFUND fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › User KYC not approved fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_SOURCE_OVER_MONTHLY_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › routes the KYC rejection on its wire code, and does not retry it
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_USER_NOT_PROVISIONED fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › a refused idempotency key tells the user to scan again, not to contact support
3.1s src/components/Card/share-asset/__tests__/shareAssetLayout.test.ts › never places two stickers in heavy overlap (broad seed sweep)
3.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Scan that recovers on the retry lands on the payment screen, not an error
📍 Inline annotations are in the **Unit test report** check above. Coverage artifact: `coverage-unit`. Generated by `.github/workflows/tests.yml`.

@kushagrasarathe

Copy link
Copy Markdown
Contributor Author

/chip review

@github-actions

Copy link
Copy Markdown
Contributor

🖼 Visual diff — 9 screens moved

16 of 96 shots changed · 80 identical · baseline 404f40e → head d47208a

worst % screen widths
70.37% early-user 320, 430
29.33% card-application 320, 430
26.92% card-holder 320, 430
12.59% avatar-picker 320, 430
5.14% card-prohibited 320, 430
3.60% identity-verification 430
2.17% card-pending 320, 430
0.85% withdraw-bank-form 320, 430
0.36% guest-invite 320

job summary · before/after/diff images — artifact

Fixture screenshots, no backend. Advisory — this check never blocks a merge. Posted from the default branch by ds-shots-comment.yml; the report it renders is untrusted data.

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

No findings in the exact-head review.

Checked clean

  • Exact head and merge base matched the supplied SHAs; trusted PR metadata matched the supplied author and dev base.
  • Receipt action hierarchy, public/private PDF routing, native/web sharing and downloading, referral eligibility, and receipt/PDF model changes.
  • Processing-state replacements across QR pay and fiat/crypto deposit rails, including reduced-motion behavior.
  • Controlled Tabs integration and TokenSelector network/token state transitions.
  • Legal re-consent priority over the migration download prompt, including cold login and account-switch ownership.
  • Core CI gates passed. Screen-library publication alone failed during external Cloudflare token verification; the PR does not change that workflow or its storage scripts.

Security review by moonshotai/kimi-k3: 0 finding(s), marked with the model name. It reads the diff only and answers only security, privacy and money, so treat its findings as advice.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: d47208a83db0 · Context: repo · Took 19m

@kushagrasarathe
kushagrasarathe marked this pull request as ready for review September 17, 2026 09:42
@kushagrasarathe
kushagrasarathe merged commit 48f3bce into dev Sep 17, 2026
35 of 37 checks passed
@chip-peanut-bot

Copy link
Copy Markdown
Contributor

This pull request was already closed when the review finished, so these findings are follow-up work rather than a gate.

Chip review — no blocking findings — this is not an approval

No findings in the exact-head review.

Checked clean

  • Exact head and merge base matched the supplied SHAs; trusted PR metadata matched the supplied author and dev base.
  • Receipt action hierarchy, public/private PDF routing, native/web sharing and downloading, referral eligibility, and receipt/PDF model changes.
  • Processing-state replacements across QR pay and fiat/crypto deposit rails, including reduced-motion behavior.
  • Controlled Tabs integration and TokenSelector network/token state transitions.
  • Legal re-consent priority over the migration download prompt, including cold login and account-switch ownership.
  • Core CI gates passed. Screen-library publication alone failed during external Cloudflare token verification; the PR does not change that workflow or its storage scripts.

Security review by moonshotai/kimi-k3: 0 finding(s), marked with the model name. It reads the diff only and answers only security, privacy and money, so treat its findings as advice.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: d47208a83db0 · Context: repo · Took 13m

This branch was successfully deployed

1 active deployment
Preview — d47208a8 Deployed Sep 17, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant