Repository navigation
TASK-23054: QR pay is open everywhere; checklist follow-ups (First payment, held card, Hide) - #3481
Conversation
Hugo: any verified user anywhere can pay QR codes; only Manteca top-up is limited to Argentina and Brazil. The checklist had its own residence rule (AR/BR only) and hid the QR option from everyone else. It now reads the same selector as the QR pay page (selectQrKycGate, extracted from useQrPayKycGate), so the two cannot disagree: QR is a path now, or once verified or fixed, unless a provider blocks it or the region is refused. The carousel's Pay with QR slide reads the same gate. canReachQrPay, hasQrPayRail and the AR/BR list are gone.
… with, Hide, stuck states Hugo: 'First payment' is the row title. A user who holds a card or applied for one is told to pay with it, not to get it again. Once only the payment row is left, the list can be hidden: people who only move money in and out would otherwise keep a 75% list forever. Hiding uses the one Home CTA dismissal store (carousel cards and the checklist now merge into it instead of overwriting). Fixtures cover the stuck states.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: peanutprotocol/peanut-ui/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code-analysis diffPainscore total: 8937.88 → 8946.85 (+8.97) 🆕 New findings (52)
…and 32 more. ✅ Resolved (44)
…and 24 more. 📈 Painscore deltas (top movers)
|
🧪 UI test report — ✅ all greenSuites
📊 Coverage (unit)
⏱ 10 slowest test cases
|
There was a problem hiding this comment.
Chip review — no blocking findings — this is not an approval
One checklist state-update defect: the held-card subtitle can remain stale after an application appears.
Findings
- MAJOR · src/components/Home/GettingStartedChecklist.tsx:152 · Recompute the payment subtitle when cardHeld changes
If a card-eligible user opens Home before applying, the card_qr row says to get the card. When the card application is submitted and the refreshed capability adds a card relationship, cardHeld becomes true but the route can remain card_qr. The rows useMemo does not include onboarding.cardHeld, so it retains the old subtitle and still asks this applicant to get the card. Add cardHeld to that memo’s dependencies (and cover the false→true rerender).
Checked clean
- Confirmed the exact head, trusted PR metadata, and two-commit diff from the merge base; no issue or review comments were fetched.
- Checked QR selector extraction against the existing pay-page gate and API QR-pool enrollment behavior; found no additional actionable divergence.
- Checked checklist route and hide rules, per-user dismissal merging, locale fallback, and the changed fixtures and tests.
- At review time unit, typecheck, lint, format, and security-scan checks passed; visual captures and press-contract were still running.
Security review by moonshotai/kimi-k3: 0 finding(s), marked with the model name. It reads the diff only and answers only security, privacy and money, so treat its findings as advice.
Third opinion: did not run — claude-api_error. This review is one reviewer short.
Exact head: f525ea9e9464 · Context: repo, other-repository, ci · Took 7m
…no Hide while the payment row loads Chip: the rows memo missed onboarding.cardHeld, so an application submitted mid-session kept 'Get the Peanut Card'. And a pending payment row is not a known last step, so the list cannot be hidden on it. The card-holder fixture now carries its card rail.
There was a problem hiding this comment.
Chip review — no blocking findings — this is not an approval
No findings at this head. Prior P1 is fixed.
Checked clean
- Confirmed the exact head and trusted PR metadata; reviewed the follow-up commit against the prior head and the full PR diff from its merge base.
- P1 fixed: the checklist row memo now depends on cardHeld, and a rerender test covers an application arriving without a route change.
- The payment-row pending state now disables Hide, and the held-card fixture has matching card and QR capabilities.
- Rechecked the previously reviewed QR gate, checklist route, carousel, dismissal storage, and locale behavior for new regressions.
- At review time the available bot and security checks passed; remaining CI jobs were still running. Local dependencies were unavailable, so no duplicate test run was performed.
Security review by moonshotai/kimi-k3: 0 finding(s), marked with the model name. It reads the diff only and answers only security, privacy and money, so treat its findings as advice.
Third opinion: did not run — it reads only the first review of a pull request; the first reviewer checks later rounds. This review is one reviewer short.
Exact head: 9e427919bc19 · Context: repo, other-repository, ci · Took 4m
|
English · Español · Español (Argentina) · Português (Brasil) After merge: c5843c4 → 3f10b4a. Capture complete in all locales. |
The screen captures wait for loaders to clear; this state is the held row's placeholder, so it names that placeholder instead.
TASK-23054. Follow-up to #3474. Hugo caught a wrong rule and asked for four more checklist changes.
QR pay is open to every user, in any country
Hugo: any verified Peanut user anywhere can pay QR codes. Only topping up through Manteca is limited to Argentina and Brazil. #3474 had its own residence rule (
canReachQrPay, AR/BR only), which hid the QR option from everyone else.selectQrKycGateis extracted fromuseQrPayKycGateintofeatures/payments/flows/qr-pay/qrKycGate.utils.ts. The page, the checklist and the carousel's "Pay with QR" slide all read it, so they cannot disagree.qrPayIsAPath(state)maps the gate to the checklist:pending: the row holds its place and the list cannot complete.canReachQrPay,hasQrPayRailand the AR/BR list are deleted.API, read-only:
user_railsrow.autoEnrollUserRailsgives Manteca geo rails only to AR/BR at KYC start, so the resolver emits no Manteca rail and the gate returns REQUIRES_IDENTITY_VERIFICATION, which is a path.enableQrPoolRails(sumsub/status-processor.ts, "QR is geo-agnostic for pool users") sets PIX_BR and MERCADOPAGO_QR_AR to ENABLED at pool tier, whatever the residence.Hugo's checklist follow-ups
hasCardRelationship), the subtitle is "Pay with the card", or "Pay a QR or with the card" when QR is also open. A card-only tap opens /card. The row is done only on the first spend (APIisActivated), as before. The copy has no pronoun ("the card", not "your card"), per the copy rule.LinkButtonsits under the list, 24px below the last row.home_checklist_hidden.hideHomeCta/readHiddenHomeCtasinhome-carousel.utils.ts). Both now merge into the stored record instead of overwriting it.home-verify-processing-long: ID check in review for two weeks.home-card-application-pending: card application in review.home-card-info-failed: card info fails to load, so the payment row holds.home-money-in-out-only: money in and out, no spend, so the Hide link shows.home-qr-blocked-unfunded: the three-row case. QR pay is blocked and a bank rail works.What changes per state
Captures of every state, the stuck-state table and the full copy table are in mono
local/scratch/home-viz/onboarding.html(section 2 and 2b).Tests
qrKycGate.utils.test.ts: every gate state, including the new user with no Manteca rail (REQUIRES_IDENTITY_VERIFICATION), andqrPayIsAPathfor all of them.activation-step.utils.test.ts: route pending while the QR gate loads, andcanHideChecklist.useActivationStatus.test.tsx: card + QR before verification for residences BR, US, DE and none. QR only without the card. Blocked QR with no card gives none. A held card setscardHeld.GettingStartedChecklist.test.tsx: held-card copy and tap. Hide shows only at the payment row, calls back and sends the event.HomePage.test.tsx: a hidden list hands over. It comes back when it may not be hidden. It never hides a rejection card.home-carousel.utils.test.ts: one store, merged, per user.