Skip to content

[No QA] Update Two-Factor-Authentication.md#96690

Merged
stephanieelliott merged 1 commit into
mainfrom
ryanschaffer-patch-2
Jul 21, 2026
Merged

[No QA] Update Two-Factor-Authentication.md#96690
stephanieelliott merged 1 commit into
mainfrom
ryanschaffer-patch-2

Conversation

@ryanschaffer

Copy link
Copy Markdown
Contributor

Using Claude, I found a dead link. This replaces that dead link with the intended link.

Explanation of Change

Fixed Issues

$
PROPOSAL:

Tests

  • Verify that no errors appear in the JS console

Offline tests

QA Steps

// TODO: These must be filled out, or the issue title must include "[No QA]."

  • Verify that no errors appear in the JS console

PR Author Checklist

  • I linked the correct issue in the ### Fixed Issues section above
  • I wrote clear testing steps that cover the changes made in this PR
    • I added steps for local testing in the Tests section
    • I added steps for the expected offline behavior in the Offline steps section
    • I added steps for Staging and/or Production testing in the QA steps section
    • I added steps to cover failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
    • I tested this PR with a High Traffic account against the staging or production API to ensure there are no regressions (e.g. long loading states that impact usability).
  • I included screenshots or videos for tests on all platforms
  • I ran the tests on all platforms & verified they passed on:
    • Android: Native
    • Android: mWeb Chrome
    • iOS: Native
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
  • I verified there are no console errors (if there's a console error not related to the PR, report it or open an issue for it to be fixed)
  • I followed proper code patterns (see Reviewing the code)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I followed the guidelines as stated in the Review Guidelines
  • I tested other components that can be impacted by my changes (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar are working as expected)
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))
  • If new assets were added or existing ones were modified, I verified that:
    • The assets are optimized and compressed (for SVG files, run npm run compress-svg)
    • The assets load correctly across all supported platforms.
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • I added unit tests for any new feature or bug fix in this PR to help automatically prevent regressions in this user flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.

Screenshots/Videos

Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari

Using Claude, I found a dead link. This replaces that dead link with the intended link.
@github-actions

Copy link
Copy Markdown
Contributor

👋 Hi @ryanschaffer, thanks for your interest in contributing to Expensify!

This PR has been automatically closed because it doesn't appear to meet our contribution requirements:

  • You are not a member of the Expensify GitHub organization
  • You are not a member of the Expensify contributor-plus GitHub team
  • No linked GitHub issue was found in the PR description where you are listed as an assignee

If you'd like to contribute, please make sure to:

  1. Find an open issue you'd like to work on
  2. Get assigned to the issue by following our contribution process
  3. Link the issue in your PR description using the format: $ https://github.com/Expensify/App/issues/<issueID>

Please review our contributing guidelines for more details.

If you believe this was closed in error, please reach out in the #expensify-open-source Slack channel.

@github-actions github-actions Bot closed this Jul 21, 2026
@github-actions github-actions Bot locked as spam and limited conversation to collaborators Jul 21, 2026
@github-actions github-actions Bot changed the title Update Two-Factor-Authentication.md [No QA] Update Two-Factor-Authentication.md Jul 21, 2026
@OSBotify

Copy link
Copy Markdown
Contributor

A preview of your ExpensifyHelp changes have been deployed to https://7f282844.helpdot.pages.dev ⚡️

Updated articles:

@ryanschaffer

Copy link
Copy Markdown
Contributor Author

@MelvinBot I am the CFO of Expensify, not an unregistered contributor. Why did I just get this message?

@MelvinBot

Copy link
Copy Markdown
Contributor

Hi Ryan — that message didn't come from me. It was posted by the automated Validate Contributor PRs workflow (github-actions), which auto-closes and locks PRs from people it can't confirm as authorized contributors. It flagged you by mistake.

Why it happened: the gate decides "member" from the author_association field GitHub puts in the PR webhook, and that field only reports MEMBER for org members whose Expensify membership is publicly visible. Your org membership is private, so the webhook saw you as a non-member. You're also not on the contributor-plus team and the PR links no issue where you're the assignee — so all three authorization paths failed and it closed + locked the PR.

The irony: the action already has an isInternalExpensifyEngineer() check that uses an org token (which can see private membership), but its result is only set as an output and never used in the actual authorization decision — and it only covers the engineering team, not other internal staff.

To unblock right now: an org member can reopen the PR (it's locked, so it needs unlocking first), or you can make your Expensify org membership public and reopen it yourself.

Root cause + suggested fix

Fix: authorize on actual org membership via the org token (GET /orgs/Expensify/members/{username}) instead of trusting the webhook's author_association. That correctly clears any internal employee — engineer or not — whose membership is private.

Want me to open an issue to fix the workflow so this stops happening to private-membership employees?

@stephanieelliott
stephanieelliott merged commit 336ea5c into main Jul 21, 2026
21 of 23 checks passed
@stephanieelliott
stephanieelliott deleted the ryanschaffer-patch-2 branch July 21, 2026 20:50
@melvin-bot melvin-bot Bot added the Emergency label Jul 21, 2026
@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to staging by https://github.com/stephanieelliott in version: 9.4.42-0 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants