fix(kyc-controller): Remove consent property from the GET /disclaimers return type - #10079
Merged
Merged
Conversation
The generated action-types file copies JSDoc verbatim from the source, so the hand-reflowed comment made `messenger-action-types:check` fail. Co-authored-by: Cursor <cursoragent@cursor.com>
10 tasks
jiexi
added a commit
to MetaMask/metamask-mobile
that referenced
this pull request
Sep 2, 2026
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until this PR meets the canonical
Definition of Ready For Review in `docs/readme/ready-for-review.md`.
In short: the template must be materially complete (not just section
titles
present), all status checks must be currently passing, and the only
expected
follow-up commits must be reviewer-driven.
-->
<!--
mms-check directive vocabulary — read by
.github/scripts/shared/pr-template-checks.ts
at module load to build the validation plan. Directives are invisible in
rendered
markdown and must NOT be removed or edited without updating the
validator registry.
type=text Section must contain non-placeholder prose.
type=changelog Section must have a valid CHANGELOG entry: line.
type=issue-link Section must have a Fixes:/Closes:/Refs: line with a
value.
type=manual-testing Section must have real testing steps or an explicit
N/A.
type=screenshot Section must have evidence (image/URL) or an explicit
N/A.
type=checklist Section must have all checkboxes consciously checked.
required=true|false Whether a missing/invalid section runs the validator
at all.
blocking=true|false Whether a failure of this check fails the CI
workflow.
Default: false — failures are shown as warnings in the sticky
comment but do not block the PR.
Sections without a directive are checked for structural presence only.
-->
## **Description**
Adopts the changes in MetaMask/core#10062
and the changes in MetaMask/core#10079
## **Changelog**
<!-- mms-check: type=changelog required=true blocking=true -->
<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`
If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`
(This helps the Release Engineer do their job more quickly and
accurately)
-->
CHANGELOG entry:
## **Related issues**
<!-- mms-check: type=issue-link required=true -->
Fixes:
## **Manual testing steps**
<!-- mms-check: type=manual-testing required=true -->
```gherkin
Feature: my feature name
Scenario: user [verb for user action]
Given [describe expected initial app state]
When user [verb for user action]
Then [describe expected outcome]
```
## **Screenshots/Recordings**
<!-- mms-check: type=screenshot required=true -->
<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->
### **Before**
<!-- [screenshots/recordings] -->
### **After**
<!-- [screenshots/recordings] -->
## **Pre-merge author checklist**
<!-- mms-check: type=checklist required=true -->
<!--
Every checklist item must be consciously assessed before marking this PR
as
"Ready for review". A checked box means you deliberately considered that
responsibility, not that you literally performed every action listed.
Unchecked boxes are ambiguous: they are not an implicit "N/A" and they
are not
a silent "skip". See `docs/readme/ready-for-review.md` for the full
checklist
semantics.
-->
- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.
#### Performance checks (if applicable)
- [ ] I've tested on Android
- Ideally on a mid-range device; emulator is acceptable
- [ ] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [ ] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example
For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).
## **Pre-merge reviewer checklist**
<!--
Reviewer checklist items follow the same semantics as the author
checklist: an
unchecked box is ambiguous, a checked box means the reviewer consciously
assessed that responsibility. See `docs/readme/ready-for-review.md`.
-->
- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **High Risk**
> Touches identity verification (Iron/UKYC/Sumsub), EIP-191 wallet
registration, autoramp creation against live dev proxies, and persistent
KYC state—mistakes could affect money onboarding or signing prompts.
>
> **Overview**
> Adds **Brazil virtual bank account (VBA) demo flow** end-to-end:
navigation for mock KYC email/success and account status screens, **Iron
→ Sumsub** orchestration via new `ironKycFlow` helpers, and **Get Pix
Key** now initializes Iron KYC before advancing instead of only
navigating.
>
> **Engine** registers **`KycService`**, **`KycController`** (with React
Native Sumsub launcher), and **`NeoBankService`**, clears KYC state on
wallet reset, and subscribes **`registerMoneyAccountOnKycCompletion`**
to `KycController:statusChanged` so completed KYC can auto **register
the Money Account wallet** and **create a BRL→mUSD/Monad autoramp**
(deduped with the manual pipeline on `MockKycSuccess`).
**`VirtualBankAccount`** refreshes autoramps and listens on a **neobank
WebSocket** while focused.
>
> **Money tab** gains **`useNeobankSandboxDepositEvents`** (Iron
customer id resolution + dev WebSocket) to show a **deposit success
toast only**—no vault submit. **Dev tooling**: `vbaTrace` streams to the
ramps debug dashboard; neobank `fetch` is traced in `__DEV__`. Android
adds the **Sumsub Maven** repo; **idOS JWKS** URLs land in
`AppConstants`; **`addPrecreatedOrder`** passes required `chainId`.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
80b869c. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation
Fixes incorrect typing causing validation to fail when fetching session disclaimers
References
Checklist
Note
Medium Risk
Breaking public types and response validation for disclaimer flows; incorrect assumptions about
consentedon the global catalog could break compile-time or runtime consumers until they adoptKycCatalogDocument.Overview
Separates global disclaimer catalog documents from session-scoped consent documents so
GET /disclaimersno longer implies per-documentconsentedstate.Introduces
KycCatalogDocument(key, version, title, url only) and typesKycDisclaimersCatalogwithKycCatalogDocument[].KycConsentDocumentis nowKycCatalogDocument & { consented: boolean }, andKycSessionDisclaimersexplicitly uses consent documents pluscredentialReusabilityConsentGiven.Runtime validation in
KycServicematches the API:GlobalDisclaimersResponseStructvalidates catalog fields only; session responses still requireconsentedon each document (new test whenconsentedis omitted). Docs and tests are updated accordingly.Breaking for TypeScript consumers that treated global catalog entries as
KycConsentDocumentwithconsented.Reviewed by Cursor Bugbot for commit 33c8851. Bugbot is set up for automated code reviews on this repo. Configure here.