You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
@metamask/profile-controller 1.0.1
Changed
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
@metamask/profile-metrics-controller 5.1.3
Changed
Bump @metamask/transaction-controller from ^72.0.0 to ^72.1.0 (#10462, #10652)
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
@metamask/profile-sync-controller 34.0.0
Changed
Open the verification session on enrollment and let the server set its lifetime (#10653)
completeCredentialEnrollment opens a verification session with the assertion POST /api/v2/mfa/enroll/complete returns for the new credential, replacing any earlier one, so no separate verification is needed right after enrolling. If the token exchange fails, the enrollment still succeeds and the earlier session is kept
SRPJwtBearerAuth.completeMfaEnrollment and JwtBearerAuth.completeMfaEnrollment return that assertion
The session lasts for the token's expires_in, measured on the device clock, instead of at most 15 minutes
Replace JS AES implementation with @metamask/cryptography (#10621)
BREAKING: Remove VERIFICATION_SESSION_TTL_MS, as the server now sets the verification session lifetime (#10653)
Fixed
Coalesce overlapping performSignIn calls so only one sign-in runs at a time (#10646)
Rely on @metamask/key-tree crypto implementation for HMAC-SHA-512 instead of hardcoded noble implementation (#10424)
@metamask/key-tree uses WebCrypto API if available and fallback to noble otherwise.
One note, we expect the platform to provide a fully-compliant WebCrypto (crypto.subtle) implementation for this to work (@metamask/key-tree detection is global and not "per crypto functions").
@metamask/ramps-controller 26.2.0
Changed
RampsController.setSelectedToken matches eip155 ERC-20 asset ids case-insensitively and keeps the catalog token's own assetId. Non-EVM asset ids still require an exact match (#10545)
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
@metamask/shield-controller 7.0.4
Changed
Bump @metamask/transaction-controller from ^72.0.0 to ^72.1.0 (#10462, #10652)
Bump @metamask/base-data-service from ^2.0.0 to ^2.1.0 (#10502)
Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
Bump @ethersproject/transactions from ^5.7.0 to ^5.8.0 (#10483)
Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
@metamask/social-controllers 3.6.0
Added
Add block, fetchBlockedProfiles, and fetchBlockedContent methods to SocialService (and the matching SocialService:block, SocialService:fetchBlockedProfiles, and SocialService:fetchBlockedContent messenger actions) for the social-api moderation block endpoints (#10656)
block calls PUT /moderation/block with exactly one of profileId, commentId, or replyId, plus an optional reason. The endpoint returns 204.
fetchBlockedProfiles calls GET /moderation/blocks/profiles and returns traders the caller has blocked, most recently blocked first. Pass cursor from the previous page; cursor is null on the last page.
fetchBlockedContent calls GET /moderation/blocks/content and returns comments and replies the caller has blocked, most recently blocked first, with the same cursor pagination.
Changed
Bump @metamask/core-backend from ^12.0.0 to ^12.0.1 (#10662)
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)
@metamask/subscription-controller 12.0.1
Changed
Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)