feat(widget): add borrowing flows and migrate runtime to Effect - #551
Conversation
|
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
This pull request is automatically being deployed by Amplify Hosting (learn more). |
|
This pull request is automatically being deployed by Amplify Hosting (learn more). |
6cf3187 to
5dac944
Compare
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, Cursor Security Agent left an unresolved medium-severity finding, and required checks did not finish on the latest commit (Bugbot cancelled; Security Agent still running). Assigned jdomingos and dnehl for human review.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
16d2bb4 to
67eb76f
Compare
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
66cee96 to
0d6ed5f
Compare
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent has an unresolved medium-severity tabnabbing finding on
complete.tsx. jdomingos and dnehl are already assigned for human review.Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Not approving: this large earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
| {provider.website && ( | ||
| <Text | ||
| as="a" | ||
| href={provider.website} |
There was a problem hiding this comment.
🔒 Agentic Security Review
Severity: MEDIUM
The provider website link uses the raw Yield catalog provider.website string as href, with no scheme allowlist. The dashboard path already routes the same field through formatProviderWebsiteHref, which prefixes non-http(s) values. A catalog value such as javascript: or data: can become an executable link in the host document when this widget is embedded same-origin.
Impact: Poisoned provider metadata can run script in the embedding origin on click, or open an unexpected scheme.
Reviewed by Cursor Security Reviewer for commit e893af6. Configure here.
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn/borrow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. No new reviewers assigned; two reviewers are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: Cursor Security Agent did not reach a terminal state within the polling window, and this earn/borrow refactor exceeds the low-risk approval threshold. Human review is needed; reviewers were already assigned.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: Cursor Security Agent did not reach a terminal state within the polling window, and this large earn-flow refactor exceeds the low-risk approval threshold. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: Cursor Security Agent did not reach a terminal state within the polling window, and this earn/borrow refactor exceeds the low-risk approval threshold. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: Cursor Security Agent did not reach a terminal state within the polling window, and this earn-flow refactor exceeds the low-risk approval threshold. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: this earn-flow refactor exceeds the low-risk approval threshold, and Cursor Security Agent still has unresolved high findings that need human review. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment: Cursor Security Agent did not reach a terminal state within the polling window, and this earn-flow refactor exceeds the low-risk approval threshold. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment and did not approve: this large earn-flow refactor exceeds the low-risk threshold, and Cursor Security Agent did not finish within the wait window. Human review is needed; no additional reviewers were assigned because two are already requested.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment and did not approve: this earn-flow refactor exceeds the low-risk threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Risk: high. Left a non-blocking comment and did not approve: this earn-flow refactor exceeds the low-risk threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
3b58f30 to
0b0a3d5
Compare
There was a problem hiding this comment.
Risk: high. Left a non-blocking comment and did not approve: this earn-flow refactor exceeds the low-risk threshold, and Cursor Security Agent still has unresolved high and medium findings that need human review. Reviewers were already assigned, so none were added.
Sent by Cursor Approval Agent: Pull Request Router and Approver
34e6d6f to
4b751ed
Compare
Introduce a feature-flagged dashboard borrowing experience for opening and managing positions, including market and collateral selection, LTV and risk checks, wallet signing, transaction execution, repayment, and withdrawals. Move wallet, API resources, transaction workflows, Earn, Activity, and portfolio state into scoped Effect services and atom-backed views. Replace the legacy XState/store integration and centralize route and lifecycle ownership. Add generated Borrow API and schema tooling, Stellar wallet and Robinhood network support, and update package declarations, build tooling, CI, and production-consumer coverage.
86f03c8 to
ae6e6e6
Compare




Note
High Risk
Large new DeFi borrow path with wallet signing, transaction submission, and LTV validation touches money-moving flows; earn routing/state refactor could regress staking if mis-wired.
Overview
Adds a feature-flagged borrow experience in the dashboard (form → review → steps → complete, plus borrow position management), backed by a new
borrowmodule: Effect Schema domain models, OpenAPI-generatedBorrowApiclient, and@effect/atom-reactatoms for markets/positions, form state, action execution (sign/submit/confirm), and post-tx cache refresh.Earn flow cleanup: drops
EarnPageStateUsageBoundaryProvider/@xstate/store, removescommon/get-token-balances.tsandgetInitialTokenfrom stake types, and tightens validator handling via a compositeValidator.key(address + optional subnet) used in select-validator and position balance keys.Tooling/config: OpenAPI generator gains
BorrowApi(fullhttpclient+ spec prep), optional CLI spec selection,VITE_BORROW_API_URL/VITE_FORCE_BORROW, and rootpnpm.patchedDependenciesremoved; adds skeleton line/circle loaders for borrow UI loading states.Reviewed by Cursor Bugbot for commit 6cf3187. Configure here.