refactor(kyc-controller): cleanup controller state - #10062
Merged
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2c34b3a. Configure here.
Extract vendor disclaimer acceptance helpers into their own module so the branch-per-vendor logic can be covered directly, add PR links to the breaking-change changelog entries, and resolve the eslint and prettier violations that were failing CI. Co-authored-by: Cursor <cursoragent@cursor.com>
jiexi
commented
Sep 1, 2026
Member
Author
There was a problem hiding this comment.
i suppose a new helper file doesn't hurt here. The controller is a few thousand long already
Member
Author
|
@metamaskbot publish-previews |
Contributor
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
10 tasks
Akaryatrh
previously approved these changes
Sep 1, 2026
jiexi
added a commit
to MetaMask/metamask-mobile
that referenced
this pull request
Sep 2, 2026
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until this PR meets the canonical
Definition of Ready For Review in `docs/readme/ready-for-review.md`.
In short: the template must be materially complete (not just section
titles
present), all status checks must be currently passing, and the only
expected
follow-up commits must be reviewer-driven.
-->
<!--
mms-check directive vocabulary — read by
.github/scripts/shared/pr-template-checks.ts
at module load to build the validation plan. Directives are invisible in
rendered
markdown and must NOT be removed or edited without updating the
validator registry.
type=text Section must contain non-placeholder prose.
type=changelog Section must have a valid CHANGELOG entry: line.
type=issue-link Section must have a Fixes:/Closes:/Refs: line with a
value.
type=manual-testing Section must have real testing steps or an explicit
N/A.
type=screenshot Section must have evidence (image/URL) or an explicit
N/A.
type=checklist Section must have all checkboxes consciously checked.
required=true|false Whether a missing/invalid section runs the validator
at all.
blocking=true|false Whether a failure of this check fails the CI
workflow.
Default: false — failures are shown as warnings in the sticky
comment but do not block the PR.
Sections without a directive are checked for structural presence only.
-->
## **Description**
Adopts the changes in MetaMask/core#10062
and the changes in MetaMask/core#10079
## **Changelog**
<!-- mms-check: type=changelog required=true blocking=true -->
<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`
If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`
(This helps the Release Engineer do their job more quickly and
accurately)
-->
CHANGELOG entry:
## **Related issues**
<!-- mms-check: type=issue-link required=true -->
Fixes:
## **Manual testing steps**
<!-- mms-check: type=manual-testing required=true -->
```gherkin
Feature: my feature name
Scenario: user [verb for user action]
Given [describe expected initial app state]
When user [verb for user action]
Then [describe expected outcome]
```
## **Screenshots/Recordings**
<!-- mms-check: type=screenshot required=true -->
<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->
### **Before**
<!-- [screenshots/recordings] -->
### **After**
<!-- [screenshots/recordings] -->
## **Pre-merge author checklist**
<!-- mms-check: type=checklist required=true -->
<!--
Every checklist item must be consciously assessed before marking this PR
as
"Ready for review". A checked box means you deliberately considered that
responsibility, not that you literally performed every action listed.
Unchecked boxes are ambiguous: they are not an implicit "N/A" and they
are not
a silent "skip". See `docs/readme/ready-for-review.md` for the full
checklist
semantics.
-->
- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.
#### Performance checks (if applicable)
- [ ] I've tested on Android
- Ideally on a mid-range device; emulator is acceptable
- [ ] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [ ] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example
For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).
## **Pre-merge reviewer checklist**
<!--
Reviewer checklist items follow the same semantics as the author
checklist: an
unchecked box is ambiguous, a checked box means the reviewer consciously
assessed that responsibility. See `docs/readme/ready-for-review.md`.
-->
- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **High Risk**
> Touches identity verification (Iron/UKYC/Sumsub), EIP-191 wallet
registration, autoramp creation against live dev proxies, and persistent
KYC state—mistakes could affect money onboarding or signing prompts.
>
> **Overview**
> Adds **Brazil virtual bank account (VBA) demo flow** end-to-end:
navigation for mock KYC email/success and account status screens, **Iron
→ Sumsub** orchestration via new `ironKycFlow` helpers, and **Get Pix
Key** now initializes Iron KYC before advancing instead of only
navigating.
>
> **Engine** registers **`KycService`**, **`KycController`** (with React
Native Sumsub launcher), and **`NeoBankService`**, clears KYC state on
wallet reset, and subscribes **`registerMoneyAccountOnKycCompletion`**
to `KycController:statusChanged` so completed KYC can auto **register
the Money Account wallet** and **create a BRL→mUSD/Monad autoramp**
(deduped with the manual pipeline on `MockKycSuccess`).
**`VirtualBankAccount`** refreshes autoramps and listens on a **neobank
WebSocket** while focused.
>
> **Money tab** gains **`useNeobankSandboxDepositEvents`** (Iron
customer id resolution + dev WebSocket) to show a **deposit success
toast only**—no vault submit. **Dev tooling**: `vbaTrace` streams to the
ramps debug dashboard; neobank `fetch` is traced in `__DEV__`. Android
adds the **Sumsub Maven** repo; **idOS JWKS** URLs land in
`AppConstants`; **`addPrecreatedOrder`** passes required `chainId`.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
80b869c. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Explanation
References
See: MetaMask/metamask-mobile#35561
Checklist
Note
High Risk
Wide breaking API and persisted-state shape changes for identity/KYC flows; integrators must migrate callers and stored state or users may be forced through terms again or fail session creation.
Overview
Breaking refactor of
KycControllerpersisted and session state so multi-vendor KYC terms and T&C2 consents are modeled explicitly and MoonPay-only tokens are named clearly.State and API renames:
sessionToken/accessTokenbecomemoonpaySessionToken/moonpayAccessToken; loaded vendor copy moves tovendorDisclaimers/vendorError. FlattermsAcceptedAt,acceptedDisclaimerIds, andtermsAcceptedVendorare replaced byvendorDisclaimersAccepted(moonpay: { termsAcceptedAt } | null,iron: { disclaimerIds } | null). T&C2 booleans becomeproviderDisclaimersAccepted(sumsub: KycConsentRecord[] | null) andidosDisclaimersAccepted(KycConsentRecord[] | null).acceptTermsAndStartSessionnow requiresproviderDisclaimersAcceptedandidosDisclaimersAccepteddocument lists instead ofsumsubTncSigned/idosTncSigned.Behavior: A new
vendorDisclaimerAcceptancehelper module records, checks, and clears per-vendor T&C1 acceptance without wiping another vendor’s persisted acceptance when switching vendors (the old vendor-scoped drop oncreateVendorCustomeris removed). Consents-path session posting maps accepted{ key, version }records onto catalog rows rather than treating whole categories as accepted booleans. MoonPay auto-resume can load disclaimers when missing before#createSession. Docs, changelog, and tests are updated throughout.Reviewed by Cursor Bugbot for commit 4ac21d4. Bugbot is set up for automated code reviews on this repo. Configure here.