Skip to content

fix: replace mock JWT tokens with real wallet-signature auth (Closes #35) - #67

Merged
EmeditWeb merged 1 commit into
mainfrom
fix/wire-real-auth
Sep 29, 2026
Merged

EmeditWeb merged 1 commit into
mainfrom
fix/wire-real-auth

Conversation

@EmeditWeb

Copy link
Copy Markdown
Member

Summary

Closes #35

Replaces the mock-access-token / mock-refresh-token placeholders with real wallet-signature JWT auth. After wallet connect, the register flow now runs authService.authenticate: it fetches a nonce + SEP-10-style challenge transaction, signs the challenge XDR with the connected wallet (Freighter directly, mobile Lobstr over WalletConnect using the stored sessionId), and exchanges the signed challenge with POST /auth/verify (signatureType: sep0010) for JWT tokens. This pairs with the API side (StepFi-app/StepFi-API#138) that issues and verifies the challenge.

This repo is for the React Native mobile app only

  • My changes are React Native components or Expo code
  • I have NOT added web-only APIs (window, document, localStorage)
  • I have NOT hardcoded hex color values (use constants/colors.ts only)
  • All icons are from lucide-react-native only
  • No API calls made directly in screen files (use services/ layer only)
  • Every screen has loading, error, and empty states

Type of change

  • Bug fix
  • Service or store change

Testing

  • npx expo export --platform web passes
  • No TypeScript errors
  • Tested on Android emulator or physical device
  • No hardcoded hex colors
  • No console errors

Verified locally: npm run typecheck, npm run lint, and npm test (64/64) all clean, and npx expo export --platform web exits 0. Added services/__tests__/auth.service.test.ts covering both wallet types plus the signing-failure and network-failure paths (challenge is signed once, /auth/verify posts sep0010, wallet/session failures surface as WALLET_SIGNING_FAILED). Also removed the dead legacy simulated sign-in path (components/pages/SignIn.tsx, hooks/auth/use-sign-in.ts) — nothing referenced them.

Context files reviewed

  • context/architecture-context.md
  • context/code-standards.md

Wire the SEP-10-style challenge-transaction login into the app.
After wallet connect, register now runs the real flow via
authService.authenticate: fetch a nonce + challenge XDR, sign the
challenge with the connected wallet (Freighter directly, Lobstr over
WalletConnect using the stored sessionId), and exchange the signed
challenge for JWT tokens — replacing the mock-access-token /
mock-refresh-token placeholders.

- services/auth.service.ts: add WalletType, sep0010 verify body, and
  the authenticate() orchestration; wallet signing failures surface as
  a WALLET_SIGNING_FAILED ApiClientError.
- types/errors.ts: add WALLET_SIGNING_FAILED code + user message.
- app/(auth)/register.tsx: call authenticate() with a wallet guard,
  keeping the existing error banner and finally reset.
- Delete the dead legacy simulated sign-in path (components/pages/
  SignIn.tsx, hooks/auth/use-sign-in.ts) — nothing referenced them.
- Add services/__tests__/auth.service.test.ts covering both wallet
  types and the signing/network error paths.

Closes #35
@EmeditWeb
EmeditWeb merged commit 1e51527 into main Sep 29, 2026
4 checks passed
@EmeditWeb
EmeditWeb deleted the fix/wire-real-auth branch September 29, 2026 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: sign-in flow uses simulated timeout instead of real WalletConnect + API auth

1 participant