Repository navigation
feat(authentication-controller): Add pairedIdentifierIds to UserProfile in srpSessionData - #10394
Merged
Merged
Conversation
…le in srpSessionData
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit baf2c82. Configure here.
ccharly
approved these changes
Sep 23, 2026
This was referenced Sep 23, 2026
Merged
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Sep 23, 2026
## Explanation Publish `@metamask/profile-sync-controller@32.3.0` so clients can consume the additive changes that have accumulated on `main` since 32.2.0, including the `pairedIdentifierIds` field on `UserProfile` in `srpSessionData` (MetaMask#10394). Minor bump: the release only adds new, optional API surface (AAL2-gated MFA enrollment, elevated tokens for credential enrollment, `pairedIdentifierIds`) and bumps the internal `immer` dependency. Nothing existing changes, so it is not breaking. All 15 workspace packages that depend on `@metamask/profile-sync-controller` now pin `^32.3.0`; none are being published in this release. `yarn.lock` is updated accordingly. ## References - Add `pairedIdentifierIds` to `UserProfile`: MetaMask#10394 - MFA / AAL2 enrollment support: MetaMask#10374 - Bump `immer` from `^9.0.6` to `^9.0.21`: MetaMask#10331 ## Checklist - [x] I've updated the test suite for new or updated code as appropriate - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Releases auth/MFA and profile-session API surface; the diff is dependency pins only, but consumers will pick up security-sensitive behavior from 32.3.0. > > **Overview** > This release PR cuts **`@metamask/profile-sync-controller@32.3.0`** (monorepo **`1280.0.0`**) and propagates it across the workspace. The **15** packages that depend on profile sync now pin **`^32.3.0`** in `package.json`, with matching **Unreleased** changelog notes and **`yarn.lock`** updates; those dependents are **not** republished here. > > The **32.3.0** changelog section documents what clients get from this publish: **AAL2-gated MFA enrollment** (elevated `accessToken` for `beginMfaEnrollment`, new MFA error codes / `StepUpRequiredError`, `retry_after_seconds` handling), **`pairedIdentifierIds`** on `UserProfile` in `srpSessionData`, and an internal **`immer`** bump. No runtime code changes appear in this diff—only versioning and release notes. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3a7ced6. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
runway-github Bot
pushed a commit
to MetaMask/metamask-mobile
that referenced
this pull request
Sep 23, 2026
…6726) ## **Description** Detects social profiles linked to an imported SRP from AuthenticationController profile signals and persists that cohort marker. When a linked-social wallet was already consolidated before the signal arrived, this repairs the missing Basic Functionality migration bottom sheet without rewriting preferences or emitting migration analytics. This draft depends on a future `@metamask/profile-sync-controller` release containing MetaMask/core#10394. The currently released package does not yet expose persisted `profile.pairedIdentifierIds`. ## **Changelog** CHANGELOG entry: Fixed the missing Basic Functionality migration notice for restored wallets linked to social login profiles ## **Related issues** Refs: MetaMask/core#10394 ## **Manual testing steps** ```gherkin Feature: Linked-social Basic Functionality migration notice Scenario: Restore an SRP previously linked to social login Given a wallet was originally onboarded with Google, Apple, or Telegram And the same SRP is imported into a fresh installation And Basic Functionality is enabled and the wallet was already consolidated When AuthenticationController signs in and restores the linked profile metadata Then the Basic Functionality migration bottom sheet is scheduled And existing Basic Functionality preferences are not rewritten Scenario: Do not repeat a dismissed notice Given the linked-social migration notice was dismissed When the wallet is locked and unlocked again Then the migration bottom sheet is not scheduled again ``` ## **Screenshots/Recordings** ### **Before** N/A — controller and migration state wiring only. ### **After** N/A — controller and migration state wiring only. ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [x] I've included tests if applicable - [x] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [x] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [x] I've tested on Android - Considered not applicable for controller and migration state wiring. - [x] I've tested with a power user scenario - Considered not applicable for controller and migration state wiring. - [x] I've instrumented key operations with Sentry traces for production performance metrics - Considered not applicable; this does not add a key timed operation. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- Generated with the help of the pr-description AI skill --> Made with [Cursor](https://cursor.com) --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
runway-github Bot
added a commit
to MetaMask/metamask-mobile
that referenced
this pull request
Sep 23, 2026
…6726) ## **Description** Detects social profiles linked to an imported SRP from AuthenticationController profile signals and persists that cohort marker. When a linked-social wallet was already consolidated before the signal arrived, this repairs the missing Basic Functionality migration bottom sheet without rewriting preferences or emitting migration analytics. This draft depends on a future `@metamask/profile-sync-controller` release containing MetaMask/core#10394. The currently released package does not yet expose persisted `profile.pairedIdentifierIds`. ## **Changelog** CHANGELOG entry: Fixed the missing Basic Functionality migration notice for restored wallets linked to social login profiles ## **Related issues** Refs: MetaMask/core#10394 ## **Manual testing steps** ```gherkin Feature: Linked-social Basic Functionality migration notice Scenario: Restore an SRP previously linked to social login Given a wallet was originally onboarded with Google, Apple, or Telegram And the same SRP is imported into a fresh installation And Basic Functionality is enabled and the wallet was already consolidated When AuthenticationController signs in and restores the linked profile metadata Then the Basic Functionality migration bottom sheet is scheduled And existing Basic Functionality preferences are not rewritten Scenario: Do not repeat a dismissed notice Given the linked-social migration notice was dismissed When the wallet is locked and unlocked again Then the migration bottom sheet is not scheduled again ``` ## **Screenshots/Recordings** ### **Before** N/A — controller and migration state wiring only. ### **After** N/A — controller and migration state wiring only. ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [x] I've included tests if applicable - [x] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [x] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [x] I've tested on Android - Considered not applicable for controller and migration state wiring. - [x] I've tested with a power user scenario - Considered not applicable for controller and migration state wiring. - [x] I've instrumented key operations with Sentry traces for production performance metrics - Considered not applicable; this does not add a key timed operation. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- Generated with the help of the pr-description AI skill --> Made with [Cursor](https://cursor.com) --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
runway-github Bot
pushed a commit
to MetaMask/metamask-mobile
that referenced
this pull request
Sep 23, 2026
## **Description** Detects social profiles linked to an imported SRP from AuthenticationController profile signals and persists that cohort marker. When a linked-social wallet was already consolidated before the signal arrived, this repairs the missing Basic Functionality migration bottom sheet without rewriting preferences or emitting migration analytics. This draft depends on a future `@metamask/profile-sync-controller` release containing MetaMask/core#10394. The currently released package does not yet expose persisted `profile.pairedIdentifierIds`. ## **Changelog** CHANGELOG entry: Fixed the missing Basic Functionality migration notice for restored wallets linked to social login profiles ## **Related issues** Refs: MetaMask/core#10394 ## **Manual testing steps** ```gherkin Feature: Linked-social Basic Functionality migration notice Scenario: Restore an SRP previously linked to social login Given a wallet was originally onboarded with Google, Apple, or Telegram And the same SRP is imported into a fresh installation And Basic Functionality is enabled and the wallet was already consolidated When AuthenticationController signs in and restores the linked profile metadata Then the Basic Functionality migration bottom sheet is scheduled And existing Basic Functionality preferences are not rewritten Scenario: Do not repeat a dismissed notice Given the linked-social migration notice was dismissed When the wallet is locked and unlocked again Then the migration bottom sheet is not scheduled again ``` ## **Screenshots/Recordings** ### **Before** N/A — controller and migration state wiring only. ### **After** N/A — controller and migration state wiring only. ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [x] I've included tests if applicable - [x] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [x] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [x] I've tested on Android - Considered not applicable for controller and migration state wiring. - [x] I've tested with a power user scenario - Considered not applicable for controller and migration state wiring. - [x] I've instrumented key operations with Sentry traces for production performance metrics - Considered not applicable; this does not add a key timed operation. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- Generated with the help of the pr-description AI skill --> Made with [Cursor](https://cursor.com) --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
Merged
8 of 10 tasks
pull Bot
pushed a commit
to AmirulAndalib/metamask-mobile
that referenced
this pull request
Sep 23, 2026
…k#36726) ## **Description** Detects social profiles linked to an imported SRP from AuthenticationController profile signals and persists that cohort marker. When a linked-social wallet was already consolidated before the signal arrived, this repairs the missing Basic Functionality migration bottom sheet without rewriting preferences or emitting migration analytics. This draft depends on a future `@metamask/profile-sync-controller` release containing MetaMask/core#10394. The currently released package does not yet expose persisted `profile.pairedIdentifierIds`. ## **Changelog** CHANGELOG entry: Fixed the missing Basic Functionality migration notice for restored wallets linked to social login profiles ## **Related issues** Refs: MetaMask/core#10394 ## **Manual testing steps** ```gherkin Feature: Linked-social Basic Functionality migration notice Scenario: Restore an SRP previously linked to social login Given a wallet was originally onboarded with Google, Apple, or Telegram And the same SRP is imported into a fresh installation And Basic Functionality is enabled and the wallet was already consolidated When AuthenticationController signs in and restores the linked profile metadata Then the Basic Functionality migration bottom sheet is scheduled And existing Basic Functionality preferences are not rewritten Scenario: Do not repeat a dismissed notice Given the linked-social migration notice was dismissed When the wallet is locked and unlocked again Then the migration bottom sheet is not scheduled again ``` ## **Screenshots/Recordings** ### **Before** N/A — controller and migration state wiring only. ### **After** N/A — controller and migration state wiring only. ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [x] I've included tests if applicable - [x] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [x] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [x] I've tested on Android - Considered not applicable for controller and migration state wiring. - [x] I've tested with a power user scenario - Considered not applicable for controller and migration state wiring. - [x] I've instrumented key operations with Sentry traces for production performance metrics - Considered not applicable; this does not add a key timed operation. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- Generated with the help of the pr-description AI skill --> Made with [Cursor](https://cursor.com) --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
sleepytanya
pushed a commit
to MetaMask/metamask-mobile
that referenced
this pull request
Sep 24, 2026
) - fix(bft): repair notice for linked social profiles cp-8.13.0 (#36726) ## **Description** Detects social profiles linked to an imported SRP from AuthenticationController profile signals and persists that cohort marker. When a linked-social wallet was already consolidated before the signal arrived, this repairs the missing Basic Functionality migration bottom sheet without rewriting preferences or emitting migration analytics. This draft depends on a future `@metamask/profile-sync-controller` release containing MetaMask/core#10394. The currently released package does not yet expose persisted `profile.pairedIdentifierIds`. ## **Changelog** CHANGELOG entry: Fixed the missing Basic Functionality migration notice for restored wallets linked to social login profiles ## **Related issues** Refs: MetaMask/core#10394 ## **Manual testing steps** ```gherkin Feature: Linked-social Basic Functionality migration notice Scenario: Restore an SRP previously linked to social login Given a wallet was originally onboarded with Google, Apple, or Telegram And the same SRP is imported into a fresh installation And Basic Functionality is enabled and the wallet was already consolidated When AuthenticationController signs in and restores the linked profile metadata Then the Basic Functionality migration bottom sheet is scheduled And existing Basic Functionality preferences are not rewritten Scenario: Do not repeat a dismissed notice Given the linked-social migration notice was dismissed When the wallet is locked and unlocked again Then the migration bottom sheet is not scheduled again ``` ## **Screenshots/Recordings** ### **Before** N/A — controller and migration state wiring only. ### **After** N/A — controller and migration state wiring only. ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [x] I've included tests if applicable - [x] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [x] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [x] I've tested on Android - Considered not applicable for controller and migration state wiring. - [x] I've tested with a power user scenario - Considered not applicable for controller and migration state wiring. - [x] I've instrumented key operations with Sentry traces for production performance metrics - Considered not applicable; this does not add a key timed operation. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- Generated with the help of the pr-description AI skill --> Made with [Cursor](https://cursor.com) --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net> [7dca96b](7dca96b) Co-authored-by: Nidhi Kumari <nidhi.kumari@consensys.net> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

…
Explanation
References
Checklist
Note
Medium Risk
Changes sign-in state persistence and social/SRP pairing response handling in authentication code, though behavior is mostly additive with log redaction for sensitive identifier data.
Overview
Adds optional
pairedIdentifierIdsonUserProfilein persistedsrpSessionData, populated from auth APIpaired_identifier_idson SRP login and after multi-SRP profile pairing or social identifier pairing, so clients can tell whether a profile is socially paired.AuthenticationController keeps the last known list when login omits the field, writes paired identifiers only on the primary SRP session after pair flows, and redacts them from state logs alongside access tokens. The JWT bearer layer maps the field on login and
pairProfiles, andpairSocialIdentifiernow parses the success response and returns the paired identifiers instead of treating 2xx as body-less.Reviewed by Cursor Bugbot for commit 8f2c14b. Bugbot is set up for automated code reviews on this repo. Configure here.