Skip to content

feat(authentication-controller): Add pairedIdentifierIds to UserProfile in srpSessionData - #10394

Merged
mathieuartu merged 3 commits into
mainfrom
feat/add-paired-identifier-ids-state
Sep 23, 2026
Merged

mathieuartu merged 3 commits into
mainfrom
feat/add-paired-identifier-ids-state

Conversation

@mathieuartu

@mathieuartu mathieuartu commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

…

Explanation

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Medium Risk
Changes sign-in state persistence and social/SRP pairing response handling in authentication code, though behavior is mostly additive with log redaction for sensitive identifier data.

Overview
Adds optional pairedIdentifierIds on UserProfile in persisted srpSessionData, populated from auth API paired_identifier_ids on SRP login and after multi-SRP profile pairing or social identifier pairing, so clients can tell whether a profile is socially paired.

AuthenticationController keeps the last known list when login omits the field, writes paired identifiers only on the primary SRP session after pair flows, and redacts them from state logs alongside access tokens. The JWT bearer layer maps the field on login and pairProfiles, and pairSocialIdentifier now parses the success response and returns the paired identifiers instead of treating 2xx as body-less.

Reviewed by Cursor Bugbot for commit 8f2c14b. Bugbot is set up for automated code reviews on this repo. Configure here.

@mathieuartu mathieuartu self-assigned this Sep 23, 2026
@mathieuartu
mathieuartu requested review from a team as code owners September 23, 2026 11:15

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit baf2c82. Configure here.

@mathieuartu
mathieuartu added this pull request to the merge queue Sep 23, 2026
Merged via the queue into main with commit 60667c6 Sep 23, 2026
136 checks passed
@mathieuartu
mathieuartu deleted the feat/add-paired-identifier-ids-state branch September 23, 2026 11:56
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 23, 2026
## Explanation

Publish `@metamask/profile-sync-controller@32.3.0` so clients can
consume the additive changes that have accumulated on `main` since
32.2.0, including the `pairedIdentifierIds` field on `UserProfile` in
`srpSessionData` (MetaMask#10394).

Minor bump: the release only adds new, optional API surface (AAL2-gated
MFA enrollment, elevated tokens for credential enrollment,
`pairedIdentifierIds`) and bumps the internal `immer` dependency.
Nothing existing changes, so it is not breaking.

All 15 workspace packages that depend on
`@metamask/profile-sync-controller` now pin `^32.3.0`; none are being
published in this release. `yarn.lock` is updated accordingly.

## References

- Add `pairedIdentifierIds` to `UserProfile`:
MetaMask#10394
- MFA / AAL2 enrollment support:
MetaMask#10374
- Bump `immer` from `^9.0.6` to `^9.0.21`:
MetaMask#10331

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Releases auth/MFA and profile-session API surface; the diff is
dependency pins only, but consumers will pick up security-sensitive
behavior from 32.3.0.
> 
> **Overview**
> This release PR cuts **`@metamask/profile-sync-controller@32.3.0`**
(monorepo **`1280.0.0`**) and propagates it across the workspace. The
**15** packages that depend on profile sync now pin **`^32.3.0`** in
`package.json`, with matching **Unreleased** changelog notes and
**`yarn.lock`** updates; those dependents are **not** republished here.
> 
> The **32.3.0** changelog section documents what clients get from this
publish: **AAL2-gated MFA enrollment** (elevated `accessToken` for
`beginMfaEnrollment`, new MFA error codes / `StepUpRequiredError`,
`retry_after_seconds` handling), **`pairedIdentifierIds`** on
`UserProfile` in `srpSessionData`, and an internal **`immer`** bump. No
runtime code changes appear in this diff—only versioning and release
notes.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
3a7ced6. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
runway-github Bot pushed a commit to MetaMask/metamask-mobile that referenced this pull request Sep 23, 2026
…6726)

## **Description**

Detects social profiles linked to an imported SRP from
AuthenticationController profile signals and persists that cohort
marker. When a linked-social wallet was already consolidated before the
signal arrived, this repairs the missing Basic Functionality migration
bottom sheet without rewriting preferences or emitting migration
analytics.

This draft depends on a future `@metamask/profile-sync-controller`
release containing MetaMask/core#10394. The
currently released package does not yet expose persisted
`profile.pairedIdentifierIds`.

## **Changelog**

CHANGELOG entry: Fixed the missing Basic Functionality migration notice
for restored wallets linked to social login profiles

## **Related issues**

Refs: MetaMask/core#10394

## **Manual testing steps**

```gherkin
Feature: Linked-social Basic Functionality migration notice

  Scenario: Restore an SRP previously linked to social login
    Given a wallet was originally onboarded with Google, Apple, or Telegram
    And the same SRP is imported into a fresh installation
    And Basic Functionality is enabled and the wallet was already consolidated
    When AuthenticationController signs in and restores the linked profile metadata
    Then the Basic Functionality migration bottom sheet is scheduled
    And existing Basic Functionality preferences are not rewritten

  Scenario: Do not repeat a dismissed notice
    Given the linked-social migration notice was dismissed
    When the wallet is locked and unlocked again
    Then the migration bottom sheet is not scheduled again
```

## **Screenshots/Recordings**

### **Before**

N/A — controller and migration state wiring only.

### **After**

N/A — controller and migration state wiring only.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [x] I've tested on Android
  - Considered not applicable for controller and migration state wiring.
- [x] I've tested with a power user scenario
  - Considered not applicable for controller and migration state wiring.
- [x] I've instrumented key operations with Sentry traces for production
performance metrics
  - Considered not applicable; this does not add a key timed operation.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- Generated with the help of the pr-description AI skill -->

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
runway-github Bot added a commit to MetaMask/metamask-mobile that referenced this pull request Sep 23, 2026
…6726)

## **Description**

Detects social profiles linked to an imported SRP from
AuthenticationController profile signals and persists that cohort
marker. When a linked-social wallet was already consolidated before the
signal arrived, this repairs the missing Basic Functionality migration
bottom sheet without rewriting preferences or emitting migration
analytics.

This draft depends on a future `@metamask/profile-sync-controller`
release containing MetaMask/core#10394. The
currently released package does not yet expose persisted
`profile.pairedIdentifierIds`.

## **Changelog**

CHANGELOG entry: Fixed the missing Basic Functionality migration notice
for restored wallets linked to social login profiles

## **Related issues**

Refs: MetaMask/core#10394

## **Manual testing steps**

```gherkin
Feature: Linked-social Basic Functionality migration notice

  Scenario: Restore an SRP previously linked to social login
    Given a wallet was originally onboarded with Google, Apple, or Telegram
    And the same SRP is imported into a fresh installation
    And Basic Functionality is enabled and the wallet was already consolidated
    When AuthenticationController signs in and restores the linked profile metadata
    Then the Basic Functionality migration bottom sheet is scheduled
    And existing Basic Functionality preferences are not rewritten

  Scenario: Do not repeat a dismissed notice
    Given the linked-social migration notice was dismissed
    When the wallet is locked and unlocked again
    Then the migration bottom sheet is not scheduled again
```

## **Screenshots/Recordings**

### **Before**

N/A — controller and migration state wiring only.

### **After**

N/A — controller and migration state wiring only.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [x] I've tested on Android
  - Considered not applicable for controller and migration state wiring.
- [x] I've tested with a power user scenario
  - Considered not applicable for controller and migration state wiring.
- [x] I've instrumented key operations with Sentry traces for production
performance metrics
  - Considered not applicable; this does not add a key timed operation.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- Generated with the help of the pr-description AI skill -->

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
runway-github Bot pushed a commit to MetaMask/metamask-mobile that referenced this pull request Sep 23, 2026
## **Description**

Detects social profiles linked to an imported SRP from
AuthenticationController profile signals and persists that cohort
marker. When a linked-social wallet was already consolidated before the
signal arrived, this repairs the missing Basic Functionality migration
bottom sheet without rewriting preferences or emitting migration
analytics.

This draft depends on a future `@metamask/profile-sync-controller`
release containing MetaMask/core#10394. The
currently released package does not yet expose persisted
`profile.pairedIdentifierIds`.

## **Changelog**

CHANGELOG entry: Fixed the missing Basic Functionality migration notice
for restored wallets linked to social login profiles

## **Related issues**

Refs: MetaMask/core#10394

## **Manual testing steps**

```gherkin
Feature: Linked-social Basic Functionality migration notice

  Scenario: Restore an SRP previously linked to social login
    Given a wallet was originally onboarded with Google, Apple, or Telegram
    And the same SRP is imported into a fresh installation
    And Basic Functionality is enabled and the wallet was already consolidated
    When AuthenticationController signs in and restores the linked profile metadata
    Then the Basic Functionality migration bottom sheet is scheduled
    And existing Basic Functionality preferences are not rewritten

  Scenario: Do not repeat a dismissed notice
    Given the linked-social migration notice was dismissed
    When the wallet is locked and unlocked again
    Then the migration bottom sheet is not scheduled again
```

## **Screenshots/Recordings**

### **Before**

N/A — controller and migration state wiring only.

### **After**

N/A — controller and migration state wiring only.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [x] I've tested on Android
  - Considered not applicable for controller and migration state wiring.
- [x] I've tested with a power user scenario
  - Considered not applicable for controller and migration state wiring.
- [x] I've instrumented key operations with Sentry traces for production
performance metrics
  - Considered not applicable; this does not add a key timed operation.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- Generated with the help of the pr-description AI skill -->

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
pull Bot pushed a commit to AmirulAndalib/metamask-mobile that referenced this pull request Sep 23, 2026
…k#36726)

## **Description**

Detects social profiles linked to an imported SRP from
AuthenticationController profile signals and persists that cohort
marker. When a linked-social wallet was already consolidated before the
signal arrived, this repairs the missing Basic Functionality migration
bottom sheet without rewriting preferences or emitting migration
analytics.

This draft depends on a future `@metamask/profile-sync-controller`
release containing MetaMask/core#10394. The
currently released package does not yet expose persisted
`profile.pairedIdentifierIds`.

## **Changelog**

CHANGELOG entry: Fixed the missing Basic Functionality migration notice
for restored wallets linked to social login profiles

## **Related issues**

Refs: MetaMask/core#10394

## **Manual testing steps**

```gherkin
Feature: Linked-social Basic Functionality migration notice

  Scenario: Restore an SRP previously linked to social login
    Given a wallet was originally onboarded with Google, Apple, or Telegram
    And the same SRP is imported into a fresh installation
    And Basic Functionality is enabled and the wallet was already consolidated
    When AuthenticationController signs in and restores the linked profile metadata
    Then the Basic Functionality migration bottom sheet is scheduled
    And existing Basic Functionality preferences are not rewritten

  Scenario: Do not repeat a dismissed notice
    Given the linked-social migration notice was dismissed
    When the wallet is locked and unlocked again
    Then the migration bottom sheet is not scheduled again
```

## **Screenshots/Recordings**

### **Before**

N/A — controller and migration state wiring only.

### **After**

N/A — controller and migration state wiring only.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [x] I've tested on Android
  - Considered not applicable for controller and migration state wiring.
- [x] I've tested with a power user scenario
  - Considered not applicable for controller and migration state wiring.
- [x] I've instrumented key operations with Sentry traces for production
performance metrics
  - Considered not applicable; this does not add a key timed operation.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- Generated with the help of the pr-description AI skill -->

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
sleepytanya pushed a commit to MetaMask/metamask-mobile that referenced this pull request Sep 24, 2026
)

- fix(bft): repair notice for linked social profiles cp-8.13.0 (#36726)

## **Description**

Detects social profiles linked to an imported SRP from
AuthenticationController profile signals and persists that cohort
marker. When a linked-social wallet was already consolidated before the
signal arrived, this repairs the missing Basic Functionality migration
bottom sheet without rewriting preferences or emitting migration
analytics.

This draft depends on a future `@metamask/profile-sync-controller`
release containing MetaMask/core#10394. The
currently released package does not yet expose persisted
`profile.pairedIdentifierIds`.

## **Changelog**

CHANGELOG entry: Fixed the missing Basic Functionality migration notice
for restored wallets linked to social login profiles

## **Related issues**

Refs: MetaMask/core#10394

## **Manual testing steps**

```gherkin
Feature: Linked-social Basic Functionality migration notice

  Scenario: Restore an SRP previously linked to social login
    Given a wallet was originally onboarded with Google, Apple, or Telegram
    And the same SRP is imported into a fresh installation
    And Basic Functionality is enabled and the wallet was already consolidated
    When AuthenticationController signs in and restores the linked profile metadata
    Then the Basic Functionality migration bottom sheet is scheduled
    And existing Basic Functionality preferences are not rewritten

  Scenario: Do not repeat a dismissed notice
    Given the linked-social migration notice was dismissed
    When the wallet is locked and unlocked again
    Then the migration bottom sheet is not scheduled again
```

## **Screenshots/Recordings**

### **Before**

N/A — controller and migration state wiring only.

### **After**

N/A — controller and migration state wiring only.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding

Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling

guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [x] I've tested on Android
  - Considered not applicable for controller and migration state wiring.
- [x] I've tested with a power user scenario
  - Considered not applicable for controller and migration state wiring.
- [x] I've instrumented key operations with Sentry traces for production
performance metrics
  - Considered not applicable; this does not add a key timed operation.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- Generated with the help of the pr-description AI skill -->

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
[7dca96b](7dca96b)

Co-authored-by: Nidhi Kumari <nidhi.kumari@consensys.net>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Mathieu Artu <mathieu.artu@consensys.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants