Skip to content

fix: retain FCM token when re-enabling notifications with all accounts disabled [GE-516] - #10401

Merged
baptiste-marchand merged 2 commits into
mainfrom
fix/retain-fcm-token-when-account-activity-disabled
Sep 23, 2026
Merged

baptiste-marchand merged 2 commits into
mainfrom
fix/retain-fcm-token-when-account-activity-disabled

Conversation

@baptiste-marchand

@baptiste-marchand baptiste-marchand commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

Fixes push setup when notifications are turned back on but every wallet-activity account stays off. Previously an empty enabled-address list triggered device unregistration, so the locally created FCM token was discarded and a later per-account opt-in had nothing to link.

References

Fixes https://consensyssoftware.atlassian.net/browse/GE-516

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Medium Risk
Changes push registration when no wallet-activity addresses are enabled, but scope is narrow and covered by new tests; Trigger API failures still leave existing links unchanged.

Overview
Fixes push setup when MetaMask notifications are turned back on but every wallet-activity account stays off. Previously an empty enabled-address list caused device unregistration, so the locally created FCM token was dropped and a later per-account opt-in had nothing to link.

NotificationServicesController now always calls push enable (including []) instead of unregistering when no addresses are enabled. activatePushNotifications still creates the FCM registration token but skips the links API when the address list is empty, since that endpoint rejects an empty list without clearing the token.

Tests and the changelog are updated to match the new “register token, link addresses later” behavior for createOnChainTriggers, enableMetamaskNotifications, and enablePushNotifications.

Reviewed by Cursor Bugbot for commit b636cc9. Bugbot is set up for automated code reviews on this repo. Configure here.

…e-enabling notifications with all accounts disabled
@baptiste-marchand
baptiste-marchand requested review from a team as code owners September 23, 2026 13:08
@baptiste-marchand baptiste-marchand changed the title fix: retain FCM token when re-enabling notifications with all accounts disabled fix: retain FCM token when re-enabling notifications with all accounts disabled [GE-516] Sep 23, 2026
@baptiste-marchand
baptiste-marchand added this pull request to the merge queue Sep 23, 2026
Merged via the queue into main with commit a38b8a4 Sep 23, 2026
42 checks passed
@baptiste-marchand
baptiste-marchand deleted the fix/retain-fcm-token-when-account-activity-disabled branch September 23, 2026 14:57
pull Bot pushed a commit to firas9941/metamask-mobile that referenced this pull request Sep 24, 2026
…9.0.1 [GE-516] (MetaMask#36793)

<!--
Please submit this PR as a draft initially.

Do not mark it as "Ready for review" until this PR meets the canonical
Definition of Ready For Review in `docs/readme/ready-for-review.md`.

In short: the template must be materially complete (not just section
titles
present), all status checks must be currently passing, and the only
expected
follow-up commits must be reviewer-driven.
-->
<!--
mms-check directive vocabulary — read by
.github/scripts/shared/pr-template-checks.ts
at module load to build the validation plan. Directives are invisible in
rendered
markdown and must NOT be removed or edited without updating the
validator registry.

  type=text           Section must contain non-placeholder prose.
  type=changelog      Section must have a valid CHANGELOG entry: line.
type=issue-link Section must have a Fixes:/Closes:/Refs: line with a
value.
type=manual-testing Section must have real testing steps or an explicit
N/A.
type=screenshot Section must have evidence (image/URL) or an explicit
N/A.
type=checklist Section must have all checkboxes consciously checked.
required=true|false Whether a missing/invalid section runs the validator
at all.
blocking=true|false Whether a failure of this check fails the CI
workflow.
Default: false — failures are shown as warnings in the sticky
                      comment but do not block the PR.

Sections without a directive are checked for structural presence only.
-->

## **Description**

<!-- mms-check: type=text required=true -->

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

Updates `@metamask/notification-services-controller` from `29.0.0` to
`29.0.1`. There are no client code changes.

That release fixes two notification bugs:

- Turning wallet activity off for an account also deleted that address's
FCM token link, which stopped every notification source for the address.
Account toggles now write only the Trigger API. Push links follow the
accounts this installation holds: they are added when an account is
added, removed when an account is removed, and registered for every
account when notifications are enabled.
- Turning notifications off and back on while wallet activity was
disabled for every account created no FCM token, so push could not be
delivered. The device token is now created and kept in that case.

The next unlock after this build registers push links for every held
account. Wallet-activity subscriptions are left as they are.

## **Changelog**

<!-- mms-check: type=changelog required=true blocking=true -->

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Fixed push notifications stopping for every source when
wallet activity was turned off, and not being registered again when
notifications were re-enabled with every account's wallet activity
disabled

## **Related issues**

<!-- mms-check: type=issue-link required=true -->

Fixes:

Refs: GE-516
Refs: MetaMask/core#10401
Refs: MetaMask/core#10417

## **Manual testing steps**

<!-- mms-check: type=manual-testing required=true -->

```gherkin
Feature: notification push registration

  Scenario: turning off wallet activity for one account leaves other sources linked
    Given notifications are enabled
    And push permission is granted
    And the wallet holds at least two accounts

    When the user opens Settings > Notifications > Wallet activity
    And turns wallet activity off for one account
    Then that account's wallet-activity subscription is updated through the Trigger API
    And the device token stays linked to that account

  Scenario: re-enabling notifications with every wallet-activity account disabled still registers push
    Given notifications are enabled
    And wallet activity is disabled for every account

    When the user turns the main notifications toggle off and then on
    Then a device token is created
    And the token is linked to every account the wallet holds
```

## **Screenshots/Recordings**

<!-- mms-check: type=screenshot required=true -->

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

N/A

### **After**

N/A

## **Pre-merge author checklist**

<!-- mms-check: type=checklist required=true -->

<!--
Every checklist item must be consciously assessed before marking this PR
as
"Ready for review". A checked box means you deliberately considered that
responsibility, not that you literally performed every action listed.

Unchecked boxes are ambiguous: they are not an implicit "N/A" and they
are not
a silent "skip". See `docs/readme/ready-for-review.md` for the full
checklist
semantics.
-->

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [x] I've tested on Android
  - Ideally on a mid-range device; emulator is acceptable
- [x] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [x] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example

For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).

## **Pre-merge reviewer checklist**

<!--
Reviewer checklist items follow the same semantics as the author
checklist: an
unchecked box is ambiguous, a checked box means the reviewer consciously
assessed that responsibility. See `docs/readme/ready-for-review.md`.
-->

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Dependency-only change, but it alters push/FCM linking and
notification enablement paths in a user-facing subsystem; regression
risk is in notification delivery, not app code edits.
> 
> **Overview**
> Bumps **`@metamask/notification-services-controller`** from `29.0.0`
to **`29.0.1`** in `package.json` and refreshes **`yarn.lock`**
(including transitive updates such as
`@metamask/authenticated-user-storage` **4.1.0**). There are **no mobile
app source changes**; behavior comes from the core package patch.
> 
> That release fixes push notification registration: disabling **wallet
activity** for one account no longer removes the device’s **FCM token
link** for that address (only Trigger API subscriptions change), and
toggling notifications off/on when every account has wallet activity
disabled still **creates and links** the device token to held accounts.
After this build ships, the **next unlock** is expected to register push
links for all held accounts without altering existing wallet-activity
subscriptions.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
fb9e2ba. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 24, 2026
## Explanation

Toggling wallet activity for an account was also adding or deleting that
address's FCM token link. Those links are not scoped to wallet activity:
they associate the device token with an address for every notification
source. Turning wallet activity off therefore stopped push for the other
sources as well.

`enableAccounts` and `disableAccounts` now write only the Trigger API,
which is the wallet-activity subscription. FCM links follow the
addresses this installation holds:

- Adding an account links the existing token, and removing an account
unlinks it. This still runs only while the main notifications toggle is
on.
- Enabling notifications, including the daily refresh, registers the
token for every keyring address. A wallet-activity opt-out stays linked,
so other sources keep working, and the next unlock restores links that
an older client deleted.

No client change is required. The public method signatures are
unchanged.

## References

* Related to MetaMask#10401
* Related to MetaMask#8108
* Related to MetaMask#8449

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them


Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
gauthierpetetin added a commit that referenced this pull request Sep 24, 2026
- Remove readonly from #eventPurposes and #eventsConfigVersion private
  fields so #fetchEventsConfig can update them after construction
- Fix changelog PR links from #10401 to #10448 in both packages

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
pull Bot pushed a commit to Reality2byte/metamask-extension that referenced this pull request Sep 24, 2026
…9.0.1 [GE-516] (MetaMask#46616)

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

Updates `@metamask/notification-services-controller` from `29.0.0` to
`29.0.1`. There are no extension code changes.

That release fixes two notification bugs:

- Turning wallet activity off for an account also deleted that address's
FCM token link, which stopped every notification source for the address.
Account toggles now write only the Trigger API. Push links follow the
accounts this installation holds: they are added when an account is
added, removed when an account is removed, and registered for every
account when notifications are enabled.
- Turning notifications off and back on while wallet activity was
disabled for every account created no FCM token, so push could not be
delivered. The device token is now created and kept in that case.

The next unlock after this build registers push links for every held
account. Wallet-activity subscriptions are left as they are.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Fixed push notifications stopping for every source when
wallet activity was turned off, and not being registered again when
notifications were re-enabled with every account's wallet activity
disabled

## **Related issues**

Fixes:

Refs: GE-516
Refs: MetaMask/core#10401
Refs: MetaMask/core#10417

## **Manual testing steps**

1. Load this build and unlock a wallet that holds at least two accounts.
2. Open Settings > Notifications and turn notifications on.
3. Open Wallet activity and turn it off for one account. Confirm the
request updates the Trigger API and does not delete that address's FCM
token link.
4. Turn wallet activity off for every account.
5. Turn the main notifications toggle off, then on again.
6. Confirm a device token is created and linked to every account,
including accounts whose wallet activity is off.

<!--
## **Screenshots/Recordings**
### **Before**
### **After**
-->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Transitive keyring and authenticated-storage dependency updates plus
LavaMoat allowance changes around `@metamask/utils` and keyring paths
warrant policy review, though runtime behavior is intended to fix
notification registration bugs only.
> 
> **Overview**
> Bumps **`@metamask/notification-services-controller`** from `29.0.0`
to **`29.0.1`** in `package.json` / `yarn.lock`, with no extension
application code changes. The lockfile also picks up related transitive
bumps (e.g. **`@metamask/authenticated-user-storage` 4.1.0**,
**`@metamask/keyring-controller` 28.1.0**,
**`@metamask/profile-sync-controller` 32.3.1**) as required by that
release.
> 
> **LavaMoat** webpack policies for all MV2/MV3 build flavors are
updated to match the new dependency graph: `@metamask/utils` is
referenced on shorter paths for several controllers (e.g. bridge-status,
profile-sync, wallet keyring entries), a scoped entry is added for
authenticated-user-storage → controller-utils → utils,
**`@metamask/bridge-status-controller>@metamask/utils`** gains `Buffer`
/ text encoding globals plus `@scure/base` and `buffer`, and redundant
**`keyring-controller>@metamask/utils`** policy blocks are removed or
renamed (e.g. profile-metrics).
> 
> The upstream patch fixes notification push behavior: disabling wallet
activity for an account no longer removes that address’s FCM link (only
Trigger API is updated), and re-enabling notifications after all
accounts had wallet activity off still registers device tokens and links
for held accounts.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
5ccf28e. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: MetaMask Bot <metamaskbot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants