Skip to content

feat(money): loosen money account api response validation - #10538

Merged
ffmcgee725 merged 1 commit into
mainfrom
jc/refactor-money-account-data-service-structs
Sep 28, 2026
Merged

ffmcgee725 merged 1 commit into
mainfrom
jc/refactor-money-account-data-service-structs

Conversation

@ffmcgee725

@ffmcgee725 ffmcgee725 commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Explanation

  • Loosen Money Account API response validation in @metamask/money-account-api-data-service by switching all ten superstruct schemas from object() to type().
  • Additive backend fields no longer throw MoneyAccountApiResponseValidationError; unknown keys are passed through at runtime and are not part of the exported response types.
  • Required fields, field types, and enum values are still validated as before.

Changelog

@metamask/money-account-api-data-service

[Unreleased]

Changed

  • Response validation now tolerates unknown fields returned by the Money Account API instead of throwing MoneyAccountApiResponseValidationError, so additive backend changes no longer break clients (#0)
    • Unknown fields are passed through on the returned object but are not part of the exported response types.

Test plan

  • yarn workspace @metamask/money-account-api-data-service run test --coverage (100% statements, branches, functions, lines)
  • yarn workspace @metamask/money-account-api-data-service run changelog:validate
  • yarn oxlint packages/money-account-api-data-service (Node 24+)

Note

Low Risk
Forward-compatible validation loosening only; malformed or missing required fields still fail validation as before.

Overview
@metamask/money-account-api-data-service now treats additive Money Account API JSON as valid instead of failing client fetches.

All response superstruct schemas in structs.ts switch from object() to type(), so extra keys no longer trigger MoneyAccountApiResponseValidationError. Unknown properties are returned on the parsed result (not stripped); exported TypeScript response types are unchanged. Required fields, types, and enum values are still enforced.

New integration tests cover positions, interest, history, rate-history, and vault-rate responses with nested unknown fields. The package changelog documents the behavior under [Unreleased] → Changed.

Reviewed by Cursor Bugbot for commit 8b2cfeb. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

No dependency changes detected. Learn more about Socket for GitHub.

👍 No dependency changes detected in pull request

@ffmcgee725
ffmcgee725 force-pushed the jc/refactor-money-account-data-service-structs branch from 59f86d7 to 96bff01 Compare September 28, 2026 15:32
@ffmcgee725
ffmcgee725 added this pull request to stack #10540 September 28, 2026 15:35
@ffmcgee725
ffmcgee725 marked this pull request as ready for review September 28, 2026 15:39
@ffmcgee725
ffmcgee725 requested review from a team as code owners September 28, 2026 15:39
@ffmcgee725
ffmcgee725 deployed to default-branch September 28, 2026 15:40 — with GitHub Actions Active
Matt561
Matt561 previously approved these changes Sep 28, 2026
Base automatically changed from jc/MUSD-1376 to main September 28, 2026 19:01
@ffmcgee725
ffmcgee725 force-pushed the jc/refactor-money-account-data-service-structs branch from 73e06c1 to 8b2cfeb Compare September 28, 2026 19:03
@ffmcgee725
ffmcgee725 added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 73dc0ef Sep 28, 2026
60 checks passed
@ffmcgee725
ffmcgee725 deleted the jc/refactor-money-account-data-service-structs branch September 28, 2026 19:09
@ffmcgee725

Copy link
Copy Markdown
Member Author

@metamaskbot publish-preview

@ffmcgee725 ffmcgee725 mentioned this pull request Sep 28, 2026
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 29, 2026
## @metamask/money-account-api-data-service

## [2.1.0]

### Added

- Add `fetchVaultRate`, which reads a vault's current Accountant
exchange rate from `GET /v1/vaults/:address/rate` and is exposed as the
`MoneyAccountApiDataService:fetchVaultRate` action. Export
`VaultRateResponse`, `VaultRateOptions`, and
`MoneyAccountApiDataServiceFetchVaultRateAction`
([MetaMask#10504](MetaMask#10504))

### Changed

- Response validation now tolerates unknown fields returned by the Money
Account API instead of throwing
`MoneyAccountApiResponseValidationError`, so additive backend changes no
longer break clients
([MetaMask#10538](MetaMask#10538))
- Bump `@tanstack/query-core` from `^5.89.0` to `^5.103.2`
([MetaMask#10511](MetaMask#10511))

## @metamask/money-account-balance-service

## [3.1.1]

### Changed

- Bump `@metamask/money-account-api-data-service` from `^2.0.0` to
`^2.1.0` ([MetaMask#10544](MetaMask#10544))

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants