Repository navigation
feat: extend the RWA token API types for security metadata - #10542
Merged
Merged
Conversation
ameliejyc
marked this pull request as ready for review
September 28, 2026 17:56
Prithpal-Sooriya
approved these changes
Sep 28, 2026
7 tasks
pull Bot
pushed a commit
to Ramyromel/metamask-extension
that referenced
this pull request
Sep 29, 2026
<!-- Please submit this PR as a draft initially. Do not mark it as "Ready for review" until the template has been completely filled out, and PR status checks have passed at least once. --> ## **Description** Adds trust signal badges to RWAs. The changes to the RWA token types have been made in [core](MetaMask/core#10542) but not yet released, so the types written here can be updated at a later date. ## **Changelog** <!-- If this PR is not End-User-Facing and should not show up in the CHANGELOG, you can choose to either: 1. Write `CHANGELOG entry: null` 2. Label with `no-changelog` If this PR is End-User-Facing, please write a short User-Facing description in the past tense like: `CHANGELOG entry: Added a new tab for users to see their NFTs` `CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker` (This helps the Release Engineer do their job more quickly and accurately) --> CHANGELOG entry: Adds trust signal badges to RWAs ## **Related issues** Fixes: https://consensyssoftware.atlassian.net/browse/CEUX-1352 ## **Manual testing steps** 1. Click the search icon on homepage 2. Click on the Stocks tab 3. Verify that stocks show a trust badge at the end of the token name 4. Spot check against the api e.g. `https://token.api.cx.metamask.io/v1/rwas?query=abcl&includeTokenSecurityData=true` swapping out the token name to make sure the `securityData.resultType` matches what's shown in the UI ## **Screenshots/Recordings** <!-- If applicable, add screenshots and/or recordings to visualize the before and after of your change. --> ### **Before** <img width="472" height="793" alt="image" src="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/user-attachments/assets/8880c48c-105c-4d2c-b48e-89fa5d89728c" /> ### **After** <img width="439" height="766" alt="image" src="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/user-attachments/assets/09ebaff6-6da8-46cd-93d4-175557a2a392" /> ## **Pre-merge author checklist** - [ ] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Extension Coding Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [ ] I've completed the PR template to the best of my ability - [ ] I’ve included tests if applicable - [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [ ] I’ve applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.
cryptodev-2s
pushed a commit
to cryptodev-2s/core
that referenced
this pull request
Oct 5, 2026
## Explanation This release candidate publishes: - `@metamask/phishing-controller` `18.2.0` - `@metamask/assets-controllers` `112.1.0` `@metamask/phishing-controller` adds optional request-source attribution for URL scans. `NftController` in `@metamask/assets-controllers` adopts that API for NFT metadata scans using the `nft-detection` source. The assets-controllers minor release also includes its existing additive consumer-facing changes, including optional RWA token security metadata, as documented in its changelog. No breaking API changes are included. The assets-controllers dependency range is updated to consume `@metamask/phishing-controller@^18.2.0`. ## References - Related to MetaMask#10357 - Related to MetaMask#10542 ## Checklist - [x] I've updated the test suite for new or updated code as appropriate - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by updating changelogs for packages I've changed - [ ] I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Release-only dependency and version updates with additive, optional phishing attribution APIs and no breaking changes called out in this PR. > > **Overview** > This PR cuts **monorepo release 1307.0.0** by publishing **`@metamask/phishing-controller@18.2.0`** and **`@metamask/assets-controllers@112.1.0`**, then wiring dependents to those versions. > > **`@metamask/phishing-controller@18.2.0`** (documented in its changelog) adds optional **request-source** parameters on `scanUrl` / `bulkScanUrls`, which set an **`x-request-source`** header on phishing URL scans. > > **`@metamask/assets-controllers@112.1.0`** rolls that dependency forward and records **`NftController`** passing the **`nft-detection`** source on **`PhishingController:bulkScanUrls`** so NFT metadata URL checks are tagged separately in service metrics. The same release line also captures already-shipped additive API work (e.g. optional RWA **`securityData`** when **`includeTokenSecurityData`** is used). > > **`@metamask/assets-controller`** and **`@metamask/bridge-controller`** bump their **`@metamask/assets-controllers`** and **`@metamask/phishing-controller`** ranges; **`yarn.lock`** and changelog compare links are updated accordingly. No application source changes appear in this diff—only versioning, changelogs, and lockfile alignment. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 6a4ff12. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation
Extends the RWA token API types so callers can opt into security metadata on fetch and receive it on each token in the response. This is so on the client we can show trust signal badges on RWA token discovery.
References
Relates to https://consensyssoftware.atlassian.net/browse/CEUX-1352
Checklist
Note
Low Risk
Additive optional TypeScript fields and changelog only; no runtime logic changes in the diff.
Overview
Extends the RWA token API types so callers can opt into security metadata on fetch and receive it on each token in the response.
FetchRwasParamsgains an optionalincludeTokenSecurityDataflag (aligned with existing token search/trending options).RwaTokengains an optionalsecurityDatafield typed asTokenSecurityData, filled when that flag is used. The changelog documents both additions under Unreleased.Reviewed by Cursor Bugbot for commit d8819e1. Bugbot is set up for automated code reviews on this repo. Configure here.