fix: MM Pay transaction with isQuoteRequired that have same source and destination chain and token - #9150
Merged
Conversation
…d destination chain and token
jpuri
enabled auto-merge
June 16, 2026 14:23
vinistevam
previously approved these changes
Jun 17, 2026
matthewwalsh0
requested changes
Jun 17, 2026
| const hasAccountOverride = | ||
| txParamsFrom && from.toLowerCase() !== txParamsFrom.toLowerCase(); | ||
|
|
||
| return isSameSourceAndTarget && hasAccountOverride ? txParamsFrom : from; |
Member
There was a problem hiding this comment.
Is the condition also that the recipient matches the account override?
Contributor
Author
There was a problem hiding this comment.
Good point, I updated PR to include the condition.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 0853289. Configure here.
…/core into same_token_withdraw_fix
matthewwalsh0
approved these changes
Jun 18, 2026
4 tasks done
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Jun 18, 2026
…aMask#9187) ## Explanation Fix small issue introduced by [PR](MetaMask#9150) ## References <!-- Are there any issues that this pull request is tied to? Are there other links that reviewers should consult to understand these changes better? Are there client or consumer pull requests to adopt any breaking changes? For example: * Fixes #12345 * Related to #67890 --> ## Checklist - [X] I've updated the test suite for new or updated code as appropriate - [X] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [X] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [X] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Wrong Relay `user` can break quote or execute paths for MM Pay post-quote delegation flows; the change is narrow and covered by a new test. > > **Overview** > Fixes a regression from the post-quote same-chain/same-token work where **`getQuoteUser`** always rewrote the Relay request **`user`** to **`txParams.from`** when an account override matched the recipient. > > **`getQuoteUser`** now only applies that rewrite when **`!request.isPostQuote`**, so post-quote same-chain/same-token transfers with an override keep **`user`** as the override account (`from`). A unit test covers the post-quote + override case. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 9c8410b. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
4 tasks done
geositta
added a commit
that referenced
this pull request
Jun 18, 2026
* main: (497 commits) Release/1053.0.0 (#9195) Revert @metamask/transaction-pay-controller changes not required (#9194) chore: add discovery event names (#9178) chore: deprecate CurrencyRateController (#9182) Release/1052.0.0 (#9188) fix: getQuoteUser function is broken if request is not postQuote (#9187) fix(network-controller): Remove deprecated NetworkControllerGetNetworkConfigurationByNetworkClientId type (#9185) fix(network-controller): Remove MegaETH v1 default configuration (#9183) Release/1051.0.0 (#9181) fix: MM Pay transaction with isQuoteRequired that have same source and destination chain and token (#9150) Release/1050.0.0 (#9180) fix(network-controller): Only consider failover endpoints when using Infura (#9125) feat(assets-controllers): add isDeprecated to multichain controllers (#9044) refactor(smart-transactions-controller): import AuthenticationController namespace (#9167) Release 1049.0.0 (#9177) fix(transaction-pay-controller): vault musd via sentinel (#9161) Release 1048.0.0 (#9174) chore: remove orphaned semver.sh helper (#9172) fix(rpc-service): Consider all Infura HTTP errors as service failures except 400 and 429 (#9123) chore: remove outdated migrate-tags guide (#9171) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Explanation
Fix MM Pay transaction with isQuoteRequired that have same source and destination chain and token
References
Related to https://consensyssoftware.atlassian.net/browse/CONF-1548
Checklist
Note
Medium Risk
Touches MM Pay quote eligibility and Relay request identity for accountOverride post-quote paths; scoped logic with tests, but incorrect user/source handling could break pay execution.
Overview
Fixes MM Pay post-quote flows where source and destination are the same chain and token but
isQuoteRequiredstill needs a Relay quote (previously those legs were dropped or quoted with the wronguser).Source amounts: Post-quote
calculatePostQuoteSourceAmountsno longer skips identical source/target tokens whenisQuoteRequiredis set, so quote retrieval can run instead of ending with emptysourceAmounts.Relay quotes: Quote bodies now set
userviagetQuoteUser. For same-chain/same-token with an activeaccountOverrideand recipient equal to the override wallet,useristxParams.from(the real sender); external recipients or cross-chain/token cases keep using the resolvedfromaddress.Changelog and unit tests cover both behaviors.
Reviewed by Cursor Bugbot for commit 35456e2. Bugbot is set up for automated code reviews on this repo. Configure here.