Skip to content

fix: MM Pay transaction with isQuoteRequired that have same source and destination chain and token - #9150

Merged
jpuri merged 11 commits into
mainfrom
same_token_withdraw_fix
Jun 18, 2026
Merged

jpuri merged 11 commits into
mainfrom
same_token_withdraw_fix

Conversation

@jpuri

@jpuri jpuri commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

Fix MM Pay transaction with isQuoteRequired that have same source and destination chain and token

References

Related to https://consensyssoftware.atlassian.net/browse/CONF-1548

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Medium Risk
Touches MM Pay quote eligibility and Relay request identity for accountOverride post-quote paths; scoped logic with tests, but incorrect user/source handling could break pay execution.

Overview
Fixes MM Pay post-quote flows where source and destination are the same chain and token but isQuoteRequired still needs a Relay quote (previously those legs were dropped or quoted with the wrong user).

Source amounts: Post-quote calculatePostQuoteSourceAmounts no longer skips identical source/target tokens when isQuoteRequired is set, so quote retrieval can run instead of ending with empty sourceAmounts.

Relay quotes: Quote bodies now set user via getQuoteUser. For same-chain/same-token with an active accountOverride and recipient equal to the override wallet, user is txParams.from (the real sender); external recipients or cross-chain/token cases keep using the resolved from address.

Changelog and unit tests cover both behaviors.

Reviewed by Cursor Bugbot for commit 35456e2. Bugbot is set up for automated code reviews on this repo. Configure here.

@jpuri
jpuri requested a review from a team as a code owner June 16, 2026 14:20
@jpuri
jpuri temporarily deployed to default-branch June 16, 2026 14:20 — with GitHub Actions Inactive
@jpuri
jpuri requested a review from a team as a code owner June 16, 2026 14:23
@jpuri
jpuri enabled auto-merge June 16, 2026 14:23
@matthewwalsh0
matthewwalsh0 requested a review from vinistevam June 17, 2026 10:53
vinistevam
vinistevam previously approved these changes Jun 17, 2026
const hasAccountOverride =
txParamsFrom && from.toLowerCase() !== txParamsFrom.toLowerCase();

return isSameSourceAndTarget && hasAccountOverride ? txParamsFrom : from;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the condition also that the recipient matches the account override?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, I updated PR to include the condition.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0853289. Configure here.

@jpuri
jpuri requested a review from matthewwalsh0 June 18, 2026 08:34
@jpuri
jpuri added this pull request to the merge queue Jun 18, 2026
Merged via the queue into main with commit 5b161bd Jun 18, 2026
380 checks passed
@jpuri
jpuri deleted the same_token_withdraw_fix branch June 18, 2026 08:43
@cursor cursor Bot mentioned this pull request Jun 18, 2026
4 tasks done
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Jun 18, 2026
…aMask#9187)

## Explanation

Fix small issue introduced by
[PR](MetaMask#9150)

## References

<!--
Are there any issues that this pull request is tied to?
Are there other links that reviewers should consult to understand these
changes better?
Are there client or consumer pull requests to adopt any breaking
changes?

For example:

* Fixes #12345
* Related to #67890
-->

## Checklist

- [X] I've updated the test suite for new or updated code as appropriate
- [X] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [X] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [X] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Wrong Relay `user` can break quote or execute paths for MM Pay
post-quote delegation flows; the change is narrow and covered by a new
test.
> 
> **Overview**
> Fixes a regression from the post-quote same-chain/same-token work
where **`getQuoteUser`** always rewrote the Relay request **`user`** to
**`txParams.from`** when an account override matched the recipient.
> 
> **`getQuoteUser`** now only applies that rewrite when
**`!request.isPostQuote`**, so post-quote same-chain/same-token
transfers with an override keep **`user`** as the override account
(`from`). A unit test covers the post-quote + override case.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
9c8410b. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
geositta added a commit that referenced this pull request Jun 18, 2026
* main: (497 commits)
  Release/1053.0.0 (#9195)
  Revert @metamask/transaction-pay-controller changes not required (#9194)
  chore: add discovery event names (#9178)
  chore: deprecate CurrencyRateController (#9182)
  Release/1052.0.0 (#9188)
  fix: getQuoteUser function is broken if request is not postQuote (#9187)
  fix(network-controller): Remove deprecated NetworkControllerGetNetworkConfigurationByNetworkClientId type (#9185)
  fix(network-controller): Remove MegaETH v1 default configuration (#9183)
  Release/1051.0.0 (#9181)
  fix: MM Pay transaction with isQuoteRequired that have same source and destination chain and token (#9150)
  Release/1050.0.0 (#9180)
  fix(network-controller): Only consider failover endpoints when using Infura (#9125)
  feat(assets-controllers): add isDeprecated to multichain controllers (#9044)
  refactor(smart-transactions-controller): import AuthenticationController namespace (#9167)
  Release 1049.0.0 (#9177)
  fix(transaction-pay-controller): vault musd via sentinel (#9161)
  Release 1048.0.0 (#9174)
  chore: remove orphaned semver.sh helper (#9172)
  fix(rpc-service): Consider all Infura HTTP errors as service failures except 400 and 429 (#9123)
  chore: remove outdated migrate-tags guide (#9171)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants