Skip to content

[DON'T MERGE] Bump authenticated-user-storage to use mutations for persisting watchlist - #36083

Draft
mcmire wants to merge 1 commit into
mainfrom
test-execute-mutation
Draft

mcmire wants to merge 1 commit into
mainfrom
test-execute-mutation

Conversation

@mcmire

@mcmire mcmire commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

This PR bumps @metamask/authenticated-user-storage and @metamask/base-data-service to preview versions where AuthenticatedUserStorageService.setAssetsWatchlist uses executeMutation — a new method in BaseDataService — to make the underlying API request.

Also see MetaMask/core#9324 for the changes to BaseDataService which make this possible.

This PR will be removed once this smoke test is complete.

Manual testing steps

  1. Check out this branch and run yarn watch:clean.
  2. Open your emulator, then open MetaMask.
  3. Load the home screen.
  4. Scroll down to Watchlist and tap on the header.
  5. Tap on the Edit button in the corner.
  6. Reorder the list of tokens by holding down on the scrub icon until the row grows bigger and then dragging up or down. Then tap Done.
  7. Observe the following lines in your terminal:
    LOG  [useTokenWatchlistUpdateListMutation] Calling writeToTokenWatchList...
    LOG  [writeToTokenWatchList] Calling AuthenticatedUserStorageService:setAssetsWatchlist...
    LOG  [useTokenWatchlistUpdateListMutation] FINISHED calling writeToTokenWatchList
    
  8. This proves that the messenger call continues to work without producing any errors.
  9. Go back to the home screen and pull down to refresh.
  10. Scroll back down to Watchlist. Your tokens should be in the same order that you arranged them in.

@github-actions

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamask-ci metamask-ci Bot added team-core-platform Core Platform team INVALID-PR-TEMPLATE PR's body doesn't match template labels Sep 10, 2026
@metamask-ci

metamask-ci Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

PR template — items to address before "Ready for review"

Warnings — informational, address before merging:

See docs/readme/ready-for-review.md for the full Definition of Ready for Review.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​metamask-previews/​base-data-service@​1.0.0-preview-8bfa290fb821007598100
Addednpm/​@​metamask-previews/​authenticated-user-storage@​3.0.2-preview-8bfa290fb7910010098100

View full report

@socket-security

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Network access: npm @metamask-previews/authenticated-user-storage in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: package.json → npm/@metamask-previews/authenticated-user-storage@3.0.2-preview-8bfa290fb

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@metamask-previews/authenticated-user-storage@3.0.2-preview-8bfa290fb. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @metamask-previews/base-data-service in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: package.json → npm/@metamask-previews/base-data-service@1.0.0-preview-8bfa290fb

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@metamask-previews/base-data-service@1.0.0-preview-8bfa290fb. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

Copy link
Copy Markdown
Contributor

🔍 Smart E2E Test Selection

  • Selected E2E tags: None (no tests recommended)
  • Selected Performance tags: None (no tests recommended)
  • Risk Level: low
  • AI Confidence: 97%
click to see 🤖 AI reasoning details

E2E Test Selection:
All changes in this PR are cosmetic or non-functional:

  1. useTokenWatchlistMutations.ts: Only adds two console.log statements around the writeToTokenWatchList call. Per the cosmetic changes rule, adding/removing console.log calls have zero functional impact and must NOT trigger any additional test selection.

  2. storage.ts: Only adds one console.log statement before the Engine.controllerMessenger.call. Same cosmetic change rule applies.

  3. package.json: Adds a previewBuilds metadata section for @metamask/base-data-service and @metamask/authenticated-user-storage. This is a metadata annotation section (not a dependencies, devDependencies, or peerDependencies change) that does not alter any actually installed package versions. No functional dependency changes were made.

  4. yarn.lock: Likely reflects the package.json metadata change, but no actual dependency resolution changes.

Since all changes are either cosmetic (console.log additions) or non-functional metadata (previewBuilds section), no E2E tests need to be run.

Performance Test Selection:
All changes are cosmetic (console.log additions) or non-functional metadata (previewBuilds section in package.json). No performance-sensitive code paths were modified. No performance tests are warranted.

View GitHub Actions results

@sonarqubecloud

Copy link
Copy Markdown

pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 23, 2026
…taMask#9324)

## Explanation

<!--
Thanks for your contribution! Take a moment to answer these questions so
that reviewers have the information they need to properly understand
your changes:

* What is the current state of things and why does it need to change?
* What is the solution your changes offer and how does it work?
* Are there any changes whose purpose might not obvious to those
unfamiliar with the domain?
* If your primary goal was to update one package but you found you had
to update another one along the way, why did you do so?
* If you had to upgrade a dependency, why did you do so?
-->

Currently, `BaseDataService` has a `fetchQuery` method which is best
used for making read-only requests ("queries" in TanStack Query
parlance), but does not work as well for requests that change state on
the server side ("mutations"). For instance, it makes sense for queries
to be cached and retried, but not so much for mutations.

This commit adds a separate method, `executeMutation`, which
accommodates mutations better. Besides the differences mentioned above,
it also uses the mutation cache instead of the query cache.

## References

<!--
Are there any issues that this pull request is tied to?
Are there other links that reviewers should consult to understand these
changes better?
Are there client or consumer pull requests to adopt any breaking
changes?

For example:

* Fixes #12345
* Related to #67890
-->

Closes https://consensyssoftware.atlassian.net/browse/WPC-1118.

## Manual testing

I've created MetaMask#10176, which converts
`AuthenticatedUserStorageService.setAssetsWatchlist` to use
`executeMutation` under the hood, and
MetaMask/metamask-mobile#36083, which loads
those changes into the mobile app. You can check out the mobile branch
and run through the manual testing steps there to confirm that
`executeMutation` still exhibits the same basic behavior as
`fetchQuery`.

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them



<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes shared cache/event contracts (`objectType`, mutation sync) and
introduces server-mutating paths; incorrect retry or hydration behavior
could cause duplicate writes or stale UI state, though mutations are
explicitly non-retried.
> 
> **Overview**
> Adds **mutation support** alongside existing query flows in
`BaseDataService` and `@metamask/react-data-query`, so write requests no
longer go through query-style caching and retries.
> 
> **`BaseDataService`** gains a protected **`executeMutation`** API
(plus exported **`MutationKey`**) that runs through TanStack’s mutation
cache, optional Superstruct validation via
**`processMutationResponse`**, and **no retry policy** (only the circuit
breaker runs the request). Mutations can carry a **`globalId`** (default
UUID) in `meta` to correlate with the UI client. **`:cacheUpdated`**
payloads now include **`objectType: 'query' | 'mutation'`**, and
mutation cache lifecycle is wired into persistence, dehydration, and
**`destroy()`** (including clearing mutation GC timers).
> 
> **`react-data-query`** exposes **`useMutation`** (retries off by
default), routes data-service mutations through the messenger with the
UI’s **`globalId`**, and syncs service-side mutation state via
**`hydrateMutations`** on **`updated`** cache events only (so idle
`added` events do not clobber settled UI results).
> 
> **`@tanstack/query-core`** (and **`@tanstack/react-query`**) are
bumped to **`^5.89.0`** across dependent packages; **`uuid`** is added
where mutation IDs are minted.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
2bc6446. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

INVALID-PR-TEMPLATE PR's body doesn't match template size-S team-core-platform Core Platform team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant