-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
fix: Add PPOM validation for deeplink requests #22473
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+181
−34
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
OGPoyraz
commented
Nov 11, 2025
|
|
||
| // Temporary solution for preventing back to back deeplink requests | ||
| if (isAddingDeeplinkTransaction) { | ||
| Logger.error(new Error('Cannot add another deeplink transaction')); |
Member
Author
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is causing false positives in the Sentry logs - hence we are decreasing it to log instead of error.
See comment here: #17358 (comment)
|
vinistevam
approved these changes
Nov 12, 2025
tommasini
approved these changes
Nov 12, 2025
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
release-7.60.0
Issue or pull request that will be included in release 7.60.0
size-M
team-confirmations
Push issues to confirmations team
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.



Description
This PR aims to add PPOM validation requests for deeplinks.
Changelog
CHANGELOG entry: null
Related issues
Fixes: https://github.com/MetaMask/mobile-planning/issues/2370
Fixes: #17358
Manual testing steps
Screenshots/Recordings
Before
After
Pre-merge author checklist
Pre-merge reviewer checklist
Note
Integrates PPOM validation into deeplink transfer/approve flows, generating a securityAlertId and passing it to addTransaction, with refactors and tests.
app/components/Views/confirmations/utils/deeplink.ts):validateWithPPOMto build a PPOM request (with uuid-basedsecurityAlertId) and callppomUtil.validateRequest.securityAlertResponsetoaddTransactionfor both native and ERC20 transfers.txParamsandtransactionType; downgrade duplicate-request log from error to log.app/core/DeeplinkManager/TransactionManager/approveTransaction.ts):chainId/networkClientId, callvalidateWithPPOM, and includesecurityAlertResponseinaddTransaction.securityAlertResponse, andnetworkClientIdwiring.Written by Cursor Bugbot for commit daa4941. This will update automatically on new commits. Configure here.