Skip to content

Conversation

@lwin-kyaw
Copy link
Contributor

@lwin-kyaw lwin-kyaw commented Oct 30, 2025

Explanation

Fixed Invalid Revoke Token.

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed, highlighting breaking changes as necessary
  • I've prepared draft pull requests for clients and consumer packages to resolve any breaking changes

Note

Makes revokeToken optional in authenticate, retrieves access/revoke tokens from vault when missing, hardens validation/expiry checks, and fixes InvalidRevokeToken during token refresh.

  • Seedless Onboarding Controller:
    • Make authenticate param revokeToken optional and stop passing it on refresh re-auth.
    • Add #getAccessTokenAndRevokeToken(password) to source tokens from state or decrypted vault; throw InvalidAccessToken/InvalidRevokeToken if absent.
    • Use new helper in #createNewVaultWithAuthData; improve error logging.
    • Treat missing access token as expired in checkAccessTokenExpired.
    • Replace internal assertIsAuthUserInfoValid usage with #assertIsAuthenticatedUser.
  • Assertions & Types:
    • Simplify assertIsSeedlessOnboardingUserAuthenticated; remove revoke/access checks from auth assertion.
    • Require revokeToken in VaultData and throw specific errors for missing/invalid accessToken/revokeToken in assertIsValidVaultData.
    • Remove revokeToken/accessToken from AuthenticatedUserDetails type.
  • Token Refresh:
    • In refreshAuthTokens, re-authenticate with refreshed tokens without revokeToken.
  • Tests:
    • Update/add tests for missing tokens, vault-driven token retrieval, and expiry checks; adjust expectations to new error types and ordering.
  • Docs:
    • Update CHANGELOG.md with the above changes and the fix for InvalidRevokeToken in refreshAuthTokens.

Written by Cursor Bugbot for commit cc7e30d. This will update automatically on new commits. Configure here.

@lwin-kyaw lwin-kyaw requested review from a team as code owners October 30, 2025 17:57
cursor[bot]

This comment was marked as outdated.

@lwin-kyaw
Copy link
Contributor Author

@metamaskbot publish-preview

@github-actions
Copy link
Contributor

Preview builds have been published. See these instructions for more information about preview builds.

Expand for full list of packages and versions.
{
  "@metamask-previews/account-tree-controller": "2.0.0-preview-79b6f72",
  "@metamask-previews/accounts-controller": "34.0.0-preview-79b6f72",
  "@metamask-previews/address-book-controller": "7.0.0-preview-79b6f72",
  "@metamask-previews/announcement-controller": "8.0.0-preview-79b6f72",
  "@metamask-previews/app-metadata-controller": "2.0.0-preview-79b6f72",
  "@metamask-previews/approval-controller": "8.0.0-preview-79b6f72",
  "@metamask-previews/assets-controllers": "85.0.0-preview-79b6f72",
  "@metamask-previews/base-controller": "9.0.0-preview-79b6f72",
  "@metamask-previews/bridge-controller": "57.0.0-preview-79b6f72",
  "@metamask-previews/bridge-status-controller": "57.0.0-preview-79b6f72",
  "@metamask-previews/build-utils": "3.0.4-preview-79b6f72",
  "@metamask-previews/chain-agnostic-permission": "1.2.2-preview-79b6f72",
  "@metamask-previews/composable-controller": "12.0.0-preview-79b6f72",
  "@metamask-previews/controller-utils": "11.15.0-preview-79b6f72",
  "@metamask-previews/core-backend": "4.0.0-preview-79b6f72",
  "@metamask-previews/delegation-controller": "1.0.0-preview-79b6f72",
  "@metamask-previews/earn-controller": "9.0.0-preview-79b6f72",
  "@metamask-previews/eip-5792-middleware": "2.0.0-preview-79b6f72",
  "@metamask-previews/eip-7702-internal-rpc-middleware": "0.1.0-preview-79b6f72",
  "@metamask-previews/eip1193-permission-middleware": "1.0.2-preview-79b6f72",
  "@metamask-previews/ens-controller": "18.0.0-preview-79b6f72",
  "@metamask-previews/error-reporting-service": "3.0.0-preview-79b6f72",
  "@metamask-previews/eth-block-tracker": "14.0.0-preview-79b6f72",
  "@metamask-previews/eth-json-rpc-middleware": "21.0.0-preview-79b6f72",
  "@metamask-previews/eth-json-rpc-provider": "5.0.1-preview-79b6f72",
  "@metamask-previews/foundryup": "1.0.1-preview-79b6f72",
  "@metamask-previews/gas-fee-controller": "25.0.0-preview-79b6f72",
  "@metamask-previews/gator-permissions-controller": "0.3.0-preview-79b6f72",
  "@metamask-previews/json-rpc-engine": "10.1.1-preview-79b6f72",
  "@metamask-previews/json-rpc-middleware-stream": "8.0.8-preview-79b6f72",
  "@metamask-previews/keyring-controller": "24.0.0-preview-79b6f72",
  "@metamask-previews/logging-controller": "7.0.0-preview-79b6f72",
  "@metamask-previews/message-manager": "14.0.0-preview-79b6f72",
  "@metamask-previews/messenger": "0.3.0-preview-79b6f72",
  "@metamask-previews/multichain-account-service": "2.0.0-preview-79b6f72",
  "@metamask-previews/multichain-api-middleware": "1.2.4-preview-79b6f72",
  "@metamask-previews/multichain-network-controller": "2.0.0-preview-79b6f72",
  "@metamask-previews/multichain-transactions-controller": "6.0.0-preview-79b6f72",
  "@metamask-previews/name-controller": "9.0.0-preview-79b6f72",
  "@metamask-previews/network-controller": "25.0.0-preview-79b6f72",
  "@metamask-previews/network-enablement-controller": "3.1.0-preview-79b6f72",
  "@metamask-previews/notification-services-controller": "19.0.0-preview-79b6f72",
  "@metamask-previews/permission-controller": "12.1.0-preview-79b6f72",
  "@metamask-previews/permission-log-controller": "5.0.0-preview-79b6f72",
  "@metamask-previews/phishing-controller": "15.0.0-preview-79b6f72",
  "@metamask-previews/polling-controller": "15.0.0-preview-79b6f72",
  "@metamask-previews/preferences-controller": "21.0.0-preview-79b6f72",
  "@metamask-previews/profile-sync-controller": "26.0.0-preview-79b6f72",
  "@metamask-previews/rate-limit-controller": "7.0.0-preview-79b6f72",
  "@metamask-previews/remote-feature-flag-controller": "2.0.0-preview-79b6f72",
  "@metamask-previews/sample-controllers": "3.0.0-preview-79b6f72",
  "@metamask-previews/seedless-onboarding-controller": "6.0.0-preview-79b6f72",
  "@metamask-previews/selected-network-controller": "25.0.0-preview-79b6f72",
  "@metamask-previews/shield-controller": "1.1.0-preview-79b6f72",
  "@metamask-previews/signature-controller": "35.0.0-preview-79b6f72",
  "@metamask-previews/subscription-controller": "3.1.0-preview-79b6f72",
  "@metamask-previews/token-search-discovery-controller": "4.0.0-preview-79b6f72",
  "@metamask-previews/transaction-controller": "61.1.0-preview-79b6f72",
  "@metamask-previews/transaction-pay-controller": "1.0.0-preview-79b6f72",
  "@metamask-previews/user-operation-controller": "40.0.0-preview-79b6f72"
}

smgv
smgv previously approved these changes Oct 30, 2025
cursor[bot]

This comment was marked as outdated.

@lwin-kyaw
Copy link
Contributor Author

@metamaskbot publish-preview

@github-actions
Copy link
Contributor

Preview builds have been published. See these instructions for more information about preview builds.

Expand for full list of packages and versions.
{
  "@metamask-previews/account-tree-controller": "2.0.0-preview-cc7e30d0",
  "@metamask-previews/accounts-controller": "34.0.0-preview-cc7e30d0",
  "@metamask-previews/address-book-controller": "7.0.0-preview-cc7e30d0",
  "@metamask-previews/announcement-controller": "8.0.0-preview-cc7e30d0",
  "@metamask-previews/app-metadata-controller": "2.0.0-preview-cc7e30d0",
  "@metamask-previews/approval-controller": "8.0.0-preview-cc7e30d0",
  "@metamask-previews/assets-controllers": "85.0.0-preview-cc7e30d0",
  "@metamask-previews/base-controller": "9.0.0-preview-cc7e30d0",
  "@metamask-previews/bridge-controller": "57.0.0-preview-cc7e30d0",
  "@metamask-previews/bridge-status-controller": "57.0.0-preview-cc7e30d0",
  "@metamask-previews/build-utils": "3.0.4-preview-cc7e30d0",
  "@metamask-previews/chain-agnostic-permission": "1.2.2-preview-cc7e30d0",
  "@metamask-previews/composable-controller": "12.0.0-preview-cc7e30d0",
  "@metamask-previews/controller-utils": "11.15.0-preview-cc7e30d0",
  "@metamask-previews/core-backend": "4.0.0-preview-cc7e30d0",
  "@metamask-previews/delegation-controller": "1.0.0-preview-cc7e30d0",
  "@metamask-previews/earn-controller": "9.0.0-preview-cc7e30d0",
  "@metamask-previews/eip-5792-middleware": "2.0.0-preview-cc7e30d0",
  "@metamask-previews/eip-7702-internal-rpc-middleware": "0.1.0-preview-cc7e30d0",
  "@metamask-previews/eip1193-permission-middleware": "1.0.2-preview-cc7e30d0",
  "@metamask-previews/ens-controller": "18.0.0-preview-cc7e30d0",
  "@metamask-previews/error-reporting-service": "3.0.0-preview-cc7e30d0",
  "@metamask-previews/eth-block-tracker": "14.0.0-preview-cc7e30d0",
  "@metamask-previews/eth-json-rpc-middleware": "21.0.0-preview-cc7e30d0",
  "@metamask-previews/eth-json-rpc-provider": "5.0.1-preview-cc7e30d0",
  "@metamask-previews/foundryup": "1.0.1-preview-cc7e30d0",
  "@metamask-previews/gas-fee-controller": "25.0.0-preview-cc7e30d0",
  "@metamask-previews/gator-permissions-controller": "0.3.0-preview-cc7e30d0",
  "@metamask-previews/json-rpc-engine": "10.1.1-preview-cc7e30d0",
  "@metamask-previews/json-rpc-middleware-stream": "8.0.8-preview-cc7e30d0",
  "@metamask-previews/keyring-controller": "24.0.0-preview-cc7e30d0",
  "@metamask-previews/logging-controller": "7.0.0-preview-cc7e30d0",
  "@metamask-previews/message-manager": "14.0.0-preview-cc7e30d0",
  "@metamask-previews/messenger": "0.3.0-preview-cc7e30d0",
  "@metamask-previews/multichain-account-service": "2.0.0-preview-cc7e30d0",
  "@metamask-previews/multichain-api-middleware": "1.2.4-preview-cc7e30d0",
  "@metamask-previews/multichain-network-controller": "2.0.0-preview-cc7e30d0",
  "@metamask-previews/multichain-transactions-controller": "6.0.0-preview-cc7e30d0",
  "@metamask-previews/name-controller": "9.0.0-preview-cc7e30d0",
  "@metamask-previews/network-controller": "25.0.0-preview-cc7e30d0",
  "@metamask-previews/network-enablement-controller": "3.1.0-preview-cc7e30d0",
  "@metamask-previews/notification-services-controller": "19.0.0-preview-cc7e30d0",
  "@metamask-previews/permission-controller": "12.1.0-preview-cc7e30d0",
  "@metamask-previews/permission-log-controller": "5.0.0-preview-cc7e30d0",
  "@metamask-previews/phishing-controller": "15.0.0-preview-cc7e30d0",
  "@metamask-previews/polling-controller": "15.0.0-preview-cc7e30d0",
  "@metamask-previews/preferences-controller": "21.0.0-preview-cc7e30d0",
  "@metamask-previews/profile-sync-controller": "26.0.0-preview-cc7e30d0",
  "@metamask-previews/rate-limit-controller": "7.0.0-preview-cc7e30d0",
  "@metamask-previews/remote-feature-flag-controller": "2.0.0-preview-cc7e30d0",
  "@metamask-previews/sample-controllers": "3.0.0-preview-cc7e30d0",
  "@metamask-previews/seedless-onboarding-controller": "6.0.0-preview-cc7e30d0",
  "@metamask-previews/selected-network-controller": "25.0.0-preview-cc7e30d0",
  "@metamask-previews/shield-controller": "1.1.0-preview-cc7e30d0",
  "@metamask-previews/signature-controller": "35.0.0-preview-cc7e30d0",
  "@metamask-previews/subscription-controller": "3.1.0-preview-cc7e30d0",
  "@metamask-previews/token-search-discovery-controller": "4.0.0-preview-cc7e30d0",
  "@metamask-previews/transaction-controller": "61.1.0-preview-cc7e30d0",
  "@metamask-previews/transaction-pay-controller": "1.0.0-preview-cc7e30d0",
  "@metamask-previews/user-operation-controller": "40.0.0-preview-cc7e30d0"
}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants