Skip to content

Conversation

@tomerqodo
Copy link

@tomerqodo tomerqodo commented Dec 4, 2025

User description

Benchmark PR Expensify#73035

Type: Clean (correct implementation)

Original PR Title: feat: Better detect third party card connection issues
Original PR Description:

Explanation of Change

Fixed Issues

$ Expensify#72363
PROPOSAL: Expensify#72363 (comment)

Tests

  1. Go to Workspace -> Company Cards
  2. Click Add cards -> Select United States -> Direct Feed -> Other
  3. When entering Plaid flow, press X button -> Yes, exit
  4. Verify that: The "Something not working?" Modal opens
  5. Finish the Plaid flow to add Company card
  6. Click assign card
  7. Click back button
  8. Verify that: The prompt text shows "Choose a card for . Can't find the card you're looking for? Let us know." which matches the design.
  • Verify that no errors appear in the JS console

Offline tests

QA Steps

  1. Go to Workspace -> Company Cards
  2. Click Add cards -> Select United States -> Direct Feed -> Other
  3. When entering Plaid flow, press X button -> Yes, exit
  4. Verify that: The "Something not working?" Modal opens
  5. Finish the Plaid flow to add Company card
  6. Click assign card
  7. Click back button
  8. Verify that: The prompt text shows "Choose a card for . Can't find the card you're looking for? Let us know." which matches the design.
  • Verify that no errors appear in the JS console

PR Author Checklist

  • I linked the correct issue in the ### Fixed Issues section above
  • I wrote clear testing steps that cover the changes made in this PR
    • I added steps for local testing in the Tests section
    • I added steps for the expected offline behavior in the Offline steps section
    • I added steps for Staging and/or Production testing in the QA steps section
    • I added steps to cover failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
    • I tested this PR with a High Traffic account against the staging or production API to ensure there are no regressions (e.g. long loading states that impact usability).
  • I included screenshots or videos for tests on all platforms
  • I ran the tests on all platforms & verified they passed on:
    • Android: Native
    • Android: mWeb Chrome
    • iOS: Native
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
    • MacOS: Desktop
  • I verified there are no console errors (if there's a console error not related to the PR, report it or open an issue for it to be fixed)
  • I verified there are no new alerts related to the canBeMissing param for useOnyx
  • I followed proper code patterns (see Reviewing the code)
    • I verified that any callback methods that were added or modified are named for what the method does and never what callback they handle (i.e. toggleReport and not onIconClick)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text shown in the product is localized by adding it to src/languages/* files and using the translation method
      • If any non-english text was added/modified, I used JaimeGPT to get English > Spanish translation. I then posted it in #expensify-open-source and it was approved by an internal Expensify engineer. Link to Slack message:
    • I verified all numbers, amounts, dates and phone numbers shown in the product are using the localization methods
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
    • I verified proper file naming conventions were followed for any new files or renamed files. All non-platform specific files are named after what they export and are not named "index.js". All platform-specific files are named for the platform the code supports as outlined in the README.
    • I verified the JSDocs style guidelines (in STYLE.md) were followed
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I followed the guidelines as stated in the Review Guidelines
  • I tested other components that can be impacted by my changes (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar are working as expected)
  • I verified all code is DRY (the PR doesn't include any logic written more than once, with the exception of tests)
  • I verified any variables that can be defined as constants (ie. in CONST.ts or at the top of the file that uses the constant) are defined as such
  • I verified that if a function's arguments changed that all usages have also been updated correctly
  • If any new file was added I verified that:
    • The file has a description of what it does and/or why is needed at the top of the file if the code is not self explanatory
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))
  • If new assets were added or existing ones were modified, I verified that:
    • The assets are optimized and compressed (for SVG files, run npm run compress-svg)
    • The assets load correctly across all supported platforms.
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • If a new page is added, I verified it's using the ScrollView component to make it scrollable when more elements are added to the page.
  • I added unit tests for any new feature or bug fix in this PR to help automatically prevent regressions in this user flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.

Screenshots/Videos

Android: Native
Screen.Recording.2025-10-21.at.15.22.00.mov
Android: mWeb Chrome
Screen.Recording.2025-10-21.at.15.23.34.mov
iOS: Native
Screen.Recording.2025-10-21.at.15.25.06.mp4
iOS: mWeb Safari
Screen.Recording.2025-10-21.at.15.26.21.mov
MacOS: Chrome / Safari
Screen.Recording.2025-10-21.at.15.27.07.mp4
MacOS: Desktop
Screen.Recording.2025-10-21.at.15.28.21.mp4

Original PR URL: Expensify#73035


PR Type

Enhancement


Description

  • Add exit modal to detect third-party card connection issues

  • Update chooseCardFor message to use AssigneeParams instead of AssignCardParams

  • Simplify card selection prompt with HTML formatting and concierge link

  • Remove unused AssignCardParams type definition across all language files


Diagram Walkthrough

flowchart LR
  A["PlaidConnectionStep"] -->|onExit callback| B["AddNewCardPage"]
  B -->|setIsModalVisible| C["ConfirmModal"]
  C -->|onConfirm| D["navigateToConciergeChat"]
  E["CardSelectionStep"] -->|RenderHTML| F["Updated chooseCardFor message"]
  G["Language files"] -->|exitModal translations| C
  G -->|AssigneeParams| F
Loading

File Walkthrough

Relevant files
Enhancement
13 files
en.ts
Add exit modal translations and update card selection message
+8/-2     
de.ts
Add exit modal translations and update card selection message
+8/-2     
es.ts
Add exit modal translations and update card selection message
+8/-2     
fr.ts
Add exit modal translations and update card selection message
+8/-2     
it.ts
Add exit modal translations and update card selection message
+8/-2     
ja.ts
Add exit modal translations and update card selection message
+8/-2     
nl.ts
Add exit modal translations and update card selection message
+8/-2     
pl.ts
Add exit modal translations and update card selection message
+8/-2     
pt-BR.ts
Add exit modal translations and update card selection message
+8/-2     
zh-hans.ts
Add exit modal translations and update card selection message
+7/-2     
AddNewCardPage.tsx
Add exit modal for Plaid connection flow                                 
+28/-8   
PlaidConnectionStep.tsx
Propagate exit callback from Plaid connection step             
+5/-2     
CardSelectionStep.tsx
Update card selection message with HTML rendering               
+8/-8     
Miscellaneous
1 files
params.ts
Remove unused `AssignCardParams` type definition                 
+0/-6     

@qodo-code-review
Copy link

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status:
Action not logged: The new user exit action from the Plaid flow triggers a modal and navigation but adds no
audit logging of the exit event, user, or outcome.

Referred Code
        setPlaidEvent(event);
        // Limit the number of times a user can submit Plaid credentials
        if (event === 'SUBMIT_CREDENTIALS') {
            handleRestrictedEvent(event);
        }
    }}
    // User prematurely exited the Plaid flow
    // eslint-disable-next-line react/jsx-props-no-multi-spaces
    onExit={() => {
        onExit?.();
        handleBackButtonPress();
    }}
/>

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status:
Missing fallback: The confirm action relies on navigateToConciergeChat without visible error handling or
fallback if navigation fails or chat is unavailable.

Referred Code
<ConfirmModal
    isVisible={isModalVisible}
    title={translate('workspace.companyCards.addNewCard.exitModal.title')}
    success
    confirmText={translate('workspace.companyCards.addNewCard.exitModal.confirmText')}
    cancelText={translate('workspace.companyCards.addNewCard.exitModal.cancelText')}
    prompt={translate('workspace.companyCards.addNewCard.exitModal.prompt')}
    onCancel={() => setIsModalVisible(false)}
    onConfirm={() => {
        setIsModalVisible(false);
        navigateToConciergeChat();
    }}
/>

Learn more about managing compliance generic rules or creating your own custom rules

Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review
Copy link

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion                                                                                                                                    Impact
Security
Prevent a potential XSS vulnerability

To prevent a potential XSS vulnerability, use placeholder substitution
({assignee}) instead of template literal interpolation (${assignee}) for the
assignee display name in translation strings.

src/languages/en.ts [4507-4508]

 chooseCardFor: ({assignee}: AssigneeParams) =>
-    `Choose a card for <strong>${assignee}</strong>. Can't find the card you're looking for? <concierge-link>Let us know.</concierge-link>`,
+    `Choose a card for <strong>{assignee}</strong>. Can't find the card you're looking for? <concierge-link>Let us know.</concierge-link>`,
  • Apply / Chat
Suggestion importance[1-10]: 9

__

Why: The suggestion correctly identifies a potential XSS vulnerability due to direct string interpolation of a user-provided display name into an HTML string and provides a valid fix.

High
General
Improve component structure and styling

Wrap the RenderHTML component in a Text component instead of a View to ensure
proper text style inheritance.

src/pages/workspace/companyCards/assignCard/CardSelectionStep.tsx [161-167]

 <Text style={[styles.textSupporting, styles.ph5, styles.mv3]}>
-    {translate('workspace.companyCards.chooseCardFor', {
-        assignee: assigneeDisplayName,
-        feed: plaidUrl && formattedFeedName ? formattedFeedName : getBankName(feed),
-    })}
+    <RenderHTML
+        html={translate('workspace.companyCards.chooseCardFor', {
+            assignee: assigneeDisplayName,
+        })}
+    />
 </Text>

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 5

__

Why: The suggestion correctly points out that wrapping RenderHTML in a Text component is better for style inheritance, but the current implementation with a View is not incorrect and achieves the desired styling.

Low
  • More

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants