Skip to content

chore(runway): cherry-pick feat: legacy-ios-redirect#28283

Merged
chloeYue merged 1 commit into
release/7.72.0from
cherry-pick-7-72-0-d6d4c1b
Apr 2, 2026
Merged

chore(runway): cherry-pick feat: legacy-ios-redirect#28283
chloeYue merged 1 commit into
release/7.72.0from
cherry-pick-7-72-0-d6d4c1b

Conversation

@runway-github

@runway-github runway-github Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

Description

Fixes: https://github.com/MetaMask/MetaMask-planning/issues/7148

Support webcredential for ios google login
Part 3/4 - Support legacy/ webcredential ios google login based on
feature flag

This pr add feature flag for the ios google login
use legacy ios google login when flag is true
use webcredential ios google login when flag is false for ios > 17.4

Part 1/ 4 - #27741
Part 2/ 4 - #27848
Part 3/ 4 - #27850 (defer to 7.72.0)
Part 4/ 4 -
#27875

Changelog

CHANGELOG entry: Support legacy/ webcredential ios google login based
feature flag

Related issues

Fixes:

Manual testing steps

Feature: iOS Google OAuth and token refresh (seedless)

  Scenario: Sign in with Google on iOS using legacy configuration
    Given the legacy iOS Google feature flag and OS version yield legacy client/redirect
    When the user completes seedless Google onboarding
    Then login completes and the app persists onboarding OAuth context as expected

  Scenario: Sign in with Google on iOS using web client and universal link redirect
    Given the app selects the web Google client and universal link redirect for iOS Google
    When the user completes Google OAuth via the browser/universal link flow
    Then the user returns to the app with a successful login

  Scenario: Refresh auth tokens after Google login on iOS
    Given an existing seedless Google session on iOS
    When the client refreshes JWT / auth tokens (e.g. after background or controller refresh)
    Then refresh succeeds without client_id mismatch errors

  Scenario: Wallet reset clears seedless onboarding state
    Given seedless onboarding metadata exists in Redux
    When the user deletes the wallet or resets onboarding as implemented
    Then seedless onboarding state is cleared with other onboarding fields

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Note

Medium Risk
Changes OAuth login/refresh behavior and auth-connection selection for
iOS Google, including new Redux-persisted client IDs and feature-flagged
config switching; mistakes could break Google sign-in or token refresh
on iOS.

Overview
Adds persisted seedless onboarding OAuth context to Redux (new
SET/CLEAR_SEEDLESS_ONBOARDING actions + reducer state) and clears it
when restarting onboarding or deleting/resetting a wallet.

Updates iOS Google OAuth to switch between legacy iOS
redirect/clientId and web/universal-link credentials
via a new
getIosGoogleConfig() helper and legacy feature flag logic (with an iOS
< 17.4 safety fallback), while unifying Google web constants/redirect
naming.

Ensures refresh-token requests on iOS Google reuse the original
client_id by reading the persisted onboarding clientId (fallbacking to
legacy IosGID), and updates OAuth authentication to pick iOS vs
Android auth-connection IDs based on device/clientId. Tests were
expanded/updated to cover these paths (including Google prompt
select-account and state reset).

Written by Cursor
Bugbot
for commit
24579e7. This will update automatically
on new commits. Configure
here.

[d6d4c1b](https://github.com/MetaMask/metamask-mobile/commit/d6d4c1bf0891b43b2051d905500b54787ff2f675)

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

Fixes: MetaMask/MetaMask-planning#7148
<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->
Support webcredential for ios google login
Part 3/4 - Support legacy/ webcredential ios google login based on
feature flag

This pr add feature flag for the ios google login
use legacy ios google login when flag is true
use webcredential ios google login when flag is false for ios > 17.4

Part 1/ 4 - #27741
Part 2/ 4 - #27848
Part 3/ 4 - #27850 (defer to 7.72.0)
Part 4/ 4 -
[#27875](#27875)

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Support legacy/ webcredential ios google login based
feature flag

Fixes:

```gherkin
Feature: iOS Google OAuth and token refresh (seedless)

  Scenario: Sign in with Google on iOS using legacy configuration
    Given the legacy iOS Google feature flag and OS version yield legacy client/redirect
    When the user completes seedless Google onboarding
    Then login completes and the app persists onboarding OAuth context as expected

  Scenario: Sign in with Google on iOS using web client and universal link redirect
    Given the app selects the web Google client and universal link redirect for iOS Google
    When the user completes Google OAuth via the browser/universal link flow
    Then the user returns to the app with a successful login

  Scenario: Refresh auth tokens after Google login on iOS
    Given an existing seedless Google session on iOS
    When the client refreshes JWT / auth tokens (e.g. after background or controller refresh)
    Then refresh succeeds without client_id mismatch errors

  Scenario: Wallet reset clears seedless onboarding state
    Given seedless onboarding metadata exists in Redux
    When the user deletes the wallet or resets onboarding as implemented
    Then seedless onboarding state is cleared with other onboarding fields
```

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

<!-- [screenshots/recordings] -->

<!-- [screenshots/recordings] -->

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes OAuth login/refresh behavior and auth-connection selection for
iOS Google, including new Redux-persisted client IDs and feature-flagged
config switching; mistakes could break Google sign-in or token refresh
on iOS.
>
> **Overview**
> Adds persisted *seedless onboarding OAuth context* to Redux (new
`SET/CLEAR_SEEDLESS_ONBOARDING` actions + reducer state) and clears it
when restarting onboarding or deleting/resetting a wallet.
>
> Updates iOS Google OAuth to *switch between legacy iOS
redirect/clientId and web/universal-link credentials* via a new
`getIosGoogleConfig()` helper and legacy feature flag logic (with an iOS
< 17.4 safety fallback), while unifying Google web constants/redirect
naming.
>
> Ensures refresh-token requests on iOS Google reuse the original
`client_id` by reading the persisted onboarding clientId (fallbacking to
legacy `IosGID`), and updates OAuth authentication to pick iOS vs
Android auth-connection IDs based on device/clientId. Tests were
expanded/updated to cover these paths (including Google prompt
select-account and state reset).
>
> <sup>Written by [Cursor
Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit
24579e7. This will update automatically
on new commits. Configure
[here](https://cursor.com/dashboard?tab=bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@runway-github runway-github Bot requested a review from a team as a code owner April 1, 2026 17:00
@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamaskbot metamaskbot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label Apr 1, 2026
@github-actions github-actions Bot added size-L risk-medium Moderate testing recommended · Possible bug introduction risk labels Apr 1, 2026

@ieow ieow left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@chloeYue chloeYue left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chloeYue chloeYue added the skip-smart-e2e-selection Skip Smart E2E selection, i.e. select all E2E tests to run label Apr 1, 2026
@github-actions github-actions Bot added risk-high Extensive testing required · High bug introduction risk and removed risk-medium Moderate testing recommended · Possible bug introduction risk labels Apr 1, 2026
@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

🔍 Smart E2E Test Selection

⏭️ Smart E2E selection skipped - skip-smart-e2e-selection label found

All E2E tests pre-selected.

View GitHub Actions results

@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

E2E Fixture Validation — Schema is up to date
17 value mismatches detected (expected — fixture represents an existing user).
View details

@sonarqubecloud

sonarqubecloud Bot commented Apr 1, 2026

Copy link
Copy Markdown

@chloeYue chloeYue merged commit 47a356b into release/7.72.0 Apr 2, 2026
274 of 277 checks passed
@chloeYue chloeYue deleted the cherry-pick-7-72-0-d6d4c1b branch April 2, 2026 05:30
@github-actions github-actions Bot locked and limited conversation to collaborators Apr 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

risk-high Extensive testing required · High bug introduction risk size-L skip-smart-e2e-selection Skip Smart E2E selection, i.e. select all E2E tests to run team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants