Skip to content

chore(runway): cherry-pick fix: fix block explorer redirection cp-7.74.0#28971

Merged
chloeYue merged 1 commit into
release/7.74.00from
runway-cherry-pick-7.74.0-1776423729
Apr 17, 2026
Merged

chore(runway): cherry-pick fix: fix block explorer redirection cp-7.74.0#28971
chloeYue merged 1 commit into
release/7.74.00from
runway-cherry-pick-7.74.0-1776423729

Conversation

@runway-github

@runway-github runway-github Bot commented Apr 17, 2026

Copy link
Copy Markdown
Contributor

Description

Fixes the block explorer URL generation for Solana SPL tokens in the
Security Trust screen. The params.address contains a full CAIP asset
type ID (e.g.,
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp/token:USD1ttGY1N17NEEHLmELoaybftRBUSErhqYiQzvEmuB)
but the block explorer URL template expects just the raw token address.

This change extracts the assetReference from the CAIP asset type before
passing it to getBlockExplorerTokenUrl.

Changelog

CHANGELOG entry: Fix block explorer redirection for solana.

Related issues

Fixes:
https://consensyssoftware.atlassian.net/browse/ASSETS-3076?focusedCommentId=412599

Manual testing steps

Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]

Screenshots/Recordings

Before

After

Screen.Recording.2026-04-17.at.11.51.22.mov

Pre-merge author checklist

Performance checks (if applicable)

  • I've tested on Android
    • Ideally on a mid-range device; emulator is acceptable
  • I've tested with a power user scenario
  • Use these power-user
    SRPs

    to import wallets with many accounts and tokens
  • I've instrumented key operations with Sentry traces for production
    performance metrics
  • See trace() for usage and
    addToken
    for an example

For performance guidelines and tooling, see the Performance
Guide
.

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Note

Low Risk
Low risk: a small, localized change to external link URL generation
plus targeted unit tests; main risk is incorrect CAIP parsing leading to
broken explorer links for some non-EVM assets.

Overview
Fixes block explorer redirection from SecurityTrustScreen by
detecting CAIP asset type addresses and passing only the parsed
assetReference (e.g., Solana mint) into getBlockExplorerTokenUrl
instead of the full CAIP identifier.

Updates SecurityTrustScreen.test.tsx to make route params
configurable and adds assertions that EVM addresses are passed through
unchanged while Solana CAIP addresses are correctly parsed before URL
generation (with useBlockExplorer now mocked to verify calls).

Reviewed by Cursor Bugbot for commit
a5464e1. Bugbot is set up for automated
code reviews on this repo. Configure
here.

[47ee978](https://github.com/MetaMask/metamask-mobile/commit/47ee978dc26bedfbaf8b7c63bee45ff9115e2bc3)

…4.0 (#28966)

## **Description**

Fixes the block explorer URL generation for Solana SPL tokens in the
Security Trust screen. The params.address contains a full CAIP asset
type ID (e.g.,
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp/token:USD1ttGY1N17NEEHLmELoaybftRBUSErhqYiQzvEmuB)
but the block explorer URL template expects just the raw token address.

This change extracts the assetReference from the CAIP asset type before
passing it to getBlockExplorerTokenUrl.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Fix block explorer redirection for solana.

## **Related issues**

Fixes:
https://consensyssoftware.atlassian.net/browse/ASSETS-3076?focusedCommentId=412599

## **Manual testing steps**

```gherkin
Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]
```

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->


https://github.com/user-attachments/assets/a84d3264-4545-444f-961d-a3bf8e10a5a8


## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [ ] I've tested on Android
  - Ideally on a mid-range device; emulator is acceptable
- [ ] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [ ] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example

For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.


<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Low risk: a small, localized change to external link URL generation
plus targeted unit tests; main risk is incorrect CAIP parsing leading to
broken explorer links for some non-EVM assets.
> 
> **Overview**
> Fixes block explorer redirection from `SecurityTrustScreen` by
detecting CAIP asset type addresses and passing only the parsed
`assetReference` (e.g., Solana mint) into `getBlockExplorerTokenUrl`
instead of the full CAIP identifier.
> 
> Updates `SecurityTrustScreen.test.tsx` to make route params
configurable and adds assertions that EVM addresses are passed through
unchanged while Solana CAIP addresses are correctly parsed before URL
generation (with `useBlockExplorer` now mocked to verify calls).
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
a5464e1. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@github-actions

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamaskbotv2 metamaskbotv2 Bot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label Apr 17, 2026
@github-actions github-actions Bot added the risk-high Extensive testing required · High bug introduction risk label Apr 17, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Smart E2E Test Selection

⏭️ Smart E2E selection skipped - PR targets a release branch (release/*)

All E2E tests pre-selected.

View GitHub Actions results

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown
Contributor

E2E Fixture Validation — Schema is up to date
11 value mismatches detected (expected — fixture represents an existing user).
View details

@chloeYue chloeYue left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chloeYue chloeYue merged commit ae27d88 into release/7.74.00 Apr 17, 2026
111 checks passed
@chloeYue chloeYue deleted the runway-cherry-pick-7.74.0-1776423729 branch April 17, 2026 12:09
@github-actions github-actions Bot locked and limited conversation to collaborators Apr 17, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

risk-high Extensive testing required · High bug introduction risk size-M team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants