Skip to content

chore(runway): cherry-pick chore: pass cached security data from token list to token details cp-7.76.0#29644

Merged
chloeYue merged 1 commit into
release/7.76.0from
runway-cherry-pick-7.76.0-1777880885
May 4, 2026
Merged

chore(runway): cherry-pick chore: pass cached security data from token list to token details cp-7.76.0#29644
chloeYue merged 1 commit into
release/7.76.0from
runway-cherry-pick-7.76.0-1777880885

Conversation

@runway-github

@runway-github runway-github Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

Description

When the token list security badges feature flag is enabled, read the
already-fetched security data from the TanStack Query
cache on item press and forward it via navigation params, eliminating
the on-demand fetch in TokenDetails.

Changelog

CHANGELOG entry: remove on demand api call to get security data when
passed from token list and FF is ON

Related issues

Fixes:

Manual testing steps

Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]

Screenshots/Recordings

Before

After

Pre-merge author checklist

Performance checks (if applicable)

  • I've tested on Android
    • Ideally on a mid-range device; emulator is acceptable
  • I've tested with a power user scenario
  • Use these power-user
    SRPs

    to import wallets with many accounts and tokens
  • I've instrumented key operations with Sentry traces for production
    performance metrics
  • See trace() for usage and
    addToken
    for an example

For performance guidelines and tooling, see the Performance
Guide
.

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Note

Medium Risk
Changes the token list tap navigation payload to optionally include
cached TokenSecurityData from TanStack Query, which could affect the
Asset Details screen’s behavior when the security-badges feature flag is
enabled. Risk is limited by feature-flag gating but still touches
navigation params and cache key usage.

Overview
When selectTokenListSecurityBadgesEnabled is on and a CAIP asset id
has been resolved, tapping a token in TokenListItem now reads
TokenSecurityData from the TanStack Query cache
(tokenListSecurityBadgeKeys.byAsset(caipId)) and forwards it to the
Asset route via securityData navigation params.

Adds/updates unit tests to mock useQueryClient + CAIP resolution and
assert securityData is included only when the flag is enabled and
cached data exists.

Reviewed by Cursor Bugbot for commit
224e470. Bugbot is set up for automated
code reviews on this repo. Configure
here.

[6b9885e](https://github.com/MetaMask/metamask-mobile/commit/6b9885e6d44e03790c9dfda5962c7deec1a54364)

…n list to token details cp-7.76.0 (#29603)

## **Description**

When the token list security badges feature flag is enabled, read the
already-fetched security data from the TanStack Query
cache on item press and forward it via navigation params, eliminating
the on-demand fetch in TokenDetails.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: remove on demand api call to get security data when
passed from token list and FF is ON

## **Related issues**

Fixes:

## **Manual testing steps**

```gherkin
Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]
```

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

<!--
Every checklist item must be consciously assessed before marking this PR
as
"Ready for review". A checked box means you deliberately considered that
responsibility, not that you literally performed every action listed.

Unchecked boxes are ambiguous: they are not an implicit "N/A" and they
are not
a silent "skip". See `docs/readme/ready-for-review.md` for the full
checklist
semantics.
-->

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [ ] I've tested on Android
  - Ideally on a mid-range device; emulator is acceptable
- [ ] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [ ] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example

For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).

## **Pre-merge reviewer checklist**

<!--
Reviewer checklist items follow the same semantics as the author
checklist: an
unchecked box is ambiguous, a checked box means the reviewer consciously
assessed that responsibility. See `docs/readme/ready-for-review.md`.
-->

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes the token list tap navigation payload to optionally include
cached `TokenSecurityData` from TanStack Query, which could affect the
Asset Details screen’s behavior when the security-badges feature flag is
enabled. Risk is limited by feature-flag gating but still touches
navigation params and cache key usage.
> 
> **Overview**
> When `selectTokenListSecurityBadgesEnabled` is on and a CAIP asset id
has been resolved, tapping a token in `TokenListItem` now reads
`TokenSecurityData` from the TanStack Query cache
(`tokenListSecurityBadgeKeys.byAsset(caipId)`) and forwards it to the
`Asset` route via `securityData` navigation params.
> 
> Adds/updates unit tests to mock `useQueryClient` + CAIP resolution and
assert `securityData` is included only when the flag is enabled and
cached data exists.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
224e470. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@runway-github runway-github Bot requested a review from a team as a code owner May 4, 2026 07:48
@github-actions

github-actions Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamaskbotv2 metamaskbotv2 Bot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label May 4, 2026
@github-actions github-actions Bot added the size-M label May 4, 2026
@github-actions

github-actions Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🔍 Smart E2E Test Selection

  • Selected E2E tags: SmokeWalletPlatform
  • Selected Performance tags: @PerformanceAssetLoading
  • Risk Level: low
  • AI Confidence: 82%
click to see 🤖 AI reasoning details

E2E Test Selection:
The changes are focused on TokenListItem.tsx and its test file. The modification adds useQueryClient to read cached security data from React Query cache and passes it as a navigation parameter when navigating to the Asset details screen. This is gated behind the selectTokenListSecurityBadgesEnabled feature flag.

Key observations:

  1. No UI rendering changes: The visual appearance of the token list item is unchanged - only the navigation params are enriched with security data.
  2. Feature-flag gated: The new behavior only activates when selectTokenListSecurityBadgesEnabled is true AND a CAIP asset ID is resolved.
  3. Navigation impact: The onItemPress callback now passes securityData to the 'Asset' screen navigation params, which could affect the Asset details screen if it consumes this data.
  4. TokenListItem is used in: TokenList.tsxTokensSection.tsx (Homepage) → core wallet platform.

SmokeWalletPlatform is the most relevant tag as it covers core wallet platform features including token display and transaction history. The token list is a central component of the wallet home screen.

No other tags are needed because:

  • This is not a confirmation/transaction flow change (SmokeConfirmations not needed)
  • Not related to account management (SmokeAccounts not needed)
  • Not related to network management (SmokeNetworkAbstractions not needed)
  • Not related to swap/stake/money flows directly
  • The change is purely additive (passing extra data in nav params) and feature-flag gated

Performance Test Selection:
The TokenListItem is a frequently rendered component in the wallet's token list. The change adds a queryClient.getQueryData call inside the onItemPress callback (not in the render path), so it doesn't directly impact rendering performance. However, since this component is part of the asset loading flow and the change touches the token list item interaction, @PerformanceAssetLoading is marginally relevant. That said, the change is in a press handler (not render), so performance impact is minimal. Including it as a precaution since the token list is a performance-sensitive area.

View GitHub Actions results

@sonarqubecloud

sonarqubecloud Bot commented May 4, 2026

Copy link
Copy Markdown

@chloeYue chloeYue left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chloeYue chloeYue merged commit a654e01 into release/7.76.0 May 4, 2026
92 checks passed
@chloeYue chloeYue deleted the runway-cherry-pick-7.76.0-1777880885 branch May 4, 2026 09:53
@github-actions github-actions Bot locked and limited conversation to collaborators May 4, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

size-M team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants