chore(runway): cherry-pick chore: pass cached security data from token list to token details cp-7.76.0#29644
Conversation
…n list to token details cp-7.76.0 (#29603) ## **Description** When the token list security badges feature flag is enabled, read the already-fetched security data from the TanStack Query cache on item press and forward it via navigation params, eliminating the on-demand fetch in TokenDetails. ## **Changelog** <!-- If this PR is not End-User-Facing and should not show up in the CHANGELOG, you can choose to either: 1. Write `CHANGELOG entry: null` 2. Label with `no-changelog` If this PR is End-User-Facing, please write a short User-Facing description in the past tense like: `CHANGELOG entry: Added a new tab for users to see their NFTs` `CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker` (This helps the Release Engineer do their job more quickly and accurately) --> CHANGELOG entry: remove on demand api call to get security data when passed from token list and FF is ON ## **Related issues** Fixes: ## **Manual testing steps** ```gherkin Feature: my feature name Scenario: user [verb for user action] Given [describe expected initial app state] When user [verb for user action] Then [describe expected outcome] ``` ## **Screenshots/Recordings** <!-- If applicable, add screenshots and/or recordings to visualize the before and after of your change. --> ### **Before** <!-- [screenshots/recordings] --> ### **After** <!-- [screenshots/recordings] --> ## **Pre-merge author checklist** <!-- Every checklist item must be consciously assessed before marking this PR as "Ready for review". A checked box means you deliberately considered that responsibility, not that you literally performed every action listed. Unchecked boxes are ambiguous: they are not an implicit "N/A" and they are not a silent "skip". See `docs/readme/ready-for-review.md` for the full checklist semantics. --> - [ ] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [ ] I've completed the PR template to the best of my ability - [ ] I've included tests if applicable - [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [ ] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [ ] I've tested on Android - Ideally on a mid-range device; emulator is acceptable - [ ] I've tested with a power user scenario - Use these [power-user SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93) to import wallets with many accounts and tokens - [ ] I've instrumented key operations with Sentry traces for production performance metrics - See [`trace()`](/app/util/trace.ts) for usage and [`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274) for an example For performance guidelines and tooling, see the [Performance Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers). ## **Pre-merge reviewer checklist** <!-- Reviewer checklist items follow the same semantics as the author checklist: an unchecked box is ambiguous, a checked box means the reviewer consciously assessed that responsibility. See `docs/readme/ready-for-review.md`. --> - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Changes the token list tap navigation payload to optionally include cached `TokenSecurityData` from TanStack Query, which could affect the Asset Details screen’s behavior when the security-badges feature flag is enabled. Risk is limited by feature-flag gating but still touches navigation params and cache key usage. > > **Overview** > When `selectTokenListSecurityBadgesEnabled` is on and a CAIP asset id has been resolved, tapping a token in `TokenListItem` now reads `TokenSecurityData` from the TanStack Query cache (`tokenListSecurityBadgeKeys.byAsset(caipId)`) and forwards it to the `Asset` route via `securityData` navigation params. > > Adds/updates unit tests to mock `useQueryClient` + CAIP resolution and assert `securityData` is included only when the flag is enabled and cached data exists. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 224e470. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
🔍 Smart E2E Test Selection
click to see 🤖 AI reasoning detailsE2E Test Selection: Key observations:
No other tags are needed because:
Performance Test Selection: |
|



Description
When the token list security badges feature flag is enabled, read the
already-fetched security data from the TanStack Query
cache on item press and forward it via navigation params, eliminating
the on-demand fetch in TokenDetails.
Changelog
CHANGELOG entry: remove on demand api call to get security data when
passed from token list and FF is ON
Related issues
Fixes:
Manual testing steps
Screenshots/Recordings
Before
After
Pre-merge author checklist
Docs and MetaMask Mobile
Coding
Standards.
if applicable
guidelines).
Not required for external contributors.
Performance checks (if applicable)
SRPs
to import wallets with many accounts and tokens
performance metrics
trace()for usage andaddTokenfor an example
For performance guidelines and tooling, see the Performance
Guide.
Pre-merge reviewer checklist
app, test code being changed).
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
Note
Medium Risk
Changes the token list tap navigation payload to optionally include
cached
TokenSecurityDatafrom TanStack Query, which could affect theAsset Details screen’s behavior when the security-badges feature flag is
enabled. Risk is limited by feature-flag gating but still touches
navigation params and cache key usage.
Overview
When
selectTokenListSecurityBadgesEnabledis on and a CAIP asset idhas been resolved, tapping a token in
TokenListItemnow readsTokenSecurityDatafrom the TanStack Query cache(
tokenListSecurityBadgeKeys.byAsset(caipId)) and forwards it to theAssetroute viasecurityDatanavigation params.Adds/updates unit tests to mock
useQueryClient+ CAIP resolution andassert
securityDatais included only when the flag is enabled andcached data exists.
Reviewed by Cursor Bugbot for commit
224e470. Bugbot is set up for automated
code reviews on this repo. Configure
here.