Skip to content

hotfix(step-up): stop prompting where the flow already proves the passkey#2515

Merged
Hugo0 merged 1 commit into
mainfrom
hotfix/step-up-self-proving-withdrawals
Jul 25, 2026
Merged

hotfix(step-up): stop prompting where the flow already proves the passkey#2515
Hugo0 merged 1 commit into
mainfrom
hotfix/step-up-self-proving-withdrawals

Conversation

@jjramirezn

@jjramirezn jjramirezn commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Summary

FE half of peanutprotocol/peanut-api-ts#1241 — removes stepUp: true from prepareWithdrawal and submitWithdrawSessionApproval. These flows are self-proving (admin EIP-712 / enable signature follow immediately from the same passkey), so the step-up assertion added by #2463 only added a third fingerprint sheet to every collateral-funded send (the triple-prompt reports from Hugo and Jota, confirmed on-chain: the send tx carries exactly 2 WebAuthn signatures).

Card PAN/CVV/PIN and bank-account add keep step-up.

Risks / breaking changes

  • Deploy order: backend PR first. If STEP_UP_ENFORCED is on and this ships before the BE drops the gate, withdraw prepare would 401.

QA

  • prettier clean, step-up service tests pass (8/8), 0 typecheck errors in changed file. 3 failing suites are the known missing-submodule worktree gotcha (content/countryCurrency/add-money), green in CI.
  • After both deploy: a collateral-funded send link = 2 fingerprint prompts (admin sig + userop); card-detail reveal still prompts.

Screenshots: N/A (no UI change — prompt-count behavior only)


Hotfix to main (production user-visible triple-prompt). Supersedes #2514 (dev-targeted). Deploy order: peanut-api-ts hotfix first. Back-merge main→dev after merge.

Summary by CodeRabbit

  • Bug Fixes
    • Reduced unnecessary passkey or fingerprint prompts during withdrawal preparation and session approval.
    • Withdrawal actions now rely on the provided passkey-derived approval signature for verification.

withdraw/prepare is followed by the admin EIP-712 the passkey must sign,
and session-approve's payload is itself a passkey enable signature — the
step-up assertion before them proved nothing extra and turned every
collateral-funded send into three fingerprint prompts (the triple-prompt
reports). PAN/CVV/PIN and bank-add keep step-up: there the cookie is the
only proof.

Pairs with peanut-api-ts dropping requireStepUp from the same routes;
backend deploys first (enforcement would 401 clients that stop sending
the header).
@vercel

vercel Bot commented Jul 24, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
peanut-wallet Ready Ready Preview, Comment Jul 24, 2026 10:45pm

Request Review

@coderabbitai

coderabbitai Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 143ab6dc-a9b8-4de2-aa29-bf4ebcc015e6

📥 Commits

Reviewing files that changed from the base of the PR and between d5e9789 and fd7de0f.

📒 Files selected for processing (1)
  • src/services/rain.ts

📝 Walkthrough

Walkthrough

Rain withdrawal preparation and session approval requests no longer enable step-up/WebAuthn. Their documentation now identifies the subsequent passkey-derived signature as the authentication step.

Changes

Rain withdrawal authentication flow

Layer / File(s) Summary
Disable step-up on withdrawal requests
src/services/rain.ts
Removes stepUp: true from the session approval and withdrawal preparation requests while preserving their endpoints and method interfaces; updates the related documentation.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: hugo0

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: removing unnecessary step-up prompts in passkey-proven withdrawal flows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hotfix/step-up-self-proving-withdrawals

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed: dependency version conflict. Check your lock file or package.json.


Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Code-analysis diff

Painscore total: 6270.06 → 6270.18 (+0.12)
Findings: 0 net (+2 new, -2 resolved)

🆕 New findings (2)

  • critical complexity — src/services/rain.ts — CC 65, MI 60.08, SLOC 262
  • medium hotspot — src/services/rain.ts — 27 commits, +868/-119 lines since 6 months ago

✅ Resolved (2)

  • src/services/rain.ts — CC 65, MI 59.99, SLOC 264
  • src/services/rain.ts — 26 commits, +859/-117 lines since 6 months ago

@github-actions

Copy link
Copy Markdown
Contributor

🧪 UI test report — ✅ all green

Suites

  • unit: 2156 ran, 0 failed, 0 skipped, 35.6s

📊 Coverage (unit)

metric %
statements 60.9%
branches 44.5%
functions 50.0%
lines 61.3%
⏱ 10 slowest test cases
time test
3.4s src/components/Card/share-asset/__tests__/shareAssetLayout.test.ts › never places two stickers in heavy overlap (broad seed sweep)
1.1s src/utils/__tests__/demo-api.test.ts › isDemoMode() is false when not running under Capacitor
0.4s src/app/actions/__tests__/api-headers.test.ts › should include Content-Type in validateInviteCode
0.4s src/components/Card/share-asset/__tests__/shareAssetLayout.test.ts › every sticker stays within canvas at any count
0.3s src/app/actions/__tests__/api-headers-extended.test.ts › should not include apiKey in validateInviteCode body
0.3s src/app/(mobile-ui)/withdraw/__tests__/withdraw-states.test.tsx › Bank withdrawal keeps the $1 minimum for sub-$1 amounts
0.2s src/components/Card/share-asset/__tests__/shareAssetLayout.test.ts › keeps stickers off the username pill (final pass respects the keep-out)
0.2s src/utils/__tests__/demo-balance.test.ts › auto-refills a wallet older than the TTL on cold start
0.2s src/utils/__tests__/demo-balance.test.ts › auto-refills a stored balance that has no timestamp (legacy install)
0.2s src/utils/__tests__/url.utils.test.ts › uses the public BASE_URL in Capacitor, not the localhost WebView origin
📍 Inline annotations are in the **Unit test report** check above. Coverage artifact: `coverage-unit`. Generated by `.github/workflows/tests.yml`.

@jjramirezn

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@jjramirezn
jjramirezn marked this pull request as ready for review July 24, 2026 22:54
@jjramirezn
jjramirezn requested a review from Hugo0 July 24, 2026 22:55
@Hugo0
Hugo0 merged commit e52eb69 into main Jul 25, 2026
24 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants