feat(engine): wire NeoBankService for Money Account onboarding - #35896
Conversation
Replace the client-side KYC API fetch in useKycDisclaimers with KycController.loadDisclaimers so Iron/MoonPay vendor terms use a single Engine source of truth. Wires preview @metamask/kyc-controller with minimal KycService/KycController init for disclaimer loading only. TRAM-3978 Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: Sébastien Van Eyck <sebastien.vaneyck@consensys.net>
…ers-from-controller
…ers-from-controller
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
|
No dependency changes detected. Learn more about Socket for GitHub. 👍 No dependency changes detected in pull request |
…ntroller' into feat/vba-kyc-disclaimers-from-controller
Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: Sébastien Van Eyck <sebastien.vaneyck@consensys.net>
Signed-off-by: Sébastien Van Eyck <sebastien.vaneyck@consensys.net>
Signed-off-by: Sébastien Van Eyck <sebastien.vaneyck@consensys.net>
Signed-off-by: Sébastien Van Eyck <sebastien.vaneyck@consensys.net>
Signed-off-by: Sébastien Van Eyck <sebastien.vaneyck@consensys.net>
…ntroller' into feat/vba-kyc-disclaimers-from-controller
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #35896 +/- ##
==========================================
+ Coverage 85.96% 86.00% +0.04%
==========================================
Files 6859 6886 +27
Lines 192237 192854 +617
Branches 47836 47991 +155
==========================================
+ Hits 165265 165873 +608
+ Misses 16261 16249 -12
- Partials 10711 10732 +21 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 25cc449. Configure here.
| ...RAMPS_CONTROLLER_REQUIRED_SERVICE_ACTIONS, | ||
| // The onboarding stage lookup refreshes KYC and resolves the customer | ||
| // before reading wallet and autoramp status. | ||
| ...RAMPS_CONTROLLER_REQUIRED_CONTROLLER_ACTIONS, |
There was a problem hiding this comment.
Ramps messenger drops feature-flag action
High Severity
getRampsControllerMessenger no longer delegates RemoteFeatureFlagController:getState. RampsController still reads moneyHeadlessAllProviders through that action on each quote. Without the delegate, the check fails closed and quote widening stays native-only, so aggregator and WebView deposit providers stay hidden even when the flag is on.
Reviewed by Cursor Bugbot for commit 25cc449. Configure here.
There was a problem hiding this comment.
False positive — no production fix needed.
RemoteFeatureFlagController:getState is still delegated. This PR only removed the hand-maintained duplicate; the same action is already a member of RAMPS_CONTROLLER_REQUIRED_CONTROLLER_ACTIONS, which getRampsControllerMessenger now spreads.
Verified against the resolved @metamask/ramps-controller@20.3.0:
RAMPS_CONTROLLER_REQUIRED_CONTROLLER_ACTIONS = [
'AuthenticationController:getSessionProfile',
'KeyringController:signPersonalMessage',
'RemoteFeatureFlagController:getState',
]Pinned in ramps-controller-messenger.test.ts so a future package bump that drops the action from that list fails CI instead of silently breaking quote widening.
Pin RemoteFeatureFlagController:getState via the package-owned required actions list, and add init/messenger tests matching the Transak pattern. Co-authored-by: Cursor <cursoragent@cursor.com>
🔍 Smart E2E Test Selection
click to see 🤖 AI reasoning detailsE2E Test Selection: Performance Test Selection: |
|
PR template — items to address before "Ready for review"Warnings — informational, address before merging:
See docs/readme/ready-for-review.md for the full Definition of Ready for Review. |
⚡ Performance Test Results
✅ All tests passed · 2 tests · 1 device 📱 Devices tested (1)Android: Google Pixel 8 Pro (v14.0) ✅ Passed Tests (2)
Branch: |





Description
Wires
NeoBankServicefrom@metamask/ramps-controllerinto the Mobile Engine, and moves theRampsControllermessenger onto the package-owned list of required controller actions.Why: Money Account onboarding needs to reach the neo-bank API (autoramp lookup, MoonPay customer resolution, self-hosted wallet registration), and the
RampsControlleronboarding stage lookup needs access to the controller actions the package declares it depends on. Neither was available on Mobile.What changed:
NeoBankServiceis registered as a stateless service. A newneo-bank-service-init.tsconstructs it the same wayTransakServiceis — sharinggetRampsEnvironment()/getRampsContext()and the globalfetch. The service is added to theEngineinit map and context,STATELESS_NON_CONTROLLER_NAMES,MESSENGER_FACTORIES, and theMessengerClients/MessengerClientsToInitializetypes.getNeoBankServiceMessenger. DelegatesAuthenticationController:getBearerTokenso the service can authenticate its requests.NeoBankServiceActions/NeoBankServiceEventsare now unioned intoGlobalActions/GlobalEventsnext to the other ramps entries, alongside theNeoBankServiceclass import they belong to.getRampsControllerMessengerspreadsRAMPS_CONTROLLER_REQUIRED_CONTROLLER_ACTIONSin addition to the existingRAMPS_CONTROLLER_REQUIRED_SERVICE_ACTIONS. The hand-maintainedRemoteFeatureFlagController:getStatedelegate is dropped because that action is already a member of the package-owned list — spreading it means the KYC/customer actions the onboarding stage lookup will need (from MetaMask/core#10116) arrive automatically on the next@metamask/ramps-controllerbump instead of silently going missing.neoBankServiceInit,getNeoBankServiceMessenger, and pin thatRemoteFeatureFlagController:getStateremains delegated via the package-owned controller-actions list.Scope note: this branch originally also carried the KYC controller wiring and the React Native SumSub launcher. Those have since landed on
mainvia #35540 and #36081, so they no longer appear in this diff. What remains is theNeoBankServicewiring and the ramps messenger permission change.Follow-up:
RAMPS_CONTROLLER_REQUIRED_CONTROLLER_ACTIONSin the currently resolved@metamask/ramps-controller@20.3.0is['AuthenticationController:getSessionProfile', 'KeyringController:signPersonalMessage', 'RemoteFeatureFlagController:getState']. The KYC-facing additions land with MetaMask/core#10116; no dependency bump is required for this PR to compile and behave correctly today.Changelog
CHANGELOG entry: Added NeoBankService Engine wiring for Money Account onboarding
Related issues
Partially completes: https://consensyssoftware.atlassian.net/browse/TRAM-3900
Manual testing steps
Screenshots/Recordings
Before
N/A — Engine wiring only, no UI surface in this PR.
After
N/A — Engine wiring only, no UI surface in this PR.
Pre-merge author checklist
Performance checks (if applicable)
Pre-merge reviewer checklist
Note
Medium Risk
Touches Engine startup and ramps messenger allow-lists used for buy/onboarding flows, including auth token delegation for external neo-bank APIs; regressions would surface as init or quote/onboarding failures rather than data loss.
Overview
Registers
NeoBankServiceon the Mobile Engine so Money Account onboarding can call the neo-bank API. A new init module constructs the service likeTransakService(shared ramps environment/context, globalfetch), exposes it onEngine.context, and adds messenger wiring that delegatesAuthenticationController:getBearerTokenfor authenticated API calls.Updates
RampsControllermessenger permissions by spreadingRAMPS_CONTROLLER_REQUIRED_CONTROLLER_ACTIONSfrom@metamask/ramps-controlleralongside the existing required service actions, replacing the hand-maintainedRemoteFeatureFlagController:getStateentry so package upgrades pick up new dependencies (including future onboarding/KYC actions) without silent gaps.Tests cover service init, neo-bank messenger delegation, and that ramps-controller delegates all package-declared required actions without duplicates.
Reviewed by Cursor Bugbot for commit 53c66f8. Bugbot is set up for automated code reviews on this repo. Configure here.