Skip to content

Refine avatar picker, profile settings, and verification cooldown UX - #3028

Merged
innolope-dev merged 21 commits into
devfrom
codex/avatar-dice-flow
Sep 7, 2026
Merged

innolope-dev merged 21 commits into
devfrom
codex/avatar-dice-flow

Conversation

@innolope-dev

Copy link
Copy Markdown
Collaborator

Avatar selection now starts with a horizontal initials row and an explicit confirmation. Rolling the dice plays a full-screen CSS animation with haptics, then offers a unique 3×3 or 4×4 avatar grid sized for the screen. The flow selectively incorporates the avatar-dealing logic from #3014 and uses existing app colors and components without adding libraries.

  • Keep the username's first letter selected and visible first; match initial and avatar tile sizes. Exclude initials and repeated artwork from random deals, and require selection before confirming an avatar.
  • Replace the pink background circle/ripples with a grounded dice landing; support reduced motion and cancellation.
  • Make the profile link username bold, domain regular, with more space before the share icon.
  • Move “Liking it so far?” above “The official bits” on About; retain dev's vertically centered ListItem rows.
  • Rename the verification screen/menu to Payment Channels and update English menu capitalization. Use Bank Transfers for Europe, wrap long row labels, align row heights, show a full green unlimited Peanut-to-Peanut bar, and use a status pill for unavailable cards.
  • Put the full-name visibility toggle on the page background without its eye icon/container; use sentence case for Delete my account.
  • Show verification rate limits with their retry date/time and one “I'll try later” action. Preserve recovery actions for state conflicts and other errors.
  • Prevent background pull-to-refresh while dialogs are open and cancel pending/cancelled gestures.

Latest dev is merged, including its long-press callout guard, drawer body drag handling, and shadow-padding fixes. Those fixes remain intact; the avatar layout is reconciled with the updated shared drawer padding.

Backend companion: https://github.com/peanutprotocol/peanut-api-ts/pull/1543. It allows reopening unfinished uploads without another reset cooldown and advances the longer cooldown on completed provider decisions.

Validation: 148 tests passed across 14 focused suites; UI TypeScript check and diff whitespace check passed. Native device checks remain for long-press behavior, drawer gestures, VoiceOver/TalkBack, and haptics. No deployment performed.

@vercel

vercel Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
peanut-wallet Ready Ready Preview Sep 7, 2026 11:19pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 10042e22-a67f-45ff-9d17-cb2845213c3e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Code-analysis diff

Painscore total: 7268.94 → 7279.31 (+10.37)
Findings: +6 net (+113 new, -107 resolved)

🆕 New findings (113)

  • critical complexity — src/app/(mobile-ui)/qr-pay/page.tsx — CC 334, MI 52.85, SLOC 1217
  • critical complexity — src/app/(mobile-ui)/withdraw/manteca/page.tsx — CC 160, MI 51.55, SLOC 628
  • critical complexity — src/components/Profile/views/UnlockPayments.view.tsx — CC 154, MI 57.92, SLOC 515
  • critical complexity — src/app/(mobile-ui)/add-money/[country]/bank/page.tsx — CC 122, MI 57.37, SLOC 411
  • critical complexity — src/components/AddWithdraw/AddWithdrawCountriesList.tsx — CC 122, MI 56.47, SLOC 380
  • critical complexity — src/components/Claim/Link/views/BankFlowManager.view.tsx — CC 112, MI 47.3, SLOC 437
  • critical complexity — src/app/(mobile-ui)/withdraw/[country]/bank/page.tsx — CC 107, MI 53.38, SLOC 400
  • critical complexity — src/hooks/useSumsubKycFlow.ts — CC 105, MI 51.55, SLOC 458
  • critical method-complexity — src/app/(mobile-ui)/qr-pay/page.tsx:103 — QRPayPage CC 87 SLOC 451
  • critical complexity — src/hooks/useMultiPhaseKycFlow.ts — CC 79, MI 56, SLOC 387
  • critical complexity — src/components/Kyc/InitiateKycModal.tsx — CC 72, MI 52.2, SLOC 173
  • critical complexity — src/components/AddMoney/components/MantecaAddMoney.tsx — CC 61, MI 57.13, SLOC 233
  • critical complexity — src/hooks/usePullToRefresh.ts — CC 58, MI 57.55, SLOC 254
  • critical complexity — src/components/Avatar/AvatarPicker.tsx — CC 52, MI 59.03, SLOC 181
  • high hotspot — src/app/(mobile-ui)/qr-pay/page.tsx — 145 commits, +1981/-1657 lines since 6 months ago
  • high hotspot — src/app/(mobile-ui)/withdraw/manteca/page.tsx — 89 commits, +808/-502 lines since 6 months ago
  • high hotspot — src/app/(mobile-ui)/add-money/[country]/bank/page.tsx — 76 commits, +720/-452 lines since 6 months ago
  • high hotspot — src/app/(mobile-ui)/withdraw/[country]/bank/page.tsx — 68 commits, +607/-320 lines since 6 months ago
  • high hotspot — src/hooks/useSumsubKycFlow.ts — 58 commits, +847/-360 lines since 6 months ago
  • high hotspot — src/components/AddWithdraw/AddWithdrawCountriesList.tsx — 55 commits, +737/-484 lines since 6 months ago

…and 93 more.

✅ Resolved (107)

  • src/app/(mobile-ui)/qr-pay/page.tsx — CC 329, MI 52.65, SLOC 1209
  • src/app/(mobile-ui)/withdraw/manteca/page.tsx — CC 159, MI 51.28, SLOC 625
  • src/components/Profile/views/UnlockPayments.view.tsx — CC 152, MI 58.03, SLOC 510
  • src/app/(mobile-ui)/add-money/[country]/bank/page.tsx — CC 121, MI 57.15, SLOC 408
  • src/components/AddWithdraw/AddWithdrawCountriesList.tsx — CC 121, MI 56.18, SLOC 377
  • src/components/Claim/Link/views/BankFlowManager.view.tsx — CC 111, MI 46.73, SLOC 434
  • src/app/(mobile-ui)/withdraw/[country]/bank/page.tsx — CC 106, MI 53.01, SLOC 397
  • src/hooks/useSumsubKycFlow.ts — CC 102, MI 51.04, SLOC 443
  • src/app/(mobile-ui)/qr-pay/page.tsx:103 — QRPayPage CC 84 SLOC 447
  • src/hooks/useMultiPhaseKycFlow.ts — CC 79, MI 56.12, SLOC 383
  • src/components/Kyc/InitiateKycModal.tsx — CC 71, MI 52.34, SLOC 171
  • src/components/AddMoney/components/MantecaAddMoney.tsx — CC 60, MI 56.67, SLOC 230
  • src/hooks/usePullToRefresh.ts — CC 54, MI 57.8, SLOC 237
  • src/app/(mobile-ui)/qr-pay/page.tsx — 144 commits, +1960/-1653 lines since 6 months ago
  • src/app/(mobile-ui)/withdraw/manteca/page.tsx — 87 commits, +806/-501 lines since 6 months ago
  • src/app/(mobile-ui)/add-money/[country]/bank/page.tsx — 74 commits, +710/-450 lines since 6 months ago
  • src/app/(mobile-ui)/withdraw/[country]/bank/page.tsx — 66 commits, +599/-319 lines since 6 months ago
  • src/hooks/useSumsubKycFlow.ts — 56 commits, +835/-358 lines since 6 months ago
  • src/components/AddWithdraw/AddWithdrawCountriesList.tsx — 53 commits, +735/-483 lines since 6 months ago
  • src/components/Profile/views/UnlockPayments.view.tsx:131 — CC 46 SLOC 244

…and 87 more.

📈 Painscore deltas (top movers)

File Before After Δ
src/components/Avatar/DiceRoll.tsx 0.0 5.7 +5.7
src/components/Kyc/KycRestartCooldownModal.tsx 0.0 5.6 +5.6
src/components/Kyc/SumsubKycModals.tsx 1.9 2.9 +1.0
src/components/Avatar/avatar.utils.ts 5.0 5.9 +0.9
src/app/actions/sumsub.ts 8.8 9.5 +0.7
src/components/Profile/views/UnlockPayments.view.tsx 12.3 12.9 +0.6

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

🧪 UI test report — ✅ all green

Suites

  • ✅ unit: 6369 ran, 0 failed, 0 skipped, 2.1m

📊 Coverage (unit)

metric %
statements 75.1%
branches 61.5%
functions 69.2%
lines 76.0%
⏱ 10 slowest test cases
time test
🐢 9.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Network failure keeps loading while retries remain, then shows the generic error
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › User KYC not approved fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_RECENT_REFUND fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_MERCHANT_VOLUME_NEAR_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_SOURCE_OVER_MONTHLY_CAP fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › MANTECA_USER_NOT_PROVISIONED fails fast with copy that names the real cause
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › a refused idempotency key tells the user to scan again, not to contact support
4.0s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › routes the KYC rejection on its wire code, and does not retry it
3.1s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Going offline blames the connection, and reconnecting clears it for the recovered scan
3.1s src/app/(mobile-ui)/qr-pay/__tests__/qr-pay-states.test.tsx › Scan that recovers on the retry lands on the payment screen, not an error
📍 Inline annotations are in the **Unit test report** check above. Coverage artifact: `coverage-unit`. Generated by `.github/workflows/tests.yml`.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

🖼 Visual diff — ⚠️ no result for the latest push

The newest Tests run produced no diff report in any attempt: ds-shots was skipped, failed before the diff, or had no cached baseline.
The previous result on this comment no longer reflects the latest run, so it was cleared.

Fixture screenshots, no backend. Advisory — this check never blocks a merge.

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

Found a global pull-to-refresh regression and three smaller release/copy defects. Exact-head required CI is red in the unit job.

Findings

  • MAJOR · src/hooks/usePullToRefresh.ts:169 · Ignore only dialogs that are actually open
    The selector treats every mounted role=dialog element without data-state=closed or hidden as open. SupportDrawer is always mounted by both app layouts and, while closed, still has role=dialog with aria-modal=false and neither of those attributes. Therefore every touchstart hits this guard and pull-to-refresh is disabled across the app even when no overlay is visible. Restrict the check to real open state (for example data-state=open or aria-modal=true), and add a layout-level regression case with a closed always-mounted SupportDrawer.

  • MINOR · src/i18n/app/messages/en.json:597 · Update delete-account tests for the new label
    The required unit job fails all ten DeleteAccountButton cases because they still query the exact old text 'Delete My Account'; after this line changes the rendered label, none of those tests reaches its behavioral assertions. Update the shared test query/fixture to the new sentence-case label (preferably by accessible role and name) so the required unit gate can pass.

  • MINOR · src/i18n/app/messages/en.json:314 · Resolve the exchange-rate translation drift
    Changing this menu value to 'Exchange Rates and Fees' makes it identical to exchangeRate.title, but the resolved Spanish catalogs render the two keys differently ('Tipos de cambio y comisiones' versus 'Tipo de cambio y comisiones'). The exact-head duplicate-value drift tests fail for es-419 and es-AR. Align the translations, reuse one canonical key, or explicitly document a genuine context distinction in the test allowlist.

  • MINOR · src/i18n/app/messages/en.json:310 · Carry the Payment Channels rename into every locale
    Only the English menu and page title are renamed here. Switching to es-419, es-AR, or pt-BR still shows the old imperative 'Unlock payments' wording for both keys, so the product rename disappears with the language setting even though the other new copy in this PR is localized. Add approved equivalents for profile.menu.unlockedRegions and profile.unlockPayments.title in each supported catalog.

Checked clean

  • Confirmed the detached worktree HEAD, PR metadata, supplied base SHA, and merge base exactly match the requested review coordinates.
  • Reviewed the avatar picker deal, persistence fallback, save serialization, responsive grid, reduced-motion path, haptics cleanup, and drawer lifecycle.
  • Reviewed restart-cooldown parsing and presentation against the sibling API policy branch, including 429 retryAt and Retry-After behavior; no security, privacy, or money surface was introduced.
  • Checked the live canonical Lexicon and all four locale catalogs for the changed payment terminology.
  • Reviewed the profile header, About ordering, profile-edit toggle, payment-channel rows, limit bars, and associated focused tests.
  • Exact-head CI: typecheck, eslint, format, native-export, design-system checks, workflow analysis, and deployment passed; required unit failed with 12 tests across DeleteAccountButton and translation drift, causing ci-success to fail.
  • Focused local execution passed 26 tests in usePullToRefresh, Sumsub refusal parsing, and avatar dealing; five additional focused suites could not resolve next-intl from the available external dependency tree, while exact-head CI did execute them.
  • git diff --check reported no whitespace errors.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion: did not run — claude-unparseable-reply. This review is one reviewer short.

Exact head: 277e4f4017a7 · Context: repo, product, api · Took 23m

Comment thread src/hooks/usePullToRefresh.ts
Comment thread src/i18n/app/messages/en.json
Comment thread src/i18n/app/messages/en.json
Comment thread src/i18n/app/messages/en.json

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

The avatar, profile, dialog, and verification-cooldown behavior is sound, but the Payment Channels rename remains English-only and exact-head unit CI fails on Spanish exchange-rate translation drift.

Findings

  • MINOR · src/i18n/app/messages/en.json:314 · Make the Spanish exchange-rate labels agree
    Exact-head unit CI fails duplicate-value drift because these two English labels now both read Exchange Rates and Fees, while es-419 renders the profile menu as Tipos de cambio y comisiones and the destination page as Tipo de cambio y comisiones; es-AR inherits the same mismatch. Pick one Spanish rendering for both keys so the menu and page title agree and the required unit gate passes.

  • MINOR · src/i18n/app/messages/en.json:310 · Translate the Payment Channels rename
    The English menu and page are renamed to Payment Channels, but es-419 and pt-BR still render the old Unlock payments concept, and es-AR explicitly overrides both labels with that old name. A user switching languages therefore sees the previous information architecture return. Update both profile.menu.unlockedRegions and profile.unlockPayments.title in es-419, es-AR, and pt-BR to carry the rename through every supported app locale.

  • MAJOR · src/i18n/app/messages/en.json:390 · [claude-opus] Europe rail relabelled "Bank Transfers" over-promises non-EUR European bank support
    profile.unlockPayments.rows.sepa changed from "SEPA transfers" to "Bank Transfers" (same in es-419/es-AR/pt-BR: "Transferencias bancarias" / "Transferências bancárias"). That row is the sole row of the europe group (src/utils/unlock-payments.utils.ts:168, bankRow('sepa','sepa','bank','europe',['bridge'])), so a user in the Europe section now reads "Europe → Bank Transfers → Active" with no mention of the scheme or currency.

Product truth says the European rail is SEPA and EUR-only: product/countries.md:416 ("SEPA deposits currently EUR-only... Multi-currency SEPA on roadmap"), product/countries.md:452, product/currencies.md:124 (EUR (SEPA) only), product/quick-ref.md:37, and the customer-facing phrasing in product/support-answers/deposit-options-by-region.md:16 ("EU (SEPA, 41 countries): EUR bank transfer"). product/countries.md:459 further records that UK residents are blocked from every bank rail (TASK-20729), so the broader label is not more accurate for GB/FPS either. The code is the side that is wrong.

This is the exact failure mode already logged as recurring in product/feedback/problems/non-eur-sepa-deposits-unsupported.md — "docs/UI imply they're supported" while PLN/GBP/CZK transfers bounce, sometimes with fees, flagged as the "10th time" it recurs. Every sibling row on this screen keeps its rail and country explicit ("ACH, Wire (US) & SPEI (Mexico)", "PIX (Brazil)..."), so this row is now the only vague one.

Fix: restore the scheme and currency in the label, e.g. "SEPA transfers (EUR)" in en.json and the three locales (product truth allows naming the SEPA zone; it only forbids asserting a country count). Note the label also feeds the unlock modal title (UnlockPayments.view.tsx:313), so the fix propagates there for free.

Checked clean

  • Confirmed the detached worktree HEAD, supplied base SHA, merge base, trusted author, and dev target exactly match the review coordinates.
  • P1 is fixed at this head: Vaul dialogs are selected only by data-state=open, HeadlessUI exposes aria-modal only in its open state, and the always-mounted support dialog sets aria-modal=false while closed; the new regression test covers that support-drawer case.
  • P2 is fixed at this head: every changed delete-account interaction now queries the sentence-case Delete my account button label.
  • Reviewed avatar deal eligibility and art deduplication, responsive 3x3/4x4 sizing, staged confirmation, duplicate-save prevention, device-local letter fallback, dice timer and haptic cleanup, and reduced-motion handling.
  • Reviewed the verification restart 429 contract, retryAt and Retry-After normalization, cooldown state reset, localized date rendering, and the single dismiss action.
  • Reviewed profile-link composition, About ordering, name-visibility toggle placement, payment-row wrapping and status treatments, and the unlimited Peanut-to-Peanut progress bar.
  • Exact-head CI passed format, eslint, typecheck, ds-lint, native-export, ds-shots, analyze, human-authors, bot-approval, and Deploy Preview; unit failed only the two Spanish duplicate-value drift assertions described in P3, leaving ci-success red.
  • Focused local Jest execution was unavailable because the detached worktree has no installed Jest binary; git diff --check passed.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion by claude-opus: 1 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: 8164af9483ef · Context: repo · Took 22m

Comment thread src/i18n/app/messages/en.json
Comment thread src/i18n/app/messages/en.json

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

Two localization defects remain: non-English users still see the retired verification name, and the Spanish exchange-rate labels disagree and fail exact-head unit CI. The other supplied prior findings are fixed or refuted.

Findings

  • MINOR · src/i18n/app/messages/en.json:310 · Carry the Payment Channels rename into every locale
    The English menu and destination now say Payment Channels, but es-419, es-AR, and pt-BR still render their old Unlock payments wording for both profile.menu.unlockedRegions and profile.unlockPayments.title. Switching the app locale therefore makes the rename disappear. Translate the new product name in both keys for each shipped locale.

  • MINOR · src/i18n/app/messages/en.json:314 · Make the Spanish exchange-rate labels agree
    This head makes the English menu and page title share Exchange Rates and Fees, but es-419 resolves those keys to Tipos de cambio y comisiones and Tipo de cambio y comisiones; es-AR inherits the same mismatch. Exact-head unit CI now fails both duplicate-value drift cases. Align the two Spanish renderings, or mark the contexts divergent only if that grammatical difference is intentional.

Checked clean

  • Confirmed the supplied detached worktree is exactly the requested head and its merge base is the supplied dev base SHA.
  • Reviewed avatar dealing, selection confirmation, save fallback, duplicate-submit guard, reduced-motion behavior, and responsive grid sizing.
  • Reviewed restart cooldown parsing and presentation, non-429 recovery behavior, and KYC flow state reset paths.
  • Reviewed profile-header formatting, About ordering, delete-account label coverage, and pull-to-refresh overlay cancellation.
  • Exact-head typecheck, lint, formatting, design-system checks, native export, visual snapshots, and deploy preview passed; unit CI ran 6,119 tests and failed only the two Spanish duplicate-value drift assertions reported above.
  • P5 is the same surviving Spanish catalog defect as P3 and is represented once under P3; P6 is the same surviving locale rename defect as P4 and is represented once under P4.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: a49e4f70bb5e · Context: repo, product · Took 22m

Comment thread src/i18n/app/messages/en.json
Comment thread src/i18n/app/messages/en.json

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

The locale and test findings are fixed, but restart cooldown UX still reaches only the profile Payment Channels screen; the other payment flows discard the retry time.

Findings

  • MAJOR · src/hooks/useMultiPhaseKycFlow.ts:547 · Render restart cooldowns in every payment flow
    errorCooldown is returned by the shared KYC flow, but only UnlockPayments consumes it. Add-money, withdraw, claim, and QR restart paths still pass only flow.error to InitiateKycModal or a notification. When restart returns 429 with retryAt, those screens therefore show the raw error—some replacing the action with Contact support—instead of the dated cooldown and single I'll try later action promised by this change. Centralize cooldown presentation in the shared modal layer, or thread the metadata through every consumer, and cover one non-profile restart path.

Checked clean

  • Confirmed the detached worktree HEAD, trusted author, dev target, supplied base SHA, and merge base exactly match the requested review coordinates.
  • Reviewed restart 429 parsing, retryAt and Retry-After normalization, cooldown state reset, the profile cooldown modal, and every useMultiPhaseKycFlow payment consumer.
  • Reviewed avatar dealing, staged confirmation, duplicate-submit prevention, device-local letter fallback, responsive sizing, reduced motion, haptic cleanup, and drawer lifecycle.
  • Reviewed profile-link formatting, About ordering, full-name toggle placement, payment-row wrapping and status treatments, the unlimited Peanut-to-Peanut bar, and pull-to-refresh overlay isolation.
  • Checked the live canonical Lexicon and all four resolved locale catalogs; Payment Channels is not defined in the Lexicon, so the PR description is the available naming intent rather than an invented Lexicon definition.
  • Exact-head required CI is green: unit, typecheck, eslint, format, native export, design-system lint, workflow analysis, and deployment passed. Advisory ds-shots failed during next build with its log ending inside the webpack bundle and no actionable test or compile diagnostic; the immediately preceding PR head passed that job.
  • git diff --check passed; the detached worktree has no installed dependencies, so no additional local Jest or build run was available.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: 5bf6420533e0 · Context: repo, product · Took 22m

Comment thread src/hooks/useMultiPhaseKycFlow.ts

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

The supplied P1-P9 findings are fixed, and the avatar, profile, locale, and pull-to-refresh changes are otherwise sound. One minor cooldown-dismissal bug remains in payment flows whose restart prompt stays mounted.

Findings

  • MINOR · src/components/Kyc/SumsubKycModals.tsx:21 · Dismiss the cooldown back to the payment screen
    When QR Pay is in PROVIDER_RESTART_IDENTITY, its parent ActionModal remains hard-coded visible while this line mounts the cooldown as a second dialog. Tapping ‘I’ll try later’ only clears errorCooldown, so the underlying restart dialog immediately takes over and still offers the blocked restart; the bank modal/page hosts likewise keep their visibility state or verify step active. Make cooldown dismissal also close/reset the host initiation surface (or pass a host onCooldownClose callback and suppress direct restart dialogs) so only one dialog is mounted and the dismiss action actually returns to the payment screen.

Checked clean

  • Confirmed the detached worktree HEAD and merge base exactly match the supplied head and base SHAs.
  • Rechecked P1: pull-to-refresh now ignores only open or aria-modal dialogs, covers the always-mounted closed support drawer, and cancels gestures when a dialog opens mid-pull.
  • Rechecked P2-P8: delete-account tests use the sentence-case label, and Payment Channels plus exchange-rate wording is consistent across en, es-419, es-AR, and pt-BR.
  • Rechecked P9: restart cooldown state and the dated shared renderer now reach every payment-flow host; the remaining dismissal behavior is reported separately.
  • Reviewed avatar selection, random dealing, duplicate-art exclusion, save serialization, local letter fallback, cancellation, reduced motion, haptics, and focused tests.
  • Reviewed the profile header, About ordering, name-visibility toggle, payment-channel rows, limit-bar presentation, and their focused tests.
  • Required exact-head CI is green. Advisory ds-shots failed inside its duplicate Next build with no actionable diagnostic, while native-export and the aggregate required CI passed.
  • Checked the live Peanut Lexicon; it does not define these menu-label terms, so their wording was assessed against the trusted PR scope and locale consistency rather than an invented definition.
  • Local Jest and TypeScript binaries are absent from the detached worktree, so focused tests were verified through exact-head CI rather than rerun locally.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: 99bfe77e23d3 · Context: repo, product · Took 24m

Comment thread src/components/Kyc/SumsubKycModals.tsx Outdated

@chip-peanut-bot chip-peanut-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Chip review — no blocking findings — this is not an approval

No actionable defects found at the pinned head. All ten supplied prior findings are fixed in code, tests, or locale catalogs.

Checked clean

  • P1: pull-to-refresh now matches only open dialog states, cancels interrupted gestures, and retains coverage for the closed always-mounted support dialog.
  • P2: every delete-account interaction test now targets the sentence-case label.
  • P3-P8: Payment Channels and exchange-rate labels now agree across English, Spanish, Argentine Spanish inheritance, and Brazilian Portuguese.
  • P9-P10: restart cooldowns render through the shared KYC modal host in payment flows, suppress the underlying initiation prompt, and dismiss back to the payment screen; the sibling API contract supplies the sanitized retryAt field.
  • Avatar picker state, explicit save behavior, art deduplication, responsive square deals, keyboard navigation, reduced motion, cancellation, and haptic cleanup were traced without finding a reachable regression.
  • Profile share-pill formatting, About-page ordering, full-name toggle presentation, payment-row wrapping, unavailable-card status, and unlimited P2P bar were checked against the stated PR behavior.
  • Exact-head unit, eslint, typecheck, format, native-export, analyze, required ci-success, and deployment checks passed. Advisory ds-shots failed during its build after compilation and before screenshots; the separate build-bearing checks passed.
  • A local focused Jest run was unavailable because the detached worktree has no node_modules; exact-head CI unit coverage passed instead.
  • The canonical Lexicon was checked for the changed product terminology; it defines rails and related payment concepts but does not define Payment Channels, while the trusted PR description explicitly requires that UI label.

Security review: did not run — this change has no security, privacy or money surface, so it was not asked. This review is one reviewer short.

Third opinion by claude-opus: 0 finding(s), marked with the model name. It answers only product truth, missing tests and the cross-repo contract, so treat its findings as advice.

Exact head: 36acbdd7670a · Context: repo, product, sibling · Took 22m

@innolope-dev
innolope-dev merged commit 2c1a669 into dev Sep 7, 2026
22 of 23 checks passed

This branch was successfully deployed

1 active deployment
Preview — 36acbdd7 Deployed Sep 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant