Skip to content

feat(settings): serve /subscriptions redirects from React - #21295

Merged
vbudhram merged 1 commit into
mainfrom
fxa-6661
Sep 25, 2026
Merged

vbudhram merged 1 commit into
mainfrom
fxa-6661

Conversation

@vbudhram

@vbudhram vbudhram commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Because

  • /subscriptions still runs in Backbone, so it blocks the move of post-verify routes to React.
  • The earlier plan kept this route in Backbone until FXA-6117. This PR moves it now instead, behind the staged rollout flag.

This pull request

  • Adds a SubscriptionsRedirect page in fxa-settings for /subscriptions.
  • Keeps parity with Backbone: usePaymentsNextSubscriptionManagement picks subscriptions/landing.
  • Serves the route from React through postVerifyOtherRoutes in the content-server react-app routes, with fullProdRollout: false.
  • Passes the subscriptions config from content-server to fxa-settings.

Issue that this pull request solves

Closes: FXA-6661

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

  • Key files/areas to focus on: getSubscriptionsRedirect in SubscriptionsRedirect/index.tsx.
  • Suggested review order: the react-app routes, then App/index.tsx, then the page and its tests.
  • Risky or complex parts: the choice between the legacy management URL and the payments-next landing URL.

Screenshots (Optional)

Other information (Optional)

  • fullProdRollout: false stays. A reviewer asked to change it, but the epic rolls these routes out in stages.
  • SubscriptionsRedirect unit tests: 7 passed, 0 failed. eslint on the changed files and tsc --noEmit on fxa-settings exit 0.
  • I did not run functional tests. The operator validates the flows manually.
  • /subscriptions/products/:productId is out of scope because it has no users. The Backbone route and view for it stay for now.

@vbudhram vbudhram added the auto label Sep 23, 2026
@vbudhram
vbudhram requested a review from a team September 23, 2026 21:00
Copilot AI balanced review requested due to automatic review settings September 23, 2026 21:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Three moderate redirect correctness and privacy issues remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Moves subscription redirects from Backbone into the feature-gated React settings app while preserving payment routing and authentication behavior.

Changes:

  • Adds the SubscriptionsRedirect page and tests.
  • Registers gated subscription routes.
  • Exposes subscription configuration to settings.

Required changes:

  • Use the app’s resolved metricsEnabled value to avoid forwarding flow identifiers when metrics preferences are unknown.
  • Preserve literal + characters when forwarding query parameters.
  • Detect ?signin= by parameter presence rather than its value.
File Description
packages/​fxa-settings/​src/​pages/​SubscriptionsRedirect/​index.tsx Implements subscription redirect and token logic.
packages/​fxa-settings/​src/​pages/​SubscriptionsRedirect/​index.test.tsx Tests redirect and authentication scenarios.
packages/​fxa-settings/​src/​lib/​config.ts Defines subscription configuration.
packages/​fxa-settings/​src/​components/​App/​index.tsx Registers subscription routes.
packages/​fxa-content-server/​server/​lib/​routes/​react-app/​index.js Adds routes to the rollout group.
packages/​fxa-content-server/​server/​lib/​beta-settings.js Exposes subscription settings.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/fxa-settings/src/pages/SubscriptionsRedirect/index.tsx Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Six moderate issues remain in rollout routing, authentication, token issuance, metrics propagation, and query preservation.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
Resolved since last review (1)

Comment on lines +133 to +136
routes: reactRoute.getRoutes([
'subscriptions',
'subscriptions/products/[\\w_]+',
]),
Comment thread packages/fxa-settings/src/pages/SubscriptionsRedirect/index.tsx Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved moderate issues affect rollout, telemetry opt-out behavior, and duplicate redirect execution.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
Resolved since last review (1)

Comment thread packages/fxa-settings/src/pages/SubscriptionsRedirect/index.tsx Outdated
@vbudhram

Copy link
Copy Markdown
Contributor Author

The ai-fixme pipeline used both review rounds on this PR, so it stops here. One review comment is still open: guard the redirect effect with a ref so that StrictMode does not request two OAuth tokens in development. A human needs to decide on that fix and review the PR.

Copilot AI review requested due to automatic review settings September 25, 2026 16:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Product redirects and staged client-side handoff are incomplete, while the redirect effect can issue duplicate OAuth tokens.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 6 Medium severity

Open (6)

brandMessagingMode: config.get('brandMessagingMode'),
glean: { ...config.get('glean'), appDisplayVersion: config.get('version') },
redirectAllowlist: config.get('redirect_check.allow_list'),
subscriptions: config.get('subscriptions'),
postVerifyOtherRoutes: {
featureFlagOn: showReactApp.postVerifyOtherRoutes,
routes: [],
routes: reactRoute.getRoutes(['subscriptions']),
Comment on lines +679 to +680
path="/subscriptions"
element={<SubscriptionsRedirect {...{ isSignedIn }} />}
Comment on lines +32 to +36
const base = usePaymentsNextSubscriptionManagement
? `${config.servers.paymentsNext.url}/subscriptions/landing`
: `${managementUrl}/subscriptions`;
const query = params.toString();
const url = `${base}${query ? `?${query}` : ''}`;

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Backbone router and frontend rollout configuration do not yet hand enrolled users to the React route.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 6 Medium severity

Open (6)
Resolved since last review (1)

postVerifyOtherRoutes: {
featureFlagOn: showReactApp.postVerifyOtherRoutes,
routes: [],
routes: reactRoute.getRoutes(['subscriptions']),
flow: MetricsFlow | null;
metricsEnabled: boolean;
}) {
const { managementUrl, usePaymentsNextSubscriptionManagement } =

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion: remove usePaymentsNextSubscriptionManagement flag and managementUrl.

This boolean was added as part of the SP3 cutover. All traffic now goes to the SP3 sub manage page, so this feature flag can be removed.

Comment on lines +49 to +76
useEffect(() => {
if (redirected.current) {
return;
}
redirected.current = true;
const { url, unauthenticatedUrl } = getSubscriptionsRedirect({
config,
flow: getMetricsFlow(),
metricsEnabled: currentAccount()?.metricsEnabled !== false,
});

if (!isSignedIn) {
hardNavigate(unauthenticatedUrl);
return;
}

const { managementClientId, managementScopes, managementTokenTTL } =
config.subscriptions;
authClient
.createOAuthToken(sessionToken()!, managementClientId, {
scope: managementScopes,
ttl: managementTokenTTL,
})
.then(({ access_token }) =>
hardNavigate(`${url}#accessToken=${encodeURIComponent(access_token)}`)
)
.catch(() => hardNavigate(unauthenticatedUrl));
}, [authClient, config, isSignedIn]);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion: remove this logic and just redirect to {payments-next}/subscriptions/landing

Much of this logic has been refactored and moved to payments-next and should no longer be the responsibility of content-server.

## Because

- `/subscriptions` still runs in Backbone, so it blocks the move of post-verify routes to React.
- The earlier plan kept this route in Backbone until FXA-6117. This PR moves it now instead, behind the staged rollout flag.

## This pull request

- Adds a `SubscriptionsRedirect` page in fxa-settings that sends `/subscriptions` to payments-next `subscriptions/landing`, with flow params.
- Serves the route from React through `postVerifyOtherRoutes`, with `fullProdRollout: false`.
- Hands Backbone `/subscriptions` navigations to React with `createReactOrBackboneViewHandler`.

## Issue that this pull request solves

Closes: FXA-6661
Copilot AI review requested due to automatic review settings September 25, 2026 18:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The React redirect ignores the subscription-management rollout flag and always sends users to Payments Next.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 6 Medium severity

Open (7)

Comment on lines +39 to +42
getSubscriptionsRedirect({
paymentsNextUrl: config.servers.paymentsNext.url,
flow: getMetricsFlow(),
metricsEnabled: currentAccount()?.metricsEnabled !== false,

@StaberindeZA StaberindeZA left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

r+. lgtm. ty.

@vbudhram
vbudhram merged commit 459e0c8 into main Sep 25, 2026
23 checks passed
@vbudhram
vbudhram deleted the fxa-6661 branch September 25, 2026 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants