refactor(auth): remove stub account and finish_setup routes - #21332
Open
fxa-agent[bot] wants to merge 1 commit into
Open
fxa-agent[bot] wants to merge 1 commit into
fxa-agent[bot] wants to merge 1 commit into
Conversation
## Because - The ticket title asks us to investigate `POST /account/finish_setup`. The reporter's comment on the ticket decided to remove both halves of the stub-account flow, `POST /account/stub` and `POST /account/finish_setup`. This PR follows the comment. - No first-party caller remains. The passwordless checkout in fxa-payments-server used this flow, and that checkout is gone. Nothing issues the `fin` JWT that `finish_setup` consumes. - `/account/stub` is an unauthenticated endpoint that creates accounts. ## This pull request This PR only deletes code: 10 files, 888 lines removed, 0 lines added. - Removes the `/account/stub` and `/account/finish_setup` route entries, the `accountStub` and `finishSetup` handlers, and the `setPasswordOnStubAccount` helper from `account.ts`. Also removes the imports that only they used (`getClientById`, `generateAccessToken`, `oauth/jwt`, `uuidTransformer`). - Removes `ACCOUNT_STUB_POST` and `ACCOUNT_FINISH_SETUP_POST` from the swagger docs. - Removes the related tests: the `account.spec.ts` describe blocks with the jwt, oauth-client and oauth-grant mocks that only they used, the `stubAccount` and `finishAccountSetup` test-client helpers, and 4 remote tests in `account_create.in.spec.ts`. - Removes `finishSetup` and `finishSetupWithAuthPW` from fxa-auth-client. - Removes `finishSetup` from the content-server `lib/fxa-client.js`, `models/account.js` and `models/user.js`. These had no callers and no specs. This is a breaking API change. It removes two public auth-server endpoints and two fxa-auth-client methods. An external caller of these endpoints will get a 404. We know of no legitimate external caller. ## Issue that this pull request solves Closes: https://mozilla-hub.atlassian.net/browse/FXA-14623
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The subscription reminder flow still generates links and tokens for the removed setup endpoint.
Review effort: Lite
Findings: 1
What changed in this PR
Removes the obsolete stub-account and finish-setup flows across auth-server, auth-client, and content-server.
Changes:
- Deletes both public endpoints and Swagger documentation.
- Removes related handlers, client methods, models, and tests.
- Leaves the subscription reminder flow targeting the removed setup endpoint.
| File | Summary |
|---|---|
packages/fxa-content-server/app/scripts/models/user.js |
Removes the setup method. |
packages/fxa-content-server/app/scripts/models/account.js |
Removes the setup method. |
packages/fxa-content-server/app/scripts/lib/fxa-client.js |
Removes the client wrapper. |
packages/fxa-auth-server/test/remote/account_create.in.spec.ts |
Removes integration tests. |
packages/fxa-auth-server/test/client/index.js |
Removes test helpers. |
packages/fxa-auth-server/test/client/api.js |
Removes test API methods. |
packages/fxa-auth-server/lib/routes/account.ts |
Removes handlers and routes. |
packages/fxa-auth-server/lib/routes/account.spec.ts |
Removes route tests and mocks. |
packages/fxa-auth-server/docs/swagger/account-api.ts |
Removes endpoint documentation. |
packages/fxa-auth-client/lib/client.ts |
Removes setup methods. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -2602,49 +2399,6 @@ export const accountRoutes = ( | |||
| }, | |||
| handler: (request: AuthRequest) => accountHandler.accountCreate(request), | |||
| }, | |||
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Because
POST /account/finish_setup. The reporter's comment on the ticket decided to remove both halves of the stub-account flow,POST /account/stubandPOST /account/finish_setup. This PR follows the comment.finJWT thatfinish_setupconsumes./account/stubis an unauthenticated endpoint that creates accounts.This pull request
This PR only deletes code: 10 files, 888 lines removed, 0 lines added.
/account/stuband/account/finish_setuproute entries, theaccountStubandfinishSetuphandlers, and thesetPasswordOnStubAccounthelper fromaccount.ts. Also removes the imports that only they used (getClientById,generateAccessToken,oauth/jwt,uuidTransformer).ACCOUNT_STUB_POSTandACCOUNT_FINISH_SETUP_POSTfrom the swagger docs.account.spec.tsdescribe blocks with the jwt, oauth-client and oauth-grant mocks that only they used, thestubAccountandfinishAccountSetuptest-client helpers, and 4 remote tests inaccount_create.in.spec.ts.finishSetupandfinishSetupWithAuthPWfrom fxa-auth-client.finishSetupfrom the content-serverlib/fxa-client.js,models/account.jsandmodels/user.js. These had no callers and no specs.This is a breaking API change. It removes two public auth-server endpoints and two fxa-auth-client methods. An external caller of these endpoints will get a 404. We know of no legitimate external caller.
Issue that this pull request solves
Closes: https://mozilla-hub.atlassian.net/browse/FXA-14623
Checklist
Put an
xin the boxes that applyHow to review (Optional)
packages/fxa-auth-server/lib/routes/account.tsScreenshots (Optional)
Other information (Optional)
I ran these checks locally through
/fxa-verify. Each one passed:curl POST localhost:9000/v1/account/stubwith a valid payload returns 404. Before this change, the same request created an account.curl POST localhost:9000/v1/account/finish_setupreturns 404.accountsrow for the email sent to/account/stub.signIn.spec.ts"login as an existing user" passes. This test loads the content-server bundle.test/remote/account_create.in.spec.ts: 68 passed, 0 failed.lib/routes/account.spec.ts: 133 passed, 0 failed.tscandeslintpass for auth-server (tsconfig.build.json) and auth-client.I ran
tsc --noEmitfor content-server andeslinton its 3 changed files by hand. Both passed.CI runs the full suites.
Not in this PR:
fxa_route_catalog.pyare not in this repo.signupUtilsandsubscriptionAccountRemindersparams ofAccountHandlerare now unused. We keep them so that the positional wiring does not change. A follow-up can remove them.scripts/verification-reminders.jsstill signs afinJWT for the subscription "finish setup" reminder emails. Those emails and thesubscription_account_finish_setupmetric are out of scope.