Skip to content

refactor(auth): remove stub account and finish_setup routes - #21332

Open
fxa-agent[bot] wants to merge 1 commit into
mainfrom
fxa-14623
Open

fxa-agent[bot] wants to merge 1 commit into
mainfrom
fxa-14623

Conversation

@fxa-agent

@fxa-agent fxa-agent Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Because

  • The ticket title asks us to investigate POST /account/finish_setup. The reporter's comment on the ticket decided to remove both halves of the stub-account flow, POST /account/stub and POST /account/finish_setup. This PR follows the comment.
  • No first-party caller remains. The passwordless checkout in fxa-payments-server used this flow, and that checkout is gone. Nothing issues the fin JWT that finish_setup consumes.
  • /account/stub is an unauthenticated endpoint that creates accounts.

This pull request

This PR only deletes code: 10 files, 888 lines removed, 0 lines added.

  • Removes the /account/stub and /account/finish_setup route entries, the accountStub and finishSetup handlers, and the setPasswordOnStubAccount helper from account.ts. Also removes the imports that only they used (getClientById, generateAccessToken, oauth/jwt, uuidTransformer).
  • Removes ACCOUNT_STUB_POST and ACCOUNT_FINISH_SETUP_POST from the swagger docs.
  • Removes the related tests: the account.spec.ts describe blocks with the jwt, oauth-client and oauth-grant mocks that only they used, the stubAccount and finishAccountSetup test-client helpers, and 4 remote tests in account_create.in.spec.ts.
  • Removes finishSetup and finishSetupWithAuthPW from fxa-auth-client.
  • Removes finishSetup from the content-server lib/fxa-client.js, models/account.js and models/user.js. These had no callers and no specs.

This is a breaking API change. It removes two public auth-server endpoints and two fxa-auth-client methods. An external caller of these endpoints will get a 404. We know of no legitimate external caller.

Issue that this pull request solves

Closes: https://mozilla-hub.atlassian.net/browse/FXA-14623

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

  • Key files/areas to focus on: packages/fxa-auth-server/lib/routes/account.ts
  • Suggested review order: auth-server, then auth-client, then content-server.
  • Risky or complex parts: the removal of the two public endpoints. One reviewer call: remove both endpoints now, without a deprecation period?

Screenshots (Optional)

Other information (Optional)

I ran these checks locally through /fxa-verify. Each one passed:

  • curl POST localhost:9000/v1/account/stub with a valid payload returns 404. Before this change, the same request created an account.
  • curl POST localhost:9000/v1/account/finish_setup returns 404.
  • MySQL has no accounts row for the email sent to /account/stub.
  • Functional: signIn.spec.ts "login as an existing user" passes. This test loads the content-server bundle.
  • Integration: test/remote/account_create.in.spec.ts: 68 passed, 0 failed.
  • Unit: lib/routes/account.spec.ts: 133 passed, 0 failed.
  • tsc and eslint pass for auth-server (tsconfig.build.json) and auth-client.

I ran tsc --noEmit for content-server and eslint on its 3 changed files by hand. Both passed.

CI runs the full suites.

Not in this PR:

  • The dashboard panels in fxa_route_catalog.py are not in this repo.
  • The signupUtils and subscriptionAccountReminders params of AccountHandler are now unused. We keep them so that the positional wiring does not change. A follow-up can remove them.
  • scripts/verification-reminders.js still signs a fin JWT for the subscription "finish setup" reminder emails. Those emails and the subscription_account_finish_setup metric are out of scope.
  • We could not check external clients (PyFxA, Firefox desktop and mobile) from this VM.

## Because

- The ticket title asks us to investigate `POST /account/finish_setup`. The reporter's comment on the ticket decided to remove both halves of the stub-account flow, `POST /account/stub` and `POST /account/finish_setup`. This PR follows the comment.
- No first-party caller remains. The passwordless checkout in fxa-payments-server used this flow, and that checkout is gone. Nothing issues the `fin` JWT that `finish_setup` consumes.
- `/account/stub` is an unauthenticated endpoint that creates accounts.

## This pull request

This PR only deletes code: 10 files, 888 lines removed, 0 lines added.

- Removes the `/account/stub` and `/account/finish_setup` route entries, the `accountStub` and `finishSetup` handlers, and the `setPasswordOnStubAccount` helper from `account.ts`. Also removes the imports that only they used (`getClientById`, `generateAccessToken`, `oauth/jwt`, `uuidTransformer`).
- Removes `ACCOUNT_STUB_POST` and `ACCOUNT_FINISH_SETUP_POST` from the swagger docs.
- Removes the related tests: the `account.spec.ts` describe blocks with the jwt, oauth-client and oauth-grant mocks that only they used, the `stubAccount` and `finishAccountSetup` test-client helpers, and 4 remote tests in `account_create.in.spec.ts`.
- Removes `finishSetup` and `finishSetupWithAuthPW` from fxa-auth-client.
- Removes `finishSetup` from the content-server `lib/fxa-client.js`, `models/account.js` and `models/user.js`. These had no callers and no specs.

This is a breaking API change. It removes two public auth-server endpoints and two fxa-auth-client methods. An external caller of these endpoints will get a 404. We know of no legitimate external caller.

## Issue that this pull request solves

Closes: https://mozilla-hub.atlassian.net/browse/FXA-14623
@fxa-agent
fxa-agent Bot requested a review from a team as a code owner September 28, 2026 23:47
@fxa-agent fxa-agent Bot added the auto label Sep 28, 2026
@vbudhram
vbudhram requested a lite review from Copilot September 28, 2026 23:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The subscription reminder flow still generates links and tokens for the removed setup endpoint.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Removes the obsolete stub-account and finish-setup flows across auth-server, auth-client, and content-server.

Changes:

  • Deletes both public endpoints and Swagger documentation.
  • Removes related handlers, client methods, models, and tests.
  • Leaves the subscription reminder flow targeting the removed setup endpoint.
File Summary
packages/​fxa-content-server/​app/​scripts/​models/​user.js Removes the setup method.
packages/​fxa-content-server/​app/​scripts/​models/​account.js Removes the setup method.
packages/​fxa-content-server/​app/​scripts/​lib/​fxa-client.js Removes the client wrapper.
packages/​fxa-auth-server/​test/​remote/​account_create.in.spec.ts Removes integration tests.
packages/​fxa-auth-server/​test/​client/​index.js Removes test helpers.
packages/​fxa-auth-server/​test/​client/​api.js Removes test API methods.
packages/​fxa-auth-server/​lib/​routes/​account.ts Removes handlers and routes.
packages/​fxa-auth-server/​lib/​routes/​account.spec.ts Removes route tests and mocks.
packages/​fxa-auth-server/​docs/​swagger/​account-api.ts Removes endpoint documentation.
packages/​fxa-auth-client/​lib/​client.ts Removes setup methods.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@@ -2602,49 +2399,6 @@ export const accountRoutes = (
},
handler: (request: AuthRequest) => accountHandler.accountCreate(request),
},

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants