feat: add tracing for money-account-balance-service network requests - #9451
Merged
Conversation
… requests Add a `trace` constructor callback to MoneyAccountApiDataService that emits best-effort backdated spans for all HTTP calls (fetchPositions, fetchInterest, fetchHistory, fetchRateHistory). Tracing is isolated from fetch/retry logic so trace failures never impact queries. Mirrors the approach used in money-account-balance-service (PR #9434). Co-authored-by: Cursor <cursoragent@cursor.com>
Member
Author
|
@metamaskbot publish-preview |
Contributor
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
The live Money Account API now returns a `balance` object in the positions response. The strict superstruct `object()` validator rejected the unknown key, causing `fetchPositions` to throw a validation error. Add the `balance` field as optional to the struct and export the new `Balance` type. Co-authored-by: Cursor <cursoragent@cursor.com>
Member
Author
|
@metamaskbot publish-preview |
Contributor
|
Preview builds have been published. Learn how to use preview builds in other projects. Expand for full list of packages and versions. |
Resolve conflicts by keeping API data service network tracing and adopting main's nullable PositionBalance contract from #9554. Co-authored-by: Cursor <cursoragent@cursor.com>
ffmcgee725
marked this pull request as ready for review
July 21, 2026 14:34
ffmcgee725
temporarily deployed
to
default-branch
July 21, 2026 14:35 — with
GitHub Actions
Inactive
Co-authored-by: Cursor <cursoragent@cursor.com>
ffmcgee725
enabled auto-merge
July 21, 2026 14:51
shane-t
approved these changes
Jul 21, 2026
pull Bot
pushed a commit
to dmrazzy/core
that referenced
this pull request
Jul 22, 2026
## @metamask/money-account-api-data-service ## [0.3.0] ### Added - Add optional `trace` callback to `MoneyAccountApiDataService` constructor for network request tracing ([MetaMask#9451](MetaMask#9451)) - All HTTP calls (`fetchPositions`, `fetchInterest`, `fetchHistory`, `fetchRateHistory`) emit best-effort backdated traces with `startTime`, `success`, and `errorName` attributes - Tracing is isolated from fetch/retry logic; trace failures do not impact queries ## @metamask/chomp-api-service ## [4.0.0] ### Added - Add `getAssociatedAddresses` method, exposed as the `ChompApiService:getAssociatedAddresses` messenger action, which fetches the active address associations of the authenticated profile via `GET /v1/auth/address` ([MetaMask#9387](MetaMask#9387)) - Also adds the `ProfileAddressEntry` type describing each returned entry and the `ChompApiServiceGetAssociatedAddressesAction` type - Returned addresses are parsed into canonical lowercase form, entries are guaranteed to have `status: 'active'`, and results are never served from cache - The query cache key is scoped to the authenticated profile via a SHA-256 digest of the bearer token, so concurrent calls only share an in-flight request when they are for the same profile and one profile's associations are never cached under another's key ### Changed - **BREAKING:** `associateAddress` now throws an `HttpError` on a 409 response instead of returning the parsed body ([MetaMask#9387](MetaMask#9387)) - A 409 from `POST /v1/auth/address` indicates the address is associated with a _different_ profile; the previous handling attempted to parse the error body as an association result and failed with a confusing validation error. An address already associated with the authenticated profile is reported via a 201 response with `status: 'active'`, which is unchanged. - Bump `@metamask/utils` from `^11.9.0` to `^11.11.0` ([MetaMask#9074](MetaMask#9074)) - Bump `@metamask/controller-utils` from `^12.0.0` to `^12.3.0` ([MetaMask#8774](MetaMask#8774), [MetaMask#9058](MetaMask#9058), [MetaMask#9083](MetaMask#9083), [MetaMask#9218](MetaMask#9218)) - Bump `@metamask/base-data-service` from `^0.1.2` to `^0.1.3` ([MetaMask#8799](MetaMask#8799)) - Bump `@metamask/messenger` from `^1.2.0` to `^2.0.0` ([MetaMask#9392](MetaMask#9392)) - Update `LICENSE` text ([MetaMask#9472](MetaMask#9472)) ## @metamask/money-account-upgrade-controller ## [3.0.0] - **BREAKING:** Add persisted state tracking fully upgraded accounts ([MetaMask#9500](MetaMask#9500)) - `MoneyAccountUpgradeControllerState` changes from `Record<string, never>` to `{ upgradedAccounts }`, keyed by lowercased account address. Each entry records when the upgrade sequence completed and a fingerprint of the config it completed under (see new `MoneyAccountUpgradeStatus` type). Code constructing the state type (e.g. `{}` in tests or default-state maps) must include `upgradedAccounts`. - The constructor now accepts an optional `state` option, merged with the defaults; add `getDefaultMoneyAccountUpgradeControllerState` to construct those defaults. - Add `TerminalUpgradeError` and `isTerminalMoneyAccountUpgradeError`, and a `terminal` property on `MoneyAccountUpgradeStepError`, marking failures that cannot resolve by retrying — currently an account delegated to a third-party EIP-7702 implementation, an account with unexpected on-chain code, or an address confirmed to be associated with a different CHOMP profile ([MetaMask#9500](MetaMask#9500)) - The controller does not retry on its own; clients implementing their own retry logic around `upgradeAccount` can use `isTerminalMoneyAccountUpgradeError` to stop retrying failures that cannot succeed. ### Changed - **BREAKING:** The `associate-address` upgrade step now checks the profile's existing address associations via `ChompApiService:getAssociatedAddresses` before signing, and reports `already-done` without signing or submitting anything when the address is already associated ([MetaMask#9387](MetaMask#9387)) - `MoneyAccountUpgradeControllerMessenger` consumers must grant the `ChompApiService:getAssociatedAddresses` action alongside the previously required actions, and must provide a `@metamask/chomp-api-service` version that registers it (`>=4.0.0`). - The lookup is an optimization: if it fails, the step falls through to the previous sign-and-submit behavior. - A 409 conflict from the association request is disambiguated by re-fetching the associations, so a same-profile create race reports `already-done` instead of failing the upgrade; a genuine conflict (address associated with a different profile) still fails the step. - `upgradeAccount` now skips the step sequence entirely when the account is recorded in state as upgraded under the active config fingerprint, and records the account after a successful run. If the chain, CHOMP contract addresses, or Delegation Framework version change, the fingerprint no longer matches and the sequence re-runs ([MetaMask#9500](MetaMask#9500)) - Bump `@metamask/messenger` from `^1.2.0` to `^2.0.0` ([MetaMask#9392](MetaMask#9392)) - Bump `@metamask/authenticated-user-storage` from `^3.0.0` to `^3.0.1` ([MetaMask#9458](MetaMask#9458)) - Bump `@metamask/chomp-api-service` from `^3.1.0` to `^4.0.0` ([MetaMask#9586](MetaMask#9586)) <!-- Thanks for your contribution! Take a moment to answer these questions so that reviewers have the information they need to properly understand your changes: * What is the current state of things and why does it need to change? * What is the solution your changes offer and how does it work? * Are there any changes whose purpose might not obvious to those unfamiliar with the domain? * If your primary goal was to update one package but you found you had to update another one along the way, why did you do so? * If you had to upgrade a dependency, why did you do so? --> ## References <!-- Are there any issues that this pull request is tied to? Are there other links that reviewers should consult to understand these changes better? Are there client or consumer pull requests to adopt any breaking changes? For example: * Fixes #12345 * Related to #67890 --> ## Checklist - [ ] I've updated the test suite for new or updated code as appropriate - [ ] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [ ] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **High Risk** > Multiple breaking releases affect CHOMP address association error handling and Money account upgrade state/messenger permissions; consumers must adopt new versions and migration steps together. > > **Overview** > **Monorepo release `1137.0.0`** — version bumps, finalized changelogs, and `yarn.lock` alignment for Money/CHOMP packages (no new implementation in this diff beyond release metadata). > > **`@metamask/chomp-api-service@4.0.0` (breaking):** ships `getAssociatedAddresses` and changes **`associateAddress`** to **throw on HTTP 409** instead of parsing the error body. > > **`@metamask/money-account-upgrade-controller@3.0.0` (breaking):** persisted **`upgradedAccounts`** state (config fingerprint), **terminal upgrade errors**, associate-address pre-check via **`getAssociatedAddresses`**, and **409 disambiguation**; depends on **`chomp-api-service@^4.0.0`**. > > **`@metamask/money-account-api-data-service@0.3.0`:** optional constructor **`trace`** callback for Money API HTTP calls. **`money-account-balance-service`** only bumps that dependency to `^0.3.0` (changelog under Unreleased; no package version bump in this diff). > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit edd0ba1. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Merged
10 tasks
pull Bot
pushed a commit
to Reality2byte/metamask-mobile
that referenced
this pull request
Jul 23, 2026
…etaMask#33701) ## **Description** Adds Sentry tracing instrumentation to `MoneyAccountApiDataService` network calls (`fetchPositions`, `fetchInterest`, `fetchHistory`, `fetchRateHistory`). Bumps `@metamask/money-account-api-data-service` to `^0.3.0` which exposes an optional `trace` constructor callback ([MetaMask/core#9451](MetaMask/core#9451)), then wires a Sentry adapter into the service init — matching the pattern already established in `money-account-balance-service-init.ts`. ### Changes - Bumped `@metamask/money-account-api-data-service` from `^0.2.0` to `^0.3.0` - Added `sentryTrace` adapter in `money-account-api-data-service-init.ts` that: - Forwards trace requests into the shared `trace()` utility (Sentry `startSpan`) - Tags spans with `op: TraceOperation.MoneyAccountDataFetch` for Sentry filtering - Includes `app_state` (foreground/background) in trace data for performance segmentation - Passes through service-provided `tags` and `data` (e.g. `success`, `errorName`) - Passed `trace: sentryTrace` to the `MoneyAccountApiDataService` constructor - Added unit tests covering trace callback forwarding, operation tagging, app state enrichment, and caller data preservation ## **Changelog** CHANGELOG entry: Instrument Money Account API data service HTTP calls with Sentry tracing ## **Related issues** Fixes: N/A Related: https://consensyssoftware.atlassian.net/browse/MUSD-1044 Related: - Core tracing PR: MetaMask/core#9451 - Balance service tracing (prior art): MetaMask/core#9434 ## **Manual testing steps** ```gherkin Feature: Sentry tracing for Money Account API calls Scenario: Traces appear in Sentry for API data service calls Given the user has metrics consent enabled And the user has a funded Money Account When the user navigates to Money home (triggering fetchPositions) Then a Sentry span is emitted with operation "money.account.data_fetch" And the span includes startTime, success, and app_state attributes Scenario: Trace failures do not impact queries Given Sentry is unreachable or throws internally When the user triggers a Money API fetch Then the balance still loads successfully And no user-facing error is shown ``` ## **Screenshots/Recordings** N/A — observability-only change with no visual impact ## **Pre-merge author checklist** - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [x] I've included tests if applicable - [x] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [ ] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [ ] I've tested on Android - [ ] I've tested with a power user scenario - [x] I've instrumented key operations with Sentry traces for production performance metrics ## **Pre-merge reviewer checklist** - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Observability-only wiring with no changes to fetch logic or user-facing behavior; pattern matches existing balance service tracing. > > **Overview** > Wires **Sentry tracing** into `MoneyAccountApiDataService` by bumping `@metamask/money-account-api-data-service` to **^0.3.0** and passing a new `sentryTrace` adapter at init time, mirroring the balance service pattern. > > The adapter forwards the package’s optional trace callback into the shared `trace()` helper, sets `op` to `TraceOperation.MoneyAccountDataFetch`, and enriches span data with **`app_state`** (or `unknown` when unset) while preserving caller `tags` and `data`. Unit tests cover constructor wiring, operation tagging, app state handling, data merge behavior, and callback forwarding. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit e4a1f88. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add a
traceconstructor callback to MoneyAccountApiDataService that emits best-effort backdated spans for all HTTP calls (fetchPositions, fetchInterest, fetchHistory, fetchRateHistory). Tracing is isolated from fetch/retry logic so trace failures never impact queries. Mirrors the approach used in money-account-balance-service (PR #9434).Explanation
References
Checklist
Note
Low Risk
Additive, optional observability with isolated error handling; no changes to API contracts or core fetch/retry semantics beyond wrapping existing logic.
Overview
Adds an optional
traceconstructor callback so consumers can observe Money Account API HTTP calls without changing fetch, cache, or retry behavior.Each of
fetchPositions,fetchInterest,fetchHistory, andfetchRateHistoryruns its network work through a shared#traceNetworkRequesthelper that emits best-effort backdated spans withstartTime,success, anderrorName(when applicable). Traces fire only on cache misses (when thequeryFnactually runs). Trace emission is wrapped so sync throws and async rejections are logged and never affect query results.New public types include
MoneyAccountApiDataServiceOptions,MoneyAccountApiDataServiceTraceCallback,MoneyAccountApiDataServiceTraceRequest, andTRACESname constants; the changelog documents the feature.Reviewed by Cursor Bugbot for commit fa19ff9. Bugbot is set up for automated code reviews on this repo. Configure here.