You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Verify the default approval flow is still visible and the admin is set as the approver
Offline tests
None
QA Steps
Same as Tests
PR Author Checklist
I linked the correct issue in the ### Fixed Issues section above
I wrote clear testing steps that cover the changes made in this PR
I added steps for local testing in the Tests section
I added steps for the expected offline behavior in the Offline steps section
I added steps for Staging and/or Production testing in the QA steps section
I added steps to cover failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
I tested this PR with a High Traffic account against the staging or production API to ensure there are no regressions (e.g. long loading states that impact usability).
I included screenshots or videos for tests on all platforms
I ran the tests on all platforms & verified they passed on:
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari
I verified there are no console errors (if there's a console error not related to the PR, report it or open an issue for it to be fixed)
I verified there are no new alerts related to the canBeMissing param for useOnyx
I verified that any callback methods that were added or modified are named for what the method does and never what callback they handle (i.e. toggleReport and not onIconClick)
I verified that comments were added to code that is not self explanatory
I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
I verified any copy / text shown in the product is localized by adding it to src/languages/* files and using the translation method
If any non-english text was added/modified, I used JaimeGPT to get English > Spanish translation. I then posted it in #expensify-open-source and it was approved by an internal Expensify engineer. Link to Slack message:
I verified all numbers, amounts, dates and phone numbers shown in the product are using the localization methods
I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
I verified proper file naming conventions were followed for any new files or renamed files. All non-platform specific files are named after what they export and are not named "index.js". All platform-specific files are named for the platform the code supports as outlined in the README.
I verified the JSDocs style guidelines (in STYLE.md) were followed
If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
I tested other components that can be impacted by my changes (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar are working as expected)
I verified all code is DRY (the PR doesn't include any logic written more than once, with the exception of tests)
I verified any variables that can be defined as constants (ie. in CONST.ts or at the top of the file that uses the constant) are defined as such
I verified that if a function's arguments changed that all usages have also been updated correctly
If any new file was added I verified that:
The file has a description of what it does and/or why is needed at the top of the file if the code is not self explanatory
If a new CSS style is added I verified that:
A similar style doesn't already exist
The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))
If new assets were added or existing ones were modified, I verified that:
The assets are optimized and compressed (for SVG files, run npm run compress-svg)
The assets load correctly across all supported platforms.
If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
I verified that all the inputs inside a form are aligned with each other.
I added Design label and/or tagged @Expensify/design so the design team can review the changes.
If a new page is added, I verified it's using the ScrollView component to make it scrollable when more elements are added to the page.
I added unit tests for any new feature or bug fix in this PR to help automatically prevent regressions in this user flow.
If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.
Objective: To create a detailed and reliable record of critical system actions for security analysis and compliance.
Status: Missing audit logs: Newly added logic updates approval workflows and removes members but adds no explicit audit logging of these critical changes (who removed whom, which workflows changed).
Referred Code
Navigation.navigate(ROUTES.WORKSPACE_INVITE.getRoute(route.params.policyID,Navigation.getActiveRouteWithoutParams()));},[route.params.policyID,isAccountLocked,showLockedAccountModal]);/** * Remove selected users from the workspace * Please see https://github.com/Expensify/App/blob/main/README.md#Security for more details */constremoveUsers=()=>{// Check if any of the members are approversconsthasApprovers=selectedEmployees.some((email)=>isApprover(policy,email));if(hasApprovers){constownerEmail=ownerDetails.login;for(constloginofselectedEmployees){constaccountID=policyMemberEmailsToAccountIDs[login];constremovedApprover=personalDetails?.[accountID];if(!removedApprover?.login||!ownerEmail){continue;}constupdatedWorkflows=updateWorkflowDataOnApproverRemoval({approvalWorkflows,
... (clipped21lines)
Generic: Robust Error Handling and Edge Case Management
Objective: Ensure comprehensive error handling that provides meaningful context and graceful degradation
Status: No error paths: The new removal flow updates workflows and policy settings but does not handle or surface API or update failures in the added code paths, relying on underlying APIs without local fallback or user-facing error handling.
Referred Code
constremoveUser=useCallback(()=>{constownerEmail=ownerDetails?.login;constremovedApprover=personalDetails?.[accountID];// If the user is not an approver, proceed with member removalif(!isApproverUserAction(policy,memberLogin)||!removedApprover?.login||!ownerEmail){removeMemberAndCloseModal();return;}// Update approval workflows after approver removalconstupdatedWorkflows=updateWorkflowDataOnApproverRemoval({
approvalWorkflows,
removedApprover,
ownerDetails,});for(constworkflowofupdatedWorkflows){if(workflow?.removeApprovalWorkflow){const{removeApprovalWorkflow, ...updatedWorkflow}=workflow;
... (clipped9lines)
Generic: Security-First Input Validation and Data Handling
Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent vulnerabilities
Status: Missing validation: The added logic derives emails and account IDs from state and proceeds with updates/removals without explicit validation or authorization checks in these new call sites, assuming upstream correctness.
The logic for updating approval workflows upon member removal is duplicated across WorkspaceMembersPage.tsx and WorkspaceMemberDetailsPage.tsx. This should be consolidated into a single new action to centralize logic and improve maintainability.
constremoveUsers=()=>{// Check if any of the members are approversconsthasApprovers=selectedEmployees.some((email)=>isApprover(policy,email));if(hasApprovers){constownerEmail=ownerDetails.login;for(constloginofselectedEmployees){constaccountID=policyMemberEmailsToAccountIDs[login];constremovedApprover=personalDetails?.[accountID];if(!removedApprover?.login||!ownerEmail){
... (clipped18lines)
constremoveUser=useCallback(()=>{constownerEmail=ownerDetails?.login;constremovedApprover=personalDetails?.[accountID];// If the user is not an approver, proceed with member removalif(!isApproverUserAction(policy,memberLogin)||!removedApprover?.login||!ownerEmail){removeMemberAndCloseModal();return;}
... (clipped20lines)
Solution Walkthrough:
Before:
// In WorkspaceMembersPage.tsxfunctionremoveUsers(){// ... check if removed members are approversif(hasApprovers){// ... loop through removed members// ... call updateWorkflowDataOnApproverRemoval// ... loop through updated workflows// ... call removeApprovalWorkflowAction or updateApprovalWorkflow}removeMembers(...);}// In WorkspaceMemberDetailsPage.tsxfunctionremoveUser(){// ... check if removed member is an approverif(isApprover){// ... call updateWorkflowDataOnApproverRemoval// ... loop through updated workflows// ... call removeApprovalWorkflowAction or updateApprovalWorkflow}removeMemberAndCloseModal();// which calls removeMembers()}
After:
// In a new action in src/libs/actions/Policy/Member.tsfunctionremoveMembersAndUpdateWorkflows(policyID,membersToRemove, ...){// ... check if removed members are approversif(hasApprovers){// ... loop through removed members// ... call updateWorkflowDataOnApproverRemoval// ... loop through updated workflows// ... call removeApprovalWorkflowAction or updateApprovalWorkflow}// Handle "Prevent Self Approval" logicif(remainingEmployeeCount===1&&policy.preventSelfApproval){setPolicyPreventSelfApproval(policyID,false);}removeMembers(policyID, ...);}// In WorkspaceMembersPage.tsx and WorkspaceMemberDetailsPage.tsx// Call the new consolidated actionremoveMembersAndUpdateWorkflows(policyID,selectedEmployees, ...);
Suggestion importance[1-10]: 9
__
Why: The suggestion correctly identifies significant code duplication of business logic in two UI components, which is a major maintainability concern, and proposes a sound architectural improvement by centralizing it into a single action.
High
Possible issue
Correctly count active workspace members
Correct the calculation of previousEmployeesCount by filtering out employees with a pendingAction of 'delete' to ensure an accurate count of active members.
// Function to remove a member and close the modal
const removeMemberAndCloseModal = useCallback(() => {
removeMembers(policyID, [memberLogin], {[memberLogin]: accountID});
- const previousEmployeesCount = Object.keys(policy?.employeeList ?? {}).length;+ const previousEmployeesCount = Object.values(policy?.employeeList ?? {}).filter(+ (employee) => employee.pendingAction !== CONST.RED_BRICK_ROAD_PENDING_ACTION.DELETE,+ ).length;
const remainingEmployeeCount = previousEmployeesCount - 1;
if (remainingEmployeeCount === 1 && policy?.preventSelfApproval) {
// We can't let the "Prevent Self Approvals" enabled if there's only one workspace user
setPolicyPreventSelfApproval(policyID, false);
}
setIsRemoveMemberConfirmModalVisible(false);
}, [accountID, memberLogin, policy?.employeeList, policy?.preventSelfApproval, policyID]);
Apply / Chat
Suggestion importance[1-10]: 8
__
Why: The suggestion correctly identifies a bug where the count of remaining employees includes those pending deletion, which could lead to incorrect logic for disabling the 'Prevent Self Approval' setting.
Medium
More
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
Benchmark PR Expensify#76153
Type: Clean (correct implementation)
Original PR Title: Revert "Merge pull request Expensify#73676 from mkzie2/mkzie2-issue/70286"
Original PR Description: ### Explanation of Change
Reverts Expensify#73676
Fixed Issues
$ Expensify#76086
Tests
Offline tests
None
QA Steps
Same as Tests
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectioncanBeMissingparam foruseOnyxtoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Screen.Recording.2025-11-26.at.11.04.50.AM.mov
Original PR URL: Expensify#76153
PR Type
Bug fix
Description
Revert approval workflow changes that incorrectly handled pending actions during member removal
Simplify
pendingActionlogic by removing conditional preservation of DELETE statusMove workflow update logic from
Member.tsto UI layer for better separation of concernsRemove unused helper functions and consolidate workflow management code
Diagram Walkthrough
File Walkthrough
WorkflowUtils.ts
Simplify pending action assignment logicsrc/libs/WorkflowUtils.ts
pendingActionassignment to always use the provided valueupdated
ExpenseReportRulesSection.tsx
Simplify prevent self approvals lock logicsrc/pages/workspace/rules/ExpenseReportRulesSection.tsx
membersCountandshouldLockPreventSelfApprovalsworkflowApprovalsUnavailableMember.ts
Remove workflow handling from member removalsrc/libs/actions/Policy/Member.ts
removeMembersfunctionapprovalWorkflowsandallPersonalDetailsparametersmember removal
Policy.ts
Consolidate prevent self approval logicsrc/libs/actions/Policy/Policy.ts
getSetPolicyPreventSelfApprovalOnyxDatalogic intosetPolicyPreventSelfApprovalgetSetPolicyPreventSelfApprovalOnyxDatafunctiondata
Workflow.ts
Consolidate workflow update and remove functionssrc/libs/actions/Workflow.ts
getUpdateApprovalWorkflowOnyxDatalogic intoupdateApprovalWorkflowgetRemoveApprovalWorkflowOnyxDatalogic intoremoveApprovalWorkflowPolicyMemberTest.ts
Update tests for simplified member removaltests/actions/PolicyMemberTest.ts
removeMemberswith simplified parametersallPersonalDetailsand emptyapprovalWorkflowsarray fromfunction calls
PersonalDetailsListtype importWorkspaceMembersPage.tsx
Move workflow handling to UI layersrc/pages/workspace/WorkspaceMembersPage.tsx
removeUsersfunction before callingremoveMembersaccordingly
removeApprovalWorkflowActionorupdateApprovalWorkflowbased onworkflow state
removeMemberscall by removing workflow-related parametersWorkspaceMemberDetailsPage.tsx
Add workflow and self-approval handling to member detailssrc/pages/workspace/members/WorkspaceMemberDetailsPage.tsx
removeUsercallback before memberremoval
accordingly
remains
setPolicyPreventSelfApprovalto handle self-approval setting