fix(auth,settings): keep account data usable on subscription errors - #21358
Open
fxa-agent[bot] wants to merge 1 commit into
Open
fxa-agent[bot] wants to merge 1 commit into
fxa-agent[bot] wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Add App Store failure coverage and prevent duplicate Sentry reporting for account outages.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Improves account and subscription error handling so Settings avoids misleading defaults and invalid password dates.
Changes:
- Returns empty subscriptions on provider failures, with reporting for unexpected errors.
- Shows an error dialog for account-fetch failures.
- Hides missing password creation dates and adds test coverage.
| File | Summary |
|---|---|
packages/fxa-settings/src/lib/hooks/useAccountData/index.ts |
Propagates account-fetch errors. |
packages/fxa-settings/src/lib/hooks/useAccountData/index.test.ts |
Tests account and profile failure handling. |
packages/fxa-settings/src/components/Settings/Security/index.tsx |
Hides missing password dates. |
packages/fxa-settings/src/components/Settings/Security/index.test.tsx |
Tests password date rendering. |
packages/fxa-settings/src/components/Settings/Security/index.stories.tsx |
Adds the missing-date story. |
packages/fxa-auth-server/lib/routes/account.ts |
Handles subscription read failures. |
packages/fxa-auth-server/lib/routes/account.spec.ts |
Tests subscription failure behavior. |
packages/functional-tests/tests/settings/accountFetchError.spec.ts |
Adds functional error coverage. |
packages/functional-tests/pages/settings/index.ts |
Adds the error-dialog page-object getter. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+268
to
+271
| Sentry.captureMessage( | ||
| `Failed to fetch account: ${accountResult.reason}` | ||
| ); | ||
| throw accountResult.reason; |
## Because
- GET /v1/account returned a 5xx when the Stripe, Google Play or App Store read failed. One subscriptions error broke the whole account response.
- Settings ignored a rejected account fetch and showed default values, such as 2FA off and no recovery key. This looked like lost account data.
- The Security section showed a password "Created" date of 1969 or 1970 when `passwordCreated` was 0 or missing.
## This pull request
- Changes the subscriptions `catch` in the GET /v1/account handler (`account.ts`). It now returns 200 with `subscriptions: []`, logs `Account.get.subscriptions.error` with `log.error`, and reports the error with `reportSentryError`. The response schema does not change.
- Resets all three lists (Stripe, Google Play, App Store) on any failure. A Play or App Store failure after a Stripe success also returns empty subscriptions. This is by design.
- Keeps `UNKNOWN_SUBSCRIPTION_CUSTOMER` silent, with no log and no Sentry report.
- Makes `useAccountData` set its `error` when the account fetch fails for a reason other than an invalid token. Settings then shows `AppErrorDialog` ("Something went wrong"), not default values. Profile and attached-clients failures keep their soft handling.
- Removes the `Sentry.captureMessage` call for a failed account fetch in `useAccountData`. `SettingsError` already reports that error with `Sentry.captureException`, so the hook sent a second event.
- Hides the "Created" date in the Security password row when `passwordCreated` is 0 or missing.
- Adds the story "Password set, no created date", the page-object getter `errorLoadingApp`, and the functional test `accountFetchError.spec.ts`.
## Issue that this pull request solves
Closes: https://mozilla-hub.atlassian.net/browse/FXA-14647
fxa-agent
Bot
force-pushed
the
fxa-14647
branch
from
October 1, 2026 21:48
46c6586 to
e0c6660
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Because
passwordCreatedwas 0 or missing.This pull request
catchin the GET /v1/account handler (account.ts). It now returns 200 withsubscriptions: [], logsAccount.get.subscriptions.errorwithlog.error, and sends the error to Sentry withreportSentryError. The response schema does not change.UNKNOWN_SUBSCRIPTION_CUSTOMERsilent, with no log and no Sentry report.useAccountDataset itserrorwhen the account fetch is rejected for a reason other than an invalid token. Settings then showsAppErrorDialog("Something went wrong") instead of default values. Profile and attached-clients failures keep their soft handling.passwordCreatedis 0 or missing.errorLoadingApp, and the functional testaccountFetchError.spec.ts.Issue that this pull request solves
Closes: https://mozilla-hub.atlassian.net/browse/FXA-14647
Checklist
Put an
xin the boxes that applyHow to review (Optional)
catchinaccount.tsandfetchAccountDatainuseAccountData/index.ts.account.ts,useAccountData/index.ts,Security/index.tsx, then the tests.Screenshots (Optional)
Storybook, Security section with a password and no created date:
Storybook, Security section with a created date, for comparison:
Other information (Optional)
I ran these checks through
/fxa-verify --run:packages/functional-tests/tests/settings/accountFetchError.spec.tson the local stack: 2 passed.page.routeforces /v1/account to return 500.fxa-auth-server/lib/routes/account.spec.ts: 143 passed, 0 failed. The /account block includes a Stripe failure, a Play failure after a Stripe success, and a silent unknown customer.fxa-settingsuseAccountData/index.test.tsandSecurity/index.test.tsx: 9 passed, 0 failed./fxa-verify.Not observable on the local stack: the subscriptions failure path. Stripe, Google Play and App Store are off locally. The route unit tests cover this path, and CI runs the full suites.