Repository navigation
Conversation
## Because - `showReactApp.signUpRoutes` is true in stage and in production. React serves the signup routes, so the Backbone views behind them are unreachable. - Part of FXA-6117, "Decommission Backbone". ## This pull request - Deletes the Backbone views `sign_up_password`, `confirm_signup_code`, `choose_what_to_sync`, `would_you_like_to_sync` and `confirm`, the `signup-mixin` and `open-webmail-mixin` mixins, their templates and specs, and their lines in `app/tests/test_start.js`. - Deletes the modules that this change orphans: `account-suggestion-mixin`, `cwts-on-signup-password`, `session-verification-poll-mixin`, `sync-optional-mixin`, `models/polls/session-verification` and `templates/partial/account-suggestion`, with their specs. Also removes an unused `#open-webmail` line from `test_template.mustache`. - Removes the `choose_what_to_sync`, `would_you_like_to_sync`, `signup_permissions`, `confirm` and `confirm_signin` routes from `router.js`. Also removes the OAuth and Sync escape hatch in the `confirm_signup_code` handler. - Converts `signup`, `oauth/signup`, `confirm_signup_code`, `primary_email_verified`, `signup_confirmed` and `signup_verified` to React-only handlers. Live Backbone code (`views/base.js`, `complete_sign_up.js`, the auth brokers, `signin-mixin`) still navigates to them, and Backbone does nothing for a route with no match. 9b9dc99 did the same for `signin` and `signin_confirmed`. - Removes `showReactApp.signUpRoutes` from `configuration.js`, `local.json-dist`, `beta-settings.js`, `react-app/types.ts` and the fxa-settings `config.ts`. In `react-app/index.js`, `signUpRoutes` now has `featureFlagOn: true` and keeps `fullProdRollout: true`. - Fixes 2 specs. `tests/spec/lib/router.js` loads `ready` in place of the deleted `sign_up_password`. The `resend-mixin` spec uses `confirm_secondary_email.mustache` in place of the deleted `confirm.mustache`. ## Issue that this pull request solves Closes: FXA-14374
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Remaining Backbone callers lose confirmation and Sync-choice routes, and OAuth/Sync key data is not preserved across the React handoff.
Review effort: Lite
Findings: 3
Open (3)
What changed in this PR
Refactors signup flows from Backbone to React and removes obsolete implementations and configuration.
Changes:
- Enables React signup routes unconditionally.
- Deletes legacy Backbone views, mixins, models, templates, and tests.
- Updates router coverage and remaining fixtures.
| File | Reviewed change |
|---|---|
packages/fxa-settings/src/lib/config.ts |
Removes signup route configuration. |
packages/fxa-content-server/server/lib/routes/react-app/types.ts |
Removes obsolete flag typing. |
packages/fxa-content-server/server/lib/routes/react-app/index.js |
Enables React signup routes. |
packages/fxa-content-server/server/lib/configuration.js |
Removes signup configuration. |
packages/fxa-content-server/server/lib/beta-settings.js |
Removes obsolete setting exposure. |
packages/fxa-content-server/server/config/local.json-dist |
Removes local signup configuration. |
packages/fxa-content-server/app/tests/test_start.js |
Removes deleted test registrations. |
packages/fxa-content-server/app/tests/spec/views/sign_up_password.js |
Deleted obsolete view spec. |
packages/fxa-content-server/app/tests/spec/views/mixins/sync-optional-mixin.js |
Deleted obsolete mixin spec. |
packages/fxa-content-server/app/tests/spec/views/mixins/signup-mixin.js |
Deleted obsolete mixin spec. |
packages/fxa-content-server/app/tests/spec/views/mixins/session-verification-poll-mixin.js |
Deleted obsolete mixin spec. |
packages/fxa-content-server/app/tests/spec/views/mixins/resend-mixin.js |
Updates template fixture. |
packages/fxa-content-server/app/tests/spec/views/mixins/open-webmail-mixin.js |
Deleted obsolete mixin spec. |
packages/fxa-content-server/app/tests/spec/views/mixins/cwts-on-signup-password.js |
Deleted obsolete mixin spec. |
packages/fxa-content-server/app/tests/spec/views/mixins/account-suggestion-mixin.js |
Deleted obsolete mixin spec. |
packages/fxa-content-server/app/tests/spec/views/confirm.js |
Deleted obsolete view spec. |
packages/fxa-content-server/app/tests/spec/views/confirm_signup_code.js |
Deleted obsolete view spec. |
packages/fxa-content-server/app/tests/spec/views/choose_what_to_sync.js |
Deleted obsolete view spec. |
packages/fxa-content-server/app/tests/spec/models/polls/session-verification.js |
Deleted orphaned model spec. |
packages/fxa-content-server/app/tests/spec/lib/router.js |
Updates route-handler coverage. |
packages/fxa-content-server/app/scripts/views/would_you_like_to_sync.js |
Deleted obsolete view. |
packages/fxa-content-server/app/scripts/views/sign_up_password.js |
Deleted obsolete view. |
packages/fxa-content-server/app/scripts/views/mixins/sync-optional-mixin.js |
Deleted obsolete mixin. |
packages/fxa-content-server/app/scripts/views/mixins/signup-mixin.js |
Deleted obsolete mixin. |
packages/fxa-content-server/app/scripts/views/mixins/session-verification-poll-mixin.js |
Deleted obsolete mixin. |
packages/fxa-content-server/app/scripts/views/mixins/open-webmail-mixin.js |
Deleted obsolete mixin. |
packages/fxa-content-server/app/scripts/views/mixins/cwts-on-signup-password.js |
Deleted obsolete mixin. |
packages/fxa-content-server/app/scripts/views/mixins/account-suggestion-mixin.js |
Deleted obsolete mixin. |
packages/fxa-content-server/app/scripts/views/confirm.js |
Deleted obsolete view. |
packages/fxa-content-server/app/scripts/views/confirm_signup_code.js |
Deleted obsolete view. |
packages/fxa-content-server/app/scripts/views/choose_what_to_sync.js |
Deleted obsolete view. |
packages/fxa-content-server/app/scripts/templates/would-you-like-to-sync.mustache |
Deleted obsolete template. |
packages/fxa-content-server/app/scripts/templates/test_template.mustache |
Removes obsolete fixture markup. |
packages/fxa-content-server/app/scripts/templates/sign_up_password.mustache |
Deleted obsolete template. |
packages/fxa-content-server/app/scripts/templates/partial/account-suggestion.mustache |
Deleted obsolete template. |
packages/fxa-content-server/app/scripts/templates/confirm.mustache |
Deleted obsolete template. |
packages/fxa-content-server/app/scripts/templates/confirm_signup_code.mustache |
Deleted obsolete template. |
packages/fxa-content-server/app/scripts/templates/choose_what_to_sync.mustache |
Deleted obsolete template. |
packages/fxa-content-server/app/scripts/models/polls/session-verification.js |
Deleted orphaned polling model. |
packages/fxa-content-server/app/scripts/lib/router.js |
Removes Backbone routes and forces React handlers. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| 'choose_what_to_sync(/)': createViewHandler(ChooseWhatToSyncView), | ||
| 'clear(/)': function () { | ||
| this.createReactViewHandler('clear'); | ||
| }, |
Comment on lines
113
to
+120
| 'confirm_signup_code(/)': function () { | ||
| /* If a user initiates the OAuth Signup flow in React (e.g. they create an account | ||
| * through an RP), they will be navigated to the React version of `confirm_signup_code` | ||
| * and can be redirected to that RP after signup completion as expected. | ||
| * | ||
| * *However*, `keyFetchToken` and `unwrapBKey`, which are used on `confirm_signup_code` | ||
| * in the OAuth flow, are provided to us when a user creates an unverified account. | ||
| * We do not want to pass these params back and forth between Backbone and React. | ||
| * We can also retrieve these when a user signs in. | ||
|
|
||
| * This means users that have previously created an account but did not verify it | ||
| * and are in the OAuth flow will be in a problematic state when going from Backbone's | ||
| * `signin` to React's `confirm_signup_code`. For this case, we want to use the | ||
| * Backbone `confirm_signup_code` until `signin` is Reactified. See: | ||
| * https://github.com/mozilla/fxa/pull/15839/files#r1344333026 | ||
| * | ||
| * Later comment: additionally, we need `keyFetchToken` and `unwrapBKey` to send a | ||
| * webchannel message to the browser for Sync. For this case, we will also show | ||
| * Backbone's `confirm_signup_code` until `signin` is Reactified. | ||
| * */ | ||
|
|
||
| const routeName = 'confirm_signup_code'; | ||
| // Users that have already reached React Signup will be navigated in-app to this | ||
| // page next (in React). This check handles the OAuth flow and Sync flow when the | ||
| // previous page was Backbone `/signin` - always show Backbone `confirm_signup_code`. | ||
| if (this.relier.isOAuth() || this.relier.isSync()) { | ||
| return getView(routeName).then((View) => { | ||
| return this.showView(View); | ||
| }); | ||
| } else { | ||
| this.createReactOrBackboneViewHandler( | ||
| routeName, | ||
| ConfirmSignupCodeView, | ||
| { | ||
| ...Url.searchParams(this.window.location.search), | ||
| // for subplat redirect only | ||
| ...(this.relier.get('redirectTo') && { | ||
| redirect_to: this.relier.get('redirectTo'), | ||
| }), | ||
| } | ||
| ); | ||
| } | ||
| this.createReactViewHandler('confirm_signup_code', { | ||
| ...Url.searchParams(this.window.location.search), | ||
| // for subplat redirect only | ||
| ...(this.relier.get('redirectTo') && { | ||
| redirect_to: this.relier.get('redirectTo'), | ||
| }), | ||
| }); |
Contributor
There was a problem hiding this comment.
I think this is intended, we are not going back to backbone. Follow up tickets will remove the other pieces.
| @@ -462,7 +386,6 @@ Router = Router.extend({ | |||
| 'verify_secondary_email(/)': createViewHandler(CompleteSignUpView, { | |||
| type: VerificationReasons.SECONDARY_EMAIL_VERIFIED, | |||
| }), | |||
vbudhram
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Because
showReactApp.signUpRoutesis true in stage and in production. React serves the signup routes, so the Backbone views behind them are unreachable.This pull request
sign_up_password,confirm_signup_code,choose_what_to_sync,would_you_like_to_syncandconfirm, thesignup-mixinandopen-webmail-mixinmixins, their templates and specs, and their lines inapp/tests/test_start.js.account-suggestion-mixin,cwts-on-signup-password,session-verification-poll-mixin,sync-optional-mixin,models/polls/session-verificationandtemplates/partial/account-suggestion, with their specs. Also removes an unused#open-webmailline fromtest_template.mustache.choose_what_to_sync,would_you_like_to_sync,signup_permissions,confirmandconfirm_signinroutes fromrouter.js. Also removes the OAuth and Sync escape hatch in theconfirm_signup_codehandler.signup,oauth/signup,confirm_signup_code,primary_email_verified,signup_confirmedandsignup_verifiedto React-only handlers. Live Backbone code (views/base.js,complete_sign_up.js, the auth brokers,signin-mixin) still navigates to them, and Backbone does nothing for a route with no match. 9b9dc99 did the same forsigninandsignin_confirmed.showReactApp.signUpRoutesfromconfiguration.js,local.json-dist,beta-settings.js,react-app/types.tsand the fxa-settingsconfig.ts. Inreact-app/index.js,signUpRoutesnow hasfeatureFlagOn: trueand keepsfullProdRollout: true.tests/spec/lib/router.jsloadsreadyin place of the deletedsign_up_password. Theresend-mixinspec usesconfirm_secondary_email.mustachein place of the deletedconfirm.mustache.Issue that this pull request solves
Closes: FXA-14374
Checklist
Put an
xin the boxes that applyHow to review (Optional)
app/scripts/lib/router.js.router.js. Backbone code still navigates to them.Screenshots (Optional)
Other information (Optional)
Shared files that stay, because other code still uses them:
views/permissions.js,templates/permissions.mustacheandtemplates/partial/permission.mustache: thesignin_permissionsroute uses them.views/mixins/email-opt-in-mixin.js:views/post_verify/newsletters/add_newsletters.jsuses it.One reviewer call: keep the 6 signup routes as React-only handlers, or delete them and fix the Backbone callers in this pull request.
Checks I ran in the VM with
/fxa-verify:curlon the running stack./signup,/oauth/signup,/confirm_signup_code,/primary_email_verified,/signup_confirmedand/signup_verifiedserve the React app (#root, no Backbone#stage) with the flag removed.nx build fxa-content-server, eslint on each changed file, and the fxa-settings lint, types and tests: pass. I lintedtypes.tswith@typescript-eslint/parser, because the content-server eslint config has no TS parser. Main has the same gap.git grepfinds no string or import reference to a deleted module.react-conversion/signup.spec.ts, "signup web" and "signup sync desktop v3, verify account": pass.oauthSignup.spec.ts: not passed locally. It reached React/confirm_signup_code, then the 123done token exchange failed with errno 109, because the VM has no 123done secrets file. CI covers it.fxa-content-serverhas no test script, so CI does not run it either.Follow-ups, not in this pull request:
REACT_CONVERSION_SIGNUP_ROUTESfrom cloudops and from.circleci/config.yml.signin-mixin.jsandviews/base.jsstill navigate to the removedwould_you_like_to_sync,confirm_signinandconfirmroutes. FXA-9054 made these paths dead.FRONTEND_ROUTESinreact-app/content-server-routes.jsand the event map inserver/lib/amplitude.jsstill have entries for the removed routes, as after 9b9dc99.react-conversion-signup-se-1bdbf-oke-signup-react-signup-web-local.webm
react-conversion-signup-se-f0fbd-c-desktop-v3-verify-account-local.webm