Skip to content

refactor(content-server): remove Backbone signup views and routes - #21366

Merged
vbudhram merged 1 commit into
mainfrom
fxa-14374
Oct 5, 2026
Merged

vbudhram merged 1 commit into
mainfrom
fxa-14374

Conversation

@fxa-agent

@fxa-agent fxa-agent Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Because

  • showReactApp.signUpRoutes is true in stage and in production. React serves the signup routes, so the Backbone views behind them are unreachable.
  • Part of FXA-6117, "Decommission Backbone".

This pull request

  • Deletes the Backbone views sign_up_password, confirm_signup_code, choose_what_to_sync, would_you_like_to_sync and confirm, the signup-mixin and open-webmail-mixin mixins, their templates and specs, and their lines in app/tests/test_start.js.
  • Deletes the modules that this change orphans: account-suggestion-mixin, cwts-on-signup-password, session-verification-poll-mixin, sync-optional-mixin, models/polls/session-verification and templates/partial/account-suggestion, with their specs. Also removes an unused #open-webmail line from test_template.mustache.
  • Removes the choose_what_to_sync, would_you_like_to_sync, signup_permissions, confirm and confirm_signin routes from router.js. Also removes the OAuth and Sync escape hatch in the confirm_signup_code handler.
  • Converts signup, oauth/signup, confirm_signup_code, primary_email_verified, signup_confirmed and signup_verified to React-only handlers. Live Backbone code (views/base.js, complete_sign_up.js, the auth brokers, signin-mixin) still navigates to them, and Backbone does nothing for a route with no match. 9b9dc99 did the same for signin and signin_confirmed.
  • Removes showReactApp.signUpRoutes from configuration.js, local.json-dist, beta-settings.js, react-app/types.ts and the fxa-settings config.ts. In react-app/index.js, signUpRoutes now has featureFlagOn: true and keeps fullProdRollout: true.
  • Fixes 2 specs. tests/spec/lib/router.js loads ready in place of the deleted sign_up_password. The resend-mixin spec uses confirm_secondary_email.mustache in place of the deleted confirm.mustache.

Issue that this pull request solves

Closes: FXA-14374

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

  • Key files/areas to focus on: app/scripts/lib/router.js.
  • Suggested review order:
  • Risky or complex parts: the 6 React-only handlers in router.js. Backbone code still navigates to them.

Screenshots (Optional)

Other information (Optional)

Shared files that stay, because other code still uses them:

  • views/permissions.js, templates/permissions.mustache and templates/partial/permission.mustache: the signin_permissions route uses them.
  • views/mixins/email-opt-in-mixin.js: views/post_verify/newsletters/add_newsletters.js uses it.

One reviewer call: keep the 6 signup routes as React-only handlers, or delete them and fix the Backbone callers in this pull request.

Checks I ran in the VM with /fxa-verify:

  • I used curl on the running stack. /signup, /oauth/signup, /confirm_signup_code, /primary_email_verified, /signup_confirmed and /signup_verified serve the React app (#root, no Backbone #stage) with the flag removed.
  • nx build fxa-content-server, eslint on each changed file, and the fxa-settings lint, types and tests: pass. I linted types.ts with @typescript-eslint/parser, because the content-server eslint config has no TS parser. Main has the same gap.
  • git grep finds no string or import reference to a deleted module.
  • react-conversion/signup.spec.ts, "signup web" and "signup sync desktop v3, verify account": pass.
  • oauthSignup.spec.ts: not passed locally. It reached React /confirm_signup_code, then the 123done token exchange failed with errno 109, because the VM has no 123done secrets file. CI covers it.
  • The Backbone mocha suite: not run. fxa-content-server has no test script, so CI does not run it either.

Follow-ups, not in this pull request:

  • SRE can remove REACT_CONVERSION_SIGNUP_ROUTES from cloudops and from .circleci/config.yml.
  • signin-mixin.js and views/base.js still navigate to the removed would_you_like_to_sync, confirm_signin and confirm routes. FXA-9054 made these paths dead.
  • FRONTEND_ROUTES in react-app/content-server-routes.js and the event map in server/lib/amplitude.js still have entries for the removed routes, as after 9b9dc99.

react-conversion-signup-se-1bdbf-oke-signup-react-signup-web-local.webm

react-conversion-signup-se-f0fbd-c-desktop-v3-verify-account-local.webm

## Because

- `showReactApp.signUpRoutes` is true in stage and in production. React serves the signup routes, so the Backbone views behind them are unreachable.
- Part of FXA-6117, "Decommission Backbone".

## This pull request

- Deletes the Backbone views `sign_up_password`, `confirm_signup_code`, `choose_what_to_sync`, `would_you_like_to_sync` and `confirm`, the `signup-mixin` and `open-webmail-mixin` mixins, their templates and specs, and their lines in `app/tests/test_start.js`.
- Deletes the modules that this change orphans: `account-suggestion-mixin`, `cwts-on-signup-password`, `session-verification-poll-mixin`, `sync-optional-mixin`, `models/polls/session-verification` and `templates/partial/account-suggestion`, with their specs. Also removes an unused `#open-webmail` line from `test_template.mustache`.
- Removes the `choose_what_to_sync`, `would_you_like_to_sync`, `signup_permissions`, `confirm` and `confirm_signin` routes from `router.js`. Also removes the OAuth and Sync escape hatch in the `confirm_signup_code` handler.
- Converts `signup`, `oauth/signup`, `confirm_signup_code`, `primary_email_verified`, `signup_confirmed` and `signup_verified` to React-only handlers. Live Backbone code (`views/base.js`, `complete_sign_up.js`, the auth brokers, `signin-mixin`) still navigates to them, and Backbone does nothing for a route with no match. 9b9dc99 did the same for `signin` and `signin_confirmed`.
- Removes `showReactApp.signUpRoutes` from `configuration.js`, `local.json-dist`, `beta-settings.js`, `react-app/types.ts` and the fxa-settings `config.ts`. In `react-app/index.js`, `signUpRoutes` now has `featureFlagOn: true` and keeps `fullProdRollout: true`.
- Fixes 2 specs. `tests/spec/lib/router.js` loads `ready` in place of the deleted `sign_up_password`. The `resend-mixin` spec uses `confirm_secondary_email.mustache` in place of the deleted `confirm.mustache`.

## Issue that this pull request solves

Closes: FXA-14374
@fxa-agent
fxa-agent Bot requested a review from a team as a code owner October 1, 2026 18:13
@fxa-agent fxa-agent Bot added the auto label Oct 1, 2026
@fxa-agent fxa-agent Bot assigned LZoog Oct 1, 2026
@vbudhram
vbudhram requested a lite review from Copilot October 1, 2026 21:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Remaining Backbone callers lose confirmation and Sync-choice routes, and OAuth/Sync key data is not preserved across the React handoff.

Review effort: Lite
Findings: 3 High severity

Open (3)
What changed in this PR

Refactors signup flows from Backbone to React and removes obsolete implementations and configuration.

Changes:

  • Enables React signup routes unconditionally.
  • Deletes legacy Backbone views, mixins, models, templates, and tests.
  • Updates router coverage and remaining fixtures.
File Reviewed change
packages/​fxa-settings/​src/​lib/​config.ts Removes signup route configuration.
packages/​fxa-content-server/​server/​lib/​routes/​react-app/​types.ts Removes obsolete flag typing.
packages/​fxa-content-server/​server/​lib/​routes/​react-app/​index.js Enables React signup routes.
packages/​fxa-content-server/​server/​lib/​configuration.js Removes signup configuration.
packages/​fxa-content-server/​server/​lib/​beta-settings.js Removes obsolete setting exposure.
packages/​fxa-content-server/​server/​config/​local.json-dist Removes local signup configuration.
packages/​fxa-content-server/​app/​tests/​test_start.js Removes deleted test registrations.
packages/​fxa-content-server/​app/​tests/​spec/​views/​sign_up_password.js Deleted obsolete view spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​sync-optional-mixin.js Deleted obsolete mixin spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​signup-mixin.js Deleted obsolete mixin spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​session-verification-poll-mixin.js Deleted obsolete mixin spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​resend-mixin.js Updates template fixture.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​open-webmail-mixin.js Deleted obsolete mixin spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​cwts-on-signup-password.js Deleted obsolete mixin spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​mixins/​account-suggestion-mixin.js Deleted obsolete mixin spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​confirm.js Deleted obsolete view spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​confirm_signup_code.js Deleted obsolete view spec.
packages/​fxa-content-server/​app/​tests/​spec/​views/​choose_what_to_sync.js Deleted obsolete view spec.
packages/​fxa-content-server/​app/​tests/​spec/​models/​polls/​session-verification.js Deleted orphaned model spec.
packages/​fxa-content-server/​app/​tests/​spec/​lib/​router.js Updates route-handler coverage.
packages/​fxa-content-server/​app/​scripts/​views/​would_you_like_to_sync.js Deleted obsolete view.
packages/​fxa-content-server/​app/​scripts/​views/​sign_up_password.js Deleted obsolete view.
packages/​fxa-content-server/​app/​scripts/​views/​mixins/​sync-optional-mixin.js Deleted obsolete mixin.
packages/​fxa-content-server/​app/​scripts/​views/​mixins/​signup-mixin.js Deleted obsolete mixin.
packages/​fxa-content-server/​app/​scripts/​views/​mixins/​session-verification-poll-mixin.js Deleted obsolete mixin.
packages/​fxa-content-server/​app/​scripts/​views/​mixins/​open-webmail-mixin.js Deleted obsolete mixin.
packages/​fxa-content-server/​app/​scripts/​views/​mixins/​cwts-on-signup-password.js Deleted obsolete mixin.
packages/​fxa-content-server/​app/​scripts/​views/​mixins/​account-suggestion-mixin.js Deleted obsolete mixin.
packages/​fxa-content-server/​app/​scripts/​views/​confirm.js Deleted obsolete view.
packages/​fxa-content-server/​app/​scripts/​views/​confirm_signup_code.js Deleted obsolete view.
packages/​fxa-content-server/​app/​scripts/​views/​choose_what_to_sync.js Deleted obsolete view.
packages/​fxa-content-server/​app/​scripts/​templates/​would-you-like-to-sync.mustache Deleted obsolete template.
packages/​fxa-content-server/​app/​scripts/​templates/​test_template.mustache Removes obsolete fixture markup.
packages/​fxa-content-server/​app/​scripts/​templates/​sign_up_password.mustache Deleted obsolete template.
packages/​fxa-content-server/​app/​scripts/​templates/​partial/​account-suggestion.mustache Deleted obsolete template.
packages/​fxa-content-server/​app/​scripts/​templates/​confirm.mustache Deleted obsolete template.
packages/​fxa-content-server/​app/​scripts/​templates/​confirm_signup_code.mustache Deleted obsolete template.
packages/​fxa-content-server/​app/​scripts/​templates/​choose_what_to_sync.mustache Deleted obsolete template.
packages/​fxa-content-server/​app/​scripts/​models/​polls/​session-verification.js Deleted orphaned polling model.
packages/​fxa-content-server/​app/​scripts/​lib/​router.js Removes Backbone routes and forces React handlers.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

'choose_what_to_sync(/)': createViewHandler(ChooseWhatToSyncView),
'clear(/)': function () {
this.createReactViewHandler('clear');
},
Comment on lines 113 to +120
'confirm_signup_code(/)': function () {
/* If a user initiates the OAuth Signup flow in React (e.g. they create an account
* through an RP), they will be navigated to the React version of `confirm_signup_code`
* and can be redirected to that RP after signup completion as expected.
*
* *However*, `keyFetchToken` and `unwrapBKey`, which are used on `confirm_signup_code`
* in the OAuth flow, are provided to us when a user creates an unverified account.
* We do not want to pass these params back and forth between Backbone and React.
* We can also retrieve these when a user signs in.

* This means users that have previously created an account but did not verify it
* and are in the OAuth flow will be in a problematic state when going from Backbone's
* `signin` to React's `confirm_signup_code`. For this case, we want to use the
* Backbone `confirm_signup_code` until `signin` is Reactified. See:
* https://github.com/mozilla/fxa/pull/15839/files#r1344333026
*
* Later comment: additionally, we need `keyFetchToken` and `unwrapBKey` to send a
* webchannel message to the browser for Sync. For this case, we will also show
* Backbone's `confirm_signup_code` until `signin` is Reactified.
* */

const routeName = 'confirm_signup_code';
// Users that have already reached React Signup will be navigated in-app to this
// page next (in React). This check handles the OAuth flow and Sync flow when the
// previous page was Backbone `/signin` - always show Backbone `confirm_signup_code`.
if (this.relier.isOAuth() || this.relier.isSync()) {
return getView(routeName).then((View) => {
return this.showView(View);
});
} else {
this.createReactOrBackboneViewHandler(
routeName,
ConfirmSignupCodeView,
{
...Url.searchParams(this.window.location.search),
// for subplat redirect only
...(this.relier.get('redirectTo') && {
redirect_to: this.relier.get('redirectTo'),
}),
}
);
}
this.createReactViewHandler('confirm_signup_code', {
...Url.searchParams(this.window.location.search),
// for subplat redirect only
...(this.relier.get('redirectTo') && {
redirect_to: this.relier.get('redirectTo'),
}),
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is intended, we are not going back to backbone. Follow up tickets will remove the other pieces.

@@ -462,7 +386,6 @@ Router = Router.extend({
'verify_secondary_email(/)': createViewHandler(CompleteSignUpView, {
type: VerificationReasons.SECONDARY_EMAIL_VERIFIED,
}),
@vbudhram
vbudhram merged commit 7353ba6 into main Oct 5, 2026
22 of 23 checks passed
@vbudhram
vbudhram deleted the fxa-14374 branch October 5, 2026 13:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants