refactor(settings): use typed properties in SensitiveDataClient - #21228
Merged
Merged
Conversation
## Because - `SensitiveDataClient` kept every value in one private object behind `setDataType(key, value)` and `getDataType(key)`. - The generic accessors hid the type of each value behind the `SensitiveData.Key` enum and the `SensitiveData.DataMap` lookup type. A reader had to follow both to learn what a call returns. - The file already carried a `TODO(FXA-10929)` on `KeyStretchUpgradeData` that showed the wanted shape. ## This pull request - Removes `SensitiveData.Key`, `SensitiveData.DataMap`, the private storage object, the constructor and both accessors from `sensitive-data-client.ts`. - Adds one typed public property per former key: `AuthData`, `AccountResetData`, `NewRecoveryKeyData`, `Password` and `DecryptedRecoveryKeyData`. - Keeps the `SensitiveData` data types. Four prop types still intersect `SensitiveData.AuthData`. - Updates the call sites to assign and read the properties directly. - Updates the specs to set the property on a real client instead of replacing a getter with `jest.fn()`. Two specs now use the shared `mockSensitiveDataClient` helper in place of an ad-hoc `{getDataType, setDataType}` object. Storage semantics do not change. The client stores the same values, and it clears them at the same points. ## Issue that this pull request solves Closes: https://mozilla-hub.atlassian.net/browse/FXA-10929
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved review comments remain, and all supplied assessments indicate approval readiness.
Pull request overview
Refactors SensitiveDataClient to use typed public properties while preserving existing storage behavior.
Changes:
- Replaces generic getters/setters with typed properties.
- Migrates signup, signin, recovery, and reset-password call sites.
- Updates affected tests and mocks.
File summaries
| File | Change |
|---|---|
packages/fxa-settings/src/pages/Signup/index.tsx |
Stores signup auth data directly. |
packages/fxa-settings/src/pages/Signup/index.test.tsx |
Updates signup storage assertions. |
packages/fxa-settings/src/pages/Signup/ConfirmSignupCode/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/Signup/ConfirmSignupCode/container.test.tsx |
Updates auth-data mocks. |
packages/fxa-settings/src/pages/Signin/SigninUnblock/container.tsx |
Reads password and stores auth data. |
packages/fxa-settings/src/pages/Signin/SigninUnblock/container.test.tsx |
Updates password mocks. |
packages/fxa-settings/src/pages/Signin/SigninTotpCode/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/Signin/SigninTotpCode/container.test.tsx |
Resets typed mock state. |
packages/fxa-settings/src/pages/Signin/SigninTokenCode/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/Signin/SigninTokenCode/container.test.tsx |
Updates auth-data mocks. |
packages/fxa-settings/src/pages/Signin/SigninRecoveryPhone/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/Signin/SigninRecoveryCode/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/Signin/SigninRecoveryCode/container.test.tsx |
Updates recovery-code assertions. |
packages/fxa-settings/src/pages/Signin/index.tsx |
Stores passwords directly. |
packages/fxa-settings/src/pages/Signin/index.test.tsx |
Updates password assertions. |
packages/fxa-settings/src/pages/Signin/container.tsx |
Stores sign-in auth data directly. |
packages/fxa-settings/src/pages/Signin/container.test.tsx |
Updates sign-in assertions. |
packages/fxa-settings/src/pages/Signin/components/SigninDecider/index.test.tsx |
Uses the shared client mock. |
packages/fxa-settings/src/pages/ResetPassword/ResetPasswordWithRecoveryKeyVerified/container.tsx |
Reads reset and recovery-key data. |
packages/fxa-settings/src/pages/ResetPassword/ResetPasswordConfirmed/container.tsx |
Reads reset data directly. |
packages/fxa-settings/src/pages/ResetPassword/CompleteResetPassword/container.tsx |
Reads and stores reset data directly. |
packages/fxa-settings/src/pages/ResetPassword/CompleteResetPassword/container.test.tsx |
Uses the shared client mock. |
packages/fxa-settings/src/pages/ResetPassword/AccountRecoveryConfirmKey/container.tsx |
Stores decrypted recovery-key data. |
packages/fxa-settings/src/pages/PostVerify/SetPassword/container.test.tsx |
Removes obsolete setter mocking. |
packages/fxa-settings/src/pages/InlineRecoverySetupFlow/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/InlineRecoverySetupFlow/container.test.tsx |
Updates auth-data tests. |
packages/fxa-settings/src/pages/InlineRecoveryKeySetup/container.tsx |
Reads typed auth data. |
packages/fxa-settings/src/pages/InlineRecoveryKeySetup/container.test.tsx |
Updates recovery-key mocks. |
packages/fxa-settings/src/lib/sensitive-data-client.ts |
Defines typed sensitive-data properties. |
Review details
- Files reviewed: 29/29 changed files
- Comments generated: 0
- Review effort level: Lite (auto)
Note
Copilot is running an experiment and ran this review at Lite.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
vpomerleau
approved these changes
Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Because
SensitiveDataClientkept every value in one private object behindsetDataType(key, value)andgetDataType(key).SensitiveData.Keyenum and theSensitiveData.DataMaplookup type. A reader had to follow both to learn what a call returns.TODO(FXA-10929)onKeyStretchUpgradeDatathat showed the wanted shape.This pull request
SensitiveData.Key,SensitiveData.DataMap, the private storage object, the constructor and both accessors fromsensitive-data-client.ts.AuthData,AccountResetData,NewRecoveryKeyData,PasswordandDecryptedRecoveryKeyData.SensitiveDatadata types. Four prop types still intersectSensitiveData.AuthData.jest.fn(). Two specs now use the sharedmockSensitiveDataClienthelper in place of an ad-hoc{getDataType, setDataType}object.Storage semantics do not change. The client stores the same values, and it clears them at the same points.
Issue that this pull request solves
Closes: https://mozilla-hub.atlassian.net/browse/FXA-10929
Checklist
Put an
xin the boxes that applyHow to review (Optional)
packages/fxa-settings/src/lib/sensitive-data-client.tsholds the whole API change. The rest follows from it.SigninUnblock/container.tsxis the one non-mechanical spot. It keeps the previous non-null assertion, now onsensitiveDataClient.Password!. Every other edit is a direct swap of an accessor call for a property.Screenshots (Optional)
There is no user interface change.
Other information (Optional)
29 files changed, 89 insertions and 206 deletions, all under
packages/fxa-settings/src.Local checks:
npx tsc -p packages/fxa-settings/tsconfig.json --noEmit: passes. This is the real gate. The change deletes an API, so a missed call site fails the compile.npx nx lint fxa-settings: exits 0.Conflict warning for FXA-13151 (passwordless Sync): PRs #21223 and #21224 add a
PasskeyWrapkey to this same file. After this pull request lands, that work must addPasskeyWrapas a property, not as an enum member. Expect a merge conflict.