Skip to content

chore: promote develop to main (30M release) - #73

Merged
MakelangelOO merged 22 commits into
mainfrom
develop
Sep 29, 2026
Merged

MakelangelOO merged 22 commits into
mainfrom
develop

Conversation

@MakelangelOO

Copy link
Copy Markdown
Collaborator

Release 2026-09-25 — develop → main

22 commits · 59 files · +2,779 / −328 · 0 new env vars · SDK 0.13.0 → 0.13.3

The wallet moves to the 30M origin and ships the "wallet 3.0" cleanup: flows the backend can't serve yet are marked coming soon, money flows require an active virtual account, Bloque Friends resolves the real destination account, and the legal section goes live.

Part of BQE-2719. Blocked on bloque-app/payment-rails#986 — do not merge until that release is deployed and the post-deploy checks below pass.

Deploy prerequisites — backend, not this repo

Needs in prod Why If missing
30m origin (payment-rails #976, migration Create30MOrigin) Login and registration go through origin 30m only (#66) Nobody can log in
Alias resolution (payment-rails #975) + ORIGINS_MEDIUMS_* env on origins Bloque Friends sends to account_urn from GET /api/aliases (#64) Every Bloque Friends send is blocked with "No pudimos verificar el bolsillo receptor"
display_name on aliases (payment-rails #980) Recipient name on the confirm dialog (#69) Degrades gracefully to the raw alias
Alias rate limit keyed per client (payment-rails#986, known gap #1) Login and Bloque Friends both call GET /api/aliases If the limit is shared platform-wide, login fails after 30 lookups/hour
KYC / ToS configured for 30m New 30M users must pass ToS + KYC before creating their pocket Users stall at onboarding

No wallet env var changes. deploy.yml publishes to Cloudflare Pages on push to main, built against https://api.bloque.sh.

What ships

1. Auth through the 30M origin

PR: #66 · BQE-2458

Every login and registration uses origin 30m (email or WhatsApp) instead of bloque-email / bloque-whatsapp. Existing prod users of those origins register again under 30m: ToS, KYC and a new pocket.

2. Bloque Friends

PRs: #64, #69, #70 · BQE-2635, BQE-2713

Sends to the recipient's resolved account_urn, shows their display name, shows a readable message for an unknown alias instead of E_ALIAS_NOT_FOUND, and lets the user pick the source pocket (default when there's only one). Users can see and copy their own alias from the profile.

3. Virtual-account gating

PR: #70 · BQE-2713

Top-up, send and BRE-B require an active pocket — enforced by layout routes, so direct URLs are covered. New BRE-B keys and Plaid links are anchored to a pocket, and every money-movement picker only offers active pockets.

4. Coming soon

PRs: #70, #71 · BQE-2713

Driven by flags in src/config/features.ts, all false:

  • US_RAILS_ENABLED — US payins/payouts and Plaid (options, direct URLs, legal fees section).
  • USD_ENABLED — home balance defaults to COP with USD blocked; USD blocked in Bloque Friends, own transfers and card preferred asset; balances list COP first.
  • CARDS_ENABLED — the cards section (tab, details, add-product option).

Plus a Mexico section with SPEI as a coming-soon method in send and top-up.

5. Legal

PRs: #67, #68, #72 · BQE-2687, BQE-2713

Terms and conditions, fees grouped by country, and the personal data treatment policy (Pagos Cube S.A.S. v1.2).

6. Navigation

PR: #70 · BQE-2713

The account detail back button returns to where the user came from (home, profile, card or the pockets list) instead of bouncing on the single-account redirect.

After deploy — smoke test in prod

  • Log in with a 30M email alias and a 30M WhatsApp alias.
  • New user: ToS → KYC → create pocket; top-up/send/BRE-B unlock once the pocket is active.
  • Bloque Friends: unknown alias shows the readable message; a known alias shows the recipient's name and the send leaves from the chosen pocket.
  • Coming soon on US options, cards and Mexico/SPEI; home opens on COP.
  • Profile → Legal → Privacy policy renders the v1.2 policy.

Rollback

Redeploy the previous Cloudflare Pages deployment (or revert the merge on main). Users already registered under 30m keep their identity; the old wallet would route them back to bloque-email / bloque-whatsapp, where they'd appear as new users again.

MakelangelOO and others added 22 commits September 22, 2026 21:29
* fix(wallet): use resolved account URN for Bloque Friends transfers

alias.find now returns account_urn/account_resolution_error
(payment-rails#975, sdk#78) — send it as destinationUrn instead of the
identity URN that never matched an account. Show a clear error when the
recipient has no receiving account yet, and let users see/copy their own
alias from the profile screen so they can actually share it.

* fix(wallet): verify friend destinations safely

* test(wallet): keep SDK mock exports complete

* chore(wallet): consume SDK 0.13.2
* feat(auth): route wallet through 30m

* fix(auth): detect legacy aliases

* fix(auth): trust alias lookup
)

Terms and privacy policy rows in profile were dead UI (no onClick).
Adds internal /legal/terms, /legal/privacy, /legal/fees routes since
there's no public URL to host these on yet. Terms uses the real T&C
doc from Roy; privacy shows a coming-soon placeholder pending the
data-treatment policy; fees shows a full table of the values already
surfaced per-operation on send/topup.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
…#68)

The flat send/topup grouping read as too generic. Costs actually vary
by country, so BRE-B/Colombian-banks/US-banks each now show their
send and top-up fee under one Colombia/US section instead of two
undifferentiated lists.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
fix(wallet): consume real sdk 0.13.3, show display_name for Bloque Friends
Carry origin (home/profile/card) and list flag through account routes;
back no longer bounces through the single-account redirect.
Alias lookup throws a 404 instead of resolving empty, so the not-found
branch never ran and the raw E_ALIAS_NOT_FOUND code reached the toast.
US options in send, top-up and add-product are disabled with a coming
soon badge; the US routes render a coming soon screen when opened
directly, and the US section is dropped from legal fees.
Top-up, send and BRE-B are gated by layout routes (direct URLs included),
home quick actions, card creation and add-product are disabled until the
user holds an active pocket.
Product pickers only offer active pockets; a single pocket is used by
default, several prompt a choice, and a ledgerId from the URL is only
honored when it belongs to one of the user's pockets.
Top-up destinations, send sources, BRE-B payout sources, own-account
transfer destinations and BRE-B deposit keys only consider active
pockets.
A single pocket is selected by default; with several, the user must
choose one before sending.
Bloque Friends defaults to COP with USD disabled, own-account transfers
are disabled while a USD balance is selected, and cards can't switch
their preferred asset to USD.
Card tab and card details render a coming soon screen (direct URLs
included) and the card option in add-product is disabled.
Send and top-up list a Mexico group with SPEI as a disabled, coming soon
method.
feat(wallet): wallet 3.0 cleanup — gating, coming soon, back nav, alias error
Home starts on COP with the USD chip disabled as coming soon, and
balances list COP first while USD is disabled. The flag is renamed to
USD_ENABLED since it now covers display as well as movements.
feat(wallet): default home balance to COP and block USD
Replaces the privacy coming soon placeholder with Pagos Cube's personal
data treatment policy v1.2, rendered like the terms page.
feat(wallet): publish the personal data policy in legal
@linear

linear Bot commented Sep 25, 2026

Copy link
Copy Markdown

BQE-2719

@MakelangelOO
MakelangelOO marked this pull request as ready for review September 29, 2026 23:47
@MakelangelOO
MakelangelOO merged commit ec0c631 into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant