[Fraud Protection] Track events for detecting abusive user invites#73550
Merged
cristipaval merged 4 commits intomainfrom Nov 5, 2025
Merged
[Fraud Protection] Track events for detecting abusive user invites#73550cristipaval merged 4 commits intomainfrom
cristipaval merged 4 commits intomainfrom
Conversation
Contributor
|
LGTM |
Codecov Report❌ Patch coverage is
... and 4 files with indirect coverage changes 🚀 New features to boost your workflow:
|
coleaeason
approved these changes
Nov 5, 2025
Contributor
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
64 tasks
Contributor
|
🚀 Deployed to staging by https://github.com/cristipaval in version: 9.2.46-0 🚀
|
Contributor
|
🚀 Deployed to production by https://github.com/luacmartins in version: 9.2.46-3 🚀
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
We want to track events that we need to detect accounts that abuse our viral onboarding flow.
For now, we're focusing on the following patterns that we want to automatically block:
Explanation of Change
This PR tracks when the user invites emails in the product. We're starting with the API calls that use the invitee email filtering in Web-E, which is the utility function that we added to extinguish the fire that we had back in May this year.
Fixed Issues
$ https://github.com/Expensify/Expensify/issues/535327
PROPOSAL:
Tests
Tested by verifying that the events are sent to the Group-IB dashboard.
Offline tests
QA Steps
Ping me (@cristipaval) to QA this. Cole and I currently have access to the Group-IB dashboard. All expensify emails will be able to access it when Cole is done with the SSO
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectioncanBeMissingparam foruseOnyxtoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari
MacOS: Desktop