[NoQA] Feature: Travel Invoicing - Release 2.6 & 2.7: Reveal CVV Flow#79824
[NoQA] Feature: Travel Invoicing - Release 2.6 & 2.7: Reveal CVV Flow#79824blimpich merged 24 commits intoExpensify:mainfrom
Conversation
|
Hey, I noticed you changed If you want to automatically generate translations for other locales, an Expensify employee will have to:
Alternatively, if you are an external contributor, you can run the translation script locally with your own OpenAI API key. To learn more, try running: npx ts-node ./scripts/generateTranslations.ts --helpTypically, you'd want to translate only what you changed by running |
|
@parasharrajat Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
src/pages/workspace/travel/WorkspaceTravelSettlementAccountPage.tsx
Outdated
Show resolved
Hide resolved
src/pages/workspace/travel/WorkspaceTravelSettlementAccountPage.tsx
Outdated
Show resolved
Hide resolved
src/pages/workspace/travel/WorkspaceTravelSettlementAccountPage.tsx
Outdated
Show resolved
Hide resolved
src/pages/workspace/travel/WorkspaceTravelInvoicingSettlementFrequencyPage.tsx
Show resolved
Hide resolved
src/pages/workspace/travel/WorkspaceTravelSettlementAccountPage.tsx
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4e1e6b972a
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Codecov Report✅ Changes either increased or maintained existing code coverage, great job!
|
|
🟢 Ready for review! |
|
@ikevin127 Merge main. |
|
Can you try this SVG instead? It should look good in dark and light mode cc @Expensify/design |
|
Nice, thanks Jon! |
|
@dubielzyk-expensify Not sure what's going on with github, it doesn't allow me to download the archive: Screen.Recording.2026-01-28.at.15.26.57.mov |
…7-travel-invoicing-26/27
|
Testing in few hours. |
|
bump @parasharrajat ETA on review here? |
|
Yes, I need to run final checks before I can approve this. So far, it seems everything is resolved at this point. I will have it done in the morning. |
|
Testing... |
|
@ikevin127 I don't see the Card and CVV. I enabled all betas.
|
|
@parasharrajat Try changing the function canUseAllBetas(betas: OnyxEntry<Beta[]>): boolean {
return Array.isArray(betas);
}Otherwise not sure what's the issue on your side - I just checked with test account on ngrok which has all betas enabled (incl. recent travel invoicing one) and it shows:
|
|
Got it. I need to have Expensify card on same workspace as travel. |
|
BUG: After revealing, if I close the page and reopen, the CVV remains visible. Steps: Close the page after revealing by clicking the backdrop. |
Screenshots🔲 iOS / native14.02.2026_00.21.34_REC.mp4🔲 MacOS / Chrome13.02.2026_16.52.02_REC.mp4 |
|
Now, my account got locked bcz of multiple otpss. 😄 |
|
Looks good except that bug and conflicts. |
…/ikevin127/Expensify\; branch 'main' of https://github.com/Expensify/App into ikevin127-travel-invoicing-26/27
Good catch, fixed in the latest commit ✅
@parasharrajat 🟢 Ready for another take! |
…7-travel-invoicing-26/27
|
♻️ Resolved conflict. |
parasharrajat
left a comment
There was a problem hiding this comment.
Reviewer Checklist
- I have verified the author checklist is complete (all boxes are checked off).
- I verified the correct issue is linked in the
### Fixed Issuessection above - I verified testing steps are clear and they cover the changes made in this PR
- I verified the steps for local testing are in the
Testssection - I verified the steps for Staging and/or Production testing are in the
QA stepssection - I verified the steps cover any possible failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
- I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
- I verified the steps for local testing are in the
- I checked that screenshots or videos are included for tests on all platforms
- I included screenshots or videos for tests on all platforms
- I verified tests pass on all platforms & I tested again on:
- Android: Native
- Android: mWeb Chrome
- iOS: Native
- iOS: mWeb Safari
- MacOS: Chrome / Safari
- MacOS: Desktop
- If there are any errors in the console that are unrelated to this PR, I either fixed them (preferred) or linked to where I reported them in Slack
- I verified proper code patterns were followed (see Reviewing the code)
- I verified that any callback methods that were added or modified are named for what the method does and never what callback they handle (i.e.
toggleReportand notonIconClick). - I verified that the left part of a conditional rendering a React component is a boolean and NOT a string, e.g.
myBool && <MyComponent />. - I verified that comments were added to code that is not self explanatory
- I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
- I verified any copy / text shown in the product is localized by adding it to
src/languages/*files and using the translation method - I verified all numbers, amounts, dates and phone numbers shown in the product are using the localization methods
- I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is approved by marketing by adding the
Waiting for Copylabel for a copy review on the original GH to get the correct copy. - I verified proper file naming conventions were followed for any new files or renamed files. All non-platform specific files are named after what they export and are not named "index.js". All platform-specific files are named for the platform the code supports as outlined in the README.
- I verified the JSDocs style guidelines (in
STYLE.md) were followed
- I verified that any callback methods that were added or modified are named for what the method does and never what callback they handle (i.e.
- If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
- I verified that this PR follows the guidelines as stated in the Review Guidelines
- I verified other components that can be impacted by these changes have been tested, and I retested again (i.e. if the PR modifies a shared library or component like
Avatar, I verified the components usingAvatarhave been tested & I retested again) - I verified all code is DRY (the PR doesn't include any logic written more than once, with the exception of tests)
- I verified any variables that can be defined as constants (ie. in CONST.js or at the top of the file that uses the constant) are defined as such
- If a new component is created I verified that:
- A similar component doesn't exist in the codebase
- All props are defined accurately and each prop has a
/** comment above it */ - The file is named correctly
- The component has a clear name that is non-ambiguous and the purpose of the component can be inferred from the name alone
- The only data being stored in the state is data necessary for rendering and nothing else
- For Class Components, any internal methods passed to components event handlers are bound to
thisproperly so there are no scoping issues (i.e. foronClick={this.submit}the methodthis.submitshould be bound tothisin the constructor) - Any internal methods bound to
thisare necessary to be bound (i.e. avoidthis.submit = this.submit.bind(this);ifthis.submitis never passed to a component event handler likeonClick) - All JSX used for rendering exists in the render method
- The component has the minimum amount of code necessary for its purpose, and it is broken down into smaller components in order to separate concerns and functions
- If any new file was added I verified that:
- The file has a description of what it does and/or why is needed at the top of the file if the code is not self explanatory
- If a new CSS style is added I verified that:
- A similar style doesn't already exist
- The style can't be created with an existing StyleUtils function (i.e.
StyleUtils.getBackgroundAndBorderStyle(theme.componentBG)
- If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
- If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like
Avataris modified, I verified thatAvataris working as expected in all cases) - If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
- If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
- If the PR modifies the form input styles:
- I verified that all the inputs inside a form are aligned with each other.
- I added
Designlabel so the design team can review the changes.
- If a new page is added, I verified it's using the
ScrollViewcomponent to make it scrollable when more elements are added to the page. - If the
mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps. - I have checked off every checkbox in the PR reviewer checklist, including those that don't apply to this PR.
🎀 👀 🎀 C+ reviewed
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
|
🚧 @blimpich has triggered a test Expensify/App build. You can view the workflow run here. |
|
🧪🧪 Use the links below to test this adhoc build on Android, iOS, and Web. Happy testing! 🧪🧪
|
|
🚀 Deployed to staging by https://github.com/blimpich in version: 9.3.21-0 🚀
|
|
🚀 Deployed to production by https://github.com/mountiny in version: 9.3.21-4 🚀
|





Explanation of Change
2.6 Eligibility & Rendering
UX Flow
When the user opens the
Walletscreen:Wallet.Data & Onyx
Eligibility is derived from:
useOnyx(ONYXKEYS.SESSION)anduseOnyx(ONYXKEYS.BETAS)(e.g., domain, betas).useOnyx(ONYXKEYS.COLLECTION.POLICY)or a domain settings key that marks users as travel‑enabled.We store only:
isRevealed,isLoading, and CVV in local component state.Components & reuse
New component: We add
WalletTravelCVVSectionto theWalletscreen (responsible for eligibility, actions, and local state), but it reuses the CVV row UI refactored out of the existing Expensify Card implementation from PR #59541. This lets us keep a Travel‑specific container while sharing the exact same visual/interaction pattern as the card CVV row.It uses a new shared component extracted from the existing Expensify Card detail screen:
SensitiveInfoRow(generic “reveal secret” row).Testing
Component tests:
WalletTravelCVVSectionrenders nothing.2.7 Reveal CVV Flow
UX Flow
WalletTravelCVVSection:isLoadingstate.isRevealedas true and shows the plaintext CVV.Walletscreen unmounts:💡 Note: We intentionally do not auto‑mask on a timer; this matches Expensify Card’s current behavior (no time‑based hiding once revealed). The CVV becomes hidden again on navigation/unmount.
Actions
In
src/libs/actions/TravelInvoicing.ts, we’ll addrevealTravelCVV({policyID, accountID})which will have the following attributes:RevealExpensifyCardDetailscommand (no new backend command is added).PROGRAM_TRAVEL_USfeed for the current user) intoRevealExpensifyCardDetails.RevealExpensifyCardDetailscan return other card details,revealTravelCVVwill only resolve the CVV field and will not expose or store PAN or other sensitive fields.WalletTravelCVVSectionand never persisted in Onyx or logs.Components & reuse
For the visual treatment and interaction of the CVV reveal,
WalletTravelCVVSectionwill reuse the same pattern already implemented for Expensify Card CVV display:src/pages/settings/Wallet/ExpensifyCardPage.tsxandsrc/WalletPage/CardDetails.tsx(and the way it’s surfaced frompages/settings/Wallet/PaymentMethodList.tsx) will be refactored into a small shared CVV row component (e.g.CardSecurityCodeRow).WalletTravelCVVSectionwill render that shared CVV row with a different label (“Travel booking CVV”) and will wire itsonRevealcallback to the Travel Invoicing action instead of the card action.WalletTravelCVVSection:
CardSecurityCodeRowwith:translate('travelInvoicing.travelCVVTitle')(e.g., “Travel booking CVV”).revealTravelCVVand the existing clipboard utility.Testing
Component tests:
isLoadingand callsrevealTravelCVV.Fixed Issues
$ #78679
$ #78678
PROPOSAL:
Tests
Important
The feature is currently Dev/Adhoc-Build/Staging-locked and uses the first available card (Expensify Card) despite not having
isTravelCardundefined - this was done on purpose to allow testing.Prerequisites
ALLorTRAVEL_INVOICINGbetas enabledisTravelCVVTestingEnabledflag, you can test with any assigned card if you don't have a specific Travel Card - just ensure you have at least one Expensify Card assigned on your email address in Settings > Wallet (must be Expensify Card)Test 1: Navigation & UI Verification
•••and a "Reveal details" button.Test 2: CVV Reveal Flow
•••is replaced by the actual CVV number from the server response.Test 3: Navigation Persistence (Refresh)
Offline tests
Test 4: Offline Behavior
FullPageOfflineBlockingViewactivates, blocking access to the sensitive page content and showing the "You appear to be offline." message.QA Steps
Same as tests.
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectioncanBeMissingparam foruseOnyxtoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
web.mov
ios-hybrid.mov