Skip to content

feat: add legal name step subheader, validate PMB addresses, and update address step subheader copy for VBBA#92289

Merged
justinpersaud merged 22 commits into
Expensify:mainfrom
samranahm:92019/update-subheader-on-address-and-name-step
Jun 24, 2026
Merged

feat: add legal name step subheader, validate PMB addresses, and update address step subheader copy for VBBA#92289
justinpersaud merged 22 commits into
Expensify:mainfrom
samranahm:92019/update-subheader-on-address-and-name-step

Conversation

@samranahm

@samranahm samranahm commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Explanation of Change

Fixed Issues

$ #92019
PROPOSAL: #92019 (comment)

Tests

  1. Open the "Wallet" or "Workflows" page and press "Add bank account".
  2. Enter the routing and account numbers, then press Next.
  3. On the legal name step, verify the subheader matches the styling of other step subheaders and the copy is:
    Please enter your full legal name as it appears on your ID.
  4. Enter the legal name and press Next.
  5. On the company address and personal address steps, verify the subheader is:
    A physical address is required. PO boxes and mail drops are not accepted.
  6. Enter a PO Box address (e.g. PO Box 123) or a PMB address (e.g. PMB #123) and verify the inline error is:
    A physical address is required. PO boxes and mail drops are not accepted.
  7. Enter an address that contain emoji, or address is only emojis, and verify the inline error is:
    Please enter a valid street address.
  • Verify that no errors appear in the JS console

Offline tests

QA Steps

Same as test

// TODO: These must be filled out, or the issue title must include "[No QA]."

  • Verify that no errors appear in the JS console

PR Author Checklist

  • I linked the correct issue in the ### Fixed Issues section above
  • I wrote clear testing steps that cover the changes made in this PR
    • I added steps for local testing in the Tests section
    • I added steps for the expected offline behavior in the Offline steps section
    • I added steps for Staging and/or Production testing in the QA steps section
    • I added steps to cover failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
    • I tested this PR with a High Traffic account against the staging or production API to ensure there are no regressions (e.g. long loading states that impact usability).
  • I included screenshots or videos for tests on all platforms
  • I ran the tests on all platforms & verified they passed on:
    • Android: Native
    • Android: mWeb Chrome
    • iOS: Native
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
  • I verified there are no console errors (if there's a console error not related to the PR, report it or open an issue for it to be fixed)
  • I followed proper code patterns (see Reviewing the code)
    • I verified that any callback methods that were added or modified are named for what the method does and never what callback they handle (i.e. toggleReport and not onIconClick)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text shown in the product is localized by adding it to src/languages/* files and using the translation method
    • I verified all numbers, amounts, dates and phone numbers shown in the product are using the localization methods
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
    • I verified proper file naming conventions were followed for any new files or renamed files. All non-platform specific files are named after what they export and are not named "index.js". All platform-specific files are named for the platform the code supports as outlined in the README.
    • I verified the JSDocs style guidelines (in STYLE.md) were followed
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I followed the guidelines as stated in the Review Guidelines
  • I tested other components that can be impacted by my changes (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar are working as expected)
  • I verified all code is DRY (the PR doesn't include any logic written more than once, with the exception of tests)
  • I verified any variables that can be defined as constants (ie. in CONST.ts or at the top of the file that uses the constant) are defined as such
  • I verified that if a function's arguments changed that all usages have also been updated correctly
  • If any new file was added I verified that:
    • The file has a description of what it does and/or why is needed at the top of the file if the code is not self explanatory
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))
  • If new assets were added or existing ones were modified, I verified that:
    • The assets are optimized and compressed (for SVG files, run npm run compress-svg)
    • The assets load correctly across all supported platforms.
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • If a new page is added, I verified it's using the ScrollView component to make it scrollable when more elements are added to the page.
  • I added unit tests for any new feature or bug fix in this PR to help automatically prevent regressions in this user flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.

Screenshots/Videos

Android: Native
Android.Native.mp4
Android: mWeb Chrome
Android.mWeb.Chrome.mp4
iOS: Native
IOS.Native.mp4
iOS: mWeb Safari
IOS.mWeb.Safari.mp4
MacOS: Chrome / Safari
macOS.Chrome.mp4

@samranahm
samranahm requested review from a team as code owners June 1, 2026 22:03
@melvin-bot

melvin-bot Bot commented Jun 1, 2026

Copy link
Copy Markdown

Hey, I noticed you changed src/languages/en.ts in a PR from a fork. For security reasons, translations are not generated automatically for PRs from forks.

If you want to automatically generate translations for other locales, an Expensify employee will have to:

  1. Look at the code and make sure there are no malicious changes.
  2. Run the Generate static translations GitHub workflow. If you have write access and the K2 extension, you can simply click: [this button]

Alternatively, if you are an external contributor, you can run the translation script locally with your own OpenAI API key. To learn more, try running:

npx ts-node ./scripts/generateTranslations.ts --help

Typically, you'd want to translate only what you changed by running npx ts-node ./scripts/generateTranslations.ts --compare-ref main

@melvin-bot

melvin-bot Bot commented Jun 1, 2026

Copy link
Copy Markdown

@dannymcclain @marufsharifi One of you needs to copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button]

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 85a48293b2

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/CONST/index.ts Outdated
@marufsharifi

Copy link
Copy Markdown
Contributor

@samranahm, tests failed; could you please check? thanks.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@codecov

codecov Bot commented Jun 2, 2026

Copy link
Copy Markdown

@samranahm

Copy link
Copy Markdown
Contributor Author

@marufsharifi all test passing please take a look.

@marufsharifi

Copy link
Copy Markdown
Contributor

@samranahm, could you please check this.

@MelvinBot

Copy link
Copy Markdown
Contributor

Review

Overall this looks solid: the implementation matches the expanded scope agreed in the issue thread (legal-name subtitle plus the address-copy update and PO box / PMB validation that clarajones-expensify requested), all CI is green, and the unit tests are good — including the spaced-hash PMB # 123 case that the earlier Codex comment flagged. A few things worth confirming before approving:

1. Changing the shared isValidAddress extends PMB rejection beyond the VBBA flows

The PR adds PMB rejection inside isValidAddress, which is shared by 6 callers. Three of them are outside the bank-account address scope discussed in the issue and were not updated with the new copy:

This is incremental (those callers already rejected PO boxes before this PR, so it's just adding PMB), so it's likely fine — but it's a behavior change in unrelated features. Worth a conscious 👍 that we want PMB rejected app-wide and not just in the VBBA flows.

2. Non-English translations were hand-added and have a register mismatch

Because this is a fork PR, generateTranslations is skipped, and all 10 locale files were edited by hand. At least the German strings use the formal register, which is inconsistent with the rest of de.ts (informal "du"):

  • de.ts:3777'Bitte geben **Sie Ihren**...' vs. the file's usual 'Bitte gib...' / '...du...' style.

Recommend an Expensify employee run the Generate static translations workflow (after a security pass on the diff) so the non-en locales are generated consistently rather than hand-written.

Minor / nits
  • PMB regex breadthCONST.REGEX.PMB reduces to M…B…<digits> with the inner letters (a/i/l, o/x) all optional, so something like Mailbox Lane 3 (digits trailing) could be flagged. It's constrained enough in practice and the test cases cover the realistic formats, just noting the false-positive surface. The literal | inside classes like [P|p]/[O|o|0] is also redundant, but it matches the existing PO_BOX style so it's consistent.
  • NamespaceaddressSubtitle / legalNameSubtitle live under personalInfoStep but are reused in business contexts (businessInfoStep, beneficialOwnerInfoStep). Works fine; minor organizational smell.
  • Subtitle applied broadly — the legal-name subtitle is wired into more flows than the original 3 in the proposal (e.g. MissingPersonalDetails/subPages/LegalName.tsx). That's arguably good for consistency, just flagging it's wider than the proposal text since MissingPersonalDetails isn't a bank-account flow.

I didn't spot any blocking correctness bugs. The two items above are mostly "confirm intent" — once you're satisfied with the app-wide PMB behavior and the translations are properly generated, this looks good to go.

@samranahm

Copy link
Copy Markdown
Contributor Author

@marufsharifi The Codecov decrease isn't an actual case here

The only logic change is in ValidationUtils.ts isValidAddress , which shows 100% patch coverage <100.00%> and +1.95% overall, it's fully covered by the new tests in ValidationUtilsTest.ts.

CONST/index.ts (-0.05%) only adds the PMB regex string constant the tiny drop is just from adding a non-executable regex line.

The .tsx files all show no change. They are already at 0% coverage on main and my edits only pass a new formSubtitle/addressSubtitle prop, so there's nothing to add here extra and we're good to GO

@samranahm

samranahm commented Jun 3, 2026

Copy link
Copy Markdown
Contributor Author

@clarajones-expensify isValidAddress also check if the street address contains an emoji (or is only emoji) in this case we were showing Please enter a valid street address and now it would be A physical address is required. PO boxes and mail drops are not accepted., although that street address isn't related to PO boxes or PMBs, could you confirm this behaviour please.

@clarajones-expensify

Copy link
Copy Markdown
Contributor

@samranahm oo that is a great question. can you make it so that if the address only contains an emoji, it will still say Please enter a valid street address. ?

@samranahm

Copy link
Copy Markdown
Contributor Author

@marufsharifi Done.

@marufsharifi

Copy link
Copy Markdown
Contributor

Doing a re-test. thanks

@marufsharifi

Copy link
Copy Markdown
Contributor

@heyjennahay, could you please check this when you get a chance? thanks.

heyjennahay
heyjennahay previously approved these changes Jun 22, 2026

@heyjennahay heyjennahay left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Product change LGTM

@samranahm

Copy link
Copy Markdown
Contributor Author

Thanks for confirmation @heyjennahay, I'll update the copy in both locations shortly.

@samranahm

Copy link
Copy Markdown
Contributor Author

Merging main to fix flaky test.

@samranahm
samranahm requested a review from marufsharifi June 23, 2026 15:17
@samranahm

Copy link
Copy Markdown
Contributor Author

@marufsharifi Could you take another look at this PR please when you get a chance.

@marufsharifi

Copy link
Copy Markdown
Contributor

I am checking this again. thanks.

@melvin-bot
melvin-bot Bot requested a review from justinpersaud June 24, 2026 08:48
@marufsharifi

Copy link
Copy Markdown
Contributor

LGTM

@justinpersaud

Copy link
Copy Markdown
Contributor

@marufsharifi PR reviewer checklist check is failing. Maybe the one you used wasn't up to date? Check here https://raw.githubusercontent.com/Expensify/App/main/contributingGuides/REVIEWER_CHECKLIST.md

@justinpersaud
justinpersaud merged commit bcccb95 into Expensify:main Jun 24, 2026
34 of 36 checks passed
@OSBotify

Copy link
Copy Markdown
Contributor

✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release.

@github-actions

Copy link
Copy Markdown
Contributor

🚧 justinpersaud has triggered a test Expensify/App build. You can view the workflow run here.

@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to staging by https://github.com/justinpersaud in version: 9.4.19-1 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

Bundle Size Analysis (Sentry):

@MelvinBot

Copy link
Copy Markdown
Contributor

🤖 I reviewed the changes in this PR and confirmed that help site updates are required.

This PR changes user-facing copy and validation in the verified business bank account (VBBA) setup flow:

  • Added the legal name step subheader: Please enter your full legal name as it appears on your ID.
  • Added the address step subheader and now blocks PO boxes and mail drops (PMB) with the inline error: A physical address is required. PO boxes and mail drops are not accepted.

The existing help article Connect-a-US-Business-Bank-Account.md was out of date — it stated that PO boxes / mail drops "will be flagged for review and may delay verification," but with this PR they are now rejected outright at the address step. The article also didn't mention entering your legal name exactly as it appears on your ID (the core fix from #92019).

Draft help site PR: #94501

It applies the HelpDot label and:

  1. Corrects the company address guidance to reflect the new blocking behavior.
  2. Adds a "What personal details to enter when connecting your bank account" section covering the legal name guidance and the physical address requirement.

⚠️ I couldn't auto-assign the draft PR to samranahm — that account isn't an assignable user on Expensify/App (external contributors without triage/write access can't be set as assignees). Please self-assign on the linked PR.

@samranahm, please review the linked help site PR and confirm it reflects the current behavior. Then mark the linked help site PR Ready for review

@mitarachim

Copy link
Copy Markdown

Deploy Blocker #94519 was identified to be related to this PR.

@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to production by https://github.com/blimpich in version: 9.4.19-5 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants