Skip to content

Fix WhatsApp country-code handling on Mobile Safari - #828

Merged
defangdevs merged 2 commits into
masterfrom
fix/820-whatsapp-phone
Oct 4, 2026
Merged

defangdevs merged 2 commits into
masterfrom
fix/820-whatsapp-phone

Conversation

@defangdevs

@defangdevs defangdevs commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Why

Mobile Safari can offer a saved +1... phone number for the WhatsApp pairing field but insert only its national form. The settings handler accepted that 10-digit value as if it still carried a country code, so pairing could proceed with a different number than the operator selected.

Changes

  • Stop asking the browser to autofill a saved telephone contact while retaining the telephone input type.
  • Use a plus-capable telephone keyboard instead of a digits-only keypad.
  • Require nonblank form input to start with +, then validate and normalize the same punctuation the form already accepted.
  • Preserve a blank form submission as the existing LOCAL_WHATSAPP_PHONE secret fallback.
  • Drive the real HTTP handler in regression tests for national-number rejection without state mutation, valid international normalization, and blank fallback.
  • Regenerate the standalone module and web golden payload.

User-visible and security effects

The field now says that the number must start with + and its country code. A national-format substitution receives a readable 400 response instead of changing the saved pairing number. Credential storage and bridge permissions are unchanged; the phone continues to be normalized to digits before it is saved.

Verification

  • python3 tests/test-connect-card.py - 38 passed.
  • python3 tests/test_agentbox.py - 156 passed, 1 skipped.
  • nix build -L --keep-going .#ci-native - passed after the final commit.
  • Targeted generated-module, assembler escaping, golden snapshot, backend parity, and one-spec checks passed.
  • git diff --check and Python compilation passed.
  • Correctness review: PASS.
  • Phone-width Chromium render at 390 px: PASS, no overflow.

WhatsApp pairing card at phone width

Delivery checklist

  • Implementation and focused regressions
  • Generated artifacts
  • Full native validation
  • Correctness review
  • Phone-width verification
  • Required GitHub checks
  • Merge and post-merge verification

Fixes #820.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 36403bea-0e32-4297-acbd-59e24d283a3a
📥 Commits

Reviewing files that changed from the base of the PR and between 35ed460 and eb40608.

📒 Files selected for processing (4)
  • modules/agent-box.nix
  • modules/src/settings-daemon.py
  • tests/golden/web/payloads/agent-box-settings/bin/agent-box-settings
  • tests/test-connect-card.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The WhatsApp pairing form now requests a phone number with an explicit international prefix. The request handler validates nonblank numbers before saving normalized digits. Blank submissions continue to use the saved-number fallback.

Changes

WhatsApp phone pairing

Layer / File(s) Summary
Pairing field and prompt
modules/agent-box.nix, modules/src/settings-daemon.py, tests/golden/web/payloads/agent-box-settings/bin/agent-box-settings, tests/test-connect-card.py
The phone field uses telephone input mode, disables contact autocomplete, and requests a number starting with +. The pairing-card test checks the field attributes and prompt.
Request validation and regression tests
modules/agent-box.nix, modules/src/settings-daemon.py, tests/golden/web/payloads/agent-box-settings/bin/agent-box-settings, tests/test-connect-card.py
The handler requires nonblank numbers to start with +, contain permitted characters, and normalize to 7–15 ASCII digits. HTTP tests check rejection without changing the saved number, successful saving of normalized digits, and preservation of the saved fallback for blank submissions.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: lionello

Merge Risk: ⚪ Minimal · up to eb406

The pairing change is ready to merge after normal checks; no unresolved issue was established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to eb406

The change rejects ambiguous phone numbers before saving them and preserves the existing saved-number fallback. No new privilege or access-control bypass was established. Assurance remains limited because live pairing, concurrent submissions, and deployed access controls were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed value affects the settings user's saved pairing number and the WhatsApp pairing process consuming it. The inspected change does not add caller-selected commands, cross-user targets, or additional authority.

Security Findings and Attack Paths

  • inferred — The prior path from an ambiguous national-format form value to saved pairing identity is narrowed: the new validator rejects that value before persistence and launch. This is input disambiguation, not proof of ownership of the supplied WhatsApp account.

Trust Boundaries and Controls

  • observed — The connection POST remains behind the existing same-origin gate and fixed flow/action selection. At launch, the normalized phone remains quoted data rather than shell-command structure. These source controls do not establish the deployed authentication or proxy configuration.

Resilience and Maintainability Implications

  • inferred — Pre-existing transition limitations remain: saving precedes profile persistence and launch, so later failure can leave the new phone saved. A repeated start can replace the saved number while an existing pairing pane continues with its captured number. These conditions are unchanged, not introduced or worsened by this validation tightening.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 2 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #820 requires explicit country-code syntax for nonblank submissions, no telephone-contact autofill, a plus-capable telephone keyboard, and the existing blank-secret fallback. The PR summary repo…
Out of Scope Changes check ✅ Passed The reported source changes, handler and rendering tests, and regenerated artifacts directly support issue #820. The summary reports no unrelated changes. The whole-PR diff could not be retrieved beca…
Title check ✅ Passed The title clearly describes the main change: preventing Mobile Safari from mishandling the WhatsApp country code.
Description check ✅ Passed The description explains the Safari issue, the phone-number validation changes, and the related regression tests.
Full details: Docstring Coverage

Explanation

Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 2 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@defangdevs
defangdevs merged commit 34581a7 into master Oct 4, 2026
8 checks passed
@defangdevs
defangdevs deleted the fix/820-whatsapp-phone branch October 4, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Preserve country code in WhatsApp phone pairing on Mobile Safari

1 participant