Repository navigation
Public room - Not here page opens when drag and drop an image to Home as guest #82722
Description
Activity
- addedDeployBlockerCashThis issue or pull request should block deploymentThis issue or pull request should block deployment
on Feb 18, 2026 - addedDailyKSv2KSv2BugSomething is broken. Auto assigns a BugZero manager.Something is broken. Auto assigns a BugZero manager.DeployBlockerIndicates it should block deploying the APIIndicates it should block deploying the API
on Feb 18, 2026 You have been assigned to this deploy blocker because you recently merged this PR: #82562
💬 A slack conversation has been started in #expensify-open-source
Triggered auto assignment to @sonialiap (
Bug), see https://stackoverflow.com/c/expensify/questions/14418 for more details. Please add this bug to a GH project, as outlined in the SO.github-actions commented
on Feb 18, 2026 on Feb 18, 2026 – with GitHub ActionsContributorMore actions👋 Friendly reminder that deploy blockers are time-sensitive ⏱ issues! Check out the open `StagingDeployCash` deploy checklist to see the list of PRs included in this release, then work quickly to do one of the following:
- Identify the pull request that introduced this issue and revert it.
- Find someone who can quickly fix the issue.
- Fix the issue yourself.
Proposal
Please re-state the problem that we are trying to solve in this issue.
When a guest (anonymous/unauthenticated) user visits a public room, navigates to the Home tab, and drags and drops an image onto the page, a semi-transparent "Hmm... it's not here" blocking page appears. Guest users should not be able to trigger receipt drag-and-drop functionality on the Home page.
What is the root cause of that problem?
PR #82562 added drag-and-drop receipt scanning to
HomePage.tsxby wrapping it withDragAndDropProviderand using the newuseReceiptScanDrophook. Neither the HomePage component nor the hook checks whether the user is anonymous before enabling this functionality.The bug flow:
-
A guest visiting a public room receives an anonymous
authToken(typeanonymousAccount). SinceuseIsAuthenticated(src/hooks/useIsAuthenticated.tsx:7) only checks for the presence of an authToken (not its type), the anonymous user is treated as "authenticated" and getsAuthScreens, including the realHomePage. -
The Home tab in
NavigationTabBar(src/components/Navigation/NavigationTabBar/index.tsx:178-183) does not useinterceptAnonymousUser— unlike the Search tab (line 219) and Settings tab (line 263), which do guard against anonymous access. -
HomePage.tsx(lines 42-91) wraps its content in<DragAndDropProvider>with noisDisabledprop and no auth check. TheuseReceiptScanDrophook (lines 1-121) also has zero authentication checks. -
When the anonymous user drops a file,
initScanRequestfires, callsinitMoneyRequest, and navigates to the money request participants page (MONEY_REQUEST_STEP_PARTICIPANTS). That page is wrapped inwithFullTransactionOrNotFound(src/pages/iou/request/step/withFullTransactionOrNotFound.tsx:88-89), which rendersFullPageNotFoundView("Hmm... it's not here") because the anonymous user has no valid transaction data.
What changes do you think we should make in order to solve the problem?
The most consistent and minimal fix is to add an anonymous user check inside
useReceiptScanDrop. At the beginning of theinitScanRequestcallback insrc/hooks/useReceiptScanDrop.tsx, callinterceptAnonymousUserto gate the entire drop handler. If the user is anonymous, show the sign-in modal instead of proceeding with the money request flow.This approach fixes the issue for both
HomePageandSearchPage(which shares the same hook and has the same vulnerability, though it's currently unreachable because the Search tab itself is guarded byinterceptAnonymousUser).What alternative solutions did you explore? (Optional)
-
Pass
isDisabledtoDragAndDropProviderin HomePage: Could checkuseIsAnonymousUser()and passisDisabled={isAnonymousUser}toDragAndDropProvider. This fixes the symptom for HomePage specifically but doesn't protect the shared hook from other future consumers. -
Add
interceptAnonymousUserto the Home tab navigation in NavigationTabBar: This would prevent anonymous users from reaching HomePage at all (like Search/Settings tabs). However, this may be too aggressive — there could be legitimate reasons for anonymous users to see the Home page, just not interact with receipt scanning. -
Both hook-level and provider-level guards (defense in depth): Gate
useReceiptScanDropwithinterceptAnonymousUserAND passisDisabled={isAnonymousUser}toDragAndDropProvider. This provides the strongest protection but may be over-engineering for this case.
Next Steps for Contributor+ team: Reply with
@MelvinBot implement thisto create a draft PR, or@MelvinBot <your feedback>to refine this analysis.-
17 remaining items
@mallenexpensify Can you help with the payment summary here?
- addedAwaiting PaymentAuto-added when associated PR is deployed to productionAuto-added when associated PR is deployed to productionand removedReviewingHas a PR in reviewHas a PR in review
on Apr 6, 2026 Triggered auto assignment to @mallenexpensify (
Awaiting Payment)@ShridharGoel is this a regression from #82926
I see
@grgia Can you assign me here since I had reviewed?
When you reference or issue, please always hyperlink to the PR or issue.
@ShridharGoel plz complete the BZ checklist and tag me in a post once you have. Thx
Reacted by Shridhar GoelBugZero Checklist:
-
[Contributor] The offending PR has been commented on, pointing out the bug it caused and why, so the author and reviewers can learn from the mistake.
Link to comment: [Home Page] New feature: Drag&Drop scan #82562 (comment)
-
[Contributor] If the regression was CRITICAL (e.g. interrupts a core flow) A discussion in #expensify-open-source has been started about whether any other steps should be taken (e.g. updating the PR review checklist) in order to catch this type of bug sooner.
Link to discussion:
-
[Contributor] If it was decided to create a regression test for the bug, please propose the regression test steps using the template below to ensure the same bug will not reach production again.
-
[BugZero Assignee] Create a GH issue for creating/updating the regression test once above steps have been agreed upon.
Link to issue: https://github.com/Expensify/Expensify/issues/621439
Regression Test Proposal
Test:
- Open https://staging.new.expensify.com/r/6594704240385493 while logged out, go to Home, drag an image. No drop zone should appear
- Try Search tab if reachable. Same, no drop zone
- Log in, go to Home, drag an image. Drop zone works normally
- Try Search tab. Same, drop zone now works as expected
Do we agree 👍 or 👎
Zapier Logs
Run ID: 00040eee-39c6-ad43-6453-488710111fc4-
@mallenexpensify Added
$250 approved for @ShridharGoel
Metadata
Metadata
Labels
Type
Projects
- StatusShow more project fieldsDone
If you haven’t already, check out our contributing guidelines for onboarding and email contributors@expensify.com to request to join our Slack channel!
Version Number: 9.3.21-0
Reproducible in staging?: Yes
Reproducible in production?: No
If this was caught during regression testing, add the test name, ID and link from BrowserStack: #82562
Email or phone of affected tester (no customers): sdjoisjndoisnjodsoijo@gmail.com
Issue reported by: Applause Internal Team
Bug source: Exploratory - Significant User Experience Deterioration
Device used: Mac 26.2 / Chrome
App Component: Other
Action Performed:
Expected Result:
User cannot drag and drop an image to Home.
Actual Result:
User can drag and drop an image to Home which opens semi-transparent not here page.
Workaround:
Unknown
Platforms:
Screenshots/Videos
Bug7080937_1771374564338.2.mp4
View all open jobs on GitHub
Issue Owner
Current Issue Owner: @ShridharGoel