Skip to content

Public room - Not here page opens when drag and drop an image to Home as guest #82722

Description

@mitarachim

If you haven’t already, check out our contributing guidelines for onboarding and email contributors@expensify.com to request to join our Slack channel!


Version Number: 9.3.21-0
Reproducible in staging?: Yes
Reproducible in production?: No
If this was caught during regression testing, add the test name, ID and link from BrowserStack: #82562
Email or phone of affected tester (no customers): sdjoisjndoisnjodsoijo@gmail.com
Issue reported by: Applause Internal Team
Bug source: Exploratory - Significant User Experience Deterioration
Device used: Mac 26.2 / Chrome
App Component: Other

Action Performed:

  1. Log out if logged in.
  2. Navigate to public room - https://staging.new.expensify.com/r/6594704240385493
  3. Go to Home.
  4. Drag and drop an image to Home.

Expected Result:

User cannot drag and drop an image to Home.

Actual Result:

User can drag and drop an image to Home which opens semi-transparent not here page.

Workaround:

Unknown

Platforms:

  • Android: App
  • Android: mWeb Chrome
  • iOS: App
  • iOS: mWeb Safari
  • iOS: mWeb Chrome
  • Windows: Chrome
  • MacOS: Chrome / Safari

Screenshots/Videos

Bug7080937_1771374564338.2.mp4

View all open jobs on GitHub

Issue OwnerCurrent Issue Owner: @ShridharGoel

Activity

  1. added
    BugSomething is broken. Auto assigns a BugZero manager.
    DeployBlockerIndicates it should block deploying the API
    on Feb 18, 2026
  2. melvin-bot commented on Feb 18, 2026

    @melvin-bot

    You have been assigned to this deploy blocker because you recently merged this PR: #82562

  3. melvin-bot commented on Feb 18, 2026

    @melvin-bot

    💬 A slack conversation has been started in #expensify-open-source

  4. melvin-bot commented on Feb 18, 2026

    @melvin-bot

    Triggered auto assignment to @sonialiap (Bug), see https://stackoverflow.com/c/expensify/questions/14418 for more details. Please add this bug to a GH project, as outlined in the SO.

  5. github-actions commented on Feb 18, 2026

    @github-actions
    Contributor

    👋 Friendly reminder that deploy blockers are time-sensitive ⏱ issues! Check out the open `StagingDeployCash` deploy checklist to see the list of PRs included in this release, then work quickly to do one of the following:

    1. Identify the pull request that introduced this issue and revert it.
    2. Find someone who can quickly fix the issue.
    3. Fix the issue yourself.
  6. MelvinBot commented on Feb 18, 2026

    @MelvinBot
    Contributor

    Proposal

    Please re-state the problem that we are trying to solve in this issue.

    When a guest (anonymous/unauthenticated) user visits a public room, navigates to the Home tab, and drags and drops an image onto the page, a semi-transparent "Hmm... it's not here" blocking page appears. Guest users should not be able to trigger receipt drag-and-drop functionality on the Home page.

    What is the root cause of that problem?

    PR #82562 added drag-and-drop receipt scanning to HomePage.tsx by wrapping it with DragAndDropProvider and using the new useReceiptScanDrop hook. Neither the HomePage component nor the hook checks whether the user is anonymous before enabling this functionality.

    The bug flow:

    1. A guest visiting a public room receives an anonymous authToken (type anonymousAccount). Since useIsAuthenticated (src/hooks/useIsAuthenticated.tsx:7) only checks for the presence of an authToken (not its type), the anonymous user is treated as "authenticated" and gets AuthScreens, including the real HomePage.

    2. The Home tab in NavigationTabBar (src/components/Navigation/NavigationTabBar/index.tsx:178-183) does not use interceptAnonymousUser — unlike the Search tab (line 219) and Settings tab (line 263), which do guard against anonymous access.

    3. HomePage.tsx (lines 42-91) wraps its content in <DragAndDropProvider> with no isDisabled prop and no auth check. The useReceiptScanDrop hook (lines 1-121) also has zero authentication checks.

    4. When the anonymous user drops a file, initScanRequest fires, calls initMoneyRequest, and navigates to the money request participants page (MONEY_REQUEST_STEP_PARTICIPANTS). That page is wrapped in withFullTransactionOrNotFound (src/pages/iou/request/step/withFullTransactionOrNotFound.tsx:88-89), which renders FullPageNotFoundView ("Hmm... it's not here") because the anonymous user has no valid transaction data.

    What changes do you think we should make in order to solve the problem?

    The most consistent and minimal fix is to add an anonymous user check inside useReceiptScanDrop. At the beginning of the initScanRequest callback in src/hooks/useReceiptScanDrop.tsx, call interceptAnonymousUser to gate the entire drop handler. If the user is anonymous, show the sign-in modal instead of proceeding with the money request flow.

    This approach fixes the issue for both HomePage and SearchPage (which shares the same hook and has the same vulnerability, though it's currently unreachable because the Search tab itself is guarded by interceptAnonymousUser).

    What alternative solutions did you explore? (Optional)

    1. Pass isDisabled to DragAndDropProvider in HomePage: Could check useIsAnonymousUser() and pass isDisabled={isAnonymousUser} to DragAndDropProvider. This fixes the symptom for HomePage specifically but doesn't protect the shared hook from other future consumers.

    2. Add interceptAnonymousUser to the Home tab navigation in NavigationTabBar: This would prevent anonymous users from reaching HomePage at all (like Search/Settings tabs). However, this may be too aggressive — there could be legitimate reasons for anonymous users to see the Home page, just not interact with receipt scanning.

    3. Both hook-level and provider-level guards (defense in depth): Gate useReceiptScanDrop with interceptAnonymousUser AND pass isDisabled={isAnonymousUser} to DragAndDropProvider. This provides the strongest protection but may be over-engineering for this case.


    Next Steps for Contributor+ team: Reply with @MelvinBot implement this to create a draft PR, or @MelvinBot <your feedback> to refine this analysis.

  7. 17 remaining items

  8. ShridharGoel commented on Apr 3, 2026

    @ShridharGoel
    Contributor

    @mallenexpensify Can you help with the payment summary here?

  9. added
    Awaiting PaymentAuto-added when associated PR is deployed to production
    and removed
    ReviewingHas a PR in review
    on Apr 6, 2026
  10. melvin-bot commented on Apr 6, 2026

    @melvin-bot

    Triggered auto assignment to @mallenexpensify (Awaiting Payment)

  11. mallenexpensify commented on Apr 6, 2026

    @mallenexpensify
    Contributor

    @ShridharGoel is this a regression from #82926

    I see

    @grgia Can you assign me here since I had reviewed?

    When you reference or issue, please always hyperlink to the PR or issue.

    @ShridharGoel plz complete the BZ checklist and tag me in a post once you have. Thx

  12. ShridharGoel commented on Apr 6, 2026

    @ShridharGoel
    Contributor

    is this a regression from #82926

    #82926 is the one which solves this issue.

  13. ShridharGoel commented on Apr 6, 2026

    @ShridharGoel
    Contributor

    BugZero Checklist:

    • [Contributor] The offending PR has been commented on, pointing out the bug it caused and why, so the author and reviewers can learn from the mistake.

      Link to comment: [Home Page] New feature: Drag&Drop scan  #82562 (comment)

    • [Contributor] If the regression was CRITICAL (e.g. interrupts a core flow) A discussion in #expensify-open-source has been started about whether any other steps should be taken (e.g. updating the PR review checklist) in order to catch this type of bug sooner.

      Link to discussion:

    • [Contributor] If it was decided to create a regression test for the bug, please propose the regression test steps using the template below to ensure the same bug will not reach production again.

    • [BugZero Assignee] Create a GH issue for creating/updating the regression test once above steps have been agreed upon.

      Link to issue: https://github.com/Expensify/Expensify/issues/621439

    Regression Test Proposal

    Test:

    1. Open https://staging.new.expensify.com/r/6594704240385493 while logged out, go to Home, drag an image. No drop zone should appear
    2. Try Search tab if reachable. Same, no drop zone
    3. Log in, go to Home, drag an image. Drop zone works normally
    4. Try Search tab. Same, drop zone now works as expected

    Do we agree 👍 or 👎

    Zapier Logs Run ID: 00040eee-39c6-ad43-6453-488710111fc4
  14. ShridharGoel commented on Apr 6, 2026

    @ShridharGoel
    Contributor
  15. mallenexpensify commented on Apr 7, 2026

    @mallenexpensify
    Contributor

    Payment Summary

    Contributor+: @ShridharGoel due $250 via NewDot

    Thx!

  16. JmillsExpensify commented on Apr 9, 2026

    @JmillsExpensify
    Contributor

    $250 approved for @ShridharGoel

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Awaiting PaymentAuto-added when associated PR is deployed to productionBugSomething is broken. Auto assigns a BugZero manager.EngineeringWeeklyKSv2

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions