Skip to content

feat: incoming message origin validation for react native#477

Draft
michaeljsXu wants to merge 1 commit into
07-15-feat_incoming_message_origin_validation_for_iosfrom
07-15-feat_incoming_message_origin_validation_for_react_native
Draft

feat: incoming message origin validation for react native#477
michaeljsXu wants to merge 1 commit into
07-15-feat_incoming_message_origin_validation_for_iosfrom
07-15-feat_incoming_message_origin_validation_for_react_native

Conversation

@michaeljsXu

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

Assisted-By: devx/6d172f11-c70b-447c-9803-84d58a5e6c3a
@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more

This stack of pull requests is managed by Graphite. Learn more about stacking.

}

if (config.hasKey("allowedMessageOrigins")) {
configuration.setAllowedMessageOrigins(toStringSet(config.getArray("allowedMessageOrigins")));

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like both native SDKs are still pinned to 4.0.0-alpha.2, which predates the APIs used by the Android and iOS bridges in this PR. Could we update both pins once compatible native releases are available so normal consumer builds pick up these APIs?

*
* @default [] (all origins trusted)
*/
allowedMessageOrigins?: string[];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would it make sense to expose a typed rejection callback or event through both native bridges? React Native consumers cannot currently observe rejected messages, and the debug log is hidden by the default error log level. Native debug logging could remain the fallback.

colorScheme?: string;
logLevel?: string;
preloading?: boolean;
allowedMessageOrigins?: string[];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like getConfig() will omit allowedMessageOrigins after it has been set. Could we add the field to the result spec and both native getters, with a round-trip test?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants