Skip to content

docs: incoming message origin validation across platforms#478

Draft
michaeljsXu wants to merge 1 commit into
07-15-feat_incoming_message_origin_validation_for_react_nativefrom
07-15-docs_incoming_message_origin_validation
Draft

docs: incoming message origin validation across platforms#478
michaeljsXu wants to merge 1 commit into
07-15-feat_incoming_message_origin_validation_for_react_nativefrom
07-15-docs_incoming_message_origin_validation

Conversation

@michaeljsXu

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

Assisted-By: devx/6d172f11-c70b-447c-9803-84d58a5e6c3a

Copy link
Copy Markdown
Contributor Author

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more

This stack of pull requests is managed by Graphite. Learn more about stacking.

Comment thread platforms/web/README.md
| `*` | Every origin — disables origin validation entirely. |

```html
<shopify-checkout src="..." allowed-origins="https://checkout.example.com https://*.example.com" />

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like the React TypeScript declaration has a closed attribute list and omits allowed-origins, so consumers following this example will get a type error. Could we add 'allowed-origins'?: string here?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants