refactor(android): log message rejections as warnings - #647
Merged
tiagocandido merged 1 commit intoAug 17, 2026
Merged
Conversation
Contributor
Author
This stack of pull requests is managed by Graphite. Learn more about stacking. |
This was referenced Aug 14, 2026
tiagocandido
marked this pull request as ready for review
August 14, 2026 15:05
Package Size
Android file breakdown
Measured from the PR base SHA and PR head SHA. The file breakdown shows uncompressed sizes within each package artifact, so individual files do not sum to the compressed artifact total. This comment reports package artifact sizes only; it is not a final app binary-size report. |
Install this buildOpen Tophat, select your target device, then click Install. Links open on the Mac running Tophat.
Checkout Kit E2E results
|
markmur
approved these changes
Aug 14, 2026
Contributor
Author
Merge activity
|
tiagocandido
changed the base branch from
08-14-refactor_swift_message_rejection_warn_logging
to
graphite-base/647
August 17, 2026 08:15
Remove Configuration.onMessageRejected and the public RejectedMessage type before they ship in a release. Origin-validation rejections are now always logged at warn level with the verified origin and reason; the untrusted message body is never logged.
tiagocandido
force-pushed
the
08-14-refactor_android_message_rejection_warn_logging
branch
from
August 17, 2026 08:15
3f2c7cc to
417767b
Compare
tiagocandido
deleted the
08-14-refactor_android_message_rejection_warn_logging
branch
August 17, 2026 08:21
5 tasks
tiagocandido
added a commit
that referenced
this pull request
Aug 17, 2026
### What changes are you making? Release the Android package as `4.0.0-alpha.5`. This updates the Maven artifact version and public installation examples. The release includes the Android changes merged since `4.0.0-alpha.4`, including the removal of the `onMessageRejected` configuration callback in favor of warn-level rejection logging (#647). ### How to test ```sh .github/scripts/validate-release-version Android 4.0.0-alpha.5 platforms/android/gradlew -p platforms/android clean test --console=plain platforms/android/gradlew -p platforms/android :lib:apiCheck protocol/languages/kotlin/gradlew -p protocol/languages/kotlin :embedded-checkout-protocol:apiCheck platforms/android/samples/CheckoutKitAndroidDemo/gradlew -p platforms/android/samples/CheckoutKitAndroidDemo :app:testDebugUnitTest --console=plain ``` --- ### Before you merge - [x] Existing tests cover the release contents - [x] I have read and agree with the [Contribution Guidelines](./CONTRIBUTING.md) - [x] I have read and agree with the [Code of Conduct](./CODE_OF_CONDUCT.md) - [x] I've updated `platforms/android/README.md` - [x] I have bumped `checkoutKitAndroid` in `platforms/android/gradle/libs.versions.toml`
This was referenced Aug 17, 2026
tiagocandido
added a commit
that referenced
this pull request
Aug 17, 2026
### What changes are you making? Expose `allowedMessageOrigins` through the React Native configuration and round-trip it across both native bridges. Rejections are logged as warnings by the native SDKs (#646, #647); there is no JavaScript callback. Bumps the native SDK pins to `4.0.0-alpha.5` — the first release with warn-level rejection logging and without `onMessageRejected` — and regenerates both Podfile.locks against the published pods. Replaces #477. ### How to test From `platforms/react-native`: ```sh pnpm test modules/@shopify/checkout-kit-react-native/tests/index.test.ts --runInBand pnpm module typecheck pnpm module api:dump ```
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What changes are you making?
Same as #646, for Android: remove
Configuration.onMessageRejectedand the publicRejectedMessagetype while they have only shipped in an alpha. Origin-validation rejections are always logged as warnings with the verified origin and reason; the untrusted message body is not logged.How to test
From
platforms/android:./gradlew test ./gradlew :lib:apiCheck