Skip to content

feat(react-native): incoming message origin validation - #648

Merged
tiagocandido merged 1 commit into
mainfrom
08-14-feat_incoming_message_origin_validation_for_react_native_v2
Aug 17, 2026
Merged

feat(react-native): incoming message origin validation#648
tiagocandido merged 1 commit into
mainfrom
08-14-feat_incoming_message_origin_validation_for_react_native_v2

Conversation

@tiagocandido

@tiagocandido tiagocandido commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

What changes are you making?

Expose allowedMessageOrigins through the React Native configuration and round-trip it across both native bridges. Rejections are logged as warnings by the native SDKs (#646, #647); there is no JavaScript callback.

Bumps the native SDK pins to 4.0.0-alpha.5 — the first release with warn-level rejection logging and without onMessageRejected — and regenerates both Podfile.locks against the published pods.

Replaces #477.

How to test

From platforms/react-native:

pnpm test modules/@shopify/checkout-kit-react-native/tests/index.test.ts --runInBand
pnpm module typecheck
pnpm module api:dump

@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Aug 14, 2026

tiagocandido commented Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

@tiagocandido
tiagocandido marked this pull request as ready for review August 14, 2026 15:05
@tiagocandido
tiagocandido requested a review from a team as a code owner August 14, 2026 15:05
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown

React Native — Coverage Report

Lines Statements Branches Functions
Coverage: 92%
91.64% (307/335) 88.88% (176/198) 100% (81/81)

@github-actions

Copy link
Copy Markdown

Package Size

Platform Artifact Base Head Delta
React Native npm tarball 101.6 KiB 102.0 KiB +487 B
React Native file breakdown
File Base Head Delta
node_modules/@shopify/checkout-kit-protocol/src/generated/Models.ts 85.4 KiB 85.4 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/Models.d.ts 53.0 KiB 53.0 KiB 0 B
ios/AcceleratedCheckoutButtons.swift 14.1 KiB 14.1 KiB 0 B
ios/ShopifyCheckoutKit.swift 13.5 KiB 13.8 KiB +288 B
android/src/main/java/com/shopify/reactnative/checkoutkit/ShopifyCheckoutKitModule.java 12.8 KiB 13.5 KiB +688 B
src/components/AcceleratedCheckoutButtons.tsx 13.0 KiB 13.0 KiB 0 B
lib/commonjs/index.js 12.3 KiB 12.3 KiB 0 B
src/index.ts 12.2 KiB 12.2 KiB 0 B
lib/commonjs/components/AcceleratedCheckoutButtons.js 11.4 KiB 11.4 KiB 0 B
lib/commonjs/components/AcceleratedCheckoutButtons.js.map 10.4 KiB 10.4 KiB 0 B
lib/module/components/AcceleratedCheckoutButtons.js 10.2 KiB 10.2 KiB 0 B
lib/module/index.js 10.2 KiB 10.2 KiB 0 B
src/index.d.ts 9.1 KiB 9.9 KiB +744 B
node_modules/@shopify/checkout-kit-protocol/src/generated/ProtocolNotifications.ts 9.5 KiB 9.5 KiB 0 B
lib/module/components/AcceleratedCheckoutButtons.js.map 9.1 KiB 9.1 KiB 0 B
src/present-dispatcher.ts 8.0 KiB 8.0 KiB 0 B
lib/module/index.js.map 7.9 KiB 7.9 KiB 0 B
lib/commonjs/index.js.map 7.7 KiB 7.7 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/ProtocolNotifications.d.ts 7.6 KiB 7.6 KiB 0 B
node_modules/@shopify/checkout-kit-protocol/src/generated/ProtocolRenameMap.ts 7.2 KiB 7.2 KiB 0 B
…and 110 smaller files

Measured from the PR base SHA and PR head SHA. The file breakdown shows uncompressed sizes within each package artifact, so individual files do not sum to the compressed artifact total. This comment reports package artifact sizes only; it is not a final app binary-size report.

@bitrise

bitrise Bot commented Aug 14, 2026

Copy link
Copy Markdown

Install this build

Open Tophat, select your target device, then click Install. Links open on the Mac running Tophat.

SDK Install
React Native Install with Tophat

Checkout Kit E2E results

Status Suite Target Platform OS version tag Device
react-native-ios react-native ios latest iPhone 15
iOS 27 Beta
react-native-android react-native android latest Google Pixel 9
Android 17.0

@tiagocandido
tiagocandido changed the base branch from 08-14-refactor_android_message_rejection_warn_logging to graphite-base/648 August 17, 2026 08:15
@tiagocandido
tiagocandido force-pushed the 08-14-feat_incoming_message_origin_validation_for_react_native_v2 branch from ed44e45 to 92fd0f2 Compare August 17, 2026 08:21
@graphite-app
graphite-app Bot changed the base branch from graphite-base/648 to main August 17, 2026 08:22
@tiagocandido
tiagocandido force-pushed the 08-14-feat_incoming_message_origin_validation_for_react_native_v2 branch 2 times, most recently from 7ea6852 to de2c1ef Compare August 17, 2026 12:33
Expose allowedMessageOrigins through the React Native configuration and
round-trip it across both native bridges. Rejections are logged as
warnings by the native SDKs; no JavaScript callback is involved.
@tiagocandido
tiagocandido force-pushed the 08-14-feat_incoming_message_origin_validation_for_react_native_v2 branch from de2c1ef to ceb7fb9 Compare August 17, 2026 12:46
@tiagocandido
tiagocandido merged commit d58170a into main Aug 17, 2026
33 checks passed
@tiagocandido
tiagocandido deleted the 08-14-feat_incoming_message_origin_validation_for_react_native_v2 branch August 17, 2026 13:12
kieran-osgood-shopify added a commit that referenced this pull request Aug 18, 2026
…ureReason.WebContentProcessTerminated` (#669)

### What changes are you making?

`main` `ci.yml` started failing: https://github.com/Shopify/checkout-kit/actions/runs/32117716909 

A compilation error was introduced in this PR: https://github.com/Shopify/checkout-kit/pull/654/changes#diff-d07025bb8c20a702c435f86f64c6c5f6ef2e38bfc536c50734b369be0f3da8cb

## Why

This was a merge timing issue between it merging and #648 merging 

Each passed CI independently, but fail together

We don't force rebasing main before submission, which would have caught this issue, but it's a rare occurrence and would have more negative impact that positive


<img width="2294" height="397" alt="image" src="https://github.com/user-attachments/assets/43ea6c89-3b5b-4c63-a5bb-7297c6e3595f" />


---

### Before you merge

> [!IMPORTANT]
>
> - [ ] I've added tests to support my implementation
> - [ ] I have read and agree with the [Contribution Guidelines](./CONTRIBUTING.md)
> - [ ] I have read and agree with the [Code of Conduct](./CODE_OF_CONDUCT.md)
> - [ ] I've updated the relevant platform README (`platforms/swift/README.md` and/or `platforms/android/README.md`)

---

<details>
<summary>Releasing a new Swift version?</summary>

- [ ] I have bumped the version in `ShopifyCheckoutKit.podspec`
- [ ] I have bumped the version in `platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift`
- [ ] I have updated the SwiftPM/CocoaPods version snippets in `platforms/swift/README.md` (major version only)

</details>

<details>
<summary>Releasing a new Embedded Checkout Protocol version?</summary>

- [ ] I have bumped `embeddedCheckoutProtocolAndroid` in `platforms/android/gradle/libs.versions.toml`
- [ ] I have updated `protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api` if the public API changed

</details>

<details>
<summary>Releasing a new Android version?</summary>

- [ ] I have bumped `checkoutKitAndroid` in `platforms/android/gradle/libs.versions.toml`
- [ ] I have updated the Gradle/Maven version snippets in `platforms/android/README.md`

</details>

> [!TIP]
> See the [Contributing documentation](./CONTRIBUTING.md) for the full release process per platform.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants