feat(react-native): incoming message origin validation - #648
Merged
tiagocandido merged 1 commit intoAug 17, 2026
Merged
Conversation
Contributor
Author
This stack of pull requests is managed by Graphite. Learn more about stacking. |
Package Size
React Native file breakdown
Measured from the PR base SHA and PR head SHA. The file breakdown shows uncompressed sizes within each package artifact, so individual files do not sum to the compressed artifact total. This comment reports package artifact sizes only; it is not a final app binary-size report. |
Install this buildOpen Tophat, select your target device, then click Install. Links open on the Mac running Tophat.
Checkout Kit E2E results
|
markmur
approved these changes
Aug 14, 2026
tiagocandido
changed the base branch from
08-14-refactor_android_message_rejection_warn_logging
to
graphite-base/648
August 17, 2026 08:15
tiagocandido
force-pushed
the
graphite-base/648
branch
from
August 17, 2026 08:21
3f2c7cc to
56f482a
Compare
tiagocandido
force-pushed
the
08-14-feat_incoming_message_origin_validation_for_react_native_v2
branch
from
August 17, 2026 08:21
ed44e45 to
92fd0f2
Compare
tiagocandido
force-pushed
the
08-14-feat_incoming_message_origin_validation_for_react_native_v2
branch
2 times, most recently
from
August 17, 2026 12:33
7ea6852 to
de2c1ef
Compare
Expose allowedMessageOrigins through the React Native configuration and round-trip it across both native bridges. Rejections are logged as warnings by the native SDKs; no JavaScript callback is involved.
tiagocandido
force-pushed
the
08-14-feat_incoming_message_origin_validation_for_react_native_v2
branch
from
August 17, 2026 12:46
de2c1ef to
ceb7fb9
Compare
This was referenced Aug 17, 2026
tiagocandido
deleted the
08-14-feat_incoming_message_origin_validation_for_react_native_v2
branch
August 17, 2026 13:12
11 tasks
11 tasks
kieran-osgood-shopify
added a commit
that referenced
this pull request
Aug 18, 2026
…ureReason.WebContentProcessTerminated` (#669) ### What changes are you making? `main` `ci.yml` started failing: https://github.com/Shopify/checkout-kit/actions/runs/32117716909 A compilation error was introduced in this PR: https://github.com/Shopify/checkout-kit/pull/654/changes#diff-d07025bb8c20a702c435f86f64c6c5f6ef2e38bfc536c50734b369be0f3da8cb ## Why This was a merge timing issue between it merging and #648 merging Each passed CI independently, but fail together We don't force rebasing main before submission, which would have caught this issue, but it's a rare occurrence and would have more negative impact that positive <img width="2294" height="397" alt="image" src="https://github.com/user-attachments/assets/43ea6c89-3b5b-4c63-a5bb-7297c6e3595f" /> --- ### Before you merge > [!IMPORTANT] > > - [ ] I've added tests to support my implementation > - [ ] I have read and agree with the [Contribution Guidelines](./CONTRIBUTING.md) > - [ ] I have read and agree with the [Code of Conduct](./CODE_OF_CONDUCT.md) > - [ ] I've updated the relevant platform README (`platforms/swift/README.md` and/or `platforms/android/README.md`) --- <details> <summary>Releasing a new Swift version?</summary> - [ ] I have bumped the version in `ShopifyCheckoutKit.podspec` - [ ] I have bumped the version in `platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift` - [ ] I have updated the SwiftPM/CocoaPods version snippets in `platforms/swift/README.md` (major version only) </details> <details> <summary>Releasing a new Embedded Checkout Protocol version?</summary> - [ ] I have bumped `embeddedCheckoutProtocolAndroid` in `platforms/android/gradle/libs.versions.toml` - [ ] I have updated `protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api` if the public API changed </details> <details> <summary>Releasing a new Android version?</summary> - [ ] I have bumped `checkoutKitAndroid` in `platforms/android/gradle/libs.versions.toml` - [ ] I have updated the Gradle/Maven version snippets in `platforms/android/README.md` </details> > [!TIP] > See the [Contributing documentation](./CONTRIBUTING.md) for the full release process per platform.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What changes are you making?
Expose
allowedMessageOriginsthrough the React Native configuration and round-trip it across both native bridges. Rejections are logged as warnings by the native SDKs (#646, #647); there is no JavaScript callback.Bumps the native SDK pins to
4.0.0-alpha.5— the first release with warn-level rejection logging and withoutonMessageRejected— and regenerates both Podfile.locks against the published pods.Replaces #477.
How to test
From
platforms/react-native:pnpm test modules/@shopify/checkout-kit-react-native/tests/index.test.ts --runInBand pnpm module typecheck pnpm module api:dump