Skip to content

widen possible shop domains - #604

Open
kiftio wants to merge 1 commit into
mainfrom
08-07-widen_possible_shop_domains
Open

widen possible shop domains#604
kiftio wants to merge 1 commit into
mainfrom
08-07-widen_possible_shop_domains

Conversation

@kiftio

@kiftio kiftio commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

What changes are you making?

Widen accepted domains to includeshop.comas a potential future trusted origin

How to test

  1. Configure an explicit allowedMessageOrigins / allowedOrigins allowlist (e.g. ["https://trusted.example.com"]) on any of the three platforms.
  2. Simulate or send a checkout-protocol message from https://shop.com and from a subdomain such as https://checkout.shop.com.
  3. Verify the messages are accepted without adding shop.com to the merchant-configured allowlist.
  4. Verify that origins outside the allowlist (and not shop.app/shop.com) are still rejected.
  5. Run the existing unit tests — OriginAllowlistTest, MessageOriginValidatorTests, CheckoutWebViewTest/CheckoutWebViewTests, and the web checkout-protocol tests — and confirm they all pass.

Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Aug 7, 2026

kiftio commented Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@kiftio
kiftio marked this pull request as ready for review August 7, 2026 08:15
@kiftio
kiftio requested a review from a team as a code owner August 7, 2026 08:15
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Web — Coverage Report

Lines Statements Branches Functions
Coverage: 96%
94.63% (300/317) 81.72% (152/186) 98.71% (77/78)

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Package Size

Platform Artifact Base Head Delta
Web npm tarball 70.1 KiB 70.2 KiB +132 B
Android release AAR 273.6 KiB 273.7 KiB +81 B
Web file breakdown
File Base Head Delta
dist/index.js.map 192.0 KiB 192.2 KiB +225 B
dist/index.d.ts 44.7 KiB 44.9 KiB +184 B
dist/custom-elements.json 43.7 KiB 43.8 KiB +116 B
dist/index.js 31.5 KiB 31.5 KiB +48 B
README.md 18.1 KiB 18.1 KiB 0 B
package.json 2.8 KiB 2.8 KiB 0 B
LICENSE 1.1 KiB 1.1 KiB 0 B
Android file breakdown
File Base Head Delta
classes.jar 289.5 KiB 289.6 KiB +82 B
res/layout/checkout_view_content.xml 2.3 KiB 2.3 KiB 0 B
res/layout/checkout_sheet_content.xml 2.0 KiB 2.0 KiB 0 B
res/values/values.xml 1.2 KiB 1.2 KiB 0 B
R.txt 1.1 KiB 1.1 KiB 0 B
proguard.txt 798 B 798 B 0 B
AndroidManifest.xml 578 B 578 B 0 B
res/drawable/close.xml 431 B 431 B 0 B
res/menu/checkout_menu.xml 354 B 354 B 0 B
META-INF/com/android/build/gradle/aar-metadata.properties 157 B 157 B 0 B

Measured from the PR base SHA and PR head SHA. The file breakdown shows uncompressed sizes within each package artifact, so individual files do not sum to the compressed artifact total. This comment reports package artifact sizes only; it is not a final app binary-size report.

@bitrise

bitrise Bot commented Aug 7, 2026

Copy link
Copy Markdown

Install this build

Open Tophat, select your target device, then click Install. Links open on the Mac running Tophat.

SDK Install
Swift Install with Tophat
Kotlin Install with Tophat

Checkout Kit E2E results

Status Suite Target Platform OS version tag Device
tests/shared/launch-smoke.yaml kotlin android latest Google Pixel 9
Android 17.0
tests/shared/launch-smoke.yaml swift ios latest iPhone 15
iOS 27 Beta

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant