Repository navigation
v0.2.0
Published to npm as customdomain-js@0.2.0 and @customdomain/react@0.2.0, with provenance.
Published from 1055c8f, tag v0.2.0 (the tag was added on 2026-09-26, pointing at the commit
recorded in the npm provenance attestation). This was the first version published to npm, and the
first from this repo; the source changes in it were developed in the monorepo (b3287ef), where
the version bump from 0.1.0 is visible.
Added
customdomain-js: the purchase rail: acustomdomain:purchasewindow event, the
PurchaseInitiatedpayload type (domain,sessionId,clientSecret,url), and the handoff
it represents. The widget cannot mount Stripe.js inside its own iframe, so it creates the
checkout session on the server and hands it to the host, which mounts Embedded Checkout and then
finalizes withPOST /v1/registrar/fulfill.customdomain-js:OpenConfig.endUserRef, the integrator's own identifier for the end user
a connect belongs to, sent to the control plane asend_user_refso the console can show who
connected a domain. Distinct fromuserId, which is only echoed back on step events.customdomain-js:OpenConfig.managed, which opts the Domain Connect flow into the durable
asynchronous rail (ongoing DNS authority) instead of a one-shot connect. The control plane falls
back to the synchronous redirect when the provider or deployment cannot do async, so enabling it
never breaks a connect. Defaults tofalse.customdomain-js:SuccessResult.alreadyConnected(a resume of a live domain rather than a
fresh connect), plusprocessedDomainsandpendingDomainsfor multi-domain flows.- Repository:
.github/workflows/release.yml, which publishes both packages with--provenance.
@customdomain/react'scustomdomain-js: workspace:*dependency is rewritten to the concrete
published version bypnpm publish(plainnpm publishwould not). - Repository:
.github/workflows/ci.yml, a recursive build and typecheck, plus a behavior
gate that drives the real built bundles through headless Chromium (both connect journeys,
locale, white-label theming, multi-domain, resume). - Both packages:
publishConfig: { access: "public", provenance: true }in both manifests, andrepository,
homepageandbugspointing atCUSTOM-DOMAIN-APP/customdomain-sdk.
Changed
customdomain-js:prefilledDomainis forwarded to the widget whole (string or array);
previously only the first entry survived, which silently truncated multi-domain flows.customdomain-js:loadSharedFlow()posts the init payload oncustomdomain:ready, so a
resumed shared flow renders with the tenant's branding.open()andloadSharedFlow()share one
buildInitPayload()so the two entry points cannot drift.
Removed
Breaking for TypeScript consumers who referenced them (both were type level only):
customdomain-js:DNSRecord.fallbackValue.customdomain-js:OpenConfig.applicationUrl.
Full changelog: CHANGELOG.md