Skip to content

feat: incoming mesage origin validation for web#474

Draft
michaeljsXu wants to merge 1 commit into
mainfrom
07-15-feat_incoming_mesage_origin_validation_for_web
Draft

feat: incoming mesage origin validation for web#474
michaeljsXu wants to merge 1 commit into
mainfrom
07-15-feat_incoming_mesage_origin_validation_for_web

Conversation

@michaeljsXu

@michaeljsXu michaeljsXu commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Jul 15, 2026
function isValidOriginPattern(pattern: string): boolean {
if (pattern === "*") return true;
if (pattern.includes("*")) return WILDCARD_ORIGIN_PATTERN.test(pattern);
return URL.canParse(pattern);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this could break exact allowlist entries on Safari 16.4–16.6. URL.canParse starts in Safari 17, while this package supports Safari 16.4+. Could we validate with new URL(...) in a try/catch and add a test with URL.canParse unavailable?

if (scheme === undefined || suffix === undefined) return false;

if (`${scheme.toLowerCase()}:` !== origin.protocol) return false;
if ((port ?? "") !== origin.port) return false;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we normalize the configured wildcard port before comparing it? Browsers remove the default :443, so https://*.example.com:443 can reject a valid message from that origin. A regression test for explicit default ports would be helpful too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants