Skip to content

feat: incoming message origin validation for ios#476

Draft
michaeljsXu wants to merge 1 commit into
07-15-feat_incoming_message_origin_validation_for_androidfrom
07-15-feat_incoming_message_origin_validation_for_ios
Draft

feat: incoming message origin validation for ios#476
michaeljsXu wants to merge 1 commit into
07-15-feat_incoming_message_origin_validation_for_androidfrom
07-15-feat_incoming_message_origin_validation_for_ios

Conversation

@michaeljsXu

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more

This stack of pull requests is managed by Graphite. Learn more about stacking.

///
/// Entries are origin patterns:
/// - `"https://example.com"` — an exact origin.
/// - `"https://*.example.com"` — any subdomain of `example.com`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These are public Swift API additions, but I could not find the matching API baseline update. Could we refresh platforms/swift/api/ShopifyCheckoutKit.json so the API check stays green?


var host = authority
var port: Int?
if let colon = authority.lastIndex(of: ":") {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think IPv6 origins can fail here: this parser keeps the brackets, while URL.host and WKSecurityOrigin.host remove them. Could we make the parsing and serialization bracket-aware and add default- and explicit-port IPv6 tests?

@@ -465,6 +476,15 @@ extension CheckoutWebView: WKScriptMessageHandler {
return

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we also check message.frameInfo.isMainFrame here? Swift currently accepts child-frame messages, while Web and Android require the main checkout frame. A regression test would help keep the platforms aligned.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants