add stripe 3ds support - #1450
pbennett1-godaddy wants to merge 21 commits into
Conversation
🦋 Changeset detectedLatest commit: a89eb45 The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
…-stripe-3ds-support
checkout-api returns a null draftOrder once an order is paid or awaiting offline payment, so the paid-order redirect and lost-response recovery never saw PAID, and a returning shopper with a paid order was sent to returnUrl. Read CheckoutSession.orderStatus through a separate query and redirect to successUrl when payment is PAID or PENDING (not CANCELED). Without orderStatus (older API) the lookup fails quietly and the existing returnUrl fallback applies. The test API mock now nulls draftOrder for non-mutable orders, matching checkout-api, so these paths are exercised as they behave in production. Co-Authored-By: Claude Opus 5.5 <[email protected]>
A blocked express confirmation returned without calling paymentFailed, so the wallet sheet waited for an outcome that never came. It now fails the sheet without tracking a payment error. The order-status lookup ran on every checkout load and window focus. A focus refetch counted as in-flight work and could block an express confirmation started as a wallet popup closed. Fetch it only when the draft order is unavailable (always the case for paid or pending orders), never on focus; confirmation recovery still fills it directly. Co-Authored-By: Claude Opus 5.5 <[email protected]>
wcole1-godaddy
left a comment
There was a problem hiding this comment.
Reviewed together with checkout-api #182, platform-applications-router #64, and applications-post-actions-service #7 as one feature.
Approving. Stripe next actions run only on the complete expected contract, the pending intent is retained across ambiguous failures and remounts, blocked express confirmations now close the wallet sheet (a89eb45), and the order-status lookup is lazy with focus refetch off. Legacy error handling is unchanged for older checkout-api responses. Analytics owners should note the new expressCheckoutCompleted event.
Summary
Adds backward-compatible Stripe 3DS support to the React checkout card flow.
When checkout confirmation returns a valid
PAYMENT_ACTION_REQUIREDGraphQL error from checkout-api, the frontend now:stripe.handleNextActionwith the returned client secret.Stripe next actions are only invoked when the response contains the complete expected contract:
code = PAYMENT_ACTION_REQUIREDpaymentResult.status = ACTION_REQUIREDpaymentResult.provider = STRIPEnextStep.type = SDK_ACTIONnextStep.sdk = STRIPE_JSnextStep.action = HANDLE_NEXT_ACTIONnextStep.clientSecretExisting payment success and error behavior remains unchanged for older checkout-api responses, non-Stripe providers, and malformed action-required responses. Stripe failures and repeated
action-required responses fail safely and unlock checkout without entering a retry loop.
The Stripe card button also uses the local payment-processing state to prevent duplicate submissions during tokenization and 3DS authentication.
Changeset
Added a patch changeset for
@godaddy/react.Test Plan
paymentResult.nextStep, are preserved.stripe.handleNextActionwith the client secretpi_*PaymentIntent IDpnpm --dir packages/react typecheckpnpm --dir packages/react testResult: 58 test files passed, 578 tests passed.
git diff --check