Skip to content

fix: sync PaymentMethodsType enum with Flow API spec - #385

Open
armando-rodriguez-cko wants to merge 1 commit into
masterfrom
fix/payment-methods-type-enum-sync
Open

armando-rodriguez-cko wants to merge 1 commit into
masterfrom
fix/payment-methods-type-enum-sync

Conversation

@armando-rodriguez-cko

Copy link
Copy Markdown
Contributor

Summary

  • Adds 26 payment methods that were missing from PaymentMethodsType (alipay_cn, alipay_hk, alma, benefit, bizum, dana, gcash, kakaopay, klarna, mbway, mobilepay, octopus, paynow, plaid, qpay, remember_me, sepa, stcpay, stored_card, tabby, tamara, tng, truemoney, twint, vipps, wechatpay), keeping the enum in sync with the Flow API's enabled_payment_methods / disabled_payment_methods values.
  • Marks giropay and sofort as @deprecated since they are no longer part of the specification, without removing them (backward compatibility).

Fixes #338

Test plan

  • No existing tests reference PaymentMethodsType, no test changes needed
  • composer lint / code sniffer already run clean on commit

@armando-rodriguez-cko
armando-rodriguez-cko requested a review from a team September 29, 2026 09:48
@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/Checkout/Payments/Sessions/PaymentMethodsType.php

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/Checkout/Payments/Sessions/PaymentMethodsType.php classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🟠 Advisory review: Concerns worth a look

This PR needs a human approval. Before you give it, these are the things I'd want resolved.

Adds 26 new payment method constants and deprecates two existing ones in a string-enum class, matching the stated intent, but the properties are declared as instance variables (public $X) rather than class constants (const X), meaning every caller must instantiate the class to use them — this is inconsistent with how string-enum classes are normally used in PHP and is a potential footgun.

Concerns

  • All properties are declared as public $X = "value" (instance properties) rather than const X = "value" (class constants), so callers cannot do PaymentMethodsType::KLARNA without an instance; this is likely a pre-existing pattern but adding 26 more of these properties amplifies the problem if any new caller expects the constant syntax.
  • The REMEMBER_ME comment says the value is 'deliberately unlisted in the public specification so that merchants do not disable Remember Me en masse' — shipping this in a public SDK enum is self-defeating if the goal is to keep it hidden from merchants; a human should decide whether it belongs here.
  • GCASH appears after GIROPAY in the diff, breaking what was otherwise alphabetical ordering — minor but worth verifying the string value is also correct (it is "gcash", which looks fine).

This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02

Adds 26 payment methods missing from the enum (alipay_cn, alipay_hk,
alma, benefit, bizum, dana, gcash, kakaopay, klarna, mbway, mobilepay,
octopus, paynow, plaid, qpay, remember_me, sepa, stcpay, stored_card,
tabby, tamara, tng, truemoney, twint, vipps, wechatpay) and marks
giropay and sofort as deprecated since they are no longer part of the
specification.

Fixes #338

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@armando-rodriguez-cko
armando-rodriguez-cko force-pushed the fix/payment-methods-type-enum-sync branch from 9b5c7a0 to a21217d Compare September 30, 2026 08:58
@agent-wall-e

agent-wall-e Bot commented Sep 30, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/Checkout/Payments/Sessions/PaymentMethodsType.php

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Sep 30, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/Checkout/Payments/Sessions/PaymentMethodsType.php classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
B Maintainability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Flow API enabled_payment_methods enum values are out of sync with PHP SDK PaymentMethodsType

2 participants