Skip to content

fix: sync PaymentMethodsType enum with Flow API spec - #213

Open
armando-rodriguez-cko wants to merge 1 commit into
masterfrom
fix/payment-methods-type-enum-sync
Open

armando-rodriguez-cko wants to merge 1 commit into
masterfrom
fix/payment-methods-type-enum-sync

Conversation

@armando-rodriguez-cko

Copy link
Copy Markdown
Contributor

Summary

  • Adds 26 payment methods that were missing from PaymentMethodsType (alipay_cn, alipay_hk, alma, benefit, bizum, dana, gcash, kakaopay, klarna, mbway, mobilepay, octopus, paynow, plaid, qpay, remember_me, sepa, stcpay, stored_card, tabby, tamara, tng, truemoney, twint, vipps, wechatpay), keeping the enum in sync with the Flow API's enabled_payment_methods / disabled_payment_methods values.
  • Marks giropay and sofort as deprecated since they are no longer part of the specification, without removing them (backward compatibility).

Related to checkout/checkout-sdk-php#338 (same enum drift found on the PHP SDK)

Test plan

  • No existing specs reference PaymentMethodsType, no test changes needed
  • RuboCop pre-commit hook passed clean

@armando-rodriguez-cko
armando-rodriguez-cko requested a review from a team September 29, 2026 09:58
@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/checkout_sdk/payments/sessions/payment_methods_type.rb

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/checkout_sdk/payments/sessions/payment_methods_type.rb classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🔵 Advisory review: Sound, but needs your judgement

This PR needs a human approval. The code itself reads as correct; whether it should land depends on context I don't have.

Adds 26 new payment method constants and deprecates giropay/sofort to sync the enum with the Flow API spec; the change looks mechanically correct but the REMEMBER_ME constant has unusual handling that warrants explicit sign-off.

For you to decide

  • The REMEMBER_ME = 'remember_me' constant is described as 'deliberately unlisted in the public specification' to prevent merchants from disabling it en masse — exposing it in the SDK but not the spec is an intentional policy decision that the reviewer should confirm is sanctioned by the product/API team.
  • The deprecation comments on GIROPAY and SOFORT are purely documentary; there is no runtime warning (e.g. Ruby warn) emitted when they are used, which may be acceptable for a constants-only module but is worth confirming against the project's deprecation policy.
  • No tests reference PaymentMethodsType per the PR description, so there is nothing to verify coverage-wise, but a reviewer should confirm whether adding a simple values-presence test is expected by project convention.
  • The string values (e.g. 'alipay_cn', 'klarna', 'wechatpay') should be verified against the live Flow API spec to ensure no typos were introduced; the diff itself cannot be cross-checked without the spec.

This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02

Adds 26 payment methods missing from the enum (alipay_cn, alipay_hk,
alma, benefit, bizum, dana, gcash, kakaopay, klarna, mbway, mobilepay,
octopus, paynow, plaid, qpay, remember_me, sepa, stcpay, stored_card,
tabby, tamara, tng, truemoney, twint, vipps, wechatpay) and marks
giropay and sofort as deprecated since they are no longer part of the
specification.

Related to checkout/checkout-sdk-php#338

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@armando-rodriguez-cko
armando-rodriguez-cko force-pushed the fix/payment-methods-type-enum-sync branch from e215aa5 to c1ac250 Compare September 30, 2026 08:59
@agent-wall-e

agent-wall-e Bot commented Sep 30, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/checkout_sdk/payments/sessions/payment_methods_type.rb

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Sep 30, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/checkout_sdk/payments/sessions/payment_methods_type.rb classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants