Skip to content

fix: sync PaymentMethodsType enum with Flow API spec - #213

Merged
armando-rodriguez-cko merged 1 commit into
masterfrom
fix/payment-methods-type-enum-sync
Oct 7, 2026
Merged

armando-rodriguez-cko merged 1 commit into
masterfrom
fix/payment-methods-type-enum-sync

Conversation

@armando-rodriguez-cko

Copy link
Copy Markdown
Contributor

Summary

  • Adds 26 payment methods that were missing from PaymentMethodsType (alipay_cn, alipay_hk, alma, benefit, bizum, dana, gcash, kakaopay, klarna, mbway, mobilepay, octopus, paynow, plaid, qpay, remember_me, sepa, stcpay, stored_card, tabby, tamara, tng, truemoney, twint, vipps, wechatpay), keeping the enum in sync with the Flow API's enabled_payment_methods / disabled_payment_methods values.
  • Marks giropay and sofort as deprecated since they are no longer part of the specification, without removing them (backward compatibility).

Related to checkout/checkout-sdk-php#338 (same enum drift found on the PHP SDK)

Test plan

  • No existing specs reference PaymentMethodsType, no test changes needed
  • RuboCop pre-commit hook passed clean

@armando-rodriguez-cko
armando-rodriguez-cko requested a review from a team September 29, 2026 09:58
@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/checkout_sdk/payments/sessions/payment_methods_type.rb

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/checkout_sdk/payments/sessions/payment_methods_type.rb classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🔵 Advisory review: Sound, but needs your judgement

This PR needs a human approval. The code itself reads as correct; whether it should land depends on context I don't have.

Adds 26 new payment method constants and deprecates giropay/sofort to sync the enum with the Flow API spec; the diff is mechanically correct but the REMEMBER_ME constant has an unusual inline comment explaining it is intentionally undocumented, which a human should validate against internal policy.

For you to decide

  • The REMEMBER_ME = 'remember_me' constant includes an in-code comment stating it is 'deliberately unlisted in the public specification so that merchants do not disable Remember Me en masse' — a reviewer with product/API knowledge should confirm this is the right place to document that intent and that shipping it in a public SDK is consistent with that goal.
  • All 26 string values (e.g. 'alipay_cn', 'alipay_hk', 'alma', etc.) should be verified against the actual Flow API spec or an authoritative source; the diff itself provides no cross-reference, and the PR description cites only a PHP SDK issue rather than a spec document.
  • PRZELEWY24 maps to 'p24' (not 'przelewy24'), which is pre-existing and consistent, but a reviewer should confirm the new constants follow the same mapping convention — all new ones appear to map name to identical string value, which looks correct.
  • No tests exist or are added for this module (acknowledged in the PR), so there is no automated protection against future string-value typos in the new constants.
  • The deprecation of GIROPAY and SOFORT is handled only via a @deprecated YARD comment with no runtime warning; this is a reasonable approach for a constants module, but the reviewer should decide if that level of signal is sufficient for SDK consumers.

This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02

@armando-rodriguez-cko
armando-rodriguez-cko force-pushed the fix/payment-methods-type-enum-sync branch from e215aa5 to c1ac250 Compare September 30, 2026 08:59
@agent-wall-e

agent-wall-e Bot commented Sep 30, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/checkout_sdk/payments/sessions/payment_methods_type.rb

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Sep 30, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/checkout_sdk/payments/sessions/payment_methods_type.rb classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

Adds 26 payment methods missing from the enum (alipay_cn, alipay_hk,
alma, benefit, bizum, dana, gcash, kakaopay, klarna, mbway, mobilepay,
octopus, paynow, plaid, qpay, remember_me, sepa, stcpay, stored_card,
tabby, tamara, tng, truemoney, twint, vipps, wechatpay) and marks
giropay and sofort as deprecated since they are no longer part of the
specification.

Related to checkout/checkout-sdk-php#338

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@armando-rodriguez-cko
armando-rodriguez-cko force-pushed the fix/payment-methods-type-enum-sync branch from c1ac250 to 95849be Compare October 7, 2026 12:36
@agent-wall-e

agent-wall-e Bot commented Oct 7, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:lib/checkout_sdk/payments/sessions/payment_methods_type.rb

Operational gates

  • ✅ jira_ticket
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Oct 7, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path — lib/checkout_sdk/payments/sessions/payment_methods_type.rb classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@armando-rodriguez-cko
armando-rodriguez-cko merged commit b15585d into master Oct 7, 2026
5 checks passed
@armando-rodriguez-cko
armando-rodriguez-cko deleted the fix/payment-methods-type-enum-sync branch October 7, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants