Skip to content

Fill approved Link cards in hosted payment frames - #159

Merged
fmhall merged 3 commits into
mainfrom
mason/fix-link-hosted-fields
Oct 2, 2026
Merged

fmhall merged 3 commits into
mainfrom
mason/fix-link-hosted-fields

Conversation

@fmhall

@fmhall fmhall commented Oct 2, 2026

Copy link
Copy Markdown
Member

OpenInstinct stopped before Link approval when checkout used processor-hosted card fields. fill_from_link now accepts an exact checkout URL and explicit field bindings, resolves unique visible inputs across supported payment frames, and fills the approved one-time card inside application code. This retains the official Eve Link extension's wallet and purchase-approval flow.

The executor discovers out-of-process descendants through CDP parent relationships, pins page and frame URLs including fragments, handles formatted inputs and padded/unpadded expiration-month selects, checks ancestor-frame visibility before discovery and each write, and masks filled controls. Existing same-origin vault protection and legacy native card autofill remain in place. Unknown frame origins, duplicate or ambiguous targets, and uncertain writes stop execution; filling does not submit checkout.

Related to #157.

Validation:

  • pnpm check: all six tasks passed; 803 tests across 90 files.
  • pnpm build and pnpm exec eve build: passed.
  • Real Kernel-browser tests with dummy cards: same-origin inputs, Braintree/Shopify/PayPal/Stripe frame origins, nested frames, fragment URLs, separate expiration selects with padded and unpadded month values, and hidden/hidden-nested duplicate frames. Checked formatting/input handlers, field masking, and no submission.

Browser fixtures use controlled HTML served at the listed origins. Actual processor sandbox checkouts and live purchases have not been tested.

Independent review identified month-option encoding and ancestor-frame visibility gaps. Both were corrected and verified with focused regressions and real-browser fixtures. The final visibility repair has not had another independent review.

@fmhall
fmhall merged commit e545185 into main Oct 2, 2026
2 checks passed

This branch was successfully deployed

1 active deployment
Preview — 1a5ca928 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant