Skip to content

Allow payment requests inside the hosted cart iframe - #852

Merged
acasazza merged 2 commits into
mainfrom
fix/hosted-cart-allow-payment
Oct 1, 2026
Merged

acasazza merged 2 commits into
mainfrom
fix/hosted-cart-allow-payment

Conversation

@acasazza

Copy link
Copy Markdown
Member

Problem

The hosted cart <iframe> did not declare a Permissions Policy. Without one, the browser blocks the Payment Request API inside the frame, so payment flows that rely on it cannot start from the embedded cart.

Change

Add allow="payment" to both iframes rendered by HostedCart:

  • the mini cart panel (the slide-in variant)
  • the inline cart

Two lines, no behaviour change beyond lifting the policy restriction.

Notes for the reviewer

  • This branch also carries the v5.0.6-beta.0 version bump commit, already tagged and published to the next dist-tag.
  • The same change has been backported to the v4 line and released as v4.29.8-beta.1. The diff there is byte-identical.

Verification

allow is a valid property of IframeHTMLAttributes in the installed React types. Worth flagging honestly: the local install has React 19 types while the v4 backport declares @types/react ^18.3.1, so the backport was checked against the v5 types rather than its own. In the worst case that would surface as a type error, never at runtime.

🤖 Generated with Claude Code

Alessandro Casazza and others added 2 commits September 30, 2026 17:59
The hosted cart iframe did not declare a Permissions Policy, so the
Payment Request API was blocked inside it. Add `allow="payment"` to
both the mini cart iframe and the inline one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@acasazza acasazza added bug Something isn't working components Components package labels Sep 30, 2026
@acasazza acasazza self-assigned this Sep 30, 2026
@netlify

netlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for commercelayer-react-components ready!

Name Link
🔨 Latest commit 4f98d7e
🔍 Latest deploy log https://app.netlify.com/projects/commercelayer-react-components/deploys/6abd4769e0910300090e7b72
😎 Deploy Preview https://deploy-preview-852--commercelayer-react-components.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@acasazza
acasazza merged commit 88910e7 into main Oct 1, 2026
10 checks passed
@acasazza
acasazza deleted the fix/hosted-cart-allow-payment branch October 1, 2026 08:48
@acasazza acasazza mentioned this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working components Components package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants