Skip to content

Commit

Permalink
Merge pull request #2397 from SwedbankPay/feature/devp-503_fix_csp_ad…
Browse files Browse the repository at this point in the history
…dress

DEVP-503: Updated CSP address
  • Loading branch information
arebra authored Dec 4, 2024
2 parents c03c88b + e505509 commit e4dcb39
Show file tree
Hide file tree
Showing 9 changed files with 18 additions and 19 deletions.
5 changes: 2 additions & 3 deletions checkout-v3/get-started/display-payment-ui/seamless-view.md
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 119 in checkout-v3/get-started/display-payment-ui/seamless-view.md

View workflow job for this annotation

GitHub Actions / alex

[alex] checkout-v3/get-started/display-payment-ui/seamless-view.md#L119

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  119:16-119:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -140,10 +140,9 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |


### Events

When integrating Seamless View we strongly recommend that you implement the
Expand Down
4 changes: 2 additions & 2 deletions checkout-v3/get-started/display-payment-ui/ui-migration.md
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 123 in checkout-v3/get-started/display-payment-ui/ui-migration.md

View workflow job for this annotation

GitHub Actions / alex

[alex] checkout-v3/get-started/display-payment-ui/ui-migration.md#L123

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  123:16-123:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -144,7 +144,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

[custom-logo]: /checkout-v3/features/customize-ui/custom-logo/
Expand Down
4 changes: 2 additions & 2 deletions old-implementations/checkout-v2/checkin.md
Original file line number Diff line number Diff line change
Expand Up @@ -209,7 +209,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 210 in old-implementations/checkout-v2/checkin.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/checkout-v2/checkin.md#L210

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  210:16-210:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -231,7 +231,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

## How It Looks
Expand Down
4 changes: 2 additions & 2 deletions old-implementations/checkout-v2/payment-menu.md
Original file line number Diff line number Diff line change
Expand Up @@ -189,7 +189,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 190 in old-implementations/checkout-v2/payment-menu.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/checkout-v2/payment-menu.md#L190

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  190:16-190:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. Merchants are responsible for whitelisting these domains and keeping

Check warning on line 195 in old-implementations/checkout-v2/payment-menu.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/checkout-v2/payment-menu.md#L195

`whitelisting` may be insensitive, use `passlisting`, `alrightlisting`, `safelisting`, `allow-listing` instead whitelisting retext-equality
Raw output
  195:41-195:53  warning  `whitelisting` may be insensitive, use `passlisting`, `alrightlisting`, `safelisting`, `allow-listing` instead  whitelisting  retext-equality
Expand All @@ -203,7 +203,7 @@ redirect, which will repeal the merchant's CSP.
| URL | Description |
| :------ | :--------------- |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |

This should bring up the Payment Menu in a Seamless View looking like
Expand Down
4 changes: 2 additions & 2 deletions old-implementations/checkout-v2/ui-migration.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 52 in old-implementations/checkout-v2/ui-migration.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/checkout-v2/ui-migration.md#L52

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
    52:16-52:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -73,7 +73,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

[dp]: /checkout-v3/
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 125 in old-implementations/payment-instruments-v1/card/seamless-view.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/payment-instruments-v1/card/seamless-view.md#L125

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  125:16-125:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -146,7 +146,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

## Events
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 123 in old-implementations/payment-instruments-v1/card/ui-migration.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/payment-instruments-v1/card/ui-migration.md#L123

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  123:16-123:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -144,7 +144,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

[dp]: /checkout-v3/
Expand Down
4 changes: 2 additions & 2 deletions old-implementations/payment-menu-v2/payment-order.md
Original file line number Diff line number Diff line change
Expand Up @@ -163,7 +163,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 164 in old-implementations/payment-menu-v2/payment-order.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/payment-menu-v2/payment-order.md#L164

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  164:16-164:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -185,7 +185,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

This should bring up the Payment Menu in a Seamless View. It should look like
Expand Down
4 changes: 2 additions & 2 deletions old-implementations/payment-menu-v2/ui-migration.md
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,7 @@ rules to monitor and authorize scripts.

Merchants must whitelist the following domains to restrict browser content

Check warning on line 128 in old-implementations/payment-menu-v2/ui-migration.md

View workflow job for this annotation

GitHub Actions / alex

[alex] old-implementations/payment-menu-v2/ui-migration.md#L128

`whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead whitelist retext-equality
Raw output
  128:16-128:25  warning  `whitelist` may be insensitive, use `passlist`, `alrightlist`, `safelist`, `allow list` instead                 whitelist     retext-equality
retrieval to approved sources. While `https://*.payex.com` and
`https://*.swedbank.com` cover most payment methods, digital wallets such as
`https://*.swedbankpay.com` cover most payment methods, digital wallets such as
Apple Pay, Click to Pay, and Google Pay are delivered via Payair. Alongside the
Payair URL, these wallets may also generate URLs from Apple, Google, MasterCard,
and Visa. See the table below for more information.
Expand All @@ -149,7 +149,7 @@ case of URL changes, or if you need to whitelist URLs not listed here." %}
| https://*.mastercard.com | URL needed for Click to Pay. |
| https://*.payair.com | URL for the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.payex.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbank.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.swedbankpay.com | Universal URL for all payment methods except the digital wallets Apple Pay, Click to Pay and Google Pay. |
| https://*.visa.com | URL needed for Click to Pay. |

[custom-logo]: /old-implementations/payment-menu-v2/features/optional/custom-logo
Expand Down

0 comments on commit e4dcb39

Please sign in to comment.