Skip to content

feat: require environmentSubdomain or an explicit useLegacyDomain opt-out - #649

Merged
armando-rodriguez-cko merged 13 commits into
masterfrom
feat/INT-1688-mandatory-subdomain
Aug 31, 2026
Merged

feat: require environmentSubdomain or an explicit useLegacyDomain opt-out#649
armando-rodriguez-cko merged 13 commits into
masterfrom
feat/INT-1688-mandatory-subdomain

Conversation

@armando-rodriguez-cko

@armando-rodriguez-cko armando-rodriguez-cko commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Makes the merchant-specific subdomain (MSSD) mandatory. Callers must now call environmentSubdomain(...), or explicitly opt out with the new, already-@Deprecated useLegacyDomain(). Setting both, or neither, throws CheckoutArgumentException at client construction. MSSD is no longer beta and non-MSSD usage will be deprecated, so the previous silent fallback to api.checkout.com had to go.

Changes

  • AbstractCheckoutSdkBuilder — the subdomain is held as a String and the EnvironmentSubdomain is built when the configuration is assembled, so environmentSubdomain() no longer has to be called after environment(); new useLegacyDomain() marked @Deprecated; new validateEnvironmentSettings(); new requiresEnvironmentSubdomain()
  • EnvironmentSubdomaincreateUrlWithSubdomain throws on an invalid subdomain instead of returning the URL unchanged
  • CheckoutPreviousSdkBuilder — Previous/ABC exempted via requiresEnvironmentSubdomain()
  • CheckoutSdkBuilderTest — covers all four combinations (subdomain only, legacy only, both, neither), an invalid subdomain, and the Previous exemption
  • DefaultCheckoutConfigurationTest — the parameterised bad-subdomain case now asserts the throw instead of the silent fallback
  • TestDomainConfiguration (new) + SandboxTestFixture and seven integration fixtures — every client the suite builds now chooses a domain

Fixed along the way

environmentSubdomain() used to build the URLs from whatever environment was set at call time, so calling it before environment() silently produced the wrong host.

API Reference

Breaking changes

Yes, two. This needs a major release, classified and versioned when the release is cut.

  1. The merchant-specific subdomain is mandatory for the Default and DefaultOAuth platforms. Code that omitted it and relied on the implicit fallback to api.checkout.com / access.checkout.com now fails at client construction. Migration: set the subdomain, or use the legacy-domain opt-out as a temporary measure. The Previous (ABC) platform is unaffected.
  2. An invalid subdomain now fails instead of being silently ignored. Callers passing a malformed value keep working against the shared host today; after this change they fail fast. This one is easy to miss because it is not what the ticket asked for, so it needs its own line in the release notes.

README

Updated in this PR: a "Subdomain value" section above the Default example, the subdomain added to the configuration samples, and a "Legacy domain (emergency use only)" section at the bottom.

Notes

The suite routes every client it builds through a single helper that uses the shared hosts. Applying the merchant-specific subdomain there looked better, since it is the path merchants are being moved to, but the sandbox OAuth clients are not provisioned for it: .NET CI failed 224 integration tests with invalid_client when the token request went to {subdomain}.access.sandbox.checkout.com. Binding those OAuth clients to the subdomain is a platform task and should land before merchants are told the subdomain is mandatory.

Reference implementation: checkout-sdk-net#590. Tracked as INT-1688.

No version bump here: that happens on master when the release is cut, per the release workflow.


Review follow-ups (2026-08-31)

Breaking changes, complete list:

  1. The merchant-specific subdomain is now required; building without it (and without the legacy opt-out) throws.
  2. An invalid subdomain now throws instead of being silently ignored.

Behaviour note: host resolution is now deferred to build time, which also fixes a latent order-dependence bug where setting the subdomain before the environment produced the wrong host.

Deprecation signal: compile-time (@deprecated + Javadoc).

Option A applied (2026-08-31): an explicit OAuth authorization URI and the environment subdomain are now mutually exclusive at build time; the README OAuth example no longer sets an authorization URI, subdomain-only is the documented path.

@agent-wall-e

agent-wall-e Bot commented Aug 10, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 19


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 10, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Aug 10, 2026

Copy link
Copy Markdown

🔵 Advisory review: Sound, but needs your judgement

This PR needs a human approval. The code itself reads as correct; whether it should land depends on context I don't have.

The change correctly enforces that callers supply either environmentSubdomain or useLegacyDomain at build time, with a clean opt-out path and Previous-platform exemption. The logic is sound, but the widespread use of useLegacyDomain() in integration tests—combined with the explicit PR note that sandbox OAuth clients are not yet provisioned for MSSD—means this PR ships a breaking API change before the platform work that would let real callers actually comply with it.

For you to decide

  • AbstractCheckoutSdkBuilder.environmentSubdomain(null) silently stores null and then fails at build time with 'environmentSubdomain is required' rather than the more intuitive 'subdomain must be specified'; this is a deliberate design choice (null == unset) but a reviewer should confirm this is the intended UX.
  • The integration test suite (SandboxTestFixture, OAuthTestIT, AccountsTestIT, BaseIssuingTestIT, AccountsPayoutSchedulesIT, RequestApmPaymentsIT) adds .useLegacyDomain() to every OAuth client because sandbox OAuth clients are not yet provisioned for MSSD; the PR notes this but it means the 'required' enforcement in production code ships before the corresponding platform provisioning, which is a deployment-sequencing risk the reviewer must accept.
  • CheckoutSdkTelemetryIntegrationTest and CardMetadataIT use the hard-coded subdomain '1234doma' and System.getenv('CHECKOUT_MERCHANT_SUBDOMAIN') respectively; if CHECKOUT_MERCHANT_SUBDOMAIN is unset in CI the card-metadata test will throw NullPointerException at build time, not a clear error message.
  • The mutually exclusive authorizationUri + environmentSubdomain check in CheckoutSdkBuilder.getSdkCredentials() is evaluated after the subdomain is retrieved via getEnvironmentSubdomain(), which constructs an EnvironmentSubdomain (and validates the pattern) before the conflict check fires; a reviewer should confirm the desired exception order is 'conflict first' vs 'invalid subdomain first'.
  • SUBDOMAIN_PATTERN (^(?:pl-)?[a-z0-9]+$) has no upper-length bound; a reviewer should confirm whether arbitrarily long subdomains should be accepted or whether an 8-char (or pl- + 8-char) constraint belongs here.
  • The README 'Legacy domain' section says 'Exactly one of environmentSubdomain(...) or useLegacyDomain() must be set'; this is accurate, but the README Default and OAuth examples use the placeholder string 'subdomain' rather than the actual 8-character format described in the new 'Subdomain value' section—minor accuracy concern worth noting.
  • The breaking-change note in the PR is explicit and correctly identifies two distinct breaks; a reviewer must decide whether the release-versioning process (major bump deferred to cut time) is appropriate for their workflow before approving.

⚠️ The diff was too large to read in full, so this review covers only part of the change.


This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02

Comment thread src/test/java/com/checkout/CheckoutSdkBuilderTest.java Dismissed
Comment thread src/test/java/com/checkout/CheckoutSdkBuilderTest.java Fixed
Comment thread src/test/java/com/checkout/OAuthTestIT.java Dismissed
Comment thread src/test/java/com/checkout/TestDomainConfiguration.java Fixed
@agent-wall-e

agent-wall-e Bot commented Aug 10, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 19


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 10, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Aug 11, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 19


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 11, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Aug 11, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:.github/workflows/build-master.yml
  • security_sensitive_path:.github/workflows/build-pull-request.yml
  • security_sensitive_path:.github/workflows/build-release.yml
  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 22


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 11, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path.github/workflows/build-master.yml classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).
security_sensitive_path.github/workflows/build-pull-request.yml classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).
security_sensitive_path.github/workflows/build-release.yml classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Aug 12, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:.github/workflows/build-master.yml
  • security_sensitive_path:.github/workflows/build-pull-request.yml
  • security_sensitive_path:.github/workflows/build-release.yml
  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 21


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 12, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_path.github/workflows/build-master.yml classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).
security_sensitive_path.github/workflows/build-pull-request.yml classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).
security_sensitive_path.github/workflows/build-release.yml classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Aug 12, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 17


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 12, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

Comment thread src/test/java/com/checkout/OAuthTestIT.java Dismissed
Comment thread src/test/java/com/checkout/OAuthTestIT.java Dismissed
Comment thread src/test/java/com/checkout/OAuthTestIT.java Dismissed
Comment thread src/test/java/com/checkout/SandboxTestFixture.java Fixed
Comment thread src/test/java/com/checkout/SandboxTestFixture.java Fixed
Comment thread src/test/java/com/checkout/accounts/AccountsPayoutSchedulesIT.java Dismissed
Comment thread src/test/java/com/checkout/accounts/AccountsTestIT.java Dismissed
Comment thread src/test/java/com/checkout/issuing/BaseIssuingTestIT.java Dismissed
Comment thread src/test/java/com/checkout/metadata/CardMetadataIT.java Fixed
Comment thread src/test/java/com/checkout/payments/RequestApmPaymentsIT.java Dismissed
…-out

The merchant-specific subdomain is how merchants should reach the API, but it
was optional and an unset value silently fell back to api.checkout.com, so a
forgotten subdomain looked exactly like a deliberate opt-out and the SDK could
not warn about either. Callers must now choose: set environmentSubdomain, or
call the already-deprecated useLegacyDomain(). Both, or neither, throws.

An invalid subdomain now throws instead of being quietly ignored, which is a
second breaking change: callers passing a malformed value are currently served
by the shared host and never find out.

environmentSubdomain no longer needs environment() to be set first, since the
EnvironmentSubdomain is now built when the configuration is assembled.

The Previous (ABC) platform predates merchant-specific subdomains and stays
exempt via requiresEnvironmentSubdomain().

Mirrors checkout-sdk-net#590. Refs INT-1688.
…tion

Seven integration fixtures build their own clients outside SandboxTestFixture
(OAuth, Issuing, Accounts, Accounts payout schedules, APM previews, card
metadata), so the mandatory subdomain would have failed them at construction.

They now share TestDomainConfiguration.configureDomain, which uses the shared
hosts. Applying the merchant-specific subdomain instead looked better, since it
is the path merchants are being moved to, but the sandbox OAuth clients are not
provisioned for it: .NET CI failed 224 integration tests with invalid_client
when the token request went to {subdomain}.access.sandbox.checkout.com. The
reason is recorded on the class so nobody repeats the experiment.
…onfiguration

CI runs the full suite, so three OAuthTestIT cases that build their own client
were still failing at construction. Local runs excluded integration tests, which
is why they were missed.
Flagged in review, and fair: a bulk edit added the subdomain to the Previous
(ABC) builder, the one platform that is exempt from needing one. That made the
test misleading and, worse, removed the only coverage of the exemption actually
working. It builds without a subdomain again.
The suite could only run against the shared hosts, so the subdomain path this PR
makes mandatory had no integration coverage. Reviewers flagged that on every SDK,
and it is the right thing to flag.

The domain helper now has two modes. Default is unchanged, the shared hosts,
because the sandbox OAuth clients are not provisioned for the subdomain and the
token request returns invalid_client. Set CHECKOUT_TEST_USE_SUBDOMAIN=true and the
suite runs against CHECKOUT_MERCHANT_SUBDOMAIN instead, so once sandbox is
provisioned like production it is a one-line change in the workflows, already
wired and documented, rather than a rewrite of every fixture.

The switch is deliberately separate from CHECKOUT_MERCHANT_SUBDOMAIN, which CI
already exports: provisioning should drive the behaviour, not the presence of a
secret.
Versions are bumped on master during the release, not in a feature branch, per
the release workflow. This branch should carry only the change itself; the major
bump is classified and applied when the release is cut.
Two problems with the previous approach. It needed a new variable in 21 workflow
files, which is not viable without access to create secrets. And it wrapped the
builder chain in a configureDomain helper that is not part of the public API, so
the tests stopped looking like the code a merchant would actually write.

Every fixture now calls the real opt-out inline, in the chain, with a comment
saying why: the sandbox OAuth clients are not provisioned for the merchant-specific
subdomain, so the token request comes back invalid_client. When sandbox is
provisioned, those calls become the subdomain setter.

The unit tests covering all four combinations are untouched: they already used the
public API directly.
@armando-rodriguez-cko
armando-rodriguez-cko force-pushed the feat/INT-1688-mandatory-subdomain branch from b136f1e to 163db6e Compare August 27, 2026 13:37
@agent-wall-e

agent-wall-e Bot commented Aug 27, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 18


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 27, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

Comment thread gradle.properties Outdated
@agent-wall-e

agent-wall-e Bot commented Aug 28, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 17


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 28, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@armando-rodriguez-cko
armando-rodriguez-cko requested a review from a team August 28, 2026 16:11
…th client

The dedicated sandbox clients are not provisioned for the merchant
subdomain; the default client now carries every scope the suites need.
@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 18


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 17


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

david-ruiz-cko
david-ruiz-cko previously approved these changes Aug 31, 2026
- Sandbox test fixture: static-keys clients now use the subdomain from
  CHECKOUT_MERCHANT_SUBDOMAIN; the legacy-domain opt-out stays only on the
  OAuth client (sandbox OAuth clients lack subdomain provisioning), and the
  Previous platform applies neither since it is exempt
- Hoist the subdomain validation regex to a private static final constant
  (Sonar S4248)
- Reword the subdomain error messages: typically your client ID excluding
  the cli_ prefix
- Treat environmentSubdomain(null) as unset and fail at build time with the
  standard required-subdomain error, matching the other SDKs; test added
- README: note that Private Link merchants use their pl- prefixed subdomain,
  which the SDK also accepts
@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 17


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

Comment thread src/test/java/com/checkout/CheckoutSdkBuilderTest.java Dismissed
@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 18


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

Comment thread src/test/java/com/checkout/CheckoutSdkBuilderTest.java Dismissed
david-ruiz-cko
david-ruiz-cko previously approved these changes Aug 31, 2026
Also fixes a real miss: CardMetadataIT.createStaticKeyApi() used the
legacy opt-out on a static-keys client, which never calls the token
endpoint and so was never blocked by the sandbox OAuth provisioning
gap - it now runs against the real merchant subdomain like the other
static-keys fixtures.

The other six sites are genuine OAuth clients whose sandbox clients
lack subdomain provisioning; @SuppressWarnings("deprecation") marks
that as deliberate instead of leaving 15 code-scanning findings open.
@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown

🔴 Risk Classification: MAJOR

Approval route: AI Review + Human Approval Required
Rollback controls: Change-freeze window + documented rollback plan

Classification reasons

  • security_sensitive_path:src/test/java/com/checkout/OAuthTestIT.java

Operational gates

  • ✅ jira_ticket (INT-1688)
  • ✅ independent_review

Files analysed: 18


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Aug 31, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
security_sensitive_pathsrc/test/java/com/checkout/OAuthTestIT.java classifying §2.1 M4/M5 Path matched a sensitive pattern (auth, secrets, crypto, PCI, migrations, network IaC).

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@sonarqubecloud

Copy link
Copy Markdown

@armando-rodriguez-cko
armando-rodriguez-cko merged commit e4a6770 into master Aug 31, 2026
4 checks passed
@armando-rodriguez-cko
armando-rodriguez-cko deleted the feat/INT-1688-mandatory-subdomain branch August 31, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants