Repository navigation
feat(checkout): enforce embed hosts through frame-ancestors - #14234
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
No issues found across 5 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Requires human review: Enforces checkout embed allowlist via frame-ancestors CSP and X-Frame-Options; author explicitly says to merge later after log checks, and the change may break existing embeds not on the allowlist.
Re-trigger cubic
| const checkout = request.nextUrl.pathname.match(CHECKOUT_CLIENT_SECRET) | ||
| if (checkout) { | ||
| const frameAncestors = isFramed(request) | ||
| ? await getFrameAncestors(request, checkout[1]) |
There was a problem hiding this comment.
Follow-up improvement: I would be okay if we simply add a property embed_policy directly in the CheckoutPublic object. Would avoid an extra request.
There was a problem hiding this comment.
We would avoid 1 extra endpoint, not the extra request, the proxy needs to know the policy before we renders the page.
There was a problem hiding this comment.
I wonder what the impact will be on our TTFB for a checkout in production
There was a problem hiding this comment.
It adds ~20ms server side, but only for framed checkout (~15% of all checkouts since yesterday)
There was a problem hiding this comment.
0 issues found across 3 files (changes from recent commits).
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Requires human review: Enforces checkout embed allowlist via frame-ancestors CSP; feature flag claim not visible in diff, and enforcement may break existing embedders not on the allowlist.
Re-trigger cubic
Summary
Actual enforcement of for ENG-12.
To be merged later when we checked the logs for breaking framed page.Behind a feature flag, safe to merge now #14349
Checklist
uv run task lint && uv run task lint_types)