Skip to content

feat(protected-inputs): per-field collection SDK (cumulative) - #2128

Merged
mPaella merged 5 commits into
mainfrom
codex/protected-input-transport
Oct 1, 2026
Merged

mPaella merged 5 commits into
mainfrom
codex/protected-input-transport

Conversation

@mPaella

@mPaella mPaella commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Cumulative SDK implementation: #2129 was squash-merged into this PR. Replaces the password-only protected-input interface with individually rendered buyer fields and per-field collection refs.

  • Public typed field descriptors support protected single-line text, number and integer.
  • CrossmintProtectedInput exposes ref.collect(), returning collected, invalid, unavailable or superseded. The application owns ordinary answers, labels, error messages and submission.
  • Existing CrossmintProvider supplies the client API key; the application supplies its external-auth buyer JWT. Authentication crosses the verified window channel rather than the iframe URL.
  • Concurrent collections share work; auth/descriptor changes, iframe reload and unmount supersede pending results. Window actions accept AbortSignal cancellation.
  • disabled and invalid update through the iframe state channel. Hosted height and paint gutters keep the field aligned with native inputs.
  • Remove the old password iframe component; migrate the demo and document the replacement interface.

Release changeset

Minor bumps, per owner decision:

  • @crossmint/client-sdk-base: 4.1.0 → 4.2.0
  • @crossmint/client-sdk-react-ui: 4.8.0 → 4.9.0
  • @crossmint/client-sdk-window: 1.1.1 → 1.2.0

Changesets also plans a dependent patch for @crossmint/client-sdk-rn-window (0.3.18 → 0.3.19). The release plan contains no major bumps. This PR adds the changeset; package versioning/publication follows the repository's release PR workflow.

The old merchantUrl/onCreated interface is intentionally replaced; consumers need to adopt field, jwt and ref.collect().

Validation

  • feat(protected-inputs): expose individual React collection refs #2129's reviewed tip passed build/test, lint and smoke-test CI.
  • After squash consolidation, the base branch's Git tree exactly matched that reviewed tip (before adding the changeset).
  • Changeset status validates the minor/dependent-patch release plan; SDK lint exits successfully.
  • The actual React SDK was exercised across origins with real Basis Theory controls and simulated Crossmint registration.
  • Review regressions reproduce and fix collection replacement before passive effects and identity changes from abandoned concurrent renders. Committed props own collection identity; replacing work cancels the prior request promptly.
  • All 20 focused React/transport tests pass, including dynamic disabled/invalid updates preserving the iframe, channel and pending collection. The real URL builder also verifies these flags do not change the iframe URL.
  • React ESM/CJS/declaration build and root lint pass. Standalone React typecheck still reports existing dependency-declaration errors; none reference the changed files.
  • SDK channel tests do not qualify after-typing value preservation in live Basis Theory controls. That browser regression and actual provider registration/release remain integration gates.
  • Consolidated PR CI reruns after the review-fix push.

Integration boundary

Matching hosted iframe: channel #31185, collection #31186. UC's typed request/answer and protected BF application stack must be consumed together.

Reactor configuration/deployment and a real registration/release round trip remain integration gates. SDK publication enables Crossmint/playground dependency updates and the playground migration. No main merge or package publication performed during consolidation.

@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 21f6b2e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
Name Type
@crossmint/client-sdk-base Minor
@crossmint/client-sdk-react-ui Minor
@crossmint/client-sdk-window Minor
@crossmint/client-sdk-nextjs-starter Patch
@crossmint/client-sdk-auth Patch
@crossmint/client-sdk-react-base Patch
@crossmint/client-sdk-react-native-ui Patch
@crossmint/client-sdk-verifiable-credentials Patch
@crossmint/client-sdk-smart-wallet Patch
@crossmint/common-sdk-auth Patch
@crossmint/auth-ssr-nextjs-demo Patch
@crossmint/wallets-quickstart-devkit Patch
@crossmint/wallets-playground-react Patch
@crossmint/client-sdk-rn-window Patch
@crossmint/wallets-sdk Patch
@crossmint/wallets-playground-expo Patch
@crossmint/server-sdk Patch
crossmint-auth-node Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

devin-ai-integration[bot]

This comment was marked as resolved.

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Medium risk] Refactors protected input field collection to per-field transport.

The PR is not ready to merge while the in-repository React consumer and example remain incompatible with the new base contract.

Reviews (1) · Last reviewed commit: "feat(protected-inputs): add per-field co..."

greptile-apps[bot]

This comment was marked as resolved.

mPaella and others added 3 commits October 1, 2026 03:26
* feat(protected-inputs): collect individual protected fields with refs

* fix: settle protected collections when their component changes
@mPaella mPaella changed the title feat(protected-inputs): add per-field collection transport feat(protected-inputs): per-field collection SDK (cumulative) Oct 1, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

mPaella commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Review follow-up pushed in 21f6b2e. Both collection lifecycle findings were reproduced, fixed and covered by regressions; their threads are now resolved. All 20 focused React/transport tests, the React ESM/CJS/declaration build and root lint pass. Standalone React typecheck still hits existing external dependency declarations, with no diagnostics in changed files.

The older Greptile concern about the React consumer/demo using the prior interface was addressed by #2129, now squash-consolidated here; cumulative build/test and lint CI passed before this follow-up. The new tests also verify dynamic disabled/invalid updates preserve the SDK iframe/channel and pending work; they do not qualify live Basis Theory value preservation after typing. CI is rerunning for this push.

@mPaella
mPaella merged commit e7905a8 into main Oct 1, 2026
4 checks passed
@mPaella
mPaella deleted the codex/protected-input-transport branch October 1, 2026 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant