feat(protected-inputs): per-field collection SDK (cumulative) - #2128
Conversation
🦋 Changeset detectedLatest commit: 21f6b2e The changes in this PR will be included in the next version bump. This PR includes changesets to release 18 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
* feat(protected-inputs): collect individual protected fields with refs * fix: settle protected collections when their component changes
|
Review follow-up pushed in 21f6b2e. Both collection lifecycle findings were reproduced, fixed and covered by regressions; their threads are now resolved. All 20 focused React/transport tests, the React ESM/CJS/declaration build and root lint pass. Standalone React typecheck still hits existing external dependency declarations, with no diagnostics in changed files. The older Greptile concern about the React consumer/demo using the prior interface was addressed by #2129, now squash-consolidated here; cumulative build/test and lint CI passed before this follow-up. The new tests also verify dynamic disabled/invalid updates preserve the SDK iframe/channel and pending work; they do not qualify live Basis Theory value preservation after typing. CI is rerunning for this push. |
Summary
Cumulative SDK implementation: #2129 was squash-merged into this PR. Replaces the password-only protected-input interface with individually rendered buyer fields and per-field collection refs.
fielddescriptors support protected single-line text, number and integer.CrossmintProtectedInputexposesref.collect(), returningcollected,invalid,unavailableorsuperseded. The application owns ordinary answers, labels, error messages and submission.CrossmintProvidersupplies the client API key; the application supplies its external-auth buyer JWT. Authentication crosses the verified window channel rather than the iframe URL.disabledandinvalidupdate through the iframe state channel. Hosted height and paint gutters keep the field aligned with native inputs.Release changeset
Minor bumps, per owner decision:
@crossmint/client-sdk-base: 4.1.0 → 4.2.0@crossmint/client-sdk-react-ui: 4.8.0 → 4.9.0@crossmint/client-sdk-window: 1.1.1 → 1.2.0Changesets also plans a dependent patch for
@crossmint/client-sdk-rn-window(0.3.18 → 0.3.19). The release plan contains no major bumps. This PR adds the changeset; package versioning/publication follows the repository's release PR workflow.The old
merchantUrl/onCreatedinterface is intentionally replaced; consumers need to adoptfield,jwtandref.collect().Validation
disabled/invalidupdates preserving the iframe, channel and pending collection. The real URL builder also verifies these flags do not change the iframe URL.Integration boundary
Matching hosted iframe: channel #31185, collection #31186. UC's typed request/answer and protected BF application stack must be consumed together.
Reactor configuration/deployment and a real registration/release round trip remain integration gates. SDK publication enables Crossmint/playground dependency updates and the playground migration. No main merge or package publication performed during consolidation.