Skip to content

Move the SCA page's values into Stimulus data attributes - #1274

Merged
excid3 merged 2 commits into
mainfrom
sca-page-stimulus-values
Sep 20, 2026
Merged

excid3 merged 2 commits into
mainfrom
sca-page-stimulus-values

Conversation

@excid3

@excid3 excid3 commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator

Summary

View. show.html.erb interpolated the publishable key, the Connect account, and two translated messages straight into JavaScript string literals. A translation containing an apostrophe would break the script. The values now live on the root element as Stimulus values (publicKey, stripeAccount, nameMissingMessage, confirmedMessage), the controller builds this.stripe in initialize() (Stimulus runs value callbacks before connect(), and statusValueChanged may call confirmPayment immediately), and the <script> block has no ERB in it at all. window.stripe is gone. The sanitize around link_to did nothing and is removed.

Controller. URI.parse(params[:back]).path raised URI::InvalidURIError on a malformed value (a 500) and threw away the query string of a legitimate /billing?tab=invoices. Rails 7's url_from returns same-site URLs intact and nil for anything else, so @redirect_to = url_from(params[:back]) || root_path keeps the open-redirect protection with less code. With one action and one ivar the before_action is inlined.

Layout. Two commented-out asset tags removed.

Apps that copied the payment view with rails g pay:views should regenerate it; noted in the changelog.

Test plan

  • Controller tests assert the data attributes with and without a Connect account, and that the script section contains no ERB.
  • New tests: a same-site back path keeps its query string; an external URL and a malformed URL both fall back to root without raising.
  • Full suite: 586 runs, 0 failures, 0 errors. standardrb clean.

🤖 Generated with Claude Code

excid3 and others added 2 commits September 20, 2026 17:21
The script interpolated the publishable key, the Connect account and
two translations directly into JavaScript strings, so a translation
with an apostrophe broke the page. Everything the controller needs is
now a Stimulus value on the root element, Stripe.js is created in
initialize() (value callbacks run before connect), and the script
contains no ERB.

The back link used URI.parse(params[:back]).path, which raised on a
malformed value and dropped a legitimate query string. url_from keeps
same-site URLs intact and rejects everything else. The redundant
sanitize around link_to and two commented-out asset tags in the
layout are gone.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Engine route helpers don't persist across a second request in the same
integration test on Rails 7.0, so the external and malformed back-link
cases get their own tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@excid3
excid3 force-pushed the sca-page-stimulus-values branch from bc9ec78 to 3ec3911 Compare September 20, 2026 22:21
@excid3
excid3 merged commit 14db70c into main Sep 20, 2026
@excid3
excid3 deleted the sca-page-stimulus-values branch September 20, 2026 22:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant