fix: ask 3-D Secure of debit cards only, and send the cardholder as the card payer
All checks were successful
Build and deploy / Validate source (push) Successful in 4s
Build and deploy / Integration suite on a real stack (push) Successful in 2m13s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images (push) Successful in 1m9s
All checks were successful
Build and deploy / Validate source (push) Successful in 4s
Build and deploy / Integration suite on a real stack (push) Successful in 2m13s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images (push) Successful in 1m9s
A credit card payment with the test credentials was refused with 10113
("the payment method is excluded by a rule"). Every card was sent with
three_d_secure_mode, which only debit needs, and with the order's CNPJ as
payer instead of the cardholder's document from the card form. Debit
methods keep 3-D Secure, and the card form's document is the payer.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -192,6 +192,10 @@ class PaymentMethod(StrictModel):
|
||||
payment_method_id: str | None = Field(default=None, max_length=40, pattern=r'^[a-z_]+$')
|
||||
installments: int = Field(default=1, ge=1, le=12, strict=True)
|
||||
issuer_id: str | None = Field(default=None, max_length=40)
|
||||
# The cardholder's document from the card form: for a card, the payer is
|
||||
# the cardholder, not necessarily the company on the invoice.
|
||||
payer_document_type: Literal['CPF', 'CNPJ'] | None = None
|
||||
payer_document: str | None = Field(default=None, pattern=r'^[0-9]{11,14}$')
|
||||
|
||||
@model_validator(mode='after')
|
||||
def card_needs_token(self):
|
||||
|
||||
@@ -80,11 +80,15 @@ class MercadoPagoPayment:
|
||||
expires_at = (datetime.now(BRASILIA) + timedelta(minutes=PIX_MINUTES)).isoformat(timespec='milliseconds')
|
||||
body['date_of_expiration'] = expires_at
|
||||
elif method['type'] == 'card':
|
||||
# The issuer decides whether the cardholder must confirm in the
|
||||
# bank's app or page (3-D Secure); debit cards usually must.
|
||||
body.update(token=method['token'], payment_method_id=method['payment_method_id'],
|
||||
installments=int(method.get('installments', 1)),
|
||||
three_d_secure_mode='optional')
|
||||
installments=int(method.get('installments', 1)))
|
||||
# 3-D Secure (the bank's confirmation) only for debit, which needs
|
||||
# it; asking it of every card was refused as a rule (10113).
|
||||
if method['payment_method_id'].startswith('deb'):
|
||||
body['three_d_secure_mode'] = 'optional'
|
||||
if method.get('payer_document_type') and method.get('payer_document'):
|
||||
body['payer']['identification'] = {'type': method['payer_document_type'],
|
||||
'number': method['payer_document']}
|
||||
# No issuer_id: Mercado Pago takes the issuer from the card number.
|
||||
# The form's suggestion was refused for its own test cards
|
||||
# (10111, "the issuer does not have the BIN configured").
|
||||
|
||||
Reference in New Issue
Block a user