fix: ask 3-D Secure of debit cards only, and send the cardholder as the card payer
All checks were successful
Build and deploy / Validate source (push) Successful in 4s
Build and deploy / Integration suite on a real stack (push) Successful in 2m13s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images (push) Successful in 1m9s

A credit card payment with the test credentials was refused with 10113
("the payment method is excluded by a rule"). Every card was sent with
three_d_secure_mode, which only debit needs, and with the order's CNPJ as
payer instead of the cardholder's document from the card form. Debit
methods keep 3-D Secure, and the card form's document is the payer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-29 13:57:19 -03:00
parent 593ddf82c8
commit f5fed013ab
4 changed files with 30 additions and 6 deletions

View File

@@ -139,7 +139,15 @@ class MercadoPagoTests(unittest.TestCase):
{'type': 'card', 'token': 'tok_def', 'payment_method_id': 'visa'})
self.assertNotEqual(self.requests[-1].headers['x-idempotency-key'], first_key)
self.assertTrue(first_key.startswith('dtf-quote-q-card-'))
self.assertEqual(body['three_d_secure_mode'], 'optional')
# 3-D Secure is asked of debit only; the cardholder is the payer.
self.assertNotIn('three_d_secure_mode', body)
self.mp.create('q', 1000, {'mail': 'a@example.test', 'cnpj': '11222333000181'},
{'type': 'card', 'token': 'tok_deb', 'payment_method_id': 'debmaster',
'payer_document_type': 'CPF', 'payer_document': '12345678909'})
debit = json.loads(self.requests[-1].content)
self.assertEqual(debit['three_d_secure_mode'], 'optional')
self.assertEqual(debit['payer']['identification'], {'type': 'CPF', 'number': '12345678909'})
self.assertEqual(body['payer']['identification'], {'type': 'CNPJ', 'number': '11222333000181'})
self.mp.create('q', 1000, {'mail': 'a@example.test', 'cnpj': '11222333000181'},
{'type': 'card', 'token': 'tok_iss', 'payment_method_id': 'master', 'issuer_id': '24'})
self.assertNotIn('issuer_id', json.loads(self.requests[-1].content))