fix: ask 3-D Secure of debit cards only, and send the cardholder as the card payer
All checks were successful
Build and deploy / Validate source (push) Successful in 4s
Build and deploy / Integration suite on a real stack (push) Successful in 2m13s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images (push) Successful in 1m9s

A credit card payment with the test credentials was refused with 10113
("the payment method is excluded by a rule"). Every card was sent with
three_d_secure_mode, which only debit needs, and with the order's CNPJ as
payer instead of the cardholder's document from the card form. Debit
methods keep 3-D Secure, and the card form's document is the payer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-29 13:57:19 -03:00
parent 593ddf82c8
commit f5fed013ab
4 changed files with 30 additions and 6 deletions

View File

@@ -427,6 +427,13 @@
});
return sdkLoading;
}
// The cardholder's document as the card form collected it.
function cardholder(id) {
const number=String(id?.number||'').replace(/\D/g,'');
const type=String(id?.type||'').toUpperCase();
return ['CPF','CNPJ'].includes(type) && /^[0-9]{11,14}$/.test(number)
? {payer_document_type:type, payer_document:number} : {};
}
let cardBrick=null;
function unmountCard() {
if (cardBrick) { try { cardBrick.unmount(); } catch(_) {} cardBrick=null; }
@@ -463,7 +470,8 @@
result=await api('/payments/intent',{quote_id:draftId,method:{
type:'card', token:data.token, payment_method_id:data.payment_method_id,
installments:Number(data.installments)||1,
issuer_id:data.issuer_id==null?null:String(data.issuer_id)}});
issuer_id:data.issuer_id==null?null:String(data.issuer_id),
...cardholder(data.payer?.identification)}});
} catch(error) {
// Rejecting stops the form's spinner; the reason is shown above it.
message(error.message || 'Não foi possível concluir o pagamento. Tente de novo.');