Repository navigation
Conversation
…lt on the order Stores with high chargeback risk can now refuse any credit card purchase not authenticated by the issuer (3DS), instead of falling back to fraud analysis. - New `braspag_3ds.required`: anything other than authenticated (failed challenge, card not enrolled, brand without 3DS, script error or timeout) is refused before calling Cielo, with a message suggesting Pix or billet. If the 3DS token can't be generated, credit card is not listed and Pix and billet keep working - Accepted ECI from Cielo table: Visa, Elo and Amex 05/06, Mastercard 02/01 - `braspag_3ds.timeout` (30 to 900 s, default 300 when required): the challenge may need the bank app or an SMS code; legacy app had 30 s fixed - `braspag_3ds.fraud_analysis` keeps ClearSale on authenticated purchases (default unchanged: captured without it) - 3DS result, ECI, version and reference on transaction custom fields Ported from the legacy app (MPI V2 script, token and ExternalAuthentication). 3DS rules are isolated in `3ds/policy.mjs`: MPI V3 keeps the same authorization data, so only the authentication step changes. Only the 3DS fields Cielo expects are forwarded from the browser hash. Without `braspag_3ds` credentials nothing changes for current stores. Unit tests: `node --test tests-unit/`. Browser flow checked against a stubbed MPI for authenticated, failed, unsupported brand, script error, timeout and missing token. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ports the Cielo 3DS (MPI V2) from the legacy app to the v3 Braspag/Cielo app, with a required 3DS policy for stores with high chargeback risk (Bom Ar Condicionado: "no card purchase without 3DS").
Behavior
required: false(default)required: trueExternalAuthentication, capturebraspag_3ds.timeout: 30–900 s (default 300 when required; legacy had 30 s fixed). The challenge may need the bank app or an SMS code.braspag_3ds.fraud_analysis: optionally keep ClearSale on authenticated purchases (default unchanged).custom_fields, shown on the order.Cavv,Xid,Eci,Version,ReferenceIdare forwarded from the browser hash.braspag_3dscredentials: no change.MPI V3
Cielo will retire MPI V2 (no date yet) and V3 isn't available for Silent Order Post. Rules live in
lib-mjs/lib/braspag/3ds/policy.mjs; V3 keeps the same authorization data, so only the browser/token step changes.Market schema
New fields
required,timeout,fraud_analysisinsidebraspag_3ds(snippet in the app README).Tests
node --test packages/apps/braspag/tests-unit/(policy, ECI, timeout, transaction payload).🤖 Generated with Claude Code