Repository navigation
chore(POCP-1226): support 8-digit IINs in card event - #279
Conversation
Card.getIIN emitted a flat 8-digit IIN for every scheme, over-exposing the BIN for schemes the backend caps at 6 (notably Amex). Mirror the allow-list in api (controllers/card_inn.go): only visa, mastercard, discover, jcb, union-pay and carte bancaire surface 8 digits; every other scheme - plus unknown or co-badged/ambiguous prefixes - falls back to 6. Applies to both consumers of getIIN: the emitted card_iin field event and the Dynamic Checkout restrict_to_iins prefix match. Note: the backend api-deactivate-eight-digit-bin LaunchDarkly flag is per-project and server-side, so the client cap is scheme-based only.
|
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Add optional support for 8-digit IIN/BIN handling to improve issuer/scheme accuracy while keeping compatibility with 6-digit IIN flows.
Changes:
- Extend IIN extraction / matching logic to handle 8-digit values (and prefix matching for restrictions).
- Introduce
exposeIIN8option and add card helpers (getIIN8,canExpose8DigitIIN) to enforce when 8 digits may be surfaced. - Update example usage and bump package version.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| src/processout/processout.ts | Changes IIN extraction used for iins/${iin} API calls to 8 digits. |
| src/processout/cardfield.ts | Adds exposeIIN8 option and propagates it through options parsing; formatting cleanups. |
| src/processout/card.ts | Adds helpers and allow-list logic to decide when 8-digit IIN can be exposed. |
| src/dynamic-checkout/payment-methods/card.ts | Updates restriction matching to support mixed 6/8-digit configured IINs via prefix logic. |
| package.json | Bumps version to 1.9.11. |
| examples/card-form/index.html | Demonstrates enabling exposeIIN8 and adjusts event trigger threshold. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…ow-8-digin-inns-v2
|
9eb6a16 to
91dbebf
Compare
| let preferredCardType = null; | ||
| form.getNumberField().on("input", function (e) { | ||
| if (e.card_number_length == 6) { | ||
| if (e.card_iin.length >= 6) { |
There was a problem hiding this comment.
nit: Why not check for 6 and 16, so it won't call getCardInformation for every number >=6 & <=15?
There was a problem hiding this comment.
good spot, that should be e.card_number_lenght >= 6 not iin
There was a problem hiding this comment.
also this is an example form
There was a problem hiding this comment.
ok, after few minutes of thinking, it makes sense to check for 6 and 16 and make 2 requests and not 11
91dbebf to
a1594ca
Compare
a1594ca to
c4ab1df
Compare

This pull request introduces support for exposing 8-digit IINs (Issuer Identification Numbers) where PCI rules allow, improving card scheme detection and issuer information accuracy. The changes ensure that 8-digit IINs are surfaced only for permitted card schemes and 16-digit PANs, while maintaining 6-digit IINs for others. The configuration is now exposed to both the card field and the example form, and IIN restriction logic is updated to match on prefixes.
8-digit IIN support and configuration:
exposeIIN8option to the card field configuration, allowing merchants to opt into exposing 8-digit IINs when permitted (src/processout/cardfield.ts,examples/card-form/index.html).src/processout/card.ts).IIN extraction and API usage:
src/processout/processout.ts,examples/card-form/index.html).IIN restriction logic:
src/dynamic-checkout/payment-methods/card.ts).