Skip to content

chore(POCP-1226): support 8-digit IINs in card event - #279

Merged
lukasz-k-bieszczad-cko merged 14 commits into
masterfrom
chore/POCP-1226/allow-8-digin-inns-v2
Sep 29, 2026
Merged

lukasz-k-bieszczad-cko merged 14 commits into
masterfrom
chore/POCP-1226/allow-8-digin-inns-v2

Conversation

@lukasz-k-bieszczad-cko

@lukasz-k-bieszczad-cko lukasz-k-bieszczad-cko commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

This pull request introduces support for exposing 8-digit IINs (Issuer Identification Numbers) where PCI rules allow, improving card scheme detection and issuer information accuracy. The changes ensure that 8-digit IINs are surfaced only for permitted card schemes and 16-digit PANs, while maintaining 6-digit IINs for others. The configuration is now exposed to both the card field and the example form, and IIN restriction logic is updated to match on prefixes.

8-digit IIN support and configuration:

  • Added the exposeIIN8 option to the card field configuration, allowing merchants to opt into exposing 8-digit IINs when permitted (src/processout/cardfield.ts, examples/card-form/index.html).
  • Implemented logic to determine when an 8-digit IIN can be exposed, including an allow-list of schemes and PAN length checks (src/processout/card.ts).

IIN extraction and API usage:

  • Updated the logic for extracting the IIN to use up to 8 digits when available, falling back to 6 digits otherwise, and ensured only 6- or 8-digit IINs are sent to the API (src/processout/processout.ts, examples/card-form/index.html).

IIN restriction logic:

  • Modified the IIN restriction logic to match allowed IINs as prefixes, supporting both 6- and 8-digit entries (src/dynamic-checkout/payment-methods/card.ts).

Card.getIIN emitted a flat 8-digit IIN for every scheme, over-exposing
the BIN for schemes the backend caps at 6 (notably Amex). Mirror the
allow-list in api (controllers/card_inn.go): only visa, mastercard,
discover, jcb, union-pay and carte bancaire surface 8 digits; every
other scheme - plus unknown or co-badged/ambiguous prefixes - falls
back to 6.

Applies to both consumers of getIIN: the emitted card_iin field event
and the Dynamic Checkout restrict_to_iins prefix match.

Note: the backend api-deactivate-eight-digit-bin LaunchDarkly flag is
per-project and server-side, so the client cap is scheme-based only.
@datadog-eu-processout

datadog-eu-processout Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Pipelines

⚠️ Warnings

Your PR has warnings. Please review the issues below.

🚦 1 Pipeline job failed

Check version bumped | Check version bumped — 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 1938e6b | Docs | View more details | Give us feedback!

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Add optional support for 8-digit IIN/BIN handling to improve issuer/scheme accuracy while keeping compatibility with 6-digit IIN flows.

Changes:

  • Extend IIN extraction / matching logic to handle 8-digit values (and prefix matching for restrictions).
  • Introduce exposeIIN8 option and add card helpers (getIIN8, canExpose8DigitIIN) to enforce when 8 digits may be surfaced.
  • Update example usage and bump package version.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
src/processout/processout.ts Changes IIN extraction used for iins/${iin} API calls to 8 digits.
src/processout/cardfield.ts Adds exposeIIN8 option and propagates it through options parsing; formatting cleanups.
src/processout/card.ts Adds helpers and allow-list logic to decide when 8-digit IIN can be exposed.
src/dynamic-checkout/payment-methods/card.ts Updates restriction matching to support mixed 6/8-digit configured IINs via prefix logic.
package.json Bumps version to 1.9.11.
examples/card-form/index.html Demonstrates enabling exposeIIN8 and adjusts event trigger threshold.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/processout/processout.ts Outdated
Comment thread src/processout/card.ts
Comment thread src/processout/card.ts
Comment thread src/processout/card.ts
Comment thread examples/card-form/index.html
Comment thread examples/card-form/index.html Outdated
@datadog-processout

Copy link
Copy Markdown

Pipelines

⚠️ Warnings

Your PR has warnings. Please review the issues below.

🚦 1 Pipeline job failed

Check version bumped | Check version bumped

View in Datadog · View in GitHub Actions

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 1938e6b | Docs | View more details | Give us feedback!

@lukasz-k-bieszczad-cko

Copy link
Copy Markdown
Contributor Author

Tests

image

with

        client.setupform(
          formelement,
          {
            exposeiin8: true,
          },

when typing card number I receive 6-digits IINs until the the full 16-digit PAN is typed, then I receive 8-digit IIN instead.

@lukasz-k-bieszczad-cko
lukasz-k-bieszczad-cko marked this pull request as ready for review September 28, 2026 11:58
@lukasz-k-bieszczad-cko
lukasz-k-bieszczad-cko force-pushed the chore/POCP-1226/allow-8-digin-inns-v2 branch from 9eb6a16 to 91dbebf Compare September 28, 2026 12:03
Comment thread examples/card-form/index.html Outdated
let preferredCardType = null;
form.getNumberField().on("input", function (e) {
if (e.card_number_length == 6) {
if (e.card_iin.length >= 6) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Why not check for 6 and 16, so it won't call getCardInformation for every number >=6 & <=15?

@lukasz-k-bieszczad-cko lukasz-k-bieszczad-cko Sep 28, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good spot, that should be e.card_number_lenght >= 6 not iin

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

also this is an example form

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok, after few minutes of thinking, it makes sense to check for 6 and 16 and make 2 requests and not 11

@lukasz-k-bieszczad-cko
lukasz-k-bieszczad-cko force-pushed the chore/POCP-1226/allow-8-digin-inns-v2 branch from 91dbebf to a1594ca Compare September 28, 2026 12:58
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lukasz-k-bieszczad-cko
lukasz-k-bieszczad-cko force-pushed the chore/POCP-1226/allow-8-digin-inns-v2 branch from a1594ca to c4ab1df Compare September 28, 2026 13:09
@lukasz-k-bieszczad-cko
lukasz-k-bieszczad-cko merged commit 2c1d7b2 into master Sep 29, 2026
5 checks passed
@lukasz-k-bieszczad-cko
lukasz-k-bieszczad-cko deleted the chore/POCP-1226/allow-8-digin-inns-v2 branch September 29, 2026 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants