Skip to content

[in_app_purchase] Return jwsRepresentation and jsonRepresentation for StoreKit2 #9280

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 15 commits into
base: main
Choose a base branch
from

Conversation

shaunpanjabi
Copy link

@shaunpanjabi shaunpanjabi commented May 18, 2025

Fix for flutter/flutter#164433

Providing access to jwsRepresentation. property of the transaction. With the most recent update PurchaseVerificationData returns empty now. I think it could make sense to repurpose it and return the:

  • jsonRepresentation for localVerificationData
  • jwsRepresentation for serverVerificationData

Pre-Review Checklist

If you need help, consider asking for advice on the #hackers-new channel on Discord.

Footnotes

  1. Regular contributors who have demonstrated familiarity with the repository guidelines only need to comment if the PR is not auto-exempted by repo tooling. 2 3

@flutter-dashboard
Copy link

It looks like this pull request may not have tests. Please make sure to add tests or get an explicit test exemption before merging.

If you are not sure if you need tests, consider this rule of thumb: the purpose of a test is to make sure someone doesn't accidentally revert the fix. Ask yourself, is there anything in your PR that you feel it is important we not accidentally revert back to how it was before your fix?

Reviewers: Read the Tree Hygiene page and make sure this patch meets those guidelines before LGTMing.If you believe this PR qualifies for a test exemption, contact "@test-exemption-reviewer" in the #hackers channel in Discord (don't just cc them here, they won't see it!). The test exemption team is a small volunteer group, so all reviewers should feel empowered to ask for tests, without delegating that responsibility entirely to the test exemption group.

@maks-epowar
Copy link

Hi is there any update on adding this? This is more logical than returning empty verification data

Copy link
Contributor

@LouiseHsu LouiseHsu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved, with a comment about the versioning

@@ -1,6 +1,8 @@
## NEXT

* Updates minimum supported SDK version to Flutter 3.27/Dart 3.6.
* Add `jwsRepresentation` to `SK2PurchaseDetails` as `serverVerificationData`
* Add `jsonRepresentation` to `SK2PurchaseDetails` as `localVerificationData`

Copy link
Contributor

@LouiseHsu LouiseHsu Jun 2, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The reason the repo_check is failing is b/c of this - could you add lines 3-5 to a new 0.4.1 version and remove the NEXT?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! I updated to 0.4.2 since 0.4.1 just got merged in recently. Hope that is okay 🙏

@LouiseHsu LouiseHsu added the autosubmit Merge PR when tree becomes green via auto submit App label Jun 3, 2025
@auto-submit auto-submit bot removed the autosubmit Merge PR when tree becomes green via auto submit App label Jun 3, 2025
Copy link
Contributor

auto-submit bot commented Jun 3, 2025

autosubmit label was removed for flutter/packages/9280, because This PR has not met approval requirements for merging. The PR author is not a member of flutter-hackers and needs 1 more review(s) in order to merge this PR.

  • Merge guidelines: A PR needs at least one approved review if the author is already part of flutter-hackers or two member reviews if the author is not a flutter-hacker before re-applying the autosubmit label. Reviewers: If you left a comment approving, please use the "approve" review action instead.

@LouiseHsu
Copy link
Contributor

@LongCatIsLooong Can you take a look at this when you have time? 😺

Copy link
Contributor

@LongCatIsLooong LongCatIsLooong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the patch!

I couldn't find the relevant information in the PurchaseVerificationData documentation so could you clarify how localVerificationData and serverVerificationData are supposed to be used? From reading the storekit documentation, my impression is that you don't have to do anything with localVerificationData (as StoreKit has already verified it), but you can optionally check the signed information in serverVerificationData on your own server or on the device, to verify the purchase?

final Stream<List<PurchaseDetails>> stream =
iapStoreKitPlatform.purchaseStream;

late StreamSubscription<List<PurchaseDetails>> subscription;
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: final instead of late?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe it has to be late since it is being referenced inside the listen callback. So it is being referenced before it is initialized.

@@ -88,7 +88,8 @@ extension InAppPurchasePlugin: InAppPurchase2API {
case .success(let verification):
switch verification {
case .verified(let transaction):
self.sendTransactionUpdate(transaction: transaction)
self.sendTransactionUpdate(
transaction: transaction, receipt: "\(verification.jwsRepresentation)")
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(here and below) I don't think the string interpolation here is necessary, since jwsRepresentation is a string itself: https://developer.apple.com/documentation/storekit/verificationresult/jwsrepresentation-21vgo (if I'm looking at the right jwsRepresentation, that is)

## 0.4.2

* Add `jwsRepresentation` to `SK2PurchaseDetails` as `serverVerificationData`
* Add `jsonRepresentation` to `SK2PurchaseDetails` as `localVerificationData`
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you add a bit color to what are jwsRepresentation and jsonRepresentation? Also maybe which jwsRepresentation and jsonRepresentation since there are several fields with identical names in the StoreKit documentation. The 2 lines seem a bit vague without the context.

@shaunpanjabi
Copy link
Author

Thanks for the patch!

I couldn't find the relevant information in the PurchaseVerificationData documentation so could you clarify how localVerificationData and serverVerificationData are supposed to be used? From reading the storekit documentation, my impression is that you don't have to do anything with localVerificationData (as StoreKit has already verified it), but you can optionally check the signed information in serverVerificationData on your own server or on the device, to verify the purchase?

Yeah the localVerificationData isn't really necessary. I just thought it might be useful for debugging locally or for accessing the properties of transaction directly if they aren't already exposed. I'd be open to removing it if people don't think it's useful.

serverVerificationData is used to pass the signed transaction securely to your server so it can be verified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants