We have a client keen on replacing their current payment methods including Payflow Link and PayPal WPS with Braintree in order to be PCI DSS 3.0 SAQ A compliant.
As the current Drop-in UI product does not allow to customise UI, so we are heading to provide Hosted Fields integration. We have created a sandbox project by forking the current commerce_braintree module here:
https://www.drupal.org/sandbox/cityreader/2534858
After implementing both Hosted Fields and PayPal integration, we have found all three implementation including Drop-in UI, PayPal and Hosted Fields could be just included in one module with different settings.
As our client has a small budget to allow us maintain code of this new project, we think if possible we can create a version 3 branch and develop new features in it.
If we can develop in this version 3 branch, we plans to :
- move Transparent Direct from main module to a separate sub module, as it is not SAQ A compliant anymore.
- make Braintree.js integration more generic to include existing Drop-in UI in dev, and new Hosted Fields and PayPal in one module
- add some API function to main module to allow add-on features supplied by other contributed modules as we have plan to add account management and subscription management based on Braintree
Any advices are welcome. Thanks:D
| Comment | File | Size | Author |
|---|---|---|---|
| #33 | commerce_braintree-add_hosted_fields-2540268-33.patch | 2.15 KB | dpalmer |
| #28 | interdiff.txt | 2.67 KB | andyg5000 |
| #28 | commerce_braintree-add_hosted_fields-2540268-28.patch | 61.95 KB | andyg5000 |
| #20 | commerce_braintree-add_hosted_fields-2540268-19.patch | 50.75 KB | andyg5000 |
| #18 | interdiff.txt | 1.36 KB | aaronbauman |
Comments
Comment #1
luksakI am sorry for replying late...
There is a discussion at #2483675: [meta] 7.x-2.0 stable release about a stable release, which has some ideas.
How is your development progressing? I see there is some development going on...
In my opinion we should provide the three different integrations as submodules, fix all critical issues and get to a 2.x stable release.
A 3.x release needs a discussion of all maintainers. Most importantly we need to discuss a D8 port, which could involve integrating with https://www.drupal.org/project/payment since the first D8 ports of payment providers happen there. It could also involve integrating through Omnipay according to https://drupalcommerce.org/blog/14871/launching-commerce-drupal-8 What do the others think?
Renaming the issue accordingly.
Comment #2
eric.chenchao commentedHi @Lukas,
Thanks you for the reply. We also had some discussion inside our project about how we want to structure and separate functions by module in the last week.
The current work we have done in the sandbox is adding integration with Hosted fields and PayPal by borrowing some code from commerce_braintree_dropin module as we do not want to make dropin as dependency. Also we have found the integration of both Hosted fields and PayPal share majority of logic except settings and some js code. So we add both integrations to one module commerce_braintree_web. Also, Drop-in UI is a capsulation of both credit card and PayPal payment methods. When users use Drop-in UI, they are most likely not to use Hosted Field and PayPal as separate payment methods any more.
Due to the restriction of no destroy function of braintree function during the time of development, we cannot create more than one braintree instance when change payment method via Ajax. That's why we have to do the monkey patching and reload page when user change from Hosted Fields to PayPal and etc. It is probably they will launch newer version with destroy method next week so we hope get rid of monkey patching at that time. Read more here.
Byond payment method in commerce, in our project we also need to implement subscription and payment method management in Drupal. So we decide to create a braintree module as core dependency and move basic functions including credit card form by Hosted Fields, global settings page and etc into it. Then adding submodules to include other features. We want to make that module for general use although we reckon not too many sites need that function.
Regarding the stable release of branch version 2, we will keep an eye on it and see we can help to fix bugs.
Comment #3
luksakSo let's keep the scope of this issue to create a patch for 2.x providing a separate module providing Hosted Fields integration. We don't need to fix having both payments enabled since this is not really a use case. Or is it? Could you create a patch?
Comment #4
eric.chenchao commentedHi @Lukas, yes in our project, we use both Hosted Fields and PayPal integration. It works quite like Drop in UI with credit card and PayPal payment methods. And it allows us to custom style of the credit card form.
Also most of functions used in hosted fields module would be very close or even same as those used in dropin module, do you reckon just create clone copy of different function names or move some utility functions from dropin module to commerce_braintree for sharing?
Comment #5
aaronbaumanAny updates here?
commerce_stripe has managed to figure it out, but I would rather use Braintree. Does the 3.x API solve the javascript issue?
Comment #6
luksakcommerce_braintree integrates with Braintree's Drop-in payment solution which is more prowerful than Stripe's Checkout.
Comment #7
aaronbaumanOh, I see commerce_braintree_dropin in the dev release.
I was looking at 2.0-beta1 -- derp.
Also: I suppose one could use a
hook_js_alterto replacecommerce_braintree_dropin.jsand implement their own Hosted Fields API, yeah?Comment #8
eric.chenchao commented@aaronbauman I have written a module braintree integration to support this hosted fields. We use this in our client websites. You may be interested to check https://github.com/cityreader/braintree/blob/7.x-1.x/modules/braintree_p...
Comment #9
luksakUnexpectedly i am going to build one more D7 commerce site. I will test this when developing it next year.
@eric.chenchao could you please post a patch? Otherwise I won't be able to test this. Looking at your repository you made lots of changes to the module providing functionality not related to the Hosted fields integration.
Comment #10
iampumaFor a project we also needed the Hosted Fields integration to settle/void/refund transactions.
We have updated sandbox module mentioned above to support that (https://www.drupal.org/node/2852166)
and patched the commerce_braintree module to support the sandbox modules new payment (diff attached)
Comment #11
mglamanThe 8.x version of this module is the HPF approach. I'll be working to backport this into the 7.x branch.
It looks like we have three efforts which were never formalized into a single patch
Also, I'm not sure how any of the patches provided here can truly implement HPF since it involves embedded individual
<div>elements for the JS to render as iframes.Comment #12
mglamanComment #13
mglamanHere is the gateway! Just missing backoffice settlement (capture) and refunds.
Comment #14
mglamanUpdate for access callbacks
Comment #15
mglamanNew patch which adds integration with Kount for the Advanced Fraud Detection.
Comment #16
aaronbaumanThis is getting close, and perfect timing for the project I'm working on - thank you all for your work here!
I'm getting a WSOD on checkout due to an exception when calling ::sale in commerce_braintree_hostedfields_submit_form_submit():
1. why bother catching, just to throw again?
2. why not log the exception, and show a user-friendly error message?
There's at least one call to
debuggerleft over in commerce_braintree_hostedfields.jsLastly, why do we need to require Merchant Account ID per currency?
I've implemented Hosted Fields previously with only the API Merchant ID, Pub key, and Private key.
Seems like we should allow it fall back on default if not provided.
I'll submit a new patch when I've got it working.
Comment #17
mglaman:( whoops, 2.x-ism; Commerce catches those in new API on D8.
That's what the module does in others, just followed suit
Comment #18
aaronbaumanHmm, ok.
Out of scope for this issue then.
Once I entered the correct Merchant ID, this patch is working.
Update for the 2 minor issues discussed above - thanks again!
Comment #19
andyg5000Comment #20
andyg5000Don't kill me, but here's an update that includes a ton of refactoring so we can recycle methods for dropin and hosted fields. This is 95%, but needs the card on file update for hosted fields fixed or removed. I'll pick back up on this Monday!
Comment #21
andyg5000Forgot to include interdiff and comment that this adds terminal and card on file support for hosted fields.
Comment #22
aaronbaumanthank you for hook_commerce_braintree_hostedfields_fieldstyles_alter - i was just about to need that.
A few points:
- should probably be named like hook_commerce_braintree_hostedfields_js_alter(), since we're altering (potentially) the entire hostedFields specification.
- do we really want to allow contrib to alter the *entire* specification? Do we really want to provide so much rope for people to shoot themselves in the foot?
- the api.php alter hook needs to take its first arg by reference, like this:
Comment #23
mglamanWell nothing's really stopping them from altering the entire JS. But that is a valid point to just scope it to
hook_commerce_braintree_hostedfields_js_altername change and only allow returning / altering the field styles.Comment #24
andyg5000Yup. I agree with #23. I was working on this yesterday, but had some issues with Card on File integration. I think I got over the hump and should be able to wrap this up today. We'll need to get a commit for COF to fix one issue, but Glaman can do that.
Comment #25
andyg5000Adds card on file support and fixes issues with transparent redirect. Interdiff is between #18 and this.
Comment #26
andyg5000Comment #27
mglamanEDIT
I'm an idiot and can't read diffs.
Comment #28
andyg5000Updates to fix undefined index issues and replace the module_implements_alter implementation with a requirement of #2865117: Add drupal_alter to allow other modules to update payment terminal UI
Comment #29
mglamanLocally I got a notice from this. Had to add a check for triggering element first.
Fixed locally for pending commit.
Comment #31
mglamanWoo! Thanks everyone. I'll wait a few days before tagging a beta (maybe just RC) to release hosted fields.
You'll need https://www.drupal.org/project/commerce_cardonfile/releases/7.x-2.0-beta6 for proper integration with CoF + terminal
Comment #32
dpalmer commentedHi, I have tested the latest release and it working well for me. I have also added a patch to add support for the "descriptor name" field in the sale data. This is needed for anyone running multiple stores with the same braintree account to provide an attribute to filter transactions by store. See https://developers.braintreepayments.com/reference/request/transaction/s...
Comment #33
dpalmer commented"Descriptor name" patch.
Comment #35
EddyFK commentedI have a strange problem using hosted fields:
Payment and shipping services are on the same pane: shipping. When an anonymous user inputs the credit card credentials and selects a payment method and continues to review the order backend shows the correct amount that should be charged.
If i return to the payment and shipping step the whole form is shown again and i need to re-enter my credentials and select maybe a different shipping service. When i continue now again to review braintree throws and error, that the amount shouldn't be negative. In my order backend i see that the first payment is still there and a second with a negative amount. I guess what happened is, that there was a difference between the total amount before and the total amount after the shipping service change (because it costs less) and braintree subtracts that amount to get the correct total.
Is that a hosted fields problem because drupal payment works that way? When is the actual amount charged: After the user completes the last step or as soon as he approves the credit card credentials? Would it be possible to disable re-entering the complete credit card form, as the user maybe just wants to change the shipping service? I think it would make sense to show instead of the form a info showing the message from braintree here and a button that would maybe delete this payment and adds another braintree form...
Can somebody help?