Skip to content

[2.3.1] Update to stash-native 2.3.1 - #32

Merged
oliexe merged 1 commit into
mainfrom
update/stash-native-2.3.1
Sep 3, 2026
Merged

oliexe merged 1 commit into
mainfrom
update/stash-native-2.3.1

Conversation

@oliexe

@oliexe oliexe commented Sep 3, 2026 •

Copy link
Copy Markdown
Member

Releases gg.stash.unity 2.3.1 with embedded Stash Native 2.3.1 (Android AAR + iOS StashNative.xcframework).

Changes

  • Embedded binaries: StashNative-2.3.0.aar → StashNative-2.3.1.aar (Unity .meta GUID preserved via rename); xcframework device + simulator slices replaced in place (identical file layout, no .meta churn). Both binaries verified to report 2.3.1 internally.
  • New wrapper API: StashNative.SetInspectableWebViewsEnabled(bool) + IsInspectableWebViewsEnabled — opt-in QA/debug flag making checkout WebViews inspectable (Safari Web Inspector on iOS 16.4+, chrome://inspect on Android). Off by default; documented as not for production. Wired through both bridges (StashNativeCardBridge.mm, StashNativeCardUnityBridge.java) to the new static native API. The .mm bridge compiles clean against the embedded 2.3.1 headers.
  • Docs: package.json 2.3.0 → 2.3.1, README embedded-version line + API reference table, full CHANGELOG entry covering the upstream 2.3.1 changes (external-browser new-window navigation, sub-frame deeplinks, Google Pay redirect code removal, dark-mode/height-clamp/locale fixes).

Native-only behavior changes ship inside the binaries and need no wrapper changes; see the native release notes for details.

The Unity sample intentionally does not enable webview inspection (unlike the native sample apps) since it's copy-paste reference code.


Note

Medium Risk
Upgrades embedded payment/checkout native SDKs and changes in-WebView navigation and deeplink handling; the inspectable WebView flag is a security concern if enabled in production builds.

Overview
Releases gg.stash.unity 2.3.1 by bumping the embedded Stash Native 2.3.1 Android AAR and iOS StashNative.xcframework, with package.json, README, and CHANGELOG updated to match.

The only new Unity-facing API is StashNative.SetInspectableWebViewsEnabled(bool) and IsInspectableWebViewsEnabled, an opt-in QA/debug switch (off by default) to make checkout WebViews inspectable via Safari Web Inspector or chrome://inspect. It is plumbed through StashNativeCardUnityBridge.java, StashNativeCardBridge.mm, and StashNative.cs; callers must enable it before opening checkout and should not ship it enabled in production.

Checkout behavior changes from native 2.3.1 (new-window links opening externally, sub-frame deeplinks, removal of Android Google Pay redirect handling, dark-mode WebView and card height/inset fixes) ship inside the binaries with no other wrapper changes.

Reviewed by Cursor Bugbot for commit 5d4b1c8. Bugbot is set up for automated code reviews on this repo. Configure here.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Embed StashNative-2.3.1.aar and xcframework; bump package version and docs.
Expose new SetInspectableWebViewsEnabled / IsInspectableWebViewsEnabled in
the Unity API (C# + iOS/Android bridges).
@oliexe
oliexe merged commit b2ee7d0 into main Sep 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant