feature/INT-1667 - ChallengeIndicator/SessionChallengeIndicator enum alignment - #631
Conversation
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 10 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 17 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
82cfa16 to
d3535ac
Compare
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 17 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 27 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 27 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
|
Release 7.15.0 bundles the 3DS challenge indicator alignment plus a broader refresh of the Sessions model (#631), and a dependency/security update (#632). ### 3DS Challenge Indicator Modeling * Introduced a new `SessionChallengeIndicator` enum in `sessions` to represent all nine possible challenge indicator values for session endpoints, including exemption requests, with detailed documentation for each value. (`src/main/java/com/checkout/sessions/SessionChallengeIndicator.java`) * Updated `ChallengeIndicator` in `common` to clarify its use for payment-related endpoints and to deprecate exemption values, which are now only valid for sessions. Improved documentation for each enum value and marked exemptions as deprecated. (`src/main/java/com/checkout/common/ChallengeIndicator.java`) * Changed the type of the `challengeIndicator` field in both `CreateSessionAcceptedResponse` and `GetSessionResponse` from `ChallengeIndicator` to `SessionChallengeIndicator`, ensuring correct deserialization and alignment with API behaviour. * Removed the now unnecessary imports of `ChallengeIndicator` from `CreateSessionAcceptedResponse`, `GetSessionResponse` and `SessionRequest`. ### Sessions Model Additions * Added Google SPA support with four new classes: `GoogleSpa`, `GoogleSpaInfo`, `GoogleSpaIframe` and `GoogleSpaToken`. (`src/main/java/com/checkout/sessions/GoogleSpa*.java`) * Added the preferred experiences model: `SessionPreferredExperiences`, `Experience`, `ExperienceStatus` and `ExperienceOutcome`. * Added `ThreeDSInfo` and `ThreeDSErrorDetails` to model the 3DS information and error detail objects returned by the session endpoints. * Added the `SessionScheme` enum with the full set of spec values, replacing loosely typed scheme fields. * Extended `SessionRequest` with the new fields (Google SPA, preferred experiences, device information) and fixed the `priorTransactionReference` handling. * Updated `TransactionType` and `SessionsCardMetadataResponse` to match the current spec. ### Documentation * Added comprehensive Javadoc for every field in `CreateSessionAcceptedResponse`, `GetSessionResponse` and `SessionRequest`, clarifying requirements, formats, patterns and default values. ### Test Coverage * New serialization suites: `CreateSessionAcceptedResponseSerializationTest`, `GetSessionResponseSerializationTest`, `SessionRequestSerializationTest`. * New enum conformance suites: `ChallengeIndicatorTest`, `SessionChallengeIndicatorTest`, `SessionSchemeTest`, `TransactionTypeTest`. * Updated the sessions integration tests (`AbstractSessionsTestIT`, `RequestAndGetSessionsTestIT`) for the new indicator type. ### Security and Dependency Update Dependency updates: - sonarqube to 7.3.1.8318 - log4j to `log4j-api:2.25.5`, `log4j-core:2.25.5`, `log4j-slf4j2-impl:2.25.5` Dependabot configuration: * Added a `test-deps` group to combine updates for testing-related dependencies (`org.junit*`, `org.mockito*`, `org.apache.logging.log4j*`, `org.hamcrest*`) into single pull requests. * Increased `open-pull-requests-limit` to 10 for the main package ecosystem. * Added a `github-actions` ecosystem entry with a weekly update schedule.



This pull request refines how 3DS challenge indicators are modeled and documented in the codebase, clarifying the distinction between payment and session APIs and improving the accuracy of API response models. The main changes involve introducing a dedicated
SessionChallengeIndicatorenum for session-related endpoints, updating documentation for both enums, and enhancing the field-level documentation for session response classes.3DS Challenge Indicator Modeling
SessionChallengeIndicatorenum insessionsto represent all nine possible challenge indicator values for session endpoints, including exemption requests, with detailed documentation for each value. (src/main/java/com/checkout/sessions/SessionChallengeIndicator.java)ChallengeIndicatorincommonto clarify its use for payment-related endpoints and to deprecate exemption values, which are now only valid for sessions. Improved documentation for each enum value and marked exemptions as deprecated. (src/main/java/com/checkout/common/ChallengeIndicator.java)Session Response Model Updates
challengeIndicatorfield in bothCreateSessionAcceptedResponseandGetSessionResponsefromChallengeIndicatortoSessionChallengeIndicator, ensuring correct deserialization and alignment with API behavior. (src/main/java/com/checkout/sessions/CreateSessionAcceptedResponse.java,src/main/java/com/checkout/sessions/GetSessionResponse.java) [1] [2]CreateSessionAcceptedResponseandGetSessionResponse, clarifying requirements, formats, and default values for each field. [1] [2]Code Clean-up
ChallengeIndicatorfrom session-related files to prevent confusion and maintain separation of concerns. (src/main/java/com/checkout/sessions/CreateSessionAcceptedResponse.java,src/main/java/com/checkout/sessions/GetSessionResponse.java,src/main/java/com/checkout/sessions/SessionRequest.java) [1] [2] [3]