Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
# Changelog

## Unreleased
* Fix missing deprecation warnings import causing payment method creation and updates with legacy fields to raise `NameError`

## 4.47.0
* Fix path traversal vulnerability in `CreditCard`, `CreditCardVerification`, `Customer`, `MerchantAccount`, `PayPalAccount`, `PaymentMethod`, `PaymentMethodNonce`, `Plan`, `SepaDirectDebitAccount`, `Subscription`, `Testing`, `Transaction`, `TransactionLineItem`, `UsBankAccount`, and `UsBankAccountVerification` gateways by validating that IDs used in request paths do not contain path separators or relative-path segments
* Add `ach_type` to transaction search
Expand Down
1 change: 1 addition & 0 deletions braintree/payment_method_gateway.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@
from braintree.util.validation import is_invalid_path_segment

import sys
import warnings
from urllib.parse import urlencode


Expand Down
32 changes: 32 additions & 0 deletions tests/unit/test_payment_method_gateway.py
Original file line number Diff line number Diff line change
Expand Up @@ -214,3 +214,35 @@ def setup_payment_method_gateway_and_mock_http(self):
http_mock = MagicMock(name='config.http.delete')
braintree_gateway.config.http = http_mock
return payment_method_gateway, http_mock


class TestPaymentMethodGatewayDeprecation(unittest.TestCase):
def test_create_with_deprecated_device_session_id(self):
gateway = PaymentMethodGateway(BraintreeGateway(Configuration.instantiate()))
gateway._post = MagicMock()
params = {"device_session_id": "legacy-session"}

with self.assertWarnsRegex(DeprecationWarning, "device_session_id is deprecated"):
result = gateway.create(params)

gateway._post.assert_called_once_with("/payment_methods", {"payment_method": params})
self.assertIs(result, gateway._post.return_value)

def test_update_with_deprecated_attributes(self):
cases = [
("device_session_id", "device_session_id is deprecated"),
("fraud_merchant_id", "fraud_merchant_id is deprecated"),
("venmo_sdk_payment_method_code", "The Venmo SDK integration is Unsupported"),
]
for attribute, message in cases:
with self.subTest(attribute=attribute):
gateway = PaymentMethodGateway(BraintreeGateway(Configuration.instantiate()))
gateway._put = MagicMock()
params = {attribute: "legacy-value"}

with self.assertWarnsRegex(DeprecationWarning, message):
result = gateway.update("some_token", params)

gateway._put.assert_called_once_with(
"/payment_methods/any/some_token", {"payment_method": params})
self.assertIs(result, gateway._put.return_value)