From 25cf56abbcdb8d011cba87817cc72fe959cc84b1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Mon, 20 Jul 2026 08:37:48 +0200 Subject: [PATCH 1/8] chore(POCP-1226): support 8-digit IINs in card event --- src/dynamic-checkout/payment-methods/card.ts | 7 ++++++- src/processout/card.ts | 4 ++-- src/processout/processout.ts | 5 ++++- 3 files changed, 12 insertions(+), 4 deletions(-) diff --git a/src/dynamic-checkout/payment-methods/card.ts b/src/dynamic-checkout/payment-methods/card.ts index c7e3be86..dcc6b668 100644 --- a/src/dynamic-checkout/payment-methods/card.ts +++ b/src/dynamic-checkout/payment-methods/card.ts @@ -918,7 +918,12 @@ module ProcessOut { return } - const isAllowedIin = restrictToIins.indexOf(iin) !== -1 + // card_iin may carry more digits than the configured entries (IINs can + // be 6 or 8 digits), so match on prefix: an allowed entry matches when + // the detected IIN starts with it. + const isAllowedIin = restrictToIins.some(function (allowedIin) { + return allowedIin.length > 0 && iin.substring(0, allowedIin.length) === allowedIin + }) this.setCardRestrictionState(!isAllowedIin) } diff --git a/src/processout/card.ts b/src/processout/card.ts index 480d8789..f7e111bf 100644 --- a/src/processout/card.ts +++ b/src/processout/card.ts @@ -456,8 +456,8 @@ module ProcessOut { number = Card.parseNumber(number); // Remove potential spaces var l = number.length; - if (l > 6) - l = 6; + if (l > 8) + l = 8; return number.substring(0, l); } diff --git a/src/processout/processout.ts b/src/processout/processout.ts index 2ae80956..d5a8df4c 100644 --- a/src/processout/processout.ts +++ b/src/processout/processout.ts @@ -1676,7 +1676,10 @@ module ProcessOut { return } - const iin = cardNumber.substring(0, 6) + // Support up to 8-digit IINs (some networks issue 8-digit IINs, which + // yield more accurate issuer information); fall back to whatever is + // available when fewer digits were provided. + const iin = cardNumber.substring(0, 8) const apiEndpoint = `iins/${iin}` this.apiRequest( From a1bf701874f64bb5269622a045615c5042ee459e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Mon, 20 Jul 2026 08:52:20 +0200 Subject: [PATCH 2/8] update example --- examples/card-form/index.html | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/examples/card-form/index.html b/examples/card-form/index.html index e4824ff6..8d09bf09 100644 --- a/examples/card-form/index.html +++ b/examples/card-form/index.html @@ -55,7 +55,7 @@ function (form) { let preferredCardType = null; form.getNumberField().on("input", function (e) { - if (e.card_number_length == 6) { + if (e.card_number_length == 8) { client.getCardInformation( e.card_iin, function(cardInfo) { @@ -65,7 +65,7 @@ const radioGroup = document.createElement('div') radioGroup.className = 'combo-card-types' radioGroup.style.cssText = 'margin: 15px 0; padding: 15px; border: 1px solid #ddd; border-radius: 5px; background: #f9f9f9;' - + radioGroup.innerHTML = `

Select Card Type:

${cardInfo.combo_card_types.map((type, index) => ` @@ -75,11 +75,11 @@

Select Card Type:

`).join('')} ` - + // Insert before the Pay button const payButton = document.querySelector('.submit-button') payButton.parentNode.insertBefore(radioGroup, payButton) - + // Add event listener to track selection changes const radioButtons = radioGroup.querySelectorAll('input[name="cardType"]') radioButtons.forEach(radio => { @@ -88,7 +88,7 @@

Select Card Type:

console.log("User selected card type:", preferredCardType) }) }) - + // Set initial value preferredCardType = null } @@ -98,7 +98,7 @@

Select Card Type:

} ) } - + document.getElementById("errors").innerHTML = "" }) From 1f3179d0912b6167d6baf3d1c219f33e1fc55cf6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Thu, 23 Jul 2026 15:01:59 +0200 Subject: [PATCH 3/8] fix(POCP-1226): cap 8-digit IIN exposure per scheme Card.getIIN emitted a flat 8-digit IIN for every scheme, over-exposing the BIN for schemes the backend caps at 6 (notably Amex). Mirror the allow-list in api (controllers/card_inn.go): only visa, mastercard, discover, jcb, union-pay and carte bancaire surface 8 digits; every other scheme - plus unknown or co-badged/ambiguous prefixes - falls back to 6. Applies to both consumers of getIIN: the emitted card_iin field event and the Dynamic Checkout restrict_to_iins prefix match. Note: the backend api-deactivate-eight-digit-bin LaunchDarkly flag is per-project and server-side, so the client cap is scheme-based only. --- src/processout/card.ts | 39 +++++++++++++++++++++++++++++++++++++-- 1 file changed, 37 insertions(+), 2 deletions(-) diff --git a/src/processout/card.ts b/src/processout/card.ts index f7e111bf..65329180 100644 --- a/src/processout/card.ts +++ b/src/processout/card.ts @@ -455,12 +455,47 @@ module ProcessOut { public static getIIN(number: string): string { number = Card.parseNumber(number); // Remove potential spaces + // Only expose an 8-digit IIN for schemes the backend allows to + // do so; every other scheme is capped at 6 to avoid + // over-exposing the BIN. Mirrors api (controllers/card_inn.go). + var max = Card.canExpose8DigitIIN(number) ? 8 : 6; var l = number.length; - if (l > 8) - l = 8; + if (l > max) + l = max; return number.substring(0, l); } + /** + * Schemes permitted to surface an 8-digit IIN, mirroring the backend + * allow-list in api (controllers/card_inn.go). Every other scheme - + * notably American Express - is capped at 6 digits. Note the JS + * scheme key "union-pay" maps to the backend's "china union pay". + */ + private static iin8DigitSchemes: Array = [ + "visa", "mastercard", "discover", "jcb", "union-pay", "carte bancaire" + ]; + + /** + * canExpose8DigitIIN reports whether the card number's detected + * scheme(s) are allowed to surface an 8-digit IIN. Conservative: every + * detected scheme must be in the allow-list, so co-badged or ambiguous + * prefixes (and unknown schemes) fall back to 6 digits. + * @param {string} number + * @return {boolean} + */ + public static canExpose8DigitIIN(number: string): boolean { + var schemes = Card.getPossibleSchemes(number); + if (schemes.length == 0) + return false; + + for (var i = 0; i < schemes.length; i++) { + if (Card.iin8DigitSchemes.indexOf(schemes[i]) === -1) + return false; + } + + return true; + } + /** * GetLast4Digits returns the last4 digits of the card number * @param {string} number From 7b3e36756dfc01b20a9b64e31bf5a56c5eb97cf3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Fri, 24 Jul 2026 12:13:04 +0200 Subject: [PATCH 4/8] allow 8 digits iin only when card number lenght == 16 --- src/processout/card.ts | 34 ++++++++++++++++++++++------------ 1 file changed, 22 insertions(+), 12 deletions(-) diff --git a/src/processout/card.ts b/src/processout/card.ts index 65329180..8f80efe9 100644 --- a/src/processout/card.ts +++ b/src/processout/card.ts @@ -455,14 +455,17 @@ module ProcessOut { public static getIIN(number: string): string { number = Card.parseNumber(number); // Remove potential spaces - // Only expose an 8-digit IIN for schemes the backend allows to - // do so; every other scheme is capped at 6 to avoid - // over-exposing the BIN. Mirrors api (controllers/card_inn.go). - var max = Card.canExpose8DigitIIN(number) ? 8 : 6; - var l = number.length; - if (l > max) - l = max; - return number.substring(0, l); + if (number.length < 6) + return number; + + // Only expose an 8-digit IIN when PCI rules allow it: the scheme + // must permit it and the full PAN must be exactly 16 digits. + // Everything else caps at 6 to avoid over-exposing the BIN. + // Mirrors binder's TruncateNumber / api (controllers/card_inn.go). + if (Card.canExpose8DigitIIN(number)) + return number.substring(0, 8); + + return number.substring(0, 6); } /** @@ -476,14 +479,21 @@ module ProcessOut { ]; /** - * canExpose8DigitIIN reports whether the card number's detected - * scheme(s) are allowed to surface an 8-digit IIN. Conservative: every - * detected scheme must be in the allow-list, so co-badged or ambiguous - * prefixes (and unknown schemes) fall back to 6 digits. + * canExpose8DigitIIN reports whether an 8-digit IIN may be surfaced + * for the given card number. Mirrors binder's TruncateNumber: the PAN + * must be exactly 16 digits and every detected scheme must be in the + * allow-list. Conservative on co-badged or ambiguous prefixes (and + * unknown schemes), which fall back to 6 digits. * @param {string} number * @return {boolean} */ public static canExpose8DigitIIN(number: string): boolean { + number = Card.parseNumber(number); // Remove potential spaces + + // PCI: 8-digit BINs are only defined for 16-digit PANs. + if (number.length != 16) + return false; + var schemes = Card.getPossibleSchemes(number); if (schemes.length == 0) return false; From 51e82b845b6f70121801eda9df4837ca465f94b1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Mon, 20 Jul 2026 08:38:25 +0200 Subject: [PATCH 5/8] v1.9.8 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 01c213d8..24836bcf 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "processout.js", - "version": "1.9.7", + "version": "1.9.8", "description": "ProcessOut.js is a JavaScript library for ProcessOut's payment processing API.", "scripts": { "build:processout": "tsc -p src/processout && uglifyjs --compress --keep-fnames --ie8 dist/processout.js -o dist/processout.js", From f2225a14bebcd3f4043cbd9cec934344687270a2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Mon, 17 Aug 2026 13:29:30 +0200 Subject: [PATCH 6/8] add 8-digit IIN field, keep card_iin at 6 --- examples/card-form/index.html | 2 +- src/dynamic-checkout/payment-methods/card.ts | 11 ++++++++--- src/processout/card.ts | 20 ++++++++++++++++---- 3 files changed, 25 insertions(+), 8 deletions(-) diff --git a/examples/card-form/index.html b/examples/card-form/index.html index 8d09bf09..6bc5e965 100644 --- a/examples/card-form/index.html +++ b/examples/card-form/index.html @@ -57,7 +57,7 @@ form.getNumberField().on("input", function (e) { if (e.card_number_length == 8) { client.getCardInformation( - e.card_iin, + e.card_iin8, function(cardInfo) { // Check for combo card types and display radio buttons if they exist if (cardInfo.combo_card_types && Array.isArray(cardInfo.combo_card_types) && cardInfo.combo_card_types.length > 0) { diff --git a/src/dynamic-checkout/payment-methods/card.ts b/src/dynamic-checkout/payment-methods/card.ts index dcc6b668..81e95c1c 100644 --- a/src/dynamic-checkout/payment-methods/card.ts +++ b/src/dynamic-checkout/payment-methods/card.ts @@ -646,7 +646,10 @@ module ProcessOut { const eventData = e.data ? JSON.parse(e.data) : {} if (eventData.action === "inputEvent") { - if (eventData.data && eventData.data.card_iin !== undefined) { + if ( + eventData.data && + (eventData.data.card_iin8 !== undefined || eventData.data.card_iin !== undefined) + ) { this.handleIinRestrictionFromMessage(eventData.data) } @@ -911,14 +914,16 @@ module ProcessOut { return } - const iin = data.card_iin || "" + // Prefer the 8-digit IIN when present so 8-digit allowlist entries can + // match; fall back to the legacy 6-digit card_iin. + const iin = data.card_iin8 || data.card_iin || "" if (iin.length === 0) { this.setCardRestrictionState(false) return } - // card_iin may carry more digits than the configured entries (IINs can + // card_iin8 may carry more digits than the configured entries (IINs can // be 6 or 8 digits), so match on prefix: an allowed entry matches when // the detected IIN starts with it. const isAllowedIin = restrictToIins.some(function (allowedIin) { diff --git a/src/processout/card.ts b/src/processout/card.ts index 8f80efe9..795be0c3 100644 --- a/src/processout/card.ts +++ b/src/processout/card.ts @@ -455,13 +455,25 @@ module ProcessOut { public static getIIN(number: string): string { number = Card.parseNumber(number); // Remove potential spaces + var l = number.length; + if (l > 6) + l = 6; + return number.substring(0, l); + } + + /** + * GetIIN8 returns the IIN of the card number, exposing up to 8 digits + * when PCI rules allow it (scheme in the allow-list and a 16-digit + * PAN) and 6 digits otherwise. + * @param {string} number + * @return {string} + */ + public static getIIN8(number: string): string { + number = Card.parseNumber(number); // Remove potential spaces + if (number.length < 6) return number; - // Only expose an 8-digit IIN when PCI rules allow it: the scheme - // must permit it and the full PAN must be exactly 16 digits. - // Everything else caps at 6 to avoid over-exposing the BIN. - // Mirrors binder's TruncateNumber / api (controllers/card_inn.go). if (Card.canExpose8DigitIIN(number)) return number.substring(0, 8); From a8edb361c08878c886c3da0818a5f8d0e05930d3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Tue, 18 Aug 2026 10:24:55 +0200 Subject: [PATCH 7/8] Update index.html --- examples/card-form/index.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/examples/card-form/index.html b/examples/card-form/index.html index 6bc5e965..2aff9d91 100644 --- a/examples/card-form/index.html +++ b/examples/card-form/index.html @@ -55,9 +55,9 @@ function (form) { let preferredCardType = null; form.getNumberField().on("input", function (e) { - if (e.card_number_length == 8) { + if (e.card_number_length == 6) { client.getCardInformation( - e.card_iin8, + e.card_iin, function(cardInfo) { // Check for combo card types and display radio buttons if they exist if (cardInfo.combo_card_types && Array.isArray(cardInfo.combo_card_types) && cardInfo.combo_card_types.length > 0) { From f5b627b4952a0c212adf67e5aa13da50296d355a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Bieszczad?= Date: Mon, 17 Aug 2026 13:31:21 +0200 Subject: [PATCH 8/8] v1.9.11 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 4b6112af..faa35f1b 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "processout.js", - "version": "1.9.10", + "version": "1.9.11", "description": "ProcessOut.js is a JavaScript library for ProcessOut's payment processing API.", "scripts": { "build:processout": "tsc -p src/processout && uglifyjs --compress --keep-fnames --ie8 dist/processout.js -o dist/processout.js",