Skip to content

Conversation

@arjun-dureja
Copy link
Collaborator

What changed? Why?

  • The Cross-Origin-Opener-Policy for the /pay route specifically needs to be set to unsafe-none because this route needs to be opened by keys.coinbase.com. It's currently set to same-origin-allow-popups which causes a browser error when we try to open it

Notes to reviewers

How has it been tested?

  • Manually.

On /pay:
Screenshot 2025-09-30 at 3 36 17 PM

On all other routes:

Screenshot 2025-09-30 at 3 36 03 PM

Have you tested the following pages?

BaseWeb

  • base.org
  • base.org/names
  • base.org/builders
  • base.org/ecosystem
  • base.org/name/jesse
  • base.org/manage-names
  • base.org/resources

@cb-heimdall
Copy link
Collaborator

cb-heimdall commented Sep 30, 2025

✅ Heimdall Review Status

Requirement Status More Info
Reviews 1/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

@vercel
Copy link

vercel bot commented Sep 30, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
base-web Ready Ready Preview Comment Sep 30, 2025 7:43pm

@arjun-dureja arjun-dureja merged commit 9bf15ee into master Oct 7, 2025
11 checks passed
@arjun-dureja arjun-dureja deleted the arjun/update-coop-header branch October 7, 2025 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants