Friday, September 25, 2026
2 changes · 18.0
Enhancements to existing features
Xendit payments are updated to use Xendit's newer hosted payment flow because older payment endpoints are being retired. Customers will now be redirected to Xendit's payment page for all payment methods, while existing saved card tokens remain supported and administrators are warned to update webhook settings.
Original PR description
Xendit is deprecating the v2/invoices and credit_card_charges endpoints for new payments. This switches checkout and card sessions to the Payment Sessions API (/sessions) and charges v3 tokens…
Xendit is deprecating the v2/invoices and credit_card_charges endpoints for
new payments. This switches checkout and card sessions to the Payment
Sessions API (/sessions) and charges v3 tokens through /v3/payment_requests,
while still charging pre-existing v2 tokens through the legacy
credit_card_charges endpoint, as there is no migration path for them.
- the inline card form, its direct flow, and the Xendit SDK are removed; all
payment methods now redirect to the Xendit-hosted payment link
- a v3 token charge that unexpectedly still requires 3DS exposes the
authentication URL as a processing value; the frontend navigates the top
window to it directly, since Xendit's challenge page must be top-level and
only accepts GET
- a customer returning from checkout, or from a 3DS challenge, is checked
directly against Xendit before falling back to pending, in case the
webhook is delayed or dropped
- webhook payloads are unwrapped from their {event, data} envelope, and
transactions are looked up by reference_id, falling back to external_id
for legacy charges and to a suffix-stripped reference_id otherwise
Upgrade / stable-version compatibility:
- the inline_form view is emptied rather than removed (it's noupdate, and
ondelete='restrict' would abort the module update otherwise); it is never
rendered
- xendit_public_key is kept but unused, and several touched methods keep
their old name or signature (_xendit_make_request, _xendit_create_charge,
_xendit_prepare_invoice_request_payload, _get_redirect_form_view, the
/payment/xendit/payment route), since partners may override them and a
stable version can't drop or break an override
- bump the module version so partners upgrading notice the change
Webhook migration notice:
Xendit replaced the single webhook field with separate v3 event groups, so
already-configured databases silently stop receiving updates. Remind admins
once via the daily autovacuum cron (works without an upgrade or a new
ir.cron record), tracked through the payment_xendit.v3_notification_sent
system parameter so it's only sent once.
Task-6373405The update prevents non-French companies from being checked against the French business directory when validating electronic invoicing endpoints, even if they have French-style identifiers recorded. This reduces incorrect validation attempts and helps international partner setup work more smoothly.
Original PR description
for non-french partners, a check on the annuaire shouldnt happen when checking their endpoints, even if they have a siren/siret related-task-id-6327357