레이아웃 scripts[] 에만 있던 원격 스크립트 차단 게이트가 다른 주입 경로에는 없어, 저장측(SafeLayoutExpressions·NoExternalUrls)이 외부 URL 저장을 422 로 막아도 런타임 디스패치 한 번으로 임의 원격 코드가 로드됐다. 저장 검증이 통째로 무의미해지는 상태였고 오류도 경고도 남지 않았다. 판정식을 support/scriptSrcPolicy.ts 로 분리해 런타임 SSoT 를 하나로 두고, loadScript 액션 · 확장 핸들러 재로드 · 편집기 프리뷰 · 편집기 자산 매니페스트 · G7Core.asset.loadScript · PG 플러그인 SDK 주입이 모두 그것을 경유하게 했다. 사본을 두지 않은 이유는 차집합이 그대로 우회로가 되기 때문이다. - 게이트는 캐시 검사보다 앞에 둔다 (뒤에 두면 이미 로드된 미신뢰 스크립트가 캐시 히트로 통과한다) - NoExternalUrls 순회를 9키로 확대 — 번들 레이아웃 601개 사전 스캔으로 정당한 외부 URL 0건을 확인한 뒤 넓혔다 (저장 회귀 없음) - callExternal 은 생성자를 참조 동일성으로 거부하고(별칭 전역 포함), 프로토타입 경로 세그먼트를 읽기·매핑 키 양쪽에서 차단한다 - PG SDK 는 서비스 SDK 라 자체 호스팅이 불가능하므로 manifest 선언 + 주입 직전 호스트 확인이 게이트다. tosspayments SDK URL 은 확장자가 없어 정적 검사에 걸리지 않아 그 런타임 확인이 유일한 게이트다 - 함께 드러난 결함: 동시 loadScript 가 로드 전에 완료 처리되던 문제, 확장 재로드에서 script 기존재가 CSS 까지 건너뛰던 문제, loadCSS 의 in-flight 미공유
160 lines
8.9 KiB
JSON
160 lines
8.9 KiB
JSON
{
|
|
"editor": {
|
|
"data_source": {
|
|
"nicepay_easy_pay_config": "Easy Pay Config",
|
|
"nicepay_escrow": "Escrow",
|
|
"nicepay_status": "Payment Status",
|
|
"nicepay_test_mode_status": "Test Mode Status",
|
|
"nicepay_test_map": "Test Payment Map",
|
|
"settings": "Payment Settings",
|
|
"vbank_info": "Virtual Account Info"
|
|
}
|
|
},
|
|
"settings": {
|
|
"title": "NicePayments Settings",
|
|
"description": "NicePayments PG integration settings",
|
|
"test_mode": "Test Mode",
|
|
"test_mode_hint": "Real card authorization/withdrawal notifications may still occur in test mode. Test account payments are batch-cancelled around 23:30 on the same day.",
|
|
"section_test_keys": "Test Key Settings",
|
|
"test_mid": "Test Merchant ID (MID)",
|
|
"test_mid_hint": "NicePayments shared test MID. No change needed for testing.",
|
|
"test_merchant_key": "Test Merchant Key",
|
|
"test_merchant_key_hint": "NicePayments shared test key. No change needed for testing.",
|
|
"section_live_keys": "Live Key Settings",
|
|
"live_mid": "Live Merchant ID (MID)",
|
|
"live_mid_hint": "Check in NicePayments merchant portal > Merchant Info > KEY Management. Enter only the part after 'SR'.",
|
|
"live_mid_example": "e.g. If your MID is SRpaytestm, enter only paytestm → Result: SRpaytestm",
|
|
"live_merchant_key": "Live Merchant Key",
|
|
"live_merchant_key_hint": "Keep this key secret.",
|
|
"live_mode_warning_title": "Live Mode Active",
|
|
"live_mode_warning_body": "Real payments are being processed. Make sure your live MID and merchant key are correctly configured.",
|
|
"section_vbank_notify": "Virtual Account Deposit Notification URL",
|
|
"vbank_notify_hint": "When using virtual accounts, register the URL below in the NicePayments merchant portal (Merchant Info settings). Deposits will be automatically notified to this address.",
|
|
"vbank_notify_copied": "URL copied to clipboard.",
|
|
"copy": "Copy",
|
|
"section_redirect": "Redirect URLs",
|
|
"redirect_success_url": "Payment Success Redirect URL",
|
|
"redirect_success_url_hint": "{shopBase} is filled in from the storefront address setting. You may also enter a full URL (https://...). {orderId} will be replaced with the actual order number.",
|
|
"redirect_fail_url": "Payment Failure Redirect URL",
|
|
"redirect_fail_url_hint": "Supports relative paths or full URLs. Error details are appended as query parameters.",
|
|
"use_escrow": "Enable Escrow Payment",
|
|
"use_escrow_hint": "Enables escrow payment for buyer protection when selling physical goods. Delivery registration is required after escrow payment.",
|
|
"section_easy_pay": "Easy Pay Settings",
|
|
"section_easy_pay_hint": "Enable the easy pay services you want to offer. Only activate services where you have a signed contract with NicePayments.",
|
|
"easy_pay_naverpay": "Naver Pay",
|
|
"easy_pay_naverpay_hint": "Available in test mode",
|
|
"easy_pay_kakaopay": "Kakao Pay",
|
|
"easy_pay_samsungpay": "Samsung Pay",
|
|
"easy_pay_applepay": "Apple Pay",
|
|
"easy_pay_applepay_hint": "Available on Safari and Apple devices only",
|
|
"easy_pay_payco": "PAYCO",
|
|
"easy_pay_skpay": "11pay (SK Pay)",
|
|
"easy_pay_ssgpay": "SSG Pay",
|
|
"easy_pay_lpay": "L.pay",
|
|
"easy_pay_allow_with_other_pg": "Allow with other PG",
|
|
"easy_pay_allow_with_other_pg_hint": "When enabled, NicePay easy pay buttons will appear on the checkout page even when another PG is set as the default payment provider."
|
|
},
|
|
"admin": {
|
|
"transaction_query_title": "TID Transaction Query",
|
|
"transaction_query_description": "Query payment status directly using a NicePayments transaction ID (TID).",
|
|
"transaction_tid_label": "Transaction ID (TID)",
|
|
"transaction_query_button": "Query",
|
|
"transaction_query_error": "Query Failed",
|
|
"transaction_result_title": "Query Result",
|
|
"result_tid": "Transaction ID (TID)",
|
|
"result_order_id": "Order ID (Moid)",
|
|
"result_amount": "Amount",
|
|
"result_status": "Payment Status",
|
|
"result_method": "Payment Method",
|
|
"result_auth_code": "Authorization Code",
|
|
"result_auth_date": "Authorization Date",
|
|
"result_result_code": "Result Code",
|
|
"order_verify_title": "NicePayments Verification",
|
|
"order_verify_description": "Query real-time payment status from NicePayments server.",
|
|
"order_verify_button": "Verify",
|
|
"order_verify_error": "Query Failed",
|
|
"pay_status_approved": "Approved",
|
|
"pay_status_cancelled": "Cancelled",
|
|
"pay_status_unknown": "Unknown",
|
|
"vbank_noti_title": "Virtual Account Deposit Notifications",
|
|
"vbank_noti_description": "Audit log of NicePay deposit notifications (auto-accumulated)",
|
|
"vbank_noti_count": "Notification count",
|
|
"vbank_noti_first_at": "First received",
|
|
"vbank_noti_last_at": "Last received",
|
|
"vbank_noti_deposited_at": "Deposit confirmed at",
|
|
"vbank_noti_cancelled_at": "Deposit cancelled at",
|
|
"vbank_noti_depositor": "Depositor (last)",
|
|
"vbank_noti_history": "History (chronological)",
|
|
"vbank_noti_type_deposited": "Deposited",
|
|
"vbank_noti_type_cancelled": "Cancelled",
|
|
"vbank_noti_type_other": "Other",
|
|
"vbank_noti_query_button": "Load notification log",
|
|
"vbank_noti_loading": "Loading...",
|
|
"vbank_noti_not_loaded": "Click the button to view the NicePay deposit notification log.",
|
|
"vbank_noti_empty": "No deposit notifications received.",
|
|
"vbank_noti_load_error": "Failed to load notification log.",
|
|
"escrow_badge": "Escrow",
|
|
"result_escrow": "Escrow",
|
|
"escrow_yes": "Escrow Payment",
|
|
"escrow_no": "Regular Payment",
|
|
"escrow_payment_notice": "This is an escrow payment. Buyer confirmation is required after delivery registration.",
|
|
"escrow_delivery_title": "Escrow Delivery Registration",
|
|
"escrow_delivery_company": "Courier Company",
|
|
"escrow_delivery_company_placeholder": "e.g. FedEx",
|
|
"escrow_tracking_number": "Tracking Number",
|
|
"escrow_tracking_number_placeholder": "Enter tracking number",
|
|
"escrow_buyer_address": "Delivery Address",
|
|
"escrow_register_name": "Registrant Name",
|
|
"escrow_register_button": "Register Delivery",
|
|
"escrow_register_success": "Escrow delivery has been registered.",
|
|
"escrow_register_error": "Failed to register escrow delivery.",
|
|
"test_mode_badge": "TEST",
|
|
"test_mode_order_notice": "This order was processed in test mode. Real card authorization/withdrawal notifications may occur, but NicePayments test account payments are batch-cancelled around 23:30 on the same day. Verify live payment status before shipping.",
|
|
"test_mode_settings_warning_plugin": "NicePayments",
|
|
"test_mode_settings_warning_title": "Warning: NicePayments is currently set to test mode.",
|
|
"test_mode_settings_warning_body": "Test payments do not create real payments. If the shop is live, switch this plugin to live payment mode before operating.",
|
|
"test_mode_settings_warning_action": "Switch to live mode",
|
|
"test_mode_orders_in_list": "Test payment orders included"
|
|
},
|
|
"easy_pay": {
|
|
"section_title": "Easy Pay"
|
|
},
|
|
"user": {
|
|
"receipt_label": "Receipt",
|
|
"view_receipt": "View Receipt",
|
|
"view_cash_receipt": "View Cash Receipt",
|
|
"easy_pay_label": "Easy Pay",
|
|
"test_mode_badge": "TEST",
|
|
"tax_breakdown_title": "Tax Breakdown",
|
|
"supply_amount": "Supply Amount",
|
|
"vat_amount": "VAT",
|
|
"tax_free_amount": "Tax-Free Amount",
|
|
"vbank_deposit_info": "Virtual Account Deposit Info",
|
|
"vbank_bank": "Bank",
|
|
"vbank_account": "Account Number",
|
|
"vbank_holder": "Account Holder",
|
|
"vbank_amount": "Deposit Amount",
|
|
"vbank_due": "Deposit Due",
|
|
"vbank_notice": "If deposit is not completed by the due date, the order will be auto-cancelled."
|
|
},
|
|
"messages": {
|
|
"refund": {
|
|
"missing_tid": "Payment transaction ID (TID) is missing.",
|
|
"default_reason": "Admin refund"
|
|
},
|
|
"payment": {
|
|
"auth_failed": "Payment authentication failed.",
|
|
"mid_mismatch": "Merchant ID does not match.",
|
|
"signature_mismatch": "Payment signature verification failed.",
|
|
"order_not_found": "Order not found.",
|
|
"amount_mismatch": "Payment amount does not match.",
|
|
"authorize_failed": "Payment authorization failed."
|
|
}
|
|
},
|
|
"payment": {
|
|
"error": {
|
|
"sdk_url_untrusted": "The payment module address is not valid, so the payment cannot proceed. Please contact the administrator."
|
|
}
|
|
}
|
|
}
|