Files
Gnuboard7/plugins/_bundled/sirsoft-tosspayments/resources/lang/en.json
T
HeuJung 1e89335258 fix(core,extensions): 동적 스크립트 주입 경로 전부에 출처 게이트 적용
레이아웃 scripts[] 에만 있던 원격 스크립트 차단 게이트가 다른 주입 경로에는
없어, 저장측(SafeLayoutExpressions·NoExternalUrls)이 외부 URL 저장을 422 로
막아도 런타임 디스패치 한 번으로 임의 원격 코드가 로드됐다. 저장 검증이
통째로 무의미해지는 상태였고 오류도 경고도 남지 않았다.

판정식을 support/scriptSrcPolicy.ts 로 분리해 런타임 SSoT 를 하나로 두고,
loadScript 액션 · 확장 핸들러 재로드 · 편집기 프리뷰 · 편집기 자산 매니페스트 ·
G7Core.asset.loadScript · PG 플러그인 SDK 주입이 모두 그것을 경유하게 했다.
사본을 두지 않은 이유는 차집합이 그대로 우회로가 되기 때문이다.

- 게이트는 캐시 검사보다 앞에 둔다 (뒤에 두면 이미 로드된 미신뢰 스크립트가
 캐시 히트로 통과한다)
- NoExternalUrls 순회를 9키로 확대 — 번들 레이아웃 601개 사전 스캔으로
 정당한 외부 URL 0건을 확인한 뒤 넓혔다 (저장 회귀 없음)
- callExternal 은 생성자를 참조 동일성으로 거부하고(별칭 전역 포함),
 프로토타입 경로 세그먼트를 읽기·매핑 키 양쪽에서 차단한다
- PG SDK 는 서비스 SDK 라 자체 호스팅이 불가능하므로 manifest 선언 +
 주입 직전 호스트 확인이 게이트다. tosspayments SDK URL 은 확장자가 없어
 정적 검사에 걸리지 않아 그 런타임 확인이 유일한 게이트다
- 함께 드러난 결함: 동시 loadScript 가 로드 전에 완료 처리되던 문제,
 확장 재로드에서 script 기존재가 CSS 까지 건너뛰던 문제, loadCSS 의
 in-flight 미공유
2026-09-02 21:43:13 +09:00

100 lines
5.1 KiB
JSON

{
"editor": {
"data_source": {
"settings": "Payment Settings"
}
},
"plugin_name": "TossPayments",
"plugin_description": "TossPayments gateway (integrated payment window)",
"settings": {
"title": "TossPayments Settings",
"description": "Configure TossPayments API keys.",
"test_mode": "Test Mode",
"test_mode_hint": "No real payments occur in test mode.",
"test_client_key": "Test Client Key",
"test_client_key_hint": "Found in Developer Center > API Keys",
"test_secret_key": "Test Secret Key",
"test_secret_key_hint": "Keep this key secret.",
"live_client_key": "Live Client Key",
"live_secret_key": "Live Secret Key",
"live_secret_key_hint": "Keep this key secret.",
"section_test_keys": "Test API Keys",
"section_live_keys": "Live API Keys",
"section_redirect": "Redirect Settings",
"redirect_success_url": "Payment Success Redirect URL",
"redirect_success_url_hint": "{shopBase} is filled in from the storefront address setting. You may also enter a full URL (https://...). {orderId} will be replaced with the actual order number.",
"redirect_fail_url": "Payment Failure Redirect URL",
"redirect_fail_url_hint": "{shopBase} is filled in from the storefront address setting. You may also enter a full URL. Error details (error, message, orderId) are appended as query parameters.",
"save": "Save",
"saved": "Settings saved.",
"section_payment_methods": "Payment Methods",
"order_sheet_mode": "Order-sheet Mode",
"order_sheet_mode_hint": "When ON, payment methods are chosen at checkout. When OFF, a single TossPayments integrated window (card) is used.",
"enabled_methods": "Methods to Show",
"enabled_methods_hint": "Select the payment methods shown at checkout in order-sheet mode.",
"method_card": "Card",
"method_virtual_account": "Virtual Account",
"method_transfer": "Bank Transfer",
"method_mobile_phone": "Mobile Phone",
"method_tosspay": "TossPay",
"method_kakaopay": "KakaoPay",
"method_naverpay": "NaverPay",
"method_payco": "PAYCO",
"method_samsungpay": "Samsung Pay",
"section_virtual_account": "Virtual Account",
"vbank_valid_hours": "Valid Hours",
"vbank_valid_hours_hint": "Hours available for deposit after issuing a virtual account. Max 2160 (90 days).",
"vbank_cash_receipt_type": "Auto Cash Receipt Type",
"vbank_cash_receipt_type_hint": "Cash receipt type TossPayments auto-issues when a virtual account is created.",
"vbank_cash_receipt_none": "Do not issue",
"vbank_cash_receipt_income": "Income deduction",
"vbank_cash_receipt_expense": "Expense proof",
"use_escrow": "Use Escrow",
"use_escrow_hint": "Applies to virtual account and bank transfer only.",
"use_escrow_off": "Off",
"use_escrow_on": "Force on",
"use_escrow_buyer_choice": "Buyer choice",
"escrow_no_partial_cancel_notice": "Escrow orders cannot be partially cancelled. Only full cancellation is available.",
"escrow_shipping_info_notice": "Register shipping information in the TossPayments merchant console.",
"escrow_shipping_info_link": "Open ↗",
"webhook_secret_verify": "Webhook Secret Verification",
"webhook_secret_verify_hint": "Verifies the deposit webhook secret against the payment confirmation response to block forged requests.",
"webhook_url_label": "Deposit Webhook URL",
"webhook_url_hint": "Prefix this path with your store's full domain (https://your-domain) and register it as a DEPOSIT_CALLBACK event in the TossPayments Developer Center > Webhook menu.",
"webhook_url_copy": "Copy",
"webhook_url_copied": "Webhook URL copied."
},
"payment_error_title": "Payment Error",
"payment_cancel_title": "Payment Cancelled",
"payment_cancelled_message": "Payment has been cancelled. Please try again or choose a different payment method.",
"errors": {
"confirm_failed": "Payment confirmation failed.",
"amount_mismatch": "Payment amount does not match.",
"order_not_found": "Order not found.",
"payment_failed": "Payment failed.",
"non_krw_method": "This payment method is available for KRW payments only."
},
"user": {
"payment_type_label": "Payment type",
"escrow_yes": "Escrow",
"receipt_label": "Receipt",
"receipt_view": "View receipt",
"cash_receipt_label": "Cash receipt",
"cash_receipt_view": "View cash receipt"
},
"admin": {
"payment_panel_title": "TossPayments payment info",
"escrow_label": "Payment type",
"escrow_yes": "Escrow",
"vbank_label": "Virtual account",
"vbank_due_label": "Deposit deadline",
"receipt_label": "Receipt",
"receipt_view": "View receipt"
},
"payment": {
"error": {
"sdk_url_untrusted": "The payment module address is not valid, so the payment cannot proceed. Please contact the administrator."
}
}
}