Fraud SDK Java 3.0.0

Breaking changes

  • Refactor the SDK as a client generated from the Account Protect OpenAPI specification, replacing the previous hand-written implementation
  • Update client setup to a builder pattern with Client.builder(...), replacing the previous service and options classes
  • Update event submission to one dedicated class per operation instead of a single service with validate and collect methods
  • Update payload construction to per-event builders instead of the previous event builders
  • Update payload validation to run at build time and fail on missing required fields, so the login status must now be set explicitly instead of being inferred from validate versus collect
  • Update request field overrides to a RequestMetadata object passed alongside the request instead of mutating an extracted request wrapper
  • Update error handling to checked exceptions instead of a response status field, though validate calls still fail open and allow while collect and feedback calls now throw
  • Remove the previous response and action-type classes for Response and ResponseAction, dropping the allowed, denied, and status helper methods
  • Update the address, title, and authentication model classes with new names, and give each event its own user type instead of a shared one
  • Update list and date fields in the models to standard list and string representations instead of arrays and date objects
  • Remove asynchronous validate and collect calls
  • Remove the forwarded-header configuration option and its header parsing
  • Remove support for non-servlet requests

Other changes

  • Add support for custom events with ValidateCustom and CollectCustom
  • Add support for the feedback endpoint
  • Add account type, account creation date, custom fields, and fail reason to the event payloads