HostedCheckoutScreen
Renders one hosted gateway's checkout page and watches every navigation for the return-URL pattern. docs: https://github.com/KevinnZou/compose-webview-multiplatform — state.lastLoadedUrl is the interception point; the moment matchReturn recognizes a redirect as terminal, onResult fires exactly once (the reported guard survives re-navigation inside the same page load).
SECURITY: SSL/certificate errors fail closed via sslFailClosedWebViewParams — its Android actual cancels the load and reports HostedReturnOutcome.Failure through onResult; never call handler.proceed() — a flaky regional cert is not a reason to bypass certificate validation on a checkout page.
NOT on every platform. Check sslFailClosedSupported before opening this screen for a payment session: it is false on iOS, where this module installs no TLS handling at all. This composable does not gate itself on it, because refusing to render, falling back to a native SDK or accepting the risk is the caller's policy decision, not this module's.