202ecommerce / paypal

This repository is for developpers only. To install and upgrade the module in a production shop please install the package via PrestaShop Marketplace by following this link:
https://addons.prestashop.com/fr/paiement-carte-wallet/1748-paypal-officiel.html
Academic Free License v3.0
20 stars 31 forks source link

Prove this project is endorsed by PayPal #331

Open fulldecent opened 5 months ago

fulldecent commented 5 months ago

Describe the bug and add screenshots

Currently, this project is named as the "official" PayPal module. However the project is not published by PayPal.

Please provide documentation from PayPal (i.e. on their website or published from a domain they control) recognizing this project as being official on behalf of that company.

clotairer commented 5 months ago

@202ecommerce is mandated by PayPal to develop and maintain the official opensource module for PrestaShop. The name of the module is choosen by PayPal. This repository is authorized by PayPal to communicate with the community of PrestaShop developers who want to contribute by declaring an issue or create a pull request. As you can see, this repository is a fork of the archive repo https://github.com/PrestaShopCorp/paypal maintain by PrestaShop him self un the past.

IMPORTANT: For marchands who want to trustly use this module in production install and upgrade it, we recommand to download it on the PrestaShop Marketplace at this address: https://addons.prestashop.com/en/payment-card-wallet/1748-paypal-official.html . Please note this is the same zip you’ll found on each release. Moreover PrestaShop Marketplace team supply a security validation before each publication.

If you have any questions or doubt about this repository, you can obviously contact PayPal module support on the form in the PrestaShop marketplace but 202ecommerce assume the support of the module or directly PayPal helpdesk.

Regards. Clotaire - CTO 202-ecommerce

fulldecent commented 5 months ago

Thank you for taking an interest in proving that this is officially supported by PayPal.

However, your response does not actually prove that this project is supported by PayPal.

It is just as easy for me to also fork the original repository. Of course that does not make my repository official.

Do you have any official statement from PayPal endorsing this project?

Please reopen this issue since you acknowledged that it is important and it is not yet addressed

clotairer commented 5 months ago

I reopen this issue. I suggest you to contact PayPal (and PrestaShop) to get information you need. I supply you all information about the supply chain of this module. In the meantime, I’ll contact PayPal team. Only PayPal can send you a proof.

fulldecent commented 5 months ago

Thank you. And our goal here is for PayPal to send proof to everyone. By publishing a link on their website or a public communication from their other official channels.

clotairer commented 5 months ago

PayPal supply us this like that point to the module on PrestaShop marketplace.

This repository supply the package of the module readay to downlaod on the PrestaShop Marketplace. To be sure all files of the zip is the same we add on each release for instance release 6.4.0 a v6.4.0-prod-paypal.md5 file that list all MD5 hash of file. So anyone can compare the integrity of all files from this repository and the publication on the PrestaShop MarketPlace. (The fist goal was to detect any integrity issue on an installed package but it can be use to prove this is the same code than the Marketplace).

fulldecent commented 5 months ago

Got it. Thank you for explaining.

At this point, I think labeling this project as "official" from PayPal is unsupported by the shown evidence.

clotairer commented 4 months ago

Hi, I exchange with PayPal team today. A page on developper Paypal website await an approval to link this repository. Moreover, as already explain the name of the module is the choice of PayPal that never claim this repository is not the official module. That’s why we will not change the name. We work step by step to obtain an official link. It take time… sorry for that. To be continued.