jeffharrell / minicart

The minicart is a great way to improve your PayPal shopping cart integration.
MIT License
501 stars 209 forks source link

minicart security/fraud concern #223

Closed ronenrap closed 10 years ago

ronenrap commented 10 years ago

Hi @jeffharrell and minicart users. I'm new to this amazing script and I've successfully plugged it into my site. However I have a security/fraud concern: all the parameters in my non hosted PayPal button are in clear text. That means that anyone with a bit of html knowledge can alter the price/discount of the parameters sent to the cart. How can I prevent that from happening? Thanks in advance! RON

jeffharrell commented 10 years ago

Hey @ronenrap This is a known caveat of PayPal's plain text buttons and not specific to the minicart, so I'm closing this out. There are a few things coming down the pipeline which may solve this, but for the meantime I would suggest to verify that the amounts paid are correct before shipping.