liberapay / liberapay.com

Source code of the recurrent donations platform Liberapay
https://liberapay.com/
1.67k stars 215 forks source link

Stripe's JavaScript isn't open source #1279

Open Changaco opened 6 years ago

Changaco commented 6 years ago

With Mangopay all the code running in the user's browser was open source, Stripe.js isn't.

Changaco commented 6 years ago

It looks like it would be problematic to fix this by using our own JavaScript like we did with Mangopay, because it would reduce Stripe's ability to detect and block fraudulent payment attempts, and we would have to fill a lengthy SAQ A-EP every year instead of signing a simple pre-filled SAQ A (see Stripe's guide on PCI compliance). (Mangopay never asked us to submit any PCI related paperwork, or any other security assessment.)

asddsaz commented 5 years ago

Isn't Braintree also free software? https://github.com/braintreeps