latest stable versions: v150827 (changelog)

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Paypal – "Referencing Customer ID"

Home Forums Community Forum Paypal – "Referencing Customer ID"

This topic contains 9 replies, has 3 voices. Last updated by  Jason (Lead Developer) 4 years ago.

Topic Author Topic
Posted: Sunday Dec 16th, 2012 at 8:38 pm #34798

Hey guys,

I was wondering if there was another way to secure the “customer ids” which are sent to paypal.

Cheers
Mike

List Of Topic Replies

Viewing 9 replies - 1 through 9 (of 9 total)
Author Replies
Author Replies
Posted: Friday Dec 21st, 2012 at 9:52 pm #35297

does the paid version have some control on what is sent to paypal?

Posted: Saturday Dec 22nd, 2012 at 3:21 pm #35353
Eduan
Username: Eduan
Moderator

Hello Michael,

No with the pro version you don’t get this extra control. As I’m aware, the only non-hacky way to get the customer’s ID is by checking the replacement codes available under Dashboard -› s2Member® -› API / Notifications.

Although you would need to find it under the “event” in which you need to grab the customer ID. Although I’m not sure if s2Member offers access to this ID, you’ll have to check.

– Eduan

Posted: Saturday Dec 22nd, 2012 at 5:13 pm #35366

Actually i dont want to grab the ID i prefer if something else was sent to paypal such as the email so that if the request was intercepted it wouldn’t give out the wordpress ids

Posted: Saturday Dec 22nd, 2012 at 8:56 pm #35386
Eduan
Username: Eduan
Moderator

Ah I see. For this you would need to edit s2Member itself I’m afraid. Don’t know where though. :/
I will contact Jason about this so that he can consider this. :)

– Eduan

Posted: Saturday Dec 22nd, 2012 at 10:16 pm #35393

Thanks Eduan. I just think from a security perspective its probably best to not send the user’s id, same way we try to protect the admin id.

Posted: Sunday Dec 23rd, 2012 at 9:21 am #35431
Eduan
Username: Eduan
Moderator

Yes I understand what you mean. :)

I contacted Jason sharing this opinion, if he says anything I’ll tell you. :)

– Eduan

Posted: Sunday Dec 23rd, 2012 at 7:12 pm #35450

Thanks Eduan

Posted: Monday Dec 24th, 2012 at 3:23 pm #35476
Eduan
Username: Eduan
Moderator

No problem. :)

Posted: Friday Dec 28th, 2012 at 12:12 pm #35628
Staff Member

Thanks for the heads up on this thread.

A User’s ID is not top secret information. I’m not aware of any security issue related to the use of a Customer’s ID in transaction details sent to PayPal as a reference to that User. It would actually be more secure than sending, oh say, their email address, which would be a privacy concern for sure.

That being said, if you’d like to upgrade to s2Member Pro, with the use of Pro Form there are no payment “Buttons”, and thus there is no reason for s2Member to send a Customer ID or email address through a “Button”. In the case of s2Member Pro, all communication with PayPal is handled via the PayPal Pro API. So that would allow you to bypass any details being sent to PayPal in the button, if you prefer.

Viewing 9 replies - 1 through 9 (of 9 total)

This topic is closed to new replies. Topics with no replies for 2 weeks are closed automatically.

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Contacting s2Member: Please use our Support Center for bug reports, pre-sale questions & technical assistance.