Answer the question
In order to leave comments, you need to log in
Where is the safest place to store request_id to repeat process-external-payment?
In accordance with the documentation Accepting payments from bank cards without authorization
Note that the application may need to call the process-external-payment method again. The method should be called until the completion of the payment process. This may require additional user action in the WebView.
Answer the question
In order to leave comments, you need to log in
When request-payment or request-external-payment is called, each time a new request_id will be generated and issued in response to these requests, it can be stored in cookies.
It will not be possible to repeat the write-off twice through request_id, so the value itself will not make the weather worse for an attacker.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question