#JacksonStorm

1 messages · Page 1 of 1 (latest)

dusk wolfBOT
lusty gate
#

👋 happy to help

#

the client_secret is only used to confirm a Payment/Setup Intent

#

there's no security issue with exposing it on the frontend

brave lava
#

Right... Ok.
Is it normal that is exposed?

Any suggestions to hide it?

#

I fear customers will freak out.

lusty gate
#

is it being displayed in the UI?

brave lava
#

In the URL

#

It's injecting into the confirmation page url

lusty gate
#

yes this is expected and there's no risk

brave lava
#

Ok... Seems strange.

#

I think my customers will report it as a security error .... "Client secret" doesn't seem expected

lusty gate
#

It has been used for quite sometime and no one ever came back with this feedback to be honest

brave lava
#

☺️

#

That's good enough for me.

lusty gate
#

let me know if you need any more help

brave lava
#

Can I share full url with you here so you can eyes over

#

Make sure nothing else random injected?

lusty gate
#

yes please do

lusty gate
#

looks good

brave lava
#

Superstar Tarzan.
Made my day.

lusty gate
#

let me know if you need any more help