#krutarth
1 messages · Page 1 of 1 (latest)
I don't know what you mean by validity
does clientSecret expires?
Not that I know of, no.
So basically I would be able to store the clientSecret in the database and use it later right?
Yup!
Alright, and if it gets leaked, what possible repurcussions may happen?
It's more or less available to people via the browser when they check out, so it's not entirely hidden all the time. It doesn't have a huge material impact most of the time, but some bad actors can use it to do card testing if you haven't used any other mitigation strategies: https://stripe.com/docs/disputes/prevention/card-testing