PayPal error on many subscription purchases/renewals

6 years 8 months ago #296548 by edjec
Hi Beat,

I have reported it to PayPal, but haven't received a reply yet. I have also discovered that the issue is present with DT Reg, which we use for event registration. CB uses PayFlow, while DT Reg uses PayPal Standard, so this is clearly a PayPal issue and may be systemic.

I (we) appreciate your willingness to help, but correcting for this PayPal issue may only create a verification issue within CB.

If I receive a reply and/or correction from PayPal, I will report it here.

Thanks for your response!

Please Log in to join the conversation.

6 years 8 months ago #296549 by petekuhn
Thanks,

I did contact paypal support and put two support tickets onto their merchant technical support website.

I got one reply already stating that they pushed out a fix last night, and asking if it resolved my problem.

Since there's been only two transactions since then, I told them I couldn't tell.

I've asked them what the point of item name match based fraud detection would be for us, since our store consists of only three items, each of which has a unique price.

Please Log in to join the conversation.

6 years 8 months ago #296555 by petekuhn
Here's the first paypal merchant tech support response to my question about why use item name match checking for fraud prevention:

"Are you saying that Joomla is implementing some sort of fraud protection on their end which checks the item name? And what are they checking it against?

"Any fraud system they are implementing is on their end. I am not sure why they would be doing an item name check from PayPal's point of view.

"Sincerely,

"Colin
"Global Technical Support
"PayPal"

Please Log in to join the conversation.

6 years 8 months ago #296556 by beat

petekuhn wrote: Here's the first paypal merchant tech support response to my question about why use item name match checking for fraud prevention:

"Are you saying that Joomla is implementing some sort of fraud protection on their end which checks the item name? And what are they checking it against?

"Any fraud system they are implementing is on their end. I am not sure why they would be doing an item name check from PayPal's point of view.

"Sincerely,

"Colin
"Global Technical Support
"PayPal"


I guess Paypal should check their own instructions: Checking destination, price, currency, and item bought are standard paypal guidelines since over 10 years, e.g.:

developer.paypal.com/docs/classic/ipn/ht_ipn/
"Verify the item description and transaction costs with those listed on your website and catalog."

www.paypal.com/en/cgi-bin/webscr?cmd=p/acc/ipn-info-outside
"Check other transaction details such as the item number and price to confirm that the price has not been changed"

If a cart does not verify item description, a rogue user could tamper it and then accuse you to have given cheaper plan instead of the one they bought showing their paypal description. In your case, without checking the description, a rogue user could select to buy your cheapest plan, then tamper description to most expensive premium plan, pay at paypal and then come back and say "i bought premium plan", see my paypal invoice, and get you into administrative or legal troubles.

Also for your accounting and auditing, it's important that in your paypal reports the items bought appear instead of "Shopping cart" to be able to more easily audit your accounts and reconciliate your records.

So it's still a severe Paypal bug.

I'm still looking to add a safe enough workaround to this paypal.com bug, and it should be in next nightly.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

6 years 8 months ago #296561 by petekuhn
Hi,

Thanks so much for your attention.

The message I got was just one Paypal tech's response, I may get a second and forward that too.

Please bear in mind that they're saying they've addressed the current problem, so it's not so pressing that you need to get on it right away.

I don't know how many orgs you have as customers who would never be concerned about the possibility of item name changing fraud, but we're one. We know almost every one of our members, because we are a club where everyone is physically present. We do get fraudsters on the internet, but they try to hack our site to sell boner pills, or use our site to validate stolen credit cards, etc., they don't buy memberships. You have to physically show up to benefit from our memberships, the stuff on our website isn't more valuable based on your membership.

If you decide to make a configurable fraud prevention suite, we'd be overjoyed. But we recognize that would take time. We'd be happy to pay for part of it, but there may not be enough orgs like us as your customers to make this work for you and orgs like us.

Please Log in to join the conversation.

6 years 8 months ago #296566 by beat
CBSubs nightly released.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.231 seconds

Facebook Twitter LinkedIn