PayPal BFF components
| Component | Responsibility |
|---|---|
| Create-order route | Validate item identifiers and quantities, reconstruct trusted totals, and request a Sandbox order. |
| Capture-order route | Validate the order reference and capture through PayPal Sandbox. |
| PayPal client | Acquire a server-side access token, apply timeouts, and map vendor failures without exposing credentials. |
| Catalog pricing boundary | Reject unknown items and browser-supplied prices. |
Production endpoints are prohibited. Runtime configuration must explicitly select sandbox and provide credentials through the approved secret path.