Protect payment credentials
- PayPal client secret is server-only and injected at runtime; it is never committed, logged, serialized to the browser, or embedded in static output.
- The browser sends intent and cart identifiers, not prices trusted for capture. The BFF reconstructs and validates amounts from the static catalog.
- The BFF permits only PayPal Sandbox endpoints for the MVP and uses timeouts, error mapping, and correlation IDs without sensitive payloads.
- Confirmation displays the minimum non-sensitive reference and Sandbox status.
- Source evidence contains public observations only; no AliExpress account credentials or automated runtime calls are needed.
Production credentials and live payments require a separate threat model, secret-management review, compliance decision, and go-live approval.