Skip to main content

Protect payment credentials

  • PayPal client secret is server-only and injected at runtime; it is never committed, logged, serialized to the browser, or embedded in static output.
  • The browser sends intent and cart identifiers, not prices trusted for capture. The BFF reconstructs and validates amounts from the static catalog.
  • The BFF permits only PayPal Sandbox endpoints for the MVP and uses timeouts, error mapping, and correlation IDs without sensitive payloads.
  • Confirmation displays the minimum non-sensitive reference and Sandbox status.
  • Source evidence contains public observations only; no AliExpress account credentials or automated runtime calls are needed.

Production credentials and live payments require a separate threat model, secret-management review, compliance decision, and go-live approval.