ProductCart E-Commerce Solutions Homepage
Forum Home Forum Home > ProductCart > Customizing ProductCart
  New Posts New Posts RSS Feed - Custom Product Cart Upgrade Assistance
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Custom Product Cart Upgrade Assistance

 Post Reply Post Reply
Author
Message
J220284 View Drop Down
Newbie
Newbie


Joined: 26-January-2012
Location: New York
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote J220284 Quote  Post ReplyReply Direct Link To This Post Topic: Custom Product Cart Upgrade Assistance
    Posted: 02-April-2012 at 1:41pm
We are presently on V4 SP4 and originally had a certified Product Cart developer make some modifications to both our Payment Sequence and Shipping Display.
 
Our original developer is no longer doing Product Cart work and we are seeking someone to help us with an upgarde to the latest edition of Product cart with the following custom modifications intact.
 
1 - We hold all CC information including CVV so that we can manually review the order for Fraud in the Admin panel and then process.  Then the CVV is cleared after successful charge, per PCI guidelines. (Note: Before I get flamed for security issues, PCI specifically allows you to keep the CVV "for as long as reasonably necessary to process the transaction.")  We do have an issue in that if the Authorization fails due to error in data entry by customer (i.e. invalid card number, incorrect expiration date, or cvv), we have manually edit the Database to reset/correct the card number and would like to be able to edit it through the Payment Information screen and re-submit. [This process also allows us to add/remove items to the order and waive item and/or shipping charges as we frequently do for Active/Reserve Military.]
 
2 - We show a default "Estimated Shipping Cost" for either the item or gross weight as well as API Lookup to UPS and USPS sites for shipping charges.  We also show "Time in Transit" when available.  We have the Estimated Shipping Cost as both a default and fall back as we frequently adjust the shipping costs DOWN as the cost of shipping is lower if items weights are combined vs. their indvidiual ship weights.  We would like to improve/add some custom calculations so that we can avoid having to review each order to make sure shipping charges are as low as possible for the customer.
 
3 - We use a very simple "one page" layout showing the item and its' related accessories in the cart.  We only have ten items for sale.  The two main items display the related eight possible accessories.
 
4 - We are having some problems with Check out and Internet Explorer.  Some customers complain that when they get all the way to "submit" the page just cycles.  This has been reported at various stages of checkout.  When customers use FireFox or Chrome or Safari, there is no issue and checkout completes correctly.
 
If anyone is interested in taking on this project to either tweak our current 4.0 SP4 impelementation with a few fixes (shipping and checkout) or would like to bid on the project for performing the upgrade, please contact me.
 
 
Thank you,
 
Jason Palmer
Direct Email and Phone numbers can be found at bottom of home page on the web site.
Back to Top
Hamish View Drop Down
Admin Group
Admin Group


Joined: 12-October-2006
Location: United Kingdom
Status: Offline
Points: 56
Post Options Post Options   Thanks (0) Thanks(0)   Quote Hamish Quote  Post ReplyReply Direct Link To This Post Posted: 02-April-2012 at 2:18pm
Re the cvv - sorry to say you are mistaken. Your not allowed to store it. If it were allowable we would support it within productcart. Please feel free to check with visa! The potential liabilities are truly frightening. Just look at the news re the payment processor - if they can be compromised don't imagine for a moment your store cannot be. We do our darndest to make the software secure and pci compliant, but there are many aspects of the hosting we have zero control over.
Back to Top
J220284 View Drop Down
Newbie
Newbie


Joined: 26-January-2012
Location: New York
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote J220284 Quote  Post ReplyReply Direct Link To This Post Posted: 02-April-2012 at 2:43pm
The misunderstanding in your response is that we ONLY STORE the data PRIOR to the Authorization, it is then deleted if successful.  Technically, everyone does the exact same thing, it is just a matter of the "time" that the information is stored. Even purported "Real Time" transactions have to store the data while the payment transaction is in process - until successful.
 
"Sensitive authentication data must never be stored AFTER authorization even if this data is encrypted."

"Never store full contents of any track from the card’s magnetic stripe or chip (referred to as full track, track, track 1, track 2, or magnetic stripe data). IF REQUIRED FOR BUSINESS PURPOSES, the cardholder’s name, PAN, expiration date, and service code MAY BE STORED AS LONG AS THEY ARE PROTECTED IN ACCORDANCE with PCI DSS requirements."

This comes directly from the PCI FS Storage Requirements.
 
Data MAY be stored UP TO THE POINT OF AUTHORIZATION, then MUST be cleared.
 
Hopefully this clarifies the issue. 
 
We have solid physical and human controls so we are not concerned about an unethical staff person running off with customer Credit Card data in its' entirety during the small window when full information is visible to the peson processing the orders.
 
Thank you,
 
Jason Palmer.


Edited by J220284 - 02-April-2012 at 2:44pm
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.063 seconds.