API basket shopper chain scope (1.7.0)
A security improvement to the way add-basket and get-basket-price identify the shopper from the spaaza_user_id field of the user object.
- Fixed the resolution of the shopper from
spaaza_user_idso that the shopper must belong to the chain identified in the request. Aspaaza_user_idof a shopper in another chain is now treated as not found: the basket is processed as an anonymous basket and, from API version 1.5.2, the response carries auser_not_foundwarning, exactly as for an unknown ID. Previously such a request could attach the shopper from the other chain to the basket. Themember_numberandauthentication_point_identifierfields were already limited to the chain of the request and are unchanged. This change is not tied to an API version. See shopper identification fields.