Skip to main content

API basket shopper chain scope (1.7.0)

Sam Critchley
Co-Founder

A security improvement to the way add-basket and get-basket-price identify the shopper from the spaaza_user_id field of the user object.

  • Fixed the resolution of the shopper from spaaza_user_id so that the shopper must belong to the chain identified in the request. A spaaza_user_id of a shopper in another chain is now treated as not found: the basket is processed as an anonymous basket and, from API version 1.5.2, the response carries a user_not_found warning, exactly as for an unknown ID. Previously such a request could attach the shopper from the other chain to the basket. The member_number and authentication_point_identifier fields were already limited to the chain of the request and are unchanged. This change is not tied to an API version. See shopper identification fields.