Results 1 to 5 of 5
  1. #1
    Join Date
    Nov 2007
    Posts
    21
    Plugin Contributions
    0

    Default Paypal Express versus admin profiles

    I have a store with 1.5.1 and Paypal Express configured. Both are working as they should.

    In configuring admin profiles I want to limit access to the giving out of refunds - but this does not appear a possibility within the present package. Paypal IPN is included as an optional access in admin profiles but ticking that box makes no difference to whether a user can do refunds.

    In other words, I want everyone to see the Paypal transaction is authorised (or not) in orders but only the chosen few to be able to actually press the repay button. This division of responsibilities would appear to be entirely within the spirit of admin profiles and PCI compliance.

    Any help appreciated.

    Thanks

  2. #2
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,761
    Plugin Contributions
    9

    Default Re: Paypal Express versus admin profiles

    Breaking down access to specific portions of elements would require additional custom code

    PayPal has nothing to do with PCI compliance
    Zen-Venom Get Bitten

  3. #3
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Paypal Express versus admin profiles

    The PayPal IPN menu option you mention is simply the item on the Customers->PayPal IPN menu which shows you information about notifications received from Paypal indicating that transactions have happened.

    As kobra said, the menu controls presently only control access "to the page", not to its individual parts.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Nov 2007
    Posts
    21
    Plugin Contributions
    0

    Default Re: Paypal Express versus admin profiles

    Quote Originally Posted by DrByte View Post
    The PayPal IPN menu option you mention is simply the item on the Customers->PayPal IPN menu which shows you information about notifications received from Paypal indicating that transactions have happened.

    As kobra said, the menu controls presently only control access "to the page", not to its individual parts.


    Thanks for the speedy update. To be able to split these elements does seem sensible - thus limiting 'who can do what' - in line with Admin Profiles. It seems odd that I can limit who sees a report but if someone handles sales in any way they can also refund Paypal receipts, literally at the press of a button.

    Anybody got any pointers as to how separating out the refund portion might be achieved? What would need to be done?

  5. #5
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Paypal Express versus admin profiles

    Quote Originally Posted by peterdd View Post
    Anybody got any pointers as to how separating out the refund portion might be achieved? What would need to be done?
    Ya; it's a pretty huge job:
    a) write a bunch of additional infrastructure for identifying miniscule sections of pages and storing info about those sections in the database
    b) build all the logic in every admin page to link each of those sections to display blocks
    c) build logic to lookup permissions for each section, ensuring that you don't blow out database queries by doing excessive additional lookups all over the page
    d) build a UI to allow control over every one of those things including what actions to take if permission is denied
    e) build in security protections to ensure there's no way to "trick" the system into doing the unauthorized things if attempted covertly
    f) rewrite all admin-connected plugins to support all the extensive changes made to admin pages, both core and non-core
    and so on
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. Paypal payments pro versus simple paypal buttons
    By NJR21 in forum PayPal Website Payments Pro support
    Replies: 2
    Last Post: 23 Dec 2011, 12:04 PM
  2. In Admin/Payment/PayPal Express Checkout what should order status be?
    By spterry in forum PayPal Express Checkout support
    Replies: 2
    Last Post: 9 Mar 2010, 01:20 AM
  3. Admin Profiles and/or Admin Activity? What do I need?
    By Dunk in forum All Other Contributions/Addons
    Replies: 5
    Last Post: 8 Feb 2010, 04:11 PM
  4. PayPal standard versus express. How successful?
    By AUTOMOBILIA in forum General Questions
    Replies: 15
    Last Post: 7 Nov 2009, 01:29 AM
  5. PayPal Express Checkout: Admin sees order but Paypal does not
    By MeltDown in forum PayPal Express Checkout support
    Replies: 12
    Last Post: 8 Mar 2009, 11:50 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR