Results 1 to 2 of 2
  1. #1
    Join Date
    Dec 2015
    Location
    Florida
    Posts
    1
    Plugin Contributions
    0

    Default Double Credit Card Charges for the same Sales Order using Authorize.net SIM

    There is a bug that allows double charging the same Sales Order when using Authorize.net SIM. The customer reports that they received a session timeout on ZenCart while on the Authorize.net payment page. They did not get routed to a payment confirmation webpage, however they were billed and received an authorize.net payment receipt. However this (first) authorization code was NOT captured by ZenCart status history. They went back to the cart and found it still populated and again attempted payment. This time ZenCart captured the payment and authorization code in order status history and a payment confirmation webpage was received by the customer. The time stamps between the two authorization codes/billings from authorize.net was just under 5 minutes. There was no alert of the double billing in ZenCart and we discovered it only when the customer contact us.

    There are no modifications to the authorize.net scripts (ZenCart v 1.5.3).

  2. #2
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Double Credit Card Charges for the same Sales Order using Authorize.net SIM

    Seems the bug is in whatever caused your customer to encounter a "timeout" ... because that's why the order wasn't recorded in your store.

    The order doesn't get saved to your database until the payment module completes the payment and returns back to your store.

    To prevent that symptom from happening again, you'll want to isolate the cause of the timeout. You might find the system debug logs in the /logs/ folder useful for investigating the problems your site is having.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. v154 Sudden duplicate authorize.net transactions? (Single order, double CC charges)
    By Patrick Vincent in forum General Questions
    Replies: 15
    Last Post: 17 Jun 2016, 03:23 PM
  2. Authorize.net SIM double charges
    By zg1 in forum Built-in Shipping and Payment Modules
    Replies: 4
    Last Post: 7 Oct 2010, 03:23 AM
  3. Authorize.net SIM in TEST mode not showing credit card fields
    By colortheworld in forum Built-in Shipping and Payment Modules
    Replies: 11
    Last Post: 4 May 2010, 10:14 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg