Results 1 to 3 of 3
  1. #1
    Join Date
    Jul 2005
    Posts
    115
    Plugin Contributions
    0

    Default sharing , well kinda

    ok i've got this deal with someone who's a friend... i set him up with zc and my merchant account for a share of sales.

    i'll let him use my merchant account but i don't want him to have access to the account information because the account is used for several sites. but he has complete operational control otherwise.

    also included in the agreement is that he gets full access to the site file set and database. so i can't keep the account information hidden... can i?

    is there a way to do this without resorting to writing compiled, closed source code?

  2. #2
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: sharing , well kinda

    In this regard I like what authorize.net has done by issuing an API login ID and transaction key which are completely separate from the merchant login details. They only allow you to use their API for doing transactions like CC auth/captures, etc. If someone steals the ID/key, all they can do is send you more CC auth's ... granted, they could be fraudulent and cause you trouble, but at least the info cannot be used to login and modify your account, etc.

    Linkpoint does similarly: A user ID and a certificate key (file) are required to use the module. The user ID is tied to your account, but the payment module doesn't use your real merchant password. Thus, the login details cannot be stolen.

    If you're using a payment module for a gateway that offers less separation between username and password details, you might consider exploring how to change that.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Jul 2005
    Posts
    115
    Plugin Contributions
    0

    Default Re: sharing , well kinda

    unfortunately authorize doesn't underwrite businesses that require age verification, otherwise i would've been with them for this account.

    if dr. byte can't come up with another solution i'm pretty sure i can't. guess it's closed source time... thanks though!

 

 

Similar Threads

  1. SSL works well...too well.
    By gbm in forum Basic Configuration
    Replies: 3
    Last Post: 2 Aug 2009, 08:51 AM
  2. Kinda sorta linking?
    By Childproof in forum Setting Up Categories, Products, Attributes
    Replies: 4
    Last Post: 14 Jan 2009, 07:25 PM
  3. Working perfectly...kinda.
    By jnellie in forum Built-in Shipping and Payment Modules
    Replies: 1
    Last Post: 7 Jan 2009, 07:12 PM
  4. Kinda Confused
    By TinaS in forum Templates, Stylesheets, Page Layout
    Replies: 6
    Last Post: 19 Sep 2006, 08:22 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg