- Posts: 10
- Thank you received: 0
Payment API Key Security
- Wesley Faries
- Topic Author
- Offline
- New Member
-
Less
More
1 year 7 months ago #161110
by Wesley Faries
Payment API Key Security was created by Wesley Faries
Hello. My client is needing a booking system so I was recommending Events Booking and I would purchase the Stripe plugin for him. He ask how the API keys are stored and I said within the database, but he does not want me to use Event Booking in concern if the database was hacked the hackers would have the API keys - even though my server, site, and database is very secure. Besides the fact that other booking components store the API keys the same way, is there something I can tell him to ensure him that it is ok to have the API keys within the database?
Thank you!
Thank you!
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
1 year 7 months ago #161111
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Payment API Key Security
If he does not want it to be stored in database, we can store it directly in the code. However, if the site is already hacked, that data could still get lost, too
There is no better way, I'm afraid of
Tuan
There is no better way, I'm afraid of
Tuan
Please Log in or Create an account to join the conversation.
- Wesley Faries
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 10
- Thank you received: 0
1 year 7 months ago #161123
by Wesley Faries
Replied by Wesley Faries on topic Payment API Key Security
Thanks a bunch Tuan, and makes sense. I relayed your message and he asking if the API keys could be encrypted (which I think he meant hashed) or an option to have the API keys in a separate database or split up somehow - however with my understanding API keys need to be in cleartext?
Thanks again!
Thanks again!
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
1 year 7 months ago #161134
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Payment API Key Security
Even if it is encrypted, it is still need to be decrypted to pass to the payment gateway with the right value
So even if it is encrypted, and the site was hacked, the hacker (if he wants) can still decrypt the keys, no way to make it 100% safe when the site is already hacked
Regards,
Tuan
So even if it is encrypted, and the site was hacked, the hacker (if he wants) can still decrypt the keys, no way to make it 100% safe when the site is already hacked
Regards,
Tuan
The following user(s) said Thank You: Wesley Faries
Please Log in or Create an account to join the conversation.
- Wesley Faries
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 10
- Thank you received: 0
1 year 7 months ago #161135
by Wesley Faries
Replied by Wesley Faries on topic Payment API Key Security
Make sense! Thanks!
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
1 year 7 months ago #161136
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Payment API Key Security
You're welcome !
Tuan
Tuan
Please Log in or Create an account to join the conversation.
Moderators: Tuan Pham Ngoc
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.