Skip to content

Security issue - Apple Pay on PDP - CSRF token should not be in a cached template #1483

@claygan-d3

Description

@claygan-d3

Product Detail Pages are cached by SFCC - the code is generating the CSRF token in the controller (src\cartridges\int_adyen_SFRA\cartridge\controllers\Product.js) and outputting it in an included template (src\cartridges\app_adyen_SFRA\cartridge\templates\default\product\components\addToCartButtonExtension.isml) without any regard for page caching.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions