Deweloperzy

Identity verification

Make sure nobody can pretend to be one of your customers.

When you send a user_id, Shopxare links the visitor to that user — but only if you also send a valid user_hash. Without it, anyone could type another person's ID in the browser.

How to set it up

  1. Go to Settings → Messenger → Security and copy your identity secret. Keep it on your server only.
  2. On your server, compute an HMAC-SHA256 of the user ID with the secret.
  3. Send it as user_hash in boot.
  4. Turn on Require identity verification.

Examples

PHP:

$hash = hash_hmac('sha256', (string) $user->id, getenv('SHOPXARE_IDENTITY_SECRET'));

Node.js:

const hash = crypto.createHmac('sha256', process.env.SHOPXARE_IDENTITY_SECRET).update(String(user.id)).digest('hex');

Python:

hash = hmac.new(secret.encode(), str(user.id).encode(), hashlib.sha256).hexdigest()

Rotate the secret

You can show or rotate the secret on the same screen (your password is asked). After rotating, update your server — old hashes stop working.

Company data (company) is only saved for verified users.

Nadal coś niejasne? Kontakt