To make sure customer payment data is secure, Salesforce Payments complies with the
latest PCI standard for detecting changes to Content Security Policy (CSP) headers and scripts.
The PCI standard applies to any payment form where customers enter their information, including
the checkout page, Pay Now payment pages, and mini carts that include express checkout.
If Salesforce Payments detects changes to a payment web page header or the insertion of
javascript, it triggers a Content Security Policy (CSP) platform event with these fields:
Context––URL of the payment page where the change occurred.
Notification Type–Header or script change.
Notification Message–Tells the admin what change was detected.
To secure customer payment information, subscribe to these events, and, if necessary, take
corrective action. To receive these events, create an Apex trigger or a platform
event-triggered flow. For more information, see Subscribing to Platform Events.
Note Payment pages that use the Salesforce Payments, Payment, or Dual Payment Experience
Builder components are compliant by default. If you use a third-party payment provider with a
custom payment component, verify whether change detection is implemented.
Heeft dit artikel uw probleem opgelost?
Laat ons weten wat we kunnen doen om te verbeteren!
Wordt geladen
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.