| @@ -74,8 +74,12 @@ | ||
| 74 | 74 | |
| 75 | 75 | $force_notify_url_scheme = apply_filters("ws_plugin__s2member_during_sc_paypal_button_force_notify_url_scheme", null, get_defined_vars ()); |
| 76 | 76 | $force_return_url_scheme = apply_filters("ws_plugin__s2member_during_sc_paypal_button_force_return_url_scheme", null, get_defined_vars ()); |
| 77 | 77 | |
| 78 | + //260918.2104 TO-DO PayPal Checkout cache hardening: do not embed the one-hour, visitor-specific transaction token in rendered page HTML. | |
| 79 | + // Render a cache-safe encrypted checkout definition instead, then mint the short-lived invoice/IP/user-context transaction token server-side | |
| 80 | + // when checkout actually starts (output="button", "anchor", or "url"), preserving validation, idempotency, subscription context, and return/cancel behavior. | |
| 81 | + | |
| 78 | 82 | // PayPal Checkout SDK memoization (per request; shared across all button variants). |
| 79 | 83 | static $ppco_sdks = array(); |
| 80 | 84 | |
| 81 | 85 | foreach(array_keys(get_defined_vars())as$__v)$__refs[$__v]=&$$__v; |