Platform security
IFrame limitations
Optimizely Configured Commerce does not support setting SameSite cookies as None; Secure to render inside an iframe in some procurement platforms. Configured Commerce uses SameSite cookies to authenticate with the APIs.
Security architecture
Configured Commerce uses Identity Server and the OWIN middleware to authenticate requests to the platform. This contains information that shows how the security architecture is applicable in varying scenarios such as site access and calls to the RESTful API's.
iFramed credit card processing for cloud
Optimizely Configured Commerce Cloud uses TokenEx https //tokenex. com as a common payment gateway provider for many reasons, including improved security and simpler PCI compliance.
Restrict access to the Admin Console
Access to the Admin Console can be disabled for any website within its environment. Consider the following scenario My environment has 6 web servers, 3 of them are exposed to the public and 3 are internal facing.
Use email address as username
To improve and simplify the user experience, the option to use the user's email address as the username can be enabled. This is a globally setting and is set to OFF by default.
Configure IssuerUri for IdentityServer on webfarms
The purpose of the IssuerUri option on the IdentityServer is to create tokens and generate the TokenValidationParameters. On token generation, the values for token audience and the issuer is set from the IssuerUri option.
Work with security headers
If you want to increase the security of your Optimizely Configured Commerce site, you can use the Content-Security-Policy and Referrer-Policy headers. You can find these settings under Administration > Settings > Site Configurations > Security Headers in the Admin Console.