need website security advice
Posted on 2013-01-20
The website Im working on excepts credit cards. An account can have many users.
I want to ge the option to the buyer to save his credit card info, so it makes the next checkout quicker... When I say the credit card info is saved, no information is saved on my servers for security, but when the user chooses to save their card info I send an XML string to the payment processor asking for a token to be able to rebill the same card. having said that, I want to give the option of the credit card holder to share the ability to place an order using his credit card saved on file to the users on his account providing he sets the right permissions... Any advice on this feature would be greatly appreciated. im also guessing if I would go forward I would create another table to place the users that have permission to use the credit card on file...