Developer forum

Forum » Swift » Anonymous checkout - issue with Update existing users based on email match.

Anonymous checkout - issue with Update existing users based on email match.

Didzis Kuzmans
Reply

Swift is coming with this default set-up for anonymous user checkout.

So, it means, if someone knows existing user email, they can just change user data during anonymous checkout without logging in.

Looks like anonymous user can't change password or get access to user, but ability to change address, name or other user fields without having user access sounds like a security breach.

Probably this option should be used very carefully instead of being default option in Swift? What do you think?


Replies

 
Nicolai Pedersen Dynamicweb Employee
Nicolai Pedersen
Reply
This post has been marked as an answer

Yes, this is a setting that should never be used.

"Update existing users" should not be a default setting - we will change it. Thanks for reporting.

Votes for this answer: 1

 

You must be logged in to post in the forum