diff --git a/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml b/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml index 615feec5e..174e2a689 100644 --- a/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml +++ b/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml @@ -208,7 +208,7 @@
Never trust anything but id, ignore the other fields completely, an attacker can spoof those, they are present only for backward compatibility reason:
GET request to https://btcpay.example.com/invoices/{invoiceId} with Content-Type: application/jsonGET request to https://btcpay.example.com/invoices/{invoiceId} with Content-Type: application/json; Authorization: Basic YourLegacyAPIkey", Legacy API key can be created with Access Tokens in Store settingsorderId is from your backend, that the price is correct and that status is either confirmed or complete