diff --git a/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml b/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml index 03d92ecab..49d40a5c4 100644 --- a/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml +++ b/BTCPayServer/Views/Apps/UpdatePointOfSale.cshtml @@ -210,7 +210,7 @@
Never trust anything but id, ignore the other fields completely, an attacker can spoof those, they are present only for backward compatibility reason:
GET request to https://btcpay.example.com/invoices/{invoiceId} with Content-Type: application/jsonGET request to https://btcpay.example.com/invoices/{invoiceId} with Content-Type: application/json; Authorization: Basic YourLegacyAPIkey", Legacy API key can be created with Access Tokens in Store settingsorderId is from your backend, that the price is correct and that status is either confirmed or complete