Problem/Motivation

Authorize.net rejects a repeat transaction that matches a recent one within a server-side "duplicate transaction window". The default window is 120 seconds. This is what protects a shopper from being charged twice when they do not see an order confirmation and submit again (slow network, page refresh, back button, double click).

The Accept Hosted gateway does not expose this window, so the only way to tune it is per-site custom code. We have been injecting the Authorize.net duplicateWindow transaction setting through a custom event subscriber on individual sites, which means every site that needs a wider window has to reimplement the same fix. This belongs in contrib as a first-class gateway configuration option.

Steps to reproduce

  1. Configure an Authorize.net (Accept Hosted) gateway and begin a checkout.
  2. Complete payment but, before the order confirmation renders, resubmit the payment (refresh and submit again, use the back button, or double-submit) within a short window.
  3. Depending on timing, the customer can be charged twice. There is no gateway setting to widen the window beyond Authorize.net's 120 second default.

Proposed resolution

Add an optional "Duplicate transaction window" field (in seconds) to the Accept Hosted gateway configuration form.

  • When set, include the Authorize.net duplicateWindow setting in the transaction request that generates the hosted payment page, the same request the per-site custom subscriber currently targets.
  • When empty, omit the setting so Authorize.net applies its own 120 second default (this keeps existing sites unchanged).
  • Validate the value as an integer between 0 and 28800 (0 disables duplicate checking, 28800 is the 8 hour maximum).

Remaining tasks

  • Add the config schema key, form field, and integer/range validation.
  • Wire the value into the Accept Hosted transaction request as the duplicateWindow setting.
  • Confirm the field label and help text.
  • Manual testing (confirm checkout still works and the setting is sent; note the dedup behaviour itself is hard to exercise directly) and review.

User interface changes

A new optional field on the Accept Hosted gateway configuration form:

Duplicate transaction window (seconds)
How long Authorize.net should reject a repeat transaction that matches a recent one. A customer who does not see an order confirmation and submits again within this window is declined rather than charged twice. Leave empty to use the Authorize.net default of 120 seconds. Maximum 28800 (8 hours).

API changes

None. The change is additive gateway configuration only.

Data model changes

A new optional configuration key is added to the Accept Hosted gateway config schema. The change is additive and needs no update hook: the field defaults to empty, which preserves the current behaviour (Authorize.net's 120 second default).

CommentFileSizeAuthor
image-2.png38.87 KBadrianandres
image-1.png199.75 KBadrianandres
Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

adrianandres created an issue. See original summary.

vmarchuk made their first commit to this issue’s fork.

vmarchuk’s picture

Version: 8.x-1.x-dev » 2.x-dev

vmarchuk’s picture

Status: Active » Needs review
adrianandres’s picture

Status: Needs review » Needs work

vmarchuk’s picture

Status: Needs work » Fixed

Committed!

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.