Skip to content
Freehold CMSSelf-hosted PHP website software.
Downloads soon

Store and Payments Boundary

Store owns the catalog, cart, order, fulfillment and protected-delivery records. Payments connects that order path to supported hosted providers.

Store state remains authoritative

Products, customer carts, order lines, fulfillment state and protected files belong to Store. A payment attempt refers to the related order; it does not become a second product catalog or order system.

Provider results require verification

Redirect returns improve the customer experience, while signed provider communication and reconciliation establish payment state. Processing must be repeatable so a duplicate callback cannot create duplicate fulfillment.

Transaction checks

  • Stable order and payment references.
  • Server-side amount verification.
  • Signed provider communication.
  • Idempotent callback processing.
  • Controlled fulfillment after verified state.
  • Administrator reconciliation visibility.

Prove the duplicate and delayed-message cases

Test repeated provider callbacks, a customer return before server notification, a delayed payment result and a mismatched amount. Processing must remain repeatable, the stored order must remain authoritative and protected delivery must wait for verified state.

Next: deployment requirements

The production host must support the database, private storage, email and provider communication used by the selected commerce setup.

Read Deployment Requirements.