Abuse Prevention - Extensions
Abuse Prevention
Abuse Prevention at Checkout Configuration
Overview
The Forter SFCC cartridge version 21.1.3+ contains built-in functionality to support Abuse Prevention at Checkout in the form of decline reason code handling. Merchants who would like to take advantage of this new functionality should first follow the integration guide for Fraud At Checkout including the Installation, [customizing order and payment data in the Orders Validation request](./Fraud Management/Checkout.md), and sending Order Status data.
The following Policies are supported with the dedicated Abuse Policies UI and each policy has two built-in handling options:
- “No Action”
- “Cancel and Void with custom decline message”
Fig 1. Abuse Policies Section in SFCC BM
Supported Reason Codes
The Cartridge has built-in functionality to receive and execute the following policies and reason codes
| Policy Type | reasonCode format | |
|---|---|---|
| Reshipper | MerchantPolicyReshipper | |
| INR at Checkout* | MerchantPolicyCheckoutINR | |
| Returns at Checkout* | MerchantPolicyCheckoutReturns | |
| Promotion/Coupon Abuse | MerchantPolicyCouponAbuse | |
| Limited Item | MerchantPolicyLimitedItemAbuse | |
| Reseller | MerchantPolicyReseller |
Example Response Format
The response format below shows how the reasonCode parameter is populated with a supported abuse policy string
{
"status": "success",
"transaction": "712123002479",
"action": "decline",
"message": " | Link in portal: https://portal.forter.com/dashboard/7121230",
"reasonCode": "MerchantPolicyLimitedItemAbuse",
"recommendations": [],
"additionalTags": ""
}
If you would like to leverage this functionality as-is OR would like to customize the policy reasonCode handling to execute unique customer flows or custom reason Codes, please follow the steps below:
Integration Process
Step 1: Install the SFCC Cartridge
Follow the standard Guide for [Importing the Forter Cartridge](./Installation/Import Cartridge.md) Make sure you include your Forter API credentials, specify the API version, and select your Fraud handling
| NOTE: The Fraud decline handling will be the default decline handling. If a policy is enabled but no dedicated action is selected, the cartridge will default to your Fraud decline settings |
|---|
Step 2: Select your Integration placement.
Forter’s Abuse Policies can be executed pre-auth (prior to calling your payment processor) or post-auth (after the payment has been authorized). The options for customizing the code are located below:
- [Pre-Auth Decision Flow](./Fraud Management/Checkout/Pre-Auth Credit Card/SFRA.md)
- [Post-Auth Decision Flow](./Fraud Management/Checkout/Post-Auth Credit Card/SFRA.md)
Step 3: Map your payment data/customize mapping
Customize the mapping and retrieval of the payment data. Depending on the flow selected in step 2, you will need to customize the forterOrder.js file with the appropriate payment data retrieved from your payment processor.
Step 4: Select your Policy Decline Handling
Built-in Options
Once you have successfully mapped the order and payment data, your Forter Implementations team will enable Abuse Prevention functionality. Once this is enabled, you can go to the SFCC business manager UI Merchant Tools > Site Preferences > Custom Preferences > Forter > Abuse Policies
| NOTE - The Abuse Policies section will show in cartridge version 21.1.3 upon installation but will not be executed in the cartridge unless your Forter team has exposed policy reason codes in the Forter API response and you and your Forter team have already created policy rules separate from the cartridge. |
|---|
Click on the Abuse Policy Settings option and then Toggle the “Enabled” option at the top of the page
Next, go to the policies you enforce (i.e. “Reseller Abuse Policy”) and select the action from the dropdown menu.
| NOTE - while all policies show in the BM UI, only the ones that have been enabled by your Forter team and have corresponding rules created (by Analysts or via Policy Builder) will execute in your SFCC cartridge. |
|---|
Customizing the Policy Execution
The following Policies are supported with the dedicated Abuse Policies UI and each policy has two built-in handling options:
- “No Action”
- “Cancel and Void with custom decline message”
The reasonCode strings and policies supported are listed below:
| Policy Type | reasonCode format |
|---|---|
| Reshipper | MerchantPolicyReshipper |
| INR at Checkout* | MerchantPolicyCheckoutINR |
| Returns at Checkout* | MerchantPolicyCheckoutReturns |
| Promotion/Coupon Abuse | MerchantPolicyCouponAbuse |
| Limited Item | MerchantPolicyLimitedItemAbuse |
| Reseller | MerchantPolicyReseller |
If you want to customize the reasonCode handling (i.e. “reroute back to payments page”, “cancel but don’t void and show custom decline”, etc) go to the following files to add custom functions or flows:
- cartridges/int_forter_sfra/cartridge/controllers/CheckoutServices.js
- cartridges/int_forter_sfra/cartridge/scripts/pipelets/forter/forterValidate.js
If you’re receiving a custom decline reasonCode in the API response or receiving a policy within the recommendation response parameter instead of the reasonCode, you will not be able to use the SFCC business manager UI. Instead you can add your custom policy handling via the same files:
- cartridges/int_forter_sfra/cartridge/controllers/CheckoutServices.js
- cartridges/int_forter_sfra/cartridge/scripts/pipelets/forter/forterValidate.js
Using Policy Builder for Policy Creation
Once Policy Builder has been enabled in your Forter portal, you can create custom policies and rules. Make sure to select the Decline action when they create rules in the policy builder in order for the SFCC cartridge to correctly ingest the correct parameter.
Viewing Orders Policy-Enforced Orders
You can customize the “Orders” grid UI in the Forter section of the Business manager, so that the reason code and accompanying policy that was executed on an order can be easily searched and exportable.
Step 1: Global Preferences
Go to Administration > Global Preferences > Order Search.
Step 2: Add Custom column
Click on the ... button option next to a “Custom Order Column” row and select the reasonCode option (custom.forterReasonCode) to ensure that this value is exposed in the orders grid
Additionally, When you click on the order link or search for the order in Forter portal, the enforced policy can be shown in both the Transactions Grid and the detailed transaction view.