来自 Shopee 官方资料快照 ·
- 当前资料结构化阅读页
- 固定快照已留存,可追溯
- 官方原文可核对
资料正文
§1 Penalties for Security Vulnerabilities Detected in OpenAPI Connection
Dear Developers,
To ensure that important data belonging to sellers and the Shopee platform are protected against misuse or leaks, we request that you address any detected vulnerabilities within the specified Service Level Agreement (SLA) timeframe:
| Severity | SLA lead time (calendar days) |
|---|---|
| Critical | 14 |
| High | 30 |
| Medium | 60 |
| Low | 90 |
Please visit the Security Vulnerability Dashboard on the Open Platform Console to review all detected vulnerabilities, including details such as severity, last detection date, and the rectification deadline. For each vulnerability, you can click on Detail to view the recommended corrective actions under the Action Required section.
Important: Failure to resolve vulnerabilities by the specified deadline will result in penalties.
Depending on the severity of the vulnerability, penalty/penalties may include:
| Penalty | Details |
|---|---|
| Sensitive data masked when calling sensitive data APIs | Sensitive data such as the buyer’s name, address, and contact will be masked when calling these APIs: - V2.order.get_order_detail - V2.logistics.get_shipping_document_data_info - V2.returns.get_return_detail - V2.order.get_buyer_invoice_info |
| API limit reduced | Daily API limit reduced by a certain percentage determined by Shopee Open Platform |
| Suspension of new shop authorizations | - APP(s) under the penalized developer may be unable to authorize its APP(s) to access new shops/merchants - Shops/merchants that have been granted access before the suspension can continue to use the APP before the authorization expires, but re-authorization may be disallowed until the suspension is lifted |
| Suspension of APP(s) | - APP(s) under the penalized developer may be unable to make API calls. - All authorized shop access permissions of the APP(s) may also be revoked - The penalized developer may be unable to authorize its APP(s) to access new shops/merchants |
| Removal of Shopee Open Platform account | - The penalized developer may have its Open Platform account deleted, with all permissions revoked - APP(s) under the penalized developer may be unable to make API calls - All authorized shop access permissions of the APP(s) will also be revoked - The penalized developer may no longer be able to authorize its APP(s) to access new shops/merchants |
If you have any further questions or require additional assistance, please raise an Open Platform Ticket in our Support Center.
Thank you for your cooperation in ensuring the security of the Shopee platform.
Shopee
