Perhaps it's a browser setting you have enabled to keep you logged in?
I understand how purchases through Paypal work. Just because Cryptic accepts that form of payment doesn't mean that they are in control of Paypal servers or your account.
I myself use PayPal for STO and C-points, I've never had a problem like this, after buying points and confirming the transaction I am automatically re-directed to my STO account and logged out of PayPal. This would not be Cryptic trying to scam you, it would be PayPal f-ing up lol.
And yes I always check my PayPal after every use to ensure that I am logged off. To find that someone else is having this kind of problem with PayPal is worrying to say the least.
Purchasing Cryptic Points can only be done by logging into the STO website and passing through to paypal. So therfore STO should also log me back out of Paypal. If I were just making a quick purchase at work on a shared terminal then another user could come along after me and corrupt my Paypal account.
You have to log into Paypal separately. Cryptic doesn't own your rights to the account, if cryptic were able to log out - it'd open up the potential for them to log you in.
No, you need to practice better security and log yourself out of third party paysites.
I would be willing to admit stupidity in not noticing a logout button somewhere near the continue button, perhaps a kind soul would be willing to offer some information either way?
The way I understand is that Cryptic handles Paypal interaction like any other company:
You're redirected to a PayPal page, where you log into PayPal's servers
On PayPal's server, you enter your payment information and address
You submit it and get a brief "confirmation" page for your payment saying something like "Your payment has been received"
This is your chance to log-off, usually
That said, from an IT standpoint, I'd be very worried if Cryptic were able to log you on/off of PayPal's Servers. If third parties are able to change your log-in status on a transaction that is just between you and paypal, there's a big issue.
PayPal acts as a middle-man. Technically, then receive your payment and pass it on to Cryptic via their secured servers. Allowing anyone to change that private transaction between you and them would be very sketchy indeed.
Confirming the transaction automatically redirects the user back to their STO account page and away from Pay Pal, pressing log out before this would mean canceling the transaction. I think.
Confirming the transaction automatically redirects the user back to their STO account page and away from Pay Pal, pressing log out before this would mean canceling the transaction. I think.
There's no confirmation page after completing the transaction? That sounds fishy.
I'd test this out but I don't see a PayPal option when I go to my payment option window. I take it this is for subs only?
There's no confirmation page after completing the transaction? That sounds fishy.
Edit: This is an example from buying C-Points starting from the ingame C-Store:
Basically, if I wanted to buy C-points for example, I would be directed to my account to log in, then select how may points I want to buy, then payment method which in this case is PayPal, after confirming my details and continuing, STO will automatically redirect to PayPal which requires the user to first log in, then a Transaction page is shown detailing what you are buying - basically an invoice of sorts. At the bottom of this page after reading the details are correct the user confirms the transaction and upon this action is automatically redirected back to their STO account. It's at this point PayPal should log the user out automatically after completing the transaction.
You are redirected away from Cryptic's links to Paypal and Paypal links back to Cryptic. Each website handles log in rules differently. If you notice you stay logged into your STO account when coming back from PayPal. My experience with Paypal is that as soon as you leave there site they log you out. It is possible that your browser did not preform this code correctly because of a setting or an internet snafu. It is not Cryptic's responsibility that that third party website does not do as it is intended.
Having troubles with Paypal, can not buy more than 500 points at a time, so I went back to Paypal to check on my account, only to find that STO left me logged in. MAJOR security breach! Makes me want to not trust STO with my credit card information.
I should think that simply Logging Out of STO for a second would Break the Paypal Link, then Log back into STO. Problem solved.
Comments
STO left you logged into your paypal account? Doesn't sound right to me
I understand how purchases through Paypal work. Just because Cryptic accepts that form of payment doesn't mean that they are in control of Paypal servers or your account.
And yes I always check my PayPal after every use to ensure that I am logged off. To find that someone else is having this kind of problem with PayPal is worrying to say the least.
You have to log into Paypal separately. Cryptic doesn't own your rights to the account, if cryptic were able to log out - it'd open up the potential for them to log you in.
No, you need to practice better security and log yourself out of third party paysites.
Can't you log out when you receive payment processing confirmation?
That said, from an IT standpoint, I'd be very worried if Cryptic were able to log you on/off of PayPal's Servers. If third parties are able to change your log-in status on a transaction that is just between you and paypal, there's a big issue.
PayPal acts as a middle-man. Technically, then receive your payment and pass it on to Cryptic via their secured servers. Allowing anyone to change that private transaction between you and them would be very sketchy indeed.
There's no confirmation page after completing the transaction? That sounds fishy.
I'd test this out but I don't see a PayPal option when I go to my payment option window. I take it this is for subs only?
Edit: This is an example from buying C-Points starting from the ingame C-Store:
Basically, if I wanted to buy C-points for example, I would be directed to my account to log in, then select how may points I want to buy, then payment method which in this case is PayPal, after confirming my details and continuing, STO will automatically redirect to PayPal which requires the user to first log in, then a Transaction page is shown detailing what you are buying - basically an invoice of sorts. At the bottom of this page after reading the details are correct the user confirms the transaction and upon this action is automatically redirected back to their STO account. It's at this point PayPal should log the user out automatically after completing the transaction.
I'd try taking it up with PayPal support. It's their site, their cookie that keeps you logged in, and ultimately their way of handling things.
I should think that simply Logging Out of STO for a second would Break the Paypal Link, then Log back into STO. Problem solved.