Security settings

Contents

Implementing and adjusting security settings - Passcode
Implementing and adjusting security settings - Dynamic pages IP restriction

Summary

You can set up and adjust security for your external dynamic content by doing the following:

  • Set up a passcode to be sent with GET requests to dynamic content URLs (recommended)
  • Restrict the IP addresses for which external dynamic content URLs will be displayed. 

Implementing and adjusting security settings

Passcode

When you install the dotmailer for Magento connector, we generate a unique passcode that is used to access external dynamic content. By using this passcode you can be sure that basket contents and coupon codes can be viewed only if that passcode is sent with the GET request to the external dynamic content URL, adding security.

Go to STORES > Configuration > DOTMAILER > Dynamic Content and click External Dynamic Content URL's.

The passcode field contains the 32 random characters that were generated when you installed the connector.

We recommend that you do not change this password field, although you can if you want.

Magento2_External_dynamics_content_secret_key.png

Not seeing the 32 random characters?

If you either use a version of dotmailer for Magento 2 that is lower than v2.4.5 or you upgrade from a version of dotmailer for Magento 2 that is lower than v2.4.5, we recommend that you create a random 32 character passcode.

The passcode can include the following characters:

  • Numbers (0-9)
  • Uppercase letters (A-Z)
  • Lowercase letters (a-z)

Dynamic pages IP restriction

In addition to all our URLs requiring the above passcode included, you can also manage the list of requesting IP addresses that these URLs will display for when requested from them. The 'Dynamic Pages IP Restriction' section is found in STORES > Configuration > DOTMAILER > Developer.

mag2_developer_dynamic_pages_IP_restriction.png

As a default, we include the three IP addresses (104.208.235.109, 52.174.92.164, 104.210.118.87, 89.197.25.33 and 108.165.31.134) that dotmailer sends requests from when sending emails to pull in this content, but for testing purposes you may want to add your office IP so you can view these URLs directly in your browser.

Important

When adding an IP address to this list, you need to leave a space after the comma that separates it from the last IP address in the list. Without it, your external dynamic content won't work.

Removing all IPs from this box and clicking Save Config will completely disable the IP verification on these pages. This is not recommended, however.

Have more questions? Submit a request

Comments