7 results found
-
Promotions - BOGO Improvement
We are having an issue with a Buy One Get One Free Promo.
[It requires too many promotions to be setup to be able to support this type of promotion.]This promo does work when you just order 1 of the MILW 3697-22 and you get a free MILW 48-11-1865
BUT if a customer were to order more than 1 lets say 4 for example, it's only still giving them 1 free MILW 48-11-1865 when it should give them 4 free MILW 48-11-1865, since it is a Buy one Get one.[Multiple promotions are required to set this up which…
3 votes -
Enable Cloudflare's leaked credentials detection
Please note: this idea required splitting so that various points may be addressed as information becomes available.
New request:
- WAF compromised credentials check
Original request:
Please help with implementing below security features ASAP. There are so many frequent attacks on the website that causes the websites to go down.
- Geographical Rate Limiting - Add rules with rate limiting for traffic outside of specific countries (Challenge beyond the primary range/limit and block beyond the secondary range/limit)
- Basic Rate Limiting - Can we add a rule with rate limiting to block DoS attacks
- Bot Protection - Challenge suspected bots to confirm user…
5 votesWe are currently building support in CFG for Cloudflare for SaaS/O2O, which will allow customers to implement and maintain their own Cloudflare WAF in front of Optimizely's. If a customer chooses to stand up their own WAF, they would be able to tailor it to fit their business needs specifically by including things like rate limiting, bot protection, and other Cloudflare configurations.
Note: Optimizely does already take action to mitigate attacks by working with the customer to implement challenges and/or specific rules for the issues the customer is experiencing.
-
Bot prevention measures
Please note: this idea required splitting so that various points may be addressed as information becomes available.
New request:
- Bot Protection - Challenge suspected bots to confirm user authenticity
- Bot detection with javascript to identify headless browsers
- Any other WAF rules to protect the website from anonymous usage and attacks
Original request:
Please help with implementing below security features ASAP. There are so many frequent attacks on the website that causes the websites to go down.
- Geographical Rate Limiting - Add rules with rate limiting for traffic outside of specific countries (Challenge beyond the primary range/limit and block beyond the…
11 votesWe are currently building support in CFG for Cloudflare for SaaS/O2O, which will allow customers to implement and maintain their own Cloudflare WAF in front of Optimizely's. If a customer chooses to stand up their own WAF, they would be able to tailor it to fit their business needs specifically by including things like rate limiting, bot protection, and other Cloudflare configurations.
Note: Optimizely does already take action to mitigate attacks by working with the customer to implement challenges and/or specific rules for the issues the customer is experiencing.
-
Website Stability via Rate Limiting
Please note: this idea required splitting so that various points may be addressed as information becomes available.
New request:
- Geographical Rate Limiting - Add rules with rate limiting for traffic outside of specific countries (Challenge beyond the primary range/limit and block beyond the secondary range/limit)
- Basic Rate Limiting - Can we add a rule with rate limiting to block DoS attacks
Original request:
Please help with implementing below security features ASAP. There are so many frequent attacks on the website that causes the websites to go down.
- Geographical Rate Limiting - Add rules with rate limiting for traffic outside of…
6 votesWe are currently building support in CFG for Cloudflare for SaaS/O2O, which will allow customers to implement and maintain their own Cloudflare WAF in front of Optimizely's. If a customer chooses to stand up their own WAF, they would be able to tailor it to fit their business needs specifically by including things like rate limiting, bot protection, and other Cloudflare configurations.
Note: Optimizely does already take action to mitigate attacks by working with the customer to implement challenges and/or specific rules for the issues the customer is experiencing.
-
Enable 3DS API Integration Support for Bambora
Bambora currently supports 3D Secure (3DS) authentication, which is an industry-standard security protocol designed to reduce fraud and increase authorization rates during online transactions. However, Configured Commerce does not currently offer out-of-the-box support for Bambora's 3DS API integration.
This would include:
• UI/Settings support to enable/disable 3DS within Bambora configurations.
• Backend integration to perform 3DS authentication flows as part of the payment process.
Priority: high - currently unnecessary risk for TD/Bambora enabled customers to accept online payments without 3DS.
1 vote -
Request for an out of the box configuration setting for when sessions are fully expired
Request for an out of the box configuration setting for when sessions are fully expired:
• Session Expiration and let the client decide if they would like to redirect to Session Expired Page, or use Overlay with Session Expired Modal on same page.
• In this setting we could also provide additional sub-setting with ability to enable a session expiration warning (admin can set the number of minutes)Incomplete Client-Side Inactivity Timeout: We have two different issues with this vulnerability,
• If a customer steps away from their system without an automatic logout after a period of inactivity, there is…6 votesGreat news! Our team is anticipating releasing this feature in June 2026. I'll provide another update once the release has been completed.
-
Proactive Site Monitoring
Opti should provide proactive site monitoring to its configured commerce customers. Customer should received an alert from Opti about server errors, hosting issues, site restarts, etc. As hosting provider, Opti should support the platform from this perspective and not be reliant on Partners or the Customers to address these types of errors.
9 votesThis work is in progress across multiple areas of the product, including: Mission Control alerts/notifications, Cloudflare O2O support, proactive query analysis in CFG, and other performance improvements.
Please see documentation around Mission Control's new Notifications tab - this is the main area where we will be including more alerts in the coming months: https://support.optimizely.com/hc/en-us/articles/44077180697997-Build-and-deploy-notifications
- Don't see your idea?