Entersoftone Fintech Help

🏷️ v3.2.0 — 2026-09-14

🚀 New features

Open Banking API

  • Added sandbox support for Finsim bill payments.

  • Added a new field (balanceOfPaymentCode) to support Eurobank non-SEPA payments.

Payhub API

  • The payment request ID is now automatically appended to merchant return redirect URLs.

  • Payment requests now support optional custom metadata fields.

  • A new endpoint is available to retrieve registration details including webhook configuration.

  • Merchants can now configure a return URL flow for payment links.

  • A new endpoint is available to retrieve payment request details by ID.

Paygate API

  • Users who have not yet activated their account can now set up a password through the welcome flow.

  • Inactive users are now supported in the password reset welcome flow.

  • Merchant details responses now include rejection-related information.

  • The merchant entity now stores rejection info fields for future reference.

✨ Improvements

Paygate API

  • Merchant lookups during authorization are now cached to improve performance.

🐛 Bug fixes

Open Banking API

  • Bill payment accounts are now resolved through the dedicated bill-payment backend.

Payhub API

  • Removed duplicate form field names and stabilised end-to-end checkout tests for DIAS and Worldline.

Paygate API

  • Partner certificate paths are now derived on the server side rather than supplied by the client.

  • Removed an obsolete application key field from the merchant details response.

  • Fixed a bug that could cause the total paid amount to be calculated using stale data.

  • Moved merchant adaptor application key generation to the organisation activation step.

  • Fixed transaction handling in the easy onboarding flow.

  • Increased the maximum allowed length for the adaptor application key.

  • Aligned terminal status transaction matching and fixed an IRIS logo lookup issue.

  • Fixed a race condition that could cause payment response order statuses to be processed out of order.

  • Corrected the description of the delete bank holiday endpoint to avoid a false-positive security alert.

  • Order and payment request updates are now wrapped in a single transaction, and a duplicate callback has been removed.

  • Payment status reporting is now restricted to the owning merchant.

  • Fixed an incorrect partial payment status being returned.

  • Fixed unexpected behaviour in the terminal payment request endpoint.

  • Reverted an unintended change to the payment status response format.

  • Fixed an incorrect cancellation status being returned for v1 payments.

  • Fixed incorrect response mapping for the v1 post-payment status endpoint.

  • Resolved a transaction boundary issue and a cancellation bug in the merchant send-for-approval flow.

  • Aligned the not-found payment request response with the expected legacy format.

  • Fixed the Eurobank easy registration flow.

  • Database transactions are now wrapped in a retry-compatible execution strategy to prevent failures under transient errors.

  • Fixed incorrect serialisation of the ultimate creditor info response.

  • Added explicit database transactions to prevent orphaned records when external service calls fail.

  • Fixed a typo in the terminal payment status consumer.

  • Fixed errors occurring during terminal payment status transactions.

Financing

  • Fixed an issue that could cause duplicate consent acceptance events to be recorded.

🔒 Security

Open Banking API

  • Sensitive data is now redacted from exception logs, and build and audit warnings have been resolved.

  • Test redirect URIs have been replaced with approved whitelisted domain values.

  • Sensitive HTTP headers are no longer included in global exception handler logs.

  • Swagger UI is now only accessible in development and local environments.

Payhub API

  • Worldline callback digest verification has been added, and the onboarding callback has been hardened.

  • Page scripts are now restricted to same-origin relative modules to tighten content security.

  • The subscription service token has been moved to Key Vault for secure storage.

  • DTD processing has been disabled in the Worldline XML canonicalizer to prevent XML injection.

  • Fixed a duplicate organisation code submission that could break DIAS registration.

Paygate API

  • OpenAPI and log4net vulnerabilities have been patched and build warnings cleared.

  • Admin accounts are now locked out after a configurable number of failed login attempts.

  • Callback configuration secrets are no longer exposed in the get-partner response.

  • Payment request redirect URLs are now validated before use.

  • Sensitive partner credentials are masked in the get-partner-by-ID response.

  • Secret values are no longer written to logs in the Key Vault service.

  • Payment request redirect and callback URLs are now validated on creation.

  • Registration callbacks are now bound to a one-time nonce to prevent replay.

  • The minimum allowed length for JWT signing keys is now enforced in configuration.

  • Dynamic content in email HTML is now sanitised to prevent injection attacks.

  • Sensitive data has been removed from Eurobank refund consumer logs.

  • The ALTCHA challenge search space has been increased to prevent brute-force bypass.

  • HTML content in the email generator is now sanitised to prevent injection attacks.

  • Merchant application key comparisons now use constant-time logic to prevent timing attacks.

  • Registration status lookups are now scoped to the authenticated partner.

  • Payment status requests are now scoped to the requesting merchant.

  • Application key generation now uses a cryptographically secure random source.

  • Terminal payment status processing now validates order ownership and the DIAS transaction ID.

  • OAuth tokens are no longer written to logs.

  • Unauthorised access to payment orders is now prevented.

  • OData queries against Azure Table Storage are now protected against injection.

  • An upper bound has been added to the batch size parameter for file-based orders and refunds.

Financing

  • The event grid webhook endpoint now validates the X-API-KEY header on all incoming requests.

Other changes

  • OpenBank redirect URIs are now validated, and CORS origins are sourced from the operations whitelist.

Last modified: 14 September 2026