Punch Out Security
USING: PeopleTools 8.58, FS/SCM 8.58 PUM48 (upgrading to latest tools and FS/SCM this summer
In order to get Punch Out working, given the new browser cross-origin policy, you have to set the supplier's hosts (and any hosts they reference) as trusted sites. For each site you're giving them much more access to what happens in the user's browser (java script).
As you add new Punch Out suppliers, you're adding more and more of these sites.
Our internal team is concerns about the security implications of this - since we don't normally let users go to any site they want!
How do you manage this at your own organizations? Is there any way to some how secure this "better"