Action Required: Mandatory Salesforce Sites security configuration update (July 2026)

Sorry, we didn't find any relevant articles for you.

Send us your queries using the form below and we will get back to you with a solution.

11.6 September 2026

Public Site Sharing Rules

To strengthen the security following the Mandatory Security Configuration Update for Salesforce Sites, it is recommended to remove the Public Site Guest User Sharing Rules for the following objects:

  • Campaign (Campaign)
  • Payment Txn (AAkPay__Payment_Txn__c)
  • Recurring Payment (AAkPay__Recurring_Payment__c)
  • URL Token (AAkPay__URL_Tokens__c)

New options have been added to the existing Excluded from Sites Sharing Settings field on the Merchant Facility to support these objects. For more details, please review How to setup Sites Sharing Settings.

Action Required:

  1. Go to the Merchant Facility and add the objects listed above to the Excluded from Sites Sharing Settings field.
    1. If the options are not available, add the following Object API Names as options to the picklist field:Campaign, AAkPay__Recurring_Payment__c, AAkPay__Payment_Txn__c, AAkPay__URL_Tokens__c.  
  2. Go to Setup → Sharing Settings and remove the existing Public Site Guest User sharing rules for these objects.

News and Broadcast Component

Official news and announcements from Payments2Us can now be displayed directly within your Salesforce org, helping your team stay informed about product updates, important advisories, security notices, and other guidance without leaving the Payments2Us app. News content is published by Payments2Us and delivered automatically to your org.

The following components are available:

  • Payments2Us News Broadcast: Displays recent announcements in a Latest News & Updates card, including the title, date, description, and optional New and Urgent badges. Pagination is available when multiple announcements are published.
  • Payments2Us Popup Notification: Displays high-priority announcements as a modal or banner, such as urgent news or important time critical notices.

For more information and setup instructions, see the Setup and Use News Broadcasting help article.

Payments2Us Flows

The following Payments2Us Flows have been updated, including fixes for issues that could interrupt certain flow paths. If these flows were previously active in your Salesforce org, we recommend activating the latest version of each flow.

  • Payments2Us Payment Txn Flow: Large Donation/Payment Alert
  • Payments2Us Recurring Payment Flow: Send Client Direct Debit Signup forms
  • Payments2Us Payment Txn Flow: Send Receipt Automatic
  • Payments2Us Payment Txn Flow: Skip Receipt Automatic
  • Payments2Us Payment Txn Flow: Send Interim Receipt
  • Payments2Us Payment Txn Flow: Mark Refunds as Receipted for Matching
  • Payments2Us Payment Txn Flow: Send Interim Refund Notification
  • Payments2Us Payment Txn Flow: New Online Membership Payment Notification
  • Payments2Us Batch Entry Flow: Reset Authorise Cards

If you haven't already upgraded from Workflows to Flows, please review How to Migrate a Workflow to Flow
 

Cover Transaction Fees Changes

The Reserve Bank of Australia (RBA) announced changes designed to end card surcharges in Australia. Payments2Us has already pushed a patch version of Payments2Us to your production instance with some changes as per the guidelines. Please review What the RBA's Surcharging Changes Mean for Payments2Us help article for more details.

If your organisation uses a custom Cover Fee label or description, you’ll need to review and update it manually. The patch updates the standard, out-of-the-box terminology but cannot overwrite custom text.

Smart Retry Decline Management (Beta)

To provide greater control over how failed recurring payments are handled, we are introducing Smart Retry Decline Management (Beta).

Smart Retry allows organisations to identify soft and hard declines using payment gateway response codes and configure how soft declines should be retried, including the retry schedule, allowed retry days, maximum retry attempts, and follow-up actions.

Smart Retry is enabled by configuring Default Soft Codes on the Merchant Facility. If Default Soft Codes are not configured, the existing Payments2Us recurring payment retry process continues to apply.

As this feature is currently in Beta, we strongly recommend configuring and thoroughly testing Smart Retry in a Sandbox before enabling it in Production.

For setup instructions and further information, see How to Setup Decline Management for Regular Giving

General Updates

  • Suburb/Town is now marked as a required field by default in the manualPaymentAddress fieldset to avoid confusion with the error message displayed on the Manual Payments screen.
  • The Gift Designation field can now be added to the Batch Entry view. Previously, this functionality was only available in the Splits Entry module.
  • Approve Refund was not working for users assigned the Payments2Us Standard Permission Set. This has been resolved.
  • The $0 Free Membership functionality introduced in a previous release was causing unexpected behavior with payment options on Event and Peer-to-Peer payment forms. Payment options now work as expected in these scenarios.
  • Payment transactions were intermittently being incorrectly marked as “Free Memberships”. Payment transactions are now correctly classified.
  • The Westpac QuickStream Reconciliation Processor lookback window has been increased from 3 to 10 days, allowing Direct Debit transactions with delayed settlement updates to be reconciled correctly.
  • In some cases, Ezidebit internal/external card updates were populating an invalid value in the Billing Token field on recurring payment records. The Billing Token is now populated correctly.
  • Manual Direct Debit is now supported for the Blackbaud payment gateway.
  • Default field values were not populating correctly in the Batch Entry view. Default values now populate as expected.
  • Manual Payments LWC was incorrectly setting the Payment Method to “Manual” instead of the selected value, such as “Cash.” The selected Method of Payment is now retained correctly.
  • A paused Billing Processor is now automatically detected and restarted when batch processing is manually stopped and restarted from the Merchant Facility.
  • The Attainment Gauge widget had rendering problems on Checkout Forms. The widget now renders correctly.
  • Updated Payments2Us security settings to align with the latest Salesforce security standards.
  • The Xero Settings lookup on Account is now optional. If you are linking an Account to multiple Xero instances, you can use the Xero Settings lookup to specify the applicable instance. Otherwise, the field can be left blank.
  • Several reported behavior discrepancies related to the Refresh button in the Payment Form Builder have been addressed in this release.

 

Post Upgrade Steps

  • If you are using Payments2Us flows then review and activate the latest version of updated Flows. Please review Payments2Us Flows section above.
  • Setup Payments2Us News and Broadcast components on the views your team use the most in order to stay up to date with Payments2Us announcements and advisories. Review Add the News Broadcast/Popup component to a page section in order to complete setup in your org.
  • Add following picklist values in the Excluded from Sites Sharing Settings(AAkPay__Excluded_from_Sites_Sharing_Settings__c) picklist field on Merchant Facility object:
    • Campaign
    • AAkPay__Recurring_Payment__c
    • AAkPay__Payment_Txn__c
    • AAkPay__URL_Tokens__c
       
  • Add the Payments2Us News and Broadcast component to frequently visited pages, such as Payment Txn and Recurring Payment record detail pages, to stay up to date with important announcements and updates. For more information, please refer to the Setup and Use News Broadcasting help article.

Updated at September 22nd, 2026

Was this article helpful?