如何通过PayPal确保我的支付系统的安全性?

qg_*_*137 5 javascript payment paypal

如何通过PayPal确保我的支付系统的安全性?

我使用vue-paypal-check创建前端PayPal按钮进行付款.

代码如下:

  <Pay-Pal
    v-if="paypal_live_id && paypal_sandbox_id"
    :amount="amount"
    currency="USD"
    :client="credentials"
    :env="paypal_env"

    @payment-authorized="payment_authorized_cb"
    @payment-completed="payment_completed_cb"
    @payment-cancelled="payment_cancelled_cb"

    :items="pay_items"
  >

</Pay-Pal>
Run Code Online (Sandbox Code Playgroud)

一些dota如下:

data(){
  return {
    paypal_env: this.$GLOBAL_CONST.PAYMENT.PAYPAL_ENV,

    paypal_sandbox_id: undefined,
    paypal_live_id: undefined,
  }
},
computed: {

  credentials() {
    return {
      sandbox: this.paypal_sandbox_id,
      production: this.paypal_live_id,
    }
  },
},
Run Code Online (Sandbox Code Playgroud)

薪酬成功的回调方法:

  payment_completed_cb(res){
    some method to access API for payment success // there will request the API for change the order status or reduce the balance. 
  },
Run Code Online (Sandbox Code Playgroud)

但我有一个问题,如果客户的某人是技术上的邪恶,他payment_completed_cb直接打电话,而不是通过paypal付款.

我怎么能阻止这个?

Lex*_*Lex 1

这无法在前端安全地处理。正如您所指出的,有人可以手动调用该payment_completed_cb 函数。

您拥有的代码纯粹是为了用户体验。有人点击“购买”,他们转到 PayPal,购买,然后重定向回来,您的网站会说“谢谢”。这就是该函数应该做的全部事情,处理一些感谢提示的显示。

付款可能看似已完成,但可能需要一些时间才能解决。因此,PayPal 会回复一条“看起来不错”的消息,并将客户重定向回您的网站。并在以后真正完成移植。举个例子,如果在处理交易时贝宝认为它看起来具有欺诈性,他们可以取消付款。

为了解决所有这些问题,付款确认的实际处理将在服务器上进行。您可以将 Paypal 配置为在付款实际确认时对您选择的服务器执行 ping 操作(也将对客户隐藏)。这称为即时付款通知 (IPN)

这张图说明了交易流程。

图片来自这个iPN 介绍帖子 在此输入图像描述

您可以使用 NodeJS 来完成此操作,并将其作为无服务器函数部署到 AWS(前一百万个请求免费)。或者部署到免费的Heroku实例。这些都是便宜的选择,但如果服务器空闲,启动时间很短。根据我的经验,启动只需要 200-300 毫秒,不到一秒。这对于响应 HTML 请求来说太长了,但对于处理来自某些后台 API 的最终 ping 来说是完美的。

paypal ipn的示例节点实现

var ipn = require('paypal-ipn');

ipn.verify(params, function callback(err, msg) {
  if (err) {
    console.error(err);
  } else {
    // Do stuff with original params here

    if (params.payment_status == 'Completed') {
      // Payment has been confirmed as completed
    }
  }
});

//You can also pass a settings object to the verify function:
ipn.verify(params, {'allow_sandbox': true}, function callback(err, mes) {
  //The library will attempt to verify test payments instead of blocking them
});
Run Code Online (Sandbox Code Playgroud)

有关集成步骤的深入指南 Paypal 有文档Paypal IPN