【发布时间】:2013-06-09 06:48:50
【问题描述】:
我有一个 wordpress 1 页网站,可以选择在贝宝捐赠后下载音乐曲目 - 最低金额为 3.99 美元。
按钮工作正常,paypal 付款通过 - 但我只是从 paypal 收到 INVALID - 它似乎没有正确地将内容写回 paypal。
另外 - 我如何查看 paypal 发回给我的内容?
非常感谢任何帮助!
在包含的 php 文件中:
<?php echo "<p class='small-donate'>Minimum ammount for donation is $3.99</p>
<form method='POST' action='' target='_top'>
$<input type='text' name='donate_amount' value='0' size='4' class='donate-input'>
<input type='submit' name='submit' value='Donate' class='donate-submit'></form>";
if(!empty($_POST['submit'])) {
// Form has been submitted
if($_POST['donate_amount'] >= 3.99) {
// Redirect to PayPal
$myurl = site_url();
$fileurl = site_url('wp-content/themes/MY_THEME/content-download-file.php');
header('Location: https://www.sandbox.paypal.com/cgi-bin/webscr?cmd=_donations&item_name=Donation for music track&amount='.$_POST['donate_amount'].'¤cy_code=USD&business=MY_SANDBOX_TEST_EMAIL&cbt=Download the file&return='.$fileurl.'&cancel_return='.$myurl);
}
else {
echo '<span class="error">Donation must be at least $3.99</span>';
}
}
?>
在 content-download-file.php 内
(我从贝宝开发者那里得到这个)
<?php
// STEP 1: read POST data
// Reading POSTed data directly from $_POST causes serialization issues with array data in the POST.
// Instead, read raw POST data from the input stream.
$raw_post_data = file_get_contents('php://input');
$raw_post_array = explode('&', $raw_post_data);
$myPost = array();
foreach ($raw_post_array as $keyval) {
$keyval = explode ('=', $keyval);
if (count($keyval) == 2)
$myPost[$keyval[0]] = urldecode($keyval[1]);
}
// read the IPN message sent from PayPal and prepend 'cmd=_notify-validate'
$req = 'cmd=_notify-validate';
if(function_exists('get_magic_quotes_gpc')) {
$get_magic_quotes_exists = true;
}
foreach ($myPost as $key => $value) {
if($get_magic_quotes_exists == true && get_magic_quotes_gpc() == 1) {
$value = urlencode(stripslashes($value));
} else {
$value = urlencode($value);
}
$req .= "&$key=$value";
}
// Step 2: POST IPN data back to PayPal to validate
$ch = curl_init('https://www.sandbox.paypal.com/cgi-bin/webscr');
curl_setopt($ch, CURLOPT_HTTP_VERSION, CURL_HTTP_VERSION_1_1);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_POSTFIELDS, $req);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 1);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
curl_setopt($ch, CURLOPT_FORBID_REUSE, 1);
curl_setopt($ch, CURLOPT_HTTPHEADER, array('Connection: Close'));
// In wamp-like environments that do not come bundled with root authority certificates,
// please download 'cacert.pem' from "http://curl.haxx.se/docs/caextract.html" and set
// the directory path of the certificate as shown below:
// curl_setopt($ch, CURLOPT_CAINFO, dirname(__FILE__) . '/cacert.pem');
curl_setopt($ch, CURLOPT_CAINFO, dirname(__FILE__) . '/cacert.pem');
if( !($res = curl_exec($ch)) ) {
//error_log("Got " . curl_error($ch) . " when processing IPN data");
curl_close($ch);
exit;
}
curl_close($ch);
// inspect IPN validation result and act accordingly
if (strcmp ($res, "VERIFIED") == 0) {
echo '<section id="download">
<h2>Download song</h2>
<a href="FILE_PATH">FILE Here</a>
</section>';
}
else if (strcmp ($res, "INVALID") == 0) {
echo "The response from IPN was: <b>" .$res ."</b>";
}
?>
【问题讨论】:
-
您是否传递了任何未经 URL 编码的特殊字符?你能提供一个我可以查到的交易ID吗?
-
@PayPal_Patrick 你是什么意思?我仍在寻找一种方法来回应贝宝的回应。
-
如果您在返回 PayPal 的响应中传递了一个类似 & * ^ % 或类似的字符,而没有对它们进行 URL 编码,您将得到一个无效的响应。让我拿一个我有的用于发送电子邮件的测试 IPN 脚本。它写出完整的响应并生成一封电子邮件到您定义的任何位置,并为您提供验证响应。你可以用它来测试。我会添加它作为答案。