【问题标题】:StripeJS createToken requires a secret key instead of publishable keyStripeJS createToken 需要密钥而不是可发布密钥
【发布时间】:2018-10-30 03:00:39
【问题描述】:

假设以下代码:

const stripe = window.Stripe('pk_xxx', { stripeAccount: 'acct_xxx' });
const elements = stripe.elements();
const card = elements.create('card');

stripe.createToken(card);

它在 4 种可能的设置中的 3 种成功(测试环境进行 LIVE 条带调用,测试环境进行 TEST 条带调用,实时环境进行 LIVE 条带调用),但在实时环境中进行 TEST 条带调用时则失败。

失败并出现 403 错误和以下响应:

{
  "error": {
    "code": "secret_key_required",
    "doc_url": "https://stripe.com/docs/error-codes/secret-key-required",
    "message": "This API call cannot be made with a publishable API key. Please use a secret API key. You can find a list of your API keys at https://dashboard.stripe.com/account/apikeys.",
    "type": "invalid_request_error"
  }
}

JS 调用如何需要密钥?每个人都会看到它。

这是 HTTP 请求:

card[number]: 4242424242424242
card[cvc]: 242
card[exp_month]: 04
card[exp_year]: 24
card[address_zip]: 42424
guid: 282d554c-4271-4730-9df4-ad142b19a812
muid: 722e4d63-4df0-40db-8d60-100f841d1718
sid: d5f44fce-9835-497b-a4dd-766894b4c23a
payment_user_agent: stripe.js/3b5fc4c8; stripe-js-v3/3b5fc4c8
referrer: https://app.myowndomain.com/
key: pk_test_xxx (also tried the pk_live_xxx - no difference)
_stripe_account: acct_xxx

【问题讨论】:

    标签: stripe-payments


    【解决方案1】:

    问题在于使用 Stripe Connect 请求的范围。它被设置为“read_only”,而我需要“read_write”。

    Stripe 支持承认当前错误消息根本不直观这一事实,并已将信息传递给工程团队,因此开发人员不会感到困惑。

    【讨论】:

      【解决方案2】:

      创建令牌永远不需要秘密 API 密钥。这将是一个真正的安全问题,这就是为什么 Stripe 有一对密钥:服务器端代码的密钥和客户端代码的 Publishable 密钥。

      您共享的代码将始终使用可发布的密钥,并且创建令牌永远不会因该错误而失败。 Publishable 密钥也记录在案:https://stripe.com/docs/stripe.js

      在您的示例中说出导致这种情况的原因很棘手,但它必须与该行代码无关。代码中的其他内容将在创建令牌后触发,并且其他部分必须配置错误并且您的 Publishable 密钥服务器端。我建议您与 Stripe 的支持团队联系,因为他们可以直接调查您的帐户:https://support.stripe.com/email

      【讨论】:

        猜你喜欢
        • 2014-07-29
        • 2019-08-17
        • 1970-01-01
        • 1970-01-01
        • 2020-05-06
        • 1970-01-01
        • 1970-01-01
        • 2019-09-26
        • 1970-01-01
        相关资源
        最近更新 更多