[_] PHP header() GET not POST
Mike Walters
qwerty_1997 at hotmail.com
Sun Sep 3 16:59:15 BST 2006
>You are right that I should consider a new PSP or at least find out if they
>offer any other single page interface as per DH's post.
Or maybe not ... I did a search for Bristol + PROTX and chose one of the
sites on the first few pages.
Now, I didn't actually complete an order as I want to get permission TCMA in
case I get accused of fraud.
However I was able to edit the form and change the parameters (price!!!)
then post it to PROTX.
I'm not sure that any site that requires a 3rd party for billing is secure,
unless they allow a certain amount of behind the scenes communication to the
shop. It would only work if the only data sent in the GET or POST were some
unique key and the invoice data were sent direct to the PSP prior.
Of course, I can spot this after the transaction has taken place. That is
annoying but still OK for physical merchandise but not OK for any
access/PPV/downloads/etc.
Are there any PSP's that allow a shop to communicate direct to a web service
or do they all insist on the user having at least some input, even if it is
just an 'CONFIRM PAYMENT' on their SSL site?
_________________________________________________________________
Be the first to hear what's new at MSN - sign up to our free newsletters!
http://www.msn.co.uk/newsletters