My aim is to verify the IPN return from PayPal by ensuring:

  • Gross PayPal amount is equal to Transaction Gross (attempts to prevent payment adjustment whereby the transaction sent to PayPal contains a lesser payment than the original transaction)
  • IPN came from a specific account by passing a 'secret' query in the IPN url left with PayPal and known by the paypal.module

Previously the IPN url was:

foo.com/?q=paypal/ipn

I'm proposing:

foo.com/?q=paypal/ipn&secret=unique_string

where unique_string is a variable defined in the paypal.module admin section.

CommentFileSizeAuthor
paypal_module.diff.txt3.96 KBgocarts

Comments

gocarts’s picture

Missed mentioning that if either condition fails a watchdog error is triggered (recorded in ?q=admin), and the related IPN info is not recorded in the transaction - thus avoids triggering payment confirmations.

gordon’s picture

This is an interesting approach.

The method that we are looking at using for 5, is splitting the payments from the transactions as receipts, then the receipts will be allocated to the transactions, and making the relationship a many to many. ie 1 transaction can have many payments, and 1 payment can be made against many transactions.

This means that if someone tries to spoof a payment, nothing will happen except they will have just short paid a transaction. If they start to wonder where there products are, they will get told they have not paid enough,

gordon’s picture

Status: Needs review » Fixed

This has been fixed in v4, but is able to be ported to v3

Anonymous’s picture

Status: Fixed » Closed (fixed)