Payflow Pro functions
| From: | Javier Muniz | Date: | Wed, 29 Nov 2000 02:20:02 +0000 |
| Subject: | Payflow Pro functions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-27752@lists.php.net to get a copy of this message | ||
After a short discussion with Lars Wilson, I've been asked to post the
following here... it occured to me while reading the manual's user
contributed notes, and I have yet to test it (probably will sometime
next month)
You could run two instances of apache side-by-side, one compiled with
SSL+PHP4, the other compiled with PHP4+PayfloPro SDK. The
PayFlowPro-enabled instance should listen only on lo0 as to prevent
attacks from the outside world (to snoop on lo0 you should need root, in
which case the server is already compromised). The SSL+PHP4 instance
could then make http sub-requests to the PayFlowPro-enabled server,
which would do the actual processing.
For extra cleanliness, the PayFlowPro-enabled server could respond in
XML.
I have not looked into all of the security implications of such an
implementation, and welcome comments.