[PEPr] Comment on Payment::Ewire_Payment
| From: | Philippe Jausions | Date: | Wed, 30 Mar 2005 00:00:52 +0000 |
| Subject: | [PEPr] Comment on Payment::Ewire_Payment | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-36976@lists.php.net to get a copy of this message | ||
Philippe Jausions (http://pear.php.net/user/jausions) has commented on the proposal for
Payment::Ewire_Payment.
Comment:
Hi,
Given that there is no English version of their web site, I can't help
much there, but isn't there a better secure method than parsing an e-mail
to receive the notification of payment?
Seems very flimsy as far as security is concerned. Anybody can forge an
e-mail.
Please check in their developers' site to find a better solution than
that. Callback URL for instance is much more secure.
As is, I wouldn't want this package in PEAR because of the false sense of
security for anybody that would use it.
If the package is reworked around a more secure solution, and then cleaned
up for PEAR Coding Standard, that could be a good addition to PEAR to
whoever lives "up North" ;-)
-Philippe
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=233
--
Sent by PEPr, the automatic proposal system at http://pear.php.net