
时间:2013-05-14 17:26:12

标签: html forms iframe

我继承了一个使用Cyber​​source作为信用卡处理公司的应用程序。它目前使用Cyber​​Source API,我正在尝试将其转换为使用其托管订单页面 - 特别是静默订单发布方法。 Cyber​​Source提供的运行示例如下:

<form action="" method="POST">
    <% insertSignature3("10", "USD", "sale"); %>
        <h2>Payment Information</h2>
        Card Type:      <select name="card_cardType"><br>
                            <option value="">
                            <option value="001">Visa
                            <option value="002">MasterCard
                            <option value="003">American Express
        Card Number:        <input type="text" name="card_accountNumber"><br>
        Expiration Month:   <input type="text" name="card_expirationMonth"> (mm)<br>
        Expiration Year:    <input type="text" name="card_expirationYear"> (yyyy)<br><br>

    <h2>Ready to Check Out!</h2>
                            <input type="submit" name="submit" value="Buy Now">



 public void insertSignature3( String amount, String currency, String orderPage_transactionType )
            TimeSpan timeSpanTime = DateTime.UtcNow - new DateTime( 1970, 1, 1 );
            String[] arrayTime = timeSpanTime.TotalMilliseconds.ToString().Split( '.' );
            String time = arrayTime[0];
            String merchantID = GetMerchantID();
            if ( merchantID.Equals( "" ) )
                Response.Write( "<b>Error:</b> <br>The current security script (HOP.cs) doesn't contain your merchant information. Please login to the <a href=''>CyberSource Business Center</a> and generate one before proceeding further. Be sure to replace the existing HOP.cs with the newly generated HOP.cs.<br><br>" );
            String data = merchantID + amount + currency + time + orderPage_transactionType;
            String pub = GetSharedSecret();
            String serialNumber = GetSerialNumber();
            byte[] byteData = System.Text.Encoding.UTF8.GetBytes( data );
            byte[] byteKey = System.Text.Encoding.UTF8.GetBytes( pub );
            HMACSHA1 hmac = new HMACSHA1( byteKey );
            String publicDigest = Convert.ToBase64String( hmac.ComputeHash( byteData ) );
            publicDigest = publicDigest.Replace( "\n", "" );
            System.Text.StringBuilder sb = new System.Text.StringBuilder();
            sb.Append( "<input type=\"hidden\" name=\"amount\" value=\"" );
            sb.Append( amount );
            sb.Append( "\">\n<input type=\"hidden\" name=\"currency\" value=\"" );
            sb.Append( currency );
            sb.Append( "\">\n<input type=\"hidden\" name=\"orderPage_timestamp\" value=\"" );
            sb.Append( time );
            sb.Append( "\">\n<input type=\"hidden\" name=\"merchantID\" value=\"" );
            sb.Append( merchantID );
            sb.Append( "\">\n<input type=\"hidden\" name=\"orderPage_transactionType\" value=\"" );
            sb.Append( orderPage_transactionType );
            sb.Append( "\">\n<input type=\"hidden\" name=\"orderPage_signaturePublic\" value=\"" );
            sb.Append( publicDigest );
            sb.Append( "\">\n<input type=\"hidden\" name=\"orderPage_version\" value=\"4\">\n" );
            sb.Append( "<input type=\"hidden\" name=\"orderPage_serialNumber\" value=\"" );
            sb.Append( serialNumber );
            sb.Append( "\">\n" );
            Response.Write( sb.ToString() );
        catch ( Exception e )
            Response.Write( e.StackTrace.ToString() );



1 个答案:

答案 0 :(得分:1)


protected virtual void Page_Load(Object sender, EventArgs e)

    if (!Page.IsPostBack)
        //Do any page binding, etc that needs to be done on intitial page load
        //We came back from CyberSource ...

        //Will need to get from stored client hidden field ...
        string decision = Request.Form["decision"];

        if (verifyTransactionSignature(Request))
            //Make sure we are only processing in the TEST environment if the particular setting
            //is set to test (Site_Settings.CYBERSOURCE_API_URL contains 'test' in it)
            string apiUrl = Settings.GetSetting(LocalConnectionString, "CYBERSOURCE_API_URL");
            //API isn't test, but CyberSource is (someone hacking?)
            if (!apiUrl.ToLower().Contains("test") && Request.Form["orderPage_environment"].ToLower().Contains("test"))
                lblError.Text = "Unable to verify credit card. Request is in test mode, but the site is not.  Contact Customer Service.";

            Response.Write("<span class='ccInfo hide'>");
            for (int i = 0; i < Request.Form.Count; i++)
                var key = Request.Form.GetKey(i);

                if (key != "__VIEWSTATE")
                    Response.Write("<input type='hidden' id='" + key + "' name='" + key + "' value='" + Request.Form[i] + "' class='hide' />");

            if (decision != "ACCEPT")
                string reasonCode = Request.Form["reasonCode"];

                lblError.Text = "Unable to verify credit card (" + reasonCode + ") ";
                if (reasonCode == "102")
                    lblError.Text += "<br />One or more fields in the request contains invalid data.  Typically this is the expiration date";
            lblError.Text = "Unable to verify credit card. Transaction Signature not valid.  Contact Customer Service.";


$(document).ready(function () {
    var decision = $('#decision');

    if (decision.length > 0) {
        if (decision.val() === "ACCEPT") {
            //pass in requestId, etc to the billing page

            //call billing.aspx submit function

        } else {
            //change from loading animation to iframe



