我似乎无法使用Ruby进行商家会话验证。尝试了HTTParty和RestClient,我得到了:
OpenSSL :: SSL :: SSLError(SSL_connect返回= 1 errno = 0状态= SSLv3读取完成A:sslv3警报证书已过期):
我使用此节点服务器示例https://github.com/tomdale/apple-pay-merchant-session-server尝试了相同的证书,并且它运行正常,因此它必须是我的ruby代码中的内容。
有没有人设法让这个工作?
答案 0 :(得分:4)
我遇到了同样的问题。借助您引用的示例和https://github.com/norfolkmustard/ApplePayJS处的实现(另请参阅https://forums.developer.apple.com/thread/51580处的实施讨论),我能够使其正常运行。
对我而言,关键在于传递正确的证书(Apple Pay商户身份证书),正如Apple提供的那样,并获得证书密钥,如下所示:
获得Apple的商家ID(会话)证书后,通过双击将其导入Mac上的keychain.app,右键单击钥匙串中的证书,然后将组合的私钥和证书导出为。 p12文件然后,在终端: -
openssl pkcs12 -in your_merchant_identity_cert_name.p12 -out ApplePay.key.pem -nocerts -nodes
将Apple的Apple Pay Merchant Identification证书和ApplePay.key.pem
文件的内容添加到环境变量后,我能够使用Ruby的Net :: HTTP类构建以下请求...
class YourControllerName < ApplicationController
def apple_pay_validation
respond_to do |format|
format.json { render json: start_apple_session(params[:url]) } if params[:url].include?('apple.com')
end
end
private
def start_apple_session(url)
uri = URI.parse(url) # the url from event.validationURL
data = {'merchantIdentifier' => "merchant.com.your_site_name", 'domainName' => "your_doamin", 'displayName' => "your_company_name"}
pem = File.read('path/to/your/merchant_id.cer')
key = ENV['APPLE_PAY_MERCHANT_ID_ KEY']
passphrase = 'passphrase set up when exporting certificate in keychain' # Should be an environment variable
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
http.ssl_version = :TLSv1_2
http.ciphers = ['ECDHE-RSA-AES128-GCM-SHA256']
http.cert = OpenSSL::X509::Certificate.new(pem)
http.key = OpenSSL::PKey::RSA.new(key, passphrase)
http.verify_mode = OpenSSL::SSL::VERIFY_PEER
request = Net::HTTP::Post.new(uri.request_uri, 'Content-Type' => 'application/json')
request.body = data.to_json
response = http.request(request)
response.body
end
end
这是从我的performValidation
函数调用的(在上面列出的ApplePayJS repo中修改过),看起来像这样。
performValidation = (valURL) ->
new Promise((resolve, reject) ->
xhr = new XMLHttpRequest
xhr.open 'GET', '/your_controller_name/apple_pay_validation?url=' + valURL
xhr.onerror = reject
xhr.onload = ->
data = JSON.parse(@responseText)
resolve data
xhr.send()
)
希望这有助于节省一些时间和白发!