【问题标题】:MIGS Online Payments SHA256 HMAC ErrorMIGS 在线支付 SHA256 HMAC 错误
【发布时间】:2016-11-22 05:21:17
【问题描述】:

Bendigo Bank 告诉我,我们需要将 md5 更改为 SHA256。我已按照他们的指示进行操作,但出现此错误:

HTTP Status - 400
E5000: Cannot form a matching secure hash based on the merchant's request using either of the two merchant's secrets

他们的示例代码是这样的:

<?php foreach($_POST as $key => $value) {
    if (strlen($value) > 0) { ?>
            <input type="hidden" name="<?php echo($key); ?>" value="<?php echo($value); ?>"/><br>
    <?php           
        if ((strlen($value) > 0) && ((substr($key, 0,4)=="vpc_") || (substr($key,0,5) =="user_"))) {
            $hashinput .= $key . "=" . $value . "&";
        }
    }
}
$hashinput = rtrim($hashinput,"&");
?>
<!-- attach SecureHash -->
<input type="hidden" name="vpc_SecureHash" value="<?php echo(strtoupper(hash_hmac('SHA256', $hashinput, pack('H*',$securesecret)))); ?>"/>
<input type="hidden" name="vpc_SecureHashType" value="SHA256">

这是我的帖子:

Array (
    [AgainLink] => http://fallscreekcountryclub.com.au/make-a-booking/submit-booking.html
    [b_terms] => 1
    [chargetypeid] => 33
    [deposit] => 580.00
    [notes] => 4 Nights - 26/11/2016 to 30/11/2016
    [propertyid] => 2
    [total] => 580.00
    [vpc_AccessCode] => 903876BC
    [vpc_Amount] => 58000
    [vpc_Command] => pay
    [vpc_Locale] => en
    [vpc_MerchTxnRef] => 1479746896
    [vpc_Merchant] => BBL5800396
    [vpc_OrderInfo] => Studio Deluxe
    [vpc_ReturnURL] => http://fallscreekcountryclub.com.au/make-a-booking/booking-complete.html
    [vpc_Version] => 1
)

这是我的代码:

        $appendAmp = 0;
        $isencoded = '';
        $notencoded = '';
        foreach($_POST as $key => $value) {
            if (strlen($value) > 0) {
                if ($appendAmp == 0) :
                    $notencoded     .= $key . '=' . $value;
                    $isencoded      .= urlencode($key) . '=' . urlencode($value);
                    $appendAmp       = 1;
                else :
                    $notencoded     .= '&' . $key . '=' . $value;
                    $isencoded      .= '&' . urlencode($key) . '=' . urlencode($value);
                endif;
            }
        }

        if (strlen($SECURE_SECRET) > 0) {
            #$vpcURL .= "&vpc_SecureHash=" . strtoupper(md5($md5HashData));
            $SecureHash     = strtoupper(hash_hmac('SHA256',$notencoded,pack('H*',$SECURE_SECRET)));
            $SecureHashType = 'SHA256';
        }
        $vpcURL .= $notencoded.'&vpc_SecureHash='.$SecureHash.'&vpc_SecureHashType='.$SecureHashType;

我有“isencoded”和“notencoded”,因为我看到人们说在我构建 vpcURL 之前对 vpc_ReturnURL 的字符串进行 urlencode,但两者都不起作用。

vpcURL 的 urlencoded 版本是:

https://migs.mastercard.com.au/vpcpay?AgainLink=http%3A%2F%2Ffallscreekcountryclub.com.au%2Fmake-a-booking%2Fsubmit-booking.html&b_terms=1&chargetypeid=33&deposit=580.00&notes=4+Nights+-+26%2F11%2F2016+to+30%2F11%2F2016&propertyid=2&total=580.00&vpc_AccessCode=903876BC&vpc_Amount=58000&vpc_Command=pay&vpc_Locale=en&vpc_MerchTxnRef=1479746896&vpc_Merchant=BBL5800396&vpc_OrderInfo=Studio+Deluxe&vpc_ReturnURL=http%3A%2F%2Ffallscreekcountryclub.com.au%2Fmake-a-booking%2Fbooking-complete.html&vpc_Version=1&vpc_SecureHash=A5BA6503FC7A169A90C9AAC7039878F45D761180D874789172EB5A58298022E4&vpc_SecureHashType=SHA256 

非urlencoded版本是:

https://migs.mastercard.com.au/vpcpay?AgainLink=http://fallscreekcountryclub.com.au/make-a-booking/submit-booking.html&b_terms=1&chargetypeid=33&deposit=580.00&notes=4 Nights - 26/11/2016 to 30/11/2016&propertyid=2&total=580.00&vpc_AccessCode=903876BC&vpc_Amount=58000&vpc_Command=pay&vpc_Locale=en&vpc_MerchTxnRef=1479746896&vpc_Merchant=BBL5800396&vpc_OrderInfo=Studio Deluxe&vpc_ReturnURL=http://fallscreekcountryclub.com.au/make-a-booking/booking-complete.html&vpc_Version=1&vpc_SecureHash=A5BA6503FC7A169A90C9AAC7039878F45D761180D874789172EB5A58298022E4&vpc_SecureHashType=SHA256 

关于我做错了什么有什么想法吗?我打电话给银行,他们无法帮助我,他们甚至不知道我在说什么..

我知道 $SECURE_SECRET 数字是正确的,因为它与我用于原始 md5 哈希的数字相同。所以问题出在 sha256 哈希上,我不知道为什么,也不知道如何解决。

【问题讨论】:

    标签: php payment-gateway sha256 hmac


    【解决方案1】:

    您好,我正在与您分享我的工作代码。 享受吧。

       $secretHash="xxxxxx";
        $accessCode='xxxxx';
        $merchantId='xxxxx';    
    
        $data = array(
            "vpc_AccessCode" => $accessCode,
            "vpc_Amount" => '100',
            "vpc_Command" => 'pay',
            "vpc_Locale" => 'en',
            "vpc_MerchTxnRef" =>  "REF_".time(),
            "vpc_Merchant" => $merchantId,
            "vpc_OrderInfo" => "Order_N_".time(),
            "vpc_ReturnURL" => urlencode("yourReturnUrl"),
            "vpc_Version" => '1',
            'vpc_SecureHashType' => 'SHA256'    
        );
    
        ksort($data);
        $hash = null;
        foreach ($data as $k => $v) {
            if (in_array($k, array('vpc_SecureHash', 'vpc_SecureHashType'))) {
                continue;
            }
            if ((strlen($v) > 0) && ((substr($k, 0, 4)=="vpc_") || (substr($k, 0, 5) =="user_"))) {
                $hash .= $k . "=" . $v . "&";
            }
        }
        $hash = rtrim($hash, "&");
    
        $secureHash = strtoupper(hash_hmac('SHA256', $hash, pack('H*', $secretHash)));
        $paraFinale = array_merge($data, array('vpc_SecureHash' => $secureHash));
        $actionurl = 'https://migs.mastercard.com.au/vpcpay?'.http_build_query($paraFinale);
    
        //print_r($actionurl);
        header("Location:".$actionurl);
    

    【讨论】:

    • 谢谢你:)
    • 经过一整天的搜索,这是唯一有效的版本
    • @moussa 你知道用post 的方法吗?
    【解决方案2】:
    1. 在链接参数之前使用ksort() 对数组进行排序。
    2. 不要使用urlencode()处理vpc_ReturnURL,这会导致SHA256哈希结果不正确。以下是我从官方故障排除指南中找到的内容:

    c) 确保 vpc_ReturnURL 未经过 URL 编码(即“/”变为 %2f) 您可以使用以下链接来解码 URL - http://meyerweb.com/eric/tools/dencoder/ 基于此示例的排序字符串示例如下:(从 2b 的输出中删除了 jsessionid、noheader、tdrid)即可以在排序之前删除这些元素

    vpc_AccessCode=A837820A&vpc_Amount=100&vpc_Card=VC&vpc_CardNum=4222222222222&vpc_CardSecurityCode=100&vpc_Command=pay&vpc_Gateway=threeDSecure&vpc_Locale=en&vpc_MerchTxnRef=T2_7956&vpc_Merchant=TESTDIALECTTEST&vpc_ReturnURL=http://anjumpc:8080/dev-pg/payment/3dprocess.do&vpc_Version=1
    
    1. 不要发送/散列不以 vpc_ 开头的键的值,因为 MGIS 不关心这些值,也不在散列检查中使用这些值。该指南还提到了这一点:

    b) 删除不必要的哈希计算字段,例如 vpc_SecureHashType、vpc_SecureHash 和任何不以 vpc_ 或 user_ 开头的字段 - 即上面 2a 中以粗体突出显示的字段

    1. (忽略此,SHA256 可用于工作的 MIGS 商户)

    【讨论】:

    • 好的,所以我做了更多的更改,我将我的字段更改为 user_,然后我还将 AgainLink 更改为 vpc_AgainLink,它起作用了.. :)
    • 你有官方故障排除指南的链接吗?
    • @MohamedSanaulla 抱歉,该指南只能从银行获得,恐怕我无法提供。
    • 谢谢,我们得到了指南,虽然有点晚了。但我之前在 ANZ 支付网关上找到了一张,上面有测试卡和关于 MIGS 支付系统的非常清晰的信息。
    【解决方案3】:

    尝试从被散列的字符串中排除 vpc_SecureHash 和 vpc_SecureHashType。这是代码sn -p

    https://gist.github.com/lucasnetau/bcacb528d664f0ad1339086c1a585021

    让我知道它是否有效..

    【讨论】:

    • 是的,这两个不是散列的一部分,它们是在全部散列后添加到末尾的。
    猜你喜欢
    • 1970-01-01
    • 2014-09-03
    • 1970-01-01
    • 1970-01-01
    • 2015-03-19
    • 2014-10-13
    • 2013-01-07
    • 2017-06-27
    • 1970-01-01
    相关资源
    最近更新 更多