Jump to content

Recommended Posts

This may be a long shot but is there a way to configure your server to disable certain POSTs? I'm working with the Authorize.net SIM API which after a successful transaction you can get authorize.net to POST data to a particular web page. The POST sends back customer name, amount of transaction, date, billing information, shipping information, and it also post back the credit card like so "XXXXXXXX3043".

 

To limit my exposure to any kind of credit card information i'd rather just disable the $_POST['x_card_number'] that gets posted.

 

Is that possible?

Link to comment
https://forums.phpfreaks.com/topic/242503-disable-certain-posts/
Share on other sites

POST data is just sent as a simple sting to the web server. Plus you can't "conditionally deny a request" without the server having received it. What are you going to do with the last 4 digits though? It's sent that way purposefully to make it useless.

Absolutely nothing. I only want to store Customer name, transaction ID, and the amount but since the POST has cardholder data, that requires my server and code to be PCI compliant...which is a headache.

 

Who else will be able to see POST['x_card_number']?

 

I dont see the security issue here.

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.