PHP集成Cybersource Secure Hosted Checkout遇403未授权错误求助
Cybersource Secure Hosted Checkout 403授权错误排查
我在尝试用PHP脚本集成Cybersource支付网关的Secure Hosted Checkout功能,但提交结账请求后一直跳403错误页面,提示:
You are not authorized to view this page. The transaction has not been processed. Cybersource Secure Hosted Checkout
无法正常进入结账流程,相关代码如下:
核心变量定义
$access_key = "xxx"; $profile_id = "xxx-F35F-43D3-A952-4484D3F7635E"; $secret_key = "xxx"; $transaction_uuid = uniqid(); $signed_date_time = gmdate("Y-m-d\TH:i:s\Z"); $order_id = time(); $reference_number = $order_id; $signed_field_names = "access_key,profile_id,amount,currency,locale,signed_date_time,signed_field_names,transaction_type,transaction_uuid"; $amount = '19.95'; $locale = 'en'; $transaction_type = 'sale'; $unsigned_field_names = ""; $currency = 'USD';
签名生成函数
function makeSignature($request_form_data, $secret_key) { echo "<pre>"; echo "Request FormData: <br>"; print_r($request_form_data); return signData(buildDataToSign($request_form_data), $secret_key); } function buildDataToSign($request_form_data) { $signedFieldNames = explode(",", $request_form_data["signed_field_names"]); foreach ($signedFieldNames as $field) { $dataToSign[] = $field . "=" . $request_form_data[$field]; } return commaSeparate($dataToSign); } function commaSeparate($dataToSign) { return implode(",", $dataToSign); } function signData($data, $secret_key) { return base64_encode(hash_hmac('sha256', $data, $secret_key, true)); }
提交表单
<form method="post" action="https://testsecureacceptance.cybersource.com/pay" name="checkout_form"> <input id="access_key" type="hidden" value="<?= $access_key ?>" name="access_key"> <input id="profile_id" type="hidden" value="<?= $profile_id ?>" name="profile_id"> <input id="transaction_type" type="hidden" value="<?= $transaction_type ?>" name="transaction_type"> <input id="amount" type="hidden" value="<?= $amount ?>" name="amount"> <input id="locale" type="hidden" value="<?= $locale ?>" name="locale"> <input id="transaction_uuid" type="hidden" value="<?= $transaction_uuid ?>" name="transaction_uuid"> <input id="signed_date_time" type="hidden" value="<?= $signed_date_time ?>" name="signed_date_time"> <input id="signed_field_names" type="hidden" value="<?= $signed_field_names ?>" name="signed_field_names"> <input id="currency" type="hidden" value="<?= $currency ?>" name="currency"> <input id="signature" type="hidden" value="<?= $signature ?>" name="signature"> <input type="submit" value="Submit"> </form>
排查与修复方案
签名验证失败(最常见原因)
- 确保生成签名时,
$request_form_data数组包含了signed_field_names里的所有字段,且字段值和表单提交的完全一致。需手动把所有签名字段打包成数组传入makeSignature:$request_form_data = [ 'access_key' => $access_key, 'profile_id' => $profile_id, 'amount' => $amount, 'currency' => $currency, 'locale' => $locale, 'signed_date_time' => $signed_date_time, 'signed_field_names' => $signed_field_names, 'transaction_type' => $transaction_type, 'transaction_uuid' => $transaction_uuid ]; $signature = makeSignature($request_form_data, $secret_key); - 检查
signed_date_time的格式:必须是GMT时间,严格遵循YYYY-MM-DDTHH:MM:SSZ格式,注意是大写Z,不能有空格或格式错误。 - 字段顺序严格匹配:
buildDataToSign函数必须按照signed_field_names定义的顺序拼接字段,顺序错误会直接导致签名验证不通过。
- 确保生成签名时,
凭证与配置问题
- 确认
access_key、profile_id、secret_key是测试环境的有效凭证,且已关联到正确的Secure Hosted Checkout配置文件。 - 检查Cybersource后台是否限制了请求来源IP,需将你的服务器IP添加到白名单中。
- 确认
表单提交细节
- 确认表单
action地址正确:测试环境为https://testsecureacceptance.cybersource.com/pay,生产环境地址不同,请勿混淆。 - 确保
$signature没有被HTML转义(比如避免用htmlspecialchars处理签名值),否则会破坏签名的有效性。
- 确认表单
内容的提问来源于stack exchange,提问作者Bishal Jung Chettri
相关产品推荐
相关产品推荐

