You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Salesforce LWC中无法通过Stripe创建支付方式的问题

Stripe添加银行卡错误解决及合规方案

问题说明

当前遇到错误:sending credit card numbers directly to the stripe api is generally unsafe.,需求是为用户添加银行卡并返回支付方式ID。

错误原因

直接将银行卡号、CVC等敏感信息通过后端发送到Stripe API,违反了Stripe的PCI合规要求,同时存在数据泄露风险,因此Stripe阻止了这类请求。

正确解决方案(生产环境必须使用)

Stripe要求通过前端Stripe Elements组件收集银行卡信息,前端调用Stripe SDK生成支付Token(如tok_xxx或pm_xxx),后端仅需将Token发送给Stripe API来创建支付方式,全程不触碰敏感卡号数据。

修改后端Apex代码

将原直接处理卡号的逻辑改为接收前端生成的Token:

@AuraEnabled
public static Map<String, TS_Stripe.StripeResponse> createCardOnStripe(TS_Stripe input) {
    Map<String, TS_Stripe.StripeResponse> responseMap = new Map<String, TS_Stripe.StripeResponse>();
    TS_Stripe.StripeResponse stripeResponse = new TS_Stripe.StripeResponse();
    System.debug('createCardOnStripe :: ' + input);

    try {
        // 推荐使用新版payment_methods端点,替代旧版sources
        String endpoint = BASE_URL + '/customers/' + input.stripeCardInput?.customerId + '/payment_methods';

        // 使用前端传递的支付Token创建支付方式
        String body = 'payment_method=' + EncodingUtil.urlEncode(input.stripeCardInput?.paymentToken, 'UTF-8');

        String response = makeStripeRequest('POST', endpoint, body);

        Map<String, Object> jsonResponse = (Map<String, Object>) JSON.deserializeUntyped(response);
        System.debug('JSON Response :: ' + jsonResponse);
        String paymentMethodId = (String) jsonResponse.get('id');

        stripeResponse.response = jsonResponse;
        stripeResponse.cardId = paymentMethodId; // 可改为paymentMethodId更贴合语义
        responseMap.put('success', stripeResponse);
    } catch (Exception e) {
        System.debug(e);
        stripeResponse.errorMessage = e.getMessage();
        responseMap.put('error', stripeResponse);
    }

    return responseMap;
}

前端配合操作

  1. 集成Stripe Elements组件到前端页面,用于安全收集用户银行卡信息;
  2. 用户提交卡片信息时,调用Stripe SDK的createPaymentMethod或createToken方法,生成支付Token;
  3. 将生成的Token传递给上述Apex方法,完成支付方式绑定。

测试环境临时解决方案

仅用于测试场景,生产环境绝对禁止使用:
登录Stripe后台,进入【开发者】->【API设置】,找到测试模式下允许原始银行卡数据选项,开启后测试环境可暂时使用原代码直接发送卡号信息,但生产环境必须关闭该选项并切换到Token方案。

内容的提问来源于stack exchange,提问作者Isara Didulantha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 16:42:32