在Salesforce LWC中无法通过Stripe创建支付方式的问题
Stripe添加银行卡错误解决及合规方案
问题说明
当前遇到错误:sending credit card numbers directly to the stripe api is generally unsafe.,需求是为用户添加银行卡并返回支付方式ID。
错误原因
直接将银行卡号、CVC等敏感信息通过后端发送到Stripe API,违反了Stripe的PCI合规要求,同时存在数据泄露风险,因此Stripe阻止了这类请求。
正确解决方案(生产环境必须使用)
Stripe要求通过前端Stripe Elements组件收集银行卡信息,前端调用Stripe SDK生成支付Token(如tok_xxx或pm_xxx),后端仅需将Token发送给Stripe API来创建支付方式,全程不触碰敏感卡号数据。
修改后端Apex代码
将原直接处理卡号的逻辑改为接收前端生成的Token:
@AuraEnabled public static Map<String, TS_Stripe.StripeResponse> createCardOnStripe(TS_Stripe input) { Map<String, TS_Stripe.StripeResponse> responseMap = new Map<String, TS_Stripe.StripeResponse>(); TS_Stripe.StripeResponse stripeResponse = new TS_Stripe.StripeResponse(); System.debug('createCardOnStripe :: ' + input); try { // 推荐使用新版payment_methods端点,替代旧版sources String endpoint = BASE_URL + '/customers/' + input.stripeCardInput?.customerId + '/payment_methods'; // 使用前端传递的支付Token创建支付方式 String body = 'payment_method=' + EncodingUtil.urlEncode(input.stripeCardInput?.paymentToken, 'UTF-8'); String response = makeStripeRequest('POST', endpoint, body); Map<String, Object> jsonResponse = (Map<String, Object>) JSON.deserializeUntyped(response); System.debug('JSON Response :: ' + jsonResponse); String paymentMethodId = (String) jsonResponse.get('id'); stripeResponse.response = jsonResponse; stripeResponse.cardId = paymentMethodId; // 可改为paymentMethodId更贴合语义 responseMap.put('success', stripeResponse); } catch (Exception e) { System.debug(e); stripeResponse.errorMessage = e.getMessage(); responseMap.put('error', stripeResponse); } return responseMap; }
前端配合操作
- 集成Stripe Elements组件到前端页面,用于安全收集用户银行卡信息;
- 用户提交卡片信息时,调用Stripe SDK的
createPaymentMethod或createToken方法,生成支付Token; - 将生成的Token传递给上述Apex方法,完成支付方式绑定。
测试环境临时解决方案
仅用于测试场景,生产环境绝对禁止使用:
登录Stripe后台,进入【开发者】->【API设置】,找到测试模式下允许原始银行卡数据选项,开启后测试环境可暂时使用原代码直接发送卡号信息,但生产环境必须关闭该选项并切换到Token方案。
内容的提问来源于stack exchange,提问作者Isara Didulantha
相关产品推荐
相关产品推荐

