Stripe Payment Intent API GET/POST方法异常问题求助
Stripe Payment Intent API移动端调用异常解决方案
核心问题分析
1. 严重安全漏洞:前端暴露Stripe Secret Key
你当前代码里直接在移动端使用sk_test_开头的Secret Key,这是绝对禁止的。Secret Key拥有Stripe账户的全部权限,一旦泄露会导致账户被盗用,所有支付意图创建操作必须移到后端执行,前端只能调用自己的后端接口获取Payment Intent的client_secret。
2. 请求方法与API规范不符
创建Payment Intent必须使用POST方法,Stripe的GET /v1/payment_intents接口是用来查询已有支付意图列表的,根本不支持创建资源。Android端看似能用GET调用成功,其实是异常的错误情况,并非API的正常行为。
3. 请求数据格式错误
- 你设置的
Content-Type是application/x-www-form-urlencoded,但却把数据用JSON.stringify转成了JSON字符串,Stripe无法正确解析这种格式的参数,所以POST请求会报Missing required param: amount。 - GET请求时,Axios会把
data里的内容拼接到URL的查询参数中,当参数内容过长时会触发移动端的URL长度限制,导致resource exceeds maximum size错误。
解决方案
第一步:后端实现创建Payment Intent的接口
必须在后端使用Stripe官方SDK来创建Payment Intent,以下是Node.js示例:
const stripe = require('stripe')('sk_test_你的SecretKey'); app.post('/create-payment-intent', async (req, res) => { const { customerId } = req.body; const paymentIntent = await stripe.paymentIntents.create({ customer: customerId, currency: 'inr', amount: 1000, // 单位:最小货币单位,这里对应10印度卢比 automatic_payment_methods: { enabled: true, }, }); res.json({ clientSecret: paymentIntent.client_secret }); });
第二步:前端调用自己的后端接口获取client_secret
修改前端代码,不再直接调用Stripe API,而是请求自己的后端:
// 前端请求自有后端接口 axios.post('/create-payment-intent', { customerId: customerId }) .then(function (response) { const clientSecret = response.data.clientSecret; // 用clientSecret初始化Payment Sheet initPaymentSheet(clientSecret); }) .catch(function (error) { console.error('创建支付意图失败', error); }); // 初始化Payment Sheet示例(基于Stripe官方SDK) async function initPaymentSheet(clientSecret) { const { error } = await stripe.initPaymentSheet({ paymentIntentClientSecret: clientSecret, merchantDisplayName: '你的商家名称', }); if (!error) { await stripe.presentPaymentSheet(); } }
为什么Postman能正常运行?
Postman里你大概率是正确设置了表单格式的参数(而非JSON),并且使用了POST方法,所以能正常请求。但移动端代码的格式、请求方法都不符合Stripe API要求,同时还存在严重的安全风险。
内容的提问来源于stack exchange,提问作者Vishal Dhanotiya
相关产品推荐
相关产品推荐

