Core PHP集成Instamojo支付网关:获取longurl跳转链接报错
Instamojo生产环境跳转longurl报错的解决方案
问题背景
用原生PHP集成Instamojo支付网关,测试环境(test.instamojo.com)运行正常,但切换到生产环境后,在获取longurl并执行跳转时出现错误。
Instamojo返回的JSON响应:
{ "success": true, "payment_request": { "id": "47a321d9*****************bbb55f64", "phone": "+9170******55", "email": "a*******@gmail.com", "buyer_name": "Aman", "amount": "100.00", "purpose": "FIFA", "expires_at": null, "status": "Pending", "send_sms": true, "send_email": true, "sms_status": "Pending", "email_status": "Pending", "shorturl": null, "longurl": "https://www.instamojo.com/@EXAMPLE/47a321d95c5c4d7f8e0e7742bbb55f64", "redirect_url": "http://www.example.com/thankyou.php/", "webhook": null, "allow_repeated_payments": false, "created_at": "2022-09-10T09:16:12.104302Z", "modified_at": "2022-09-10T09:16:12.104336Z" } }
原报错代码(错误行:header('location:'.$response->payment_request->longurl);):
<?php $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, 'https://www.instamojo.com/api/1.1/payment-requests/'); curl_setopt($ch, CURLOPT_HEADER, FALSE); curl_setopt($ch, CURLOPT_RETURNTRANSFER, TRUE); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, TRUE); curl_setopt($ch, CURLOPT_HTTPHEADER, array("X-Api-Key:*****************************************", "X-Auth-Token:**************************************")); $payload = Array( 'purpose' => 'FIFA', 'amount' => '100', 'phone' => '70*****55', 'buyer_name' => 'Aman', 'redirect_url' => 'http://www.example.com/thankyou.php/', 'send_email' => true, 'send_sms' => true, 'email' => 'a******@gmail.com', 'allow_repeated_payments' => false ); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($payload)); $response = curl_exec($ch); curl_close($ch); header('location:'.$response->payment_request->longurl); ?>
错误原因
curl_exec()返回的是JSON格式字符串,不是PHP对象,直接用->访问属性会触发"试图获取非对象的属性"错误。测试环境可能因调试残留或偶然情况掩盖了问题,生产环境暴露了核心逻辑缺陷。
修复方案
核心修复点
- 用
json_decode()将JSON字符串转成PHP对象 - 增加CURL执行错误、API响应状态的校验逻辑
- 验证
longurl存在后再执行跳转
修改后的完整代码
<?php $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, 'https://www.instamojo.com/api/1.1/payment-requests/'); curl_setopt($ch, CURLOPT_HEADER, FALSE); curl_setopt($ch, CURLOPT_RETURNTRANSFER, TRUE); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, TRUE); // 生产环境强制开启SSL验证,避免安全风险 curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_HTTPHEADER, array("X-Api-Key:*****************************************", "X-Auth-Token:**************************************")); $payload = Array( 'purpose' => 'FIFA', 'amount' => '100', 'phone' => '70*****55', 'buyer_name' => 'Aman', 'redirect_url' => 'http://www.example.com/thankyou.php/', 'send_email' => true, 'send_sms' => true, 'email' => 'a******@gmail.com', 'allow_repeated_payments' => false ); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($payload)); $response = curl_exec($ch); // 检查CURL执行是否失败 if(curl_errno($ch)){ die('CURL错误:'.curl_error($ch)); } curl_close($ch); // 解码JSON响应为PHP对象 $responseData = json_decode($response); // 校验解码结果及API响应状态 if(!$responseData || !$responseData->success){ die('请求失败:'.($responseData->message ?? '未知错误')); } // 验证支付链接存在后跳转 if(!empty($responseData->payment_request->longurl)){ header('Location: '.$responseData->payment_request->longurl); exit; }else{ die('无法获取有效支付链接'); } ?>
额外注意事项
- 生产环境必须开启SSL验证,防止恶意劫持
- 保留错误处理逻辑,便于排查API限流、密钥失效等问题
- 确保
redirect_url为公网可访问地址,否则支付完成后无法正常回调
内容的提问来源于stack exchange,提问作者Aman
相关产品推荐
相关产品推荐

