You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel中如何安全传递Stripe密钥与OAuth令牌至视图

Stripe密钥与OAuth令牌的安全传递方案

当前方案的问题

你现在用base64编码传递密钥和令牌的方式完全起不到安全隐藏的作用——base64是编码而非加密,任何用户打开浏览器开发者工具,都能轻松解码出原始内容,属于伪安全措施。

先明确Stripe密钥的安全边界

Stripe的密钥分为两类,安全要求完全不同:

  • 发布密钥(Publishable Key):格式为pk_xxx,这类密钥设计就是要暴露给前端的,用于初始化Stripe.js、收集支付信息等,无需隐藏。
  • 秘密密钥(Secret Key):格式为sk_xxx,这类密钥绝对不能出现在前端,只能在后端服务器使用,用于创建支付意图、处理退款等敏感操作。

另外,你提到的oauth_token如果是连接账户ID(格式为acct_xxx),那也是可以安全暴露给前端的——Stripe.js需要它来代表连接的商户账户发起支付;但如果是OAuth刷新令牌(refresh token),那绝对不能传到前端,必须存在后端用于刷新凭证。

正确的安全实现方案

1. 前端仅传递允许公开的凭证

后端控制器只向前端传递发布密钥和连接账户ID(如果是OAuth场景):

return view($filepath, [
    'stripe_publishable_key' => $this->getPublishableApiKey($project),
    'stripe_account_id' => $project->stripe_account_id, // 这里应为连接账户的ID,而非敏感令牌
]);

前端直接使用这些公开凭证初始化Stripe:

@if(!empty($stripe_account_id))
    const stripe = Stripe("{{ $stripe_publishable_key }}", { stripeAccount: "{{ $stripe_account_id }}" });
@else
    const stripe = Stripe("{{ $stripe_publishable_key }}");
@endif

2. 敏感操作完全在后端执行

所有涉及资金交易的敏感操作(创建支付意图、退款、查询交易等),必须在后端用秘密密钥和服务器端的OAuth凭证处理:

后端创建支付意图示例:

// 后端接口方法
$stripe = new \Stripe\StripeClient($this->getSecretApiKey($project));
$paymentIntent = $stripe->paymentIntents->create([
    'amount' => 1000, // 金额单位为分
    'currency' => 'usd',
    'payment_method_types' => ['card'],
    'stripe_account' => $project->stripe_oauth_token, // 用于平台代付场景的连接账户ID
]);

return response()->json(['client_secret' => $paymentIntent->client_secret]);

前端通过调用后端接口获取client_secret,再完成支付确认:

fetch('/create-payment-intent', {
    method: 'POST',
    headers: {
        'Content-Type': 'application/json',
        'X-CSRF-TOKEN': '{{ csrf_token() }}'
    },
    body: JSON.stringify({ amount: 1000 })
})
.then(response => response.json())
.then(data => {
    const stripe = Stripe("{{ $stripe_publishable_key }}", { stripeAccount: "{{ $stripe_account_id }}" });
    // 用后端返回的client_secret完成支付
    stripe.confirmCardPayment(data.client_secret, {
        payment_method: {
            card: cardElement, // 前端收集的卡片元素
            billing_details: {
                name: '用户姓名'
            }
        }
    });
});

总结

  • 放弃base64编码这类无效的“安全手段”,遵循Stripe的官方安全规范
  • 发布密钥和连接账户ID可以直接暴露给前端,无需隐藏
  • 所有敏感操作必须在后端执行,绝对不能把秘密密钥或敏感OAuth令牌传到前端

内容的提问来源于stack exchange,提问作者bilalahmedcodes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 02:53:10