stagebrace:
This change in error handling has worked for me. Caution, it may break other things.
IN FILE:
includes\modules\payment\paypaldp.php
Near Lines 1455
REPLACE or REMARK:
if ($basicError ||
(isset($_SESSION['paypal_ec_token']) && $_SESSION['paypal_ec_token'] != urldecode($response['TOKEN'])) ) {
WITH:
if ($basicError) {
Stagebrace, you're correct -- the $response[TOKEN] isn't always set in the data that comes back from PayPal. So much for consistency in their APIs. Your approach should be fine. Nevertheless ...
I think the following is slightly more efficient from a security standpoint:
Replace this:if ($basicError || (isset($_SESSION['paypal_ec_token']) && $_SESSION['paypal_ec_token'] != urldecode($response['TOKEN'])) ) {with this:```
if ($basicError ||
([B]([/B]isset($_SESSION['paypal_ec_token'])[B] && isset($response['TOKEN']))[/B] && $_SESSION['paypal_ec_token'] != urldecode($response['TOKEN'])) ) {
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.