01-31-2004, 04:46 PM
Is there any known way to encrypt a paypal page that has the return link on it? It's very easy on my page to view the source, find the return link and get the password to access the content area. I have seen some programs that do this but want your opinion.


01-31-2004, 04:51 PM
There's no real way to do this, to make it secure you will need to use a serverside language, or htaccess.

A basic example would be to check to see if they've come from paypal and only then display the password, if they not come from paypal, send them back to your form

01-31-2004, 08:01 PM
You can use a little serverside script as your return page to check for PP's posted payment details to it...If they're not there, you can deny access. PP's IPN really isn't needed unless you want to record data in your own db. This is php:

$payment_status = $_POST["payment_status"];
$mc_gross = $_POST["mc_gross"];
$receiver_email = $_POST["receiver_email"];

...are the 3 you should check for. Then you make a if/else statement. I've converted them back to regular vars here for easier coding. The PP dev site is worthless...They'll just wanna sell you scripts.

Here's what I used in my return page that PP automatically posts it's vars to:

if ($payment_status == 'Completed' && $receiver_email == 'zoobie@site.com' && $mc_gross=='5.99')
{ //go to d/l page or wherever}
else{ //get lost}

