1) Care to elaborate on how the IPN is open to fraud?
The reason I ask is this, The verification system is hardcoded (i.e. you cannot send it dynamic data to try to *spoof* my script into thinking that you are paypal's IPN server) to send the information only to one server, Papal's IPN verfier, if that server did not send the information, it returns an INVALID response, if my hack receives ANY INVALID response, or if it receives any suspicious information, the information is dumped into a seperate table for questionable transactions.
So the long and short of the matter is that the information HAS to come from Paypal's server, or it won't be added to the contributions.
2) This is the second post where someone has basically said, they've a better system....however, I did search the the site here, and found nothing that comes close to what has been requested, and what I need specifically for my site.
While I appreciate the fact that the users should have a choice of what hacks they can use, etc, and if there is a better hack somewhere, they should know about it...What I don't appreciate is when someone posts they've a better hack than the one I'm trying to build within this thread. If you've a better hack, kewl, post that with a link to where we can find it so we can make the choice.
3) While currently the hack relies on Paypal's IPN, it is in no way the only system that will be used once this goes into full release. I have plans in the works for you to be able to use any number of payment gateways that use and instant notification system. But that goes into the code later on. I simply want to get the system working first off. The other gateways will be added as simple code upgrades that will require nothing more to upgrade than simply uploading a new file.
Thanks.
Sorry if I sound irritated, but I am slightly...I hope you can understand.
Love and light to you all
)O( Cloudrunner )O(
|