4 ms·
Actual approaches I've seen: * Trust the submitted data. Sadly, very popular. Of things I've seen lately, Authorize.Net's new Direct Post Method does this, as
by midnightmonster 15y ago
Actual approaches I've seen:
* Trust the submitted data. Sadly, very popular. Of things I've seen lately, Authorize.Net's new Direct Post Method does this, as does the Prolific gateway.
* Have the merchant optionally crypto-sign all the interesting-to-manipulate parts and submit the signature along with. Braintree's old API worked this way, not sure about the current. USAePay does this, but they don't let you sign all the important fields.
* Stripe has your form submit to you, but they use JavaScript to submit the card details to them first and replace them in your form with a customer ID which you charge as you like.
* PayPal Express Checkout (but not any of their other checkout methods) uses the method you suggest. Although of course with them you leave the merchant's site to complete your payment. I suspect the reason it's not used more is that it requires the gateway to maintain some state that they wouldn't otherwise have to, and it involves an extra server round trip versus signing the submission.