Our highest priority is to satisfy the customer through early and continuous delivery of valuable and working software.

Sunday, July 8, 2007

Payment Gateway Integration: Part I

Are you a PHP web developer?
Lookig for "How to integrate a payment gateway with your site?" Want to know about Payment Gateway?
Check it here...

Various web definitions for "Payment Gateway"

- Company that provides the transaction-processing network that receives encrypted transactions from a merchant’s website and sends them to the card issuing bank for approval.

- It allows the secure transfer of credit card funds from users on your website to your merchant account.

- A payment gateway can be thought of as a digital equivalent to a credit card processing terminal.

- An online system for real-time charging of credit cards when a customer places an order, which normally requires a merchant account.

- A software usually provided by a third party such as (Authorize.Net, PayPal, 2CheckOut) that allows a website to be integrated to a merchant account.

How "Payment Gateway" works...

var PG = Authorize.Net or PayPal or 2CheckOut

A Secure Sockets Layer (SSL) connection is established between merchant web storefront application and $PG's transaction servers to securely exchange payment data between parties.

1. A customer visits your Web site and makes a purchase.
2. The transaction data is then passed from your storefront to the $PG's transaction server.
3. $PG's transaction server collects the transaction information from your site and then securely routes the transaction via the payment gateway through the financial network to the appropriate bank, ensuring that customers are authorised to make their purchases.
4. The funds for the transaction will be transferred to merchant’s bank account.
5. The payment gateway sends an acknowledgement to customer with Transaction Status.

Who are involved...

(1) Merchants:
Want to sell their products via internet / want payment through internet.
Normally interested in trusted Payment Gateway provider.
Have knowledge about Payment Gateway

(2) Customers (Two types of Customer)
- Normal Customers
Want to buy products via Internet / want to make payment through Internet.

- Customers with basic awareness of secure transaction.
Want to buy products via Internet / want to make payment through Internet
But always verify that: transaction is secure (SSL, https://).
may / may not have knowledge about Payment Gateway

(3) Web Developers (Me & U all)
Want to integrate the web site with Payment Gateway.
Have knowledge about Payment Gateway

Well known Payment Gateway Providers...

Paypal.com
2Checkout.com
Authorize.net
Google Checkout

If you know about osCommerce, then you might know that "it is providing readymade payment gateway integration solution for shopping sites" as one of its best feature.

osCommerce is an Open Source based online shop e-commerce solution that is available for free under the GNU General Public License.


Click here to read more about osCommerce supported payment gateways

To be continued... [Integration code in PHP]

Wednesday, May 30, 2007

Debugging php scripts - Xdebug

Want to debug your PHP scripts :) Use Xdebug.

The Xdebug extension helps you debugging your script by providing a lot of valuable debug information.

The debug information that Xdebug can provide includes the following:

(1) stack and function traces in error messages with:
o full parameter display for user defined functions
o function name, file name and line indications
o support for member functions

(2) memory allocation

(3) protection for infinite recursions

Xdebug also provides:


(1) profiling information for PHP scripts
- Xdebug's Profiler is a powerful tool that gives you the ability to analyze your PHP code and determine bottlenecks or generally see which parts of your code are slow and could use a speed boost. The profiler offers a number of output modes, that are suited for a variety of tasks when analyzing code. Thus allowing you to select the output that would be most suited for your needs. Even output itself can be retrieved in number of ways to allow for maximum flexibility.

(2) script execution analysis

(3) capabilities to debug your scripts interactively with a debug client

Check for more details
http://www.xdebug.org

Link to documentation for Xdebug 2
http://www.xdebug.org/docs/

Download & install Xdebug for debugging your PHP scripts.
http://www.xdebug.org/docs/install

Monday, May 28, 2007

PHP Server Side Validation


I have made a PHP Server Side Validator for PHP4 and PHP5. It is a simple server side validator, which is based on OOPs concept. Those who want to save time while developing any PHP application & wants server side validation of their data on the fly, can use this class.

Use PHP validator class (validation.class.php), follow some simple rules & validate your data.

How to use validation class?

# Include validation class
require_once("validation.class.php")

# Create Object of class validation
$obj = new validation();

# Call add_fields() functions for all the fields, for which you want server side validation
$obj->add_fields($postVar, $authType, $errorMsg);

# Validate your data using validate() function, which will return errors if any...
$error = $obj->validate();

if($error){
# Display ERROR messages...
}else{
# Proceed with other code...
}

How to use add_fields($postVar, $authType, $errorMsg) function?

$postVar: $_POST, $_GET, $_FILES e.g.$_POST['username'], $_FILES['images']
$authType: Authentication/validation Type
(Currently supports 26 validation types as follow)

(01) req - Check for blank, unselected, unchecked field/fields

(02) alpha - Only alphabets are allowed (az, AZ)

(03) alphanum - Only alphanumerics are allowed (az, AZ, 09)

(04) num - Only numbers are allowed (09)

(05) max - Check for maximum character length e.g. max=10
i.e. only a string of maximum length 10 is allowed

(06) min - Check for minimum character length e.g. min=6
i.e. only a string of minimum length 6 is allowed

(07) lte - value should be less than/equal to some value. e.g lte=2
In case of Selection Box, Check Box it checks for minimum no of selections.

(08) gte - value should be greater than/equal to some value. e.g gte=4
In case of Selection Box, Check Box it checks for maximum no of selections.

(09) username - validate username

(10) name - validate first name, last name

(11) address - validate address

(12) phone - validate phone no.Allowed Options:
in-India, us-US, fr-France, sw-Swedish, br-Brazil

(13) mobile - validate Mobile no.

(14) zip - validate ZIP code

(15) uszip - validate US ZIP code

(16) ukzip - validate UK ZIP code

(17) ssn - validate Social Security Number

(18) currency - validate currency

(19) email - validate EMAIL address

(20) url - validate URL

(21) ip - validate IP address

(22) date - validate date default: ddmmyyyy e.g. date=ddmmyyyy,dd/mm/yyyy
Allowed Date Formats:
# ddmmyyyy, ddmmyy, dd/mm/yyyy, dd/mm/yy, dd.mm.yyyy, dd.mm.yy
# mmddyyyy, mmddyy, mm/dd/yyyy, mm/dd/yy, mm.dd.yyyy, mm.dd.yy
# yyyyddmm, yyddmm, yyyy/dd/mm, yy/dd/mm, yyyy.dd.mm, yy.dd.mm
# yyyymmdd, yymmdd, yyyy/mm/dd, yy/mm/dd, yyyy.mm.dd, yy.mm.dd

(23) ftype - validate file types e.g. ftype=jpg,gif,png
Allowed Options:
txt, xml, csv
zip, tar, ctar
pdf, doc, xls, ppt
jpg, gif, bmp, icon, font

(24) fsize - validate file size e.g. fsize=500

(25) imgwh - validate image width, heigth e.g. imgwh=800,600
You will need to compile PHP with the GD library of image functions for this to work.

(26) custom - custom validation e.g. custom=/^some regular exp$/

$errorMsg: Error message to be displayed upon error

Download the source code from
http://sourceforge.net/projects/php-validator/

See Demo at
http://php-validator.sourceforge.net/

Feel free to comment! :)

Monday, May 21, 2007

php|tek 2007 at Chicago, USA [May 15-17, 2007]


Ilia Alshanetsky had given some good sceurity tips in php|tek 2007 at Chicago, USA [May 15-17, 2007]

Ilia Alshanetsky is a primarily a programmer although he frequently dabbles in network/server security. Ilia is a chief software architect for Advanced Internet Designs Inc, a company supplying support and development services to a variety of corporate and government entities. Aside from commercial development, he is involved in a number of Open Source projects. Lately Ilia can be found speaking at various PHP conferences and writing articles for print and online magazines.

Download the presentation slide here. http://ilia.ws/files/phptek2007_secpitfalls.pdf

also, you will find other good resources at http://ilia.ws/talks.php

Friday, May 18, 2007

Internet archive - Yahoo in 1996, Google in 1998 & Microsoft in 1996

One of my friend has pointed me to visit one good website. http://web.archive.org/web/

The website has large no. of Internet Archive. The Internet Archive Wayback Machine puts the history of the World Wide Web at your fingertips.

The Archive contains over 100 terabytes and 10 billion web pages archived from 1996 to the present.

To start using the Wayback Machine to surf the web as it was, just type a URL (a web site address) into the box above, click the Take Me Back button, and start exploring the past.

See below the screen shots of Yahoo in 1996, Google in 1998 & Microsoft in 1996.
Yahoo in 1996


Google in 1998


Microsoft in 1996