关于苹果内购的验证防止被刷单

最近有一个项目的苹果充值被刷单,发现他们的验证方式很简单,把客户端发过来的receptdata打包发给服务器,服务器那这个数据去苹果验证,仅仅看返回的状态以及对应的transactionid,如果数据库里没有这个transactionid,并且返回0说明是合法的数据,就这样被刷了,所以应该还要判断购买商品的id,这样才确保万无一失,不知道这个思路对不对呢

----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------


猜你喜欢

转载自blog.csdn.net/jingyanbiao3880/article/details/53955676
今日推荐