doulan2827 2016-10-28 03:55
浏览 12

在付款顺序中将用户ID存储到会话,这样安全吗? (Laravel)

Users are able to purchase products without an account. However, after they have purchased the product they must create an account to access the product. Their email is entered into a stripe form during registration, as I am using stripe for payments. In the back-end I am creating an account for the user post-purchase like this:

 $newUser = new User;
 $newUser->email = $request->stripeEmail;

Next, I am storing the user's ID to session.

Session::put('id', $user->id);

The user is then redirected to a page to fill out further information, here, I am retrieving the user's ID from the session and finishing off their account.

 $id = Session::get('id');
 $user = User::where('id',$id)->first();
 // add details to user submitted from form

Obviously, since I am dealing with payments I want to be as careful as possible. Is this method of storing the user's ID for completion at a later stage entirely safe?

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥100 set_link_state
    • ¥15 虚幻5 UE美术毛发渲染
    • ¥15 CVRP 图论 物流运输优化
    • ¥15 Tableau online 嵌入ppt失败
    • ¥100 支付宝网页转账系统不识别账号
    • ¥15 基于单片机的靶位控制系统
    • ¥15 真我手机蓝牙传输进度消息被关闭了,怎么打开?(关键词-消息通知)
    • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
    • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
    • ¥15 手机接入宽带网线,如何释放宽带全部速度