107 lines
4.9 KiB
PHP
107 lines
4.9 KiB
PHP
<?php
|
|
// This is just for very basic implementation reference, in production, you should validate the incoming requests and implement your backend more securely.
|
|
// Please refer to this docs for sample HTTP notifications:
|
|
// https://docs.midtrans.com/en/after-payment/http-notification?id=sample-of-different-payment-channels
|
|
|
|
namespace Midtrans;
|
|
|
|
require_once dirname(__FILE__) . '/midtrans/Midtrans.php';
|
|
Config::$isProduction = true;
|
|
Config::$serverKey = 'Mid-server-aSXAMMosYIoElA_k9eSQb1_w';
|
|
|
|
// non-relevant function only used for demo/example purpose
|
|
printExampleWarningMessage();
|
|
|
|
try {
|
|
$notif = new Notification();
|
|
}
|
|
catch (\Exception $e) {
|
|
exit($e->getMessage());
|
|
}
|
|
|
|
$notif = $notif->getResponse();
|
|
$transaction = $notif->transaction_status;
|
|
$type = $notif->payment_type;
|
|
$order_id = $notif->order_id;
|
|
$fraud = $notif->fraud_status;
|
|
|
|
include '../config/connect.php';
|
|
$stmt = $pdo->prepare("SELECT * FROM apk_payment WHERE order_id = :order_id");
|
|
$stmt->bindParam(':order_id', $order_id);
|
|
$stmt->execute();
|
|
// Ambil satu baris data hasil query
|
|
$result = $stmt->fetch();
|
|
|
|
if ($transaction == 'capture') {
|
|
// For credit card transaction, we need to check whether transaction is challenge by FDS or not
|
|
if ($type == 'credit_card') {
|
|
if ($fraud == 'challenge') {
|
|
// TODO set payment status in merchant's database to 'Challenge by FDS'
|
|
// TODO merchant should decide whether this transaction is authorized or not in MAP
|
|
// echo "Transaction order_id: " . $order_id ." is challenged by FDS";
|
|
} else {
|
|
$stmt = $pdo->prepare("UPDATE data_server SET status = 'Aktif', expaired_date = :expaired WHERE id = :id");
|
|
$stmt->bindParam(':expaired', $result['expaired_time']);
|
|
$stmt->bindParam(':id', $result['id_data_server']);
|
|
$stmt->execute();
|
|
|
|
$stmt = $pdo->prepare("UPDATE apk_payment SET status = 'LUNAS' WHERE order_id = :order_id");
|
|
$stmt->bindParam(':order_id', $order_id);
|
|
$stmt->execute();
|
|
// TODO set payment status in merchant's database to 'Success'
|
|
// echo "Transaction order_id: " . $order_id ." successfully captured using " . $type;
|
|
}
|
|
}
|
|
} else if ($transaction == 'settlement') {
|
|
$stmt = $pdo->prepare("UPDATE data_server SET status = 'Aktif', expaired_date = :expaired WHERE id = :id");
|
|
$stmt->bindParam(':expaired', $result['expaired_time']);
|
|
$stmt->bindParam(':id', $result['id_data_server']);
|
|
$stmt->execute();
|
|
|
|
$stmt = $pdo->prepare("UPDATE apk_payment SET status = 'LUNAS' WHERE order_id = :order_id");
|
|
$stmt->bindParam(':order_id', $order_id);
|
|
$stmt->execute();
|
|
// header('Location: https://bilspro.com/index.php?c2V0dGluZ19wcm9maWxl');
|
|
// echo "Transaction order_id: " . $order_id ." successfully transfered using " . $type;
|
|
} else if ($transaction == 'pending') {
|
|
$stmt = $pdo->prepare("UPDATE apk_payment SET status = 'PENDING' WHERE order_id = :order_id");
|
|
$stmt->bindParam(':order_id', $order_id);
|
|
$stmt->execute();
|
|
// header('Location: https://bilspro.com/index.php?c2V0dGluZ19wcm9maWxl');
|
|
// TODO set payment status in merchant's database to 'Pending'
|
|
// echo "Waiting customer to finish transaction order_id: " . $order_id . " using " . $type;
|
|
} else if ($transaction == 'deny') {
|
|
$stmt = $pdo->prepare("UPDATE apk_payment SET status = 'GAGAL' WHERE order_id = :order_id");
|
|
$stmt->bindParam(':order_id', $order_id);
|
|
$stmt->execute();
|
|
// header('Location: https://bilspro.com');
|
|
// TODO set payment status in merchant's database to 'Denied'
|
|
// echo "Payment using " . $type . " for transaction order_id: " . $order_id . " is denied.";
|
|
} else if ($transaction == 'expire') {
|
|
$stmt = $pdo->prepare("UPDATE apk_payment SET status = 'EXPAIRED' WHERE order_id = :order_id");
|
|
$stmt->bindParam(':order_id', $order_id);
|
|
$stmt->execute();
|
|
// header('Location: https://bilspro.com/index.php?c2V0dGluZ19wcm9maWxl');
|
|
// TODO set payment status in merchant's database to 'expire'
|
|
// echo "Payment using " . $type . " for transaction order_id: " . $order_id . " is expired.";
|
|
} else if ($transaction == 'cancel') {
|
|
// header('Location: https://bilspro.com');
|
|
// TODO set payment status in merchant's database to 'Denied'
|
|
// echo "Payment using " . $type . " for transaction order_id: " . $order_id . " is canceled.";
|
|
}
|
|
|
|
function printExampleWarningMessage() {
|
|
if ($_SERVER['REQUEST_METHOD'] != 'POST') {
|
|
echo 'Notification-handler are not meant to be opened via browser / GET HTTP method. It is used to handle Midtrans HTTP POST notification / webhook.';
|
|
}
|
|
if (strpos(Config::$serverKey, 'your ') != false ) {
|
|
echo "<code>";
|
|
echo "<h4>Please set your server key from sandbox</h4>";
|
|
echo "In file: " . __FILE__;
|
|
echo "<br>";
|
|
echo "<br>";
|
|
echo htmlspecialchars('Config::$serverKey = \'<your server key>\';');
|
|
die();
|
|
}
|
|
}
|
|
?>
|