Skip to content

Fix PayPal donation crediting and redirect, add REST/Webhooks support - #85

Merged
MrKeiKun merged 1 commit into
HerculesWS:masterfrom
MrKeiKun:paypal-rest-ipn-fix
Oct 3, 2026
Merged

MrKeiKun merged 1 commit into
HerculesWS:masterfrom
MrKeiKun:paypal-rest-ipn-fix

Conversation

@MrKeiKun

Copy link
Copy Markdown
Collaborator

The classic IPN handler verified PayPal notifications with a raw fsockopen/hand-built HTTP request, and required the sender's reverse-DNS hostname to match ipn.sandbox.paypal.com/notify.paypal.com. PayPal doesn't guarantee reverse-DNS records for its IPN-sending IPs, so this check silently rejected genuine, verified transactions and left accounts uncredited. Replaced verify() with a cURL request and dropped the hostname check, relying solely on the notify-validate handshake as PayPal's docs describe.

Also fixes the post-donation redirect: button.php pointed PayPal's return URL at the main page instead of donate/complete, and the dead code in preprocess.php that was supposed to catch it relied on a merchant_return_link parameter PayPal never actually sends.

Adds an opt-in PayPal REST API + Webhooks donation flow (PayPalMode = 'rest') alongside the existing classic IPN, for admins who want to move off the legacy integration. Both paths were tested end-to-end against PayPal's sandbox, including duplicate delivery, held/untrusted accounts, and PHP 8.3 deprecation warnings, turning up and fixing a handful of smaller pre-existing bugs along the way (a schema column too narrow for real PayPal IDs, a directory permission bug that broke transaction file logging, and a couple of null-handling issues).

Fixes #41, #58

Fixes HerculesWS#41 (donations not crediting) and HerculesWS#58 (wrong post-donation redirect), plus adds an opt-in PayPal REST API + Webhooks flow alongside classic IPN.
Comment thread config/application.php
@MrKeiKun
MrKeiKun merged commit 14d4d5a into HerculesWS:master Oct 3, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Donation Module Broken?

2 participants