The VeriSign Payflow Link scripts are:
VERISIGN_mailorder.asp
VERISIGN_callback.asp
These should be located on the root of the CactuShop web.
8.8.2.1 VS_EmailCustomer
y/n determines whether CactuShop will send an email to the customer for
orders made using this gateway.
8.8.2.2 VS_EmailMerchant
y/n determines whether CactuShop will send an email to you for orders
made using this gateway.
8.8.2.3 VS_Login
This is your login name for VeriSign this information should be supplied to
you by VeriSign when you set up your account.
8.8.2.4 VS_Partner
This is your partner for VeriSign. If you sign up through the VeriSign site
directly this is generally `VeriSign'.
8.8.2.5 VS_Password
This is a callback password (not your login password!) of your own choosing.
This should match the password set in the querystring within the VeriSign
silent post URL . Leave it blank to disable (not recommended).
8.8.2.6 VS_ProcessCurrency
At the time of writing, VeriSign payment processing accounts can only process
one currency. For this reason, you must ensure that the ISO code of the
currency you have set up your VeriSign account to process is entered in this
config setting, for example `USD'.
8.8.2.7 VS_Type
This is VeriSign's `type' attribute. It can be set to `S' for sale (where
transactions are authorized and billed immediately) or `A' for authorization
(where the card is authorized but not billed until you decide to accept the
payment). The latter method is useful if you need to check stock levels or
perform extra fraud checks before despatching the order and accepting the
payment.
8.8.2.8 VS_VeriSignURL
This is the URL of the secure payment form on VeriSign's web site. The
default value is
https://payflowlink.verisign.com/payflowlink.cfm
. It is very
unlikely this will change. Do not alter this unless VeriSign tells you to.
8.8.2.9 VS_Password
This is a special callback password not your verisign login password! that
can be any made up password you choose. This should match the password
set in the querystring within VeriSign silent post URL . When the callback is
made, the password in the querystring is checked with this password to
ensure it matches. You can leave this blank to disable the security check, but
this isn t recommended as it ensures that, as long as this password is
unknown, users can t spoof a callback. See 8.8.3.3 for more details.
81
New Page 1