[security] 토스 결제창 customerName 출력 시 get_text 인코딩 적용

토스페이먼츠 결제 요청 폼의 customerName hidden 필드에 주문자명
($od_name)이 인코딩 없이 출력되던 것을 get_text() 적용으로 정리.
직전 주문 필드 인코딩 처리와 동일한 맥락의 마무리.

hidden value 의 엔티티는 결제 SDK 가 값을 읽을 때 브라우저가
디코딩하므로 토스로 전달되는 구매자명에는 영향 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-05-29 06:30:29 +00:00
co-authored by Claude Opus 4.8
parent 1fa4467cd1
commit 9869be5970
3 changed files with 3 additions and 3 deletions
+1 -1
View File
@@ -5,7 +5,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<input type="hidden" name="method" value="">
<input type="hidden" name="orderId" value="<?php echo isset($od_id) ? $od_id : ''; ?>">
<input type="hidden" name="orderName" value="<?php echo isset($goods) ? $goods : ''; ?>">
<input type="hidden" name="customerName" value="<?php echo isset($od_name) ? $od_name : ''; ?>">
<input type="hidden" name="customerName" value="<?php echo isset($od_name) ? get_text($od_name) : ''; ?>">
<input type="hidden" name="customerEmail" value="<?php echo isset($od_email) ? $od_email : ''; ?>">
<input type="hidden" name="customerMobilePhone" value="<?php echo isset($od_hp) ? $od_hp : ''; ?>">
<input type="hidden" name="cardUseEscrow" value="false">