Looks like the code is not authenticating the relay response from authorize.net using the x_MD5_Hash provided by authorize.net. Is it safe to not validate that? Couldn't someone craft a response back to server as valid payment without actually entering any CC info at authorize.net?
Thanks
