WXBizMsgCrypt.php 5.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183
  1. <?php
  2. namespace wx\work\callback;
  3. /**
  4. * 企业微信回调消息加解密示例代码.
  5. *
  6. * @copyright Copyright (c) 1998-2014 Tencent Inc.
  7. */
  8. include_once "sha1.php";
  9. include_once "xmlparse.php";
  10. include_once "pkcs7Encoder.php";
  11. include_once "errorCode.php";
  12. class WXBizMsgCrypt
  13. {
  14. private $m_sToken;
  15. private $m_sEncodingAesKey;
  16. private $m_sReceiveId;
  17. /**
  18. * 构造函数
  19. * @param $token string 开发者设置的token
  20. * @param $encodingAesKey string 开发者设置的EncodingAESKey
  21. * @param $receiveId string, 不同应用场景传不同的id
  22. */
  23. public function __construct($token, $encodingAesKey, $receiveId)
  24. {
  25. $this->m_sToken = $token;
  26. $this->m_sEncodingAesKey = $encodingAesKey;
  27. $this->m_sReceiveId = $receiveId;
  28. }
  29. /*
  30. *验证URL
  31. *@param sMsgSignature: 签名串,对应URL参数的msg_signature
  32. *@param sTimeStamp: 时间戳,对应URL参数的timestamp
  33. *@param sNonce: 随机串,对应URL参数的nonce
  34. *@param sEchoStr: 随机串,对应URL参数的echostr
  35. *@param sReplyEchoStr: 解密之后的echostr,当return返回0时有效
  36. *@return:成功0,失败返回对应的错误码
  37. */
  38. public function VerifyURL($sMsgSignature, $sTimeStamp, $sNonce, $sEchoStr, &$sReplyEchoStr)
  39. {
  40. if (strlen($this->m_sEncodingAesKey) != 43) {
  41. return \ErrorCode::$IllegalAesKey;
  42. }
  43. $pc = new \Prpcrypt($this->m_sEncodingAesKey);
  44. //verify msg_signature
  45. $sha1 = new \SHA1;
  46. $array = $sha1->getSHA1($this->m_sToken, $sTimeStamp, $sNonce, $sEchoStr);
  47. $ret = $array[0];
  48. if ($ret != 0) {
  49. return $ret;
  50. }
  51. $signature = $array[1];
  52. if ($signature != $sMsgSignature) {
  53. return \ErrorCode::$ValidateSignatureError;
  54. }
  55. $result = $pc->decrypt($sEchoStr, $this->m_sReceiveId);
  56. if ($result[0] != 0) {
  57. return $result[0];
  58. }
  59. $sReplyEchoStr = $result[1];
  60. return \ErrorCode::$OK;
  61. }
  62. /**
  63. * 将公众平台回复用户的消息加密打包.
  64. * <ol>
  65. * <li>对要发送的消息进行AES-CBC加密</li>
  66. * <li>生成安全签名</li>
  67. * <li>将消息密文和安全签名打包成xml格式</li>
  68. * </ol>
  69. *
  70. * @param $replyMsg string 公众平台待回复用户的消息,xml格式的字符串
  71. * @param $timeStamp string 时间戳,可以自己生成,也可以用URL参数的timestamp
  72. * @param $nonce string 随机串,可以自己生成,也可以用URL参数的nonce
  73. * @param &$encryptMsg string 加密后的可以直接回复用户的密文,包括msg_signature, timestamp, nonce, encrypt的xml格式的字符串,
  74. * 当return返回0时有效
  75. *
  76. * @return int 成功0,失败返回对应的错误码
  77. */
  78. public function EncryptMsg($sReplyMsg, $sTimeStamp, $sNonce, &$sEncryptMsg)
  79. {
  80. $pc = new \Prpcrypt($this->m_sEncodingAesKey);
  81. //加密
  82. $array = $pc->encrypt($sReplyMsg, $this->m_sReceiveId);
  83. $ret = $array[0];
  84. if ($ret != 0) {
  85. return $ret;
  86. }
  87. if ($sTimeStamp == null) {
  88. $sTimeStamp = time();
  89. }
  90. $encrypt = $array[1];
  91. //生成安全签名
  92. $sha1 = new \SHA1;
  93. $array = $sha1->getSHA1($this->m_sToken, $sTimeStamp, $sNonce, $encrypt);
  94. $ret = $array[0];
  95. if ($ret != 0) {
  96. return $ret;
  97. }
  98. $signature = $array[1];
  99. //生成发送的xml
  100. $xmlparse = new \XMLParse;
  101. $sEncryptMsg = $xmlparse->generate($encrypt, $signature, $sTimeStamp, $sNonce);
  102. return \ErrorCode::$OK;
  103. }
  104. /**
  105. * 检验消息的真实性,并且获取解密后的明文.
  106. * <ol>
  107. * <li>利用收到的密文生成安全签名,进行签名验证</li>
  108. * <li>若验证通过,则提取xml中的加密消息</li>
  109. * <li>对消息进行解密</li>
  110. * </ol>
  111. *
  112. * @param $msgSignature string 签名串,对应URL参数的msg_signature
  113. * @param $timestamp string 时间戳 对应URL参数的timestamp
  114. * @param $nonce string 随机串,对应URL参数的nonce
  115. * @param $postData string 密文,对应POST请求的数据
  116. * @param &$msg string 解密后的原文,当return返回0时有效
  117. *
  118. * @return int 成功0,失败返回对应的错误码
  119. */
  120. public function DecryptMsg($sMsgSignature, $sTimeStamp = null, $sNonce, $sPostData, &$sMsg)
  121. {
  122. if (strlen($this->m_sEncodingAesKey) != 43) {
  123. return \ErrorCode::$IllegalAesKey;
  124. }
  125. $pc = new \Prpcrypt($this->m_sEncodingAesKey);
  126. //提取密文
  127. $xmlparse = new \XMLParse;
  128. $array = $xmlparse->extract($sPostData);
  129. $ret = $array[0];
  130. if ($ret != 0) {
  131. return $ret;
  132. }
  133. if ($sTimeStamp == null) {
  134. $sTimeStamp = time();
  135. }
  136. $encrypt = $array[1];
  137. //验证安全签名
  138. $sha1 = new \SHA1;
  139. $array = $sha1->getSHA1($this->m_sToken, $sTimeStamp, $sNonce, $encrypt);
  140. $ret = $array[0];
  141. if ($ret != 0) {
  142. return $ret;
  143. }
  144. $signature = $array[1];
  145. if ($signature != $sMsgSignature) {
  146. return \ErrorCode::$ValidateSignatureError;
  147. }
  148. $result = $pc->decrypt($encrypt, $this->m_sReceiveId);
  149. if ($result[0] != 0) {
  150. return $result[0];
  151. }
  152. $sMsg = $result[1];
  153. return \ErrorCode::$OK;
  154. }
  155. }