wechat_service_api.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447
  1. package gopay
  2. import (
  3. "crypto/aes"
  4. "crypto/cipher"
  5. "crypto/hmac"
  6. "crypto/md5"
  7. "crypto/sha256"
  8. "encoding/base64"
  9. "encoding/hex"
  10. "encoding/json"
  11. "encoding/xml"
  12. "errors"
  13. "fmt"
  14. "hash"
  15. "io/ioutil"
  16. "net/http"
  17. "reflect"
  18. "strings"
  19. )
  20. //获取微信支付所需参数里的Sign值(通过支付参数计算Sign值)
  21. // 注意:BodyMap中如无 sign_type 参数,默认赋值 sign_type 为 MD5
  22. // appId:应用ID
  23. // mchId:商户ID
  24. // ApiKey:API秘钥值
  25. // 返回参数 sign:通过Appid、MchId、ApiKey和BodyMap中的参数计算出的Sign值
  26. func GetWeChatParamSign(appId, mchId, apiKey string, bm BodyMap) (sign string) {
  27. bm.Set("appid", appId)
  28. bm.Set("mch_id", mchId)
  29. var (
  30. signType string
  31. h hash.Hash
  32. )
  33. signType = bm.Get("sign_type")
  34. if signType == null {
  35. bm.Set("sign_type", SignType_MD5)
  36. }
  37. if signType == SignType_HMAC_SHA256 {
  38. h = hmac.New(sha256.New, []byte(apiKey))
  39. } else {
  40. h = md5.New()
  41. }
  42. h.Write([]byte(bm.EncodeWeChatSignParams(apiKey)))
  43. sign = strings.ToUpper(hex.EncodeToString(h.Sum(nil)))
  44. return
  45. }
  46. //获取微信支付沙箱环境所需参数里的Sign值(通过支付参数计算Sign值)
  47. // 注意:沙箱环境默认 sign_type 为 MD5
  48. // appId:应用ID
  49. // mchId:商户ID
  50. // ApiKey:API秘钥值
  51. // 返回参数 sign:通过Appid、MchId、ApiKey和BodyMap中的参数计算出的Sign值
  52. func GetWeChatSanBoxParamSign(appId, mchId, apiKey string, bm BodyMap) (sign string, err error) {
  53. bm.Set("appid", appId)
  54. bm.Set("mch_id", mchId)
  55. bm.Set("sign_type", SignType_MD5)
  56. var (
  57. sandBoxApiKey string
  58. hashMd5 hash.Hash
  59. )
  60. if sandBoxApiKey, err = getSanBoxKey(mchId, GetRandomString(32), apiKey, SignType_MD5); err != nil {
  61. return
  62. }
  63. hashMd5 = md5.New()
  64. hashMd5.Write([]byte(bm.EncodeWeChatSignParams(sandBoxApiKey)))
  65. sign = strings.ToUpper(hex.EncodeToString(hashMd5.Sum(nil)))
  66. return
  67. }
  68. //解析微信支付异步通知的结果到BodyMap
  69. // req:*http.Request
  70. // 返回参数bm:Notify请求的参数
  71. // 返回参数err:错误信息
  72. func ParseWeChatNotifyResultToBodyMap(req *http.Request) (bm BodyMap, err error) {
  73. var bs []byte
  74. if bs, err = ioutil.ReadAll(req.Body); err != nil {
  75. return nil, fmt.Errorf("ioutil.ReadAll:%v", err.Error())
  76. }
  77. bm = make(BodyMap)
  78. if err = xml.Unmarshal(bs, &bm); err != nil {
  79. return nil, fmt.Errorf("xml.Unmarshal:%v", err.Error())
  80. }
  81. return
  82. }
  83. //解析微信支付异步通知的参数
  84. // req:*http.Request
  85. // 返回参数notifyReq:Notify请求的参数
  86. // 返回参数err:错误信息
  87. func ParseWeChatNotifyResult(req *http.Request) (notifyReq *WeChatNotifyRequest, err error) {
  88. notifyReq = new(WeChatNotifyRequest)
  89. if err = xml.NewDecoder(req.Body).Decode(notifyReq); err != nil {
  90. return nil, fmt.Errorf("xml.NewDecoder:%v", err.Error())
  91. }
  92. return
  93. }
  94. //微信同步返回参数验签或异步通知参数验签
  95. // ApiKey:API秘钥值
  96. // signType:签名类型(调用API方法时填写的类型)
  97. // bean:微信同步返回的结构体 wxRsp 或 异步通知解析的结构体 notifyReq
  98. // 返回参数ok:是否验签通过
  99. // 返回参数err:错误信息
  100. func VerifyWeChatSign(apiKey, signType string, bean interface{}) (ok bool, err error) {
  101. if bean == nil {
  102. return false, errors.New("bean is nil")
  103. }
  104. var (
  105. bm BodyMap
  106. bs []byte
  107. kind reflect.Kind
  108. bodySign string
  109. )
  110. kind = reflect.ValueOf(bean).Kind()
  111. if kind == reflect.Map {
  112. bm = bean.(BodyMap)
  113. goto Verify
  114. }
  115. if bs, err = json.Marshal(bean); err != nil {
  116. return false, fmt.Errorf("json.Marshal:%v", err.Error())
  117. }
  118. bm = make(BodyMap)
  119. if err = json.Unmarshal(bs, &bm); err != nil {
  120. return false, fmt.Errorf("json.Unmarshal:%v", err.Error())
  121. }
  122. Verify:
  123. bodySign = bm.Get("sign")
  124. bm.Remove("sign")
  125. return getWeChatReleaseSign(apiKey, signType, bm) == bodySign, nil
  126. }
  127. type WeChatNotifyResponse struct {
  128. ReturnCode string `xml:"return_code"`
  129. ReturnMsg string `xml:"return_msg"`
  130. }
  131. //返回数据给微信
  132. func (w *WeChatNotifyResponse) ToXmlString() (xmlStr string) {
  133. var buffer strings.Builder
  134. buffer.WriteString("<xml><return_code><![CDATA[")
  135. buffer.WriteString(w.ReturnCode)
  136. buffer.WriteString("]]></return_code>")
  137. buffer.WriteString("<return_msg><![CDATA[")
  138. buffer.WriteString(w.ReturnMsg)
  139. buffer.WriteString("]]></return_msg></xml>")
  140. xmlStr = buffer.String()
  141. return
  142. }
  143. //JSAPI支付,统一下单获取支付参数后,再次计算出小程序用的paySign
  144. // appId:APPID
  145. // nonceStr:随即字符串
  146. // prepayId:统一下单成功后得到的值
  147. // signType:签名类型
  148. // timeStamp:时间
  149. // ApiKey:API秘钥值
  150. // 微信小程序支付API:https://developers.weixin.qq.com/miniprogram/dev/api/open-api/payment/wx.requestPayment.html
  151. func GetMiniPaySign(appId, nonceStr, prepayId, signType, timeStamp, apiKey string) (paySign string) {
  152. var (
  153. buffer strings.Builder
  154. h hash.Hash
  155. )
  156. buffer.WriteString("appId=")
  157. buffer.WriteString(appId)
  158. buffer.WriteString("&nonceStr=")
  159. buffer.WriteString(nonceStr)
  160. buffer.WriteString("&package=")
  161. buffer.WriteString(prepayId)
  162. buffer.WriteString("&signType=")
  163. buffer.WriteString(signType)
  164. buffer.WriteString("&timeStamp=")
  165. buffer.WriteString(timeStamp)
  166. buffer.WriteString("&key=")
  167. buffer.WriteString(apiKey)
  168. if signType == SignType_HMAC_SHA256 {
  169. h = hmac.New(sha256.New, []byte(apiKey))
  170. } else {
  171. h = md5.New()
  172. }
  173. h.Write([]byte(buffer.String()))
  174. return strings.ToUpper(hex.EncodeToString(h.Sum(nil)))
  175. }
  176. //微信内H5支付,统一下单获取支付参数后,再次计算出微信内H5支付需要用的paySign
  177. // appId:APPID
  178. // nonceStr:随即字符串
  179. // packages:统一下单成功后拼接得到的值
  180. // signType:签名类型
  181. // timeStamp:时间
  182. // ApiKey:API秘钥值
  183. // 微信内H5支付官方文档:https://pay.weixin.qq.com/wiki/doc/api/external/jsapi.php?chapter=7_7&index=6
  184. func GetH5PaySign(appId, nonceStr, packages, signType, timeStamp, apiKey string) (paySign string) {
  185. var (
  186. buffer strings.Builder
  187. h hash.Hash
  188. )
  189. buffer.WriteString("appId=")
  190. buffer.WriteString(appId)
  191. buffer.WriteString("&nonceStr=")
  192. buffer.WriteString(nonceStr)
  193. buffer.WriteString("&package=")
  194. buffer.WriteString(packages)
  195. buffer.WriteString("&signType=")
  196. buffer.WriteString(signType)
  197. buffer.WriteString("&timeStamp=")
  198. buffer.WriteString(timeStamp)
  199. buffer.WriteString("&key=")
  200. buffer.WriteString(apiKey)
  201. if signType == SignType_HMAC_SHA256 {
  202. h = hmac.New(sha256.New, []byte(apiKey))
  203. } else {
  204. h = md5.New()
  205. }
  206. h.Write([]byte(buffer.String()))
  207. paySign = strings.ToUpper(hex.EncodeToString(h.Sum(nil)))
  208. return
  209. }
  210. //APP支付,统一下单获取支付参数后,再次计算APP支付所需要的的sign
  211. // appId:APPID
  212. // partnerid:partnerid
  213. // nonceStr:随即字符串
  214. // prepayId:统一下单成功后得到的值
  215. // signType:此处签名方式,务必与统一下单时用的签名方式一致
  216. // timeStamp:时间
  217. // ApiKey:API秘钥值
  218. // APP支付官方文档:https://pay.weixin.qq.com/wiki/doc/api/app/app.php?chapter=9_12
  219. func GetAppPaySign(appid, partnerid, noncestr, prepayid, signType, timestamp, apiKey string) (paySign string) {
  220. var (
  221. buffer strings.Builder
  222. h hash.Hash
  223. )
  224. buffer.WriteString("appid=")
  225. buffer.WriteString(appid)
  226. buffer.WriteString("&noncestr=")
  227. buffer.WriteString(noncestr)
  228. buffer.WriteString("&package=Sign=WXPay")
  229. buffer.WriteString("&partnerid=")
  230. buffer.WriteString(partnerid)
  231. buffer.WriteString("&prepayid=")
  232. buffer.WriteString(prepayid)
  233. buffer.WriteString("&timestamp=")
  234. buffer.WriteString(timestamp)
  235. buffer.WriteString("&key=")
  236. buffer.WriteString(apiKey)
  237. if signType == SignType_HMAC_SHA256 {
  238. h = hmac.New(sha256.New, []byte(apiKey))
  239. } else {
  240. h = md5.New()
  241. }
  242. h.Write([]byte(buffer.String()))
  243. paySign = strings.ToUpper(hex.EncodeToString(h.Sum(nil)))
  244. return
  245. }
  246. //解密开放数据到结构体
  247. // encryptedData:包括敏感数据在内的完整用户信息的加密数据,小程序获取到
  248. // iv:加密算法的初始向量,小程序获取到
  249. // sessionKey:会话密钥,通过 gopay.Code2Session() 方法获取到
  250. // beanPtr:需要解析到的结构体指针,操作完后,声明的结构体会被赋值
  251. // 文档:https://developers.weixin.qq.com/miniprogram/dev/framework/open-ability/signature.html
  252. func DecryptWeChatOpenDataToStruct(encryptedData, iv, sessionKey string, beanPtr interface{}) (err error) {
  253. var (
  254. cipherText, aesKey, ivKey, plainText []byte
  255. block cipher.Block
  256. blockMode cipher.BlockMode
  257. )
  258. beanValue := reflect.ValueOf(beanPtr)
  259. if beanValue.Kind() != reflect.Ptr {
  260. return errors.New("传入beanPtr类型必须是以指针形式")
  261. }
  262. if beanValue.Elem().Kind() != reflect.Struct {
  263. return errors.New("传入interface{}必须是结构体")
  264. }
  265. cipherText, _ = base64.StdEncoding.DecodeString(encryptedData)
  266. aesKey, _ = base64.StdEncoding.DecodeString(sessionKey)
  267. ivKey, _ = base64.StdEncoding.DecodeString(iv)
  268. if len(cipherText)%len(aesKey) != 0 {
  269. return errors.New("encryptedData is error")
  270. }
  271. if block, err = aes.NewCipher(aesKey); err != nil {
  272. return fmt.Errorf("aes.NewCipher:%v", err.Error())
  273. }
  274. blockMode = cipher.NewCBCDecrypter(block, ivKey)
  275. plainText = make([]byte, len(cipherText))
  276. blockMode.CryptBlocks(plainText, cipherText)
  277. if len(plainText) > 0 {
  278. plainText = PKCS7UnPadding(plainText)
  279. }
  280. if err = json.Unmarshal(plainText, beanPtr); err != nil {
  281. return fmt.Errorf("json.Unmarshal:%v", err.Error())
  282. }
  283. return
  284. }
  285. //解密开放数据到 BodyMap
  286. // encryptedData:包括敏感数据在内的完整用户信息的加密数据,小程序获取到
  287. // iv:加密算法的初始向量,小程序获取到
  288. // sessionKey:会话密钥,通过 gopay.Code2Session() 方法获取到
  289. // 文档:https://developers.weixin.qq.com/miniprogram/dev/framework/open-ability/signature.html
  290. func DecryptWeChatOpenDataToBodyMap(encryptedData, iv, sessionKey string) (bm BodyMap, err error) {
  291. var (
  292. cipherText, aesKey, ivKey, plainText []byte
  293. block cipher.Block
  294. blockMode cipher.BlockMode
  295. )
  296. cipherText, _ = base64.StdEncoding.DecodeString(encryptedData)
  297. aesKey, _ = base64.StdEncoding.DecodeString(sessionKey)
  298. ivKey, _ = base64.StdEncoding.DecodeString(iv)
  299. if len(cipherText)%len(aesKey) != 0 {
  300. return nil, errors.New("encryptedData is error")
  301. }
  302. if block, err = aes.NewCipher(aesKey); err != nil {
  303. return nil, fmt.Errorf("aes.NewCipher:%v", err.Error())
  304. } else {
  305. blockMode = cipher.NewCBCDecrypter(block, ivKey)
  306. plainText = make([]byte, len(cipherText))
  307. blockMode.CryptBlocks(plainText, cipherText)
  308. if len(plainText) > 0 {
  309. plainText = PKCS7UnPadding(plainText)
  310. }
  311. bm = make(BodyMap)
  312. if err = json.Unmarshal(plainText, &bm); err != nil {
  313. return nil, fmt.Errorf("json.Unmarshal:%v", err.Error())
  314. }
  315. return
  316. }
  317. }
  318. //App应用微信第三方登录,code换取access_token
  319. // appId:应用唯一标识,在微信开放平台提交应用审核通过后获得
  320. // appSecret:应用密钥AppSecret,在微信开放平台提交应用审核通过后获得
  321. // code:App用户换取access_token的code
  322. func GetAppWeChatLoginAccessToken(appId, appSecret, code string) (accessToken *AppWeChatLoginAccessToken, err error) {
  323. accessToken = new(AppWeChatLoginAccessToken)
  324. url := "https://api.weixin.qq.com/sns/oauth2/access_token?appid=" + appId + "&secret=" + appSecret + "&code=" + code + "&grant_type=authorization_code"
  325. if _, _, errs := HttpAgent().Get(url).EndStruct(accessToken); len(errs) > 0 {
  326. return nil, errs[0]
  327. }
  328. return
  329. }
  330. //刷新App应用微信第三方登录后,获取的 access_token
  331. // appId:应用唯一标识,在微信开放平台提交应用审核通过后获得
  332. // appSecret:应用密钥AppSecret,在微信开放平台提交应用审核通过后获得
  333. // code:App用户换取access_token的code
  334. func RefreshAppWeChatLoginAccessToken(appId, refreshToken string) (accessToken *RefreshAppWeChatLoginAccessTokenRsp, err error) {
  335. accessToken = new(RefreshAppWeChatLoginAccessTokenRsp)
  336. url := "https://api.weixin.qq.com/sns/oauth2/refresh_token?appid=" + appId + "&grant_type=refresh_token&refresh_token=" + refreshToken
  337. if _, _, errs := HttpAgent().Get(url).EndStruct(accessToken); len(errs) > 0 {
  338. return nil, errs[0]
  339. }
  340. return
  341. }
  342. //获取微信小程序用户的OpenId、SessionKey、UnionId
  343. // appId:APPID
  344. // appSecret:AppSecret
  345. // wxCode:小程序调用wx.login 获取的code
  346. // 文档:https://developers.weixin.qq.com/miniprogram/dev/api-backend/open-api/login/auth.code2Session.html
  347. func Code2Session(appId, appSecret, wxCode string) (sessionRsp *Code2SessionRsp, err error) {
  348. sessionRsp = new(Code2SessionRsp)
  349. url := "https://api.weixin.qq.com/sns/jscode2session?appid=" + appId + "&secret=" + appSecret + "&js_code=" + wxCode + "&grant_type=authorization_code"
  350. if _, _, errs := HttpAgent().Get(url).EndStruct(sessionRsp); len(errs) > 0 {
  351. return nil, errs[0]
  352. }
  353. return
  354. }
  355. //获取微信小程序全局唯一后台接口调用凭据(AccessToken:157字符)
  356. // appId:APPID
  357. // appSecret:AppSecret
  358. // 获取access_token文档:https://developers.weixin.qq.com/miniprogram/dev/api-backend/open-api/access-token/auth.getAccessToken.html
  359. func GetWeChatAppletAccessToken(appId, appSecret string) (accessToken *AccessToken, err error) {
  360. accessToken = new(AccessToken)
  361. url := "https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid=" + appId + "&secret=" + appSecret
  362. if _, _, errs := HttpAgent().Get(url).EndStruct(accessToken); len(errs) > 0 {
  363. return nil, errs[0]
  364. }
  365. return
  366. }
  367. //授权码查询openid(AccessToken:157字符)
  368. // appId:APPID
  369. // mchId:商户号
  370. // ApiKey:apiKey
  371. // authCode:用户授权码
  372. // nonceStr:随即字符串
  373. // 文档:https://pay.weixin.qq.com/wiki/doc/api/micropay.php?chapter=9_13&index=9
  374. func GetOpenIdByAuthCode(appId, mchId, apiKey, authCode, nonceStr string) (openIdRsp *OpenIdByAuthCodeRsp, err error) {
  375. var (
  376. url string
  377. bm BodyMap
  378. bs []byte
  379. errs []error
  380. )
  381. url = "https://api.mch.weixin.qq.com/tools/authcodetoopenid"
  382. bm = make(BodyMap)
  383. bm.Set("appid", appId)
  384. bm.Set("mch_id", mchId)
  385. bm.Set("auth_code", authCode)
  386. bm.Set("nonce_str", nonceStr)
  387. bm.Set("sign", getWeChatReleaseSign(apiKey, SignType_MD5, bm))
  388. if _, bs, errs = HttpAgent().Post(url).Type("xml").SendString(generateXml(bm)).EndBytes(); len(errs) > 0 {
  389. return nil, errs[0]
  390. }
  391. openIdRsp = new(OpenIdByAuthCodeRsp)
  392. if err = xml.Unmarshal(bs, openIdRsp); err != nil {
  393. return nil, fmt.Errorf("xml.Unmarshal:%v", err.Error())
  394. }
  395. return
  396. }
  397. //微信小程序用户支付完成后,获取该用户的 UnionId,无需用户授权。
  398. // accessToken:接口调用凭据
  399. // openId:用户的OpenID
  400. // transactionId:微信支付订单号
  401. // 文档:https://developers.weixin.qq.com/miniprogram/dev/api-backend/open-api/user-info/auth.getPaidUnionId.html
  402. func GetWeChatAppletPaidUnionId(accessToken, openId, transactionId string) (unionId *PaidUnionId, err error) {
  403. unionId = new(PaidUnionId)
  404. url := "https://api.weixin.qq.com/wxa/getpaidunionid?access_token=" + accessToken + "&openid=" + openId + "&transaction_id=" + transactionId
  405. if _, _, errs := HttpAgent().Get(url).EndStruct(unionId); len(errs) > 0 {
  406. return nil, errs[0]
  407. }
  408. return
  409. }
  410. //获取用户基本信息(UnionID机制)
  411. // accessToken:接口调用凭据
  412. // openId:用户的OpenID
  413. // lang:默认为 zh_CN ,可选填 zh_CN 简体,zh_TW 繁体,en 英语
  414. // 获取用户基本信息(UnionID机制)文档:https://mp.weixin.qq.com/wiki?t=resource/res_main&id=mp1421140839
  415. func GetWeChatUserInfo(accessToken, openId string, lang ...string) (userInfo *WeChatUserInfo, err error) {
  416. userInfo = new(WeChatUserInfo)
  417. var url string
  418. if len(lang) > 0 {
  419. url = "https://api.weixin.qq.com/cgi-bin/user/info?access_token=" + accessToken + "&openid=" + openId + "&lang=" + lang[0]
  420. } else {
  421. url = "https://api.weixin.qq.com/cgi-bin/user/info?access_token=" + accessToken + "&openid=" + openId + "&lang=zh_CN"
  422. }
  423. if _, _, errs := HttpAgent().Get(url).EndStruct(userInfo); len(errs) > 0 {
  424. return nil, errs[0]
  425. }
  426. return
  427. }