web_paymsg.go 46 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416
  1. package msg
  2. import (
  3. "bytes"
  4. "crypto"
  5. "crypto/hmac"
  6. "crypto/md5"
  7. "crypto/rand"
  8. "crypto/rsa"
  9. "crypto/sha1"
  10. "crypto/x509"
  11. "database/sql"
  12. "encoding/base64"
  13. "encoding/hex"
  14. "encoding/json"
  15. "encoding/pem"
  16. "encoding/xml"
  17. "fmt"
  18. "io"
  19. "net/http"
  20. "net/url"
  21. "rocommon/service"
  22. "rocommon/socket/mysql"
  23. "rocommon/util"
  24. "roserver/baseserver/model"
  25. gmweb "roserver/gmweb/model"
  26. selfmodel "roserver/gmweb/model"
  27. "roserver/serverproto"
  28. "sort"
  29. "strconv"
  30. "strings"
  31. "time"
  32. "github.com/gin-gonic/gin"
  33. )
  34. // https://blog.csdn.net/chunyouhai5703/article/details/100978656?utm_medium=distribute.pc_relevant.none-task-blog-title-1&spm=1001.2101.3001.4242
  35. type QuickPayNotify struct {
  36. XMLName xml.Name `xml:"quicksdk_message"`
  37. Message QuickTBData `xml:"message"`
  38. }
  39. type QuickTBData struct {
  40. IsTest bool `xml:"is_test"`
  41. Channel string `xml:"channel"`
  42. ChannelUid string `xml:"channel_uid"`
  43. GameOrder string `xml:"game_order"`
  44. PayTime string `xml:"pay_time"`
  45. Amount float32 `xml:"amount"`
  46. Status int32 `xml:"status"`
  47. ExtrasParams string `xml:"extras_params"`
  48. }
  49. /*
  50. <?xml version="1.0" encoding="UTF-8" standalone="no">
  51. <quicksdk_message>
  52. <message>
  53. <is_test>0</is_test>
  54. <channel>8888</channel>
  55. <channel_uid>231845</channel_uid>
  56. <game_order>123456789</game_order>
  57. <order_no>12520160612114220441168433</order_no>
  58. <pay_time>2016-06-12 11:42:20</pay_time>
  59. <amount>1.00</amount>
  60. <status>0</status>
  61. <extras_params>{1}_{2}</extras_params>
  62. </message>
  63. </quicksdk_message>
  64. */
  65. func WebPayQuickNotify(c *gin.Context) {
  66. //ntData := c.PostForm("nt_data")
  67. //sign := c.PostForm("sign")
  68. //md5Sign := c.PostForm("md5Sign")
  69. //
  70. //data := ntData + sign + service.GetServiceConfig().SDKConfig.QuickMd5key
  71. //tmpSign := md5.Sum([]byte(data))
  72. //md5Str := fmt.Sprintf("%x", tmpSign)
  73. //util.DebugF("WebPayQuickNotify ntData=%v sign=%v md5sign=%v tmpsign=%v", ntData, sign, md5Sign, md5Str)
  74. //if md5Str == md5Sign {
  75. // util.InfoF("WebPayQuickNotify ok")
  76. //} else {
  77. // util.ErrorF("WebPayQuickNotify sign invalid!!!")
  78. // c.JSON(http.StatusOK, "FAILED")
  79. // return
  80. //}
  81. //
  82. ////decode nt_data
  83. //tmpNtDataList := strings.Split(ntData, "@")
  84. //tmpNtData := make([]byte, len(tmpNtDataList))
  85. //tmpKeyData := []byte(service.GetServiceConfig().SDKConfig.QuickCallbackKey)
  86. //for idx := 1; idx < len(tmpNtDataList); idx++ {
  87. // tmpVal, _ := strconv.Atoi(tmpNtDataList[idx])
  88. // tmpNtData[idx] = (byte)(tmpVal - (int)(0xff&tmpKeyData[(idx-1)%len(tmpKeyData)]))
  89. //}
  90. ////字符串最前面会有一个空格
  91. //if string(tmpNtData[0]) == "\u0000" {
  92. // tmpNtData = append(tmpNtData[:0], tmpNtData[1:]...)
  93. //}
  94. //util.InfoF("WebPayQuickNotify ntdata=%v", string(tmpNtData))
  95. //
  96. //tmpSt := &QuickPayNotify{}
  97. //err := xml.Unmarshal(tmpNtData, tmpSt)
  98. //if err != nil {
  99. // util.ErrorF("WebPayQuickNotify xml decode err=%v", err)
  100. // c.JSON(http.StatusOK, "FAILED")
  101. // return
  102. //}
  103. //
  104. //ntfData := &WebNotifyData{}
  105. //ntfData.CpOrderId = tmpSt.Message.GameOrder
  106. //ntfData.SdkOrderId = ""
  107. //ntfData.PayMethod = ""
  108. //ntfData.PayCurrency = ""
  109. //ntfData.PayTime = uint64(util.GetTimeSeconds())
  110. //ntfData.PayChannel = ""
  111. //webPayNotify(ntfData, tmpSt.Message.Amount, c)
  112. //c.JSON(http.StatusOK, "SUCCESS")
  113. game_order := c.PostForm("game_order") //游戏订单号
  114. order_no := c.PostForm("order_no") //SDK订单ID
  115. amount := c.PostForm("amount") //充值金额
  116. PayChannel := c.PostForm("channel") //充值渠道
  117. serverId := c.PostForm("server_id") //充值服ID
  118. util.DebugF("收到充值订单:GameOrder=%v, SdkOfderId=%v, PauAmount=%v, PayChannel=%v, serverId=%v", game_order, order_no, amount, PayChannel, serverId)
  119. checkPayAmount, _ := model.Str2Float32(amount)
  120. ntfData := &WebNotifyData{}
  121. ntfData.CpOrderId = game_order
  122. ntfData.SdkOrderId = order_no
  123. ntfData.PayMethod = ""
  124. ntfData.PayCurrency = ""
  125. ntfData.PayTime = uint64(util.GetTimeSeconds())
  126. ntfData.PayChannel = PayChannel
  127. retState := webPayNotify(ntfData, checkPayAmount, c)
  128. //c.JSON(http.StatusOK, `success`)
  129. c.Data(http.StatusOK, "text/plain; charset=utf-8", []byte(retState))
  130. }
  131. func getMd5Sign(callbackKey string, params map[string]string) string {
  132. // 删除参数中的 sign 字段
  133. delete(params, "sign")
  134. // 按参数名进行升序排序
  135. var keys []string
  136. for key := range params {
  137. keys = append(keys, key)
  138. }
  139. sort.Strings(keys)
  140. // 拼接参数和值
  141. var signKey strings.Builder
  142. for _, key := range keys {
  143. signKey.WriteString(key)
  144. signKey.WriteString("=")
  145. signKey.WriteString(params[key])
  146. signKey.WriteString("&")
  147. }
  148. // 添加回调密钥
  149. signKey.WriteString(callbackKey)
  150. // 计算 MD5
  151. hash := md5.Sum([]byte(signKey.String()))
  152. return hex.EncodeToString(hash[:])
  153. }
  154. func getMd5SignXiaoqi(params map[string]string) string {
  155. // 删除参数中的 sign 字段
  156. delete(params, "sign_data")
  157. // 按参数名进行升序排序
  158. var keys []string
  159. for key := range params {
  160. keys = append(keys, key)
  161. }
  162. sort.Strings(keys)
  163. // 拼接参数和值
  164. var signKey strings.Builder
  165. for _, key := range keys {
  166. signKey.WriteString(key)
  167. signKey.WriteString("=")
  168. signKey.WriteString(params[key])
  169. signKey.WriteString("&")
  170. }
  171. return signKey.String()
  172. }
  173. func getMd5RuSign(callbackKey string, params map[string]string) string {
  174. // 删除参数中的 sign 字段
  175. delete(params, "sign")
  176. // 按参数名进行升序排序
  177. var keys []string
  178. for key := range params {
  179. keys = append(keys, key)
  180. }
  181. sort.Strings(keys)
  182. // 拼接参数和值
  183. var signKey strings.Builder
  184. for i, key := range keys {
  185. signKey.WriteString(key)
  186. signKey.WriteString("=")
  187. signKey.WriteString(params[key])
  188. if i != len(keys)-1 {
  189. signKey.WriteString("&")
  190. }
  191. }
  192. // 添加回调密钥
  193. signKey.WriteString(callbackKey)
  194. // 计算 MD5
  195. hash := md5.Sum([]byte(signKey.String()))
  196. return hex.EncodeToString(hash[:])
  197. }
  198. func getMd5DnSign(callbackKey string, username, order_id, server, amount, extra, sandbox, timestamp string) string {
  199. // 拼接参数和值
  200. var signKey strings.Builder
  201. signKey.WriteString(username)
  202. signKey.WriteString(order_id)
  203. signKey.WriteString(server)
  204. signKey.WriteString(amount)
  205. signKey.WriteString(extra)
  206. signKey.WriteString(sandbox)
  207. signKey.WriteString(timestamp)
  208. // 添加回调密钥
  209. signKey.WriteString(callbackKey)
  210. // 计算 MD5
  211. hash := md5.Sum([]byte(signKey.String()))
  212. return hex.EncodeToString(hash[:])
  213. }
  214. type Extras struct {
  215. ServerId int `json:"serverId"`
  216. Platform string `json:"platform"`
  217. SubPlatform string `json:"subPlatform"`
  218. Bima string `json:"bima"`
  219. CpOrderId string `json:"cpOrderId"`
  220. }
  221. type ExtrasRu struct {
  222. AccountId string `json:"accountId"`
  223. Money string `json:"money"`
  224. Addtime string `json:"addtime"`
  225. OrderId string `json:"orderId"`
  226. CustomorderId string `json:"customorderId"`
  227. Paytype string `json:"paytype"`
  228. Success string `json:"success"`
  229. }
  230. type ExtrasDn struct {
  231. OrderNo string `json:"orderNo"`
  232. Uid string `json:"uid"`
  233. Platform string `json:"platform"`
  234. GoodsId int32 `json:"goodsId"`
  235. GoodsType int32 `json:"goodsType"`
  236. }
  237. type ExtrasDnIos struct {
  238. OrderNo string `json:"biwb"`
  239. Uid string `json:"uid"`
  240. Platform string `json:"bivz"`
  241. GoodsId int32 `json:"goodsId"`
  242. GoodsType int32 `json:"goodsType"`
  243. }
  244. // 海外版quick回调
  245. func WebPayHwQuickNotify(c *gin.Context) {
  246. //util.DebugF("支付回调信息:%v", c.Request.PostForm)
  247. params := make(map[string]string)
  248. if err := c.Request.ParseForm(); err != nil {
  249. util.InfoF("parseForm falied")
  250. c.String(http.StatusOK, "FAILED")
  251. return
  252. }
  253. util.DebugF("支付回调信息2:%v", c.Request.PostForm)
  254. for key, value := range c.Request.PostForm {
  255. params[key] = value[0] // 假设每个参数只有一个值
  256. }
  257. sign := params["sign"]
  258. info2 := params["extrasParams"]
  259. info := strings.ReplaceAll(info2, "\\", "")
  260. var extras Extras
  261. err := json.Unmarshal([]byte(info), &extras)
  262. if err != nil {
  263. util.ErrorF("支付回调参数解析错误:%v", err)
  264. }
  265. util.InfoF("支付签名认证:%v params:%v", extras, params)
  266. if extras.Platform == "SDKYOUYI_IOS" || extras.Bima == "SDKYOUYI_IOS" {
  267. util.ErrorF("ios 支付签名认证:%v", info)
  268. newSign := getMd5Sign("58696021497436514481898335416221", params)
  269. if newSign != sign {
  270. util.ErrorF("签名错误%v", sign)
  271. c.String(http.StatusOK, "FAILED")
  272. return
  273. }
  274. } else if extras.Platform == "SDKYOUYI_IOS_MyCard" || extras.Platform == "SDKHwQuick_MyCard" {
  275. util.ErrorF("mycard 支付签名认证:%v", info)
  276. newSign := getMd5Sign("03422134397322604272901806704074", params)
  277. if newSign != sign {
  278. util.ErrorF("签名错误%v", sign)
  279. c.String(http.StatusOK, "FAILED")
  280. return
  281. }
  282. } else {
  283. util.ErrorF("android 支付签名认证:%v", info)
  284. newSign := getMd5Sign("47409863970932353623015025039223", params)
  285. if newSign != sign {
  286. util.ErrorF("签名错误%v", sign)
  287. c.String(http.StatusOK, "FAILED")
  288. return
  289. }
  290. }
  291. uid := c.PostForm("uid")
  292. cpOrderId := c.PostForm("cpOrderNo")
  293. if cpOrderId == "" {
  294. if extras.CpOrderId != "" {
  295. cpOrderId = extras.CpOrderId
  296. } else {
  297. util.ErrorF("mycard pay cporderId is nil extras:%v", extras)
  298. }
  299. }
  300. orderNo := c.PostForm("orderNo")
  301. payAmount := c.PostForm("payAmount")
  302. payCurrency := c.PostForm("payCurrency")
  303. payType := c.PostForm("payType")
  304. usdAmount := c.PostForm("usdAmount")
  305. ntfData := &WebNotifyData{}
  306. ntfData.CpOrderId = cpOrderId
  307. ntfData.SdkOrderId = orderNo
  308. ntfData.PayMethod = payType
  309. ntfData.PayCurrency = payCurrency
  310. ntfData.PayTime = uint64(util.GetTimeSeconds())
  311. ntfData.PayChannel = "qk_hw"
  312. util.WarnF("paycallback uid=%v cpOrderNo=%v orderNo=%v payAmount=%v payCurrency=%v payType=%v usdAmount=%v",
  313. uid, cpOrderId, orderNo, payAmount, payCurrency, payType, usdAmount)
  314. f64, err := strconv.ParseFloat(usdAmount, 32)
  315. if err != nil {
  316. fmt.Println("Error:", err)
  317. return
  318. }
  319. webPayNotify(ntfData, float32(f64), c)
  320. c.String(http.StatusOK, "SUCCESS")
  321. }
  322. // 海外版xiaoqi回调
  323. func WebPayHwXiaoQiNotify(c *gin.Context) {
  324. //util.DebugF("支付回调信息:%v", c.Request.PostForm)
  325. params := make(map[string]string)
  326. if err := c.Request.ParseForm(); err != nil {
  327. util.InfoF("parseForm falied")
  328. c.String(http.StatusOK, "FAILED")
  329. return
  330. }
  331. util.DebugF("支付回调信息2:%v", c.Request.PostForm)
  332. for key, value := range c.Request.PostForm {
  333. params[key] = value[0] // 假设每个参数只有一个值
  334. }
  335. info2 := params["extends_info_data"]
  336. info := strings.ReplaceAll(info2, "\\", "")
  337. var extras Extras
  338. err := json.Unmarshal([]byte(info), &extras)
  339. if err != nil {
  340. util.ErrorF("支付回调参数解析错误:%v", err)
  341. }
  342. util.InfoF("xiaoqi 透传参数:%v params:%v", extras, params)
  343. if extras.Platform == "IOS_X7" || extras.Bima == "IOS_X7" {
  344. util.ErrorF("xiaoqi ios 支付签名认证:%v", info)
  345. b, err2 := VerifySignature(params, "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCfYd3FqSaWqCpWLSktBSSgAelt0F6T+tO4C25YKR/6X/sPacDBbX662/0fW+H+YbXigHWFB/yangkhiZTpD/VmiOo5lISX6L0/m+13ti9b8jzTZcfVngfLsP+Ztbk81N1Jk0gWF4bndZxREJ3IxcEDHnIrwXgLGA2GJ89kdgudwIDAQAB")
  346. if err2 != nil || !b {
  347. util.ErrorF("签名错误%v", err2)
  348. c.String(http.StatusOK, "FAILED")
  349. return
  350. }
  351. } else {
  352. util.ErrorF("android 支付签名认证:%v", info)
  353. b, err2 := VerifySignature(params, "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCfYd3FqSaWqCpWLSktBSSgAelt0F6T+tO4C25YKR/6X/sPacDBbX662/0fW+H+YbXigHWFB/yangkhiZTpD/VmiOo5lISX6L0/m+13ti9b8jzTZcfVngfLsP+Ztbk81N1Jk0gWF4bndZxREJ3IxcEDHnIrwXgLGA2GJ89kdgudwIDAQAB")
  354. if err2 != nil || !b {
  355. util.ErrorF("签名错误%v", err2)
  356. c.String(http.StatusOK, "FAILED")
  357. return
  358. }
  359. }
  360. myData, err3 := DecryptDataToMap(params["encryp_data"], "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCfYd3FqSaWqCpWLSktBSSgAelt0F6T+tO4C25YKR/6X/sPacDBbX662/0fW+H+YbXigHWFB/yangkhiZTpD/VmiOo5lISX6L0/m+13ti9b8jzTZcfVngfLsP+Ztbk81N1Jk0gWF4bndZxREJ3IxcEDHnIrwXgLGA2GJ89kdgudwIDAQAB")
  361. if err3 != nil {
  362. util.ErrorF("解析encryp_data error:%v", err3)
  363. c.String(http.StatusOK, "FAILED")
  364. return
  365. }
  366. uid := myData["uid"]
  367. cpOrderId := myData["game_orderid"]
  368. if cpOrderId == "" {
  369. if extras.CpOrderId != "" {
  370. cpOrderId = extras.CpOrderId
  371. } else {
  372. util.ErrorF("mycard pay cporderId is nil extras:%v", extras)
  373. }
  374. }
  375. orderNo := myData["xiao7_goid"]
  376. payCurrency := myData["game_currency"]
  377. payType := myData["game_currency"]
  378. usdAmount := myData["pay_price"]
  379. ntfData := &WebNotifyData{}
  380. ntfData.CpOrderId = cpOrderId
  381. ntfData.SdkOrderId = orderNo
  382. ntfData.PayMethod = payType
  383. ntfData.PayCurrency = payCurrency
  384. ntfData.PayTime = uint64(util.GetTimeSeconds())
  385. ntfData.PayChannel = "xiaoqi"
  386. util.WarnF("paycallback uid=%v cpOrderNo=%v orderNo=%v payAmount=%v payCurrency=%v payType=%v usdAmount=%v",
  387. uid, cpOrderId, orderNo, usdAmount, payCurrency, payType, usdAmount)
  388. f64, err := strconv.ParseFloat(usdAmount, 32)
  389. if err != nil {
  390. fmt.Println("Error:", err)
  391. return
  392. }
  393. webPayNotify(ntfData, float32(f64), c)
  394. c.String(http.StatusOK, "success")
  395. }
  396. func DecryptDataToMap(encrypDataBase64 string, privateKeyStr string) (map[string]string, error) {
  397. // 1. Base64 解码得到 raw_encryp_data
  398. rawEncrypData, err := base64.StdEncoding.DecodeString(encrypDataBase64)
  399. if err != nil {
  400. return nil, fmt.Errorf("base64解码失败: %v", err)
  401. }
  402. // 2. 使用 RSA 私钥解密
  403. decryptedData, err := rsaPrivateDecrypt(rawEncrypData, privateKeyStr)
  404. if err != nil {
  405. return nil, fmt.Errorf("RSA解密失败: %v", err)
  406. }
  407. // 3. 解析查询字符串为 map
  408. return parseQueryStringToMap(string(decryptedData)), nil
  409. }
  410. // rsaPrivateDecrypt RSA私钥解密
  411. func rsaPrivateDecrypt(ciphertext []byte, privateKeyStr string) ([]byte, error) {
  412. // 解析私钥
  413. privateKey, err := parsePrivateKey(privateKeyStr)
  414. if err != nil {
  415. return nil, err
  416. }
  417. // RSA 私钥解密(PKCS1v15 填充)
  418. plaintext, err := rsa.DecryptPKCS1v15(rand.Reader, privateKey, ciphertext)
  419. if err != nil {
  420. return nil, fmt.Errorf("解密失败: %v", err)
  421. }
  422. return plaintext, nil
  423. }
  424. // parsePrivateKey 解析 PEM 格式的私钥
  425. func parsePrivateKey(privateKeyStr string) (*rsa.PrivateKey, error) {
  426. // 去除空白字符
  427. privateKeyStr = strings.TrimSpace(privateKeyStr)
  428. // 确保是 PEM 格式
  429. if !strings.Contains(privateKeyStr, "-----BEGIN") {
  430. privateKeyStr = "-----BEGIN RSA PRIVATE KEY-----\n" +
  431. privateKeyStr +
  432. "\n-----END RSA PRIVATE KEY-----"
  433. }
  434. // 解码 PEM
  435. block, _ := pem.Decode([]byte(privateKeyStr))
  436. if block == nil {
  437. return nil, fmt.Errorf("PEM解码失败")
  438. }
  439. // 解析私钥(支持 PKCS1 和 PKCS8 格式)
  440. privateKey, err := x509.ParsePKCS1PrivateKey(block.Bytes)
  441. if err != nil {
  442. // 尝试 PKCS8 格式
  443. key, err := x509.ParsePKCS8PrivateKey(block.Bytes)
  444. if err != nil {
  445. return nil, fmt.Errorf("解析私钥失败: %v", err)
  446. }
  447. var ok bool
  448. privateKey, ok = key.(*rsa.PrivateKey)
  449. if !ok {
  450. return nil, fmt.Errorf("不是RSA私钥")
  451. }
  452. return privateKey, nil
  453. }
  454. return privateKey, nil
  455. }
  456. // parseQueryStringToMap 解析查询字符串为 map
  457. func parseQueryStringToMap(queryStr string) map[string]string {
  458. params := make(map[string]string)
  459. if queryStr == "" {
  460. return params
  461. }
  462. pairs := strings.Split(queryStr, "&")
  463. for _, pair := range pairs {
  464. if pair == "" {
  465. continue
  466. }
  467. kv := strings.SplitN(pair, "=", 2)
  468. if len(kv) == 2 {
  469. params[kv[0]] = kv[1]
  470. } else if len(kv) == 1 {
  471. params[kv[0]] = ""
  472. }
  473. }
  474. return params
  475. }
  476. func VerifySignature(params map[string]string, publicKeyStr string) (bool, error) {
  477. // 1. 获取并解码 sign_data 参数
  478. signDataBase64, ok := params["sign_data"]
  479. if !ok {
  480. return false, fmt.Errorf("缺少 sign_data 参数")
  481. }
  482. // base64_decode 得到 raw_sign_data
  483. rawSignData, err := base64.StdEncoding.DecodeString(signDataBase64)
  484. if err != nil {
  485. return false, fmt.Errorf("base64解码失败: %v", err)
  486. }
  487. // 2. 构建 source_str(排除 sign_data,其他参数按字典序排序)
  488. sourceStr := buildSourceString(params)
  489. // 3. 验证签名
  490. err = verifyWithPublicKey(sourceStr, rawSignData, publicKeyStr)
  491. if err != nil {
  492. return false, err
  493. }
  494. return true, nil
  495. }
  496. // buildSourceString 构建查询字符串(排除 sign_data,按字典序排序)
  497. func buildSourceString(params map[string]string) string {
  498. // 收集除 sign_data 外的所有键
  499. keys := make([]string, 0)
  500. for key := range params {
  501. if key != "sign_data" {
  502. keys = append(keys, key)
  503. }
  504. }
  505. // 字典序排序
  506. sort.Strings(keys)
  507. // 拼接成 key=value&key=value 格式
  508. var pairs []string
  509. for _, key := range keys {
  510. value := params[key]
  511. pairs = append(pairs, fmt.Sprintf("%s=%s", key, value))
  512. }
  513. return strings.Join(pairs, "&")
  514. }
  515. // verifyWithPublicKey 使用公钥验证签名
  516. func verifyWithPublicKey(data string, signature []byte, publicKeyStr string) error {
  517. // 1. 解析公钥(支持多种格式)
  518. publicKey, err := parsePublicKey(publicKeyStr)
  519. if err != nil {
  520. return fmt.Errorf("解析公钥失败: %v", err)
  521. }
  522. // 2. 计算 SHA1 哈希
  523. hash := sha1.Sum([]byte(data))
  524. // 3. 验证签名
  525. err = rsa.VerifyPKCS1v15(publicKey, crypto.SHA1, hash[:], signature)
  526. if err != nil {
  527. return fmt.Errorf("签名验证失败: %v", err)
  528. }
  529. return nil
  530. }
  531. // parsePublicKey 解析 PEM 格式的公钥
  532. func parsePublicKey(publicKeyStr string) (*rsa.PublicKey, error) {
  533. // 去除空白字符
  534. publicKeyStr = strings.TrimSpace(publicKeyStr)
  535. // 如果公钥字符串不包含 PEM 头,尝试添加
  536. if !strings.Contains(publicKeyStr, "-----BEGIN") {
  537. publicKeyStr = "-----BEGIN PUBLIC KEY-----\n" +
  538. publicKeyStr +
  539. "\n-----END PUBLIC KEY-----"
  540. }
  541. // 解码 PEM
  542. block, _ := pem.Decode([]byte(publicKeyStr))
  543. if block == nil {
  544. return nil, fmt.Errorf("PEM解码失败")
  545. }
  546. // 解析公钥
  547. pubInterface, err := x509.ParsePKIXPublicKey(block.Bytes)
  548. if err != nil {
  549. return nil, err
  550. }
  551. publicKey, ok := pubInterface.(*rsa.PublicKey)
  552. if !ok {
  553. return nil, fmt.Errorf("不是RSA公钥")
  554. }
  555. return publicKey, nil
  556. }
  557. // parsePublicKey 解析 PEM 格式的公钥
  558. //func parsePublicKey(publicKeyStr string) (*rsa.PublicKey, error) {
  559. // // 去除可能的空白字符
  560. // publicKeyStr = strings.TrimSpace(publicKeyStr)
  561. //
  562. // // 如果公钥字符串不包含 PEM 头,尝试添加
  563. // if !strings.Contains(publicKeyStr, "-----BEGIN") {
  564. // publicKeyStr = "-----BEGIN PUBLIC KEY-----\n" +
  565. // publicKeyStr +
  566. // "\n-----END PUBLIC KEY-----"
  567. // }
  568. //
  569. // // 解码 PEM
  570. // block, _ := pem.Decode([]byte(publicKeyStr))
  571. // if block == nil {
  572. // return nil, fmt.Errorf("PEM 解码失败")
  573. // }
  574. //
  575. // // 解析公钥
  576. // pubInterface, err := x509.ParsePKIXPublicKey(block.Bytes)
  577. // if err != nil {
  578. // return nil, err
  579. // }
  580. //
  581. // publicKey, ok := pubInterface.(*rsa.PublicKey)
  582. // if !ok {
  583. // return nil, fmt.Errorf("不是 RSA 公钥")
  584. // }
  585. //
  586. // return publicKey, nil
  587. //}
  588. func WebPayHwRuNotify(c *gin.Context) {
  589. //util.DebugF("支付回调信息:%v", c.Request.PostForm)
  590. params := make(map[string]string)
  591. if err := c.Request.ParseForm(); err != nil {
  592. util.InfoF("parseForm falied")
  593. c.String(http.StatusOK, "FAILED")
  594. return
  595. }
  596. util.DebugF("支付回调信息2:%v", c.Request.PostForm)
  597. for key, value := range c.Request.PostForm {
  598. params[key] = value[0] // 假设每个参数只有一个值
  599. }
  600. sign := params["sign"]
  601. info2 := params["custominfo"]
  602. info := strings.ReplaceAll(info2, "\\", "")
  603. var extras Extras
  604. err := json.Unmarshal([]byte(info), &extras)
  605. if err != nil {
  606. util.ErrorF("支付回调参数解析错误:%v", err)
  607. }
  608. util.InfoF("支付签名认证:%v params:%v", extras, params)
  609. if extras.Platform == "ZT_IOS" || extras.Bima == "ZT_IOS" {
  610. util.ErrorF("ios 支付签名认证:%v", info)
  611. newSign := getMd5RuSign("80c648e7df8aaa72", params)
  612. if newSign != sign {
  613. util.ErrorF("签名错误%v", sign)
  614. c.String(http.StatusOK, "FAILED")
  615. return
  616. }
  617. } else if extras.Platform == "SDKYOUYI_IOS_MyCard" || extras.Platform == "SDKHwQuick_MyCard" {
  618. util.ErrorF("mycard 支付签名认证:%v", info)
  619. newSign := getMd5Sign("03422134397322604272901806704074", params)
  620. if newSign != sign {
  621. util.ErrorF("签名错误%v", sign)
  622. c.String(http.StatusOK, "FAILED")
  623. return
  624. }
  625. } else {
  626. util.ErrorF("android 支付签名认证:%v", info)
  627. newSign := getMd5RuSign("80c648e7df8aaa72", params)
  628. if newSign != sign {
  629. util.ErrorF("签名错误%v", sign)
  630. c.String(http.StatusOK, "FAILED")
  631. return
  632. }
  633. }
  634. uid := c.PostForm("account")
  635. cpOrderId := c.PostForm("customorderid")
  636. orderNo := c.PostForm("orderid")
  637. payAmount := c.PostForm("money")
  638. payCurrency := c.PostForm("currency")
  639. payType := c.PostForm("paytype")
  640. usdAmount := c.PostForm("doller")
  641. ntfData := &WebNotifyData{}
  642. ntfData.CpOrderId = cpOrderId
  643. ntfData.SdkOrderId = orderNo
  644. ntfData.PayMethod = payType
  645. ntfData.PayCurrency = payCurrency
  646. ntfData.PayTime = uint64(util.GetTimeSeconds())
  647. ntfData.PayChannel = "qk_hw"
  648. util.WarnF("paycallback uid=%v cpOrderNo=%v orderNo=%v payAmount=%v payCurrency=%v payType=%v usdAmount=%v",
  649. uid, cpOrderId, orderNo, payAmount, payCurrency, payType, usdAmount)
  650. f64, err := strconv.ParseFloat(payAmount, 32)
  651. if err != nil {
  652. fmt.Println("Error:", err)
  653. return
  654. }
  655. webPayNotify(ntfData, float32(f64), c)
  656. //// 简单粗暴,直接给其他服转发,不需要确认是哪个服
  657. //payPostRouter := service.GetServiceConfig().SDKConfig.PayPostRouter
  658. //util.WarnF("paycallback payPostRouter:%v\n", payPostRouter)
  659. //// 组装转发body
  660. //params["sign"] = sign
  661. //var routerStr strings.Builder
  662. //for key, value := range params {
  663. // routerStr.WriteString(key)
  664. // routerStr.WriteString("=")
  665. // routerStr.WriteString(value)
  666. // routerStr.WriteString("&")
  667. //}
  668. //routerString := routerStr.String()
  669. //util.WarnF("paycallback routerString:%v\n", routerString)
  670. //go sendPosts(payPostRouter, routerString)
  671. c.String(http.StatusOK, "success")
  672. }
  673. func WebPayHwDn2Notify(c *gin.Context) {
  674. //util.DebugF("支付回调信息:%v", c.Request.PostForm)
  675. orderId := c.DefaultQuery("order_id", "")
  676. payAmount := c.DefaultQuery("amount", "")
  677. sign := c.DefaultQuery("sign", "")
  678. extra := c.DefaultQuery("extra", "")
  679. username := c.DefaultQuery("username", "")
  680. server := c.DefaultQuery("server", "")
  681. sandbox := c.DefaultQuery("sandbox", "")
  682. timestamp := c.DefaultQuery("timestamp", "")
  683. var extras ExtrasDn
  684. err := json.Unmarshal([]byte(extra), &extras)
  685. if err != nil {
  686. util.ErrorF("支付回调参数解析错误:%v", err)
  687. }
  688. //cpOrderId := extras.OrderNo
  689. util.ErrorF("支付回调信息东南亚2:orderId:%v,payAmount:%v,sign:%v,extra:%v,username:%v,server:%v,sandbox:%v,timestamp:%v", orderId, payAmount, sign, extra, username, server, sandbox, timestamp)
  690. if extras.Platform == "XUAN_YOU_Google_Android" {
  691. if sign != getMd5DnSign("e81c2bd2ffb7feb7f0df477dc02b0bbd", username, orderId, server, payAmount, extra, sandbox, timestamp) {
  692. c.JSON(http.StatusOK, gin.H{"status": 1, "msg": "sign error"})
  693. return
  694. }
  695. } else if extras.Platform == "XUAN_YOU_IOS" {
  696. if sign != getMd5DnSign("3f8e9fec0794443f76d3a27cd41e2711", username, orderId, server, payAmount, extra, sandbox, timestamp) {
  697. c.JSON(http.StatusOK, gin.H{"status": 1, "msg": "sign error"})
  698. return
  699. }
  700. } else {
  701. if sign != getMd5DnSign("cee1b45a9aa02a75f9d720d6b9e7b7d4", username, orderId, server, payAmount, extra, sandbox, timestamp) {
  702. c.JSON(http.StatusOK, gin.H{"status": 1, "msg": "sign error"})
  703. return
  704. }
  705. }
  706. cpOrderId := extras.OrderNo
  707. if cpOrderId != "" {
  708. //f64, err := strconv.ParseFloat(payAmount, 64)
  709. //if err != nil {
  710. // fmt.Println("Error:", err)
  711. // return
  712. //}
  713. util.WarnF("paycallbackDn2 uid=%v cpOrderNo=%v orderNo=%v payAmount=%v",
  714. extras.Uid, cpOrderId, orderId, payAmount)
  715. res := webPayNotifyDn(cpOrderId, payAmount, orderId)
  716. if res == "SUCCESS" {
  717. c.JSON(http.StatusOK, gin.H{"status": 0})
  718. } else {
  719. c.JSON(http.StatusOK, gin.H{"status": 1, "msg": "order already complete"})
  720. }
  721. } else { //走的网页支付流程游戏这边没有orderid,只发代金券礼包
  722. for _, v := range ResDnyPayInfo.GiftList {
  723. if v.Id == strconv.Itoa(int(extras.GoodsId)) {
  724. //发送对应奖励
  725. var bfInfo *WebBriefInfo
  726. service.GetMysql().Operate(func(rawClient interface{}) interface{} {
  727. wrapper := mysql.NewWrapper(rawClient.(*sql.DB))
  728. wrapper.Query("select uid,nick_name,base_level,create_date,last_login_date,ban_date,map_level,fight_power,active_code,open_id,serverid from role where open_id=?", username).Each(func(wrapper2 *mysql.Wrapper) bool {
  729. bfInfo = parseUserInfo(wrapper2)
  730. return true
  731. })
  732. if wrapper.Err != nil {
  733. util.ErrorF("uid=%v WebGmProcessUserGet err=%v", username, wrapper.Err)
  734. }
  735. return nil
  736. })
  737. if bfInfo == nil {
  738. util.ErrorF("uid=%v not found err=%v", username)
  739. c.JSON(http.StatusOK, gin.H{"status": 1, "msg": "not found user"})
  740. return
  741. }
  742. uidStr := bfInfo.Uid
  743. titleStr := "system award"
  744. contentStr := v.Desc
  745. rewardStr := v.Reward
  746. // list表示获取邮件列表
  747. // attach添加替换邮件
  748. // del删除延迟发送邮件
  749. //mailType := c.DefaultQuery("type", "")
  750. //uid
  751. var uidList []uint64
  752. uidList = append(uidList, uidStr)
  753. //reward
  754. var rewardList []*serverproto.KeyValueType
  755. rewardStrList := strings.Split(rewardStr, ",")
  756. for idx := 0; idx < len(rewardStrList); idx++ {
  757. key, val := model.Str2Res(rewardStrList[idx])
  758. if key > 0 && val > 0 {
  759. rewardList = append(rewardList, &serverproto.KeyValueType{Key: key, Value: val})
  760. }
  761. }
  762. util.ErrorF("东南亚网页支付:orderId:%v,payAmount:%v,sign:%v,extra:%v,username:%v,server:%v,sandbox:%v,timestamp:%v,award:%v", orderId, payAmount, sign, extra, username, server, sandbox, timestamp, rewardStr)
  763. gmweb.GetMailUpdateMag().AttachMail2Update(1, uidList, titleStr, contentStr, util.GetTimeMilliseconds(), rewardList)
  764. c.JSON(http.StatusOK, gin.H{"status": 0})
  765. }
  766. }
  767. }
  768. }
  769. func WebPayHwDnOpenServerNotify(c *gin.Context) {
  770. //util.DebugF("支付回调信息:%v", c.Request.PostForm)
  771. sidStr := c.DefaultQuery("sid", "")
  772. nameStr := c.DefaultQuery("name", "")
  773. timeStr := c.DefaultQuery("time", "") //2019-01-01 12:00:00
  774. gameIdStr := c.DefaultQuery("gameid", "") //2019-01-01 12:00:00
  775. signKeyStr := c.DefaultQuery("signkey", "") //2019-01-01 12:00:00
  776. if nameStr == "" || sidStr == "" || timeStr == "" || gameIdStr == "" {
  777. c.JSON(http.StatusOK, "param error:"+nameStr+sidStr+timeStr)
  778. return
  779. }
  780. reqUrl := "https://i.dze-game.com/game/center/sync_server"
  781. now := strconv.FormatInt(time.Now().Unix(), 10)
  782. // 准备表单数据
  783. formData := url.Values{}
  784. formData.Add("GAME_ID", gameIdStr)
  785. formData.Add("SID", sidStr)
  786. formData.Add("_SID", sidStr)
  787. formData.Add("NAME", nameStr)
  788. formData.Add("START_TIME", timeStr)
  789. formData.Add("sign", Md5Dn(gameIdStr, nameStr, sidStr, timeStr, sidStr, now, signKeyStr))
  790. formData.Add("timestamp", now)
  791. resp, err := http.Post(
  792. reqUrl,
  793. "application/x-www-form-urlencoded",
  794. strings.NewReader(formData.Encode()),
  795. )
  796. if err != nil {
  797. util.ErrorF("req error:%v", err)
  798. c.JSON(http.StatusOK, "req error:"+nameStr+sidStr+timeStr)
  799. return
  800. }
  801. defer resp.Body.Close()
  802. body, err := io.ReadAll(resp.Body)
  803. if err != nil {
  804. util.ErrorF("red body error:%v", err)
  805. c.JSON(http.StatusOK, "res error:"+nameStr+sidStr+timeStr)
  806. return
  807. }
  808. util.ErrorF("东南亚开服信息,sid:%v,name:%v,time:%v,response:%v", sidStr, nameStr, timeStr, string(body))
  809. c.JSON(http.StatusOK, gin.H{"status": 0})
  810. }
  811. func Md5Dn(gameId, name, sid, time, _sid, timestamp, signKey string) string {
  812. key := gameId + name + sid + time + _sid + timestamp + signKey
  813. hash := md5.Sum([]byte(key))
  814. return hex.EncodeToString(hash[:])
  815. }
  816. func WebPayHwDnNotify(c *gin.Context) {
  817. //util.DebugF("支付回调信息:%v", c.Request.PostForm)
  818. params := make(map[string]string)
  819. if err := c.Request.ParseForm(); err != nil {
  820. util.InfoF("parseForm falied")
  821. c.String(http.StatusOK, "FAILED")
  822. return
  823. }
  824. util.ErrorF("支付回调信息东南亚:%v", c.Request.PostForm)
  825. for key, value := range c.Request.PostForm {
  826. params[key] = value[0] // 假设每个参数只有一个值
  827. }
  828. cpOrderId := params["order_code"]
  829. payAmount := params["amount"]
  830. //f64, err := strconv.ParseFloat(payAmount, 32)
  831. //if err != nil {
  832. // fmt.Println("Error:", err)
  833. // return
  834. //}
  835. res := webPayNotifyDn(cpOrderId, payAmount, "")
  836. //// 简单粗暴,直接给其他服转发,不需要确认是哪个服
  837. //payPostRouter := service.GetServiceConfig().SDKConfig.PayPostRouter
  838. //util.WarnF("paycallback payPostRouter:%v\n", payPostRouter)
  839. //// 组装转发body
  840. //params["sign"] = sign
  841. //var routerStr strings.Builder
  842. //for key, value := range params {
  843. // routerStr.WriteString(key)
  844. // routerStr.WriteString("=")
  845. // routerStr.WriteString(value)
  846. // routerStr.WriteString("&")
  847. //}
  848. //routerString := routerStr.String()
  849. //util.WarnF("paycallback routerString:%v\n", routerString)
  850. //go sendPosts(payPostRouter, routerString)
  851. if res == "SUCCESS" {
  852. c.JSON(http.StatusOK, gin.H{"processingStatus": "completed"})
  853. } else {
  854. c.JSON(404, gin.H{"code": "ORDER_CODE_NOT_FOUND", "message": "order_code does not exist"})
  855. }
  856. }
  857. func sendPosts(urls []string, routerString string) {
  858. for i := 0; i < len(urls); i++ {
  859. sendPostToOtherServer(urls[i], []byte(routerString))
  860. }
  861. }
  862. // http://110.40.223.119:8002/pay/hwQucikFromS1GmWeb
  863. func WebPayHwQuickNotifyFromS1GmWeb(c *gin.Context) {
  864. params := make(map[string]string)
  865. if err := c.Request.ParseForm(); err != nil {
  866. util.InfoF("parseForm falied")
  867. c.String(http.StatusOK, "FAILED")
  868. return
  869. }
  870. for key, value := range c.Request.PostForm {
  871. params[key] = value[0] // 假设每个参数只有一个值
  872. }
  873. sign := params["sign"]
  874. newSign := getMd5Sign("03422134397322604272901806704074", params)
  875. util.ErrorF("sign:%v", sign)
  876. util.ErrorF("newSign:%v", newSign)
  877. util.ErrorF("params:%v", params)
  878. if newSign != sign {
  879. util.ErrorF("签名错误%v", sign)
  880. c.String(http.StatusOK, "FAILED")
  881. return
  882. }
  883. uid := c.PostForm("uid")
  884. cpOrderId := c.PostForm("cpOrderNo")
  885. orderNo := c.PostForm("orderNo")
  886. payAmount := c.PostForm("payAmount")
  887. payCurrency := c.PostForm("payCurrency")
  888. payType := c.PostForm("payType")
  889. usdAmount := c.PostForm("usdAmount")
  890. ntfData := &WebNotifyData{}
  891. ntfData.CpOrderId = cpOrderId
  892. ntfData.SdkOrderId = orderNo
  893. ntfData.PayMethod = payType
  894. ntfData.PayCurrency = payCurrency
  895. ntfData.PayTime = uint64(util.GetTimeSeconds())
  896. ntfData.PayChannel = "qk_hw"
  897. util.DebugF("uid=%v cpOrderNo=%v orderNo=%v payAmount=%v payCurrency=%v payType=%v usdAmount=%v",
  898. uid, cpOrderId, orderNo, payAmount, payCurrency, payType, usdAmount)
  899. f64, err := strconv.ParseFloat(usdAmount, 32)
  900. if err != nil {
  901. fmt.Println("Error:", err)
  902. return
  903. }
  904. webPayNotify(ntfData, float32(f64), c)
  905. c.JSON(http.StatusOK, "SUCCESS")
  906. }
  907. // sendPostToOtherServer 发送给其他服务器
  908. func sendPostToOtherServer(url string, body []byte) {
  909. // 创建请求
  910. req, err := http.NewRequest("POST", url, bytes.NewReader(body))
  911. if err != nil {
  912. util.ErrorF("r1 NewRequest:%v \n", err.Error())
  913. }
  914. // 设置Header
  915. req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
  916. req.Header.Set("Custom-Header", "custom-value")
  917. // 发送请求
  918. client := &http.Client{}
  919. resp, err := client.Do(req)
  920. if err != nil {
  921. util.ErrorF("r1 client.Do(req):%v \n", err.Error())
  922. return
  923. }
  924. defer resp.Body.Close()
  925. }
  926. type KVSt struct {
  927. ParamKey string
  928. ParamVal string
  929. }
  930. func WebPayNBSDKNotify(c *gin.Context) {
  931. tmpReq := c.Request
  932. err := tmpReq.ParseMultipartForm(32 << 20)
  933. if err != nil {
  934. return
  935. }
  936. formCache := tmpReq.PostForm
  937. //util.DebugF("formCache2=%v", formCache)
  938. var kvList []*KVSt
  939. for k, v := range formCache {
  940. if k == "sign" {
  941. continue
  942. }
  943. kv := &KVSt{
  944. ParamKey: k,
  945. ParamVal: v[0],
  946. }
  947. kvList = append(kvList, kv)
  948. }
  949. sort.Slice(kvList, func(i, j int) bool {
  950. return kvList[i].ParamKey < kvList[j].ParamKey
  951. })
  952. //util.DebugF("kvlist=%v", kvList)
  953. verifyStr := ""
  954. for idx := 0; idx < len(kvList); idx++ {
  955. key := url.QueryEscape(kvList[idx].ParamKey)
  956. val := url.QueryEscape(kvList[idx].ParamVal)
  957. if idx == 0 {
  958. verifyStr += key + "=" + val
  959. } else {
  960. verifyStr += "&" + key + "=" + val
  961. }
  962. }
  963. sign := c.PostForm("sign")
  964. sdkOrderId := c.PostForm("sdk_order_id") //SDK订单ID
  965. cpOrderId := c.PostForm("cp_order_id") //游戏方订单ID,由游戏客户端生成(服务器生成给到客户端)
  966. serverId := c.PostForm("server_id") //游戏区服ID
  967. pfUid := c.PostForm("pf_uid") //渠道平台的UID
  968. roleId := c.PostForm("role_id") //游戏方自己的角色ID
  969. payAmount := c.PostForm("pay_amount") //支付金额(int,单位分,CP方需要验证是否与计费点金额一致,不做此判断,后果自负哦!!!)
  970. gameKey := service.GetServiceConfig().SDKConfig.NbGameKey
  971. tmpHmac := hmac.New(md5.New, []byte(gameKey))
  972. tmpHmac.Write([]byte(verifyStr))
  973. tmpSign := hex.EncodeToString(tmpHmac.Sum([]byte("")))
  974. util.DebugF("uid=%v verifyStr=%v cpOrderId=%v pfUid=%v sdkOrderId=%v serverId=%v tmpSign=%v sign=%v gamekey=%v", roleId, verifyStr, cpOrderId, pfUid,
  975. sdkOrderId, serverId, tmpSign, sign, gameKey)
  976. if tmpSign != sign {
  977. util.InfoF("uid=%v WebPayNBSDKNotify sign verify failed cpOrderId=%v", roleId, cpOrderId)
  978. return
  979. }
  980. checkPayAmount, _ := model.Str2Num(payAmount)
  981. ntfData := &WebNotifyData{}
  982. ntfData.CpOrderId = cpOrderId
  983. ntfData.SdkOrderId = sdkOrderId
  984. ntfData.PayMethod = ""
  985. ntfData.PayCurrency = ""
  986. ntfData.PayTime = uint64(util.GetTimeSeconds())
  987. ntfData.PayChannel = ""
  988. ret := webPayNotify(ntfData, float32(checkPayAmount)/100, c)
  989. //c.JSON(http.StatusOK, `success`)
  990. c.Data(http.StatusOK, "text/plain; charset=utf-8", []byte(ret))
  991. }
  992. type UniSDKPayExtraST struct {
  993. Aid int `json:"aid"` //用户唯一标识
  994. PrivateParam string `json:"privateparam"`
  995. PayChannel string `json:"paychannel"` //支付渠道
  996. AppChannel string `json:"appchannel"` //appchannel
  997. Platform string `json:"platfrom"`
  998. UidId string `json:"uidid"` //设备id
  999. GoodsCount int `json:"goodscount"` //商品数量
  1000. PayMoney string `json:"paymoney"` //玩家实际支付金额
  1001. FreeMoney string `json:"freemoney"` //免费总价,供游戏服写运营日志(如果渠道不提供,该字段为0)
  1002. PayCurrency string `json:"paycurrency"` //玩家实际支付币种
  1003. Deduct int `json:"deduct"`
  1004. DeductPercent string `json:"deductpercent"`
  1005. DeductReason string `json:"deductreason"` //扣除原因,是黑设备还是黑币种
  1006. JsonData string `json:"jsondata"`
  1007. InitTime int `json:"inittime"` //订单创建时间戳,精确到秒;若订单不通过create_order接口创建(例如web 支付),则此值为0
  1008. PayTime int `json:"paytime"` //订单支付时间戳,精确到秒
  1009. IsTest int `json:"istest"` //订单来源:0,正式环境订单;1,测试环境订单(v3.6.2新增)
  1010. FreeYuanBao int `json:"free_yuanbao"`
  1011. PayYuanBao int `json:"pay_yuanbao"`
  1012. PayMethod string `json:"paymethod"`
  1013. }
  1014. type UniSDKPayST struct {
  1015. GameId string `json:"gameid"`
  1016. HostId int `json:"hostid"`
  1017. RoleId string `json:"roleid"`
  1018. GoodsId string `json:"goodsid"`
  1019. UserName string `json:"username"` //玩家渠道帐号(玩家帐号被sdk渠道转换之后的字符串)
  1020. SN string `json:"sn"` //游戏订单号
  1021. ConsumeSN string `json:"consumesn"` //渠道流水订单号(苹果渠道对应为transaction-id)
  1022. ExtraData UniSDKPayExtraST
  1023. }
  1024. type UniSDKPayResponseST struct {
  1025. Code int `json:"code"`
  1026. Msg string `json:"msg"`
  1027. Data interface{} `json:"data"`
  1028. }
  1029. func WebPayUniSDKNotify(c *gin.Context) {
  1030. sign := c.GetHeader("Gas-Ship-Signature")
  1031. payInfo := &UniSDKPayST{}
  1032. bodyData, err := c.GetRawData()
  1033. if err != nil {
  1034. util.ErrorF("WebPayUniSDKNotify body get error=%v", err)
  1035. return
  1036. }
  1037. err = json.Unmarshal(bodyData, payInfo)
  1038. if err != nil {
  1039. util.ErrorF("WebPayUniSDKNotify body Unmarshal error=%v", err)
  1040. return
  1041. }
  1042. secretKey := service.GetServiceConfig().SDKConfig.UniSecretKey
  1043. tmpHmac := hmac.New(md5.New, []byte(secretKey))
  1044. tmpHmac.Write(bodyData)
  1045. tmpSign := hex.EncodeToString(tmpHmac.Sum([]byte("")))
  1046. if tmpSign != sign {
  1047. util.InfoF("uid=%v WebPayUniSDKNotify sign verify failed cpOrderId=%v", payInfo.RoleId, payInfo.SN)
  1048. c.Header("Gas-Ship-Signature", tmpSign)
  1049. responseSt := &UniSDKPayResponseST{
  1050. Code: 403,
  1051. Msg: "ok",
  1052. Data: nil,
  1053. }
  1054. c.JSON(http.StatusOK, responseSt)
  1055. return
  1056. }
  1057. checkPayAmount, _ := model.Str2Num(payInfo.ExtraData.PayMoney)
  1058. ntfData := &WebNotifyData{}
  1059. ntfData.CpOrderId = payInfo.SN
  1060. ntfData.SdkOrderId = payInfo.ConsumeSN
  1061. ntfData.PayMethod = payInfo.ExtraData.PayMethod
  1062. ntfData.PayCurrency = payInfo.ExtraData.PayCurrency
  1063. ntfData.PayTime = uint64(payInfo.ExtraData.PayTime)
  1064. ntfData.PayChannel = payInfo.ExtraData.PayChannel
  1065. ret := webPayNotify(ntfData, float32(checkPayAmount)/100, c)
  1066. if ret == "FAILED" {
  1067. c.JSON(http.StatusOK, "FAILED")
  1068. }
  1069. c.Header("Gas-Ship-Signature", tmpSign)
  1070. responseSt := &UniSDKPayResponseST{
  1071. Code: 200,
  1072. Msg: "ok",
  1073. Data: nil,
  1074. }
  1075. c.JSON(http.StatusOK, responseSt)
  1076. }
  1077. func WebPayNBH5Notify(c *gin.Context) {
  1078. sdkOrderId := c.PostForm("sdk_order_id") //SDK订单ID
  1079. cpOrderId := c.PostForm("cp_order_id") //游戏方订单ID,由游戏客户端生成(服务器生成给到客户端)
  1080. serverId := c.PostForm("server_id") //游戏区服ID
  1081. pfUid := c.PostForm("pf_uid") //渠道平台的UID
  1082. roleId := c.PostForm("role_id") //游戏方自己的角色ID(uid)
  1083. payAmount := c.PostForm("pay_amount") //支付金额(int,单位分,CP方需要验证是否与计费点金额一致,不做此判断,后果自负哦!!!)
  1084. goodsType := c.PostForm("goods_type")
  1085. goodsID := c.PostForm("goods_id")
  1086. util.InfoF("WebPayH5Notify roleId=%v pfUid=%v sdkOrderId=%v serverId=%v", roleId, pfUid, sdkOrderId, serverId)
  1087. if cpOrderId == "" {
  1088. cpOrderId = "WebPayH5Notify"
  1089. }
  1090. gameRoleId, _ := model.Str2NumU64(roleId)
  1091. checkPayAmount, _ := model.Str2Num(payAmount)
  1092. if gameRoleId <= 0 || checkPayAmount <= 0 {
  1093. c.Data(http.StatusOK, "text/plain; charset=utf-8", []byte("FAILED"))
  1094. return
  1095. }
  1096. ntfData := &WebNotifyData{}
  1097. ntfData.GameRoleId = gameRoleId
  1098. ntfData.CpOrderId = cpOrderId
  1099. ntfData.SdkOrderId = sdkOrderId
  1100. ntfData.PayMethod = ""
  1101. ntfData.PayCurrency = ""
  1102. ntfData.PayTime = uint64(util.GetTimeSeconds())
  1103. ntfData.PayChannel = "WebPayH5Notify"
  1104. ntfData.GoodsType, _ = model.Str2NumU64(goodsType)
  1105. ntfData.GoodsID, _ = model.Str2NumU64(goodsID)
  1106. ret := webPayNotifyH5(ntfData, float32(checkPayAmount)/100, c)
  1107. c.Data(http.StatusOK, "text/plain; charset=utf-8", []byte(ret))
  1108. }
  1109. type WebNotifyData struct {
  1110. CpOrderId string
  1111. SdkOrderId string
  1112. PayMethod string
  1113. PayCurrency string
  1114. PayTime uint64
  1115. PayChannel string
  1116. GameRoleId uint64
  1117. GoodsType uint64
  1118. GoodsID uint64
  1119. }
  1120. func webPayNotify(webNtf *WebNotifyData, payAmount float32, c *gin.Context) string {
  1121. //流程处理gmweb保存订单状态到redis中设置为 成功充值状态
  1122. //发送给gameserver,成功收到后设置订单状态为成功获取充值状态,如果gameserver没有收到
  1123. //每次玩家上线时,重新获取一次订单状态如果是成功充值,但是没有获取成功就获取一次
  1124. // 充值成功获取对应的ntdata数据
  1125. // 1,回复成/失败消息给quick
  1126. // 2,订单状态写入redis(判重处理),并发送给social做获取奖励处理
  1127. msgStr, err := service.GetRedis().HGet(model.PayOrderPrefix, webNtf.CpOrderId).Result()
  1128. if err != nil {
  1129. //util.ErrorF("WebPayQuickNotify order not exist err=%v", err)
  1130. util.ErrorF("WebPayQuickNotify order not exist err=%v, cpOrderId=%v, sdkOrderId=%v", err, webNtf.CpOrderId, webNtf.SdkOrderId)
  1131. //c.JSON(http.StatusOK, "FAILED")
  1132. //return "FAILED"
  1133. return fmt.Sprintf("FAILED,cpOrderId=%v err=%v", webNtf.CpOrderId, err)
  1134. }
  1135. payInfo := &serverproto.PayOrderSaveInfo{}
  1136. err = model.GetDecodeMessage(payInfo, msgStr)
  1137. if err != nil {
  1138. util.ErrorF("WebPayQuickNotify GetDecodeMessage err=%, cpOrderId=%v, sdkOrderId=%v", err, webNtf.CpOrderId, webNtf.SdkOrderId)
  1139. //util.ErrorF("WebPayQuickNotify GetDecodeMessage err=%v", err)
  1140. //c.JSON(http.StatusOK, "FAILED")
  1141. //return "FAILED"
  1142. return fmt.Sprintf("FAILED,cpOrderId=%v err=%v", webNtf.CpOrderId, err)
  1143. }
  1144. if payInfo.OrderState == int32(serverproto.PayOrderState_EPayOrderState_Gen) {
  1145. //实际支付 == 订单的钱,否则为支付失败
  1146. payAmount := int32(payAmount * 10) //该渠道是以分为单位(游戏以卢布为单位)
  1147. //服务器订单实际金额:
  1148. orderAmount := int32(payInfo.Amount * 1000)
  1149. if payAmount == orderAmount {
  1150. payInfo.OrderState = int32(serverproto.PayOrderState_EPayOrderState_PayOk)
  1151. } else {
  1152. payInfo.OrderState = int32(serverproto.PayOrderState_EPayOrderState_PayFailed)
  1153. util.ErrorF("uid=%v WebPayQuickNotify failed payAmount:%v order=%v", payInfo.Uid, payAmount, payInfo)
  1154. }
  1155. payInfo.OrderProcessTime = util.GetTimeMilliseconds()
  1156. payInfo.SdkOrderId = webNtf.SdkOrderId //sdk订单id\
  1157. payInfo.PayMethod = webNtf.PayMethod
  1158. payInfo.PayCurrency = webNtf.PayCurrency
  1159. payInfo.PayTime = webNtf.PayTime
  1160. payInfo.PayChannel = webNtf.PayChannel
  1161. //订单状态修改,写入数据库(后续玩家发货成功后会再次修改订单状态为PayOrderState_EPayOrderState_PayOkReward)
  1162. err, newPayInfoStr := model.GetEncodeMessage(payInfo)
  1163. if err == nil {
  1164. service.GetRedis().HSet(model.PayOrderPrefix, webNtf.CpOrderId, newPayInfoStr)
  1165. }
  1166. //完成订单id列表(避免上次发货不成功,玩家下次登陆时可以重新获取一次奖励)
  1167. uidStr := strconv.FormatUint(payInfo.Uid, 10)
  1168. okListKeyStr := model.PayOrderOKIdListPrefix + uidStr
  1169. service.GetRedis().SAdd(okListKeyStr, payInfo.CpOrderId)
  1170. if payInfo.OrderState == int32(serverproto.PayOrderState_EPayOrderState_PayOk) {
  1171. ssNtfMsg := &serverproto.SSPayInfoOrderNtf{
  1172. PayOrderInfo: payInfo,
  1173. }
  1174. selfmodel.SendSocial(ssNtfMsg)
  1175. }
  1176. util.InfoF("uid=%v WebPayQuickNotify ok order=%v", payInfo.Uid, payInfo)
  1177. } else {
  1178. util.ErrorF("WebPayQuickNotify uid=%v state error state=%v", payInfo.Uid, payInfo.OrderState)
  1179. //return "FAILED"
  1180. return fmt.Sprintf("FAILED,cpOrderId=%v state error=%v", webNtf.CpOrderId, payInfo.OrderState)
  1181. }
  1182. return "SUCCESS"
  1183. }
  1184. func webPayNotifyDn(cpOrderId string, Amount, sdkOrderId string) string {
  1185. //流程处理gmweb保存订单状态到redis中设置为 成功充值状态
  1186. //发送给gameserver,成功收到后设置订单状态为成功获取充值状态,如果gameserver没有收到
  1187. //每次玩家上线时,重新获取一次订单状态如果是成功充值,但是没有获取成功就获取一次
  1188. // 充值成功获取对应的ntdata数据
  1189. // 1,回复成/失败消息给quick
  1190. // 2,订单状态写入redis(判重处理),并发送给social做获取奖励处理
  1191. msgStr, err := service.GetRedis().HGet(model.PayOrderPrefix, cpOrderId).Result()
  1192. if err != nil {
  1193. //util.ErrorF("WebPayQuickNotify order not exist err=%v", err)
  1194. util.ErrorF("WebPayQuickNotify order not exist err=%v, cpOrderId=%v, sdkOrderId=%v", err, cpOrderId, 0)
  1195. //c.JSON(http.StatusOK, "FAILED")
  1196. //return "FAILED"
  1197. return fmt.Sprintf("FAILED,cpOrderId=%v err=%v", cpOrderId, err)
  1198. }
  1199. payInfo := &serverproto.PayOrderSaveInfo{}
  1200. err = model.GetDecodeMessage(payInfo, msgStr)
  1201. if err != nil {
  1202. util.ErrorF("WebPayQuickNotify GetDecodeMessage err=%, cpOrderId=%v, sdkOrderId=%v", err, cpOrderId, 0)
  1203. //util.ErrorF("WebPayQuickNotify GetDecodeMessage err=%v", err)
  1204. //c.JSON(http.StatusOK, "FAILED")
  1205. //return "FAILED"
  1206. return fmt.Sprintf("FAILED,cpOrderId=%v err=%v", cpOrderId, err)
  1207. }
  1208. if payInfo.OrderState == int32(serverproto.PayOrderState_EPayOrderState_Gen) {
  1209. //实际支付 == 订单的钱,否则为支付失败
  1210. //payAmount := int32(Amount * 1000)
  1211. ////服务器订单实际金额:
  1212. orderAmount := fmt.Sprintf("%.2f", payInfo.Amount)
  1213. if Amount == orderAmount {
  1214. payInfo.OrderState = int32(serverproto.PayOrderState_EPayOrderState_PayOk)
  1215. } else {
  1216. payInfo.OrderState = int32(serverproto.PayOrderState_EPayOrderState_PayFailed)
  1217. util.ErrorF("uid=%v WebPayQuickNotify failed payAmount:%v order=%v ,price=%v", payInfo.Uid, Amount, payInfo, orderAmount)
  1218. return ""
  1219. }
  1220. //payInfo.OrderState = int32(serverproto.PayOrderState_EPayOrderState_PayOk)
  1221. payInfo.OrderProcessTime = util.GetTimeMilliseconds()
  1222. payInfo.SdkOrderId = sdkOrderId //sdk订单id\
  1223. //payInfo.PayMethod = webNtf.PayMethod
  1224. //payInfo.PayCurrency = webNtf.PayCurrency
  1225. payInfo.PayTime = util.GetTimeMilliseconds()
  1226. payInfo.PayChannel = "dn"
  1227. //订单状态修改,写入数据库(后续玩家发货成功后会再次修改订单状态为PayOrderState_EPayOrderState_PayOkReward)
  1228. err, newPayInfoStr := model.GetEncodeMessage(payInfo)
  1229. if err == nil {
  1230. service.GetRedis().HSet(model.PayOrderPrefix, cpOrderId, newPayInfoStr)
  1231. }
  1232. //完成订单id列表(避免上次发货不成功,玩家下次登陆时可以重新获取一次奖励)
  1233. uidStr := strconv.FormatUint(payInfo.Uid, 10)
  1234. okListKeyStr := model.PayOrderOKIdListPrefix + uidStr
  1235. service.GetRedis().SAdd(okListKeyStr, payInfo.CpOrderId)
  1236. if payInfo.OrderState == int32(serverproto.PayOrderState_EPayOrderState_PayOk) {
  1237. ssNtfMsg := &serverproto.SSPayInfoOrderNtf{
  1238. PayOrderInfo: payInfo,
  1239. }
  1240. selfmodel.SendSocial(ssNtfMsg)
  1241. }
  1242. util.InfoF("uid=%v WebPayQuickNotify ok order=%v", payInfo.Uid, payInfo)
  1243. } else {
  1244. util.ErrorF("WebPayQuickNotify uid=%v state error state=%v", payInfo.Uid, payInfo.OrderState)
  1245. //return "FAILED"
  1246. return fmt.Sprintf("FAILED,cpOrderId=%v state error=%v", cpOrderId, payInfo.OrderState)
  1247. }
  1248. return "SUCCESS"
  1249. }
  1250. // 外层发起主动充值(不走游戏流程)
  1251. func webPayNotifyH5(webNtf *WebNotifyData, payAmount float32, c *gin.Context) string {
  1252. payInfo := &serverproto.PayOrderSaveInfo{}
  1253. payInfo.Uid = webNtf.GameRoleId
  1254. payInfo.Amount = payAmount
  1255. payInfo.OrderProcessTime = util.GetTimeMilliseconds()
  1256. payInfo.SdkOrderId = webNtf.SdkOrderId //sdk订单id\
  1257. payInfo.PayMethod = webNtf.PayMethod
  1258. payInfo.PayCurrency = webNtf.PayCurrency
  1259. payInfo.PayTime = webNtf.PayTime
  1260. payInfo.PayChannel = webNtf.PayChannel
  1261. payInfo.GoodsType = int32(webNtf.GoodsType)
  1262. payInfo.GoodsId = int32(webNtf.GoodsID)
  1263. rewardStr := c.DefaultQuery("reward", "")
  1264. //reward
  1265. rewardStrList := strings.Split(rewardStr, ",")
  1266. for idx := 0; idx < len(rewardStrList); idx++ {
  1267. key, val := model.Str2Res(rewardStrList[idx])
  1268. if key > 0 && val > 0 {
  1269. payInfo.RewardList = append(payInfo.RewardList, &serverproto.KeyValueType{Key: key, Value: val})
  1270. }
  1271. }
  1272. payInfo.OrderState = int32(serverproto.PayOrderState_EPayOrderState_PayOk)
  1273. //订单状态修改,写入数据库(后续玩家发货成功后会再次修改订单状态为PayOrderState_EPayOrderState_PayOkReward)
  1274. err, newPayInfoStr := model.GetEncodeMessage(payInfo)
  1275. if err == nil {
  1276. service.GetRedis().HSet(model.PayOrderPrefix, webNtf.CpOrderId, newPayInfoStr)
  1277. }
  1278. //完成订单id列表(避免上次发货不成功,玩家下次登陆时可以重新获取一次奖励)
  1279. uidStr := strconv.FormatUint(payInfo.Uid, 10)
  1280. okListKeyStr := model.PayOrderOKIdListPrefix + uidStr
  1281. service.GetRedis().SAdd(okListKeyStr, payInfo.CpOrderId)
  1282. util.InfoF("webPayNotifyH5: %v", payInfo)
  1283. ssNtfMsg := &serverproto.SSPayInfoOrderNtf{
  1284. PayOrderInfo: payInfo,
  1285. }
  1286. selfmodel.SendSocial(ssNtfMsg)
  1287. return "SUCCESS"
  1288. }