server.go 7.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297
  1. package server
  2. import (
  3. "encoding/json"
  4. "encoding/xml"
  5. "errors"
  6. "fmt"
  7. "io/ioutil"
  8. "net/http"
  9. "reflect"
  10. "runtime/debug"
  11. "strconv"
  12. "strings"
  13. log "github.com/sirupsen/logrus"
  14. "github.com/silenceper/wechat/v2/officialaccount/context"
  15. "github.com/silenceper/wechat/v2/officialaccount/message"
  16. "github.com/silenceper/wechat/v2/util"
  17. "github.com/tidwall/gjson"
  18. )
  19. // Server struct
  20. type Server struct {
  21. *context.Context
  22. Writer http.ResponseWriter
  23. Request *http.Request
  24. skipValidate bool
  25. openID string
  26. messageHandler func(*message.MixMessage) *message.Reply
  27. RequestRawXMLMsg []byte
  28. RequestMsg *message.MixMessage
  29. ResponseRawXMLMsg []byte
  30. ResponseMsg interface{}
  31. isSafeMode bool
  32. isJSONContent bool
  33. random []byte
  34. nonce string
  35. timestamp int64
  36. }
  37. // NewServer init
  38. func NewServer(context *context.Context) *Server {
  39. srv := new(Server)
  40. srv.Context = context
  41. return srv
  42. }
  43. // SkipValidate set skip validate
  44. func (srv *Server) SkipValidate(skip bool) {
  45. srv.skipValidate = skip
  46. }
  47. // Serve 处理微信的请求消息
  48. func (srv *Server) Serve() error {
  49. if !srv.Validate() {
  50. log.Error("Validate Signature Failed.")
  51. return fmt.Errorf("请求校验失败")
  52. }
  53. echostr, exists := srv.GetQuery("echostr")
  54. if exists {
  55. srv.String(echostr)
  56. return nil
  57. }
  58. response, err := srv.handleRequest()
  59. if err != nil {
  60. return err
  61. }
  62. // debug print request msg
  63. log.Debugf("request msg =%s", string(srv.RequestRawXMLMsg))
  64. return srv.buildResponse(response)
  65. }
  66. // Validate 校验请求是否合法
  67. func (srv *Server) Validate() bool {
  68. if srv.skipValidate {
  69. return true
  70. }
  71. timestamp := srv.Query("timestamp")
  72. nonce := srv.Query("nonce")
  73. signature := srv.Query("signature")
  74. log.Debugf("validate signature, timestamp=%s, nonce=%s", timestamp, nonce)
  75. return signature == util.Signature(srv.Token, timestamp, nonce)
  76. }
  77. // HandleRequest 处理微信的请求
  78. func (srv *Server) handleRequest() (reply *message.Reply, err error) {
  79. // set isSafeMode
  80. srv.isSafeMode = false
  81. encryptType := srv.Query("encrypt_type")
  82. if encryptType == "aes" {
  83. srv.isSafeMode = true
  84. }
  85. //set request contentType
  86. contentType := srv.Request.Header.Get("Content-Type")
  87. srv.isJSONContent = strings.Contains(contentType, "application/json")
  88. // set openID
  89. srv.openID = srv.Query("openid")
  90. var msg interface{}
  91. msg, err = srv.getMessage()
  92. if err != nil {
  93. return
  94. }
  95. mixMessage, success := msg.(*message.MixMessage)
  96. if !success {
  97. err = errors.New("消息类型转换失败")
  98. }
  99. srv.RequestMsg = mixMessage
  100. reply = srv.messageHandler(mixMessage)
  101. return
  102. }
  103. // GetOpenID return openID
  104. func (srv *Server) GetOpenID() string {
  105. return srv.openID
  106. }
  107. // getMessage 解析微信返回的消息
  108. func (srv *Server) getMessage() (interface{}, error) {
  109. var rawXMLMsgBytes []byte
  110. var err error
  111. if srv.isSafeMode {
  112. encryptedXMLMsg, dataErr := srv.getEncryptBody()
  113. if dataErr != nil {
  114. return nil, dataErr
  115. }
  116. // 验证消息签名
  117. timestamp := srv.Query("timestamp")
  118. srv.timestamp, err = strconv.ParseInt(timestamp, 10, 32)
  119. if err != nil {
  120. return nil, err
  121. }
  122. nonce := srv.Query("nonce")
  123. srv.nonce = nonce
  124. msgSignature := srv.Query("msg_signature")
  125. msgSignatureGen := util.Signature(srv.Token, timestamp, nonce, encryptedXMLMsg.EncryptedMsg)
  126. if msgSignature != msgSignatureGen {
  127. return nil, fmt.Errorf("消息不合法,验证签名失败")
  128. }
  129. // 解密
  130. srv.random, rawXMLMsgBytes, err = util.DecryptMsg(srv.AppID, encryptedXMLMsg.EncryptedMsg, srv.EncodingAESKey)
  131. if err != nil {
  132. return nil, fmt.Errorf("消息解密失败, err=%v", err)
  133. }
  134. } else {
  135. rawXMLMsgBytes, err = ioutil.ReadAll(srv.Request.Body)
  136. if err != nil {
  137. return nil, fmt.Errorf("从body中解析xml失败, err=%v", err)
  138. }
  139. }
  140. srv.RequestRawXMLMsg = rawXMLMsgBytes
  141. return srv.parseRequestMessage(rawXMLMsgBytes)
  142. }
  143. func (srv *Server) getEncryptBody() (*message.EncryptedXMLMsg, error) {
  144. var encryptedXMLMsg = &message.EncryptedXMLMsg{}
  145. if srv.isJSONContent {
  146. if err := json.NewDecoder(srv.Request.Body).Decode(encryptedXMLMsg); err != nil {
  147. return nil, fmt.Errorf("从body中解析json失败,err=%v", err)
  148. }
  149. } else {
  150. if err := xml.NewDecoder(srv.Request.Body).Decode(encryptedXMLMsg); err != nil {
  151. return nil, fmt.Errorf("从body中解析xml失败,err=%v", err)
  152. }
  153. }
  154. return encryptedXMLMsg, nil
  155. }
  156. func (srv *Server) parseRequestMessage(rawXMLMsgBytes []byte) (msg *message.MixMessage, err error) {
  157. msg = &message.MixMessage{}
  158. if !srv.isJSONContent {
  159. err = xml.Unmarshal(rawXMLMsgBytes, msg)
  160. return
  161. }
  162. //parse json
  163. err = json.Unmarshal(rawXMLMsgBytes, msg)
  164. if err != nil {
  165. return
  166. }
  167. // nonstandard json, 目前小程序订阅消息返回数据格式不标准,订阅消息模板单个List返回是对象,多个List返回是数组。
  168. if msg.MsgType == message.MsgTypeEvent {
  169. listData := gjson.Get(string(rawXMLMsgBytes), "List")
  170. if listData.IsObject() {
  171. listItem := message.SubscribeMsgPopupEvent{}
  172. if parseErr := json.Unmarshal([]byte(listData.Raw), &listItem); parseErr != nil {
  173. return msg, parseErr
  174. }
  175. msg.SetSubscribeMsgPopupEvents([]message.SubscribeMsgPopupEvent{listItem})
  176. } else if listData.IsArray() {
  177. listItems := make([]message.SubscribeMsgPopupEvent, 0)
  178. if parseErr := json.Unmarshal([]byte(listData.Raw), &listItems); parseErr != nil {
  179. return msg, parseErr
  180. }
  181. msg.SetSubscribeMsgPopupEvents(listItems)
  182. }
  183. }
  184. return
  185. }
  186. // SetMessageHandler 设置用户自定义的回调方法
  187. func (srv *Server) SetMessageHandler(handler func(*message.MixMessage) *message.Reply) {
  188. srv.messageHandler = handler
  189. }
  190. func (srv *Server) buildResponse(reply *message.Reply) (err error) {
  191. defer func() {
  192. if e := recover(); e != nil {
  193. err = fmt.Errorf("panic error: %v\n%s", e, debug.Stack())
  194. }
  195. }()
  196. if reply == nil {
  197. // do nothing
  198. return nil
  199. }
  200. msgType := reply.MsgType
  201. switch msgType {
  202. case message.MsgTypeText:
  203. case message.MsgTypeImage:
  204. case message.MsgTypeVoice:
  205. case message.MsgTypeVideo:
  206. case message.MsgTypeMusic:
  207. case message.MsgTypeNews:
  208. case message.MsgTypeTransfer:
  209. default:
  210. err = message.ErrUnsupportReply
  211. return
  212. }
  213. msgData := reply.MsgData
  214. value := reflect.ValueOf(msgData)
  215. // msgData must be a ptr
  216. kind := value.Kind().String()
  217. if kind != "ptr" {
  218. return message.ErrUnsupportReply
  219. }
  220. params := make([]reflect.Value, 1)
  221. params[0] = reflect.ValueOf(srv.RequestMsg.FromUserName)
  222. value.MethodByName("SetToUserName").Call(params)
  223. params[0] = reflect.ValueOf(srv.RequestMsg.ToUserName)
  224. value.MethodByName("SetFromUserName").Call(params)
  225. params[0] = reflect.ValueOf(msgType)
  226. value.MethodByName("SetMsgType").Call(params)
  227. params[0] = reflect.ValueOf(util.GetCurrTS())
  228. value.MethodByName("SetCreateTime").Call(params)
  229. srv.ResponseMsg = msgData
  230. srv.ResponseRawXMLMsg, err = xml.Marshal(msgData)
  231. return
  232. }
  233. // Send 将自定义的消息发送
  234. func (srv *Server) Send() (err error) {
  235. replyMsg := srv.ResponseMsg
  236. log.Debugf("response msg =%+v", replyMsg)
  237. if srv.isSafeMode {
  238. // 安全模式下对消息进行加密
  239. var encryptedMsg []byte
  240. encryptedMsg, err = util.EncryptMsg(srv.random, srv.ResponseRawXMLMsg, srv.AppID, srv.EncodingAESKey)
  241. if err != nil {
  242. return
  243. }
  244. // TODO 如果获取不到timestamp nonce 则自己生成
  245. timestamp := srv.timestamp
  246. timestampStr := strconv.FormatInt(timestamp, 10)
  247. msgSignature := util.Signature(srv.Token, timestampStr, srv.nonce, string(encryptedMsg))
  248. replyMsg = message.ResponseEncryptedXMLMsg{
  249. EncryptedMsg: string(encryptedMsg),
  250. MsgSignature: msgSignature,
  251. Timestamp: timestamp,
  252. Nonce: srv.nonce,
  253. }
  254. }
  255. if replyMsg != nil {
  256. srv.XML(replyMsg)
  257. }
  258. return
  259. }