server.go 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302
  1. package server
  2. import (
  3. "encoding/json"
  4. "encoding/xml"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "net/http"
  9. "reflect"
  10. "runtime/debug"
  11. "strconv"
  12. "strings"
  13. log "github.com/sirupsen/logrus"
  14. "github.com/tidwall/gjson"
  15. "github.com/silenceper/wechat/v2/officialaccount/context"
  16. "github.com/silenceper/wechat/v2/officialaccount/message"
  17. "github.com/silenceper/wechat/v2/util"
  18. )
  19. // Server struct
  20. type Server struct {
  21. *context.Context
  22. Writer http.ResponseWriter
  23. Request *http.Request
  24. skipValidate bool
  25. openID string
  26. messageHandler func(*message.MixMessage) *message.Reply
  27. RequestRawXMLMsg []byte
  28. RequestMsg *message.MixMessage
  29. ResponseRawXMLMsg []byte
  30. ResponseMsg interface{}
  31. isSafeMode bool
  32. isJSONContent bool
  33. random []byte
  34. nonce string
  35. timestamp int64
  36. }
  37. // NewServer init
  38. func NewServer(context *context.Context) *Server {
  39. srv := new(Server)
  40. srv.Context = context
  41. return srv
  42. }
  43. // SkipValidate set skip validate
  44. func (srv *Server) SkipValidate(skip bool) {
  45. srv.skipValidate = skip
  46. }
  47. // Serve 处理微信的请求消息
  48. func (srv *Server) Serve() error {
  49. if !srv.Validate() {
  50. log.Error("Validate Signature Failed.")
  51. return fmt.Errorf("请求校验失败")
  52. }
  53. echostr, exists := srv.GetQuery("echostr")
  54. if exists {
  55. srv.String(echostr)
  56. return nil
  57. }
  58. response, err := srv.handleRequest()
  59. if err != nil {
  60. return err
  61. }
  62. // 非安全模式下,请求处理方法返回为nil则直接回复success给微信服务器
  63. if response == nil && !srv.isSafeMode {
  64. srv.String("success")
  65. return nil
  66. }
  67. // debug print request msg
  68. log.Debugf("request msg =%s", string(srv.RequestRawXMLMsg))
  69. return srv.buildResponse(response)
  70. }
  71. // Validate 校验请求是否合法
  72. func (srv *Server) Validate() bool {
  73. if srv.skipValidate {
  74. return true
  75. }
  76. timestamp := srv.Query("timestamp")
  77. nonce := srv.Query("nonce")
  78. signature := srv.Query("signature")
  79. log.Debugf("validate signature, timestamp=%s, nonce=%s", timestamp, nonce)
  80. return signature == util.Signature(srv.Token, timestamp, nonce)
  81. }
  82. // HandleRequest 处理微信的请求
  83. func (srv *Server) handleRequest() (reply *message.Reply, err error) {
  84. // set isSafeMode
  85. srv.isSafeMode = false
  86. encryptType := srv.Query("encrypt_type")
  87. if encryptType == "aes" {
  88. srv.isSafeMode = true
  89. }
  90. // set request contentType
  91. contentType := srv.Request.Header.Get("Content-Type")
  92. srv.isJSONContent = strings.Contains(contentType, "application/json")
  93. // set openID
  94. srv.openID = srv.Query("openid")
  95. var msg interface{}
  96. msg, err = srv.getMessage()
  97. if err != nil {
  98. return
  99. }
  100. mixMessage, success := msg.(*message.MixMessage)
  101. if !success {
  102. err = errors.New("消息类型转换失败")
  103. }
  104. srv.RequestMsg = mixMessage
  105. reply = srv.messageHandler(mixMessage)
  106. return
  107. }
  108. // GetOpenID return openID
  109. func (srv *Server) GetOpenID() string {
  110. return srv.openID
  111. }
  112. // getMessage 解析微信返回的消息
  113. func (srv *Server) getMessage() (interface{}, error) {
  114. var rawXMLMsgBytes []byte
  115. var err error
  116. if srv.isSafeMode {
  117. encryptedXMLMsg, dataErr := srv.getEncryptBody()
  118. if dataErr != nil {
  119. return nil, dataErr
  120. }
  121. // 验证消息签名
  122. timestamp := srv.Query("timestamp")
  123. srv.timestamp, err = strconv.ParseInt(timestamp, 10, 32)
  124. if err != nil {
  125. return nil, err
  126. }
  127. nonce := srv.Query("nonce")
  128. srv.nonce = nonce
  129. msgSignature := srv.Query("msg_signature")
  130. msgSignatureGen := util.Signature(srv.Token, timestamp, nonce, encryptedXMLMsg.EncryptedMsg)
  131. if msgSignature != msgSignatureGen {
  132. return nil, fmt.Errorf("消息不合法,验证签名失败")
  133. }
  134. // 解密
  135. srv.random, rawXMLMsgBytes, err = util.DecryptMsg(srv.AppID, encryptedXMLMsg.EncryptedMsg, srv.EncodingAESKey)
  136. if err != nil {
  137. return nil, fmt.Errorf("消息解密失败, err=%v", err)
  138. }
  139. } else {
  140. rawXMLMsgBytes, err = io.ReadAll(srv.Request.Body)
  141. if err != nil {
  142. return nil, fmt.Errorf("从body中解析xml失败, err=%v", err)
  143. }
  144. }
  145. srv.RequestRawXMLMsg = rawXMLMsgBytes
  146. return srv.parseRequestMessage(rawXMLMsgBytes)
  147. }
  148. func (srv *Server) getEncryptBody() (*message.EncryptedXMLMsg, error) {
  149. var encryptedXMLMsg = &message.EncryptedXMLMsg{}
  150. if srv.isJSONContent {
  151. if err := json.NewDecoder(srv.Request.Body).Decode(encryptedXMLMsg); err != nil {
  152. return nil, fmt.Errorf("从body中解析json失败,err=%v", err)
  153. }
  154. } else {
  155. if err := xml.NewDecoder(srv.Request.Body).Decode(encryptedXMLMsg); err != nil {
  156. return nil, fmt.Errorf("从body中解析xml失败,err=%v", err)
  157. }
  158. }
  159. return encryptedXMLMsg, nil
  160. }
  161. func (srv *Server) parseRequestMessage(rawXMLMsgBytes []byte) (msg *message.MixMessage, err error) {
  162. msg = &message.MixMessage{}
  163. if !srv.isJSONContent {
  164. err = xml.Unmarshal(rawXMLMsgBytes, msg)
  165. return
  166. }
  167. // parse json
  168. err = json.Unmarshal(rawXMLMsgBytes, msg)
  169. if err != nil {
  170. return
  171. }
  172. // nonstandard json, 目前小程序订阅消息返回数据格式不标准,订阅消息模板单个List返回是对象,多个List返回是数组。
  173. if msg.MsgType == message.MsgTypeEvent {
  174. listData := gjson.Get(string(rawXMLMsgBytes), "List")
  175. if listData.IsObject() {
  176. listItem := message.SubscribeMsgPopupEvent{}
  177. if parseErr := json.Unmarshal([]byte(listData.Raw), &listItem); parseErr != nil {
  178. return msg, parseErr
  179. }
  180. msg.SetSubscribeMsgPopupEvents([]message.SubscribeMsgPopupEvent{listItem})
  181. } else if listData.IsArray() {
  182. listItems := make([]message.SubscribeMsgPopupEvent, 0)
  183. if parseErr := json.Unmarshal([]byte(listData.Raw), &listItems); parseErr != nil {
  184. return msg, parseErr
  185. }
  186. msg.SetSubscribeMsgPopupEvents(listItems)
  187. }
  188. }
  189. return
  190. }
  191. // SetMessageHandler 设置用户自定义的回调方法
  192. func (srv *Server) SetMessageHandler(handler func(*message.MixMessage) *message.Reply) {
  193. srv.messageHandler = handler
  194. }
  195. func (srv *Server) buildResponse(reply *message.Reply) (err error) {
  196. defer func() {
  197. if e := recover(); e != nil {
  198. err = fmt.Errorf("panic error: %v\n%s", e, debug.Stack())
  199. }
  200. }()
  201. if reply == nil {
  202. // do nothing
  203. return nil
  204. }
  205. msgType := reply.MsgType
  206. switch msgType {
  207. case message.MsgTypeText:
  208. case message.MsgTypeImage:
  209. case message.MsgTypeVoice:
  210. case message.MsgTypeVideo:
  211. case message.MsgTypeMusic:
  212. case message.MsgTypeNews:
  213. case message.MsgTypeTransfer:
  214. default:
  215. err = message.ErrUnsupportReply
  216. return
  217. }
  218. msgData := reply.MsgData
  219. value := reflect.ValueOf(msgData)
  220. // msgData must be a ptr
  221. kind := value.Kind().String()
  222. if kind != "ptr" {
  223. return message.ErrUnsupportReply
  224. }
  225. params := make([]reflect.Value, 1)
  226. params[0] = reflect.ValueOf(srv.RequestMsg.FromUserName)
  227. value.MethodByName("SetToUserName").Call(params)
  228. params[0] = reflect.ValueOf(srv.RequestMsg.ToUserName)
  229. value.MethodByName("SetFromUserName").Call(params)
  230. params[0] = reflect.ValueOf(msgType)
  231. value.MethodByName("SetMsgType").Call(params)
  232. params[0] = reflect.ValueOf(util.GetCurrTS())
  233. value.MethodByName("SetCreateTime").Call(params)
  234. srv.ResponseMsg = msgData
  235. srv.ResponseRawXMLMsg, err = xml.Marshal(msgData)
  236. return
  237. }
  238. // Send 将自定义的消息发送
  239. func (srv *Server) Send() (err error) {
  240. replyMsg := srv.ResponseMsg
  241. log.Debugf("response msg =%+v", replyMsg)
  242. if srv.isSafeMode {
  243. // 安全模式下对消息进行加密
  244. var encryptedMsg []byte
  245. encryptedMsg, err = util.EncryptMsg(srv.random, srv.ResponseRawXMLMsg, srv.AppID, srv.EncodingAESKey)
  246. if err != nil {
  247. return
  248. }
  249. // TODO 如果获取不到timestamp nonce 则自己生成
  250. timestamp := srv.timestamp
  251. timestampStr := strconv.FormatInt(timestamp, 10)
  252. msgSignature := util.Signature(srv.Token, timestampStr, srv.nonce, string(encryptedMsg))
  253. replyMsg = message.ResponseEncryptedXMLMsg{
  254. EncryptedMsg: string(encryptedMsg),
  255. MsgSignature: msgSignature,
  256. Timestamp: timestamp,
  257. Nonce: srv.nonce,
  258. }
  259. }
  260. if replyMsg != nil {
  261. srv.XML(replyMsg)
  262. }
  263. return
  264. }