Alipay.php 18.9 KB
Newer Older
D
v1.2.0  
devil_gong 已提交
1 2 3 4
<?php
// +----------------------------------------------------------------------
// | ShopXO 国内领先企业级B2C免费开源电商系统
// +----------------------------------------------------------------------
D
devil_gong 已提交
5
// | Copyright (c) 2011~2019 http://shopxo.net All rights reserved.
D
v1.2.0  
devil_gong 已提交
6 7 8 9 10 11 12 13
// +----------------------------------------------------------------------
// | Licensed ( http://www.apache.org/licenses/LICENSE-2.0 )
// +----------------------------------------------------------------------
// | Author: Devil
// +----------------------------------------------------------------------
namespace payment;

/**
14
 * 支付宝支付 - 新版本接口
D
v1.2.0  
devil_gong 已提交
15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
 * @author   Devil
 * @blog    http://gong.gg/
 * @version 1.0.0
 * @date    2018-09-19
 * @desc    description
 */
class Alipay
{
    // 插件配置参数
    private $config;

    /**
     * 构造方法
     * @author   Devil
     * @blog    http://gong.gg/
     * @version 1.0.0
     * @date    2018-09-17
     * @desc    description
     * @param   [array]           $params [输入参数(支付配置参数)]
     */
    public function __construct($params = [])
    {
        $this->config = $params;
    }

    /**
     * 配置信息
     * @author   Devil
     * @blog    http://gong.gg/
     * @version 1.0.0
     * @date    2018-09-19
     * @desc    description
     */
    public function Config()
    {
        // 基础信息
        $base = [
            'name'          => '支付宝',  // 插件名称
G
gongfuxiang 已提交
53
            'version'       => '1.1.0',  // 插件版本
D
v1.2.0  
devil_gong 已提交
54
            'apply_version' => '不限',  // 适用系统版本描述
D
devil_gong 已提交
55
            'apply_terminal'=> ['pc','h5'], // 适用终端 默认全部 ['pc', 'h5', 'app', 'alipay', 'weixin', 'baidu']
G
gongfuxiang 已提交
56
            'desc'          => '2.0版本,适用PC+H5,即时到帐支付方式,买家的交易资金直接打入卖家支付宝账户,快速回笼交易资金。 <a href="http://www.alipay.com/" target="_blank">立即申请</a>',  // 插件描述(支持html)
D
v1.2.0  
devil_gong 已提交
57 58 59 60 61 62 63 64 65 66
            'author'        => 'Devil',  // 开发者
            'author_url'    => 'http://shopxo.net/',  // 开发者主页
        ];

        // 配置信息
        $element = [
            [
                'element'       => 'input',
                'type'          => 'text',
                'default'       => '',
67 68 69
                'name'          => 'appid',
                'placeholder'   => '应用ID',
                'title'         => '应用ID',
D
v1.2.0  
devil_gong 已提交
70
                'is_required'   => 0,
71
                'message'       => '请填写应用ID',
D
v1.2.0  
devil_gong 已提交
72 73
            ],
            [
74 75 76 77
                'element'       => 'textarea',
                'name'          => 'rsa_public',
                'placeholder'   => '应用公钥',
                'title'         => '应用公钥',
G
gongfuxiang 已提交
78
                'desc'          => '去除以 -- 开头结尾的字符和换行',
D
v1.2.0  
devil_gong 已提交
79
                'is_required'   => 0,
80 81
                'rows'          => 6,
                'message'       => '请填写应用公钥',
D
v1.2.0  
devil_gong 已提交
82 83
            ],
            [
84 85 86 87
                'element'       => 'textarea',
                'name'          => 'rsa_private',
                'placeholder'   => '应用私钥',
                'title'         => '应用私钥',
G
gongfuxiang 已提交
88
                'desc'          => '去除以 -- 开头结尾的字符和换行',
89 90 91 92 93 94 95 96 97
                'is_required'   => 0,
                'rows'          => 6,
                'message'       => '请填写应用私钥',
            ],
            [
                'element'       => 'textarea',
                'name'          => 'out_rsa_public',
                'placeholder'   => '支付宝公钥',
                'title'         => '支付宝公钥',
G
gongfuxiang 已提交
98
                'desc'          => '去除以 -- 开头结尾的字符和换行',
D
v1.2.0  
devil_gong 已提交
99
                'is_required'   => 0,
100 101
                'rows'          => 6,
                'message'       => '请填写支付宝公钥',
D
v1.2.0  
devil_gong 已提交
102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
            ],
        ];

        return [
            'base'      => $base,
            'element'   => $element,
        ];
    }

    /**
     * 支付入口
     * @author   Devil
     * @blog    http://gong.gg/
     * @version 1.0.0
     * @date    2018-09-19
     * @desc    description
     * @param   [array]           $params [输入参数]
     */
    public function Pay($params = [])
    {
122 123 124 125 126 127 128 129 130 131 132 133 134
        // 参数
        if(empty($params))
        {
            return DataReturn('参数不能为空', -1);
        }
        
        // 配置信息
        if(empty($this->config))
        {
            return DataReturn('支付缺少配置', -1);
        }

        // 手机/PC
D
v1.2.0  
devil_gong 已提交
135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
        if(IsMobile())
        {
            $ret = $this->PayMobile($params);
        } else {
            $ret = $this->PayWeb($params);
        }
        return $ret;
    }

    /**
     * [PayMobile wap手机支付]
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
     * @datetime 2018-09-28T00:41:09+0800
     * @param   [array]           $params [输入参数]
     */
    private function PayMobile($params = [])
    {
154
        // 支付参数
D
v1.2.0  
devil_gong 已提交
155
        $parameter = array(
156 157 158 159 160 161 162 163 164
            'app_id'                =>  $this->config['appid'],
            'method'                =>  'alipay.trade.wap.pay',
            'format'                =>  'JSON',
            'charset'               =>  'utf-8',
            'sign_type'             =>  'RSA2',
            'timestamp'             =>  date('Y-m-d H:i:s'),
            'version'               =>  '1.0',
            'return_url'            =>  $params['call_back_url'],
            'notify_url'            =>  $params['notify_url'],
D
v1.2.0  
devil_gong 已提交
165
        );
166 167 168 169 170 171 172
        $biz_content = array(
            'product_code'          =>  'QUICK_WAP_WAY',
            'subject'               =>  $params['name'],
            'out_trade_no'          =>  $params['order_no'],
            'total_amount'          =>  $params['total_price'],
        );
        $parameter['biz_content'] = json_encode($biz_content, JSON_UNESCAPED_UNICODE);
D
v1.2.0  
devil_gong 已提交
173

174 175 176 177 178
        // 生成签名参数+签名
        $parameter['sign'] = $this->MyRsaSign($this->GetSignContent($parameter));
        
        // 输出执行form表单post提交
        exit($this->BuildRequestForm($parameter));
D
v1.2.0  
devil_gong 已提交
179 180
    }

181

D
v1.2.0  
devil_gong 已提交
182
    /**
183
     * [PayWeb PC支付]
D
v1.2.0  
devil_gong 已提交
184 185 186
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
187
     * @datetime 2018-09-28T00:23:04+0800
D
v1.2.0  
devil_gong 已提交
188 189
     * @param   [array]           $params [输入参数]
     */
190
    private function PayWeb($params = [])
D
v1.2.0  
devil_gong 已提交
191
    {
192
        // 支付参数
D
v1.2.0  
devil_gong 已提交
193
        $parameter = array(
194 195 196 197 198 199 200 201 202 203 204 205
            'app_id'                =>  $this->config['appid'],
            'method'                =>  'alipay.trade.page.pay',
            'format'                =>  'JSON',
            'charset'               =>  'utf-8',
            'sign_type'             =>  'RSA2',
            'timestamp'             =>  date('Y-m-d H:i:s'),
            'version'               =>  '1.0',
            'return_url'            =>  $params['call_back_url'],
            'notify_url'            =>  $params['notify_url'],
        );
        $biz_content = array(
            'product_code'          =>  'FAST_INSTANT_TRADE_PAY',
D
v1.2.0  
devil_gong 已提交
206 207
            'subject'               =>  $params['name'],
            'out_trade_no'          =>  $params['order_no'],
208
            'total_amount'          =>  $params['total_price'],
D
v1.2.0  
devil_gong 已提交
209
        );
210 211 212 213
        $parameter['biz_content'] = json_encode($biz_content, JSON_UNESCAPED_UNICODE);

        // 生成签名参数+签名
        $parameter['sign'] = $this->MyRsaSign($this->GetSignContent($parameter));
D
v1.2.0  
devil_gong 已提交
214
        
215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232
        // 输出执行form表单post提交
        exit($this->BuildRequestForm($parameter));
    }


    /**
     * 支付回调处理
     * @author   Devil
     * @blog    http://gong.gg/
     * @version 1.0.0
     * @date    2018-09-19
     * @desc    description
     * @param   [array]           $params [输入参数]
     */
    public function Respond($params = [])
    {
        $data = empty($_POST) ? $_GET :  array_merge($_GET, $_POST);
        ksort($data);
D
v1.2.0  
devil_gong 已提交
233

234 235 236
        // 参数字符串
        $prestr = '';
        foreach($data AS $key=>$val)
D
v1.2.0  
devil_gong 已提交
237
        {
238 239 240 241
            if ($key != 'sign' && $key != 'sign_type' && $key != 'code')
            {
                $prestr .= "$key=$val&";
            }
D
v1.2.0  
devil_gong 已提交
242
        }
243 244 245 246
        $prestr = substr($prestr, 0, -1);

        // 签名
        if(!$this->OutRsaVerify($prestr, $data['sign']))
D
devil_gong 已提交
247
        {
248
            return DataReturn('签名校验失败', -1);
D
devil_gong 已提交
249
        }
D
v1.2.0  
devil_gong 已提交
250

251 252
        // 支付状态
        if(!empty($data['trade_no']) || (isset($data['trade_status']) && in_array($data['trade_status'], ['TRADE_SUCCESS', 'TRADE_FINISHED'])))
D
v1.2.0  
devil_gong 已提交
253
        {
254
            return DataReturn('支付成功', 0, $this->ReturnData($data));
D
v1.2.0  
devil_gong 已提交
255
        }
256
        return DataReturn('处理异常错误', -100);
D
v1.2.0  
devil_gong 已提交
257 258 259
    }

    /**
260
     * [ReturnData 返回数据统一格式]
D
v1.2.0  
devil_gong 已提交
261 262 263
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
264 265
     * @datetime 2018-10-06T16:54:24+0800
     * @param    [array]                   $data [返回数据]
D
v1.2.0  
devil_gong 已提交
266
     */
267
    private function ReturnData($data)
D
v1.2.0  
devil_gong 已提交
268
    {
269 270 271 272 273 274
        // 返回数据固定基础参数
        $data['trade_no']       = $data['trade_no'];        // 支付平台 - 订单号
        $data['buyer_user']     = $data['seller_id'];       // 支付平台 - 用户
        $data['out_trade_no']   = $data['out_trade_no'];    // 本系统发起支付的 - 订单号
        $data['subject']        = isset($data['subject']) ? $data['subject'] : ''; // 本系统发起支付的 - 商品名称
        $data['pay_price']      = $data['total_amount'];    // 本系统发起支付的 - 总价
D
v1.2.0  
devil_gong 已提交
275

276
        return $data;
D
v1.2.0  
devil_gong 已提交
277 278
    }

D
devil_gong 已提交
279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303
    /**
     * 退款处理
     * @author  Devil
     * @blog    http://gong.gg/
     * @version 1.0.0
     * @date    2019-05-28
     * @desc    description
     * @param   [array]           $params [输入参数]
     */
    public function Refund($params = [])
    {
        // 参数
        $p = [
            [
                'checked_type'      => 'empty',
                'key_name'          => 'order_no',
                'error_msg'         => '订单号不能为空',
            ],
            [
                'checked_type'      => 'empty',
                'key_name'          => 'trade_no',
                'error_msg'         => '交易平台订单号不能为空',
            ],
            [
                'checked_type'      => 'empty',
D
devil_gong 已提交
304
                'key_name'          => 'refund_price',
D
devil_gong 已提交
305 306 307 308 309 310 311 312 313 314
                'error_msg'         => '退款金额不能为空',
            ],
        ];
        $ret = ParamsChecked($params, $p);
        if($ret !== true)
        {
            return DataReturn($ret, -1);
        }

        // 退款原因
D
devil_gong 已提交
315
        $refund_reason = empty($params['refund_reason']) ? $params['order_no'].'订单退款'.$params['refund_price'].'元' : $params['refund_reason'];
D
devil_gong 已提交
316 317 318 319 320 321 322 323 324 325 326 327 328 329

        // 退款参数
        $parameter = array(
            'app_id'                =>  $this->config['appid'],
            'method'                =>  'alipay.trade.refund',
            'format'                =>  'JSON',
            'charset'               =>  'utf-8',
            'sign_type'             =>  'RSA2',
            'timestamp'             =>  date('Y-m-d H:i:s'),
            'version'               =>  '1.0',
        );
        $biz_content = array(
            'out_trade_no'          =>  $params['order_no'],
            'trade_no'              =>  $params['trade_no'],
D
devil_gong 已提交
330
            'refund_amount'         =>  $params['refund_price'],
D
devil_gong 已提交
331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350
            'refund_reason'         =>  $refund_reason,
        );
        $parameter['biz_content'] = json_encode($biz_content, JSON_UNESCAPED_UNICODE);

        // 生成签名参数+签名
        $parameter['sign'] = $this->MyRsaSign($this->GetSignContent($parameter));

        // 执行请求
        $result = $this->HttpRequest('https://openapi.alipay.com/gateway.do', $parameter);
        $key = str_replace('.', '_', $parameter['method']).'_response';

        // 验证签名
        if(!$this->SyncRsaVerify($result, $key))
        {
            return DataReturn('签名验证错误', -1);
        }

        // 状态
        if(isset($result[$key]['code']) && $result[$key]['code'] == 10000)
        {
D
devil_gong 已提交
351 352 353 354 355 356 357 358 359
            // 统一返回格式
            $data = [
                'out_trade_no'  => isset($result[$key]['out_trade_no']) ? $result[$key]['out_trade_no'] : '',
                'trade_no'      => isset($result[$key]['trade_no']) ? $result[$key]['trade_no'] : '',
                'buyer_user'    => isset($result[$key]['buyer_user_id']) ? $result[$key]['buyer_user_id'] : '',
                'refund_price'  => isset($result[$key]['refund_fee']) ? $result[$key]['refund_fee'] : 0.00,
                'return_params' => $result[$key],
            ];
            return DataReturn('退款成功', 0, $data);
D
devil_gong 已提交
360 361 362 363 364 365
        }

        // 直接返回支付信息
        return DataReturn($result[$key]['sub_msg'].'['.$result[$key]['sub_code'].']', -1000);
    }

D
v1.2.0  
devil_gong 已提交
366
    /**
367
     * 建立请求,以表单HTML形式构造(默认)
D
v1.2.0  
devil_gong 已提交
368
     * @author   Devil
369 370 371 372 373 374
     * @blog    http://gong.gg/
     * @version 1.0.0
     * @date    2019-03-15
     * @desc    description
     * @param   [array]          $params [请求参数数组]
     * @return  [string]                 [提交表单HTML文本]
D
v1.2.0  
devil_gong 已提交
375
     */
376
    private function BuildRequestForm($params)
D
v1.2.0  
devil_gong 已提交
377
    {
378
        $html = "<form id='alipaysubmit' name='alipaysubmit' action='https://openapi.alipay.com/gateway.do?charset=utf-8' method='POST'>";
D
devil_gong 已提交
379
        foreach($params as $key=>$val)
D
v1.2.0  
devil_gong 已提交
380
        {
381 382 383 384 385
            if(!empty($val))
            {
                $val = str_replace("'", "&apos;", $val);
                $html .= "<input type='hidden' name='".$key."' value='".$val."'/>";
            }
D
v1.2.0  
devil_gong 已提交
386 387
        }

388 389 390 391 392 393
        //submit按钮控件请不要含有name属性
        $html .= "<input type='submit' value='ok' style='display:none;''></form>";
        
        $html .= "<script>document.forms['alipaysubmit'].submit();</script>";
        
        return $html;
D
v1.2.0  
devil_gong 已提交
394 395
    }

D
devil_gong 已提交
396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440
    /**
     * [HttpRequest 网络请求]
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
     * @datetime 2017-09-25T09:10:46+0800
     * @param    [string]          $url  [请求url]
     * @param    [array]           $data [发送数据]
     * @return   [mixed]                 [请求返回数据]
     */
    private function HttpRequest($url, $data)
    {
        $ch = curl_init();
        curl_setopt($ch, CURLOPT_URL, $url);
        curl_setopt($ch, CURLOPT_FAILONERROR, false);
        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
        curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);

        $body_string = '';
        if(is_array($data) && 0 < count($data))
        {
            foreach($data as $k => $v)
            {
                $body_string .= $k.'='.urlencode($v).'&';
            }
            curl_setopt($ch, CURLOPT_POST, true);
            curl_setopt($ch, CURLOPT_POSTFIELDS, $body_string);
        }
        $headers = array('content-type: application/x-www-form-urlencoded;charset=UTF-8');
        curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);
        $reponse = curl_exec($ch);
        if(curl_errno($ch))
        {
            return false;
        } else {
            $httpStatusCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
            if(200 !== $httpStatusCode)
            {
                return false;
            }
        }
        curl_close($ch);
        return json_decode($reponse, true);
    }

D
v1.2.0  
devil_gong 已提交
441
    /**
442
     * 获取签名内容
D
v1.2.0  
devil_gong 已提交
443 444 445
     * @author   Devil
     * @blog    http://gong.gg/
     * @version 1.0.0
446
     * @date    2019-03-15
D
v1.2.0  
devil_gong 已提交
447
     * @desc    description
448
     * @param   [array]          $params [需要签名的参数]
D
v1.2.0  
devil_gong 已提交
449
     */
450
    public function GetSignContent($params)
D
v1.2.0  
devil_gong 已提交
451
    {
452 453 454 455
        ksort($params);
        $string = "";
        $i = 0;
        foreach($params as $k => $v)
D
v1.2.0  
devil_gong 已提交
456
        {
457
            if(!empty($v) && "@" != substr($v, 0, 1))
D
v1.2.0  
devil_gong 已提交
458
            {
459 460 461 462
                if ($i == 0) {
                    $string .= "$k" . "=" . "$v";
                } else {
                    $string .= "&" . "$k" . "=" . "$v";
D
v1.2.0  
devil_gong 已提交
463
                }
464
                $i++;
D
v1.2.0  
devil_gong 已提交
465 466
            }
        }
467 468 469
        unset($k, $v);
        return $string;
    }
D
v1.2.0  
devil_gong 已提交
470

471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505
    /**
     * [MyRsaSign 签名字符串]
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
     * @datetime 2017-09-24T08:38:28+0800
     * @param    [string]                   $prestr [需要签名的字符串]
     * @return   [string]                           [签名结果]
     */
    private function MyRsaSign($prestr)
    {
        $res = "-----BEGIN RSA PRIVATE KEY-----\n";
        $res .= wordwrap($this->config['rsa_private'], 64, "\n", true);
        $res .= "\n-----END RSA PRIVATE KEY-----";
        return openssl_sign($prestr, $sign, $res, OPENSSL_ALGO_SHA256) ? base64_encode($sign) : null;
    }

    /**
     * [MyRsaDecrypt RSA解密]
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
     * @datetime 2017-09-24T09:12:06+0800
     * @param    [string]                   $content [需要解密的内容,密文]
     * @return   [string]                            [解密后内容,明文]
     */
    private function MyRsaDecrypt($content)
    {
        $res = "-----BEGIN PUBLIC KEY-----\n";
        $res .= wordwrap($this->config['rsa_public'], 64, "\n", true);
        $res .= "\n-----END PUBLIC KEY-----";
        $res = openssl_get_privatekey($res);
        $content = base64_decode($content);
        $result  = '';
        for($i=0; $i<strlen($content)/128; $i++)
D
v1.2.0  
devil_gong 已提交
506
        {
507 508 509
            $data = substr($content, $i * 128, 128);
            openssl_private_decrypt($data, $decrypt, $res, OPENSSL_ALGO_SHA256);
            $result .= $decrypt;
D
v1.2.0  
devil_gong 已提交
510
        }
511 512 513
        openssl_free_key($res);
        return $result;
    }
D
v1.2.0  
devil_gong 已提交
514

515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532
    /**
     * [OutRsaVerify 支付宝验证签名]
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
     * @datetime 2017-09-24T08:39:50+0800
     * @param    [string]                   $prestr [需要签名的字符串]
     * @param    [string]                   $sign   [签名结果]
     * @return   [boolean]                          [正确true, 错误false]
     */
    private function OutRsaVerify($prestr, $sign)
    {
        $res = "-----BEGIN PUBLIC KEY-----\n";
        $res .= wordwrap($this->config['out_rsa_public'], 64, "\n", true);
        $res .= "\n-----END PUBLIC KEY-----";
        $pkeyid = openssl_pkey_get_public($res);
        $sign = base64_decode($sign);
        if($pkeyid)
D
v1.2.0  
devil_gong 已提交
533
        {
534 535
            $verify = openssl_verify($prestr, $sign, $pkeyid, OPENSSL_ALGO_SHA256);
            openssl_free_key($pkeyid);
D
v1.2.0  
devil_gong 已提交
536
        }
537
        return (isset($verify) && $verify == 1) ? true : false;
D
v1.2.0  
devil_gong 已提交
538 539
    }

540 541
     /**
     * [SyncRsaVerify 同步返回签名验证]
D
v1.2.0  
devil_gong 已提交
542 543 544
     * @author   Devil
     * @blog     http://gong.gg/
     * @version  1.0.0
545
     * @datetime 2017-09-25T13:13:39+0800
D
v1.2.0  
devil_gong 已提交
546
     * @param    [array]                   $data [返回数据]
547
     * @param    [boolean]                 $key  [数据key]
D
v1.2.0  
devil_gong 已提交
548
     */
549
    private function SyncRsaVerify($data, $key)
D
v1.2.0  
devil_gong 已提交
550
    {
551 552
        $string = json_encode($data[$key], JSON_UNESCAPED_UNICODE);
        return $this->OutRsaVerify($string, $data['sign']);
D
v1.2.0  
devil_gong 已提交
553 554 555
    }
}
?>