VipbackController.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375
  1. <?php
  2. // +----------------------------------------------------------------------
  3. // | ThinkCMF [ WE CAN DO IT MORE SIMPLE ]
  4. // +----------------------------------------------------------------------
  5. // | Copyright (c) 2013-2014 http://www.thinkcmf.com All rights reserved.
  6. // +----------------------------------------------------------------------
  7. // | Author: Dean <zxxjjforever@163.com>
  8. // +----------------------------------------------------------------------
  9. namespace app\appapi\controller;
  10. use cmf\controller\HomeBaseController;
  11. use think\facade\Db;
  12. use think\db\Query;
  13. /**
  14. * 支付回调
  15. */
  16. class VipbackController extends HomebaseController {
  17. private $wxDate = null;
  18. //支付宝 回调
  19. public function notify_ali() {
  20. $configpri=getConfigPri();
  21. require_once(CMF_ROOT."sdk/alipay/alipay_app/alipay.config.php");
  22. $alipay_config['partner'] = $configpri['aliapp_partner'];
  23. require_once(CMF_ROOT."sdk/alipay/alipay_app/lib/alipay_core.function.php");
  24. require_once(CMF_ROOT."sdk/alipay/alipay_app/lib/alipay_rsa.function.php");
  25. require_once(CMF_ROOT."sdk/alipay/alipay_app/lib/alipay_notify.class.php");
  26. //计算得出通知验证结果
  27. $alipayNotify = new \AlipayNotify($alipay_config);
  28. $verify_result = $alipayNotify->verifyNotify();
  29. $this->logali_vip("ali_data:".json_encode($_POST));
  30. if($verify_result) {//验证成功
  31. //商户订单号
  32. $out_trade_no = $_POST['out_trade_no'];
  33. //支付宝交易号
  34. $trade_no = $_POST['trade_no'];
  35. //交易状态
  36. $trade_status = $_POST['trade_status'];
  37. //交易金额
  38. $total_fee = $_POST['total_fee'];
  39. if($_POST['trade_status'] == 'TRADE_FINISHED') {
  40. //判断该笔订单是否在商户网站中已经做过处理
  41. //如果没有做过处理,根据订单号(out_trade_no)在商户网站的订单系统中查到该笔订单的详细,并执行商户的业务程序
  42. //如果有做过处理,不执行商户的业务程序
  43. //注意:
  44. //退款日期超过可退款期限后(如三个月可退款),支付宝系统发送该交易状态通知
  45. //请务必判断请求时的total_fee、seller_id与通知时获取的total_fee、seller_id为一致的
  46. //调试用,写文本函数记录程序运行情况是否正常
  47. //logResult("这里写入想要调试的代码变量值,或其他运行的结果记录");
  48. }else if ($_POST['trade_status'] == 'TRADE_SUCCESS') {
  49. //判断该笔订单是否在商户网站中已经做过处理
  50. //如果没有做过处理,根据订单号(out_trade_no)在商户网站的订单系统中查到该笔订单的详细,并执行商户的业务程序
  51. //如果有做过处理,不执行商户的业务程序
  52. //注意:
  53. //付款完成后,支付宝系统发送该交易状态通知
  54. //请务必判断请求时的total_fee、seller_id与通知时获取的total_fee、seller_id为一致的
  55. //调试用,写文本函数记录程序运行情况是否正常
  56. //logResult("这里写入想要调试的代码变量值,或其他运行的结果记录");
  57. $orderinfo=Db::name("user_vip_charge")->where("orderno='{$out_trade_no}' and money='{$total_fee}' and status='0' and type='1'")->find();
  58. $this->logali_vip("orderinfo:".json_encode($orderinfo));
  59. if($orderinfo){
  60. $now=time();
  61. //更新用户vip信息
  62. $vipinfo=getUserVipInfo($orderinfo['touid']);
  63. $days=$orderinfo['days']*24*60*60;
  64. if($vipinfo['isvip']==0){ //用户不是vip
  65. $endtime=$now+$days;
  66. }else{
  67. $endtime=Db::name("user")->where("id='{$orderinfo['touid']}'")->value("vip_endtime");
  68. $endtime=$endtime+$days;
  69. }
  70. //更新用户vip信息
  71. Db::name("user")->where("id='{$orderinfo['touid']}'")->update(array("vip_endtime"=>$endtime));
  72. // 更新订单状态
  73. Db::name("user_vip_charge")->where("id='{$orderinfo['id']}'")->update(array("status"=>1,"trade_no"=>$trade_no));
  74. $this->logali_vip("成功");
  75. echo "success"; //请不要修改或删除
  76. return;
  77. }else{
  78. $this->logali_vip("orderno:".$out_trade_no.' 订单信息不存在');
  79. }
  80. }
  81. //——请根据您的业务逻辑来编写程序(以上代码仅作参考)——
  82. echo "fail"; //请不要修改或删除
  83. /////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
  84. }else {
  85. $this->logali_vip("验证失败");
  86. //验证失败
  87. echo "fail";
  88. //调试用,写文本函数记录程序运行情况是否正常
  89. //logResult("这里写入想要调试的代码变量值,或其他运行的结果记录");
  90. }
  91. }
  92. /* 支付宝支付 */
  93. /* 微信支付 */
  94. public function notify_wx(){
  95. $config=getConfigPri();
  96. //$xmlInfo = $GLOBALS['HTTP_RAW_POST_DATA'];
  97. $xmlInfo=file_get_contents("php://input");
  98. //解析xml
  99. $arrayInfo = $this -> xmlToArray($xmlInfo);
  100. $this -> wxDate = $arrayInfo;
  101. //$this -> logawx_vip("wx_data:".json_encode($arrayInfo));//log打印保存
  102. if($arrayInfo['return_code'] == "SUCCESS"){
  103. // if($return_msg != null){
  104. // echo $this -> returnInfo("FAIL","签名失败");
  105. // $this -> logawx_vip("签名失败:".$sign);//log打印保存
  106. // return;
  107. // }else{
  108. $wxSign = $arrayInfo['sign'];
  109. unset($arrayInfo['sign']);
  110. $arrayInfo['appid'] = $config['wx_appid'];
  111. $arrayInfo['mch_id'] = $config['wx_mchid'];
  112. $key = $config['wx_key'];
  113. ksort($arrayInfo);//按照字典排序参数数组
  114. $sign = $this -> sign($arrayInfo,$key);//生成签名
  115. $this -> logawx_vip("数据打印测试签名signmy:".$sign.":::微信sign:".$wxSign);//log打印保存
  116. if($this -> checkSign($wxSign,$sign)){
  117. echo $this -> returnInfo("SUCCESS","OK");
  118. $this -> logawx_vip("签名验证结果成功:".$sign);//log打印保存
  119. $this -> orderServer();//订单处理业务逻辑
  120. return;
  121. }else{
  122. echo $this -> returnInfo("FAIL","签名失败");
  123. $this -> logawx_vip("签名验证结果失败:本地加密:".$sign.':::::三方加密'.$wxSign);//log打印保存
  124. return;
  125. }
  126. //}
  127. }else{
  128. echo $this -> returnInfo("FAIL","签名失败");
  129. $this -> logawx_vip($arrayInfo['return_code']);//log打印保存
  130. return;
  131. }
  132. }
  133. private function returnInfo($type,$msg){
  134. if($type == "SUCCESS"){
  135. return $returnXml = "<xml><return_code><![CDATA[{$type}]]></return_code></xml>";
  136. }else{
  137. return $returnXml = "<xml><return_code><![CDATA[{$type}]]></return_code><return_msg><![CDATA[{$msg}]]></return_msg></xml>";
  138. }
  139. }
  140. //签名验证
  141. private function checkSign($sign1,$sign2){
  142. return trim($sign1) == trim($sign2);
  143. }
  144. /* 订单查询加值业务处理
  145. * @param orderNum 订单号
  146. */
  147. private function orderServer(){
  148. $info = $this -> wxDate;
  149. $this->logawx_vip("info:".json_encode($info));
  150. $orderinfo=Db::name("user_vip_charge")->where("orderno='{$info['out_trade_no']}' and status='0' and type='2'")->find();
  151. //$this->logawx_vip("sql:".M()->getLastSql());
  152. $this->logawx_vip("orderinfo:".json_encode($orderinfo));
  153. if($orderinfo){
  154. $now=time();
  155. //更新用户vip信息
  156. $vipinfo=getUserVipInfo($orderinfo['touid']);
  157. $days=$orderinfo['days']*24*60*60;
  158. if($vipinfo['isvip']==0){ //用户不是vip
  159. $endtime=$now+$days;
  160. }else{
  161. $endtime=Db::name("user")->where("id='{$orderinfo['touid']}'")->value("vip_endtime");
  162. $endtime=$endtime+$days;
  163. }
  164. //更新用户vip信息
  165. Db::name("user")->where("id='{$orderinfo['touid']}'")->update(array("vip_endtime"=>$endtime));
  166. /* 更新 订单状态 */
  167. Db::name("user_vip_charge")->where("id='{$orderinfo['id']}'")->update(array("status"=>1,"trade_no"=>$info['transaction_id']));
  168. }else{
  169. $this->logawx_vip("orderno:".$out_trade_no.' 订单信息不存在');
  170. return false;
  171. }
  172. }
  173. /**
  174. * sign拼装获取
  175. */
  176. private function sign($param,$key){
  177. $sign = "";
  178. foreach($param as $k => $v){
  179. $sign .= $k."=".$v."&";
  180. }
  181. $sign .= "key=".$key;
  182. $sign = strtoupper(md5($sign));
  183. return $sign;
  184. }
  185. /**
  186. * xml转为数组
  187. */
  188. private function xmlToArray($xmlStr){
  189. $msg = array();
  190. $postStr = $xmlStr;
  191. $msg = (array)simplexml_load_string($postStr, 'SimpleXMLElement', LIBXML_NOCDATA);
  192. return $msg;
  193. }
  194. /* 微信支付 */
  195. /* 苹果支付 */
  196. public function notify_ios(){
  197. $content=file_get_contents("php://input");
  198. $data = json_decode($content,true);
  199. $receipt = $data["receipt-data"];
  200. $version_ios = $data["version_ios"];
  201. $out_trade_no = $data["out_trade_no"];
  202. $info = $this->getReceiptData($receipt, $version_ios);
  203. $this->logios_vip("info:".json_encode($info));
  204. $iforderinfo=Db::name("user_vip_charge")->where("trade_no='{$info['transaction_id']}' and type='3'")->find();
  205. if($iforderinfo){
  206. echo '{"status":"fail","info":"非法提交-001"}';return;
  207. }
  208. //判断订单是否存在
  209. $orderinfo=Db::name("user_vip_charge")->where("orderno='{$out_trade_no}' and status='0' and type='3'")->find();
  210. if($orderinfo){
  211. $now=time();
  212. //更新用户vip信息
  213. $vipinfo=getUserVipInfo($orderinfo['touid']);
  214. $days=$orderinfo['days']*24*60*60;
  215. if($vipinfo['isvip']==0){ //用户不是vip
  216. $endtime=$now+$days;
  217. }else{
  218. $endtime=Db::name("user")->where("id='{$orderinfo['touid']}'")->value("vip_endtime");
  219. $endtime=$endtime+$days;
  220. }
  221. //更新用户vip信息
  222. Db::name("user")->where("id='{$orderinfo['touid']}'")->update(array("vip_endtime"=>$endtime));
  223. /* 更新 订单状态 */
  224. Db::name("user_vip_charge")->where("id='{$orderinfo['id']}'")->update(array("status"=>1,"trade_no"=>$info['transaction_id']));
  225. }else{
  226. $this->logios_vip("orderno:".$out_trade_no.' 订单信息不存在');
  227. echo '{"status":"fail","info":"订单信息不存在-003"}';
  228. return;
  229. }
  230. echo '{"status":"success","info":"充值支付成功"}';
  231. }
  232. public function getReceiptData($receipt, $version_ios){
  233. $config=getConfigPub();
  234. if ($version_ios == $config['ios_shelves']) {
  235. //沙盒
  236. $endpoint = 'https://sandbox.itunes.apple.com/verifyReceipt';
  237. }else {
  238. //生产
  239. $endpoint = 'https://buy.itunes.apple.com/verifyReceipt';
  240. }
  241. $postData = json_encode(
  242. array('receipt-data' => $receipt)
  243. );
  244. $ch = curl_init($endpoint);
  245. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  246. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); //关闭安全验证
  247. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); //关闭安全验证
  248. curl_setopt($ch, CURLOPT_POST, true);
  249. curl_setopt($ch, CURLOPT_POSTFIELDS, $postData);
  250. $response = curl_exec($ch);
  251. $errno = curl_errno($ch);
  252. $errmsg = curl_error($ch);
  253. curl_close($ch);
  254. if($errno != 0) {
  255. echo '{"status":"fail","info":"服务器出错,请联系管理员"}';
  256. return;
  257. }
  258. $data = json_decode($response,1);
  259. if (!is_array($data)) {
  260. echo '{"status":"fail","info":"验证失败,如有疑问请联系管理"}';
  261. return;
  262. }
  263. if (!isset($data['status']) || $data['status'] != 0) {
  264. echo '{"status":"fail","info":"验证失败,如有疑问请联系管理"}';
  265. return;
  266. }
  267. return array(
  268. 'product_id' => $data['receipt']['in_app'][0]['product_id'],
  269. 'transaction_id' => $data['receipt']['in_app'][0]['transaction_id'],
  270. );
  271. }
  272. /* 苹果支付 */
  273. /* 打印log */
  274. public function logali_vip($msg){
  275. file_put_contents(CMF_ROOT.'data/log/vipback/logali_vip'.date('Y-m-d').'.txt',date('y-m-d h:i:s').' msg:'.$msg."\r\n",FILE_APPEND);
  276. }
  277. /* 打印log */
  278. public function logawx_vip($msg){
  279. file_put_contents(CMF_ROOT.'data/log/vipback/logwx_vip'.date('Y-m-d').'.txt',date('y-m-d h:i:s').' msg:'.$msg."\r\n",FILE_APPEND);
  280. }
  281. /* 打印log */
  282. public function logios_vip($msg){
  283. file_put_contents(CMF_ROOT.'data/log/vipback/logios_vip'.date('Y-m-d').'.txt',date('y-m-d h:i:s').' msg:'.$msg."\r\n",FILE_APPEND);
  284. }
  285. }