CallbackController.cs 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132
  1. using OASystem.Domain.Dtos.CallBack.QiYeWeChat;
  2. namespace OASystem.API.Controllers
  3. {
  4. /// <summary>
  5. /// 回调地址
  6. /// </summary>
  7. [Route("/callback")]
  8. public class CallbackController : Controller
  9. {
  10. private readonly IMapper _mapper;
  11. private readonly ILogger<CallbackController> _logger;
  12. #region 企业微信 通讯录通知回调key And token
  13. private readonly string _qiYeWechat_Token = "WWiCDK";
  14. private readonly string _qiYeWechat_EncodingAESKey = "3BWKiWnvp6xJGQ5oD3TBaOKYniNgX1g6kZZEehbM3ym";
  15. private readonly string _qiYeWechat_CorpId = "wwe978bef5495a0728";
  16. #endregion
  17. public CallbackController(IMapper mapper, ILogger<CallbackController> logger)
  18. {
  19. _mapper = mapper;
  20. _logger = logger;
  21. }
  22. #region 企业微信回调
  23. /// <summary>
  24. /// 回调通知
  25. /// </summary>
  26. /// <returns></returns>
  27. [Route("memberschange")]
  28. [HttpGet, HttpPost]
  29. public async Task<ActionResult> ApproveCallBack(string msg_signature, string timestamp, string nonce, string echostr)
  30. {
  31. _logger.LogInformation("【企业微信】【通讯录助手】【回调】进入回调");
  32. ApproveCallBackInputDTO input = new ApproveCallBackInputDTO();
  33. input.msg_signature = msg_signature;
  34. input.timestamp = timestamp;
  35. input.nonce = nonce;
  36. input.echostr = echostr;
  37. _logger.LogInformation("【企业微信】【通讯录助手】【回调】【参数】" + input.ToJson());
  38. if (HttpContext.Request.Method == System.Net.Http.HttpMethod.Get.Method)
  39. {
  40. var model = await VerifyURLCallBack(input);
  41. return Content(model, "text/xml");
  42. }
  43. if (HttpContext.Request.Method == System.Net.Http.HttpMethod.Post.Method)
  44. {
  45. var stream = Request.Body;
  46. var model = await ApproveCallBack(stream, input);
  47. return Content(model, "text/xml");
  48. }
  49. _logger.LogInformation("【企业微信】【通讯录助手】【回调】回调成功");
  50. return Content("ok", "text/xml");
  51. }
  52. /// <summary>
  53. /// 验证URL有效性
  54. /// </summary>
  55. /// <returns></returns>
  56. private async Task<string> VerifyURLCallBack(ApproveCallBackInputDTO input)
  57. {
  58. int ret = 0;
  59. string sEchoStr = "";
  60. try
  61. {
  62. //企业微信官方加解密校验解析类
  63. Tencent.WXBizMsgCrypt wxcpt = new Tencent.WXBizMsgCrypt(_qiYeWechat_Token, _qiYeWechat_EncodingAESKey, _qiYeWechat_CorpId);
  64. string sReqMsgSig = input.msg_signature;
  65. string sReqTimeStamp = input.timestamp;
  66. string sReqNonce = input.nonce;
  67. string sReqEchostr = input.echostr;
  68. //企业微信官方验证URL
  69. ret = wxcpt.VerifyURL(sReqMsgSig, sReqTimeStamp, sReqNonce, sReqEchostr, ref sEchoStr);
  70. if (ret != 0)
  71. {
  72. throw new Exception($"ERR: VerifyURL fail, ret: {ret}");
  73. }
  74. return sEchoStr;
  75. }
  76. catch (Exception ex)
  77. {
  78. return ex.Message;
  79. }
  80. }
  81. /// <summary>
  82. /// 回调通知处理业务
  83. /// </summary>
  84. /// <returns></returns>
  85. private async Task<string> ApproveCallBack(Stream context, ApproveCallBackInputDTO input)
  86. {
  87. var sReqData = "";
  88. int ret = 0;
  89. string sMsg = "";
  90. try
  91. {
  92. //企业微信官方加解密校验解析类
  93. Tencent.WXBizMsgCrypt wxcpt = new Tencent.WXBizMsgCrypt(_qiYeWechat_Token, _qiYeWechat_EncodingAESKey, _qiYeWechat_CorpId);
  94. string sReqMsgSig = input.msg_signature;
  95. string sReqTimeStamp = input.timestamp;
  96. string sReqNonce = input.nonce;
  97. string sReqEchostr = input.echostr;
  98. // Post请求的密文数据
  99. using (var reader = new StreamReader(context))
  100. {
  101. sReqData = await reader.ReadToEndAsync();
  102. }
  103. //回调数据
  104. // 解析之后的明文
  105. ret = wxcpt.DecryptMsg(sReqMsgSig, sReqTimeStamp, sReqNonce, sReqData, ref sMsg);
  106. if (ret != 0)
  107. {
  108. throw new Exception($"ERR: Decrypt Fail, ret: {ret}");
  109. }
  110. // ret==0表示解密成功,sMsg表示解密之后的明文xml串
  111. //下一步处理实际业务数据了
  112. return sMsg;
  113. }
  114. catch (Exception ex)
  115. {
  116. throw new Exception(ex.Message);
  117. }
  118. }
  119. #endregion
  120. }
  121. }