Payios - 副本.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573
  1. <?php
  2. namespace app\api\controller;
  3. use app\common\controller\Api;
  4. use think\Db;
  5. use addons\epay\library\Service;
  6. /**
  7. * 充值配置与充值订单
  8. */
  9. class Payios extends Api
  10. {
  11. protected $noNeedLogin = ['auto_renewal_vip_notify'];
  12. protected $noNeedRight = ['*'];
  13. //vip ios用的
  14. public function vip_config_ios(){
  15. $list = Db::name('payvip_config_ios')->field('id,money,days,title,info,bundle_id,is_lianxu')->where('is_show',1)->order('weight asc,id asc')->select();
  16. $data['vipconfig'] = $list;
  17. $data['vip_endtime'] = model('wallet')->getWallet($this->auth->id,'vip_endtime');
  18. $data['is_vip'] = $data['vip_endtime'] > time() ? 1 : 0;
  19. $data['avatar'] = localpath_to_netpath($this->auth->avatar,['nickname'=>$this->auth->nickname],true);
  20. $this->success('success',$data);
  21. }
  22. //vip用的,创建订单
  23. public function vip_recharge_ios(){
  24. $rc_id = input('rc_id',0);
  25. $platform = 'app';
  26. $uid = $this->auth->id;
  27. if(!$rc_id){
  28. $this->error('请选择会员套餐');
  29. }
  30. if(!$this->user_auth_limit()){
  31. $this->error('请先完成实名认证');
  32. }
  33. //赋值money
  34. $recharge_config = Db::name('payvip_config_ios')->where('id',$rc_id)->find();
  35. $money = $recharge_config['money'];
  36. if($money<=0)
  37. {
  38. $this->error('支付金额必须大于0');
  39. }
  40. if($money > 10000){
  41. $this->error('支付金额太大');
  42. }
  43. //创建订单
  44. $data = [];
  45. $data['user_id'] = $uid;
  46. $data['out_trade_no'] = createUniqueNo('V',$uid); // 数据库订单号加密
  47. $data['order_amount'] = $money;
  48. $data['createtime'] = time();
  49. $data['pay_type'] = 'ios';
  50. $data['platform'] = $platform;
  51. $data['order_status'] = 0;
  52. $data['table_name'] = 'vip_recharge';
  53. $data['table_id'] = 0;
  54. $data['args'] = json_encode(['days'=>$recharge_config['days']]);
  55. $data['bundle_id'] = $recharge_config['bundle_id'];
  56. $orderid = Db::name('pay_order')->insertGetId($data);
  57. $this->success('success',$data['out_trade_no']);
  58. }
  59. //vip,苹果内购支付回调
  60. //因前端不传入订单号,作废,且与gold_notify_iosnew 已完成合并
  61. public function vip_notify_ios(){
  62. //苹果内购的验证收据
  63. $receipt_data = input('apple_receipt', '', 'trim');
  64. $order_no = input('order_no', '', 'trim');
  65. filePut('VIP ios充值:参数apple_receipt='.$receipt_data.',order_no='.$order_no);
  66. if (!$receipt_data || !$order_no) {
  67. $this->error('缺少参数');
  68. }
  69. Db::startTrans();
  70. // 查找订单
  71. $order_info = Db::name('pay_order')->where(['out_trade_no' => $order_no])->lock(true)->find();
  72. if (!$order_info) {
  73. Db::rollback();
  74. filePut('VIP ios充值:订单丢失out_trade_no='.$order_no);
  75. $this->error('订单丢失');
  76. }
  77. if ($order_info['order_status'] == 1) {
  78. Db::rollback();
  79. $this->success('充值成功');
  80. }
  81. // 验证支付状态
  82. $result = $this->validate_apple_pay($receipt_data);
  83. if (!$result['status']) {// 验证不通过
  84. Db::rollback();
  85. filePut('VIP ios充值:验证out_trade_no='.$order_no.','.$result['message']);
  86. $this->error($result['message']);
  87. }
  88. $count = count($result['data']['receipt']['in_app']);
  89. $use_count = $count - 1;
  90. $args = json_decode($order_info['args'],true);
  91. if ($result['data']['receipt']['in_app'][$use_count]['product_id'] != $order_info['bundle_id']) {
  92. Db::rollback();
  93. filePut('VIP ios充值:非法请求,请立刻停止out_trade_no='.$order_no.','.$result['message'].','.$result['data']['receipt']['in_app'][$use_count]['product_id'].'!='.$order_info['bundle_id']);
  94. $this->error('非法请求,请立刻停止');
  95. }
  96. //逻辑开始
  97. //先充值
  98. $user_info = Db::name('user_wallet')->where('user_id',$order_info['user_id'])->lock(true)->find();
  99. if($user_info['vip_endtime'] < time()){
  100. //过期了
  101. $vip_endtime = time() + (intval($args['days']) * 86400);
  102. }else{
  103. //追加vip
  104. $vip_endtime = $user_info['vip_endtime'] + (intval($args['days']) * 86400);
  105. }
  106. $update_data = [
  107. 'vip_endtime'=>$vip_endtime,
  108. ];
  109. $result = Db::name('user_wallet')->where('user_id',$order_info['user_id'])->update($update_data);
  110. if($result === false)
  111. {
  112. Db::rollback();
  113. filePut('VIP ios充值:验证out_trade_no='.$order_no.',逻辑续费vip时间失败');
  114. $this->error('充值失败');
  115. }
  116. // 修改订单状态
  117. $ros = Db::name('pay_order')->where(['out_trade_no' => $order_no])->update(['order_status'=>1,'notifytime'=>time()]);
  118. if($ros === false) {
  119. filePut('VIP ios充值:充值失败out_trade_no='.$order_no.','.$result['message'].','.'修改订单状态失败');
  120. Db::rollback();
  121. $this->error('充值失败');
  122. }
  123. Db::commit();
  124. $this->success('充值成功');
  125. //逻辑结束
  126. }
  127. ////////////////////////////////
  128. //金币充值
  129. public function gold_config_ios(){
  130. $list = Db::name('paygold_webcon_ios')->field('id,money,gold,bundle_id')->where('is_show',1)->order('weigh asc,id asc')->select();
  131. $data['goldconfig'] = $list;
  132. $wallet = model('wallet')->getWallet($this->auth->id);
  133. $data['wallet'] = $wallet;
  134. $data['money_to_gold'] = config('site.money_to_gold');
  135. $this->success('success',$data);
  136. }
  137. //充值金币 创建订单
  138. public function gold_recharge_ios(){
  139. $rc_id = input_post('rc_id',0);
  140. $pay_type = 'ios';
  141. $platform = 'app';
  142. $uid = $this->auth->id;
  143. if(!$rc_id){
  144. $this->error('请选择充值金额');
  145. }
  146. if(!$this->user_auth_limit()){
  147. $this->error('请先完成实名认证');
  148. }
  149. //赋值money
  150. $recharge_config = Db::name('paygold_webcon_ios')->where('id',$rc_id)->find();
  151. $money = $recharge_config['money'] ?: 0;
  152. $gold = $recharge_config['gold'] ?: 0;
  153. //
  154. if($money<=0)
  155. {
  156. $this->error('支付金额必须大于0');
  157. }
  158. if($money > 10000){
  159. $this->error('支付金额太大');
  160. }
  161. //创建订单
  162. $data['user_id'] = $uid;
  163. $data['out_trade_no'] = createUniqueNo('P',$uid); // 数据库订单号加密
  164. $data['order_amount'] = $money;
  165. $data['createtime'] = time();
  166. $data['pay_type'] = $pay_type;
  167. $data['platform'] = $platform;
  168. $data['order_status'] = 0;
  169. $data['table_name'] = 'gold_recharge';
  170. $data['table_id'] = 0;
  171. $data['args'] = json_encode(['gold'=>$gold]);
  172. $data['bundle_id'] = $recharge_config['bundle_id'];
  173. $orderid = Db::name('pay_order')->insertGetId($data);
  174. $this->success('success',$data['out_trade_no']);
  175. }
  176. //金币+vip,苹果内购支付回调,app请求的接口
  177. public function gold_notify_iosnew(){
  178. //苹果内购的验证收据
  179. $receipt_data = input('apple_receipt', '', 'trim');
  180. $out_trade_no = input('out_trade_no', '', 'trim');
  181. $transaction_id = input('transaction_id', '', 'trim');
  182. if (!$receipt_data || !$out_trade_no || !$transaction_id) {
  183. $this->error('缺少参数');
  184. }
  185. filePut("\r\n\r\n".'新请求');
  186. $prefix = 'ios充值,登录user_id:'.$this->auth->id.',out_trade_no:'.$out_trade_no.',传入transaction_id:'.$transaction_id.'。';
  187. filePut($prefix.'参数apple_receipt:'.$receipt_data);
  188. Db::startTrans();
  189. // 查找订单
  190. $order_map = [
  191. // 'user_id' => $this->auth->id,
  192. 'out_trade_no' => $out_trade_no,
  193. ];
  194. $order_info = Db::name('pay_order')->where($order_map)->lock(true)->find();
  195. if (!$order_info) {
  196. Db::rollback();
  197. filePut($prefix.'不存在的订单');
  198. $this->error('不存在的订单');
  199. }
  200. if ($order_info['order_status'] == 1) {
  201. Db::rollback();
  202. filePut($prefix.'充值早已完成');
  203. $this->success('充值已完成');
  204. }
  205. // 验证支付状态
  206. $result = $this->validate_apple_pay($receipt_data);
  207. if (!$result['status']) {// 验证不通过
  208. Db::rollback();
  209. filePut($prefix.'验证'.$result['message']);
  210. $this->error($result['message']);
  211. }
  212. $in_app = $result['data']['receipt']['in_app'];
  213. $only_trans = [];
  214. foreach($in_app as $key => $trans){
  215. if($trans['transaction_id'] == $transaction_id && $trans['product_id'] == $order_info['bundle_id']){
  216. $only_trans = $trans;
  217. }
  218. }
  219. if(empty($only_trans)){
  220. Db::rollback();
  221. filePut($prefix.'未找到匹配的交易,产品id'.$order_info['bundle_id'].',交易id'.$transaction_id);
  222. $this->error('未找到匹配的交易,产品id'.$order_info['bundle_id'].',交易id'.$transaction_id);
  223. }
  224. /*
  225. $count = count($result['data']['receipt']['in_app']);
  226. $use_count = $count - 1;
  227. $product_id = $result['data']['receipt']['in_app'][$use_count]['product_id'];
  228. $my_transaction_id = $result['data']['receipt']['in_app'][$use_count]['transaction_id'];
  229. if($product_id != $order_info['bundle_id']){
  230. Db::rollback();
  231. filePut($prefix.'验证'.'非法请求,请立刻停止product_id:'.$product_id.'!='.$order_info['bundle_id']);
  232. $this->error('非法请求,请立刻停止,产品id错误');
  233. }
  234. if($my_transaction_id != $transaction_id){
  235. Db::rollback();
  236. filePut($prefix.'验证'.'非法请求,请立刻停止transaction_id:'.$my_transaction_id.'!='.$transaction_id);
  237. $this->error('非法请求,请立刻停止,交易id错误');
  238. }*/
  239. //逻辑开始
  240. $args = json_decode($order_info['args'],true);
  241. //先充值
  242. if($order_info['table_name'] == 'gold_recharge'){
  243. $result = model('Wallet')->lockChangeAccountRemain($order_info['user_id'],'gold',$args['gold'],10, '金币充值','pay_order',$order_info['id']);
  244. if($result['status']===false)
  245. {
  246. filePut($prefix.'逻辑添加金币失败');
  247. Db::rollback();
  248. $this->error('充值失败');
  249. }
  250. }
  251. //先充值
  252. if($order_info['table_name'] == 'vip_recharge'){
  253. $user_info = Db::name('user_wallet')->where('user_id',$order_info['user_id'])->lock(true)->find();
  254. if($user_info['vip_endtime'] < time()){
  255. //过期了
  256. $vip_endtime = time() + (intval($args['days']) * 86400);
  257. }else{
  258. //追加vip
  259. $vip_endtime = $user_info['vip_endtime'] + (intval($args['days']) * 86400);
  260. }
  261. $update_data = [
  262. 'vip_endtime'=>$vip_endtime,
  263. ];
  264. $result = Db::name('user_wallet')->where('user_id',$order_info['user_id'])->update($update_data);
  265. if($result === false)
  266. {
  267. filePut($prefix.'逻辑续费vip时间失败');
  268. Db::rollback();
  269. $this->error('充值失败');
  270. }
  271. }
  272. // 修改订单状态
  273. $ros = Db::name('pay_order')->where(['id' => $order_info['id']])->update(['order_status'=>1,'transaction_id' => $transaction_id,'notifytime'=>time()]);
  274. if($ros === false) {
  275. filePut($prefix.'修改订单状态失败');
  276. Db::rollback();
  277. $this->error('充值失败');
  278. }
  279. Db::commit();
  280. filePut($prefix.'充值成功');
  281. $this->success('充值成功');
  282. //逻辑结束
  283. }
  284. //因前端不传入订单号,作废
  285. public function gold_notify_ios(){
  286. //苹果内购的验证收据
  287. $receipt_data = input('apple_receipt', '', 'trim');
  288. $order_no = input('order_no', '', 'trim');
  289. filePut('金币 ios充值:参数apple_receipt='.$receipt_data.',order_no='.$order_no);
  290. if (!$receipt_data || !$order_no) {
  291. $this->error('缺少参数');
  292. }
  293. Db::startTrans();
  294. // 查找订单
  295. $order_info = Db::name('pay_order')->where(['out_trade_no' => $order_no])->lock(true)->find();
  296. if (!$order_info) {
  297. Db::rollback();
  298. filePut('金币 ios充值:订单丢失out_trade_no='.$order_no);
  299. $this->error('订单丢失');
  300. }
  301. if ($order_info['order_status'] == 1) {
  302. Db::rollback();
  303. $this->success('充值成功');
  304. }
  305. // 验证支付状态
  306. $result = $this->validate_apple_pay($receipt_data);
  307. if (!$result['status']) {// 验证不通过
  308. Db::rollback();
  309. filePut('金币 ios充值:验证out_trade_no='.$order_no.','.$result['message']);
  310. $this->error($result['message']);
  311. }
  312. $count = count($result['data']['receipt']['in_app']);
  313. $use_count = $count - 1;
  314. $args = json_decode($order_info['args'],true);
  315. if ($result['data']['receipt']['in_app'][$use_count]['product_id'] != $order_info['bundle_id']) {
  316. Db::rollback();
  317. filePut('金币 ios充值:非法请求,请立刻停止out_trade_no='.$order_no.','.$result['message'].','.$result['data']['receipt']['in_app'][$use_count]['product_id'].'!='.$order_info['bundle_id']);
  318. $this->error('非法请求,请立刻停止');
  319. }
  320. //逻辑开始
  321. //先充值
  322. $result = model('Wallet')->lockChangeAccountRemain($order_info['user_id'],'gold',$args['gold'],10, '金币充值','pay_order',$order_info['id']);
  323. if($result['status']===false)
  324. {
  325. filePut('金币 ios充值:验证out_trade_no='.$order_no.',逻辑添加金币失败');
  326. Db::rollback();
  327. return false;
  328. }
  329. // 修改订单状态
  330. $ros = Db::name('pay_order')->where(['out_trade_no' => $order_no])->update(['order_status'=>1,'notifytime'=>time()]);
  331. if($ros === false) {
  332. filePut('金币 ios充值:充值失败out_trade_no='.$order_no.','.$result['message'].','.'修改订单状态失败');
  333. Db::rollback();
  334. $this->error('充值失败');
  335. }
  336. Db::commit();
  337. $this->success('充值成功');
  338. //逻辑结束
  339. }
  340. ////////////////////////////////////
  341. //苹果自动扣费回调
  342. public function auto_renewal_vip_notify(){
  343. $this->notify_log_start('ios');
  344. }
  345. ///////////////////////////////////////////////////////////////////////////////////////////////
  346. //异步日志
  347. private function notify_log_start($paytype = 'ios'){
  348. //记录支付回调数据
  349. ignore_user_abort(); // run script in background
  350. set_time_limit(30);
  351. // 日志文件 start
  352. $log_base_dir = '../paylog/'.$paytype.'/';
  353. if (!is_dir($log_base_dir))
  354. {
  355. mkdir($log_base_dir, 0770, true);
  356. @chmod($log_base_dir, 0770);
  357. }
  358. $notify_file = $log_base_dir.'notify.txt';
  359. if(!file_exists($notify_file)) {
  360. @touch($notify_file);
  361. @chmod($notify_file, 0770);
  362. }
  363. if(filesize($notify_file)>5242880)//大于5M自动切换
  364. {
  365. rename($notify_file, $log_base_dir.'notify_'.date('Y_m_d_H_i_s').'.txt');
  366. }
  367. if(!file_exists($notify_file)) {
  368. @touch($notify_file);
  369. @chmod($notify_file, 0770);
  370. }
  371. // 日志文件 end
  372. //开始写入
  373. $_REQUEST = isset($_REQUEST) ? $_REQUEST : array();
  374. if($_REQUEST && $paytype == 'alipay') {
  375. file_put_contents($notify_file, "\r\n\r\n".date('Y-m-d H:i:s')." [notify][入口接收request]".json_encode($_REQUEST), FILE_APPEND);
  376. } else {
  377. $xml = file_get_contents("php://input");
  378. file_put_contents($notify_file, "\r\n\r\n".date('Y-m-d H:i:s')." [notify][入口接收php://input流原始数据] \n".$xml, FILE_APPEND);
  379. $xmlObj = simplexml_load_string($xml, 'SimpleXMLElement', LIBXML_NOCDATA);
  380. file_put_contents($notify_file, "\r\n\r\n".date('Y-m-d H:i:s')." [notify][入口接收php://input流] ".json_encode($xmlObj), FILE_APPEND);
  381. }
  382. ini_set('display_errors','On');
  383. return $notify_file;
  384. }
  385. /**
  386. * 验证AppStore内付
  387. * @param string $receipt_data 付款后凭证
  388. * @return array 验证是否成功
  389. */
  390. function validate_apple_pay($receipt_data = '') {
  391. // 验证参数
  392. if (strlen($receipt_data) < 20) {
  393. $result = array(
  394. 'status' => false,
  395. 'message' => '非法参数'
  396. );
  397. return $result;
  398. }
  399. // 请求验证
  400. $html = $this->curl($receipt_data);
  401. $data = json_decode($html, true);
  402. $data['sandbox'] = '0';
  403. // p($data);die;
  404. if ($data['status'] == '21002') {
  405. $result = array(
  406. 'status' => false,
  407. 'message' => 'status:21002'
  408. );
  409. return $result;
  410. }
  411. // 如果是沙盒数据 则验证沙盒模式 21008;正式数据 21007
  412. if ($data['status'] == '21007') {
  413. // 请求验证
  414. $html = $this->curl($receipt_data, 1);
  415. $data = json_decode($html, true);
  416. $data['sandbox'] = '1';
  417. }
  418. if (isset($_GET['debug'])) {
  419. exit(json_encode($data));
  420. }
  421. if ($data['receipt']['bundle_id'] != 'com.huxiu.tken') {
  422. $result = array(
  423. 'status' => false,
  424. 'message' => '非法请求',
  425. 'data' => $data
  426. );
  427. return $result;
  428. }
  429. // 判断是否购买成功
  430. if (intval($data['status']) === 0) {
  431. $result = array(
  432. 'status' => true,
  433. 'message' => '购买成功',
  434. 'data' => $data
  435. );
  436. } else {
  437. $result = array(
  438. 'status' => false,
  439. 'message' => '购买失败 status:' . $data['status']
  440. );
  441. }
  442. return $result;
  443. }
  444. /**
  445. * 0 票据校验成功
  446. * 21000 App Store不能读取你提供的JSON对象25
  447. * 21002 receipt-data域的数据有问题
  448. * 21003 receipt无法通过验证
  449. * 21004 提供的shared secret不匹配你账号中的shared secret
  450. * 21005 receipt服务器当前不可用
  451. * 21006 receipt合法,但是订阅已过期。服务器接收到这个状态码时,receipt数据仍然会解码并一起发送
  452. * 21007 receipt是Sandbox receipt,但却发送至生产系统的验证服务
  453. * 21008 receipt是生产receipt,但却发送至Sandbox环境的验证服务
  454. */
  455. //苹果也是建议这个校验逻辑由服务端完成。服务器需要先去请求正式环境。如果receipt是正式环境的,那么这个时候苹果会返回(21007)告诉我们这个是沙盒的receipt,那么服务器再去请求sandbox环境。
  456. function curl($receipt_data,$sandbox = 0) {
  457. //小票信息
  458. $POSTFIELDS = [
  459. 'receipt-data' => $receipt_data,
  460. 'password' => 'd6c4cae953804133b40e44418dce2afb'
  461. ];
  462. $POSTFIELDS = json_encode($POSTFIELDS, 320);
  463. //正式购买地址 沙盒购买地址
  464. $url_buy = "https://buy.itunes.apple.com/verifyReceipt";
  465. $url_sandbox = "https://sandbox.itunes.apple.com/verifyReceipt";
  466. //默认后台控制
  467. if (config('site.ios_pay_sandbox') > 0 ) {
  468. $url = $url_buy;
  469. } else {
  470. $url = $url_sandbox;
  471. }
  472. //强制沙盒
  473. if($sandbox == 1){
  474. $url = $url_sandbox;
  475. }
  476. $ch = curl_init($url);
  477. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  478. curl_setopt($ch, CURLOPT_POST, true);
  479. curl_setopt($ch, CURLOPT_POSTFIELDS, $POSTFIELDS);
  480. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); //这两行一定要加,不加会报SSL 错误
  481. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  482. $response = curl_exec($ch);
  483. $errno = curl_errno($ch);
  484. curl_close($ch);
  485. if ($errno != 0) {
  486. return $errno;
  487. } else {
  488. return $response;
  489. }
  490. }
  491. }