文档 https://mp.weixin.qq.com/wiki?t=resource/res_main&id=mp1421141115
微信 JS 接口签名校验工具 https://mp.weixin.qq.com/debug/cgi-bin/sandbox?t=jsapisign
<?php
namespace app\Services;
use RedisFacade;
class WxShare {
private $appId;
private $appSecret;
public function __construct($appId, $appSecret) {
$this->appId = $appId;
$this->appSecret = $appSecret;
}
public function getSignPackage($url) {
$jsapiTicket = $this->getJsApiTicket();
// 注意 URL 一定要动态获取,不能 hardcode.Ajax获取的时候前端传递 location.href.split('#')[0]
$protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' || $_SERVER['SERVER_PORT'] == 443) ? "https://" : "http://";
// $url = "$protocol$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]";
$timestamp = time();
$nonceStr = $this->createNonceStr();
// 这里参数的顺序要按照 key 值 ASCII 码升序排序
$string = "jsapi_ticket=$jsapiTicket&noncestr=$nonceStr×tamp=$timestamp&url=$url";
$signature = sha1($string);
$signPackage = array(
"appId" => $this->appId,
"nonceStr" => $nonceStr,
"timestamp" => $timestamp,
"url" => $url,
"signature" => $signature,
"rawString" => $string
);
return $signPackage;
}
private function createNonceStr($length = 16) {
$chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
$str = "";
for ($i = 0; $i < $length; $i++) {
$str .= substr($chars, mt_rand(0, strlen($chars) - 1), 1);
}
return $str;
}
private function getJsApiTicket() {
// jsapi_ticket 应该全局存储与更新,以下代码以写入到文件中做示例
$key_ticket = 'wechatshare_ticket';
$jsondata = RedisFacade::get($key_ticket);
if (empty($jsondata)) {
$accessToken = $this->getAccessToken();
// 如果是企业号用以下 URL 获取 ticket
// $url = "https://qyapi.weixin.qq.com/cgi-bin/get_jsapi_ticket?access_token=$accessToken";
$url = "https://api.weixin.qq.com/cgi-bin/ticket/getticket?type=jsapi&access_token=$accessToken";
$res = json_decode($this->httpGet($url));
$ticket = $res->ticket;
if ($ticket) {
$jsondata = serialize($ticket);
RedisFacade::set($key_ticket,$jsondata);
RedisFacade::expire($key_ticket, 1800);
}
} else {
//$ticket = $data->jsapi_ticket;
$ticket = unserialize($jsondata);
}
return $ticket;
}
private function getAccessToken() {
// access_token 应该全局存储与更新,以下代码以写入到文件中做示例
$key_token = 'wechatshare_token';
$jsondata = RedisFacade::get($key_token);
if (empty($jsondata)) {
// 如果是企业号用以下URL获取access_token
// $url = "https://qyapi.weixin.qq.com/cgi-bin/gettoken?corpid=$this->appId&corpsecret=$this->appSecret";
$url = "https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid=$this->appId&secret=$this->appSecret";
$ret = $this->httpGet($url);
$res = json_decode($ret);
$access_token = $res->access_token;
if ($access_token) {
$jsondata = serialize($access_token);
RedisFacade::set($key_token,$jsondata);
RedisFacade::expire($key_token, 1800);
}
} else {
$access_token = unserialize($jsondata);
}
return $access_token;
}
private function httpGet($url) {
$curl = curl_init();
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
curl_setopt($curl, CURLOPT_TIMEOUT, 500);
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, false);
curl_setopt($curl, CURLOPT_URL, $url);
$res = curl_exec($curl);
$errors = curl_error($curl);
\Log::info("Share",['ret'=>json_encode($res),'error'=>$errors]);
curl_close($curl);
return $res;
}
}
先登录公众号 功能设置”里填写“JS接口安全域名” 不加 http 一个月只能改3次,还要在根目录上传一个TXT问题
invalid signature 签名错误 可能是 Ajax来获取签名的时候 url 和访问页面的url不同
获取access_token时却报出下列错误信息:
{"errcode":40164,"errmsg":"invalid ip 61.172.68.219, not in whitelist hint: [KJZfAa0644e575]"}
{"ret":""{"errcode":41001,"errmsg":"access_token missing hint:[FOOOrA0226vr29!]"}"","error":""}
解读:错误代码:40164,
错误信息:无效ip,不在白名单中
于是开始往IP白名单这个方向思考,因为换了个地方,网络不同,电脑的ip地址变了。所以要再设置一下白名单
二、解决方法
登录公众平台,开发->基本配置->IP白名单->查看->修改->将ip地址添加进去即可
文档 https://mp.weixin.qq.com/wiki?t=resource/res_main&id=mp1421141115
微信 JS 接口签名校验工具 https://mp.weixin.qq.com/debug/cgi-bin/sandbox?t=jsapisign
先登录公众号 功能设置”里填写“JS接口安全域名” 不加 http 一个月只能改3次,还要在根目录上传一个TXT问题
invalid signature 签名错误 可能是 Ajax来获取签名的时候 url 和访问页面的url不同
获取access_token时却报出下列错误信息:
{"errcode":40164,"errmsg":"invalid ip 61.172.68.219, not in whitelist hint: [KJZfAa0644e575]"}
{"ret":""{"errcode":41001,"errmsg":"access_token missing hint:[FOOOrA0226vr29!]"}"","error":""}
解读:错误代码:40164,
错误信息:无效ip,不在白名单中
于是开始往IP白名单这个方向思考,因为换了个地方,网络不同,电脑的ip地址变了。所以要再设置一下白名单
二、解决方法
登录公众平台,开发->基本配置->IP白名单->查看->修改->将ip地址添加进去即可