jssdk.php 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113
  1. <?php
  2. class JSSDK {
  3. private $appId;
  4. private $appSecret;
  5. public function __construct($appId, $appSecret) {
  6. $this->appId = $appId;
  7. $this->appSecret = $appSecret;
  8. }
  9. public function getSignPackage() {
  10. $jsapiTicket = $this->getJsApiTicket();
  11. // 注意 URL 一定要动态获取,不能 hardcode.
  12. $protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' || $_SERVER['SERVER_PORT'] == 443) ? "https://" : "http://";
  13. $url = "$protocol$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]";
  14. $timestamp = time();
  15. $nonceStr = $this->createNonceStr();
  16. // 这里参数的顺序要按照 key 值 ASCII 码升序排序
  17. $string = "jsapi_ticket=$jsapiTicket&noncestr=$nonceStr&timestamp=$timestamp&url=$url";
  18. $signature = sha1($string);
  19. $signPackage = array(
  20. "appId" => $this->appId,
  21. "nonceStr" => $nonceStr,
  22. "timestamp" => $timestamp,
  23. "url" => $url,
  24. "signature" => $signature,
  25. "rawString" => $string
  26. );
  27. return $signPackage;
  28. }
  29. private function createNonceStr($length = 16) {
  30. $chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
  31. $str = "";
  32. for ($i = 0; $i < $length; $i++) {
  33. $str .= substr($chars, mt_rand(0, strlen($chars) - 1), 1);
  34. }
  35. return $str;
  36. }
  37. private function getJsApiTicket() {
  38. // jsapi_ticket 应该全局存储与更新,以下代码以写入到文件中做示例
  39. $data = json_decode($this->get_php_file("jsapi_ticket.php"));
  40. if ($data->expire_time < time()) {
  41. $accessToken = $this->getAccessToken();
  42. // 如果是企业号用以下 URL 获取 ticket
  43. // $url = "https://qyapi.weixin.qq.com/cgi-bin/get_jsapi_ticket?access_token=$accessToken";
  44. $url = "https://api.weixin.qq.com/cgi-bin/ticket/getticket?type=jsapi&access_token=$accessToken";
  45. $res = json_decode($this->httpGet($url));
  46. $ticket = $res->ticket;
  47. if ($ticket) {
  48. $data->expire_time = time() + 7000;
  49. $data->jsapi_ticket = $ticket;
  50. $this->set_php_file("jsapi_ticket.php", json_encode($data));
  51. }
  52. } else {
  53. $ticket = $data->jsapi_ticket;
  54. }
  55. return $ticket;
  56. }
  57. private function getAccessToken() {
  58. // access_token 应该全局存储与更新,以下代码以写入到文件中做示例
  59. $data = json_decode($this->get_php_file("access_token.php"));
  60. if ($data->expire_time < time()) {
  61. // 如果是企业号用以下URL获取access_token
  62. // $url = "https://qyapi.weixin.qq.com/cgi-bin/gettoken?corpid=$this->appId&corpsecret=$this->appSecret";
  63. $url = "https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid=$this->appId&secret=$this->appSecret";
  64. $res = json_decode($this->httpGet($url));
  65. $access_token = $res->access_token;
  66. if ($access_token) {
  67. $data->expire_time = time() + 7000;
  68. $data->access_token = $access_token;
  69. $this->set_php_file("access_token.php", json_encode($data));
  70. }
  71. } else {
  72. $access_token = $data->access_token;
  73. }
  74. return $access_token;
  75. }
  76. private function httpGet($url) {
  77. $curl = curl_init();
  78. curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
  79. curl_setopt($curl, CURLOPT_TIMEOUT, 500);
  80. // 为保证第三方服务器与微信服务器之间数据传输的安全性,所有微信接口采用https方式调用,必须使用下面2行代码打开ssl安全校验。
  81. // 如果在部署过程中代码在此处验证失败,请到 http://curl.haxx.se/ca/cacert.pem 下载新的证书判别文件。
  82. curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, true);
  83. curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, true);
  84. curl_setopt($curl, CURLOPT_URL, $url);
  85. $res = curl_exec($curl);
  86. curl_close($curl);
  87. return $res;
  88. }
  89. private function get_php_file($filename) {
  90. return trim(substr(file_get_contents($filename), 15));
  91. }
  92. private function set_php_file($filename, $content) {
  93. $fp = fopen($filename, "w");
  94. fwrite($fp, "<?php exit();?>" . $content);
  95. fclose($fp);
  96. }
  97. }