AlipaySignature.cs 35 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Text;
  4. using System.IO;
  5. using Org.BouncyCastle.X509;
  6. using PaySharp.Alipay.Util.Asymmetric;
  7. namespace PaySharp.Alipay.Util
  8. {
  9. /// <summary>
  10. /// 支付宝签名工具类
  11. /// </summary>
  12. public static class AlipaySignature
  13. {
  14. /** 默认编码字符集 */
  15. private static readonly string DEFAULT_CHARSET = "GBK";
  16. /// <summary>
  17. /// 从支付宝公钥证书中提取支付宝公钥
  18. /// </summary>
  19. /// <param name="certPath">证书路径</param>
  20. /// <returns>公钥字符串</returns>
  21. public static string ExtractPemPublicKeyFromCert(string certPath)
  22. {
  23. ArgumentValidator.CheckArgument(!String.IsNullOrEmpty(certPath), "证书文件路径不可为空。");
  24. X509Certificate alipayPublicKeyCert = AntCertificationUtil.ParseCert(File.ReadAllText(certPath));
  25. return AntCertificationUtil.ExtractPemPublicKeyFromCert(alipayPublicKeyCert);
  26. }
  27. /// <summary>
  28. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法
  29. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  30. /// </summary>
  31. /// <param name="parameters">待验签的参数集合</param>
  32. /// <param name="alipayPublicCertPath">支付宝公钥证书路径</param>
  33. /// <param name="charset">参数编码字符集</param>
  34. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  35. /// <returns>true:验证成功;false:验证失败</returns>
  36. public static bool CertVerifyV1(IDictionary<string, string> parameters, string alipayPublicCertPath, string charset, string signType)
  37. {
  38. return RSACertCheckV1(parameters, alipayPublicCertPath, charset, signType);
  39. }
  40. /// <summary>
  41. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法CertVerifyV1
  42. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  43. /// </summary>
  44. /// <param name="parameters">待验签的参数集合</param>
  45. /// <param name="alipayPublicCertPath">支付宝公钥证书路径</param>
  46. /// <param name="charset">参数编码字符集</param>
  47. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  48. /// <returns>true:验证成功;false:验证失败</returns>
  49. public static bool RSACertCheckV1(IDictionary<string, string> parameters, string alipayPublicCertPath, string charset, string signType)
  50. {
  51. ArgumentValidator.CheckNotNull(parameters, "parameters参数不可为Null");
  52. ArgumentValidator.CheckArgument(!String.IsNullOrEmpty(alipayPublicCertPath), "证书文件路径不可为空。");
  53. string alipayPublicKey = ExtractPemPublicKeyFromCert(alipayPublicCertPath);
  54. return RSACheckV1(parameters, alipayPublicKey, charset, signType, false);
  55. }
  56. /// <summary>
  57. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法
  58. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  59. /// </summary>
  60. /// <param name="parameters">待验签字符串</param>
  61. /// <param name="publicKey">支付宝公钥</param>
  62. /// <param name="charset">参数编码字符集</param>
  63. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  64. /// <param name="keyFromFile">是否从文件加载支付宝公钥内容。
  65. /// 如果该参数为true,则publicKey为公钥文件路径;
  66. /// 如果该参数为false,则publicKey为公钥内容
  67. /// </param>
  68. /// <returns>true:验证成功;false:验证失败</returns>
  69. public static bool VerifyV1(IDictionary<string, string> parameters, string publicKey, string charset, string signType, bool keyFromFile)
  70. {
  71. return RSACheckV1(parameters, publicKey, charset, signType, keyFromFile);
  72. }
  73. /// <summary>
  74. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法VerifyV1
  75. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  76. /// </summary>
  77. /// <param name="parameters">待验签字符串</param>
  78. /// <param name="publicKey">支付宝公钥</param>
  79. /// <param name="charset">参数编码字符集</param>
  80. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  81. /// <param name="keyFromFile">是否从文件加载支付宝公钥内容。
  82. /// 如果该参数为true,则publicKey为公钥文件路径;
  83. /// 如果该参数为false,则publicKey为公钥内容
  84. /// </param>
  85. /// <returns>true:验证成功;false:验证失败</returns>
  86. public static bool RSACheckV1(IDictionary<string, string> parameters, string publicKey, string charset, string signType, bool keyFromFile)
  87. {
  88. ArgumentValidator.CheckNotNull(parameters, "parameters参数不可为Null");
  89. string sign = parameters["sign"];
  90. parameters.Remove("sign");
  91. parameters.Remove("sign_type");
  92. string signContent = GetSignContent(parameters);
  93. return RSACheckContent(signContent, sign, publicKey, charset, signType, keyFromFile);
  94. }
  95. /// <summary>
  96. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法
  97. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  98. /// </summary>
  99. /// <param name="parameters">待验签的参数集合</param>
  100. /// <param name="alipayPublicCertPath">支付宝公钥证书路径</param>
  101. /// <param name="charset">参数编码字符集</param>
  102. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  103. /// <returns>true:验证成功;false:验证失败</returns>
  104. public static bool CertVerifyV2(IDictionary<string, string> parameters, string alipayPublicCertPath, string charset, string signType)
  105. {
  106. return RSACertCheckV2(parameters, alipayPublicCertPath, charset, signType);
  107. }
  108. /// <summary>
  109. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法CertVerifyV2
  110. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  111. /// </summary>
  112. /// <param name="parameters">待验签的参数集合</param>
  113. /// <param name="alipayPublicCertPath">支付宝公钥证书路径</param>
  114. /// <param name="charset">参数编码字符集</param>
  115. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  116. /// <returns>true:验证成功;false:验证失败</returns>
  117. public static bool RSACertCheckV2(IDictionary<string, string> parameters, string alipayPublicCertPath, string charset, string signType)
  118. {
  119. ArgumentValidator.CheckNotNull(parameters, "parameters参数不可为Null");
  120. string alipayPublicKey = ExtractPemPublicKeyFromCert(alipayPublicCertPath);
  121. return RSACheckV2(parameters, alipayPublicKey, charset, signType, false);
  122. }
  123. /// <summary>
  124. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法
  125. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  126. /// </summary>
  127. /// <param name="parameters">待验签字符串</param>
  128. /// <param name="publicKey">支付宝公钥</param>
  129. /// <param name="charset">参数编码字符集</param>
  130. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  131. /// <param name="keyFromFile">是否从文件加载支付宝公钥内容。
  132. /// 如果该参数为true,则publicKey为公钥文件路径;
  133. /// 如果该参数为false,则publicKey为公钥内容
  134. /// </param>
  135. /// <returns>true:验证成功;false:验证失败</returns>
  136. public static bool VerifyV2(IDictionary<string, string> parameters, string publicKey, string charset, string signType, bool keyFromFile)
  137. {
  138. return RSACheckV2(parameters, publicKey, charset, signType, keyFromFile);
  139. }
  140. /// <summary>
  141. /// 异步通知参数验签,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法VerifyV2
  142. /// V1版本方法将删除sign_type参数再进行验签,V2版本方法则不会
  143. /// </summary>
  144. /// <param name="parameters">待验签字符串</param>
  145. /// <param name="publicKey">支付宝公钥</param>
  146. /// <param name="charset">参数编码字符集</param>
  147. /// <param name="signType">签名类型,RSA2或RSA、SM2</param>
  148. /// <param name="keyFromFile">是否从文件加载支付宝公钥内容。
  149. /// 如果该参数为true,则publicKey为公钥文件路径;
  150. /// 如果该参数为false,则publicKey为公钥内容
  151. /// </param>
  152. /// <returns>true:验证成功;false:验证失败</returns>
  153. public static bool RSACheckV2(IDictionary<string, string> parameters, string publicKey, string charset, string signType, bool keyFromFile)
  154. {
  155. ArgumentValidator.CheckNotNull(parameters, "parameters参数不可为Null");
  156. string sign = parameters["sign"];
  157. parameters.Remove("sign");
  158. string signContent = GetSignContent(parameters);
  159. return RSACheckContent(signContent, sign, publicKey, charset, signType, keyFromFile);
  160. }
  161. /// <summary>
  162. /// 验证指定内容的签名,支持RSA、RSA2、SM2三种算法
  163. /// </summary>
  164. /// <param name="content">待验签的内容</param>
  165. /// <param name="sign">签名字符串</param>
  166. /// <param name="publicKey">支付宝公钥</param>
  167. /// <param name="charset">字符集编码</param>
  168. /// <param name="signType">签名算法类型,RSA2或RSA、SM2</param>
  169. /// <param name="keyFromFile">是否从文件加载支付宝公钥内容。
  170. /// 如果该参数为true,则publicKey为公钥文件路径;
  171. /// 如果该参数为false,则publicKey为公钥内容
  172. /// </param>
  173. /// <returns>true:验证成功;false:验证失败</returns>
  174. public static bool VerifyContent(string content, string sign, string publicKey, string charset, string signType, bool keyFromFile)
  175. {
  176. return RSACheckContent(content, sign, publicKey, charset, signType, keyFromFile);
  177. }
  178. /// <summary>
  179. /// 验证指定内容的签名,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法VerifyContent
  180. /// </summary>
  181. /// <param name="content">待验签的内容</param>
  182. /// <param name="sign">签名字符串</param>
  183. /// <param name="publicKey">支付宝公钥</param>
  184. /// <param name="charset">字符集编码</param>
  185. /// <param name="signType">签名算法类型,RSA2或RSA、SM2</param>
  186. /// <param name="keyFromFile">是否从文件加载支付宝公钥内容。
  187. /// 如果该参数为true,则publicKey为公钥文件路径;
  188. /// 如果该参数为false,则publicKey为公钥内容
  189. /// </param>
  190. /// <returns>true:验证成功;false:验证失败</returns>
  191. public static bool RSACheckContent(string content, string sign, string publicKey, string charset, string signType, bool keyFromFile)
  192. {
  193. if (keyFromFile)
  194. {
  195. ArgumentValidator.CheckArgument(!String.IsNullOrEmpty(publicKey), "公钥文件路径不可为空。");
  196. publicKey = File.ReadAllText(publicKey);
  197. }
  198. return AsymmetricManager.GetByName(signType).Verify(content, charset, publicKey, sign);
  199. }
  200. /// <summary>
  201. /// 对指定参数进行签名,支持RSA、RSA2、SM2三种算法
  202. /// </summary>
  203. /// <param name="parameters">参数集合</param>
  204. /// <param name="privateKey">商户私钥</param>
  205. /// <param name="charset">字符集编码</param>
  206. /// <param name="signType">签名算法类型,RSA2或RSA、SM2</param>
  207. /// <param name="keyFromFile">是否从私钥证书文件中加载私钥
  208. /// 如果该参数为true,privateKey为私钥证书文件路径;
  209. /// 如果该参数为false,privateKey为私钥内容字符串
  210. /// </param>
  211. /// <returns>签名字符串</returns>
  212. public static string Sign(IDictionary<string, string> parameters, string privateKey, string charset, string signType, bool keyFromFile)
  213. {
  214. return RSASign(parameters, privateKey, charset, signType, keyFromFile);
  215. }
  216. /// <summary>
  217. /// 对指定参数进行签名,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法Sign
  218. /// </summary>
  219. /// <param name="parameters">参数集合</param>
  220. /// <param name="privateKey">商户私钥</param>
  221. /// <param name="charset">字符集编码</param>
  222. /// <param name="signType">签名算法类型,RSA2或RSA、SM2</param>
  223. /// <param name="keyFromFile">是否从私钥证书文件中加载私钥
  224. /// 如果该参数为true,privateKey为私钥证书文件路径;
  225. /// 如果该参数为false,privateKey为私钥内容字符串
  226. /// </param>
  227. /// <returns>签名字符串</returns>
  228. public static string RSASign(IDictionary<string, string> parameters, string privateKey, string charset, string signType, bool keyFromFile)
  229. {
  230. ArgumentValidator.CheckNotNull(parameters, "parameters参数不可为Null");
  231. string signContent = GetSignContent(parameters);
  232. return RSASignCharSet(signContent, privateKey, charset, signType, keyFromFile);
  233. }
  234. /// <summary>
  235. /// 对指定内容进行签名,支持RSA、RSA2、SM2三种算法
  236. /// </summary>
  237. /// <param name="data">内容字符串</param>
  238. /// <param name="privateKey">商户私钥</param>
  239. /// <param name="charset">字符集编码</param>
  240. /// <param name="signType">签名算法类型,RSA2或RSA、SM2</param>
  241. /// <param name="keyFromFile">是否从私钥证书文件中加载私钥
  242. /// 如果该参数为true,privateKey为私钥证书文件路径;
  243. /// 如果该参数为false,privateKey为私钥内容字符串
  244. /// </param>
  245. /// <returns>签名字符串</returns>
  246. public static string Sign(string data, string privateKey, string charset, string signType, bool keyFromFile)
  247. {
  248. return RSASign(data, privateKey, charset, signType, keyFromFile);
  249. }
  250. /// <summary>
  251. /// 对指定内容进行签名,支持RSA、RSA2、SM2三种算法,推荐替换为相同功能的方法Sign
  252. /// </summary>
  253. /// <param name="data">内容字符串</param>
  254. /// <param name="privateKey">商户私钥</param>
  255. /// <param name="charset">字符集编码</param>
  256. /// <param name="signType">签名算法类型,RSA2或RSA、SM2</param>
  257. /// <param name="keyFromFile">是否从私钥证书文件中加载私钥
  258. /// 如果该参数为true,privateKey为私钥证书文件路径;
  259. /// 如果该参数为false,privateKey为私钥内容字符串
  260. /// </param>
  261. /// <returns>签名字符串</returns>
  262. public static string RSASign(string data, string privateKey, string charset, string signType, bool keyFromFile)
  263. {
  264. return RSASignCharSet(data, privateKey, charset, signType, keyFromFile);
  265. }
  266. /// <summary>
  267. /// 验签并解密,目前仅适用于生活号
  268. /// </summary>
  269. /// <param name="parameters">待验签并解密的参数</param>
  270. /// <param name="alipayPublicKey">支付宝公钥字符串,用于验签</param>
  271. /// <param name="cusPrivateKey">商户私钥字符串,用于解密</param>
  272. /// <param name="isCheckSign">是否检查签名</param>
  273. /// <param name="isDecrypt">是否解密</param>
  274. /// <param name="signType">非对称加密算法类型,RSA2或RSA、SM2</param>
  275. /// <param name="keyFromFile">是否从文件加载支付宝公钥和商户私钥
  276. /// 如果该参数为true,alipayPublicKey为公钥文件路径,cusPrivateKey为私钥证书文件路径;
  277. /// 如果该参数为false,则publicKeyPem为公钥内容字符串,cusPrivateKey为私钥内容字符串
  278. /// </param>
  279. /// <returns>验签解密后的内容</returns>
  280. public static string CheckSignAndDecrypt(IDictionary<string, string> parameters, string alipayPublicKey, string cusPrivateKey,
  281. bool isCheckSign, bool isDecrypt, string signType, bool keyFromFile)
  282. {
  283. ArgumentValidator.CheckNotNull(parameters, "parameters参数不可为Null");
  284. string charset = parameters["charset"];
  285. string bizContent = parameters["biz_content"];
  286. if (isCheckSign)
  287. {
  288. if (!RSACheckV2(parameters, alipayPublicKey, charset, signType, keyFromFile))
  289. {
  290. throw new Exception("rsaCheck failure:rsaParams=" + parameters);
  291. }
  292. }
  293. if (isDecrypt)
  294. {
  295. return RSADecrypt(bizContent, cusPrivateKey, charset, signType, keyFromFile);
  296. }
  297. return bizContent;
  298. }
  299. /// <summary>
  300. /// 加密并加签,目前仅适用于生活号
  301. /// </summary>
  302. /// <param name="bizContent">待加密和加签的原文</param>
  303. /// <param name="alipayPublicKey">支付宝公钥字符串,用于加密</param>
  304. /// <param name="cusPrivateKey">商户私钥字符串,用于加签</param>
  305. /// <param name="charset">字符集编码</param>
  306. /// <param name="isEncrypt">是否需要加密</param>
  307. /// <param name="isSign">是否需要加签</param>
  308. /// <param name="signType">非对称加密算法类型,RSA或RSA2、SM2</param>
  309. /// <param name="keyFromFile">是否从文件加载支付宝公钥和商户私钥
  310. /// 如果该参数为true,alipayPublicKey为公钥文件路径,cusPrivateKey为私钥证书文件路径;
  311. /// 如果该参数为false,则publicKeyPem为公钥内容字符串,cusPrivateKey为私钥内容字符串
  312. /// </param>
  313. /// <returns>加密加签后的内容</returns>
  314. public static string EncryptAndSign(string bizContent, string alipayPublicKey, string cusPrivateKey, string charset,
  315. bool isEncrypt, bool isSign, string signType, bool keyFromFile)
  316. {
  317. StringBuilder sb = new StringBuilder();
  318. if (string.IsNullOrEmpty(charset))
  319. {
  320. charset = DEFAULT_CHARSET;
  321. }
  322. sb.Append("<?xml version=\"1.0\" encoding=\"" + charset + "\"?>");
  323. if (isEncrypt)
  324. {
  325. // 加密
  326. sb.Append("<alipay>");
  327. String encrypted = RSAEncrypt(bizContent, alipayPublicKey, charset, keyFromFile);
  328. sb.Append("<response>" + encrypted + "</response>");
  329. sb.Append("<encryption_type>" + signType + "</encryption_type>");
  330. if (isSign)
  331. {
  332. String sign = RSASign(encrypted, cusPrivateKey, charset, signType, keyFromFile);
  333. sb.Append("<sign>" + sign + "</sign>");
  334. sb.Append("<sign_type>" + signType + "</sign_type>");
  335. }
  336. sb.Append("</alipay>");
  337. }
  338. else if (isSign)
  339. {
  340. // 不加密,但需要签名
  341. sb.Append("<alipay>");
  342. sb.Append("<response>" + bizContent + "</response>");
  343. String sign = RSASign(bizContent, cusPrivateKey, charset, signType, keyFromFile);
  344. sb.Append("<sign>" + sign + "</sign>");
  345. sb.Append("<sign_type>" + signType + "</sign_type>");
  346. sb.Append("</alipay>");
  347. }
  348. else
  349. {
  350. // 不加密,不加签
  351. sb.Append(bizContent);
  352. }
  353. return sb.ToString();
  354. }
  355. public static string GetSignContent(IDictionary<string, string> parameters)
  356. {
  357. // 第一步:把字典按Key的字母顺序排序
  358. IDictionary<string, string> sortedParams = new SortedDictionary<string, string>(parameters, StringComparer.Ordinal);
  359. IEnumerator<KeyValuePair<string, string>> dem = sortedParams.GetEnumerator();
  360. // 第二步:把所有参数名和参数值串在一起
  361. StringBuilder query = new StringBuilder("");
  362. while (dem.MoveNext())
  363. {
  364. string key = dem.Current.Key;
  365. string value = dem.Current.Value;
  366. if (!string.IsNullOrEmpty(key) && !string.IsNullOrEmpty(value))
  367. {
  368. query.Append(key).Append("=").Append(value).Append("&");
  369. }
  370. }
  371. string content = query.ToString().Substring(0, query.Length - 1);
  372. return content;
  373. }
  374. public static string RSASignCharSet(string data, string privateKeyPem, string charset, string signType, bool keyFromFile)
  375. {
  376. if (keyFromFile)
  377. {
  378. ArgumentValidator.CheckArgument(!String.IsNullOrEmpty(privateKeyPem), "私钥文件路径不可为空。");
  379. privateKeyPem = LoadPrivateKeyFromRSACertFile(privateKeyPem);
  380. }
  381. return AsymmetricManager.GetByName(signType).Sign(data, charset, privateKeyPem);
  382. }
  383. public static string RSAEncrypt(string content, string publicKeyPem, string charset, bool keyFromFile)
  384. {
  385. if (keyFromFile)
  386. {
  387. ArgumentValidator.CheckArgument(!String.IsNullOrEmpty(publicKeyPem), "公钥文件路径不可为空。");
  388. publicKeyPem = File.ReadAllText(publicKeyPem);
  389. }
  390. return AsymmetricManager.GetByName("RSA").Encrypt(content, charset, publicKeyPem);
  391. }
  392. public static string RSADecrypt(string content, string privateKeyPem, string charset, string signType, bool keyFromFile)
  393. {
  394. if (keyFromFile)
  395. {
  396. ArgumentValidator.CheckArgument(!String.IsNullOrEmpty(privateKeyPem), "私钥文件路径不可为空。");
  397. privateKeyPem = LoadPrivateKeyFromRSACertFile(privateKeyPem);
  398. }
  399. return AsymmetricManager.GetByName(signType).Decrypt(content, charset, privateKeyPem);
  400. }
  401. private static string LoadPrivateKeyFromRSACertFile(string filename)
  402. {
  403. using (FileStream fs = File.OpenRead(filename))
  404. {
  405. byte[] data = new byte[fs.Length];
  406. fs.Read(data, 0, data.Length);
  407. if (data[0] != 0x30)
  408. {
  409. return GetPem("RSA PRIVATE KEY", data);
  410. }
  411. throw new Exception("证书文件格式不符合预期,无法提取私钥。");
  412. }
  413. }
  414. private static string GetPem(string type, byte[] data)
  415. {
  416. string pem = Encoding.UTF8.GetString(data);
  417. string header = String.Format("-----BEGIN {0}-----\\n", type);
  418. string footer = String.Format("-----END {0}-----", type);
  419. int start = pem.IndexOf(header, StringComparison.Ordinal) + header.Length;
  420. int end = pem.IndexOf(footer, start, StringComparison.Ordinal);
  421. return pem.Substring(start, (end - start));
  422. }
  423. public static SignSourceData ExtractSignContent(String str, int begin)
  424. {
  425. if (str == null)
  426. {
  427. return null;
  428. }
  429. int beginIndex = ExtractBeginPosition(str, begin);
  430. if (beginIndex >= str.Length)
  431. {
  432. return null;
  433. }
  434. int endIndex = ExtractEndPosition(str, beginIndex);
  435. return new SignSourceData()
  436. {
  437. SourceData = str.Substring(beginIndex, endIndex - beginIndex),
  438. BeginIndex = beginIndex,
  439. EndIndex = endIndex
  440. };
  441. }
  442. private static int ExtractBeginPosition(String responseString, int begin)
  443. {
  444. int beginPosition = begin;
  445. //找到第一个左大括号(对应响应的是JSON对象的情况:普通调用OpenAPI响应明文)
  446. //或者双引号(对应响应的是JSON字符串的情况:加密调用OpenAPI响应Base64串),作为待验签内容的起点
  447. while (beginPosition < responseString.Length
  448. && responseString[beginPosition] != '{'
  449. && responseString[beginPosition] != '"')
  450. {
  451. ++beginPosition;
  452. }
  453. return beginPosition;
  454. }
  455. private static int ExtractEndPosition(String responseString, int beginPosition)
  456. {
  457. //提取明文验签内容终点
  458. if (responseString[beginPosition] == '{')
  459. {
  460. return ExtractJsonObjectEndPosition(responseString, beginPosition);
  461. }
  462. //提取密文验签内容终点
  463. else
  464. {
  465. return ExtractJsonBase64ValueEndPosition(responseString, beginPosition);
  466. }
  467. }
  468. private static int ExtractJsonBase64ValueEndPosition(String responseString, int beginPosition)
  469. {
  470. for (int index = beginPosition; index < responseString.Length; ++index)
  471. {
  472. //找到第2个双引号作为终点,由于中间全部是Base64编码的密文,所以不会有干扰的特殊字符
  473. if (responseString[index] == '"' && index != beginPosition)
  474. {
  475. return index + 1;
  476. }
  477. }
  478. //如果没有找到第2个双引号,说明验签内容片段提取失败,直接尝试选取剩余整个响应字符串进行验签
  479. return responseString.Length;
  480. }
  481. private static int ExtractJsonObjectEndPosition(String responseString, int beginPosition)
  482. {
  483. //记录当前尚未发现配对闭合的大括号
  484. LinkedList<String> braces = new LinkedList<String>();
  485. //记录当前字符是否在双引号中
  486. bool inQuotes = false;
  487. //记录当前字符前面连续的转义字符个数
  488. int consecutiveEscapeCount = 0;
  489. //从待验签字符的起点开始遍历后续字符串,找出待验签字符串的终止点,终点即是与起点{配对的}
  490. for (int index = beginPosition; index < responseString.Length; ++index)
  491. {
  492. //提取当前字符
  493. char currentChar = responseString[index];
  494. //如果当前字符是"且前面有偶数个转义标记(0也是偶数)
  495. if (currentChar == '"' && consecutiveEscapeCount % 2 == 0)
  496. {
  497. //是否在引号中的状态取反
  498. inQuotes = !inQuotes;
  499. }
  500. //如果当前字符是{且不在引号中
  501. else if (currentChar == '{' && !inQuotes)
  502. {
  503. //将该{加入未闭合括号中
  504. braces.AddLast("{");
  505. }
  506. //如果当前字符是}且不在引号中
  507. else if (currentChar == '}' && !inQuotes)
  508. {
  509. //弹出一个未闭合括号
  510. braces.RemoveLast();
  511. //如果弹出后,未闭合括号为空,说明已经找到终点
  512. if (braces.Count == 0)
  513. {
  514. return index + 1;
  515. }
  516. }
  517. //如果当前字符是转义字符
  518. if (currentChar == '\\')
  519. {
  520. //连续转义字符个数+1
  521. ++consecutiveEscapeCount;
  522. }
  523. else
  524. {
  525. //连续转义字符个数置0
  526. consecutiveEscapeCount = 0;
  527. }
  528. }
  529. //如果没有找到配对的闭合括号,说明验签内容片段提取失败,直接尝试选取剩余整个响应字符串进行验签
  530. return responseString.Length;
  531. }
  532. /// <summary>
  533. /// 获取公钥证书序列号
  534. /// </summary>
  535. /// <param name="certPath">公钥证书路径</param>
  536. /// <returns>公钥证书序列号</returns>
  537. public static String GetCertSN(String certPath)
  538. {
  539. X509Certificate cert = AntCertificationUtil.ParseCert(File.ReadAllText(certPath));
  540. return AntCertificationUtil.GetCertSN(cert);
  541. }
  542. [Obsolete("因之前方法命名不符合C#规范而废弃的方法,请替换为EncryptAndSign方法")]
  543. public static string encryptAndSign(string bizContent, string alipayPublicKey, string cusPrivateKey, string charset,
  544. bool isEncrypt, bool isSign, string signType, bool keyFromFile)
  545. {
  546. return EncryptAndSign(bizContent, alipayPublicKey, cusPrivateKey, charset, isEncrypt, isSign, signType, keyFromFile);
  547. }
  548. [Obsolete("请替换为EncryptAndSign方法,显式设置参数:signTyp=RSA,keyFromFile=true")]
  549. public static string encryptAndSign(string bizContent, string alipayPublicKey, string cusPrivateKey, string charset,
  550. bool isEncrypt, bool isSign)
  551. {
  552. return EncryptAndSign(bizContent, alipayPublicKey, cusPrivateKey, charset, isEncrypt, isSign, "RSA", true);
  553. }
  554. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  555. public static string CheckSignAndDecrypt(IDictionary<string, string> parameters, string alipayPublicKey,
  556. string cusPrivateKey, bool isCheckSign, bool isDecrypt)
  557. {
  558. return CheckSignAndDecrypt(parameters, alipayPublicKey, cusPrivateKey, isCheckSign, isDecrypt, "RSA", true);
  559. }
  560. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  561. public static string RSASign(IDictionary<string, string> parameters, string privateKeyPem, string charset, string signType)
  562. {
  563. string signContent = GetSignContent(parameters);
  564. return RSASignCharSet(signContent, privateKeyPem, charset, signType);
  565. }
  566. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  567. public static string RSASign(string data, string privateKeyPem, string charset, string signType)
  568. {
  569. return RSASignCharSet(data, privateKeyPem, charset, signType);
  570. }
  571. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,按照惯例将keyFromFile参数列在最后")]
  572. public static string RSASign(IDictionary<string, string> parameters, string privateKey, string charset, bool keyFromFile, string signType)
  573. {
  574. string signContent = GetSignContent(parameters);
  575. return RSASignCharSet(signContent, privateKey, charset, signType, keyFromFile);
  576. }
  577. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  578. public static string RSASignCharSet(string data, string privateKeyPem, string charset, string signType)
  579. {
  580. return RSASignCharSet(data, privateKeyPem, charset, signType, true);
  581. }
  582. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  583. public static bool RSACheckV1(IDictionary<string, string> parameters, string publicKeyPem, string charset)
  584. {
  585. string sign = parameters["sign"];
  586. parameters.Remove("sign");
  587. parameters.Remove("sign_type");
  588. string signContent = GetSignContent(parameters);
  589. return RSACheckContent(signContent, sign, publicKeyPem, charset, "RSA");
  590. }
  591. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  592. public static bool RSACheckV1(IDictionary<string, string> parameters, string publicKeyPem)
  593. {
  594. string sign = parameters["sign"];
  595. parameters.Remove("sign");
  596. parameters.Remove("sign_type");
  597. string signContent = GetSignContent(parameters);
  598. return RSACheckContent(signContent, sign, publicKeyPem, DEFAULT_CHARSET, "RSA");
  599. }
  600. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  601. public static bool RSACheckV2(IDictionary<string, string> parameters, string publicKeyPem)
  602. {
  603. string sign = parameters["sign"];
  604. parameters.Remove("sign");
  605. string signContent = GetSignContent(parameters);
  606. return RSACheckContent(signContent, sign, publicKeyPem, DEFAULT_CHARSET, "RSA");
  607. }
  608. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  609. public static bool RSACheckV2(IDictionary<string, string> parameters, string publicKeyPem, string charset)
  610. {
  611. string sign = parameters["sign"];
  612. parameters.Remove("sign");
  613. string signContent = GetSignContent(parameters);
  614. return RSACheckContent(signContent, sign, publicKeyPem, charset, "RSA");
  615. }
  616. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  617. public static bool RSACheckContent(string signContent, string sign, string publicKeyPem, string charset, string signType)
  618. {
  619. return RSACheckContent(signContent, sign, publicKeyPem, charset, signType, true);
  620. }
  621. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  622. public static bool RSACheckContent(string signContent, string sign, string publicKeyPem, string charset, bool keyFromFile)
  623. {
  624. return RSACheckContent(signContent, sign, publicKeyPem, charset, "RSA", keyFromFile);
  625. }
  626. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  627. public static string RSAEncrypt(string content, string publicKeyPem, string charset)
  628. {
  629. return RSAEncrypt(content, publicKeyPem, charset, true);
  630. }
  631. [Obsolete("请替换为未废弃的有完整参数列表的重载版本,明确指定各参数的值")]
  632. public static string RSADecrypt(string content, string privateKeyPem, string charset, string signType)
  633. {
  634. return RSADecrypt(content, privateKeyPem, charset, signType, true);
  635. }
  636. }
  637. }