在看这篇文章之前,开发者对微信公众号要有一定的了解,如果你是小白请移驾微信公众号官方开发文档
现在大多数开发者都是使用测试号进行开发,测试号开发会遇到一些坑,比如第一次获取不到code等,有经验的大佬都会说是微信那边的bug,具体什么原因我们也不深究,正是好则不会出现这些问题。
进入正题,获取用户授权这些我们都不讲了,直接去微信官方API查看,都是调相关API,很简单,只是注意一下用户的授权,分为静默授权和需要用户手动点击确认授权两种,主要是要获取到用户的openId和相关的用户信息,具体采用哪种授权方式视业务而定,记得注意一下token的过期时间。下面直接进入接入微信支付。
1:前端页面得引入微信支付相关的js
//引入微信支付相关的js
<script src="http://res.wx.qq.com/open/js/jweixin-1.1.0.js"></script>
2:通过ajax获取支付相关的数据
//前端代码,获取相关数据 openid,时间戳,随机串,签名
$.ajax({
url: "/wechat/jsapisign",
type: "post",
data: {
url: location.href.split('#')[0]
},
contentType: 'application/x-www-form-urlencoded;charset=utf-8',
async: true,
success: function (data) {
var obj = eval("(" + data + ")")
var appid = obj.appid;
var signature = obj.signature;
var nonce = obj.nonceStr;
var timestamp = obj.timestamp;
wx.config({
debug: false, // 开启调试模式,调用的所有api的返回值会在客户端alert出来,若要查看传入的参数,可以在pc端打开,参数信息会通过log打出,仅在pc端时才会打印。
appId: appid, // 必填,公众号的唯一标识
timestamp: timestamp, // 必填,生成签名的时间戳
nonceStr: nonce, // 必填,生成签名的随机串
signature: signature,// 必填,签名,见附录1
jsApiList: ["chooseWXPay"] // 必填,需要使用的JS接口列表
})
}
});
//后端接口
@RequestMapping("/jsapisign")
@ResponseBody
public String jsApiSign(String url) {
//添加微信js签名信息
Map<String, String> signMap = WXJsapiticket.jsApiSign(url);
return JSON.toJSONString(signMap);
}
public static Map<String, String> jsApiSign(String url) {
Map<String, String> ret = new HashMap<String, String>();
String nonce_str = CheckUtil.create_nonce_str();
String timestamp = CheckUtil.create_timestamp();
String jsapi_ticket = getJsApiTicket();
String string1 = CheckUtil.getString1(nonce_str,timestamp,jsapi_ticket,url);
String signature = CheckUtil.getSha1(string1);
ret.put("appid", WexinUtil.APP_ID);//取你自己的公众号appid
ret.put("url", url);
ret.put("jsapi_ticket", jsapi_ticket);
ret.put("nonceStr", nonce_str);
ret.put("timestamp", timestamp);
ret.put("signature", signature);
return ret;
}
3:做好准备工作就可以进入微信支付啦,调用微信支付接口,发起支付
//前端发起支付
$.ajax({
url: "/wechat/paySubmit",
type: "get",
dataType: "json",
success: function (data) {
if (data.status == "true") {
wx.chooseWXPay({
timestamp: data.timeStamp, // 支付签名时间戳,注意微信jssdk中的所有使用timestamp字段均为小写。但最新版的支付后台生成签名使用的timeStamp字段名需大写其中的S字符
nonceStr: data.nonceStr, // 支付签名随机串,不长于 32 位
package: "prepay_id=" + data.prepay_id,
signType: 'MD5', // 签名方式,默认为'SHA1',使用新版支付需传入'MD5'
paySign: data.sign, // 支付签名
success: function (res) {
window.location.href = "/wechat/paySuccess"
}
});
//后端代码
/**
* 微信支付下单
*/
@RequestMapping("/paySubmit")
@ResponseBody
public String pay(HttpSession session, String totalFee, HttpServletRequest request) throws Exception {
long orderNo = new Date().getTime() / 1000;
String characterEncoding = "UTF-8";
WeiXinUserInfo weiXinUserInfo = (WeiXinUserInfo) request.getSession().getAttribute("weiXinUserInfo");
//判断用户openid不为空
if (weiXinUserInfo.getOpenId() != null && weiXinUserInfo != null) {
UserInfoQuery userInfoQuery = new UserInfoQuery();
userInfoQuery.setOpenId(weiXinUserInfo.getOpenId());
ExtendedUserInfo extendedUserInfo = userInfoService.queryOne(userInfoQuery);
//判断是否注册 如果没注册先让他注册
if (extendedUserInfo.getPhoneNumber() != null && extendedUserInfo.getRegisterDate() != null) {
String paramContent = "";
String sign = "";
String nonceStr = CheckUtil.create_nonce_str();
SortedMap<String, String> param = new TreeMap<String, String>();
//你的appId
param.put("appid", WexinUtil.APP_ID);
param.put("body", "微信支付测试");
//这个api上有说明,你是什么方式就选择什么方式
param.put("device_info", "WEB");
//商户id
param.put("mch_id", "商户id");
//随机签名串
param.put("nonce_str", nonceStr);
//支付成功后的回调
param.put("notify_url", "回调接口");
//订单id
param.put("out_trade_no", OrderNoUtil.createOrderNo(new Date()));
param.put("openid", weiXinUserInfo.getOpenId());
//交易金额 注意单位是分
param.put("total_fee", "1980000");
//交易类型 具体参考API 是什么填什么
param.put("trade_type", "JSAPI");
//IP地址
String spbill_create_ip = CheckUtil.getIpAddr(request);
if (StringUtils.isEmpty(spbill_create_ip)) {
param.put("spbill_create_ip", "192.168.0.1");// 消费IP地址
} else {
param.put("spbill_create_ip", spbill_create_ip);// 消费IP地址
}
//生成签名 重点生成签名,可以说签名成功你微信支付就成功一大半了
sign = PayCommonUtil.createSign(characterEncoding, param);
param.put("sign", sign);
//转xml的格式
paramContent = (String) PayCommonUtil.getRequestXml(param);
//调用微信预下单接口 把支付相关xml传过去
String orderInfo = HttpUtil.sendHttpByPost("https://api.mch.weixin.qq.com/pay/unifiedorder", paramContent);
String prepay_id;
try {
//读取微信返回的预下单报文, prepay_id 生成订单的id,拿到此id你基本就成功了
Map<String, String> orderInfoMap = CheckUtil.xmlToMap(orderInfo);
if (orderInfoMap.get("return_code").equals("SUCCESS") && orderInfoMap.get("result_code").equals("SUCCESS")) {
//预支付id
prepay_id = orderInfoMap.get("prepay_id");
String timestamp = CheckUtil.create_timestamp();
SortedMap<String, String> pageParam = new TreeMap<String, String>();
pageParam.put("appId", WexinUtil.APP_ID);
pageParam.put("nonceStr", nonceStr);
pageParam.put("package", "prepay_id=" + prepay_id);
pageParam.put("timeStamp", timestamp);
pageParam.put("signType", "MD5");
sign = PayCommonUtil.createSign(characterEncoding, pageParam);
pageParam.put("sign", sign);
pageParam.put("prepay_id", prepay_id);
pageParam.put("status", "true");
return JSON.toJSONString(pageParam);
}
} catch (Exception e) {
System.out.println("生成的预订单格式xml转map异常");
}
} else {
HashMap<String, String> map = new HashMap<>();
map.put("status", "false");
return JSON.toJSONString(map);
}
} else {
return "false";
}
return "null";
}
特别是生成签名这个地方,实在是坑,相信你只要认真阅读了API也不是什么大问题,注意生成签名这个地方要特别注意,签名默认MD5加密,微信根据参数字段的ASCII码值进行排序 加密签名,故使用SortMap进行参数排序,本人也在此吃过大亏,注意支付相关参数写得是否正确,如果出错微信报文会指出你是参数错误还是签名错误,这个还是很好排查,可以使用微信支付签名官方校验工具,进行验证你生成的签名是否正确,本人在此处遇到过一个坑,官方签名校验工具验证签名正确,但是后台始终报签名错误,检查了各种参数都是正确的,最后重置了商户号的KEY,问题一下就解决了,所有有时候微信还是很坑的,下面我会贴出使用到的相关工具类的代码
PayCommonUtil.java
public class PayCommonUtil {
//定义签名,微信根据参数字段的ASCII码值进行排序 加密签名,故使用SortMap进行参数排序
public static String createSign(String characterEncoding, SortedMap<String,String> parameters){
StringBuffer sb = new StringBuffer();
Set es = parameters.entrySet();
Iterator it = es.iterator();
while(it.hasNext()) {
Map.Entry entry = (Map.Entry)it.next();
String k = (String)entry.getKey();
Object v = entry.getValue();
if(null != v && !"".equals(v)
&& !"sign".equals(k) && !"key".equals(k)) {
sb.append(k + "=" + v + "&");
}
}
sb.append("key=" +WexinUtil.KEY //商户号秘钥
);//最后加密时添加商户密钥,由于key值放在最后,所以不用添加到SortMap里面去,单独处理,编码方式采用UTF-8
String sign = MD5Util.MD5Encode(sb.toString(), characterEncoding).toUpperCase();
System.out.println(sb);
return sign;
}
//将封装好的参数转换成Xml格式类型的字符串
public static String getRequestXml(SortedMap<String,String> parameters){
StringBuffer sb = new StringBuffer();
sb.append("<xml>");
Set es = parameters.entrySet();
Iterator it = es.iterator();
while(it.hasNext()) {
Map.Entry entry = (Map.Entry)it.next();
String k = (String)entry.getKey();
String v = (String)entry.getValue();
if("sign".equalsIgnoreCase(k)){
}
else if ("attach".equalsIgnoreCase(k)||"body".equalsIgnoreCase(k)) {
sb.append("<"+k+">"+"<![CDATA["+v+"]]></"+k+">");
}
else {
sb.append("<"+k+">"+v+"</"+k+">");
}
}
sb.append("<"+"sign"+">"+"<![CDATA["+parameters.get("sign")+"]]></"+"sign"+">");
sb.append("</xml>");
return sb.toString();
}
}
CheckUtil.java
public class CheckUtil {
public static final String token = "aXRzb3VyY2U0NTYxMjMyMDE0"; //开发者自行定义Token
/**
* 对所有待签名参数按照字段名的ASCII 码从小到大排序(字典序)后,使用URL键值对的格式 (即 key1=value1&key2=value2…)拼接成字符串string1
* @param nonce_str
* @param timestamp
* @param jsapi_ticket
* @param url
* @return
*/
public static String getString1(String nonce_str,String timestamp,String jsapi_ticket,String url){
//1.定义数组存放nonce_str,timestamp,jsapi_ticket,url
String[] arr = {"noncestr="+nonce_str,"timestamp="+timestamp,"jsapi_ticket="+jsapi_ticket,"url="+url};
//2.对数组进行排序
Arrays.sort(arr);
//3.生成字符串
StringBuffer sb = new StringBuffer();
for(String s : arr){
sb.append(s);
sb.append("&");
}
sb.deleteCharAt(sb.length()-1);
return sb.toString();
}
public static String getSha1(String str){
if(str==null||str.length()==0){
return null;
}
char hexDigits[] = {'0','1','2','3','4','5','6','7','8','9',
'a','b','c','d','e','f'};
try {
MessageDigest mdTemp = MessageDigest.getInstance("SHA1");
mdTemp.update(str.getBytes("UTF-8"));
byte[] md = mdTemp.digest();
int j = md.length;
char buf[] = new char[j*2];
int k = 0;
for (int i = 0; i < j; i++) {
byte byte0 = md[i];
buf[k++] = hexDigits[byte0 >>> 4 & 0xf];
buf[k++] = hexDigits[byte0 & 0xf];
}
return new String(buf);
} catch (Exception e) {
// TODO: handle exception
return null;
}
}
public static String create_nonce_str() {
return UUID.randomUUID().toString().replaceAll("-", "").substring(0, 32);
}
public static String create_timestamp() {
return Long.toString(System.currentTimeMillis() / 1000);
}
/**
* 获取ip地址
* @param request
* @return
* @throws Exception
*/
public static String getIpAddr(HttpServletRequest request) throws Exception {
String ip = request.getHeader("x-forwarded-for");
if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
ip = request.getHeader("Proxy-Client-IP");
}
if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
ip = request.getHeader("WL-Proxy-Client-IP");
}
if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
ip = request.getHeader("HTTP_CLIENT_IP");
}
if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
ip = request.getHeader("HTTP_X_FORWARDED_FOR");
}
if (ip == null || ip.length() == 0 || "unknown".equalsIgnoreCase(ip)) {
ip = request.getRemoteAddr();
}
return ip;
}
/**
* 生成签名. 注意,若含有sign_type字段,必须和signType参数保持一致。
* @param data 待签名数据
* @param key API密钥
* @param signType 签名方式
* @return 签名
*/
// public static String generateSignature(final Map<String, String> data, String key, String signType) throws Exception {
// Set<String> keySet = data.keySet();
// String[] keyArray = keySet.toArray(new String[keySet.size()]);
// Arrays.sort(keyArray);
// StringBuilder sb = new StringBuilder();
// for (String k : keyArray) {
// // 参数值为空,则不参与签名
// if (data.get(k).trim().length() > 0) {
// sb.append(k).append("=").append(data.get(k).trim()).append("&");
// }
// }
// sb.append("key=").append(key);
// if (SignType.MD5.equals(signType)) {
// return MD5(sb.toString()).toUpperCase();
// }
// else if (SignType.HMACSHA256.equals(signType)) {
// return HMACSHA256(sb.toString(), key);
// }
// else {
// throw new Exception(String.format("Invalid sign_type: %s", signType));
// }
// }
/**
* XML格式字符串转换为Map
*
* @param strXML XML字符串
* @return XML数据转换后的Map
* @throws Exception
*/
public static Map<String, String> xmlToMap(String strXML) throws Exception {
try {
Map<String, String> data = new HashMap<String, String>();
DocumentBuilderFactory documentBuilderFactory = DocumentBuilderFactory.newInstance();
DocumentBuilder documentBuilder = documentBuilderFactory.newDocumentBuilder();
InputStream stream = new ByteArrayInputStream(strXML.getBytes("UTF-8"));
org.w3c.dom.Document doc = documentBuilder.parse(stream);
doc.getDocumentElement().normalize();
NodeList nodeList = doc.getDocumentElement().getChildNodes();
for (int idx = 0; idx < nodeList.getLength(); ++idx) {
Node node = nodeList.item(idx);
if (node.getNodeType() == Node.ELEMENT_NODE) {
org.w3c.dom.Element element = (org.w3c.dom.Element) node;
data.put(element.getNodeName(), element.getTextContent());
}
}
try {
stream.close();
} catch (Exception ex) {
// do nothing
}
return data;
} catch (Exception ex) {
throw ex;
}
}
public static String getXMLFromMap(Map<Object, Object> map) throws Exception {
StringBuffer sb = new StringBuffer();
sb.append("<xml>");
Set<Object> set = map.keySet();
Iterator<Object> it = set.iterator();
while (it.hasNext()) {
String key = (String) it.next();
sb.append("<" + key + ">").append(map.get(key)).append("</" + key + ">");
}
sb.append("</xml>");
return sb.toString();
}
}
4:微信回调,处理你的业务逻辑,比如订单号是否支付成功等等,返回的订单ID等,貌似微信回调接口会重复调3-5次,具体我没去深究。
@RequestMapping("/payNotify")
@ResponseBody
public synchronized String payNotify(HttpServletRequest request, HttpServletResponse response) {
String characterEncoding = "UTF-8";
Map<Object, Object> returnData = new HashMap<>();
String returnXML = "";
String retStr = "";
try {
retStr = new String(readInput(request.getInputStream()), "utf-8");
} catch (IOException e) {
e.printStackTrace();
}
try {
Map<String, String> responseResult = CheckUtil.xmlToMap(retStr);
//可以判断一下签名是否符合 微信端回调传回的签名
// String localSign = (String) PayCommonUtil.createSign(characterEncoding,responseResult);
String sign = responseResult.get("sign");
String openid = responseResult.get("openid");
String prepay_id = responseResult.get("prepay_id");
String total_fee = responseResult.get("total_fee");
//订单编号
String out_trade_no = responseResult.get("out_trade_no");
// if (Objects.equals(sign, localSign)) {
if (!responseResult.get("return_code").toString().equals("SUCCESS") || !responseResult.get("result_code").toString().equals("SUCCESS")) {
returnData.put("return_code", "FAIL");
returnData.put("return_msg", "return_code不正确");
} else {
//todo 你的业务逻辑 业务逻辑
}
returnData.put("return_code", "SUCCESS");
returnData.put("return_msg", "ok");
}
// } else {
// returnData.put("return_code", "FAIL");
// returnData.put("return_msg", "签名错误");
// }
} catch (Exception e) {
System.out.println("支付回调错误" + e.getMessage());
returnData.put("return_code", "FAIL");
returnData.put("return_msg", "支付回调失败");
try {
returnXML = CheckUtil.getXMLFromMap(returnData);
} catch (Exception e1) {
e1.printStackTrace();
}
return returnXML;
}
return returnXML;
}