jssdk.php 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133
  1. <?php
  2. class JSSDK {
  3. private $appId;
  4. private $appSecret;
  5. var $platform = "";
  6. var $component_appid = "";
  7. var $component_access_token = "";
  8. var $is_platform = 0;
  9. var $url = '';
  10. public function __construct($appId = "", $appSecret = "",$component_access_token) {
  11. $this->appId = $appId;
  12. $this->appSecret = $appSecret;
  13. // $weixin_conf = load_auto_cache("weixin_conf");
  14. if($appSecret==""){
  15. $this->component_access_token = $component_access_token;
  16. }
  17. }
  18. public function set_url($url){
  19. if($url){
  20. $this->url = $url;
  21. }
  22. }
  23. public function getSignPackage() {
  24. $jsapiTicket = $this->getJsApiTicket();
  25. // 注意 URL 一定要动态获取,不能 hardcode.
  26. $protocol = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' || $_SERVER['SERVER_PORT'] == 443) ? "https://" : "http://";
  27. if($this->url){
  28. $url = $this->url;
  29. }else{
  30. $url = "$protocol$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]";
  31. }
  32. $timestamp = time();
  33. $nonceStr = $this->createNonceStr();
  34. // 这里参数的顺序要按照 key 值 ASCII 码升序排序
  35. $string = "jsapi_ticket=$jsapiTicket&noncestr=$nonceStr&timestamp=$timestamp&url=$url"; $signature = sha1($string);
  36. $signPackage = array(
  37. "appId" => $this->appId,
  38. "nonceStr" => $nonceStr,
  39. "timestamp" => $timestamp,
  40. "url" => $url,
  41. "signature" => $signature,
  42. "rawString" => $string
  43. );
  44. return $signPackage;
  45. }
  46. private function createNonceStr($length = 16) {
  47. $chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
  48. $str = "";
  49. for ($i = 0; $i < $length; $i++) {
  50. $str .= substr($chars, mt_rand(0, strlen($chars) - 1), 1);
  51. }
  52. return $str;
  53. }
  54. private function getJsApiTicket() {
  55. // jsapi_ticket 应该全局存储与更新,以下代码以写入到文件中做示例
  56. $data = json_decode(file_get_contents("../public".$GLOBALS['saas_public']."/runtime/wap/jsapi_ticket.json"));
  57. if ($data->expire_time < time()) {
  58. if($this->is_platform){
  59. $accessToken = $this->component_access_token;
  60. }else{
  61. if($this->component_access_token){
  62. $accessToken = $this->component_access_token;
  63. }else{
  64. $accessToken = $this->getAccessToken();
  65. }
  66. }
  67. // 如果是企业号用以下 URL 获取 ticket
  68. // $url = "https://qyapi.weixin.qq.com/cgi-bin/get_jsapi_ticket?access_token=$accessToken";
  69. $url = "https://api.weixin.qq.com/cgi-bin/ticket/getticket?type=jsapi&access_token=$accessToken";
  70. $res = json_decode($this->httpGet($url));
  71. $ticket = $res->ticket;
  72. if ($ticket) {
  73. $data->expire_time = time() + 7000;
  74. $data->jsapi_ticket = $ticket;
  75. $fp = fopen("../public".$GLOBALS['saas_public']."/runtime/wap/jsapi_ticket.json", "w");
  76. fwrite($fp, json_encode($data));
  77. fclose($fp);
  78. }
  79. } else {
  80. $ticket = $data->jsapi_ticket;
  81. }
  82. return $ticket;
  83. }
  84. private function getAccessToken() {
  85. // access_token 应该全局存储与更新,以下代码以写入到文件中做示例
  86. $data = json_decode(file_get_contents("../public".$GLOBALS['saas_public']."/runtime/wap/access_token.json"));
  87. if ($data->expire_time < time()) {
  88. // 如果是企业号用以下URL获取access_token
  89. $url = "https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid=$this->appId&secret=$this->appSecret";
  90. $res = json_decode($this->httpGet($url));
  91. $access_token = $res->access_token;
  92. if ($access_token) {
  93. $data->expire_time = time() + 7000;
  94. $data->access_token = $access_token;
  95. $fp = fopen("../public".$GLOBALS['saas_public']."/runtime/wap/access_token.json", "w");
  96. fwrite($fp, json_encode($data));
  97. fclose($fp);
  98. }
  99. } else {
  100. $access_token = $data->access_token;
  101. }
  102. return $access_token;
  103. }
  104. private function httpGet($url) {
  105. $curl = curl_init();
  106. curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
  107. curl_setopt($curl, CURLOPT_TIMEOUT, 500);
  108. curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
  109. curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, false);
  110. curl_setopt($curl, CURLOPT_URL, $url);
  111. $res = curl_exec($curl);
  112. curl_close($curl);
  113. return $res;
  114. }
  115. }