修正ca签章
This commit is contained in:
@@ -1,105 +0,0 @@
|
||||
<?php
|
||||
|
||||
namespace Extend\Ca;
|
||||
|
||||
use App\Constants\HttpEnumCode;
|
||||
use App\Exception\BusinessException;
|
||||
use GuzzleHttp\Client;
|
||||
use GuzzleHttp\Exception\GuzzleException;
|
||||
use Hyperf\Di\Annotation\Inject;
|
||||
use Hyperf\Utils\ApplicationContext;
|
||||
use Psr\Container\ContainerInterface;
|
||||
|
||||
class Base
|
||||
{
|
||||
#[Inject]
|
||||
protected ContainerInterface $container;
|
||||
|
||||
#[Inject]
|
||||
protected Client $client;
|
||||
|
||||
protected string $app_id;
|
||||
protected string $api_url;
|
||||
protected string $secret;
|
||||
|
||||
public function __construct()
|
||||
{
|
||||
$this->container = ApplicationContext::getContainer();
|
||||
$this->client = $this->container->get(Client::class);
|
||||
}
|
||||
|
||||
/**
|
||||
* 封装公共请求
|
||||
* @param string $path
|
||||
* @param array $arg
|
||||
* @return mixed
|
||||
* @throws GuzzleException
|
||||
*/
|
||||
protected function httpRequest(string $path, array $arg = []): mixed
|
||||
{
|
||||
$option = [
|
||||
"headers" => [
|
||||
"app_id" => $this->app_id,
|
||||
"signature" => $this->getRequestSign($arg),
|
||||
],
|
||||
];
|
||||
|
||||
$arg = array_merge($arg, $option);
|
||||
|
||||
$response = $this->client->post($path, $arg);
|
||||
|
||||
if ($response->getStatusCode() != '200') {
|
||||
// 请求失败
|
||||
throw new BusinessException($response->getBody()->getContents());
|
||||
}
|
||||
$body = json_decode($response->getBody(), true);
|
||||
dump($body);
|
||||
if (empty($body)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
|
||||
if ($body['result_code'] != 0) {
|
||||
// 请求失败
|
||||
if (!empty($body['result_msg'])) {
|
||||
throw new BusinessException($body['result_msg']);
|
||||
}
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
|
||||
return $body['body'];
|
||||
}
|
||||
|
||||
/**
|
||||
* 获取请求签名
|
||||
* @param array $data
|
||||
* @return string
|
||||
*/
|
||||
protected function getRequestSign(array $data): string
|
||||
{
|
||||
$sign_data = array();
|
||||
if (isset($data['form_params'])) {
|
||||
$sign_data = $data['form_params'];
|
||||
}
|
||||
|
||||
if (isset($data['multipart'])) {
|
||||
foreach ($data['multipart'] as $item) {
|
||||
// pdf进行签章时,此参数为文件流,不参与签名
|
||||
if ($item['name'] == "pdfFile") {
|
||||
continue;
|
||||
}
|
||||
|
||||
$sign_data[$item['name']] = $item['contents'];
|
||||
}
|
||||
}
|
||||
|
||||
if (!empty($sign_data)){
|
||||
ksort($sign_data);
|
||||
$data = implode('&', $sign_data);
|
||||
}else{
|
||||
$data = "";
|
||||
}
|
||||
|
||||
return hash_hmac("sha1", $data, $this->secret);
|
||||
}
|
||||
}
|
||||
+119
-54
@@ -4,8 +4,6 @@ namespace Extend\Ca;
|
||||
|
||||
use App\Constants\HttpEnumCode;
|
||||
use App\Exception\BusinessException;
|
||||
use App\Utils\Log;
|
||||
use Exception;
|
||||
use GuzzleHttp\Client;
|
||||
use GuzzleHttp\Exception\GuzzleException;
|
||||
use Hyperf\Di\Annotation\Inject;
|
||||
@@ -13,39 +11,30 @@ use Hyperf\Snowflake\IdGeneratorInterface;
|
||||
use Hyperf\Utils\ApplicationContext;
|
||||
use Psr\Container\ContainerInterface;
|
||||
|
||||
/**
|
||||
* 四川ca云证书+电子签章-线下
|
||||
*/
|
||||
class Ca extends Base
|
||||
abstract class Ca
|
||||
{
|
||||
#[Inject]
|
||||
protected ContainerInterface $container;
|
||||
|
||||
#[Inject]
|
||||
protected Client $client;
|
||||
|
||||
protected string $app_id;
|
||||
protected string $api_url;
|
||||
protected string $secret;
|
||||
|
||||
public function __construct()
|
||||
{
|
||||
$this->container = ApplicationContext::getContainer();
|
||||
$this->client = $this->container->get(Client::class);
|
||||
}
|
||||
|
||||
/**
|
||||
* 获取云证书
|
||||
* 申请云证书
|
||||
* @param array $data
|
||||
* @param string $type
|
||||
* @return mixed
|
||||
*/
|
||||
public function getCloudCert(array $data,string $type = "Personal"): mixed
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'entityId' => $data['user_id'], // 用户唯一标识,由业务系统定义
|
||||
'entityType' => $type,// 用户类型,可选值[Personal/Organizational]
|
||||
'pin' => $data['user_id'], // 证书PIN码
|
||||
'cardNumber' => $data['card_num'], // 证件号码(个人身份证;企业统一社会信用代码)
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(config("ca.api_url") . '/cloud-certificate-service' . '/api/cloudCert/open/v2/cert/offlineAuthCertEnroll', $option);
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
abstract public function getCloudCert(array $data, string $type = "Personal");
|
||||
|
||||
/**
|
||||
* 获取云证书签名
|
||||
@@ -59,15 +48,14 @@ class Ca extends Base
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'entityId' => $user_id, // 用户唯一标识,由业务系统定义
|
||||
'toSign' => hash_hmac("sha1", json_encode($data, JSON_UNESCAPED_UNICODE), config("ca.secret")), // 签名原文
|
||||
'toSign' => hash_hmac("sha1", json_encode($data, JSON_UNESCAPED_UNICODE), $this->secret), // 签名原文
|
||||
'pin' => $pin, // 证书PIN码
|
||||
]
|
||||
];
|
||||
|
||||
dump($option);
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
config("ca.api_url") . '/cloud-certificate-service' . '/api/cloudCert/open/cert/sign',
|
||||
$this->api_url . '/cloud-certificate-service' . '/api/cloudCert/open/cert/sign',
|
||||
$option
|
||||
);
|
||||
if (empty($response)) {
|
||||
@@ -80,8 +68,10 @@ class Ca extends Base
|
||||
}
|
||||
}
|
||||
|
||||
// PKCS7签名验证接口
|
||||
// 对客户端签名信息进行验证,返回证书信息,同时可以配置回调服务,在验证成功后回调业务系统
|
||||
/**
|
||||
* PKCS7签名验证接口
|
||||
* 对客户端签名信息进行验证,返回证书信息,同时可以配置回调服务,在验证成功后回调业务系统
|
||||
*/
|
||||
public function verifyPkcs7(string $sign_p7, array $data)
|
||||
{
|
||||
$generator = $this->container->get(IdGeneratorInterface::class);
|
||||
@@ -91,7 +81,7 @@ class Ca extends Base
|
||||
'opType' => "签名验证",
|
||||
'requestId' => $generator->generate(),// 业务流水号,唯一
|
||||
'signedData' => $sign_p7, // 签名值:签名接口返回的signP7
|
||||
'toSign' => hash_hmac("sha1", json_encode($data, JSON_UNESCAPED_UNICODE), config("ca.secret")), // 签名原文
|
||||
'toSign' => hash_hmac("sha1", json_encode($data, JSON_UNESCAPED_UNICODE), $this->secret), // 签名原文
|
||||
]
|
||||
];
|
||||
|
||||
@@ -99,7 +89,7 @@ class Ca extends Base
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
config("ca.api_url") . '/signgw-service/api/signature/verifyPkcs7',
|
||||
$this->api_url . '/signgw-service/api/signature/verifyPkcs7',
|
||||
$option
|
||||
);
|
||||
if (empty($response)) {
|
||||
@@ -114,12 +104,12 @@ class Ca extends Base
|
||||
|
||||
/**
|
||||
* 添加签章配置
|
||||
* @param string $user_id 用户id
|
||||
* @param string $card_num 身份证号
|
||||
* @param string $user_id
|
||||
* @param string $card_num
|
||||
* @param array $data
|
||||
* @return mixed
|
||||
* @return bool
|
||||
*/
|
||||
public function addUserSignConfig(string $user_id, string $card_num, array $data): mixed
|
||||
public function addUserSignConfig(string $user_id, string $card_num, array $data): bool
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
@@ -137,7 +127,7 @@ class Ca extends Base
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
config("ca.api_url") . '/signature-server/api/open/signature/userSignConfig',
|
||||
$this->api_url . '/signature-server/api/open/signature/userSignConfig',
|
||||
$option
|
||||
);
|
||||
|
||||
@@ -150,9 +140,9 @@ class Ca extends Base
|
||||
/**
|
||||
* 删除签章配置
|
||||
* @param string $user_id
|
||||
* @return mixed
|
||||
* @return bool
|
||||
*/
|
||||
public function deleteUserSignConfig(string $user_id): mixed
|
||||
public function deleteUserSignConfig(string $user_id): bool
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
@@ -163,7 +153,7 @@ class Ca extends Base
|
||||
|
||||
try {
|
||||
$this->httpRequest(
|
||||
config("ca.api_url") . '/signature-server/api/open/signature/delSignConfig',
|
||||
$this->api_url . '/signature-server/api/open/signature/delSignConfig',
|
||||
$option
|
||||
);
|
||||
return true;
|
||||
@@ -187,7 +177,7 @@ class Ca extends Base
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
config("ca.api_url") . '/signature-server/api/open/signature/fetchUserSeal',
|
||||
$this->api_url . '/signature-server/api/open/signature/fetchUserSeal',
|
||||
$option
|
||||
);
|
||||
if (empty($response)) {
|
||||
@@ -206,7 +196,7 @@ class Ca extends Base
|
||||
* @param array $data
|
||||
* @return mixed
|
||||
*/
|
||||
public function addSignPdf(string $user_id, array $data)
|
||||
public function addSignPdf(string $user_id, array $data): mixed
|
||||
{
|
||||
$option = [
|
||||
'multipart' => [
|
||||
@@ -235,7 +225,7 @@ class Ca extends Base
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
config("ca.api_url") . '/signature-server/api/open/signature/signPdf',
|
||||
$this->api_url . '/signature-server/api/open/signature/signPdf',
|
||||
$option
|
||||
);
|
||||
|
||||
@@ -251,11 +241,11 @@ class Ca extends Base
|
||||
|
||||
/**
|
||||
* 下载签章的pdf文件
|
||||
* @param string $user_id
|
||||
* @param string $entity_id
|
||||
* @param string $file_id
|
||||
* @return mixed
|
||||
* @return string
|
||||
*/
|
||||
public function getSignedFile(string $entity_id, string $file_id): mixed
|
||||
public function getSignedFile(string $entity_id, string $file_id): string
|
||||
{
|
||||
$arg = [
|
||||
'form_params' => [
|
||||
@@ -267,14 +257,14 @@ class Ca extends Base
|
||||
try {
|
||||
$option = [
|
||||
"headers" => [
|
||||
"app_id" => config("ca.app_id"),
|
||||
"app_id" => $this->app_id,
|
||||
"signature" => $this->getRequestSign($arg),
|
||||
],
|
||||
];
|
||||
|
||||
$option = array_merge($arg, $option);
|
||||
|
||||
$response = $this->client->post(config("ca.api_url") . '/signature-server/api/open/signature/fetchSignedFile', $option);
|
||||
$response = $this->client->post($this->api_url . '/signature-server/api/open/signature/fetchSignedFile', $option);
|
||||
|
||||
if ($response->getStatusCode() != '200') {
|
||||
// 请求失败
|
||||
@@ -306,7 +296,7 @@ class Ca extends Base
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
config("ca.api_url") . '/signature-server/api/open/signature/verifyPdf',
|
||||
$this->api_url . '/signature-server/api/open/signature/verifyPdf',
|
||||
$option
|
||||
);
|
||||
|
||||
@@ -319,4 +309,79 @@ class Ca extends Base
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 封装公共请求
|
||||
* @param string $path
|
||||
* @param array $arg
|
||||
* @return mixed
|
||||
* @throws GuzzleException
|
||||
*/
|
||||
public function httpRequest(string $path, array $arg = []): mixed
|
||||
{
|
||||
$option = [
|
||||
"headers" => [
|
||||
"app_id" => $this->app_id,
|
||||
"signature" => $this->getRequestSign($arg),
|
||||
],
|
||||
];
|
||||
|
||||
$arg = array_merge($arg, $option);
|
||||
|
||||
$response = $this->client->post($path, $arg);
|
||||
|
||||
if ($response->getStatusCode() != '200') {
|
||||
// 请求失败
|
||||
throw new BusinessException($response->getBody()->getContents());
|
||||
}
|
||||
$body = json_decode($response->getBody(), true);
|
||||
dump($body);
|
||||
if (empty($body)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
|
||||
if ($body['result_code'] != 0) {
|
||||
// 请求失败
|
||||
if (!empty($body['result_msg'])) {
|
||||
throw new BusinessException($body['result_msg']);
|
||||
}
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
|
||||
return $body['body'];
|
||||
}
|
||||
|
||||
/**
|
||||
* 获取请求签名
|
||||
* @param array $data
|
||||
* @return string
|
||||
*/
|
||||
public function getRequestSign(array $data): string
|
||||
{
|
||||
$sign_data = array();
|
||||
if (isset($data['form_params'])) {
|
||||
$sign_data = $data['form_params'];
|
||||
}
|
||||
|
||||
if (isset($data['multipart'])) {
|
||||
foreach ($data['multipart'] as $item) {
|
||||
// pdf进行签章时,此参数为文件流,不参与签名
|
||||
if ($item['name'] == "pdfFile") {
|
||||
continue;
|
||||
}
|
||||
|
||||
$sign_data[$item['name']] = $item['contents'];
|
||||
}
|
||||
}
|
||||
|
||||
if (!empty($sign_data)) {
|
||||
ksort($sign_data);
|
||||
$data = implode('&', $sign_data);
|
||||
} else {
|
||||
$data = "";
|
||||
}
|
||||
|
||||
return hash_hmac("sha1", $data, $this->secret);
|
||||
}
|
||||
}
|
||||
+3
-275
@@ -10,7 +10,7 @@ use Hyperf\Snowflake\IdGeneratorInterface;
|
||||
/**
|
||||
* 四川ca云证书+电子签章-线下
|
||||
*/
|
||||
class CaOffline extends Base
|
||||
class CaOffline extends Ca
|
||||
{
|
||||
public function __construct()
|
||||
{
|
||||
@@ -25,12 +25,12 @@ class CaOffline extends Base
|
||||
}
|
||||
|
||||
/**
|
||||
* 获取云证书
|
||||
* 申请云证书
|
||||
* @param array $data
|
||||
* @param string $type
|
||||
* @return mixed
|
||||
*/
|
||||
public function getCloudCert(array $data,string $type = "Personal"): mixed
|
||||
protected function getCloudCert(array $data,string $type = "Personal"): mixed
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
@@ -52,276 +52,4 @@ class CaOffline extends Base
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 获取云证书签名
|
||||
* @param string $user_id
|
||||
* @param string $pin
|
||||
* @param array $data
|
||||
* @return mixed
|
||||
*/
|
||||
public function getCertSign(string $user_id, string $pin, array $data): mixed
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'entityId' => $user_id, // 用户唯一标识,由业务系统定义
|
||||
'toSign' => hash_hmac("sha1", json_encode($data, JSON_UNESCAPED_UNICODE), $this->secret), // 签名原文
|
||||
'pin' => $pin, // 证书PIN码
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
$this->api_url . '/cloud-certificate-service' . '/api/cloudCert/open/cert/sign',
|
||||
$option
|
||||
);
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
// PKCS7签名验证接口
|
||||
// 对客户端签名信息进行验证,返回证书信息,同时可以配置回调服务,在验证成功后回调业务系统
|
||||
public function verifyPkcs7(string $sign_p7, array $data)
|
||||
{
|
||||
$generator = $this->container->get(IdGeneratorInterface::class);
|
||||
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'opType' => "签名验证",
|
||||
'requestId' => $generator->generate(),// 业务流水号,唯一
|
||||
'signedData' => $sign_p7, // 签名值:签名接口返回的signP7
|
||||
'toSign' => hash_hmac("sha1", json_encode($data, JSON_UNESCAPED_UNICODE), $this->secret), // 签名原文
|
||||
]
|
||||
];
|
||||
|
||||
dump($option);
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
$this->api_url . '/signgw-service/api/signature/verifyPkcs7',
|
||||
$option
|
||||
);
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 添加签章配置
|
||||
* @param string $user_id 用户id
|
||||
* @param string $card_num 身份证号
|
||||
* @param array $data
|
||||
* @return bool
|
||||
*/
|
||||
public function addUserSignConfig(string $user_id, string $card_num, array $data): bool
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'userId' => $user_id,//用户标识信息(为云证书entityId)
|
||||
'configKey' => $user_id, // 签章配置唯一标识,一张云证书配置一个
|
||||
'keypairType' => "3", // 秘钥类型(3云证书)
|
||||
'certSn' => $card_num, // 证书序列号,使用医生身份证号即可
|
||||
'signType' => "4", // 签章方式(签章类型; 4客户端坐标签章;5客户端关键字签章;)
|
||||
'signParam' => $data['sign_param'], // 签章配置,JSON
|
||||
'sealImg' => $data['seal_img'], // 签章图片,base64格式
|
||||
'sealType' => "4",
|
||||
'signTemplate' => "0",
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
$this->api_url . '/signature-server/api/open/signature/userSignConfig',
|
||||
$option
|
||||
);
|
||||
|
||||
return true;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 删除签章配置
|
||||
* @param string $user_id
|
||||
* @return bool
|
||||
*/
|
||||
public function deleteUserSignConfig(string $user_id): bool
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'userId' => $user_id,//用户标识信息(为云证书entityId)
|
||||
'configKey' => $user_id, // 签章配置唯一标识,一张云证书配置一个
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$this->httpRequest(
|
||||
$this->api_url . '/signature-server/api/open/signature/delSignConfig',
|
||||
$option
|
||||
);
|
||||
return true;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 获取用户签章图片
|
||||
* @param string $user_id
|
||||
* @return mixed
|
||||
*/
|
||||
public function getFetchUserSeal(string $user_id): mixed
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'userId' => $user_id,//用户标识信息(为云证书entityId)
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
$this->api_url . '/signature-server/api/open/signature/fetchUserSeal',
|
||||
$option
|
||||
);
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* PDF添加电子签章
|
||||
* @param string $user_id
|
||||
* @param array $data
|
||||
* @return mixed
|
||||
*/
|
||||
public function addSignPdf(string $user_id, array $data): mixed
|
||||
{
|
||||
$option = [
|
||||
'multipart' => [
|
||||
[
|
||||
'name' => 'pdfFile',
|
||||
'contents' => $data['pdf_file'],// 待签章PDF文件(字节流)
|
||||
],
|
||||
[
|
||||
'name' => 'userId',
|
||||
'contents' => $user_id, // 用户标识信息
|
||||
],
|
||||
[
|
||||
'name' => 'configKey',
|
||||
'contents' => $user_id, // 签章配置唯一标识
|
||||
],
|
||||
[
|
||||
'name' => 'signParams',
|
||||
'contents' => $data['sign_param'],// 签章参数,JSON格式数据,如果不指定,那么以签章配置接口配置为准
|
||||
],
|
||||
[
|
||||
'name' => 'cloudCertPass',
|
||||
'contents' => $user_id,// 云证书PIN码,云证书签章时使用
|
||||
],
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
$this->api_url . '/signature-server/api/open/signature/signPdf',
|
||||
$option
|
||||
);
|
||||
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 下载签章的pdf文件
|
||||
* @param string $user_id
|
||||
* @param string $file_id
|
||||
* @return mixed
|
||||
*/
|
||||
public function getSignedFile(string $entity_id, string $file_id): mixed
|
||||
{
|
||||
$arg = [
|
||||
'form_params' => [
|
||||
'userId' => $entity_id,// 用户标识信息(为云证书entityId)
|
||||
'fileId' => $file_id,// 签章接口返回的文件标识
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$option = [
|
||||
"headers" => [
|
||||
"app_id" => $this->app_id,
|
||||
"signature" => $this->getRequestSign($arg),
|
||||
],
|
||||
];
|
||||
|
||||
$option = array_merge($arg, $option);
|
||||
|
||||
$response = $this->client->post($this->api_url . '/signature-server/api/open/signature/fetchSignedFile', $option);
|
||||
|
||||
if ($response->getStatusCode() != '200') {
|
||||
// 请求失败
|
||||
throw new BusinessException($response->getBody()->getContents());
|
||||
}
|
||||
|
||||
// 将 Stream 对象转换为字符串
|
||||
return (string)$response->getBody()->getContents();
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* PDF签章文件验证
|
||||
* @param array $data
|
||||
* @return mixed
|
||||
*/
|
||||
public function verifyPdf(array $data): mixed
|
||||
{
|
||||
$option = [
|
||||
'multipart' => [
|
||||
[
|
||||
'name' => 'pdfFile',
|
||||
'contents' => $data['pdf_file'],// 待签章PDF文件(字节流)
|
||||
],
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest(
|
||||
$this->api_url . '/signature-server/api/open/signature/verifyPdf',
|
||||
$option
|
||||
);
|
||||
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,65 @@
|
||||
<?php
|
||||
|
||||
namespace Extend\Ca;
|
||||
|
||||
use App\Constants\HttpEnumCode;
|
||||
use App\Exception\BusinessException;
|
||||
use GuzzleHttp\Exception\GuzzleException;
|
||||
use Hyperf\Snowflake\IdGeneratorInterface;
|
||||
|
||||
/**
|
||||
* ca-四川ca云证书+电子签章-线上
|
||||
*/
|
||||
class CaOnline extends Ca
|
||||
{
|
||||
public function __construct()
|
||||
{
|
||||
parent::__construct();
|
||||
$offline = config('ca.online');
|
||||
if (empty($offline)) {
|
||||
throw new BusinessException("缺少ca线上配置");
|
||||
}
|
||||
$this->app_id = $offline['app_id'];
|
||||
$this->api_url = $offline['api_url'];
|
||||
$this->secret = $offline['secret'];
|
||||
}
|
||||
|
||||
/**
|
||||
* 申请云证书
|
||||
* @param array $data
|
||||
* @param string $type
|
||||
* @return mixed
|
||||
*/
|
||||
protected function getCloudCert(array $data, string $type = "Personal"): mixed
|
||||
{
|
||||
$option = [
|
||||
'form_params' => [
|
||||
'entityId' => $data['user_id'], // 用户唯一标识,由业务系统定义
|
||||
'entityType' => $type,// 用户类型,可选值[Personal/Organizational]
|
||||
'personalPhone' => (string)$data['mobile'], // 联系人电话
|
||||
'personalName' => $data['card_name'] ?? "", // 个人姓名,类型为Personal时必填
|
||||
'personalIdNumber' => $data['card_num'] ?? "", // 个人证件号,类型为Personal时必填
|
||||
'orgName' => $data['org_name'] ?? "", // 组织机构名称,信用代码类型为Organizational时必填
|
||||
'orgNumber' => $data['org_number'] ?? "", // 组织机构代码,信用代码类型为Organizational时必填
|
||||
'pin' => $data['user_id'], // 证书PIN码
|
||||
'province' => "四川省", // 卫生证书:省、州
|
||||
'locality' => "成都市", // 卫生证书:城市
|
||||
'authType' => "实人认证", // 委托鉴证方式[实人认证、线下认证、其它方式认证]
|
||||
'authTime' => time(), // 委托鉴证时间(鉴证完成的时间戳)单位:秒
|
||||
'authResult' => "认证通过", // 委托鉴证结果[认证通过]
|
||||
'authNoticeType' => "数字证书申请告知", // 委托鉴证告知类型[数字证书申请告知]
|
||||
]
|
||||
];
|
||||
|
||||
try {
|
||||
$response = $this->httpRequest($this->api_url . '/cloud-certificate-service' . '/api/cloudCert/open/v2/cert/certEnroll', $option);
|
||||
if (empty($response)) {
|
||||
// 返回值为空
|
||||
throw new BusinessException(HttpEnumCode::getMessage(HttpEnumCode::SERVER_ERROR));
|
||||
}
|
||||
return $response;
|
||||
} catch (GuzzleException $e) {
|
||||
throw new BusinessException($e->getMessage());
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user