TestSecurity.php 12 KB


  1. <?php
  2. /**
  3. * Created by PhpStorm.
  4. * User: stanley-king
  5. * Date: 2018/12/12
  6. * Time: 11:01 AM
  7. */
  8. declare(strict_types=1);
  9. define('APP_ID', 'test');
  10. define('BASE_ROOT_PATH', str_replace('/test', '', dirname(__FILE__)));
  11. require_once(BASE_ROOT_PATH . '/global.php');
  12. require_once(BASE_CORE_PATH . '/lrlz.php');
  13. require_once(BASE_ROOT_PATH . '/fooder.php');
  14. use PHPUnit\Framework\TestCase;
  15. class TestAddData extends TestCase
  16. {
  17. public static function setUpBeforeClass() : void
  18. {
  19. Base::run_util();
  20. }
  21. public function testDecode()
  22. {
  23. $x = 'eyJpdiI6InpmVEFJOEtCNkxaL3Q5UHB4TFZOK2c9PSIsImVuY3J5cHRlZERhdGEiOiI0NWpJL2dsVXBBc1lpRTZXWVJ1bjlUeXVrUFlVTmJqRysxRy9MYnNQcUZFeTNUZFVROSsvTzNNTEZOaGJIbEdUdzdDMVhwN0lEbTdkQ1dVNVd4Z21sUzRYSGNNR2wrbUR5ZnVWcDAvNjhmVU81ajQ5eU1tNzZkRnl0NnZvOGtpRWxqdStCN0dBQzN6M3hpakhuY0dGbWl4Ujhwd1k2SnN0eWZQb3gzSHlpaFg2ZGE4cHZrbisxK0FLOVNyR0JsRGlCUFI4cUJzbkkxbzNlVzZ5YkRGQzVBPT0ifQ%253D%253D';
  24. $x = urldecode($x);
  25. $y = urldecode($x);
  26. $user = base64_decode($y);
  27. $z = json_decode($user,true);
  28. Log::record("{$z}",Log::DEBUG);
  29. }
  30. public function testPay()
  31. {
  32. $pri_key = BASE_DATA_PATH .'/api/alipay/key/rsa_private_key.pem';
  33. $pub_key = BASE_DATA_PATH.'/api/alipay/key/alipay_public_key.pem';
  34. $key = file_get_contents($pri_key);
  35. $pri = openssl_get_privatekey($key);
  36. $err = openssl_error_string();
  37. //
  38. $key = file_get_contents($pub_key);
  39. $pub = openssl_get_publickey($key);
  40. $err = openssl_error_string();
  41. $body = 'discount=0.00&payment_type=1&subject=%E5%AE%9E%E7%89%A9%E8%AE%A2%E5%8D%95_580507223514222365&trade_no=2016012721001004800042946454&buyer_email=13911129867&gmt_create=2016-01-27+15%3A25%3A29&notify_type=trade_status_sync&quantity=1&out_trade_no=580507223514222365&seller_id=2088121219613123&notify_time=2016-01-27+15%3A25%3A29&body=%E5%95%86%E5%93%81%E8%AF%A6%E6%83%85&trade_status=WAIT_BUYER_PAY&is_total_fee_adjust=Y&total_fee=8.00&seller_email=napheir.ao%40lrlz.com&price=8.00&buyer_id=2088202332994802&notify_id=66af3b99b765d046d2d533eaf6558fcm68&use_coupon=N';
  42. $body = 'discount=0.00&payment_type=1&subject=%E5%AE%9E%E7%89%A9%E8%AE%A2%E5%8D%95_280507226197761365&trade_no=2016012721001004800047345139&buyer_email=13911129867&gmt_create=2016-01-27+16%3A10%3A55&notify_type=trade_status_sync&quantity=1&out_trade_no=280507226197761365&seller_id=2088121219613123&notify_time=2016-01-27+16%3A10%3A55&body=%E5%95%86%E5%93%81%E8%AF%A6%E6%83%85&trade_status=WAIT_BUYER_PAY&is_total_fee_adjust=Y&total_fee=8.00&seller_email=napheir.ao%40lrlz.com&price=8.00&buyer_id=2088202332994802&notify_id=44d5cc359f27f5cb6e31fb10f480fb0m68&use_coupon=N';
  43. openssl_sign($body, $signed, $pri);
  44. $res = openssl_verify($body, $signed, $pub);
  45. $err = openssl_error_string();
  46. $s = base64_encode($signed);
  47. $s = urlencode($s);
  48. $sign='lnxpRmnHsaeUoPgtCrGm%2FtWohi3ORJk85q9Ic6X4c10q9O%2FASMXA2Z%2BzAH9%2BgPZAwsMywUA9O4HQ3ZCCrSpPhzJ8hEQ8Dc2SsMnvmeY6UqA7Zi6MZBTSeU1AuV3IV0tN4DTpnuk9ceetwQhNEwCiRo9vjrC%2B0TTHGfXb94OfJuM%3D';
  49. $signx = urldecode($sign);
  50. $signy = base64_decode($signx);
  51. $res = openssl_verify($body, $signy, $pub);
  52. $err = openssl_error_string();
  53. // openssl_encrypt()
  54. //
  55. //
  56. // $signed = base64_encode($signed);
  57. // $signed = urlencode($signed);
  58. //
  59. // $body = 'body=%E5%95%86%E5%93%81%E8%AF%A6%E6%83%85&buyer_email=bestcoolbear%40163.com&buyer_id=2088402949754402&discount=0.00&gmt_create=2015-12-31+14%3A51%3A41&gmt_payment=2015-12-31+14%3A51%3A41&is_total_fee_adjust=N&notify_id=35ceee6a4348f21bb27838770223ad0j34&notify_time=2015-12-31+14%3A51%3A41&notify_type=trade_status_sync&out_trade_no=150504888692984277&payment_type=1&price=0.01&quantity=1&seller_email=napheir.ao%40lrlz.com&seller_id=2088121219613123&subject=%E5%AE%9E%E7%89%A9%E8%AE%A2%E5%8D%95_150504888692984277&total_fee=0.01&trade_no=2015123121001004400035472261&trade_status=TRADE_SUCCESS&use_coupon=N';
  60. // $data = 'gNvKQd0GXULuvr%2F1FKjQrKVI%2BeT%2B8qz2ohSohfkzn%2Fx5ajMUdDD1zBXsxbv9%2FJZbaLq7KihhJmlb28E02S6hI9OlG7f7%2BTJ%2FTtrh8Xy2%2FYiU2KNpjtowS%2FM3io23lgfyQgIEQ0xIpyMZg4NRdaoW6thnrgQzs%2B9rY57iFgdG%2B24%3D';
  61. // openssl_sign($body, $sig, $pri);
  62. // $sig64 = base64_encode($sig);
  63. // $res = openssl_verify($body, $sig, $pub);
  64. // $err = openssl_error_string();
  65. }
  66. public static function zero_iv($ivlen) {
  67. $result = '';
  68. for ($i = 0; $i < $ivlen; ++$i) {
  69. $result .= chr(0);
  70. }
  71. return $result;
  72. }
  73. public function testEncrypt()
  74. {
  75. $plaintext = "message to be encrypted";
  76. $cipher="AES-128-CBC";
  77. $ivlen = openssl_cipher_iv_length($cipher);
  78. // $iv = openssl_random_pseudo_bytes($ivlen);
  79. $iv = self::zero_iv($ivlen);
  80. $key = '55668899';
  81. $ciphertext = openssl_encrypt($plaintext, $cipher, $key, 0, $iv);
  82. $original_plaintext = openssl_decrypt($ciphertext, $cipher, $key, 0, $iv);
  83. }
  84. public function testDecrypt()
  85. {
  86. $ciphers = openssl_get_cipher_methods();
  87. $cipher_text = 'pvmi16xnV6C3/1O8637DUKMTuNuZruETPg5TXE8rs78=';
  88. $cipher="AES-128-CBC";
  89. $ivlen = openssl_cipher_iv_length($cipher);
  90. $iv = self::zero_iv($ivlen);
  91. $key = '55668899';
  92. $plaintext = openssl_decrypt($cipher_text, $cipher, $key, 0, $iv);
  93. }
  94. public function testSign()
  95. {
  96. //$body= 'body=order_sn=8000000000295701&buyer_email=13911129867&buyer_id=2088202332994802&discount=0.00&gmt_create=2016-10-29 20:51:36&gmt_payment=2016-10-29 20:51:37&is_total_fee_adjust=N&notify_id=0960c111697dbcdfbedad9ed94625adm6a&notify_time=2016-10-29 20:51:38&notify_type=trade_status_sync&out_trade_no=650531089488891490&payment_type=1&price=1.80&quantity=1&seller_email=napheir.ao@lrlz.com&seller_id=2088121219613123&subject=实物订单_650531089488891490&total_fee=1.80&trade_no=2016102921001004800260656982&trade_status=TRADE_SUCCESS&use_coupon=N';
  97. $body = "xxxxffff";
  98. $pri_key = BASE_DATA_PATH .'/api/alipay/key/rsa_private_key.pem';
  99. $pub_key = BASE_DATA_PATH.'/api/alipay/key/alipay_public_key.pem';
  100. $key = file_get_contents($pri_key);
  101. $pri = openssl_get_privatekey($key);
  102. openssl_sign($body, $signed, $pri);
  103. $sign = base64_encode($signed);
  104. $key = file_get_contents($pub_key);
  105. $pub = openssl_get_publickey($key);
  106. $res = openssl_verify($body, $signed, $pub);
  107. }
  108. public function testB64()
  109. {
  110. $pub_key = BASE_DATA_PATH.'/api/alipay/key/alipay_public_key.pem';
  111. $key = file_get_contents($pub_key);
  112. $pub = openssl_get_publickey($key);
  113. $err = openssl_error_string();
  114. $data = 'MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAL+I5/3VVhfpc3TmsUjuwc8mrZycavjuE4MV9Z+EXDvPy55PAYjDvKfMtRMCsJYgO4R0fyyb1OhvglyXUKLFajxOhUm/4K2hnI1E/+8zPbY0CU5Osr4C9sxWHtY66ugTx+O4W3e4CxYTfHn+C6EuiYJ2DWJig+Obphd8CPFYFzLxAgMBAAECgYA+og9zEytXIHEv/ixlNCZOjlBhkUjt5DSfPjQXGNpseLQWLbHLvm5X1Po1oECMpzevRcU8mizSYXyYuKaWw8XMJ7/CC6A8fSBdlUeLEfTfisurEnzeUsal2K/n+WAAFj+TUncnqYtEqCCT+9c4jVkfik7FNxjbcio9p27QKDzYwQJBAOlWs593knByuSFOVnIiphhKlZy+6MUxquxhP+3NlXVaTCHHbBl8xt3fLqLmrXPUHvAt39wJ8fAvLDuNUQgP2gkCQQDSIt7bZi2hmzqfXK9rqVyJ16o0Hwqa8Z6PYhodSSsf61h3+wxdEpDFxIV9JnPWBPhCxcX+d1VddyLZacXbKuupAkBpwFesID8II5Zv19cp5zYrsDHaVlOce4QhmXmlxxTDmOcEMCN38asXhzzVq4JVCn/zDnd0fDVgS6DaZJOi+bwxAkAJg2iheCvCsDtkMZcDgcRdvTTIbUtWnm+2QBO8la5tIIN90xDJOejx+yar9syxuMHgjAGdtptXwugB/cbmWDgZAkEAiRoMv6p7WKNU34kZqpvXMIhN6hUihquVFZDJ7wiBr1tCLw/kW3uhciCViM68FgLStuefTfssgr9+oHVw/o4GjA==';
  115. $pem = "-----BEGIN PUBLIC KEY-----\n" . $data . "-----END PUBLIC KEY-----\n";
  116. $x = openssl_pkey_get_private($pem);
  117. $y = openssl_error_string();
  118. }
  119. public function testLocalSign()
  120. {
  121. // $pri_key = BASE_DATA_PATH.'/api/alipay/key/rsa_private_key.pem';
  122. // $pub_key = BASE_DATA_PATH.'/api/alipay/key/rsa_public_key.pem';
  123. $body ='body=order_sn=8000000000295404&buyer_email=13911129867&buyer_id=2088202332994802&discount=0.00&gmt_create=2016-10-29 20:24:18&gmt_payment=2016-10-29 20:24:18&is_total_fee_adjust=N&notify_id=f29b67caf1da662d7210f04b3675f3am6a&notify_time=2016-10-29 23:52:32&notify_type=trade_status_sync&out_trade_no=850531087853085490&payment_type=1&price=0.76&quantity=1&seller_email=napheir.ao@lrlz.com&seller_id=2088121219613123&subject=实物订单_850531087853085490&total_fee=0.76&trade_no=2016102921001004800260616422&trade_status=TRADE_SUCCESS&use_coupon=N';
  124. $sign ='WG+9QtqYOlmxVRzTVyso2toN1wOxXz4aBUS7ZRL7nzvDCdXaZRU3I2bN8EZ2pcag8DiU6eUXI99YY0MaTjnAJgGGESzd5S1KHDSg0ZNdsZueaLhmYQNGpap7jyRxBSDNIR+tEPU5FzgDivU4uK4f5PWu0FiOd9jOfXLIkGneRxg=';
  125. $pub_key = '/Users/stanley-king/Desktop/payment/alipay/key/alipay_public_key.pem';
  126. // $pri_key = '/Users/stanley-king/.ssh/rsa_private_key.pem';
  127. // $pub_key = '/Users/stanley-king/.ssh/rsa_public_key.pem';
  128. // $pri_key = '/Users/stanley-king/work/PHPProject/rsa_private_key.pem';
  129. // $pub_key = '/Users/stanley-king/work/PHPProject/rsa_public_key.pem';
  130. // $key = file_get_contents($pri_key);
  131. // $pri = openssl_get_privatekey($key);
  132. // openssl_sign($body, $signed, $pri);
  133. // $sign = base64_encode($signed);
  134. $key = file_get_contents($pub_key);
  135. $pub = openssl_get_publickey($key);
  136. $signed = base64_decode($sign);
  137. $res = openssl_verify($body, $signed, $pub);
  138. }
  139. public function testCmbpay()
  140. {
  141. $x = 'BranchID=0021&CoNo=006438&BillNo=5320089577&Amount=2.05&Date=20161030&ExpireTimeSpan=30&MerchantUrl=http%3A%2F%2F121.43.114.153%2Fmobile%2Fcmbpay_notify.php&MerchantPara=pay_sn%3A610531141658503490%7Corder_sn%3A8000000000298701%7Cmember_id%3A36490&MerchantCode=%7C4xKshccAHleC65HWnU828KX1n5MtZAcd1Ma4XfVTwPibT3QJLqgRwZhxSclZyyV8WE%2Fkv8jT01eYd1y%2Aed6SsJHw2BuxSoIqGeXL4b0HMTqYaZ%2AcGEyJ4n8nVYW7vDn%2AM%2FvnDRoCuahqmft0i2suJlgZP07w36WzDPmN9SKRd60%2A4HCG2GdSy0gJ1f8tcW9C7qW6ltC7XzWlZ9yJnuKeDSJ4JHzSy24invATyz8qOuehypiWCCRLYouNCJorAqFETHZgB5kfEEJzH%2AODIf24Fywe%2Amuib96thBMGwJ1A%2AuLl4FqlchHx6QYCUyxxRNcmnF7YPkfcQs43g4ekaiHKudxmAZ%2AwJMKxPRen3g9TUyXvqSW%2FpxyPELKlKJQYUGodBn6kZN0yQ7Pw%7C4fd51f4fe55b76e5e17538d7969b2fdd8f0b8e67&MerchantRetUrl=http%3A%2F%2F121.43.114.153%2Fmobile%2Findex.php&MerchantRetPara=act%3Dpay_return%26op%3Dcmbpay%26pay_sn%3D610531141658503490%26order_sn%3D8000000000298701%26member_id%3D36490';
  142. $y = urldecode($x);
  143. }
  144. public function testPubkey()
  145. {
  146. $file = fopen('/Users/stanley-king/work/PHPProject/public.key','r');
  147. $data = fread($file,1024);
  148. fclose($file);
  149. $base64 = base64_encode($data);
  150. }
  151. public function testPublicKey()
  152. {
  153. $CMPPAY_ONLINE = true;
  154. if($CMPPAY_ONLINE == true) {
  155. $pub_key = 'MIGJAoGBALKsktbh7j9O9pM0p7qnxxImgODqxjpiT7Xl2bvZCywJtwsNI6CchqAagOYGJjG0NZsnjFunTw5YM9TD5KxsUOILAL6IaNMH/fWREhVjkUDJ4CYtLWlKozElvXRp1iZxf66yHHhN4t7TE5S9NWpEBSn37TEfFLU99Go1WReI1XN1AgMBAAE=';
  156. } else {
  157. $pub_key = 'MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBALuUIwMGhvbpCwYzKCMzvSMQiLAAj5y74cN09N1TXVONPWhvLWkuzEPSd1ogPJLWiVyEG7gEIBT3zTlCV+NMou0CAwEAAQ==';
  158. }
  159. $pk = chunk_split($pub_key, 64, "\n");
  160. $pk = "-----BEGIN PUBLIC KEY-----\n{$pk}-----END PUBLIC KEY-----\n";
  161. $pkid = openssl_pkey_get_public($pub_key);
  162. }
  163. public function priKey()
  164. {
  165. $pri_key = BASE_DATA_PATH . '/api/alipay/key/lrlz_private_key.pem';
  166. $key = file_get_contents($pri_key);
  167. return $key;
  168. }
  169. public function pubKey()
  170. {
  171. $pub_key = BASE_DATA_PATH . '/api/alipay/key/lrlz_public_key.pem';
  172. $key = file_get_contents($pub_key);
  173. return $key;
  174. }
  175. public function testVerify()
  176. {
  177. $body = "act=login&channel=0&client_type=mini&op=wxauthen&relay_id=0&user_info=%5Bobject%20Object%5D";
  178. $sign64 = 'jm0ieDFHo+7sDsIg4Jt7W+hqvX8O6Qq6uLqIP7N2pdH07K7A3qDqc5ymDayiwp/wgMEgEACkqPV8P8z6xP/jdduyu6DmZqkjt00EXfHXTglhd58Y4BMVqTtf53LeMN+U+Z9F5L2Y/2mFyI0q+tv1XGDtOqLiHUeiRSzdfE1qyso=';
  179. // $pri = openssl_get_privatekey($this->priKey());
  180. // openssl_sign($body, $signed, $pri);
  181. // $sign = base64_encode($signed);
  182. $signed = base64_decode($sign64);
  183. $pub = openssl_get_publickey($this->pubKey());
  184. $res = openssl_verify($body, $signed, $pub);
  185. }
  186. }