Home >Backend Development >PHP Tutorial >Alipay payment PHP background signature implementation method
Signing and signature verification can also be completed on the APP side. Considering security issues, signing and signature verification are best completed on the server side. This is also the official recommendation of Alipay, so the PHP side needs to pass the signed parameters to the APP. end. This article mainly shares with you the implementation method of PHP background signature for Alipay payment. I hope it can help everyone.
1. Download php Alipay sdk
https://doc.open.alipay.com/docs/doc.htm?spm=a219a.7629140.0.0.eCtVsf&treeId=54&articleId=103419&docType= 1 (old)
https://docs.open.alipay.com/54/103419/ (new)
2. View the Alipay App payment request parameter document, splice the request parameters, and sign
App payment request Parameter description
https://doc.open.alipay.com/docs/doc.htm?spm=a219a.7629140.0.0.wM4mV1&treeId=204&articleId=105465&docType=1 (old)
https://docs. open.alipay.com/204/105465/ (New)
First, the parameters are spliced to generate a signature, and then the previous parameters and signature are assembled. The core code is as follows:
require_once '/Alipay/aop/AopClient.php'; $private_path = "/Alipay/key/rsa_private_key.pem";//私钥路径 //构造业务请求参数的集合(订单信息) $content = array(); $content['subject'] = "商品的标题/交易标题/订单标题/订单关键字等"; $content['out_trade_no'] = "商户网站唯一订单号"; $content['timeout_express'] = "该笔订单允许的最晚付款时间"; $content['total_amount'] = "订单总金额(必须定义成浮点型)"; $content['product_code'] = "QUICK_MSECURITY_PAY";/销售产品码,固定值 $con = json_encode($content);//$content是biz_content的值,将之转化成json字符串
//公共参数 $Client = new \AopClient();//实例化支付宝sdk里面的AopClient类,下单时需要的操作,都在这个类里面 $param['app_id'] = '支付宝分配给开发者的应用ID'; $param['method'] = 'alipay.trade.app.pay';//接口名称,固定值 $param['charset'] = 'utf-8';//请求使用的编码格式 $param['sign_type'] = 'RSA2';//商户生成签名字符串所使用的签名算法类型 $param['timestamp'] = date("Y-m-d Hi:i:s");//发送请求的时间 $param['version'] = '1.0';//调用的接口版本,固定为:1.0 $param['notify_url'] = '支付宝服务器异步回调地址'; $param['biz_content'] = $con;//业务请求参数的集合,长度不限,json格式,即前面一步得到的 $paramStr = $Client->getSignContent($param);//组装请求签名参数 $sign = $Client->alonersaSign($paramStr, $private_path, 'RSA2', true);//生成签名 $param['sign'] = $sign; $str = $Client->getSignContentUrlencode($param);//最终请求参数
The description of the request, Alipay said very clearly, here is a screenshot again:
3. Signature verification
App will return a string after successful payment. The customer service side also needs to make a judgment, so I won’t be too verbose here, as shown below:
The next step is to verify the signature on the PHP server. Alipay asynchronously returns the data to the asynchronous callback address in post mode:
function notify() { require_once('/alipay/aop/AopClient.php'); $aop = new \AopClient; //$public_path = "key/rsa_public_key.pem";//公钥路径 $aop->alipayrsaPublicKey = "支付宝公钥"; //此处验签方式必须与下单时的签名方式一致 $flag = $aop->rsaCheckV1($_POST, NULL, "RSA2"); //验签通过后再实现业务逻辑,比如修改订单表中的支付状态。 /** * ①验签通过后核实如下参数out_trade_no、total_amount、seller_id * ②修改订单表 **/ //打印success,应答支付宝。必须保证本界面无错误。只打印了success,否则支付宝将重复请求回调地址。 echo 'success'; }
The signature verification failed all the time before. After searching for a long time, it was finally solved. The document says that the Alipay public key is used for signature verification, not the RSA2 public key. Special attention needs to be paid here to avoid using the wrong one.
Please see the screenshot:
Related recommendations:
realize WeChat scan code payment PHP code sharing
PHP realizes QQ, WeChat and Alipay payment collection The codes are consistent
Detailed explanation of UnionPay payment and refund examples on the PHP backend
The above is the detailed content of Alipay payment PHP background signature implementation method. For more information, please follow other related articles on the PHP Chinese website!