Home  >  Article  >  Backend Development  >  How to develop api interface security verification example with PHP

How to develop api interface security verification example with PHP

小云云
小云云Original
2018-03-14 14:14:551972browse


In actual work, it is common to use PHP to write api interfaces. After PHP writes the interface, the front desk can obtain the data provided by the interface through the link, and the returned data is generally divided into For the two cases, xml and json, during this process, the server does not know the source of the request. It may be that someone else illegally calls our interface to obtain data, so security verification must be used.

Verification Principle

Schematic diagram

How to develop api interface security verification example with PHP

Principle

It can be seen clearly from the picture that the front desk wants to call interface, several parameters need to be used to generate a signature.

  • Time stamp: current time

  • Random number: randomly generated random number

  • Password : During front-end and back-end development, a logo known to both parties is equivalent to a secret code

  • Algorithm rules: The agreed-upon operation rules, the above three parameters can use the algorithm rules to generate a signature.

The frontend generates a signature. When accessing the interface is required, the timestamp, random number, and signature are passed to the backend through the URL. After getting the timestamp and random number in the background, it calculates the signature through the same algorithm rules, and then compares it with the passed signature. If it is the same, the data is returned.

Algorithm rules

In front-end and back-end interactions, algorithm rules are very important. The front-end and back-end must calculate signatures through algorithm rules. As for how to formulate the rules, it depends on how you like it.

My algorithm rules are

  1. Time stamp, random number, password are sorted in case order of the first letter

  2. Then Spliced ​​into a string

  3. perform sha1 encryption

  4. and then perform MD5 encryption

  5. Convert to uppercase .

Front desk

I don’t have an actual front desk here. I directly use a PHP file instead of the front desk, and then simulate a GET request through CURL. I am using the TP framework and the URL format is pathinfo format.

Source code

 createNonceStr();
        //生成签名
        $signature = $this -> arithmetic($timeStamp,$randomStr);
        //url地址
        $url = "http://www.apitest.com/Server/Server/respond/t/{$timeStamp}/r/{$randomStr}/s/{$signature}";
        $result = $this -> httpGet($url);
        dump($result);
    }

    //curl模拟get请求。
    private function httpGet($url){
        $curl = curl_init();

        //需要请求的是哪个地址
        curl_setopt($curl,CURLOPT_URL,$url);
        //表示把请求的数据已文件流的方式输出到变量中
        curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);

        $result = curl_exec($curl);
        curl_close($curl);
        return $result;
    }

    //随机生成字符串
    private function createNonceStr($length = 8) {
        $chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
        $str = "";
        for ($i = 0; $i 

Server side

Accept foreground data for verification

Source code

 arithmetic($timeStamp,$randomStr);
        if($str != $signature){
            echo "-1";
            exit;
        }
        //模拟数据
        $arr['name'] = 'api';
        $arr['age'] = 15;
        $arr['address'] = 'zz';
        $arr['ip'] = "192.168.0.1";
        echo json_encode($arr);
    }

    /**
     * @param $timeStamp 时间戳
     * @param $randomStr 随机字符串
     * @return string 返回签名
     */
    public function arithmetic($timeStamp,$randomStr){
        $arr['timeStamp'] = $timeStamp;
        $arr['randomStr'] = $randomStr;
        $arr['token'] = self::TOKEN;
        //按照首字母大小写顺序排序
        sort($arr,SORT_STRING);
        //拼接成字符串
        $str = implode($arr);
        //进行加密
        $signature = sha1($str);
        $signature = md5($signature);
        //转换成大写
        $signature = strtoupper($signature);
        return $signature;
    }
}

Result

string(57) "{"name":"api","age":15,"address":"zz","ip":"192.168.0.1"}"

Summary

This method is just one of them. In fact, there are many methods that can be used for security verification.

Related recommendations:

PHP about API interface instance sharing

PHP development API interface code sharing

How to use PHP to call the API interface to implement the weather query function

The above is the detailed content of How to develop api interface security verification example with PHP. For more information, please follow other related articles on the PHP Chinese website!

Statement:
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn