WeChatWebApp.php 8.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304
  1. <?php
  2. namespace App\Servers\Wechat;
  3. use App\Facades\Servers\Logs\Log;
  4. /**
  5. * 微信网站应用
  6. * @author 唐远望
  7. * @version 1.0
  8. * @date 2026-01-19
  9. */
  10. class WeChatWebApp
  11. {
  12. private $appId;
  13. private $appSecret;
  14. private $redirectUri;
  15. /**
  16. * 构造函数
  17. *
  18. * @param string $appId 应用唯一标识
  19. * @param string $appSecret 应用密钥
  20. * @param string $redirectUri 授权回调地址
  21. */
  22. public function __construct()
  23. {
  24. $this->appId = config('wechat.openplat.app_id',[]);
  25. $this->appSecret = config('wechat.openplat.secret',[]);
  26. $this->redirectUri = urlencode(config('wechat.openplat.release_host_url',[]));
  27. }
  28. /**
  29. * 第一步:生成授权URL,引导用户跳转到微信授权页面
  30. *
  31. * @param string $scope 应用授权作用域
  32. * snsapi_base - 静默授权,不弹出授权页面,只能获取openid
  33. * snsapi_userinfo - 弹出授权页面,可获取用户信息
  34. * @param string $state 重定向后会带上state参数,开发者可以填写任意参数值
  35. * @return string 授权URL
  36. */
  37. public function getAuthorizeUrl($scope = 'snsapi_base', $state = 'STATE')
  38. {
  39. $url = "https://open.weixin.qq.com/connect/oauth2/authorize?appid={$this->appId}&redirect_uri={$this->redirectUri}&response_type=code&scope={$scope}&state={$state}#wechat_redirect";
  40. return $url;
  41. }
  42. /**
  43. * 第二步:通过code获取access_token和openid
  44. *
  45. * @param string $code 授权code
  46. * @return array|false 成功返回数组,失败返回false
  47. */
  48. public function getAccessTokenByCode($code)
  49. {
  50. $url = "https://api.weixin.qq.com/sns/oauth2/access_token?appid={$this->appId}&secret={$this->appSecret}&code={$code}&grant_type=authorization_code";
  51. $result = $this->httpGet($url);
  52. if ($result) {
  53. $data = json_decode($result, true);
  54. if (!isset($data['errcode'])) {
  55. return $data; // 成功返回
  56. } else {
  57. $this->logError("获取access_token失败", $data);
  58. return false;
  59. }
  60. }
  61. return false;
  62. }
  63. /**
  64. * 刷新access_token
  65. *
  66. * @param string $refreshToken 刷新token
  67. * @return array|false 成功返回数组,失败返回false
  68. */
  69. public function refreshAccessToken($refreshToken)
  70. {
  71. $url = "https://api.weixin.qq.com/sns/oauth2/refresh_token?appid={$this->appId}&grant_type=refresh_token&refresh_token={$refreshToken}";
  72. $result = $this->httpGet($url);
  73. if ($result) {
  74. $data = json_decode($result, true);
  75. if (!isset($data['errcode'])) {
  76. return $data; // 成功返回
  77. } else {
  78. $this->logError("刷新access_token失败", $data);
  79. return false;
  80. }
  81. }
  82. return false;
  83. }
  84. /**
  85. * 获取用户信息(需要scope为snsapi_userinfo)
  86. *
  87. * @param string $accessToken 接口调用凭证
  88. * @param string $openid 用户唯一标识
  89. * @return array|false 成功返回数组,失败返回false
  90. */
  91. public function getUserInfo($accessToken, $openid)
  92. {
  93. $url = "https://api.weixin.qq.com/sns/userinfo?access_token={$accessToken}&openid={$openid}&lang=zh_CN";
  94. $result = $this->httpGet($url);
  95. if ($result) {
  96. $data = json_decode($result, true);
  97. if (!isset($data['errcode'])) {
  98. return $data; // 成功返回
  99. } else {
  100. $this->logError("获取用户信息失败", $data);
  101. return false;
  102. }
  103. }
  104. return false;
  105. }
  106. /**
  107. * 验证access_token是否有效
  108. *
  109. * @param string $accessToken 接口调用凭证
  110. * @param string $openid 用户唯一标识
  111. * @return bool 是否有效
  112. */
  113. public function checkAccessToken($accessToken, $openid)
  114. {
  115. $url = "https://api.weixin.qq.com/sns/auth?access_token={$accessToken}&openid={$openid}";
  116. $result = $this->httpGet($url);
  117. if ($result) {
  118. $data = json_decode($result, true);
  119. if (isset($data['errcode']) && $data['errcode'] == 0) {
  120. return true; // 有效
  121. }
  122. }
  123. return false; // 无效
  124. }
  125. /**
  126. * 完整的授权流程处理
  127. *
  128. * @return array|false 成功返回用户信息数组,失败返回false
  129. */
  130. public function handleAuthorization()
  131. {
  132. // 检查是否有授权code
  133. if (!isset($_GET['code'])) {
  134. // 没有code,跳转到授权页面
  135. $url = $this->getAuthorizeUrl('snsapi_userinfo', 'authorize');
  136. header("Location: {$url}");
  137. exit;
  138. }
  139. // 获取授权code
  140. $code = $_GET['code'];
  141. // 通过code获取access_token
  142. $tokenData = $this->getAccessTokenByCode($code);
  143. if (!$tokenData) {
  144. return false;
  145. }
  146. // 存储token信息到session
  147. session_start();
  148. $_SESSION['wechat_access_token'] = $tokenData['access_token'];
  149. $_SESSION['wechat_refresh_token'] = $tokenData['refresh_token'];
  150. $_SESSION['wechat_openid'] = $tokenData['openid'];
  151. $_SESSION['wechat_token_expire'] = time() + $tokenData['expires_in'];
  152. return $tokenData;
  153. }
  154. /**
  155. * 获取当前有效的access_token(自动刷新)
  156. *
  157. * @return string|false 有效的access_token
  158. */
  159. public function getValidAccessToken()
  160. {
  161. session_start();
  162. // 检查session中是否有token信息
  163. if (!isset($_SESSION['wechat_access_token'])) {
  164. return false;
  165. }
  166. $accessToken = $_SESSION['wechat_access_token'];
  167. $refreshToken = $_SESSION['wechat_refresh_token'];
  168. $openid = $_SESSION['wechat_openid'];
  169. $expireTime = $_SESSION['wechat_token_expire'];
  170. // 检查token是否即将过期(提前5分钟刷新)
  171. if (time() > $expireTime - 300) {
  172. // 刷新token
  173. $newTokenData = $this->refreshAccessToken($refreshToken);
  174. if ($newTokenData) {
  175. // 更新session中的token信息
  176. $_SESSION['wechat_access_token'] = $newTokenData['access_token'];
  177. $_SESSION['wechat_refresh_token'] = $newTokenData['refresh_token'];
  178. $_SESSION['wechat_token_expire'] = time() + $newTokenData['expires_in'];
  179. $accessToken = $newTokenData['access_token'];
  180. } else {
  181. // 刷新失败,需要重新授权
  182. return false;
  183. }
  184. }
  185. return $accessToken;
  186. }
  187. /**
  188. * HTTP GET 请求
  189. *
  190. * @param string $url 请求URL
  191. * @return string|false 响应内容
  192. */
  193. private function httpGet($url)
  194. {
  195. if (function_exists('curl_init')) {
  196. $ch = curl_init();
  197. curl_setopt($ch, CURLOPT_URL, $url);
  198. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  199. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
  200. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);
  201. curl_setopt($ch, CURLOPT_TIMEOUT, 30);
  202. $response = curl_exec($ch);
  203. if (curl_errno($ch)) {
  204. $this->logError("CURL错误", curl_error($ch));
  205. curl_close($ch);
  206. return false;
  207. }
  208. curl_close($ch);
  209. return $response;
  210. } else {
  211. // 备用方法:使用file_get_contents
  212. $context = stream_context_create([
  213. 'ssl' => [
  214. 'verify_peer' => false,
  215. 'verify_peer_name' => false,
  216. ]
  217. ]);
  218. return file_get_contents($url, false, $context);
  219. }
  220. }
  221. /**
  222. * 错误日志记录
  223. *
  224. * @param string $message 错误信息
  225. * @param mixed $data 错误数据
  226. */
  227. private function logError($message, $data = null)
  228. {
  229. $log = date('Y-m-d H:i:s') . " - {$message}";
  230. if ($data !== null) {
  231. $log .= " - " . (is_array($data) ? json_encode($data) : $data);
  232. }
  233. Log::info('wechat_oauth_error', '微信登录错误日志', ['data' => $log, 'error' => PHP_EOL]);
  234. }
  235. /**
  236. * 获取当前openid
  237. *
  238. * @return string|false openid
  239. */
  240. public function getOpenId()
  241. {
  242. session_start();
  243. return isset($_SESSION['wechat_openid']) ? $_SESSION['wechat_openid'] : false;
  244. }
  245. /**
  246. * 清除session中的授权信息
  247. */
  248. public function clearSession()
  249. {
  250. session_start();
  251. unset(
  252. $_SESSION['wechat_access_token'],
  253. $_SESSION['wechat_refresh_token'],
  254. $_SESSION['wechat_openid'],
  255. $_SESSION['wechat_token_expire']
  256. );
  257. }
  258. }