Signer.cs 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473
  1. using System;
  2. using System.Collections.Generic;
  3. using System.Globalization;
  4. using System.IO;
  5. using System.Net;
  6. using System.Net.Http;
  7. using System.Security.Cryptography;
  8. using System.Text;
  9. // HWS API Gateway Signature
  10. namespace PTMedicalInsurance.APIGATEWAY_SDK
  11. {
  12. public class HttpRequest
  13. {
  14. public string method;
  15. public string host; /* http://example.com */
  16. public string uri = "/"; /* /request/uri */
  17. public Dictionary<string, List<string>> query = new Dictionary<string, List<string>>();
  18. public WebHeaderCollection headers = new WebHeaderCollection();
  19. public string body = "";
  20. public string canonicalRequest;
  21. public string stringToSign;
  22. public HttpRequest(string method = "GET", Uri url = null, WebHeaderCollection headers = null, string body = null)
  23. {
  24. if (method != null)
  25. {
  26. this.method = method;
  27. }
  28. if (url != null)
  29. {
  30. host = url.Scheme + "://" + url.Host + ":" + url.Port;
  31. uri = url.GetComponents(UriComponents.Path | UriComponents.KeepDelimiter, UriFormat.Unescaped);
  32. query = new Dictionary<string, List<string>>();
  33. if (url.Query.Length > 1)
  34. {
  35. foreach (var kv in url.Query.Substring(1).Split('&'))
  36. {
  37. string[] spl = kv.Split(new char[] { '=' }, 2);
  38. string key = Uri.UnescapeDataString(spl[0]);
  39. string value = "";
  40. if (spl.Length > 1)
  41. {
  42. value = Uri.UnescapeDataString(spl[1]);
  43. }
  44. if (query.ContainsKey(key))
  45. {
  46. query[key].Add(value);
  47. }
  48. else
  49. {
  50. query[key] = new List<string> { value };
  51. }
  52. }
  53. }
  54. }
  55. if (headers != null)
  56. {
  57. this.headers = headers;
  58. }
  59. if (body != null)
  60. {
  61. this.body = body;
  62. }
  63. }
  64. }
  65. public partial class Signer
  66. {
  67. const string BasicDateFormat = "yyyyMMddTHHmmssZ";
  68. const string Algorithm = "SDK-HMAC-SHA256";
  69. const string HeaderXDate = "X-Sdk-Date";
  70. const string HeaderHost = "host";
  71. const string HeaderAuthorization = "Authorization";
  72. const string HeaderContentSha256 = "X-Sdk-Content-Sha256";
  73. readonly HashSet<string> unsignedHeaders = new HashSet<string> { "content-type" };
  74. private string key;
  75. private string secret;
  76. public string AppKey
  77. {
  78. get => key;
  79. set => key = value;
  80. }
  81. public string AppSecret
  82. {
  83. get => secret;
  84. set => secret = value;
  85. }
  86. public string Key
  87. {
  88. get => key;
  89. set => key = value;
  90. }
  91. public string Secret
  92. {
  93. get => secret;
  94. set => secret = value;
  95. }
  96. byte[] hmacsha256(byte[] keyByte, string message)
  97. {
  98. byte[] messageBytes = Encoding.UTF8.GetBytes(message);
  99. using (var hmacsha256 = new HMACSHA256(keyByte))
  100. {
  101. return hmacsha256.ComputeHash(messageBytes);
  102. }
  103. }
  104. // Build a CanonicalRequest from a regular request string
  105. //
  106. // CanonicalRequest =
  107. // HTTPRequestMethod + '\n' +
  108. // CanonicalURI + '\n' +
  109. // CanonicalQueryString + '\n' +
  110. // CanonicalHeaders + '\n' +
  111. // SignedHeaders + '\n' +
  112. // HexEncode(Hash(RequestPayload))
  113. private void WriteLogFile(string FunNO, string InParam, string OutParam)
  114. {
  115. string filePath = AppDomain.CurrentDomain.BaseDirectory + "GSYBLogLog";
  116. if (!Directory.Exists(filePath))
  117. {
  118. Directory.CreateDirectory(filePath);
  119. }
  120. string logPath = AppDomain.CurrentDomain.BaseDirectory + "GSYBLog\\" + DateTime.Now.ToString("yyyy-MM-dd") + "C#.txt";
  121. try
  122. {
  123. using (StreamWriter sw = File.AppendText(logPath))
  124. {
  125. sw.WriteLine(" 交易名:" + FunNO);
  126. sw.WriteLine(" 时间:" + DateTime.Now.ToString("yyyy-MM-dd HH:mm:ss"));
  127. sw.WriteLine(" 入参:" + InParam);
  128. sw.WriteLine(" 出参:" + OutParam);
  129. sw.WriteLine("****************分割线**********************************");
  130. sw.WriteLine();
  131. sw.Flush();
  132. sw.Close();
  133. sw.Dispose();
  134. }
  135. }
  136. catch (IOException e)
  137. {
  138. using (StreamWriter sw = File.AppendText(logPath))
  139. {
  140. sw.WriteLine(" 交易名:" + FunNO);
  141. sw.WriteLine(" 入参:" + InParam);
  142. sw.WriteLine(" 异常:" + e.Message);
  143. sw.WriteLine(" 时间:" + DateTime.Now.ToString("yyy-MM-dd HH:mm:ss"));
  144. sw.WriteLine("********************分割线******************************");
  145. sw.WriteLine();
  146. sw.Flush();
  147. sw.Close();
  148. sw.Dispose();
  149. }
  150. }
  151. }
  152. string CanonicalRequest(HttpRequest r, List<string> signedHeaders)
  153. {
  154. string hexencode;
  155. if (r.headers.Get(HeaderContentSha256) != null)
  156. {
  157. hexencode = r.headers.Get(HeaderContentSha256);
  158. }
  159. else
  160. {
  161. var data = Encoding.UTF8.GetBytes(r.body);
  162. hexencode = HexEncodeSHA256Hash(data);
  163. }
  164. return string.Format("{0}\n{1}\n{2}\n{3}\n{4}\n{5}", r.method, CanonicalURI(r), CanonicalQueryString(r), CanonicalHeaders(r, signedHeaders), string.Join(";", signedHeaders), hexencode);
  165. }
  166. string CanonicalURI(HttpRequest r)
  167. {
  168. var pattens = r.uri.Split('/');
  169. List<string> uri = new List<string>();
  170. foreach (var v in pattens)
  171. {
  172. uri.Add(UrlEncode(v));
  173. }
  174. var urlpath = string.Join("/", uri);
  175. if (urlpath[urlpath.Length - 1] != '/')
  176. {
  177. urlpath = urlpath + "/"; // always end with /
  178. }
  179. //r.uri = urlpath;
  180. return urlpath;
  181. }
  182. string CanonicalQueryString(HttpRequest r)
  183. {
  184. List<string> keys = new List<string>();
  185. foreach (var pair in r.query)
  186. {
  187. keys.Add(pair.Key);
  188. }
  189. keys.Sort(String.CompareOrdinal);
  190. List<string> a = new List<string>();
  191. foreach (var key in keys)
  192. {
  193. string k = UrlEncode(key);
  194. List<string> values = r.query[key];
  195. values.Sort(String.CompareOrdinal);
  196. foreach (var value in values)
  197. {
  198. string kv = k + "=" + UrlEncode(value);
  199. a.Add(kv);
  200. }
  201. }
  202. return string.Join("&", a);
  203. }
  204. string CanonicalHeaders(HttpRequest r, List<string> signedHeaders)
  205. {
  206. List<string> a = new List<string>();
  207. foreach (string key in signedHeaders)
  208. {
  209. var values = new List<string>(r.headers.GetValues(key));
  210. values.Sort(String.CompareOrdinal);
  211. foreach (var value in values)
  212. {
  213. a.Add(key + ":" + value.Trim());
  214. r.headers.Set(key, Encoding.GetEncoding("iso-8859-1").GetString(Encoding.UTF8.GetBytes(value)));
  215. }
  216. }
  217. return string.Join("\n", a) + "\n";
  218. }
  219. List<string> SignedHeaders(HttpRequest r)
  220. {
  221. List<string> a = new List<string>();
  222. foreach (string key in r.headers.AllKeys)
  223. {
  224. string keyLower = key.ToLower();
  225. if (!unsignedHeaders.Contains(keyLower))
  226. {
  227. a.Add(key.ToLower());
  228. }
  229. }
  230. a.Sort(String.CompareOrdinal);
  231. return a;
  232. }
  233. static char GetHexValue(int i)
  234. {
  235. if (i < 10)
  236. {
  237. return (char)(i + '0');
  238. }
  239. return (char)(i - 10 + 'a');
  240. }
  241. public static string toHexString(byte[] value)
  242. {
  243. int num = value.Length * 2;
  244. char[] array = new char[num];
  245. int num2 = 0;
  246. for (int i = 0; i < num; i += 2)
  247. {
  248. byte b = value[num2++];
  249. array[i] = GetHexValue(b / 16);
  250. array[i + 1] = GetHexValue(b % 16);
  251. }
  252. return new string(array, 0, num);
  253. }
  254. // Create a "String to Sign".
  255. string StringToSign(string canonicalRequest, DateTime t)
  256. {
  257. SHA256 sha256 = new SHA256Managed();
  258. var bytes = sha256.ComputeHash(Encoding.UTF8.GetBytes(canonicalRequest));
  259. sha256.Clear();
  260. return string.Format("{0}\n{1}\n{2}", Algorithm, t.ToUniversalTime().ToString(BasicDateFormat), toHexString(bytes));
  261. }
  262. // Create the HWS Signature.
  263. string SignStringToSign(string stringToSign, byte[] signingKey)
  264. {
  265. byte[] hm = hmacsha256(signingKey, stringToSign);
  266. return toHexString(hm);
  267. }
  268. // HexEncodeSHA256Hash returns hexcode of sha256
  269. public static string HexEncodeSHA256Hash(byte[] body)
  270. {
  271. SHA256 sha256 = new SHA256Managed();
  272. var bytes = sha256.ComputeHash(body);
  273. sha256.Clear();
  274. return toHexString(bytes);
  275. }
  276. public static string HexEncodeSHA256HashFile(string fname)
  277. {
  278. SHA256 sha256 = new SHA256Managed();
  279. using (var fs = new FileStream(fname, FileMode.Open))
  280. {
  281. var bytes = sha256.ComputeHash(fs);
  282. sha256.Clear();
  283. return toHexString(bytes);
  284. }
  285. }
  286. // Get the finalized value for the "Authorization" header. The signature parameter is the output from SignStringToSign
  287. string AuthHeaderValue(string signature, List<string> signedHeaders)
  288. {
  289. return string.Format("{0} Access={1}, SignedHeaders={2}, Signature={3}", Algorithm, key, string.Join(";", signedHeaders), signature);
  290. }
  291. public bool Verify(HttpRequest r, string signature)
  292. {
  293. if (r.method != "POST" && r.method != "PATCH" && r.method != "PUT")
  294. {
  295. r.body = "";
  296. }
  297. var time = r.headers.GetValues(HeaderXDate);
  298. if (time == null)
  299. {
  300. return false;
  301. }
  302. DateTime t = DateTime.ParseExact(time[0], BasicDateFormat, CultureInfo.CurrentCulture);
  303. var signedHeaders = SignedHeaders(r);
  304. var canonicalRequest = CanonicalRequest(r, signedHeaders);
  305. var stringToSign = StringToSign(canonicalRequest, t);
  306. return signature == SignStringToSign(stringToSign, Encoding.UTF8.GetBytes(secret));
  307. }
  308. // SignRequest set Authorization header
  309. public HttpWebRequest Sign(HttpRequest r)
  310. {
  311. if (r.method != "POST" && r.method != "PATCH" && r.method != "PUT")
  312. {
  313. r.body = "";
  314. }
  315. var time = r.headers.GetValues(HeaderXDate);
  316. DateTime t;
  317. if (time == null)
  318. {
  319. t = DateTime.Now;
  320. r.headers.Add(HeaderXDate, t.ToUniversalTime().ToString(BasicDateFormat));
  321. }
  322. else
  323. {
  324. t = DateTime.ParseExact(time[0], BasicDateFormat, CultureInfo.CurrentCulture);
  325. }
  326. var queryString = CanonicalQueryString(r);
  327. if (queryString != "")
  328. {
  329. queryString = "?" + queryString;
  330. }
  331. HttpWebRequest req = (HttpWebRequest)WebRequest.Create(r.host + r.uri + queryString);
  332. string host = null;
  333. if (r.headers.GetValues(HeaderHost) != null)
  334. {
  335. host = r.headers.GetValues(HeaderHost)[0];
  336. req.Host = host;
  337. }
  338. else
  339. {
  340. host = req.Host;
  341. }
  342. r.headers.Set("host", host);
  343. var signedHeaders = SignedHeaders(r);
  344. var canonicalRequest = CanonicalRequest(r, signedHeaders);
  345. var stringToSign = StringToSign(canonicalRequest, t);
  346. var signature = SignStringToSign(stringToSign, Encoding.UTF8.GetBytes(secret));
  347. var authValue = AuthHeaderValue(signature, signedHeaders);
  348. r.headers.Set(HeaderAuthorization, authValue);
  349. req.Method = r.method;
  350. r.headers.Remove("host");
  351. string[] reservedHeaders = new String[]
  352. {
  353. "content-type","accept","date","if-modified-since","referer","user-agent",
  354. };
  355. Dictionary<string, string> savedHeaders = new Dictionary<string, string>();
  356. foreach (string header in reservedHeaders)
  357. {
  358. if (r.headers.GetValues(header) != null)
  359. {
  360. savedHeaders[header] = r.headers.GetValues(header)[0];
  361. r.headers.Remove(header);
  362. }
  363. }
  364. req.Headers = r.headers;
  365. if (savedHeaders.ContainsKey("content-type"))
  366. {
  367. req.ContentType = savedHeaders["content-type"];
  368. }
  369. if (savedHeaders.ContainsKey("accept"))
  370. {
  371. req.Accept = savedHeaders["accept"];
  372. }
  373. if (savedHeaders.ContainsKey("date"))
  374. {
  375. req.Date = Convert.ToDateTime(savedHeaders["date"]);
  376. }
  377. if (savedHeaders.ContainsKey("if-modified-since"))
  378. {
  379. req.IfModifiedSince = Convert.ToDateTime(savedHeaders["if-modified-since"]);
  380. }
  381. if (savedHeaders.ContainsKey("referer"))
  382. {
  383. req.Referer = savedHeaders["referer"];
  384. }
  385. if (savedHeaders.ContainsKey("user-agent"))
  386. {
  387. req.UserAgent = savedHeaders["user-agent"];
  388. }
  389. return req;
  390. }
  391. public HttpRequestMessage SignHttp(HttpRequest r)
  392. {
  393. var queryString = CanonicalQueryString(r);
  394. if (queryString != "")
  395. {
  396. queryString = "?" + queryString;
  397. }
  398. Console.WriteLine(r.method + "--" +r.host + r.uri + queryString);
  399. HttpRequestMessage req = new HttpRequestMessage(new HttpMethod(r.method), r.host + r.uri + queryString);
  400. if (r.method != "POST" && r.method != "PATCH" && r.method != "PUT")
  401. {
  402. r.body = "";
  403. }
  404. else
  405. {
  406. req.Content = new StringContent(r.body);
  407. }
  408. var time = r.headers.GetValues(HeaderXDate);
  409. Console.WriteLine(time);
  410. DateTime t;
  411. if (time == null)
  412. {
  413. t = DateTime.Now;
  414. r.headers.Add(HeaderXDate, t.ToUniversalTime().ToString(BasicDateFormat));
  415. }
  416. else
  417. {
  418. t = DateTime.ParseExact(time[0], BasicDateFormat, CultureInfo.CurrentCulture);
  419. }
  420. string host = null;
  421. if (r.headers.GetValues(HeaderHost) != null)
  422. {
  423. host = r.headers.GetValues(HeaderHost)[0];
  424. req.Headers.Host = host;
  425. }
  426. else
  427. {
  428. host = req.RequestUri.Host;
  429. }
  430. r.headers.Set("host", host);
  431. var signedHeaders = SignedHeaders(r);
  432. var canonicalRequest = CanonicalRequest(r, signedHeaders);
  433. r.canonicalRequest = canonicalRequest;
  434. var stringToSign = StringToSign(canonicalRequest, t);
  435. r.stringToSign = stringToSign;
  436. var signature = SignStringToSign(stringToSign, Encoding.UTF8.GetBytes(secret));
  437. var authValue = AuthHeaderValue(signature, signedHeaders);
  438. r.headers.Set(HeaderAuthorization, authValue);
  439. r.headers.Remove("host");
  440. foreach (string key in r.headers.AllKeys)
  441. {
  442. req.Headers.TryAddWithoutValidation(key, r.headers[key]);
  443. }
  444. return req;
  445. }
  446. }
  447. }