钉钉对接接口

DingTalkCrypt.cs 9.8KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263
  1. using System;
  2. using System.Collections;
  3. using System.Collections.Generic;
  4. using System.Security.Cryptography;
  5. using System.Text;
  6. namespace DingDingDemo.Common
  7. {
  8. public class DingTalkCrypt
  9. {
  10. private string m_sEncodingAESKey;
  11. private string m_sToken;
  12. private string m_sSuiteKey;
  13. /**ask getPaddingBytes key固定长度**/
  14. private static int AES_ENCODE_KEY_LENGTH = 43;
  15. /**加密随机字符串字节长度**/
  16. private static int RANDOM_LENGTH = 16;
  17. enum DingTalkCryptErrorCode
  18. {
  19. /**成功**/
  20. SUCCESS = 0,
  21. /**加密明文文本非法**/
  22. ENCRYPTION_PLAINTEXT_ILLEGAL = 900001,
  23. /**加密时间戳参数非法**/
  24. ENCRYPTION_TIMESTAMP_ILLEGAL = 900002,
  25. /**加密随机字符串参数非法**/
  26. ENCRYPTION_NONCE_ILLEGAL = 900003,
  27. /**不合法的aeskey**/
  28. AES_KEY_ILLEGAL = 900004,
  29. /**签名不匹配**/
  30. SIGNATURE_NOT_MATCH = 900005,
  31. /**计算签名错误**/
  32. COMPUTE_SIGNATURE_ERROR = 900006,
  33. /**计算加密文字错误**/
  34. COMPUTE_ENCRYPT_TEXT_ERROR = 900007,
  35. /**计算解密文字错误**/
  36. COMPUTE_DECRYPT_TEXT_ERROR = 900008,
  37. /**计算解密文字长度不匹配**/
  38. COMPUTE_DECRYPT_TEXT_LENGTH_ERROR = 900009,
  39. /**计算解密文字suiteKey不匹配**/
  40. COMPUTE_DECRYPT_TEXT_SuiteKey_ERROR = 900010,
  41. };
  42. /// <summary>
  43. /// 构造函数
  44. /// </summary>
  45. /// <param name="token">钉钉开放平台上,开发者设置的token</param>
  46. /// <param name="encodingAesKey">钉钉开放台上,开发者设置的EncodingAESKey</param>
  47. /// <param name="suiteKey">钉钉开放平台上,开发者设置的suiteKey</param>
  48. public DingTalkCrypt(string token, string encodingAesKey, string suiteKey)
  49. {
  50. m_sToken = token;
  51. m_sSuiteKey = suiteKey;
  52. m_sEncodingAESKey = encodingAesKey;
  53. }
  54. /// <summary>
  55. /// 将消息加密,返回加密后字符串
  56. /// </summary>
  57. /// <param name="sReplyMsg">传递的消息体明文</param>
  58. /// <param name="sTimeStamp">时间戳</param>
  59. /// <param name="sNonce">随机字符串</param>
  60. /// <param name="sEncryptMsg">加密后的消息信息</param>
  61. /// <param name="signature">解密用的签名串</param>
  62. /// <returns>成功0,失败返回对应的错误码</returns>
  63. public int EncryptMsg(string sReplyMsg, string sTimeStamp, string sNonce, ref string sEncryptMsg, ref string signature)
  64. {
  65. if (string.IsNullOrEmpty(sReplyMsg))
  66. return (int)DingTalkCryptErrorCode.ENCRYPTION_PLAINTEXT_ILLEGAL;
  67. if (string.IsNullOrEmpty(sTimeStamp))
  68. return (int)DingTalkCryptErrorCode.ENCRYPTION_TIMESTAMP_ILLEGAL;
  69. if (string.IsNullOrEmpty(sNonce))
  70. return (int)DingTalkCryptErrorCode.ENCRYPTION_NONCE_ILLEGAL;
  71. if (m_sEncodingAESKey.Length != AES_ENCODE_KEY_LENGTH)
  72. return (int)DingTalkCryptErrorCode.AES_KEY_ILLEGAL;
  73. string raw = "";
  74. try
  75. {
  76. raw = Cryptography.AES_encrypt(sReplyMsg, m_sEncodingAESKey, m_sSuiteKey);
  77. }
  78. catch (Exception)
  79. {
  80. return (int)DingTalkCryptErrorCode.AES_KEY_ILLEGAL;
  81. }
  82. string msgSigature = "";
  83. int ret = GenerateSignature(m_sToken, sTimeStamp, sNonce, raw, ref msgSigature);
  84. sEncryptMsg = raw;
  85. signature = msgSigature;
  86. return ret;
  87. }
  88. /// <summary>
  89. /// 密文解密
  90. /// </summary>
  91. /// <param name="sMsgSignature">签名串</param>
  92. /// <param name="sTimeStamp">时间戳</param>
  93. /// <param name="sNonce">随机串</param>
  94. /// <param name="sPostData">密文</param>
  95. /// <param name="sMsg">解密后的原文,当return返回0时有效</param>
  96. /// <returns>成功0,失败返回对应的错误码</returns>
  97. public int DecryptMsg(string sMsgSignature, string sTimeStamp, string sNonce, string sPostData, ref string sMsg)
  98. {
  99. if (m_sEncodingAESKey.Length != AES_ENCODE_KEY_LENGTH)
  100. return (int)DingTalkCryptErrorCode.AES_KEY_ILLEGAL;
  101. string sEncryptMsg = sPostData;
  102. int ret = VerifySignature(m_sToken, sTimeStamp, sNonce, sEncryptMsg, sMsgSignature);
  103. string cpid = "";
  104. try
  105. {
  106. sMsg = Cryptography.AES_decrypt(sEncryptMsg, m_sEncodingAESKey, ref cpid);
  107. }
  108. catch (FormatException)
  109. {
  110. sMsg = "";
  111. return (int)DingTalkCryptErrorCode.COMPUTE_DECRYPT_TEXT_SuiteKey_ERROR;
  112. }
  113. catch (Exception)
  114. {
  115. sMsg = "";
  116. return (int)DingTalkCryptErrorCode.COMPUTE_DECRYPT_TEXT_SuiteKey_ERROR;
  117. }
  118. if (cpid != m_sSuiteKey)
  119. return (int)DingTalkCryptErrorCode.COMPUTE_DECRYPT_TEXT_SuiteKey_ERROR;
  120. return ret;
  121. }
  122. /// <summary>
  123. /// 生成签名
  124. /// </summary>
  125. /// <param name="sToken"></param>
  126. /// <param name="sTimeStamp"></param>
  127. /// <param name="sNonce"></param>
  128. /// <param name="sMsgEncrypt"></param>
  129. /// <param name="sMsgSignature"></param>
  130. /// <returns></returns>
  131. public static int GenerateSignature(string sToken, string sTimeStamp, string sNonce, string sMsgEncrypt, ref string sMsgSignature)
  132. {
  133. ArrayList AL = new ArrayList();
  134. AL.Add(sToken);
  135. AL.Add(sTimeStamp);
  136. AL.Add(sNonce);
  137. AL.Add(sMsgEncrypt);
  138. AL.Sort(new DictionarySort());
  139. string raw = "";
  140. for (int i = 0; i < AL.Count; ++i)
  141. {
  142. raw += AL[i];
  143. }
  144. SHA1 sha;
  145. ASCIIEncoding enc;
  146. string hash = "";
  147. try
  148. {
  149. sha = new SHA1CryptoServiceProvider();
  150. enc = new ASCIIEncoding();
  151. byte[] dataToHash = enc.GetBytes(raw);
  152. byte[] dataHashed = sha.ComputeHash(dataToHash);
  153. hash = BitConverter.ToString(dataHashed).Replace("-", "");
  154. hash = hash.ToLower();
  155. }
  156. catch (Exception)
  157. {
  158. return (int)DingTalkCryptErrorCode.COMPUTE_SIGNATURE_ERROR;
  159. }
  160. sMsgSignature = hash;
  161. return 0;
  162. }
  163. /// <summary>
  164. /// 验证签名
  165. /// </summary>
  166. /// <param name="sToken"></param>
  167. /// <param name="sTimeStamp"></param>
  168. /// <param name="sNonce"></param>
  169. /// <param name="sMsgEncrypt"></param>
  170. /// <param name="sSigture"></param>
  171. /// <returns></returns>
  172. private static int VerifySignature(string sToken, string sTimeStamp, string sNonce, string sMsgEncrypt, string sSigture)
  173. {
  174. string hash = "";
  175. int ret = 0;
  176. ret = GenerateSignature(sToken, sTimeStamp, sNonce, sMsgEncrypt, ref hash);
  177. if (ret != 0)
  178. return ret;
  179. if (hash == sSigture)
  180. return 0;
  181. else
  182. {
  183. return (int)DingTalkCryptErrorCode.SIGNATURE_NOT_MATCH;
  184. }
  185. }
  186. /// <summary>
  187. /// 验证URL
  188. /// </summary>
  189. /// <param name="sMsgSignature">签名串,对应URL参数的msg_signature</param>
  190. /// <param name="sTimeStamp">时间戳,对应URL参数的timestamp</param>
  191. /// <param name="sNonce">随机串,对应URL参数的nonce</param>
  192. /// <param name="sEchoStr">经过加密的消息体,对应URL参数的encrypt</param>
  193. /// <param name="sReplyEchoStr"></param>
  194. /// <returns></returns>
  195. public int VerifyURL(string sMsgSignature, string sTimeStamp, string sNonce, string sEchoStr, ref string sReplyEchoStr)
  196. {
  197. int ret = 0;
  198. if (m_sEncodingAESKey.Length != 43)
  199. {
  200. return (int)DingTalkCryptErrorCode.AES_KEY_ILLEGAL;
  201. }
  202. ret = VerifySignature(m_sToken, sTimeStamp, sNonce, sEchoStr, sMsgSignature);
  203. sReplyEchoStr = "";
  204. string cpid = "";
  205. try
  206. {
  207. sReplyEchoStr = Cryptography.AES_decrypt(sEchoStr, m_sEncodingAESKey, ref cpid); //m_sCorpID);
  208. }
  209. catch (Exception)
  210. {
  211. sReplyEchoStr = "";
  212. return (int)DingTalkCryptErrorCode.COMPUTE_SIGNATURE_ERROR;
  213. }
  214. if (cpid != m_sSuiteKey)
  215. {
  216. sReplyEchoStr = "";
  217. return (int)DingTalkCryptErrorCode.COMPUTE_DECRYPT_TEXT_SuiteKey_ERROR;
  218. }
  219. return ret;
  220. }
  221. /// <summary>
  222. /// 字典排序
  223. /// </summary>
  224. public class DictionarySort : System.Collections.IComparer
  225. {
  226. public int Compare(object oLeft, object oRight)
  227. {
  228. string sLeft = oLeft as string;
  229. string sRight = oRight as string;
  230. int iLeftLength = sLeft.Length;
  231. int iRightLength = sRight.Length;
  232. int index = 0;
  233. while (index < iLeftLength && index < iRightLength)
  234. {
  235. if (sLeft[index] < sRight[index])
  236. return -1;
  237. else if (sLeft[index] > sRight[index])
  238. return 1;
  239. else
  240. index++;
  241. }
  242. return iLeftLength - iRightLength;
  243. }
  244. }
  245. }
  246. }