因爲正式環境須要商戶信息,因此這裏使用支付寶提供的沙箱環境。切換到正式環境後只需稍改配置。html
一、點擊進入螞蟻金服平臺官網。git
二、以下圖選擇:開發者中心->開發服務下的研發服務->沙箱。github
下載祕鑰生成工具:數據庫
解壓後目錄以下:json
雙擊驗籤工具,打開後直接點擊生成祕鑰:api
此時驗籤工具目錄下會生成 RSA祕鑰 文件夾:app
目錄以下:dom
直接將上一步生成的 公鑰2048 內容貼入保存:ide
設置完以後會生成 查看支付寶公鑰 按鈕:工具
支付寶公鑰會在設置應用公鑰後自動生成,無需手動設置:
pip install pycryptodome
from datetime import datetime from Crypto.PublicKey import RSA from Crypto.Signature import PKCS1_v1_5 from Crypto.Hash import SHA256 from urllib.parse import quote_plus from urllib.parse import urlparse, parse_qs from base64 import decodebytes, encodebytes import json class AliPay(object): """ 支付寶支付接口(PC端支付接口) """ def __init__(self, appid, app_notify_url, app_private_key_path, alipay_public_key_path, return_url, debug=False): self.appid = appid self.app_notify_url = app_notify_url self.app_private_key_path = app_private_key_path self.app_private_key = None self.return_url = return_url with open(self.app_private_key_path) as fp: self.app_private_key = RSA.importKey(fp.read()) self.alipay_public_key_path = alipay_public_key_path with open(self.alipay_public_key_path) as fp: self.alipay_public_key = RSA.importKey(fp.read()) if debug is True: self.__gateway = "https://openapi.alipaydev.com/gateway.do" else: self.__gateway = "https://openapi.alipay.com/gateway.do" def direct_pay(self, subject, out_trade_no, total_amount, return_url=None, **kwargs): biz_content = { "subject": subject, "out_trade_no": out_trade_no, "total_amount": total_amount, "product_code": "FAST_INSTANT_TRADE_PAY", # "qr_pay_mode":4 } biz_content.update(kwargs) data = self.build_body("alipay.trade.page.pay", biz_content, self.return_url) return self.sign_data(data) def build_body(self, method, biz_content, return_url=None): data = { "app_id": self.appid, "method": method, "charset": "utf-8", "sign_type": "RSA2", "timestamp": datetime.now().strftime("%Y-%m-%d %H:%M:%S"), "version": "1.0", "biz_content": biz_content } if return_url is not None: data["notify_url"] = self.app_notify_url data["return_url"] = self.return_url return data def sign_data(self, data): data.pop("sign", None) # 排序後的字符串 unsigned_items = self.ordered_data(data) unsigned_string = "&".join("{0}={1}".format(k, v) for k, v in unsigned_items) sign = self.sign(unsigned_string.encode("utf-8")) # ordered_items = self.ordered_data(data) quoted_string = "&".join("{0}={1}".format(k, quote_plus(v)) for k, v in unsigned_items) # 得到最終的訂單信息字符串 signed_string = quoted_string + "&sign=" + quote_plus(sign) return signed_string def ordered_data(self, data): complex_keys = [] for key, value in data.items(): if isinstance(value, dict): complex_keys.append(key) # 將字典類型的數據dump出來 for key in complex_keys: data[key] = json.dumps(data[key], separators=(',', ':')) return sorted([(k, v) for k, v in data.items()]) def sign(self, unsigned_string): # 開始計算簽名 key = self.app_private_key signer = PKCS1_v1_5.new(key) signature = signer.sign(SHA256.new(unsigned_string)) # base64 編碼,轉換爲unicode表示並移除回車 sign = encodebytes(signature).decode("utf8").replace("\n", "") return sign def _verify(self, raw_content, signature): # 開始計算簽名 key = self.alipay_public_key signer = PKCS1_v1_5.new(key) digest = SHA256.new() digest.update(raw_content.encode("utf8")) if signer.verify(digest, decodebytes(signature.encode("utf8"))): return True return False def verify(self, data, signature): if "sign_type" in data: sign_type = data.pop("sign_type") # 排序後的字符串 unsigned_items = self.ordered_data(data) message = "&".join(u"{}={}".format(k, v) for k, v in unsigned_items) return self._verify(message, signature)
-----BEGIN RSA PRIVATE KEY----- MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCln7XrQxciEcJiLSgBQYiLLmDo8ES6osoZg6/o67JnsRutyxPVDvdmlSRh4+BKisdUuj54uHUYKH99oXnv7P+OMQu6oNbyo82UdJSOT2wSh+jjSPUqpZrHZEmABs380xD3okD6L312IZDMP4GcjA1b06kug2m6uFi4Dh2VVvts/32j4E9d49m3O70BL0OgrJf/ogT7qZT+tsKZd+B2l1zBTV9MJAjW4J3Rj4HC0a2o1c8iKnlbEEg6hOrrZXByKitOsMkZ69Z0bjgXP6k2o+pKdmA5zs9Iscu3D3BsPXAi/5Rbguh61UzJW5S2BLShx9WNRmdA62ZD+nGWgz0zG7BxAgMBAAECggEAaSIdd26KA61kR6/EYi+4Pik9iP/jkNl/En0eL+tVvy6UlFiBiVBLyUlI4/6jxI2dhHII79afNauXaicTYTJ+8kK94ETyzOkfuWnbVw6hWo39TjFktyKSQpmtcmBfZ2qPrbHIL0fwCwm5gX2ah8X7QNv127m9ZrJYVtVXABJL3V60oh3dMfZiITLmGA+dp2ppMahHfLf0pWhc75u1wznqheIFYWEEuF6KhHQuHVPi7yrCfWK0eHeuFbLm1i9RB48XKJYt0DyfcByF2JZiOmm/RRMtKF7LFP9zRaBw1JVYkbmbnA38L0Tq8Wo+xyiDiQLBOF/P/z2j799I43QSg3VxpQKBgQDug9vBmwHU5/ATnXM6zueEr9YDow5XChYNgS+isVYWOAmfaGbLhRozqyTTiwugISYIa5YJE+h0fJZWQYj/w19uQH7my61uc88ap/zQpSk9/iEHG4/fYm4poiToeTs7iOSJyFRCLr4WA3vIW0wD6ZTV9oEUGZHJCrkMO4CQXhvpVwKBgQCxw+y0zSfvwR4ElNx8EmOwfTIrBm7wdba93sWbub/iHX9rnLxCrt3ZP7wiL/VcYhh3DXzA/rUIWozAiF8pb5+deHLdVkiyfpzTeP6uvirhRsYbZ861lpuBm7CnF8ztAmjjwm05nxEHNxIBTfHPkilSx64hFj64raUnrbj49MbvdwKBgEnW9nSUiVehSli4ONEu9svEJ+xOUYUusS8THG0wm2cbiBcamiBNn5P5WthGxp2XRY/7xqIe0KsnWt9vQHt1v5iBTQgkbBeysJ4e/YyWZRM1FoJ9zOeqMFKhSO3TgjvnIGFrbHJkyCJGh866POlFKfenbcSMOe7Ua/9WeHG5QMjXAoGBAKWx6Q4x+Fq7GB7PHqErhu54E+4Uxg2uu1JJtsnLnvbF5gJJixVg53rbtKHtL/gXm5RE5xcBk36g4HeJ5aG64P2nyvFSvtpZuBZJvqLksRVgocHjxcJvCq4Jj+SAA8ybpWc+0A6YnQerpkW/AHkpVQlLBJzknjwH51yPyk2L425LAoGBAIYel91QaxEXcVZ7dqZ0+wGixocB2p0Tj2RYqOH3tEdNjqHBAZWTGPlSaPzhlNdNdqYUZAvNe+NbpTVUzr/EVBEb6iLK6lylJDgPVXh20wPKFaZhG4cEjdeMlYXrvzif0lDnGPz4ynRqyqsVBzq8rJazH+2G01p8awuHLzJpJnlv -----END RSA PRIVATE KEY-----
-----BEGIN PUBLIC KEY----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwrww6DyKMamYkFEH+KWoMmXW9UOmFB63XZuYlENz3ijgIeA1eGV4t7NhTb7gtwcRWXG1octr2xaAtOLaaS9cBuRm6Esd5JYVp7+k6bt4oWO88ghLs2rNyQstW7OXqtrflCAUrqXYdEWpcXOZZALDIgLW/xFfXTYI2PvKZlUaKYCNVMoM1Ed0TqakJ7B1ZhLfQWy++Z8ZJ0MrFEpEv2XQ8NO2GuAD7KHVj6HaQ+1Mbvq9D4VhVrWNvgKSftom1VjsaxSkdWZr6AqVq/GOyZw/Dov24ggyMHIZ7aQKlVN52MYIiD57E55D1UJ66edMdofTivdlsqFUZ8Q9ylRTAMJJhwIDAQAB -----END PUBLIC KEY-----
注意:這兩個文件中的頭和尾標識符不可缺乏,中間是生成的key。
APPID = "2016092300580728" NOTIFY_URL = "http://.../update_order/" # 上面這個地址應該是在公網可以訪問到的地址,不然接收不到支付寶的回調。 RETURN_URL = "http://.../pay_result/" PRI_KEY_PATH = "keys/app_private_2048.txt" PUB_KEY_PATH = "keys/alipay_public_2048.txt"
def aliPay(): obj = AliPay( appid=settings.APPID, # 沙箱環境->沙箱應用 提供的APPID 我這裏是 2016092300580728 app_notify_url=settings.NOTIFY_URL, # 若是支付成功,支付寶會向這個地址發送POST請求(校驗是否支付已經完成) return_url=settings.RETURN_URL, # 若是支付成功,重定向回到你的網站的地址。 alipay_public_key_path=settings.PUB_KEY_PATH, # 支付寶公鑰 app_private_key_path=settings.PRI_KEY_PATH, # 應用私鑰 debug=True, # 默認False, ) return obj
def index(request): if request.method == 'GET': return render(request, 'index.html') alipay = aliPay() # 對購買的數據進行加密 money = float(request.POST.get('price')) out_trade_no = "x2" + str(time.time()) # 1. 在數據庫建立一條數據:狀態(待支付) query_params = alipay.direct_pay( subject="充氣式娃娃", # 商品簡單描述 out_trade_no=out_trade_no, # 商戶訂單號 total_amount=money, # 交易金額(單位: 元 保留倆位小數) ) pay_url = "https://openapi.alipaydev.com/gateway.do?{}".format(query_params) return redirect(pay_url)
重定向到生成的URL後,支付寶方會根據URL攜帶的參數解密展現信息以下:
支付成功後支付寶會向咱們指定的地址發送 POST 請求,咱們能夠在此回調中進行邏輯處理:
@csrf_exempt def update_order(request): if request.method == 'POST': from urllib.parse import parse_qs body_str = request.body.decode('utf-8') post_data = parse_qs(body_str) post_dict = {} for k, v in post_data.items(): post_dict[k] = v[0] alipay = aliPay() sign = post_dict.pop('sign', None) status = alipay.verify(post_dict, sign) if status: # 1. 獲取訂單號 out_trade_no = post_dict.get('out_trade_no') print(out_trade_no) # 2. 根據訂單號將數據庫中的數據進行更新 return HttpResponse('success') else: return HttpResponse('fail') return HttpResponse('')
def pay_result(request): """ 支付完成後,跳轉回的地址 :param request: :return: """ params = request.GET.dict() sign = params.pop('sign', None) alipay = aliPay() # 校驗支付是否成功 status = alipay.verify(params, sign) if status: return HttpResponse('支付成功') return HttpResponse('支付失敗')
https://github.com/zze326/alipay_test.git