ess.go 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536
  1. package tencent
  2. import (
  3. "crypto/aes"
  4. "crypto/cipher"
  5. "crypto/hmac"
  6. "crypto/sha256"
  7. "encoding/base64"
  8. "encoding/hex"
  9. "encoding/json"
  10. "fmt"
  11. "mtp2_if/config"
  12. "mtp2_if/db"
  13. "mtp2_if/logger"
  14. "mtp2_if/models"
  15. "mtp2_if/services/tencent/essapi"
  16. "mtp2_if/utils"
  17. essbasic "github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/essbasic/v20210526"
  18. )
  19. func CreateConsoleLoginUrl(agent *essbasic.Agent, proxyOrganizationName string) (response *essbasic.CreateConsoleLoginUrlResponse, err error) {
  20. response, err = essapi.CreateConsoleLoginUrl(agent, proxyOrganizationName)
  21. return
  22. }
  23. func DescribeIntegrationEmployees(agent *essbasic.Agent) (response *essbasic.ChannelDescribeEmployeesResponse, err error) {
  24. response, err = essapi.DescribeIntegrationEmployees(agent)
  25. return
  26. }
  27. func SyncProxyOrganizationOperators(agent *essbasic.Agent) (response *essbasic.SyncProxyOrganizationOperatorsResponse, err error) {
  28. response, err = essapi.SyncProxyOrganizationOperators(agent)
  29. return
  30. }
  31. // InitTencentESS 按用户ID和机构ID创建腾讯电子签业务信息
  32. func InitTencentESS(userId, areaUserId int) (err error) {
  33. esignTemplateConfigs, err := models.QueryEsignTemplateConfigs(2, 4)
  34. if err != nil {
  35. return
  36. }
  37. session := db.GetEngine().NewSession()
  38. defer session.Close()
  39. // 开启事务
  40. session.Begin()
  41. // 新增 MdUserSwapProtocol
  42. err = models.InsertMdUserSwapProtocol(userId, areaUserId, 1, session)
  43. if err != nil {
  44. session.Rollback()
  45. return
  46. }
  47. // 新增 UserEsignRecord
  48. for _, item := range esignTemplateConfigs {
  49. err = models.InsertUserEsignRecord(userId, areaUserId, item, session)
  50. if err != nil {
  51. session.Rollback()
  52. return
  53. }
  54. }
  55. return session.Commit()
  56. }
  57. func InitMdUserSwapProtocol(userId, areaUserId int) (err error) {
  58. // 新增 MdUserSwapProtocol
  59. err = models.InsertMdUserSwapProtocol(userId, areaUserId, 3, db.GetEngine().NewSession())
  60. if err != nil {
  61. return
  62. }
  63. return
  64. }
  65. // CreateFlowByTemplateDirectly 通过合同模板创建合同签署流程
  66. func CreateFlowByTemplateDirectly(tmplateName string, userType int,
  67. personName, personMobile, personIdCardNumber string,
  68. organizationName string,
  69. record *models.Useresignrecord,
  70. idCardType int) (flowId, signUrl string, err error) {
  71. var (
  72. appId *string
  73. proxyOrganizationOpenId *string
  74. proxyOperatorOpenId *string
  75. )
  76. if esignConfig, err := models.GetEsignareatemplateconfig(int(record.AREAUSERID)); err == nil && esignConfig.USERID != 0 {
  77. appId = &esignConfig.APPID
  78. proxyOrganizationOpenId = &esignConfig.PROXYORGANIZATIONOPENID
  79. proxyOperatorOpenId = &esignConfig.PROXYOPERATOROPENID
  80. }
  81. // 获取模板信息
  82. templateInfo, err := GetTemplateInfo(&tmplateName, appId, proxyOrganizationOpenId, proxyOperatorOpenId)
  83. if err != nil {
  84. return
  85. }
  86. if templateInfo == nil {
  87. err = fmt.Errorf("获取模板信息失败, tmplateName:%v", tmplateName)
  88. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  89. return
  90. }
  91. // 获取模板里面的参与方RecipientId
  92. recipients := templateInfo.Recipients
  93. if recipients == nil {
  94. err = fmt.Errorf("获取模板参与方信息失败, tmplateName:%v", tmplateName)
  95. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  96. return
  97. }
  98. // 此处为快速发起的签署方;如果是正式接入,构造签署方,请参考函数内说明,构造需要的场景参数
  99. var flowApproverInfos []*essbasic.FlowApproverInfo
  100. for i := range recipients {
  101. recipient := recipients[i]
  102. // if config.SerCfg.TencentCfg.ProxyOrganizationName == *recipient.RoleName {
  103. // if *recipient.SignType != 1 {
  104. // // 签署方为本企业,同时不是自动签署时(一般为甲方非自动签署)
  105. // flowApproverInfos = append(flowApproverInfos, buildSelfOrganizationApprovers(recipient)...)
  106. // }
  107. // } else {
  108. // // 乙方
  109. // if userType == 1 {
  110. // // 个人
  111. // flowApproverInfos = append(flowApproverInfos, buildPersonApprovers(personName, personMobile, personIdCardNumber, idCardType, recipient)...)
  112. // } else {
  113. // // 企业
  114. // flowApproverInfos = append(flowApproverInfos, buildOrganizationApprovers(organizationName, recipient)...)
  115. // }
  116. // }
  117. if *recipient.SignType != 1 {
  118. if userType == 1 {
  119. // 个人
  120. flowApproverInfos = append(flowApproverInfos, buildPersonApprovers(personName, personMobile, personIdCardNumber, idCardType, recipient)...)
  121. } else {
  122. // 企业
  123. flowApproverInfos = append(flowApproverInfos, buildOrganizationApprovers(organizationName, recipient)...)
  124. }
  125. }
  126. }
  127. // 判断是否添加发起方角色的填写控件
  128. // 说明:如果合同模板开启了“本企业自动填写”,合同甲乙双方都不能添加填写控件,需要由发起方添加填写控件
  129. fields, err := models.GetEsignTemplateFields(int(record.TEMPLATECONFIGID), 3)
  130. if err != nil {
  131. return
  132. }
  133. formFields := buildSelfFormFields(int(record.AREAUSERID), int(record.USERID), fields)
  134. // 发起合同
  135. resp, err := essapi.CreateFlowByTemplateDirectly(*templateInfo.TemplateName, *templateInfo.TemplateId, flowApproverInfos, formFields,
  136. appId, proxyOrganizationOpenId, proxyOperatorOpenId)
  137. if err != nil {
  138. return
  139. }
  140. if resp == nil || len(resp["flowIds"]) == 0 || len(resp["urls"]) == 0 {
  141. err = fmt.Errorf("发起合同签署流程失败, tmplateName:%v", tmplateName)
  142. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  143. return
  144. }
  145. if len(resp["flowIds"]) > 0 {
  146. flowId = *resp["flowIds"][0]
  147. }
  148. if len(resp["urls"]) > 0 {
  149. signUrl = *resp["urls"][0]
  150. }
  151. // 更新电子签记录表信息状态
  152. record.CONTRACTNO = flowId
  153. record.SIGNURL = signUrl
  154. record.RECORDSTATUS = 2
  155. if err = record.Update("CONTRACTNO,SIGNURL,RECORDSTATUS"); err != nil {
  156. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  157. }
  158. return
  159. }
  160. // GetFlowStatus 获取合同状态
  161. func GetFlowStatus(flowId string) (recordStatus int, err error) {
  162. // 获取对应电子签信息
  163. var record *models.Useresignrecord
  164. record, err = models.GetUseresignRecordByFlowID(flowId)
  165. if err != nil {
  166. err = fmt.Errorf("获取电子签信息失败")
  167. return
  168. }
  169. var (
  170. appId *string
  171. proxyOrganizationOpenId *string
  172. proxyOperatorOpenId *string
  173. )
  174. if esignConfig, err := models.GetEsignareatemplateconfig(int(record.AREAUSERID)); err == nil && esignConfig.USERID != 0 {
  175. appId = &esignConfig.APPID
  176. proxyOrganizationOpenId = &esignConfig.PROXYORGANIZATIONOPENID
  177. proxyOperatorOpenId = &esignConfig.PROXYOPERATOROPENID
  178. }
  179. agent := utils.SetAgent(appId, proxyOrganizationOpenId, proxyOperatorOpenId)
  180. response, err := essapi.DescribeFlowDetailInfo(agent, []*string{&flowId})
  181. if err == nil {
  182. if len(response.Response.FlowInfo) == 0 {
  183. err = fmt.Errorf("获取合同明细失败")
  184. return
  185. }
  186. flowDetailInfo := response.Response.FlowInfo[0]
  187. // 更新电子签信息状态
  188. if *flowDetailInfo.FlowStatus == "ALL" {
  189. recordStatus = 3
  190. }
  191. if *flowDetailInfo.FlowStatus == "REJECT" {
  192. recordStatus = 4
  193. }
  194. if recordStatus == 0 {
  195. err = fmt.Errorf("合同状态异常")
  196. return
  197. }
  198. record.RECORDSTATUS = int32(recordStatus)
  199. if err = record.Update("RECORDSTATUS"); err != nil {
  200. logger.GetLogger().Errorf("GetFlowStatus, %v", err.Error())
  201. }
  202. if recordStatus == 3 {
  203. // 更新用户掉期协议签署表
  204. UpdateMdUserSwapProtocol(flowId)
  205. }
  206. }
  207. return
  208. }
  209. func UpdateMdUserSwapProtocol(flowId string) (err error) {
  210. // 获取对应的电子签记录
  211. var record *models.Useresignrecord
  212. record, err = models.GetUseresignRecordByFlowID(flowId)
  213. if err != nil {
  214. logger.GetLogger().Errorf("UpdateMdUserSwapProtocol, 获取对应的电子签记录失败:%v", err.Error())
  215. return
  216. }
  217. // 获取此用户对应机构的电子签记录列表
  218. records, err := models.QueryUsereSignRecords(int(record.USERID), int(record.AREAUSERID), nil, nil, nil)
  219. if err == nil {
  220. // 所有合同签署完成后,更新用户掉期协议签署表
  221. flag := true
  222. for _, item := range records {
  223. if item.RECORDSTATUS != 3 {
  224. flag = false
  225. break
  226. }
  227. }
  228. if flag {
  229. // 获取对应用户掉期协议签署记录
  230. var datas []models.Mduserswapprotocol
  231. datas, err = models.QueryMdUserSwapProtocol(int(record.USERID), &record.AREAUSERID)
  232. if err == nil {
  233. if len(datas) > 0 {
  234. data := datas[0]
  235. // 获取用户信息,如果是用户所属机构则改状态为 4:已审核,否则改为 3:已签署
  236. var userAccount *models.Useraccount
  237. if userAccount, err = models.GetUserAccount(int(record.USERID)); err == nil {
  238. status := 4
  239. if userAccount.Memberuserid != record.AREAUSERID {
  240. status = 3
  241. }
  242. data.PROTOCOLSTATUS = int32(status)
  243. err = data.Update("PROTOCOLSTATUS")
  244. }
  245. }
  246. } else {
  247. logger.GetLogger().Errorf("UpdateMdUserSwapProtocol, 获取对应用户掉期协议签署记录失败:%v", err.Error())
  248. }
  249. }
  250. } else {
  251. logger.GetLogger().Errorf("UpdateMdUserSwapProtocol, 获取对应的机构电子签记录失败:%v", err.Error())
  252. }
  253. return
  254. }
  255. // GetTemplateInfo 获取模板信息
  256. func GetTemplateInfo(contractName, appId, proxyOrganizationOpenId, proxyOperatorOpenId *string) (templateInfo *essbasic.TemplateInfo, err error) {
  257. agent := utils.SetAgent(appId, proxyOrganizationOpenId, proxyOperatorOpenId)
  258. templatesResp, err := essapi.DescribeTemplates(agent, contractName)
  259. if err == nil {
  260. if len(templatesResp.Response.Templates) > 0 {
  261. templateInfo = templatesResp.Response.Templates[0]
  262. } else {
  263. err = fmt.Errorf("获取模板信息失败")
  264. }
  265. }
  266. return
  267. }
  268. // buildPersonApprovers 构造个人签署人 - 以BtoC为例, 实际请根据自己的场景构造签署方、控件
  269. func buildPersonApprovers(personName, personMobile, personIdCardNumber string, idCardType int, recipient *essbasic.Recipient) []*essbasic.FlowApproverInfo {
  270. var flowApproverInfos []*essbasic.FlowApproverInfo
  271. // 传入个人签署方
  272. flowApproverInfo := &essbasic.FlowApproverInfo{}
  273. approverType := "PERSON"
  274. flowApproverInfo.ApproverType = &approverType
  275. flowApproverInfo.Name = &personName
  276. flowApproverInfo.Mobile = &personMobile
  277. if idCardType == 0 {
  278. flowApproverInfo.IdCardType = utils.SetPointValue("ID_CARD")
  279. } else if idCardType == 1 {
  280. flowApproverInfo.IdCardType = utils.SetPointValue("HONGKONG_AND_MACAO")
  281. } else {
  282. flowApproverInfo.IdCardType = utils.SetPointValue("ID_CARD")
  283. }
  284. flowApproverInfo.IdCardNumber = &personIdCardNumber
  285. // 模板中对应签署方的参与方id
  286. flowApproverInfo.RecipientId = recipient.RecipientId
  287. flowApproverInfos = append(flowApproverInfos, flowApproverInfo)
  288. // 传入企业静默签署,此处需要在config.php中设置一个持有的印章值serverSignSealId
  289. // flowApproverInfos = append(flowApproverInfos, BuildServerSignApprover())
  290. // 内容控件填充结构,详细说明参考
  291. // https://cloud.tencent.com/document/api/1420/61525#FormField
  292. return flowApproverInfos
  293. }
  294. // buildOrganizationApprovers 构造企业签署人
  295. func buildOrganizationApprovers(organizationName string, recipient *essbasic.Recipient) []*essbasic.FlowApproverInfo {
  296. var flowApproverInfos []*essbasic.FlowApproverInfo
  297. // 传入企业签署方
  298. flowApproverInfo := &essbasic.FlowApproverInfo{}
  299. approverType := "ORGANIZATION"
  300. flowApproverInfo.ApproverType = &approverType
  301. flowApproverInfo.OrganizationName = &organizationName
  302. // 模板中对应签署方的参与方id
  303. flowApproverInfo.RecipientId = recipient.RecipientId
  304. flowApproverInfos = append(flowApproverInfos, flowApproverInfo)
  305. return flowApproverInfos
  306. }
  307. // buildSelfOrganizationApprovers 构造本企业签署人
  308. func buildSelfOrganizationApprovers(recipient *essbasic.Recipient) []*essbasic.FlowApproverInfo {
  309. var flowApproverInfos []*essbasic.FlowApproverInfo
  310. // 传入企业签署方
  311. flowApproverInfo := &essbasic.FlowApproverInfo{}
  312. approverType := "ORGANIZATION"
  313. flowApproverInfo.ApproverType = &approverType
  314. flowApproverInfo.OrganizationOpenId = &config.SerCfg.TencentCfg.ProxyOrganizationOpenId // 本企业OpenID
  315. // 模板中对应签署方的参与方id
  316. flowApproverInfo.RecipientId = recipient.RecipientId
  317. flowApproverInfo.OpenId = &config.SerCfg.TencentCfg.ProxyOperatorOpenId // 本企业员工OpenID
  318. flowApproverInfos = append(flowApproverInfos, flowApproverInfo)
  319. return flowApproverInfos
  320. }
  321. // buildSelfFormFields 构造本企业填写控件
  322. // selfUserId 本企业用户ID
  323. // userId 乙方用户ID
  324. func buildSelfFormFields(selfUserId int, userId int, fields []models.Esigntemplatefield) (formFields []*essbasic.FormField) {
  325. formFields = make([]*essbasic.FormField, 0)
  326. // 获取本企业信息(合同发起方,一般为交易所或合同所属机构)
  327. selfuserInfo, err := models.GetUserInfo(selfUserId)
  328. if err != nil {
  329. return
  330. }
  331. userInfo, err := models.GetUserInfo(userId)
  332. if err != nil {
  333. return
  334. }
  335. key, _ := hex.DecodeString(utils.AESSecretKey)
  336. for _, item := range fields {
  337. filedName := item.FIELDNAME
  338. switch filedName {
  339. case "甲方地址":
  340. address := selfuserInfo.Province + selfuserInfo.City + selfuserInfo.District + selfuserInfo.Address
  341. formFields = append(formFields, &essbasic.FormField{
  342. ComponentName: &filedName,
  343. ComponentValue: &address,
  344. })
  345. case "甲方邮箱":
  346. email := ""
  347. if len(selfuserInfo.Email) > 0 {
  348. // 手机号码解密
  349. if h, err := hex.DecodeString(selfuserInfo.Email); err == nil { // hex -> []byte
  350. if d, err := utils.AESDecrypt(h, key); err == nil {
  351. email = string(d)
  352. }
  353. }
  354. }
  355. formFields = append(formFields, &essbasic.FormField{
  356. ComponentName: &filedName,
  357. ComponentValue: &email,
  358. })
  359. case "甲方电话号码":
  360. telphone := ""
  361. if len(selfuserInfo.Email) > 0 {
  362. // 手机号码解密
  363. if h, err := hex.DecodeString(selfuserInfo.Telphone); err == nil { // hex -> []byte
  364. if d, err := utils.AESDecrypt(h, key); err == nil {
  365. telphone = string(d)
  366. }
  367. }
  368. }
  369. formFields = append(formFields, &essbasic.FormField{
  370. ComponentName: &filedName,
  371. ComponentValue: &telphone,
  372. })
  373. case "乙方地址":
  374. address := userInfo.Province + userInfo.City + userInfo.District + userInfo.Address
  375. formFields = append(formFields, &essbasic.FormField{
  376. ComponentName: &filedName,
  377. ComponentValue: &address,
  378. })
  379. }
  380. }
  381. return
  382. }
  383. func ProcessNotice(content string) {
  384. // "{\"MsgId\":\"yDSLWUUckposmdf8UBxiJvuDbgiYRYbj\",\"MsgType\":\"FlowStatusChange\",\"MsgVersion\":\"ThirdPartyApp\",\"MsgData\":{\"ApplicationId\":\"yDwiuUUckpogfoa4UxhigrYChFMdSJQV\",\"ProxyOrganizationOpenId\":\"TJMD\",\"CustomerData\":\"\",\"FlowId\":\"yDSLWUUckposcsthUwvcaGSuV5EKZAzu\",\"FlowName\":\"1000_P_风险揭示书\",\"FlowType\":\"合同\",\"FlowStatus\":\"INIT\",\"FlowMessage\":\"\",\"CreateOn\":1699077064,\"Deadline\":1730613064,\"FlowApproverInfo\":[{\"ProxyOrganizationOpenId\":\"\",\"ProxyOperatorOpenId\":\"\",\"recipientId\":\"yDSLNUUckpos1i71UuGNih5yMGbZij46\",\"RecipientId\":\"yDSLNUUckpos1i71UuGNih5yMGbZij46\",\"PhoneNumber\":\"15914012152\",\"ProxyOrganizationName\":\"\",\"SignOrder\":0,\"ApproveName\":\"曹晓亮\",\"ApproveStatus\":\"PENDING\",\"ApproveMessage\":\"\",\"ApproveTime\":0,\"CaSign\":\"\"}],\"OccurTime\":1699077064,\"CcInfo\":[]}}"
  385. m := make(map[string]interface{})
  386. if err := json.Unmarshal([]byte(content), &m); err == nil {
  387. // 判断通知类型
  388. msgType, _ := m["MsgType"].(string)
  389. if msgType == "FlowStatusChange" {
  390. // 合同相关回调
  391. // https://qian.tencent.com/developers/partner/callback_types_contracts_sign
  392. msgData, _ := m["MsgData"].(map[string]interface{})
  393. flowId, _ := msgData["FlowId"].(string)
  394. flowStatus, _ := msgData["FlowStatus"].(string)
  395. if flowStatus == "ALL" || flowStatus == "REJECT" {
  396. // 更新电子签合同状态
  397. if record, err := models.GetUseresignRecordByFlowID(flowId); err == nil {
  398. if flowStatus == "ALL" {
  399. record.RECORDSTATUS = 3
  400. } else {
  401. record.RECORDSTATUS = 4
  402. }
  403. if err = record.Update("RECORDSTATUS"); err != nil {
  404. logger.GetLogger().Errorf("ProcessNotice, %v", err.Error())
  405. }
  406. if record.RECORDSTATUS == 3 {
  407. // 更新用户掉期协议签署表
  408. UpdateMdUserSwapProtocol(flowId)
  409. }
  410. }
  411. }
  412. }
  413. }
  414. }
  415. // VerifySign 电子签通知推送验签
  416. func VerifySign(payload, signFromHeader string) bool {
  417. // 验证签名
  418. hash := "sha256=" + hmacsha256hex(payload, config.SerCfg.TencentCfg.SignToken)
  419. return hash == signFromHeader
  420. }
  421. // DecryptContent 电子签通知推送内容解密
  422. func DecryptContent(payload string) (content string, err error) {
  423. // string -> json
  424. m := make(map[string]string)
  425. err = json.Unmarshal([]byte(payload), &m)
  426. if err != nil {
  427. return
  428. }
  429. encrypt, ok := m["encrypt"]
  430. if !ok {
  431. err = fmt.Errorf("电子签通知推送内容解密失败")
  432. logger.GetLogger().Errorf("DecryptContent, %v", err.Error())
  433. return
  434. }
  435. // base64解密
  436. crypted, err := base64.StdEncoding.DecodeString(encrypt)
  437. if err != nil {
  438. logger.GetLogger().Errorf("base64 DecodeString returned: %s", err)
  439. return
  440. }
  441. b, err := aesDecrypt(crypted, []byte(config.SerCfg.TencentCfg.SignKey))
  442. if err != nil {
  443. logger.GetLogger().Errorf("AesDecrypt returned: %s", err)
  444. return
  445. }
  446. content = string(b)
  447. return
  448. }
  449. // Hmacsha256hex hmac sha256
  450. func hmacsha256hex(s, key string) string {
  451. hashed := hmac.New(sha256.New, []byte(key))
  452. hashed.Write([]byte(s))
  453. return hex.EncodeToString(hashed.Sum(nil))
  454. }
  455. // 使用callbackKey解密
  456. func aesDecrypt(crypted, key []byte) ([]byte, error) {
  457. block, err := aes.NewCipher(key)
  458. if err != nil {
  459. return nil, err
  460. }
  461. blockSize := block.BlockSize()
  462. blockMode := cipher.NewCBCDecrypter(block, key[:blockSize])
  463. origData := make([]byte, len(crypted))
  464. blockMode.CryptBlocks(origData, crypted)
  465. origData = pkcs7UnPadding(origData)
  466. return origData, nil
  467. }
  468. // PKCS7UnPadding 去除填充
  469. func pkcs7UnPadding(origData []byte) []byte {
  470. length := len(origData)
  471. unPadding := int(origData[length-1])
  472. return origData[:(length - unPadding)]
  473. }