ess.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411
  1. package tencent
  2. import (
  3. "crypto/aes"
  4. "crypto/cipher"
  5. "crypto/hmac"
  6. "crypto/sha256"
  7. "encoding/base64"
  8. "encoding/hex"
  9. "encoding/json"
  10. "fmt"
  11. "mtp2_if/config"
  12. "mtp2_if/db"
  13. "mtp2_if/logger"
  14. "mtp2_if/models"
  15. "mtp2_if/services/tencent/essapi"
  16. "mtp2_if/utils"
  17. essbasic "github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/essbasic/v20210526"
  18. )
  19. func CreateConsoleLoginUrl(agent *essbasic.Agent, proxyOrganizationName string) (response *essbasic.CreateConsoleLoginUrlResponse, err error) {
  20. response, err = essapi.CreateConsoleLoginUrl(agent, proxyOrganizationName)
  21. return
  22. }
  23. // InitTencentESS 按用户ID和机构ID创建腾讯电子签业务信息
  24. func InitTencentESS(userId, areaUserId int) (err error) {
  25. esignTemplateConfigs, err := models.QueryEsignTemplateConfigs(2, 4)
  26. if err != nil {
  27. return
  28. }
  29. session := db.GetEngine().NewSession()
  30. defer session.Close()
  31. // 开启事务
  32. session.Begin()
  33. // 新增 MdUserSwapProtocol
  34. err = models.InsertMdUserSwapProtocol(userId, areaUserId, 1, session)
  35. if err != nil {
  36. session.Rollback()
  37. return
  38. }
  39. // 新增 UserEsignRecord
  40. for _, item := range esignTemplateConfigs {
  41. err = models.InsertUserEsignRecord(userId, areaUserId, item, session)
  42. if err != nil {
  43. session.Rollback()
  44. return
  45. }
  46. }
  47. return session.Commit()
  48. }
  49. func InitMdUserSwapProtocol(userId, areaUserId int) (err error) {
  50. // 新增 MdUserSwapProtocol
  51. err = models.InsertMdUserSwapProtocol(userId, areaUserId, 3, db.GetEngine().NewSession())
  52. if err != nil {
  53. return
  54. }
  55. return
  56. }
  57. // CreateFlowByTemplateDirectly 通过合同模板创建合同签署流程
  58. func CreateFlowByTemplateDirectly(tmplateName string, userType int,
  59. personName, personMobile, personIdCardNumber string,
  60. organizationName string,
  61. record *models.Useresignrecord) (flowId, signUrl string, err error) {
  62. // 获取模板信息
  63. templateInfo, err := GetTemplateInfo(&tmplateName)
  64. if err != nil {
  65. return
  66. }
  67. if templateInfo == nil {
  68. err = fmt.Errorf("获取模板信息失败, tmplateName:%v", tmplateName)
  69. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  70. return
  71. }
  72. // 获取模板里面的参与方RecipientId
  73. recipients := templateInfo.Recipients
  74. if recipients == nil {
  75. err = fmt.Errorf("获取模板参与方信息失败, tmplateName:%v", tmplateName)
  76. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  77. return
  78. }
  79. // 此处为快速发起的签署方;如果是正式接入,构造签署方,请参考函数内说明,构造需要的场景参数
  80. var flowApproverInfos []*essbasic.FlowApproverInfo
  81. for i := range recipients {
  82. recipient := recipients[i]
  83. if config.SerCfg.TencentCfg.ProxyOrganizationName == *recipient.RoleName &&
  84. *recipient.SignType != 1 {
  85. // 签署方为本企业,同时不是自动签署时(一般为甲方非自动签署)
  86. flowApproverInfos = append(flowApproverInfos, buildSelfOrganizationApprovers(recipient)...)
  87. } else {
  88. // 乙方
  89. if userType == 1 {
  90. // 个人
  91. flowApproverInfos = append(flowApproverInfos, buildPersonApprovers(personName, personMobile, personIdCardNumber, recipient)...)
  92. } else {
  93. // 企业
  94. flowApproverInfos = append(flowApproverInfos, buildOrganizationApprovers(organizationName, recipient)...)
  95. }
  96. }
  97. }
  98. // 发起合同
  99. resp, err := essapi.CreateFlowByTemplateDirectly(*templateInfo.TemplateName, *templateInfo.TemplateId, flowApproverInfos)
  100. if err != nil {
  101. return
  102. }
  103. if resp == nil || len(resp["flowIds"]) == 0 || len(resp["urls"]) == 0 {
  104. err = fmt.Errorf("发起合同签署流程失败, tmplateName:%v", tmplateName)
  105. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  106. return
  107. }
  108. if len(resp["flowIds"]) > 0 {
  109. flowId = *resp["flowIds"][0]
  110. }
  111. if len(resp["urls"]) > 0 {
  112. signUrl = *resp["urls"][0]
  113. }
  114. // 更新电子签记录表信息状态
  115. record.CONTRACTNO = flowId
  116. record.SIGNURL = signUrl
  117. record.RECORDSTATUS = 2
  118. if err = record.Update("CONTRACTNO,SIGNURL,RECORDSTATUS"); err != nil {
  119. logger.GetLogger().Errorf("CreateFlowByTemplateDirectly, %v", err.Error())
  120. }
  121. return
  122. }
  123. // GetFlowStatus 获取合同状态
  124. func GetFlowStatus(flowId string) (recordStatus int, err error) {
  125. agent := utils.SetAgent()
  126. response, err := essapi.DescribeFlowDetailInfo(agent, []*string{&flowId})
  127. if err == nil {
  128. if len(response.Response.FlowInfo) == 0 {
  129. err = fmt.Errorf("获取合同明细失败")
  130. return
  131. }
  132. flowDetailInfo := response.Response.FlowInfo[0]
  133. // 获取对应电子签信息
  134. var record *models.Useresignrecord
  135. record, err = models.GetUseresignRecordByFlowID(flowId)
  136. if err != nil {
  137. err = fmt.Errorf("获取电子签信息失败")
  138. return
  139. }
  140. // 更新电子签信息状态
  141. if *flowDetailInfo.FlowStatus == "ALL" {
  142. recordStatus = 3
  143. }
  144. if *flowDetailInfo.FlowStatus == "REJECT" {
  145. recordStatus = 4
  146. }
  147. if recordStatus == 0 {
  148. err = fmt.Errorf("合同状态异常")
  149. return
  150. }
  151. record.RECORDSTATUS = int32(recordStatus)
  152. if err = record.Update("RECORDSTATUS"); err != nil {
  153. logger.GetLogger().Errorf("GetFlowStatus, %v", err.Error())
  154. }
  155. if recordStatus == 3 {
  156. // 更新用户掉期协议签署表
  157. UpdateMdUserSwapProtocol(flowId)
  158. }
  159. }
  160. return
  161. }
  162. func UpdateMdUserSwapProtocol(flowId string) (err error) {
  163. // 获取对应的电子签记录
  164. var record *models.Useresignrecord
  165. record, err = models.GetUseresignRecordByFlowID(flowId)
  166. if err != nil {
  167. logger.GetLogger().Errorf("UpdateMdUserSwapProtocol, 获取对应的电子签记录失败:%v", err.Error())
  168. return
  169. }
  170. // 获取此用户对应机构的电子签记录列表
  171. records, err := models.QueryUsereSignRecords(int(record.USERID), int(record.AREAUSERID), nil, nil, nil)
  172. if err == nil {
  173. // 所有合同签署完成后,更新用户掉期协议签署表
  174. flag := true
  175. for _, item := range records {
  176. if item.RECORDSTATUS != 3 {
  177. flag = false
  178. break
  179. }
  180. }
  181. if flag {
  182. // 获取对应用户掉期协议签署记录
  183. var datas []models.Mduserswapprotocol
  184. datas, err = models.QueryMdUserSwapProtocol(int(record.USERID), &record.AREAUSERID)
  185. if err == nil {
  186. if len(datas) > 0 {
  187. data := datas[0]
  188. // 获取用户信息,如果是用户所属机构则改状态为 4:已审核,否则改为 3:已签署
  189. var userAccount *models.Useraccount
  190. if userAccount, err = models.GetUserAccount(int(record.USERID)); err == nil {
  191. status := 4
  192. if userAccount.Memberuserid != record.AREAUSERID {
  193. status = 3
  194. }
  195. data.PROTOCOLSTATUS = int32(status)
  196. err = data.Update("PROTOCOLSTATUS")
  197. }
  198. }
  199. } else {
  200. logger.GetLogger().Errorf("UpdateMdUserSwapProtocol, 获取对应用户掉期协议签署记录失败:%v", err.Error())
  201. }
  202. }
  203. } else {
  204. logger.GetLogger().Errorf("UpdateMdUserSwapProtocol, 获取对应的机构电子签记录失败:%v", err.Error())
  205. }
  206. return
  207. }
  208. // GetTemplateInfo 获取模板信息
  209. func GetTemplateInfo(contractName *string) (templateInfo *essbasic.TemplateInfo, err error) {
  210. agent := utils.SetAgent()
  211. templatesResp, err := essapi.DescribeTemplates(agent, contractName)
  212. if err == nil {
  213. if len(templatesResp.Response.Templates) > 0 {
  214. templateInfo = templatesResp.Response.Templates[0]
  215. } else {
  216. err = fmt.Errorf("获取模板信息失败")
  217. }
  218. }
  219. return
  220. }
  221. // buildPersonApprovers 构造个人签署人 - 以BtoC为例, 实际请根据自己的场景构造签署方、控件
  222. func buildPersonApprovers(personName, personMobile, personIdCardNumber string, recipient *essbasic.Recipient) []*essbasic.FlowApproverInfo {
  223. var flowApproverInfos []*essbasic.FlowApproverInfo
  224. // 传入个人签署方
  225. flowApproverInfo := &essbasic.FlowApproverInfo{}
  226. approverType := "PERSON"
  227. flowApproverInfo.ApproverType = &approverType
  228. flowApproverInfo.Name = &personName
  229. flowApproverInfo.Mobile = &personMobile
  230. flowApproverInfo.IdCardType = utils.SetPointValue("ID_CARD")
  231. flowApproverInfo.IdCardNumber = &personIdCardNumber
  232. // 模板中对应签署方的参与方id
  233. flowApproverInfo.RecipientId = recipient.RecipientId
  234. flowApproverInfos = append(flowApproverInfos, flowApproverInfo)
  235. // 传入企业静默签署,此处需要在config.php中设置一个持有的印章值serverSignSealId
  236. // flowApproverInfos = append(flowApproverInfos, BuildServerSignApprover())
  237. // 内容控件填充结构,详细说明参考
  238. // https://cloud.tencent.com/document/api/1420/61525#FormField
  239. return flowApproverInfos
  240. }
  241. // buildOrganizationApprovers 构造企业签署人
  242. func buildOrganizationApprovers(organizationName string, recipient *essbasic.Recipient) []*essbasic.FlowApproverInfo {
  243. var flowApproverInfos []*essbasic.FlowApproverInfo
  244. // 传入企业签署方
  245. flowApproverInfo := &essbasic.FlowApproverInfo{}
  246. approverType := "ORGANIZATION"
  247. flowApproverInfo.ApproverType = &approverType
  248. flowApproverInfo.OrganizationName = &organizationName
  249. // 模板中对应签署方的参与方id
  250. flowApproverInfo.RecipientId = recipient.RecipientId
  251. flowApproverInfos = append(flowApproverInfos, flowApproverInfo)
  252. return flowApproverInfos
  253. }
  254. // buildSelfOrganizationApprovers 构造本企业签署人
  255. func buildSelfOrganizationApprovers(recipient *essbasic.Recipient) []*essbasic.FlowApproverInfo {
  256. var flowApproverInfos []*essbasic.FlowApproverInfo
  257. // 传入企业签署方
  258. flowApproverInfo := &essbasic.FlowApproverInfo{}
  259. approverType := "ORGANIZATION"
  260. flowApproverInfo.ApproverType = &approverType
  261. flowApproverInfo.OrganizationOpenId = &config.SerCfg.TencentCfg.ProxyOrganizationOpenId // 本企业OpenID
  262. // 模板中对应签署方的参与方id
  263. flowApproverInfo.RecipientId = recipient.RecipientId
  264. flowApproverInfo.OpenId = &config.SerCfg.TencentCfg.ProxyOperatorOpenId // 本企业员工OpenID
  265. flowApproverInfos = append(flowApproverInfos, flowApproverInfo)
  266. return flowApproverInfos
  267. }
  268. func ProcessNotice(content string) {
  269. // "{\"MsgId\":\"yDSLWUUckposmdf8UBxiJvuDbgiYRYbj\",\"MsgType\":\"FlowStatusChange\",\"MsgVersion\":\"ThirdPartyApp\",\"MsgData\":{\"ApplicationId\":\"yDwiuUUckpogfoa4UxhigrYChFMdSJQV\",\"ProxyOrganizationOpenId\":\"TJMD\",\"CustomerData\":\"\",\"FlowId\":\"yDSLWUUckposcsthUwvcaGSuV5EKZAzu\",\"FlowName\":\"1000_P_风险揭示书\",\"FlowType\":\"合同\",\"FlowStatus\":\"INIT\",\"FlowMessage\":\"\",\"CreateOn\":1699077064,\"Deadline\":1730613064,\"FlowApproverInfo\":[{\"ProxyOrganizationOpenId\":\"\",\"ProxyOperatorOpenId\":\"\",\"recipientId\":\"yDSLNUUckpos1i71UuGNih5yMGbZij46\",\"RecipientId\":\"yDSLNUUckpos1i71UuGNih5yMGbZij46\",\"PhoneNumber\":\"15914012152\",\"ProxyOrganizationName\":\"\",\"SignOrder\":0,\"ApproveName\":\"曹晓亮\",\"ApproveStatus\":\"PENDING\",\"ApproveMessage\":\"\",\"ApproveTime\":0,\"CaSign\":\"\"}],\"OccurTime\":1699077064,\"CcInfo\":[]}}"
  270. m := make(map[string]interface{})
  271. if err := json.Unmarshal([]byte(content), &m); err == nil {
  272. // 判断通知类型
  273. msgType, _ := m["MsgType"].(string)
  274. if msgType == "FlowStatusChange" {
  275. // 合同相关回调
  276. // https://qian.tencent.com/developers/partner/callback_types_contracts_sign
  277. msgData, _ := m["MsgData"].(map[string]interface{})
  278. flowId, _ := msgData["FlowId"].(string)
  279. flowStatus, _ := msgData["FlowStatus"].(string)
  280. if flowStatus == "ALL" || flowStatus == "REJECT" {
  281. // 更新电子签合同状态
  282. if record, err := models.GetUseresignRecordByFlowID(flowId); err == nil {
  283. if flowStatus == "ALL" {
  284. record.RECORDSTATUS = 3
  285. } else {
  286. record.RECORDSTATUS = 4
  287. }
  288. if err = record.Update("RECORDSTATUS"); err != nil {
  289. logger.GetLogger().Errorf("ProcessNotice, %v", err.Error())
  290. }
  291. if record.RECORDSTATUS == 3 {
  292. // 更新用户掉期协议签署表
  293. UpdateMdUserSwapProtocol(flowId)
  294. }
  295. }
  296. }
  297. }
  298. }
  299. }
  300. // VerifySign 电子签通知推送验签
  301. func VerifySign(payload, signFromHeader string) bool {
  302. // 验证签名
  303. hash := "sha256=" + hmacsha256hex(payload, config.SerCfg.TencentCfg.SignToken)
  304. return hash == signFromHeader
  305. }
  306. // DecryptContent 电子签通知推送内容解密
  307. func DecryptContent(payload string) (content string, err error) {
  308. // string -> json
  309. m := make(map[string]string)
  310. err = json.Unmarshal([]byte(payload), &m)
  311. if err != nil {
  312. return
  313. }
  314. encrypt, ok := m["encrypt"]
  315. if !ok {
  316. err = fmt.Errorf("电子签通知推送内容解密失败")
  317. logger.GetLogger().Errorf("DecryptContent, %v", err.Error())
  318. return
  319. }
  320. // base64解密
  321. crypted, err := base64.StdEncoding.DecodeString(encrypt)
  322. if err != nil {
  323. logger.GetLogger().Errorf("base64 DecodeString returned: %s", err)
  324. return
  325. }
  326. b, err := aesDecrypt(crypted, []byte(config.SerCfg.TencentCfg.SignKey))
  327. if err != nil {
  328. logger.GetLogger().Errorf("AesDecrypt returned: %s", err)
  329. return
  330. }
  331. content = string(b)
  332. return
  333. }
  334. // Hmacsha256hex hmac sha256
  335. func hmacsha256hex(s, key string) string {
  336. hashed := hmac.New(sha256.New, []byte(key))
  337. hashed.Write([]byte(s))
  338. return hex.EncodeToString(hashed.Sum(nil))
  339. }
  340. // 使用callbackKey解密
  341. func aesDecrypt(crypted, key []byte) ([]byte, error) {
  342. block, err := aes.NewCipher(key)
  343. if err != nil {
  344. return nil, err
  345. }
  346. blockSize := block.BlockSize()
  347. blockMode := cipher.NewCBCDecrypter(block, key[:blockSize])
  348. origData := make([]byte, len(crypted))
  349. blockMode.CryptBlocks(origData, crypted)
  350. origData = pkcs7UnPadding(origData)
  351. return origData, nil
  352. }
  353. // PKCS7UnPadding 去除填充
  354. func pkcs7UnPadding(origData []byte) []byte {
  355. length := len(origData)
  356. unPadding := int(origData[length-1])
  357. return origData[:(length - unPadding)]
  358. }