OfpayHelper.py 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441
  1. # -*- coding: utf-8 -*-
  2. import os
  3. import re
  4. import sys
  5. import time
  6. import pymysql
  7. import logging
  8. # import jwt
  9. import json
  10. from datetime import datetime
  11. from mitmproxy import flowfilter
  12. from mitmproxy import http
  13. from mitmproxy import ctx
  14. # from http.cookies import SimpleCookie
  15. sys.path.append('../')
  16. import utils.Utils as Utils
  17. sys.path.pop()
  18. """
  19. #http.HTTPFlow 实例 flow
  20. flow.request.http_version #HTTP 版本
  21. flow.request.headers #获取所有头信息,包含Host、User-Agent、Content-type等字段
  22. flow.request.cookies #cookie头
  23. flow.request.url #完整的请求地址,包含域名及请求参数,但是不包含放在body里面的请求参数
  24. flow.request.pretty_url #同flow.request.url目前没看出什么差别
  25. flow.request.host #域名
  26. flow.request.port #请求的目标端口
  27. flow.request.method #请求方式。POST、GET等
  28. flow.request.scheme #什么请求 ,如https
  29. flow.request.path # 请求的路径,url除域名之外的内容
  30. flow.request.get_text() #请求中body内容,有一些http会把请求参数放在body里面,那么可通过此方法获取,返回字典类型
  31. flow.request.replace() # 使用正则替换content中的内容
  32. flow.request.query #返回MultiDictView类型的数据,url直接带的键值参数
  33. flow.request.get_content()#bytes,结果如flow.request.get_text()
  34. flow.request.raw_content #bytes,结果如flow.request.get_content()
  35. flow.request.urlencoded_form #MultiDictView,content-type:application/x-www-form-urlencoded时的请求参数,不包含url直接带的键值参数
  36. flow.request.multipart_form #MultiDictView,content-type:multipart/form-data
  37. flow.request.timestamp_start #请求开始的时间戳
  38. flow.request.timestamp_end #请求结束的时间戳
  39. 时的请求参数,不包含url直接带的键值参数
  40. #以上均为获取request信息的一些常用方法,对于response,同理
  41. flow.response.status_code #状态码
  42. flow.response.headers #获取所有头信息
  43. flow.response.cookies #cookie头
  44. flow.response.text#返回内容,已解码
  45. flow.response.content #返回内容,二进制
  46. flow.response.set_text() #修改返回内容,不需要转码
  47. flow.response.replace() # 使用正则替换content中的内容
  48. flow.response.timestamp_start #响应开始的时间戳
  49. flow.response.timestamp_end #响应结束的时间戳
  50. """
  51. class OfpayHelper:
  52. order_simple_data = {
  53. "awardId": "W1155090378949787660",
  54. "activityId": "A923605206137307136",
  55. "activityName": "采集",
  56. "activityState": "2",
  57. "activityStartTime": "2024-01-01 00:00",
  58. "activityEndTime": "2888-12-31 23:59",
  59. "businessType": "4005",
  60. "outActivityCode": "eCoffee",
  61. "mobile": "",
  62. "prizeId": "sku14117",
  63. "prizeName": "数据采集成功",
  64. "prizeAlias": "",
  65. "prizeDesc": None,
  66. "prizeDescUrl": "https://mstatic.ofpay.com/marketing/upload/ca2ed3a05b2846b7909debf2df8e3495.png",
  67. "prizeBannerUrl": "https://mstatic.ofpay.com/marketing/upload/c4d1a0b94b50462eb0f040306a9badf4.png",
  68. "categoryId": "1",
  69. "rechargeType": "09",
  70. "goodsScene": "0",
  71. "goodsList": [],
  72. "orderNum": 1,
  73. "createTime": None,
  74. "imgUrl": "https://mstatic.ofpay.com/marketing/upload/7e21faea6ba94379bf16968c246cb044.png",
  75. "orderStatus": "3",
  76. "detailId": "T123456789",
  77. "clientAccount": "13430389115",
  78. "redeemCode": "",
  79. "redeemCodeStatus": "",
  80. "dynamicCodeSign": "1",
  81. "startEffectTime": "",
  82. "endEffectTime": None,
  83. "toExpireFlag": "0",
  84. "faceVal": "",
  85. "orderId": "T240226090160697",
  86. "tenantId": "0000000191",
  87. "price": "",
  88. "awardPrice": "0.0",
  89. "salePrice": "0.0",
  90. "rechargeId": "R1211608194317672448",
  91. "rechargeTime": "2024-01-01 00:00:00",
  92. "payStatus": "2",
  93. "discountPrice": "",
  94. "activityPrice": "",
  95. "customerInfo": "{\"device_id\":\"D29ED082-549A-4882-98FC-8BB881D1552B\",\"loginType\":\"interactiveIGoChoose\",\"gameAccount\":\"13430389115\",\"city_code\":\"440100\",\"cisno\":\"ZbHv0CEM2cGjx0DB9DXVJg==\",\"isNewUser\":\"0\",\"marketId\":\"M923156289016692736\",\"city_name\":\"广州市\",\"phone\":\"13430389115\",\"fromEntry\":\"APP\",\"currentTimeMillis\":\"1709515975349\",\"userUuid\":\"Pfd6kjTSmjCfQ8boswe1PpAmfgZW0acz\",\"cust_id\":\"Pfd6kjTSmjCfQ8boswe1PpAmfgZW0acz\",\"invitationCode\":\"BGCKWC\"}",
  96. "callbackOrder": "",
  97. "activityRechargeEffectStartTime": "",
  98. "activityRechargeEffectEndTime": "",
  99. "accountType": "",
  100. "payFlag": "1",
  101. "activityPayFlag": True,
  102. "thirdInfo": "{\"faceValue\":\"20.00\",\"customGatewayId\":\"ZDY_ICBC_NJFH\",\"showSign\":\"1\",\"xcxShowSign\":\"2\",\"order\":\"24\",\"toBPrice\":\"19.20\",\"appId\":\"gh_58e6ebeaa1ea\",\"showFlag\":\"eCoffee-Tims\",\"showPhone\":\"1\",\"pointActivity\":\"HD046012y3VGiMMHzP\",\"stockShowSign\":\"2\"}",
  103. "vendorVoucher": "",
  104. "productUseMsg": "",
  105. "proof": "",
  106. "amount": 1,
  107. "parentActivityNo": "",
  108. "parentDetailId": "",
  109. "subOrderExt": "{\"orderStatus\":\"\",\"payStatus\":\"\"}",
  110. "logisticsNo": "",
  111. "company": "",
  112. "promoteId": "",
  113. "version": 1,
  114. "gateWayId": "",
  115. "payType": "",
  116. "needRechargeNum": "0"
  117. }
  118. def __init__(self):
  119. self.domain_name = 'market-web.ofpay.com';
  120. self.host_ip = None;
  121. ip_address = Utils.get_ip_address(self.domain_name);
  122. if ip_address:
  123. self.host_ip = ip_address;
  124. self.db_conn = None;
  125. self.connect_mysql();
  126. def connect_mysql(self):
  127. config = {
  128. 'host':'47.106.225.136',
  129. 'port':3306,
  130. 'user':'root',
  131. 'passwd':'sjojo123456',
  132. 'database':'mitmproxy',
  133. 'charset':'utf8'
  134. };
  135. db_conn = None;
  136. while True:
  137. try:
  138. db_conn = pymysql.connect(**config);
  139. db_conn.ping(reconnect=True);
  140. except pymysql.OperationalError as e:
  141. print(e);
  142. print('连接断开,正在尝试重新连接...');
  143. if db_conn:
  144. db_conn.close();
  145. db_conn = pymysql.connect(**config);
  146. time.sleep(1);
  147. else:
  148. break;
  149. self.db_conn = db_conn;
  150. def check_mysql_connect(self):
  151. try:
  152. with self.db_conn.cursor() as cursor:
  153. cursor.execute('SELECT 1');
  154. except pymysql.MySQLError as e:
  155. print(e);
  156. self.db_conn.close();
  157. print('mysql重连...');
  158. self.connect_mysql();
  159. def check_host_pass(self, host):
  160. if self.host_ip:
  161. if host != self.host_ip and host != self.domain_name:
  162. return False;
  163. else:
  164. if host != self.domain_name:
  165. return False;
  166. return True;
  167. def request(self, flow: http.HTTPFlow):
  168. if not self.check_host_pass(flow.request.host):
  169. return;
  170. url = flow.request.url;
  171. path = flow.request.path;
  172. request = flow.request;
  173. def response(self, flow: http.HTTPFlow):
  174. if not self.check_host_pass(flow.request.host):
  175. return;
  176. url = flow.request.url;
  177. path = flow.request.path;
  178. print("###[OfpayHelper]path=%s"%path);
  179. if path.startswith('/h5/union/interactiveIGoChoose/index'):
  180. self.handle_login(flow);
  181. elif path.startswith('/h5/union/api/interactiveIGoChoose/indexConfigRebuild'):
  182. self.handle_activitylist(flow);
  183. elif path.startswith('/h5/union/api/interactiveIGoChoose/orderList'):
  184. self.handle_orderlist(flow);
  185. def get_jwt_token_data(self, flow: http.HTTPFlow):
  186. request = flow.request;
  187. headers = dict(request.headers);
  188. jwt_data = None;
  189. try:
  190. jwt_str = None;
  191. if 'Authorization' in headers:
  192. jwt_str = headers['Authorization'];
  193. else:
  194. cookies = dict(request.cookies);
  195. if 'unionToken_interactiveIGoChoose' in cookies:
  196. jwt_str = cookies['unionToken_interactiveIGoChoose'];
  197. if jwt_str:
  198. jwt_data = Utils.parse_jwt(jwt_str);
  199. except jwt.PyJWTError as e:
  200. print('jwt token解析失败');
  201. else:
  202. pass
  203. finally:
  204. pass
  205. if jwt_data:
  206. payload = jwt_data['payload'];
  207. if 'customerInfo' in payload:
  208. info_str = payload['customerInfo'];
  209. customer_info = json.loads(info_str);
  210. payload['customerInfo'] = customer_info;
  211. return jwt_data;
  212. def handle_login(self, flow: http.HTTPFlow):
  213. ctx.log.info('###handle_login###');
  214. request = flow.request;
  215. response = flow.response;
  216. jwt_data = self.get_jwt_token_data(flow);
  217. if not jwt_data:
  218. return;
  219. login_params = flow.request.query.get('loginParams');
  220. ori_cookies = dict(request.cookies);
  221. rsp_cookies = dict(response.cookies);
  222. for key in rsp_cookies:
  223. ori_cookies[key] = rsp_cookies[key];
  224. # # 获取所有的Set-Cookie头部
  225. # set_cookie_headers = flow.response.headers.get_all("Set-Cookie")
  226. # for cookie_header in set_cookie_headers:
  227. # cookie = SimpleCookie();
  228. # cookie.load(cookie_header);
  229. # # SimpleCookie对象可以像字典一样工作
  230. # for key, morsel in cookie.items():
  231. # # 这里可以添加进一步的逻辑来处理cookie的键和值
  232. # # 例如,可以检查cookie的过期时间,路径等属性
  233. # print("Attributes:", morsel);
  234. authorization = ori_cookies['unionToken_interactiveIGoChoose'];
  235. sign_time = None;
  236. expire_time = None;
  237. try:
  238. jwt_data = Utils.parse_jwt(authorization);
  239. if not jwt_data:
  240. return;
  241. payload = jwt_data['payload'];
  242. if 'customerInfo' in payload:
  243. info_str = payload['customerInfo'];
  244. customer_info = json.loads(info_str);
  245. payload['customerInfo'] = customer_info;
  246. account = payload['customerInfo']['phone'];
  247. tmp_dt = datetime.utcfromtimestamp(payload['iat']);
  248. sign_time = tmp_dt.strftime('%Y-%m-%d %H:%M:%S');
  249. tmp_dt = datetime.utcfromtimestamp(payload['exp']);
  250. expire_time = tmp_dt.strftime('%Y-%m-%d %H:%M:%S');
  251. except Exception as e:
  252. print(e);
  253. try:
  254. sql_query = f'''
  255. UPDATE elife_account_data
  256. SET
  257. authorization = %s,
  258. cookies = %s,
  259. update_time = %s,
  260. expire_time = %s,
  261. login_params = %s
  262. WHERE account = %s;
  263. ''';
  264. sql_params = (authorization, repr(ori_cookies), sign_time, expire_time, login_params);
  265. self.check_mysql_connect();
  266. cursor = self.db_conn.cursor();
  267. cursor.execute(sql_query, sql_params);
  268. self.db_conn.commit();
  269. cursor.close();
  270. except pymysql.OperationalError as e:
  271. print(e);
  272. def handle_activitylist(self, flow: http.HTTPFlow):
  273. ctx.log.info('###handle_activitylist###');
  274. request = flow.request;
  275. response = flow.response;
  276. jwt_data = self.get_jwt_token_data(flow);
  277. if not jwt_data:
  278. return;
  279. payload = jwt_data['payload'];
  280. if 'customerInfo' not in payload:
  281. return;
  282. account = payload['customerInfo']['phone'];
  283. if not account:
  284. return;
  285. if account != '13430389115':
  286. return;
  287. rsp_params = json.loads(response.get_text());
  288. if rsp_params['code'] != 'success':
  289. return;
  290. rsp_data = rsp_params['data'];
  291. sql_activity_query = f'''
  292. CALL UpdateElifeActivities(%s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s);
  293. ''';
  294. sql_activity_params = [];
  295. sql_award_query = f'''
  296. CALL UpdateElifeActivityAwards(%s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s);
  297. ''';
  298. sql_award_params = [];
  299. activity_list = rsp_params['data'];
  300. activity_sort_num = 0;
  301. for activity_info in activity_list:
  302. sql_activity_params.append(('1',
  303. activity_info['activityId'], activity_info['activityAlias'], activity_info['outActivityCode'],
  304. activity_info['activityTitle'], activity_info['activityState'], activity_info['activityIcon'],
  305. activity_info['activityLink'], activity_info['activityBanner'], activity_info['subLoginType'],
  306. activity_info['subActivityId'] if 'subActivityId' in activity_info else '', activity_info['activityDesc'], activity_sort_num));
  307. activity_sort_num += 1;
  308. award_list = activity_info['awardList'];
  309. for award_info in award_list:
  310. # print(award_info)
  311. sql_award_params.append((
  312. award_info['awardId'], award_info['prizeName'], award_info['activityId'],
  313. award_info['prizeId'], award_info['prizeDesc'], award_info['prizeBannerUrl'],
  314. award_info['prizeDescUrl'], award_info['imgUrl'], int(award_info['stockNum']),
  315. float(award_info['price']), award_info['categoryType'], award_info['goodsScene'],
  316. award_info['rechargeType'], int(award_info['useStock']), int(award_info['remainStock']),
  317. int(award_info['cycleStock']), int(award_info['cycleRemainStock']), int(award_info['orderNum']),
  318. award_info['payFlag'], award_info['thirdInfo'], award_info['awardType'],
  319. int(award_info['firstSignAward']), int(award_info['renewSignAward']), award_info['prizeAlias'] if 'prizeAlias' in award_info else '',
  320. award_info['parentAwardId'] if 'parentAwardId' in award_info else ''));
  321. try:
  322. self.check_mysql_connect();
  323. cursor = self.db_conn.cursor();
  324. cursor.executemany(sql_activity_query, sql_activity_params);
  325. cursor.executemany(sql_award_query, sql_award_params);
  326. self.db_conn.commit();
  327. cursor.close();
  328. except pymysql.OperationalError as e:
  329. print(e);
  330. def handle_orderlist(self, flow: http.HTTPFlow):
  331. ctx.log.info('###handle_orderlist###');
  332. request = flow.request;
  333. response = flow.response;
  334. cookies = dict(request.cookies); # 转换cookies格式为dict
  335. # if 'unionToken_interactiveIGoChoose' not in cookies:
  336. # return;
  337. # account = None;
  338. # try:
  339. # jwt_str = cookies['unionToken_interactiveIGoChoose'];
  340. # # payload = jwt.decode(jwt_str, '', algorithms=['HS256'], verify=False, options={'verify_signature':False});
  341. # # info_str = payload.get('customerInfo');
  342. # # 不依赖库,简单方法解析
  343. # jwt_data = Utils.parse_jwt(jwt_str);
  344. # if jwt_data:
  345. # payload = jwt_data['payload'];
  346. # info_str = payload['customerInfo'];
  347. # customer_info = json.loads(info_str);
  348. # account = customer_info['phone'];
  349. # except jwt.PyJWTError as e:
  350. # print('jwt token解析失败');
  351. # else:
  352. # pass
  353. # finally:
  354. # pass
  355. jwt_data = self.get_jwt_token_data(flow);
  356. if not jwt_data:
  357. return;
  358. payload = jwt_data['payload'];
  359. if 'customerInfo' not in payload:
  360. return;
  361. account = payload['customerInfo']['phone'];
  362. if not account:
  363. return;
  364. headers = dict(request.headers);
  365. uuid = headers['UUID'];
  366. authorization = headers['Authorization'];
  367. user_agent = headers['User-Agent'];
  368. market_id = request.query.get('marketId');
  369. event_visitor_id = request.query.get('eventVisitorId');
  370. clientAccount = account if account else '13400000000';
  371. # create_time = '2024-01-01 00:00:00';
  372. create_time = datetime.now().strftime('%Y-%m-%d %H:%M:%S');
  373. capture_code = Utils.generate_random_code(6);
  374. simple_data = OfpayHelper.order_simple_data;
  375. simple_data['prizeDesc'] = capture_code;
  376. simple_data['createTime'] = create_time;
  377. simple_data['endEffectTime'] = create_time;
  378. simple_data['clientAccount'] = clientAccount;
  379. rsp_params = json.loads(response.get_text());
  380. if rsp_params['code'] == 'success':
  381. rsp_data = rsp_params['data'];
  382. rsp_data['list'].insert(0, simple_data);
  383. update_time = create_time;
  384. tmp_dt = datetime.utcfromtimestamp(payload['iat']);
  385. sign_time = tmp_dt.strftime('%Y-%m-%d %H:%M:%S');
  386. tmp_dt = datetime.utcfromtimestamp(payload['exp']);
  387. expire_time = tmp_dt.strftime('%Y-%m-%d %H:%M:%S');
  388. simple_data['createTime'] = expire_time;
  389. sql_query = f'''
  390. CALL UpdateElifeAccountData(%s, %s, %s, %s, %s, %s, %s, %s, %s, %s);
  391. ''';
  392. sql_params = (account, uuid, authorization, repr(cookies), user_agent, market_id, event_visitor_id, capture_code , update_time, expire_time);
  393. try:
  394. self.check_mysql_connect();
  395. cursor = self.db_conn.cursor();
  396. cursor.execute(sql_query, sql_params);
  397. self.db_conn.commit();
  398. cursor.close();
  399. simple_data['prizeName'] = '数据采集成功';
  400. except pymysql.OperationalError as e:
  401. print(e);
  402. simple_data['prizeName'] = '数据采集失败';
  403. simple_data['prizeDesc'] = '';
  404. response.set_text(json.dumps(rsp_params));