You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WhatsApp Flows响应解密失败求助:Business API发送响应遇报错

WhatsApp Business API Flows响应解密失败问题排查与修复

问题描述

使用WhatsApp Business API生成WhatsApp Flows响应时,请求解密环节运行正常,但返回响应时收到报错:"Could not decrypt the response received from the server"。已查阅官方文档,但未找到正确的响应生成与验证方法,附上相关代码,寻求响应格式、发送方式的指导或示例。

def post(self, request, *args, **kwargs):
        try:
            dict_data = json.loads(request.body.decode('utf-8'))
            encrypted_flow_data_b64 = dict_data['encrypted_flow_data']
            encrypted_aes_key_b64 = dict_data['encrypted_aes_key']
            initial_vector_b64 = dict_data['initial_vector']
            
            flipped_iv = self.flip_iv(initial_vector_b64.encode('utf-8'))
            
            encrypted_aes_key = b64decode(encrypted_aes_key_b64)
            key_private = open('*******.pem', 'rb').read().decode('utf-8')
            private_key = load_pem_private_key(key_private.encode('utf-8'), password="*************".encode('utf-8'))
            
            aes_key = private_key.decrypt(encrypted_aes_key, OAEP(mgf=MGF1(algorithm=hashes.SHA256()), algorithm=hashes.SHA256(), label=None))
            aes_key_b64 = b64encode(aes_key).decode('utf-8')
            
            flow_data  = b64decode(encrypted_flow_data_b64)
            key = b64decode(aes_key_b64)
            iv = b64decode(initial_vector_b64)
            
            encrypted_flow_data_body = flow_data[:-16]
            encrypted_flow_data_tag = flow_data[-16:]
            cipher = Cipher(algorithms.AES(key), modes.GCM(iv,encrypted_flow_data_tag))
            decryptor = cipher.decryptor()
            decrypted_data = decryptor.update(encrypted_flow_data_body) + decryptor.finalize()
            flow_data_request_raw = decrypted_data.decode("utf-8")
            
            hello_world_text = "HELLO WORLD"
            
            response_data = {
                "version": "3.0",
                "screen": "MY_FIRST_SCREEN",
                "data": {
                    "hello_world_text": hello_world_text
                }
            }

            response_json = json.dumps(response_data)
            
            # Obtendo a chave AES após descriptografar encrypted_aes_key
            fb_aes_key = private_key.decrypt(encrypted_aes_key, OAEP(mgf=MGF1(algorithm=hashes.SHA256()), algorithm=hashes.SHA256(), label=None))

            # Usando a chave AES para criptografar a resposta
            response_cipher = Cipher(algorithms.AES(fb_aes_key), modes.GCM(iv))
            encryptor = response_cipher.encryptor()
            encrypted_response = (
                encryptor.update(response_json.encode("utf-8")) +
                encryptor.finalize() +
                encryptor.tag
            )
            encrypted_response_b64 = b64encode(encrypted_response).decode('utf-8')
            
            # Construct the final response
            final_response = {
                "encrypted_flow_data": encrypted_response_b64,
                "encrypted_aes_key": encrypted_aes_key_b64,
                "initial_vector": initial_vector_b64
            }
            
            return JsonResponse(final_response, status=200)
        except Exception as e:
            print(e)
            return HttpResponse(status=500, content='ok')

    
    def flip_iv(self, iv):
        flipped_bytes = []
        for byte in iv:
            flipped_byte = byte ^ 0xFF
            flipped_bytes.append(flipped_byte)
        return bytes(flipped_bytes)

问题分析与修复方案

核心错误点

  1. IV使用不符合规范:加密响应时必须使用翻转后的IV(即你代码中计算的flipped_iv),但当前代码仍用原始IV加密,且响应返回的也是原始IV,这是导致解密失败的关键原因。
  2. 重复解密AES密钥:代码中两次调用private_key.decrypt解密同一个AES密钥,属于冗余操作,可直接复用第一次解密结果。

修正后的关键代码片段

# 复用首次解密得到的AES密钥,无需重复解密
fb_aes_key = aes_key

# 使用翻转后的IV进行响应加密(注意先解码flipped_iv)
response_cipher = Cipher(algorithms.AES(fb_aes_key), modes.GCM(b64decode(flipped_iv)))
encryptor = response_cipher.encryptor()
# 先加密响应内容,再拼接GCM标签
encrypted_response = encryptor.update(response_json.encode("utf-8")) + encryptor.finalize()
encrypted_response_with_tag = encrypted_response + encryptor.tag
encrypted_response_b64 = b64encode(encrypted_response_with_tag).decode('utf-8')

# 最终响应的initial_vector必须传翻转后的IV的Base64编码
final_response = {
    "encrypted_flow_data": encrypted_response_b64,
    "encrypted_aes_key": encrypted_aes_key_b64,
    "initial_vector": b64encode(flipped_iv).decode('utf-8')
}

额外注意事项

  • 确保flip_iv方法逻辑正确:对每个字节异或0xFF是WhatsApp要求的IV翻转规则,当前实现无误。
  • JSON序列化保持紧凑:json.dumps不要添加额外空格,避免加密后的数据与预期不一致。
  • 私钥格式验证:确认私钥为PKCS#8格式,解密AES密钥时的OAEP参数(SHA256算法、MGF1-SHA256掩码)与官方要求完全匹配。

内容的提问来源于stack exchange,提问作者erick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 18:24:50