WhatsApp Flows响应解密失败求助:Business API发送响应遇报错
WhatsApp Business API Flows响应解密失败问题排查与修复
问题描述
使用WhatsApp Business API生成WhatsApp Flows响应时,请求解密环节运行正常,但返回响应时收到报错:"Could not decrypt the response received from the server"。已查阅官方文档,但未找到正确的响应生成与验证方法,附上相关代码,寻求响应格式、发送方式的指导或示例。
def post(self, request, *args, **kwargs): try: dict_data = json.loads(request.body.decode('utf-8')) encrypted_flow_data_b64 = dict_data['encrypted_flow_data'] encrypted_aes_key_b64 = dict_data['encrypted_aes_key'] initial_vector_b64 = dict_data['initial_vector'] flipped_iv = self.flip_iv(initial_vector_b64.encode('utf-8')) encrypted_aes_key = b64decode(encrypted_aes_key_b64) key_private = open('*******.pem', 'rb').read().decode('utf-8') private_key = load_pem_private_key(key_private.encode('utf-8'), password="*************".encode('utf-8')) aes_key = private_key.decrypt(encrypted_aes_key, OAEP(mgf=MGF1(algorithm=hashes.SHA256()), algorithm=hashes.SHA256(), label=None)) aes_key_b64 = b64encode(aes_key).decode('utf-8') flow_data = b64decode(encrypted_flow_data_b64) key = b64decode(aes_key_b64) iv = b64decode(initial_vector_b64) encrypted_flow_data_body = flow_data[:-16] encrypted_flow_data_tag = flow_data[-16:] cipher = Cipher(algorithms.AES(key), modes.GCM(iv,encrypted_flow_data_tag)) decryptor = cipher.decryptor() decrypted_data = decryptor.update(encrypted_flow_data_body) + decryptor.finalize() flow_data_request_raw = decrypted_data.decode("utf-8") hello_world_text = "HELLO WORLD" response_data = { "version": "3.0", "screen": "MY_FIRST_SCREEN", "data": { "hello_world_text": hello_world_text } } response_json = json.dumps(response_data) # Obtendo a chave AES após descriptografar encrypted_aes_key fb_aes_key = private_key.decrypt(encrypted_aes_key, OAEP(mgf=MGF1(algorithm=hashes.SHA256()), algorithm=hashes.SHA256(), label=None)) # Usando a chave AES para criptografar a resposta response_cipher = Cipher(algorithms.AES(fb_aes_key), modes.GCM(iv)) encryptor = response_cipher.encryptor() encrypted_response = ( encryptor.update(response_json.encode("utf-8")) + encryptor.finalize() + encryptor.tag ) encrypted_response_b64 = b64encode(encrypted_response).decode('utf-8') # Construct the final response final_response = { "encrypted_flow_data": encrypted_response_b64, "encrypted_aes_key": encrypted_aes_key_b64, "initial_vector": initial_vector_b64 } return JsonResponse(final_response, status=200) except Exception as e: print(e) return HttpResponse(status=500, content='ok') def flip_iv(self, iv): flipped_bytes = [] for byte in iv: flipped_byte = byte ^ 0xFF flipped_bytes.append(flipped_byte) return bytes(flipped_bytes)
问题分析与修复方案
核心错误点
- IV使用不符合规范:加密响应时必须使用翻转后的IV(即你代码中计算的
flipped_iv),但当前代码仍用原始IV加密,且响应返回的也是原始IV,这是导致解密失败的关键原因。 - 重复解密AES密钥:代码中两次调用
private_key.decrypt解密同一个AES密钥,属于冗余操作,可直接复用第一次解密结果。
修正后的关键代码片段
# 复用首次解密得到的AES密钥,无需重复解密 fb_aes_key = aes_key # 使用翻转后的IV进行响应加密(注意先解码flipped_iv) response_cipher = Cipher(algorithms.AES(fb_aes_key), modes.GCM(b64decode(flipped_iv))) encryptor = response_cipher.encryptor() # 先加密响应内容,再拼接GCM标签 encrypted_response = encryptor.update(response_json.encode("utf-8")) + encryptor.finalize() encrypted_response_with_tag = encrypted_response + encryptor.tag encrypted_response_b64 = b64encode(encrypted_response_with_tag).decode('utf-8') # 最终响应的initial_vector必须传翻转后的IV的Base64编码 final_response = { "encrypted_flow_data": encrypted_response_b64, "encrypted_aes_key": encrypted_aes_key_b64, "initial_vector": b64encode(flipped_iv).decode('utf-8') }
额外注意事项
- 确保
flip_iv方法逻辑正确:对每个字节异或0xFF是WhatsApp要求的IV翻转规则,当前实现无误。 - JSON序列化保持紧凑:
json.dumps不要添加额外空格,避免加密后的数据与预期不一致。 - 私钥格式验证:确认私钥为PKCS#8格式,解密AES密钥时的OAEP参数(SHA256算法、MGF1-SHA256掩码)与官方要求完全匹配。
内容的提问来源于stack exchange,提问作者erick
相关产品推荐
相关产品推荐

