如何基于CCAVENUE示例代码实现订单状态API并返回指定响应
CCAVENUE订单状态API实现方案(基于官方示例改造)
已完成经银行审计的CCAVENUE支付网关集成,现需按照银行要求实现订单状态查询API,基于官方提供的PHP示例代码调整后,返回指定格式的JSON响应。
官方原示例代码
<?php error_reporting(0); $working_key = ''; //Shared by CCAVENUES $access_code = ''; $merchant_json_data = array( 'order_no' => '', 'reference_no'=>'' ); $merchant_data = json_encode($merchant_json_data); $encrypted_data = encrypt($merchant_data, $working_key); $final_data = 'enc_request='.$encrypted_data.'&access_code='.$access_code.'&command=orderStatusTracker&request_type=JSON&response_type=JSON'; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://apitest.ccavenue.com/apis/servlet/DoWebTrans"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_VERBOSE, 1); curl_setopt($ch, CURLOPT_HTTPHEADER,'Content-Type: application/json') ; curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $final_data); // Get server response ... $result = curl_exec($ch); curl_close($ch); $status = ''; $information = explode('&', $result); $dataSize = sizeof($information); for ($i = 0; $i < $dataSize; $i++) { $info_value = explode('=', $information[$i]); if ($info_value[0] == 'enc_response') { $status = decrypt(trim($info_value[1]), $working_key); } } echo 'Status revert is: ' . $status.'<pre>'; $obj = json_decode($status); print_r($obj); ?> <?php //ADD NEW ENCRYPT Function function encrypt($plainText,$key) { $key = hextobin(md5($key)); $initVector = pack("C*", 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f); $openMode = openssl_encrypt($plainText, 'AES-128-CBC', $key, OPENSSL_RAW_DATA, $initVector); $encryptedText = bin2hex($openMode); return $encryptedText; } function decrypt($encryptedText,$key) { $key = hextobin(md5($key)); $initVector = pack("C*", 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f); $encryptedText = hextobin($encryptedText); $decryptedText = openssl_decrypt($encryptedText, 'AES-128-CBC', $key, OPENSSL_RAW_DATA, $initVector); return $decryptedText; } //*********** Padding Function ********************* function pkcs5_pad ($plainText, $blockSize) { $pad = $blockSize - (strlen($plainText) % $blockSize); return $plainText . str_repeat(chr($pad), $pad); } //********** Hexadecimal to Binary function for php 4.0 version ******** function hextobin($hexString) { $length = strlen($hexString); $binString=""; $count=0; while($count<$length) { $subString =substr($hexString,$count,2); $packedString = pack("H*",$subString); if ($count==0) { $binString=$packedString; } else { $binString.=$packedString; } $count+=2; } return $binString; } ?>
期望的响应格式
{"reference_no":"309001234567","order_no":"abc123","order_currncy":"INR","order_amt":1049.0,"order_date_time":"2020-10-20 17:14:18.42","order_bill_name":"","order_bill_address":"","order_bill_zip":"","order_bill_tel":"","order_bill_email":"","order_bill_country":"","order_ship_name":"yang","order_ship_address":"fthfyggg","order_ship_country":"India","order_ship_tel":"185"}
改造要点说明
- 配置填充:替换CCAVENUE提供的
working_key和access_code - 参数接收:从GET/POST请求中动态获取
order_no和reference_no,避免硬编码 - 请求头修正:原示例中
Content-Type设置错误,改为表单提交的application/x-www-form-urlencoded - 响应格式化:直接返回符合要求的纯JSON格式,移除冗余输出
- 错误处理:增加参数校验、CURL请求失败、响应解析失败等场景的异常处理
改造后的完整代码
<?php error_reporting(E_ALL & ~E_NOTICE); header('Content-Type: application/json'); // 1. 配置CCAVENUE密钥和访问码 $working_key = 'YOUR_WORKING_KEY'; // 替换为官方提供的密钥 $access_code = 'YOUR_ACCESS_CODE'; // 替换为官方提供的访问码 // 2. 接收请求参数(支持GET/POST) $order_no = isset($_REQUEST['order_no']) ? trim($_REQUEST['order_no']) : ''; $reference_no = isset($_REQUEST['reference_no']) ? trim($_REQUEST['reference_no']) : ''; // 参数校验 if (empty($order_no) || empty($reference_no)) { echo json_encode([ 'error' => '参数缺失', 'message' => 'order_no和reference_no为必填项' ]); exit; } // 3. 构造请求数据 $merchant_json_data = [ 'order_no' => $order_no, 'reference_no' => $reference_no ]; $merchant_data = json_encode($merchant_json_data); $encrypted_data = encrypt($merchant_data, $working_key); // 构造POST表单数据(使用http_build_query避免拼接错误) $final_data = http_build_query([ 'enc_request' => $encrypted_data, 'access_code' => $access_code, 'command' => 'orderStatusTracker', 'request_type' => 'JSON', 'response_type' => 'JSON' ]); // 4. 发起CURL请求 $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://apitest.ccavenue.com/apis/servlet/DoWebTrans"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true); // 生产环境建议开启SSL验证 curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $final_data); curl_setopt($ch, CURLOPT_HTTPHEADER, [ 'Content-Type: application/x-www-form-urlencoded' // 修正请求头 ]); $result = curl_exec($ch); // CURL错误处理 if (curl_errno($ch)) { $error_msg = curl_error($ch); curl_close($ch); echo json_encode([ 'error' => '请求失败', 'message' => $error_msg ]); exit; } curl_close($ch); // 5. 解析响应 $status = ''; $information = explode('&', $result); foreach ($information as $info) { $info_value = explode('=', $info, 2); // 限制分割次数,避免值中包含=的情况 if (isset($info_value[0]) && $info_value[0] == 'enc_response') { $status = decrypt(trim($info_value[1]), $working_key); break; } } // 解密结果校验 if (empty($status)) { echo json_encode([ 'error' => '响应解析失败', 'message' => '未获取到有效的加密响应' ]); exit; } // 6. 格式化输出指定JSON格式 $response_data = json_decode($status, true); if (json_last_error() !== JSON_ERROR_NONE) { echo json_encode([ 'error' => '响应解析失败', 'message' => 'JSON格式错误' ]); exit; } // 确保返回字段与期望格式一致(兼容官方返回可能的拼写差异) $formatted_response = [ 'reference_no' => $response_data['reference_no'] ?? '', 'order_no' => $response_data['order_no'] ?? '', 'order_currncy' => $response_data['order_currency'] ?? $response_data['order_currncy'] ?? '', 'order_amt' => isset($response_data['order_amt']) ? (float)$response_data['order_amt'] : 0.0, 'order_date_time' => $response_data['order_date_time'] ?? '', 'order_bill_name' => $response_data['order_bill_name'] ?? '', 'order_bill_address' => $response_data['order_bill_address'] ?? '', 'order_bill_zip' => $response_data['order_bill_zip'] ?? '', 'order_bill_tel' => $response_data['order_bill_tel'] ?? '', 'order_bill_email' => $response_data['order_bill_email'] ?? '', 'order_bill_country' => $response_data['order_bill_country'] ?? '', 'order_ship_name' => $response_data['order_ship_name'] ?? '', 'order_ship_address' => $response_data['order_ship_address'] ?? '', 'order_ship_country' => $response_data['order_ship_country'] ?? '', 'order_ship_tel' => $response_data['order_ship_tel'] ?? '' ]; echo json_encode($formatted_response, JSON_UNESCAPED_UNICODE); // 加密解密函数(保留官方实现) function encrypt($plainText,$key) { $key = hextobin(md5($key)); $initVector = pack("C*", 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f); $openMode = openssl_encrypt($plainText, 'AES-128-CBC', $key, OPENSSL_RAW_DATA, $initVector); $encryptedText = bin2hex($openMode); return $encryptedText; } function decrypt($encryptedText,$key) { $key = hextobin(md5($key)); $initVector = pack("C*", 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f); $encryptedText = hextobin($encryptedText); $decryptedText = openssl_decrypt($encryptedText, 'AES-128-CBC', $key, OPENSSL_RAW_DATA, $initVector); return $decryptedText; } function pkcs5_pad ($plainText, $blockSize) { $pad = $blockSize - (strlen($plainText) % $blockSize); return $plainText . str_repeat(chr($pad), $pad); } function hextobin($hexString) { $length = strlen($hexString); $binString=""; $count=0; while($count<$length) { $subString = substr($hexString,$count,2); $packedString = pack("H*",$subString); if ($count==0) { $binString=$packedString; } else { $binString.=$packedString; } $count+=2; } return $binString; } ?>
内容的提问来源于stack exchange,提问作者Mayank Sinha
相关产品推荐
相关产品推荐

