

namespace Home\Controller;

use Think\Controller;


class ShoppingController extends Controller {
    //严重说明:  上面的命名空间给引入类要换成自己的路径

    private $app_id = '';                                   //appid
    private $mch_id = '';                                //商户号
    private $makesign = '';      //支付的签名(在商户平台API安全按钮中获取)
    private $parameters = NULL;
    private $notify = 'http://自己的域名/wxpay.php'; //配置回调地址(给pays中转文件上传到根目录下面)
    private $app_secret = '';                               //微信官方获取
    public $error = 0;
    public $orderid = null;
    public $openid = '';

    public function wxPay() {
        #获取openid ID
        if ($_SESSION['openid'] == null) {

        $reannumb = $this->randomkeys(6);  //生成随机数 以后可以当做 订单号
        $pays = 1;                       //获取需要支付的价格
        $conf = $this->payconfig('Bm' . $reannumb, $pays * 100, '报名费用支付');
        if (!$conf || $conf['return_code'] == 'FAIL')
            exit("<script>alert('对不起,微信支付接口调用错误!" . $conf['return_msg'] . "');history.go(-1);</script>");
        $this->orderid = $conf['prepay_id'];
        $jsApiObj["appId"] = $conf['appid'];
        $timeStamp = time();
        $jsApiObj["timeStamp"] = "$timeStamp";
        $jsApiObj["nonceStr"] = $this->createNoncestr();
        $jsApiObj["package"] = "prepay_id=" . $conf['prepay_id'];
        $jsApiObj["signType"] = "MD5";
        $jsApiObj["paySign"] = $this->MakeSign($jsApiObj);
        $this->parameters  = json_encode($jsApiObj);
        $json = json_encode($jsApiObj);
        $this->assign('parameters', $json);  
        $this->title = "用户订单充值管理";

    protected function payconfig($no, $fee, $body) {
        $url = "";
        $data['appid'] = $this->app_id;
        $data['mch_id'] = $this->mch_id;           //商户号
        $data['device_info'] = 'WEB';
        $data['body'] = $body;
        $data['out_trade_no'] = $no;               //订单号
        $data['total_fee'] = $fee;                 //金额
        $data['spbill_create_ip'] = $_SERVER["REMOTE_ADDR"];  //ip地址
        $data['notify_url'] = $this->notify;
        $data['trade_type'] = 'JSAPI';
        $data['openid'] = $_SESSION['openid'];   //获取保存用户的openid
        $data['nonce_str'] = $this->createNoncestr();
        $data['sign'] = $this->MakeSign($data);
        $xml = $this->ToXml($data);
        $curl = curl_init(); // 启动一个CURL会话
        curl_setopt($curl, CURLOPT_URL, $url); // 要访问的地址
        curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, FALSE);
        curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, FALSE);
        curl_setopt($curl, CURLOPT_HEADER, FALSE);
        curl_setopt($curl, CURLOPT_RETURNTRANSFER, TRUE);
        curl_setopt($curl, CURLOPT_POST, TRUE); // 发送一个常规的Post请求
        curl_setopt($curl, CURLOPT_POSTFIELDS, $xml); // Post提交的数据包
        curl_setopt($curl, CURLOPT_TIMEOUT, 30); // 设置超时限制防止死循环
        $tmpInfo = curl_exec($curl); // 执行操作
        curl_close($curl); // 关闭CURL会话
        $arr = $this->FromXml($tmpInfo);
        return $arr;

     *    作用:产生随机字符串,不长于32位
    public function createNoncestr($length = 32) {
        $chars = "abcdefghijklmnopqrstuvwxyz0123456789";
        $str = "";
        for ($i = 0; $i < $length; $i++) {
            $str .= substr($chars, mt_rand(0, strlen($chars) - 1), 1);
        return $str;

     *    作用:产生随机字符串,不长于32位
    public function randomkeys($length) {
        $pattern = '1234567890123456789012345678905678901234';
        $key = null;
        for ($i = 0; $i < $length; $i++) {
            $key .= $pattern{mt_rand(0, 30)};    //生成php随机数
        return $key;

     * 将xml转为array
     * @param string $xml
     * @throws WxPayException
    public function FromXml($xml) {
        return json_decode(json_encode(simplexml_load_string($xml, 'SimpleXMLElement', LIBXML_NOCDATA)), true);

     * 输出xml字符
     * @throws WxPayException
     * */
    public function ToXml($arr) {
        $xml = "<xml>";
        foreach ($arr as $key => $val) {
            if (is_numeric($val)) {
                $xml .= "<" . $key . ">" . $val . "</" . $key . ">";
            } else {
                $xml .= "<" . $key . "><![CDATA[" . $val . "]]></" . $key . ">";
        $xml .= "</xml>";
        return $xml;

     * 生成签名
     * @return 签名,本函数不覆盖sign成员变量,如要设置签名需要调用SetSign方法赋值
    protected function MakeSign($arr) {
        $string = $this->ToUrlParams($arr);
        $string = $string . "&key=" . $this->makesign;
        $string = md5($string);
        $result = strtoupper($string);
        return $result;

     * 格式化参数格式化成url参数
    protected function ToUrlParams($arr) {
        $buff = "";
        foreach ($arr as $k => $v) {
            if ($k != "sign" && $v != "" && !is_array($v)) {
                $buff .= $k . "=" . $v . "&";

        $buff = trim($buff, "&");
        return $buff;

    #获取openid ID

    public function Wxcallback() {
        $direct = $this->get_page_url(); //当前访问URL
        //$code =Yii::app()->request->getParam('code');  //获取code码号
        $code = $_GET['code'];  //获取code码号
        if ($code == null) {
            header("Location:" . "" . $this->app_id . "&redirect_uri=" . urlencode($direct) . "&response_type=code&scope=snsapi_base&state=STATE#wechat_redirect");
        } else {
            $url = "" . $this->app_id . "&secret=" . $this->app_secret . "&code={$code}&grant_type=authorization_code";
            $res = $this->request_get($url);
            if ($res) {
                $data = json_decode($res, true);
                //Yii::app()->session["openid"] = $data['openid'];    //设置session
                $_SESSION['openid'] = $data['openid'];    //设置session
            } else {
                echo json_encode(array('status' => 0, 'msg' => '获取openid出错', 'v' => 4));


    public function get_page_url($site = false) {
        $url = (isset($_SERVER['SERVER_PORT']) && $_SERVER['SERVER_PORT'] == '443') ? 'https://' : 'http://';
        $url .= $_SERVER['HTTP_HOST'];
        if ($site)
            return $this->seldir() . '/'; //访问域名网址
        $url .= isset($_SERVER['REQUEST_URI']) ? $_SERVER['REQUEST_URI'] : urlencode($_SERVER['PHP_SELF']) . '?' . urlencode($_SERVER['QUERY_STRING']);
        return $url;

    public function seldir() {
        $baseUrl = str_replace('\\', '/', dirname($_SERVER['SCRIPT_NAME']));
        $baseUrl = empty($baseUrl) ? '/' : '/' . trim($baseUrl, '/');
        return 'http://' . $_SERVER['HTTP_HOST'] . $baseUrl;

    public function callback(){

            $xml = file_get_contents("php://input");
            $log = json_decode(json_encode(simplexml_load_string($xml, 'SimpleXMLElement', LIBXML_NOCDATA)), true);
            $id = $log['out_trade_no'];  //获取订单号
    public function request_get($url) {
        $curl = curl_init();
        curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
        curl_setopt($curl, CURLOPT_TIMEOUT, 500);
        curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
        curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, false);
        curl_setopt($curl, CURLOPT_URL, $url);
        $res = curl_exec($curl);
        return $res;




$xml = file_get_contents("php://input");

$url ='http://域名/Home/Shopping/callback';

$ch = curl_init();

curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);

curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);

curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);

curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);

curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);  //get the response as a string from curl_exec(), rather than echoing it

curl_setopt($ch, CURLOPT_URL, $url );

curl_setopt($ch, CURLOPT_POST, 1 );

curl_setopt($ch, CURLOPT_POSTFIELDS,$xml);

//取到的$info 即为拿到的script 信息

$info =     curl_exec($ch) ;

curl_close($ch);    //close the handle

echo $info; //输出



    <script type="text/javascript">
        //调用微信JS api 支付
        function jsApiCall()

            var b = {$parameters};

                        "appId": b.appId,
                        "nonceStr": b.nonceStr,
                        "package": b.package,
                        "paySign": b.paySign,
                        "signType": b.signType,
                        "timeStamp": b.timeStamp
                    function (res) {
                        if (res.err_msg == 'get_brand_wcpay_request:ok') {
                        } else {
//                           alert(JSON.stringify(res));


        function callpay() {

            if (typeof WeixinJSBridge == "undefined") {

                if (document.addEventListener) {

                    document.addEventListener('WeixinJSBridgeReady', jsApiCall, false);

                } else if (document.attachEvent) {

                    document.attachEvent('WeixinJSBridgeReady', jsApiCall);
                    document.attachEvent('onWeixinJSBridgeReady', jsApiCall);

            } else {



    <div align="center">

        <button style="width:210px; height:50px; border-radius: 15px; border:0px #FE6714 solid; cursor: pointer;  color:white;  font-size:16px;" type="button" onclick="callpay()" >立即支付</button>


