支付相关

支付宝支付介绍

# 线上支付
    -支付宝支付
    -微信支付:网页版
    -云闪付的支付
# 用户把钱打到第三方平台(支付宝,微信)商家账户中----》提现提出来---》手续费
# 必须是商户:企业,有营业执照才能申请支付宝,微信的支付接入
# 用的支付宝的沙箱环境:https://openhome.alipay.com/platform/appDaily.htm?tab=info

# 原来支付宝没有提供python的sdk,第三方有人基于api接口封装了一个sdk
#现在支付宝提供了python的sdk了
# 目前还是用第三方的sdk:https://github.com/fzlee/alipay

# 对称加密和非堆成

# 使用支付宝支付:加密是非对称加密---》支付宝官方提供了工具(https://opendocs.alipay.com/common/02kipl)--》下载用
    -公钥:配置在支付宝官方网站上----》生成支付宝公钥---》拿着用
    -私钥:拿着用
from alipay import AliPay

app_private_key_string = open("./pri").read()
alipay_public_key_string = open("./pub").read()
alipay = AliPay(
    appid="2016092000554611",
    app_notify_url=None,  # 默认回调 url
    app_private_key_string=app_private_key_string,
    # 支付宝的公钥,验证支付宝回传消息使用,不是你自己的公钥,
    alipay_public_key_string=alipay_public_key_string,
    # sign_type="RSA2",  # RSA 或者 RSA2
    debug=True,  # 默认 False
)
# 电脑网站支付,需要跳转到:https://openapi.alipay.com/gateway.do? + order_string
res=alipay.api_alipay_trade_page_pay(
    out_trade_no='1000101',
    total_amount=float(999),  # 只有生成支付宝链接时,不能用Decimal
    subject='充气球',
    return_url='http://127.0.0.1:8000',
    notify_url='http://127.0.0.1:8000',
)

gataway = 'https://openapi.alipaydev.com/gateway.do?'
print(gataway+res)

支付宝支付二次封装

ipay  #包名
    -pem  #存放公钥私钥
    alipay_public_key.pem
    app_private_key.pem
    __init__.py 
    pay.py   #生成一个对象
    settings.py #配置文件

init.py

from .pay import alipay
from .settings import GATEWAY

pay.py

from alipay import AliPay

from . import settings

alipay = AliPay(
    appid=settings.APP_ID,
    app_notify_url=None,  # 默认回调 url
    app_private_key_string=settings.APP_PRIVATE_KEY_STRING,
    # 支付宝的公钥,验证支付宝回传消息使用,不是你自己的公钥,
    alipay_public_key_string=settings.ALIPAY_PUBLIC_KEY_STRING,
    sign_type=settings.SIGN,  # RSA 或者 RSA2
    debug=settings.DEBUG,  # 默认 False
)

settings.py

import os

# 应用私钥
APP_PRIVATE_KEY_STRING = open(os.path.join(os.path.dirname(os.path.abspath(__file__)), 'pem', 'app_private_key.pem')).read()

# 支付宝公钥
ALIPAY_PUBLIC_KEY_STRING = open(os.path.join(os.path.dirname(os.path.abspath(__file__)), 'pem', 'alipay_public_key.pem')).read()

# 应用ID
APP_ID = '2016092000554611'

# 加密方式
SIGN = 'RSA2'

# 是否是支付宝测试环境(沙箱环境),如果采用真是支付宝环境,配置False
DEBUG = True

# 支付网关
GATEWAY = 'https://openapi.alipaydev.com/gateway.do?' if DEBUG else 'https://openapi.alipay.com/gateway.do?'

订单相关表设计

# 订单表
# 订单详情表  (一个订单有多个订单详情)
from django.db import models
from user.models import User
from course.models import Course
class Order(models.Model):
    """订单模型"""
    status_choices = (
        (0, '未支付'),
        (1, '已支付'),
        (2, '已取消'),
        (3, '超时取消'),
    )
    pay_choices = (
        (1, '支付宝'),
        (2, '微信支付'),
    )
    subject = models.CharField(max_length=150, verbose_name="订单标题")
    total_amount = models.DecimalField(max_digits=10, decimal_places=2, verbose_name="订单总价", default=0)
    # 咱们生成的订单号,唯一,后期改订单状态需要使用这个号
    out_trade_no = models.CharField(max_length=64, verbose_name="订单号", unique=True)
    # 支付宝有个流水号
    trade_no = models.CharField(max_length=64, null=True, verbose_name="流水号")
    #订单状态
    order_status = models.SmallIntegerField(choices=status_choices, default=0, verbose_name="订单状态")
    pay_type = models.SmallIntegerField(choices=pay_choices, default=1, verbose_name="支付方式")
    pay_time = models.DateTimeField(null=True, verbose_name="支付时间")
    #  db_constraint=False  不建立外键
    user = models.ForeignKey(User, related_name='order_user', on_delete=models.DO_NOTHING, db_constraint=False, verbose_name="下单用户")
    created_time = models.DateTimeField(auto_now_add=True, verbose_name='创建时间')

    class Meta:
        db_table = "luffy_order"
        verbose_name = "订单记录"
        verbose_name_plural = "订单记录"

    def __str__(self):
        return "%s - ¥%s" % (self.subject, self.total_amount)

    @property
    def courses(self):
        data_list = []
        for item in self.order_courses.all():
            data_list.append({
                "id": item.id,
                "course_name": item.course.name,
                "real_price": item.real_price,
            })
        return data_list


class OrderDetail(models.Model):
    """订单详情"""
    order = models.ForeignKey(Order, related_name='order_courses', on_delete=models.CASCADE, db_constraint=False, verbose_name="订单")
    course = models.ForeignKey(Course, related_name='course_orders', on_delete=models.CASCADE, db_constraint=False, verbose_name="课程")
    price = models.DecimalField(max_digits=6, decimal_places=2, verbose_name="课程原价")
    real_price = models.DecimalField(max_digits=6, decimal_places=2, verbose_name="课程实价")

    class Meta:
        db_table = "luffy_order_detail"
        verbose_name = "订单详情"
        verbose_name_plural = "订单详情"

    def __str__(self):
        try:
            return "%s的订单:%s" % (self.course.name, self.order.out_trade_no)
        except:
            return super().__str__()

生成订单接口

# 下单---》用户要登录---》认证类(自己写,使用内置的:认证类,权限类)
# 前端携带数据发送post请求到后端----》生成订单(待支付状态),生成支付链接---》把支付链接返回给前端---》重定向到支付链接(支付宝地址)--->等待用户支付
# 前端提交的数据格式:
        {courses:[1,2],total_amount:'99',pay_type:1,subject:很多课程}

路由

from rest_framework.routers import SimpleRouter
from . import views

router = SimpleRouter()
# 127.0.0.1:8000/api/v1/order/pay
router.register('pay', views.OrderView, 'pay')

urlpatterns = [

]
urlpatterns += router.urls

视图类

from django.shortcuts import render, HttpResponse, redirect

# Create your views here.
import uuid
from libs.ipay import alipay, GATEWAY

# def pay(request):
#     price = 1999
#     subject = '气球'
#     order_id = str(uuid.uuid4())
#     res = alipay.api_alipay_trade_page_pay(
#         out_trade_no=order_id,
#         total_amount=float(price),  # 只有生成支付宝链接时,不能用Decimal
#         subject=subject,
#         return_url='http://127.0.0.1:8000',
#         notify_url='http://127.0.0.1:8000',
#     )
#     pay_url = GATEWAY + res
#     return redirect(pay_url)


from rest_framework.viewsets import GenericViewSet
from rest_framework.mixins import CreateModelMixin
from .models import Order
from .serializer import OrderSerializer
from utils.response import APIResponse
from rest_framework_jwt.authentication import JSONWebTokenAuthentication
from rest_framework.permissions import IsAuthenticated
class OrderView(GenericViewSet, CreateModelMixin):
    queryset = Order.objects.all()
    serializer_class = OrderSerializer
    authentication_classes = [JSONWebTokenAuthentication,]
    permission_classes = [IsAuthenticated,]

    def create(self, request, *args, **kwargs):
        serializer = self.get_serializer(data=request.data, context={'request': request})
        serializer.is_valid(raise_exception=True)
        self.perform_create(serializer)
        pay_url = serializer.context.get('pay_url')
        return APIResponse(pay_url=pay_url)

序列化类

from rest_framework import serializers
from .models import Order, OrderDetail
from course.models import Course
from rest_framework.exceptions import APIException
import uuid
from libs.ipay import alipay, GATEWAY
from django.conf import settings


class OrderSerializer(serializers.ModelSerializer):
    # 不是表的字段要重写
    # courses=serializers.ListSerializer(required= True,write_only=True)
    # 更高级的用法--->[2,3,]--->[id为2的课程对象,id为3的课程对象]  一定要加many=True
    # courses = serializers.PrimaryKeyRelatedField(queryset=Course.objects.all(), many=True,required=True, write_only=True)
    courses = serializers.PrimaryKeyRelatedField(queryset=Course.objects.all(), write_only=True, many=True)
    class Meta:
        model = Order
        fields = ['courses', 'total_amount', 'pay_type', 'subject']
        extra_kwargs = {
            'total_amount': {
                'required': True,
                'write_only': True
            },
            'pay_type': {
                'required': True,
                'write_only': True
            },
            'subject': {
                'required': True,
                'write_only': True
            },
        }

    def _check_total_amount(self, attrs):
        total_amount = float(attrs.get('total_amount'))
        # 取出每个课程价格加到一起和这个数字做比较
        course_list = attrs.get('courses')
        new_total_amount = 0
        for course in course_list:
            new_total_amount += course.price
        if not new_total_amount == total_amount:
            raise APIException(detail='传入的价格不合法')
        else:
            return new_total_amount

    def _get_out_trade_no(self):
        return str(uuid.uuid4())  # 全局唯一,分布式id的生成方案:雪花算法,美团leaf算法

    def _get_user(self):
        return self.context.get('request').user

    def _get_pay_url(self, out_trade_no, total_amount, subject):
        # 生成pay_url,放入到context中
        res = alipay.api_alipay_trade_page_pay(
            out_trade_no=out_trade_no,
            total_amount=float(total_amount),  # 只有生成支付宝链接时,不能用Decimal
            subject=subject,
            return_url=settings.RETURN_URL,
            notify_url=settings.NOTIFY_URL,
        )
        pay_url = GATEWAY + res
        self.context['pay_url'] = pay_url

    def _before_create(self, attrs, user, out_trade_no):
        # attrs中只有:'courses', 'total_amount', 'pay_type','subject'
        attrs['out_trade_no'] = out_trade_no
        attrs['user'] = user

    def validate(self, attrs):
        # 1)订单总价校验
        total_amount = self._check_total_amount(attrs)
        # 2)生成订单号
        out_trade_no = self._get_out_trade_no()
        # 3)支付用户:request.user
        user = self._get_user()
        # 4)支付链接生成
        self._get_pay_url(out_trade_no, total_amount, attrs.get('subject'))
        # 5)入库(两个表)的信息准备
        self._before_create(attrs, user, out_trade_no)

        # 代表该校验方法通过,进入入库操作
        return attrs

    def create(self, validated_data):
        # attrs中只有:'courses', 'total_amount', 'pay_type','subject',out_trade_no,user
        course_list = validated_data.pop('courses')
        order = Order.objects.create(**validated_data)
        for course in course_list:
            OrderDetail.objects.create(order=order, course=course, price=course.price, real_price=course.price)

        return order

支付成功后端回调接口

# 支付宝:get回调,调前端---》已经写好了---->发送ajax请求,给咱们后端,做一个二次校验(校验订单是否支付)----》后端配合一个get接口,查询订单是否支付
# 支付宝:post回调,调后端---》后端需要配合一个post接口,接受支付宝的post回调,修改订单状态


# 写在一个视图类中-----》支付宝的post回调,我们的视图类能有登录认证吗?---》没有认证,我们信得过吗?验证签名(第三方支付宝sdk提供了,调它方案验证即可)----》修改订单状态
class PaySuccessView(ViewSet):
    authentication_classes = []
    permission_classes = []

    # 给前端做二次校验用
    def list(self, resquest):
        out_trade_no = resquest.query_params.get('out_trade_no')
        order = Order.objects.filter(out_trade_no=out_trade_no, order_status=1).first()
        if order:
            return APIResponse()
        else:
            return APIResponse(code=101, msg='暂时还没收到你的付款')

    # 给支付宝用的--->必须把项目部署在公网上才能回调成功
    def create(self, request):
        try:
            # post提交的数据(支付宝回调格式:urlencoded,QueryDic)
            #
            # from django.http.request import QueryDict
            #
            # print(type(request.data))
            # 把QueryDic对象转成真正的dict对象,就可以修改,pop
            result_data = request.data.dict()
            #我们的订单号
            out_trade_no = result_data.get('out_trade_no')
            #支付宝的签名
            signature = result_data.pop('sign')
            from libs.ipay import alipay
            result = alipay.verify(result_data, signature)
            if result and result_data["trade_status"] in ("TRADE_SUCCESS", "TRADE_FINISHED"):
                # 完成订单修改:订单状态、流水号、支付时间
                Order.objects.filter(out_trade_no=out_trade_no).update(order_status=1)
                # 完成日志记录
                logger.warning('%s订单支付成功' % out_trade_no)
                # 支付宝要的格式就这个格式
                return Response('success')
            else:
                logger.error('%s订单支付失败' % out_trade_no)
        except:
            pass
        return Response('failed')

内网穿透

# 把自己内网的项目,可以被外网访问

https://zhuanlan.zhihu.com/p/370483324
posted @ 2022-07-31 14:31  thrombus  阅读(28)  评论(0编辑  收藏  举报