Files
coruna-lab/app/Http/Middleware/DecryptXxbbBody.php
T
2026-08-13 06:30:07 +08:00

106 lines
3.5 KiB
PHP

<?php
namespace App\Http\Middleware;
use App\Services\CorunaCrypto;
use App\Services\IngestService;
use Closure;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
/**
* xxbb native reporting: same AES envelope as lab, header is x-ts,
* session key is hardcoded Ek8pl31K2yeHgQwy.
*/
class DecryptXxbbBody
{
public static function crypto(): CorunaCrypto
{
return app('xxbb.crypto');
}
public function handle(Request $request, Closure $next): Response
{
$crypto = self::crypto();
$headers = [];
foreach (['x-ts', 'x-hash', 'sdkv', 'ver', 'accept', 'content-type', 'user-agent'] as $h) {
if ($request->headers->has($h)) {
$headers[$h] = $request->headers->get($h);
}
}
$raw = $request->getContent();
$timestamp = (string) $request->header('x-ts', '');
$payload = null;
$decryptOk = false;
$error = null;
$deviceKey = null;
$isMultipart = str_contains((string) $request->header('content-type'), 'multipart/');
$path = '/'.ltrim($request->path(), '/');
if ($request->isMethod('GET') || $request->isMethod('HEAD')) {
$decryptOk = true;
} elseif ($isMultipart) {
$payload = [
'form' => $request->except(['file']),
'has_file' => $request->hasFile('file'),
];
$decryptOk = true;
$deviceKey = $request->input('d') ?: $request->input('f');
} elseif ($raw !== '' && $timestamp !== '') {
try {
$payload = $crypto->decryptJsonBody($raw, $timestamp);
$decryptOk = true;
} catch (\Throwable $e) {
$error = $e->getMessage();
}
} elseif ($raw === '') {
$decryptOk = true;
} else {
$error = 'missing x-ts or body';
}
if (is_array($payload)) {
foreach (['d', 'f'] as $k) {
if (! empty($payload[$k]) && is_string($payload[$k])) {
$deviceKey = $payload[$k];
break;
}
}
if (isset($payload['form']) && is_array($payload['form']) && ($deviceKey === null || $deviceKey === '')) {
foreach (['d', 'f'] as $k) {
if (! empty($payload['form'][$k]) && is_string($payload['form'][$k])) {
$deviceKey = $payload['form'][$k];
break;
}
}
}
}
if (is_string($deviceKey) && $deviceKey !== '') {
$deviceKey = IngestService::normalizeDeviceKey(substr($deviceKey, 0, 64));
}
create_log([
'dir' => 'in',
'campaign' => 'xxbb',
'method' => $request->method(),
'path' => $path,
'ip' => $request->ip(),
'device_key' => $deviceKey ? substr((string) $deviceKey, 0, 64) : null,
'timestamp_hdr' => $timestamp ?: null,
'headers' => $headers,
'payload' => is_array($payload) || $payload === null ? $payload : ['value' => $payload],
'decrypt_ok' => $decryptOk,
'error' => $error,
], 'c2');
$request->attributes->set('coruna_payload', $payload);
$request->attributes->set('coruna_decrypt_ok', $decryptOk);
$request->attributes->set('coruna_device_key', $deviceKey);
$request->attributes->set('xxbb_ts', $timestamp);
return $next($request);
}
}