Repository navigation
🐛 #4133 【微信支付】V3 应答验签增加时间戳新鲜度校验,防止重放 - #4137
Merged
binarywang merged 2 commits intoOct 10, 2026
Merged
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
🟡 Changes recommended
时间戳差值计算存在 long 溢出边界,可能将非法时间戳判定为新鲜。
1 open finding
Long.MIN_VALUE时间戳绕过时效校验 · New
What changed in this PR
为微信支付 V3 应答验签增加时间戳新鲜度校验,降低重放攻击风险。
Changes:
- 默认校验 5 分钟时间戳容差,并支持自定义或关闭。
- 新增时间戳边界、异常值及兼容性测试。
- 将测试注册到 TestNG 套件。
| File | Description |
|---|---|
WxPayValidator.java |
实现时间戳新鲜度校验。 |
WxPayValidatorTest.java |
覆盖主要校验场景。 |
testng.xml |
注册新增测试。 |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Fixes #4133
问题
WxPayValidator对微信支付 V3 应答只做了密码学验签,没有校验Wechatpay-Timestamp的新鲜度(代码里留有// todo: check timestamp)。签名能证明应答是微信签发的,但证明不了是"刚刚"签发的,因此一份被截获的合法应答可以在任意时间后原样重放并通过验签。微信支付 V3 签名验证规范要求商户侧校验时间戳与本地时间之差不超过 5 分钟,官方 Java SDK 也实现了这一步。改动
WxPayValidator新增时间戳容差(秒),默认DEFAULT_TIMESTAMP_TOLERANCE_SECONDS = 300,与官方 SDK 一致。WxPayValidator(Verifier, long timestampToleranceSeconds)。容差传 0 或负数表示关闭时间戳校验,给本地时钟确实无法与微信保持同步的环境一个显式的口子,避免用户因此把整个 Validator 换成永远返回 true。WxPayConfig、AutoUpdateCertificatesVerifier)自动获得默认 5 分钟校验;非 JSON 应答跳过校验的既有行为不变。测试
新增
WxPayValidatorTest(TestNG,已登记到testng.xml),通过注入固定时钟覆盖:时间戳等于当前时间、恰好在容差边界、滞后 6 分钟、超前 6 分钟、非数字、缺少时间戳头、自定义容差、容差为 0 关闭校验、默认构造器行为、非 JSON 应答跳过校验。支付模块离线套件 190 个用例全部通过。