Skip to content

🐛 #4133 【微信支付】V3 应答验签增加时间戳新鲜度校验,防止重放 - #4137

Merged
binarywang merged 2 commits into
binarywang:developfrom
sisyfy-Zhang:fix/v3-response-timestamp-check
Oct 10, 2026
Merged

binarywang merged 2 commits into
binarywang:developfrom
sisyfy-Zhang:fix/v3-response-timestamp-check

Conversation

@sisyfy-Zhang

Copy link
Copy Markdown
Contributor

Fixes #4133

问题

WxPayValidator 对微信支付 V3 应答只做了密码学验签,没有校验 Wechatpay-Timestamp 的新鲜度(代码里留有 // todo: check timestamp)。签名能证明应答是微信签发的,但证明不了是"刚刚"签发的,因此一份被截获的合法应答可以在任意时间后原样重放并通过验签。微信支付 V3 签名验证规范要求商户侧校验时间戳与本地时间之差不超过 5 分钟,官方 Java SDK 也实现了这一步。

改动

  • WxPayValidator 新增时间戳容差(秒),默认 DEFAULT_TIMESTAMP_TOLERANCE_SECONDS = 300,与官方 SDK 一致。
  • 校验顺序:四个应答头齐全 → 时间戳在容差范围内 → 密码学验签。超出容差或时间戳非法的应答直接判为验签失败,并打一条 warn 日志说明原因(上层仍抛出原有的"应答的微信支付签名验证失败")。
  • 新增构造器 WxPayValidator(Verifier, long timestampToleranceSeconds)。容差传 0 或负数表示关闭时间戳校验,给本地时钟确实无法与微信保持同步的环境一个显式的口子,避免用户因此把整个 Validator 换成永远返回 true。
  • 现有的单参构造器保持不变,两处既有调用(WxPayConfig、AutoUpdateCertificatesVerifier)自动获得默认 5 分钟校验;非 JSON 应答跳过校验的既有行为不变。
  • 兼容 JDK 8。

测试

新增 WxPayValidatorTest(TestNG,已登记到 testng.xml),通过注入固定时钟覆盖:时间戳等于当前时间、恰好在容差边界、滞后 6 分钟、超前 6 分钟、非数字、缺少时间戳头、自定义容差、容差为 0 关闭校验、默认构造器行为、非 JSON 应答跳过校验。支付模块离线套件 190 个用例全部通过。

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T05:58:33.509102Z 732da3c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

时间戳差值计算存在 long 溢出边界,可能将非法时间戳判定为新鲜。

1 open finding
What changed in this PR

为微信支付 V3 应答验签增加时间戳新鲜度校验,降低重放攻击风险。

Changes:

  • 默认校验 5 分钟时间戳容差,并支持自定义或关闭。
  • 新增时间戳边界、异常值及兼容性测试。
  • 将测试注册到 TestNG 套件。
File Description
WxPayValidator.java 实现时间戳新鲜度校验。
WxPayValidatorTest.java 覆盖主要校验场景。
testng.xml 注册新增测试。

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@binarywang
binarywang merged commit 11bff83 into binarywang:develop Oct 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

【安全】WxPayValidator 未校验微信支付 V3 应答时间戳(Wechatpay-Timestamp),缺少重放攻击防护

3 participants