#include #include #include "eetsender.h" #include "eetsigner.h" #include #include #include #include #include #include #include const QString EetSender::ms_nsDef = "declare namespace eet = \"http://fs.mfcr.cz/eet/schema/v3\";\n" "declare namespace ds = \"http://www.w3.org/2000/09/xmldsig#\";\n" "declare namespace wsu = \"http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd\";\n" "declare namespace wsse = \"http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd\";\n" "declare namespace senc = \"http://schemas.xmlsoap.org/soap/encoding/\";\n" "declare namespace senv = \"http://schemas.xmlsoap.org/soap/envelope/\";\n"; EetSender::EetSender(QObject *parent) : QObject(parent) { m_signer = nullptr; m_resut = nullptr; m_checkSignature = true; m_manager = new QNetworkAccessManager(this); connect(m_manager, SIGNAL(finished(QNetworkReply*)), this, SLOT(replyFinished(QNetworkReply*))); connect(m_manager, &QNetworkAccessManager::sslErrors, [this](QNetworkReply *rep, QList errs){ emit serviceCertError(); }); } void EetSender::sendRequest(EetRequest *request) { if (m_signer == nullptr) { emit certError(); return; } request->setUuidZpravy(QUuid::createUuid()); EetTemplate tempBody(BODY_TEMPLATE); tempBody.setSigner(m_signer); QString strBody = tempBody.fillTemplate(request); QByteArray digest = m_signer->sha256HashData(strBody.toUtf8()); QMap val; val["digest"] = QString(digest.toBase64()); EetTemplate tempSignature(SIGNATURE_TEMPLATE); QString strSignature = tempSignature.fillTemplate(val); QByteArray sign = m_signer->signData(strSignature.toUtf8()); val["signature"] = QString(sign.toBase64()); val["soap:Body"] = strBody; val["certb64"] = m_signer->getCertificate(); EetTemplate tempRequest(REQUEST_TEMPLATE); QString strRequest = tempRequest.fillTemplate(val); QNetworkRequest req(QUrl("https://pg.eet.cz/eet/services/EETServiceSOAP/v3")); m_manager->post(req, strRequest.toUtf8()); QFile file("/home/pepa/Dokumenty/dev/eet/req.xml"); file.open(QIODevice::WriteOnly); file.write(strRequest.toUtf8()); } void EetSender::setupSigner(const QString &certPath, const QString &passwd) { if (m_signer != nullptr) { delete m_signer; } m_signer = new EetSigner(this); m_signer->setup(certPath, QCA::SecureArray(passwd.toUtf8())); } void EetSender::setCheckSignature(bool checkSignature) { m_checkSignature = checkSignature; } bool EetSender::checkSignature() const { return m_checkSignature; } EetResult *EetSender::resut() const { return m_resut; } bool EetSender::verifySignature(const QByteArray &repData) { QString queryString("//senv:Envelope/senv:Header/wsse:Security/ds:Signature/ds:SignedInfo"); QString signedInfo, certB64, signatureB64; QXmlQuery q; q.setFocus(QString(repData)); q.setQuery(ms_nsDef + queryString); q.evaluateTo(&signedInfo); QStringList list = signedInfo.split("\n"); signedInfo = "\n"; for (int i = 1; i < list.length(); i++) { QString line = list[i]; line = line.replace(QRegExp("^(\\s+)<([A-Za-z]+)([A-Za-z0-9-\"=/#:\\.\\ ]+)/>"), "\\1<\\2\\3>"); signedInfo += line + "\n"; } signedInfo = signedInfo.trimmed(); signedInfo = signedInfo.replace(" ", " "); queryString = "//senv:Envelope/senv:Header/wsse:Security/wsse:BinarySecurityToken/text()"; q.setQuery(ms_nsDef + queryString); q.evaluateTo(&certB64); queryString = "//senv:Envelope/senv:Header/wsse:Security/ds:Signature/ds:SignatureValue/text()"; q.setQuery(ms_nsDef + queryString); q.evaluateTo(&signatureB64); QCA::ConvertResult res; QCA::Certificate cert = QCA::Certificate::fromDER(QByteArray::fromBase64(certB64.toUtf8()), &res); if (res != QCA::ConvertGood) { emit serviceCertError(); return false; } QCA::PublicKey pubKey = cert.subjectPublicKey(); if (!pubKey.canVerify()) { emit serviceCertError(); return false; } bool signValid = pubKey.verifyMessage(QCA::MemoryRegion(signedInfo.toUtf8()), QByteArray::fromBase64(signatureB64.toUtf8()), QCA::EMSA3_SHA256); if (!signValid) { emit signInvalid(); return false; } return true; } void EetSender::replyFinished(QNetworkReply *reply) { if (reply->error() != QNetworkReply::NoError) { emit sendError(); reply->deleteLater(); return; } QByteArray repData = reply->readAll(); /*QFile file("/home/pepa/Dokumenty/dev/eet/reply.xml"); file.open(QIODevice::ReadOnly); repData = file.readAll();*/ if (m_checkSignature && !verifySignature(repData)) { return; } QXmlQuery q; q.setFocus(QString(repData)); QString result; QString queryString("//senv:Envelope/senv:Body/eet:Odpoved/eet:Hlavicka/@uuid_zpravy/data(.)"); q.setQuery(ms_nsDef + queryString); q.evaluateTo(&result); result = result.trimmed(); if (m_resut == nullptr) { m_resut = new EetResult(this); } m_resut->setUuid(QUuid(result)); queryString = "//senv:Envelope/senv:Body/eet:Odpoved/eet:Hlavicka/@dat_prij/data(.)"; q.setQuery(ms_nsDef + queryString); q.evaluateTo(&result); result = result.trimmed(); m_resut->setReciveDate(QDateTime::fromString(result)); queryString = "//senv:Envelope/senv:Body/eet:Odpoved/eet:Potvrzeni/@fik/data(.)"; q.setQuery(ms_nsDef + queryString); q.evaluateTo(&result); result = result.trimmed(); m_resut->setFik(result); QXmlResultItems items; queryString = "//senv:Envelope/senv:Body/eet:Odpoved/eet:Varovani"; q.setQuery(ms_nsDef + queryString); q.evaluateTo(&items); EetMessageList warnings; QXmlItem item = items.next(); while (!item.isNull()) { EetMessage *mesg = new EetMessage(m_resut); queryString = "./@kod_varov/data(.)"; q.setQuery(ms_nsDef + queryString); q.setFocus(item); q.evaluateTo(&result); result = result.trimmed(); mesg->setCode(result.toInt()); queryString = "./text(.)"; q.setQuery(ms_nsDef + queryString); q.setFocus(item); q.evaluateTo(&result); result = result.trimmed(); mesg->setMessage(result); warnings.append(mesg); item = items.next(); } m_resut->setWarnings(warnings); queryString = "//senv:Envelope/senv:Body/eet:Odpoved/eet:Chyba"; q.setQuery(ms_nsDef + queryString); q.evaluateTo(&items); EetMessageList errors; item = items.next(); while (!item.isNull()) { EetMessage *mesg = new EetMessage(m_resut); queryString = "./@kod/data(.)"; q.setQuery(ms_nsDef + queryString); q.setFocus(item); q.evaluateTo(&result); result = result.trimmed(); mesg->setCode(result.toInt()); queryString = "./text(.)"; q.setQuery(ms_nsDef + queryString); q.setFocus(item); q.evaluateTo(&result); result = result.trimmed(); mesg->setMessage(result); errors.append(mesg); item = items.next(); } m_resut->setErrors(errors); emit responseRecieved(m_resut); reply->deleteLater(); }