如何处理收到的HTTP标头

时间:2016-02-28 20:53:15

标签: php http-headers patreon

我的问题是如何使用从其他网站收到的php读取标题信息。 (我正在使用patreon webhooks) 文档页面说:

  

当其中一个事件发生时,我们的服务器会将HTTP POST发送到您指定的URL。此HTTP POST将包含来自JSON格式的用户操作的相关数据。它也有标题
  X-Patreon-Event: <trigger>
  X-Patreon-Signature: <message signature>
  其中消息签名是与您的client_secret

签署(使用MD5)的JSON POST正文HMAC

这是我的代码:

<?php
logData("asd");
$headers = getallheaders();
$X_Patreon_Event = $headers['X-Patreon-Event'];
$X_Patreon_Signature = $headers['X-Patreon-Signature'];
logMusic(json_decode($X_Patreon_Event));
logMusic(json_decode($X_Patreon_Signature));
function logData($str){
    $url = '/var/www/websitelog.txt';
    $current = "$str\n";
    file_put_contents($url,$current,FILE_APPEND | LOCK_EX);
}

3 个答案:

答案 0 :(得分:2)

getallheaders(自PHP 5.4.0起)将所有标题作为关联数组返回...

$headers = getallheaders();

...然后您就可以检查以获取所需的标头值

$X_Patreon_Event = $headers['X-Patreon-Event'];
$X_Patreon_Signature = $headers['X-Patreon-Signature'];

旁注:getallheaders()函数可能不可用(例如,如果您的Web服务器是nginx)。在这种情况下,您始终可以使用一小段代码重新实现该功能:Get the http headers from current request in PHP

答案 1 :(得分:2)


我有一个完整的webhooks页面使用PHP和mysqli希望这有帮助
注意**你需要php 5.6&gt;为此工作
我的实现所需的mysql数据库表

/ **

- 表格顾客的表格结构

CREATE TABLE IF NOT EXISTS patrons (
patron_key bigint(20) NOT NULL AUTO_INCREMENT COMMENT 'key to row',
patron_id tinytext NOT NULL COMMENT 'patron id',
patron_fullname tinytext NOT NULL COMMENT 'fullname',
patron_firstname tinytext NOT NULL,
patron_lastname tinytext NOT NULL,
patron_email tinytext NOT NULL,
patron_image_url tinytext NOT NULL,
patron_pledge bigint(20) NOT NULL,
patron_list tinyint(4) NOT NULL COMMENT 'include in patrons honour list',
patron_decline tinytext,
PRIMARY KEY (patron_key)
) ENGINE=InnoDB DEFAULT CHARSET=latin1 AUTO_INCREMENT=1 ;

- - 表通知的表结构

CREATE TABLE IF NOT EXISTS notifications (
notification_id bigint(20) NOT NULL AUTO_INCREMENT,
notification_type tinytext NOT NULL,
notification text NOT NULL,
notification_action int(11) NOT NULL,
notification_date tinytext NOT NULL,
notification_archived tinytext NOT NULL,
PRIMARY KEY (notification_id)
) ENGINE=InnoDB DEFAULT CHARSET=latin1 AUTO_INCREMENT=1401 ;

* /

$secret_webhook_id = "your-secret-key-here";

/** get the headers */
$headers = getallheaders();
$X_Patreon_Event = $headers['X-Patreon-Event'];
$X_Patreon_Signature = $headers['X-Patreon-Signature'];

/** get the json body */
$body = @file_get_contents("php://input");

/** get json body as array */
$patron_data = json_decode($body, true);

/** compute an md5 hash using the body and your secret key */
$signature = hash_hmac('md5', $body, $secret_webhook_id);

/** Timing attack safe string comparison */
if (hash_equals ($X_Patreon_Signature, $signature)){

/** get the data from the json array - look for errors*/
if (isset($patron_data['included']) && isset($patron_data['data'])) {
$data             = $patron_data['data'];
$declined         = $data['attributes']['declined_since'];

/** stored as a string*/
$declined         = is_null($declined) ? "":$declined;

$included         = $patron_data['included'];
$patron_id        = $included[0]['id'];
$patron_full_name = $included[0]['attributes']['full_name'];
$patron_firstname = $included[0]['attributes']['first_name'];
$patron_lastname  = $included[0]['attributes']['last_name'];
$patron_email     = $included[0]['attributes']['email'];
$patron_image_url = $included[0]['attributes']['image_url'];
$pledge           = $included[1]['attributes']['amount_cents'];

/** select event for db insert/update/delete*/
switch ($X_Patreon_Event){
    case "pledges:create":
        $sql = "INSERT INTO patrons SET patron_id  = ?, patron_fullname = ?, patron_firstname = ?, patron_lastname = ?, patron_email = ?, patron_image_url = ?, patron_pledge = ?, patron_list = 1, patron_decline = ?";
        $stmt = $conn->prepare($sql);
        $stmt->bind_param("ssssssis", $patron_id, $patron_full_name, $patron_firstname, $patron_lastname, $patron_email, $patron_image_url, $pledge, $declined);
        if (!$stmt->execute()) {
            /** your_error_routine(__LINE__, __FILE__, $sql, $stmt->error); */
        }
        break;
    case "pledges:update":
        $sql = "UPDATE patrons SET patron_fullname = ?, patron_firstname = ?, patron_lastname = ?, patron_email = ?, patron_image_url = ?, patron_pledge = ?, patron_decline = ? WHERE patron_id = ?";
        $stmt = $conn->prepare($sql);
        $stmt->bind_param("sssssiss", $patron_full_name, $patron_firstname, $patron_lastname, $patron_email, $patron_image_url, $pledge, $declined, $patron_id);
        if (!$stmt->execute()) {
            /** your_error_routine(__LINE__, __FILE__, $sql, $stmt->error); */
        }
        break;
    case "pledges:delete":
        $sql = "DELETE FROM patrons WHERE patron_id = ?";
        $stmt = $conn->prepare($sql);
        $stmt->bind_param("s", $patron_id);
        if (!$stmt->execute()) {
             /** your_error_routine(__LINE__, __FILE__, $sql, $stmt->error); */
        }
        break;
}

/** now update your own admin notifications */
$notification = "Patreon Webhook update for: $patron_full_name - X_Patreon_Event: $X_Patreon_Event";
$sql = "INSERT INTO notifications SET notification_type = 'Patreon', notification = ?, notification_date = ".time();
$stmt = $conn->prepare($sql);
$stmt->bind_param("s", $notification);
if (!$stmt->execute()) {
    /** your_error_routine(__LINE__, __FILE__, $sql, $stmt->error); */
}

}

答案 2 :(得分:1)

在你的剧本中写:

var_dump($_SERVER);

你将看到返回的变量。然后,您可以像数组一样访问它们。

正如在这里所回答的那样,getallheaders()正是你要找的。

由于它的JSON,在这些变量上使用json_decode(),请阅读有关json_decode / encode的手册。