字典是有序的,而字典键值对对应的地址存储是一个哈希表映射,是无序的。说字典是无序的显然是错误。
如果我们需要一个签名来验证客户端或服务端的请求是否是伪造的。签名的产生规则是按照传给对方的参数顺序进行拼接并进行MD5编码。而客户端传给服务的参数都是通过给AFNetworking传递一个字典,由AFNetworking来进行参数的拼接。那么我们如何保证传递给服务端的参数顺序和我们拼接参数的顺序一致呢?这就需要对传递的参数字典进行排序。
尝试直接采用字典的allKeys和paramsDic访问字典的键值对字典进行直接拼接,很不幸,服务端签名验证失败。
+ (NSString *)getEncodeKeyWithParamsDic:(NSMutableDictionary *)paramsDic { if((!paramsDic) || ![paramsDic isKindOfClass:[NSDictionary class]]) { return @""; } // NSMutableDictionary *tempDic = [NSMutableDictionary dictionary]; // for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) // { // [tempDic setValue:paramsDic.allKeys[i] forKey:paramsDic.allValues[i]]; // } [paramsDic removeAllObjects]; for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) { [paramsDic setValue:paramsDic.allKeys[i] forKey:paramsDic.allValues[i]]; } NSString *sign = @""; for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) { if(sign.length == 0) { sign = [NSString stringWithFormat:@"%@=%@", paramsDic.allKeys[i], getisBITSingleObjectNotNilString(paramsDic.allValues[i])]; } else { sign = [NSString stringWithFormat:@"%@&%@=%@", sign, paramsDic.allKeys[i], getisBITSingleObjectNotNilString(paramsDic.allValues[i])]; } } NSLog(@"paramsDic:%@ ;sign:%@", paramsDic, sign); sign = [NSString stringWithFormat:@"%@", sign]; NSLog(@"paramsDic:%@ ;sign:%@ ; result:%@",paramsDic, sign, [self commonMd5:sign]); return [self commonMd5:sign]; }
接着尝试采用按照字典的allKeys顺序重新生成paramsDic字典然后按照访问字典的键值对字典进行拼接,很不幸,服务端签名验证失败。单步调试发现paramsDic字典顺序和allKeys字典的顺序相反。然后按照排序后字典的allKeys反顺序拼接,服务端签名失败。
+ (NSString *)getEncodeKeyWithParamsDic:(NSMutableDictionary *)paramsDic { if((!paramsDic) || ![paramsDic isKindOfClass:[NSDictionary class]]) { return @""; } NSMutableDictionary *tempDic = [NSMutableDictionary dictionary]; for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) { [tempDic setValue:paramsDic.allKeys[i] forKey:paramsDic.allValues[i]]; } [paramsDic removeAllObjects]; for(NSUInteger i = 0; i < tempDic.allKeys.count; i++) { [paramsDic setValue:tempDic.allKeys[i] forKey:tempDic.allValues[i]]; } NSString *sign = @""; for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) { if(sign.length == 0) { sign = [NSString stringWithFormat:@"%@=%@", paramsDic.allKeys[i], getisBITSingleObjectNotNilString(paramsDic.allValues[i])]; } else { sign = [NSString stringWithFormat:@"%@&%@=%@", sign, paramsDic.allKeys[i], getisBITSingleObjectNotNilString(paramsDic.allValues[i])]; } } // NSString *sign = @""; // sign = [NSString stringWithFormat:@"%@", [self stringWithDict:paramsDic]]; NSLog(@"paramsDic:%@ ;sign:%@", paramsDic, sign); sign = [NSString stringWithFormat:@"%@", sign]; NSLog(@"paramsDic:%@ ;sign:%@ ; result:%@",paramsDic, sign, [self commonMd5:sign]); return [self commonMd5:sign]; }
我十分困惑,我排序仍旧不行,是否是字典的键值对的顺序是无序的呢?感觉它应该是有顺序,必定它是按照顺序加入的。我gan后对字典进行递归排序,然后进行键值拼接,测试签名OK。
对字典进行排序算法代码:
+(NSString*)stringWithDict:(NSDictionary*)dict{ NSArray*keys = [dict allKeys]; NSArray*sortedArray = [keys sortedArrayUsingComparator:^NSComparisonResult(id obj1,id obj2) { return[obj1 compare:obj2 options:NSNumericSearch];//正序 }]; NSString*str =@""; for(NSString*categoryId in sortedArray) { id value = [dict objectForKey:categoryId]; if([value isKindOfClass:[NSDictionary class]]) { value = [self stringWithDict:value]; } if([str length] !=0) { str = [str stringByAppendingString:@"&"]; } str = [str stringByAppendingFormat:@"%@=%@",categoryId,value]; } NSLog(@"str:%@",str); return str; }
实际使用的代码:
+ (NSString *)getEncodeKeyWithParamsDic:(NSMutableDictionary *)paramsDic { if((!paramsDic) || ![paramsDic isKindOfClass:[NSDictionary class]]) { return @""; } // NSMutableDictionary *tempDic = [NSMutableDictionary dictionary]; // for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) // { // [tempDic setValue:paramsDic.allKeys[i] forKey:paramsDic.allValues[i]]; // } // [paramsDic removeAllObjects]; // for(NSUInteger i = 0; i < tempDic.allKeys.count; i++) // { // [paramsDic setValue:tempDic.allKeys[i] forKey:tempDic.allValues[i]]; // } // NSString *sign = @""; // for(NSUInteger i = 0; i < paramsDic.allKeys.count; i++) // { // if(sign.length == 0) // { // sign = [NSString stringWithFormat:@"%@=%@", paramsDic.allKeys[i], getisBITSingleObjectNotNilString(paramsDic.allValues[i])]; // } // else // { // sign = [NSString stringWithFormat:@"%@&%@=%@", sign, paramsDic.allKeys[i], getisBITSingleObjectNotNilString(paramsDic.allValues[i])]; // } // } NSString *sign = @""; sign = [NSString stringWithFormat:@"%@", [self stringWithDict:paramsDic]]; NSLog(@"paramsDic:%@ ;sign:%@", paramsDic, sign); sign = [NSString stringWithFormat:@"%@", sign]; NSLog(@"paramsDic:%@ ;sign:%@ ; result:%@",paramsDic, sign, [self commonMd5:sign]); return [self commonMd5:sign]; }