|  | @@ -65,15 +65,15 @@ public class ExamOrderController extends BaseController {
 | 
											
												
													
														|  |          signParams.put("appId", ConfigInit.appId);
 |  |          signParams.put("appId", ConfigInit.appId);
 | 
											
												
													
														|  |          signParams.put("amount", amount);
 |  |          signParams.put("amount", amount);
 | 
											
												
													
														|  |          signParams.put("orderNo", orderNo);
 |  |          signParams.put("orderNo", orderNo);
 | 
											
												
													
														|  | -        signParams.put("notifyUrl", notifyUrl);
 |  | 
 | 
											
												
													
														|  | -        signParams.put("returnUrl", returnUrl);
 |  | 
 | 
											
												
													
														|  | 
 |  | +//        signParams.put("notifyUrl", notifyUrl);
 | 
											
												
													
														|  | 
 |  | +//        signParams.put("returnUrl", returnUrl);
 | 
											
												
													
														|  |          signParams.put("orderSubject", orderSubject);
 |  |          signParams.put("orderSubject", orderSubject);
 | 
											
												
													
														|  |          signParams.put("orderBody", orderBody);
 |  |          signParams.put("orderBody", orderBody);
 | 
											
												
													
														|  |          signParams.put("wxAppId", ConfigInit.wxAppId);
 |  |          signParams.put("wxAppId", ConfigInit.wxAppId);
 | 
											
												
													
														|  |  
 |  |  
 | 
											
												
													
														|  |          String originalStr = JSONObject.toJSONString(signParams);
 |  |          String originalStr = JSONObject.toJSONString(signParams);
 | 
											
												
													
														|  |          String newSign = DigestUtils.md5DigestAsHex(originalStr.getBytes());
 |  |          String newSign = DigestUtils.md5DigestAsHex(originalStr.getBytes());
 | 
											
												
													
														|  | -        if(sign != newSign){
 |  | 
 | 
											
												
													
														|  | 
 |  | +        if(!sign.equals(newSign)){
 | 
											
												
													
														|  |              return failed("请勿非法请求");
 |  |              return failed("请勿非法请求");
 | 
											
												
													
														|  |          }
 |  |          }
 | 
											
												
													
														|  |  
 |  |  
 |