/* Processed by ecpg (15.18 (Debian 15.18-0+deb12u1)) */ /* These include files are added by the preprocessor */ #include #include #include /* End of automatic include section */ #line 1 "app/online/mg_ol_0021.pgc" /* @tier easy @module mg @transform msg-gateway-online */ /* * mg_ol_0021.pgc - 전문게이트웨이 카드번호 마스킹 서비스 (MG_OL_0021) [tier=easy] * * PCI-DSS 노출규칙에 따라 카드번호(PAN)를 앞 6자리(BIN)와 뒤 4자리만 * 노출하고 중간 자릿수를 '*' 로 마스킹한다. 12자리 미만 등 마스킹 불가 * 길이는 전량 마스킹(fail-safe)한다. 마스킹 결과를 전문 카드필드 규격 * (16)으로 정렬해 MASKED 로 반환한다. */ #include #include #include "txcore.h" #include "txcore_dbio.h" #include "acq_util.h" #include "mg_core.h" #line 1 "/usr/include/postgresql/sqlca.h" #ifndef POSTGRES_SQLCA_H #define POSTGRES_SQLCA_H #ifndef PGDLLIMPORT #if defined(WIN32) || defined(__CYGWIN__) #define PGDLLIMPORT __declspec (dllimport) #else #define PGDLLIMPORT #endif /* __CYGWIN__ */ #endif /* PGDLLIMPORT */ #define SQLERRMC_LEN 150 #ifdef __cplusplus extern "C" { #endif struct sqlca_t { char sqlcaid[8]; long sqlabc; long sqlcode; struct { int sqlerrml; char sqlerrmc[SQLERRMC_LEN]; } sqlerrm; char sqlerrp[8]; long sqlerrd[6]; /* Element 0: empty */ /* 1: OID of processed tuple if applicable */ /* 2: number of rows processed */ /* after an INSERT, UPDATE or */ /* DELETE statement */ /* 3: empty */ /* 4: empty */ /* 5: empty */ char sqlwarn[8]; /* Element 0: set to 'W' if at least one other is 'W' */ /* 1: if 'W' at least one character string */ /* value was truncated when it was */ /* stored into a host variable. */ /* * 2: if 'W' a (hopefully) non-fatal notice occurred */ /* 3: empty */ /* 4: empty */ /* 5: empty */ /* 6: empty */ /* 7: empty */ char sqlstate[5]; }; struct sqlca_t *ECPGget_sqlca(void); #ifndef POSTGRES_ECPG_INTERNAL #define sqlca (*ECPGget_sqlca()) #endif #ifdef __cplusplus } #endif #endif #line 18 "app/online/mg_ol_0021.pgc" #define PAN_HEAD 6 /* 앞 노출 자릿수 (BIN) */ #define PAN_TAIL 4 /* 뒤 노출 자릿수 */ TX_SERVICE(MG_OL_0021, ctx) { char card[24]; char masked[24]; int len; int i; tx_log(TX_LOG_INFO, "[MG_OL_0021] 카드번호 마스킹 서비스 진입"); if (tx_buf_get(ctx->in, "CARDNO", card, sizeof(card)) != TX_OK || card[0] == '\0') { tx_log(TX_LOG_ERROR, "[MG_OL_0021] 카드번호(CARDNO) 누락"); tx_return(ctx, TX_EINVAL, ctx->out); return; } len = (int)strlen(card); /* 카드번호는 숫자만 허용 (구분자 포함시 검증 실패) */ for (i = 0; i < len; i++) { if (card[i] < '0' || card[i] > '9') { tx_log(TX_LOG_WARN, "[MG_OL_0021] 카드번호 형식 오류 len=%d", len); tx_buf_reset(ctx->out); tx_buf_sets(ctx->out, "RESPCODE", RESP_INVALID); tx_return(ctx, TX_FAIL, ctx->out); return; } } memset(masked, 0, sizeof(masked)); if (len < PAN_HEAD + PAN_TAIL + 1) { /* 노출규칙 적용 불가 → 전량 마스킹(fail-safe) */ for (i = 0; i < len; i++) masked[i] = '*'; tx_log(TX_LOG_WARN, "[MG_OL_0021] 짧은 PAN 전량마스킹 len=%d", len); } else { for (i = 0; i < len; i++) { if (i < PAN_HEAD || i >= len - PAN_TAIL) masked[i] = card[i]; /* 앞6/뒤4 노출 */ else masked[i] = '*'; /* 중간 마스킹 */ } } tx_buf_reset(ctx->out); tx_buf_sets(ctx->out, "RESPCODE", RESP_OK); tx_buf_sets(ctx->out, "MASKED", masked); tx_buf_setlong(ctx->out, "PANLEN", (long)len); /* 마스킹 이력(mg_mask_log)을 임베디드 SQL 로 적재 (원본 PAN 은 저장하지 않음) */ { /* exec sql begin declare section */ #line 75 "app/online/mg_ol_0021.pgc" char h_mk_masked [ 24 ] ; #line 76 "app/online/mg_ol_0021.pgc" long h_mk_len ; /* exec sql end declare section */ #line 77 "app/online/mg_ol_0021.pgc" strncpy(h_mk_masked, masked, sizeof(h_mk_masked) - 1); h_mk_masked[sizeof(h_mk_masked) - 1] = '\0'; h_mk_len = (long)len; if (tx_begin() == TX_OK) { { ECPGdo(__LINE__, 0, 1, NULL, 0, ECPGst_normal, "insert into mg_mask_log ( masked_pan , pan_len ) values ( $1 , $2 )", ECPGt_char,(h_mk_masked),(long)24,(long)1,(24)*sizeof(char), ECPGt_NO_INDICATOR, NULL , 0L, 0L, 0L, ECPGt_long,&(h_mk_len),(long)1,(long)1,sizeof(long), ECPGt_NO_INDICATOR, NULL , 0L, 0L, 0L, ECPGt_EOIT, ECPGt_EORT);} #line 86 "app/online/mg_ol_0021.pgc" if (sqlca.sqlcode != TX_SQL_OK) { TX_DBIO_LOG_ERR("INSERT mg_mask_log"); tx_abort(); } else { tx_commit(); } } } tx_log(TX_LOG_INFO, "[MG_OL_0021] 마스킹 완료 len=%d masked=%s", len, masked); tx_return(ctx, TX_OK, ctx->out); }