Skip to content

语言调用示例 ​

本页展示云病毒查询引擎的服务端调用方式。示例均以 SHA-256 为例;请将示例中的密钥替换为部署环境注入的真实值,且不要把密钥交给浏览器或移动端。

cURL ​

bash
curl --get 'https://virus.api.tqxtu.com/hash_scan' \
  --data-urlencode "api_key=$VIRUS_SCAN_API_KEY" \
  --data-urlencode 'hash=40fee2a4be91d9d46cc133328ed41a3bdf9099be5084efbc95c8d0535ecee496'

Node.js ​

以下示例适用于支持全局 fetch 的 Node.js 运行时。URLSearchParams 会正确编码查询参数。

js
const endpoint = 'https://virus.api.tqxtu.com/hash_scan'

export async function scanHash(hash) {
  const apiKey = process.env.VIRUS_SCAN_API_KEY
  if (!apiKey) {
    throw new Error('VIRUS_SCAN_API_KEY is not configured')
  }

  const url = new URL(endpoint)
  url.search = new URLSearchParams({ api_key: apiKey, hash }).toString()

  const response = await fetch(url, {
    headers: { accept: 'application/json' },
    signal: AbortSignal.timeout(10_000)
  })

  if (!response.ok) {
    throw new Error(`Virus scan request failed: HTTP ${response.status}`)
  }

  const result = await response.json()
  if (result.status !== 'success' || typeof result.is_virus !== 'boolean') {
    throw new Error('Virus scan returned an unexpected response')
  }

  return result
}

const result = await scanHash('40fee2a4be91d9d46cc133328ed41a3bdf9099be5084efbc95c8d0535ecee496')
console.log(result.is_virus ? '检测到风险' : '未检出')

Python ​

python
import os
import requests

ENDPOINT = 'https://virus.api.tqxtu.com/hash_scan'

def scan_hash(file_hash: str) -> dict:
    api_key = os.environ.get('VIRUS_SCAN_API_KEY')
    if not api_key:
        raise RuntimeError('VIRUS_SCAN_API_KEY is not configured')

    response = requests.get(
        ENDPOINT,
        params={'api_key': api_key, 'hash': file_hash},
        timeout=10,
    )
    response.raise_for_status()

    result = response.json()
    if result.get('status') != 'success' or not isinstance(result.get('is_virus'), bool):
        raise RuntimeError('Virus scan returned an unexpected response')
    return result

result = scan_hash('40fee2a4be91d9d46cc133328ed41a3bdf9099be5084efbc95c8d0535ecee496')
print('检测到风险' if result['is_virus'] else '未检出')

PHP ​

php
<?php

function scanHash(string $hash): array
{
    $apiKey = getenv('VIRUS_SCAN_API_KEY');
    if (!$apiKey) {
        throw new RuntimeException('VIRUS_SCAN_API_KEY is not configured');
    }

    $url = 'https://virus.api.tqxtu.com/hash_scan?' . http_build_query([
        'api_key' => $apiKey,
        'hash' => $hash,
    ]);

    $ch = curl_init($url);
    curl_setopt_array($ch, [
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_TIMEOUT => 10,
        CURLOPT_HTTPHEADER => ['Accept: application/json'],
    ]);

    $body = curl_exec($ch);
    $status = curl_getinfo($ch, CURLINFO_RESPONSE_CODE);
    curl_close($ch);

    if ($body === false || $status < 200 || $status >= 300) {
        throw new RuntimeException("Virus scan request failed: HTTP {$status}");
    }

    $result = json_decode($body, true, 512, JSON_THROW_ON_ERROR);
    if (($result['status'] ?? null) !== 'success' || !is_bool($result['is_virus'] ?? null)) {
        throw new RuntimeException('Virus scan returned an unexpected response');
    }

    return $result;
}

文件哈希计算示例 ​

查询接口只接收哈希。以下 Node.js 片段以流式方式计算文件 SHA-256,适合在上传服务或后台任务中使用:

js
import { createHash } from 'node:crypto'
import { createReadStream } from 'node:fs'

export function sha256File(filePath) {
  return new Promise((resolve, reject) => {
    const hash = createHash('sha256')
    const stream = createReadStream(filePath)

    stream.on('error', reject)
    stream.on('data', chunk => hash.update(chunk))
    stream.on('end', () => resolve(hash.digest('hex')))
  })
}

前端接入边界 ​

不要从浏览器直接调用该接口,因为查询参数中包含 api_key。正确方式是:浏览器将文件或哈希提交给自己的后端;后端负责计算或校验哈希、调用云病毒查询引擎,并只向前端返回业务允许展示的风险状态。

重试策略 ​

仅在网络临时失败、超时或服务端错误等可恢复异常时进行有限重试,并使用指数退避。对于接口正常返回但 status 非 success、响应结构异常或文件命中风险的情况,不应盲目重试,应记录并转入相应的业务处置流程。

更多字段和判定含义请参考 云病毒查询引擎概览。