mirror of
https://github.com/jackwener/wx-cli.git
synced 2026-10-08 07:55:46 +00:00
feat(attachment): wire wx attachments / wx extract end-to-end
把 V1 (legacy XOR + V1 fixed-AES) + 平台相关 V2 (macOS / Windows) image 解
密能力一路接到 CLI:
- ipc: 新增 Attachments / Extract 两个 Request variant
- daemon/server: dispatch 路由到 query::q_attachments / q_extract
- daemon/cache: DbCache::db_dir() 公开,让 resolver 推 wxchat_base
- daemon/query: q_attachments 走 Msg_<chat> 表按 (local_type & 0xFFFFFFFF)
IN (...) 过滤、按 ts DESC 全局排序后分页,返回不透明 attachment_id;
q_extract 解码 attachment_id → 查 message_resource.db → 找本地 .dat →
按 magic 分发 v1/v2 解码 → 写盘。bridge 用 ImageKeyMaterial.{aes_key,
xor_key}(codex 实测真实账号 xor_key=0xa2,不能硬编码 0x88)
- cli: 新增 wx attachments / wx extract 两个子命令,flag 风格与现有
history / biz-articles 对齐
- README + SKILL: 加附件提取章节,含三档解码档位与 V2 image key 派生说明
This commit is contained in:
@@ -242,6 +242,34 @@ wx biz-articles --since 2026-05-10 --json | jq '.[].url'
|
||||
|
||||
每条返回的字段:`account` / `account_username`(`gh_*`)/ `title` / `url`(`mp.weixin.qq.com` 链接)/ `digest` / `cover_url` / `time` + `timestamp`(文章发布时间)/ `recv_time_str` + `recv_time`(微信接收推送的时间)。多图文推送会展开为多行。
|
||||
|
||||
### 附件提取(图片 / 视频 / 文件 / 语音)
|
||||
|
||||
聊天里的图片/视频/文件本体在 `xwechat_files/<wxid>/msg/attach/...` 下加密存储(`.dat`),需要按消息所在 `message_resource.db` 的 md5 + 平台相关 image key 才能解码。两步走:
|
||||
|
||||
```bash
|
||||
# 1) 先列出附件,拿到不透明的 attachment_id(默认 image,可多选)
|
||||
wx attachments "张三"
|
||||
wx attachments "AI群" --kind image --kind video -n 100
|
||||
wx attachments "AI群" --since 2026-04-01 --until 2026-04-15
|
||||
|
||||
# 2) 用 attachment_id 把单个资源解密写到指定路径
|
||||
wx extract <attachment_id> -o ~/Desktop/photo.jpg
|
||||
wx extract <attachment_id> -o /tmp/x.jpg --overwrite
|
||||
```
|
||||
|
||||
`attachments` 输出每条带:`attachment_id` / `kind`(image/voice/video/file)/ `type` / `local_id` / `timestamp` / `time`,群聊里另带 `sender`。
|
||||
|
||||
`extract` 报告里带:`md5` / `dat_path` / `dat_size` / `output` / `output_size` / `format`(实际识别出的图片格式:jpg / png / gif / webp / hevc 等)/ `decoder`(实际选用的解码器:`legacy_xor` / `v1_aes` / `v2`)。
|
||||
|
||||
支持的解码档位:
|
||||
- **legacy XOR**:早期单字节 XOR,无 magic(按文件首字节探测格式自动反推)
|
||||
- **V1 fixed-AES**(`07 08 V1 08 07`):AES-128-ECB + 固定 key `cfcd208495d565ef`
|
||||
- **V2 AES + XOR**(`07 08 V2 08 07`):AES-128-ECB + raw + XOR;AES key 平台派生
|
||||
|
||||
V2 image key 提取(macOS / Windows 自动;Linux 暂不支持):
|
||||
- macOS:`kvcomm` cache(`key_<uin>_*.statistic` 文件名取 uin → `md5(str(uin) + wxid)[:16]`)+ brute-force fallback;`xor_key = uin & 0xff`
|
||||
- Windows:扫 `Weixin.exe` 内存匹配 `[A-Za-z0-9]{32|16}` 候选,按 V2 template ciphertext-block 反验
|
||||
|
||||
### 收藏与统计
|
||||
|
||||
```bash
|
||||
|
||||
Reference in New Issue
Block a user