Example #1
0
        //取得使用者信息
        public User GetUser(string token)
        {
            var split     = token.Split('.');
            var iv        = split[0];
            var encrypt   = split[1];
            var signature = split[2];

            //检查签章是否正确
            if (signature != TokenCrypto.ComputeHMACSHA256(iv + "." + encrypt, key.Substring(0, 64)))
            {
                return(null);
            }

            //使用 AES 解密 Payload
            var base64  = TokenCrypto.AESDecrypt(encrypt, key.Substring(0, 16), iv);
            var json    = Encoding.UTF8.GetString(Convert.FromBase64String(base64));
            var payload = JsonConvert.DeserializeObject <Payload>(json);

            //检查是否过期
            if (payload.Exp < Convert.ToInt32(
                    (DateTime.Now - new DateTime(1970, 1, 1)).TotalSeconds))
            {
                return(null);
            }

            return(payload.Info);
        }