예제 #1
0
        /// <summary>
        /// 颁发JWT字符串
        /// </summary>
        /// <param name="tokenModel"></param>
        /// <returns></returns>
        public static string IssueJwt(TokenModelJwt tokenModel)
        {
            var iss    = AppSettings.Apply("Audience", "Issuer");
            var aud    = AppSettings.Apply("Audience", "Audience");
            var secret = AppSettings.Apply("Audience", "Secret");

            var claims = new List <Claim>
            {
                //jwt的唯一身份标识,主要用来作为一次性token,从而回避重放攻击
                new Claim(JwtRegisteredClaimNames.Jti, tokenModel.Uid),
                //签发时间
                new Claim(JwtRegisteredClaimNames.Iat, $"{new DateTimeOffset(DateTime.Now).ToUnixTimeSeconds()}"),
                //生效时间
                new Claim(JwtRegisteredClaimNames.Nbf, $"{new DateTimeOffset(DateTime.Now).ToUnixTimeSeconds()}"),
                //过期时间
                new Claim(JwtRegisteredClaimNames.Exp,
                          $"{new DateTimeOffset(DateTime.Now.AddDays(5)).ToUnixTimeSeconds()}"),
                // 签发人
                new Claim(JwtRegisteredClaimNames.Iss, iss),
                //受众
                new Claim(JwtRegisteredClaimNames.Aud, aud),

                new Claim(ClaimTypes.Role, tokenModel.Role), //为了解决一个用户多个角色(比如:Admin,System),用下边的方法
            };

            // 可以将一个用户的多个角色全部赋予;
            //claims.AddRange(tokenModel.Role.Split(',').Select(s => new Claim(ClaimTypes.Role, s)));

            //秘钥 (SymmetricSecurityKey 对安全性的要求,密钥的长度太短会报出异常)
            var key         = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(secret));
            var credentials = new SigningCredentials(key, SecurityAlgorithms.HmacSha256);

            var jwt = new JwtSecurityToken(
                issuer: iss,
                claims: claims,
                signingCredentials: credentials);

            var jwtHandler = new JwtSecurityTokenHandler();
            var encodedJwt = jwtHandler.WriteToken(jwt);

            return(encodedJwt);
        }
예제 #2
0
        /// <summary>
        /// 解析
        /// </summary>
        /// <param name="jwtStr"></param>
        /// <returns></returns>
        public static TokenModelJwt SerializeJwt(string jwtStr)
        {
            var    jwtHandler = new JwtSecurityTokenHandler();
            var    jwtToken   = jwtHandler.ReadJwtToken(jwtStr);
            object role;

            try
            {
                jwtToken.Payload.TryGetValue(ClaimTypes.Role, out role);
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
                throw;
            }
            var tm = new TokenModelJwt
            {
                Uid  = jwtToken.Id,
                Role = role != null?role.ToString() : string.Empty
            };

            return(tm);
        }