<small id='zbKic'></small><noframes id='zbKic'>

    • <bdo id='zbKic'></bdo><ul id='zbKic'></ul>

      <legend id='zbKic'><style id='zbKic'><dir id='zbKic'><q id='zbKic'></q></dir></style></legend>
        <tfoot id='zbKic'></tfoot>

        <i id='zbKic'><tr id='zbKic'><dt id='zbKic'><q id='zbKic'><span id='zbKic'><b id='zbKic'><form id='zbKic'><ins id='zbKic'></ins><ul id='zbKic'></ul><sub id='zbKic'></sub></form><legend id='zbKic'></legend><bdo id='zbKic'><pre id='zbKic'><center id='zbKic'></center></pre></bdo></b><th id='zbKic'></th></span></q></dt></tr></i><div id='zbKic'><tfoot id='zbKic'></tfoot><dl id='zbKic'><fieldset id='zbKic'></fieldset></dl></div>

        如何使用 System.IdentityModel.Tokens.Jwt 生成具有 Goo

        时间:2023-06-03
              <tbody id='pGpBI'></tbody>
          • <i id='pGpBI'><tr id='pGpBI'><dt id='pGpBI'><q id='pGpBI'><span id='pGpBI'><b id='pGpBI'><form id='pGpBI'><ins id='pGpBI'></ins><ul id='pGpBI'></ul><sub id='pGpBI'></sub></form><legend id='pGpBI'></legend><bdo id='pGpBI'><pre id='pGpBI'><center id='pGpBI'></center></pre></bdo></b><th id='pGpBI'></th></span></q></dt></tr></i><div id='pGpBI'><tfoot id='pGpBI'></tfoot><dl id='pGpBI'><fieldset id='pGpBI'></fieldset></dl></div>
              <bdo id='pGpBI'></bdo><ul id='pGpBI'></ul>

              <small id='pGpBI'></small><noframes id='pGpBI'>

              <tfoot id='pGpBI'></tfoot>

              • <legend id='pGpBI'><style id='pGpBI'><dir id='pGpBI'><q id='pGpBI'></q></dir></style></legend>
                1. 本文介绍了如何使用 System.IdentityModel.Tokens.Jwt 生成具有 Google OAuth2 兼容算法 RSA SHA-256 的 JWT?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

                  问题描述

                  限时送ChatGPT账号..

                  我正在尝试创建一个 JWT 以使用 Google 文档中所述的服务帐户进行授权,使用 System.IdentityModel.Tokens.Jwt.我有以下代码:

                  I'm trying to create a JWT to authorize with a service account as described in Google documentation using System.IdentityModel.Tokens.Jwt. I have the following code:

                  byte[] key = Convert.FromBase64String("...");
                  var certificate = new X509Certificate2(key, "notasecret");
                  
                  DateTime now = DateTime.UtcNow;
                  TimeSpan span = now - UnixEpoch;
                  Claim[] claims =
                  {
                      new Claim("iss", "email@developer.gserviceaccount.com"),
                      new Claim("scope", "https://www.googleapis.com/auth/plus.me"),
                      new Claim("aud", "https://accounts.google.com/o/oauth2/token"),
                      new Claim("iat", span.TotalSeconds.ToString()),
                      new Claim("exp", span.Add(TimeSpan.FromHours(1)).TotalSeconds.ToString())
                  };
                  
                  JwtSecurityTokenHandler handler = new JwtSecurityTokenHandler();
                  var descriptor = new SecurityTokenDescriptor
                  {
                      SigningCredentials = new SigningCredentials(
                          new InMemorySymmetricSecurityKey(key),
                          "http://www.w3.org/2001/04/xmldsig-more#hmac-sha256",
                          "http://www.w3.org/2001/04/xmlenc#sha256"),
                      Subject = new ClaimsIdentity(claims)
                  };
                  
                  JwtSecurityToken jwtSecurityToken = (JwtSecurityToken)handler.CreateToken(descriptor);
                  string json = handler.WriteToken(jwtSecurityToken);
                  

                  哪个输出:

                  { "typ" : "JWT" , "alg" : "HS256" }
                  

                  虽然 Google 明确声明它支持 SHA-256:

                  While Google explicitly states it supports SHA-256:

                  服务帐号依赖于 RSA SHA-256 算法和 JWT 令牌格式

                  Service accounts rely on the RSA SHA-256 algorithm and the JWT token format

                  根据 wtSecurityTokenHandler.InboundAlgorithmMap:

                  RS256 => http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
                  HS256 => http://www.w3.org/2001/04/xmldsig-more#hmac-sha256 
                  

                  所以当我更改代码时:

                  new SigningCredentials(
                      new InMemorySymmetricSecurityKey(key),
                          "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256",
                          "http://www.w3.org/2001/04/xmlenc#sha256");
                  

                  我遇到了一个异常:

                  System.InvalidOperationException: IDX10632: SymmetricSecurityKey.GetKeyedHashAlgorithm( 'http://www.w3.org/2001/04/xmldsig-more#rsa-sha256' ) threw an exception.
                  SymmetricSecurityKey: 'System.IdentityModel.Tokens.InMemorySymmetricSecurityKey'
                  SignatureAlgorithm: 'http://www.w3.org/2001/04/xmldsig-more#rsa-sha256', check to make sure the SignatureAlgorithm is supported.
                  

                  这是否意味着微软不支持谷歌独家支持的算法?

                  Does it mean Microsoft doesn't support the algorithm Google supports exclusively?

                  推荐答案

                  private static async Task<string> GetAuthorizationToken(GoogleAuthOptions authOptions)
                  {
                      string jwt = CreateJwt(authOptions);
                  
                      var dic = new Dictionary<string, string>
                      {
                          { "grant_type", "urn:ietf:params:oauth:grant-type:jwt-bearer" },
                          { "assertion", jwt }
                      };
                      var content = new FormUrlEncodedContent(dic);
                  
                      var httpClient = new HttpClient { BaseAddress = new Uri("https://accounts.google.com") };
                      var response = await httpClient.PostAsync("/o/oauth2/token", content);
                      response.EnsureSuccessStatusCode();
                  
                      dynamic dyn = await response.Content.ReadAsAsync<dynamic>();
                      return dyn.access_token;
                  }
                  
                  private static readonly DateTime UnixEpoch = new DateTime(1970, 1, 1, 0, 0, 0, 0, DateTimeKind.Utc);
                  
                  private static string CreateJwt(GoogleAuthOptions authOptions)
                  {
                      var certificate = new X509Certificate2(Convert.FromBase64String(authOptions.CertificateKey), authOptions.CertificateSecret);
                  
                      DateTime now = DateTime.UtcNow;
                      var claimset = new
                      {
                          iss = authOptions.Issuer,
                          scope = "https://www.googleapis.com/auth/plus.me",
                          aud = authOptions.Audience,
                          iat = ((int)now.Subtract(UnixEpoch).TotalSeconds).ToString(CultureInfo.InvariantCulture),
                          exp = ((int)now.AddMinutes(55).Subtract(UnixEpoch).TotalSeconds).ToString(CultureInfo.InvariantCulture)
                      };
                  
                      // header
                      var header = new { typ = "JWT", alg = "RS256" };
                  
                      // encoded header
                      var headerSerialized = JsonConvert.SerializeObject(header);
                      var headerBytes = Encoding.UTF8.GetBytes(headerSerialized);
                      var headerEncoded = TextEncodings.Base64Url.Encode(headerBytes);
                  
                      // encoded claimset
                      var claimsetSerialized = JsonConvert.SerializeObject(claimset);
                      var claimsetBytes = Encoding.UTF8.GetBytes(claimsetSerialized);
                      var claimsetEncoded = TextEncodings.Base64Url.Encode(claimsetBytes);
                  
                      // input
                      var input = String.Join(".", headerEncoded, claimsetEncoded);
                      var inputBytes = Encoding.UTF8.GetBytes(input);
                  
                      // signiture
                      var rsa = (RSACryptoServiceProvider)certificate.PrivateKey;
                      var cspParam = new CspParameters
                      {
                          KeyContainerName = rsa.CspKeyContainerInfo.KeyContainerName,
                          KeyNumber = rsa.CspKeyContainerInfo.KeyNumber == KeyNumber.Exchange ? 1 : 2
                      };
                      var cryptoServiceProvider = new RSACryptoServiceProvider(cspParam) { PersistKeyInCsp = false };
                      var signatureBytes = cryptoServiceProvider.SignData(inputBytes, "SHA256");
                      var signatureEncoded = TextEncodings.Base64Url.Encode(signatureBytes);
                  
                      // jwt
                      return String.Join(".", headerEncoded, claimsetEncoded, signatureEncoded);
                  }
                  

                  这篇关于如何使用 System.IdentityModel.Tokens.Jwt 生成具有 Google OAuth2 兼容算法 RSA SHA-256 的 JWT?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持html5模板网!

                  上一篇:来自文件的 .NET Core IssuerSigningKey 用于 JWT 不记名 下一篇:如何对 ASP.NET WebApi 的每个请求应用自定义验证到

                  相关文章

                  最新文章

                2. <legend id='T7zwt'><style id='T7zwt'><dir id='T7zwt'><q id='T7zwt'></q></dir></style></legend>

                    <bdo id='T7zwt'></bdo><ul id='T7zwt'></ul>
                  <i id='T7zwt'><tr id='T7zwt'><dt id='T7zwt'><q id='T7zwt'><span id='T7zwt'><b id='T7zwt'><form id='T7zwt'><ins id='T7zwt'></ins><ul id='T7zwt'></ul><sub id='T7zwt'></sub></form><legend id='T7zwt'></legend><bdo id='T7zwt'><pre id='T7zwt'><center id='T7zwt'></center></pre></bdo></b><th id='T7zwt'></th></span></q></dt></tr></i><div id='T7zwt'><tfoot id='T7zwt'></tfoot><dl id='T7zwt'><fieldset id='T7zwt'></fieldset></dl></div>
                  1. <small id='T7zwt'></small><noframes id='T7zwt'>

                    1. <tfoot id='T7zwt'></tfoot>